Download

World Cup Shows Insurers How to Avoid a Red Card

Amid a hugely successful World Cup tournament, Argentina demonstrated how actions by a few bad actors can chase away millions of fans (or customers).

Image
WC

A World Cup soccer tournament wouldn't be a World Cup without controversies, and the just-concluded event had its share. 

Then Argentina said, Hold my Fernet con Cola. 

Following the team's 1-0 loss in the finals to a clearly superior Spanish team, an Argentine player picked a fight on the field that included grabbing a Spanish player by the throat and throwing him to the ground, and Argentine teammates backed him up. Just about the whole Argentine team then acted churlish during the awards ceremony, even turning their backs as the Spanish players were awarded their gold medals and the team trophy. 

Within minutes, reporters and fans were revisiting every untoward thing Argentina had done during the tournament, then during prior tournaments, then on the team bus, then.... 

Argentina provides a great example of how actions taken even by a few in the heat of the moment can sour masses of people on a group or a brand. It's a lesson that I think insurers, in particular, should take to heart, given that our most consequential actions tend to come when dealing with people in situations where their emotions are running hot. 

Let's have a look. 

Argentina had been a possible feel-good story coming into the tournament this year. It had finally won the World Cup in 2022 for its captain, all-time great Lionel Messi. If Argentina had repeated as champion, it would have been the first to do so since Brazil in 1962. Messi, who had won the Golden Ball award in 2022, given to the best player in the tournament, was in the running for the award again. Going into the final, he also had a shot at the Golden Boot, given to the top scorer in the World Cup. At 39 years old, a beloved player was putting in a remarkable performance.

Now, Argentina is known for being chippy, even dirty, and it played to form throughout the tournament, including by having a player sent off in the final after a violent tackle. Spain, while hardly free of fouls, played a classic style that contrasted sharply with Argentina and led any number of people to post at the conclusion of the game some variant of, "Football won today." 

The history of writeups about the Argentine team suggests that would have been about the extent of the complaints about Argentina's tactics. 

Then the Argentine players started knocking around some of the Spaniards after the final whistle, and all bets were off. 

Someone quickly shared a clip of the Argentine player instigating the post-game brawl. Then people started going back through the whole game, pointing out everything even borderline that Argentine players did here is one-such 13-minute clip. But why stop there? Here is a 5 1/2-minute clip of transgressions by Argentina that weren't penalized in the semifinal against England. Of course, there was group play, too here is nine minutes of uncalled fouls against Switzerland. 

Earlier incidents became fair game, as well. A video surfaced in 2024 of Enzo Gonzalez, the Argentine player who drew a red card in the final, and teammates chanting racist slurs on the team bus, as posts such as this one quickly noted over the weekend. Gonzalez had apologized profusely, including personally to Black players on his club team, and surely thought the incident was behind him. No longer. Many on social media also noted that the Spanish goalkeeper had been classy in accepting the Golden Glove award, for the best at his position in this year's tournament, while the Argentine keeper had used the award to make an obscene gesture when he won in 2022.

Analysts were universally brutal about Argentina after the final. The New York Times ran a story under the headline, "Argentina disgraced themselves, and the World Cup final, with their charmless petulance." In case that wasn't enough, the NYT ran another story, full of images, under the headline, "How Argentina turned the World Cup final dirty with shoves, skulduggery and squealing."

My point being: Once sentiment turns against you, even based on an incident by one person or a small group, things can go downhill fast and keep going.  

This surely isn't news to insurance companies, which understand that claims are the moment of truth. Everyone and everything has to line up just right when you're dealing with longstanding, loyal customers in their moment of need. They've earned compassionate, professional excellence and they'll react in horror if they don't get it. 

But I still think object lessons like those provided by Argentina are worth noting and spreading, because it only takes a few people, or even a single person, to undercut what so many other people are doing to earn loyalty. Social media can broadcast bad actions incredibly fast these days and seems to relish doing so, especially if there is compelling video. 

And narratives are hard to shake once they take hold. The Argentine team is being cooked especially hard because it was already known as a dirty team. In insurance, if you're not known for great customer service, complaints will find an especially alert audience — I'm sure State Farm, for instance, is being incredibly careful these days, given the controversy over its handling of claims from last year's wildfires in California.

I won't suggest buying the jersey of Leandro Paredes, the Argentine player who ran up on a Spanish player from behind after the game and knocked him over, because some of the money would find its way back to him. But maybe he can be an anti-hero for anyone dealing with insurance customers. Whatever you do, people, don't earn us a reputation like that guy....

Cheers,

Paul

P.S. When I think back on the World Cup, I'll prefer to think about the positive surprises. Who knew that Costco and ranch dressing would be such delights for those visiting the U.S.? Erling Haaland? I've spent years hating on him in a Man City kit but found him impossibly charming both in a Norway jersey and in his experience with U.S. culture. Then there was Spanish star Lamine Yamal's three-year-old brother, Keyne, who stole every scene he was in throughout the tournament. 

And I'll especially cherish a moment that Jude Bellingham and Bukayo Saka and their English team had in their third-place game against the French. 

When England earned a penalty kick, Bellingham prepared to take it. He had emerged as a full-on star for England and had already scored six goals; seven would be unworldly. But he knew that Saka had scored twice against France, knew that concerns about injury had (unwisely, in my view) kept Saka out of the semifinal that England lost against Argentina, and may have been thinking about how Saka and two Black teammates had missed penalty kicks in a tournament in 2021 and had endured wildly racist criticism. 

Bellingham told Saka, "Go on and get your hat trick," and handed him the ball. Saka converted with a kick that the keeper wouldn't have touched even if he had guessed right, rather than diving in the opposite direction. Saka's goal turned out to be the winner. 

Bellingham, by the way, got his seventh goal a few minutes later with an extraordinary display of technical virtuosity. So nice guys finish.... first?

Becoming a Frontier Insurer

Explore how Frontier Insurers use AI, GenAI, and Agentic AI to lead on competitiveness, cost structure, and growth in the intelligent era.

Frontier Insurer

AI has moved past the hype stage—it's reshaping cost structures, competitiveness, and growth across insurance. Carriers who hesitate are locking in cost and risk profiles that only get harder to unwind. Drawing on original research with insurance executives, this report shows how AI, GenAI, and Agentic AI are separating Leaders from Followers and Laggards—and why 2026 is the point of no return.

AI is now a boardroom priority, tied to insurers' top 2026 goals: cutting costs, streamlining operations, and improving customer experience. Across underwriting, claims, servicing, billing, distribution, and loss control, carriers are moving from talk to active pilots, targeting friction in paperwork-heavy areas like claims and service. But appetite is outpacing the data foundation needed to support it, raising scalability and reliability risks without stronger governance.

The center of gravity is shifting from "AI as a data tool" to "AI as a workforce multiplier," powered by the Frontier Firm—companies built on on-demand intelligence and human-agent teams, where staff act as "agent bosses." Leaders are already scaling GenAI and Agentic AI with mature data capabilities behind them; laggards risk losing ground on performance and cost.

Download this report to explore:

  • Why modernized data and an Intelligent Core are essential for scalable, responsible AI
  • How to bring the Frontier Firm and Agent Boss models into your organization
  • How AI is reshaping cost, competitiveness, and growth across the insurance value chain

 

 

Get Started>>


ITL Partner: Majesco

Profile picture for user majescopartner

ITL Partner: Majesco

Majesco isn’t just riding the AI wave — we’re leading it across the P&C, L&AH, and Pension & Retirement markets. Born in the cloud and built with an AI-native vision, we’ve reimagined the insurance and pension core as an intelligent platform that enables insurers and retirement providers to move faster, see farther, and operate smarter. As leaders in intelligent SaaS, we embed AI and Agentic AI across our portfolio of core, underwriting, loss control, distribution, digital, and pension & retirement administration solutions — empowering customers with real-time insights, optimized operations, and measurable business outcomes.


