New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs
Fintech & financial services
Privacy & Security for Insurtech Companies
Insurtech companies answer to two audiences that rarely move on the same clock: the carrier whose OSFI B-10 vendor review decides whether a pilot ever launches, and the privacy regulators watching how quote funnels, telematics feeds and underwriting models handle personal information. Privacy Horizon builds the security leadership, privacy accountability and audit-ready evidence a digital MGA, embedded-insurance platform or claims-automation vendor needs before either audience says no.
Reviewed by the Privacy Horizon team · Last reviewed
Who this is for
Digital MGAs and embedded-insurance platforms selling or advising on coverage, where provincial licensing (RIBO, FSRA, the AMF) and CCIR/CISRO Fair Treatment of Customers guidance reach the business directly rather than through a carrier contract alone.
Claims-automation, underwriting-AI and comparison-site vendors that hold no distribution licence at all. OSFI never regulates you directly — your carrier client's B-10 third-party due diligence does, through a security schedule you must satisfy before the first policy binds.
Québec-facing insurtechs running a French quote funnel or distributing without a representative under the Regulation respecting alternative distribution methods, where Law 25's privacy-officer, PIA and automated-decision duties stack on top of the distribution rules.
Venture-backed teams between Series A and a national carrier rollout, where one OSFI-flavoured questionnaire, one AMF filing or one AI underwriting launch can stall a partnership that took a year to negotiate.

Services
Privacy & security services for insurtech companies
Each service below is scoped for how insurtech companies actually operate — their systems, their regulators and the reviews they face.
Virtual CISO
Virtual CISO for Insurtech Companies
vCISO for insurtech companies: security leadership for OSFI B-10 carrier reviews, underwriting-AI risk and a pilot stalled on a security questionnaire.
Virtual Privacy Officer
Virtual Privacy Officer for Insurtech Companies
Virtual Privacy Officer for insurtech companies: a named privacy lead for quote-funnel consent, telematics data, claims files and Québec's DWR duties.
Penetration Testing
Penetration Testing for Insurtech Companies
Penetration testing for insurtech companies: quote APIs, embedded SDKs and claims-automation pipelines tested at a cadence carrier procurement accepts.
Incident Response Planning
Incident Response Planning for Insurtech Companies
Incident response plan for insurtech companies: vendor-side IR built to meet carriers' 24-hour OSFI and AMF reporting clocks written into vendor contracts.
Privacy & Security Policy Development
Privacy & Security Policy Development for Insurtech Companies
Privacy and security policy development for insurtech companies: policies mapped to carrier security schedules, bordereau terms and AI-use rules.
Privacy & Security Training
Privacy & Security Training for Insurtech Companies
Privacy and security training for insurtech companies: role-specific sessions for claims handlers, underwriting-ops and quote-API engineering teams.
Vendor Security Review & Questionnaire Support
Vendor Security Review & Questionnaire Support for Insurtech Companies
Vendor security review for insurtech companies: vetting OCR, LLM API, data-enrichment and telematics subprocessors so carrier audits pass through cleanly.
SOC 2 Readiness
SOC 2 Readiness for Insurtech Companies
SOC 2 readiness for insurtech companies: scoping a Type II report around the quote API, claims pipeline and what carrier procurement now expects by default.
ISO 27001 Readiness
ISO 27001 Readiness for Insurtech Companies
ISO 27001 readiness for insurtech companies: certification for global reinsurers, EU MGA partners and carrier RFPs, expert-led with platform automation.
AI Privacy Impact Assessment
AI Privacy Impact Assessment for Insurtech Companies
AI-PIA for insurtech companies: documented assessment of underwriting and claims models against Law 25 section 12.1 and OSFI-FCAC bias risks.
What you hold
What a digital MGA or claims-AI vendor actually has to protect
Insurtech data sets look like nothing a generic SaaS business carries, and mishandling any one of them can end a carrier relationship outright.
Quote-flow personal information
Addresses, driver's licences, VINs and claims history get collected the moment someone starts a quote, often before a policy exists or a consent conversation has happened.
