Internal Audit And Algorithmic Underwriting In Australia
Algorithmic underwriting is changing how insurers assess risk, price policies, set limits and determine eligibility. Models can process thousands of data points in seconds, identify patterns across large portfolios and support more consistent decisions. They can also introduce errors, hidden bias and control weaknesses at a scale that is difficult to detect through traditional file reviews.
Internal audit has a central role in providing independent assurance over these systems. Its work extends beyond checking whether a model produces statistically reliable results. Auditors must examine governance, data lineage, regulatory obligations, security, explainability, human oversight and the way automated outputs affect customers and the balance sheet.
For Australian insurers, the review also needs to reflect local market conditions. Catastrophe exposure in Queensland and New South Wales, sensitive pricing decisions in home and motor insurance, APRA prudential expectations and obligations under the Privacy Act all shape the control environment. A well-designed audit helps executives use automation with confidence while preserving accountability.
Why Automated Underwriting Needs Independent Scrutiny
An underwriting model may influence acceptance, pricing, exclusions, claims referral or the level of information requested from an applicant. These decisions can be generated by a rules engine, machine learning model, external data service or a combination of technologies. Internal audit should establish exactly where the model sits in the insurance value chain and which decisions depend on it.
Independence matters because model owners are often measured on growth, loss ratios, efficiency or customer conversion. Those objectives can make it difficult for a product or data team to challenge its own assumptions. Internal audit can test whether performance claims are supported by evidence, whether exceptions are handled consistently and whether senior management receives a realistic view of residual risk.
A review should consider both intended and unintended effects. A model might comply with its design specification yet produce outcomes that disadvantage particular customer groups, rely on data that is no longer reliable or behave unpredictably after a portfolio changes. The audit function therefore provides a bridge between technical validation and broader organisational accountability.
Mapping Algorithmic Risk Across Insurance Operations
The first practical step is to create an inventory of automated decision systems. This should cover models developed internally, purchased from vendors, embedded in policy administration platforms and accessed through application programming interfaces. The inventory should identify each model’s purpose, owner, version, data sources, materiality, approval status and connection to pricing or underwriting authority.
Auditors should then map the controls around the model’s full lifecycle. That includes business requirements, data preparation, development, testing, approval, deployment, monitoring, change management, incident response and retirement. A model that appears low risk in isolation may become material when it influences a large book of business or feeds a downstream pricing engine.
The Australian context makes this mapping particularly important. A model used for flood or bushfire risk may affect customers in regional communities as well as policyholders in Sydney, Melbourne or Brisbane. It should be tested against local geographic data, changing weather patterns and the availability of suitable insurance. The audit trail should show who approved the use of each factor and how exceptions are escalated.
Testing Data, Features And Customer Outcomes
Data quality is often the most significant source of model risk. Internal audit should trace important fields back to their origin and assess whether they are complete, accurate, current and used for an approved purpose. This includes checking data supplied by brokers, property databases, telematics providers, credit-related sources and other external partners.
Feature selection deserves careful scrutiny. Variables that appear neutral may act as proxies for characteristics that require greater sensitivity. Location, occupation, payment behaviour or property attributes can create uneven outcomes across communities. Auditors do not need to rebuild every model, but they should understand why material features were selected, whether alternatives were assessed and how management monitors their effect.
Outcome testing should compare model performance across relevant cohorts and time periods. Useful measures can include approval rates, referral rates, premium changes, loss ratios, error rates and complaint volumes. The results should be interpreted by qualified specialists, with documented thresholds for investigation. A model that performs well in aggregate may still produce unacceptable results for a smaller group of policyholders.
For Australian insurers, this analysis should connect with customer remediation and dispute processes. Complaints lodged internally or with the Australian Financial Complaints Authority can reveal patterns that standard model metrics miss. Internal audit can compare complaint themes with model decisions, review whether staff can override automated outcomes and verify that customers receive meaningful reasons where a decision requires explanation.
Evidence That Supports A Defensible Audit
A strong review depends on evidence that allows another qualified person to understand what was decided, why it was decided and whether the decision remains appropriate. Screenshots alone are rarely enough. Auditors should seek version-controlled documentation, test results, approvals and operating records that connect model design to customer and financial outcomes.
The evidence should cover the model’s technical performance and its governance. It should also show how management responds when monitoring identifies drift, unusual results or a material change in the underlying portfolio. The following records are especially useful:
- A current model inventory with owners, risk ratings, approval dates and retirement plans
- Data dictionaries, lineage records and documented explanations for material features
- Independent validation reports covering performance, limitations, bias testing and scenario analysis
- Change tickets, deployment approvals, rollback procedures and records of production incidents
- Monitoring dashboards showing drift, overrides, exceptions, complaints and remediation activity
Audit sampling should be risk-based rather than evenly distributed. A model used for a high-volume consumer product may require more frequent testing than a specialist tool supporting a small commercial portfolio. Sampling should include accepted, declined, referred and manually overridden cases so that the audit captures how the system operates in practice.
