EU AI ACTto the 2 December 2027 Annex III enforcement deadline.Check your tier →
Home · Customer Stories · Health TPA, India
Insurance · Asia

An AI Centre of Excellence for a Health TPA — From a Pre-Authorisation Backlog to a Governed Pipeline of Use Cases

Standing up the operating model, the sovereign platform and the first three production use cases — so IRDAI's one-hour cashless clock became an engineering target rather than a compliance risk.

1 hr
Routine cashless pre-auths decided inside the IRDAI window
12w
Delivery duration
On-Premises
Deployment
6
Accelerators used
On-PremisesHealth TPA, India — 1 hr Routine cashless pre-auths decided inside the IRDAI window
12
Use cases in the governed pipeline
3
In production in the first quarter
1 hr
Pre-auth window met on routine cases
On-prem
Every medical record stays inside the TPA
In this storyAI CoETPAPre-authorisationClaimsSovereign AI
01
The challenge

The challenge

The TPA adjudicates cashless pre-authorisations and health claims for several insurers across a network of thousands of hospitals. In May 2024 IRDAI's master circular on health insurance rewrote the clock: cashless authorisation within one hour of the hospital's request, final discharge authorisation within three hours. The TPA's pre-auth desk was built for a working day, not an hour. Requests arrived as scanned forms, discharge summaries, investigation reports and itemised bills through hospital portals and email, and an adjudicator read every page before checking the tariff and the policy.

AI was already in the building, in the worst possible way. Three vendors had run pilots on pre-auth extraction, a chatbot and a fraud model; none was in production, none had a model inventory or an audit trail, and one had been trained on claim files uploaded to a public API. The Digital Personal Data Protection Act had made that a board-level problem. Leadership wanted an AI Centre of Excellence but had watched two large firms' CoEs produce roadmaps and nothing else.

The brief was blunt: a CoE that ships, a platform the CISO would sign, and the one-hour clock met on the routine cases that make up most of the volume — within a quarter.

02
The approach

The approach

We set the operating model up first and kept it small. A governance board chaired by the Chief Operating Officer with the medical director, the CISO and the head of compliance meets fortnightly and owns one artefact: a scored pipeline of use cases, ranked on claims volume affected, hours saved, regulatory exposure and data sensitivity. Every use case enters through the same intake, gets a model card and a data-protection assessment before build, and is not called 'live' until its human-oversight design has been signed by the medical director.

The platform came second and before any use case. The Sovereign LLM Platform accelerator was deployed in the TPA's own data centre, with DocuMage for document processing, Guardrail System for output checks and Human-in-Loop Manager for the review queues. The three vendor pilots were closed and their data deleted with evidence.

The first three use cases were chosen for volume, not glamour. Pre-authorisation extraction and completeness checking reads the request pack, extracts the fields the adjudicator needs, and returns missing-document queries to the hospital in minutes instead of after a human read. Adjudication assist, built on Prior Auth Accelerator and Claims Router, matches procedures to the tariff and the policy terms and drafts the decision with its reasons; the adjudicator approves, edits or overrides, and every override trains the next version. Anomaly Detector runs across bills and provider patterns and routes outliers to the investigation team with an explanation. MindMap squads built alongside TPA staff, and forty adjudicators, medical officers and analysts went through a practitioner programme so the CoE is staffed by the TPA, not by us.

Accelerators in this engagement

The pre-built building blocks

Rather than commission a ground-up build, the engagement leaned on MindMap's pre-built accelerator library — production-tested components that compress what would otherwise be a six-to-nine-month build into weeks.

Sl

Sovereign LLM Platform

On-prem model serving, gateway and audit logging

Dm

DocuMage

Pre-auth pack intake, extraction and completeness checks

Pa

Prior Auth Accelerator

Tariff and policy matching for pre-authorisation decisions

Cr

Claims Router

Drafted decisions with reasons, routed to the adjudicator queue

Ad

Anomaly Detector

Billing and provider-pattern outliers for investigation

Hl

Human-in-Loop Manager

Adjudicator review queue; every override becomes training data

03
The architecture

The architecture

Everything runs on a GPU cluster in the TPA's primary data centre, on the Sovereign LLM Platform accelerator: open-weight models served through vLLM, a vector store for policy wordings and tariff schedules, and an LLM gateway that logs every prompt and response to an immutable audit store. No claim document, prompt or model output leaves the TPA's network.

DocuMage handles intake from the hospital portal and the claims mailbox: classification, OCR of scans and photographs, extraction into the pre-auth schema, and completeness checks against the request form. Prior Auth Accelerator and Claims Router take the structured request through tariff and policy matching and produce a drafted decision with citations back to the source pages. Human-in-Loop Manager runs the adjudicator queue and captures every edit and override as labelled data.

Integration with the TPA's claims administration system is through its existing APIs; the AI layer never writes a decision directly. Guardrail System checks every drafted communication to a hospital or a member against approved templates. The model inventory, the model cards and the audit logs are exposed to the TPA's insurer clients' auditors through a read-only portal.

The outcomes

The numbers behind the story

12
Use cases in the governed pipeline
3
In production in the first quarter
1 hr
Pre-auth window met on routine cases
On-prem
Every medical record stays inside the TPA

Routine cashless pre-authorisations — complete request packs for procedures within the tariff — are now decided inside the one-hour window, with the adjudicator's approval as the final step. Missing-document queries go back to hospitals in minutes, which removed the largest single cause of pre-auth delay.

Adjudicator time on a routine case has fallen to a review rather than a read, and the same desk handles the volume it used to backlog. Anomaly Detector has surfaced billing patterns across the hospital network that the investigation team is now working through.

The CoE's pipeline holds twelve scored use cases; three are in production, three are in build, and the board has declined two for data-protection reasons — which is the governance working as designed. The model inventory and audit logs passed an insurer client's audit in the first quarter without a finding.

The TPA's own staff run the intake, the board and the review queues. MindMap remains as the engineering partner on a co-run basis, not as the owner of the CoE.

We had three AI pilots and no way to answer an auditor's first question. Within a quarter we had a platform our CISO signed, three use cases in production, and routine pre-auths inside the regulator's hour. The board meets, the pipeline moves, and our people run it.
Chief Operating Officer· Health TPA, India
04
Why MindMap was chosen

Why MindMap was chosen

The TPA had seen the deck-producing version of an AI Centre of Excellence and did not want another. MindMap's CoE method starts with a sovereign platform and a production use case in the first quarter, and it is the method described publicly in our own writing on the subject — the TPA checked it against what we had done elsewhere.

The 117-accelerator library meant the first three use cases were configuration and tuning rather than new software: DocuMage, Prior Auth Accelerator, Claims Router and Anomaly Detector were already in production at insurers on three continents.

The CISO's condition was that no claim record would leave the building and that every model output would be traceable. The Sovereign LLM Platform was the only proposal the TPA received that met that condition without a caveat.

Want an outcome like this?

Start with a 2-week AI Readiness Sprint. We deliver a prioritised use-case backlog and business case grounded in what's actually buildable with our accelerator library.

Book a walkthrough →Explore Insurance
Talk to the product team