Insurance IT Compliance Bundle for Kenya’s Insurers | Sentinel Assurance Partners Ltd
Insurance IT Compliance Bundle · Risk Register · Audit Program · Dashboards · Reports

Insurance IT Compliance Bundle for Kenya’s Insurers

The complete IRA-aligned IT compliance toolkit purpose-built for Kenya’s insurers, reinsurers and intermediaries — a Risk Register with 126 controls across 19 domains, 126+ audit procedures, 6 management dashboards, an IT audit findings log, an evidence request log, and board-ready report templates. Walk into your IRA supervision with every document ready.

126Controls in Register
126+Audit Procedures
6Built-in Dashboards
Instant download · Microsoft Excel & PowerPoint · One-insurer licence
IRA Prudential & ICT Guidelines Insurance Act (Cap 487) ODPC Data Protection Act 2019 NIST CSF 2.0 ISO/IEC 27001:2022
IRA risk-based supervision is active — insurers without documented IT controls risk qualification findings. Get examination-ready today →
The compliance challenge

New supervisory expectations have raised the bar — is your insurer ready?

The Insurance Act and IRA guidelines set mandatory requirements for every regulated insurer offering digital services. Non-compliance now attracts directed remediation, penalties, and in serious cases licence conditions.

Risk-based supervision has raised the bar

IRA supervision now tests the design and operating effectiveness of your IT and cybersecurity controls — not just their existence. Undocumented controls are becoming examination findings, not management-letter observations.

Digital distribution is under scrutiny

Supervisors are specifically testing customer portals, mobile apps, USSD and payment integrations. Insurers without documented, tested digital-channel controls are exposed where they previously were not.

Outsourcing and vendor risk is a primary focus

Documented oversight of core-system vendors, insurtech partners and cloud providers is now expected. Undocumented vendor relationships and missing contractual controls are among the most common new findings.

Generic audit templates are not enough

Generic IT audit programs do not reference the Insurance Act or IRA instruments, and do not cover insurer-specific systems — policy administration, claims, actuarial and reinsurance returns. Supervisors notice.

What’s included

126 audit controls across 19 domains

A complete insurance IT compliance bundle — Risk Register (126 controls), Overall Audit Program (126+ procedures), 6 dashboards, findings log, evidence request log and board-ready report templates. Every document a regulated insurer needs for IRA supervision readiness — ready to deploy.

GV3 procedures

ICT Governance & Strategy

  • ICT strategy aligned to the insurance business plan
  • Board and committee oversight of ICT
  • Qualified ICT leadership and accountability
RM3 procedures

ICT Risk Management & Assurance

  • ICT risk framework, register and appetite
  • Independent IT audit coverage
  • KRI monitoring and reporting
CS5 procedures

Core Insurance Systems & Regulatory Returns

  • IRA statutory return accuracy and reconciliation
  • Core-system input validation and interface controls
  • Supported, board-visible core platform roadmap
  • PAS underwriting and pricing-engine controls
  • Claims / FNOL validation against active cover
AM3 procedures

Access Management

  • Timely provisioning and revocation of access
  • Privileged access control and monitoring
  • Periodic user access reviews and SoD
CM3 procedures

Change Management

  • Authorised, tested production changes
  • Rating and product configuration change control
  • Segregation of development and production
SD3 procedures

System Development & Acquisition

  • Documented SDLC methodology and framework
  • Controlled data migration and go-live
  • Third-party development and outsourcing oversight
CY3 procedures

Cybersecurity & Vulnerability Management

  • Vulnerability scanning and patch management
  • Ransomware and destructive-attack defence
  • Security logging and monitoring (SIEM / SOC)
DP3 procedures

Data Protection & Information Security

  • ODPC / Data Protection Act 2019 compliance
  • Policyholder data encryption
  • Data classification and controlled sharing
IN3 procedures

IT Infrastructure & Data Centre

  • Data-centre environmental controls
  • Physical access security
  • Capacity and performance monitoring
BC3 procedures

Backup, BCM & Disaster Recovery

  • Tested backups and restoration
  • BCP / DRP with defined RTO and RPO
  • Business impact analysis for critical processes
IM3 procedures

