Data Governance and the Insurance Data Estate - Policy, Claims, Third-Party, Telematics, IoT, Satellite, Drone, Weather
Data governance is the substrate underneath every line of the AI program - the layer the chief actuary's ASOP-23 work product depends on, the layer Colorado Reg 10-1-1 ECDIS inventory documents, the layer the AM Best readiness composite's data-readiness category measures, the layer the chief AI officer's vendor scorecard tracks for upstream data flow, and the layer that fails first when the program runs into trouble. The 2026 insurance data estate at a rated carrier or specialty MGA includes policy data, claims data, third-party enrichments (LexisNexis, Verisk, ISO, Moody's RMS, AAIS, advisory-bureau experience), external behavioral data (credit attributes, payment patterns where permitted by state law), telematics streams (Cambridge Mobile Telematics, Octo, Arity), IoT sensor feeds (Notion, Roost, Hippo, Whisker-style commercial), satellite imagery (ICEYE SAR, Vexcel, EagleView, Planet, Maxar), drone-derived aerial imagery from commercial claims, and weather data (Athenium Analytics, DTN, Tomorrow.io, NOAA). The data council that supports the AI program is the cross-functional body that owns the policy, the inventory, the quality, the lineage, and the regulator-facing documentation across that estate. This lesson is the data governance discipline at L5: the estate map, the data council structure, the ECDIS inventory under Colorado Reg 10-1-1, the ASOP-23 alignment that protects the chief actuary's professional liability, the cross-functional integration with the seven-domain policy stack from Lesson 7, and the data-quality discipline that holds the AI program defensible at AM Best, AISET, and state DOI review.
The 2026 Insurance Data Estate Map
The data estate at a rated specialty commercial carrier divides into seven structural categories. Each category has a different data source, refresh cadence, retention requirement, privacy posture, and regulatory disclosure exposure.
Policy data. Policy admin system (Guidewire PolicyCenter, Duck Creek, Sapiens, Majesco) - application data, policy terms, premium, endorsements, billing. Refresh: real-time. Retention: 7-10 years post-cancellation typically. Privacy: GLBA Safeguards Rule, state privacy laws on personal data. Regulatory disclosure: state DOI rate filings reference policy-data populations.
Claims data. Claims admin system (Guidewire ClaimCenter, Five Sigma, Snapsheet, Sapiens) - FNOL, reserves, payments, closure outcomes, subrogation, litigation. Refresh: event-driven. Retention: 7-10 years post-closure for most lines; longer for product liability and asbestos. Privacy: GLBA, HIPAA for L&H. Regulatory disclosure: market-conduct exam scope.
Third-party enrichments. LexisNexis Risk Solutions (consumer-lines and L&H attributes), Verisk (claims history via ISO ClaimSearch, 360Value for property), ISO (advisory-bureau loss costs, advisory plans), Moody's RMS (cat modeling), AAIS (advisory-bureau alternative), advisory-bureau experience data. Refresh: nightly to monthly depending on vendor. Retention: contractual. Privacy: vendor flow-downs under §4. Regulatory disclosure: ECDIS inventory references third-party enrichments touching consumer-line decisions.
External behavioral data. Credit attributes (where state law permits insurance scoring), payment patterns, driving records (motor vehicle reports), public records, social-data attributes (carefully scoped under state and federal anti-discrimination posture). Refresh: triggered (at quote, at renewal) or periodic. Privacy: FCRA on consumer-reporting agencies. Regulatory disclosure: FCRA adverse-action workflow if these data influence adverse decisions; ECDIS inventory.
Telematics data. Cambridge Mobile Telematics (personal and commercial fleet), Octo Telematics, Arity (Allstate-affiliated), and carrier-platform-direct telematics. Refresh: continuous. Retention: 3-7 years typically. Privacy: GLBA, state telematics-specific guidance. Regulatory disclosure: telematics-driven rate filings include telematics methodology under Akur8 or internal pricing.
IoT sensor feeds. Water-leak (Notion, Roost), freeze (Notion, Roost), smoke and CO sensors, connected-property security (Kangaroo, SimpliSafe), smart-thermostat (Hippo partnerships), Whisker-style commercial property sensors. Refresh: continuous to event-driven. Privacy: GLBA, customer consent for sensor data flow. Regulatory disclosure: ECDIS inventory if used in consumer-line decisions; rate filings reference if sensor data feeds rate adequacy.
Satellite, drone, and weather. ICEYE SAR for flood, Vexcel and EagleView for property aerial, Planet and Maxar for visual imagery, drone-derived imagery from commercial claims handlers (e.g., for large-loss property), weather data from Athenium Analytics, DTN, Tomorrow.io, NOAA. Refresh: ranging from weekly orbital to event-driven post-event. Privacy: commercial property generally clean; residential satellite imagery requires state-law alignment. Regulatory disclosure: ASOP-23 data quality for any input to actuarial work; ASOP-38 for cat-model overlays.
