Join our Newsletter — 33% off our NHI Course

Who should be accountable for compliance when insurers use external customer data and algorithms?

Accountability should sit with senior management, while the board or an appropriate board committee provides oversight. That split matters because compliance depends on enterprise-wide decisions about data sources, vendor selection, testing, monitoring, and remediation. Clear ownership also makes reporting more reliable, since the organisation must identify who is responsible for each requirement and what corrective action is underway.

Why accountability has to sit above the data and model teams

When insurers use external customer data and algorithms, compliance cannot be left to the teams buying the data feed or tuning the model. The accountable owner has to be high enough in the organisation to make decisions about purpose, lawful use, vendor selection, testing, monitoring, and remediation across business, legal, risk, and technology functions. That is why senior management owns accountability, with board-level oversight.

In practice, accountability should track the part of the organisation that can actually change the control environment. If a compliance issue depends on contract terms, third-party assurance, model validation, or how exceptions are handled, the accountable owner must be able to direct those changes and accept the residual risk.

What the board oversees versus what management executes

The board, or an appropriate board committee, should focus on whether the insurer has an effective control framework, receives reliable reporting, and escalates material issues quickly enough. That oversight is not the same as operational ownership. Senior management must ensure the policy is implemented, responsibilities are assigned, and evidence exists for each requirement the insurer claims to meet.

This split matters most when external data or algorithms introduce dependencies outside the insurer’s direct control. The board should challenge whether the organisation knows what data is being used, whether the vendor relationship is properly governed, and whether testing and monitoring are frequent enough to detect drift, errors, or non-compliant use before they become systemic.

  • Accountability should follow decision authority, not technical proximity.
  • Oversight should confirm that reporting is complete, timely, and actionable.
  • Execution should sit where remediation can actually be directed and verified.

Where insurers rely on third-party data or model outputs, the governance model should be strong enough to answer who approved the use, who owns the control, and who signs off when the risk profile changes.

Risk and Threat Considerations

External data and algorithms increase compliance exposure because the insurer may not fully control data quality, provenance, change management, or the behaviour of the vendor’s service. If accountability is diffuse, failures can persist unnoticed, especially when multiple teams assume someone else is validating the source, monitoring the output, or responding to a breach or model issue.

Failure mechanism: Weak ownership leads to gaps in vendor due diligence, contract controls, testing, monitoring, and remediation, so non-compliant data use or inaccurate automated decisions can continue without a clear escalation path.

Impact: The insurer can end up with unreliable reporting, unreviewed third-party exposure, and delayed corrective action, which increases regulatory, legal, and reputational risk.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the technical controls, while ISO/IEC 42001:2023 and DORA define the regulatory obligations.

Framework Control / Reference Relevance
ISO/IEC 42001:2023 4.1 — Understanding the organization and its context External algorithms affect organisational AI governance and compliance context.
Recommendation — Identify external AI dependencies and assign governance to the accountable management owner.
NIST CSF 2.0 GV.RM-01 — Risk management strategy established and maintained Accountability for third-party data and algorithms is a governance and risk ownership issue.
GV.OV-01 — Organizational context and risk management oversight Board oversight is needed for enterprise-wide control decisions and reporting.
Recommendation — Define management ownership for external-data and algorithm compliance risk. Use board oversight to challenge reporting quality, escalation, and remediation.
CIS Controls v8 15.1 — Manage Service Provider Inventory External data and algorithm use depends on governed third-party relationships.
6.1 — Establish an Asset Inventory and Control The insurer must know what external data and algorithmic assets are in use.
Recommendation — Maintain an owner-approved inventory of providers and their compliance obligations. Inventory external data feeds and algorithmic services with accountable owners.
NIST SP 800-63 5.1.1 — Identity Proofing and Registration Customer data use often depends on assurance that identity-related data handling is governed.
5.2.3 — Federation Assurance External data and algorithm integrations often rely on trusted third-party assertions.
Recommendation — Apply strict registration and assurance rules when external data influences customer decisions. Require documented trust and assurance for externally sourced assertions and data.
DORA 5 — ICT risk management Third-party data and algorithm dependencies create operational resilience and oversight obligations.
Recommendation — Assign senior accountability for ICT third-party risk and monitoring.

Practitioner Guidance

What to verify: Confirm that one named executive owns the compliance outcome for each external data source and algorithm, and that the board can see the control evidence behind that ownership. If no one can show who approves use, monitors exceptions, and closes findings, the accountability model is not working.

Decision rule: If the issue can affect customer outcomes, regulatory reporting, or third-party risk, treat it as a senior-management accountability item rather than a project-level control issue. Delegate execution, but keep ownership at the level that can force remediation across procurement, risk, legal, and technology.

Practitioner takeaway: The right test is not who built the data pipeline or the model, but who can be held responsible when the insurer cannot prove compliant use, reliable monitoring, and timely remediation.