RSA's Head of Data: The Region's Insurers Are Stuck at "Level Two" on a Five-Point Data Maturity Scale
Asked to place the Middle East insurance industry on a data-maturity curve running from 0 (basic reporting) to 5 (full AI deployment), Varghese Skariah, regional head of data at RSA Middle East, didn't hedge. Data-native insurtechs like Lemonade, he said, sit around level four -- companies that "really redefined insurance using behaviour and science" and run lean specifically because data does the work traditional operations used to. Traditional insurers in the region, including RSA itself, land around level two. "They do explore, they touch upon it... but do we really see the expected value coming out of it? We're on the journey, I'd say."
That's a blunt admission from someone whose job is literally to close that gap, and it's worth taking at face value rather than as false modesty -- the rest of the conversation is largely an explanation of why the gap exists and what closing it actually requires.
Sixty percent of the work is cleaning, not modelling
The first myth Skariah wanted to dismiss is that having data is the hard part. "Many people assume that, okay, if I've got data..." he said, trailing off to make the point: having data and having usable data are different problems, and the gap between them is mostly manual. "Data cleaning really just takes majority of the time... I'd say the first data scientists effectively were actuaries." His estimate: cleaning eats roughly 60% of the effort in any analytics project, with modelling itself under 40%.
That reframes what "data maturity" actually means in practice. It isn't primarily a modelling-sophistication problem -- it's a data-infrastructure problem. An insurer whose systems were built with the right underlying warehouse structure from the start can extract and transform data with minimal friction; one that wasn't has to solve that foundational problem before any AI ambition is realistic. Skariah credits RSA's ability to move quickly on dashboards directly to earlier, deliberate investment by the company's CTO in getting that foundation right -- not a data-science hire, but plumbing work done years in advance.
Governance is the pillar nobody wants to fund, and the one AI actually depends on
Skariah's three-pillar model for a data organisation is warehouse/ETL, governance, and analytics -- in that order, and deliberately so. Analytics is what people actually want and where they see value fastest: live dashboards, KPIs, the ability to sit in a room and make a pricing or portfolio decision within an hour instead of the week or two it used to take pulling numbers manually. Governance, by contrast, is the pillar companies chronically underinvest in because the payoff isn't visible. "Unfortunately, there [is a case where] people don't see immediate value from it," he said of governance work like GDPR compliance, data lineage documentation, and defining critical data elements -- it reads as a regulatory box-tick rather than a business investment.
The catch, in his account, is that governance is exactly what determines whether an insurer's AI ambitions are realistic. "The moment anyone really wants to step up their game on data... without having a robust governance in place, without understanding your data lineage, understanding your critical data elements... you are actually in a bad space." For any regional insurer currently talking about machine learning or AI pilots while treating governance as a compliance afterthought, that's a direct warning: the sequencing matters, and skipping ahead to the exciting pillar without the boring one underneath it tends to produce models built on data nobody can actually vouch for.
A concrete example: not calling customers who already renewed
Asked for a tangible output of RSA's data work rather than an abstract capability, Skariah pointed to something almost mundane: understanding when different customer segments actually renew relative to their policy expiry date. Standard practice was to have the retention team call everyone at a fixed point before renewal -- say, 30 to 45 days out. What the data showed was that this timing varies meaningfully by demographic and by vehicle value: some segments renew well before that call would ever reach them, meaning the call centre was spending effort on customers who had, in effect, already made their decision.
It's not a dramatic finding, and that's precisely the point Skariah was making about data maturity: the value isn't necessarily in a sophisticated predictive model, it's in noticing something specific and structural about customer behaviour that a spreadsheet, run consistently and looked at regularly, will surface. "You actually find nuggets which you didn't expect," he said of the general pattern -- and a functioning dashboard culture, not a data science team, is what produces those nuggets on a recurring basis.
What COVID's traffic data actually showed
A second example carried more direct financial consequence. During pandemic lockdowns, RSA's data showed a sharp drop in accident frequency -- consistent with sharply reduced driving -- alongside a smaller but real spike in new car purchases among younger drivers, plausibly people who had previously relied on ride-hailing or car rental and now wanted their own vehicle instead. Overall new car sales dropped hard in that window even as this specific segment ticked up.
On the back of the frequency data, RSA's senior management chose to proactively credit customers a portion of their premium, reasoning that a customer who effectively didn't drive for months shouldn't be charged as if they had. Skariah drew a direct parallel to Admiral's much-publicised UK premium giveback around the same period -- a modest amount per customer (Admiral's was in the £25-50 range) that nonetheless generated real goodwill relative to its actual cost to the insurer. The regulatory postscript in the UAE, he noted, was that the market ultimately gave back considerably more -- 40-50% in places -- once regulation pushed the whole industry to respond, rather than leaving it to individual insurers' discretion.
The looming question data can't yet answer: who's liable in an autonomous car
Asked to look further out, Skariah didn't dodge the structural threat autonomous vehicles pose to motor insurance -- currently, by his account, the single largest non-health portfolio line in the region. His timeline estimate is seven to ten years before the shift becomes material, but the direction is not in question: as driving decisions shift from humans to onboard AI systems, the basic liability question -- who's at fault in an accident -- shifts with it, from the driver to potentially the vehicle manufacturer or the company that built the autonomous system's decision-making chip.
The upside is substantial and worth stating plainly: global road deaths currently run to roughly one to one-and-a-half million people a year, and autonomous driving at scale should meaningfully cut that number. The downside for insurers is that motor ticket sizes shrink as accidents and repairs decline, with the risk pool consolidating around fewer, larger counterparties -- manufacturers and AI providers -- rather than millions of individual drivers. Skariah's framing isn't alarmist, but it is direct: "We can be bracing for some of this to come through in the near future."
Segment-based pricing versus true pay-how-you-drive
On a nearer-term question -- whether telematics-style, individual pay-how-you-drive pricing (as used by Root in the US) will arrive in the region -- Skariah made a distinction worth sitting with. RSA already underwrites on driver behaviour, not just the vehicle, and has done so for seven to eight years, which he says has produced a meaningfully better book than the wider market. But that's still segment-based: individuals are grouped into behavioural buckets, however granular.
The real disruption threat, in his view, doesn't come from insurers refining their segments further -- it comes from technology companies that skip segmentation entirely and price directly off an individual's actual, current driving data, with no need for historic claims experience at all. "I can be an anomaly," he said. "I could be a much worse risk in a segment which is really good, and I'll get the benefit" under segment pricing -- a mispricing that individual telematics data would simply eliminate. That's the scenario behind his half-joking reference to "Google or Apple eating the insurance lunch": not a new insurer entering the market, but a data-rich technology company that never needed the region's historic actuarial tables in the first place.
What this means for the region
Skariah's own ranking -- regional insurers at level two while data-native insurtechs sit at level four -- is a useful, specific benchmark for any GCC insurer assessing its own data maturity rather than assuming digital transformation spend has closed the gap. His sequencing argument is the more actionable takeaway: governance and warehouse infrastructure have to precede any serious AI ambition, and an insurer skipping straight to machine learning pilots without that foundation is building on sand. For a region where motor remains the dominant non-health line and aggregator-driven price competition already keeps margins thin, the insurers that treat data governance as infrastructure rather than a compliance line item are the ones positioned to price -- and eventually personalise -- risk more accurately than a market still largely competing on discount alone.
This post draws on the FS Brew episode 08: Data is much more than the “new oil” for insurance. Conversation with Head of Data- RSA Insurance.