Insurance

AI strategy for insurers: a board guide

An insurance board does not need to know how a model is built. It needs to know what the model decides, who answers for it, and what the GFSC will ask when it goes wrong.

By Zakir Hoosen, Director, Fuzzelogic Solutions. Board-level guidance in plain English.

An insurance director does not need to understand the maths behind a pricing model. The director needs to understand what the model changes in the business, who owns it when a customer complains, and whether the regulator will accept the answer. That is the conversation that matters, and most AI strategies skip it.

This guide covers what an insurance board should demand before approving AI, what the GFSC expects on the Island, and where the real cost of getting it wrong sits.

Insurance is not like other industries

Insurance runs on data. It always has. Underwriting is pattern recognition. Claims handling is judgement based on evidence. Pricing is probability. AI fits the business. But fitting the business and being ready for AI are different things.

The difference is governance. An underwriting model that adjusts prices without anyone tracking why is a problem the moment a customer asks why their premium went up, or the moment the GFSC asks the same question. The model might be more accurate than the old one. Accuracy is not the point. Explainability is.

For Isle of Man insurers, the GFSC is the relevant regulator, and the direction mirrors the JFSC. Boards are accountable. AI governance is not optional. The regulator expects insurers to be able to explain automated decisions, to maintain human oversight on material decisions, and to prove the data feeding the models is reliable.

"21% of organisations have no AI governance at all, and governance and risk is the fastest growing barrier to adoption."

Source: Deloitte, State of AI in the Enterprise

In insurance, that number should alarm any board. The claims process, the pricing engine, the fraud detection system, each of these touches customers directly. Each one needs governance.

Where AI already sits in insurers

Most Isle of Man insurers already use AI without calling it that. Claims triage rules that route cases. Fraud scoring that flags unusual claims. Pricing models that blend historical data with external signals. Customer service tools that handle routine queries.

The question is not whether AI exists in the business. It is whether the board has seen it, classified it, and decided who governs each piece. Fuzzelogic finds that most boards have not. The technology sits under the radar, maintained by a small team, with no formal oversight and no one appointed to answer if it goes wrong.

"Ninety percent of companies have launched some flavor of digital transformation, and only a third of the expected revenue benefits, on average, have been realized."

Source: McKinsey, Rewired to Outcompete

The two thirds that did not deliver often share a pattern. The technology worked. The process change around it did not. In insurance, that means the underwriter still overrides the model without logging why. The claims handler still makes decisions based on habit rather than the system output. The model runs, but the business does not follow it.

The five tests for insurance AI

Fuzzelogic works with a definition of AI-ready that applies to any insurance AI strategy. Run them against any proposal and the gaps show up.

  1. Reachable. Can the underwriting or claims data the model needs actually be found when it needs it?
  2. Trustworthy. Do you know the data is accurate, current, and complete across all policies?
  3. Explainable. Can someone explain why the model priced a policy or flagged a claim in words a customer or the GFSC would accept?
  4. Changeable. Can the model be updated when the market, the risk profile, or the regulation changes?
  5. Governed. Has the board decided what the model may and may not do?

If the strategy cannot answer all five, it needs more work before a board vote. The gaps are not technology problems. They are governance and data problems, and they are the board's responsibility.

What the GFSC expects

The GFSC has not issued AI-specific rules in the same detail as the JFSC. But the expectation is clear. Insurers must manage operational risk. AI is operational risk. The board must understand the systems that make material decisions, and it must ensure those systems are controlled.

That means documentation. Not technical documentation for engineers. Board-level documentation that explains what the AI does, what data it uses, who maintains it, what the failure modes are, and what human oversight exists. If the insurer cannot produce that document today, it is not ready for board-level AI.

Isle of Man insurers that operate across borders face an additional burden. Cross-border policies may touch jurisdictions with stricter AI requirements. The strategy must account for the most demanding regulator, not the most convenient one.

The 10-20-70 rule in insurance

BCG publishes a finding that every insurance board should know. Ten percent of AI success is the algorithm. Twenty percent is the technology and the data. Seventy percent is the process change inside the business.

"The 10-20-70 rule: 10% algorithms, 20% technology and data, 70% process change."

Source: BCG

In insurance, the seventy percent is where most projects die. The pricing model works in the test environment. Moving it into the live business means retraining underwriters to trust it, adjusting commission structures that reward the wrong behaviour, and rewriting the claims handbook. That takes months, not weeks. It takes executive sponsorship, not a technology budget.

For Isle of Man insurers, the talent question is real. The Island does not have a deep pool of AI specialists. The strategy must plan for who inside the business will own the system after the consultants leave. If the answer is nobody, the strategy is not finished.

The honest assessment

Here is what most consultants will not tell an insurance board. Some processes should not have AI near them. Complex claims that require empathy and judgement. Reinsurance arrangements where the relationship matters more than the model. High-value client negotiations where a human must read the room.

If the honest answer is that AI should not touch a process, Fuzzelogic puts it in writing rather than build it anyway. That honesty is worth more than a system that runs but no one trusts.

The board should ask three questions before any AI vote. Who owns this? What does the GFSC need to see? What is the cost of being wrong versus the cost of standing still?

"61% of CEOs say boards are rushing AI transformation, and around 40% of boards lack an informed view of how AI changes growth strategy."

Source: BCG, CEOs and Boards are aligned on AI in theory but divided in practice

Rushing without that information is the most expensive thing an insurance board can do.

Start with the assessment. Two to four weeks, fixed price, and you own the verdict and the roadmap whether or not we build any of it. When you are ready to talk AI, call Fuzzelogic Solutions and ask for Zak. www.FuzzelogicSolutions.com | info@FuzzelogicSolutions.com | +44 (0)1624 618950

Start with the assessment

Two to four weeks, fixed price, and you own the verdict and the roadmap whether or not we build any of it.

Get in touch

When you are ready to talk AI, call Fuzzelogic Solutions and ask for Zak.

www.FuzzelogicSolutions.com | info@FuzzelogicSolutions.com | +44 (0)1624 618950