EIS
EIS holds the artificial intelligence governance credential that every other core platform in this index lacks. In June 2025 it became the first insurance technology provider certified to ISO/IEC 42001:2023, the international standard for artificial intelligence management systems, audited by a named certification body with a named partner conducting its service organisation control assessment alongside. It is separately the first core insurance platform certified by the MACH Alliance, an independent body assessing microservices, interface first, cloud native and headless architecture.
The platform is EIS OneSuite, built on EIS Platform and CustomerCore with a middleware layer managing interfaces between front end applications and back end microservices. In October 2025 it added CoreGentic, embedding artificial intelligence, agentic orchestration and natural language control into the core rather than beside it, grounded in a domain specific model the company calls the EIS Knowledge Base. A capability called GuideMe lets business users design, configure and test products, workflows and experiences through plain language rather than development cycles.
What distinguishes the governance material is that it is specific rather than procedural. The company states that grounding, provenance, bias testing, human oversight and auditability are built directly into the core, that outputs are traceable and decisions reviewable and defensible, and that execution is governed through interfaces and workflows with permissions and approvals rather than black box automation. Naming bias testing as a built in capability is something no competitor in this lane does.
Deployment is unusually flexible for a cloud native vendor, supporting cloud, on premises and hybrid infrastructure across any line of business. Named customers span a large United States automobile club insurer, a Canadian auto insurer named the country's best in 2025, the Irish property and casualty brand of a European group, and a United Kingdom motor insurer. Headquartered in San Francisco.
Capability Axes
Capability grades
15 of 15 axes rated · 11 graded A or B
The embedding claim is stronger here than at most core platforms and the removal test still resolves the same way. What the company argues is genuine: the chief technology officer describes moving intelligence from the edge of the system into its heart, the material distinguishes native artificial intelligence usage from bolted on capabilities, and the grounding model sits inside the core rather than alongside it.
Natural language configuration through the business user assistant changes how the platform is operated rather than adding a feature to it. But the platform existed and administered insurance before October 2025, when the agentic layer was announced as a major expansion of the flagship, and the language of expansion is accurate.
Strip the models and policy, billing, claims, customer service and the event driven architecture underneath continue to run insurance operations; what is lost is the speed of change, since configuration reverts from plain language to development cycles. That is a significant loss and it is not the same as the product ceasing to exist.
Oversight described as mechanism rather than sentiment, which is the difference between this and most of the lane. The published position names the controls: humans kept in control through guardrails, approvals and audit trails matched to regulated insurance workflows and internal policies, and governed execution through interfaces and workflows carrying permissions and controls rather than black box automation.
Approvals and permissions are enforceable objects in a system; human in the loop as a phrase is not, and several competitors offer only the phrase. Agentic orchestration is described as coordinating processes across policy, billing, claims and beyond, so machine action is real, and it operates inside that permission structure. Two things hold it below the top band.
Nothing published states what an agent may complete unattended or what specifically requires approval, so the floor is described in kind but not in scope. And the business user assistant lets non technical staff configure products and workflows in plain language, which is powerful and, absent published change control detail, moves configuration authority outside engineering review.
Mechanisms named precisely and an audited process behind them, with no measurements published. The named mechanisms are the right ones for this problem: grounding, so that outputs rest on the domain specific knowledge base rather than on open ended generation; provenance, so an output can be traced to what produced it; and auditability, so a decision can be reviewed and defended after the fact, which is the standard a regulator applies.
Governed execution through permissioned interfaces rather than black box automation describes a system designed to be inspected. Behind them sits certification to the artificial intelligence management systems standard, which requires documented lifecycle controls examined by a third party, so a buyer has external evidence that model risk processes exist even without seeing their output. What is absent is every number. Across two passes no accuracy figure, error rate, validation methodology, benchmark or model documentation was located, and the claims about change velocity are unquantified.
Named customers across four countries with one independently corroborated distinction, and no scale figures at all. The named roster is genuinely international: a large United States automobile club insurer that replaced legacy technology with the platform and reports lower underwriting expense and improved retention, a Canadian auto insurer that went live on the agentic release and was named the country's best auto insurer in 2025 by a national business publication, the Irish property and casualty commercial brand of a major European group continuing and expanding its partnership, and a United Kingdom motor insurer whose former chief executive is quoted by name.
An analyst house named the company a technology standout in policy administration for architecture, scale and real world impact. What is entirely absent is quantification: across two passes no customer count, revenue figure, premium administered, go live count or any numeric measure of scale was located, which leaves this record without the operational metrics its direct competitors publish.
The only externally audited artificial intelligence governance credential located in this index. In June 2025 the company was certified to the international standard for artificial intelligence management systems, stated as the first insurance technology provider to hold it, with the audit performed by a named management systems certification body and engagement management and service organisation control work provided by a named partner firm.
That standard requires a documented management system covering artificial intelligence risk assessment, impact assessment, lifecycle controls and oversight, examined by a third party rather than asserted, which is categorically different from every governance claim graded elsewhere in this lane.
