Industries · Insurance

AI in a Zimbabwean insurer: claims first

Claims delay is the complaint IPEC hears most. It is also the process where AI is safest to introduce, provided the rejection stays human and health data is handled under the Act's written-consent rule.

Sector figures

US$317.01m
Insurance revenue of direct short-term insurers for the year ended 31 December 2025 (ZWG 8.43 billion), of which USD 245.55 million, or 77%, was foreign-currency denominated; short-term insurer revenue rose 20% from US$255.56 million in 2024.
IPEC Short-Term Insurance Sector Report 2025, via Equity Axis (April 2026)
21
Direct short-term insurers registered at 31 December 2025, 15 of which met the USD 1.5 million minimum capital requirement; 905 registered entities in the sector in all; sector combined ratio 98%.
IPEC 2025 report via Equity Axis
74%
Share of the 155 complaints IPEC received in 2025 that concerned claims delays (complaints up 23% on 2024).
IPEC 2025 report via Equity Axis

Regulatory position

As at September 2026 we could not locate an IPEC guideline that speaks specifically to AI or model governance for insurers; the Insurance and Pensions Commission Amendment Bill gazetted on 20 December 2024 extends IPEC's reach (including to medical aid societies) but is not an AI instrument. What binds an insurer today is the Cyber and Data Protection Act and SI 155 of 2024: written consent for health data (s.12), no solely automated decision with significant effect (s.25), transfer rules (s.28–29), a Tier licence and a certified DPO. Insurers with a banking parent should expect the RBZ's group-wide expectations (Cybersecurity Guideline 5.4) to reach them.

Three use cases with risk notes

  1. 01

    Claims triage and document extraction

    Models classify incoming claims, extract fields from forms, quotes and reports, check completeness against the policy, draft the request-for-information letter and route the claim. Assessors decide; the system shortens the queue.

    Risk notes. Medical claims are health data: written consent at policy inception and claim (s.12(1)); rejection, reduction or repudiation stays human (s.25); retrieval filtered so an assessor sees only assigned claims; in-country hosting for the index; measurable outcome is the IPEC complaint category itself.

  2. 02

    Fraud and duplicate-claim detection

    Scoring across claims, providers and repairers surfaces patterns for an investigator; the investigator opens the case.

    Risk notes. A fraud flag is not a decision until someone acts on it; keep it that way in the process design and in the audit log; bias review across regions and provider types; data sharing with other insurers is a transfer requiring a basis, even inside Zimbabwe under the Act's processing principles.

  3. 03

    Underwriting and pricing support

    Models assist with risk classification and pricing recommendations that an underwriter or actuary approves; recommendations and outcomes are logged for back-testing.

    Risk notes. No RBZ model standard applies, but adopt its register and independent-validation discipline anyway; forex is structural (77% of revenue in USD) so hosted-model costs are affordable in principle, yet personal data still cannot leave without a s.28 basis; document actuarial sign-off on any model that changes price.

Sources

  1. Equity Axis (April 2026) — analysis of IPEC's Short-Term Insurance Sector Report for the year ended 31 December 2025
  2. Muvingi and Mugadza — Summary of the Insurance and Pensions Commission Amendment Bill, 2024 (gazetted 20 December 2024)
  3. Data Protection Act, Act 5 of 2021 (Cyber and Data Protection Act [Chapter 12:07]) — s.12, s.25, s.28–29; SI 155 of 2024
  4. RBZ Cybersecurity and Resilience Guideline (August 2025) — para 5.4 (group service providers)