Everything we build is designed to strip away complexity so our clients can focus on what matters most: delivering exceptional products, experiences, and long-term financial security for policyholders and plan participants. In a world of constant change, our native-cloud SaaS platform gives insurers, MGAs, and pension & retirement providers the agility to adapt to evolving risk, regulation, and market expectations, modernize operating models, and accelerate innovation at scale. With 1,400+ implementations and more than 375 customers worldwide, Majesco is the AI-native solution trusted to power the future of insurance and pension & retirement. Break free from the past and build what’s next at www.majesco.com


Additional Resources

Modernize or Fall Behind: 2025 Retirement & Pension Top Industry Trends

Read More

Closing the Insurance Customer Protection Gap: How Generational Differences in Risk, Readiness, and Coverage Are Redefining Insurance Value

Read More

Bridging the Customer Protection Gap

Read More

Transforming Specialty Insurance with AI

Read More

Leaders Reinventing Insurance: Strategic Focus on Business Operating Model and Technology Foundation

Read More

How to Accelerate Recovery From Floods

Bipartisan legislation would use federal mitigation funds to support parametric flood insurance, accelerating disaster recovery in underinsured communities.

flood

Forecasts suggest this year's hurricane season could bring lower than average storm activity. But disaster risk is not measured solely by the number of named storms.

It only takes one major flood to expose the vulnerabilities that persist across the US flood protection system. And increasingly, flood losses are not confined to coastal communities or storm surge alone. Flooding driven by heavy rainfall, overflowing rivers, and flash floods are increasingly affecting communities far beyond traditional flood zones, often in places where insurance take-up is low and financial resilience is limited.

This reality highlights an urgent policy challenge; America's flood protection gap continues to widen at a time when economic exposure is growing.

Flooding can happen almost anywhere, yet millions of American households and businesses remain uninsured or underinsured against flood risk. When disasters strike, the consequences extend well beyond individual property losses, which alone are already devastating. Delayed recovery affects local employers, municipal budgets, infrastructure systems, housing markets, and broader regional economic activity.

Insurance plays a critical role in helping individuals, businesses, and communities recover more quickly and reducing long-term economic disruption. Strong insurance participation supports financial stability after disasters, accelerates rebuilding, and reduces reliance on post-event federal assistance. It's an essential component of economic resilience for all Americans.

That's why Congress should advance the bipartisan Community Flood Resilience Act, introduced by Congressman Andrew Garbarino and Congressman Gregory Meeks.

The legislation reflects a pragmatic recognition that resilience requires both physical mitigation and financial preparedness. By allowing a portion of federal flood mitigation assistance funding to support community-based parametric flood insurance solutions, Congress is advancing a thoughtful public-private sector approach to disaster resilience.

This legislation does not replace the National Flood Insurance Program (NFIP). Instead, it acknowledges that public and private solutions can work together to expand protection, improve awareness, and strengthen recovery capabilities. In today's evolving risk environment, collaboration is essential.

Community-based parametric insurance provides funding when predefined conditions are met, such as measured rainfall levels, river heights, or other objective flood triggers. Because payments are tied to those triggers rather than lengthy loss-adjustment processes, communities can access funds much more quickly after a disaster. Faster access to funding can help local governments stabilize essential services, support small businesses, and assist vulnerable populations during the critical days immediately after flooding occurs.

Speed matters after disasters. Delays in recovery funding often translate into prolonged economic hardship for communities already under strain. Parametric insurance policies can deliver payments within 30 days, or less, when the funds are needed the most.

The legislation also emphasizes education, outreach, and transparency. Participating communities must describe how they promote flood insurance awareness, encourage mitigation efforts, and communicate clearly about how these products function alongside traditional coverage. These provisions recognize that resilience begins with understanding what's at risk.

The insurance industry has long played a foundational role in supporting economic growth and recovery following catastrophic events. As risks evolve, innovation in risk transfer and resilience financing will increasingly become important complements to infrastructure investment, stronger building standards, and disaster mitigation programs.

Public-private collaboration will be critical to narrowing the protection gap. Legislation like the Community Flood Resilience Act demonstrates how policymakers can encourage innovation while strengthening community preparedness and preserving the role of insurance in supporting economic resilience.

Resilience is built before disasters through smarter planning, stronger mitigation, and broader financial protection. Public policy that improves flood insurance participation and accelerates recovery better protects homes and businesses, and promotes the long-term economic stability of communities across the country.

As flood risk expands beyond traditional geographic boundaries, policymakers need tools that strengthen both physical resilience and financial preparedness. The Community Flood Resilience Act is a practical way to do both.


Adrian Hall

Profile picture for user AdrianHall

Adrian Hall

Adrian Hall is CEO US for Swiss Re Corporate Solutions.

He is also a member of the Swiss Re Corporate Solutions global executive committee and a board director for Swiss Re Corporate Solutions America Insurance.

Previously, he was the managing director & head, UK, Ireland, South Africa and EMEA Wholesale, and CEO & Chief, Agent Canada, for Swiss Re Corporate Solutions. An insurance industry veteran with over 30 years of experience, he has lived and worked across five continents.

Hall holds a bachelor of science degree in business from University of Wales, Swansea and a master’s certification in marketing leadership from York University, Schulich Business School, Canada.

The Ghost in State Farm's Machine

State Farm's sweeping cuts to agent compensation signal how private equity thinking now shapes even mutual insurers' operating models.

Ghost in the Machine

State Farm just told 19,000 captive agents the deal has changed. Deferred compensation? Gone. Health benefits? Reduced. Renewal commissions? Squeezed in favor of new-business production.

State Farm is a policyholder-owned mutual—the largest in the country—not a private equity play. Yet the announcement reads like it came straight out of a KKR, Apollo, or Blackstone operating playbook.

For decades, State Farm's model rested on a simple premise: a book of business is not self-sustaining. It requires labor. Agents weren't just selling policies; they were maintaining them—fielding calls, resolving issues, retaining customers, spotting risks before they became claims. Renewal commissions weren't a bonus. They were the operating system.

But operating systems get deprecated.

Every generation redraws the line between labor and leverage, between what requires a human and what can be systematized. The real question isn't whether people add value. It's whether they add the same value they once did—and whether that value supports the same cost structure.

Seen through that lens, State Farm's move wasn't surprising. It was inevitable.

Three forces have been quietly closing in.

First, competition. Progressive and GEICO operate without an agent-heavy cost base. They built direct models—leaner, faster, less sentimental. As they gained share—Progressive recently passed State Farm as the top writer of auto policies in the US—State Farm was forced to respond.

Second, management migration. Over the past two decades, executives have moved through private equity portfolio companies, internalizing a shared language—almost a mantra—of efficiency, productivity, and return on capital. What was once distinctive to private equity is becoming simply how management thinks.

Third, AI. Service calls, billing questions, renewals, first notice of loss—tasks that once justified large workforces and long-tail commissions—are increasingly handled by software that doesn't sleep, doesn't churn, and declines in marginal cost over time.

This doesn't make human agents obsolete. It makes legacy compensation models obsolete.

Human value doesn't disappear, it concentrates in complex cases, edge scenarios, trust, judgment—the hard stuff. But the routine? The repeatable? The predictable? That's already slipping out of human hands.

The private equity approach asks a relentless question of every line item: if we were building this today, would we pay for it this way? That question is destabilizing inside legacy models, because once you ask it honestly, a lot of "strategic investments" start to look like habits. And habits, over time, get expensive.

So this isn't a story about private equity taking over State Farm. It's something more consequential: the normalization of a worldview private equity helped industrialize. Nothing is sacred—except the spreadsheet. Every cost is conditional. Yesterday's logic expires faster than anyone wants to admit.

