Year 2 Workstream — This BRD defines requirements for ACME Highland Health's AI-powered underwriting and risk assessment capability: predictive risk-scoring models that augment actuarial judgment in group and individual underwriting, with mandatory fairness/disparate-impact testing before any model influences pricing or coverage decisions. BRD-03 is the most fairness-sensitive workstream in Project Catalyst — the models directly affect what members pay and whether coverage is offered. Developed through 6 JAD sessions during Year 2 with the same mandatory governance structure as BRD-01 and BRD-02.
Table of Contents
- Executive Summary & Business Case
- Regulatory & Fairness Context
- Current State Assessment
- Target State & Capability Description
- Functional Requirements
- AI Model Specifications
- Data Requirements
- Integration Requirements
- Non-Functional Requirements
- Human Oversight & Actuarial Review Requirements
- Fairness, Bias & Disparate-Impact Requirements
- Testing & Validation Requirements
- Acceptance Criteria & Definition of Done
- Constraints, Assumptions & Dependencies
- Regulatory Traceability Matrix
- BRD-03 Delivery Team & Governance
- Sign-Off & Approval
1. Executive Summary & Business Case
ACME Highland Health underwrites approximately 12,000 group accounts and 180,000 individual/family policies annually. The current underwriting process relies on manual actuarial analysis using historical claims experience, demographic data, and industry benchmarks. Average underwriting turnaround is 14–21 business days for large groups and 5–7 business days for individual/family applications. Inter-actuarial consistency is approximately 82% on matched cases — meaning that the same application, evaluated by two different actuaries, produces materially different risk assessments 18% of the time. This inconsistency creates both competitive risk (losing accounts due to over-pricing) and financial risk (under-pricing accounts that produce adverse claims experience).
BRD-03 delivers AI-powered predictive risk-scoring models that augment actuarial judgment — they do not replace actuaries. The models analyze historical claims patterns, population health indicators, industry benchmarks, and ACME's own loss-ratio experience to produce a risk score, predicted loss ratio, and confidence interval for each application. Actuaries use this AI-generated assessment as one input alongside their professional judgment, market conditions, and competitive positioning analysis. The AI score is advisory; the actuary makes the final pricing and acceptance decision.
1.1 Business Objectives
| Objective | Metric | Current Baseline | Target (12 months post-production) |
|---|---|---|---|
| Improve underwriting consistency | Inter-actuarial agreement rate on matched cases | ~82% | ≥ 93% (AI score as shared reference point) |
| Reduce underwriting cycle time | Average business days from submission to quote | 14–21 days (large group); 5–7 days (individual) | 7–10 days (large group); 2–3 days (individual) |
| Improve loss-ratio accuracy | Actual vs. predicted loss ratio (12-month lookback) | ±12% average deviation | ±6% average deviation |
| Reduce adverse selection | Annual adverse-selection losses | Current baseline measured Phase 0 | 25% reduction |
| Improve competitive win rate | % of quoted accounts that bind | Baseline measured Phase 0 | 10% improvement (through more accurate, competitive pricing) |
1.2 Investment & Timeline
Budget: BRD-03 delivery funded within SOW-02 ($41.58M Year 2, shared with BRD-02 and cross-cutting workstreams). BRD-03-specific delivery labor: approximately $5M.
Timeline: Runs in parallel with BRD-02 during Year 2. JAD sessions: Feb–Apr 2028. Requirements sign-off: Apr 2028. Build: May–Sep 2028. Pilot: Oct–Nov 2028. Production: Dec 2028.
Team: 14 people, led by Z. Thompson (BRD-03 Lead, Pulaski). Includes 1 senior ML engineer, 2 ML engineers, 2 ACME actuarial analysts (domain expertise — not replaceable by AI engineers), 2 data scientists, 1 fairness testing specialist (embedded in the delivery team, separate from Independent Model Validation), and supporting product, integration, QA, Scrum, and documentation roles.
2. Regulatory & Fairness Context
2.1 NAIC Model Bulletin on AI in Insurance
The National Association of Insurance Commissioners (NAIC) issued a Model Bulletin on the Use of Algorithms, Predictive Models, and AI Systems by Insurers (adopted 2023, updated 2024). While model bulletins are not binding law, they represent regulatory consensus and are being adopted by state insurance departments as enforcement guidance. Key provisions applicable to BRD-03:
- Unfair discrimination prohibition: AI/ML models used in underwriting, pricing, or claims shall not produce outcomes that are unfairly discriminatory based on race, color, national origin, religion, sex, sexual orientation, disability, gender identity, or marital status — even if the model does not use these variables as direct inputs. Proxy discrimination (where facially neutral variables correlate with protected characteristics) is explicitly covered.
