AI Knowledge Hub

How should delegated authority firms document AI decision-making for audit and regulatory purposes?

Quick answer

Firms should keep two distinct layers of documentation for AI use in delegated authority: a governance framework describing how AI is overseen generally, and decision-level records showing what a specific AI system did, with what confidence, and what human review took place for an individual case. The decision-level layer is what allows a firm to answer a specific audit or regulatory question about a particular bordereau or decision, and it needs to be captured automatically as part of the process rather than reconstructed afterwards from memory.

What to remember

Key takeaways

  • Governance framework documentation and decision-level audit trail serve different purposes and both are needed.
  • Decision-level records should show what the AI recommended, its confidence, and what human review took place.
  • This documentation should be captured automatically as part of the process, not reconstructed after the fact.
  • Clear documentation supports internal audit, external audit and regulatory review without needing a separate exercise each time.

Delegated authority firms adopting AI-assisted bordereaux processing are usually aware that they need a governance framework: who is accountable, what oversight exists, how the AI is monitored.

Fewer firms plan, from the outset, for a question that internal audit, external audit or a regulator can ask about a specific case: why did the process treat this particular bordereau entry the way it did, and what human review took place?

Answering that question requires a different kind of documentation from a governance policy. It requires a record of what actually happened for that individual decision, captured at the time it happened.

Two layers of documentation firms need

It helps to separate two things that are often discussed together but serve different purposes.

The first is governance framework documentation: the policy describing how AI use is overseen, who is accountable, what controls exist, and how the system as a whole is monitored and reviewed. This answers the question "how do we manage AI use generally".

The second is decision-level documentation: the record of what happened for a specific bordereau entry or decision, including what the AI system output, its confidence, whether it was escalated, and what a human reviewer decided. This answers a different question: "what happened in this particular case, and why".

Firms that have only built the first layer often discover, when an auditor or regulator asks about a specific case, that they cannot answer without reconstructing events from memory or informal notes, which is neither reliable nor efficient.

How delegated authority firms traditionally documented decisions

Before AI-assisted processing, decisions made by underwriters or operations staff were typically documented through case notes, sign-off records, and audit trails built into policy administration or bordereaux systems.

These records existed because manual decisions have always needed to be explainable after the fact, whether for internal quality review, external audit, or a coverholder dispute. The expectation that a decision can be reconstructed and explained is not new.

What is new is that some of the interpretive work behind a decision is now performed by an AI system rather than a person, and that work needs to be documented with the same rigour as a human decision, even though it happens differently.

What decision-level documentation looks like for AI-assisted processing

For an individual AI-assisted decision, useful documentation typically includes what the AI system extracted, mapped or flagged, its confidence score at the time, whether that score triggered escalation to human review under the applicable threshold, who reviewed the escalation if one occurred, and what they decided and why.

This does not need to be a lengthy narrative. In most cases, a structured, machine-generated record capturing these elements is more reliable and more useful than a manually written summary, since it is created automatically and consistently rather than depending on someone remembering to write it up.

The important distinction to preserve is between what the AI recommended and what a human ultimately decided, particularly where the two differ, since that difference is often exactly what an auditor or regulator wants to understand.

Making documentation part of the process, not an afterthought

The most reliable way to produce this documentation is to build its capture into the AI-assisted process itself, so that every decision generates its own record automatically, rather than relying on staff to document cases retrospectively.

Retention periods and access controls for this documentation should generally align with the firm's existing audit, compliance and record-keeping requirements for the underlying business process, rather than being treated as a separate policy area specific to AI. Firms should confirm the retention period that applies to their own situation rather than assuming a fixed rule applies universally.

Where this documentation exists as a natural by-product of the process, internal audit, external audit and regulatory review can draw on it directly, rather than requiring a separate reconstruction exercise each time a question is asked.

Example

An insurer's internal audit function reviews a sample of claims bordereaux entries that were processed with AI assistance over the previous quarter, as part of a routine audit cycle.

For each sampled entry, the audit team can see what the AI system extracted, its confidence score, whether the entry was escalated for human review, and the reviewer's decision and reasoning where applicable. Because this information was captured automatically at the time of processing, the audit is completed without needing operations staff to reconstruct individual cases from memory.

FAQs

  • Is decision-level documentation the same as an AI governance policy?

    No. A governance policy describes how AI use is overseen in general, including accountability and monitoring arrangements. Decision-level documentation records what happened in a specific case. Firms need both, and they serve different audiences and purposes.

  • How long should decision-level AI documentation be retained?

    Retention periods should generally align with the firm's existing audit, compliance and record-keeping requirements for the underlying business process, rather than being set separately for AI-assisted cases specifically. Firms should confirm the applicable requirement for their own situation, since this can vary.

  • Does this documentation need to be reviewed manually for every case?

    No. Most firms rely on automated capture of the record at the time of processing, combined with periodic sampling for audit purposes, similar to how other operational controls are typically reviewed, rather than manually reviewing every single AI-assisted decision as it occurs.

What's next?

Your BDX Insights

Your BDX Insights

Answer six quick questions about your bordereaux data and tooling, and we'll give you instant, tailored insights into how you can use AI to help your BDX processing — plus a perspective we think is worth your time as you answer each question.

Our latest insurance insights