Risk Management Information Systems: Why Your Loss Triangle Is Wrong and Your Actuary Already Suspects It
If you are self insured, carry more than roughly $3M of annual retained losses across several third party administrators, and your loss triangle is assembled in Excel from four differently shaped loss runs, a build pays for itself in one renewal. A focused first release covering claim feed ingestion and normalisation, reserve change tracking and a real loss triangle typically runs $70,000 to $150,000 and ships in 12 to 18 weeks in Digital Heroes delivery experience. A full risk management information system adding incident intake, certificate of insurance tracking, cost of risk allocation and location hierarchy runs $170,000 to $420,000, phased over 6 to 12 months. If you are fully insured with a guaranteed cost programme and one carrier, do not build. Ask your broker for their analytics and spend the money on safety.
Why the loss run is the most expensive spreadsheet in the company
It is six weeks before renewal. The actuary has asked for loss data valued as of last month, by line, by accident year, with paid and incurred split out. Your workers compensation administrator sends a fixed width text file. The general liability administrator sends an Excel workbook where the reserve column is formatted as text. The auto carrier sends a PDF. The captive sends nothing until you chase it. An analyst spends nine days rebuilding a triangle, and in that triangle three claims that were reserved at $40,000 in March are now at $310,000, and nobody in the risk department knew until the file was opened.
That is the whole problem in one paragraph. The tools around it are usually a spreadsheet stack, a broker portal you can read but not query, a certificate tracking service, and possibly Origami Risk, Riskonnect or Ventiv if the organisation bought a platform. Those three are real, capable systems and they run large risk programmes properly. What they charge dearly for, and what determines whether the implementation succeeds, is the part nobody demos: mapping every administrator's feed into your coverage structure, your location hierarchy and your cause of loss taxonomy, and keeping that mapping alive when an administrator changes their export next quarter.
The exposure is not the software cost, it is the funding decision. Reserve data drives your actuarial estimate, which drives your collateral, your accrual and your retention choice. Being wrong by a few hundred thousand on incurred but not reported losses moves real money and it moves it before you find out. In risk programmes we have worked on, the recurring pattern is the same: two to three weeks of analyst time per renewal spent on data assembly, adverse development discovered at valuation rather than when it happened, and no honest allocation of cost of risk back to the locations generating the claims, which means operations managers have no financial reason to care about safety.
Problem 1: every administrator sends a different loss run and the mapping lives in a person
Administrator A calls it Claimant State. Administrator B calls it Jurisdiction. Your captive calls it Sit. One sends incurred as paid plus reserve, another sends it net of recovery, a third includes allocated expense in incurred and a fourth reports it separately. Cause of loss codes are proprietary in every case. Reconciling all of that into one taxonomy is not data entry, it is a set of business rules, and right now those rules exist in one analyst's head and a workbook with hidden columns.
Packaged platforms will build these mappings for you and charge accordingly, then charge again when a feed changes. That is a defensible commercial model, but it means the most business-critical logic in your risk function sits behind a change request queue.
What a custom build does: a feed pipeline where each administrator has a declared schema, a mapping to your canonical claim model, and validation rules that reject a file rather than quietly loading garbage. Every load is versioned and reversible, so when an administrator reissues a corrected file you can see exactly what changed. Field mappings are configuration you can edit, not code someone else owns. The immediate payoff is that a monthly load stops being a person-week, and the durable payoff is that the mapping logic becomes an asset your organisation controls when you next put the administrator contract out to tender.
Problem 2: adverse development is found at valuation, months after it happened
A claim reserve moves from $40,000 to $310,000 because an adjuster received a medical report. That single change may be more significant to your programme than everything else that happened that month. Today you find out when the quarterly file lands, if anyone reads the detail, which they do not because there are eleven thousand rows.
What a custom build does: treat every load as an event stream and diff it against the prior valuation. Reserve movements above a threshold you set generate an alert to the named risk owner the day the file lands, with the claim narrative, the adjuster note if the feed carries it, and the history of prior movements. Large loss reviews become a standing list rather than an annual archaeology exercise. This is technically simple and organisationally transformative, because it converts your risk function from reporting on the past to intervening in claims that are still open.
