Insurance AI Compliance

AI in underwriting, pricing, and claims — classified as access-to-essential-services AI under the EU AI Act

Discriminatory pricing, opaque claims denial, and proxy variables in insurance AI are the patterns regulators and plaintiffs are building cases around. The early-mover audit advantage is still available — but the window is narrowing.

Insurance at a glance iDharma
High-risk Directly in scope
Insurance underwriting and pricing AI is explicitly named in EU AI Act Annex III — access to essential services
Pre-enf. Window is open
No headline insurance-AI fine issued yet — early-mover audit advantage still available
Aug 2026 Compliance deadline
EU AI Act high-risk obligations take effect — verify current date with the EU AI Office
Measured against NIST AI RMF ISO/IEC 42001 EU AI Act HIPAA SOC 2 India DPDP

What we audit

AI systems in scope for Insurance

Every system below is covered in a standard iDharma engagement. Complex or multi-system deployments are scoped on request.

Underwriting AI

Risk classification, eligibility decisions, and pricing models — proxy discrimination testing, explainability, and Annex III conformity documentation.

Claims decision AI

Automated claims approval, denial, and fraud-scoring models — accuracy benchmarking, false-positive analysis, and human oversight verification.

Pricing algorithms

Dynamic and personalised pricing AI — differential pricing by protected class, regulatory rate-filing alignment, and proxy variable audit.

Fraud detection AI

Models flagging claims for investigation — demographic performance disparities, accuracy on sub-groups, and documentation of the escalation process.

Regulatory frameworks

What we audit against

Every iDharma Insurance engagement maps simultaneously against the frameworks below — producing one gap register, not three separate reports.

EU AI Act — Annex III (Essential Services)

Insurance AI used in underwriting, pricing, and claims is classified as high-risk access-to-essential-services AI. Conformity assessment, human oversight mechanisms, and technical documentation are mandatory.

NY DFS Circular Letter No. 2024-5

Requires insurers to assess AI and external data sources for unfair discrimination. Applies to all personal lines insurers writing NY business.

Colorado SB 21-169

Prohibits insurers from using external data, algorithms, or predictive models that unfairly discriminate on the basis of race, colour, national or ethnic origin, religion, or sex.

Our methodology

How an iDharma audit works

We do not accept vendor documentation as evidence, and we do not produce checkbox compliance reports. Every audit gives you a named auditor, a cited methodology, and a straight answer on where your AI stands.

01

We test every underwriting and pricing feature for proxy discrimination — including geodemographic proxies, behavioural data, and third-party data sources.

02

We evaluate claims AI for demographic performance disparities — a fraud model with a higher false-positive rate for one demographic is a regulatory liability, not just a model quality issue.

03

We verify that "the vendor handles compliance" is not being treated as a defence — it has not succeeded in any EU enforcement action we have reviewed.

04

We produce a conformity assessment package structured for the EU AI Act Annex III requirements — so you are not scrambling to produce documentation when the first enforcement action is announced in your sector.

Get started

Using AI in underwriting, pricing, or claims?

The enforcement window for insurance AI is still open. Start with the free Risk Snapshot to understand your exposure before the first major fine is issued.

Your situation

“AI is already making insurance decisions — with no independent proof it holds up.”

In 1–4 weeks

One prioritised gap register mapped to the frameworks you answer to — signed by a named auditor.

Scoped before you pay — nothing is charged until you approve what the engagement covers.