- Governance and accountability: Insurers shall establish governance frameworks for AI use, including documented policies, risk assessments, and accountability structures. The AI Governance & CoE framework satisfies this requirement.
- Transparency and explainability: Insurers shall be able to explain how AI models affect underwriting and pricing decisions in a manner understandable to regulators and, where required, to consumers.
- Testing and validation: Insurers shall test AI models for unfair bias before deployment and on an ongoing basis. Testing methodology shall be documented and available for regulatory examination.
2.2 State AI-in-Insurance Legislation
- Colorado SB 21-169 (AI Testing for Discrimination): Requires insurers using AI or algorithms in coverage, pricing, or claims decisions to test for unfair discrimination and provide testing results to the Division of Insurance upon request. BRD-03's fairness testing framework (Section 11) is designed to satisfy this requirement.
- Connecticut SB 1103 (AI Disclosure and Oversight): Requires disclosure of AI use in insurance decisions and mandates human oversight. BRD-03's actuarial review requirement (Section 10) satisfies the human oversight component.
- Emerging state legislation: Multiple states (New York, California, Illinois, and others) are advancing AI-in-insurance legislation. The AI CoE's regulatory tracker monitors these developments quarterly and assesses program impact within 10 business days of new legislation or guidance.
2.3 Actuarial Standards of Practice
AI-generated risk scores used in pricing must be consistent with the Actuarial Standards Board's Standards of Practice (ASOPs), particularly ASOP No. 56 (Modeling) and ASOP No. 12 (Risk Classification). ACME's actuarial analysts (D. Kowalczyk5 and E. Delvecchio5) are responsible for ensuring that AI model outputs are used in compliance with these standards. The AI model is a tool used by actuaries — it does not replace actuarial judgment, and pricing decisions that rely on AI scores must be reviewed and signed by a credentialed actuary.
3. Current State Assessment
3.1 Current Underwriting Workflow
- Application intake: Group applications received via broker/agent portal or direct submission. Individual applications via online enrollment or agent. Data entry into underwriting system (manual for complex groups; semi-automated for individual/family).
- Data collection: Actuaries gather claims history (for renewal accounts), demographic census data, industry classification (SIC/NAICS code), geographic distribution, and plan design details. For new groups, industry benchmarks and manual estimates substitute for claims history.
- Risk assessment: Actuaries evaluate risk using spreadsheet-based models, historical loss ratios, industry benchmarks (Milliman, Wakely), and professional judgment. Each actuary applies slightly different weighting and judgment calls, producing the 18% inconsistency rate.
- Pricing: Actuary produces a premium rate based on risk assessment, trend factors, administrative cost loading, profit margin, and competitive positioning. Rate reviewed by underwriting manager for large accounts.
- Quote delivery: Rate delivered to broker/agent. For large groups: 14–21 business days from application to quote. For individual/family: 5–7 business days.
3.2 Current State Pain Points
- Inconsistency: 18% inter-actuarial disagreement rate on matched cases. Two actuaries evaluating the same group can produce materially different premium rates. This creates internal friction and, when different rates are inadvertently quoted, competitive and reputational risk.
- Cycle time: 14–21 days for large groups. Brokers report that competitors who can quote in 7–10 days win business on speed alone — even if ACME's rate is competitive.
- Accuracy: Actual vs. predicted loss ratio deviates by an average of ±12%. This means ACME's pricing is, on average, 12% too high or too low — driving either competitive loss (overpriced) or financial loss (underpriced).
- Scale limitations: The manual process cannot efficiently scale to evaluate micro-variations in risk (e.g., risk differences between two similar-sized groups in different geographies with slightly different industry mixes). The AI model can analyze these variations at a granularity that manual analysis cannot practically achieve.
4. Target State & Capability Description
The target state adds an AI-generated risk assessment as an input to the actuarial workflow — not as a replacement for actuarial judgment. The actuary receives:
- AI Risk Score: A composite score (0–100) reflecting the predicted risk level of the application, calibrated against ACME's historical loss experience. Higher score = higher predicted loss ratio.