Problem 3: certificates of insurance expire and nobody notices until there is a claim
A subcontractor's general liability policy lapsed in April. They are still on site in July. There is an injury, their carrier denies, and your programme absorbs a loss that a contract said you would never carry. The certificate was in an email folder and its expiry date was in nobody's calendar.
Tracking services exist and they are cheap, but they generally answer whether a certificate exists, not whether the certificate satisfies the specific insurance requirements in the specific contract that subcontractor signed. Additional insured wording, waiver of subrogation, primary and non-contributory language and required limits vary by contract type and by project, and the certificate form itself carries only a summary of coverage.
What a custom build does: the contract holds the insurance requirement set, the vendor record holds the certificates, and the system checks one against the other rather than just checking dates. Document extraction reads the certificate and pulls carrier, policy number, limits, effective and expiry dates, and the endorsement checkboxes, then flags where the evidence falls short of the requirement. Expiries escalate before the date, not after, and the escalation goes to the project manager who has a relationship with the vendor, not to a risk inbox. Confirm the legal sufficiency of wording with your counsel and broker, because a system can tell you a limit is short but it should never be your legal opinion.
Problem 4: cost of risk allocation depends on a hierarchy that changes every acquisition
You allocate premium, retained losses, administration fees and collateral cost back to divisions and locations, usually by a formula involving payroll, revenue, headcount and loss experience. Then you acquire eight sites, close two, and restructure into new regions. Every historical allocation is now against a hierarchy that no longer exists, so trend analysis by location silently breaks and the argument at the budget meeting becomes unwinnable.
What a custom build does: an effective-dated location hierarchy where a site can be reported under whichever structure was in force at the time, or restated under the current structure, on demand and without rewriting history. Allocation formulas are versioned so a prior year's charge can be reproduced exactly as it was issued. Public entity pools have the same requirement with member entities instead of divisions, and the same failure mode when a member joins or leaves mid-year. This sounds like an accounting nicety until an operating vice president disputes a six figure charge and you cannot reconstruct how it was calculated.
Problem 5: incident data never meets claim data, so prevention is guesswork
Operations records near misses, first aid cases and vehicle incidents in one place. The administrator records claims in another. The two never join, so you cannot answer whether the sites with high near miss reporting have lower claim frequency, which is the single most useful question in the entire discipline. Your OSHA 300 log is maintained separately again, usually by someone in HR (Human Resources), and recordability decisions are made without reference to how the claim actually developed.
What a custom build does: incident intake as a phone-friendly form supervisors will actually complete on the floor, with the incident becoming the parent record a claim later attaches to when the administrator reports it. Frequency and severity analysis then works at the level where prevention happens, which is a shift at a site, not a division in a report. Recordability determination and log generation sit on the same record rather than in a parallel workbook.
What this costs and how long it takes
Across the 2,000-plus projects Digital Heroes has delivered, this category has a fairly predictable shape. A focused first release covering claim feed ingestion and normalisation from your administrators, reserve change detection with alerting, and loss triangles and standard renewal reporting runs $70,000 to $150,000 and ships in 12 to 18 weeks. That is a system your analyst uses for the next renewal rather than a proof of concept. A full risk management information system adding incident intake, certificate and vendor compliance, cost of risk allocation with an effective-dated hierarchy, safety analytics and an actuarial data extract runs $170,000 to $420,000, phased over 6 to 12 months.
What drives cost up here: the number of distinct claim feeds, because each administrator is its own mapping project measured in weeks not days. International programmes, because currency, jurisdiction and coverage structures multiply the model. Historical conversion, because loading ten years of claims from legacy files to make triangles meaningful is a real workstream. And the taxonomy decisions, which need your risk manager in the room for more hours than they expect.
What keeps cost down: starting with your two largest lines and the two administrators that carry most of the exposure, and leaving certificates and incident intake to phase two. Loss data quality is where the money is.
Build versus buy, and when buying is right
Buy if you are fully insured under a guaranteed cost programme with a single carrier and modest retentions. Your broker's analytics will cover you and a build is a waste. Origami Risk, Riskonnect and Ventiv are also the right answer if you need broad functional coverage quickly, have the budget for a proper implementation, and your programme structure is fairly conventional. There is no shame in buying a good system.
