We modelled a medium-sized EU fintech — 100–250 employees, calculated at the 100-FTE entry point of that band — becoming and staying compliant with DORA, the EU AI Act and GDPR while adopting ITIL 4 / COBIT 2019-aligned ways of working — over three years, from public benchmarks. Every number below traces to a named source, and we'll happily rebuild it with yours.
"Licence" undersells it. This is a complete governed operating framework — the table shows each component and what it would cost to have consultants build the same thing for you once.
| Included in the flat annual fee | What you get | Build-it-yourself equivalent |
|---|---|---|
| 9 governance domains | The full operating architecture — Strategy & Governance through Security, Data & AI, down to Zero Trust — every domain owned, described and connected | Architecture workshops ≈ 10–15 consulting days |
| 58 processes | Each with purpose, description, key activities, regulatory anchors and local fields for your owners and systems — ITIL/COBIT-aligned, ready to adopt | Process design ≈ 40–60 days (€56–84k) |
| 37 internal controls (ICS) | Across the Three Lines of Defence — every control carries its line, frequency, test procedure, evidence definition and an automation path to retire the manual work | Control framework ≈ 20–30 days (€28–42k) |
| 65 IT standards | Mapped to the processes they govern — policy skeleton included, you localise rather than author | Standards library ≈ 15–25 days |
| Regulatory register | DORA, EU AI Act, NIS2, GDPR and supervisory reporting mapped both directions: regulation → processes & controls that satisfy it, and back | Regulatory mapping ≈ 20–30 days |
| 9 handbooks + 4 workbooks | Domain handbooks as training curriculum; Self-Audit Workbook, Maturity Scorecard, Framework and Controls Registers with per-control integration hints for your BI/ITSM stack | Method & training material ≈ 15–20 days |
| 35-piece activity toolkit | Ready-to-use templates, registers and runbooks for the key activities — RACI, risk register, DORA incident runbook & RoI starter, DPIA, AI model register, access-review log — each with a built-in how-to page, linked from every process ("Do it now") | Template development ≈ 25–30 days (€35–42k) |
| Six-phase implementation guide | Orient → baseline → gaps → adopt → automate → run. Meeting agendas, checklists, workshop formats — the consultancy method, in writing | Playbook development ≈ 10 days |
| Interactive, multilingual | 8-language interface, framework content in EN·DE·NL·FR·ES·IT·PT·PL and growing — one product for your whole EU footprint | Localisation budget |
| Governance updates — for life of licence | Regulation changes → the register changes → your den refreshes, and you're notified what changed and which of your processes it touches. No project. No invoice. Included. | Annual regulatory-watch retainer ≈ €15–40k/yr |
| Recreate this once, alone | ≈ 130–170 consulting days ≈ €180,000–€240,000 — before any platform, and without the updates | vs €10,000/year, updates included |
The gap between the two bars above, reconciled to the euro. Each figure is the three-year difference for that line in the model — and yes, we count the Suite licence you pay us against our own case.
Three years of a mid-market GRC licence (€60,000/yr) plus its one-time implementation (€50,000). The Suite's integration hints grow your dashboard on Power BI, Qlik or the ITSM you already run instead — this single line is nearly two-thirds of the saving.
Half the baseline gap analysis (€17,500 — the Self-Audit Workbook is the same method) plus 30% off the DORA register/TPRM, GDPR and AI Act documentation setups (€38,700), because you start from templates and mapped anchors, not blank pages.
Designing an ITIL/COBIT-aligned landscape from scratch is ~40 consulting days in year one plus annual refreshes. Adopting 57 pre-built, regulator-mapped processes cuts 70% of that: you localise owners and systems, not architecture.
Six people, five days a quarter on screenshots is €62,400/yr. Evidence-by-design retires feeds year on year — we model only 25% off in year two and 40% in year three, and it's still real money.
Nine domain handbooks and the implementation guide replace 40% of formal framework training and refreshers across the three years.
Three years of the Suite licence, counted honestly against the saving. Net effect of all six lines: €230,000 + €56,200 + €54,880 + €40,560 + €11,520 − €30,000 = €363,160.