Incident Management & Regulatory Reporting

  • Incident response plan and team
  • IRA and ODPC incident notification
  • Root-cause analysis and lessons learned
VM3 procedures

Vendor & Outsourcing Management

  • Vendor due diligence before onboarding
  • Security, SLA, data and audit clauses in contracts
  • Ongoing vendor performance monitoring
DC4 procedures

Digital Channels & Payments

  • Secure customer portals, mobile apps and USSD
  • Payment integration and fraud controls
  • Channel availability and resilience
  • API security for channel integrations
ET3 procedures

Emerging Technology & Innovation

  • Governed cloud adoption
  • AI / analytics governance in underwriting and claims
  • Secure insurtech APIs and integrations
AR17 procedures

Actuarial, Reinsurance & Regulatory Reporting

  • IRA solvency and statutory return generation
  • GL-to-subledger reconciliations
  • Maker-checker over return preparation
  • Real-time premium, claims and reinsurance recording
FM15 procedures

Fraud Management System

  • Rules-based claims fraud screening
  • Hold-payment investigation workflow
  • Watchlist and industry data cross-checks
  • IRA Fraud Unit and law-enforcement reporting
PA15 procedures

Policy Administration System

  • Role-based least-privilege access
  • Elevated authorisation for high-risk actions
  • Policy-capture input validation
  • System-generated policy documents and certificates
CL17 procedures

Claims Management System

  • Claim validation against active policy cover
  • Duplicate-claim detection
  • Authorisation limits and SoD at settlement
  • Multi-level and committee settlement approvals
DS17 procedures

Digital Insurance Platform Security

  • Secure SDLC and code review
  • WAF and OWASP Top 10 defence
  • Annual independent penetration testing
  • Strong API authentication (OAuth2 / mTLS)
Built-in management dashboards

6 board-ready dashboards

Most audit programs give you a spreadsheet. This bundle gives you a complete management intelligence system. The Risk Register includes 6 dashboards that auto-populate from your data — open the file, populate your controls, and your board-ready reports are ready instantly. No configuration. No extra software.

Inherent Risk Dashboard

Visual breakdown of all 126 controls by inherent rating (Critical / High / Moderate / Low) across every domain — your pre-control exposure map before any mitigation is applied.

Residual Risk Dashboard

Post-control risk profile showing exactly what remains after your controls are applied and tested — precisely what IRA supervisors look for in your IT risk framework.

Risk Reduction Analysis

Quantifies the reduction your controls deliver — inherent vs residual by domain. The evidence your Board needs that IT investment is actually reducing risk.

Risk Responses Dashboard

Reduce / Accept / Transfer / Avoid breakdown across all 126 controls by domain — demonstrating structured, risk-based decisions to supervisors and your Audit Committee.

Controls Dashboard

Your full control architecture at a glance — by control type (Preventive / Detective / Corrective / Directive) and nature (Automated / Semi-Automated / Manual) across all 19 domains.

Risk Appetite Dashboard

Maps every control’s residual risk against Board-approved appetite thresholds — instantly flags AT LIMIT and BEYOND positions requiring Audit Committee escalation.

What the data reveals

What every insurer discovers when it runs this framework

These figures come from the populated Risk Register itself — what your Audit Committee and IRA supervisor will see, and why documentation matters.

100%

Controls start at Critical or High inherent risk

All 126 controls present at Critical or High inherent risk before mitigation. Digital channels, policyholder data and IRA obligations create a high-exposure environment for every insurer. Without a documented register, your Board cannot govern this risk.

71%

Average elevated-risk reduction once controls are documented and tested

Documenting and testing controls with this framework moves the portfolio from 126 elevated risks to 36 — the exact figure your Risk Reduction Analysis dashboard reports, and the number IRA wants to see in your governance framework.

52

Controls found less than fully effective on first structured assessment

On first formal assessment, 51 controls are Partially Effective and 1 is Ineffective — each an unmitigated exposure. Finding them yourself costs the price of this bundle. Having a supervisor find them on examination day costs far more.

68

Distinct risk groups mapped across 19 domains

The Risk Register maps 126 controls to 68 risk groups — from claims fraud and policyholder-data breach to core-system integrity, change control and IRA return accuracy. Each is documented, ownership-assigned and linked to a regulatory instrument.