The audit team should also assess whether documentation is understandable to decision-makers who are not data scientists. Complex models can be technically impressive while remaining difficult to govern. Clear summaries of purpose, limitations, assumptions and escalation triggers help boards, risk committees and accountable executives exercise informed oversight.
Governance, Accountability And Human Oversight
Effective governance assigns responsibility for the model after deployment, not just during development. The business owner should understand the model’s intended use and limitations, while risk, compliance, technology and actuarial functions should have defined review responsibilities. Internal audit evaluates whether those responsibilities are documented, performed and challenged.
Human oversight must be meaningful rather than symbolic. Staff who can override an automated recommendation need clear authority, training and reasons for intervention. Their decisions should be recorded and analysed. Excessive overrides may indicate poor model performance, confusing workflows or incentives that undermine the original control design.
Governance should also reflect prudential and conduct expectations. APRA’s operational risk focus, including the requirements introduced through CPS 230, makes accountability for critical operations and service providers particularly relevant. Information security controls under CPS 234 are also important when underwriting models depend on cloud platforms, sensitive customer data or connected vendor environments.
Practical controls for senior management include:
- A formal approval committee for material models and significant changes
- Defined thresholds for pausing, restricting or withdrawing automated decisions
- Separation between model development, validation and production approval
- Regular reporting on drift, fairness indicators, overrides, incidents and complaints
- Documented escalation to risk committees, executives and the board when thresholds are exceeded
Internal audit should test whether governance operates in real situations. Reviewing meeting minutes is useful, but auditors should also trace a recent model change from request through testing, approval and implementation. That exercise can reveal informal workarounds, missing sign-offs or gaps between policy and operational practice.
Third-Party Models, Technology And Change
Many insurers rely on external providers for data, scoring, fraud detection, pricing components or complete underwriting platforms. A vendor contract does not transfer accountability for the insurer’s customer outcomes. Internal audit should examine due diligence, service-level obligations, data use, subcontracting, resilience, access management and rights to receive assurance evidence.
The onboarding process should classify providers according to criticality and risk. A vendor supplying a minor analytics tool will require different controls from one operating a model that determines whether thousands of Australians can obtain cover. Auditors can use this vendor onboarding controls resource to connect procurement checks with regulatory compliance, ownership and ongoing monitoring.
Change management is equally important. A seemingly small adjustment to a data feed, threshold or feature can alter underwriting outcomes across a portfolio. Audit testing should confirm that changes are risk-assessed, independently tested, approved by authorised personnel and monitored after release. Emergency changes should receive retrospective review rather than bypassing governance altogether.
Proof-of-concept activity also deserves attention. Early experimentation can involve real customer data, untested external sources or assumptions that later become embedded in production design. A disciplined insurtech proof of concept approach helps define success measures, privacy safeguards, control requirements and exit criteria before a pilot is treated as an operational solution.
Reporting Findings And Building Trust
Internal audit reports should translate technical observations into business consequences. Instead of stating only that a model has weak documentation, the report should explain how that weakness could affect pricing integrity, customer treatment, regulatory reporting, operational resilience or the insurer’s ability to defend a decision.
Findings should be prioritised according to impact and likelihood, with clear owners and due dates. High-priority issues may include unapproved production changes, missing validation, unreliable data feeds, ineffective access controls or evidence that customer outcomes differ materially across cohorts. Management actions should address root causes rather than relying solely on additional manual review.
The report should distinguish between model performance risk, governance risk, conduct risk and technology risk. This allows the audit committee to see whether several findings share a common cause, such as fragmented ownership or weak change control. It also supports better investment decisions when remediation requires new data, specialist capability or platform changes.
Internal audit can add lasting value by returning after remediation. Follow-up work should test whether controls are operating consistently and whether the model’s results have improved. A mature assurance program treats algorithmic underwriting as a continuing risk area, with audit coverage adjusted as products, regulations, vendors and customer expectations change.
Executives who bring together internal audit, actuarial, compliance, technology, underwriting and customer teams gain a more complete view of automated decision-making. At the IASA Conference, insurance professionals can examine these issues alongside peers, technology providers and specialists working across finance, risk, operations and insurtech. Make algorithm assurance part of the next risk and audit agenda, and use that shared discussion to strengthen oversight before a model issue becomes a customer, regulatory or balance-sheet problem.