Legacy data is not just an IT headache. It is a strategic liability quietly determining which insurers and brokers can actually deliver on their transformation promises – and which cannot
The numbers are stark. HFS Research estimates the global insurance industry is carrying $200 billion in combined technology and process debt – $134 billion in technology debt alone, with the majority concentrated in claims processing. PwC found that 70% of an insurer’s annual IT budget typically goes toward maintaining legacy systems rather than building new ones. Gartner found that roughly 60% of large-scale data migration projects exceed budget by 30% or more – and for insurance, with its regulatory complexity, seven-to-ten year data retention requirements, and ACORD standards obligations, that figure is almost certainly higher.
The gap between the transformation ambitions UK insurers and brokers are describing in boardrooms and the data infrastructure those ambitions are built on is, for many firms, the central unacknowledged problem in their technology strategy.
Eugene Owusu, director of transformation and global compliance at Liberty Mutual Insurance, frames the challenge in terms that go beyond the technical. “A transformation or a technology transformation can be technically successful, but might still fail if you can’t demonstrate the management of risk, and trace data and evidence to the right customer outcomes for our customers,” he said at a recent Insurance Business UK Leaders Network roundtable on digital transformation.
That framing matters. Integrity, he said, is the lens through which transformation decisions are evaluated – and data quality is not a precondition to achieving that integrity, it is the means by which it is demonstrated.
The question nobody wants to answer: what do you leave behind?
The hardest decision in any legacy data migration is not how to move data forward. It is deciding what not to move.
Owusu described the core of the problem plainly. “What is the data that we need to move forward versus what we leave behind, and how is it that this data helps us in terms of better understanding of our products, our claims processes, our finance processes? How do we migrate data from our spreadsheets into the right processes whilst still maintaining that regulatory understanding and that regulatory focus?”
That decision – what to carry and what to discard – is rarely made with the rigour it demands. Data adequate for legacy systems may not be fit for purpose in a modern architecture. Data captured years ago under different regulatory expectations may need to be re-validated or retired. And data accumulated across spreadsheets, as it has at most UK insurance firms, requires a deliberate migration process rather than a wholesale transfer.
Paul Waring, director of IT and CISO at Blagrove Underwriting Agency, describes the practical constraint that makes this even harder for a firm running both underwriting and claims. “Claims can go on for years and years, and they can come in five years after a policy’s ended, and they can carry on for another 10 years potentially in some cases. So we have to be able to support all the data we captured about a claim two years ago, still today, maybe still in five years’ time.”
His response is incremental rather than transformational. “We get around that by effectively making small incremental changes, which means that we can keep supporting everything we’ve already done – whilst also improving things because there’s new regulations coming in or there’s new requirements from our perspective, or we want to do things differently and better for our policyholders.”
That discipline – change without breaking what is still needed – is the unglamorous reality of data management in a business where policy and claims obligations run on different timelines from technology refresh cycles.
The saturation problem
George Dagnall, non-executive director at Hotspot Cover and director of insurance and partnerships at Concentrix, adds a dimension that is less frequently discussed: data saturation.
“We’re in a data saturation generally at the moment. There’s so much data out there,” he said. “First and foremost is us really making sure our individuals across the business understand what
does that data mean, and what’s the importance of the data.”
That cuts against a common assumption in transformation programmes – that more data is better. In a market where brokers, carriers, and clients are all generating data in volumes that were not conceivable a decade ago, the challenge is not acquisition. It is translation, prioritisation, and interpretation.
Dagnall highlights the cross-chain translation problem directly: “From a carrier or a broker, their data perspective might be entirely different. So there’s a little bit of translation from two ways.” Data meaningful and actionable on one side of a transaction may arrive in a format incompatible with the systems or interpretive frameworks of the party receiving it. Cleaning the data at the point of receipt is one solution. Building connectivity so that it does not need to be cleaned is another – and requires commitment on both sides.
The regulatory dimension is not optional
For UK firms operating under the FCA’s Consumer Duty and the Senior Managers and Certification Regime, data quality carries a regulatory dimension that makes it more than a technical concern.
The FCA has chosen not to introduce AI-specific regulation, instead applying its existing principles-based framework. Consumer Duty obligations – producing good outcomes for customers and demonstrating that they are being produced – apply directly to AI-enabled processes, and those processes are only as reliable as the data they run on. As the FCA’s chief data officer Jessica Rusu has stated, SM&CR and Consumer Duty together give the regulator “enough regulatory bite that we don’t need to write new rules for AI.”
The accountability for AI decisions sits with senior managers. And senior managers cannot be accountable for decisions they cannot trace. Data lineage is not a compliance box to tick. It is the mechanism by which accountability is made real.
Owusu puts it plainly. “At Liberty, one thing that we’re keen on is making sure that it’s integrity first.” AI is accelerating some of this work – processes that previously took significant time are moving faster. But that acceleration does not reduce the obligation to ensure the data being processed is reliable. It raises the stakes of getting it wrong.