44

Appetite positions requiring Board escalation

On first assessment 37 controls sit Beyond Appetite and 7 At Limit — triggering mandatory Audit Committee escalation. The Risk Appetite Dashboard flags these automatically; identifying them yourself is governance maturity, not a finding.

30

Controls mapped to cybersecurity & digital-platform risk

30 controls span cybersecurity, digital channels, data protection, infrastructure and digital-platform security — covering perimeter defence, application security, WAF/penetration testing and API protection for customer-facing insurance systems.

The investment case

KES 15,000 — versus building it yourself

Every regulated insurer needs exactly what is in this bundle. Here is what producing each component independently would cost — versus purchasing the complete bundle today.

Building it in-house

  • Risk Register from scratch — 3–4 weeks of senior IT auditor research (KES 120,000+)
  • 126+ audit procedures — 2–3 weeks of drafting and regulatory alignment (KES 80,000+)
  • IRA / Insurance Act / ODPC / ISO / NIST mapping — 40–60 hours of specialist research
  • 6 management dashboards — Excel development and configuration (KES 40,000+)
  • Findings log — findings, recommendations, action plans, owners, due dates
  • Evidence request log — manual extraction from the audit program
  • Risk appetite framework calibrated to insurer thresholds
  • Board & IT management report decks — built from the dataset
  • 12-month regulatory-update maintenance
KES 280,000+
Estimated 8–10 weeks of qualified auditor time, plus ongoing maintenance

Insurance IT Compliance Bundle

  • Risk Register / RCM — 126 controls, 19 domains, fully populated
  • Overall Audit Program — 126+ procedures, 28 columns, fieldwork-ready
  • IT Audit Findings Log — findings, recommendations, action plans, owners & due dates
  • Evidence Request Log — items, date requested & response deadline
  • 6 Management Dashboards — auto-populate from your RCM data
  • Board Presentation + IT Management Report (PowerPoint)
  • IRA / Insurance Act / ODPC / ISO 27001 / COBIT / NIST — mapped, citation-ready
  • Inherent Risk Rating Calculator + scoring & appetite guides
KES 15,000
Complete bundle · Instant delivery by email · One-insurer licence
Regulatory alignment

Built on Kenya’s actual regulatory instruments

Every audit procedure is anchored to a specific regulatory requirement — not generic best practice. When supervisors ask for your audit evidence, you point to the specific control and the instrument it satisfies.

Insurance Regulatory Authority

Prudential guidelines, ICT & cybersecurity supervisory expectations and risk-based supervision for regulated insurers, reinsurers and intermediaries.

ira.go.ke ↗
Cap 487

Statutory obligations including solvency and statutory-return requirements (s.57–58) and market-conduct expectations for insurers.

Kenya Law ↗
Data Protection Act 2019

Policyholder data processing, consent, DPO appointment and ODPC registration — mapped across data-protection and digital-platform controls.

odpc.go.ke ↗
ISO/IEC 27001:2022

International information-security control framework referenced throughout the register and audit program.

iso.org ↗
COBIT 2019

IT governance and management framework anchoring governance, change, access and operations controls.

isaca.org ↗
NIST CSF 2.0 · PCI DSS v4.0

Cybersecurity framework and card-payment security for customer-facing digital insurance channels.

nist.gov ↗
Who this is for

Built for every professional involved in insurer IT assurance

Whether you are an external IT auditor, an internal audit function, a compliance officer, insurer management or a board member, this bundle gives you a structured, defensible audit approach that satisfies IRA expectations — ready to tailor and deploy.

External IT Auditors

Deploy immediately on insurer engagements — no research time. IRA-aligned procedures, evidence lists and workpaper references built in.

Internal Audit Teams

Build your annual IT audit plan around a comprehensive, regulator-aligned program that demonstrates governance maturity to the Board.

Compliance & Risk Officers

Map digital-channel and core-system controls against IRA requirements and close gaps before the supervisor does — proactive compliance.

Insurer Management

Commission a structured IT health-check to understand your compliance posture against IRA guidelines and the Insurance Act.

Board of Directors

Use the risk ratings for meaningful board-level oversight of IT and cybersecurity risk across your insurance operations.

