Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security How should insurers use AI and richer data…
Cyber Security

How should insurers use AI and richer data sources to improve risk pricing without weakening governance?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Cyber Security

Insurers should pair AI models with stronger data governance, not treat AI as a shortcut around it. The article argues that richer structured data, unstructured claims content, and third party signals can improve pricing and reserving, but only when the pipeline is auditable, bias tested, and monitored across the full model lifecycle. Governance turns new data into an actuarial edge.

Why richer data helps pricing only when governance is stronger

For insurers, better pricing comes from using more predictive evidence, not from relaxing the discipline around how that evidence is sourced, validated, and explained. AI can help bring structured policy data, claims narratives, adjuster notes, telematics, imagery, and external signals into one modelling pipeline, but each data class changes the governance burden. The key test is whether the added signal improves discrimination without undermining fairness, traceability, or model accountability.

That is why the central design choice is not “AI or governance,” but whether the model stack can support both model performance and defensible decision-making. If the insurer cannot show where a feature came from, how it was transformed, and when it was last validated, the richer dataset may improve lift while weakening trust in the pricing decision.

A useful reference point is that governance failures in identity and secret handling often create hidden exposure before they create obvious incidents. NHI Mgmt Group reports that Only 5.7% of organisations have full visibility into their service accounts. The lesson translates well to insurance AI, if the pipeline cannot see and control its inputs, it cannot reliably govern its outputs.

How to structure the data and model pipeline

The practical approach is to treat data enrichment as a governed lifecycle, not a one-time modelling exercise. That means classifying sources, setting usage rules, tracking transformations, and preserving lineage from source system to underwriting or reserving output. Unstructured claims text and third-party signals can be valuable, but they need controls for quality, consent, duplication, drift, and explainability so that the model does not absorb noise as insight.

  • Define approved source classes and prohibited features before model development begins.
  • Retain lineage for every feature that materially affects price, reserve, or referral decisions.
  • Test for bias, proxy effects, and instability across segments before production use.
  • Monitor post-deployment drift, override rates, and exception handling as part of ongoing model governance.
  • Document when human review must supersede model output, especially for edge cases or sparse data.

Insurers should also be explicit about the role of AI in the workflow. AI can assist feature extraction, triage, summarisation, and anomaly detection, but pricing authority still needs a clear owner. That ownership matters because actuarial decisions are not just statistical outputs, they are regulated business judgments that must remain explainable to internal governance, auditors, and in some cases supervisors.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST AI RMF, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST AI RMFGOVERN — AI GovernanceInsurers need accountable AI governance for pricing models using richer data.
MAP — MapModel and data use cases must be inventoried and traced to business context.
MEASURE — MeasureBias, drift, and performance need ongoing measurement across the model lifecycle.
Recommendation — Establish AI governance roles, review gates, and accountability for pricing-model use. Map pricing models, inputs, and downstream decisions to their business purpose and impact. Measure model bias, robustness, and drift before and after deployment.
ISO/IEC 42001:2023A.5 — AI policyA pricing AI programme needs policy and responsibility for governed use of data.
A.7 — AI system operationOperational controls are needed to manage lifecycle, monitoring, and change in AI systems.
Recommendation — Define AI policy, approval, and accountability for data-rich pricing use cases. Operate pricing AI with monitored lifecycle controls and documented change management.
NIST CSF 2.0GV.RM — Risk Management StrategyPricing AI should fit a defined risk strategy and governance model.
Recommendation — Align AI pricing use with explicit risk tolerance and governance oversight.
CIS Controls v814 — Security Awareness and Skills TrainingTeams building and reviewing AI pricing need competency in data handling and control use.
Recommendation — Train data, actuarial, and risk teams on secure and governed AI model practices.

Practitioner Guidance

What to verify: Before trusting a model improvement, verify that each new data source has a documented purpose, a control owner, and a reviewable lineage path. If the source cannot be explained to an auditor or challenged by a peer reviewer, it is not ready for pricing use.

Decision rule: If a signal improves pricing but cannot be tested for bias, drift, or proxy behaviour, treat it as a candidate for research, not production. If it can be measured and defended, move it into a controlled pilot with narrow scope and explicit rollback criteria.

What practitioners underestimate: The hardest part is usually not model accuracy, it is evidence quality. Richer data often expands the set of parties, systems, and transformations involved, which increases the chance that governance breaks at the joins rather than in the model itself.

Practitioner takeaway: Use AI to broaden actuarial insight, but keep every material feature, transformation, and override inside a governance model that can be audited, challenged, and repeated.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org