Cost cutting is the easy part. Plenty of companies are doing that—and calling it strategy.

The harder move is what comes next: reinvesting those savings to build something better. Better experiences. Stronger capabilities. New forms of growth that justify the disruption.

In the end, the winners won't be those who simply get leaner. They'll be the ones who get smarter about where humans still matter—and ruthlessly disciplined about where they don't.

That's the real ghost in the machine.


Riv Arthur

Profile picture for user RivArthur

Riv Arthur

Riv Arthur is a business leader and technologist working in insurance, healthcare, and private equity.

Can Insurers Break Free From the POC Trap?

Insurers struggle to scale AI beyond the proof-of-concept stage due to poor data management, not the technology itself.

Management Over AI

The insurance industry faces a key question: How can insurers successfully industrialize their AI initiatives?

Scaling AI requires a distinct approach relying on: compliance, security, and traceability. Not meeting these requirements prevents projects from moving beyond the early stages, especially when they lack clear governance, performance indicators and risk management.

AI itself is not the factor impeding or slowing down the crucial passage from POC to fully deployed projects. The real issue lies in the approach and environment in which AI initiatives are developed and industrialized. Projects are still approached from a very traditional perspective rather than as potential business use cases, overlooking the need to factor in elements such as IT infrastructures, operations and, crucially, data management.

In this case, the distinction lies in the way data is being managed. Organizations with poorly structured and scattered document silos struggle with the technological debt of outdated systems including legacy enterprise content management (ECM) platforms and archives. Data management makes a difference when it comes to successfully industrializing insurers' projects as well as being one of the main difficulties they can encounter.

Scaling up with strong decision making

To succeed, organizations must rely on clear strategies driven by high-value business use cases that show immediate and significant affect in areas that are key to the business, for example the automation of claims processing.

They should also increase the focus on modernizing the existing ECM platforms while refraining from launching a complete overhaul. As counterintuitive and challenging as it might sound, this balance is essential to success and can be achieved by intelligent information management and keeping up with the latest AI implementations.

Finally, they take into account challenges related to governance and compliance from the very beginning: data traceability, model explainability, and compliance with regulatory frameworks.

The key to success: a strong information foundation

What differentiates insurers that have successfully scaled their AI projects from others is the way they approached the issue: they started with data rather than starting with AI. Insurance is a document-driven industry; its value lies in leveraging its content: policies, claims files, contracts, correspondence, broker communications, loss reports, medical records, underwriting submissions, and regulatory documentation.

Some insurers are still dependent on legacy systems, traditional ECM/DMS platforms which are now showing their limits and slowing access to information. Their lack of flexibility, combined with the proliferation of repositories, make the use of information difficult.

To overcome these difficulties insurers must rely on technological solutions incorporating AI to automate the creation of a unified, structured, and accessible information environment. But in order to be truly impactful and bring long-lasting innovation, this can't simply be merely a new layer added on top of an existing system: what is really needed is a thorough modernization of native platforms, contextualized in real-time thanks to advanced AI tools.

Inspired industry leaders are those who know how to prioritize long-lasting sustainable industrialization over short-term and rapid changes. Integrating AI solutions is a starting point, but not the solution itself. The ideal conditions for large-scale deployment have to touch all assets of the business, from talent acquisition to fill the new skill gap to investing in research and development and, especially for a consumer-facing industry like insurance, transparency and the ability to explain the benefits stemming from the technology upgrades.

Organizations that can't align with this approach are likely bound to be left behind in the no man's land of unrealized POCs, while others successfully scale up projects and introduce innovations.

A Strategic Shift in Insurance Distribution

Insurance carriers are shifting from merely managing producer networks to leveraging distribution data for strategic competitive advantage.

Insurance Distribution Shifts from Management to Intelligence

After decades of inefficiencies, insurance carriers, MGAs, and agencies have finally begun to invest in their technology to modernize and improve distribution management. The goal is straightforward: automate producer onboarding, simplify licensing and appointments, maintain compliance, and process transactions more efficiently.

As the industry works to catch up with these investments, they've revealed a stark reality that most distribution systems were designed to execute processes rather than generate strategic intelligence. This distinction is significant because the next competitive advantage in insurance distribution won't come from simply managing producer networks more easily, though that is important; rather, advantage will come from understanding the networks more deeply.

Distribution data is the untapped goldmine in the insurance industry. The winners are already prospecting the land.

The Data Exists, You Need To Use It

Every interaction within a distribution management platform creates valuable information. Appointments, licensing timelines, agency affiliations, geographic distribution, product sales, producer tenure, renewal activity, and more data points are readily available to companies that use a centralized database.

Historically, this data has been stored to primarily support administrative functions. Once a transaction is complete, the information is saved but its strategic value goes untapped. If you ask a carrier how many appointed producers they have they can easily answer. However, if you were to ask them for more detailed insights the answers become much more difficult — or impossible — to produce.

Which newly appointed producers have generated the highest premium in their first 90 days? Which agencies consistently outperform peers in specific product lines? Where are producers successfully cross-selling multiple products versus writing only one line of business? Which states have the strongest producer recruitment outcomes relative to onboarding investment?

These are critical business questions, not operational ones. And these are the kinds of insights distribution data will be able to provide.

Reporting Vs. Intelligence

There is a distinct difference between reporting and intelligence. Reporting tells you what happened, but intelligence helps explain why it happened and what should happen next.

Let's consider producer recruiting. Many organizations measure success by the number of producers appointed each quarter. But appointments alone don't determine business value. What if data revealed that producers recruited through one regional agency network generate twice the lifetime premium of those recruited through another channel? Or that producers with certain business characteristics consistently become top performers within six months? These insights could fundamentally reshape how an organization invests in recruiting.

This isn't theoretical. One MGA connected its appointment engine directly to live production data. Instead of maintaining — and paying state fees for — appointments across its entire roster, the system now fires an appointment the moment a producer submits their first application and initiates termination when production goes dormant. Producers go from signup to production-ready in minutes instead of weeks, and state appointment fees dropped by more than 50% because the roster finally reflects reality. A report would have told this MGA how many producers it had appointed. Intelligence told it which appointments were actually earning their keep.

Identify High-Performers Earlier

One of the biggest opportunities lies in identifying successful producers much earlier in their relationship with a carrier. Many carriers and MGAs recognize top producers after they've built an established book of business and hit certain milestones. These recognitions work to build and solidify strong working relationships between top producers and carriers. This goodwill is effective, but it is only built after producers deliver large results.

What if they could identify high-potential producers within their first few months? Organizations could build these relationships earlier, and create a stronger connection with up-and-coming talent.

By analyzing historical production patterns, onboarding activity, product mix, submission behavior, and engagement trends, AI-powered analytics could recognize signals and patterns that have historically preceded long-term success. Perhaps producers who complete onboarding in less than 30 days, immediately write across multiple product lines, and maintain consistent submission activity during their first quarter have historically become top performers.

If these patterns emerge early, distribution leaders could proactively invest in those relationships through targeted marketing support, additional training, and even mentorship. Rather than reacting to success after it occurs, organizations could help accelerate it.

Opportunities Hidden in Geography

Distribution intelligence has the potential to uncover geographic expansion opportunities that may not be immediately obvious.

For example, a carrier may believe it has saturated a particular state because of the number of appointed producers operating there. However, a deeper analysis might reveal that neighboring counties with similar demographics have significantly lower producer density but higher policy growth potential.

Alternatively, the data may show that commercial lines producers are outperforming personal lines producers in a specific region, suggesting an opportunity to adjust recruiting priorities or product offerings.

These insights would allow organizations to make expansion decisions based on measurable market intelligence rather than calculated assumptions.

