Practical Guide: Insurance
Pricing, underwriting and claims are three different governance problems wearing one industry label, and the actuarial function already owns part of the answer.
- Typical top tier
- Tier 3–4 — underwriting decline, claims denial, pricing personalization
- Already-owned ground
- Actuarial control cycle, pricing governance, complaints and outcomes data
- Hardest gate
- G2 — because the data lineage question reaches external enrichment sources
- First record to fix
- The Data Lineage and Sensitivity Record for every enrichment feed
1. Where the risk actually concentrates
Insurance splits into three governance problems that are usually run as one. Pricing is a population-level decision with an actuarial control cycle already around it. Underwriting is an individual decision about access to cover. Claims is an individual decision about money owed under a contract, taken at the worst moment of the customer's year. The dimensions read differently in each, and an overlay that treats them uniformly will either over-govern pricing or under-govern claims.
The sector's distinguishing feature is enrichment. Underwriting and pricing models pull external data — credit-adjacent attributes, geospatial and peril data, telematics, medical evidence, third-party claims history. Each source is a grounding source in IRGF's sense, with an owner, a refresh cadence and a maximum staleness, and most of them belong to somebody else. That is where lineage work concentrates and where drift arrives without a deployment.
The second distinguishing feature is that the harm from an error is often invisible to the firm. A wrongly declined claim that is not appealed looks, in the data, like a claim correctly declined. Outcome monitoring is therefore a control, not a metric.
Indicative classification of the systems this sector keeps building. The scores are illustrative, not authoritative: they show how the anchors in Chapter 6 read against sector facts. Score your own system; do not copy a row.
| Typical system | Illustrative D1–D5 | Tier | What is usually mis-scored |
|---|---|---|---|
| Underwriting decline or referral decision | D1 4 · D2 2–3 · D3 3 · D4 4 · D5 4 | Tier 3–4 | D1 read as premium leakage; the consequence is a person unable to obtain cover |
| Claims denial or reduction recommendation | D1 4 · D2 2 · D3 3 · D4 4 · D5 4 | Tier 3–4 | D3 scored 1 because an appeal exists; most wrongly declined claims are never appealed |
| Pricing personalization at individual level | D1 3–4 · D2 3 · D3 2–3 · D4 4 · D5 4 | Tier 3–4 | Treated as an actuarial matter rather than a decision about an identified person |
| Fraud propensity scoring on claims | D1 4 · D2 2–3 · D3 3 · D4 3 · D5 4 | Tier 3–4 | A fraud flag that follows a person between insurers is close to irreversible |
| First notification of loss triage and routing | D1 3 · D2 2–3 · D3 2 · D4 3 · D5 3 | Tier 2–3 | Delay is the harm, and delay does not appear in accuracy metrics |
| Damage estimation from photographs | D1 3 · D2 3 · D3 2 · D4 3 · D5 3 | Tier 3 | D2 rises quietly once settlement below a threshold is auto-approved |
| Medical evidence summarization for life and health underwriting | D1 4 · D2 1–2 · D3 3 · D4 3 · D5 4 | Tier 3–4 | A summarizer that omits a condition has made an underwriting decision |
| Broker or adviser assistant answering cover questions | D1 3 · D2 2 · D3 3 · D4 4 · D5 3 | Tier 3 | A statement about what is covered may bind the firm irrespective of the policy wording |
| Reserving and portfolio analytics | D1 3 · D2 1 · D3 2 · D4 3 · D5 2 | Tier 2 | Usually already inside the actuarial control cycle; reference it rather than re-govern it |
2. The regulatory interface
Regulatory note. The regimes below are named so each IRGF record can be pointed at the obligation it evidences, not to restate them. Applicability, thresholds and commencement dates differ by jurisdiction and several have moved during implementation. Nothing here is legal advice: confirm the current position with your own counsel, and record the answer in the Regulatory Overlay Reference so it is checkable later.
