( THE BUSINESS CASE )

What compliance really costs — and what it costs to do it alone.

We modelled a medium-sized EU fintech — 100–250 employees, calculated at the 100-FTE entry point of that band — becoming and staying compliant with DORA, the EU AI Act and GDPR while adopting ITIL 4 / COBIT 2019-aligned ways of working — over three years, from public benchmarks. Every number below traces to a named source, and we'll happily rebuild it with yours.

€1.15M3-year cost of building and running compliance alone — consultants, GRC platform, testing, training and the evidence work nobody budgets
−31%the same obligations met Suite-enabled: pre-built processes, no GRC platform, self-run audits, declining evidence labour
€5.1Maverage cost of a data breach in financial services — the second most expensive industry (IBM, 2025)
€1.2bnGDPR fines issued in Europe in 2025 alone — finance is now firmly in the enforcers' scope (DLA Piper)

What the €10,000 actually buys — the full inventory

"Licence" undersells it. This is a complete governed operating framework — the table shows each component and what it would cost to have consultants build the same thing for you once.

Included in the flat annual feeWhat you getBuild-it-yourself equivalent
9 governance domainsThe full operating architecture — Strategy & Governance through Security, Data & AI, down to Zero Trust — every domain owned, described and connectedArchitecture workshops ≈ 10–15 consulting days
58 processesEach with purpose, description, key activities, regulatory anchors and local fields for your owners and systems — ITIL/COBIT-aligned, ready to adoptProcess design ≈ 40–60 days (€56–84k)
37 internal controls (ICS)Across the Three Lines of Defence — every control carries its line, frequency, test procedure, evidence definition and an automation path to retire the manual workControl framework ≈ 20–30 days (€28–42k)
65 IT standardsMapped to the processes they govern — policy skeleton included, you localise rather than authorStandards library ≈ 15–25 days
Regulatory registerDORA, EU AI Act, NIS2, GDPR and supervisory reporting mapped both directions: regulation → processes & controls that satisfy it, and backRegulatory mapping ≈ 20–30 days
9 handbooks + 4 workbooksDomain handbooks as training curriculum; Self-Audit Workbook, Maturity Scorecard, Framework and Controls Registers with per-control integration hints for your BI/ITSM stackMethod & training material ≈ 15–20 days
35-piece activity toolkitReady-to-use templates, registers and runbooks for the key activities — RACI, risk register, DORA incident runbook & RoI starter, DPIA, AI model register, access-review log — each with a built-in how-to page, linked from every process ("Do it now")Template development ≈ 25–30 days (€35–42k)
Six-phase implementation guideOrient → baseline → gaps → adopt → automate → run. Meeting agendas, checklists, workshop formats — the consultancy method, in writingPlaybook development ≈ 10 days
Interactive, multilingual8-language interface, framework content in EN·DE·NL·FR·ES·IT·PT·PL and growing — one product for your whole EU footprintLocalisation budget
Governance updates — for life of licenceRegulation changes → the register changes → your den refreshes, and you're notified what changed and which of your processes it touches. No project. No invoice. Included.Annual regulatory-watch retainer ≈ €15–40k/yr
Recreate this once, alone≈ 130–170 consulting days ≈ €180,000–€240,000 — before any platform, and without the updatesvs €10,000/year, updates included

Alone vs. enabled — three years, same obligations · medium-sized fintech, 100–250 FTE

Do it alone
€1,153,900
Suite-enabled
€790,740
Your run-team & evidence work — €289,140 DPO, GDPR & AI Act duties — €259,000 Statutory resilience testing — €120,000 Setup consulting & training — €92,600 The Suite — €30,000 (€10k/yr): the only slice paid to us ← that sliver
€1,153,900 − €790,740 = €363,160 saved−31% over three years

What's inside the €790,740? Mostly you, not us: your run-team and DPO (~€107,000/yr), statutory resilience testing (€40,000/yr), AI Act maintenance, and your people's declining evidence work. Of the full three-year figure, only €30,000 is paid to Grumpy Bear — the rest is the honest cost of being a regulated firm, which no vendor can make disappear and which we refuse to hide.

Same statutory duties in both: resilience testing, DPO, run-team. The difference is what you don't rebuild — 58 processes, 37 controls and 65 standards pre-mapped to DORA, the AI Act, NIS2 and GDPR — and what you don't licence: no seven-figure GRC platform, you grow reporting on tools you already own.

Where the €363,160 comes from — line by line

The gap between the two bars above, reconciled to the euro. Each figure is the three-year difference for that line in the model — and yes, we count the Suite licence you pay us against our own case.

The GRC platform you don't buy — €230,000

Three years of a mid-market GRC licence (€60,000/yr) plus its one-time implementation (€50,000). The Suite's integration hints grow your dashboard on Power BI, Qlik or the ITSM you already run instead — this single line is nearly two-thirds of the saving.

