Compliance across both halves of the fabric: customer-side KYC currency on real policyholder records, and data-side PII exposure, regulated data elements and open governance findings from the live catalog — plus IRDAI obligations including the Fraud Monitoring Framework.
Policies in force behind customers whose KYC is expired, rejected or pending — the exposure a regulator asks about first.
| Customer | KYC | Risk | Policies | Premium |
|---|---|---|---|---|
| Sandeep Chauhan | PENDING | LOW | 4 | ₹68,314 |
| Harish Shinde | REJECTED | LOW | 3 | ₹62,220 |
| Deepa Saxena | PENDING | LOW | 4 | ₹61,082 |
| Nisha Khandelwal | REJECTED | LOW | 3 | ₹55,527 |
| Rahul Yadav | PENDING | MEDIUM | 4 | ₹50,991 |
| Ritu Chauhan | REJECTED | LOW | 3 | ₹49,790 |
| Sneha Jadhav | REJECTED | LOW | 3 | ₹49,167 |
| Neha Gokhale | EXPIRED | MEDIUM | 2 | ₹48,821 |
| Smita Kulkarni | EXPIRED | MEDIUM | 3 | ₹48,463 |
| Suresh Joshi | VERIFIED | HIGH | 3 | ₹47,686 |
Live rows: 1,500 KYC check records read from demo_bfsi.kyc_check + customer in PostgreSQL at request time. These are genuine records with genuine structure, but they are synthetic demo data, not Generali Central's book — status distributions are near-uniform, and person, provider, branch and payer names are localised to Indian display names at read time. Scores demonstrate the scoring mechanism, not predictive performance. The reconciled ₹5,548 Cr figures elsewhere in this cockpit come from the governed SQLite book.
What the catalog knows about sensitive data in the estate, and the findings still open against it.
Column classified as 'Medical Diagnosis / Procedure (Health)' (GDPR (EU): Special Category Data (Art. 9) | PCI-DSS v4 (Payments): Cardholder Data (CHD)) under GDPR (EU) + PCI-DSS v4 (Payments). Sampled values are stored unmasked (pattern: A99). Required: Suppress or generalise to chapter level; strict need-to-know access
Column classified as 'Medical Diagnosis / Procedure (Health)' (GDPR (EU): Special Category Data (Art. 9) | PCI-DSS v4 (Payments): Cardholder Data (CHD)) under GDPR (EU) + PCI-DSS v4 (Payments). Sampled values are stored unmasked (pattern: A99.9). Required: Suppress or generalise to chapter level; strict need-to-know access
Column classified as 'Policy Monetary Value' (GDPR (EU): Personal Data | PCI-DSS v4 (Payments): Cardholder Data (CHD)) under GDPR (EU) + PCI-DSS v4 (Payments). Sampled values are stored unmasked (pattern: 9999999.99). Required: Access-restrict; not an identifier - retain for actuarial/claims use
Column classified as 'Claim Number' (GDPR (EU): Personal Data (indirect identifier) | PCI-DSS v4 (Payments): Cardholder Data (CHD)) under GDPR (EU) + PCI-DSS v4 (Payments). Sampled values are stored unmasked (pattern: AAA999999). Required: Tokenise / pseudonymise in non-production
Column classified as 'Medical Record Number' (GDPR (EU): Personal Data | PCI-DSS v4 (Payments): Cardholder Data (CHD)) under GDPR (EU) + PCI-DSS v4 (Payments). Sampled values are stored unmasked (pattern: AA999999). Required: Tokenise; encrypt at rest; need-to-know access
Column classified as 'Policy Monetary Value' (GDPR (EU): Personal Data | PCI-DSS v4 (Payments): Cardholder Data (CHD)) under GDPR (EU) + PCI-DSS v4 (Payments). Sampled values are stored unmasked (pattern: 999999.99). Required: Access-restrict; not an identifier - retain for actuarial/claims use
Column classified as 'Policy Number' (GDPR (EU): Personal Data (indirect identifier) | PCI-DSS v4 (Payments): Cardholder Data (CHD)) under GDPR (EU) + PCI-DSS v4 (Payments). Sampled values are stored unmasked (pattern: AAA999999999). Required: Tokenise / pseudonymise in non-production
Column classified as 'Policy Monetary Value' (GDPR (EU): Personal Data | PCI-DSS v4 (Payments): Cardholder Data (CHD)) under GDPR (EU) + PCI-DSS v4 (Payments). Sampled values are stored unmasked (pattern: 9999999.99). Required: Access-restrict; not an identifier - retain for actuarial/claims use
Obligations recorded in the governance repository, by regulator.
The deadline that matters: the IRDAI Fraud Monitoring Framework is effective 1 April 2026 — a board fraud committee, a dedicated monitoring unit, insurer-specific red-flag indicators, mandatory IIB participation and a caution repository. Readiness is modelled at 70%.
The figures a statutory return asks for — premium by line, net earned premium, the ratios and the solvency walk — assembled directly from the reconciled book verify.mjs guards. Audit automation: every agent run and decision lands in the Activity log.
| Line of business | GWP ₹Cr | Loss ratio | Retention |
|---|---|---|---|
| Motor | 1,886 | 68% | 84% |
| Health & Personal Accident | 1,858 | 99% | 78% |
| Crop, Rural & Miscellaneous | 904 | 55% | 60% |
| Commercial & Property | 900 | 74% | 70% |
| Total | 5,548 | 79% | 66% |