← AI Transformation Suite Business Requirements Document

BRD-03: Underwriting & Risk AI

Download Word

Year 2 Workstream — This BRD defines requirements for ACME Highland Health's AI-powered underwriting and risk assessment capability: predictive risk-scoring models that augment actuarial judgment in group and individual underwriting, with mandatory fairness/disparate-impact testing before any model influences pricing or coverage decisions. BRD-03 is the most fairness-sensitive workstream in Project Catalyst — the models directly affect what members pay and whether coverage is offered. Developed through 6 JAD sessions during Year 2 with the same mandatory governance structure as BRD-01 and BRD-02.

Table of Contents

  1. Executive Summary & Business Case
  2. Regulatory & Fairness Context
  3. Current State Assessment
  4. Target State & Capability Description
  5. Functional Requirements
  6. AI Model Specifications
  7. Data Requirements
  8. Integration Requirements
  9. Non-Functional Requirements
  10. Human Oversight & Actuarial Review Requirements
  11. Fairness, Bias & Disparate-Impact Requirements
  12. Testing & Validation Requirements
  13. Acceptance Criteria & Definition of Done
  14. Constraints, Assumptions & Dependencies
  15. Regulatory Traceability Matrix
  16. BRD-03 Delivery Team & Governance
  17. Sign-Off & Approval

1. Executive Summary & Business Case

ACME Highland Health underwrites approximately 12,000 group accounts and 180,000 individual/family policies annually. The current underwriting process relies on manual actuarial analysis using historical claims experience, demographic data, and industry benchmarks. Average underwriting turnaround is 14–21 business days for large groups and 5–7 business days for individual/family applications. Inter-actuarial consistency is approximately 82% on matched cases — meaning that the same application, evaluated by two different actuaries, produces materially different risk assessments 18% of the time. This inconsistency creates both competitive risk (losing accounts due to over-pricing) and financial risk (under-pricing accounts that produce adverse claims experience).

BRD-03 delivers AI-powered predictive risk-scoring models that augment actuarial judgment — they do not replace actuaries. The models analyze historical claims patterns, population health indicators, industry benchmarks, and ACME's own loss-ratio experience to produce a risk score, predicted loss ratio, and confidence interval for each application. Actuaries use this AI-generated assessment as one input alongside their professional judgment, market conditions, and competitive positioning analysis. The AI score is advisory; the actuary makes the final pricing and acceptance decision.

Why This Workstream Is the Most Fairness-Sensitive: BRD-01 affects coverage decisions (PA approvals/denials). BRD-02 affects information access. BRD-03 affects pricing — what members pay for insurance. A model that produces systematically different risk scores for demographically similar populations (after controlling for actuarially justified risk factors) creates disparate impact in pricing. Disparate pricing impact is the most scrutinized category of AI risk in insurance regulation, the subject of active NAIC guidance, and the target of state legislation in Colorado, Connecticut, and others. The fairness testing requirements in this BRD (Section 11) are deliberately stricter than BRD-01 or BRD-02 because the consequences of bias are more direct and more harmful.

1.1 Business Objectives

ObjectiveMetricCurrent BaselineTarget (12 months post-production)
Improve underwriting consistencyInter-actuarial agreement rate on matched cases~82%≥ 93% (AI score as shared reference point)
Reduce underwriting cycle timeAverage business days from submission to quote14–21 days (large group); 5–7 days (individual)7–10 days (large group); 2–3 days (individual)
Improve loss-ratio accuracyActual vs. predicted loss ratio (12-month lookback)±12% average deviation±6% average deviation
Reduce adverse selectionAnnual adverse-selection lossesCurrent baseline measured Phase 025% reduction
Improve competitive win rate% of quoted accounts that bindBaseline measured Phase 010% improvement (through more accurate, competitive pricing)

1.2 Investment & Timeline

Budget: BRD-03 delivery funded within SOW-02 ($41.58M Year 2, shared with BRD-02 and cross-cutting workstreams). BRD-03-specific delivery labor: approximately $5M.

Timeline: Runs in parallel with BRD-02 during Year 2. JAD sessions: Feb–Apr 2028. Requirements sign-off: Apr 2028. Build: May–Sep 2028. Pilot: Oct–Nov 2028. Production: Dec 2028.

