Skip to content

AI in Insurance: Claims, Underwriting and KVKK

Claims automation, underwriting, fraud detection and policy RAG. AI use cases in insurance and KVKK obligations for high-risk automated decisions.

SYK
Şükrü Yusuf KAYA
AI Expert · Enterprise AI Consultant

TL;DR — Insurance is one of the industries where artificial intelligence delivers the most concrete value: automated claims triage, underwriting risk scoring, RAG-powered customer service over policy documents, and usage-based pricing built on telematics data all sit within reach today. But insurance is also one of the sectors most exposed to "high-risk automated decisions": when an underwriting model misfires, it can misprice real people; when a claims model misfires, it can deny a legitimate claim. In this piece I'll walk through both the concrete use cases and the governance requirements that come with them — grounded in KVKK Article 11, the EU AI Act's August 2026 enforcement milestone, and the regulatory framework of SEDDK, Turkey's insurance regulator. My goal is to move you from the question "where should we put AI" to the question "how do we put AI in responsibly."

Why Insurance Is Different: Abundant Data, Heavy Decisions

Among the industries I consult in, insurance is one where AI projects generate business value the fastest — and simultaneously one where you need to tread the most carefully. There are two reasons for this. First, insurance companies already sit on structured, historically rich data: policy records, claims files, payment histories, call center transcripts, and in some cases telematics and IoT data. This is an ideal foundation for feeding large language models and machine learning. Second, the core function of insurance — pricing risk and compensating loss — touches people's wallets and rights directly. If an e-commerce recommendation engine suggests the wrong product, nobody is harmed. But if an underwriting model produces the wrong risk score, a family pays a higher premium for years; if a claims model wrongly flags "fraud," an honest customer doesn't get compensated.

This dual nature — high value potential and high sensitivity — explains why an AI strategy in insurance shouldn't proceed as "technology first, governance later," but rather as "technology and governance together." In this post I'll first walk through six concrete use cases one by one, then discuss which of these are considered "high-risk," what explainability and fairness require, why human oversight matters, and finally the regulatory framework specific to Turkey.

1. Claims Management: Automation and Fraud Detection

Claims management makes up the bulk of an insurer's operational cost and is simultaneously the most critical moment of the customer experience. A customer doesn't really get to know a company when they buy a policy — they get to know it when they file a claim. AI enters at three layers here:

Triage and routing. Incoming claims can be automatically classified by complexity, amount range, and documentation completeness. Simple, low-value, fully documented files get routed to fast-track processes, while complex or suspicious files go to experienced adjusters. This means human capacity gets directed to where it creates the most value.

Fraud detection. Fraudulent claims are a chronic problem in the insurance sector, and this is where AI genuinely makes a difference. Anomaly detection models learn the patterns of past fraud cases — repeated claims from the same address, losses that occur right after a policy starts, the same repairer-adjuster-customer triangle recurring — and prioritize suspicious files accordingly. The critical point here: the model shouldn't say "this claim is fraudulent," it should say "this claim merits review, for these reasons." The final decision must always rest with a human; otherwise you risk both unjust denials and reputational damage.

Straight-through processing. For very low-value, clearly documented, low-risk files, full end-to-end automation is possible. For example, in a cracked-phone-screen claim, if the invoice, photo, and policy coverage all match, the system can trigger payment without a human ever touching the file. What matters here is that the file types eligible for this scope are defined in advance with clear criteria, and that these thresholds are reviewed regularly.

Companies that build these three layers together shorten claims payment times while also freeing up adjuster capacity for genuinely complex cases. But I need to say this plainly: fraud detection models, if poorly designed, can produce systematic bias against certain demographic groups or geographic regions. I'll cover this in more depth under "fairness" below.

2. Underwriting and Risk Pricing

Underwriting is the heart of insurance, and it's the area where AI generates the most business value while simultaneously drawing the most regulatory attention. Traditional underwriting relies on actuarial tables and a limited number of variables (age, occupation, medical history, vehicle model, and the like). Machine learning models can dramatically expand this variable set and produce much finer-grained risk segmentation.