The published practices behind it are specific rather than procedural: grounding and provenance so outputs are traceable to their source, bias testing, human oversight, auditability so decisions can be reviewed and defended, and governed execution through interfaces and workflows with permissions rather than black box automation. Two honest limits: the certification covers the management system rather than any model's performance, and no evaluation results, model card or incident disclosure was located.
An architectural option and an audited assessment, without the documentary detail the leaders in this lane publish. The architectural point is deployment: supporting on premises and hybrid infrastructure alongside cloud means a carrier can keep policyholder data inside its own perimeter entirely, which is a stronger privacy position than any commitment a hosted only vendor can make, and it is available here from a vendor that is otherwise cloud native.
The platform material states that data is kept accessible to the personnel and tools that need it while remaining secure and private according to regional regulations, which acknowledges jurisdictional variation. A service organisation control assessment of the second type has been conducted by a named firm.
What is missing is specificity: across two passes no privacy policy content, data processing description, retention schedule or subprocessor list was located, and no named data protection regime appears despite operations across four countries.
Named auditors, which is rarer than named certifications and more useful. The company holds certification to the artificial intelligence management systems standard, audited by a named management systems certification body, and has undergone a service organisation control assessment of the second type conducted by a named firm which also provided engagement management for the certification.
Identifying who performed the work lets a buyer assess the assessor, and almost no vendor in this index does it. Architecture certification by an independent standards alliance adds a third externally verified credential. Three deductions keep it below the top band. No information security management certification was located across two passes, which is the credential most procurement teams ask for first.
No trust centre exists and no certificate, report or statement of applicability is obtainable, so scope cannot be read from outside. And a direct competitor in this lane publishes its documents for download or on request, which shows the achievable standard.
No financial services authorisation, and the most regulatorily useful credential in this lane. Certification to the artificial intelligence management systems standard is not a licence, but it is the framework on which conformity work under the European artificial intelligence regulation is practically built, and insurance underwriting and pricing are designated high risk under that regime.
A carrier deploying agents into those workflows must be able to evidence governance to its own supervisor, and a vendor holding an audited management system certification gives it something to point to that no competitor here can offer. Architecture certification by an independent standards body adds a second externally assessed credential. The company's framing throughout emphasises regulatory confidence, compliant action and adherence to regional regulations.
What is absent is any explicit position statement: across two passes no named regulatory regime, no artificial intelligence regulation conformity declaration, no operational resilience statement and no supervisory outcome was located.
The only vendor in this insurance sweep to name bias testing as a built in capability, and the highest grade this axis has carried in the lane. The published statement is unambiguous: grounding, provenance, bias testing, human oversight and auditability are built directly into the core, with grounding and provenance making outputs traceable and bias testing and auditability making decisions reviewable and defensible.
That is a fairness capability described as part of the product rather than a principle asserted in a blog, and it sits inside an externally certified artificial intelligence management system whose standard requires documented impact assessment. Every other core platform graded here publishes procedural governance concerning traceability and permissions while saying nothing about whether outcomes fall evenly.
What keeps this from the top band is that no results are published: across two passes no bias testing outcome, fairness metric, disparate impact analysis, model card or conformity assessment was located, so the capability and its audit exist while the findings do not.
No commercial instrument is published. Across two passes no terms of service, master agreement, warranty, indemnity, liability cap, service level or uptime commitment was located, and nothing states what an insurer is owed when the platform or its agents are wrong.
The gap is notable against the rest of this record, because the company has gone further than any competitor on governance, certifying an artificial intelligence management system, publishing bias testing and grounding as built in capabilities, and committing to auditability so decisions can be reviewed and defended. Auditability establishes what happened; it does not establish who pays.
The affected parties remain policyholders, applicants and claimants who are not the customer, receive no notice that agentic orchestration shaped their outcome, and have no published route to see or contest it. A vendor this deliberate about governance is the one most likely to be able to answer the liability question, and it has not published an answer.
The company's own model asset is disclosed and the third party layer is not. On the disclosed side, the domain specific knowledge base is named as the grounding model ensuring actions remain compliant, secure and contextually appropriate, and the agentic layer is named as a distinct product within the suite, so a buyer knows what the vendor built and what it grounds against. That is genuine provenance for the proprietary component.
What is absent is whose foundation models perform the generation. Across two passes no model provider, family, version or technique was named for the agentic orchestration, the natural language control or the business user assistant, and no third party model dependency is acknowledged or excluded.
The omission is more conspicuous here than elsewhere precisely because of the governance posture: a company certified against an artificial intelligence management standard has necessarily documented its model supply chain for the auditor, and has chosen not to publish it.
Architecture certified by an independent body rather than described by the vendor, which is what this axis should reward. The platform is the first core insurance system certified by the MACH Alliance, which assesses microservices based, interface first, cloud native and headless architecture and admits vendors as independent software providers after evaluation. That converts the usual self description into third party verification.
