Download

Can Insurers Break Free From the POC Trap?

Insurers struggle to scale AI beyond the proof-of-concept stage due to poor data management, not the technology itself.

Management Over AI

The insurance industry faces a key question: How can insurers successfully industrialize their AI initiatives?

Scaling AI requires a distinct approach relying on: compliance, security, and traceability. Not meeting these requirements prevents projects from moving beyond the early stages, especially when they lack clear governance, performance indicators and risk management.

AI itself is not the factor impeding or slowing down the crucial passage from POC to fully deployed projects. The real issue lies in the approach and environment in which AI initiatives are developed and industrialized. Projects are still approached from a very traditional perspective rather than as potential business use cases, overlooking the need to factor in elements such as IT infrastructures, operations and, crucially, data management.

In this case, the distinction lies in the way data is being managed. Organizations with poorly structured and scattered document silos struggle with the technological debt of outdated systems including legacy enterprise content management (ECM) platforms and archives. Data management makes a difference when it comes to successfully industrializing insurers' projects as well as being one of the main difficulties they can encounter.

Scaling up with strong decision making

To succeed, organizations must rely on clear strategies driven by high-value business use cases that show immediate and significant affect in areas that are key to the business, for example the automation of claims processing.

They should also increase the focus on modernizing the existing ECM platforms while refraining from launching a complete overhaul. As counterintuitive and challenging as it might sound, this balance is essential to success and can be achieved by intelligent information management and keeping up with the latest AI implementations.

Finally, they take into account challenges related to governance and compliance from the very beginning: data traceability, model explainability, and compliance with regulatory frameworks.

The key to success: a strong information foundation

What differentiates insurers that have successfully scaled their AI projects from others is the way they approached the issue: they started with data rather than starting with AI. Insurance is a document-driven industry; its value lies in leveraging its content: policies, claims files, contracts, correspondence, broker communications, loss reports, medical records, underwriting submissions, and regulatory documentation.

Some insurers are still dependent on legacy systems, traditional ECM/DMS platforms which are now showing their limits and slowing access to information. Their lack of flexibility, combined with the proliferation of repositories, make the use of information difficult.

To overcome these difficulties insurers must rely on technological solutions incorporating AI to automate the creation of a unified, structured, and accessible information environment. But in order to be truly impactful and bring long-lasting innovation, this can't simply be merely a new layer added on top of an existing system: what is really needed is a thorough modernization of native platforms, contextualized in real-time thanks to advanced AI tools.

Inspired industry leaders are those who know how to prioritize long-lasting sustainable industrialization over short-term and rapid changes. Integrating AI solutions is a starting point, but not the solution itself. The ideal conditions for large-scale deployment have to touch all assets of the business, from talent acquisition to fill the new skill gap to investing in research and development and, especially for a consumer-facing industry like insurance, transparency and the ability to explain the benefits stemming from the technology upgrades.

Organizations that can't align with this approach are likely bound to be left behind in the no man's land of unrealized POCs, while others successfully scale up projects and introduce innovations.

The Insurance M&A Deal Closed. Now the Work Begins.

Insurance M&A success depends less on closing the deal and more on preserving culture, supporting local leadership, and strengthening relationships post-acquisition.

After the deal

After working at just about every level of an insurance agency, you start to see M&A differently. I've been the person taking out the trash, the producer trying to win the account, the leader trying to make payroll, and now the CEO thinking about how to build something bigger without losing what made the business work in the first place.

It's easy to talk about acquisitions in financial terms. The numbers matter, of course – no one builds a successful brokerage on good intentions alone. But if you've ever sat in the producer's chair, serviced the client, worked through a tough renewal, or built a relationship with a carrier over many years, you know the numbers only tell part of the story. Sometimes, they're not even the most important part.

Insurance is a relationship business, and agencies aren't just books of business. They're local reputations, client histories, carrier relationships, producer instincts, service teams, personalities, and a few quirks that somehow become part of the culture. When an agency joins a larger organization, the transaction may close on paper within weeks or months – but the real work begins after that.

The deal isn't the finish line

One of the biggest mistakes in acquisition-driven growth is treating the close as the win. The legal documents are signed, the press release goes out, everyone shakes hands, then the team moves on to the next deal.

But for the people inside the agency, that's where the questions start.

Will my role change?

Will my clients feel the difference?

Will the culture change?

Will this still feel like the place I helped build?

Those questions are not a distraction from integration. They are integration.

If leaders don't address them, people will fill in the blanks themselves. And blank spaces rarely get filled with optimism – they get filled with rumors, assumptions, and hallway theories.

The best post-acquisition strategies are built around a simple idea: people aren't being absorbed. They're being supported, connected, and brought into something larger. That takes discipline. You have to listen before you start changing things, understand why the agency works, and learn what the team, clients, and local market already trust. Skip that work, and you can end up damaging what made the agency worth acquiring in the first place.

Preserve what makes the agency valuable

Successful independent agencies grow because they have something that works: a trusted team, a strong local brand, deep carrier relationships, a niche they understand better than most, a service model clients value, or a culture that makes people want to stay.

I'm a big believer that the riches are in the niches. In this industry, specialists matter. The best people usually have something they really know. It may be a coverage area, a region, a class of business, a client type, or a set of relationships that took years to build. A larger organization shouldn't flatten that – it should amplify it. The goal isn't to make every partner agency look, sound, and operate exactly the same. The goal is to understand what should be supported at scale and what needs to stay close to the client.

In many cases, the larger organization can take on back-office support, improve data and reporting, modernize tech stacks, expand market access, and reduce administrative burdens. This will give producers and service teams more room to do what they do best. But relationships, local market knowledge, client trust, and specialized expertise should be protected with intention.

Growth should make great agencies stronger, not generic.

Provide the clay to work with

You have to give your team the clay to work with. That means giving people the tools, resources, data, support, and freedom they need to shape something meaningful. It does not mean handing them a script and asking them to become someone else.

Insurance professionals are entrepreneurial by nature. Producers especially want to build, solve, connect, and win. Service teams want to take care of people and do right by the client. Local leaders want to protect the reputation they've built.

A larger brokerage can bring a lot to the table, but it has to show up as support, not control.

For example, better data shouldn't feel like someone is watching over your shoulder. It should help leaders make better decisions, help producers identify opportunities, help teams reduce manual work, and give the business a clearer view of what's working.

New systems, reporting, workflows, and processes can be valuable, but only if people understand the "why." If the only message is, "Here's the new way we do things," you'll lose people. If the message is, "Here's how this helps you serve clients, grow your book, and spend less time fighting the machine," you have a much better chance of earning buy-in.

Culture is built in the day-to-day

Every company says culture matters. Far fewer do the slow, practical work required to protect it during growth.

Culture isn't a set of values added to an onboarding deck. It's how people make decisions, solve problems, and treat each other when the work gets hard. It's how leaders communicate when the answer isn't clear. It's how wins are shared, how conflict gets handled, and whether employees feel respected after the transaction closes.

In insurance, culture shows up in very practical ways – affecting how producers collaborate, how teams respond under pressure, how leaders talk about clients, how quickly people adapt to change, and whether employees feel like they are part of the future, or simply along for the ride.

That's why communication after a deal can't be a one-time announcement.

People don't need every answer on day one. They know business is complicated. But they do need to know that leadership understands the questions. They need to hear what's changing, what's not changing, and why. And they need to see local leadership remain engaged.

Local leadership still matters

One of the smartest things a larger brokerage can do is listen to the leaders already inside the agency. They know the clients, the history, and the way work actually gets done. They can translate change to the team in a way that feels credible, because they've earned their trust. They can also identify when something looks good in theory but won't work in practice.

That feedback is gold, even when it's inconvenient.

A strong growth model doesn't silence local leadership. It gives those leaders better tools, more support, and a broader network while still respecting what they know.

This is especially important in today's market because insurance is becoming a war of capabilities. Agencies need more resources than ever: technology, data, analytics, specialty expertise, carrier access, compliance support, talent development, and operational infrastructure. But capabilities only matter if they actually help the people closest to the client.

Long-term value is built after the announcement

The insurance industry will continue to consolidate. There are too many structural reasons for it: succession planning, talent pressure, technology investment, carrier complexity, margin pressure, the need for scale. But long-term success won't come from acquiring the most agencies. It will come from helping the right agencies get stronger.

Growth happens when clients stay, producers keep producing, leaders keep leading, and teams believe they have more opportunity than they had before. It happens when the business becomes better, without forgetting what made it worth acquiring in the first place. That's the real work of insurance M&A.