Every figure comes from the same open assumptions as the bars (consultant day rate €1,400, mid-market GRC pricing, six-person evidence team) — change an assumption in the debrief and both bars and this breakdown move together.
The 31% above is the honest whole-programme number, because your statutory duties and your people's time exist in every world. But look at the solution cost alone — licence plus the professional services it takes to get a GRC solution actually online and working — and the gap is a different order of magnitude. No GRC platform is ever "just the licence".
| Year-one solution cost | The Suite | Mid-market GRC platform | Enterprise GRC platform |
|---|---|---|---|
| Annual licence | €10,000 flat — everything included | €25,000–€90,000 (typ. ~€60,000) | €80,000–€500,000 (typ. ~€150,000 entry) |
| Implementation & configuration (professional services) | €0 — the implementation guide is the method; free 30-min debrief included | €50,000–€90,000 (industry rule of thumb: 0.8–1.5× first-year licence) | €150,000–€300,000+ (SI/Big-4 programme) |
| Integrations & report building | €0 fees — integration hints per control for the Power BI / Qlik / ITSM you already own; you connect feeds at your pace | €10,000–€25,000 (connectors, dashboards) | €25,000–€75,000 |
| Admin & user training | €0 — nine handbooks and the guide are the curriculum | €5,000–€15,000 | €15,000–€40,000 |
| Dedicated platform administrator (annual, ongoing) | None — it's governed content on tools you already run | 0.3–0.5 FTE ≈ €30,000–€50,000/yr | 0.5–1 FTE ≈ €50,000–€95,000/yr |
| Year-one solution total | €10,000 | ≈ €155,000–€280,000 | ≈ €350,000–€900,000+ |
Ranges from published GRC pricing benchmarks (Archer, MetricStream, OneTrust, LogicGate, ServiceNow GRC) and standard implementation-to-licence ratios. Every platform quote you receive will itemise these same lines — ask for them.
Suite timeline = the six-phase implementation guide: orient (days 1–3), self-run baseline audit (weeks 1–4), gaps & adoption (weeks 4–10), first automated feeds (weeks 8–16). Week 16 isn't "done" — it's your first governed baseline: maturity scored, gap register live, and a clear roadmap of next steps. From there the cycle repeats — reassess, close the next gaps, connect the next feeds. Governance as continual improvement, not a finish line. And with DORA already in force, time-to-first-baseline is itself a risk number.
A lean fintech (30–50 people) doesn't have spare FTEs, so here is the resource bill spelled out — ours next to a platform programme's. This is the part no vendor puts on a slide: the licence is our price; this is yours.
| Resource we account for | With The Suite | With a GRC platform |
|---|---|---|
| Executive sponsor (CFO/COO) | 2–3 hours/month — open the baseline, unblock owners | 2–4 hours/month, for 2–4× longer programme |
| Compliance / GRC lead | 0.2–0.3 FTE during the 12–16 week adoption, then steady-state | 0.5 FTE for a 6–9+ month programme, plus permanent vendor management |
| Domain & control owners (IT, ops, risk) | ≈ 15–25 person-days total: self-audit, localisation, six 90-minute workshops | ≈ 40–80 person-days: requirements, data migration, configuration reviews, UAT |
| IT / BI engineer (integrations) | ≈ 5–10 days in year one — your stack, your pace, our hints per control | ≈ 15–30 days vendor-led connector and report configuration |
| Platform administrator | None | 0.3–0.5 FTE, permanently |
| Year-one people investment | ≈ 30–40 person-days + a part-time lead | ≈ 90–130 person-days + up to a full FTE, permanently |
So the full honest equation for a minimal-resources fintech: €10,000 + roughly 35 of your team's days gets you governed, vs €155,000–€280,000 + roughly 110 of your team's days + a permanent admin for a platform — before either of you has satisfied a single statutory duty. That's why the whole-programme saving is 31% while the solution-cost saving is ~95%: we're cheap; your obligations aren't.
