Insurance AI
O

Origami Risk

Origami Risk sells a cloud native platform spanning risk, safety, insurance and compliance operations, and it is the broadest vendor in this lane by buyer type rather than by insurance depth. The estate runs across a risk management information system, governance risk and compliance, environment health and safety, healthcare integrated risk management, and a property and casualty insurance core covering policy administration, billing, claims administration and underwriting, all delivered from one platform and one data model. The buyer set is correspondingly wide, taking in insurance carriers, third party administrators, brokers and managing general agents alongside the organisations that carry their own risk, including government, healthcare, construction, manufacturing, energy and retail, and the risk pools that serve them.

Artificial intelligence arrives as capability distributed through that platform rather than as a product line. The Q2 2026 release, announced 7 July 2026, introduced an Origami AI Tile allowing artificial intelligence powered actions to be embedded into workflows through drag and drop composition, alongside a next generation administration console, no code tools for visually designing, managing, monitoring and deploying workflows, and a Marketplace for discovering integrations, partner solutions and workflow accelerators. Origami AI Analytics performs analysis inside the risk management information system to surface trends from real time reporting, and an artificial intelligence assisted data centre handles validation and transformation.

The most substantive insurance specific artificial intelligence work is Insurance Program Management, announced 15 June 2026 and delivered inside the risk management information system as an end to end system of record for policies, placements, quotes, endorsements and program analytics. Its central claim is extraction: bringing policy information out of portable documents, spreadsheets and broker systems into structured usable form, then connecting it to claims, exposure and total cost of risk data. The company positions this as removing both manual data entry and the need for what it describes as expensive third party vendors.

Public positioning on artificial intelligence is short and control oriented, describing it as private, configurable and secure, with the customer staying in control.

Independent recognition includes leader placement in a 2025 sustainability software quadrant and market leading placement in a 2026 independent report on risk management information systems, which cites scalable architecture, breadth across claims, risk, policy and safety, and continued investment in analytics, automation and artificial intelligence.

Founded in 2009 by industry veterans and headquartered in Chicago, Illinois, the company has grown to roughly 900 to 965 employees serving more than 1,000 organisations globally. It is privately held, with Spectrum Equity its only outside investor since March 2018.

Last VerifiedAugust 26, 2026
Compare Origami Risk with other vendors
Founded
2009
Headquarters
Chicago, Illinois, United States
Categories
insurance-ai, compliance-and-surveillance
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 4 graded A or B

AI Capability
AI Centrality
CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.
Vendor Published

The removal test is emphatic here and the product architecture makes the answer visible rather than inferred. Artificial intelligence arrives as a tile dropped into a workflow, which is to say a composable optional component in a no code canvas, and a platform whose value proposition is a unified system of record across risk, safety, insurance and compliance loses none of that if the tile is never placed.

Underneath it sit the risk management information system, the governance and compliance estate, the safety estate and a property and casualty core covering policy, billing, claims and underwriting, and all of them predate the current wave and run without it.

The strongest learned dependency is extraction inside the insurance program product, where policy information is lifted out of documents, spreadsheets and broker systems, and even there the system of record is the deliverable and the extraction is a faster route into it than typing.

Autonomy and Oversight Model
CC on Autonomy and Oversight ModelAutonomy is claimed and oversight is asserted without a mechanism, or full automation is presented as the entire disclosure. Human in the loop appears as a phrase rather than a described control.
Vendor Published

Two published facts pull against each other and nothing reconciles them. The oversight claim is that the customer stays in control, always, stated as an absolute in the artificial intelligence positioning. The architecture claim is that artificial intelligence powered actions can be embedded into workflows through drag and drop composition, inside a no code environment for designing, deploying and monitoring those workflows, and an action embedded in an automated workflow executes when the workflow runs rather than when a person authorises it.

Staying in control plausibly refers to the client choosing what to automate, which is control over configuration rather than control over execution, and those are different guarantees. Nothing published names what the tile can do, whether any action type requires approval before taking effect, whether a human review step is available as a workflow component, or what monitoring surfaces when an automated action produces an unexpected result.