- Predicted Loss Ratio: A point estimate with confidence interval (e.g., "Predicted loss ratio: 84.2%, 90% CI: [78.6%, 89.8%]"). The confidence interval communicates model uncertainty — wide intervals suggest the actuary should rely more on professional judgment.
- Top Risk Factors: The 5–10 factors that most influenced the risk score, with their relative contribution (e.g., "Industry SIC code: 28% influence; Average member age: 22% influence; Geographic region: 18% influence; Prior claims trend: 15% influence"). This explainability output satisfies the NAIC transparency requirement.
- Comparable Case Analysis: 3–5 historical cases with similar characteristics and their actual loss outcomes, enabling the actuary to calibrate the AI prediction against real-world experience.
- Anomaly Flags: Indicators when the application exhibits patterns associated with known adverse-selection tactics or data quality issues that warrant additional investigation.
5. Functional Requirements
5.1 Risk Scoring & Prediction
System shall produce an AI Risk Score (0–100) for every underwriting application (group and individual), calibrated against ACME's historical loss experience. Score shall be accompanied by a predicted loss ratio with 90% confidence interval.
System shall produce a Top Risk Factors report for every scored application: the 5–10 variables that most influenced the risk score, with relative contribution percentages summing to ≥ 80% of the score variance. Presentation format shall be human-readable and suitable for inclusion in underwriting file documentation.
System shall produce a Comparable Case Analysis: 3–5 historical cases with the most similar risk profiles and their actual 12-month and 24-month loss outcomes. Similarity metric and selection methodology documented and approved by actuarial team during Phase 1.
System shall flag applications exhibiting anomaly patterns associated with adverse selection (e.g., sudden increase in high-cost service utilization before coverage effective date, enrollment patterns inconsistent with group demographics, unusually high coverage election rates for optional benefits). Flags are advisory; actuarial team investigates flagged cases.
System shall NOT use any protected characteristic — race, color, national origin, religion, sex, sexual orientation, disability, gender identity, or marital status — as a direct input variable. System shall be tested for proxy discrimination: variables that correlate with protected characteristics and produce disparate pricing impact shall be identified, evaluated, and either removed or documented with actuarial justification (see Section 11).
System shall support two underwriting modes: (a) Group underwriting (for employer groups of 2–10,000+ employees, using census demographics, industry classification, and claims history where available) and (b) Individual/family underwriting (for ACA-compliant individual market plans, using permitted rating factors only — age, tobacco use, geography, plan design).
5.2 Actuarial Integration
AI risk assessment shall be delivered to actuaries within the existing underwriting system interface — as an embedded panel, not a separate application. The actuary shall see the AI score, prediction, risk factors, comparable cases, and anomaly flags in a single view alongside the application data they already review.
System shall capture the actuary's response to the AI assessment: accepted (used score as-is), adjusted (modified score with documented reason), or overridden (disregarded score with documented reason). Response is logged in the audit trail and aggregated monthly for model improvement analysis.
No pricing decision shall be automated — every premium rate requires actuarial sign-off. The AI system is an input to the actuary's decision, not a replacement for it. The system shall not produce a premium rate or quote; it produces a risk assessment that the actuary uses to develop the rate.
5.3 Audit, Reporting & Compliance
System shall maintain a complete audit trail for every risk assessment: application ID, model version, input data hash, risk score, predicted loss ratio, confidence interval, top risk factors, comparable cases, anomaly flags, actuary response (accept/adjust/override with reason), final premium rate, and timestamps. Audit trail immutable and retained per ACME retention policy (minimum 7 years; 10 years for underwriting records per state requirements).
System shall generate regulatory reporting: model methodology documentation (suitable for state insurance department examination), fairness testing results (per NAIC bulletin and Colorado SB 21-169), and aggregate model performance metrics (predicted vs. actual loss ratios by segment). Reports producible on demand for any reporting period.
System shall support actuarial model documentation per ASOP No. 56 (Modeling): model purpose, methodology, data sources, assumptions, limitations, and sensitivity analysis. Documentation maintained by actuarial team with AI CoE support.
