Governance
Regulators And Compliance.
Written for a regulator or an insurer's compliance function as the reader. Claims handling is supervised activity, and a technology supplier into it inherits obligations from its customer.
Everything here is either a statement of applicable law, or a statement of Kempron's posture. Where Kempron does not hold an accreditation, that is said rather than implied.
Summary
Kempron's Position In One Paragraph
Kempron Inc. is a Canadian technology supplier to property and casualty insurers. It is not a regulated financial institution, holds no insurance licence, and does not underwrite, adjust or settle claims. Its exposure to insurance regulation is indirect and arises through its customers: a federally regulated insurer engaging Kempron does so as a third-party arrangement under OSFI Guideline B-10, and any technology it relies on falls within the scope of Guideline B-13. Kempron's design posture is to make that assessment straightforward rather than to argue about scope.
Privacy
Privacy Law And Personal Information
Claims data is personal information in the strict statutory sense and frequently includes sensitive categories.
Canada
- PIPEDA. The federal Personal Information Protection and Electronic Documents Act governs the collection, use and disclosure of personal information in the course of commercial activity, and applies in provinces that have not enacted substantially similar legislation.
- Quebec. The province's modernised private-sector privacy regime, commonly called Law 25, introduced phased obligations between 2022 and 2024 covering governance, breach reporting, consent, privacy impact assessments, data portability and rights in respect of automated decision-making. Quebec is the most demanding privacy jurisdiction in the country and should be designed for first rather than accommodated later.
- Alberta and British Columbia. Each has its own Personal Information Protection Act, recognised as substantially similar to PIPEDA for provincially regulated organisations.
United States
- State insurance data security requirements, widely modelled on the NAIC Insurance Data Security Model Law, impose information security programme, incident response and notification obligations that flow through to third-party service providers by contract.
- State comprehensive privacy statutes apply in parallel, with varying definitions, thresholds and rights.
- The Gramm-Leach-Bliley Act framework continues to apply to financial institutions including insurers, with its own safeguards expectations.
Kempron's Posture On Personal Information
- Minimisation over accumulation. Collect what the process requires, for a defined purpose, for a defined period. A vendor that wants more data than the task needs is describing a business model, not a design.
- Locatability. We expect to be able to state precisely where a given category of data sits, who can reach it and for how long it will be retained. If that question cannot be answered quickly it cannot be answered honestly.
- Residency as a contractual term. Commitments about holding Canadian personal information in Canada are made in writing in the agreement, not offered as a preference.
- Deletion with a deadline. Return or destruction on exit is an obligation with a date attached, agreed before go-live rather than negotiated afterwards.
- Privacy impact assessment support. Where a customer is required to conduct a PIA, we expect to supply what it needs rather than treat it as the customer's problem.
Prudential
Third-Party Risk And Technology Risk
Federally regulated insurers in Canada are supervised by the Office of the Superintendent of Financial Institutions. Two OSFI guidelines shape how such an insurer may engage a supplier like us.
Guideline B-10, Third-Party Risk Management
Effective 1 May 2024. It substantially widened the previous outsourcing framework to cover third-party arrangements generally, and sets expectations for risk assessment, contractual provisions, ongoing monitoring and exit. Arrangements entered into on or after that date are expected to comply with all applicable sections; legacy arrangements are expected to be brought into line at the earliest appropriate contract renewal or revision point. (Office of the Superintendent of Financial Institutions, Guideline B-10.)
What this means in practice is that an insurer cannot adopt a supplier faster than it can risk-assess one. Kempron's position is that this stage is substantive and should be planned for. A vendor that arrives with the material already prepared removes weeks from a procurement cycle; a vendor that treats it as a formality will find the technology discussion stalled behind a questionnaire.
Guideline B-13, Technology And Cyber Risk Management
Effective 1 January 2024. It sets expectations across three domains: governance and risk management, technology operations and resilience, and cyber security. It applies to all federally regulated financial institutions, expressly including property and casualty companies. (Office of the Superintendent of Financial Institutions, Guideline B-13.)
A supplier does not comply with B-13 in its own right. It either makes its customer's compliance easier or harder, and that difference is visible in the first security review.
Market Conduct
Who Supervises Claims Handling
Conduct regulation is where claims handling is actually policed, and it is the most fragmented layer of all.
Canada
- Ontario. Regulated by the Financial Services Regulatory Authority of Ontario, operating a statutory accident benefits schedule and the focus of successive reform packages.