Model Risk Management and Transparency
CC on Model Risk Management and TransparencyTransparency is claimed in general terms with no mechanism a model validator could interrogate.
Vendor Published

The capability most in need of a published number is extraction, and it has none. The insurance program product lifts policy terms, placements, quotes and endorsement detail out of portable documents, spreadsheets and broker systems into a structured system of record, and a structured record is trusted downstream precisely because it looks authoritative, so an extraction error propagates into renewal decisions, program analytics and total cost of risk reporting without announcing itself.

Two passes located no accuracy or error rate for that extraction, no confidence scoring description, no human verification step in the published workflow, no validation methodology, no drift monitoring and no model documentation. The analytics capability carries the same gap, with trends surfaced from real time reporting and nothing published about how the surfacing is validated or what a spurious pattern would look like to a user.

Operational and Outcome Evidence
BB on Operational and Outcome EvidenceVendor aggregate claims with real figures, or audited scale disclosures from a publicly listed company.
Vendor Published

Scale is substantial and corroborated from outside the company, with more than 1,000 organisations served globally and roughly 900 to 965 employees, figures published by its own investor as well as by private market trackers, and a 17 year operating history.

Independent recognition exists in two forms and both are recent: leader placement in a 2025 sustainability software quadrant, and market leading placement in a 2026 independent report on risk management information systems which cites scalable architecture, breadth across claims, risk, policy and safety, and continued investment in analytics, automation and artificial intelligence. Two gaps hold the grade at this band.

Two passes located no named customer at all, which is unusual at this scale and leaves the client base described only in aggregate. And no quantified outcome is published for any capability, with nothing on extraction accuracy, time saved, claim cycle reduction or cost avoided, including for the artificial intelligence features released during 2026.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

The published position is four words long and undocumented behind them: private, configurable, secure. As a statement of intent it points at the right questions, and as evidence it establishes nothing, because two passes located no artificial intelligence policy, no data handling statement and no model documentation of any kind. The unanswered questions are the standard set and each has weight given what this platform holds. Whether client data is used to train or improve any capability.

Whether one client's claims or safety records inform capability delivered to another. Where inference occurs and whether claimant medical detail or named employee incident data leaves the platform boundary when a workflow tile invokes a model. What happens to data on termination. A vendor selling governance and compliance software to risk professionals is better placed than most to publish this, which makes the absence more conspicuous rather than less.

Regulatory and Compliance
GLBA and Data Privacy Posture
CC on GLBA and Data Privacy PostureA standard privacy policy that covers the website rather than the service, or silence on a product that touches limited consumer data.
Vendor Published

Two passes located no privacy policy content covering client or claimant data, no data processing agreement, no retention schedule and no subprocessor list. The vendor's public artificial intelligence language gestures at the subject without documenting it, describing the capability as private, configurable and secure with the customer staying in control, and that formulation is a claim rather than a commitment because nothing published defines what private means in this context, whether it refers to tenancy, to model isolation or to a contractual term.

The data sensitivity here deserves emphasis, because the platform holds workers compensation and liability claim records for third party administrators and risk pools, which include injury detail and medical information about individual claimants, and it holds safety incident and chemical exposure records about named employees. Neither category is addressed by anything published.

Security Certifications and Trust Center
BB on Security Certifications and Trust CenterA recognised certification named in the vendor’s own material without the artefact, or with a scope or renewal question the buyer has to raise.
Third Party Estimated

The credential set reported is the strongest in this lane and the sourcing is weaker than the credentials deserve. Reported are service organisation control reports of both the first and second kind at the second type, meaning both the financial reporting assessment and the security assessment are examinations of operating effectiveness over a period rather than design at a point in time, which is the distinction that separates a meaningful report from a preliminary one and which several peers in this lane do not clear.

Alongside them are adherence to the federal control baseline, real time intrusion detection and prevention, penetration testing, encryption of client data, and hosting with a major cloud provider. The qualification a buyer should carry is that all of it was located in third party trade coverage which is undated, and two passes did not locate a trust centre, a security page or a certification statement on the company's own surfaces, so the reports should be requested and their dates checked rather than assumed current.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

The company holds no insurance licence and does not claim one, the ordinary position for a platform supplier, and its regulatory posture is oriented toward its clients' obligations rather than its own. The governance risk and compliance estate, the safety estate and the chemical management capability released in 2026 all exist to help organisations demonstrate compliance, with audit readiness and access to trusted information named as the outcomes.