Consulting you don't commission — €56,200

Half the baseline gap analysis (€17,500 — the Self-Audit Workbook is the same method) plus 30% off the DORA register/TPRM, GDPR and AI Act documentation setups (€38,700), because you start from templates and mapped anchors, not blank pages.

Process design you don't repeat — €54,880

Designing an ITIL/COBIT-aligned landscape from scratch is ~40 consulting days in year one plus annual refreshes. Adopting 57 pre-built, regulator-mapped processes cuts 70% of that: you localise owners and systems, not architecture.

Evidence labour that declines — €40,560

Six people, five days a quarter on screenshots is €62,400/yr. Evidence-by-design retires feeds year on year — we model only 25% off in year two and 40% in year three, and it's still real money.

Training you mostly skip — €11,520

Nine domain handbooks and the implementation guide replace 40% of formal framework training and refreshers across the three years.

Minus what you pay us — −€30,000

Three years of the Suite licence, counted honestly against the saving. Net effect of all six lines: €230,000 + €56,200 + €54,880 + €40,560 + €11,520 − €30,000 = €363,160.

Every figure comes from the same open assumptions as the bars (consultant day rate €1,400, mid-market GRC pricing, six-person evidence team) — change an assumption in the debrief and both bars and this breakdown move together.

The solution itself: not 31% cheaper — closer to 95%

The 31% above is the honest whole-programme number, because your statutory duties and your people's time exist in every world. But look at the solution cost alone — licence plus the professional services it takes to get a GRC solution actually online and working — and the gap is a different order of magnitude. No GRC platform is ever "just the licence".

~95%lower year-one solution cost than a typical mid-market GRC rollout (€10k vs ~€185k)
~98%lower than an enterprise platform programme (€350k–900k+ year one)
Day 1time to solution access — baseline audit done by week 4, vs 4–18 months of platform implementation
Year-one solution costThe SuiteMid-market GRC platformEnterprise GRC platform
Annual licence€10,000 flat — everything included€25,000–€90,000 (typ. ~€60,000)€80,000–€500,000 (typ. ~€150,000 entry)
Implementation & configuration (professional services)€0 — the implementation guide is the method; free 30-min debrief included€50,000–€90,000 (industry rule of thumb: 0.8–1.5× first-year licence)€150,000–€300,000+ (SI/Big-4 programme)
Integrations & report building€0 fees — integration hints per control for the Power BI / Qlik / ITSM you already own; you connect feeds at your pace€10,000–€25,000 (connectors, dashboards)€25,000–€75,000
Admin & user training€0 — nine handbooks and the guide are the curriculum€5,000–€15,000€15,000–€40,000
Dedicated platform administrator (annual, ongoing)None — it's governed content on tools you already run0.3–0.5 FTE ≈ €30,000–€50,000/yr0.5–1 FTE ≈ €50,000–€95,000/yr
Year-one solution total€10,000≈ €155,000–€280,000≈ €350,000–€900,000+

Ranges from published GRC pricing benchmarks (Archer, MetricStream, OneTrust, LogicGate, ServiceNow GRC) and standard implementation-to-licence ratios. Every platform quote you receive will itemise these same lines — ask for them.

Time to go-live

The Suite
Day 1 access
week-4 baseline · week 16: first leap to governed — then reassess, close gaps, repeat
Mid-market platform
4–9 months to first live use
Enterprise platform
9–18 months, phased programme

Suite timeline = the six-phase implementation guide: orient (days 1–3), self-run baseline audit (weeks 1–4), gaps & adoption (weeks 4–10), first automated feeds (weeks 8–16). Week 16 isn't "done" — it's your first governed baseline: maturity scored, gap register live, and a clear roadmap of next steps. From there the cycle repeats — reassess, close the next gaps, connect the next feeds. Governance as continual improvement, not a finish line. And with DORA already in force, time-to-first-baseline is itself a risk number.

Your side of the investment — what we're honestly asking of you

A lean fintech (30–50 people) doesn't have spare FTEs, so here is the resource bill spelled out — ours next to a platform programme's. This is the part no vendor puts on a slide: the licence is our price; this is yours.

Resource we account forWith The SuiteWith a GRC platform
Executive sponsor (CFO/COO)2–3 hours/month — open the baseline, unblock owners2–4 hours/month, for 2–4× longer programme
Compliance / GRC lead0.2–0.3 FTE during the 12–16 week adoption, then steady-state0.5 FTE for a 6–9+ month programme, plus permanent vendor management
Domain & control owners (IT, ops, risk)≈ 15–25 person-days total: self-audit, localisation, six 90-minute workshops≈ 40–80 person-days: requirements, data migration, configuration reviews, UAT
IT / BI engineer (integrations)≈ 5–10 days in year one — your stack, your pace, our hints per control≈ 15–30 days vendor-led connector and report configuration
Platform administratorNone0.3–0.5 FTE, permanently
Year-one people investment≈ 30–40 person-days + a part-time lead≈ 90–130 person-days + up to a full FTE, permanently

So the full honest equation for a minimal-resources fintech: €10,000 + roughly 35 of your team's days gets you governed, vs €155,000–€280,000 + roughly 110 of your team's days + a permanent admin for a platform — before either of you has satisfied a single statutory duty. That's why the whole-programme saving is 31% while the solution-cost saving is ~95%: we're cheap; your obligations aren't.

