Home/Concepts/Open-loop versus closed-loop control in insurance underwriting
Open-loop versus closed-loop control in insurance underwriting
Any knowledge system that cannot observe the consequences of its own outputs is an open-loop controller, and open-loop control degrades monotonically under disturbance. This is…
Setting the plant
An underwriter prices risk against a hazard curve: expected frequency and severity of loss, built from a catastrophe model, a book of exposure, and a reinsurance structure that caps the tail. That curve is a plant model. Nobody disputes the sophistication going into it — vendor cat models now run tens of thousands of stochastic event years, calibrated against decades of loss history. The question this page asks is narrower and more mechanical: once the curve is set and the policy bound, does anything measure whether the curve held? Because a hazard curve fitted once and then priced against for a full renewal cycle is an open-loop controller, however good the fit was on the day it was made.
The Large Language Model as a frozen hazard curve
Treat a Large Language Model's corpus as an analogue for a hazard curve fitted at a single point and left alone: a snapshot, however wide, taken once and then used to justify decisions long after conditions have moved. The parallel to underwriting is exact where a book gets priced at renewal off a curve built from the last cat model refresh, and then held for twelve months while wildfire behaviour, convective storm frequency, or coastal erosion rates continue to shift underneath it. The curve does not know it is stale. Nothing inside the pricing process tells it that the two seasons since its last calibration already broke its assumptions. That is not a defect of the model's statistical craftsmanship. It is what open-loop means: the plan is emitted, and the plant it plans for keeps moving, unopposed.
The Large World Model as bound renewal
A single renewal cycle does close a loop, and it is worth crediting that properly. Claims flow in against the bound policy; loss ratios update; the underwriter compares actual burn to expected burn for that treaty year and adjusts terms at the next renewal. This is feedback — measured output compared to reference, error driven down at the point of renegotiation. It behaves like a Large World Model: a bounded episode, sensed closely, corrected sharply, and then closed. The trouble is the boundary. Once the treaty renews and terms are set, the loop resets. Loss experience from three renewals ago, the hard lesson from a hurricane season that reshaped the book, does not automatically stay wired into how the next line is priced unless someone manually carries it forward. Institutional memory does this informally, and informally means unreliably — the underwriter who priced through the 2017 hurricane season retires, and the correction retires with them unless it was booked as a revisable belief rather than held as a habit.
The Large Universe Model position: streams that do not close
The stronger claim is that underwriting risk should be held as a continuously running set of beliefs rather than a periodically refreshed curve. Claims flow, catastrophe model updates, exposure registry changes, and reinsurance terms are four separate streams, each updating on its own cadence, each capable of falsifying a specific piece of the pricing logic the moment it lands. A wildfire catastrophe model revision that raises expected frequency in a given county should not wait for the annual refresh cycle to touch every policy written against that county's peril curve — it should be attributable to those exposures immediately, with provenance linking the correction to the specific belief it overturns. That is the Large Universe Model move applied to a book of business: intake stays open past the point of binding, and error, when it arrives, is booked against the claim it falsifies rather than smoothed into next year's average.
Where this is too easy
Reinsurance renewal already is the feedback loop. Treaties reset annually, cat models get refreshed by vendors multiple times a year now, and claims data flows into pricing continuously through bordereaux reporting. The industry is not blind. It is just slower than a thermostat, because underwriting cycles are annual by contract, not by ignorance.
This objection has force. Bordereaux reporting genuinely does bring claims data back into view on a rolling basis, and a well-run cat modelling function does refresh assumptions between full renewals when a major event demands it — insurers repriced Florida homeowners books mid-cycle after Hurricane Ian, not on the next anniversary. So the claim that underwriting is pure open-loop, dead-reckoning through a full year with no correction at all, overstates the case.
But look at what the correction actually does. A mid-cycle repricing after a major event adjusts the aggregate curve — it raises the loss cost assumption for a peril and geography broadly. It does not, typically, trace back through the book and say: this specific line was underpriced because it relied on a 2019 vintage flood model that assumed a levee configuration decommissioned in 2021, and that assumption is now retired with the exposure record showing exactly which policies inherited it. The correction is real but coarse. It is feedback on the aggregate, not provenance on the belief. Retrieval of fresher loss data makes the plan better next time; it does not make the system watch, in real time, which specific assumption a given claim just refuted.
The instability objection, taken seriously
There is a second objection worth more weight than the first, because it cuts against the thesis rather than merely qualifying it.
Continuous revision is dangerous in a business built on multi-year capital commitments and reinsurance treaties priced on stability. If every claims tick and every cat model patch immediately re-weighted the hazard curve, an underwriter would be repricing constantly on noise — a single large fire loss reweighting a whole peril curve before anyone confirms it wasn't an outlier. Insurance needs open-loop stability precisely because its liabilities are long-tailed and its capital is committed years in advance.
This is correct as a description of a real failure mode. A closed loop with excessive gain oscillates; a hazard curve that thrashes on every incoming claim would produce pricing whiplash, and reinsurers would rightly refuse to underwrite an underwriter who cannot hold a rate steady for a treaty term. The remedy, though, is a tuning problem inside a closed-loop architecture, not an argument for abandoning the loop. Provenance weighting lets a single-source anomaly — one large claim, one preliminary cat model patch not yet validated against a second vendor — sit in quarantine, flagged as unconfirmed, rather than immediately rewriting the priced curve. Rate limits on belief revision let the system say: this correction is real, but it updates the belief used for the next renewal decision, not the treaty terms already bound. Hysteresis lets a curve resist reversing on a signal that has not persisted. None of that is available to a purely open-loop annual cycle, which has no mechanism at all for distinguishing a confirmed shift in wildfire frequency from a single bad season — it just waits out the year and re-fits, indiscriminately, on whatever happened to land in the window.
| Open-loop annual pricing | Closed-loop continuous belief | |
|---|---|---|
| Correction unit | full renewal cycle | individual belief, provenance-tagged |
| Failure mode | undetected drift between renewals | oscillation on noisy signals |
| Remedy available | none within the cycle | rate limits, hysteresis, quarantine |
| Cost of remedy | none — but no correction either | tuning effort, calibration discipline |
Choosing between a failure mode you can tune and one you cannot treat at all is not a close call, even granting that the tuning is real work and can be got wrong.
Where the resolution actually lands
The thesis narrows rather than collapses. It is not true that underwriting is presently open-loop and unaware of it — bordereaux, mid-cycle repricing and multi-vendor cat model triangulation are real feedback, and an underwriter who ignores them is not representative of the field. What is true is that the feedback which exists corrects the aggregate curve, not the specific belief. The catastrophe model gets refreshed; the particular assumption that a particular loss just falsified is not, in most shops, traced, tagged, and retired with a record of why. The Large Universe Model position claims that this attribution — error signal wired back to the exact belief it disproves, held open past the point the policy was bound, with rate limits and quarantine to stop it from thrashing — is the terminal form of intake for a hazard model. The open question left standing is not whether more streams should feed the curve. It is whether an underwriting desk can afford, in staff time and modelling discipline, to make every stream's correction that specific. That is a resourcing argument, not an architectural one. The architecture has nowhere further to go.