AI can estimate risk, retrieve policy terms and help a claims handler assemble evidence. It can also reproduce historic exclusion, infer sensitive traits from proxies or turn a weak correlation into a higher premium. Insurance decisions need more than a model card: they need accountable product, conduct, data and claims controls.
This guide reflects UK sources available on 31 July 2026 and focuses on UK retail insurance. Commercial and wholesale insurance, Lloyd’s market participants, life and health products, intermediaries and PRA-regulated firms have different or additional requirements. Firms should establish their perimeter and obtain legal, actuarial and regulatory advice.
Existing rules still govern AI
The FCA said in its June 2026 AI engagement update-services-approach) that it did not plan a separate set of AI regulations, relying on existing frameworks including the Consumer Duty, Senior Managers and Certification Regime, governance and controls. “No new AI rule” does not mean no accountability.
The Consumer Duty requires firms to act to deliver good outcomes for retail customers, act in good faith, avoid foreseeable harm and support customers in pursuing financial objectives. The four outcomes cover products and services, price and value, consumer understanding and support.
Insurance rules were simplified during 2026. The FCA’s CP26/22 was still open at the cutoff and must not be treated as final policy. Teams should use the Handbook in force for the relevant date and product. For example, ICOBS 5.1, viewed as of 27 July 2026, says firms should take reasonable steps so a customer buys a policy under which they are eligible to claim benefits.
Inventory decisions and their consequences
Map every model, rule and external score that affects a person or policy. Include quotation, eligibility, price, fraud referral, claim triage, settlement, renewal, cancellation, support and complaint handling. A “workflow model” can be consequential if it repeatedly delays one group’s claims.
| Decision | Primary harm | Required evidence |
|---|---|---|
| Product eligibility | Customer buys unusable cover | Current terms, questions and verified answers |
| Underwriting acceptance | Unfair exclusion or wrong risk | Approved factors, source and rationale |
| Premium | Unjustified differential or poor value | Risk evidence, cost and product-value assessment |
| Fraud referral | Delay, stigma or investigation burden | Case indicators, uncertainty and review |
| Claim outcome | Incorrect rejection or underpayment | Policy version, facts and calculation |
| Support routing | Vulnerable customer cannot progress | Need, urgency and accessible alternative |
Record whether the system recommends, ranks, routes or decides; the data it uses; the accountable owner; review rights; fallback; monitoring and customer explanation. Do not label a process “human in the loop” if the handler sees only a score and is measured on agreement.
Our UK insurance AI and claims guide provides a sector overview. This article concentrates on the operating controls that make a model challengeable.
Establish a model-risk lifecycle
Before development, write the intended use, excluded use, target population, prediction horizon and decision pathway. Identify the economic and customer harm from false positives and false negatives. A claims severity model and a fraud model require different thresholds and testing.
Separate ownership:
- business owner defines the decision and customer outcome;
- actuarial or technical owner develops and documents the model;
- data owner approves sources and quality;
- independent validation challenges design and performance;
- conduct and compliance assess customer impact;
- privacy and equality specialists review personal-data and discrimination risk;
- senior management accepts residual risk.
Maintain an inventory of model, rules, prompts, data, versions, dependencies and material changes. Validate before use, periodically and after drift, product change or supplier update. Use a simple, explainable baseline as a challenger. Complexity must demonstrate incremental value after cost and harm.
The PRA’s 2025/26 annual report discusses AI roundtables in the context of model-risk expectations and notes model drift in general-insurance internal models. SS1/23 is a supervisory statement for banks, not a universal insurance rule; insurers should not claim compliance with it merely because they borrowed model-risk practices.
Govern data and proxy risk
Create a data register showing source, collection purpose, lawful basis, field meaning, coverage, missingness, retention, licence, refresh and permitted decision. Test third-party and inferred data with the same rigour as internal data. A vendor score can hide location, device or behavioural proxies.
Removing protected-characteristic fields does not prove fairness. Postcode, occupation, name, credit behaviour and device data can correlate with age, race, disability or other characteristics. Test outcomes and errors across lawful monitoring groups with specialist advice. Consider intersectional patterns and small cohorts without exposing individuals.
The ICO’s AI fairness, bias and discrimination guidance distinguishes data-protection fairness from statistical definitions and warns that simply removing sensitive attributes may not address discrimination. If special-category data is used to test fairness, identify an appropriate condition and strict separation from live decisioning.
Permit customers and staff to correct material source data. Monitor stale addresses, coding errors, identity merges and missing accessibility needs. Keep the exact feature snapshot used for each consequential outcome.
Meaningful review and explanation
Design review around the actual policy and evidence. A handler should see:
- the proposed outcome and uncertainty;
- the customer facts and their sources;
- the policy wording and version;
- model factors and known limitations;
- counter-evidence and alternative outcomes;
- vulnerability or communication adjustments;
- authority, deadline and escalation route.
Provide enough time and authority to disagree. Track overrides in both directions and investigate systematic agreement, which may indicate automation bias. High-impact rejections, cancellations and suspected fraud should receive risk-based second review.
