Insurance IT Compliance Bundle for Kenya’s Insurers
The complete IRA-aligned IT compliance toolkit purpose-built for Kenya’s insurers, reinsurers and intermediaries — a Risk Register with 126 controls across 19 domains, 126+ audit procedures, 6 management dashboards, an IT audit findings log, an evidence request log, and board-ready report templates. Walk into your IRA supervision with every document ready.
New supervisory expectations have raised the bar — is your insurer ready?
The Insurance Act and IRA guidelines set mandatory requirements for every regulated insurer offering digital services. Non-compliance now attracts directed remediation, penalties, and in serious cases licence conditions.
Risk-based supervision has raised the bar
IRA supervision now tests the design and operating effectiveness of your IT and cybersecurity controls — not just their existence. Undocumented controls are becoming examination findings, not management-letter observations.
Digital distribution is under scrutiny
Supervisors are specifically testing customer portals, mobile apps, USSD and payment integrations. Insurers without documented, tested digital-channel controls are exposed where they previously were not.
Outsourcing and vendor risk is a primary focus
Documented oversight of core-system vendors, insurtech partners and cloud providers is now expected. Undocumented vendor relationships and missing contractual controls are among the most common new findings.
Generic audit templates are not enough
Generic IT audit programs do not reference the Insurance Act or IRA instruments, and do not cover insurer-specific systems — policy administration, claims, actuarial and reinsurance returns. Supervisors notice.
126 audit controls across 19 domains
A complete insurance IT compliance bundle — Risk Register (126 controls), Overall Audit Program (126+ procedures), 6 dashboards, findings log, evidence request log and board-ready report templates. Every document a regulated insurer needs for IRA supervision readiness — ready to deploy.
ICT Governance & Strategy
- ICT strategy aligned to the insurance business plan
- Board and committee oversight of ICT
- Qualified ICT leadership and accountability
ICT Risk Management & Assurance
- ICT risk framework, register and appetite
- Independent IT audit coverage
- KRI monitoring and reporting
Core Insurance Systems & Regulatory Returns
- IRA statutory return accuracy and reconciliation
- Core-system input validation and interface controls
- Supported, board-visible core platform roadmap
- PAS underwriting and pricing-engine controls
- Claims / FNOL validation against active cover
Access Management
- Timely provisioning and revocation of access
- Privileged access control and monitoring
- Periodic user access reviews and SoD
Change Management
- Authorised, tested production changes
- Rating and product configuration change control
- Segregation of development and production
System Development & Acquisition
- Documented SDLC methodology and framework
- Controlled data migration and go-live
- Third-party development and outsourcing oversight
Cybersecurity & Vulnerability Management
- Vulnerability scanning and patch management
- Ransomware and destructive-attack defence
- Security logging and monitoring (SIEM / SOC)
Data Protection & Information Security
- ODPC / Data Protection Act 2019 compliance
- Policyholder data encryption
- Data classification and controlled sharing
IT Infrastructure & Data Centre
- Data-centre environmental controls
- Physical access security
- Capacity and performance monitoring
Backup, BCM & Disaster Recovery
- Tested backups and restoration
- BCP / DRP with defined RTO and RPO
- Business impact analysis for critical processes
Incident Management & Regulatory Reporting
- Incident response plan and team
- IRA and ODPC incident notification
- Root-cause analysis and lessons learned
Vendor & Outsourcing Management
- Vendor due diligence before onboarding
- Security, SLA, data and audit clauses in contracts
- Ongoing vendor performance monitoring
Digital Channels & Payments
- Secure customer portals, mobile apps and USSD
- Payment integration and fraud controls
- Channel availability and resilience
- API security for channel integrations
Emerging Technology & Innovation
- Governed cloud adoption
- AI / analytics governance in underwriting and claims
- Secure insurtech APIs and integrations
Actuarial, Reinsurance & Regulatory Reporting
- IRA solvency and statutory return generation
- GL-to-subledger reconciliations
- Maker-checker over return preparation
- Real-time premium, claims and reinsurance recording
Fraud Management System
- Rules-based claims fraud screening
- Hold-payment investigation workflow
- Watchlist and industry data cross-checks
- IRA Fraud Unit and law-enforcement reporting
Policy Administration System
- Role-based least-privilege access
- Elevated authorisation for high-risk actions
- Policy-capture input validation
- System-generated policy documents and certificates
Claims Management System
- Claim validation against active policy cover
- Duplicate-claim detection
- Authorisation limits and SoD at settlement
- Multi-level and committee settlement approvals
Digital Insurance Platform Security
- Secure SDLC and code review
- WAF and OWASP Top 10 defence
- Annual independent penetration testing
- Strong API authentication (OAuth2 / mTLS)
6 board-ready dashboards
Most audit programs give you a spreadsheet. This bundle gives you a complete management intelligence system. The Risk Register includes 6 dashboards that auto-populate from your data — open the file, populate your controls, and your board-ready reports are ready instantly. No configuration. No extra software.