Telematics and UBI driving data
Continuous location and driving-behaviour feeds from usage-based insurance programs are sensitive by nature, and the retention and sharing terms attached to them get read closely by regulators and carrier partners alike.
Claims files with photos and injury detail
FNOL intake and claims-automation pipelines gather images, medical detail and financial loss information that goes well beyond an ordinary customer record.
Accelerated-underwriting medical and lifestyle answers
Life insurtechs collecting health questionnaires outside a full paramedical exam hold data as sensitive as anything a clinic keeps, scored by a model instead of an underwriter.
Bordereaux and carrier data-sharing feeds
The batch files exchanged with carrier partners over managed file transfer carry policyholder detail at volume, and that channel is a known target in its own right.
Underwriting and claims model inputs and outputs
What a model scores on, and the decision it produces, remain personal information subject to the same accountability as a manual file, with far less visibility into how the outcome was reached.
Regulatory map
The regulatory stack an insurtech answers to at once
No neighbouring fintech carries this exact combination: distribution licensing where you sell, carrier oversight where you don't sell at all, and AI-specific guidance layered over both.
Provincial licensing where you distribute or advise
RIBO for Ontario P&C brokering, FSRA for life agencies and the incoming Ontario life & health MGA licence class, and the AMF in Québec apply the moment a platform sells or advises rather than merely routing a quote to a licensed party.
Québec's alternative-distribution regime
Selling insurance online without a representative in Québec falls under Distribution Without a Representative, with disclosures and conditions set by the Distribution Act, the Insurers Act and the Regulation respecting alternative distribution methods.
OSFI B-10 flowing down from carrier clients
A pure technology vendor is not a FRFI and OSFI does not license it, but a carrier client's B-10 third-party risk management obligations turn the vendor's security posture into a documented, monitored condition of the contract.
CCIR/CISRO Fair Treatment of Customers guidance
FTC guidance reaches intermediaries and outsourced functions and names protection of personal information as one of its outcomes, so a carrier's oversight of an insurtech is partly a consumer-protection exercise, not only a security one.
PIPEDA, Law 25 and Alberta PIPA
PIPEDA governs commercial handling of quote and policy data everywhere in Canada; Québec's Law 25 adds a designated privacy officer, PIAs before new systems launch and section 12.1 disclosure for automated decisions such as instant-quote declines; Alberta PIPA carries its own mandatory-reporting duty.
AI-specific guidance from privacy regulators and OSFI
The OPC and provincial commissioners' joint principles for generative AI, and the OSFI-FCAC risk report, both single out underwriting and claims management among the AI use cases carrying data, model and third-party risk.
What goes wrong
Where insurtech incidents actually start
The pattern in this sector rarely resembles generic ransomware. It follows how insurtechs concentrate carrier trust, money-adjacent data and machine decisions inside one small team.
Third-party concentration risk
The OSFI-FCAC report treats the July 2024 global IT outage as the concentration-risk exemplar for the financial sector, and an insurtech is precisely the kind of third party a carrier is now expected to assess for that failure mode.
File-transfer and vendor compromise
The 2023 MOVEit campaign, which reached roughly 100,000 Nova Scotians through a single government deployment, mirrors the exposure carrier–vendor bordereaux exchange creates whenever the transfer tool itself is the weak point.
Quote-flow data leakage and scraping
A public quote API that returns enriched personal data invites enumeration, and Equifax's Canadian finding shows how bureau-linked flows go wrong on safeguards, retention and cross-border consent.
Insider misuse of policyholder books
Desjardins, where insurance-adjacent data on roughly 9.7 million people was monetized through an advisor network, is the OPC and CAI reference case for what an insider with broad book access can do unchecked.
Automated-decision complaints
A declined applicant invoking Law 25's section 12.1 explanation rights against a black-box underwriting model turns a quiet engineering decision into a documented regulatory exchange.
Broker-channel email compromise
Compromised mailboxes upstream or downstream of the platform are a recurring cause in Alberta's breach reporting, and an insurtech sitting between brokers and carriers inherits that exposure from both directions.
When organisations call us
The moments that bring insurtechs to Privacy Horizon
Engagements start at a specific event on the calendar, not from abstract risk appetite.
