Regulators
Regulators And Compliance.
Written for a regulator or an insurer's compliance function as the reader. Claims handling is supervised activity, and a technology supplier into it inherits obligations from its customer.
Each page names the supervisory bodies and the instruments that apply in that jurisdiction, and states Kempron's posture toward them.
Summary
Kempron's Position In One Paragraph
Kempron Inc. is a Canadian technology supplier to property and casualty insurers. It is not a regulated financial institution, holds no insurance licence, and does not underwrite, adjust or settle claims. Its exposure to insurance regulation is indirect and arises through its customers: an insurer engaging Kempron does so as a third-party or service-provider arrangement under whichever supervisory framework applies to that insurer. Kempron's design posture is to make that assessment straightforward rather than to argue about scope.
On Accuracy. These pages name real bodies and real instruments. They are summaries for orientation, not legal advice, and not a substitute for the instruments themselves. Regulators and supervised firms who find an error here are invited to write to info@kempron.io; it will be corrected.
Jurisdictions that could not be sourced to this standard are not listed.
By Jurisdiction
Who Supervises What, Market By Market
Eleven jurisdictions across eight pages, each naming the bodies and the instruments. Canada and the United States are the markets Kempron is built for. The others are here because the supervisory direction of travel is consistent across all of them, and because a reader in those markets should find their own regulator described accurately. Naming a jurisdiction is not a claim to operate in it.
Canada
OSFI federally, a different conduct regulator in every province, three public insurers, and the most demanding privacy regime in North America.
Read the Canadian framework → JurisdictionUnited States
Fifty-plus state regulators, NAIC model laws, and the most developed body of insurance-specific AI supervision anywhere.
Read the US framework → JurisdictionUnited Kingdom
Twin peaks, the Consumer Duty, ICOBS claims rules, and a new oversight regime aimed directly at critical third-party suppliers.
Read the UK framework → JurisdictionEuropean Union
EIOPA and national supervisors, Solvency II, GDPR, DORA and the AI Act — the densest supplier-facing rulebook of the six.
Read the EU framework → JurisdictionSouth Africa
Twin peaks under the Financial Sector Regulation Act, the FSCA and the Prudential Authority, POPIA, and a consolidated ombud scheme.
Read the South African framework → JurisdictionAustralia
APRA and ASIC, CPS 230 on service providers, and the only market here where handling a claim is itself a licensed financial service.
Read the Australian framework → JurisdictionJapan, South Korea, Singapore
The FSA and its business improvement orders, the FSS and standalone insurance fraud legislation, and MAS with the Motor Claims Framework.
Read the Asian frameworks → JurisdictionUAE, Saudi Arabia
The CBUAE and the 2025 consolidation of its statute base, the Saudi Insurance Authority, prescribed motor wordings, and Najm.
Read the Middle East frameworks →Privacy
Privacy And Personal Information
Claims data is personal information in the strict statutory sense and frequently includes sensitive categories. This is our posture; the jurisdiction pages carry the applicable law.
- Minimisation over accumulation. Collect what the process requires, for a defined purpose, for a defined period.
- Locatability. Kempron expects to state precisely where a given category of data sits, who can reach it and how long it will be retained.
- Residency as a contractual term. Commitments about holding personal information in a particular jurisdiction are made in writing in the agreement, not offered as a preference.
- Deletion with a deadline. Return or destruction on exit is an obligation with a date attached, agreed before go-live rather than negotiated afterwards.
- Assessment support. Where a customer must conduct a privacy impact assessment, or a data protection impact assessment, we expect to supply what it needs rather than treat it as the customer's problem.
Security
Security Posture
Kempron does not hold a SOC 2 report or an ISO/IEC 27001 certification. It holds no security accreditation of any kind, in any jurisdiction.
Kempron designs and documents against the AICPA Trust Services Criteria that underpin SOC 2, and against the control domains of ISO/IEC 27001, because those are the frameworks an insurer's third-party risk function assesses suppliers within. Building to a framework is not the same as being certified against it. Where an engagement requires formal attestation, that is scoped, sequenced and funded as part of the engagement.
Commitments We Will Make In Writing
- Data ownership: the insurer's data remains the insurer's data. Processing it gives us no rights in it.
- Permitted use: defined in the agreement and limited to delivering the engagement. No secondary use, no aggregation for other customers, no use for product development beyond what is expressly agreed.
- Residency: committed contractually, including holding Canadian personal information in Canada.
- Retention and deletion: defined periods, and return or destruction on exit with a deadline.
- Sub-processors: disclosed to the customer as part of third-party risk review.
- Incident notification: contractual obligations aligned to the customer's own regulatory notification duties, which are what actually drive the clock.
- Audit and assurance: reasonable access and information rights for the customer and, where applicable, for its regulator.
- Exit: a documented route out, agreed before go-live rather than negotiated under pressure later.
Auditability
What Auditability Means At A Policy Level
These are governance commitments. They describe what must be true of a system, not how one achieves it.
A claims process is subject to after-the-fact examination by parties who were not present when it ran: an internal auditor, a market conduct examiner, an ombud, opposing counsel, a court. Auditability is the property that makes those examinations possible. A system whose output cannot be accounted for is unfit for this market, regardless of how well it performs.
Four propositions follow. Each is testable without access to implementation detail:
- Every material step leaves a record. What happened, when, on what input, and under whose authority. A step that leaves no trace cannot be defended later, and the absence will be discovered at the worst possible moment.
- Records are retained for as long as the claim can be examined. That period is set by limitation periods, regulatory retention requirements and the customer's own policy, not by what is convenient to store.
- The reasoning is reconstructable, not merely the outcome. Knowing what a process concluded is of little use to an examiner who needs to know on what basis.
- Decision rights stay with the accountable party. The insurer carries the regulatory accountability for how a claim is handled. Automation that quietly relocates a decision away from the accountable party has created a governance problem and disguised it as an efficiency.
A regulator or compliance officer needs to know what must be true of the system and how it will be evidenced. Neither requires publication of how it is built. The same applies to artificial intelligence.
Contact
Regulatory And Compliance Correspondence
Kempron responds to regulatory and compliance enquiries directly, and provides corporate particulars, registration details and a mutual non-disclosure agreement on request. Security questionnaires and third-party risk documentation are handled as part of the engagement process.
The enquiry form has a dedicated regulator route. Corrections to these pages are welcome.
Use The Enquiry Form