6. AI Model Specifications
6.1 Model Architecture
| Model | Type | Function | Performance Target |
|---|---|---|---|
| M-10: Risk Scoring Model | Gradient Boosted Ensemble (e.g., XGBoost / LightGBM) | Produce composite risk score and predicted loss ratio from application data, claims history, and population health indicators | Predicted vs. actual loss ratio: ±6% average deviation (12-month lookback) |
| M-11: Comparable Case Retriever | Nearest-Neighbor / Embedding Similarity | Identify 3–5 historical cases with most similar risk profiles and retrieve their actual outcomes | Similarity relevance rating ≥ 85% (actuarial panel assessment) |
| M-12: Anomaly Detector | Isolation Forest / Statistical Outlier Detection | Flag applications with patterns associated with adverse selection or data quality issues | Precision ≥ 75%; Recall ≥ 60% on historical adverse-selection cases |
6.2 Why Gradient Boosted Ensemble (Not Deep Learning)
The choice of gradient boosted ensemble (GBE) over deep learning for M-10 is deliberate and reflects the specific requirements of underwriting AI:
- Explainability: GBE models produce native feature importance scores and support SHAP (SHapley Additive exPlanations) values, enabling the Top Risk Factors report (FR-03.002) without post-hoc explanation bolted on. Deep learning models require additional explainability tooling that adds complexity and may produce less faithful explanations.
- Regulatory defensibility: State insurance departments examining ACME's AI underwriting will expect to understand how the model works. GBE models are more interpretable to actuarial examiners than neural networks. The NAIC bulletin implicitly favors models where "the insurer can explain how the model works" — this is easier with GBE.
- Actuarial acceptance: ACME's actuaries are trained in statistical methods closer to GBE than deep learning. A model the actuaries understand and can critique is more likely to be used effectively than a black box they distrust.
- Data scale: ACME's underwriting dataset (12,000 group + 180,000 individual cases/year × 5 years of history) is large for traditional actuarial analysis but modest for deep learning. GBE performs well at this scale without overfitting risk.
6.3 Feature Engineering & Variable Selection
- Permitted input variables: Age distribution, gender distribution (where actuarially permitted), geographic distribution, industry classification (SIC/NAICS), plan design (deductible, coinsurance, out-of-pocket max), prior claims history (where available), enrollment size, voluntary vs. mandatory coverage, tobacco-use rate, and ACME's own loss-ratio experience for similar segments.
- Prohibited input variables: Race, color, national origin, religion, sexual orientation, disability status, gender identity, marital status, credit score (prohibited for health insurance in most states), genetic information, and any variable derived from social media or web browsing behavior.
- Proxy variable analysis (mandatory): Before the model enters production, every permitted variable is tested for correlation with prohibited variables. If a permitted variable (e.g., ZIP code) correlates with a prohibited variable (e.g., race) above a threshold (Pearson r > 0.40), the variable is either: (a) removed from the model, (b) adjusted (e.g., geographic region instead of ZIP code), or (c) retained with documented actuarial justification approved by the Chief Medical Officer and General Counsel. Proxy analysis is documented in the Fairness Testing Report and available for regulatory examination.
6.4 Model Training Data
- Training corpus: 5 years of ACME underwriting history: applications, risk assessments, quoted rates, actual enrollment, and actual 12-month and 24-month loss outcomes. Approximately 60,000 group cases and 900,000 individual cases.
- Ground-truth: Actual loss ratios (claims cost / premium earned) at 12-month and 24-month windows, reconciled with ACME's financial systems.
- Holdout validation: Most recent 12 months of data held out of training for validation; model evaluated on its ability to predict actual outcomes for cases it has never seen.
- De-identification: Training data de-identified per HIPAA Safe Harbor before model development. Actuarial analysts access identified data for validation purposes under existing ACME data governance protocols.
6.5 Production Monitoring
- Prediction accuracy monitoring: Quarterly comparison of predicted loss ratios against actual loss ratios for cases scored 6+ months ago. If average deviation exceeds ±8% (against target of ±6%), retraining investigation triggered within 10 business days.
- Override rate monitoring: Monthly tracking of actuarial override rate. Target: <20% override rate. If override rate exceeds 30% for 3+ consecutive months, model retraining assessment with root-cause analysis presented to AI Governance Board.
- Fairness drift monitoring: Quarterly disparate-impact analysis of production risk scores by demographic group (Section 11). Any drift from pre-production fairness baseline reported to AI Governance Board within 48 hours.