Curtis Barton

Profile picture for user CurtisBarton

Curtis Barton

Curtis Barton is the founder and CEO of ALKEME Insurance, a full-service insurance agency.

Since its founding in 2020, ALKEME has completed over 80 acquisitions and serves its customers from more than 90 locations across 30 states. 

A Strategic Shift in Insurance Distribution

Insurance carriers are shifting from merely managing producer networks to leveraging distribution data for strategic competitive advantage.

Insurance Distribution Shifts from Management to Intelligence

After decades of inefficiencies, insurance carriers, MGAs, and agencies have finally begun to invest in their technology to modernize and improve distribution management. The goal is straightforward: automate producer onboarding, simplify licensing and appointments, maintain compliance, and process transactions more efficiently.

As the industry works to catch up with these investments, they've revealed a stark reality that most distribution systems were designed to execute processes rather than generate strategic intelligence. This distinction is significant because the next competitive advantage in insurance distribution won't come from simply managing producer networks more easily, though that is important; rather, advantage will come from understanding the networks more deeply.

Distribution data is the untapped goldmine in the insurance industry. The winners are already prospecting the land.

The Data Exists, You Need To Use It

Every interaction within a distribution management platform creates valuable information. Appointments, licensing timelines, agency affiliations, geographic distribution, product sales, producer tenure, renewal activity, and more data points are readily available to companies that use a centralized database.

Historically, this data has been stored to primarily support administrative functions. Once a transaction is complete, the information is saved but its strategic value goes untapped. If you ask a carrier how many appointed producers they have they can easily answer. However, if you were to ask them for more detailed insights the answers become much more difficult — or impossible — to produce.

Which newly appointed producers have generated the highest premium in their first 90 days? Which agencies consistently outperform peers in specific product lines? Where are producers successfully cross-selling multiple products versus writing only one line of business? Which states have the strongest producer recruitment outcomes relative to onboarding investment?

These are critical business questions, not operational ones. And these are the kinds of insights distribution data will be able to provide.

Reporting Vs. Intelligence

There is a distinct difference between reporting and intelligence. Reporting tells you what happened, but intelligence helps explain why it happened and what should happen next.

Let's consider producer recruiting. Many organizations measure success by the number of producers appointed each quarter. But appointments alone don't determine business value. What if data revealed that producers recruited through one regional agency network generate twice the lifetime premium of those recruited through another channel? Or that producers with certain business characteristics consistently become top performers within six months? These insights could fundamentally reshape how an organization invests in recruiting.

This isn't theoretical. One MGA connected its appointment engine directly to live production data. Instead of maintaining — and paying state fees for — appointments across its entire roster, the system now fires an appointment the moment a producer submits their first application and initiates termination when production goes dormant. Producers go from signup to production-ready in minutes instead of weeks, and state appointment fees dropped by more than 50% because the roster finally reflects reality. A report would have told this MGA how many producers it had appointed. Intelligence told it which appointments were actually earning their keep.

Identify High-Performers Earlier

One of the biggest opportunities lies in identifying successful producers much earlier in their relationship with a carrier. Many carriers and MGAs recognize top producers after they've built an established book of business and hit certain milestones. These recognitions work to build and solidify strong working relationships between top producers and carriers. This goodwill is effective, but it is only built after producers deliver large results.

What if they could identify high-potential producers within their first few months? Organizations could build these relationships earlier, and create a stronger connection with up-and-coming talent.

By analyzing historical production patterns, onboarding activity, product mix, submission behavior, and engagement trends, AI-powered analytics could recognize signals and patterns that have historically preceded long-term success. Perhaps producers who complete onboarding in less than 30 days, immediately write across multiple product lines, and maintain consistent submission activity during their first quarter have historically become top performers.

If these patterns emerge early, distribution leaders could proactively invest in those relationships through targeted marketing support, additional training, and even mentorship. Rather than reacting to success after it occurs, organizations could help accelerate it.

Opportunities Hidden in Geography

Distribution intelligence has the potential to uncover geographic expansion opportunities that may not be immediately obvious.

For example, a carrier may believe it has saturated a particular state because of the number of appointed producers operating there. However, a deeper analysis might reveal that neighboring counties with similar demographics have significantly lower producer density but higher policy growth potential.

Alternatively, the data may show that commercial lines producers are outperforming personal lines producers in a specific region, suggesting an opportunity to adjust recruiting priorities or product offerings.

These insights would allow organizations to make expansion decisions based on measurable market intelligence rather than calculated assumptions.

From Dashboards to Decision Engines

Collecting data is important, but not using it creates little value. Real opportunity comes from gleaning valuable insights and making them accessible to business leaders.

Modern dashboards need to move beyond displaying static metrics. They should benchmark producer performance, identify emerging trends, forecast recruiting outcomes, and highlight opportunities requiring immediate attention.

Imagine a distribution executive opening a dashboard that identifies states where onboarding times have increased, predicts recruiting shortfalls for the next quarter, highlights agencies exceeding profitability benchmarks, and recommends where additional field resources should be deployed.

Those are strategic business decisions powered by data, not just operational reports.

The Future Is AI

As AI continues to mature, the possibilities become even more compelling. Instead of simply analyzing historical performance, AI will increasingly help organizations anticipate future outcomes and identify lucrative opportunities.

Predictive models may identify producers who are likely to disengage before production declines become visible. They could flag onboarding delays that historically lead to lower first-year performance or detect compliance trends that indicate elevated regulatory risk before violations occur.

There will be a shift from responding to problems after they've affected revenue or operations, to intervening proactively before major harm is done.

Insurance has never lacked distribution data. Historically, it has lacked access to organized data and is now missing the ability to transform that information into strategic insight.

The organizations that gain the greatest competitive edge over the next few years won't simply automate more workflows and organize their back-office processes. They'll use distribution intelligence to make smarter recruiting decisions, strengthen agency relationships, optimize geographic expansion, and anticipate future risks before they materialize.

Distribution data isn't an administrative byproduct, but a strategic asset organizations can use to inform better decisions across every stage of the producer lifecycle.

The future of distribution isn't just better management; it's better intelligence.


Ido Deutsch

Profile picture for user IdoDeutsch

Ido Deutsch

Ido Deutsch is chief revenue officer at Producerflow, which modernizes and streamlines producer onboarding and licensing.

While studying for his MBA at UC-Berkeley, he teamed up with Luis Pino to build Agentero and led go-to-market functions. Deutsch built Producerflow from within Agentero, and it became its own startup in 2025.

 

Navigating Regulatory Plurality in African Insurance

African insurance programs fail not from regulatory complexity but from uncoordinated regimes governing the same risk simultaneously.

Navigating Regulatory Plurality in African Insurance Markets

From our experience, the insurance supervisor is rarely the authority that creates the greatest constraint for a program entering African markets. The insurance code is often the clear part. The difficulty tends to arrive later, when foreign exchange restrictions hold up a remittance, or when a local content obligation surfaces from legislation that was never drafted with insurance in mind, or when a sector regulator turns out to require cover that nobody priced into the program. Each requirement is manageable on its own. What catches people out is that they all bear on the same program at once, and rarely announce themselves at the same time.

This is what gets lost when the market simply calls Africa complex. The word is not wrong, but it points the wrong way. Complexity suggests disorder, and disorder counsels caution, whereas what these situations show is something with structure, several distinct regulatory regimes, each identifiable, each governing the same program in parallel. We would call it regulatory plurality, and the distinction matters because a structure can be coordinated where disorder can only be feared. It is a narrower idea than legal pluralism or multi-level governance, which describe coexisting sources of authority in the abstract. The concern here is operational, the way several regimes bind one program and collide at the point of design.

The risk, then, never sits inside a single regime. The difficulty is in the points where they meet. Any single regime, taken alone, is manageable, and the response that works is coordination begun at the design stage, before placement forces the question.

Africa has 54 sovereign jurisdictions, each with its own legislation, supervisor, and administrative practice. The variation is genuine, but it is the wrong place to locate the difficulty. The number of jurisdictions is not what makes these programs hard to run.

Regional harmonization has already reduced the fragmentation, though it has done so unevenly, in blocs and not across the whole. The clearest case is the CIMA zone, the Conférence Interafricaine des Marchés d'Assurances, which aligns prudential standards across 14 mainly Francophone countries in West and Central Africa under a common insurance code. Practitioners outside the Francophone tradition routinely underestimate that coherence. But CIMA is one family among several, sitting alongside the Maghreb codes, the Anglophone common-law markets, the Lusophone systems, and Francophone states such as the DRC that keep their own regulator outside CIMA entirely, so that even a shared language guarantees nothing about a shared framework. And within CIMA the harmonization reaches only so far, because each member state keeps its own legislator, layering national rules on top of the common code. Some states mandate local brokerage outright, some permit co-brokerage with a foreign business introducer, others restrict it to a strict framework, so that a placement structure lawful in one member state can be constrained in its neighbor under the same code and the same currency.

