I work for the If P&C Insurance company, which is the largest insurance company in the Nordic countries. We operate in Scandinavia and Baltic countries. Legally different sometimes companies, but as one big, big group of companies. And we insure and we do regular insurance, let's say. So like we insure cars, houses, people, health and their liabilities. And if you look at our portfolio of customers, we have more than half of money coming from private customers. And then there is also pretty much a large segment of commercial customers who buy standardized, replicable products from us.
And there is also a number of super large customers. We call them industrial, which have everybody have their unique risks. We have to insure. So that's the split. And what's common about all of them that we are a digital first company. We try to deliver our products and services digitally throughout the whole supply chain, not only to the customers, but also when we talk and cooperate with our partners.
And about partners, so we partner for different things with different organizations for like obviously for sales, for distribution, like car dealers, car manufacturers, brokers, banks to distribute our insurance products. And also on the claim side, when something happens. So we have assistance companies who help our customers to deal with problems when they have them. Roadside assistance, travel, medical institutions, medical organizations and some construction workers, car repair shops, different kind of partners.
Overall, we have estimated the number of partners to be about seven to eight thousand in the Nordics only because we have also many partners outside Nordics when we follow our customers across the globe like large customers. But in Nordic alone, there are about seven to eight thousand companies. We partner with. And.
Each of them have employees, and then we have to multiply number of partners with number of employees to estimate the number of how many user accounts we need to have for them when they connect to us, because because we often process our customers personal data, including sensitive data. So we we clearly have to take care of compliance, not only about security, but compliance and user experience for partners.
And so and that's that for decades, it used to be a huge pain and like really important question for us how to make sure that people who we, I mean, partner employees who we onboard are really still their work for the partners, because it's the it's pretty easy to give away new credentials. But what to do next? That's how to take care for the whole lifecycle of this credentials of this user identity. And that's a pain because it's every business unit who deals with partners. They have to appoint somebody who does audit reviews or access reviews regularly.
So to follow if that person is still there because they. Change their roles, they leave companies and every such event should trigger something on our side as well, and it doesn't always happen immediately and sometimes maybe never happens.
However, it should. And, you know, when these identity, like from employees, partner employees perspective, if this identity protects only the data captain, if I really don't care much about this data so I can easily share these credentials with somebody to help me, to back me up. Or when in car repair shops, they use the same computer to to to do insurance stuff. So everybody comes and maybe uses the same username and password. And maybe the the originally the person who has got it from us already left the company. We don't know. And that's a problem. And that was the demand from the business.
How to address this? Because at scale, it's a huge problem. And we thought, OK, what if we make it their problem, not our problem or our common problem, at least with partners? And let's bring this authentication stuff out of if. To the partner, let if if if their partners, it means we trust them, at least in some business aspects. Let's find out if we can trust them in each particular case with the user identity lifecycle management, like if they can deal properly with their own users so we can trust them in that as well.
So and that was a very important shift, I would say, because a game changer, because now they also care because they care about their own data. And if we can rely on them in this, that's a clear benefit for them and for us as well. And on the technical side, that's the most technical slide I have. But on the technical side, it wasn't really a problem for us. We have the internal identity provider broker platform, which we have all the different national schemas connected to, like BankID, MeetID, SmartID, you name it in every country.
And this is purity that is not the advertisement, but we really like it. And all our internal teams who deliver new services to the customers, to partners, they are fed from this platform for user authentication. So and we provide services internally to them. That's our enabler function. And now we just plug into the same platform new partners every time they arrive, like Ziclo Bank, for example, the one I've got permission to mention here. So but also different insurance brokers, claims assistant companies, car manufacturers, maybe some of them also who we missed today here.
So and it just works because now our internal consumers, they just call Ziclo EnterID directory to authenticate users. That's how it works. Technically, it didn't really take long from user perspective. What's the benefit for the employee of the partner was we become a native service to them. It's not anymore something they have to go somewhere, log in.
