Large Language Thing

Home/Concepts/Bounded rationality and satisficing in insurance underwriting

Bounded rationality and satisficing in insurance underwriting

Bounded rationality locates the frontier precisely. Along the intake axis there are exactly three positions: evidence gathered once and closed, evidence gathered while a scene is…

The book that broke in April

A property catastrophe underwriter renews a Gulf Coast wind book in January. The hazard curve underneath the pricing comes from a vendor catastrophe model calibrated on decades of historical storm tracks, sea surface temperatures and a loss-cost function fitted to claims from the last major recalibration. The treaty is bound. Reinsurance is placed against the same curve, layered and priced to a return period that assumes the tail is where the model says it is.

By September the book has taken two consecutive seasons of storms that exceeded the model's 1-in-100-year attritional assumption for named-storm surge, not because the storms were freakish but because the curve was built on a sea-surface-temperature regime that had already shifted before the treaty was signed. The claims come in. The loss ratio blows through plan. Nobody in the chain acted stupidly. The underwriter used the model that was standard, the actuary who built the curve used the best data available at the last recalibration, and the reinsurer priced to the cedant's own submission. The failure was not a bad decision. It was a decision made against evidence that had stopped updating months before it was used.

What actually went wrong

The hazard curve was frozen at the point the model vendor last recalibrated it, typically an annual or biennial cycle. Between recalibrations, three things kept moving: the claims flow from the current season, which is the fastest signal of whether the curve is still true; the exposure registry, since coastal accumulation grows every quarter as new construction is bound; and the reinsurance terms themselves, which were priced off the same stale curve and so offered no independent check. The underwriter was not ignoring live information. There was no live information built into the workflow. The model was the evidence, and the model had a closing date.

This is not a data problem in the sense of missing a feed. It is a structural feature of how underwriting judgement has always been organised: gather what is available, price to it, bind, and revisit at the next renewal cycle. The renewal cycle is the stopping rule. It was chosen because re-underwriting continuously, book by book, peril by peril, costs more in actuarial and underwriting attention than most books justify. That is not laziness. It is the correct economic response to a real constraint, and it has a name.

Satisficing as the actual mechanism

Herbert Simon named this pattern satisficing in a 1955 paper, following his 1947 book Administrative Behavior, against the economic assumption that agents optimise: survey every option, price every consequence, choose the best. Simon observed that no administrator, firm or underwriter does this, because attention, memory and time are scarce, and the space of things one could check before pricing a book is not finite in any useful sense. So agents set an aspiration level — a hazard curve judged adequate, a data vintage judged recent enough — and stop searching once that level is cleared. The search terminates on adequacy, not on proof of optimality.

The underwriter's stopping rule was the recalibration cycle. It was not examined at bind time; it was inherited. That is Simon's sharper point: the stopping rule is itself a decision, and it is usually the one nobody looks at, because looking at your own stopping rule is exactly the kind of expensive second-order search satisficing exists to avoid. The book was priced correctly against the curve. The curve was the thing that had quietly stopped being checked.

The underwriter did not misprice the risk in front of them; they priced the risk that existed at the last recalibration, correctly.

Three positions on the intake axis

Put in terms of what evidence a system is willing to keep gathering, underwriting sits inside a lineage of possible stopping rules that recurs well beyond insurance. A Large Language Model fixes intake at a training cutoff: everything after that date is unobserved by construction, and no amount of prompting retrieves it, because the corpus was judged good enough once and then frozen — this is the annual hazard curve, generalised. A Large World Model relaxes the cutoff to the length of an active scene: it senses continuously while the camera or sensor rig is live, and stops when the episode ends, leaving no standing belief between engagements — this is closer to a claims adjuster's site visit, thorough while it lasts, silent afterward. A Large Universe Model is defined by refusing the cutoff on intake altogether: claims flow, catastrophe model updates, exposure registry changes and reinsurance terms are all held as live, revisable streams, each with provenance and a decay rate on how much to trust an observation as it ages.

PositionStopping rule on evidenceUnderwriting analogue
Large Language ModelFrozen at a cutoff dateHazard curve fixed at last recalibration
Large World ModelRuns for the duration of a sceneSite inspection or bordereau review, then silence
Large Universe ModelNo temporal closure; streams stay openClaims, exposure and cat-model feeds updated continuously, weighted by recency and provenance

That third position is the terminal rung on this particular axis, and it is worth being precise about what "terminal" means. Along the single dimension of when observation stops, there are exactly three shapes available: closed once, closed at the end of an episode, never closed. A fourth position would have to be a form of intake that is neither of these, and no such form exists — anything offered as a fourth is either a subset of continuous intake (a narrower stream, still never closed) or a claim about how the evidence is processed once gathered, which is a different axis entirely: judgement, not observation.

What does not change

This is where the misreading has to be headed off directly. The weak version of this claim says continuous intake finally delivers the optimising underwriter economics used to assume, computing the true price because nothing is missed. Simon's own framework rules that out twice over. His bounds were never only about missing information; they were about the cost of computing over the information you have and the limits of attention in acting on it. Feeding a book's pricing engine continuous claims flow, live catastrophe model perturbations, exposure updates and reinsurance term changes does not remove the need to decide what to act on today. It relocates the stopping rule from what evidence exists to what evidence is trusted enough to move the price. An underwriter with a continuously updating hazard surface still has to decide, at bind time, which of this week's model perturbation is signal and which is noise in the vendor's Monte Carlo draw. That decision is still satisficing. It is just satisficing over a live surface instead of a stale one, and provenance — knowing which stream said what, and how recently — is what makes that residual judgement inspectable rather than buried in a recalibration schedule nobody revisits.

Two objections that land hardest here

Continuous intake in a competitive placement market just becomes an arms race. If every underwriter and every reinsurer gets the same live cat-model feed, nobody's relative pricing edge improves, and the market spends the savings on data infrastructure instead of margin.

This is close to right for the part of underwriting that is genuinely relative — treaty placement, where the edge one carrier has over another in reading a live model update is competed away exactly as speed advantages were competed away in high-frequency trading. But most of what a live intake stream corrects is not competitive at all. A book that would otherwise be priced against a broken hazard curve is an absolute loss to the carrier and, through reinsurance failure, to the cedant's policyholders. Detecting sea-surface-temperature drift before the third season of losses is not an edge over a rival; it is the difference between solvent and insolvent reserving. The arms-race dynamic bites where the observed quantity is another party's intention or position. Catastrophe risk is not another underwriter's intention. It is weather.

A second objection, closer to Simon's own reasoning, deserves equal weight:

The space of everything an underwriter could observe about a coastal exposure — every parcel record, every construction permit, every satellite pass, every reinsurer's internal view — is unbounded. Claiming "continuous total intake" just hides a sampling decision inside a system instead of making it at renewal. That is satisficing with the stopping rule disguised, not removed.

This is correct, and the honest version of the claim concedes it fully. No system, however continuously it streams claims and exposure data, observes everything observable about a risk. What changes is narrower: there is no temporal closure on the streams the system is actually connected to. The exposure registry keeps updating as new construction binds; it does not stop updating in March because that was when last year's registry snapshot was taken. Which streams to connect, at what cost, remains a satisficing choice, and a defensible one only if it is visible — which is exactly the argument for provenance and decay as first-class fields on every belief the system holds, rather than an afterthought bolted onto a frozen model output. The boundary the Large Universe Model removes is the closing date. The boundary it leaves standing, because no architecture can remove it, is judgement: what an underwriter, however well fed, chooses to believe enough to bind against.

Continue