We have seen this variance directly on a pan-CIMA industrial and logistics program we coordinate, where the placement architecture had to be adjusted country by country even though every entity sat under the same insurance code. Cameroon, Gabon, Congo and Chad did not accept the same co-brokerage structure, and a wording accepted by one national supervisor drew a query from the next. Harmonization at the prudential level, in other words, does not settle the level at which the business is actually placed.

What this points to is that the regulation bearing on a program is never a single body of rules. It is several regimes layered over one another, each developed on its own track, and the friction is almost always in how they overlap. The division that matters is by source. One regime comes from insurance law itself. The others come from everywhere else and bind the program regardless.

The insurance-internal regime is supervisory regulation. This is the one body of rules that comes from insurance law and the insurance regulator. It covers licensing, admitted insurer obligations, local retention rules, policy wording control, and the prudential standards governing whether a carrier is financially sound. It is the layer international practitioners know best and the one that dominates compliance discussions. Local admitted requirements set how the program has to be built, determining which risks the master policy can carry, which have to be placed locally, and on what terms. The code can even dictate timing, setting the window in which a premium must be paid for cover to hold. Getting this regime right makes the program legal but not yet workable, because four further regimes sit outside insurance law and bind it all the same.

The first of those external regimes is financial system regulation. Foreign exchange controls, banking settlement constraints, and capital repatriation rules govern how money crosses borders. The industry tends to treat this as a banking matter when it is squarely an insurance one, and the misclassification proves expensive. Premium remittances, claims settlements, and intra-group reinsurance flows all run through these rules, and their application turns on a jurisdiction's current account position and monetary stance. The friction wears more than one face. Sometimes it is a conversion and valuation mismatch that stalls a local invoice against its master premium, sometimes a settlement delayed for months while a repatriation queue clears, and sometimes the opposite problem of a dollarized market where the local currency barely figures. A program can clear every supervisory test and still stall because the money will not move cleanly.

The next two often arrive together, which is why they are easy to confuse, but they are worth keeping apart. The first is local content regulation. Here a distinction has to be drawn that is easy to lose. Most markets already require a share of the risk to be retained domestically, but in the CIMA zone and other code-based systems that retention is a function of the insurance code itself, part of the supervisory regime already described. Local content regulation proper is something narrower and more concentrated, standalone legislation, outside the insurance code and answering to its own authority, that conditions operation in a strategic sector on the use of domestic goods, services, and professional capacity. It clusters in particular jurisdictions and does not spread evenly across the continent, with the resource economies furthest along, and for insurance it can mean placement requirements, mandatory use of local brokers, and limits on cession to non-resident reinsurers that sit above whatever the code already demands. The trap is precise. A program can satisfy every retention rule in the insurance code and still breach a local content act that sets a higher bar, because the two are different instruments answering to different authorities, and only one of them is visible from inside insurance law.

This regime also shows up outside insurance legislation altogether, in the administrative platforms several states have built to control imported cover directly. Single-window import systems such as GUCE, GUOT, ORBUS or SEGUCE, run from the trade or customs side and not by the insurance regulator, condition the clearance of imported goods on proof of local insurance placement or local broker representation. A program can be entirely compliant with its insurance code and still be held up at the border because the cargo cover behind the shipment was not structured to satisfy the platform. It is local content regulation in its most literal form, enforced by an authority that has never read the insurance code at all.

The second is sector-specific regulation. The distinction matters because local content law governs who carries the risk, while sector law governs what has to be covered at all. Extractive industries, energy, telecommunications, and public infrastructure run under their own legislative frameworks, which often make insurance compulsory or set minimum coverage standards as a condition of licensing, and these obligations come from mining codes, petroleum legislation, construction law, and procurement rules, all of them outside insurance law. The clearest example is not exotic at all. In most Francophone markets construction carries a compulsory 10-year structural liability, the décennale, imposed by law and entirely outside the insurance code, which a program built only to the code will simply miss. Elsewhere the sector rule and a local content rule travel in the same statute, a petroleum act carrying both a compulsory cover requirement and a domestic retention share, which is exactly why a reader who treats the two as one will miss whichever obligation they were not looking for.

The last external regime is the fiscal and tax framework. Premium taxes, parafiscal charges, stamp duties, and withholding taxes on cross-border reinsurance flows vary widely and bear directly on a program's economics. In some markets the fiscal load is heavy enough to redraw structural decisions, shifting the balance between local placement and international reinsurance, or the choice between admitted and non-admitted coverage. It belongs to the jurisdiction's wider fiscal architecture, a separate body from insurance law, and it tends to surface at settlement, once the design is already fixed.

Each of these regimes is manageable on its own. The exposure comes from each answering to a different authority, resting on a different legal instrument, and following a different institutional logic, so that when separate teams or advisers handle them as separate compliance exercises, no one owns the interactions between them, and they show up only when they cause a problem.

One program we have coordinated shows how the regimes arrive in sequence, each one only visible once the last has been dealt with. A mining risk is placed globally and fronted into a producing economy, every admitted requirement met under the insurance code. The code sets the first constraint. The risk has to be carried locally and cannot simply be fronted from abroad, so a substantial share, here about half, is retained by domestic carriers, and the master placement has to be broken back down into local policies. That much is foreseeable. Less foreseeable is a second retention the code never mentions. The petroleum and mining legislation sitting above the program sets its own local content floor, higher than the code's, answering to a different authority, and satisfying the insurance regulator does nothing to satisfy it. Raising local retention to meet it is straightforward on paper. In practice the local carrier prices the retained premium in local currency, and the figure bears little relation to the master premium once conversion and local ceding charges are applied, so settlement stalls while the two are reconciled. The brokerage on the retained share, and the parafiscal and withholding charges attaching to the cross-border portion, then have to be rebuilt separately, because the master pricing never carried them. No single rule here is obscure. The retention sits partly in the insurance code and partly in the sector legislation above it, the currency friction in the exchange regime, the charges in the fiscal framework, each answering to a different authority, and the trouble is only ever visible when they are read together.

The same program makes a further point once a loss occurs, because the regimes do not rest at placement. They return at settlement, and more sharply, with a client waiting to be paid. On a major fire claim of ours in the region the coverage position was never in question, clear on the wording; the difficulty was everything that followed it, the currency conversion on the indemnity, the local insurer's own reinsurance recoveries, and the pace at which funds could actually reach the client. A coordinator who has planned only for the placement stage meets the same frictions again, later and under more pressure. A loss does not suspend the regimes that shaped the program. It tests them.

Compliance, then, has to be judged at the level of the whole system, and coordination is what that demands. The expertise to handle each regime alone generally exists. What no one owns is managing the points where they touch, from the design stage onward.

In concrete terms, the master policy architecture must be aligned with local admitted requirements before coverage terms are fixed, and foreign exchange constraints mapped against premium flows before pricing is agreed. Local content thresholds need checking against both the insurance code and any standalone act, including the administrative platforms that enforce it outside insurance law entirely. The coordinator has to identify sector-specific obligations at inception, before placement begins. And the fiscal cost of cross-border flows has to be built into the commercial logic from the outset. None of this is sequential. All of it must be held in view at once, and again at claims stage, because a loss does not suspend the regimes that shaped the program, it tests them.

Front-loading integration is a familiar principle in program management, but what distinguishes the African insurance case is that the regimes were built separately, are administered by separate bodies, and were never reconciled with one another in the drafting. Reconciling them falls to the program coordinator, and it has to be done ahead of placement, and revisited at every claim that follows.

The environment has structure. Calling it disordered is the mistake, because it is a set of overlapping regimes each governed by its own logic. Reading it as one insurance regime and four that bind from outside, financial system, local content, sector-specific, and fiscal, makes operating across 54 jurisdictions no easier, but it gives the difficulty a shape and locates the work where it belongs, in coordinating the regimes the legislation itself leaves uncoordinated.

That work falls to whoever holds the whole program, the international coordinator on one account, the client director on another, the program lead on a third. The title varies, the function does not. It means holding all five regimes in view at once and reconciling them before a single policy is placed, and again at every point a claim moves money across a border. It is demanding, but it is not disorder, and that is the point worth ending on. These markets are not the chaotic environment the word complex quietly implies. They are navigable, provided the regulation is read for the layered structure it actually has, and provided the program is built by people who can hold that structure together, the operations specialists whose competence is exactly this, as distinct from the brokers who place the risk and the underwriters who price it. The market has begun to seek them out. What these markets reward is the judgment to treat complexity as structure, and to rely on the expertise that can navigate it.


