AI-generated voices are making phone-based fraud harder to catch, and insurers are under pressure to show how their operations are governed as well as their technology. As AI makes these scams more convincing, protecting customer data depends on the people, processes and systems that handle it every day.

Norm Hudson is CEO of Staff Boom, which builds dedicated teams for insurance industry partners, and draws on more than twenty years growing insurance agencies including Cost-U-Less, Confie Seguros and Inszone. In this opinion piece he argues that closing the governance gap in insurance fraud prevention is an operational task as much as a technological one. The views are his own.
A new AI industry survey found that insurance executives are seeing real returns from implementing AI into their operations. Some 52 per cent report AI-driven revenue growth, 62 per cent say it has improved decision-making, and 50 per cent report lower costs. However, that same survey found that only 24 per cent of those executives are confident they could pass an independent review of their AI governance controls within 90 days.
Closing that gap has as much to do with how operations are run day to day as it does with the AI itself.
The gap becomes clearer
Voice-based scams have become harder to catch by ear, and AI-generated voices are a big part of why. Recent research found that 70 per cent of people aren’t confident they can tell a cloned voice from the real one, and call centres are fielding more of these attempts than they were even a year ago. The calls sound more convincing each time, and that shift is exactly the kind of thing putting AI governance on so many insurance leadership agendas right now.
Where fraud begins to sneak in
New detection tools help, but they only go so far without clear access controls behind them. The more useful question is who is allowed to touch a claim file, and under what vetting, regardless of which system flags a call first.
The gap fraud exploits lives in the organisation chart. It comes down to who has access and whether anyone would notice if that access got used the wrong way. Governance has to keep pace with how quickly these tools get adopted, or scams keep finding the space in between.
Picture a caller who has enough information to pass the standard checks, whether that’s a knowledge-based question, a voice match, or both. What happens next depends less on how they got past the front door and more on what the representative on the other end can see and touch. If that representative, wherever they’re sitting, has standing access to the full policy file with no log of what got opened or why, nobody notices anything unusual until the customer calls back confused about a change they never made.
What real governance requires
Limiting standing access has to work as a daily rule, applied the same way whether someone sits in a headquarters office or a delivery centre miles away. In practice, that means giving people access scoped to the task in front of them, logging it at the individual level, and flagging anything outside a normal pattern quickly instead of catching it months later at audit time.
Workflows also have to be audited on a real schedule. A procedure sitting in a binder says nothing about what happened on the call centre floor last Tuesday. Every authentication decision and every override needs to leave a trail that someone actually reviews.
The vetting standard has to be identical for every person who can touch a policyholder’s data, regardless of where they sit. The same background checks and the same credentialing apply whether the team is offshore or down the hall. The best-run production floors require every employee to badge into a controlled space and work from a monitored station, with personal phones kept off the floor entirely. That consistency also helps protect policyholder information. Customer data should be handled under the same security protocols no matter where the work is performed or which team member is responsible for it.
The same level of oversight should extend to any outside vendor or subcontractor involved in the work. Those relationships should be reviewed regularly to make sure security protocols continue to be followed, and customer information remains protected as processes, technology and fraud risks evolve.
Why this matters now
Detection software keeps getting better, but better tools alone don’t answer who has access and why. That is the piece operations teams, whether in-house or outsourced, are best positioned to own.
AI adoption is accelerating, and so is the fraud being built on top of it. The 24 per cent figure cited at the beginning of this piece measures something narrower than AI maturity. It shows how much distance still sits between adopting AI and being able to prove, to an outside reviewer, how the operation behind it actually runs. That’s fixable, but only when operations, not just the underlying technology, get treated as the priority.
Closing that gap starts with knowing who can access policyholder data, why they need it, and what safeguards are in place when they do. As fraud becomes more sophisticated, those day-to-day operational controls are an important part of protecting customer information from misuse, theft and impersonation.
The post Protecting Customer Data Starts with Operational Controls appeared first on The Fintech Times.