What you receive

Everything you need — ready for your next IRA IT audit engagement

Excel

Risk Control Matrix / Risk Register

Fully populated RCM with 126 controls across 19 domains — risk statement, likelihood, impact, inherent rating, control statement, type, nature, frequency, ownership, regulatory mapping and residual rating. The living document IRA expects you to maintain.

Excel

Overall Audit Program

Step-by-step program with 126+ test procedures linked by Control ID to the Risk Register. Each procedure carries the control objective, detailed test steps, evidence required, IRA regulatory reference, sample-size guidance and 28 fieldwork & reporting columns.

Excel

IT Audit Findings Log

Remediation-tracking workflow from finding to closure, with a summary dashboard and domain breakdown.

Excel

Evidence Request Log

The complete tracking register from evidence request to receipt — evidence items across all 126 controls and 19 domains.

Dashboards

6 Board-Ready Management Dashboards

Inherent Risk, Residual Risk, Risk Reduction Analysis, Risk Responses, Controls and Risk Appetite — all auto-populate from the Risk Register. Populate once; every report updates.

PowerPoint

Board Presentation

Board-level deck covering the full risk profile — executive KPIs, domain scorecard and governance action items for the Audit Committee.

PowerPoint

IT Management Report

Detailed IT management deck — full domain analysis, control-effectiveness breakdown, residual risk by domain and the complete Management Action Plan register.

Bonus

Calculator & Scoring Guides

Inherent Risk Rating Calculator plus Risk Scoring and Risk Appetite Scoring guides — calibrate ratings to your own environment.

From our insights

Know IRA’s IT and cybersecurity expectations before you deploy

Read Sentinel’s guidance on insurer technology risk and regulatory readiness, and browse our other IT audit toolkits.

Read our insights →
Get the bundle

Insurance IT Compliance Bundle

KES
15,000
Complete bundle — all files, dashboards & reports included
  • Risk Register / RCM (126 controls, 19 domains)
  • Overall Audit Program (126+ procedures, 28 columns)
  • IT Audit Findings Log (findings, actions, owners & due dates)
  • Evidence Request Log (items, dates & deadlines)
  • 6 built-in management dashboards
  • Board Presentation (PowerPoint)
  • IT Management Report (PowerPoint)
  • Inherent Risk Rating Calculator + scoring guides
  • IRA / Insurance Act / ODPC / ISO 27001 / COBIT / NIST mapping
  • Email support from Sentinel’s audit team
Purchase & Download Now
Secure payment  |  Instant delivery by email  |  Multi-entity & firm licensing available
Add-on services

Optional services to deploy the bundle faster

The KES 15,000 bundle is complete and ready to use on its own. For insurers that want hands-on support, Sentinel’s certified IT audit team offers these optional add-on services — priced separately by organisation size and scope of work.

Add-on service · Custom pricing

Done-for-you Customisation & Configuration

We configure the Risk Register and Audit Program to your insurer’s control environment, size and lines of business — populating ownership, scope and applicable domains so your team can begin testing immediately.

Add-on service · Custom pricing

Facilitated Deployment Workshop

A remote or on-site working session where our team helps your IT and internal audit functions deploy the toolkit, calibrate risk ratings and produce your first Board-ready risk report.

Add-on service · Custom pricing

Management Action Plan Tracker Build

We populate a Management Action Plan tracker from your existing findings — each with a named owner, agreed due date and live status — giving your Audit Committee a ready remediation dashboard.

Add-on service · Custom pricing

IRA Cybersecurity Gap Review

A structured review mapping your current controls against IRA ICT and cybersecurity expectations, pinpointing exactly which controls need updating.

Add-on service · Custom pricing

Independent External Examination

Sentinel independently tests and validates your populated Risk Register and controls — delivering board- and examiner-ready assurance that internal documentation alone cannot.

Add-on service · Custom pricing

Multi-Entity & Firm Licensing

For audit firms, groups and bancassurance partners deploying across multiple entities — discounted multi-engagement licensing tailored to the number of insurers.

To add any of these services, email sales@sentinelassurancepartners.co.ke or call +254 769 546 128. You can also book a consultation or explore more toolkits in our shop.

