Join our Newsletter — 33% off our NHI Course

How should insurers implement governance for external data and predictive models in underwriting?

Insurers should treat external data and predictive models as governed business systems, not ad hoc analytics. The strongest approach is a risk-based framework with board oversight, senior management accountability, written policies for design, testing, deployment, and ongoing monitoring, plus a documented inventory of data sources and models. That structure helps teams evidence fairness, control change, and respond consistently to complaints and regulatory review.

How underwriting governance should handle external data and model inputs

External data and predictive models should be governed as part of the underwriting decision chain, with clear ownership for sourcing, approval, change control, and periodic review. The key governance question is whether a given data source or model is sufficiently understood, documented, tested, and monitored to support creditable underwriting decisions, especially when it can influence eligibility, pricing, or exceptions.

That means insurers need to know where each input came from, what it is intended to measure, how it is validated, and when it must be re-assessed. A useful Ultimate Guide to NHIs principle applies here: treat externally supplied inputs as governed dependencies, not informal conveniences, because change without inventory and ownership quickly turns into blind trust.

In practice, governance works best when it distinguishes between the business purpose of a source, the quality of the source, and the decision impact of the model that consumes it. That separation helps underwriters, compliance teams, and model risk functions challenge whether a source is appropriate for the population being underwritten, whether its limitations are acceptable, and whether the resulting outputs are stable enough for production use.

Controls that make underwriting models auditable

The most important controls are a documented inventory, formal approvals, testing before deployment, and ongoing monitoring after release. The inventory should cover both external data feeds and predictive models, because model governance is weakened if teams can explain the model but not the provenance of the inputs, or can list the inputs but not the decision logic that transforms them.

Testing should focus on performance, stability, and fairness outcomes that matter to underwriting, not just technical accuracy. That includes checking whether the model behaves consistently across time, whether data drift changes the decision pattern, and whether the output can be explained in a way that supports complaint handling, audit review, and regulator challenge.

Ongoing monitoring is where many programmes fail. A model that was acceptable at launch can become unreliable when the external source changes definition, coverage, refresh cadence, or scoring behaviour. That is why governance needs a defined trigger process for revalidation, rollback, or suspension when the data or the model no longer matches the approved use case. For insurers managing broader identity and access controls around governed systems, NHIMG’s Lifecycle Processes for Managing NHIs is a useful reference point for lifecycle discipline, and the same operating logic applies here.

What good underwriting governance looks like under regulatory scrutiny

Good governance produces evidence, not just intent. Teams should be able to show who approved the source or model, what tests were run, what thresholds were accepted, what changed since the last review, and how exceptions are escalated. In regulated underwriting environments, that evidence is often more important than the model itself because it shows that the insurer can explain and defend the decision process.

External data also introduces third-party and supply-chain style risk, because the insurer may depend on a provider it does not control. Governance therefore needs contractual and operational expectations for notice of material changes, data quality issues, and downtime, along with a process for replacing a source if it stops meeting policy requirements. Where governance must support audit and complaint response, NHIMG’s Regulatory and Audit Perspectives provides a useful way to think about evidence retention and reviewability.

For practitioner teams, the practical test is simple: if the source or model changed tomorrow, could the insurer prove what changed, who approved it, and whether the change should affect underwriting outcomes? If the answer is no, the governance model is not yet mature enough for production reliance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST AI RMF, NIST CSF 2.0, NIST SP 800-63 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST AI RMF GOVERN — Govern Underwriting model governance needs accountable oversight and documented risk ownership.
MAP — Map Insurers must inventory data sources, model use, and decision impacts before approval.
MEASURE — Measure Ongoing monitoring is needed to detect drift, fairness issues, and changing model performance.
Recommendation — Assign accountable oversight for external data and predictive model governance. Map external data sources, model uses, and decision impacts before deployment. Measure drift, performance, and fairness after release and revalidate on change.
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy A formal governance strategy is needed for business-critical underwriting inputs.
GV.PO-01 — Policies, Processes, and Procedures Written policies are required for design, testing, deployment, and monitoring controls.
ID.AM-01 — Asset Inventory A complete inventory of external data feeds and models is core to accountability.
Recommendation — Set a risk management strategy for underwriting data and models. Define written policies for model and external data lifecycle controls. Maintain an inventory of all external data feeds and predictive models.
NIST SP 800-63 IAL — Identity Proofing and Assurance Level Underwriting often relies on assurance that data about a person or entity is fit for use.
AAL — Authenticator Assurance Level Where underwriting workflows depend on authenticated access to data sources, assurance matters.
Recommendation — Set assurance expectations for externally sourced identity-related attributes. Use assurance requirements for access to underwriting data sources and models.
CIS Controls v8 5.1 — Establish and Maintain an Inventory of Enterprise Assets Inventory discipline is essential for tracking governed data sources and models.
8.1 — Establish and Maintain a Data Management Process Data management controls support sourcing, quality, retention, and accountability.
Recommendation — Inventory all external data sources and predictive models under governance. Define a data management process for external underwriting inputs.

Practitioner Guidance

What to prioritise: Start with the highest-impact sources and models, meaning the ones that influence eligibility, price, referral, or decline decisions. Those are the systems that need the strongest inventory, approval, and monitoring discipline first.

What to verify: Require evidence that each external source has an owner, a defined business purpose, a documented test record, and a revalidation trigger. If any of those elements are missing, treat the input as ungoverned rather than merely undocumented.

Decision rule: If a model or data feed cannot be explained well enough to support audit, complaint handling, and regulatory challenge, it should not be treated as a routine underwriting tool. Move it into a restricted review state until the gaps are closed.

Practitioner takeaway: The objective is not to eliminate external data or predictive modelling, it is to make every underwriting dependency governable, reviewable, and defensible before it affects customer outcomes.