OIP Insurtech

OIP Insurtech Overview

OIP staff: sign in with your Google account.
Invited guests: enter your access code.

or
Access restricted. Use your OIP account or a valid access code.
Navigate by keyboard
Capability & Due Diligence

OIP Insurtech

Insurance underwriting support and InsurTech, delivered to an ISO/IEC 27001:2022 certified standard across Serbia, North Macedonia, and India.

🛡 Business Process Outsourcing for the Insurance Industry
Prepared for Kimberly DeCort, Senior Director, BPO Office • Arrowhead Intermediaries
USE ← → TO NAVIGATE
Overview

What We Will Cover

Structured to the eight areas of your due diligence request.

01

Company Profile & Overview

Who we are, services, footprint, and organization.

02

Resourcing, Capacity & Training

Workforce, scalability, and enablement.

03

Operations & Governance

Reporting, meetings, QC, and issue handling.

04

Performance Metrics & Data

KPIs, SLAs, and how we measure them.

05

Technology, Access & Automation

Systems, access model, and AI-assisted operations.

06

Compliance, Risk & Continuity

ISO 27001, risk, PII controls, and BC/DR.

07

Contract & Invoicing Controls

Commercial governance and billing accuracy.

08

Transition Readiness

Large-scale onboarding methodology and ramp.

01 • Company Profile

Who We Are

Our Mission

Outsource Insurance Professionals Insurtech (OIP Insurtech) is a trusted provider of secure, high-quality KPO and InsurTech services to the insurance industry. We focus on underwriting support and technology solutions, with an unwavering commitment to protecting client data, ensuring business continuity, and upholding the highest standards of professionalism and compliance.

Service Lines

Underwriting Support & KPO InsurTech Solutions & Automation IT Staff Augmentation Software & Technical Support

Serving clients across the insurance value chain, including programs, wholesale, and specialty lines.

0
Team Members
Serbia, North Macedonia, India
0
Delivery Countries
Multi-region resilience
ISO 27001
:2022 Certified
Independently attested
2012
Founded
[[ # active clients ]]
01 • Company Profile

Global Footprint & Organization

Delivery Footprint

  • 📍 Belgrade, Serbia - Vele Nigrinove 8 (primary operations)
  • 📍 Nis, Serbia - Bulevar Nemanjica 22 (operations)
  • 📍 Skopje, North Macedonia - operations & delivery
  • 📍 Hyderabad, India - operations & delivery
  • 📍 Zagreb, Croatia - company-owned business-continuity standby site
  • 📍 [[ US / Nevada HQ - confirm entity ]]

Governance Structure

Executive Leadership

Strategic direction, governance, and resource allocation

Management / OIPR Leaders

Department heads, key account managers, operations managers

Risk & Security Function

CISO • Risk Manager • Data Protection Officer

Delivery Teams

Underwriting support, InsurTech, IT, and administration

Corporate values: IntegrityProfessionalismConfidentialityRespect & DiversityCollaboration & Innovation
02 • Resourcing & Capacity

Workforce & Capacity

From the 2026 Operational Diversification & Business Impact Analysis.

1,316
Employees
Across 3 countries
761
Serbia & N. Macedonia
58% of core capacity
555
India
42% of core capacity
465
Critical Tasks Mapped
Short turnaround (≤48h)

Built-in Resilience

  • ✓ 152 critical tasks covered across all regions - strongest redundancy
  • ✓ Cross-regional workforce model reduces single-location dependency
  • ✓ Active cross-training program to widen coverage further
  • ✓ Full remote-work capability over secure VPN

Capacity by Function

Headcount distribution across service lines:

Underwriting Support [[ # ]] InsurTech / Dev [[ # ]] IT & Security [[ # ]] Admin / Support [[ # ]]

Surge / ramp capacity: [[ seats available per month ]]

02 • Resourcing & Capacity

Training & Enablement

Onboarding

  • ✓ Formal user registration with identity & role verification
  • ✓ Signed Statement of Loyalty & confidentiality agreements
  • ✓ Mandatory onboarding on ethics, compliance & data protection
  • ✓ Job-specific skills training before live work

Ongoing Security Awareness

  • ✓ Mandatory Social Engineering Awareness training
  • ✓ Annual secure-working & phishing training
  • ✓ Internet Safety training for mobile access
  • ✓ Developer security training across the SDLC

Upskilling & Cross-Training

  • ✓ Cross-regional task training for redundancy
  • ✓ GenAI upskilling via structured courses (Coursera, LinkedIn Learning)
  • ✓ Management succession & development programs
  • Training hours / year: [[ hrs ]] • completion: [[ % ]]
03 • Operations & Governance

Governance & Cadence

Management Review (Quarterly)

Chaired by the Risk Manager; ISMS reviewed at least quarterly against a fixed agenda:

  • → Status of prior actions & changing internal/external issues
  • → Performance trends: nonconformities, audit results, objectives
  • → Risk assessment & treatment status
  • → Threat landscape & emerging vulnerabilities
  • → Improvement decisions with an action & follow-up table

Reporting & Communication

  • ✓ Reporting lines: CISO, Risk Manager, DPO to executive leadership
  • ✓ Results shared with operations managers, VPs, and tech leaders
  • ✓ Internal comms via structured training & the Cassie 2.0 ticket system
  • ✓ Client feedback via email, calls, and on-site visits
  • ✓ Documentation control: all versions retained, archived, reviewed yearly (OIPIP18)

30+ controlled ISMS procedures on a managed document register.