That is a compliance product rather than a regulated status. Its clients include several categories carrying licensure of their own, notably third party administrators and public entity risk pools, which are supervised at state level and are examined on how claims are handled, so the software sits inside an examined process without being examined itself. Two passes located no filing capability, no statement on state reporting support and no positioning against any artificial intelligence regulation.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

This vendor sells governance software and publishes no governance of its own artificial intelligence, which is the finding worth recording. Two passes located no responsible artificial intelligence statement, no ethical principles, no governance structure, no model card, no bias testing description and no fairness metrics, while the same company markets a governance risk and compliance product line to the professionals whose job is demanding exactly those artefacts from suppliers.

The exposure is concrete rather than rhetorical. Claims administration for third party administrators and risk pools touches workers compensation and liability decisions affecting injured individuals, and analytics that surface trends across claim populations can encode patterns that disadvantage classes of claimant. Nothing published indicates that any of it is tested, and a buyer whose own regulator asks the question will find nothing to point at.

AI Liability and Recourse
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.
Vendor Published

Recourse is unaddressed and the affected parties here are among the most exposed of any vendor in this lane. The platform administers claims for third party administrators and public entity risk pools, which means workers compensation and liability matters involving injured individuals, and those claimants are not the customer, have no relationship with this vendor, receive no notice that automated extraction or analytics shaped the handling of their claim, and have no published route to obtain or contest it.

The safety estate adds named employees whose incident and chemical exposure records sit in the same system. Between vendor and client nothing published allocates liability for a mis extracted policy term that leaves a program under insured at renewal, an analytics output that misdirects a reserving decision, or an automated workflow action that advances a claim incorrectly. Two passes located no liability language, no service level commitment tied to artificial intelligence output and no error handling policy.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

Nothing in the published record identifies what the artificial intelligence runs on. Two passes located no provider, no model family, no version, no hosting arrangement and no statement distinguishing capability built in house from capability licensed in, across the workflow tile, the analytics capability, the data validation centre and the policy extraction in the insurance program product.

The company's own description of its artificial intelligence as private is the closest thing to a supply chain statement and it resolves nothing, since private could describe a self hosted open weight model, a dedicated instance at a commercial provider or an internal deployment, and each carries a different answer on where data goes and who else can see it. A buyer cannot assess concentration risk, cannot know whether a provider change would alter behaviour mid contract, and cannot answer its own regulator on where inference occurs.

Core Systems and Integration Depth
BB on Core Systems and Integration DepthNamed systems or a documented public API, with the depth or the production evidence left open.
Vendor Published

The integration story here is internal breadth rather than external reach, and it is real. Five solution families sit on one platform and one data model, covering the risk management information system, governance and compliance, environment health and safety, healthcare integrated risk management, and a property and casualty core with policy administration, billing, claims administration and underwriting.

The insurance program capability demonstrates what that consolidation buys, connecting policy and placement data directly to claims, exposure and total cost of risk analytics without a transfer between systems, which is a genuine advantage over assembling the same picture from separate vendors.

Outward connectivity was strengthened in 2026 with a Marketplace for discovering integrations, partner solutions and workflow accelerators, and a no code workflow layer for designing and deploying processes. What holds the grade at this band is that the marketplace is new and undocumented in scale, and no published interface documentation or integration count was located in two passes.

Deployment Model and Data Residency
CC on Deployment Model and Data ResidencyCloud only with nothing stated, which is the category norm.
Vendor Published

Delivery is cloud native and browser based with a mobile application for field data capture, and third party coverage names a major cloud provider as the hosting environment, which the vendor's own surfaces do not confirm in anything located during two passes. Beyond hosting the record is empty. No region list, no processing location statement, no data residency commitment, no tenancy description and no on premises or private cloud path were found.

Two facts make those omissions matter more than the grade alone suggests. The client base includes government and public entity risk pools, which frequently carry jurisdictional data location requirements written into procurement rather than negotiated afterwards. And the platform holds claimant medical detail and named employee safety records, which are the categories most often subject to location restrictions in the first place.