From Dashboards to Decision Engines

Collecting data is important, but not using it creates little value. Real opportunity comes from gleaning valuable insights and making them accessible to business leaders.

Modern dashboards need to move beyond displaying static metrics. They should benchmark producer performance, identify emerging trends, forecast recruiting outcomes, and highlight opportunities requiring immediate attention.

Imagine a distribution executive opening a dashboard that identifies states where onboarding times have increased, predicts recruiting shortfalls for the next quarter, highlights agencies exceeding profitability benchmarks, and recommends where additional field resources should be deployed.

Those are strategic business decisions powered by data, not just operational reports.

The Future Is AI

As AI continues to mature, the possibilities become even more compelling. Instead of simply analyzing historical performance, AI will increasingly help organizations anticipate future outcomes and identify lucrative opportunities.

Predictive models may identify producers who are likely to disengage before production declines become visible. They could flag onboarding delays that historically lead to lower first-year performance or detect compliance trends that indicate elevated regulatory risk before violations occur.

There will be a shift from responding to problems after they've affected revenue or operations, to intervening proactively before major harm is done.

Insurance has never lacked distribution data. Historically, it has lacked access to organized data and is now missing the ability to transform that information into strategic insight.

The organizations that gain the greatest competitive edge over the next few years won't simply automate more workflows and organize their back-office processes. They'll use distribution intelligence to make smarter recruiting decisions, strengthen agency relationships, optimize geographic expansion, and anticipate future risks before they materialize.

Distribution data isn't an administrative byproduct, but a strategic asset organizations can use to inform better decisions across every stage of the producer lifecycle.

The future of distribution isn't just better management; it's better intelligence.


Ido Deutsch

Profile picture for user IdoDeutsch

Ido Deutsch

Ido Deutsch is chief revenue officer at Producerflow, which modernizes and streamlines producer onboarding and licensing.

While studying for his MBA at UC-Berkeley, he teamed up with Luis Pino to build Agentero and led go-to-market functions. Deutsch built Producerflow from within Agentero, and it became its own startup in 2025.

 

Navigating Regulatory Plurality in African Insurance

African insurance programs fail not from regulatory complexity but from uncoordinated regimes governing the same risk simultaneously.

Navigating Regulatory Plurality in African Insurance Markets

From our experience, the insurance supervisor is rarely the authority that creates the greatest constraint for a program entering African markets. The insurance code is often the clear part. The difficulty tends to arrive later, when foreign exchange restrictions hold up a remittance, or when a local content obligation surfaces from legislation that was never drafted with insurance in mind, or when a sector regulator turns out to require cover that nobody priced into the program. Each requirement is manageable on its own. What catches people out is that they all bear on the same program at once, and rarely announce themselves at the same time.

This is what gets lost when the market simply calls Africa complex. The word is not wrong, but it points the wrong way. Complexity suggests disorder, and disorder counsels caution, whereas what these situations show is something with structure, several distinct regulatory regimes, each identifiable, each governing the same program in parallel. We would call it regulatory plurality, and the distinction matters because a structure can be coordinated where disorder can only be feared. It is a narrower idea than legal pluralism or multi-level governance, which describe coexisting sources of authority in the abstract. The concern here is operational, the way several regimes bind one program and collide at the point of design.

The risk, then, never sits inside a single regime. The difficulty is in the points where they meet. Any single regime, taken alone, is manageable, and the response that works is coordination begun at the design stage, before placement forces the question.

Africa has 54 sovereign jurisdictions, each with its own legislation, supervisor, and administrative practice. The variation is genuine, but it is the wrong place to locate the difficulty. The number of jurisdictions is not what makes these programs hard to run.

Regional harmonization has already reduced the fragmentation, though it has done so unevenly, in blocs and not across the whole. The clearest case is the CIMA zone, the Conférence Interafricaine des Marchés d'Assurances, which aligns prudential standards across 14 mainly Francophone countries in West and Central Africa under a common insurance code. Practitioners outside the Francophone tradition routinely underestimate that coherence. But CIMA is one family among several, sitting alongside the Maghreb codes, the Anglophone common-law markets, the Lusophone systems, and Francophone states such as the DRC that keep their own regulator outside CIMA entirely, so that even a shared language guarantees nothing about a shared framework. And within CIMA the harmonization reaches only so far, because each member state keeps its own legislator, layering national rules on top of the common code. Some states mandate local brokerage outright, some permit co-brokerage with a foreign business introducer, others restrict it to a strict framework, so that a placement structure lawful in one member state can be constrained in its neighbor under the same code and the same currency.

We have seen this variance directly on a pan-CIMA industrial and logistics program we coordinate, where the placement architecture had to be adjusted country by country even though every entity sat under the same insurance code. Cameroon, Gabon, Congo and Chad did not accept the same co-brokerage structure, and a wording accepted by one national supervisor drew a query from the next. Harmonization at the prudential level, in other words, does not settle the level at which the business is actually placed.

What this points to is that the regulation bearing on a program is never a single body of rules. It is several regimes layered over one another, each developed on its own track, and the friction is almost always in how they overlap. The division that matters is by source. One regime comes from insurance law itself. The others come from everywhere else and bind the program regardless.

The insurance-internal regime is supervisory regulation. This is the one body of rules that comes from insurance law and the insurance regulator. It covers licensing, admitted insurer obligations, local retention rules, policy wording control, and the prudential standards governing whether a carrier is financially sound. It is the layer international practitioners know best and the one that dominates compliance discussions. Local admitted requirements set how the program has to be built, determining which risks the master policy can carry, which have to be placed locally, and on what terms. The code can even dictate timing, setting the window in which a premium must be paid for cover to hold. Getting this regime right makes the program legal but not yet workable, because four further regimes sit outside insurance law and bind it all the same.

The first of those external regimes is financial system regulation. Foreign exchange controls, banking settlement constraints, and capital repatriation rules govern how money crosses borders. The industry tends to treat this as a banking matter when it is squarely an insurance one, and the misclassification proves expensive. Premium remittances, claims settlements, and intra-group reinsurance flows all run through these rules, and their application turns on a jurisdiction's current account position and monetary stance. The friction wears more than one face. Sometimes it is a conversion and valuation mismatch that stalls a local invoice against its master premium, sometimes a settlement delayed for months while a repatriation queue clears, and sometimes the opposite problem of a dollarized market where the local currency barely figures. A program can clear every supervisory test and still stall because the money will not move cleanly.

The next two often arrive together, which is why they are easy to confuse, but they are worth keeping apart. The first is local content regulation. Here a distinction has to be drawn that is easy to lose. Most markets already require a share of the risk to be retained domestically, but in the CIMA zone and other code-based systems that retention is a function of the insurance code itself, part of the supervisory regime already described. Local content regulation proper is something narrower and more concentrated, standalone legislation, outside the insurance code and answering to its own authority, that conditions operation in a strategic sector on the use of domestic goods, services, and professional capacity. It clusters in particular jurisdictions and does not spread evenly across the continent, with the resource economies furthest along, and for insurance it can mean placement requirements, mandatory use of local brokers, and limits on cession to non-resident reinsurers that sit above whatever the code already demands. The trap is precise. A program can satisfy every retention rule in the insurance code and still breach a local content act that sets a higher bar, because the two are different instruments answering to different authorities, and only one of them is visible from inside insurance law.

This regime also shows up outside insurance legislation altogether, in the administrative platforms several states have built to control imported cover directly. Single-window import systems such as GUCE, GUOT, ORBUS or SEGUCE, run from the trade or customs side and not by the insurance regulator, condition the clearance of imported goods on proof of local insurance placement or local broker representation. A program can be entirely compliant with its insurance code and still be held up at the border because the cargo cover behind the shipment was not structured to satisfy the platform. It is local content regulation in its most literal form, enforced by an authority that has never read the insurance code at all.