Concrete examples:

  • In life and health insurance, AI-assisted risk scoring can produce more accurate risk classification by combining health declarations, historical medical records (to the extent permitted), and lifestyle data.
  • In motor and auto liability insurance, vehicle model, usage history, claims history, and — where telematics exist — driving behavior can be combined for dynamic pricing.
  • In commercial insurance (property, liability, cargo), a business's sector, historical claims frequency, geographic location, and even publicly available news or data sources can be incorporated into risk assessment.

Here I want to share a misconception I frequently encounter in consulting work: "more data means a better model" isn't always true. Every variable a model uses as input, directly or indirectly, can correlate with a protected category (ethnicity, disability status, gender) and the model can "learn" this correlation, producing indirect discrimination. For example, a postal code doesn't directly signal race or income, but because of historical settlement patterns it can carry a strong correlation with those variables. This is why variable selection in underwriting models needs to happen alongside a fairness audit, not just a statistical performance review.

There's also an important operational problem when underwriting models become "black boxes": an insurance company that can't answer why a policy was declined or why it was priced so high can't account for itself to a regulator or a customer. This is why models used in underwriting need, at minimum, an explainability layer capable of describing the three-to-five factors that most influenced a decision in plain human language.

3. Customer Service: Chatbots and RAG Over Policy Documents

Insurance policies are technical, legally worded documents that the average consumer struggles to read and understand. This is exactly why a large share of customer service and call center load consists of "is this covered by my policy" type questions. Large language models and RAG (retrieval-augmented generation) architecture offer a genuinely practical solution here.

The logic behind RAG is simple: instead of generating an answer "from memory," the model first retrieves the relevant passages from the company's own policy texts, general terms, and special terms, then generates its response based on those passages. This approach has two major advantages:

  1. Hallucination risk drops because the model references actual policy text instead of inventing out-of-scope information.
  2. Auditability increases because every answer can be traced back to the document passage it relied on — this provides a critical chain of evidence both in customer complaints and in regulatory audits.

That said, I want to flag two traps here. First, if RAG systems don't correctly manage the hierarchy between "general terms" and "special terms," they can give the customer incorrect coverage information — for example, an exclusion found in the general terms may have been overridden by that particular policy's special terms, and the model may fail to distinguish this. Second, the chatbot needs to draw a clear line that "this is not advice, the final decision belongs to the claims/underwriting team"; otherwise a customer might treat a chatbot's answer as binding and suffer a loss of rights, exposing the company to reputational and legal risk as well.

A well-designed RAG-powered customer assistant can handle the bulk of policy inquiries, claims-initiation, premium payment reminders, and simple FAQ traffic without human intervention, freeing call center teams to focus on more complex and emotionally sensitive conversations — for instance, a bereaved family member following up on a claim process.

4. Document and Image Processing: OCR and Damage Photo Assessment

Insurance is still a paper- and photo-heavy industry. Claims files consist of a wide variety of document types — invoices, adjuster reports, medical reports, vehicle damage photos, sometimes accident reports. AI enters here through two technical areas:

OCR and document classification. Modern OCR (optical character recognition) systems no longer just "read" text — they classify document type (invoice, prescription, accident report), automatically extract relevant fields (amount, date, party names), and can push this information directly into the structured fields of a claims file. This meaningfully reduces manual data entry and prevents human error, such as an incorrectly entered amount.

Damage photo assessment. Computer vision models can estimate the location, severity, and expected repair cost of damage from vehicle photos. This speeds up the adjustment process especially in auto claims: for simple, clear-cut damage, the model performs a preliminary assessment that makes the adjuster's job easier; for complex or ambiguous damage, a human adjuster still needs to step in.

There's a caution to flag here too: vision models can lose reliability for vehicle models, damage types, or lighting/angle conditions that were underrepresented in the training data. A model's claim of "90 percent accuracy" shouldn't be accepted without asking under what conditions that 90 percent was measured. Photo-based damage estimation should also be tested against deliberately manipulated photos — taken from a misleading angle, or concealing pre-existing damage — both for model robustness and for fraud prevention.