Inherent Risk Dashboard
Visual breakdown of all 126 controls by inherent rating (Critical / High / Moderate / Low) across every domain — your pre-control exposure map before any mitigation is applied.
Residual Risk Dashboard
Post-control risk profile showing exactly what remains after your controls are applied and tested — precisely what IRA supervisors look for in your IT risk framework.
Risk Reduction Analysis
Quantifies the reduction your controls deliver — inherent vs residual by domain. The evidence your Board needs that IT investment is actually reducing risk.
Risk Responses Dashboard
Reduce / Accept / Transfer / Avoid breakdown across all 126 controls by domain — demonstrating structured, risk-based decisions to supervisors and your Audit Committee.
Controls Dashboard
Your full control architecture at a glance — by control type (Preventive / Detective / Corrective / Directive) and nature (Automated / Semi-Automated / Manual) across all 19 domains.
Risk Appetite Dashboard
Maps every control’s residual risk against Board-approved appetite thresholds — instantly flags AT LIMIT and BEYOND positions requiring Audit Committee escalation.
What every insurer discovers when it runs this framework
These figures come from the populated Risk Register itself — what your Audit Committee and IRA supervisor will see, and why documentation matters.
Controls start at Critical or High inherent risk
All 126 controls present at Critical or High inherent risk before mitigation. Digital channels, policyholder data and IRA obligations create a high-exposure environment for every insurer. Without a documented register, your Board cannot govern this risk.
Average elevated-risk reduction once controls are documented and tested
Documenting and testing controls with this framework moves the portfolio from 126 elevated risks to 36 — the exact figure your Risk Reduction Analysis dashboard reports, and the number IRA wants to see in your governance framework.
Controls found less than fully effective on first structured assessment
On first formal assessment, 51 controls are Partially Effective and 1 is Ineffective — each an unmitigated exposure. Finding them yourself costs the price of this bundle. Having a supervisor find them on examination day costs far more.
Distinct risk groups mapped across 19 domains
The Risk Register maps 126 controls to 68 risk groups — from claims fraud and policyholder-data breach to core-system integrity, change control and IRA return accuracy. Each is documented, ownership-assigned and linked to a regulatory instrument.
Appetite positions requiring Board escalation
On first assessment 37 controls sit Beyond Appetite and 7 At Limit — triggering mandatory Audit Committee escalation. The Risk Appetite Dashboard flags these automatically; identifying them yourself is governance maturity, not a finding.
Controls mapped to cybersecurity & digital-platform risk
30 controls span cybersecurity, digital channels, data protection, infrastructure and digital-platform security — covering perimeter defence, application security, WAF/penetration testing and API protection for customer-facing insurance systems.
KES 15,000 — versus building it yourself
Every regulated insurer needs exactly what is in this bundle. Here is what producing each component independently would cost — versus purchasing the complete bundle today.
