Thanks, Matthias, and thanks for having me. It's my very first time being a speaker at the EIC, so maybe you have some patience with me going forward in the presentation. I would like to run you through the way and the approach we started having a more digitalized governance. It's not really only about the topic of IAM as such. It's more about the topic of having a proper IT governance in a large enterprise like ours. Short numbers.
We do, as BMW Group, have sold 2.67 million vehicles and motorcycles. It's really about BMW, it's about MINI, it's about Rolls-Royce, but also awesome motorcycles. When we talk about a large enterprise, then we talk about 155,000 employees worldwide, a set-up of 32 production locations worldwide.
When we talk about IT, so the BMW Group IT is set up centrally, but also globally, and that's not that much the follow-the-sun idea, but more really having global set-up in the markets, first of all, but also having the right skills in the right area, meaning BMW Group IT is 16 nationalities in 30 countries. We partner in terms of scaling workforce in so-called DevOps hubs globally, and standard-wise we partner in kind of joint ventures.
And it's about a workforce of 10,000, around about 10,000 people, and more than 9,000 applications we are running out of Group IT to run our business worldwide. We are fully set up in a product orientation, so in an agile mode, and we organized our IT and our IT applications within 63 domains with hundreds of products which apply then to the IT applications.
Having said that, you might have an idea, 9,000 applications, about the complexity of how we would need to govern that landscape, and maybe to be very clear, so a grown governance, a complexity in large enterprise, you might see similar approaches in your area as well. The larger an enterprise is, the more fragmented maybe also the governance pillars are, like architecture, security, operations, but also then my area of identity and access management. Same applies to kind of implementation, so meaning having governance in different tools.
So even in the area of IAM already, we do have quite a couple of systems where applications have to document and have to provide their evidence for compliance, but also the rest of the GSC tool landscape is quite heterogeneous. And so this ends up in a no-structured, let's really call it no-structured user journey for the terms of IT governance tasks, so where do I maintain all the information for my application as an application owner to fulfill or to provide evidence how to comply.
And there's a couple of topics then coming in with increasing external regulation with the need for faster decisions in quite heavily changing times. Also in our industry, it's quite hard. And for sure, on the other hand, you have to deal with legacy systems on the one hand side, but also new technologies, and I won't use that word here in my presentation.
So you come up with for sure actions needed, how we would require to get a better user experience in terms of how we would like to provide evidence for compliance and security, and you really can bring that down to we need to change processes, how we would like to do governance as such. We need to have a look into our data structure, what kind of information do we already have. We have to apply changes into our way of writing policies and artifacts.
Oh, now I have to use the word. We for sure need to apply automation for sure, but also how can AI help us here. And at the end of the day, we got lots of complaints by the whole organization. So in the end of the day, it's also about user experience for thousands of users. Maybe you heard it or you saw it in the press. Like we redefined currently our product portfolio with the Neue Klasse, we really wanted to start reshaping our governance processes, and this is aligned to our overall strategy.
You can see it in the middle with five pillars and the operational excellence as a baseline, but overall tag for us was simplifying governance, simplifying governance, make it easier, make it more tangible. And the key for that is not applying just a tool, because a fool with a tool is still a fool. It was about the methodology behind how we would like to put a new way of doing governance into our architecture, into our organization. There's two ways of how we reshaped how we would like to deal with the information we already have and how we would like to structure to interpret the data.
So first of all, and at the end of the day, all eight topics are kind of perspectives you can take to have a view or to have a reporting on your governance perspective. First of all, on the right-hand side, so that's more the given part of enterprise architecture, more or less. So you have infrastructure assets. You can sort them into the applicability of IT systems, so what kind of assets are in the systems.
You have to use information classification, so structure your data, analyze your data, classify your information you have, you know of, and ideally put that into or align that with your processes. And then with the data and with the processes, for sure then also business kicks in. So this is actually where you have to ask your business out there, please tell me about the criticality of your processes, of your information.
Think of if you link that, so processes with the data given, with the supporting IT systems and the infrastructure assets, you can already take a lot of different perspectives, how critical an access can be, how important it is to protect an access with, for example, strong auth, in terms of the higher the criticality of a process is. And on the left-hand side, it is about how we would like to write our policies, how we would like to write our rules, and this is quite easily derived, coming from strategic targets, going down to objectives in the different governance capabilities.
