Corporate Governance Frameworks for Insurers: From Reactive Compliance to Governance Intelligence
Most insurers already have a governance framework. The harder question is whether it would catch a problem in time — or only explain it afterward.
Most insurers already have a governance framework. Almost none of them are confident it's actually working.
The gap isn't usually about missing structure. Boards exist, risk committees meet, and the documentation is often thorough enough to satisfy a supervisor. What's harder to build is a framework that surfaces the right concern at the right time — before it shows up as a loss, a regulatory finding, or a headline. That distinction, between having governance and having governance that works, is where most insurers still fall short.
What a governance framework is actually meant to do
The IAIS Insurance Core Principles set the closest thing insurance supervision has to a global baseline. ICP 7 covers corporate governance directly — the responsibilities of the board, fit-and-proper requirements for key functionaries, and the separation between oversight and management. ICP 8 sits alongside it, covering risk management and internal controls, including the control functions that are meant to give a board independent visibility into what's actually happening in the business. For insurers operating across borders, ComFrame extends the same thinking to group-wide supervision, so a holding company can't rely on governance that only holds at the entity level. None of this is new, and none of it is unique to any one insurer. What varies enormously is how these principles get implemented — whether a board genuinely gets independent, timely signal, or whether it gets a well-formatted report that arrived too late to change anything.
Where the framework usually breaks down
I spent years watching this gap play out before I ever tried to build software for it — the pattern is what eventually became the subject of Not on My Watch, a business narrative about a CEO navigating a private-equity-backed turnaround, and about the gradual way organisations drift before anyone names the decline. The observation underneath both the book and everything that followed from it is simple: companies rarely fail because they lack information. They fail because people stop seeing what has gradually become normal — because what an organisation tolerates, it eventually cultivates. In governance terms, that failure tends to show up in three specific places.
Cadence. Most governance frameworks are built around scheduled reviews — quarterly board packs, annual audits, periodic risk committee meetings. Between those checkpoints, risk doesn't pause. A framework built entirely on fixed intervals will always be, at best, current as of the last meeting. This is precisely the space between "Operations," where decisions get made every day, and "Audit," where oversight happens after the fact — a gap wide enough that a lot can drift before either side notices.
Aggregation. Insurance risk rarely announces itself as a single number. It shows up as a pattern across underwriting, claims, distribution, conduct and operations — settlement inflation, pricing drift, authority thresholds bypassed a little more each quarter — and those functions are usually monitored separately, on separate schedules. A governance framework that reviews each function in isolation can look clean in every silo while missing a problem that only exists at the intersection of two or three of them.
Escalation. Even when a concern is identified at the operational level, getting it in front of the board with enough context and urgency is often the weakest link in the chain. Signals get summarised. Summaries get shortened further as they move up. By the time something reaches board level, it can already be stripped of the specifics that made it worth escalating in the first place — leadership left reasoning about last quarter's picture, not this week's.
“These are structural issues, not failures of individual people trying to do their jobs. They're also the reason I've spent the past several years building governance and decision-support platforms for insurers alongside writing about the same problem.”
From compliance to governance intelligence. Compliance-driven governance asks a narrow question: did we follow the process? That question matters, and no framework should abandon it. But it's a backward-looking test. It confirms that a control existed and was executed. It says very little about whether the control caught what it was supposed to catch.
Governance intelligence asks a different question: what does the current pattern of information across the business suggest a board — or the operations underneath it — should be paying attention to right now? That's a harder problem, because it requires connecting signals across functions that were never designed to talk to each other, and doing it continuously rather than at the next scheduled review.
What a robust framework looks like in practice
A governance framework built for continuous oversight rather than periodic compliance tends to share a few characteristics, regardless of jurisdiction or company size:
Independent lines of sight, not just independent committees.
The three-lines-of-defence model (business operations, risk and compliance oversight, internal audit) only works if each line genuinely has visibility the others don't, rather than reviewing the same summarised reports at different points in the calendar.
Assumptions that are made visible, not just numbers. A forecast, a reserve estimate, or a capital projection is only as reliable as the assumptions underneath it. A framework that surfaces the assumptions — and flags when they shift — gives a board something to act on earlier than one that only reports the resulting figure.
Escalation paths that preserve detail and stay explainable. The specific transaction, the specific exposure, the specific pattern that triggered a concern should still be visible at board level, along with the reasoning behind why it was flagged — not smoothed into a general statement that something is "within tolerance."
Group-wide consistency. For insurers with cross-border operations, governance that holds at head-office but weakens at the subsidiary or market level isn't really group governance — it's an aspiration with a gap in the middle, which is precisely what ComFrame was designed to close.
The custodian's question
None of this is really about compliance, even though compliance is the language the industry usually reaches for. It's about whether a board can trust that it's seeing the business as it actually is, not as it was several weeks ago, or as it looks once every function has had a chance to explain its own numbers favourably.
That's a question of custodianship as much as governance: not "did we follow the process," but "would we have seen this in time." A framework built to answer the second question will usually satisfy the first one as a byproduct. A framework built only to answer the first rarely gets close to the second.