Arthur Michelino

Profile picture for user ArthurMichelino

Arthur Michelino

Arthur Michelino is head of international coordination at OLEA Insurance Solutions Africa.

Michelino previously worked at Diot-Siaci as an international coordinator for key accounts. He began his career at Willis Towers Watson (formerly Gras Savoye), implementing international programs for the mid-market segment.

It's a Wired, Wired, Wired, Wired World

As sensors have demonstrated during the World Cup, the globe is becoming so wired that it's possible to spot earthquakes, wildfires, and floods in time to mitigate harm.

Image
Early Warning

When Norway won games during the World Cup, so many people jumped up and down that earthquake sensors picked up tremors in Oslo. The same was true when Mexico won games; tremors were detected in Guadalajara and other parts of the country. 

That's some impressive fan support. Vamonos, Mexico! Dra til, Norge!

But detecting the tremors also required some very impressive sensors — of the sort that can help insurers increasingly head off injuries and property damage from earthquakes, wildfires, and floods by giving people advance notice of the impending trouble.

Let's have a look. 

Earthquake sensors are top of mind for me because of the devastating quakes in Venezuela and because of the 5.6-magnitude quake in late June that shook parts of Northern California where I lived until recently. 

Sensors in Google phones managed to alert more than 11.4 million people in Venezuela that a major earthquake was coming, at least several seconds before they felt the impact, according to the New York Times, and as much as two minutes ahead of time. It's not clear how many lives were saved and injuries prevented — and the losses were devastating, with nearly 4,500 deaths confirmed from the 7.2- and 7.5-magnitude earthquakes — but many people surely managed to protect themselves by quickly taking cover. 

What Google is doing is intriguing, and potentially a model for other alert systems. Google has turned all its phones into sensors that take advantage of the fact that earthquakes create two types of waves, as part of a system that is available in nearly 100 countries. One type (P-waves) travels very fast but does little damage. The other (S-waves) does the vast majority of the damage but travels significantly more slowly. Google's phones detect the fast-arriving P-waves as they travel through the ground, and, when Google sees all phones in an area lighting up at once, it knows S-waves and rumbling are coming. 

It's rather like thunder and lightning. Google's phones see the lightning and can tell people that thunder is coming. (The obvious difference being that, in the case of earthquakes, the damage comes after the alert, while lightning is both the alert and the cause of damage.)

The systems don't necessarily provide a lot of warning. P-waves travel at 5-6km/sec, while S-waves spread at 3-4km/sec. So you'd need to be perhaps 20 miles away from the epicenter to get five seconds of warning. People will need to be educated about what to do with those five seconds (drop, cover and hold on) and become accustomed to the idea of alerts, so they don't freeze when the warnings arrive. 

But the sensor network could still get a lot of people away from whatever might fall on them, even with little advance notice, and prevent other damage, too. A woman I know was on an on-ramp for I80 in Berkeley when the Loma Prieta earthquake hit Northern California in 1989. The on-ramp collapsed, dropping her 30 feet onto a pile of rubble. The collapse not only totaled her car, of course, but had her in and out of surgery for years, and left her traumatized from knowing how many people were crushed beneath her. With just five seconds notice, she would have been able to pull off the road and stop short of the elevated roadway. 

In the recent California quake, the governor's office bragged that the state's new early warning system had alerted more than 1 million residents before the shaking started in their area, drawing on feeds from some 600 sensors installed around the state. The system is also available in Oregon and Washington, and Apple offers a similar sort of alert system, drawing on sensors that others have installed.

Insurers don't have a role to play in the development of networks like Google's and don't have to help with the sort of deployment of hard-wired sensors like those in California, but they can certainly assist with the education. Those that do will not only reduce injury claims but will earn good citizen points. At a time when insurers are looking for ways to engage with policyholders more often — not just when collecting premiums or paying claims — offering education about how to protect yourself seems like a promising avenue.

Sensors that can detect wildfires before they get out of control are likewise becoming far more sophisticated and are being deployed on the ground, in the air, and in satellites. Personally, I'm most intrigued by what's happening with satellites, both because they can cover nearly unlimited territory, almost minute by minute, and because I believe in having others do as much work for me as possible. 

Google doesn't sell its phones on the basis that they'll detect earthquakes. People buy the phones for the obvious reasons, then Google adds a bit of software, et voila! A detection network is suddenly deployed. I think the same potential is there to add wildfire detection capabilities to the thousands of low-earth satellites that Elon Musk and others are deploying to facilitate communications. Let them pay for the expensive hardware and the launch, then add a camera and other forms of sensors that can look down and spot even small fires.

Floods, thus far, require dedicated networks of sensors, but there's progress there, too, as Houston is showing. Cities are installing small, inexpensive sensors that monitor water levels constantly, which usually providing hours of warning about developing floods. Cities can also warn motorists in real time to avoid underpasses where water has collected. 

Because these networks of sensors can't just be piggybacked onto other hardware, progress can be slow — adoption remains spotty, for instance, in Central Texas even in the wake of the disastrous flood a year ago that killed 130 people, including 25 young girls and two counselors at a summer camp. But the technology is there and will continue to make inroads.

A rule of thumb I developed some years ago now, as part of what I call the Laws of Zero, is that you can assume that any bit of information you want will be available to you at what looks like zero cost (compared with today) if you look down the road a ways. 

The concept is me looking for areas outside computer chips where the magic of Moore's law can apply. Moore's law — essentially, that the power of a computer processor doubles every year and a half to two years at no increase in cost — means that a unit of computing power that cost a dollar in 2000 costs roughly 1/600th of a penny today. So, free (almost) for anyone making long-range plans in 2000.

I won't go into all seven of the areas I identified, but it's pretty easy to see how sensors fit the Laws of Zero pattern. Moore's law will drive the cost of the computing and any memory toward zero. WiFi and satellite connectivity are becoming ubiquitous, so there's no marginal communication cost. Batteries are also plunging in cost, and many sensors won't even need them, either because they can use solar power (whose cost is heading toward zero) or because they're built into bigger systems such as Google phones or Starlink satellites. 

The Law of Zero about sensors means we will keep seeing progress. Insurers won't even have to pay for that progress. They can just piggyback on what others are doing, then help policyholders understand how to take advantage of the progress — reducing claims while earning good will.

In the meantime, if you aren't watching the France-Spain World Cup semifinal this afternoon, or at least sneaking the occasional peak while at work, I'll bet you'll be able to tell the result if you have access to seismograph readings from Paris and Madrid at 5pm or so Eastern time. 

Cheers,

Paul

 

 

A Founder's Guide to Surviving Investor Rejection

At 66, a cybersecurity veteran trades retirement planning for startup building and learns that success doesn't depend on yeses; it requires "not no"'s. 

Walking a high wire

One of my favorite movie scenes comes from "Volunteers."

Tom Hanks is trying to negotiate with a local warlord. Standing nearby is the warlord's beautiful bodyguard—whose command of English is somewhere between nonexistent and interpretive dance. Tom flashes a grin that suggests he'd be perfectly happy if she happened to be part of the bargain.

The warlord responds with something to the effect of, "If I say yes… and not no…"

I honestly don't remember exactly how the scene ended. What I remember is what popped into my own head.

I'd settle for not no.

At the time, it was just a funny line. Thirty years later, after more investor meetings than I care to count, I finally understand why it stuck with me.

Founders spend years chasing "yes." Investors rarely give you one. Instead they say…

"Interesting."

"Come back after revenue."

"Let's reconnect in six months."

"We'd like to see your next release."

"Keep us posted."

None of those are yes.

But they aren't no.

If you're building a company, you eventually realize that companies aren't built on yes.

They're built on not no.

The High Wire

Being a founder is the proverbial high-wire act. There's no safety net. No guarantee. No instruction manual.

People love talking about entrepreneurial risk. Let me save you some time. It's all risky.

The right decisions.

The wrong decisions.

The crazy decisions.

Sometimes you don't know which one you made until two years later.

Then there are the mornings.

3 a.m.

Every.

Single.

Morning.

Not because the alarm went off. Because your brain did.

There's always one more investor to research.

One more slide to improve.

One more grant proposal to edit.

One more feature to design.

One more email to send before the day job begins.

People think founders work 80-hour weeks. The truth is… founders never really stop working. The company follows you to bed. It wakes up before you do.

And then there's that feeling. If you've ever built a company, you know exactly what I'm talking about. That knot in the pit of your stomach. It never completely goes away. It's there when you wake up. It's there during investor meetings. It's there while you're brushing your teeth. It whispers the same questions over and over.