5. Churn Prediction and Cross-Sell

In insurance, retaining customers is often cheaper and more profitable than acquiring new ones. AI-powered churn models can predict, ahead of the renewal period, which customers are more likely to leave — by combining signals like payment delays, call center complaint frequency, and activity on competitor price comparison sites. This lets the customer relationship team proactively reach at-risk customers with a price review or additional service offer.

On the cross-sell side, a customer's existing policy portfolio, life stage signals (buying a home, getting married, having children — though of course processing this kind of personal data requires explicit consent and purpose limitation under KVKK), and the purchase patterns of similarly profiled customers can be analyzed to make the right product recommendation at the right time. For example, offering home insurance to a customer who has auto coverage but not home coverage, once a signal indicates they've become a homeowner.

This area is relatively "lower risk" compared to claims and underwriting, since it doesn't directly cause a loss of rights. Still, two points deserve attention: first, the datasets feeding churn and cross-sell models need to have been collected in compliance with KVKK; second, companies should be aware that "aggressive" churn-prevention tactics — like offering a discount only to high-churn-risk customers while leaving loyal customers on a higher price — can erode brand trust over the long run.

6. Telematics and Usage-Based Insurance (UBI)

Telematics-based, usage-based insurance (UBI) is the most data-intensive AI application area in insurance. Driving data (speed, braking behavior, cornering acceleration, frequency of night driving, phone use while driving) is collected through a device installed in the vehicle or a smartphone app, and this data is used instead of, or alongside, traditional demographic factors (age, gender, region) in pricing.

The promise of UBI is clear: careful, low-mileage drivers pay lower premiums — which is both fairer to the customer and produces more accurate risk pricing for the insurer. A similar model is spreading in health insurance too — "wellness"-based premium discounts built on data collected from wearable devices (step count, sleep patterns, and the like).

But UBI is one of the most sensitive data processing areas in insurance from a KVKK perspective. Driving data or health/wellness data amounts to continuous, granular personal tracking. Because of this:

  • The scope of data collection must be purpose-limited (only variables relevant to pricing should be collected; out-of-scope data like location history shouldn't be retained).
  • The consent process must be clear enough for an average consumer to genuinely understand — a long text hidden behind an "I agree" checkbox doesn't meet the "informed consent" standard KVKK requires.
  • Data retention periods and deletion policies must be clearly defined; processing must stop when the policy ends or consent is withdrawn.
  • When health data is involved, KVKK's special category personal data regime (Article 6) kicks in, and processing conditions become far stricter.

The most common mistake I see in companies I consult with is launching UBI projects with technical feasibility first and leaving KVKK compliance for last. The correct order is the reverse: first clarify what data will be processed, for what purpose, and for how long — then design the technical architecture around that.

The Governance Layer: Why These Decisions Are "High-Risk"

All six use cases I've described so far are valuable, but they don't all carry the same level of risk. A chatbot giving a wrong FAQ answer and an underwriting model placing a person in the wrong risk class can't be evaluated in the same category. Regulatory frameworks — both the EU AI Act and the spirit of KVKK — draw this distinction the same way: whether a decision significantly affects a person's legal standing or their access to important opportunities.

Underwriting and claims pricing fit this definition precisely, because:

  • They directly determine whether a person can be insured (access to a service).
  • Pricing directly affects a person's financial burden.
  • Claims denial decisions can add further financial loss on top of a loss the person has already suffered (an accident, illness, or loss).
  • These decisions are generally made at the "individual" level rather than in aggregate — meaning they're issued based on that specific person's data.

This is why AI systems used in these two areas — underwriting and claims pricing/denial decisions — need to be handled not with an "experimental" or "move fast" mindset, but with the discipline of high-risk system management. That discipline rests on three pillars: explainability and fairness, human oversight, and data quality and bias control. Let's go through each in turn.