The second is sector-specific regulation. The distinction matters because local content law governs who carries the risk, while sector law governs what has to be covered at all. Extractive industries, energy, telecommunications, and public infrastructure run under their own legislative frameworks, which often make insurance compulsory or set minimum coverage standards as a condition of licensing, and these obligations come from mining codes, petroleum legislation, construction law, and procurement rules, all of them outside insurance law. The clearest example is not exotic at all. In most Francophone markets construction carries a compulsory 10-year structural liability, the décennale, imposed by law and entirely outside the insurance code, which a program built only to the code will simply miss. Elsewhere the sector rule and a local content rule travel in the same statute, a petroleum act carrying both a compulsory cover requirement and a domestic retention share, which is exactly why a reader who treats the two as one will miss whichever obligation they were not looking for.

The last external regime is the fiscal and tax framework. Premium taxes, parafiscal charges, stamp duties, and withholding taxes on cross-border reinsurance flows vary widely and bear directly on a program's economics. In some markets the fiscal load is heavy enough to redraw structural decisions, shifting the balance between local placement and international reinsurance, or the choice between admitted and non-admitted coverage. It belongs to the jurisdiction's wider fiscal architecture, a separate body from insurance law, and it tends to surface at settlement, once the design is already fixed.

Each of these regimes is manageable on its own. The exposure comes from each answering to a different authority, resting on a different legal instrument, and following a different institutional logic, so that when separate teams or advisers handle them as separate compliance exercises, no one owns the interactions between them, and they show up only when they cause a problem.

One program we have coordinated shows how the regimes arrive in sequence, each one only visible once the last has been dealt with. A mining risk is placed globally and fronted into a producing economy, every admitted requirement met under the insurance code. The code sets the first constraint. The risk has to be carried locally and cannot simply be fronted from abroad, so a substantial share, here about half, is retained by domestic carriers, and the master placement has to be broken back down into local policies. That much is foreseeable. Less foreseeable is a second retention the code never mentions. The petroleum and mining legislation sitting above the program sets its own local content floor, higher than the code's, answering to a different authority, and satisfying the insurance regulator does nothing to satisfy it. Raising local retention to meet it is straightforward on paper. In practice the local carrier prices the retained premium in local currency, and the figure bears little relation to the master premium once conversion and local ceding charges are applied, so settlement stalls while the two are reconciled. The brokerage on the retained share, and the parafiscal and withholding charges attaching to the cross-border portion, then have to be rebuilt separately, because the master pricing never carried them. No single rule here is obscure. The retention sits partly in the insurance code and partly in the sector legislation above it, the currency friction in the exchange regime, the charges in the fiscal framework, each answering to a different authority, and the trouble is only ever visible when they are read together.

The same program makes a further point once a loss occurs, because the regimes do not rest at placement. They return at settlement, and more sharply, with a client waiting to be paid. On a major fire claim of ours in the region the coverage position was never in question, clear on the wording; the difficulty was everything that followed it, the currency conversion on the indemnity, the local insurer's own reinsurance recoveries, and the pace at which funds could actually reach the client. A coordinator who has planned only for the placement stage meets the same frictions again, later and under more pressure. A loss does not suspend the regimes that shaped the program. It tests them.

Compliance, then, has to be judged at the level of the whole system, and coordination is what that demands. The expertise to handle each regime alone generally exists. What no one owns is managing the points where they touch, from the design stage onward.

In concrete terms, the master policy architecture must be aligned with local admitted requirements before coverage terms are fixed, and foreign exchange constraints mapped against premium flows before pricing is agreed. Local content thresholds need checking against both the insurance code and any standalone act, including the administrative platforms that enforce it outside insurance law entirely. The coordinator has to identify sector-specific obligations at inception, before placement begins. And the fiscal cost of cross-border flows has to be built into the commercial logic from the outset. None of this is sequential. All of it must be held in view at once, and again at claims stage, because a loss does not suspend the regimes that shaped the program, it tests them.

Front-loading integration is a familiar principle in program management, but what distinguishes the African insurance case is that the regimes were built separately, are administered by separate bodies, and were never reconciled with one another in the drafting. Reconciling them falls to the program coordinator, and it has to be done ahead of placement, and revisited at every claim that follows.

The environment has structure. Calling it disordered is the mistake, because it is a set of overlapping regimes each governed by its own logic. Reading it as one insurance regime and four that bind from outside, financial system, local content, sector-specific, and fiscal, makes operating across 54 jurisdictions no easier, but it gives the difficulty a shape and locates the work where it belongs, in coordinating the regimes the legislation itself leaves uncoordinated.

That work falls to whoever holds the whole program, the international coordinator on one account, the client director on another, the program lead on a third. The title varies, the function does not. It means holding all five regimes in view at once and reconciling them before a single policy is placed, and again at every point a claim moves money across a border. It is demanding, but it is not disorder, and that is the point worth ending on. These markets are not the chaotic environment the word complex quietly implies. They are navigable, provided the regulation is read for the layered structure it actually has, and provided the program is built by people who can hold that structure together, the operations specialists whose competence is exactly this, as distinct from the brokers who place the risk and the underwriters who price it. The market has begun to seek them out. What these markets reward is the judgment to treat complexity as structure, and to rely on the expertise that can navigate it.


Arthur Michelino

Profile picture for user ArthurMichelino

Arthur Michelino

Arthur Michelino is head of international coordination at OLEA Insurance Solutions Africa.

Michelino previously worked at Diot-Siaci as an international coordinator for key accounts. He began his career at Willis Towers Watson (formerly Gras Savoye), implementing international programs for the mid-market segment.

It's a Wired, Wired, Wired, Wired World

As sensors have demonstrated during the World Cup, the globe is becoming so wired that it's possible to spot earthquakes, wildfires, and floods in time to mitigate harm.

Image
Early Warning

When Norway won games during the World Cup, so many people jumped up and down that earthquake sensors picked up tremors in Oslo. The same was true when Mexico won games; tremors were detected in Guadalajara and other parts of the country. 

That's some impressive fan support. Vamonos, Mexico! Dra til, Norge!

But detecting the tremors also required some very impressive sensors — of the sort that can help insurers increasingly head off injuries and property damage from earthquakes, wildfires, and floods by giving people advance notice of the impending trouble.

Let's have a look. 

Earthquake sensors are top of mind for me because of the devastating quakes in Venezuela and because of the 5.6-magnitude quake in late June that shook parts of Northern California where I lived until recently. 

Sensors in Google phones managed to alert more than 11.4 million people in Venezuela that a major earthquake was coming, at least several seconds before they felt the impact, according to the New York Times, and as much as two minutes ahead of time. It's not clear how many lives were saved and injuries prevented — and the losses were devastating, with nearly 4,500 deaths confirmed from the 7.2- and 7.5-magnitude earthquakes — but many people surely managed to protect themselves by quickly taking cover. 

What Google is doing is intriguing, and potentially a model for other alert systems. Google has turned all its phones into sensors that take advantage of the fact that earthquakes create two types of waves, as part of a system that is available in nearly 100 countries. One type (P-waves) travels very fast but does little damage. The other (S-waves) does the vast majority of the damage but travels significantly more slowly. Google's phones detect the fast-arriving P-waves as they travel through the ground, and, when Google sees all phones in an area lighting up at once, it knows S-waves and rumbling are coming. 

It's rather like thunder and lightning. Google's phones see the lightning and can tell people that thunder is coming. (The obvious difference being that, in the case of earthquakes, the damage comes after the alert, while lightning is both the alert and the cause of damage.)

The systems don't necessarily provide a lot of warning. P-waves travel at 5-6km/sec, while S-waves spread at 3-4km/sec. So you'd need to be perhaps 20 miles away from the epicenter to get five seconds of warning. People will need to be educated about what to do with those five seconds (drop, cover and hold on) and become accustomed to the idea of alerts, so they don't freeze when the warnings arrive. 

