K · Practical guide

Practical Guide: Insurance

Pricing, underwriting and claims are three different governance problems wearing one industry label, and the actuarial function already owns part of the answer.

Typical top tier
Tier 3–4 — underwriting decline, claims denial, pricing personalization
Already-owned ground
Actuarial control cycle, pricing governance, complaints and outcomes data
Hardest gate
G2 — because the data lineage question reaches external enrichment sources
First record to fix
The Data Lineage and Sensitivity Record for every enrichment feed

1. Where the risk actually concentrates

Insurance splits into three governance problems that are usually run as one. Pricing is a population-level decision with an actuarial control cycle already around it. Underwriting is an individual decision about access to cover. Claims is an individual decision about money owed under a contract, taken at the worst moment of the customer's year. The dimensions read differently in each, and an overlay that treats them uniformly will either over-govern pricing or under-govern claims.

The sector's distinguishing feature is enrichment. Underwriting and pricing models pull external data — credit-adjacent attributes, geospatial and peril data, telematics, medical evidence, third-party claims history. Each source is a grounding source in IRGF's sense, with an owner, a refresh cadence and a maximum staleness, and most of them belong to somebody else. That is where lineage work concentrates and where drift arrives without a deployment.

The second distinguishing feature is that the harm from an error is often invisible to the firm. A wrongly declined claim that is not appealed looks, in the data, like a claim correctly declined. Outcome monitoring is therefore a control, not a metric.

Distribution quotes, broker assistants Tier 3 Pricing personalization at individual level Tier 3 Underwriting accept, refer, decline Tier 4 Claims triage, estimate, settle, deny Tier 4 Portfolio reserving, analytics Tier 2
Three governance problems in one industry. Pricing has an actuarial control cycle around it already; underwriting and claims are individual decisions about access to cover and money owed, and they are where the anchors read hardest. Enrichment data flows into all five columns, which is why lineage is the first artifact to fix.

Indicative classification of the systems this sector keeps building. The scores are illustrative, not authoritative: they show how the anchors in Chapter 6 read against sector facts. Score your own system; do not copy a row.

Typical system Illustrative D1–D5 Tier What is usually mis-scored
Underwriting decline or referral decisionD1 4 · D2 2–3 · D3 3 · D4 4 · D5 4Tier 3–4D1 read as premium leakage; the consequence is a person unable to obtain cover
Claims denial or reduction recommendationD1 4 · D2 2 · D3 3 · D4 4 · D5 4Tier 3–4D3 scored 1 because an appeal exists; most wrongly declined claims are never appealed
Pricing personalization at individual levelD1 3–4 · D2 3 · D3 2–3 · D4 4 · D5 4Tier 3–4Treated as an actuarial matter rather than a decision about an identified person
Fraud propensity scoring on claimsD1 4 · D2 2–3 · D3 3 · D4 3 · D5 4Tier 3–4A fraud flag that follows a person between insurers is close to irreversible
First notification of loss triage and routingD1 3 · D2 2–3 · D3 2 · D4 3 · D5 3Tier 2–3Delay is the harm, and delay does not appear in accuracy metrics
Damage estimation from photographsD1 3 · D2 3 · D3 2 · D4 3 · D5 3Tier 3D2 rises quietly once settlement below a threshold is auto-approved
Medical evidence summarization for life and health underwritingD1 4 · D2 1–2 · D3 3 · D4 3 · D5 4Tier 3–4A summarizer that omits a condition has made an underwriting decision
Broker or adviser assistant answering cover questionsD1 3 · D2 2 · D3 3 · D4 4 · D5 3Tier 3A statement about what is covered may bind the firm irrespective of the policy wording
Reserving and portfolio analyticsD1 3 · D2 1 · D3 2 · D4 3 · D5 2Tier 2Usually already inside the actuarial control cycle; reference it rather than re-govern it

2. The regulatory interface

Regulatory note. The regimes below are named so each IRGF record can be pointed at the obligation it evidences, not to restate them. Applicability, thresholds and commencement dates differ by jurisdiction and several have moved during implementation. Nothing here is legal advice: confirm the current position with your own counsel, and record the answer in the Regulatory Overlay Reference so it is checkable later.

IRGF does not restate any of these obligations. It gives each one a record that carries the evidence, an owner, and a trigger that reopens it when the obligation or the system changes.