The page above models a ~100-person firm. The bars above show the medium band (100–250 FTE) at its entry point. Here is the same maths calibrated to three company sizes, with the salary ranges and FTE mappings we assume — so you can locate your own cost base before we rebuild the model with your real numbers in the debrief.
| Resource assumption | Very small (10–30 FTE) | Small (30–100 FTE) | Medium (100–250 FTE) |
|---|---|---|---|
| Compliance / GRC lead | 0.1–0.2 FTE — usually someone's second hat | 0.3–0.5 FTE dedicated part-role | 1.0 FTE dedicated (often + analyst) |
| Data protection officer | External retainer €12–20k/yr | Fractional 0.3–0.5 FTE ≈ €30–55k/yr | In-house share ≈ €55–75k/yr |
| People doing evidence & control work | 2–3 people, a few days/quarter | 4–6 people | 8–12 people |
| IT/BI engineer for evidence feeds | 3–5 days/yr | 5–10 days/yr | 10–20 days/yr |
| Resilience / scenario testing budget | €15–25k/yr | €30–50k/yr | €60–100k/yr (TLPT if designated: more) |
| Typical 3-year compliance cost, alone | ≈ €350–450k | ≈ €700k–1.3M | ≈ €1.3–2.2M |
| Suite-enabled (indicative) | ≈ €250–320k | ≈ €500–900k | ≈ €1.0–1.7M |
| The Suite's share of that | €10k/yr ≈ 3–4% of programme | €10k/yr ≈ 1–2% | €10k/yr < 1% |
Salary ranges assumed (NL/DE market, loaded = salary + ~30% employer costs): GRC/compliance officer €75–110k · DPO €70–100k · security/BI engineer €80–120k · internal loaded day cost €430–590 · external consultant €1,250–1,800/day. The flat licence is deliberately size-blind: a 20-person fintech pays the same €10,000 as a 250-person lender — proportionally more visible for the smallest firms, and still less than three consulting days either way. Size bands are indicative; entity type, licences held and supervisory expectations move the numbers more than headcount alone — which is exactly what the free debrief calibrates.
A significant audit finding typically means a remediation programme: ~90 consultant days, external counsel and a re-audit — roughly €171,000 before the reputational cost. Research puts the total cost of non-compliance at 2.71× the cost of staying compliant (Ponemon).
Organisations with extensive security automation see breach costs around $1.9M lower (IBM). In our model, a governed operation cuts expected annual risk loss from ~€121,000 to ~€56,000 — before counting a single fine avoided. Maxima remain real: GDPR 4% of turnover, AI Act up to 7%, DORA up to 2%.
Day 1: your team opens the framework and starts the self-audit. Week 4: baseline done, gap register live. Week 16: your first governed baseline — maturity scored, gap register live, first automated evidence feeds connected, and a dated roadmap for the next cycle. The phases are sprint-sized on purpose — a lean team runs this alongside the day job, no infrastructure procurement, no vendor onboarding queue.
Nothing, on your side. When regulation is adopted or an RTS lands, the register updates, your den refreshes, and you're notified exactly what changed and which of your processes and controls it touches. Included in the annual fee — the next regulation is an update, not a transformation programme with a budget request attached.
The implementation guide doubles as your remediation and service-improvement roadmap. Findings map to processes, processes to phases, phases to a dated plan — so you hand the regulator a clear, credible timeline to completion instead of a promise. Supervisors don't expect perfection; they expect you demonstrably on top of it. That's precisely what a phased roadmap with checkpoints shows.
None, deliberately. Annual licence, cancel any year. The content runs on tools you already own — your BI, your ITSM, your workbooks — so nothing breaks if you leave. No per-seat counting, no modules to upsell, no professional-services dependency. The renewal has to earn itself through the updates.
Start with the free Readiness Scan — twenty questions, five minutes, an honest score. In the 30-minute debrief we'll walk the TCO model through with your headcount, your tooling and your audit calendar. If the Suite doesn't fit, we'll say so.
Take the Readiness Scanhello@grumpybear.nl