But the sensor network could still get a lot of people away from whatever might fall on them, even with little advance notice, and prevent other damage, too. A woman I know was on an on-ramp for I80 in Berkeley when the Loma Prieta earthquake hit Northern California in 1989. The on-ramp collapsed, dropping her 30 feet onto a pile of rubble. The collapse not only totaled her car, of course, but had her in and out of surgery for years, and left her traumatized from knowing how many people were crushed beneath her. With just five seconds notice, she would have been able to pull off the road and stop short of the elevated roadway. 

In the recent California quake, the governor's office bragged that the state's new early warning system had alerted more than 1 million residents before the shaking started in their area, drawing on feeds from some 600 sensors installed around the state. The system is also available in Oregon and Washington, and Apple offers a similar sort of alert system, drawing on sensors that others have installed.

Insurers don't have a role to play in the development of networks like Google's and don't have to help with the sort of deployment of hard-wired sensors like those in California, but they can certainly assist with the education. Those that do will not only reduce injury claims but will earn good citizen points. At a time when insurers are looking for ways to engage with policyholders more often — not just when collecting premiums or paying claims — offering education about how to protect yourself seems like a promising avenue.

Sensors that can detect wildfires before they get out of control are likewise becoming far more sophisticated and are being deployed on the ground, in the air, and in satellites. Personally, I'm most intrigued by what's happening with satellites, both because they can cover nearly unlimited territory, almost minute by minute, and because I believe in having others do as much work for me as possible. 

Google doesn't sell its phones on the basis that they'll detect earthquakes. People buy the phones for the obvious reasons, then Google adds a bit of software, et voila! A detection network is suddenly deployed. I think the same potential is there to add wildfire detection capabilities to the thousands of low-earth satellites that Elon Musk and others are deploying to facilitate communications. Let them pay for the expensive hardware and the launch, then add a camera and other forms of sensors that can look down and spot even small fires.

Floods, thus far, require dedicated networks of sensors, but there's progress there, too, as Houston is showing. Cities are installing small, inexpensive sensors that monitor water levels constantly, which usually providing hours of warning about developing floods. Cities can also warn motorists in real time to avoid underpasses where water has collected. 

Because these networks of sensors can't just be piggybacked onto other hardware, progress can be slow — adoption remains spotty, for instance, in Central Texas even in the wake of the disastrous flood a year ago that killed 130 people, including 25 young girls and two counselors at a summer camp. But the technology is there and will continue to make inroads.

A rule of thumb I developed some years ago now, as part of what I call the Laws of Zero, is that you can assume that any bit of information you want will be available to you at what looks like zero cost (compared with today) if you look down the road a ways. 

The concept is me looking for areas outside computer chips where the magic of Moore's law can apply. Moore's law — essentially, that the power of a computer processor doubles every year and a half to two years at no increase in cost — means that a unit of computing power that cost a dollar in 2000 costs roughly 1/600th of a penny today. So, free (almost) for anyone making long-range plans in 2000.

I won't go into all seven of the areas I identified, but it's pretty easy to see how sensors fit the Laws of Zero pattern. Moore's law will drive the cost of the computing and any memory toward zero. WiFi and satellite connectivity are becoming ubiquitous, so there's no marginal communication cost. Batteries are also plunging in cost, and many sensors won't even need them, either because they can use solar power (whose cost is heading toward zero) or because they're built into bigger systems such as Google phones or Starlink satellites. 

The Law of Zero about sensors means we will keep seeing progress. Insurers won't even have to pay for that progress. They can just piggyback on what others are doing, then help policyholders understand how to take advantage of the progress — reducing claims while earning good will.

In the meantime, if you aren't watching the France-Spain World Cup semifinal this afternoon, or at least sneaking the occasional peak while at work, I'll bet you'll be able to tell the result if you have access to seismograph readings from Paris and Madrid at 5pm or so Eastern time. 

Cheers,

Paul

 

 

A Founder's Guide to Surviving Investor Rejection

At 66, a cybersecurity veteran trades retirement planning for startup building and learns that success doesn't depend on yeses; it requires "not no"'s. 

Walking a high wire

One of my favorite movie scenes comes from "Volunteers."

Tom Hanks is trying to negotiate with a local warlord. Standing nearby is the warlord's beautiful bodyguard—whose command of English is somewhere between nonexistent and interpretive dance. Tom flashes a grin that suggests he'd be perfectly happy if she happened to be part of the bargain.

The warlord responds with something to the effect of, "If I say yes… and not no…"

I honestly don't remember exactly how the scene ended. What I remember is what popped into my own head.

I'd settle for not no.

At the time, it was just a funny line. Thirty years later, after more investor meetings than I care to count, I finally understand why it stuck with me.

Founders spend years chasing "yes." Investors rarely give you one. Instead they say…

"Interesting."

"Come back after revenue."

"Let's reconnect in six months."

"We'd like to see your next release."

"Keep us posted."

None of those are yes.

But they aren't no.

If you're building a company, you eventually realize that companies aren't built on yes.

They're built on not no.

The High Wire

Being a founder is the proverbial high-wire act. There's no safety net. No guarantee. No instruction manual.

People love talking about entrepreneurial risk. Let me save you some time. It's all risky.

The right decisions.

The wrong decisions.

The crazy decisions.

Sometimes you don't know which one you made until two years later.

Then there are the mornings.

3 a.m.

Every.

Single.

Morning.

Not because the alarm went off. Because your brain did.

There's always one more investor to research.

One more slide to improve.

One more grant proposal to edit.

One more feature to design.

One more email to send before the day job begins.

People think founders work 80-hour weeks. The truth is… founders never really stop working. The company follows you to bed. It wakes up before you do.

And then there's that feeling. If you've ever built a company, you know exactly what I'm talking about. That knot in the pit of your stomach. It never completely goes away. It's there when you wake up. It's there during investor meetings. It's there while you're brushing your teeth. It whispers the same questions over and over.

What did I forget?

Are we going to make it?

Am I asking my family to believe in something impossible?

Is this the dumbest thing I've ever done… or the smartest?

I've come to think of it as the founder's tax. Nobody talks about it. Everybody pays it. Some people call it stress.

Founders call it Tuesday.

Venture Capitalists and Sea Turtles

One of my favorite startup metaphors comes from Silicon Valley.

Ron LaFlamme, the eccentric attorney, explains venture capital using sea turtles. Sea turtles lay hundreds of eggs because only one or two eventually make it to the ocean.

"That's what Peter Gregory is doing," Ron explains. "Making sure one or two of his compression plays make it to the sea."

The first time I heard that I remember thinking,

"Why not just pick stronger turtles?"

Of course, that's not how venture capital works. They're playing portfolio math. Fund enough companies and one eventually becomes the next Google.

They're not looking for certainty. They're looking for outliers.

Founders don't have that luxury.

Most of us get one turtle.

One company.

One dream.

One shot.

It's amazing how differently you look at risk when you're carrying your only turtle.

Government Grants: The Ultramarathon

If raising venture capital is a marathon… government grants are an ultramarathon.

Uphill.

Into the wind.

Dragging a filing cabinet behind you.

You spend six weeks writing.

Three weeks editing.

Two weeks wondering whether Requirement 3.2.17(b) means exactly what you think it means.

You finally hit "Submit."

Then… absolutely nothing.

Weeks become months.

Months become more months.

Eventually an email arrives.

Your pulse quickens.

Your palms get sweaty.

You open it.

"Thank you for your interest…"

That's government-speak for, "Better luck next time."

The amazing part?

You immediately start writing the next proposal.

Founders are funny that way.

The government didn't invent persistence.

Entrepreneurs did.

