# Annex IV Technical Documentation Template — Insurance Claims Triage (editable)

Not legal advice. This is an operational template designed to map each claim to evidence you can
export later.

Version: v1.0  
Last updated: 2025-12-16  
Changelog:
- 2025-12-16 v1.0 Initial release

Report an issue: https://kla.digital/contact?subject=Template%20issue%20-%20Annex%20IV%20Claims%20Triage

## Document control

- System name:
- Owner (function + name):
- Approvers (function + name):
- Scope / boundary (what is in-scope vs out-of-scope):
- Deployed regions and user groups:
- Versions in service (model/prompt/policy/workflow):
- Links (repo, runbooks, dashboards, risk register):

## One-page Annex IV summary (forwardable)

- Intended purpose:
- Decision(s) supported (triage, routing, fraud suspicion, severity scoring):
- Primary users and affected persons:
- Human oversight checkpoints:
- Data sources (top 5):
- Primary harms & mitigations (top 5):
- Monitoring signals & thresholds:
- Logging & retention policy:
- Evidence export location (manifest / bundle ID):

## 1) General description (Annex IV item 1)

### 1.1 Intended purpose + outcomes

- [ ] What decisions are influenced (routing, prioritization, investigation flags)?
- [ ] What is advisory vs automatic?
- [ ] What does “correct” look like for triage (service level + fairness + safety)?

### 1.2 Deployment context

- [ ] Where does it run and what systems does it touch (claims core, document store, payments)?
- [ ] Tool/action permissions and constraints
- [ ] Fallback modes

## 2) System elements & development process (Annex IV item 2)

### 2.1 Workflow components

- [ ] Input artifacts (claim form, notes, attachments, images)
- [ ] Extraction (OCR/NLP), validation, and normalization steps
- [ ] Model(s) used (classification, anomaly/fraud, severity estimation)
- [ ] Reviewer UI and queue behavior (what a human sees)

### 2.2 Data governance

- [ ] Sources + consent/permissions
- [ ] Handling of special category data (if applicable)
- [ ] Redaction rules for sensitive content
- [ ] Access controls and auditability

## 3) Monitoring, functioning, control (Annex IV item 3)

### 3.1 Capabilities + limitations

- [ ] Known failure modes (document quality, language, edge-case claim types)
- [ ] Bias/fairness concerns (routing delays, investigation burden)
- [ ] Safety and abuse prevention (claim manipulation)

### 3.2 Human oversight triggers

- [ ] Always-review conditions (high payout, vulnerable customers, safety issues)
- [ ] Sampled review conditions (medium-risk)
- [ ] Escalation ladder and SLAs

## 4) Performance metrics & thresholds (Annex IV item 4)

- [ ] Triage accuracy/precision/recall (by claim type)
- [ ] False positive cost (unnecessary investigations) vs false negative cost (missed fraud)
- [ ] Customer impact metrics (delay, complaint rate)
- [ ] Threshold governance (who changes what)

## 5) Risk management system (Annex IV item 5)

Link risk register:  

### 5.1 Typical claims triage harms (prompt list)

- [ ] Unfair delays or denial due to misrouting or misclassification
- [ ] Fraud flagging errors (false accusations or missed fraud)
- [ ] Sensitive data exposure in reviewer views or logs
- [ ] Overreliance on weak signals (document artifacts, proxies)
- [ ] Operational abuse (gaming claims)

### 5.2 Mitigations + verification evidence

- [ ] Mitigation implemented:
- [ ] Verification evidence (tests, sampling results, review outcomes):
- [ ] Residual risk acceptance record:

## 6) Lifecycle changes (Annex IV item 6)

- [ ] Material change definition
- [ ] Change approval process + evidence
- [ ] Versioning and rollback procedure

## 7) Standards / technical specs (Annex IV item 7)

- [ ] Standards used (if any)
- [ ] Internal controls mapped (policy-as-code references)

## 8) Declaration of conformity reference (Annex IV item 8)

- [ ] DoC location (internal reference)

## 9) Post-market monitoring plan reference (Annex IV item 9)

- [ ] Monitoring plan link:
- [ ] Sampling policy link:
- [ ] Incident response link:

## Evidence pointers

- [ ] Evidence pack manifest (bundle ID + checksums)
- [ ] Model/prompt/policy/workflow versions in effect per claim decision
- [ ] Oversight records (queue actions, overrides, escalations)
- [ ] Sampling outcomes + reviewer guidance
- [ ] Incident reports + corrective actions