IRGF does not restate any of these obligations. It gives each one a record that carries the evidence, an owner, and a trigger that reopens it when the obligation or the system changes.
| Regime or standard | What it obliges in practice | IRGF record that carries the evidence |
|---|---|---|
| EU AI Act, where it applies | Risk assessment and pricing in life and health insurance for natural persons appears in the Annex III high-risk list, bringing risk management, data governance, logging, human oversight and post-market monitoring duties. | Regulatory Overlay Reference, with the affected system list maintained rather than assessed once |
| Conduct and product governance regimes (for example IDD product oversight, FCA Consumer Duty) | Target market definition, fair value assessment, evidence that outcomes are monitored across customer groups including vulnerable customers. | Outcome monitoring as a registered runtime signal; fair value evidence referenced from the Benefit Record |
| Data protection and special category data rules | Health data, and inferences that amount to health data, carry a higher lawful basis bar; automated decisions need an oversight point and a contest route. | D5 sensitivity anchored at 4 for health inference; oversight point confirmed at G3 |
| Anti-discrimination law and proxy-variable case law in the relevant jurisdiction | Prohibitions on rating or declining on protected characteristics, and on proxies that reproduce them. | Proxy testing recorded as a control in the Control Matrix with the test method named |
| Solvency and actuarial governance regimes (for example Solvency II governance and the actuarial function) | Documented methodology, validation, and an actuarial opinion where required. | Existing actuarial validation referenced by the AI Assurance Summary |
| Claims handling rules and complaint reporting | Timeliness, reasons given, and reportable complaint statistics. | Timeliness and reasons treated as assurance criteria, not service metrics |
3. Calibrating the five dimensions
The dimensions do not change. What changes is what a 3 and a 4 look like when the subject matter is this sector, and which reading an assessor under delivery pressure reaches for first.
| Dimension | How to read it here | The mis-score to watch for |
|---|---|---|
| D1 Decision Consequence | Refusal of cover, denial of a claim, and a fraud flag that is shared externally are all 4. Referral for human review, on its own, is 2 to 3 depending on the delay it causes. | Scoring the firm's exposure. The customer's exposure is the subject of D1. |
| D2 Autonomy | Straight-through processing thresholds are autonomy settings. A claim auto-settled below a value is a D2 = 4 path even if every claim above it is reviewed. | Scoring the reviewed path and ignoring the automated one. Score the highest-autonomy path the system has. |
| D3 Reversibility Deficit | Appeal rights do not make a decision reversible. Score against the proportion of wrong outcomes that are actually corrected, not the proportion that could be. | Treating the existence of a complaints process as reversibility. |
| D4 Exposure and Scale | Anything applied at renewal reaches the whole book within a year, whatever its initial pilot scope. | Scoring the pilot population rather than the deployment path. |
| D5 Sensitivity and Uncertainty | Health data and health inference are 4. Telematics and geospatial data are 3 because they are re-identifying in combination. | Scoring each enrichment source in isolation. Sensitivity is a property of the joined record. |
4. One system, end to end
The overlay above is a map. This is one route across it: a single claim followed from notification to closure, with the record or control that attaches at each step.
5. What each gate adds
Additions only. Everything in the base gate definitions still applies; see the gate checklists for the common set.