The supporting detail is consistent with it: an event driven, interface rich platform, a middleware layer managing the boundary between front end applications and back end microservices, a headless front end option, and stated integration with all major cloud deployments, databases and core technology whether the vendor's own or a third party's. Open access to external data sources is described concretely, including feeds signalling customer life events that can trigger workflows.
A partner ecosystem exists with its own awards programme, and one named partnership delivers absence and leave management. Across two passes no public developer documentation or connector catalogue was located.
Deployment flexibility unusual for a cloud native vendor, and residency detail still unpublished. The platform is stated to operate whether the infrastructure is cloud native, on premises or hybrid, which matters more than it sounds: most modern core vendors offer hosted software only, so a carrier constrained by supervisory expectation or internal policy from placing policyholder data with a third party has no modern option at all.
Offering an on premises path from a cloud architected product keeps that carrier in the market for current technology. Integration with all major cloud deployments and databases is stated, and a headless option allows the front end to be deployed independently of the core. The platform material also states that data remains secure and private according to regional regulations, acknowledging jurisdictional variation. What is absent is the specificity a regulated buyer needs: across two passes no region list, tenancy description or explicit data residency commitment was located for the hosted option.
No price, unit or tier is published, and two passes across the company's site, its newsroom, product pages and third party coverage produced nothing on how the platform is charged. The published entry route is a demonstration request.
The company's commercial argument is made in the language of cost of change rather than cost of licence: it claims lower cost of change, faster speed to market, reduced technical debt, and that alterations once requiring months of information technology effort can be completed safely in days or hours through plain language configuration.
Those are real claims about the economics of ownership and they are unquantified, with no baseline, no customer attestation and no measurement behind any of them. Deployment flexibility across cloud, on premises and hybrid also implies materially different commercial arrangements for each, and nothing published indicates whether the model or the price differs by infrastructure choice.
Genuine line and geographic breadth, established by named deployments rather than by claim. The platform is stated to operate across any line of business and support any insurance product, and the evidence spans motor, home, life, pet and absence and disability management, the last delivered through a named partnership.
Geographically the named customers sit in the United States, Canada, Ireland and the United Kingdom, which is real multi jurisdiction operation rather than a list of offices. Deployment flexibility widens the addressable market further, since supporting cloud, on premises and hybrid infrastructure lets the platform reach carriers whose regulators or internal policy preclude a pure cloud core, a constituency the cloud only competitors cannot serve. What holds this below the top band is the absence of any figure describing how many insurers use it or at what volume, so breadth of capability is demonstrated while depth of adoption is not.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
| Entry Price | Pricing Basis | Data Protection Terms | Implementation | Source |
|---|---|---|---|---|
|
Not published. No price, unit of billing, tier or contract term appears on any vendor surface
|
Not published on any vendor surface. The suite spans policy, billing, claims, customer service and digital engagement across any line of business, built on a core platform and a customer data component with middleware between front end and back end services, and extended by an agentic layer with natural language control. Nothing published indicates whether charging follows premium, policies in force, transactions, modules, seats or subscription, and the platform's support for cloud, on premises and hybrid infrastructure introduces a further undisclosed variable, since those deployment choices normally carry different commercial structures. | No tiered data protection terms are published. Assurance rests on two externally audited credentials rather than on contract tiers: certification to the artificial intelligence management systems standard by a named certification body, and a service organisation control assessment of the second type conducted by a named firm. Published practices include grounding, provenance, bias testing, human oversight and auditability built into the core, with data stated to remain secure and private according to regional regulations. The on premises deployment option lets a carrier retain policyholder data entirely within its own perimeter. No privacy policy content, data processing agreement, retention schedule, subprocessor list or region list was located. | No implementation, configuration or professional services fee is published. The product's design intent is to reduce that spend rather than to sell it, since the business user assistant lets non technical staff design, configure and test products, workflows and user experiences through plain language, which the company presents as removing development cycles, approval queues and ticket backlogs from the change process. Claimed effect is that changes once taking weeks or months are implemented and tested in hours or days. If accurate that shifts core platform economics away from the recurring configuration spend that usually dominates them, and it is the same problem competitors in this lane address through faster upgrade cycles rather than through self service configuration. None of it is quantified or priced, no implementation timeline for a new customer is published, and a partner ecosystem with its own awards programme indicates delivery partners whose fees sit outside anything the vendor describes. | Vendor Published |
Two passes across the company's site, its newsroom, product and architecture pages and third party coverage produced no price, unit or tier. The company's commercial case is made entirely in terms of cost of change rather than cost of purchase, claiming lower cost of change, faster speed to market, reduced technical debt, and alterations that once took months of information technology effort completed safely in days or hours through plain language configuration.
Those address the expense that dominates core platform ownership, and every one of them is unquantified, with no baseline, no customer attestation and no measurement published. One structural question follows from the product's own flexibility and is not addressed anywhere: the platform runs on cloud, on premises or hybrid infrastructure, and those are three materially different commercial and support arrangements, with nothing indicating whether the licensing model, the price or the included services differ across them.