Sifflet — insurers cannot treat data trust as a quarterly project (continuous-evidence positioning + Malakoff Humanis use case)

Tag: S-2026-05-28-sifflet-insurance-continuous-evidence Type: article (vendor blog — CEO-authored thought-leadership with customer use case) Author(s): Salma Bakouk (Co-founder & CEO, Sifflet) Date of source: 2026-05-28 Date ingested: 2026-06-23 Authority weight: low — vendor marketing/thought-leadership; regulatory references are checkable but unverified this run, and the reference-customer and capability claims are self-interested. Raw file: S-2026-05-28-sifflet-insurance-continuous-evidence.md. External URL: https://www.siffletdata.com/blog/insurance-companies-cannot-keep-treating-data-trust-as-a-quarterly-project

What it claims

Sifflet — a data-observability vendor positioning itself as “the control plane for Data and AI” — argues that European (and UK/US) insurers can no longer satisfy supervisors with annual, quarterly or audit-driven evidence of data quality; supervisors now expect continuous, auditable proof that the data feeding technical provisions, reserving, disclosure and AI/ML pricing models is appropriate, complete and accurate. The piece anchors this on a convergence of obligations it characterises as: Solvency II Article 82 (data appropriateness/completeness/accuracy, in force since 2016) plus EIOPA’s Guidelines on the Valuation of Technical Provisions (“sixteen specific data quality expectations on the Actuarial Function”); a tightened ACPR posture demanding traceability, alerts and evidence from the actuarial, risk and internal-audit functions; Directive (EU) 2025/2 (the first comprehensive Solvency II revision, transposing by January 2027); DORA Article 9(2) (data integrity at rest/in use/in transit) and Article 35 (penalties up to 1% of average daily worldwide turnover for critical ICT third-party providers, oversight maturing 2026–2027); Solvency UK (PRA PS15/24, December 2024) and the BoE Insurance Taxonomy v2.0.2; and US frameworks (NAIC AI Model Bulletin, Colorado Reg 10-1-1, compliance due July 2026). Sifflet frames the operational consequence as four demands — continuous monitoring of data feeding regulated outputs, visible (not reconstructed) end-to-end lineage, end-to-end incident documentation (cause, impact, remediation, time-to-resolution), and the same controls extended over inputs to AI/ML models — and pitches its platform as delivering a single “regulator-ready record” for the Actuarial Function, CRO, CDO and auditor. It cites a named European reference customer, Malakoff Humanis (one of France’s largest health/welfare insurers, ACPR-supervised), as running continuous Solvency II Article 82 data-quality controls on Sifflet with an audit trail “built as the work happens, not reconstructed before a regulator visit.”

Notable quotes

“Regulators no longer accept evidence that was reconstructed after the fact. They want continuous, auditable proof that the data feeding capital, reserving, disclosure, and AI is sound.” — Salma Bakouk, Sifflet blog, 28 May 2026

“The only way through is to make the evidence continuous by design.” — same

“AI governance and data governance are not the same thing, but they are inseparable in a regulated environment. Data governance manages inputs. AI governance controls behavior.” — same

What’s speculative vs. asserted

  • Asserted (as regulatory references, checkable but unverified here): the specific articles, guidelines, directives and deadlines listed above. These are Sifflet’s characterisation; not independently confirmed this run.
  • Asserted (as a vendor reference-customer claim): Malakoff Humanis runs continuous Solvency II data-quality controls on Sifflet. Adoption is plausible and named, but is a self-interested vendor claim with no scope/dates/independent corroboration.
  • Speculative / vendor framing: that Sifflet’s platform constitutes a “regulator-ready record” sufficient for any specific supervisory threshold; that continuous-evidence-by-design is “the only way through.” Marketing framing, not demonstrated.

Topics this feeds

Open questions raised

  • Whether continuous data-observability evidence (monitoring + lineage + incident logs) is actually accepted by the ACPR / PRA / EIOPA as Solvency II Art 82 or DORA Art 9(2) evidence, or merely supports it — the post asserts supervisory expectation but cites no supervisory confirmation.
  • Scope and dates of the Malakoff Humanis deployment (perimeter, go-live, whether it is production-wide) — not given.
  • How Sifflet positions against the named catalogue/lineage incumbents (Collibra, Informatica, Solidatus) that EU/UK FIs already run for BCBS 239 / Solvency lineage — overlap vs. complement is unstated.