A carrier opens B-10 due diligence
The moment a national or regional carrier proposes a partnership, its risk or procurement team sends a third-party security schedule built on OSFI B-10 expectations, and the pilot stalls until someone credible answers it.
An AMF filing is due for a Québec launch
Selling or distributing insurance to Québec residents without a representative triggers the alternative-distribution filing, and the disclosures and safeguards it requires need to exist before the French quote funnel goes live, not after.
An underwriting or claims model moves to production
Straight-through processing, accelerated underwriting or an FNOL triage model leaving pilot for production is the point where data, model and third-party risks stop being theoretical.
SOC 2 becomes a procurement condition
A carrier or enterprise partner names SOC 2 Type II as a contract condition, turning a roadmap item into a deadline with a named auditor attached.
A cyber-insurance or E&O renewal is coming up
Insurers underwriting insurtechs ask increasingly detailed questions about the applicant's own posture, and a thin renewal application is its own kind of exposure.
Series A or B diligence opens the data room
Investor technical diligence increasingly includes a privacy and security review, and gaps found there get negotiated into the term sheet if they aren't closed first.
Insurtech Companies: privacy & security questions, answered
Not directly, in most cases — RIBO, FSRA and the AMF licence and supervise distributors and advisors, not the software underneath them. But your carrier client is a federally or provincially regulated insurer, and its OSFI B-10 third-party risk management obligations require it to assess and monitor you contractually. In practice you end up answering the same expectations a licensee would face, delivered through a security schedule instead of a licence application.
Fewer than the full list, usually. Most early-stage insurtechs start with a vCISO or VPO to own the security schedule and privacy answers, a policy set that closes the obvious carrier gaps, and a penetration test if the quote API is already live. SOC 2, ISO 27001 and a formal AI-PIA tend to arrive once a specific carrier, reinsurer or model launch demands them. We scope from the pilot you're actually negotiating, not a generic checklist.
Yes. The OPC and provincial commissioners' joint AI principles and the OSFI-FCAC risk report both focus on how a model is used and what data feeds it, not who wrote the code. If your platform sends applicant or claims data into a third-party underwriting or claims model and acts on its output, you carry accountability for that use, including the transparency Law 25 requires when a decision is made exclusively by automated means.
Often, yes. Institutional investors increasingly run a privacy and security review alongside legal and financial diligence, and findings can turn into term-sheet conditions or post-closing covenants. Insurtechs that get ahead of it, an accountable privacy or security lead, current policies, a documented view of where data lives, tend to close diligence faster and negotiate from a stronger position.
A questionnaire answered once is a snapshot; carrier oversight is ongoing. B-10-style relationships expect monitoring, incident notification capable of feeding the carrier's own 24-hour OSFI or AMF clock, and periodic re-assessment, not a single form. The gap usually surfaces at renewal, at a second carrier's onboarding, or the first time an incident tests whether the program behind the answers actually exists.
Hosting on a policy administration platform or carrier-provided infrastructure narrows the job; it doesn't remove it. You still control application logic, API access, staff accounts, integrations and how personal information moves in and out of that environment, and carriers and auditors will ask about exactly those layers. Shared infrastructure changes the scope of a security or SOC 2 review; it rarely changes whether one is needed.
Related industries
Answers & guides
- What is PIPEDA, and does it apply to my business?
- VPO vs vCISO: do you need one, the other, or both?
- SOC 2 vs ISO 27001 — which should we pursue first?
- How do we prepare for a customer security questionnaire?
- When do you need an AI Privacy Impact Assessment (AI-PIA)?
- What is SOC 2, and does my business need it?
- The Canadian Privacy Law Landscape in 2026: PIPEDA, PHIPA, and Quebec Law 25
- SOC 2 or ISO 27001 First? A Decision Framework for Canadian Scale-ups
- Building a Third-Party Vendor Risk Assessment Program That Scales
- An AI Vendor Privacy & Security Checklist for Procurement Teams
- VPO, vCISO, or Both? Outsourcing Your Privacy & Security Program
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.