Line of business · Life and health
Pricing a person’s life or health is high-risk by law. You will be asked to prove what never touched the decision.
The law places risk assessment and pricing of natural persons among its highest-risk uses. The hard question is not which features you used — you can list those. It is which ones you did not, and how a person outside your company could ever check the answer.
What breaks in life and health today
Absence is the thing you cannot prove
You can state that a data type was never used. You cannot show it. A statement of intent is what a policy produces; a supervisor asks for a record of what happened.
A boundary written in a document decays
The rule lives in a policy and the enforcement lives in whoever remembers it. Six months and two integrations later, the two have quietly diverged and nothing announced it.
The explanation answers a different question
A feature-importance chart describes a model. It does not tell a person why their application was declined, which is what the courts have now said is owed. (UC039)
Human-side tooling drifts into decision-side use
The same inference that is lawful for coaching an agent is unlawful for deciding eligibility. Nothing in a normal stack stops the second use once the first exists.
The boundary: psychometrics and emotion inference never reach an insurance decision
Psychometrics and emotion inference are never used in underwriting, pricing or claims decisions. Not as a feature. Not as a tie-breaker. Not as a signal carrying a small weight in a larger model. There is no configuration of the product in which a personality inference, a sentiment read or an emotion score influences whether a person is covered, at what price, or whether their claim is paid.
This is prevented architecturally, not by policy. The enforcement is a lineage tag carried by every input and a decision-context gate on every decision: an input whose lineage is psychometric or emotion-derived cannot enter an eligibility, pricing or claims context at all. A policy asks people to remember a rule. A gate does not need them to.
And the part a policy can never do: the record certifies the absence. The decision thread shows that no psychometric input touched it — a negative you can hand to a supervisor, a court or a policyholder, rather than a negative you assert to them (UC097). Proving that something did not happen is normally the hardest evidence to produce. It is the one thing a complete, tamper-evident record of what a decision used makes cheap.
THE HONEST HALF OF THAT COMMITMENT
The lineage tags and decision-context gates are designed and not built. Today the boundary holds because no psychometric input exists anywhere in the insurance decision path and because every read, write and dispatch is already scoped by a shared query predicate rather than by per-route discipline. That is a weaker mechanism than the one described above, and saying so is the point of this block.
[O]ROS/src/middleware/{organizationContext,businessUnitContext,scopeContext}.ts
lineage tags and decision-context gates — designed, not built(designed, not built)
Psychometric capability does exist in the wider platform, for human-side uses only — coaching an agent, reading a business-to-business buying committee, adapting tone — consent-gated, and never in an insurance decision path. Naming it is part of the commitment. A boundary is worth nothing if you cannot see what it is holding back.
[O]ROS/src/services/PsychologicalProfilingService.ts
The legal envelope this sits inside
Which pillars answer it
P5 · for the Chief Compliance Officer
One-Log, Many-Regulator Evidence Fabric
One governed event stream compiles into every regulator’s artefact, instead of four teams reconstructing four different stories from the same week.
One governed event stream carries what the decision used — and, because it is the same stream, what it did not.
shipped(shipped)P2 · for the Head of Claims
The Chaired Deliberation Chamber
Versioned expert personas argue the case from different angles — including one seat whose only job is to attack the conclusion — and a named human chair rules, at a durable waitpoint.
An adverse ruling is argued by seats working from different evidence and ruled on by a named human, at a waitpoint that is part of the record.
shipped(shipped)P3 · for the Chief Risk Officer
Cross-Model Computed Gate → Sealed Certificate
Two or more heterogeneous models re-derive the answer. A computed — not learned — agreement predicate must pass before anything is released, and the inputs and model versions are sealed into the record.
Two heterogeneous models must re-derive an adverse answer and agree before it is released; the inputs and versions are sealed with the verdict.
shipped(shipped)What this does not do yet, on the boundary
WHAT THIS DOES NOT DO YET
- Lineage tags and decision-context gates. The inference boundary is enforced today by the design of the decision path and by review; the mechanism that makes it self-enforcing is new build.
- The jurisdiction-pack emitters.
REFUSED
AUTHORITY_EXCEEDED
An input carrying a psychometric or emotion-derived lineage that reaches for an eligibility, pricing or claims decision is refused by name, and the decision does not proceed.
Dropping the input quietly would leave the same record as never having had it, and those are not the same fact. A refusal a person can read is the only version a supervisor can check. This refusal belongs to the lineage gate above — designed, not built — and it is drawn here so you can hold us to the shape of it.
Start with the decisions a supervisor will ask about first
You can put adverse decisions — declines, exclusions, loadings and denied claims — through the governed path first, and leave everything else where it is. Those are the decisions a supervisor asks about, and they are the ones where being able to show what was not used matters as much as showing what was.