7. Data Requirements
| Data Element | Source System | Classification | Access Control |
|---|---|---|---|
| Underwriting applications (group + individual) | Underwriting system | PII + PHI | Onshore US only; RBAC; actuarial team + AI model access |
| Historical claims experience (per group/individual) | Claims processing system | PHI | Onshore US only; RBAC; de-identified for model training |
| Premium rate history & loss ratios | Financial/actuarial system | Proprietary / Financial | Restricted to actuarial team + Finance |
| Industry benchmarks (Milliman, Wakely) | Third-party data providers | Licensed / Proprietary | Per vendor license terms |
| Census demographics (age, gender, geography) | Group enrollment data | PII | Onshore US only; RBAC |
| Population health indicators | Public health datasets (CDC, CMS) | Public data | Standard access |
| Provider network adequacy data | Provider management system | Non-sensitive | Standard access |
8. Integration Requirements
| Integration | Protocol | Direction | Latency Requirement |
|---|---|---|---|
| Underwriting system (application data + score delivery) | REST API / embedded panel | Bidirectional | Score delivery ≤ 30 seconds per application |
| Claims processing system (historical claims) | Batch ETL + API | Read | Nightly batch for training; API for on-demand scoring |
| Financial/actuarial system (loss ratios) | Batch ETL | Read | Monthly batch for model monitoring |
| Data & Cloud AI Platform Foundation | MLOps pipeline (internal) | Bidirectional | Model deployment, monitoring, retraining |
9. Non-Functional Requirements
9.1 Performance
- Scoring latency: AI risk assessment (score + prediction + risk factors + comparable cases + anomaly flags) delivered within 30 seconds per application. Batch scoring (e.g., portfolio re-scoring for renewal season): 10,000 applications scored within 4 hours.
- Availability: 99.5% uptime during business hours. Scoring system failure degrades gracefully — actuaries continue using manual process; no applications are blocked.
9.2 Security
- Underwriting data encrypted at rest and in transit. Access restricted to authorized actuarial and underwriting personnel.
- Model parameters and training data protected from unauthorized access (model theft risk).
- Audit trail tamper-evident and retained per state underwriting record requirements (minimum 7–10 years).
10. Human Oversight & Actuarial Review Requirements
- Actuaries are required to document their response to the AI assessment for every case: accepted, adjusted (with reason), or overridden (with reason). This documentation becomes part of the underwriting file and is available for regulatory examination.
- When an actuary overrides the AI score, the override reason is coded (predefined code list developed during JAD sessions) and aggregated for model improvement analysis. Common override reasons feed back into model retraining priorities.
- ACME's Chief Actuary (or designated senior actuary) reviews a 10% random sample of AI-scored cases monthly to verify that actuaries are appropriately considering, not blindly accepting, the AI scores. This review addresses the opposite risk from hallucination: automation bias, where human reviewers defer to the AI even when their professional judgment suggests otherwise.
11. Fairness, Bias & Disparate-Impact Requirements
BRD-03's fairness requirements are the strictest in the program because the models directly affect pricing — what members and employers pay for insurance.
11.1 Pre-Production Fairness Testing (Mandatory, Blocking)
- Disparate-impact analysis: Risk scores shall be analyzed for statistical disparity across demographic groups: age bracket, gender, geographic region, and (using validated proxy methods where direct data is unavailable) race/ethnicity. Analysis performed by Independent Model Validation (P. Okafor) using a methodology documented and approved by the AI Governance Board.
- Fairness threshold: No demographic group's average risk score shall deviate >3% from the actuarially expected score for that group's risk profile (after controlling for permitted rating factors). The 3% threshold is stricter than BRD-01's 5% threshold because pricing impact is more direct. Deviations beyond 3% require documented actuarial justification approved by the Chief Medical Officer, General Counsel, and AI Governance Board.
- Proxy variable audit: Every input variable tested for correlation with protected characteristics (Section 6.3). Results documented in the Fairness Testing Report.
- Counterfactual analysis: For a sample of scored applications, the model is re-scored with demographic characteristics perturbed (e.g., changing the geographic distribution to a demographically different region). If score changes exceed the 3% threshold, the driving variables are investigated for proxy discrimination.