So in our area, for sure, IAM, authentication, authorization, what do we want to achieve? And then put risks on it. So what is the topic of, or what could go wrong to not achieve my targets? According to these risks, you then put the controls in place, meaning find the way how this should be achieved, or how, as an application owner, can check myself, do I fulfill the control? Then the risk does not, or does normally not apply to me, and I can fulfill the objective. The other way around, if I don't fulfill the policy, the control, then I immediately have to check on my risk.
And as we sorted, then, also the controls to external regulations, like we mapped it to ESO, we mapped it to TSARC STORA, to SIS controls, it easily can be derived that if someone doesn't fulfill the control, we do have an issue during the audit with that application, according to that control. So that's about the methodology behind, and that's why I said relation is key. And having these insights to get, then, the different perspectives, so I can go for what are my most critical processes, what are my controls which are not fulfilled the most.
And these insights now can be built into a kind of tool chain kind of support, and this is now where an idea kicks in, where we wanted to build a governance tool chain, or a kind of governance overlay, and we would like to fulfill two different approaches.
And when it comes to IEM, now it's more the IEM part, we really would like to fulfill the horizontal approach on the one-hand side, means that's more the governance part, so documentation, and everything what we leveraged as we linked the information already between the applications, supporting, following information, and so on and so forth, we can easily derive dashboards and the full transparency on visibility on the current status. This is more the horizontal approach, and by reusing the data, it easily ends up for the different application owners with less documentation.
So think about the user experience. The best user experience is you don't have to do it. You don't have to put it in place in a different tool again, and so on and so forth.
And the other one, the second approach we would like to tackle with our set-up diamond tool is the so-called vertical integration, meaning not really put governance tasks into the organization, but making services an application has to consume implicitly compliant and bring it to everybody's attention by not documenting it, but really during the design, during the initial design of my application, I start writing my IM concept, and I start thinking of how I would like to design my roles, and this is now not a paperwork.
It's getting into action because after having the document released, so everybody has approved who needed to approve, it is applied to our IGA tool. So the roles I described in my concept will be then immediately provisioned to ready to be ordered. That's basically what we see as the vertical integration. Same applies to integrating standards for authentication, for example. And I just brought some examples how we would really like to put that, and now it's the other word in there.
So this more automated approach, this kind of bring the governance with the implementation part in application into one view allows to scale because if I do have the data available, if I can easily derive inputs or I can guide the user, the application owner to take the right input. So if my application has secret information, I do have to implement the strongest factor of authentication we as BMW provide. This is the way how we can really enforce standards in building applications.
So if we have and taking now the tool chain into consideration as a whole, we do have the continuous evidence generation. So as the people have to work with this kind of governance tool chain, it can be easily derived in terms of audit preparation. Maybe you have that also in mind. The next TSX per location audit is the recertification is ongoing. What do you do standard-wise? Send a survey, send an extra spreadsheet. Please put in your information. So that's actually we do have it at one click. Integrated governance workflows is exactly what I just mentioned as an example beforehand.
So if I go into my documentation and I change a role, I do have it changed in my concept. It is released. It will be deployed in the IGA tool. And there is never ever this no longer outdated concept any longer. The next topic is about the real-time compliance monitoring. I change something in my application. I add another instance. But I have to apply a strong authentication integration. So if I do have a new deployment and it won't get integrated into our central IDP, it's immediately measured and it's immediately alarmed to then put compensating measures in place or to just remediate.
Efficiency and transparency means, for sure, I have a validated structure of input. If you have a highest protection application, you can only use these kind of services. And there is only that one point in our whole documentation where everything is sorted and validated and qualified. So quite a journey, but I think key takeaways for you, as we learned a lot during that journey so far, it's all about know your data, for sure, and you have a lot of data. You will find it. You have to just collect it and link it to each other. This means build data relationships.
And for sure, if you are able to enable your central services to be implicitly compliant, you can really use a spread effect of these kind of platforms and standards to scale. Also, if you have 9,000 applications or much more agents. That's it. Thank you very much. Thank you very much. And they did not let me down. So we have questions, a very quick one.
Yeah, we will ask the question. We will catch up later. The vertical integration tool that you've mentioned, is this something that can be bought on the market that you created yourself? We POC'd it last year, and we see that it's a kind of an EVIP functionality, the best that we find currently in the market. So there is a couple of vendors being able to do so, and we're now really in that phase to check who scales and who is the best for BMW.
Okay, great. Thank you very much. You will be around for more questions? Sure. So please reach out for further questions to Björn. Thank you very much.