Building it in-house
- Risk Register from scratch — 3–4 weeks of senior IT auditor research (KES 120,000+)
- 126+ audit procedures — 2–3 weeks of drafting and regulatory alignment (KES 80,000+)
- IRA / Insurance Act / ODPC / ISO / NIST mapping — 40–60 hours of specialist research
- 6 management dashboards — Excel development and configuration (KES 40,000+)
- Findings log — findings, recommendations, action plans, owners, due dates
- Evidence request log — manual extraction from the audit program
- Risk appetite framework calibrated to insurer thresholds
- Board & IT management report decks — built from the dataset
- 12-month regulatory-update maintenance
Insurance IT Compliance Bundle
- Risk Register / RCM — 126 controls, 19 domains, fully populated
- Overall Audit Program — 126+ procedures, 28 columns, fieldwork-ready
- IT Audit Findings Log — findings, recommendations, action plans, owners & due dates
- Evidence Request Log — items, date requested & response deadline
- 6 Management Dashboards — auto-populate from your RCM data
- Board Presentation + IT Management Report (PowerPoint)
- IRA / Insurance Act / ODPC / ISO 27001 / COBIT / NIST — mapped, citation-ready
- Inherent Risk Rating Calculator + scoring & appetite guides
Built on Kenya’s actual regulatory instruments
Every audit procedure is anchored to a specific regulatory requirement — not generic best practice. When supervisors ask for your audit evidence, you point to the specific control and the instrument it satisfies.
Prudential guidelines, ICT & cybersecurity supervisory expectations and risk-based supervision for regulated insurers, reinsurers and intermediaries.
ira.go.ke ↗Statutory obligations including solvency and statutory-return requirements (s.57–58) and market-conduct expectations for insurers.
Kenya Law ↗Policyholder data processing, consent, DPO appointment and ODPC registration — mapped across data-protection and digital-platform controls.
odpc.go.ke ↗International information-security control framework referenced throughout the register and audit program.
iso.org ↗IT governance and management framework anchoring governance, change, access and operations controls.
isaca.org ↗Cybersecurity framework and card-payment security for customer-facing digital insurance channels.
nist.gov ↗Built for every professional involved in insurer IT assurance
Whether you are an external IT auditor, an internal audit function, a compliance officer, insurer management or a board member, this bundle gives you a structured, defensible audit approach that satisfies IRA expectations — ready to tailor and deploy.
External IT Auditors
Deploy immediately on insurer engagements — no research time. IRA-aligned procedures, evidence lists and workpaper references built in.
Internal Audit Teams
Build your annual IT audit plan around a comprehensive, regulator-aligned program that demonstrates governance maturity to the Board.
Compliance & Risk Officers
Map digital-channel and core-system controls against IRA requirements and close gaps before the supervisor does — proactive compliance.
Insurer Management
Commission a structured IT health-check to understand your compliance posture against IRA guidelines and the Insurance Act.
Board of Directors
Use the risk ratings for meaningful board-level oversight of IT and cybersecurity risk across your insurance operations.
Everything you need — ready for your next IRA IT audit engagement
Risk Control Matrix / Risk Register
Fully populated RCM with 126 controls across 19 domains — risk statement, likelihood, impact, inherent rating, control statement, type, nature, frequency, ownership, regulatory mapping and residual rating. The living document IRA expects you to maintain.
Overall Audit Program
Step-by-step program with 126+ test procedures linked by Control ID to the Risk Register. Each procedure carries the control objective, detailed test steps, evidence required, IRA regulatory reference, sample-size guidance and 28 fieldwork & reporting columns.
IT Audit Findings Log
Remediation-tracking workflow from finding to closure, with a summary dashboard and domain breakdown.
Evidence Request Log
The complete tracking register from evidence request to receipt — evidence items across all 126 controls and 19 domains.
6 Board-Ready Management Dashboards
Inherent Risk, Residual Risk, Risk Reduction Analysis, Risk Responses, Controls and Risk Appetite — all auto-populate from the Risk Register. Populate once; every report updates.
Board Presentation
Board-level deck covering the full risk profile — executive KPIs, domain scorecard and governance action items for the Audit Committee.
IT Management Report
Detailed IT management deck — full domain analysis, control-effectiveness breakdown, residual risk by domain and the complete Management Action Plan register.
Calculator & Scoring Guides
Inherent Risk Rating Calculator plus Risk Scoring and Risk Appetite Scoring guides — calibrate ratings to your own environment.
Know IRA’s IT and cybersecurity expectations before you deploy
Read Sentinel’s guidance on insurer technology risk and regulatory readiness, and browse our other IT audit toolkits.