11.2 Ongoing Fairness Monitoring (Production)
- Quarterly disparate-impact analysis of production risk scores, performed by AI CoE with results reported to AI Governance Board.
- Annual comprehensive fairness audit by Independent Model Validation, including proxy variable re-analysis and counterfactual testing. Results documented and available for regulatory examination.
- If production fairness metrics drift beyond pre-production baseline by >2 percentage points, the AI Governance Board is notified within 48 hours and a model investigation is initiated.
11.3 Regulatory Examination Readiness
ACME shall be able to produce, within 48 hours of a regulatory request, the following fairness documentation:
- Model methodology documentation (how the model works, what variables it uses, what variables it excludes)
- Pre-production fairness testing report (disparate-impact analysis, proxy variable audit, counterfactual results)
- Ongoing fairness monitoring results (quarterly analyses, annual audit)
- Actuarial justification for any fairness threshold exception
- Sample audit trail showing AI score, actuary response, and final pricing decision for examined cases
12. Testing & Validation Requirements
| Test Type | Owner | Criteria | Phase |
|---|---|---|---|
| Unit Testing | BRD-03 development team | ≥ 80% code coverage | Phase 2 (continuous) |
| Integration Testing | QA team (V. Müller) | All 4 integrations tested end-to-end | Phase 2 |
| Model Accuracy Testing | Independent Validation (P. Okafor) | Predicted vs. actual loss ratio: ±6% average deviation | Phase 3 |
| Fairness / Disparate-Impact Testing | Independent Validation (P. Okafor) | ≤ 3% demographic score deviation; proxy audit clean | Phase 3 |
| Explainability Review | Independent Validation (P. Okafor) | Top Risk Factors report verified for accuracy and completeness | Phase 3 |
| Proxy Variable Audit | Independent Validation + Actuarial | All prohibited variable proxies identified and resolved | Phase 3 |
| Counterfactual Testing | Independent Validation (P. Okafor) | Score stability under demographic perturbation within 3% threshold | Phase 3 |
| Security Testing | Cybersecurity (M. Hassan) | Zero Critical, zero High at release; model theft protection verified | Phase 3 |
| Actuarial Validation | ACME Actuarial Team | Model outputs consistent with ASOP No. 56; validated against actuarial benchmarks | Phase 3 |
| Pilot (Shadow Mode) | Actuarial Team + Product Manager | Model scores produced in parallel with manual process for 500+ cases; accuracy and bias assessed against manual outcomes | Phase 3 |
| Full UAT | Operational Testing Manager | ≥ 95% pass rate; zero open Critical/High defects; actuarial workflow integration verified | Phase 3/4 |
13. Acceptance Criteria & Definition of Done
BRD-03 is accepted into production when ALL of the following criteria are met:
- All "Must" functional requirements (FR-03.001 through FR-03.012) implemented and tested
- All 3 AI models pass Independent Model Validation (zero Critical, zero uncorrected High)
- Fairness testing passed: ≤ 3% demographic score deviation; proxy audit clean; counterfactual testing within threshold
- Model accuracy: predicted vs. actual loss ratio ±6% average deviation on holdout validation set
- Actuarial validation: model outputs consistent with ASOP No. 56; approved by ACME actuarial team
- Shadow-mode pilot: 500+ cases scored; accuracy and bias results approved by AI Governance Board
- UAT passed (≥ 95% pass rate, zero open Critical/High defects)
- Security testing passed (zero Critical/High; model theft protection verified)
- Actuarial workflow integration verified (score delivery, override capture, audit trail)
- Regulatory examination documentation package complete and producible within 48 hours
- All 3 governance boards sign off at Phase 3 gate
- Production monitoring dashboards operational (accuracy drift, override rate, fairness metrics)
14. Constraints, Assumptions & Dependencies
14.1 Constraints
- No automated pricing — every rate requires actuarial sign-off
- No prohibited variables as direct model inputs (Section 6.3)
- Fairness threshold of ≤ 3% (stricter than BRD-01/02)
- Shadow-mode pilot mandatory before production deployment
- All underwriting data onshore US only
- Model must be explainable (GBE + SHAP, not black-box deep learning)
14.2 Assumptions
- 5 years of historical underwriting data available and reconcilable with claims outcomes