Explainability and Fairness: Avoiding Discriminatory Pricing

Explainability is a model's ability to articulate, in human language, why it produced a particular output. In insurance this isn't just "good practice" — it's frequently a regulatory requirement, because in order for KVKK's right to object to automated decisions (detailed below) to be meaningful, a company needs to be able to answer the question "how did your model reach this decision."

The practical approach I recommend:

  1. Make explainability a criterion in model selection. Before choosing highly complex, "black box" models (certain deep-learning-based scoring systems, for instance) for a marginal accuracy gain, that gain should be weighed against the explainability it costs. In some cases, simpler, interpretable models (decision trees, generalized linear models) are preferable for high-risk areas like underwriting.
  2. Build an explanation layer. Even when black-box models are used (say, because the accuracy advantage is substantial), a layer using methods like SHAP or LIME should be added so the system can say "the three factors that most influenced this decision were X, Y, Z."
  3. Make fairness auditing a recurring, ongoing process. Break down model outputs by demographic group (age, gender, geographic region, disability status — to the extent the law permits) and test whether there's a systematic gap between groups with similar risk profiles. This shouldn't be a one-time "pre-launch check" — it should be a recurring audit that continues while the model is live, because data drift can produce new biases over time.
  4. Pay special attention to proxy discrimination. It's not enough to simply never feed a directly prohibited variable (like ethnicity) into the model; seemingly innocent variables like postal code, occupation, or even phone brand can carry strong correlation with protected categories. The effect of these variables needs to be tested separately.

There's an objection I hear often in the industry on this topic: "But if the risk is genuinely different, pricing differently isn't discrimination — it's actuarial accuracy." This is partly true — risk-based pricing is the fundamental logic of insurance. But the real question is whether the model is learning "actual risk" or "historical bias baked into the data." If a region historically received insufficient staffing and its claims processes therefore ran slower, a model might learn "this region is risky" — when in fact this reflects an operational bias, not the risk itself. Making this distinction requires a good data science team working closely with a good legal/compliance team.

Human Oversight: Why Human-in-the-Loop Is Non-Negotiable

The concept of "human-in-the-loop" oversight is often misunderstood — some companies reduce it to a superficial step where a human looks at the model's decision on a screen and clicks approve. Genuine human oversight requires far more than that:

  • Meaningful authority to intervene. The human reviewer needs to actually have the time, authority, and knowledge to change the model's decision. An adjuster clicking "approve" on 200 files a day isn't real oversight — this is what's known as "rubber-stamping," and it's one of the practices regulators criticize most.
  • Risk-tiered oversight. Not every decision needs the same level of human review. Low-value, well-documented claims files can be processed automatically; high-value, borderline, or suspicious files must always go before an experienced human. Similarly in underwriting, model recommendations for standard risk profiles can go through expedited approval, while borderline or unusual profiles need a human underwriter's involvement.
  • Extra scrutiny for decisions that negatively affect someone. A claims denial or a large premium increase — decisions that adversely affect a person — should always require human review, both to make KVKK's right to object to automated decisions meaningful and simply as a matter of basic fairness.
  • A feedback loop. Cases where human experts override the model's recommendation should be systematically logged and regularly analyzed — this both surfaces the model's weak points and answers the question "is the human genuinely reviewing, or just automatically approving."

I want to share an observation here: the companies that make human oversight genuinely functional treat it not as a "compliance checkbox" but as a quality control and model-improvement mechanism. In other words, a human expert's objections don't just correct that one file — they get fed back into the model's next training cycle as data. This strengthens compliance while also genuinely improving model quality.

Data Quality and Bias

The fairness of an AI model is largely bounded by the quality of the data it's trained on — the "garbage in, garbage out" cliché applies here in its fullest sense. In insurance, the data quality and bias problem is fed by several sources:

Persistence of historical bias. If a particular customer segment has historically been served more slowly, investigated more often for suspected fraud, or priced higher, a model trained on this historical data reproduces — and can even reinforce — this bias as "learned truth." A model can't be better than the quality of the historical human decisions it's trained on; instead, it repeats those decisions at scale.

