top of page
Search

Scout InsurTech Interview with Frank Bianchi

Frank Bianchi is the Founder of RightPivot LLC, where he focuses on revenue acceleration for solution, SaaS, and services firms and AI modernization consulting for carriers, MGAs, TPAs, brokers, and industry solution providers. Frank was interviewed by Andrew Daniels, Co-founder at Scout InsurTech and Co-Founder and President at CrashBay.




Frank, you've built your career at the intersection of technology, sales, operations, and insurance. What's the through line that connects all of it, and how did it shape the way you think about where the industry is headed?


“You can tell from my gray hair, or lack of it, that I've been around for a few years and seen many innovation waves. I've watched re-engineering evolve into transformation, then digital transformation, and now AI modernization. Through all of it, there is a constant theme: you can have great technology that isn't adopted when users don’t participate in the design, and you can have great technology that's adopted by operations but does not succeed due to compliance issues. For AI, you need all three organizations working together in a regulated industry like insurance. You have to look at every part of the solution, including how it aligns with a company's technical architecture and security requirements, and how it enables real business transformation that's not defined by headcount reduction. Companies want to keep expertise in-house and should promote solutions that generate more revenue, mitigate more risk, service more customers, and improve margins by teaming their knowledge workers with their AI Co-Pilot. 


For knowledge workers, AI is complementary, and it makes the underwriter or claims adjuster more efficient and empowered. To sell AI effectively at the enterprise level, you need consultative sales skills to establish credibility and trust. AI is also unique in that it is one of the major technology waves where the buyer is often somewhat conflicted and reluctant. The Board states that an insurance carrier must adopt AI to stay competitive, while the buyer, operations, and others may worry about jobs. A good, trust-based consultative seller has to effectively communicate the solution roadmap, be specific on how AI transforms the business operations, and build trust to reinforce that the team is part of that journey. Human-in-the-loop is an important message to be sending in the sales process."


What does a mature AI governance framework actually look like for a regional carrier, and what are the non-negotiables around audit readiness?


“I won't speak to LLM model design since that's not my skill set. I do expect that ISO, SOC2, NAIC, and other regulatory groups will specify governance and monitoring standards within the next year.  Regulatory teams are already defining these frameworks both on the technical and operational compliance side. In the meantime, there are firms who are developing their own standards as they extend their DevOps/SecOps processes to include AI. 

I look at AI governance in three ways:  


  • Boundaries: What you allow an agentic AI agent to do. This matters less for conversational AI, which has a defined task and response, or generative AI, which does a specific action such as digitizing a form. It's agentic AI that needs real guardrails for security and compliance and the applications they can access. 

  • Roles: Who can initiate or launch an Agentic AI routine, and how that's governed. AI  running as a regular production routine should go through rigorous production QA and vetting processes like anything else. But if AI is running on a hundred employees' desktops with a hundred separate routines, you have lost the ability to ensure that guardrails are actually in place and are at risk of security and audit issues. There must be zero ambiguity regarding who can access production data. . 

  • Explainability:. A governance framework has to include an audit trail for what was executed, who initiated the AI and what guardrails applied, and what was the basis for an action or decision. For example, a denied claim needs to have audit trails on the variables used for the denial, or for a bound case the reference to the specific underwriting guidelines must be demonstrated. Audit-ready means being able to say we had a hundred submissions bound this month; twenty processed straight through by AI agents (and the rules executed), and eighty were done by underwriters following these specific U/W guidelines, with two noted exceptions which were approved by the chief actuary. With digitization, this information is accessible. That level of explainability will be critical to any governance and compliance framework at scale. The same applies to cases declined through automated risk triage or by an underwriter after review of third-party enrichment data and loss run data."


Many mutuals are running legacy core systems that feel impossible to modernize without a full rip and replace. What's the incremental path forward, and how can you use AI to extend the life of the legacy infrastructure rather than blow it up?


"This applies to mutuals as much as commercial carriers and reinsurers. I'd argue there's actually more risk building up each year by relying on legacy systems compared to introducing AI in an incremental way with the governance points mentioned above. The experts who know the legacy applications have retired or will be retiring soon. In a few years, legacy systems risk will go up exponentially.  


The best use of AI for legacy applications is decoding the legacy apps. I work with a partner with a platform that decodes legacy applications on almost any technology like Cobol, Rocket, iSeries, SQL, etc. They interviewed 300 executives about their biggest concern with legacy modernization. Business disruption ranked third, cost and timeline delays ranked second, and first was simply preserving the business logic, especially since many of these systems came from M&A activity with no real documentation.


