NEWVenvera speaks your language: the full platform, in English, German, Spanish and Bulgarian.See what’s new →
Solvency II compliance software

Solvency II Pillar 2, without the spreadsheet marathon.

Venvera is Solvency II compliance software for your system of governance, ORSA, operational resilience and the risk-management framework your supervisor expects, one living system that stays current instead of a document you rebuild from scratch every year.

System of governanceORSARisk managementOperational resilienceFit and proper

What is Solvency II Pillar 2, and why does it land on you?

Solvency II Pillar 2 is the System of Governance the EU prudential regime (Directive 2009/138/EC) demands of every insurer and reinsurer: board responsibility, written policies, the risk management system, the ORSA (Own Risk and Solvency Assessment), the four key functions including the actuarial function, fit and proper, and outsourcing, across Articles 40 to 49. Your national supervisor expects a documented, current system of governance and a live ORSA process - not a binder you rebuild from scratch each year. When it is stale or thin, the result is supervisory findings, a remediation plan and management time you never budgeted for. Venvera holds Pillar 2 as one living system of record. It does not perform Pillar 1 capital calculation (SCR, MCR, technical provisions) or Pillar 3 QRT reporting; it complements the actuarial engine and reporting tools that do.

 app.venvera.com
/ SOLVENCY II · Pillar 2 governance on one screen
/ SOLVENCY II · Pillar 2 governance on one screen
45
Pillar 2 governance controls in one system of record
4
Key functions evidenced: risk, compliance, audit, actuarial
40-49
System of Governance articles covered
from €399
Per month, with EU data residency
Articles 40 and 41

Your whole system of governance, in one live record.

Article 40 makes the board (AMSB) ultimately responsible, and Article 41 requires an effective, proportionate system of governance: a clear structure, transparent reporting lines, segregation of duties and a full set of written policies reviewed at least annually. Venvera is the system of record for all of it. It holds the org and reporting-line map, the written policy library with approval and review cadence, and the evidence behind every one of the 45 Pillar 2 controls - so your CRO and key-function holders work from one live picture, not a folder of static documents.

  • Organisational structure and reporting lines mapped to Article 41
  • Written policy library (risk, internal control, audit, outsourcing, remuneration) with annual review cadence
  • AMSB approval workflow and sign-off records on every policy
  • Segregation of duties evidenced across the three lines of defence
  • All 45 System of Governance controls tracked with owner, status and evidence
 app.venvera.com
/ GOVERNANCE · policies, owners and reporting lines, all current
/ GOVERNANCE · policies, owners and reporting lines, all current
Article 45 · ORSA

Run the ORSA as a process your supervisor can test.

Article 45 requires every insurer to run its Own Risk and Solvency Assessment and embed it in decision-making. Venvera runs the ORSA as a governed process: the policy, the annual and ad hoc trigger schedule, the board approval workflow, the documented record and the review cadence. It is deliberately the process wrapper, not the numbers - your actuarial function and capital model own the solvency needs, technical provisions and capital. Venvera makes the assessment policy-driven, approved, documented and repeatable, which is exactly what a supervisor examines.

  • ORSA policy with defined methodology, frequency and ad hoc triggers
  • AMSB approval workflow with recorded challenge and sign-off
  • Documented ORSA record and the internal report to management
  • Review cadence and evidence that ORSA output feeds strategic decisions
  • Clear boundary: governance process only, never the capital calculation
 app.venvera.com
/ ORSA · policy, triggers and approvals on a governed cadence
/ ORSA · policy, triggers and approvals on a governed cadence
The four key functions

All four key functions, independent and evidenced.

Solvency II names four key functions: risk management (Article 44), compliance (Article 46), internal audit (Article 47) and the actuarial function (Article 48). Each must be operationally independent, held by a fit and proper person, and evidenced. Venvera gives every function its own workspace: mandate, holder, independence evidence, work plan and the reports it owes the board. The actuarial function is tracked too - coordination of technical provisions, the opinion on underwriting policy and the opinion on reinsurance are recorded as governance deliverables, produced and delivered, not computed. These insurance-specific functions are native controls, evidenced directly and never auto-satisfied from generic evidence.