Team: 14 people, led by Z. Thompson (BRD-03 Lead, Pulaski). Includes 1 senior ML engineer, 2 ML engineers, 2 ACME actuarial analysts (domain expertise — not replaceable by AI engineers), 2 data scientists, 1 fairness testing specialist (embedded in the delivery team, separate from Independent Model Validation), and supporting product, integration, QA, Scrum, and documentation roles.

2. Regulatory & Fairness Context

2.1 NAIC Model Bulletin on AI in Insurance

The National Association of Insurance Commissioners (NAIC) issued a Model Bulletin on the Use of Algorithms, Predictive Models, and AI Systems by Insurers (adopted 2023, updated 2024). While model bulletins are not binding law, they represent regulatory consensus and are being adopted by state insurance departments as enforcement guidance. Key provisions applicable to BRD-03:

2.2 State AI-in-Insurance Legislation

2.3 Actuarial Standards of Practice

AI-generated risk scores used in pricing must be consistent with the Actuarial Standards Board's Standards of Practice (ASOPs), particularly ASOP No. 56 (Modeling) and ASOP No. 12 (Risk Classification). ACME's actuarial analysts (D. Kowalczyk5 and E. Delvecchio5) are responsible for ensuring that AI model outputs are used in compliance with these standards. The AI model is a tool used by actuaries — it does not replace actuarial judgment, and pricing decisions that rely on AI scores must be reviewed and signed by a credentialed actuary.

3. Current State Assessment

3.1 Current Underwriting Workflow

  1. Application intake: Group applications received via broker/agent portal or direct submission. Individual applications via online enrollment or agent. Data entry into underwriting system (manual for complex groups; semi-automated for individual/family).
  2. Data collection: Actuaries gather claims history (for renewal accounts), demographic census data, industry classification (SIC/NAICS code), geographic distribution, and plan design details. For new groups, industry benchmarks and manual estimates substitute for claims history.
  3. Risk assessment: Actuaries evaluate risk using spreadsheet-based models, historical loss ratios, industry benchmarks (Milliman, Wakely), and professional judgment. Each actuary applies slightly different weighting and judgment calls, producing the 18% inconsistency rate.
  4. Pricing: Actuary produces a premium rate based on risk assessment, trend factors, administrative cost loading, profit margin, and competitive positioning. Rate reviewed by underwriting manager for large accounts.
  5. Quote delivery: Rate delivered to broker/agent. For large groups: 14–21 business days from application to quote. For individual/family: 5–7 business days.

3.2 Current State Pain Points

4. Target State & Capability Description

The target state adds an AI-generated risk assessment as an input to the actuarial workflow — not as a replacement for actuarial judgment. The actuary receives:

The actuary decides. The AI system produces a score, a prediction, and an explanation. The actuary evaluates this alongside market conditions, competitive dynamics, broker relationships, and professional judgment. The actuary may accept the AI score, adjust it, or override it entirely. Every pricing decision carries the actuary's sign-off — not the AI model's. This is not just a governance preference; it is an actuarial standards requirement (ASOP No. 56) and a regulatory expectation under the NAIC bulletin.

5. Functional Requirements

5.1 Risk Scoring & Prediction

FR-03.001 Must

System shall produce an AI Risk Score (0–100) for every underwriting application (group and individual), calibrated against ACME's historical loss experience. Score shall be accompanied by a predicted loss ratio with 90% confidence interval.

FR-03.002 Must

System shall produce a Top Risk Factors report for every scored application: the 5–10 variables that most influenced the risk score, with relative contribution percentages summing to ≥ 80% of the score variance. Presentation format shall be human-readable and suitable for inclusion in underwriting file documentation.

FR-03.003 Must

System shall produce a Comparable Case Analysis: 3–5 historical cases with the most similar risk profiles and their actual 12-month and 24-month loss outcomes. Similarity metric and selection methodology documented and approved by actuarial team during Phase 1.

FR-03.004 Must

System shall flag applications exhibiting anomaly patterns associated with adverse selection (e.g., sudden increase in high-cost service utilization before coverage effective date, enrollment patterns inconsistent with group demographics, unusually high coverage election rates for optional benefits). Flags are advisory; actuarial team investigates flagged cases.

