Health Check · Insurance

Salesforce health checks for insurance.

Carriers, MGAs and agencies use a health check to learn whether producer access, policyholder data and policy system links are as controlled as their auditors assume.

What health check looks like for insurance

For insurers, a health check tests the controls around policyholder and producer data and the reliability of the records service and distribution teams use every day. We review how agents and brokers access the org, what nonpublic personal information is stored and who can reach it, how policies and claims are synced from core systems, and whether licensing and appointment data is current. We also inventory automation and customization left by earlier projects. Findings are ranked by exposure to policyholders, producers and examiners, then by the operational drag they create for underwriting, service and sales.

Why it differs

Why insurance is different.

Insurance orgs serve people inside and outside the company at once. Independent agents, wholesalers and brokers log in through portals and expect to see their own book of business, and nothing else. Employees need access shaped by line of business, state and role. Policy and claims data usually arrives from core systems that were never designed for real-time sharing, so stale or partial records are common. Insurers also face market conduct exams and data security rules that expect them to explain who accessed what. Those pressures make access design and data lineage the central questions in any insurance review, ahead of layout or usability concerns.

Scope

What the work covers.

Producer portal visibility testing

We sign in as sample agency, wholesaler and broker users and record exactly which policies, quotes, commissions and policyholder details each can see. Sharing sets, account relationships and external roles are traced to explain any unexpected result. We also list portal users tied to terminated appointments or closed agencies, since those accounts are easy to miss and create avoidable exposure.

Nonpublic information inventory

Driver's license numbers, dates of birth, health details for life and disability lines and bank details for premium payments tend to appear in more places than intended. We locate those fields and free-text patterns, check encryption and field-level security and note which reports and exports can include them. The inventory gives your information security team a concrete starting point for remediation.

Licensing and appointment data check

Routing, lead assignment and portal access often depend on whether a producer is licensed and appointed in a given state. We compare how that data is stored and refreshed, look for expired licenses still marked active and check whether automation actually uses the data. Gaps here can send business to someone who should not handle it, which examiners notice. Producer hierarchy links to agencies are sampled too.

Legacy rollout debt review

Many insurers have been through more than one Salesforce program, sometimes with different partners for sales, service and distribution. We catalog duplicate objects for policies or producers, overlapping automation and custom code from those efforts, and identify which pieces still serve a purpose. The result shows what can be retired safely and what needs rework before the next initiative. Unused managed packages are listed alongside them.

Approach

How we run it.

We start with the Salesforce owner and information security, since access and data protection drive the highest-risk findings. Distribution, service and underwriting leads follow, along with a few agency users where possible. The review runs read-only and avoids renewal peaks and open enrollment. Anything that could indicate exposure of policyholder data is escalated to security straight away. The final report is written so it can be shared with internal audit, with each finding linked to the setting or record that supports it.

Policy administration system

We check sync frequency, which fields are copied versus referenced and whether policy status changes such as cancellation reach Salesforce quickly enough for service and producer views.

Claims system

We review what claim details are surfaced in Salesforce, who can see them and whether sensitive injury or medical information is restricted appropriately.

Producer licensing database

We confirm how license and appointment data is loaded, how often it refreshes and whether routing and access rules actually depend on it.

Plan for it

What to get right first.

01

Map GLBA-covered data

Insurers holding nonpublic personal information are generally subject to GLBA privacy and safeguards requirements, plus state insurance data security laws. The review documents where that information sits and how it is controlled, so compliance can assess obligations. Whether those obligations are met is a call for your compliance officer and counsel.

02

Limit what producers can export

Agents moving between agencies or carriers may try to take client lists with them. Review export permissions, report access and portal download options for external users, and make sure activity is logged well enough to investigate if a departing producer extracts data.

03

Ground AI in current policy data

An agent answering coverage or billing questions from stale policy records will give wrong answers with confidence. Before any AI pilot, confirm that policy status, endorsements and billing data sync reliably and that the agent cannot draw on claims or health details beyond its purpose.

FAQ

Health Check for insurance: questions.

Can a health check help us prepare for a market conduct exam?

It can help with the Salesforce side. The review shows how complaints, producer activity and policyholder communications are recorded, whether audit trails and field history are enabled on the right objects and whether records can be produced reliably. It does not replace exam preparation led by compliance, but it removes surprises about what your CRM can and cannot demonstrate.

We are an agency, not a carrier. Is the review different?

The emphasis shifts. Agencies usually care most about client and household records, carrier appointments, renewal tracking and producer ownership of accounts. We look at how producer departures are handled, whether commission and carrier data is reliable and how the agency management system connects. Carrier-specific items like complex portal models are reviewed only if they apply.

Do you review Financial Services Cloud configurations?

Yes. Many insurers run the insurance data model within Financial Services Cloud, sometimes alongside custom policy objects built earlier. We check whether standard and custom objects overlap, whether relationship and household rollups are accurate and whether managed package updates have been kept current. Mixed configurations are a common source of reporting disagreements that nobody can quite explain.

What if claims data is sensitive and should not be in Salesforce at all?

That is a fair question, and the review helps answer it. We show exactly which claim fields and files are present, who uses them and for what. Often service teams need only status and a handful of dates. Where more detail is stored than needed, we recommend reducing it or displaying it on demand from the claims system instead.

Planning health check for insurance? Let’s talk it through.

One onshore team with 150 Salesforce certifications, a Salesforce Consulting Partner since 2017.

Tech Talk

A monthly brief for the people who own Salesforce, AI and revenue technology

What changed in Salesforce and AI this month, and what to do about it.

One email a month. Written by the consultants who deliver the work, not by a marketing team, for the leaders who make the technology decisions.

  • What changed in Salesforce, AI, integration and RevOps, and what it means for your org
  • At least one framework, checklist or reference architecture you can take into a meeting
  • Honest opinions, including when we disagree with what a vendor is selling
  • No sales sequence. We do not sell from this list

Consultant analysis, not vendor recaps. One click to leave.

One email a month. Your industry and your address, nothing else. We never share either, and you can unsubscribe from the bottom of any issue. See what’s in Tech Talk →

Call (314) 916-4095 Book a consultation
Call (314) 916-4095 Book a call