Managing risk in a fast-growing fintech: how Floryn made compliance scalable
Dennis van de WielLinkedIn
TLDR
Floryn, a fintech lender under De Nederlandsche Bank supervision, moved its compliance and risk processes from fragmented spreadsheets to Tidal Control after finding that recording risks and policies was not enough without systematically executing and demonstrating controls. Starting from around 120 risks built with KPMG, Floryn spread its workload across the year, linked controls directly to legislation such as the EBA guidelines, and embedded risk ownership across the whole organisation. Compliance awareness and consistent execution of internal processes have increased significantly as a result.
For most companies, risk management is an obligation that comes with the territory. For Floryn, it is the business model itself. The fintech lender provides daily business financing to SME entrepreneurs, based on data analysis and real-time insight into bank transactions. When you provide loans, you make your money by assessing and managing risks. At Floryn, entrepreneurship and a strong risk culture are not opposites: they are two sides of the same coin.
In this article, you'll read how Floryn moved its compliance and risk processes from fragmented spreadsheets to a single scalable foundation using Tidal Control. And why that journey was not just about a tool, but above all about how people work together.
Under supervision, and therefore sharp on compliance
Floryn started in 2016 with a simple premise: business financing could be faster and smarter than the slow process at the major banks. Thanks to a PSD2 licence, Floryn can read customers' bank transactions, which forms the basis for the models behind every credit decision. That makes Floryn fast and distinctive, but it also brings obligations. With that licence, the company falls under the supervision of De Nederlandsche Bank.
That supervision focuses primarily on integrity, IT and the models. When obtaining the licence, Floryn was intensively guided by KPMG, which set clear requirements. When that guidance ended, the responsibility remained. This created the need for tighter processes.
At some point you're on your own. A very important part on top of that, is compliance awareness and knowledge. You need to have that at all times. That's when it became clear: we really need a tool here to bring structure.
Joris ArtsDirector Finance & Compliance | Floryn
The challenge: from fragmentation to overview
Before Tidal Control, Floryn managed compliance with multiple systems, spreadsheets and loose documents. The knowledge was there, but the overview was not. Floryn had even briefly tried another tool that did not fit the way the team worked. The problem was not in recording risks and policies, but in systematically executing, monitoring and demonstrating controls.
That last point is exactly what a regulator cares about. Policy on paper is not the same as policy that is demonstrably followed. In a fast-growing fintech, that distinction became increasingly urgent.
Why Tidal Control: flexibility and short lines of communication
While searching for a suitable GRC solution, Floryn came across Tidal Control through its network. A convenient bonus: Tidal was also based in Den Bosch, which immediately made the collaboration more accessible. Thus, Floryn became Tidal's first customer.
The choice was not determined by the platform alone, but by the combination of software and approach. The flexibility made it possible to set up risks, controls and legislation in a way that fits a fintech. No rigid templates, but a structure that moves with practice.
The collaboration with Tidal doesn't feel like a typical customer-supplier relationship, but like a real partnership. They think along actively, respond quickly and help us get the most out of the tool.
Joris ArtsDirector Finance & Compliance | Floryn
The setup: starting with what you know best
When Joris joined Floryn in January 2023, the platform was already largely populated based on the extensive risk inventory that had been compiled together with KPMG. Around 120 risks and the associated controls were ready to go. The only thing was that not a single one had actually been executed yet.
Floryn chose a sensible route: starting with the compliance controls the team knew and understood best. That was the way to get familiar with Tidal Control. Shortly after, together with Martijn and the development team, the IT controls followed. For a fintech these are among the most important risks. That core still forms the starting point from which Floryn operates.
An additional catalyst came from De Nederlandsche Bank, which strongly advised having the IT processes audited. This produced new improvement points and tightened controls, and ensured that the platform became firmly embedded in the organisation.
From 150 open tasks to a spread-out workload
In the beginning, a classic pitfall emerged. All annual reviews were scheduled at the same time, causing the workload to build up to around 150 tasks at once. The platform made that visible, and that insight led to a better approach.
You learn from it. Something doesn't have to happen in January, it has to happen annually. So we're going to spread that nicely across the whole year, to distribute the workload and also to actively involve other departments.
Joris ArtsDirector Finance & Compliance | Floryn
By spreading tasks out, compliance was no longer a peak load around audits, but a continuous process that runs alongside the annual rhythm. The flexibility to create your own plans and keep that spread in your own hands is something Joris calls one of the strongest points of the platform.
The link that made the difference during the audit
During an audit in June 2023, Joris had a printout of the EBA guidelines with him and was writing down behind each one which control it related to. Then it occurred to him that he could just as easily record that in Tidal.
That's how linking controls to applicable legislation and regulations became one of the biggest improvements Floryn made early on. For every risk and every measure, you can immediately see which legislation applies. That not only saves time: it also provides a firm footing at the moment it counts.
During an audit, Floryn can now easily show which controls relate to which legislation and how they are being executed. The information is centralised and up to date, which brings peace of mind. It also reduces the chance of errors, or last-minute searching.
Compliance belonging to the whole company, not just the compliance team
Introducing a tool is one thing. Bringing the organisation along is another. Joris describes it as an internal game he continuously plays: convincing colleagues by going back to the why. What risks is Floryn exposed to, and what are everyone's responsibilities within that?
He approaches it from two sides at once. On one hand, the laws and regulations Floryn must comply with. On the other, the intrinsic motivation of colleagues who want their own processes to run well. The platform makes both visible. That is how risk management became a topic that is alive throughout the entire organisation.
Since we started using Tidal, awareness of the importance and existence of risks, and controls has increased significantly. Tasks and responsibilities are better embedded, which means internal processes are followed more consistently.
Joris even made the outcomes part of the management report, to communicate their importance broadly. Through periodic meetings with sales, risk and IT, he discusses which risks are at play, what the controls have produced and how things can be improved together.
A learning process: embracing the tool as it is meant to be used
From his experience with earlier GRC tooling, Joris draws an important lesson. The biggest mistake people make is trying to force their existing way of thinking into a new tool. If you stick to your old patterns, you are often disappointed and you never learn more efficient ways of working.
His tip for compliance managers: step away from your own experience as much as possible and embrace what the tool can actually do.
That attitude helped Floryn not just to fulfil the wishes of the moment, but to find the need behind them. The result is a way of working that fits the organisation, rather than the other way around.
Looking ahead: scalability and sharper reporting
Floryn is growing, professionalising and looking at expansion across borders. With that, the number of risks and controls is increasing, and so is the need for overview. Joris sees the logical next step in reporting that shows at a glance where attention needs to go.
I want to be able to see in one or two glances: 100 controls, 7 groups, 3 of them need explanation and one of them we need to take seriously. Anything that helps to group and aggregate that data, that's what gets us excited.
Joris ArtsDirector Finance & Compliance | Floryn
Floryn also wants to actively involve more departments and expand the number of users. From a handful now, to at least 2 per department. That way, compliance shifts further from the first to the second line, and truly becomes the whole organisation's responsibility. The scalability of the platform makes that ambition achievable as regulations grow more complex.
Compliance as an accelerator, not a brake
Where compliance and risk management were once sometimes experienced as a burden, at Floryn they are now an optimised and efficient process. Floryn shows that strong risk management is not a brake on entrepreneurship, but it is the very condition that allows it to flourish sustainably.
Want to know what a similar journey could look like for your organisation? Take the Quickscan and schedule a conversation with our team to discover how Tidal Control makes compliance and risk management scalable for you.