FR-03.005 Must

System shall NOT use any protected characteristic — race, color, national origin, religion, sex, sexual orientation, disability, gender identity, or marital status — as a direct input variable. System shall be tested for proxy discrimination: variables that correlate with protected characteristics and produce disparate pricing impact shall be identified, evaluated, and either removed or documented with actuarial justification (see Section 11).

FR-03.006 Must

System shall support two underwriting modes: (a) Group underwriting (for employer groups of 2–10,000+ employees, using census demographics, industry classification, and claims history where available) and (b) Individual/family underwriting (for ACA-compliant individual market plans, using permitted rating factors only — age, tobacco use, geography, plan design).

5.2 Actuarial Integration

FR-03.007 Must

AI risk assessment shall be delivered to actuaries within the existing underwriting system interface — as an embedded panel, not a separate application. The actuary shall see the AI score, prediction, risk factors, comparable cases, and anomaly flags in a single view alongside the application data they already review.

FR-03.008 Must

System shall capture the actuary's response to the AI assessment: accepted (used score as-is), adjusted (modified score with documented reason), or overridden (disregarded score with documented reason). Response is logged in the audit trail and aggregated monthly for model improvement analysis.

FR-03.009 Must

No pricing decision shall be automated — every premium rate requires actuarial sign-off. The AI system is an input to the actuary's decision, not a replacement for it. The system shall not produce a premium rate or quote; it produces a risk assessment that the actuary uses to develop the rate.

5.3 Audit, Reporting & Compliance

FR-03.010 Must

System shall maintain a complete audit trail for every risk assessment: application ID, model version, input data hash, risk score, predicted loss ratio, confidence interval, top risk factors, comparable cases, anomaly flags, actuary response (accept/adjust/override with reason), final premium rate, and timestamps. Audit trail immutable and retained per ACME retention policy (minimum 7 years; 10 years for underwriting records per state requirements).

FR-03.011 Must

System shall generate regulatory reporting: model methodology documentation (suitable for state insurance department examination), fairness testing results (per NAIC bulletin and Colorado SB 21-169), and aggregate model performance metrics (predicted vs. actual loss ratios by segment). Reports producible on demand for any reporting period.

FR-03.012 Must

System shall support actuarial model documentation per ASOP No. 56 (Modeling): model purpose, methodology, data sources, assumptions, limitations, and sensitivity analysis. Documentation maintained by actuarial team with AI CoE support.

6. AI Model Specifications

6.1 Model Architecture

ModelTypeFunctionPerformance Target
M-10: Risk Scoring ModelGradient Boosted Ensemble (e.g., XGBoost / LightGBM)Produce composite risk score and predicted loss ratio from application data, claims history, and population health indicatorsPredicted vs. actual loss ratio: ±6% average deviation (12-month lookback)
M-11: Comparable Case RetrieverNearest-Neighbor / Embedding SimilarityIdentify 3–5 historical cases with most similar risk profiles and retrieve their actual outcomesSimilarity relevance rating ≥ 85% (actuarial panel assessment)
M-12: Anomaly DetectorIsolation Forest / Statistical Outlier DetectionFlag applications with patterns associated with adverse selection or data quality issuesPrecision ≥ 75%; Recall ≥ 60% on historical adverse-selection cases

6.2 Why Gradient Boosted Ensemble (Not Deep Learning)

The choice of gradient boosted ensemble (GBE) over deep learning for M-10 is deliberate and reflects the specific requirements of underwriting AI:

6.3 Feature Engineering & Variable Selection

6.4 Model Training Data

6.5 Production Monitoring

7. Data Requirements

Data ElementSource SystemClassificationAccess Control
Underwriting applications (group + individual)Underwriting systemPII + PHIOnshore US only; RBAC; actuarial team + AI model access
Historical claims experience (per group/individual)Claims processing systemPHIOnshore US only; RBAC; de-identified for model training
Premium rate history & loss ratiosFinancial/actuarial systemProprietary / FinancialRestricted to actuarial team + Finance
Industry benchmarks (Milliman, Wakely)Third-party data providersLicensed / ProprietaryPer vendor license terms
Census demographics (age, gender, geography)Group enrollment dataPIIOnshore US only; RBAC
Population health indicatorsPublic health datasets (CDC, CMS)Public dataStandard access
Provider network adequacy dataProvider management systemNon-sensitiveStandard access