The Data Council Structure and Charter
The data council is the cross-functional governance body that owns the estate. It is not the AI committee from Lesson 7 - the AI committee owns AI capability and the seven-domain policy stack; the data council owns the data layer that feeds the AI capability and several non-AI uses. The data council reports to the AI committee on AI-related data matters and reports separately to the enterprise risk committee on non-AI data matters.
Council membership: chaired by the Chief Data Officer; named members include Chief Actuary (for ASOP-23 alignment), Chief Information Security Officer (for data security and GLBA Safeguards Rule), Chief Compliance Officer (for ECDIS inventory and regulatory disclosure), Chief Privacy Officer or General Counsel privacy representative (for state privacy laws and HIPAA), Chief AI Officer (for AI-data integration), VP of Underwriting Data, VP of Claims Data, head of producer-facing data products, rotating line-of-business representatives. Quarterly full meetings, monthly working sessions on specific data domains (one month: third-party vendors; next month: telematics; next: ECDIS; next: cat-model data).
Council charter is part of the policy annex from Lesson 7. Charter includes scope, membership, decision rights, escalation path, meeting cadence, reporting destinations, and the explicit interface to the AI committee on AI-related decisions.
The ECDIS Inventory Under Colorado Reg 10-1-1
ECDIS - External Consumer Data and Information Sources - is the inventory Colorado Reg 10-1-1 requires for consumer-line insurance decisions (auto, health, life). The inventory enumerates every external data source used in covered decisions, with data lineage, quality assurance, fairness testing, and the carrier's governance posture on each source. The first compliance report is due July 1, 2026.
Sample ECDIS entry for a credit-attribute data source on personal auto: source vendor (e.g., LexisNexis), data product (insurance score), data flow (how it enters the underwriting decision), data quality assurance (vendor's certification, carrier's quality checks, ASOP-23 alignment), fairness testing (carrier's bias-testing methodology applied to this source, results, remediation), governance posture (FCRA workflow for adverse decisions influenced by this source, NY DFS Circular Letter 2024-7 proxy test compliance, Colorado SB 21-169 alignment, state-by-state allowability documented).
The ECDIS inventory is maintained by the data council with the Chief Data Officer and Chief Compliance Officer as joint owners. It refreshes quarterly with annual full review. The first July 1, 2026 compliance report is the public-facing artifact; the underlying inventory is the carrier's internal source of truth. Other states adopting similar disclosure regimes (Connecticut Bulletin MC-25-8, Nevada Bulletin 24-006, emerging guidance in California, Texas, Florida) will reference the same inventory; building it once for Colorado supports the multi-state regulatory expansion.
ASOP-23 Data Quality Alignment and the Chief Actuary
ASOP-23 (Data Quality) governs the actuary's responsibility for data inputs to actuarial work product - rate filings, reserve development, reserve adequacy, attribution methodologies. Every data source feeding actuarial work needs ASOP-23-compliant documentation: provenance, refresh cadence, missing-data handling, validation against ground truth where applicable, and the actuary's professional judgment on fitness for purpose.
The data council's role on ASOP-23: maintains the source-level documentation that the chief actuary references in actuarial work product. When the chief actuary signs a rate filing using Akur8's GLM/GBM trained on policy data plus third-party enrichments plus telematics, the chief actuary's ASOP-41 communications reference the underlying data quality discipline documented in the council's records. Without that discipline, the chief actuary's signature on the filing is contestable at DOI review or in subsequent rate-adequacy challenges.
Data Lineage and the AI Model Card Integration
Data lineage - documented path from raw data source through transformation, validation, and integration into the model - is non-negotiable at L5. Each AI model's model card (Domain 5 of the policy stack) references the data sources it consumes through their lineage paths; the algorithm inventory (Exhibit A artifact of the AISET response) references the data sources via the same lineage paths. Lineage integration ensures that when a data source's quality changes or a vendor relationship shifts, every downstream model's documentation surfaces the change automatically rather than requiring manual cross-referencing.
The lineage discipline matters operationally at three moments. First, model promotion: when a new line is being extended per Lesson 6's promotion process, the data-fabric work (step 2) confirms target-line data sources have lineage documentation before model retraining begins. Second, vendor change: when a third-party data source changes (vendor acquisition, contract amendment, data-product update), lineage shows every model affected and triggers downstream model-card refresh. Third, regulator inquiry: when a DOI examiner asks "what data influenced this decision," lineage produces the answer in minutes rather than weeks.