Once you understand what the legacy system does through automated business documentation and processing logic, you can determine your path forward. In terms of minimizing business disruption, you can introduce incremental improvements rather than a full rip and replace. Documentation generated from Agentic AI code can support Cloud refactor migration initiatives,  API access to the applications, or build an intelligence layer to buffer legacy apps from AI and CX inquiries without major modifications. “Documentation of the legacy apps using AI is a smart investment that demonstrates a real commitment to modernization for compliance and audit teams while accelerating modernization progress for the enterprise.”


What separates the organizations that successfully move from pilot to production versus those that get stuck, and what does use case maturity really mean in practice?


"Customer buy-in and sign-off requires several things to be placed up-front rather than post-pilot.  The technology platform should operate within standard and include CISO sign-off on security guardrails. The source of data or content used must be deemed trusted or have the ability to be usable. An operational leader(s) must see the efficiency gains while protecting the expertise in their team with a commitment to human-in-the-loop workflows. Finally, compliance alignment ensures everything is auditable against underwriting guidelines, state-specific rules, and regulatory requirements. Often, compliance is missed, which will pause any progress. 


Too often, there isn't enough time spent connecting these items. A small scope pilot at a low cost may look promising, but once everyone who has to sign off on production gets involved, things stall. This is often called “pilot purgatory”. AI is built to fail fast, and that's a good thing. If something fails, you move on to the next item in your AI roadmap and incorporate lessons learned. If the pilot works technically but is too costly to operate at scale, you move on to the next use case rather than halting the whole initiative. Too often everything rides on one or two proof of concepts. When results are mixed, there’s a tendency to say "let's revisit next quarter," which often turns into losing six months or a year.


I am confident that GenAI and conversational AI can be deployed at scale. Submission, underwriting, risk triage, claims, and customer experience processes are already benefiting from AI. Compliance, regulatory rate changes, risk management, and reporting are the next areas of focus for Agentic AI and AI at enterprise scale. AgenticAI requires the most planning and guardrails but ironically can be deployed very fast. There are some very promising solutions introduced recently that can extract actionable insights and initiate automation across most of  the major applications in the enterprise. It is here where the most attention to the “who, what and why” must be placed. Guardrails and audit trails are critical and should be executed with an orchestration layer tracking human actions and automated AI agents rather than allowing siloed Agentic agents running on desktops."


Despite all the momentum around AI and insurance, what are the problems that still don't have good answers? Where is the industry still flying blind, and what needs to happen, whether from carriers, vendors, or regulators, before those gaps get closed?


"For me, it comes down to commitment to the orchestration layer that runs AI, and everything else, in a coordinated way with proper audit trails. For example, an MGA under pressure to go live on a core platform often has SOPs sitting in Word, Excel or SharePoint. Firms have the opportunity to digitize those processes and run end-to-end complaint workflows that launch human actions, notify third parties, escalate issues, flag outliers, route straight-through processing where possible, and validate decisions against guidelines. 


The second point is the balance between point solutions and enterprise scale. We are facing pressure to get the first few production systems live without applying AI in a roadmap across the full value chain, where there are some real potential gold nuggets of value to be unlocked.  Commit to a business roadmap; not just a technology path. 


The third area is compliance. Ask ten operations staff how compliant their workflows are and you'll get mixed answers, since most are just doing their best with limited resources. Being able to say precisely that a hundred policies were bound this quarter, all following underwriting guidelines with three noted exceptions, builds real confidence and demonstrates audit-readiness.  Using AI to surface the hotspots auditors will find means being audit-ready at any moment, which ties back to explainability, and is where AI becomes an asset above pure automation. It will reduce the cost, fees, and fines associated with running legacy apps. “Using AI to help carriers move off legacy platforms benefits everyone, especially considering how much money gets lost to fines from cyber intrusions and other compliance failures tied to legacy systems, money that could be redirected into AI and other innovation investments instead.


Despite the successes and gaps, I encourage firms to get their roadmaps in place, define a set of phases including pilots to build momentum, get ahead of compliance and regulatory alignment, and communicate a human-in-the-loop interaction with every AI component designed and implemented."   


Scout InsurTech Thanks Our Partners















 
 
The Scout InsurTech logo
  • LinkedIn

© 2025 by Scout InsurTech

bottom of page