Commercial
Commercial Transparency
CC on Commercial TransparencyNo price is published and engagement runs through a demo form, which is the norm in this index.
Vendor Published

Pricing is absent from every vendor surface and follows a contact for quote model, which independent review content reads as indicating enterprise pricing tailored per client rather than standardised tiers. The one commercial claim the company does make is comparative and pointed: the insurance program capability is positioned as removing the need for what it calls expensive third party vendors, meaning the specialist brokers and data services organisations currently use to assemble policy information.

Making a competitor's cost part of the pitch while publishing none of its own is the tension a buyer should name early. Nothing published indicates the charging unit across a platform spanning five solution families, and nothing indicates whether the artificial intelligence capabilities released in 2026 are included for existing clients or licensed separately, though the release material states they are now available to clients.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

Buyer breadth is the widest in this lane and insurance depth is not, which is what places the grade here rather than higher. The platform serves both sides of the risk transfer: carriers, third party administrators, brokers and managing general agents on one side, and on the other the organisations carrying their own exposure, including government, healthcare, construction, manufacturing, energy, waste and retail, plus the risk pools that serve public entities.

No other vendor in this lane addresses self insured corporates and public entity pools as first class buyers, and that is a genuine coverage difference rather than a marketing list. Against it, the insurance capability itself is property and casualty only with no life or annuity presence, and the carrier core competes against platforms with far deeper installed bases in that specific market. The absence of any named customer also means segment claims rest on aggregate figures rather than on demonstrable presence in each.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

Entry Price Pricing Basis Data Protection Terms Implementation Source
Not published. Contact for quote across all solution families, with no price, unit of billing, tier or contract term on any vendor surface
Not published on any vendor surface. The platform spans a risk management information system, governance risk and compliance, environment health and safety, healthcare integrated risk management and a property and casualty insurance core covering policy, billing, claims and underwriting, and nothing published indicates whether charging follows modules, users, claim volume, premium under management, covered locations or a platform subscription. The buyer set spans carriers, third party administrators, brokers, managing general agents, self insured corporates and public entity risk pools, whose economics differ enough that a single basis is unlikely, and nothing published describes how the model varies across them. No tiered data protection terms are published. Third party trade coverage reports service organisation control reports of both the first and second kind at the second type, adherence to the federal control baseline, intrusion detection and prevention, penetration testing and encryption, and two passes did not locate a trust centre or security page on the company's own surfaces to confirm any of it or establish dates. That gap matters more than usual because of what the platform holds. Claims administration for third party administrators and risk pools brings claimant injury and medical detail into the system, the safety and chemical estates bring named employee exposure records, and healthcare integrated risk management brings a client base with its own patient information obligations. None of those categories is addressed by any published data protection commitment, and no data processing agreement, retention schedule or subprocessor list was located. No implementation, configuration or professional services fee is published, and the company's positioning treats implementation friction as the thing it removes rather than the thing it charges for, describing a secure and scalable way to manage claims, workflows, data and compliance without the friction of complex implementations, and offering support from onboarding through ongoing optimisation. The 2026 release moved further in that direction by putting configuration in client hands, with a standalone administration console described as simplifying platform management through self service, and a no code environment for visually designing, managing, monitoring and deploying workflows without engineering involvement. A specialist team is described as advising during deployment, so the function exists and is unpriced. Nothing published states a typical implementation duration, a professional services rate, or what a migration onto the platform involves for an organisation replacing an incumbent risk management information system. Vendor Published

Two passes across the company's site, its newsroom, its product update pages and third party coverage produced no price, unit or tier, and the model is contact for quote. Independent review content reads that as enterprise pricing configured per client rather than published tiers, and treats it as indicating a solution aimed at large organisations with complex requirements and budget to match, which is inference from the sales model rather than disclosure.

The company is privately held, founded in 2009, with Spectrum Equity its only outside investor since March 2018, so no financial reporting fills the gap and revenue figures circulating on data aggregators are third party estimates rather than reported results.

The unresolved commercial questions are how a platform spanning five solution families is packaged and charged, whether the artificial intelligence capabilities released during 2026 carry separate terms, and how the marketplace introduced in the same release prices partner solutions and workflow accelerators.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746