2 Days. 10+ Experts. Countless IAM & GRC Insights. Register for NEXIS INVOLVE | September 9-10 | Regensburg

Finance & Insurance

HanseMerkur unites data protection, information security, and its internal control system with NEXIS GRC

With NEXIS GRC, HanseMerkur built a comprehensive management system that brings data protection, information security, and the internal control system (ICS) together “all in one”. This maps BaFin’s supervisory IT requirements consistently, originally under VAIT and today under DORA.

Finance & Insurance

About HanseMerkur

HanseMerkur is an independent, mid-sized insurance group headquartered in Hamburg. It offers insurance coverage for health, long-term care, life, risk and retirement provision, travel and leisure, property and accident, as well as supplementary company insurance.

As a mutual insurance association (Versicherungsverein auf Gegenseitigkeit), HanseMerkur is committed solely to its customers and employees, not to shareholders or investors. It is the only self-standing and group-independent insurance group at the Hamburg financial center that operates nationwide. The Hanseatic principle of the Honorable Merchant and the guiding idea “Hand in Hand ist HanseMerkur” shape the company culture and its clear stance toward legal requirements and internal rules.

  • Location: Hamburg
  • Legal form: Mutual insurance association
  • Focus: Independent, mid-sized personal insurance
  • Operations: Nationwide (Germany)
  • Business lines: Health, long-term care, life, provision, travel and leisure, property and accident

With NEXIS GRC, HanseMerkur was able to

Bring three disciplines together "all in one"

Combine data protection, information security, and the internal control system on one integrated platform.

Implement the supervisory IT requirements

Map IT strategy, IT governance, and information risk management in line with the supervisory specifications, from VAIT to today's DORA.

Steer IT governance efficiently

Steer, monitor, and advance the required measures along common international standards.

Assess risks via protection needs

Assess, monitor, and evaluate confidentiality, integrity, availability, and data protection relevance.

Evidence audits and BaFin examinations

Demonstrate responsible conduct through an unbroken historical record and continuous documentation.

Involve business departments in a single procedure

Assess information security, data protection, and the ICS in one single assessment procedure.

The Challenge

As an insurance company, HanseMerkur is subject not only to the general requirements for information security and data protection but also to BaFin’s regulatory provisions. The Supervisory Requirements for IT in Insurance Undertakings (VAIT), published in July 2018, added regulatory specifications on IT strategy, IT governance, information risk management, information security risk management, user access management, IT projects, IT operations, and the outsourcing of IT services. Since January 17, 2025, these supervisory IT requirements have been absorbed into the EU regulation DORA (EU 2022/2554), which replaced VAIT.

 

HanseMerkur began preparing for these rising requirements as early as 2017. An intensive as-is analysis showed that sustainable procedures cannot be mapped sensibly and economically with in-house tools such as Word, Excel, or PowerPoint. It therefore looked for a tool-supported solution and a partner with many years of experience in large security and data protection projects, one that enables a collaborative “hand in hand”.

 

The goal was to:
  • Map data protection under the EU GDPR fully integrated alongside the standard ISMS modules
  • Establish a complete internal control system (ICS) as standard
  • Enable cross-cutting views across all departments and processes
  • Consolidate and evaluate data for information security risk management in a user-friendly, resource-saving way
  • Gain a partner with many years of experience and references in large security and data protection projects

The approach

HanseMerkur divided the introduction into several project phases to replace the previous procedures smoothly and to secure the acceptance of all responsible parties.

Evaluation and selection of NEXIS GRC

During the in-person presentations by the providers, it became clear that Nexis covers the requirements professionally with NEXIS GRC. The integrated data protection and information security functions and the ability to expand into a comprehensive ICS were particularly convincing. Added to this were the many years of expertise from comparable projects and the geographic proximity of the Hamburg-based company, which enables a short line of communication and quick action.

Phase 1: review and design

First, the teams reviewed all existing documents and started the design and setup phase. They adapted the DIMS framework of NEXIS GRC to HanseMerkur's document specifications. With support from Nexis, they adapted, updated, and supplemented the required policies.

Phase 2: customization, testing, and go-live

This phase was divided into a workshop to define all customization requirements, the testing phase, and go-live after acceptance of all settings. The teams imported all process representations, which existed in different formats, into NEXIS GRC. This lets the business departments assess the requirements from information security, data protection, and the ICS in a single assessment procedure.

Phase 3: training and roll-out

Finally, HanseMerkur conducted the NEXIS GRC training sessions and carried out the roll-out across the organization.

The Result

With NEXIS GRC, HanseMerkur has significantly more transparency about potential risks and their impact. The company develops appropriate measures to efficiently improve its maturity level across all requirements from data protection, information security, ICS controls, and the supervisory IT specifications (today DORA).

  • Data protection, information security, and ICS in one system: “all in one” on an integrated platform
  • Supervisory-compliant, from VAIT to DORA: The supervisory IT requirements are mapped and manageable
  • More transparency about risks: Protection needs and risks are assessed, monitored, and steered efficiently
  • Audit- and examination-proof: An unbroken historical record and continuous documentation for audits and BaFin examinations
  • One assessment procedure for business departments: Information security, data protection, and the ICS assessed together
  • Manageable maturity: Appropriate measures for the continuous advancement of the maturity level

See how a comprehensive management system for insurers works in practice

Learn how NEXIS GRC helps insurers unite data protection, information security, and the ICS in a single system, meet the supervisory IT requirements under DORA, and continuously advance their maturity.