  • Risk management function (Art 44) with the risk management system and policies
  • Compliance function (Art 46) advising the AMSB and assessing regulatory change
  • Internal audit function (Art 47) with an independent, risk-based audit plan
  • Actuarial function (Art 48): technical provisions coordination tracked as a deliverable, plus underwriting and reinsurance opinions
  • Independence, fit and proper status and AMSB reporting evidenced per function
 app.venvera.com
/ KEY FUNCTIONS · a workspace, an owner and independence proof each
/ KEY FUNCTIONS · a workspace, an owner and independence proof each
Articles 42 and 49

Fit and proper and outsourcing, never out of date.

Article 42 requires everyone who runs the undertaking or holds a key function to be fit and proper, on appointment and continuously. Article 49 governs outsourcing of critical or important functions: due diligence, contractual safeguards, ongoing monitoring and supervisory notification. Venvera keeps the fit and proper register (qualifications, assessments, good-repute checks and renewal dates) and an outsourcing register with criticality classification, contract clauses, service monitoring and the notification trail. For ICT and security outsourcing, the same evidence you maintain for DORA is reused here through the crosswalk.

  • Fit and proper register (Art 42) with reassessment and renewal reminders
  • Good-repute and competence evidence for AMSB members and key-function holders
  • Outsourcing register (Art 49) with critical-or-important classification
  • Contractual safeguards, exit plans and ongoing service monitoring tracked
  • Supervisory notification trail for outsourcing of critical or important functions
 app.venvera.com
/ REGISTERS · fit and proper plus outsourcing, dates never missed
/ REGISTERS · fit and proper plus outsourcing, dates never missed
Cross-framework crosswalk

Evidence your DORA and ISO governance once, reuse it here.

Most EU insurers already run DORA, and many hold ISO 27001 or fall under NIS2. Their governance requirements overlap heavily with the Solvency II System of Governance. Venvera maps that overlap so you evidence once: satisfying your DORA or ISO governance controls auto-satisfies the equivalent Solvency II controls - organisational structure and reporting lines, segregation of duties, protection of records, and the contractual and monitoring requirements for ICT and security outsourcing. What never auto-satisfies is the insurance-specific core: the ORSA process, the four key functions including the actuarial function, fit and proper, remuneration and non-ICT operational risk. Those stay native and are evidenced directly, because a supervisor would reject borrowed evidence for them.

  • DORA and ISO 27001 governance evidence auto-satisfies equivalent Pillar 2 controls
  • Overlap covers org structure, segregation of duties, records protection and ICT outsourcing
  • Insurance-specific controls stay native: ORSA, key functions, fit and proper, remuneration
  • No fake coverage: generic evidence never fills an actuarial or ORSA control
  • One evidence update flows to every mapped framework at once
 app.venvera.com
/ CROSSWALK · one governance update, mapped across frameworks
/ CROSSWALK · one governance update, mapped across frameworks
Why switch

The spreadsheet or Venvera.

Spreadsheets
Venvera
System of governance
Word policies in shared drives, no live status
45 controls with owner, status and evidence in one system of record
ORSA process
Actuarial add-on focused on the number, thin on governance
Governed ORSA: policy, AMSB approval, documentation, review cadence
Four key functions
Tracked in separate spreadsheets per function
A workspace per function with independence and AMSB reporting evidence
Fit and proper
HR files and manual renewal reminders
Live register with reassessment and renewal alerts per Art 42
Outsourcing (Art 49)
Contract list with no criticality or monitoring view
Register with criticality, safeguards, monitoring and notification trail
Cross-framework reuse
Re-evidenced separately for DORA, ISO and Solvency II
Evidence once via the crosswalk; native controls stay native

Solvency II Pillar 2, answered.

Get your Solvency II governance audit-ready.

Start with a free gap report across your Pillar 2 governance - 10 minutes, no email to start.

Every paid plan: audit-ready in 90 days, or your money back

10 minutes · no email to start · no credit card · yours to keep