Accelerators

I actually like accelerators.

Some of them.

Many provide genuine value.

They introduce founders to investors.

They surround you with experienced entrepreneurs.

They shorten the learning curve.

Some absolutely earn the equity they receive.

Others…

Well…

Let's just say the first image that came to my mind was a skinny kid explaining proper deadlifting technique to a professional bodybuilder.

It made me laugh.

Mostly because I've been there.

Now before anyone gets offended…

No, I don't know everything.

Far from it.

But this ain't Marine Corps boot camp.

I don't need somebody teaching me how to polish my boots. I've spent decades leading soldiers, briefing executives, running cybersecurity organizations, and solving difficult problems. Teach me something I don't know. Introduce me to someone I couldn't otherwise meet. Open a door that's been closed. Challenge my assumptions.

That's acceleration.

Teaching me how to center a title on a PowerPoint slide? Not so much.

Now, to be fair, accelerators usually introduce you to investors. Of course, they don't do it out of the goodness of their hearts. They generally take a slice of your company.

Sometimes it's a reasonable slice.

Sometimes…

It's a fat butcher's slice.

Every founder has to answer the same question.

Was it worth it?

If the answer is yes… great.

If not… that was one expensive PowerPoint lesson.

The Founder's Retirement Plan

Somewhere along this journey I stopped looking at my investment portfolio as retirement.

I see software development.

Advertising.

Patent attorneys.

Trade shows.

Cloud hosting.

Developers.

My financial advisor sees diversification.

I see operating capital.

Retirement?

I'll think about retirement after Version 5.0 ships.

Every now and then I tell Suzanne we're flying first class to the Maldives for a week of scuba diving.

Just as soon as…

well…

just as soon as we can afford a margarita machine.

Fans of "Silicon Valley" will appreciate that reference.

Everyone else probably thinks I've developed an unhealthy obsession with frozen drinks.

They're not entirely wrong.

The funny thing about founders is that we stop measuring wealth the way everyone else does.

A new car?

That's six months of development.

Kitchen remodel?

Marketing budget.

Vacation?

Another developer.

People ask how founders keep funding their companies.

Simple.

We stop thinking about assets.

We start thinking about runway.

Yin and Yang

People ask what it's like to build a company with my wife. The answer usually surprises them. We work remarkably well together.

Mostly because we work remarkably well apart.

Ron LaFlamme would probably describe us as yin and yang.

That's us.

I'm the dreamer.

Suzanne is the realist.

I see possibilities.

She sees details.

I chase ideas.

She quietly points out the 17 reasons one of them probably won't work.

She's usually right.

Long before software, we bought a short-term rental.

The number one comment from our guests wasn't the location.

It wasn't the view.

It wasn't the amenities.

It was one word.

"Immaculate."

That's Suzanne.

If NASA hired her, astronauts would dust the launch pad before liftoff.

She has standards that make hotel inspectors nervous.

Thank goodness.

Somebody has to.

Every founder needs someone willing to ask,

"Are you sure?"

Not because they doubt the dream.

Because they want the dream to survive.

People celebrate founders.

They should spend more time celebrating the people who quietly make founders better.

The Turtle on the Fence Post

There's an old saying: "If you see a turtle on a fence post, you know it didn't get there by itself."

How he got up there is anybody's guess.

Yes…

I'm mixing metaphors.

It's my article.

Besides, if you've ever started a company, you know reality stopped making sense a long time ago.

You stop measuring life normally.

Your retirement account becomes software development.

Vacation becomes cloud hosting.

Credit cards become temporary venture capital.

Your dog starts recognizing the Amazon delivery driver by first name.

Normal people call this insanity.

Founders call it product-market fit.

The truth is, nobody builds a company alone.

Somebody always believed.

Somebody always introduced you to someone.

Somebody always opened a door.

And if you're lucky enough to succeed… maybe someday you'll become the person holding the door open for the next founder trying to get through.

That's a legacy, too.

Why 66?

People may someday ask me a simple question.

"Why did it take until you were 66?"

It's a fair question.

The funny thing is…

I don't think I waited until I was 66 to become a founder.

I think I spent 40 years accidentally preparing to become one.

The Army taught me leadership.

It also taught me that no plan survives first contact.

Corporate America taught me patience.

Cybersecurity taught me skepticism.

Attackers adapt.

Technology changes.

Certainty is usually an illusion.

Marriage taught me partnership.

Investors taught me persistence.

Government grants taught me humility.

And rejection…

Rejection taught me that success usually belongs to the person willing to hear "no" one more time than everyone else.

Looking back, every assignment, every promotion, every setback, every impossible deadline, every deployment, every conference room, every board presentation, every sleepless night somehow led here.

Maybe the company wasn't waiting for me.

Maybe I was waiting to become the person capable of building the company.

The Founder Nobody Sees

People see the pitch.

They see the product.

They see the trade show booth.

They see the LinkedIn announcement.

What they don't see… is the founder sitting at the kitchen table at 3 a.m. trying to get two hours of work done before heading to the day job.

They don't see weekends disappear.

They don't see vacations turn into strategy sessions.

They don't see the credit card bill arrive.

They don't see another investor politely explaining why your company isn't quite ready.

They don't see the quiet conversations between spouses.

"Can we keep doing this?"

"How much longer?"

"Are we crazy?"

The answer, by the way… is yes.

Founders are a little crazy.

Thankfully.

If they weren't, most companies would never exist.

Looking Forward Instead of Backward

At 66, something changes.

You stop asking,

"How much money can I make?"

You start asking,

"What am I going to leave behind?"

Money is nice.

Don't misunderstand me.

I'd love to stop looking at every block of stock in my retirement account as another software release or another attorney.

I'd love to finally buy that margarita machine.

I'd really love to take Suzanne to the Maldives and spend a week underwater instead of under deadlines.

But that's not why I'm doing this.

If our company succeeds, I hope my legacy isn't the software.

I hope it isn't the patent.

I hope it isn't the valuation.

I hope it's the organization that never became tomorrow's headline because somebody finally started looking through the windshield instead of the rearview mirror.

For decades, cybersecurity has become remarkably good at explaining yesterday.

Yesterday's ransomware.

Yesterday's phishing campaign.

Yesterday's breach.

Yesterday's lessons learned.

Those things matter.

But they're history.

I've always believed we could do more.

What if we could help organizations think about tomorrow?

Not with certainty.

Not with magic.

Not with a crystal ball.

Just disciplined analysis.

Patterns.

Trends.

Probabilities.

Enough information to make one better decision before the next attack arrives.

If we accomplish that… then every sleepless night was worth it.

Every rejection.

Every investor meeting.

Every government grant proposal.

Every conference.

Every dollar we invested instead of spending on ourselves.

Worth it.

The Last Word

The funny thing about entrepreneurship is that people think the story ends when an investor finally says yes.

It doesn't.

That's just the next chapter.

The real story is everything that happened before anyone believed.

The three o'clock mornings.

The knot in your stomach.

The day job that funded the dream.

The spouse who quietly kept believing.

The people who opened doors.

The investors who didn't say yes… but thankfully didn't say no, either.

Today we're still building.

Still pitching.

Still applying.

Still hearing,

"Come back later."

We're still looking at retirement accounts and seeing software development.

We're still laughing about margarita machines.

We're still dreaming about the Maldives.

We're still walking the high wire.

And after all these years…

I'd still settle for…

not no.

Because every once in a while…

"not no" becomes "yes."

Epilogue

Or maybe just the quiet refusal to quit.

Every founder needs something that carries them through the investor meetings, the rejection emails, the three o'clock mornings, and that knot in the pit of the stomach that never quite goes away.

Keep walking.

Keep building.

Keep believing.

Because every once in a while…

one little turtle actually makes it to the sea.

I'm fortunate.

