AI Governance

Data governance is the first AI control for insurers

Insurers are deploying AI in underwriting, claims and service before information governance foundations are in place. Why trusted data, not model sophistication, is the first control.

By Jonas Osman AbdelghafourPublished July 14, 2026

Summary The argument is uncomfortable and largely correct: insurers are racing to deploy artificial intelligence across underwriting, claims and customer service while their information estates remain fragmented. Regulators are asking for transparency and explainability, and flawed inputs are converting AI programmes into compliance liabilities.

Source: Insurance Edge (Alastair Walker) · 14 July 2026 · read the original article

Why data quality becomes a regulatory problem An explainability requirement is, in practice, a lineage requirement. To explain why a model produced a particular outcome for a particular policyholder, a firm must be able to reconstruct the inputs that were available at the time of the decision, the version of the model that ran, and the transformations applied between source system and feature. Few legacy insurance estates can do this without manual reconstruction.

When data sits across disconnected policy administration, claims and CRM systems with inconsistent definitions, the model inherits every one of those inconsistencies. The failure then presents as a model failure — unstable outputs, unexplained variation between cohorts — when the root cause is upstream.

The controls that precede model controls - A data catalogue covering the sources that feed customer-affecting models, with owners and definitions - Lineage sufficient to reproduce a decision, including model version and feature values as at the decision date - Quality thresholds and monitoring on the specific fields that drive material decisions, not on the estate as a whole - Retention and access rules aligned to privacy obligations, since AI use frequently expands the population of people who can query personal data - Change control between source systems and model inputs, so an upstream schema change does not silently alter model behaviour

Sequencing an AI programme realistically The practical sequence is to classify use cases by decision impact, then remediate data only for the high-impact set rather than attempting an enterprise-wide clean-up. A pricing or claims-decisioning model justifies full lineage and monitoring. A drafting assistant with human sign-off does not, provided the human review is genuine and recorded.

This triage is also what makes the programme defensible in a supervisory conversation: the firm can show it has spent its control budget where customer outcomes are affected. The UK Financial Conduct Authority has signalled that AI will reshape financial services by 2030, and the direction of travel in conduct supervision is toward outcome evidence rather than policy documents.

Methodology and limitations This piece summarises a trade commentary as at the date shown and links to the original. It describes general control practice rather than the requirements of any single regulator, and firms should confirm obligations against the rules applicable in their jurisdictions.

Related reading See [Insurance Risk](/expertise/insurance-risk), [Governance, Risk and Compliance](/expertise/grc), [Regulatory Compliance](/expertise/regulatory-compliance) and the overview in [AI governance in insurance and banking](/insights/ai-governance-insurance-banking-2026).

Frequently asked questions

Why data quality becomes a regulatory problem?

An explainability requirement is, in practice, a lineage requirement. To explain why a model produced a particular outcome for a particular policyholder, a firm must be able to reconstruct the inputs that were available at the time of the decision, the version of the model that ran, and the transformations applied between source system and feature. Few legacy insurance estates can do this without manual reconstruction.

What should risk leaders know about sequencing an AI programme realistically?

The practical sequence is to classify use cases by decision impact, then remediate data only for the high-impact set rather than attempting an enterprise-wide clean-up. A pricing or claims-decisioning model justifies full lineage and monitoring. A drafting assistant with human sign-off does not, provided the human review is genuine and recorded.

What should risk leaders know about methodology and limitations?

This piece summarises a trade commentary as at the date shown and links to the original. It describes general control practice rather than the requirements of any single regulator, and firms should confirm obligations against the rules applicable in their jurisdictions.

What should risk leaders know about related reading?

See [Insurance Risk](/expertise/insurance-risk), [Governance, Risk and Compliance](/expertise/grc), [Regulatory Compliance](/expertise/regulatory-compliance) and the overview in [AI governance in insurance and banking](/insights/ai-governance-insurance-banking-2026).