Find your size — the people and salaries behind the numbers

The page above models a ~100-person firm. The bars above show the medium band (100–250 FTE) at its entry point. Here is the same maths calibrated to three company sizes, with the salary ranges and FTE mappings we assume — so you can locate your own cost base before we rebuild the model with your real numbers in the debrief.

Resource assumptionVery small (10–30 FTE)Small (30–100 FTE)Medium (100–250 FTE)
Compliance / GRC lead0.1–0.2 FTE — usually someone's second hat0.3–0.5 FTE dedicated part-role1.0 FTE dedicated (often + analyst)
Data protection officerExternal retainer €12–20k/yrFractional 0.3–0.5 FTE ≈ €30–55k/yrIn-house share ≈ €55–75k/yr
People doing evidence & control work2–3 people, a few days/quarter4–6 people8–12 people
IT/BI engineer for evidence feeds3–5 days/yr5–10 days/yr10–20 days/yr
Resilience / scenario testing budget€15–25k/yr€30–50k/yr€60–100k/yr (TLPT if designated: more)
Typical 3-year compliance cost, alone≈ €350–450k≈ €700k–1.3M≈ €1.3–2.2M
Suite-enabled (indicative)≈ €250–320k≈ €500–900k≈ €1.0–1.7M
The Suite's share of that€10k/yr ≈ 3–4% of programme€10k/yr ≈ 1–2%€10k/yr < 1%

Salary ranges assumed (NL/DE market, loaded = salary + ~30% employer costs): GRC/compliance officer €75–110k · DPO €70–100k · security/BI engineer €80–120k · internal loaded day cost €430–590 · external consultant €1,250–1,800/day. The flat licence is deliberately size-blind: a 20-person fintech pays the same €10,000 as a 250-person lender — proportionally more visible for the smallest firms, and still less than three consulting days either way. Size bands are indicative; entity type, licences held and supervisory expectations move the numbers more than headcount alone — which is exactly what the free debrief calibrates.

The other side of the ledger

One finding costs 17 years of licence

A significant audit finding typically means a remediation programme: ~90 consultant days, external counsel and a re-audit — roughly €171,000 before the reputational cost. Research puts the total cost of non-compliance at 2.71× the cost of staying compliant (Ponemon).

Governed operations lose less

Organisations with extensive security automation see breach costs around $1.9M lower (IBM). In our model, a governed operation cuts expected annual risk loss from ~€121,000 to ~€56,000 — before counting a single fine avoided. Maxima remain real: GDPR 4% of turnover, AI Act up to 7%, DORA up to 2%.

The questions you're actually asking

"How fast can we really move?"

Day 1: your team opens the framework and starts the self-audit. Week 4: baseline done, gap register live. Week 16: your first governed baseline — maturity scored, gap register live, first automated evidence feeds connected, and a dated roadmap for the next cycle. The phases are sprint-sized on purpose — a lean team runs this alongside the day job, no infrastructure procurement, no vendor onboarding queue.

"DORA just expanded. Now what?"

Nothing, on your side. When regulation is adopted or an RTS lands, the register updates, your den refreshes, and you're notified exactly what changed and which of your processes and controls it touches. Included in the annual fee — the next regulation is an update, not a transformation programme with a budget request attached.

"An audit just landed — what do I show them?"

The implementation guide doubles as your remediation and service-improvement roadmap. Findings map to processes, processes to phases, phases to a dated plan — so you hand the regulator a clear, credible timeline to completion instead of a promise. Supervisors don't expect perfection; they expect you demonstrably on top of it. That's precisely what a phased roadmap with checkpoints shows.

"What's the lock-in?"

None, deliberately. Annual licence, cancel any year. The content runs on tools you already own — your BI, your ITSM, your workbooks — so nothing breaks if you leave. No per-seat counting, no modules to upsell, no professional-services dependency. The renewal has to earn itself through the updates.

Want this model with your numbers in it?

Start with the free Readiness Scan — twenty questions, five minutes, an honest score. In the 30-minute debrief we'll walk the TCO model through with your headcount, your tooling and your audit calendar. If the Suite doesn't fit, we'll say so.

Take the Readiness Scanhello@grumpybear.nl
Sources & honesty notes: figures are illustrative mid-range estimates for a ~100-FTE regulated SME, EUR, excl. VAT — not legal or financial advice. Benchmarks: IBM Cost of a Data Breach 2025 · DLA Piper GDPR Survey, Jan 2026 · Ponemon, True Cost of Compliance · Hiscox Cyber Readiness 2025 · public DORA, AI Act and GRC-platform cost estimates. Statutory costs (testing, DPO, run-team) are modelled identically in both scenarios.