What lands on your desk on day 21.
This is a sample Blueprint readout for Saguaro Ridge Insurance Group, a fictional 42-person independent insurance agency. The firm, the people, and every number are made up to show the format. Your report follows the same structure, built from your firm's real findings.
Saguaro Ridge Insurance Group
The 21-Day Do More With Less Blueprint for Phoenix Insurance Agencies
Overall readiness. Staff use AI every day with no policy, and the renewal application overstates two controls. Both are fixable this quarter.
Readiness score by area.
Each area is scored from 0 to 100 against what an insurer or auditor would expect of a firm this size.
-
AI usage control31/100
At least 6 AI tools in use across 3 teams. No approved list, no policy, no data rules.
-
Data exposure48/100
Client files shared by public link from the file platform. 214 links open to anyone.
-
Identity and MFA62/100
Multi-factor authentication (MFA) on email for all staff. Not on the agency management system or the payroll portal.
-
Backup and recovery58/100
Nightly backups run. No restore has been tested in 14 months, and email is not backed up.
-
Insurance readiness44/100
Last renewal answered yes to two controls that are only partly in place.
Top findings, and what is already fixed.
Top findings
- Client data is going into personal AI accounts. Producers paste policy details and loss runs into free chatbot accounts to draft emails. Nothing stops it and nothing records it.
- The renewal application overstates MFA. It says MFA covers all remote access. The agency management system and the payroll portal sign in with a password only.
- 214 client files are shared by open link. Anyone with the link can open them, including former staff and outside adjusters.
- Email is not backed up. The backup covers the file server only. A deleted mailbox is gone after 30 days.
- Certificate requests take about 10 hours of staff time a week. About 60 certificate of insurance requests a week arrive by email and are keyed by hand.
Quick wins, done before the readout
- AI acceptable use policy signed by all 42 staffApproved tools listed. Client data stays out of personal accounts.
- Open file links switched to expire after 30 daysThe 214 existing links reviewed and closed by the IT provider.
- MFA turned on for the payroll portalA setting change, no cost. The agency system follows in month 1.
Risk map, ranked.
Likelihood and impact on a 1 to 5 scale. Every risk has an owner, so nothing sits in the gap between the agency and its IT provider.
| Risk | Likelihood | Impact | Rating | Owner |
|---|---|---|---|---|
| Client data entered into unapproved AI tools | 5 | 4 | High | Operations manager |
| Renewal answers that do not match controls | 4 | 5 | High | Agency principal |
| Account takeover on systems without MFA | 3 | 5 | High | IT provider |
| Email loss with no backup | 2 | 4 | Medium | IT provider |
| Open file links reaching former staff | 3 | 3 | Medium | Operations manager |
| New vendors added without a security review | 2 | 3 | Low | Agency principal |
12-month roadmap, excerpt.
In order, quarter by quarter. The agency's IT provider can carry most of it without us.
-
Quarter 1
Close the insurance gaps
- MFA on the agency management system
- Email backup added
- First restore test, written up
- Build the certificate request automation
-
Quarter 2
Set up AI properly
- One business AI tool approved and configured
- Data rules applied to the approved tool
- Staff training refresh
-
Quarter 3
Automate renewals prep
- Renewal reminder and document request automation
- Vendor security review for the two largest carriers' portals
-
Quarter 4
Prove it at renewal
- Evidence pack refreshed
- Incident tabletop exercise
- Rescore all five areas
First automation spec, excerpt.
Written so the agency's IT provider or RSG Logic can build it. The tool is chosen to fit what the agency already pays for.
Certificate of insurance request automation
- Problem
- About 60 certificate requests a week arrive by email. A customer service rep reads each one, finds the policy, fills the certificate, and replies. Roughly 10 hours a week.
- Trigger
- A new email arrives in the shared certificates mailbox.
- Steps
-
- Read the request and pull out the insured, the certificate holder, and any special wording.
- Look up the active policy in the agency management system, read only.
- Draft the certificate from the standard template.
- Send the draft to a rep for one-click approval. Nothing goes out unreviewed.
- On approval, email the certificate and log it to the client record.
- Data touched
- Insured name, policy numbers, coverage limits, certificate holder details. No payment or health data.
- Permissions
- Read access to the certificates mailbox and policy records only. Send rights limited to that mailbox. Its own service login, stored in the password vault and reviewed quarterly.
- Build options
- The workflow tool the agency already pays for (for example Power Automate or n8n), with an AI step for reading requests. Approved under the agency's AI policy.
- How to test
- Run 20 past requests in parallel with the manual process for one week. Compare every certificate before switching over.
- Expected result
- Illustrative estimate: rep time drops from about 10 hours to about 3 hours a week.
Cyber insurance evidence pack, excerpt.
The questions insurers commonly ask, the honest answer today, and the file that proves it. Next renewal starts from this, not from zero.
| Question | Answer today | Evidence on file |
|---|---|---|
| Is MFA required for all remote access to email? | Yes | E-03 sign-in policy screenshot, dated |
| Is MFA required for all other remote access? | Partial. Payroll yes, agency system in Quarter 1 | E-04 settings export, E-05 roadmap item |
| Are backups kept separate from the network and tested? | Separate yes. Restore test scheduled | E-07 backup report, E-08 test plan |
| Do you have a written incident response plan? | Draft, adopt in Quarter 1 | E-11 draft plan |
| Do employees receive security awareness training? | Partial. AI use training recorded; phishing and general security training not yet in place | E-12 AI training completion list, E-13 roadmap item |
| Do you have a policy for using AI tools? | Yes, signed by all staff | E-14 signed AI policy |
Sample Saguaro Ridge Insurance Group is fictional. Names, scores, counts, and estimates on this page are illustrative and describe no real client.
$4,500 up to 50 staff, $7,500 for 51 to 150
Want this for your firm? It takes 21 days.
Book a 30-minute call. If the Blueprint fits, your report follows this structure, built from your real findings.