03 • Operations & Governance

Quality Control & Issue Handling

Internal Audit

  • ✓ Conducted at least twice a year
  • ✓ Annual plan approved by executives
  • ✓ Independent auditors - no self-review
  • ✓ Findings: major / minor / improvement / positive

Corrective & Preventive Action

  • ✓ 8-step PDCA CAPA lifecycle
  • ✓ Documented root-cause analysis
  • ✓ Effectiveness verified with data
  • ✓ Feeds risk register & controls

Incident Handling

  • ✓ 4-tier severity: minor to catastrophic
  • ✓ Cassie 2.0 ticketing & tracker log
  • ✓ DPO-led breach response, 24/7
  • ✓ Formal closure + lessons learned (records ≥ 2 yrs)

Latest quarterly review: no major nonconformities identified; minor findings tracked to closure through the CAPA process.

04 • Performance Metrics

Performance Metrics & Data Sources

How We Measure

Every ISMS objective is tracked across a seven-field framework: objective, activities, resources, responsibility, deadlines, monitoring method, and results - reviewed at each quarterly management review.

Data sources:

Cassie 2.0 (tickets / incidents) Armada SIEM Nagios Google Workspace audit BitDefender GravityZone

10 incidents logged Jul 2025 - Mar 2026, all tracked to resolution; no major nonconformities in the latest quarter.

Operational KPIs & SLAs

MetricTargetSource
SLA adherence[[ % ]]Client / KAM reports
Turnaround time (core)≤ 48hOps tracking
Quality / accuracy[[ % ]]QC sampling
Volume / month[[ # ]]Ops tracking
System uptime[[ % ]]Nagios

Targets to be confirmed with current reporting.

05 • Technology & Access

Technology & Access Model

Identity & Access

  • ✓ Role-based access with least privilege (VP of IT approval)
  • ✓ MFA / 2-Step Verification mandatory for all & privileged accounts
  • ✓ Segregation of duties; unique IDs, no shared accounts
  • ✓ Joiner-Mover-Leaver process with immediate revocation
  • ✓ Access reviews annually; quarterly for privileged access

Identity platform: Google Workspace (with GCPW).

Endpoints & Remote Work

  • ✓ Full-device encryption, screen-lock PIN, remote wipe
  • ✓ Managed anti-malware / EDR on all connecting hosts
  • ✓ Encrypted VPN + MFA, 60-minute idle timeout
  • ✓ No unmanaged devices on the internal network
  • ✓ No client or personal data stored on OIP endpoints (DLP enforced)
05 • Technology & Access

Cloud, Security & Automation

Cloud & Infrastructure

  • ✓ Google Workspace + Microsoft Azure (BoundAI)
  • ✓ Aligned to ISO 27017 & ISO 27018
  • ✓ Encryption in transit & at rest; DLP integrated
  • ✓ Annual vendor security assurance

Secure Engineering

  • ✓ Separate dev / test / production
  • ✓ OWASP secure coding & code review
  • ✓ Security, performance & load testing
  • ✓ No PII in test - data masking enforced

Monitoring & Automation

  • ✓ Armada SIEM, Nagios, GravityZone
  • ✓ Weekly vulnerability scans & patching
  • ✓ Real-time DLP & alerting
  • ✓ Baselines & change control with rollback

🤖 BoundAI - AI-Assisted Operations

Proprietary AI tooling accelerates operations under strict governance: an AI Acceptable Use Policy, a dedicated Digital Transformation Team, and a mandatory human-in-the-loop review of every AI-generated output used for clients.

06 • Compliance, Risk & Continuity

ISO 27001 & Control Framework

93/93
Annex A Controls Applicable
0 exclusions
31
Governed Policies
Reviewed yearly
2x
Internal Audits / Year
+ annual management review
NIS2
DORA • NIST CSF
Aligned frameworks
Governance
Technical
Operational
Compliance
Continuity
Click any tile for details →

Annex A Coverage

ISMS Policy Suite

06 • Compliance, Risk & Continuity

Risk Management

17
Risks in the 2026 register - 14 mitigated, 3 accepted. Click for the treatment framework.
5x5 methodology, named risk owners, quarterly review, formal acceptance criteria. Click for detail.
Business Impact Analysis links risk to recovery priorities. Click for detail.