Build when two or more of these are true. You receive claim data from three or more administrators or carriers with inconsistent layouts. Your allocation formula is contested internally and cannot be reproduced from records. You have an active captive or a group pool where members join and leave. Your incident data and your claim data will never be joined by a vendor because the vendor does not know your operations. Or you have already implemented a platform and find your team still rebuilding the same spreadsheet afterwards, which is the most common story we hear in this sector.
The real decision point is whether the ingestion and normalisation of your specific feeds is the value. If it is, that logic belongs to you, because it is the thing you will still need when you change platforms, administrators or brokers.
How to choose a developer for an RMIS build
Ask them to model a claim on a whiteboard. If they do not immediately separate the claim from its valuations over time, so that paid, reserve and incurred are point-in-time facts rather than fields on a row, they will build you a database that cannot produce a triangle. That is the single most common failure in this category and it is fatal.
Ask how they handle a corrected loss run. The answer must involve versioned loads and the ability to see what changed between valuations. Anyone who plans to overwrite the prior file has not understood what you are buying.
Ask what insurance data they have actually handled. Loss runs, ACORD certificate forms, IAIABC workers compensation reporting and actuarial extracts are all specific artefacts. Ask which administrators and which formats, and treat vague answers as a no.
Ask who owns the code, the cloud accounts and the historical claim data, in writing, before kickoff. At Digital Heroes the client owns all of it from the first commit. Your loss history is the asset that prices your programme for the next decade, and it should never sit somewhere you cannot extract it from in full, in a format your actuary accepts, on a day of your choosing.
The evidence behind this guide
Independent findings on why this investment pays off. Every link goes to the primary source.
- Only 22% of firms are 'future ready' having significantly transformed digitally; these companies show average revenue growth 17.3 percentage points and net margins 14.0 percentage points above their industry average. Source: MIT Center for Information Systems Research (MIT Sloan) (2022) →
- In a McKinsey global survey of 1,259 respondents, only about 20% said their organizations excel at decision making, and just 37% said their organizations' decisions were both high quality and high in velocity. Source: McKinsey & Company (2019) →
- McKinsey found that currently demonstrated technologies can fully automate about 42% of finance activities and mostly automate a further 19%, indicating roughly 60% of finance work is technically automatable. Source: McKinsey & Company (2018) →
- Only about 30% of digital transformations succeed at meeting their objectives, but getting six critical success factors in place (leadership commitment, talent, agile culture, progress monitoring, clear strategy, and a modernized platform) raises the odds of success from 30% to 80%. Source: Boston Consulting Group (BCG) (2020) →
Eliza is a brand designer at Digital Heroes, producing the identity work that sits around a product: logos, type, color systems and the guidelines that keep it all consistent once other people start applying it. Her posts are for readers who need brand and product to look like the same company.
View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.
Frequently asked questions
How much does a custom risk management information system cost?
Is Origami Risk or Riskonnect worth it, or should we build our own RMIS?
Can custom software normalise loss runs from several third party administrators?
How do we catch adverse reserve development before renewal?
Can a custom system track certificates of insurance against contract requirements?
How long does an RMIS build take before we can use it for a renewal?
How do we allocate cost of risk when our location hierarchy keeps changing?
Should incident reporting and claims live in the same system?
Who owns the claim data if we hire an agency to build our RMIS?
When does Looker make more sense than a custom dashboard?
Can one dashboard pull from QuickBooks, Salesforce, and Google Analytics at the same time?
How small can the first version of my software be and still be worth building?
Should I embed Power BI or Tableau in my SaaS product, or build custom charts?
Will a custom dashboard stay fast once our data hits millions of rows?
Can custom software connect to the tools we already use, like QuickBooks, Stripe, and Google Workspace?
How much does a custom BI dashboard cost for a small business?
How many people does it take to build a custom BI dashboard?
Will an app built for 10 users survive growing to 500?
How long does it take to build a custom web or mobile app from scratch?
Who can build a custom business intelligence dashboards system?
Digital Heroes builds custom business intelligence dashboards systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.
Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.
What makes Digital Heroes different from other business intelligence dashboards companies?
Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.
Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.
How can I check Digital Heroes is legitimate before getting in touch?
Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.
Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.