Missing or unbalanced representation. If there isn't enough data from certain regions, age groups, or product segments, the model produces less reliable predictions for those groups — but this unreliability is usually invisible, since the model always outputs a number and never says "I'm not confident about this." This is why model performance needs to be reported at the sub-segment level rather than as an aggregate accuracy figure alone.

Implicit selection bias in the data collection process. For example, if a company trains a model only on data from customers who purchased policies through a digital channel — a group with a particular income and technology-access profile — that model won't generalize well to a different demographic coming through phone or agency channels.

Practical recommendation: build a "data lineage/data card" into the model development process from the moment data is collected — documenting where the data came from, what period it covers, and which segments it's missing. This lets you answer, quickly and with evidence, the question "why is our model underperforming for this group" when it inevitably comes up.

Turkey Context: KVKK, the EU AI Act, and SEDDK

If you operate an insurance company in Turkey, or provide technology services to this sector, you need to watch three regulatory layers simultaneously.

KVKK and the right to object to automated decisions. Article 11 of Law No. 6698 on the Protection of Personal Data lists the rights of the data subject, and among these rights is explicitly "the right to object to a result that emerges to the person's detriment solely through the analysis of processed data by automated systems." This is a vital provision for insurance: if a claims denial or premium increase decision is issued entirely by an automated system without human intervention, the person can object to that decision, and the company must evaluate that objection meaningfully. This is exactly why the human oversight mechanism described above isn't a "nice-to-have" but a legal requirement. Additionally, under the disclosure obligation in Article 10 of the Law, customers must be clearly informed about which of their data is used for what purpose in automated decision processes; when special category data (like health data) is involved, the stricter processing conditions under Article 6 apply.

The EU AI Act and the August 2026 threshold. Even though Turkey isn't an EU member, this regulation matters for two reasons: (1) direct applicability may arise for Turkish insurance companies and technology suppliers that serve the European market or work with EU-based reinsurers/partners, and (2) the EU AI Act is becoming a global "reference standard" that will likely shape the future frameworks of regulators like SEDDK. The Act's Annex III (the list of high-risk systems) explicitly classifies AI systems used for risk assessment and pricing in life and health insurance as high-risk. This creates obligations to establish a risk management system, meet data quality requirements, maintain technical documentation, ensure human oversight, and fulfill transparency obligations for these systems. The Act's implementation timeline is phased: prohibited practices took effect in early 2025, obligations for general-purpose AI models took effect in mid-2025, and most of the core obligations for high-risk systems take effect on August 2, 2026. This date is a genuine preparation milestone for every institution using AI in insurance — if your business model touches the EU, your risk management system, documentation, and human oversight mechanisms are expected to have matured by this date. Worth noting: in non-life/health lines like motor or home insurance, underwriting isn't classified as high-risk with the same directness in Annex III, but this doesn't exempt these companies from the regulation's general transparency and good-governance expectations — the prudent approach is to manage all underwriting and pricing systems with a similar level of discipline.

SEDDK and Turkey's regulatory context. The Insurance and Private Pension Regulation and Supervision Agency (Sigortacılık ve Özel Emeklilik Düzenleme ve Denetleme Kurumu, SEDDK) is Turkey's independent regulator responsible for licensing, supervision, solvency, and market conduct oversight in the insurance and private pension sector. SEDDK's focus to date has largely centered on solvency, actuarial standards, and consumer rights; a comprehensive AI-specific regulation similar to the EU AI Act isn't yet in force in Turkey. But it would be a mistake to read this as "anything goes with AI" — SEDDK's existing regulatory framework already contains principles like "fair pricing," "informing the consumer," and "functioning complaint mechanisms," and these principles apply regardless of whether a decision was made by a human or an algorithm. The trend I observe is that regulators worldwide are moving toward publishing more AI-specific guidance, and it's plausible that SEDDK will develop a similar framework over the medium term. My recommendation, therefore, is not "wait until regulation arrives," but "adopt KVKK and international good practices (including the EU AI Act) now, and turn regulatory readiness into a competitive advantage."

