Detection vs Governance: What Insurers Are Actually Pricing
Much of the digital safety conversation is dominated by detection. Platforms point to moderation tools, automated alerts, and response protocols designed to identify harm once it occurs. These mechanisms are visible, auditable, and comparatively easy to evidence. They matter, ...
Emma Parfitt
Visible, auditable tools
Detection Dominates
Much of the digital safety conversation is dominated by detection. Platforms point to moderation tools, automated alerts, and response protocols designed to identify harm once it occurs. These mechanisms are visible, auditable, and comparatively easy to evidence. They matter, particularly in regulatory contexts.
But detection answers a different question to the one insurers ultimately care about.Detection tells us that harm is happening.
Governance determines whether harm was foreseeable, governable, and containable before it escalated into loss.
Why losses escalate
Exposure Compounds First
This distinction is familiar across other insured environments. A smoke alarm detects fire. Building codes, materials, and occupancy rules govern fire risk. The same pattern exists in fraud prevention: alerts tell you something’s wrong, but it’s the segregation of duties and access controls that actually shaped whether fraud was possible in the first place.
Digital environments have become highly sophisticated at detection. Less attention has been paid to how risk is governed before detection ever becomes necessary. As a result, many systems are designed to respond quickly to harm, but not to shape the conditions under which that harm develops.
From an underwriting perspective, this matters. Losses rarely arise because detection failed entirely. More often, harm is detected, escalated, and responded to, but only after exposure has already compounded. At that point, downstream controls are managing risk that has matured inside the system. The severity and cost of loss are already influenced by earlier design decisions.
This creates a recurring pattern. Platforms demonstrate strong detection capabilities and documented response processes. Insurers assess these visible controls and take comfort from their presence. Yet claims still emerge that feel sudden, severe, and difficult to predict. What appears as an unexpected loss is often the result of risk that was never governed upstream.
Entry, signals, thresholds
Governance Runs Upstream
Governance operates earlier than detection. It shapes who enters a system, how access is granted, how early signals are interpreted, and when escalation thresholds are crossed. It determines whether risk accumulates gradually or accelerates unchecked. Where governance is weak, deferred, or fragmented, detection inherits disproportionate pressure.
Consider a platform where a user under 16 bypasses age verification, exhibits grooming behaviour patterns over several days, and eventually causes harm to another minor. Detection catches the explicit content. But governance would have asked: how did entry verification work, what signals were visible in early interactions, and when should behavioural patterns have triggered escalation? By the time detection engages, the conditions for harm were already established.
This helps explain why detection-heavy environments can still produce unstable loss profiles. Detection improves awareness. It does not reduce exposure. Without effective governance, detection simply reveals harm that the system was already structured to allow.
Harder to evidence
The Visibility Gap
For insurers, the challenge is that governance is harder to see. Detection produces metrics, dashboards, and audit trails. Governance? It’s embedded in architecture, in decision-making frameworks, in escalation design that doesn’t show up neatly in due diligence questionnaires.
Predictability starts early
Price the Conditions
This is not an argument against detection. Nor is it a criticism of platforms operating at scale in complex environments. It is an observation about how risk is currently assessed. When insurers price digital risk primarily through the lens of detection and response, they are pricing outcomes rather than conditions.
Predictability does not improve at the point of detection. It improves earlier, where risk is governed.
As digital environments continue to grow in scale and complexity, the gap between visible controls and effective governance becomes more consequential. The question for insurers is no longer whether platforms can detect harm efficiently. It is whether underwriting frameworks are equipped to assess how risk is governed before harm occurs, and how that governance shapes frequency, severity, and loss trajectory.
Detection tells us when something has gone wrong.
Governance determines whether it had to.
Decide what the CTA should be
This is a CTA: Libran Global Safeguarding will sort your shit out and make you less shit at all this type of thing.
Become less shit
Emma Parfitt
Founder & Principal Consultant
Over a decade in social work and child protection. Founder of the Front Door Theory framework. Working with organisations to build safeguarding architecture that holds under pressure.
Related Architecture

They Didn't Look at It. Now a Jury Made Them.
Yesterday, a New Mexico jury ordered Meta to pay $375 million for misleading users about child safety...

Why Age Bans Alone Won't Keep Children Safe Online
The UK is considering banning under-16s from social media. Age restrictions address access, not architecture. Here's why bans alone won't solve the child safety problem.