Regime or standard What it obliges in practice IRGF record that carries the evidence
EU AI Act, where it appliesRisk assessment and pricing in life and health insurance for natural persons appears in the Annex III high-risk list, bringing risk management, data governance, logging, human oversight and post-market monitoring duties.Regulatory Overlay Reference, with the affected system list maintained rather than assessed once
Conduct and product governance regimes (for example IDD product oversight, FCA Consumer Duty)Target market definition, fair value assessment, evidence that outcomes are monitored across customer groups including vulnerable customers.Outcome monitoring as a registered runtime signal; fair value evidence referenced from the Benefit Record
Data protection and special category data rulesHealth data, and inferences that amount to health data, carry a higher lawful basis bar; automated decisions need an oversight point and a contest route.D5 sensitivity anchored at 4 for health inference; oversight point confirmed at G3
Anti-discrimination law and proxy-variable case law in the relevant jurisdictionProhibitions on rating or declining on protected characteristics, and on proxies that reproduce them.Proxy testing recorded as a control in the Control Matrix with the test method named
Solvency and actuarial governance regimes (for example Solvency II governance and the actuarial function)Documented methodology, validation, and an actuarial opinion where required.Existing actuarial validation referenced by the AI Assurance Summary
Claims handling rules and complaint reportingTimeliness, reasons given, and reportable complaint statistics.Timeliness and reasons treated as assurance criteria, not service metrics

3. Calibrating the five dimensions

The dimensions do not change. What changes is what a 3 and a 4 look like when the subject matter is this sector, and which reading an assessor under delivery pressure reaches for first.

Dimension How to read it here The mis-score to watch for
D1 Decision ConsequenceRefusal of cover, denial of a claim, and a fraud flag that is shared externally are all 4. Referral for human review, on its own, is 2 to 3 depending on the delay it causes.Scoring the firm's exposure. The customer's exposure is the subject of D1.
D2 AutonomyStraight-through processing thresholds are autonomy settings. A claim auto-settled below a value is a D2 = 4 path even if every claim above it is reviewed.Scoring the reviewed path and ignoring the automated one. Score the highest-autonomy path the system has.
D3 Reversibility DeficitAppeal rights do not make a decision reversible. Score against the proportion of wrong outcomes that are actually corrected, not the proportion that could be.Treating the existence of a complaints process as reversibility.
D4 Exposure and ScaleAnything applied at renewal reaches the whole book within a year, whatever its initial pilot scope.Scoring the pilot population rather than the deployment path.
D5 Sensitivity and UncertaintyHealth data and health inference are 4. Telematics and geospatial data are 3 because they are re-identifying in combination.Scoring each enrichment source in isolation. Sensitivity is a property of the joined record.

4. One system, end to end

The overlay above is a map. This is one route across it: a single claim followed from notification to closure, with the record or control that attaches at each step.

Worked example — claims triage and decline recommendation D1 4 · D2 2 · D3 3 · D4 4 · D5 4 → IMPACT 4 · CONTROL DEFICIT 3 → TIER 4 IN THE WORLD IN THE RECORD, AND WHAT WATCHES IT First notification of loss received Canvas names every enrichment source the use case assumes, before architecture Enrichment joined: peril, telematics, claims history Lineage record per feed: owner, permission basis, refresh, maximum staleness Model recommends decline or fast-track Classification : D3 = 3 because most wrongly declined claims are never appealed Handler confirms and the outcome is communicated Silent-error sample: fifty random declines re- reviewed monthly by a person Claim closed; complaint window opens Drift watch: feed schema change, decline rate by group, complaint volume
The harm this sector cannot see. A wrongly declined claim that is never appealed looks, in the data, exactly like a correct decline. That is why the fourth column carries a sampling control rather than a metric, and why the enrichment lineage in column two is the first artifact to fix.

5. What each gate adds

Additions only. Everything in the base gate definitions still applies; see the gate checklists for the common set.

