Ask a carrier or MGA what its risk appetite is and you get a PDF. Ask the systems and you get three different answers: eligibility logic hard-coded in the policy administration system, a spreadsheet of class limits the product team maintains, and a set of referral habits that live in senior underwriters' heads. An automated underwriting system is supposed to make those three the same thing. In most carriers they drift apart quarter by quarter, and the underwriting queue absorbs the difference.
That drift has a number attached: straight-through processing rate. Personal auto and home bind most clean risks without a human. Mid-market commercial rarely comes close, because a single risk carries far more variables - class code, total insured value, protection class, loss history, schedule credits - and every rule that handles them is another ticket in the PAS backlog. Submission-triage vendors commonly report that roughly a quarter of incoming submissions fall outside the carrier's own stated appetite and are still screened by hand. The risks that could have bound in seconds wait behind them.
Then come the questions a spreadsheet cannot answer. Which version of the eligibility rules bound this policy last March? Who raised the TIV ceiling, who approved it, and what did it do to the referral mix? Supervisors now ask sharper versions of the same thing. The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted in December 2023 and issued in roughly half the states, expects a documented governance program covering underwriting and rating. NYDFS Circular Letter No. 7 (2024) expects New York insurers to test and document how automated underwriting and external consumer data affect protected classes. In the EU, AI systems used for risk assessment and pricing in life and health insurance sit in Annex III of the AI Act as high-risk.
If your underwriting rules are a vendor config export and a folder of change-request emails, every one of those conversations is harder than it needs to be.