The Data (Use and Access) Act changed the UK automated-decision framework. The ICO’s summary of data-protection changes says meaningful human involvement and contest safeguards remain important, while special-category restrictions continue. Final updated ICO guidance was not yet published at this cutoff; firms should check the current position before implementation.
Customer explanations should state the main information and rules relevant to their case in clear language, the result, how to correct data and how to challenge. Do not expose fraud controls or intellectual property unnecessarily, but do not use security as a blanket reason for an unintelligible decision.
Claims are the product in use
The FCA’s 2025 home and travel claims review found weaknesses in outsourced oversight, management information, customer communication and vulnerability handling. It emphasised consistent customer outcomes throughout claims.
AI can summarise chronology, retrieve terms or identify missing documents. It should not rewrite claimant evidence, infer dishonesty from language or close a claim because the customer stopped responding. Monitor walkaways, time to first useful action, communication gaps, partial settlements, complaints and reopenings.
Outsourcing does not transfer responsibility. Contracts with claims platforms, repair networks and model providers should cover service levels, data, audit, change, incident, continuity, deletion and cooperation with complaints. Firms need management information by product, supplier and customer cohort.
Our customer-service AI guide can support messaging, but urgent and vulnerable claimants require direct human routes.
Price, value and customer groups
A risk-reflective premium does not alone establish fair value. The FCA’s general-insurance value measures include claims frequency, acceptance, payouts and complaints. Its price-and-value good and poor practice, updated in July 2026, says cross-subsidies and differences between groups need evidence and each group must continue to receive fair value.
Test price and outcome together: acceptance, claim payout, service use, complaints, cancellation and retention. Do not optimise premium yield while ignoring customers unlikely to benefit. Review whether model-driven segmentation changes the target market or distribution.
Privacy, security and resilience
Underwriting and claims data may include health, biometrics, criminal allegations, finances and family relationships. Map lawful basis, special-category or criminal-data conditions, transparency, minimisation and retention. Complete a DPIA for likely high-risk profiling or significant decisions.
Limit access to case and purpose. Separate fairness-testing datasets, development data and live decisions. Contract for data provenance, subprocessors, transfers, training restrictions, deletion, security and model change notice.
Threat-model manipulated claims documents, compromised data brokers, prompt injection, model extraction and adversarial applications. The NCSC’s secure AI guidelines require secure design, deployment and operation. Keep deterministic policy and payment controls outside a generative model, and rehearse manual operation during provider failure.
Monitor outcomes, not average accuracy
Use a balanced scorecard:
- calibration, false-positive and false-negative rate by product and cohort;
- quote, eligibility and premium outcomes by customer group;
- claim acceptance, payout, duration, walkaway and reopening;
- complaint, Financial Ombudsman referral and overturn rate;
- reviewer override and second-review disagreement;
- vulnerability identification and adjustment completion;
- data correction, deletion and explanation requests;
- model drift, supplier change and security incidents.
Aggregate performance can hide a severe subgroup failure. Set tolerances before launch and link each breach to an owner, customer remedy and model action.
A measurable 90-day pilot
Days 1–30 — perimeter and baseline. Select one decision-support use case that does not make final claim or eligibility decisions. Map rules, products, data and suppliers. Build representative evaluation cohorts, complete DPIA and equality review, and baseline outcomes, overrides, complaints and processing time.
Days 31–60 — shadow challenge. Run the model without influencing customers. Compare it with current decisions and a simple baseline. Test data errors, vulnerable-customer cases, protected-group proxies, policy changes, adversarial documents and supplier outage. Independent validation documents limitations.
Days 61–90 — supervised assistance. Let trained handlers view evidence-linked recommendations for a bounded cohort. Require meaningful review and second review for adverse outcomes. Give customers the existing correction and complaint routes. Monitor daily and conduct a board or accountable-committee checkpoint.
Expand only when:
- every recommendation resolves to the decision-time data and policy version;
- no prohibited or unapproved factor enters underwriting or claims;
- cohort error and outcome measures remain within pre-agreed tolerances;
- reviewers can explain, disagree and escalate without target pressure;
- customer time improves without worse complaints, walkaways or overturns;
- supplier, security, privacy and continuity tests pass;
- an accountable senior manager accepts residual model and conduct risk.
Pause after unexplained drift, a material cohort disparity, loss of evidence, policy mismatch, inaccessible customer support or an untested supplier change. Disable automation after a wrongful rejection, payment or cancellation until root cause and remediation are complete. A model earns trust by making insurance decisions easier to challenge, not harder to see.
Primary sources checked
- AI in financial services: FCA approach, 8 June 2026
- About the Consumer Duty, FCA, February 2026
- ICOBS 5.1, FCA Handbook, version at 27 July 2026
- PRA Annual Report 2025/26, Bank of England
- AI fairness, bias and discrimination guidance, ICO
- Data-protection changes under the Data (Use and Access) Act, ICO
- Home and travel claims handling review, FCA, updated December 2025
- General insurance value measures, FCA, updated July 2026
- Price and Value Outcome: good and poor practice, FCA, updated 10 July 2026
- Guidelines for secure AI system development, NCSC