- Quebec. Bodily injury is handled by the public Société de l'assurance automobile du Québec; property damage sits with private insurers supervised by the Autorité des marchés financiers.
- Alberta. Supervised for rating purposes by the Automobile Insurance Rate Board, and undergoing structural reform following the passage of Bill 47, the Automobile Insurance Act, which received Royal Assent in May 2025. (Insurance Bureau of Canada, 15 May 2025.)
- British Columbia, Saskatchewan and Manitoba. Public insurers — ICBC, SGI and MPI respectively — with entirely different procurement routes.
United States
Insurance is regulated state by state. Unfair claims settlement practices statutes, adopted in varying forms from NAIC models, set standards for the timeliness and fairness of claims handling. State departments of insurance conduct market conduct examinations. A technology that changes how a claim is handled changes what is examined.
Other Markets, For Context Only
The Global Markets page describes conduct supervision in the United Kingdom, continental Europe and Australia. Kempron does not operate in those markets and does not hold itself out as serving them. They are included because the regulatory direction of travel is consistent across all of them and that consistency is informative.
Security
Security Posture, Stated Honestly
This is the section most likely to contain an overstatement on a vendor website, so it is written to make overstatement impossible.
Kempron does not currently hold a SOC 2 report or an ISO/IEC 27001 certification, and does not claim to. We hold no security accreditation of any kind. Any vendor page that states or implies otherwise about us is wrong.
What we do is design and document against the AICPA Trust Services Criteria that underpin SOC 2, and against the control domains of ISO/IEC 27001, because those are the frameworks an insurer's third-party risk function will assess us within. Building to a framework is not the same as being certified against it, and we will not blur the two. Where a specific engagement requires formal attestation, that is scoped, sequenced and funded as part of the engagement.
Commitments We Will Make In Writing
- Data ownership: the insurer's data remains the insurer's data. Processing it gives us no rights in it.
- Permitted use: defined in the agreement and limited to delivering the engagement. No secondary use, no aggregation for other customers, no use for product development beyond what is expressly agreed.
- Residency: Canadian personal information can be held in Canada, committed contractually.
- Retention and deletion: defined periods, and return or destruction on exit with a deadline.
- Sub-processors: disclosed to the customer as part of third-party risk review.
- Incident notification: contractual obligations aligned to the customer's own regulatory notification duties, which are what actually drive the clock.
- Audit and assurance: reasonable access and information rights for the customer and, where applicable, for its regulator.
- Exit: a documented route out, agreed before go-live rather than negotiated under pressure later.
Auditability
What Auditability Means At A Policy Level
Stated as a governance commitment. This section describes what must be true of a system, not how any system achieves it.
A claims process is subject to after-the-fact examination by parties who were not present when it ran: an internal auditor, a market conduct examiner, an ombudsman, opposing counsel, a court. Auditability is the property that makes those examinations possible. We treat it as a requirement rather than a feature, and we regard a system whose output cannot be accounted for as unfit for this market regardless of how well it performs.
Four propositions follow, and all four are testable by a reviewer without access to any implementation detail:
- Every material step leaves a record. What happened, when, on what input, and under whose authority. A step that leaves no trace cannot be defended later, and the absence will be discovered at the worst possible moment.
- Records are retained for as long as the claim can be examined. That period is set by limitation periods, regulatory retention requirements and the customer's own policy, not by what is convenient to store.
- The reasoning is reconstructable, not merely the outcome. Knowing what a process concluded is of little use to an examiner who needs to know on what basis. An answer that cannot be explained is an answer that cannot be relied on.
- Decision rights stay with the accountable party. The insurer carries the regulatory accountability for how a claim is handled. Automation that quietly relocates a decision away from the accountable party has created a governance problem and disguised it as an efficiency.
These propositions are also the reason we decline to describe our technical approach publicly while being willing to describe our governance commitments in detail. A regulator or compliance officer needs to know what must be true of the system and how it will be evidenced. Neither requires us to publish how it is built. The same logic governs our position on artificial intelligence.
Contact
Regulatory And Compliance Correspondence
We respond to regulatory and compliance enquiries directly, and will provide corporate particulars, registration details and a mutual non-disclosure agreement on request. Security questionnaires and third-party risk documentation are handled as part of the engagement process rather than left to the end of it.
admin@kempron.com