What did I forget?

Are we going to make it?

Am I asking my family to believe in something impossible?

Is this the dumbest thing I've ever done… or the smartest?

I've come to think of it as the founder's tax. Nobody talks about it. Everybody pays it. Some people call it stress.

Founders call it Tuesday.

Venture Capitalists and Sea Turtles

One of my favorite startup metaphors comes from Silicon Valley.

Ron LaFlamme, the eccentric attorney, explains venture capital using sea turtles. Sea turtles lay hundreds of eggs because only one or two eventually make it to the ocean.

"That's what Peter Gregory is doing," Ron explains. "Making sure one or two of his compression plays make it to the sea."

The first time I heard that I remember thinking,

"Why not just pick stronger turtles?"

Of course, that's not how venture capital works. They're playing portfolio math. Fund enough companies and one eventually becomes the next Google.

They're not looking for certainty. They're looking for outliers.

Founders don't have that luxury.

Most of us get one turtle.

One company.

One dream.

One shot.

It's amazing how differently you look at risk when you're carrying your only turtle.

Government Grants: The Ultramarathon

If raising venture capital is a marathon… government grants are an ultramarathon.

Uphill.

Into the wind.

Dragging a filing cabinet behind you.

You spend six weeks writing.

Three weeks editing.

Two weeks wondering whether Requirement 3.2.17(b) means exactly what you think it means.

You finally hit "Submit."

Then… absolutely nothing.

Weeks become months.

Months become more months.

Eventually an email arrives.

Your pulse quickens.

Your palms get sweaty.

You open it.

"Thank you for your interest…"

That's government-speak for, "Better luck next time."

The amazing part?

You immediately start writing the next proposal.

Founders are funny that way.

The government didn't invent persistence.

Entrepreneurs did.

Accelerators

I actually like accelerators.

Some of them.

Many provide genuine value.

They introduce founders to investors.

They surround you with experienced entrepreneurs.

They shorten the learning curve.

Some absolutely earn the equity they receive.

Others…

Well…

Let's just say the first image that came to my mind was a skinny kid explaining proper deadlifting technique to a professional bodybuilder.

It made me laugh.

Mostly because I've been there.

Now before anyone gets offended…

No, I don't know everything.

Far from it.

But this ain't Marine Corps boot camp.

I don't need somebody teaching me how to polish my boots. I've spent decades leading soldiers, briefing executives, running cybersecurity organizations, and solving difficult problems. Teach me something I don't know. Introduce me to someone I couldn't otherwise meet. Open a door that's been closed. Challenge my assumptions.

That's acceleration.

Teaching me how to center a title on a PowerPoint slide? Not so much.

Now, to be fair, accelerators usually introduce you to investors. Of course, they don't do it out of the goodness of their hearts. They generally take a slice of your company.

Sometimes it's a reasonable slice.

Sometimes…

It's a fat butcher's slice.

Every founder has to answer the same question.

Was it worth it?

If the answer is yes… great.

If not… that was one expensive PowerPoint lesson.

The Founder's Retirement Plan

Somewhere along this journey I stopped looking at my investment portfolio as retirement.

I see software development.

Advertising.

Patent attorneys.

Trade shows.

Cloud hosting.

Developers.

My financial advisor sees diversification.

I see operating capital.

Retirement?

I'll think about retirement after Version 5.0 ships.

Every now and then I tell Suzanne we're flying first class to the Maldives for a week of scuba diving.

Just as soon as…

well…

just as soon as we can afford a margarita machine.

Fans of "Silicon Valley" will appreciate that reference.

Everyone else probably thinks I've developed an unhealthy obsession with frozen drinks.

They're not entirely wrong.

The funny thing about founders is that we stop measuring wealth the way everyone else does.

A new car?

That's six months of development.

Kitchen remodel?

Marketing budget.

Vacation?

Another developer.

People ask how founders keep funding their companies.

Simple.

We stop thinking about assets.

We start thinking about runway.

Yin and Yang

People ask what it's like to build a company with my wife. The answer usually surprises them. We work remarkably well together.

Mostly because we work remarkably well apart.

Ron LaFlamme would probably describe us as yin and yang.

That's us.

I'm the dreamer.

Suzanne is the realist.

I see possibilities.

She sees details.

I chase ideas.

She quietly points out the 17 reasons one of them probably won't work.

She's usually right.

Long before software, we bought a short-term rental.

The number one comment from our guests wasn't the location.

It wasn't the view.

It wasn't the amenities.

It was one word.

"Immaculate."

That's Suzanne.

If NASA hired her, astronauts would dust the launch pad before liftoff.

She has standards that make hotel inspectors nervous.

Thank goodness.

Somebody has to.

Every founder needs someone willing to ask,

"Are you sure?"

Not because they doubt the dream.

Because they want the dream to survive.

People celebrate founders.

They should spend more time celebrating the people who quietly make founders better.

The Turtle on the Fence Post

There's an old saying: "If you see a turtle on a fence post, you know it didn't get there by itself."

How he got up there is anybody's guess.

Yes…

I'm mixing metaphors.

It's my article.

Besides, if you've ever started a company, you know reality stopped making sense a long time ago.

You stop measuring life normally.

Your retirement account becomes software development.

Vacation becomes cloud hosting.

Credit cards become temporary venture capital.

Your dog starts recognizing the Amazon delivery driver by first name.

Normal people call this insanity.

Founders call it product-market fit.

The truth is, nobody builds a company alone.

Somebody always believed.

Somebody always introduced you to someone.

Somebody always opened a door.

And if you're lucky enough to succeed… maybe someday you'll become the person holding the door open for the next founder trying to get through.

That's a legacy, too.

Why 66?

People may someday ask me a simple question.

"Why did it take until you were 66?"

It's a fair question.

The funny thing is…

I don't think I waited until I was 66 to become a founder.

I think I spent 40 years accidentally preparing to become one.

The Army taught me leadership.

It also taught me that no plan survives first contact.

Corporate America taught me patience.

Cybersecurity taught me skepticism.

Attackers adapt.

Technology changes.

Certainty is usually an illusion.

Marriage taught me partnership.

Investors taught me persistence.

Government grants taught me humility.

And rejection…

Rejection taught me that success usually belongs to the person willing to hear "no" one more time than everyone else.

Looking back, every assignment, every promotion, every setback, every impossible deadline, every deployment, every conference room, every board presentation, every sleepless night somehow led here.

Maybe the company wasn't waiting for me.

Maybe I was waiting to become the person capable of building the company.

The Founder Nobody Sees

People see the pitch.

They see the product.

They see the trade show booth.

They see the LinkedIn announcement.

What they don't see… is the founder sitting at the kitchen table at 3 a.m. trying to get two hours of work done before heading to the day job.

They don't see weekends disappear.

They don't see vacations turn into strategy sessions.

They don't see the credit card bill arrive.

They don't see another investor politely explaining why your company isn't quite ready.

They don't see the quiet conversations between spouses.

"Can we keep doing this?"

"How much longer?"

"Are we crazy?"

The answer, by the way… is yes.

Founders are a little crazy.

Thankfully.

If they weren't, most companies would never exist.

Looking Forward Instead of Backward

At 66, something changes.

You stop asking,

"How much money can I make?"

You start asking,

"What am I going to leave behind?"

Money is nice.

Don't misunderstand me.

I'd love to stop looking at every block of stock in my retirement account as another software release or another attorney.

I'd love to finally buy that margarita machine.

I'd really love to take Suzanne to the Maldives and spend a week underwater instead of under deadlines.

But that's not why I'm doing this.

If our company succeeds, I hope my legacy isn't the software.

I hope it isn't the patent.

I hope it isn't the valuation.

I hope it's the organization that never became tomorrow's headline because somebody finally started looking through the windshield instead of the rearview mirror.

For decades, cybersecurity has become remarkably good at explaining yesterday.

Yesterday's ransomware.

Yesterday's phishing campaign.

Yesterday's breach.

Yesterday's lessons learned.

Those things matter.

But they're history.

I've always believed we could do more.

What if we could help organizations think about tomorrow?

Not with certainty.

Not with magic.

Not with a crystal ball.

Just disciplined analysis.

Patterns.

Trends.

Probabilities.

Enough information to make one better decision before the next attack arrives.

If we accomplish that… then every sleepless night was worth it.

Every rejection.

Every investor meeting.

Every government grant proposal.

Every conference.

Every dollar we invested instead of spending on ourselves.

Worth it.

The Last Word

The funny thing about entrepreneurship is that people think the story ends when an investor finally says yes.