Gate Sector addition Why it is here
G1Name every external enrichment source the use case assumes, before architecture. State whether any inference amounts to health data.Enrichment decisions made in build are almost never revisited, and they set D5 for the life of the system.
G2Each enrichment feed needs an owner, a contractual permission to use it for this purpose, a refresh cadence and a maximum staleness. Proxy testing method agreed here, not after deployment.This is the gate the sector fails. A feed nobody owns is a drift source nobody watches.
G3Evidence of outcome monitoring design across customer groups, and a route by which a wrong decline is detected without relying on an appeal.Silent errors are the sector's characteristic failure. The detection mechanism has to be part of the authorization.
G4Any change to a straight-through processing threshold is an autonomy change and re-scores D2.Thresholds are edited operationally, by people who do not think of themselves as changing an AI system.
G5Retention aligned to the long tail of liability claims, which outlives the system by years.Retirement in insurance is rarely the end of the questions.

6. Controls and evidence worth adding

Control Where it attaches Evidence it produces
Enrichment source register with owner, permission basis, refresh and stalenessData Lineage and Sensitivity RecordA per-source record that a regulator or auditor can walk
Proxy and outcome testing at agreed intervalsControl Matrix; assurance cycleTest method, population, result and the action taken on a failed test
Straight-through processing threshold registerChange record; policy engineCurrent thresholds, who changed them, when, and the D2 consequence
Silent-error detection sampleRuntime control: a periodic human re-review of a random sample of declinesMeasured wrong-decline rate independent of appeals
Vulnerable customer handling pathControl Matrix, with the D1 justification pointing at itEvidence that the path exists and is used, not that it is documented

7. Runtime signals to wire first

Control Plane onboarding order matters more than coverage in the first year (Chapter 18). These are the signals that earn their place earliest in this sector.

Signal Drift category Suggested response
An enrichment feed changes schema, refresh cadence or providerData lineage and governanceDirect to the Data Owner; re-score D5 if sensitivity changed, re-run assurance if distribution changed
Straight-through processing threshold edited outside the change processConfiguration, with an autonomy consequenceTreat as autonomy change: re-score D2 and route to G4 at Tier 3–4
Decline or denial rate moves by group beyond the agreed bandBehavioralRoute to the risk lead and the product owner together; a technical owner alone cannot act on it
Model version change in a purchased scoring serviceAI-model behavioralMaterial change at Tier 3–4; require the supplier to state what changed, and record the answer
Appeal or complaint volume changes materiallyBehavioral, detected outside the systemFeed complaints data into the assurance cycle as an input, not a report

8. Failure modes this sector produces

The pilot that became the book

The tell. A model tested on one product line at one channel is extended at renewal to the whole portfolio, on the grounds that it is the same model.

The response. Population change is a Major change and re-enters deployment authorization. D4 is scored on the deployment path, not the pilot.

Enrichment by acquisition

The tell. A data source is added because a supplier offered it, and the lineage record is updated months later, if at all.

The response. Make the index or feature build fail when a source is not in the approved lineage record. A preventive control here is cheap; a detective one arrives after the pricing has already been used.

Governance that stops at the model boundary

The tell. The scoring model is validated to actuarial standard; the retrieval-based summarizer feeding the underwriter is treated as an office tool.

The response. The summarizer is part of the decision path. Score it on the decision it shapes, not on its own output.

The proxy nobody tested for

The tell. A feature that is not a protected characteristic reproduces one closely enough that outcomes diverge, and the test that would have shown it was never agreed.

The response. Agree the proxy test method at G2, while the design is still changeable, and record the method in the Control Matrix so it is repeatable.

9. A ninety-day start

If the sector is yours and the framework is new, this is the order that produces something defensible fastest. It assumes one part-time architect and one risk lead, not a programme.

  1. Separate the estate into pricing, underwriting, claims and assistance. Govern them as four populations with different anchors.
  2. Build the enrichment source register first. It is the artifact that unblocks G2 for everything else.
  3. Score the top three decision systems in claims and underwriting with an independent countersigner.
  4. Register every straight-through processing threshold and name its owner. Most firms find thresholds nobody remembers setting.
  5. Stand up one silent-error sample: fifty random declines re-reviewed by a human each month. Report the wrong-decline rate to the same body that sees the accuracy metrics.
  6. Agree proxy and outcome testing methods with the actuarial and legal functions before the next model change, not during it.
  7. Wire enrichment-feed change alerts into the Control Plane. This is the sector's highest-value first signal.
  8. Run a G3 dry run on the claims system with the complaints team in the room.