Kristen Nunery on the Role of AI in Third-Party Insurance Compliance Frameworks
The Importance of AI in Insurance Compliance by Kristen Nunery
On September 16, 2026, Kristen Nunery, CEO of illumend and the founder of myCOI, emphasized the critical role of advanced artificial intelligence (AI) systems in Certificate of Insurance (COI) compliance. In her recent article, titled "Grounding Is Half the Answer in COI Compliance," she pointed out that simply grounding AI in an organization’s specific insurance criteria is not enough. While grounding provides an essential basis for compliance evaluations, it only represents part of what constitutes a reliable COI compliance framework.
Understanding Grounded AI
Nunery defines grounded AI as a system that utilizes defined and authoritative pieces of information instead of relying solely on generalized knowledge acquired during training. In the context of COI, this foundational information includes contracts, leases, insurance stipulations, vendor classifications, along with necessary endorsements and exceptions. While this additional context allows AI systems to set clear standards for compliance evaluations, Nunery argues that it is insufficient on its own.
The true challenge lies in the fact that AI must cross-reference information among various documents—such as contracts, certificates, endorsements, schedules, and amendments—to assess compliance accurately. This means that the AI needs not only to decipher the relevant details from each document but also to understand the intricate relationships between those documents to provide a cohesive compliance verdict.
As Nunery asserts, "COI compliance is a document-relationship problem before it is a document-reading problem." An AI system may accurately assess isolated documents but can still come to flawed conclusions if it neglects to connect the information properly.
The Limitations of Document Extraction
Focusing too heavily on document extraction is where many AI compliance systems fall short. While they excel in pulling out important facts like policy numbers, coverage limits, and expiration dates, they often miss the bigger picture of how these details coalesce into the specific requirements of a vendor, contract, or project. Simple extraction and scoring cannot replace the understanding needed for compliance.
A well-structured COI compliance system should evaluate how information in separate documents influences, supports, or contradicts one another. Nunery emphasizes that "cross-document reasoning provides the comprehensive understanding that leads to accurate determinations, while grounding identifies the standards that evidence must meet. Remove either aspect, and the resulting assessment is merely a gamble dressed up in confidence."
Importance of Traceable AI Decisions
Another critical point raised by Nunery is the need for traceability in AI-informed compliance decisions. Each determination of compliance should be justifiable, detailing which contract requirements were applied, which documents were inspected, and the rationale behind conclusions drawn. This traceability ensures that compliance assessments can withstand scrutiny during audits, disputes, or claims. As Nunery noted, "A compliance verdict that cannot be reconstructed is not defensible, no matter how confidently it was reached."
In a standard compliance decision, a clear path should exist linking the governing requirement to the corresponding supporting documents. Human intervention is essential at this stage. Although AI can significantly speed up evaluations and highlight potential inadequacies, a human touch is necessary to approve any conclusion, particularly in instances where documentation may be lacking or where unusual policy language is in play.
Questions for Vendors
For organizations seeking to adopt grounded AI compliance solutions, Nunery recommends a thorough examination of various factors beyond the technology's underlying AI model, such as:
1. Who establishes the definition of "compliant" in the system?
2. Are the requirements set prior to large-scale operation?
3. Does the system connect insurance certificates with contracts, endorsements, and schedules?
4. Can the AI distinguish between missing documentation and insufficient coverage?
5. Is every determination backed by documented reasoning?
6. Is there human approval before declaring a vendor compliant?
7. What capabilities are operational today versus what is upcoming?
How illumend Addresses COI Compliance
Illumend, founded in 2025, uses AI to redefine the approaches businesses take toward third-party insurance compliance management and risk oversight based on vast historical data, reviewing over 45 million documents and managing 1.2 million agreements. During onboarding, illumend ensures that an organization's insurance specifications are configured based on its established contracts. Subsequently, submitted information is assessed against these defined requirements, reviewing endorsements and identifying potential gaps in coverage before human confirmation of compliance is issued.
The aim is to construct an efficient workflow that checks four elements: the organization’s requirements, the provided insurance documentation, the subsequent evaluation reasoning, and the necessary human approval for the final verdict.
In conclusion, Kristen Nunery asserts, “Grounding AI in an organization’s requirements is the right place to begin, but it is merely half of the equation.” Risk and compliance professionals must demand smarter systems that can grasp the full spectrum of compliance, apply correct requirements consistently, and yield decisions that hold up under scrutiny during audits or claims.