8. Integration Requirements

IntegrationProtocolDirectionLatency Requirement
Underwriting system (application data + score delivery)REST API / embedded panelBidirectionalScore delivery ≤ 30 seconds per application
Claims processing system (historical claims)Batch ETL + APIReadNightly batch for training; API for on-demand scoring
Financial/actuarial system (loss ratios)Batch ETLReadMonthly batch for model monitoring
Data & Cloud AI Platform FoundationMLOps pipeline (internal)BidirectionalModel deployment, monitoring, retraining

9. Non-Functional Requirements

9.1 Performance

9.2 Security

10. Human Oversight & Actuarial Review Requirements

Non-Negotiable Constraint: No pricing decision is automated. Every premium rate produced by ACME's underwriting operation carries the sign-off of a credentialed actuary (Fellow of the Society of Actuaries or Associate of the Society of Actuaries with appropriate experience). The AI system is an input to the actuary's professional judgment — it does not replace that judgment, and it cannot produce or commit a premium rate. This constraint exists because (a) actuarial standards of practice (ASOP No. 56) require professional judgment in modeling, (b) state insurance regulations hold actuaries personally accountable for rate adequacy and fairness, and (c) the NAIC Model Bulletin requires human oversight of AI in underwriting.

11. Fairness, Bias & Disparate-Impact Requirements

BRD-03's fairness requirements are the strictest in the program because the models directly affect pricing — what members and employers pay for insurance.

11.1 Pre-Production Fairness Testing (Mandatory, Blocking)

11.2 Ongoing Fairness Monitoring (Production)

11.3 Regulatory Examination Readiness

ACME shall be able to produce, within 48 hours of a regulatory request, the following fairness documentation:

12. Testing & Validation Requirements

Test TypeOwnerCriteriaPhase
Unit TestingBRD-03 development team≥ 80% code coveragePhase 2 (continuous)
Integration TestingQA team (V. Müller)All 4 integrations tested end-to-endPhase 2
Model Accuracy TestingIndependent Validation (P. Okafor)Predicted vs. actual loss ratio: ±6% average deviationPhase 3
Fairness / Disparate-Impact TestingIndependent Validation (P. Okafor)≤ 3% demographic score deviation; proxy audit cleanPhase 3
Explainability ReviewIndependent Validation (P. Okafor)Top Risk Factors report verified for accuracy and completenessPhase 3
Proxy Variable AuditIndependent Validation + ActuarialAll prohibited variable proxies identified and resolvedPhase 3
Counterfactual TestingIndependent Validation (P. Okafor)Score stability under demographic perturbation within 3% thresholdPhase 3
Security TestingCybersecurity (M. Hassan)Zero Critical, zero High at release; model theft protection verifiedPhase 3
Actuarial ValidationACME Actuarial TeamModel outputs consistent with ASOP No. 56; validated against actuarial benchmarksPhase 3
Pilot (Shadow Mode)Actuarial Team + Product ManagerModel scores produced in parallel with manual process for 500+ cases; accuracy and bias assessed against manual outcomesPhase 3
Full UATOperational Testing Manager≥ 95% pass rate; zero open Critical/High defects; actuarial workflow integration verifiedPhase 3/4
Shadow-Mode Pilot: Unlike BRD-01 and BRD-02, BRD-03's pilot phase uses a shadow-mode approach: the AI model produces risk scores for real applications, but the scores are visible only to the actuarial pilot team — they do not influence actual pricing decisions. This allows comparison of AI-scored outcomes against traditional actuarial-only outcomes without risk to members or ACME's competitive position. Shadow mode runs for a minimum of 8 weeks (500+ cases). Only after shadow-mode results are reviewed and approved by the AI Governance Board and the actuarial team does the model enter production (visible to all actuaries, used as an advisory input to real pricing decisions).