- ACME's actuarial team (2 analysts) available for model validation and ongoing oversight
- Industry benchmark data (Milliman, Wakely) licenses current and accessible
- State regulatory environment permits AI-assisted (not AI-automated) underwriting under current statutes
14.3 Dependencies
- DEP-03: Data & Cloud Platform Foundation must be live (inherited from Year 1)
- DEP-07: BRD-01 infrastructure and governance patterns reused
- DEP-10: Underwriting system supports embedded panel integration (API availability confirmed Phase 0)
15. Regulatory Traceability Matrix
| Regulation / Standard | Requirement | BRD-03 Implementation | Verification |
|---|---|---|---|
| NAIC Model AI Bulletin | Unfair discrimination prohibition; governance; transparency; testing | Fairness testing (Section 11), explainability (FR-03.002), AI Governance framework, actuarial oversight | Independent Validation fairness report; regulatory exam documentation package |
| Colorado SB 21-169 | Test AI for unfair discrimination in insurance decisions | Section 11 (fairness testing, ≤3% threshold, proxy audit, counterfactual analysis) | Fairness testing report; available to Division of Insurance upon request |
| Connecticut SB 1103 | Human oversight of AI in insurance decisions | Section 10 (mandatory actuarial sign-off on every pricing decision) | Audit trail showing actuary response for every scored case |
| ASOP No. 56 (Modeling) | Actuarial standards for model use | FR-03.012 (model documentation per ASOP requirements); actuarial review and sign-off | Actuarial validation; Chief Actuary sample review |
| ASOP No. 12 (Risk Classification) | Risk classification standards for rate development | Permitted variable list (Section 6.3); prohibited variable exclusion; actuarial justification for retained proxy variables | Proxy variable audit report; actuarial team review |
| HIPAA | PHI protection for underwriting data | Section 9.2 (encryption, RBAC, audit trail); de-identification for training data | Security testing; privacy impact assessment |
| NIST AI RMF | Govern, Map, Measure, Manage | Full AI Governance framework (Section 16) | AI Governance Board oversight |
16. BRD-03 Delivery Team & Governance
Team size: 14 people. Lead: Z. Thompson (Pulaski). Full roster in Resource Plan, Team 23.
Key structural note: BRD-03 includes 2 ACME actuarial analysts (D. Kowalczyk5 and E. Delvecchio5) embedded in the delivery team. Their role is domain expertise and model validation — they are not AI engineers, and their actuarial judgment is not replaceable by engineering talent. The embedded Fairness Testing Specialist (F. Solberg5, Pulaski) provides continuous fairness assessment during development, complementing the Independent Model Validation team's formal pre-production testing.
Governance: BRD-03 operates under the full Project Catalyst governance framework. Sprint-level execution uses 2-week sprints with Scrum Master (M. Rutherford4). All model releases require Independent Model Validation sign-off and AI Governance Board approval. Given the heightened fairness sensitivity, the AI Governance Board conducts additional interim fairness reviews during Phase 2 (build) — not just at the formal validation gate in Phase 3.
17. Sign-Off & Approval
| Role | Name | Sign-Off Scope | Status |
|---|---|---|---|
| Business Sponsor | ACME Chief Actuary (TBD at Year 2 kickoff) | Actuarial adequacy, business requirements, ASOP compliance | Approved — Phase 1 Gate (Year 2) |
| Legal Counsel | R. Thorne | Liability risk, NAIC bulletin compliance, state statute alignment | Approved — Phase 1 Gate (Year 2) |
| VP Compliance | J. Martinez | Regulatory alignment, unfair discrimination prohibition compliance | Approved — Phase 1 Gate (Year 2) |
| Chief Architect | D. Chen | Technical feasibility, underwriting system integration | Approved — Phase 1 Gate (Year 2) |
| CISO | M. Hassan | Security, data handling for underwriting/financial data | Approved — Phase 1 Gate (Year 2) |
| AI Governance Director | S. Khurana | Model governance, fairness framework, proxy variable methodology | Approved — Phase 1 Gate (Year 2) |
| Chief Medical Officer | Dr. N. Patel | Clinical appropriateness of risk factors used in scoring | Approved — Phase 1 Gate (Year 2) |
| BRD-03 Lead | Z. Thompson | Technical achievability | Approved — Phase 1 Gate (Year 2) |
| Program Director | C. Tyrrell | Facilitation (does not sign off on requirements) | Acknowledged |