Telematics, IoT, Satellite - The Non-Traditional Data Discipline
Telematics, IoT, and satellite data introduce discipline patterns that traditional data governance often lacks. Continuous streams (telematics is real-time during the policy period) require different storage architecture, different sampling discipline, different retention policy. Sensor data (IoT) requires explicit customer consent under GLBA, state privacy laws, and platform-specific privacy notices; consent management is a data-council responsibility. Satellite imagery on residential property requires careful state-law alignment under CCPA/CPRA and similar; commercial property is generally cleaner but still requires vendor-flow-down documentation.
The data council's discipline on these non-traditional sources: explicit consent management (telematics, IoT) with documented opt-in flow; sampling discipline (continuous data sampled to actuarial-grade aggregates rather than streamed raw into rating models); retention by source type (telematics typically 3-7 years; IoT event data shorter; satellite imagery archival); cross-border posture (some satellite data crosses jurisdictions; some IoT vendors host outside US); vendor-flow-down on §4 conformance for the data-supplying vendor.
Cross-Functional Integration With the Seven-Domain Policy
The data council's work feeds five of the seven policy domains. Domain 1 (AI Usage) - data council certifies which data sources are approved for which use cases. Domain 2 (Third-Party AI) - data council reviews data-vendor relationships alongside AI-vendor relationships. Domain 3 (Data Governance) - data council owns this domain entirely. Domain 4 (Fairness) - data council provides the data-source bias-testing inputs that fairness pipeline consumes. Domain 5 (Monitoring and Validation) - data council's lineage discipline feeds the model card structure.
The data council does not own Domain 6 (Incident Response) or Domain 7 (Ethics and Conduct), but data-related incidents (data quality breach, third-party data outage, lineage failure) route through the incident-response runbook with data council coordination. Cross-functional integration matters because regulators read across domains - Colorado Reg 10-1-1 covers Domains 3, 4, 5; AISET covers all seven; state market-conduct exams cover the consumer-line data sources across Domains 1, 3, 4.
The Data-Readiness Score on the AM Best Readiness Composite
The AM Best readiness composite's data-readiness category (one of five categories) is scored 1-5 against documented criteria. A sample scoring rubric the L5 leader uses internally: 1 = ad-hoc data, no enterprise data fabric, no lineage; 2 = some enterprise data fabric, partial lineage on top-priority sources; 3 = enterprise data fabric with documented lineage on most sources, ECDIS inventory under development; 4 = full enterprise data fabric, lineage on all sources, ECDIS inventory current under Colorado Reg 10-1-1, data council operational with quarterly cadence, ASOP-23 alignment documented per source; 5 = all of 4 plus real-time enrichment, continuous quality monitoring with automated alerts, lineage integration with AI model cards, third-party vendor scorecard with §4 conformance current. Carriers progress 1 → 5 across the three-horizon program; H1 typically lands at 2-3, H2 at 3-4, H3 at 4-5.
Key Takeaways
- The 2026 insurance data estate covers seven structural categories: policy data, claims data, third-party enrichments, external behavioral data, telematics, IoT sensors, satellite/drone/weather. Each has different source, refresh, retention, privacy, and regulatory exposure.
- The data council is the cross-functional governance body owning the estate. Chaired by Chief Data Officer; members include Chief Actuary (ASOP-23), CISO, CCO, CPO/GC privacy, CAIO, VPs of UW and Claims Data. Quarterly full + monthly working sessions on specific data domains.
- ECDIS inventory under Colorado Reg 10-1-1 enumerates every external consumer data source used in covered decisions. First compliance report due July 1, 2026. Connecticut Bulletin MC-25-8, Nevada Bulletin 24-006, and emerging guidance in CA, TX, FL reference the same inventory structure.
- ASOP-23 (Data Quality) governs every data source feeding actuarial work product. Data council maintains the source-level documentation the chief actuary references; without that discipline, rate filings and reserve work are contestable at DOI review.
- Data lineage integration with AI model cards and algorithm inventory is non-negotiable. Operational moments: model promotion (lineage confirmed before retraining), vendor change (lineage triggers model-card refresh), regulator inquiry (lineage produces answer in minutes not weeks).
- Non-traditional data (telematics, IoT, satellite) requires consent management, sampling discipline, retention by source type, cross-border posture, and vendor §4 flow-downs. Continuous streams, sensor data, and orbital imagery each introduce discipline patterns traditional data governance often lacks.
- Data council feeds five of seven policy domains: AI Usage, Third-Party AI, Data Governance (owns entirely), Fairness, Monitoring and Validation. Incidents involving data route through Domain 6 with data council coordination.
- AM Best readiness composite data-readiness category scored 1-5 with carriers progressing across three horizons. H1 typically lands at 2-3, H2 at 3-4, H3 at 4-5; full score requires real-time enrichment, continuous quality monitoring with automated alerts, lineage integration, third-party scorecard with §4 conformance.
Skill.re