It doesn't.

That's just the next chapter.

The real story is everything that happened before anyone believed.

The three o'clock mornings.

The knot in your stomach.

The day job that funded the dream.

The spouse who quietly kept believing.

The people who opened doors.

The investors who didn't say yes… but thankfully didn't say no, either.

Today we're still building.

Still pitching.

Still applying.

Still hearing,

"Come back later."

We're still looking at retirement accounts and seeing software development.

We're still laughing about margarita machines.

We're still dreaming about the Maldives.

We're still walking the high wire.

And after all these years…

I'd still settle for…

not no.

Because every once in a while…

"not no" becomes "yes."

Epilogue

Or maybe just the quiet refusal to quit.

Every founder needs something that carries them through the investor meetings, the rejection emails, the three o'clock mornings, and that knot in the pit of the stomach that never quite goes away.

Keep walking.

Keep building.

Keep believing.

Because every once in a while…

one little turtle actually makes it to the sea.

I'm fortunate.

When I need a reminder to keep going, I don't have to look very far.


Timothy O'Neil

Profile picture for user TimothyO'Neil

Timothy O'Neil

Timothy S. O’Neil, CISSP, CEH, is president and founder of AigisPoint Predictive Intelligence

A retired U.S. Army lieutenant colonel with more than 25 years of cybersecurity leadership experience, he has held senior security architecture and information security leadership roles across the healthcare, insurance, telecommunications, and consulting industries. He is the developer of the Strategic Predictive Threat Intelligence (SPTI) platform, designed to help organizations and cyber insurers anticipate emerging cyber threats before they become losses. 

The Unknowns of Enterprise AI Deployment

Property & casualty insurers face systemic unknowns when scaling AI beyond pilots into regulated workflows like underwriting, claims and pricing.

Deployment

Property & casualty insurers are moving fast from narrow machine learning pilots to enterprise-scale deployments that blend predictive models, generative AI, and agentic workflow automation. The hardest barriers to this transition are not primarily technical. They are the unknowns: the uncertain, interdependent, and often non-obvious failure modes that surface when AI systems get embedded in regulated, long-tailed, and economically sensitive insurance processes like underwriting, pricing, claims, reserving, and reinsurance.

Insurance executives must shift from model-centric thinking to system-centric thinking. Strong data and model controls are necessary but not sufficient. Without secure integration patterns, operational monitoring, model risk discipline, and clear accountability, even a high-performing model will struggle to become a safe, compliant, and profitable production system. Enterprise AI risk is not merely model risk. It is systemic risk arising from the coupling of data, models, workflows, humans, vendors, and core platforms.

Why P&C is a special environment

P&C is uniquely difficult territory for enterprise AI. The product is a promise made under uncertainty, and the balance sheet carries long-tail obligations, so decisions made or supported by AI can influence loss emergence years later through selection effects, reserving assumptions, and litigation pathways. This drives an unusually high cost of model error and governance failure. Several structural features amplify the unknowns: exposure to catastrophe clustering and tail events, rapid changes in external cost drivers like repair and medical inflation, the potential for proxy discrimination through correlated variables, complex multi-party ecosystems spanning brokers, MGAs, TPAs, and repair networks, and the fragmented reality of U.S. state-based regulation.

A taxonomy of unknowns

The key is a structured taxonomy that classifies the unknowns into eight categories, each with concrete P&C examples and matching guardrails. These span data unknowns (coverage gaps, inconsistent cause-of-loss codes, third-party data drift), model behavior unknowns (overfitting to recent inflation, LLM hallucination, proxy discrimination), system integration unknowns (automation triggering payments without adequate checks, silent integration failures), operational unknowns (drift during catastrophe season, retraining backlogs), security unknowns (prompt injection, data exfiltration, model theft), regulatory unknowns (varied state DOI expectations, market conduct exam demands), economic unknowns (unclear ROI, behavioral feedback loops, non-linear computing costs), and human and organizational unknowns (overreliance on models, adjuster workarounds, incentive misalignment). This taxonomy works both as an executive checklist for risk identification and as a technical planning artifact for control design.

Two unknowns receive special emphasis. The first is the feedback loop problem: when AI is used to price, select, investigate, or settle, it changes the composition of the book and the behavior of insureds and internal teams, which in turn alters the future data the AI is trained on. A model may appear to improve loss ratio in the short term while quietly increasing adverse selection, litigation frequency, or churn over longer horizons. The second is the tail and regime shift problem: since P&C risk is dominated by tails, models trained in routine years can fail under catastrophe clustering or new social inflation regimes, and validation that optimizes average error will systematically miss tail risk.

Mapping unknowns to governance frameworks

Rather than inventing a new compliance regime, the unknowns should be mapped onto established frameworks to create a shared language across technology, business, and regulators. The NIST AI Risk Management Framework serves as the backbone, with its four functions of Govern, Map, Measure, and Manage. This is complemented by the NAIC's 2020 AI Principles and its December 2023 Model Bulletin on the Use of AI Systems by Insurers, which set regulatory expectations for governance, documentation, and oversight, including for vendor-acquired systems, and stress compliance with existing unfair trade practice and unfair discrimination laws. Also important are NIST CSF 2.0 and the NIST Privacy Framework for cyber and privacy integration, the NAIC Insurance Data Security Model Law for data security standards, and SR 11-7 / SR 26-2 model risk management discipline adapted from banking. The Colorado AI Act also offers guidance on what the future of AI regulation in the industry looks like.

A control mapping table connects specific unknowns to control objectives, framework hooks, and evidence artifacts, and the highest-leverage leadership move is treating evidence as a product: every AI system should ship with documentation, test results, monitoring plans, and audit-ready logs.

Reference architecture and generative AI patterns

A six-layer reference architecture is needed for the heterogeneous, hybrid environments that carriers actually run: business process and orchestration, AI application, model, data and feature, platform and operations, and a cross-cutting security, privacy, and governance layer. MLOps must be treated as first-class production engineering rather than project-based delivery, because the true cost of AI is dominated by post-deployment work like monitoring, incident response, recalibration, and security patching. The main generative AI patterns in production insurance settings are: retrieval-augmented generation grounded in policy forms and claims manuals, constrained tool use, targeted fine-tuning, and agentic workflows with supervisory layers and circuit breakers for financial actions. Security by design extends existing controls while adding AI-specific safeguards drawn from OWASP's LLM vulnerability taxonomy and MITRE ATLAS.

Tiered guardrails and continuous assurance

A key insight is that not all use cases warrant the same governance intensity. A three-tier model based on decision impact is needed. Tier 1 (informational: search, summarization, document classification) allows advisory-only outputs with basic guardrails. Tier 2 (decision support: underwriting triage, pricing indications, claims severity and fraud scores) requires segmented validation, explainability, fairness tests, and human-in-the-loop review. Tier 3 (acting and automation: auto-routing claims, automated payments within limits) demands dual control for payments, transaction limits, rollback, and continuing monitoring. This tiering supports proportional governance without over-controlling low-risk productivity use cases. 

On measurement, there should be a shift from one-time validation to continuous assurance, combining pre-deployment testing (data readiness, model validation, fairness and security tests, documentation), post-deployment monitoring across technical, business, compliance, and security signals, AI-specific incident management, and exam readiness.

Operating model, roadmap, and research agenda

Deployments fail when accountability is unclear, and it challenges a common myth: that accountability for all AI initiatives should sit with the CTO, CIO, CDAO, or CAIO. This contradicts basic operational risk principles, and accountability should instead be defined by roles, responsibilities, and use case within functional areas. What is needed is a governance structure (an AI Steering Committee, an AI Risk and Controls Council, product owners with a value realization office, and an independent validation function) and a detailed table of CXO responsibilities and the specific unknowns each leader must own.

Avoid the trap of scaling models before scaling controls, and instead sequence the work: baselines in the first 90 days, enterprise repeatability at three to six months, and institutionalization at six to 18 months, including alignment to ISO/IEC 42001 and 27001. Set a research agenda covering causality and feedback loops, fairness under distribution shift, tail-risk stress testing, generative AI assurance, AI security metrics, and standardized evidence for regulators. Practical appendices provide an executive checklist mapped to NIST AI RMF, a model card outline, AI risk register fields, and an incident response playbook.

To read the full paper this article is drawn from, click HERE.


Kushal Shah

Profile picture for user KushalShah

Kushal Shah

Kushal M. Shah has 25 years of experience in the insurance industry.

He is the author of "The Unknowns of Enterprise AI in Regulated Sectors" and innovator of patent-pending aiV-Cube framework for AI risk assessment and underwriting. 

