Insurance companies are subject to a comprehensive set of regulations, including DORA. DORA (Digital Operational Resilience Act) requires financial institutions to maintain comprehensive documentation of access control to ensure digital operational resilience. This documentation should encompass e.g., roles and entitlements, access controls, and any other IAM-specific information, such as approvers, recertifications, and deviations from the standard.
Munich Re’s initial implementation comprises a combination of Word and Excel documents, as well as a custom-built web-based application. With over 5,000 applications within the company group and 1,500 IAM-integrated applications, this approach soon presents scalability challenges, difficulties in involving application owners and business departments, and concerns regarding the integrity of documented information.
To enhance and professionalise this approach, Munich Re is exploring the adoption of a standard software product (NEXIS 4) as the future standard for comprehensive end-to-end integration of Authorisation Concepts.
This session provides an overview of the obligations faced by regulated customers, highlights the challenges and limitations inherent in a document-based DIY approach, and demonstrates the use cases and capabilities investigated for the future solution.