OK, wait, I need to go to ETHNUM. It's just we are there. We are stepping into their perimeter and feel like we're a very convenient thing for them or service to them. So they authenticate with the same credentials they used to unlock or log into their computers in the morning. So and maybe and very often it's just as I saw that it's just just just there. So that's that's a game changer for them as well. And behind the scenes, of course, there is EnterID of Ziclo in this example who tells us if this user has successfully authenticated. That's what we want to know, obviously.
And more than that, this directory, this IDP provides the context, some at least some context to us who this user is. So like the security group membership. So and when we get this context, like, OK, authenticated, good. And now this user is belongs to the sales and insurance group security groups.
For us, this is a trigger or the input to make authorization decision on our side. Like when we get this information, our partner portal, for example, can check.
OK, if this is the first time we see this user from the sales and insurance groups, maybe we need to trigger the onboarding and train him and provide some online training, a certification to distribute insurance, car insurance or whatever kind of insurance they sell at that point. And if it's not the first time or the certification, this training hasn't expired or we we don't have any updates on our products. She just goes in and sees the list of policies and can can work with them and can sell and do stuff for our common customer.
So that's the very important input for us to make authorization decisions on the fly in the real time. And no manual work is needed there anymore. And obviously, she was due to some reasons, her account gets blocked or disabled or just she forget the password or some credentials. She can't log in to their own and she can't log in. So it's the time between she we shouldn't be authenticating her and we really don't do it anymore. It shrinks to zero, like from maybe a year to zero. Right.
So that's dramatic improvement in security, in how we reduce our risk exposure and in practical compliance, not only on the paper. So, yeah, that's she doesn't get anywhere with us as well. So but the problem was then when we shared these ideas and we've been sharing these ideas for some long time with the business, it sounded very much complicated because what they were, our business, I mean, what they were afraid of was, oh, we need to go to the partner and require some some technical people like the group of people to people to develop, to integrate, to do stuff.
That's a pain that we we believe they just would prefer somebody else or just not to do it. We were almost out of arguments to persuade them that that's a very good way to go. What we did, we we run one small experiment with me because I'm not a developer. I never earned any single euro in my life as a developer, but I can configure things, I can click things around and I can like configure a little entropy. So and my team, they have provided me with visual instructions of how to do this on the partner side if I was a partner. So click here, click here, type here, copy, paste.
And I did this, followed the instructions, also did screen recording and also voice voice over what I was doing. And we we've got a couple of short videos, but I did it in 70 minutes, including testing how it works. So and we use this video to promote it further, to to to to get business buying for this thing. And suddenly they yeah, OK, they decided to give it a try. And and and they couldn't expect that positive that positive feedback from the partners, partners were happy. So it really went fast.
I mean, configuring part went fast, really fast. So like half an hour or something. But then it was all about like Patrick mentioned policies and and and everything else. Like how because Federation, it's all about trust. It's not any more about technically configuring it.
It's about trust and this and finding out if we really should trust the partner, if they really follow the all the at least similar principles and their security practices and their like legal environment, how do they onboard their their employees and everything else like finding this out and out and aligning and putting everything else or some risks which we do not control into the contract and transferring those over to the partner takes time. Takes much more time than configuring things itself. So but that's something to do. And I think that makes sense doing now.
We do not run and sell these things. Our business is happy to do that. And they really approach customers and ask us, help us to deliver this message as simple as possible to the partner, because we really see value in this. And and that's booming this year, I can say. And of course, it takes also like this conversation with partners, it's it's not only like, OK, signing a contract, it's learning, teaching, maybe and also listening carefully. That's the most important part, I would say, in this B2B federation in our case. And everybody wins in this case. Everybody likes it.
Like partners, us and employees of the partners. But the best thing for us from a business perspective here is not like maybe just smooth processes, but loyalty of partners. We are in competitive situation with other insurance providers and we'd like to be preferred partner for our partners. So we'd like our insurance services to be offered to the customers, to the end customers, by our partners. So that's the loyalty and long term relationships which we are building with this federation, not federation alone.
That's, I think, the most important takeaway for us here. OK, that's it.
Thank you, Mika. We are a little bit under time, so there is time for a question or two from the audience. No.
OK, thank you very much. Thank you.