13. Acceptance Criteria & Definition of Done

BRD-03 is accepted into production when ALL of the following criteria are met:

  1. All "Must" functional requirements (FR-03.001 through FR-03.012) implemented and tested
  2. All 3 AI models pass Independent Model Validation (zero Critical, zero uncorrected High)
  3. Fairness testing passed: ≤ 3% demographic score deviation; proxy audit clean; counterfactual testing within threshold
  4. Model accuracy: predicted vs. actual loss ratio ±6% average deviation on holdout validation set
  5. Actuarial validation: model outputs consistent with ASOP No. 56; approved by ACME actuarial team
  6. Shadow-mode pilot: 500+ cases scored; accuracy and bias results approved by AI Governance Board
  7. UAT passed (≥ 95% pass rate, zero open Critical/High defects)
  8. Security testing passed (zero Critical/High; model theft protection verified)
  9. Actuarial workflow integration verified (score delivery, override capture, audit trail)
  10. Regulatory examination documentation package complete and producible within 48 hours
  11. All 3 governance boards sign off at Phase 3 gate
  12. Production monitoring dashboards operational (accuracy drift, override rate, fairness metrics)

14. Constraints, Assumptions & Dependencies

14.1 Constraints

14.2 Assumptions

14.3 Dependencies

15. Regulatory Traceability Matrix

Regulation / StandardRequirementBRD-03 ImplementationVerification
NAIC Model AI BulletinUnfair discrimination prohibition; governance; transparency; testingFairness testing (Section 11), explainability (FR-03.002), AI Governance framework, actuarial oversightIndependent Validation fairness report; regulatory exam documentation package
Colorado SB 21-169Test AI for unfair discrimination in insurance decisionsSection 11 (fairness testing, ≤3% threshold, proxy audit, counterfactual analysis)Fairness testing report; available to Division of Insurance upon request
Connecticut SB 1103Human oversight of AI in insurance decisionsSection 10 (mandatory actuarial sign-off on every pricing decision)Audit trail showing actuary response for every scored case
ASOP No. 56 (Modeling)Actuarial standards for model useFR-03.012 (model documentation per ASOP requirements); actuarial review and sign-offActuarial validation; Chief Actuary sample review
ASOP No. 12 (Risk Classification)Risk classification standards for rate developmentPermitted variable list (Section 6.3); prohibited variable exclusion; actuarial justification for retained proxy variablesProxy variable audit report; actuarial team review
HIPAAPHI protection for underwriting dataSection 9.2 (encryption, RBAC, audit trail); de-identification for training dataSecurity testing; privacy impact assessment
NIST AI RMFGovern, Map, Measure, ManageFull AI Governance framework (Section 16)AI Governance Board oversight

16. BRD-03 Delivery Team & Governance

Team size: 14 people. Lead: Z. Thompson (Pulaski). Full roster in Resource Plan, Team 23.

Key structural note: BRD-03 includes 2 ACME actuarial analysts (D. Kowalczyk5 and E. Delvecchio5) embedded in the delivery team. Their role is domain expertise and model validation — they are not AI engineers, and their actuarial judgment is not replaceable by engineering talent. The embedded Fairness Testing Specialist (F. Solberg5, Pulaski) provides continuous fairness assessment during development, complementing the Independent Model Validation team's formal pre-production testing.

Governance: BRD-03 operates under the full Project Catalyst governance framework. Sprint-level execution uses 2-week sprints with Scrum Master (M. Rutherford4). All model releases require Independent Model Validation sign-off and AI Governance Board approval. Given the heightened fairness sensitivity, the AI Governance Board conducts additional interim fairness reviews during Phase 2 (build) — not just at the formal validation gate in Phase 3.

17. Sign-Off & Approval

RoleNameSign-Off ScopeStatus
Business SponsorACME Chief Actuary (TBD at Year 2 kickoff)Actuarial adequacy, business requirements, ASOP complianceApproved — Phase 1 Gate (Year 2)
Legal CounselR. ThorneLiability risk, NAIC bulletin compliance, state statute alignmentApproved — Phase 1 Gate (Year 2)
VP ComplianceJ. MartinezRegulatory alignment, unfair discrimination prohibition complianceApproved — Phase 1 Gate (Year 2)
Chief ArchitectD. ChenTechnical feasibility, underwriting system integrationApproved — Phase 1 Gate (Year 2)
CISOM. HassanSecurity, data handling for underwriting/financial dataApproved — Phase 1 Gate (Year 2)
AI Governance DirectorS. KhuranaModel governance, fairness framework, proxy variable methodologyApproved — Phase 1 Gate (Year 2)
Chief Medical OfficerDr. N. PatelClinical appropriateness of risk factors used in scoringApproved — Phase 1 Gate (Year 2)
BRD-03 LeadZ. ThompsonTechnical achievabilityApproved — Phase 1 Gate (Year 2)
Program DirectorC. TyrrellFacilitation (does not sign off on requirements)Acknowledged