EU AI ACTto the 2 December 2027 Annex III enforcement deadline.Check your tier →
Home · Insights · Strategy
StrategySeptember 2026·11 min read

AI in Insurance and TPAs: Where It Pays Back First

Insurers have been sold AI for underwriting since 2016 and most of what shipped was a chatbot. The money is in claims, pre-authorisation and the paperwork around them — and regulators have now put a clock on exactly those workflows. A field map of what pays back first, what a TPA should do differently, and why none of it can run on a public API.

SG
Saurabh Goenka
Founder & CEO, MindMap Digital

Insurance was one of the first industries to be sold AI, and one of the last to get much from it. A decade of 'AI-powered underwriting' produced a great many pilots, a few pricing models the regulator now wants explained, and a chatbot on the website that hands off to a human after two questions. Meanwhile the work that actually consumes an insurer's people — reading claim files, chasing missing documents, matching bills to tariffs, keying broker submissions — carried on by hand. This is a map of where AI pays back first in insurance and third-party administration, drawn from what we have put into production rather than from what we would like to sell.

The clock has changed

Two regulatory moves reframed the problem. In India, IRDAI's May 2024 master circular on health insurance requires an insurer to grant cashless authorisation within one hour of the hospital's request and to clear the discharge within three hours; it also set a deadline for the systems to make that possible. In Europe, the AI Act lists AI used for risk assessment and pricing of natural persons in life and health insurance as high-risk under Annex III, with the documentation, logging, human-oversight and impact-assessment duties that follow. The first move turns document handling into a timed obligation. The second makes the glamorous use case — pricing — the most heavily regulated one. Read together, they point at the same conclusion: automate the paperwork around a decision, and keep the decision itself with a human who can be shown to have made it.

Start with claims, because that is where the documents are

A claim is a bundle of unstructured documents that has to become a structured decision. Discharge summaries, itemised bills, investigation reports, police reports, repair estimates, photographs — each one read by a person, each one a place for delay and error. Intelligent document processing that extracts these into the claim schema, checks completeness and cites the source page is the highest-return deployment in the sector because the volume is enormous and the task is repetitive. Our motor-claims and health-claims deployments settle seventy to eighty percent of low-complexity claims straight through; the rest arrive at the adjudicator with the reading already done. That is the pattern to copy: straight-through for the routine, assisted decision for the rest, and every decision logged with its reasons.

Pre-authorisation is the TPA's sharp end

Third-party administrators live at the point where the one-hour clock bites. A cashless request lands as a scanned form and a stack of reports, usually incomplete, and the desk has to decide inside the hour. Three things move the needle. First, completeness checking at intake: an AI that reads the pack and sends the missing-document query back to the hospital in minutes removes the largest single cause of delay. Second, tariff and policy matching: mapping the proposed procedure to the network tariff and the policy's terms so the adjudicator reviews a drafted decision rather than assembling one. Third, a queue that is designed for humans: the adjudicator approves, edits or overrides, and every override becomes training data. Do those three and the routine cases fit inside the hour. Try to automate the judgement call instead and you will spend the year in exception handling.

Underwriting: structure the submission, keep the underwriter

Commercial and health underwriting is throttled by data capture, not by decision-making. Broker submissions, loss runs, medical reports and financial statements arrive as PDFs, and quote turnaround is set by how fast someone can key them into the platform. Extraction into a structured submission, with the anomalies flagged, gives an underwriter three to four times the throughput without changing who prices the risk. That division of labour is also the compliant one: under the EU AI Act a system that structures the file for a human is a very different thing from a system that prices a person's life cover, and the second carries obligations you should take on deliberately, not by accident.

Servicing and distribution: voice, messaging and partner sites

Policy servicing is where the chatbot went to die, and the reason was scope. A voice or messaging agent that answers from the policy wording, the claim status and the approved FAQ — and hands off cleanly on anything that looks like advice — resolves the majority of inbound calls about renewals, endorsements, claim status and documents. Distribution has a quieter problem: partner websites. A bancassurance or broker network generates dozens of co-branded sites, each built by a different agency, each carrying product wording the compliance team has to police by hand. A single managed microsite platform, assembled from compliance-approved content blocks with AI doing the localisation drafts and the wording checks, launches a partner in days and propagates a disclaimer change in hours. It is unglamorous and it pays for itself in the first compliance cycle.

Fraud and leakage: anomaly detection beats rule sprawl

Every claims system has a rules engine and every rules engine has a maintenance backlog. Rules catch the patterns someone thought to write; anomaly detection across bills, providers, members and claim histories catches the ones nobody wrote a rule for — a hospital whose average length of stay drifts upward for one procedure, a repairer whose estimates cluster just under the approval threshold. The requirement is an explanation the investigator can act on, not a score. Run it after adjudication as a second pass and it never slows the clock.

Why insurance AI has to be sovereign

Everything above touches special-category data: medical records, financial statements, identity documents. India's Digital Personal Data Protection Act, the GDPR and HIPAA each treat that data as the most tightly controlled kind, and the EU AI Act adds logging and traceability duties for the high-risk cases. Sending a claim file to a public model API is a contract you cannot show a regulator and a data flow you cannot audit. The sovereign pattern — open-weight models served on your own infrastructure, a gateway that logs every prompt and response, a model inventory, and a human-in-the-loop queue — is not the expensive option any more. It is the only one that survives both the regulator and your own client's auditor, and for a TPA that answers to several insurers, it is the one that wins the next contract.

A 90-day plan

Days one to thirty: stand up the platform inside the perimeter before any use case, close the vendor pilots that trained on your data, and create the model inventory. Days thirty to sixty: put document extraction and completeness checking on the highest-volume intake — pre-auth for a TPA, FNOL or motor for a general insurer — with the adjudicator queue designed before the model is tuned. Days sixty to ninety: add drafted decisions with reasons, measure straight-through rate and time inside the regulatory window, and score the next three use cases with a governance board that includes the medical director and the CISO. If you want the longer version of the operating model, we have written it up separately as the AI Centre of Excellence that actually ships.

What to avoid

Do not start with pricing; it is the most regulated use case and the least document-bound. Do not buy a chatbot without the retrieval index and the hand-off designed first. Do not accept a pilot that runs on a vendor's cloud with your claim files. And do not measure the programme in models deployed — measure it in hours inside the regulatory window, claims settled straight through, and the auditor's first question answered from a log rather than a meeting.

Saurabh Goenka
About the author

Saurabh Goenka

Founder & CEO, MindMap Digital

Saurabh has spent the last five years shipping sovereign AI for regulated enterprises. He's personally led engagements with tier-1 banks across the Gulf, East Africa and South Asia, with healthcare systems in the UK and India, and with central-government agencies on three continents. He speaks regularly at industry forums on the engineering reality of EU AI Act compliance and sovereign LLM deployment.

Credentials + recognition
  • NASSCOM Tech Excellence 2026 — Healthcare AI category winner
  • Hindustan Times 40 Under 40 (2026)
  • ET NOW 40 Under 40 (2026)
  • Outlook Dynamic Leaders (2025)
  • ICAI 40 Under 40 (2025) · Chartered Accountant
  • Forbes Business Council member (2021–present)
  • 50+ enterprise AI deployments shipped
Areas of repeated lived expertise
Sovereign AI architectureEU AI Act + RBI + SAMA compliance engineeringBFSI AI transformationHealthcare AI at scalePublic-sector AI deployment
More Insights

Keep reading

View all insights →

Ready to apply these ideas?

Talk to our engineering team. No sales pitch — just a technical conversation.

Start a conversation →
Talk to the product team