Insurance IT Compliance Bundle
- Risk Register / RCM (126 controls, 19 domains)
- Overall Audit Program (126+ procedures, 28 columns)
- IT Audit Findings Log (findings, actions, owners & due dates)
- Evidence Request Log (items, dates & deadlines)
- 6 built-in management dashboards
- Board Presentation (PowerPoint)
- IT Management Report (PowerPoint)
- Inherent Risk Rating Calculator + scoring guides
- IRA / Insurance Act / ODPC / ISO 27001 / COBIT / NIST mapping
- Email support from Sentinel’s audit team
Optional services to deploy the bundle faster
The KES 15,000 bundle is complete and ready to use on its own. For insurers that want hands-on support, Sentinel’s certified IT audit team offers these optional add-on services — priced separately by organisation size and scope of work.
Done-for-you Customisation & Configuration
We configure the Risk Register and Audit Program to your insurer’s control environment, size and lines of business — populating ownership, scope and applicable domains so your team can begin testing immediately.
Facilitated Deployment Workshop
A remote or on-site working session where our team helps your IT and internal audit functions deploy the toolkit, calibrate risk ratings and produce your first Board-ready risk report.
Management Action Plan Tracker Build
We populate a Management Action Plan tracker from your existing findings — each with a named owner, agreed due date and live status — giving your Audit Committee a ready remediation dashboard.
IRA Cybersecurity Gap Review
A structured review mapping your current controls against IRA ICT and cybersecurity expectations, pinpointing exactly which controls need updating.
Independent External Examination
Sentinel independently tests and validates your populated Risk Register and controls — delivering board- and examiner-ready assurance that internal documentation alone cannot.
Multi-Entity & Firm Licensing
For audit firms, groups and bancassurance partners deploying across multiple entities — discounted multi-engagement licensing tailored to the number of insurers.
To add any of these services, email sales@sentinelassurancepartners.co.ke or call +254 769 546 128. You can also book a consultation or explore more toolkits in our shop.
A complete Risk Register — not just an audit checklist
The Risk Register and Overall Audit Program are linked by Control ID — every test procedure traces back to a documented risk and control. Each risk is captured at three levels: Enterprise → Intermediary → Library, aligning to risk-based supervision and your own appetite framework.
Risk Register — captured for every control
Risk & Control Identity
- Control ID (e.g. CL/03.1)
- Area Reference
- Risk Entry Date
- Domain
- Process / Audit Area
- Risk Title
- Risk Description / Statement
Risk Classification
- Enterprise Risk — Level 1
- Intermediary Risk — Level 2
- Library Risk — Level 3
- Inherent Likelihood
- Inherent Impact
- Inherent Risk Rating
Control Details
- Individual Control Statement
- Control Type
- Control Nature
- Control Frequency
- Control Owner
- Control Effectiveness
Assessment & Response
- Residual Likelihood / Impact
- Residual Risk Rating
- Risk Appetite Threshold & Status
- Risk Response
- Regulatory & Framework Mapping
- Next Review Date
Risk levels per control
Operational (92), Regulatory (32) and Strategic (2) enterprise risks, decomposed into 12 intermediary and 20 library risk categories.
Audit Program columns
Planning, fieldwork, findings and reporting fields — control objective, test steps, evidence, regulatory reference, sample size, conclusion and management action.
Risk groups mapped
126 controls organised into 68 distinct risk groups across all 19 domains — each ownership-assigned and linked to a regulatory instrument.
Written by certified IT auditors with 15+ years of financial-sector experience
Sentinel Assurance Partners Ltd is a Nairobi-based, structurally independent IT audit, cybersecurity assurance and technology risk advisory firm — with no vendor or reseller relationships. We serve insurers, banks, SACCOs, fintechs and government across East Africa, combining global experience with deep fluency in Kenya’s regulatory environment.
- Certified Information Systems Auditor (CISA) — ISACA
- Certified Information Systems Security Professional (CISSP)
- Certified in Risk & Information Systems Control (CRISC)
- Certified Cloud Security Professional (CCSP)
- Certified Data Privacy Solutions Engineer (CDPSE)
- AI Governance Professional (AIGP) — IAPP
Common questions from insurer auditors and compliance officers
Is this bundle aligned to IRA requirements?
Which insurers is it built for?
What format are the files, and do I need special software?
Can I customise it to my insurer?
How is it delivered?
Is licensing per entity?
Do you provide support?
Walk into your next IRA review with every document ready
Risk Register, Audit Program, 6 dashboards, findings and evidence logs, and board-ready reports — the complete insurer IT compliance toolkit, delivered instantly.
Get the Full Bundle — KES 15,000