When I need a reminder to keep going, I don't have to look very far.


Timothy O'Neil

Profile picture for user TimothyO'Neil

Timothy O'Neil

Timothy S. O’Neil, CISSP, CEH, is president and founder of AigisPoint Predictive Intelligence

A retired U.S. Army lieutenant colonel with more than 25 years of cybersecurity leadership experience, he has held senior security architecture and information security leadership roles across the healthcare, insurance, telecommunications, and consulting industries. He is the developer of the Strategic Predictive Threat Intelligence (SPTI) platform, designed to help organizations and cyber insurers anticipate emerging cyber threats before they become losses. 

The Unknowns of Enterprise AI Deployment

Property & casualty insurers face systemic unknowns when scaling AI beyond pilots into regulated workflows like underwriting, claims and pricing.

Deployment

Property & casualty insurers are moving fast from narrow machine learning pilots to enterprise-scale deployments that blend predictive models, generative AI, and agentic workflow automation. The hardest barriers to this transition are not primarily technical. They are the unknowns: the uncertain, interdependent, and often non-obvious failure modes that surface when AI systems get embedded in regulated, long-tailed, and economically sensitive insurance processes like underwriting, pricing, claims, reserving, and reinsurance.

Insurance executives must shift from model-centric thinking to system-centric thinking. Strong data and model controls are necessary but not sufficient. Without secure integration patterns, operational monitoring, model risk discipline, and clear accountability, even a high-performing model will struggle to become a safe, compliant, and profitable production system. Enterprise AI risk is not merely model risk. It is systemic risk arising from the coupling of data, models, workflows, humans, vendors, and core platforms.

Why P&C is a special environment

P&C is uniquely difficult territory for enterprise AI. The product is a promise made under uncertainty, and the balance sheet carries long-tail obligations, so decisions made or supported by AI can influence loss emergence years later through selection effects, reserving assumptions, and litigation pathways. This drives an unusually high cost of model error and governance failure. Several structural features amplify the unknowns: exposure to catastrophe clustering and tail events, rapid changes in external cost drivers like repair and medical inflation, the potential for proxy discrimination through correlated variables, complex multi-party ecosystems spanning brokers, MGAs, TPAs, and repair networks, and the fragmented reality of U.S. state-based regulation.

A taxonomy of unknowns

The key is a structured taxonomy that classifies the unknowns into eight categories, each with concrete P&C examples and matching guardrails. These span data unknowns (coverage gaps, inconsistent cause-of-loss codes, third-party data drift), model behavior unknowns (overfitting to recent inflation, LLM hallucination, proxy discrimination), system integration unknowns (automation triggering payments without adequate checks, silent integration failures), operational unknowns (drift during catastrophe season, retraining backlogs), security unknowns (prompt injection, data exfiltration, model theft), regulatory unknowns (varied state DOI expectations, market conduct exam demands), economic unknowns (unclear ROI, behavioral feedback loops, non-linear computing costs), and human and organizational unknowns (overreliance on models, adjuster workarounds, incentive misalignment). This taxonomy works both as an executive checklist for risk identification and as a technical planning artifact for control design.

Two unknowns receive special emphasis. The first is the feedback loop problem: when AI is used to price, select, investigate, or settle, it changes the composition of the book and the behavior of insureds and internal teams, which in turn alters the future data the AI is trained on. A model may appear to improve loss ratio in the short term while quietly increasing adverse selection, litigation frequency, or churn over longer horizons. The second is the tail and regime shift problem: since P&C risk is dominated by tails, models trained in routine years can fail under catastrophe clustering or new social inflation regimes, and validation that optimizes average error will systematically miss tail risk.

Mapping unknowns to governance frameworks

Rather than inventing a new compliance regime, the unknowns should be mapped onto established frameworks to create a shared language across technology, business, and regulators. The NIST AI Risk Management Framework serves as the backbone, with its four functions of Govern, Map, Measure, and Manage. This is complemented by the NAIC's 2020 AI Principles and its December 2023 Model Bulletin on the Use of AI Systems by Insurers, which set regulatory expectations for governance, documentation, and oversight, including for vendor-acquired systems, and stress compliance with existing unfair trade practice and unfair discrimination laws. Also important are NIST CSF 2.0 and the NIST Privacy Framework for cyber and privacy integration, the NAIC Insurance Data Security Model Law for data security standards, and SR 11-7 / SR 26-2 model risk management discipline adapted from banking. The Colorado AI Act also offers guidance on what the future of AI regulation in the industry looks like.

A control mapping table connects specific unknowns to control objectives, framework hooks, and evidence artifacts, and the highest-leverage leadership move is treating evidence as a product: every AI system should ship with documentation, test results, monitoring plans, and audit-ready logs.

Reference architecture and generative AI patterns

A six-layer reference architecture is needed for the heterogeneous, hybrid environments that carriers actually run: business process and orchestration, AI application, model, data and feature, platform and operations, and a cross-cutting security, privacy, and governance layer. MLOps must be treated as first-class production engineering rather than project-based delivery, because the true cost of AI is dominated by post-deployment work like monitoring, incident response, recalibration, and security patching. The main generative AI patterns in production insurance settings are: retrieval-augmented generation grounded in policy forms and claims manuals, constrained tool use, targeted fine-tuning, and agentic workflows with supervisory layers and circuit breakers for financial actions. Security by design extends existing controls while adding AI-specific safeguards drawn from OWASP's LLM vulnerability taxonomy and MITRE ATLAS.

Tiered guardrails and continuous assurance

A key insight is that not all use cases warrant the same governance intensity. A three-tier model based on decision impact is needed. Tier 1 (informational: search, summarization, document classification) allows advisory-only outputs with basic guardrails. Tier 2 (decision support: underwriting triage, pricing indications, claims severity and fraud scores) requires segmented validation, explainability, fairness tests, and human-in-the-loop review. Tier 3 (acting and automation: auto-routing claims, automated payments within limits) demands dual control for payments, transaction limits, rollback, and continuing monitoring. This tiering supports proportional governance without over-controlling low-risk productivity use cases. 

On measurement, there should be a shift from one-time validation to continuous assurance, combining pre-deployment testing (data readiness, model validation, fairness and security tests, documentation), post-deployment monitoring across technical, business, compliance, and security signals, AI-specific incident management, and exam readiness.

Operating model, roadmap, and research agenda

Deployments fail when accountability is unclear, and it challenges a common myth: that accountability for all AI initiatives should sit with the CTO, CIO, CDAO, or CAIO. This contradicts basic operational risk principles, and accountability should instead be defined by roles, responsibilities, and use case within functional areas. What is needed is a governance structure (an AI Steering Committee, an AI Risk and Controls Council, product owners with a value realization office, and an independent validation function) and a detailed table of CXO responsibilities and the specific unknowns each leader must own.

Avoid the trap of scaling models before scaling controls, and instead sequence the work: baselines in the first 90 days, enterprise repeatability at three to six months, and institutionalization at six to 18 months, including alignment to ISO/IEC 42001 and 27001. Set a research agenda covering causality and feedback loops, fairness under distribution shift, tail-risk stress testing, generative AI assurance, AI security metrics, and standardized evidence for regulators. Practical appendices provide an executive checklist mapped to NIST AI RMF, a model card outline, AI risk register fields, and an incident response playbook.

To read the full paper this article is drawn from, click HERE.


Kushal Shah

Profile picture for user KushalShah

Kushal Shah

Kushal M. Shah has 25 years of experience in insurance industry.

He is the author of "The Unknowns of Enterprise AI in Regulated Sectors" and innovator of patent-pending aiV-Cube framework for AI risk assessment and underwriting. 

He holds active producer and adjuster licenses across multiple states and has completed the Associate in Claims from The Institutes. He is currently a candidate for Associate in Insurance AI (AIAI).