He holds active producer and adjuster licenses across multiple states and has completed the Associate in Claims from The Institutes. He is currently a candidate for Associate in Insurance AI (AIAI).

Insurance AI Needs a Policy Preview Layer

Insurers can use AI to reduce manual review but only when human oversight is built into the workflow before documents reach customers.

AI Policy

As organizations adopt artificial intelligence (AI) in regulated industries, they face significant risks when validation mechanisms are not built into these systems, leading to compliance, legal, and reputational exposure. Having previously worked in technology for financial services, I can attest that there were many occasions when the technology organization was faced with the dilemma of whether to bring solutions to market quickly or in a manner safe for customers and shareholders. It is critical to establish the right balance to secure governance, while pushing the barriers to AI access in the enterprise. My current role requires me to analyze and deliver a process workflow to preview and validate policy documents.

Industry Context: Why Safe AI Matters

AI enhances productivity, speeds up decision making, and lowers costs. Yet, there are always auditors and governed policies in insurance and banking institutions for every policy document, or every autonomous decision — any deviation from expected outcomes can trigger regulatory scrutiny. Making a mistake is no longer seen solely as a technical problem, but rather as a legal or reputational case, security breaches, or people losing their money. I have observed this in cases where banks and insurers use AI to generate automated outputs, process complex tasks, detect anomalies, and reduce costs. Without proper governance, AI can amplify risks instead of reducing them.

My Approach: Designing Preview Architecture

Here is the approach I implemented. My intent was to develop an end-to-end policy documents ecosystem with the ability to AI-preview and AI-validate every incremental change before hitting the "go" button. In practice, I conceptualized the approach as a coherent journey:

  1. Document Generation: The policy documents are generated by our core systems in various formats (PDF, JSON, image).
  2. Staging and Preview: The documents are not delivered to the final destination but are first routed to a secure bucket. The documents are staged in a "preview" in which no changes happen to the customer record until validated.
  3. AI-Driven Validation: We run a comparison model using AI on the documents in the staging area. The model compares any inconsistency between the contents of the new policy and approved templates or data sources.
  4. Controlled Release: The system only allows final release if everything is checked out. Any discrepancies trigger alerts for manual review.

In this architecture, a separate preview layer is created where AI can operate independently and not interfere with the production servers, and gives the compliance teams the ability to look at every AI finding before changing the modus operandi of the business. This flexible approach supports complicated data environments where data can be captured across many different sources, from cloud software to outdated systems to manual data logging. This workflow ensures that all artifacts are consolidated and validated by AI before release (Figure 1).

Technical Insights and Implementation

The implementation uses cloud-based object storage (such as AWS S3), where each preview package is an immutable artifact. This allows downstream controlled processing exclusively to authenticated content. In practice, orchestration was accomplished using serverless functions (AWS Lambda), and AI-based document comparison runs as a separate service. The choice of a particular AI model architecture — not because of current AI market trends — lets us explain our decisions, as explainability was one of the requirements provided to us in advance by the regulator.

Auditability and logging were present throughout the whole implementation. Events and statistics of every process step are present on our monitoring platform, and metrics such as latency per document, exact detection rate, and percentage of documents sent to human validation are tracked and available for monitoring. One result we obtained from the model after integration was a validation detection rate of about 91% (precision on validation samples); false positives account for less than 10% of total detected discrepancies. This was not a guarantee, but a result of multiple validations in production cases with real samples. These statistical metrics allowed us to create visibility and confidence in the AI layer's reliability.

Most importantly, we also built a safety net: AI does not intervene directly. It detects mistakes but does not take any corrective actions itself. No policy can be modified unilaterally by AI. Our policy management system will always be updated in the traditional way, not via our AI layer. In other words, our AI can identify issues but cannot act on them. Approval and action must always occur in our official system or by an appropriate person permitted to undertake that action. We used this rule-based "exit gate" to convey our low-risk profile to the regulators.

Real-World Observations and Lessons

One of the key learnings from this project was reusability. The preview architecture I had designed for one line of business was abstract enough to fit another line of business. That team also used our architecture for their preview. They simply connected to our staging pipeline, dropped their documents in, and hooked into our AI validation pipeline. All hand-offs were defined (secure SFTP links, bucket triggers). The systems worked seamlessly together. Reusability has a multiplier effect — time and effort saved are multiplied across the enterprise.

One last thing to highlight: metrics are essential for adoption. Beyond the perceived savings in operational cost with the AI-preview system (nearly 60%, going from ~$10 to ~$4.80 per case), approximately $1.1M in annual savings from automating the repetitive task (~500 cases/day), and almost no effect on the manual workforce — since they no longer have to review every page, but just focus on identified failures — those strong results allowed us to get quick buy-in from compliance and management teams and to push the solution forward.

I also learned how to tune AI systems effectively. Initially, the system produced too many false positives. If there was a change in formatting of the document, or a small variation on a standard cover letter, we were triggering an alarm. We improved training data, tuned parameters, and reduced the noise. Another important aspect is that we ensured model behavior remained explainable. When an alarm is raised by the AI, it is possible to generate an explanation that is interpretable from the perspective of the regulator or auditor — in other words, a filtered log with all details and a digest automatically generated per alarm.

AI is ubiquitous today, and organizations are asking themselves, "Can we trust AI decision-making in our use cases?" The trust boundary is in the design. AI should be used as a recommendation engine, with clearly defined boundaries. AI should never play the role of sole decision maker. I had an AI-first architecture mindset when building this as a recommendation engine with guardrails. Architect the pipeline once as an extensible platform. The best lesson I learned is to always think platform first. Rather than trying to solve the AI access problem each time there is a new use case, build a standard reusable pipeline. When we deliver a new service such as AI document analytics, we can leverage the existing infrastructure instead of building the service from scratch. It was designed to hook into the existing document preview layer.

My second principle is to "fail fast but safely." We will never make massive changes, but instead pilot workflows, evaluate the results, and scale incrementally. Stakeholders will always be confident that we will catch any divergences early.

Key Takeaways for Practitioners
  • Design for Reuse: Create modular, consistent architecture. A generic preview pipeline can serve multiple teams and use cases, reducing duplication of effort.
  • Isolate AI Analysis: Keep AI processing separate from final system actions. Use staging areas or audit logs so that all AI-suggested changes can be reviewed before going live.
  • Instrument and Measure: Track accuracy, costs, and impacts. Solid metrics (like processing time or error rates) build confidence with stakeholders and guide improvements.
  • Prioritize Explainability: Select models and techniques that let you understand or explain decisions. In regulated settings, a "black box" is too risky.
  • Maintain Human Oversight: Automate the heavy lifting but ensure a human or rule-based review gate for any critical change. This balance preserves both efficiency and control.
  • Iterate and Improve: Begin with a strong baseline score and then enhance it by incorporating feedback. Use initial outcomes to justify an increase in the number of cases/projects and demonstrate progress.

AI does not have to be flawless to be used in regulated environments, but it must be measurable, verifiable, and governed. It should remain explainable, auditable, and never act without human oversight. A preview-based approach makes this possible by allowing AI to operate within a controlled workflow where outputs are visible and validated before they are committed. Start small, measure the impact, and expand gradually — this is how compliance shifts from a barrier into a competitive advantage.


Bhargavi Vepuri

Profile picture for user BhargaviVepuri

Bhargavi Vepuri

Bhargavi Vepuri is a director at Prudential Finance.  

She has led large-scale AI and cloud modernization initiatives focused on operational efficiency, document workflow validation, audit readiness, and regulated enterprise delivery quality.

Resting Heart Rate Reshapes Underwriting

Resting heart rate emerges as a powerful, underused mortality predictor that may outperform traditional underwriting metrics like cholesterol and BMI.

RHR Transformation

In an era defined by expanding data streams and increasingly sophisticated underwriting tools, it is often assumed that better decisions require more complex inputs. However, recent RGA research challenges that assumption by highlighting the value of a familiar, easily measured metric: resting heart rate.

Resting heart rate (RHR) – the number of heartbeats per minute when an individual is at rest – provides a real-time snapshot of cardiovascular efficiency and overall physiological health.

Despite its simplicity, RHR has historically been underused in underwriting frameworks. That gap is now narrowing.

A growing body of evidence points to RHR as a strong independent predictor of all-cause mortality. Recent research has gone so far as to describe it as a "forgotten risk factor," with findings indicating that elevated RHR can outperform traditional measures, such as hypertension, in predicting mortality risk.