Risk Control Matrix & Risk Register

A complete Risk Register — not just an audit checklist

The Risk Register and Overall Audit Program are linked by Control ID — every test procedure traces back to a documented risk and control. Each risk is captured at three levels: Enterprise → Intermediary → Library, aligning to risk-based supervision and your own appetite framework.

Risk Register — captured for every control

Risk & Control Identity

  • Control ID (e.g. CL/03.1)
  • Area Reference
  • Risk Entry Date
  • Domain
  • Process / Audit Area
  • Risk Title
  • Risk Description / Statement

Risk Classification

  • Enterprise Risk — Level 1
  • Intermediary Risk — Level 2
  • Library Risk — Level 3
  • Inherent Likelihood
  • Inherent Impact
  • Inherent Risk Rating

Control Details

  • Individual Control Statement
  • Control Type
  • Control Nature
  • Control Frequency
  • Control Owner
  • Control Effectiveness

Assessment & Response

  • Residual Likelihood / Impact
  • Residual Risk Rating
  • Risk Appetite Threshold & Status
  • Risk Response
  • Regulatory & Framework Mapping
  • Next Review Date
3

Risk levels per control

Operational (92), Regulatory (32) and Strategic (2) enterprise risks, decomposed into 12 intermediary and 20 library risk categories.

28

Audit Program columns

Planning, fieldwork, findings and reporting fields — control objective, test steps, evidence, regulatory reference, sample size, conclusion and management action.

68

Risk groups mapped

126 controls organised into 68 distinct risk groups across all 19 domains — each ownership-assigned and linked to a regulatory instrument.

Why Sentinel

Written by certified IT auditors with 15+ years of financial-sector experience

Sentinel Assurance Partners Ltd is a Nairobi-based, structurally independent IT audit, cybersecurity assurance and technology risk advisory firm — with no vendor or reseller relationships. We serve insurers, banks, SACCOs, fintechs and government across East Africa, combining global experience with deep fluency in Kenya’s regulatory environment.

CISAIT Audit
CISSPSecurity
CRISCRisk
CCSPCloud
CDPSEData Privacy
AIGPAI Governance
15+ yrsExperience
  • Certified Information Systems Auditor (CISA) — ISACA
  • Certified Information Systems Security Professional (CISSP)
  • Certified in Risk & Information Systems Control (CRISC)
  • Certified Cloud Security Professional (CCSP)
  • Certified Data Privacy Solutions Engineer (CDPSE)
  • AI Governance Professional (AIGP) — IAPP
Frequently asked questions

Common questions from insurer auditors and compliance officers

Is this bundle aligned to IRA requirements?
Yes. Every control and audit procedure is anchored to a specific regulatory instrument — the Insurance Act (Cap 487), IRA prudential and ICT/cybersecurity guidelines, IRA risk-based supervision, and the Data Protection Act 2019 — alongside ISO/IEC 27001:2022, COBIT 2019 and NIST CSF. It is citation-ready for supervisory responses.
Which insurers is it built for?
General, life, medical and composite insurers, reinsurers, and bancassurance and intermediary operations regulated by the IRA. Domains cover core insurance systems, policy administration, claims, actuarial/reinsurance returns, fraud and digital-platform security.
What format are the files, and do I need special software?
The Risk Register, Audit Program, Findings Log and Evidence Request Log are Microsoft Excel workbooks; the Board and IT Management reports are PowerPoint decks. You need Microsoft Excel and PowerPoint — no other software or subscriptions.
Can I customise it to my insurer?
Yes. All fields are unlocked. Update risk ratings, control effectiveness, ownership and findings from your own fieldwork. The dashboards recalculate automatically as you populate your data.
How is it delivered?
Instantly by email download after payment. You receive the complete bundle — all workbooks, dashboards and report templates — ready to deploy.
Is licensing per entity?
The standard price is a one-insurer licence. Audit firms, groups and bancassurance partners deploying across multiple entities can request discounted multi-entity licensing.
Do you provide support?
Yes — email support from Sentinel’s certified IT audit team is included. Hands-on customisation, deployment workshops and independent examination are available as optional add-on services.

Walk into your next IRA review with every document ready

Risk Register, Audit Program, 6 dashboards, findings and evidence logs, and board-ready reports — the complete insurer IT compliance toolkit, delivered instantly.

Get the Full Bundle — KES 15,000