The Tech Callby Sapio

For insurers · by Sapio

An engineer inside your claims team.

Insurance runs on documents, queues and handovers — which is exactly the work that stalls between a promising pilot and anything a handler uses on a Tuesday. We place one senior engineer inside the team that owns the process, until a single workflow runs every working day — and your people can run it when we leave.

Request the tech call30 minutes, no slides. Bring the queue that never clears.

01 · Why it stalls here

The model was never the hard part. The policy system, the data and the handlers were.

70.3%

of European companies that considered AI and did not proceed say the reason is lack of relevant expertise. Cost is a distant second at 38.4%.

Eurostat, statistical report KS-01-26-009, reference year 2025
72%

of senior executives name integrating AI with existing systems, tools and APIs as a blocker, and 77% name getting people to use it daily.

BCG, The Widening AI Value Gap, 1,250 executives, 2025

Neither of those is a modelling problem. Both are solved by a person who is inside your team, inside your change process, and accountable for one workflow reaching daily use.

Which is the whole of this offer.
A desk in an insurance office: a tall stack of paper claim forms and a ring binder beside a keyboard, one form open with a pen on it.
The work that never reaches a business case: reading one document and typing it into another system, a few hundred times a week.

02 · Where it usually starts

Six places the first workflow tends to come from.

None of these is a strategy. Each one is a specific, boring, countable piece of work that a handler does by hand today — which is exactly what makes it a candidate.

First notification of loss

Claims arrive as email, PDF, photographs and broker files. Turning that into a structured, triaged claim record is routing and extraction work, not judgement work.

Claim file extraction

Repair estimates, medical reports, police reports and invoices, read into the fields a handler would otherwise re-type from a screen beside them.

Coverage and completeness checks

Comparing what arrived against the policy wording and the documents the file still needs — before it reaches a handler, rather than three days into the queue.

Complaints classification

Routing, categorising and logging complaints with an audit trail that satisfies the people who will ask for one.

Policy administration changes

Mid-term adjustments arriving as free-text broker email, matched to policies and prepared for approval instead of keyed in by hand.

Regulatory reporting packs

Assembling the same return from the same sources every quarter is exactly the kind of work that should have stopped being manual years ago.

Which one is right for you is the output of the audit, not of this page. Sometimes the answer is that none of them clears the bar, and that is a cheaper thing to learn in three days than in two quarters.

03 · The part your risk function will ask about

Classification comes before building, in writing.

EU AI Act

Annex III classifies AI used for risk assessment and pricing in life and health insurance as high-risk. Triage, extraction and completeness checks generally are not. Your specific workflow is classified during the three-day audit, because the answer changes the cost and the timeline.

DORA

Insurers and reinsurers are in scope of Regulation (EU) 2022/2554. We expect to sit on your ICT third-party register, work inside your change management, and leave the dependency and failure documentation your risk function will ask for.

GDPR, and health data

Claims files carry Article 9 special category data. The lawful basis and the data path are written down and reviewed by your DPO during the audit — before anything is built, rather than in the week before go-live.

This is engineering practice, not legal advice, and it does not replace your own counsel or your DPO. It exists so that the first question your risk committee asks has a written answer already.

04 · How it runs

Three days to know. Ninety to have it running.

Step one

The tech call

30 minutes · no charge

You describe the queue. We tell you whether it is worth doing, what the first step is and what it costs. If it is not worth doing, we say so.

Step two

Audit and roadmap

3 days, on site · fixed price

Two or three processes mapped with the handlers who run them · a data-readiness check on your real extracts · AI Act classification · a written roadmap · one use case demonstrated on your own data. Credited in full against the placement if it starts within 60 days.

Step three

The embedded engineer

3 days a week · 3 months, then monthly

One senior engineer in your team, with Vlad Tudor as deployment lead. Written plan on day one, the first workflow live in your environment by day ten, weekly written update, fortnightly sponsor check-in, monthly steering.

Two colleagues at one desk reviewing something on a monitor together, seen from behind.
The end state: handlers reviewing what the workflow produced, instead of keying it in. The judgement stays with them.

05 · Questions

What insurers ask first.

Health data is a special category under GDPR Article 9, and the answer is not a blanket yes or no — it depends on the step. Most of the value in a claims workflow sits in routing, extraction and completeness checks, which can run on the structured file rather than on free-text medical detail. Where special category data genuinely has to be processed, it stays inside your infrastructure, the lawful basis is written down before anything is built, and the design goes to your DPO in the audit, not after go-live.

It depends entirely on what the workflow does. Annex III classifies AI used for risk assessment and pricing in life and health insurance as high-risk, and that brings real obligations. Routing a first notification of loss, extracting fields from a claim file, or checking a submission for completeness is usually not that. Classifying your specific use case is part of the three-day audit, in writing, before anyone commits to building it — because the answer changes what it costs and how long it takes.

As a documented ICT third-party arrangement, like any other. We expect to be on your register, to work inside your change management rather than around it, and to leave behind the artefacts your ICT risk function will ask for: what the system does, what it depends on, what happens when it fails, and who runs it now. If your procurement needs that in a specific format, say so on the call and it gets built that way from day one.

That is the normal case, and it is the reason the work needs an engineer rather than a licence. Legacy cores are reached through the surfaces they do have: database views, scheduled extracts, file drops, screen automation where there is genuinely nothing else. Which of those is appropriate is a decision made with your architecture team during the audit, and the honest answer is sometimes that a particular workflow is not worth the integration cost. We say so.

No, and selling it that way would be the fastest route to it never being used. The workflows that reach production are the ones that remove re-typing, chasing and routing from a handler's day, leaving the judgement — coverage, quantum, fraud signals, the difficult customer call. A handler who has been told the system is coming for their job will not report its errors, and a workflow nobody reports errors on is a workflow that quietly stops working.

That is what the three days are for, and it is why they are separate from the placement. The audit maps two or three candidate processes, checks what your real extracts can actually support, and ranks them. If none of them clears the bar, the audit ends there and you have a written reason why — which is a cheaper answer than finding out ninety days in.

06 · The call

Bring the queue that never clears.

Thirty minutes with the person who would lead the work. No slides, no discovery deck, no procurement process to start. You describe one process; we tell you whether it is worth doing and what the first step costs.