Putting these three layers together produces a clear principle: for an institution using AI in insurance in Turkey, the minimum standard is the human oversight and objection mechanism required by KVKK Article 11; the target standard is the high-risk system requirements of the EU AI Act (risk management, documentation, fairness auditing, transparency). Companies that close this gap before regulation forces them to gain an edge both in legal risk and in reputation.

Adoption Roadmap: Where to Start

The roadmap I recommend to insurance companies in my consulting work proceeds as follows:

Phase 1: Start with low-risk, high-volume areas. OCR/document classification, call-center summarization assistants, and simple FAQ chatbots generate fast value while carrying low regulatory risk. This phase also matters for getting your team into the habit of working alongside AI.

Phase 2: Roll out RAG-powered customer service and claims triage. In this phase, design and test human oversight mechanisms, especially for denied or borderline decisions. Start in a pilot region or product line, measure results (accuracy, customer satisfaction, objection rate), and expand from there.

Phase 3: Build fraud detection and underwriting support models — but as recommendation engines, not decision-makers. In this phase, institutionalize your fairness auditing, explainability layer, and data lineage processes. The model's output should always be a "recommendation"; the final decision should always remain with a human expert.

Phase 4: Move into the most sensitive areas — telematics/UBI and fully automated straight-through payment. Before entering this phase, a KVKK compliance assessment, an EU-AI-Act-style risk management framework, and a regular fairness/performance auditing process need to already be in place.

Parallel track: Build the governance structure from the very start. Alongside these four phases, a parallel track needs to run continuously: an AI governance committee (spanning data science, legal/compliance, business units, and ideally an external advisor), a model inventory (which model is used where, for what purpose, and by whom), and a regular model audit calendar. This structure isn't "bureaucracy to be added later" — it's a precondition for scalable growth.

Common Pitfalls I Keep Encountering

From my field experience, here are the traps insurance companies most often fall into with AI projects:

  • Declaring a pilot "successful" and postponing governance. When a model's accuracy numbers look good, the fairness audit and explainability layer get deferred to "later." Later never comes — until a complaint or an audit forces the issue.
  • Turning human oversight into a symbolic gesture. The "rubber-stamping" problem mentioned above — a human approves the model's recommendation without genuinely evaluating it. This fails to meet the standard of meaningful human intervention that KVKK requires, and it also prevents model errors from being caught.
  • Training a model once and forgetting about it. Risk profiles, economic conditions, and customer behavior change over time in insurance (data drift). Without regular retraining and performance monitoring, a model that started out fair and accurate can become both inaccurate and unfair over time.
  • Treating a vendor's model as an untouchable black box. If an externally purchased underwriting or fraud-detection model is in use, failing to demand explainability, training-data lineage, and fairness test results from the vendor — operating on a "they're the experts, we trust them" basis — is an attempt to offload ultimate responsibility, which regulators will always hold with the data controller, the insurance company itself. It doesn't work.
  • Treating the KVKK disclosure notice as a legal formality. Whether or not the disclosure text includes the sentence "automated decision processes are used" makes a significant difference in how strong or weak a company's position is in an audit or complaint. This text needs to genuinely reflect which data is used for what purpose in automated decision processes.
  • Rushing because "everyone else is doing it." A competitor's announcement of a chatbot or an automated claims-payment system sometimes pushes companies to deploy similar systems before their governance infrastructure has matured. Speed matters, but in insurance, a system that's "fast but fragile" erodes both customer trust and regulatory relationships over the long run.

The most successful examples I've seen in the field are companies that position AI not as something that "replaces" the underwriter or the adjuster, but as a tool that "helps the underwriter or the adjuster make faster, more accurate decisions." This framing aligns both with regulatory expectations and with the fundamental trust relationship at the core of insurance: the customer entrusts their claim or their policy not to an algorithm, but to an institution that uses that algorithm responsibly.

Consulting Pathways

Consulting pages closest to this article

For the most logical next step after this article, you can review the most relevant solution, role, and industry landing pages here.

Comments