Impact (vertical) x Likelihood (horizontal). Click a populated cell to see the risks it contains.

06 • Compliance, Risk & Continuity

Data Protection & PII Controls

GDPR Program

  • ✓ Controller / Processor model - client PII processed only on documented instructions
  • ✓ All 5 lawful bases & all 8 data subject rights supported
  • ✓ Appointed DPO; 24/7 Data Breach Response Team
  • ✓ 72-hour breach notification; ROPA & DPIAs maintained
  • ✓ Cross-border transfers reviewed against adequacy & SCCs

Technical PII Controls

  • ✓ Four-tier classification: Confidential / Restricted / Internal / Public
  • ✓ Encryption: 256-bit TLS, AES VPN, LUKS & BitLocker at rest
  • ✓ DLP, data masking, least-privilege access & monitoring
  • ✓ Privacy by Design & by Default embedded in processes
  • ✓ No personal data on personal email or unapproved storage
Regulatory scope: EU GDPREU AI ActConvention 108Serbian Data Protection Law
06 • Compliance, Risk & Continuity

Business Continuity & Disaster Recovery

Business Continuity ›

  • ✓ Three sites: Belgrade (primary), Nis (secondary), Zagreb standby (company-owned)
  • ✓ Recovery targets: emergency 2h, key services 4h, business-as-usual 8-24h
  • ✓ Full remote-work capability & contingency staffing across regions
  • ✓ Insurance: E&O, General Liability, Cyber, Business Interruption

Disaster Recovery ›

  • ✓ RAID-mirrored servers, UPS, redundant failover connectivity
  • ✓ DR restore at backup site within 48h; relocation within 72h
  • ✓ Backups: daily / weekly / monthly, 256-bit AES, restore-tested quarterly
  • DRP tested Oct/Nov 2025 - UPS & generators passed, residual risk Low

Independent attestation: OIP Insurtech holds ISO/IEC 27001:2022 certification as its current independent attestation. A SOC 2 examination is on the roadmap; [[ target timeframe ]].

07 • Contract & Invoicing

Contract & Commercial Governance

Contract & Third-Party Governance

  • ✓ Written agreements with confidentiality & data-processing terms
  • ✓ Supplier due diligence & right-to-audit clauses
  • ✓ 24-hour supplier breach-notification obligation
  • ✓ Ongoing monitoring & annual review; controlled offboarding
  • ✓ Currently no critical third-party suppliers in the chain

Invoicing Controls

  • ✓ SLA-linked billing tied to measured output
  • Billing reconciliation & approval workflow: [[ describe cadence ]]
  • Volume / timesheet verification: [[ method ]]
  • Dispute & adjustment process: [[ describe ]]

Pricing models, rate cards, and the contract itself are shared directly under NDA and are not included in this overview.

08 • Transition Readiness

Large-Scale Transition Methodology

A phased, governed approach to onboarding new programs at scale.

Phase 1 • Discovery & Due Diligence
Process mapping, volume & SLA baselining, data-flow and security review, transition risk assessment. Duration: [[ weeks ]]
Phase 2 • Solution Design
Target operating model, staffing & location plan, tooling & access design, governance & RACI, KPI framework.
Phase 3 • Pilot / Proof
Controlled pilot on a representative sample, quality calibration, and sign-off gate before scaling.
Phase 4 • Ramp & Knowledge Transfer
Structured shadowing, SOP capture, cross-training, and staged capacity ramp with hypercare support.
Phase 5 • Steady State & Continuous Improvement
Full production under SLA, quarterly reviews, and ongoing optimization through the CAPA process.
08 • Transition Readiness

Transition Governance & Scalability

Governance

  • ✓ Joint steering committee
  • ✓ Weekly status & risk log
  • ✓ RACI & escalation paths
  • ✓ Milestone sign-off gates

Knowledge Transfer

  • ✓ Shadow / reverse-shadow model
  • ✓ SOP capture & version control
  • ✓ Cross-regional training
  • ✓ Hypercare after go-live

Proven Scalability

  • ✓ 1,316-strong multi-region workforce
  • ✓ Cross-regional coverage & redundancy
  • ✓ BC/DR embedded from day one
  • Ramp rate: [[ seats / week ]]

Transition risk is managed through the same ISO 27001 framework used in production: formal risk assessment (including application-development risk practices), documented controls, and continuity planning - so scale never comes at the cost of security or quality.

OIP Insurtech

Your Operations. Our Expertise.

0
Team Members
0
ISO 27001 Controls
0
Governed Policies
3
Delivery Regions
💬 Questions & Discussion

Requested documentation - ISO 27001 certificate, PII control guidelines, and contract materials - is provided directly under NDA. A SOC 2 examination is on our roadmap.