Evidence that challenges underwriting conventions

RGA's research reinforces these findings with compelling consistency across populations and datasets. Analysis of UK Biobank data shows a clear and measurable relationship between RHR and mortality outcomes. For example, individuals with higher resting heart rates face significantly elevated mortality risk compared with peers with lower rates, even after adjusting for conventional underwriting factors.

What makes this relationship particularly relevant to insurers is its stability across different segments. The predictive power of RHR holds across:

  • Age groups
  • Sexes
  • Standard and substandard risk classes
  • Individuals with chronic conditions

This consistency positions RHR as more than a supplementary data point. It is a robust, independent factor that captures dimensions of risk not fully reflected in traditional metrics.

In fact, RGA findings suggest that RHR can outperform total cholesterol as a predictor of mortality and may substitute for BMI without meaningful loss of predictive accuracy. These findings challenge long-standing underwriting hierarchies and open the door to recalibrated risk models.

Why RHR captures what traditional metrics may miss

From a physiological perspective, RHR acts as a proxy for several underlying health dimensions, including cardiovascular fitness, autonomic nervous system function, and overall metabolic health. These attributes are not always fully captured by standard underwriting variables.

As a result, RHR provides incremental insight, helping underwriters identify hidden or emerging risks that might otherwise remain undetected.

Equally important is its practicality. RHR is:

  • Non-invasive and easy to measure
  • Routinely recorded in electronic health records
  • Available through medical exams and ECGs
  • Increasingly accessible through wearable devices and smartphones

Advances in photoplethysmography technology have further supported its reliability, demonstrating strong agreement with clinical-grade measurements.

Together, these characteristics make RHR predictive and operationally viable at scale.

From research to real-world application

The shift from academic insight to underwriting practice is already underway. As insurers integrate digital health data into workflows, attention is shifting toward maximizing the value of existing information rather than simply expanding data volume.

Within this context, RHR offers a compelling use case. RGA has begun incorporating RHR into underwriting decisions, including its integration into a facultative underwriting platform designed for complex cases.

This integration enables underwriters to apply evidence-based insights in real time, enhancing consistency and decision quality without introducing additional complexity.

Practical applications of RHR in underwriting include:

  • Refining preferred versus standard classifications
  • Identifying favorable risk within traditionally substandard cases
  • Supporting more proportionate evidence requirements

For example, an applicant flagged as higher risk based on conventional metrics may demonstrate a more favorable RHR profile, enabling a more nuanced – and potentially more competitive – offer.

Strategic implications for insurers

The emergence of RHR as a key underwriting variable has broader implications at the enterprise level.

  • It reinforces the importance of reexamining existing data. In many cases, valuable signals are already available but underused. Unlocking their potential can lead to meaningful improvements in risk selection without significant operational investment.
  • It highlights the growing convergence between underwriting and digital health ecosystems. As wearable devices and remote monitoring tools become more prevalent, the availability of continuous biometric data will only increase. RHR is well positioned to serve as a foundational metric in this evolving landscape.
  • It underscores the need for adaptive underwriting frameworks. Static guidelines may fail to capture emerging sources of insight. Incorporating dynamic, evidence-based metrics such as RHR can help ensure that underwriting remains aligned with real-world risk.
Conclusion: Keeping the industry's finger on the pulse

The case for integrating resting heart rate into underwriting is no longer theoretical. The evidence is robust, the data is accessible, and the operational pathways are clear.

As underwriting continues to evolve, the ability to extract deeper insight from simple metrics will become increasingly valuable. RHR exemplifies this shift, offering a blend of predictive strength, practical accessibility, and strategic relevance.

For insurers, the opportunity is twofold: improve mortality risk assessment while enhancing efficiency and customer experience.

By leveraging RHR more effectively, organizations can move toward more precise pricing, better risk differentiation, and ultimately stronger portfolio performance.

Co-Authors:

Dr. John J. Lefebre - Vice President and Senior Technical Global Medical Director at RGA

John Cardus - Vice President, Head of Global Underwriting Philosophy and Education at RGA

Dr. Guizhou Hu - Vice President, Head of Risk Analytics, Global Underwriting, Claims, and Medical at RGA

Richard Russell - Vice President, Biometric Research, Global Research and Development at RGA

Dr. Nico van Zyl - Senior Vice President, Chief Medical Director at RGA

References

Kishan Bakrania

Profile picture for user KishanBakrania

Kishan Bakrania

Kishan Bakrania is a lead biometric data scientist with RGA's global research & development team. 

Prior to joining RGA in 2017, he earned a Ph.D. in epidemiology from the University of Leicester. He also holds an M.Sc. in medical statistics and a B.Sc. in mathematics from the University of Leicester.

'But the AI Told Me To Do It!'

As AI reshapes decision-making in insurance, the industry faces a critical question: Who holds liability when algorithms influence consequential outcomes?

AI Liability

I once wrote a presentation called: "It wasn't me. AI told me to do it!"

At the time, it was half joke, half warning.

Certainly feels less comical now.

Every organization adopting AI is moving toward the same uncomfortable question. When an AI-assisted decision causes harm, who carries the liability?

Clearly not the model. Models do not sign contracts, settle claims, bind risks, approve suppliers or accept regulatory responsibility. Maybe not the vendor, whose terms will usually say that you, the customer, remain responsible for how outputs are used. Not necessarily the employee, if they were using an approved tool in an approved process. Not necessarily the committee, if it says it relied on the employee's professional judgment.

Everybody, somebody and nobody.

This is not an anti-AI argument. I use AI. Most of us now do. In most cases it is harmless enough: drafting an email, summarizing a meeting, turning scrappy notes into something coherent. No sensible firm should build a heavy governance process around every prompt. That would be maddening and almost unenforceable.

But some uses are different.

If AI helps tidy up a launch invite, nobody cares. If it helps route a claim, draft an underwriting rationale, influence a supplier decision, interpret a compliance obligation or shape a board paper, then we are in different territory. We are talking about authority.

Insurance already understands authority. A junior underwriter cannot bind whatever they like. A claims handler has limits. A TPA works within a delegated claims authority. A coverholder operates within a binder. If something goes wrong, the questions are familiar: who had authority, what was the limit, was the decision escalated, and where is the evidence?

AI does not change those principles. It just makes them harder to see.

Take claims. An AI tool triages first notice of loss, summarizes the facts and recommends settlement within a low-value authority band. A handler reviews the screen and clicks through. Months later, a pattern emerges: the tool has been routing a class of claims too generously, too harshly, or inconsistently with the carrier's authority schedule.

At that point, the question is not simply whether the model was accurate. It is whether the settlement sat within authority, who accepted it, whether the handler actually reviewed it, and whether the firm can produce a record created at the time rather than a reconstruction after the complaint lands.

The same issue appears in delegated underwriting. An MGA uses AI to draft endorsements, referrals or risk summaries. The final document may still pass through a human. But did the output stay within binder authority? Did the right person approve it? Could a coverholder audit see the trail without piecing it together from emails and meeting notes?

These are not exotic technology questions. They are ordinary insurance questions, just wearing new clothes.

The problem for underwriters is that today's AI conversation is still too blunt. A proposal form might ask, "Do you use AI?" The insured says yes. Another insured says yes. Both attach an AI policy. On paper, they look broadly similar.

But they may be completely different risks.

One firm may let staff paste AI-generated analysis straight into consequential decisions with little more than a policy telling them to be careful. Another may classify the decision, check the user's authority, require escalation, capture sign-off and preserve the evidence. Those firms should not be priced as though they are the same.

At the moment, they might be.

This is because a policy is not proof. Training is not proof. A statement that "humans remain accountable" is useful, but only if you can identify the human, the decision, the authority and the record.

The missing artefact is a decision record.

For an AI-assisted decision that matters, an insurer should be able to ask: who requested the output, what was it used for, did the person have authority, was it escalated where needed, who accepted responsibility, and can the firm prove all this without reverse-engineering the story later?

That last part matters. After a loss, everyone becomes a process expert. People remember the governance policy. They remember the meeting. They remember the human in the loop. But insurance does not work on vibes. It works on evidence.

The answer, in my view, is not more slogans about responsible AI. It is the boring stuff insurance has always understood: authority, escalation, sign-off and evidence.

The 95% of routine AI use should stay fast. Let people summarize, draft and explore. But the consequential minority needs a different track. If an output is going to move money, affect a customer, change a risk position, influence a regulatory judgment or commit the firm, someone has to own it. Not in theory. Not in a policy. In the record.

"It wasn't me. AI told me to do it" may work as a joke in a presentation. It will not work in a claim file.

The firms that can show who made the decision, who had authority and what evidence exists will look different from the firms that cannot. At some point, insurers will price that difference.

The only question is whether they do it before the first major AI-accountability claim forces the issue.