| Gate | Sector addition | Why it is here |
|---|---|---|
| G1 | Name every external enrichment source the use case assumes, before architecture. State whether any inference amounts to health data. | Enrichment decisions made in build are almost never revisited, and they set D5 for the life of the system. |
| G2 | Each enrichment feed needs an owner, a contractual permission to use it for this purpose, a refresh cadence and a maximum staleness. Proxy testing method agreed here, not after deployment. | This is the gate the sector fails. A feed nobody owns is a drift source nobody watches. |
| G3 | Evidence of outcome monitoring design across customer groups, and a route by which a wrong decline is detected without relying on an appeal. | Silent errors are the sector's characteristic failure. The detection mechanism has to be part of the authorization. |
| G4 | Any change to a straight-through processing threshold is an autonomy change and re-scores D2. | Thresholds are edited operationally, by people who do not think of themselves as changing an AI system. |
| G5 | Retention aligned to the long tail of liability claims, which outlives the system by years. | Retirement in insurance is rarely the end of the questions. |
6. Controls and evidence worth adding
| Control | Where it attaches | Evidence it produces |
|---|---|---|
| Enrichment source register with owner, permission basis, refresh and staleness | Data Lineage and Sensitivity Record | A per-source record that a regulator or auditor can walk |
| Proxy and outcome testing at agreed intervals | Control Matrix; assurance cycle | Test method, population, result and the action taken on a failed test |
| Straight-through processing threshold register | Change record; policy engine | Current thresholds, who changed them, when, and the D2 consequence |
| Silent-error detection sample | Runtime control: a periodic human re-review of a random sample of declines | Measured wrong-decline rate independent of appeals |
| Vulnerable customer handling path | Control Matrix, with the D1 justification pointing at it | Evidence that the path exists and is used, not that it is documented |
7. Runtime signals to wire first
Control Plane onboarding order matters more than coverage in the first year (Chapter 18). These are the signals that earn their place earliest in this sector.
| Signal | Drift category | Suggested response |
|---|---|---|
| An enrichment feed changes schema, refresh cadence or provider | Data lineage and governance | Direct to the Data Owner; re-score D5 if sensitivity changed, re-run assurance if distribution changed |
| Straight-through processing threshold edited outside the change process | Configuration, with an autonomy consequence | Treat as autonomy change: re-score D2 and route to G4 at Tier 3–4 |
| Decline or denial rate moves by group beyond the agreed band | Behavioral | Route to the risk lead and the product owner together; a technical owner alone cannot act on it |
| Model version change in a purchased scoring service | AI-model behavioral | Material change at Tier 3–4; require the supplier to state what changed, and record the answer |
| Appeal or complaint volume changes materially | Behavioral, detected outside the system | Feed complaints data into the assurance cycle as an input, not a report |
8. Failure modes this sector produces
The pilot that became the book
The tell. A model tested on one product line at one channel is extended at renewal to the whole portfolio, on the grounds that it is the same model.
The response. Population change is a Major change and re-enters deployment authorization. D4 is scored on the deployment path, not the pilot.
Enrichment by acquisition
The tell. A data source is added because a supplier offered it, and the lineage record is updated months later, if at all.
The response. Make the index or feature build fail when a source is not in the approved lineage record. A preventive control here is cheap; a detective one arrives after the pricing has already been used.
Governance that stops at the model boundary
The tell. The scoring model is validated to actuarial standard; the retrieval-based summarizer feeding the underwriter is treated as an office tool.
The response. The summarizer is part of the decision path. Score it on the decision it shapes, not on its own output.
The proxy nobody tested for
The tell. A feature that is not a protected characteristic reproduces one closely enough that outcomes diverge, and the test that would have shown it was never agreed.
The response. Agree the proxy test method at G2, while the design is still changeable, and record the method in the Control Matrix so it is repeatable.
9. A ninety-day start
If the sector is yours and the framework is new, this is the order that produces something defensible fastest. It assumes one part-time architect and one risk lead, not a programme.
- Separate the estate into pricing, underwriting, claims and assistance. Govern them as four populations with different anchors.
- Build the enrichment source register first. It is the artifact that unblocks G2 for everything else.
- Score the top three decision systems in claims and underwriting with an independent countersigner.
- Register every straight-through processing threshold and name its owner. Most firms find thresholds nobody remembers setting.
- Stand up one silent-error sample: fifty random declines re-reviewed by a human each month. Report the wrong-decline rate to the same body that sees the accuracy metrics.
- Agree proxy and outcome testing methods with the actuarial and legal functions before the next model change, not during it.
- Wire enrichment-feed change alerts into the Control Plane. This is the sector's highest-value first signal.
- Run a G3 dry run on the claims system with the complaints team in the room.