Mr. Mathew George, Executive Director, United India Insurance Company Limited, on Risk, Leadership and the Lessons of Experience
Risk is often discussed through models, frameworks and probabilities. Experience offers a different perspective: what happens when uncertainty becomes real, decisions carry consequences and institutions are tested.
Few leaders have observed that intersection for as long as Mathew George, Executive Director, United India Insurance Company Limited. Across several decades in insurance and institutional leadership, he has witnessed an industry transformed by competition, technology and changing expectations while confronting questions of judgement, accountability and trust that remain remarkably constant.
In this wide-ranging conversation, he reflects on what a career spent understanding uncertainty has taught him about risk, leadership, resilience and the quality of decisions when there are no easy answers.
In conversation with Prashant Laxmeshwar, Founder, Risk Awareness
You have spent several decades in an industry whose fundamental business is understanding uncertainty. Looking back to when you first entered insurance, what drew you to the profession and how different was the industry you joined from the one you see today?
When I entered insurance, I do not think any of us could have anticipated quite how profoundly the industry would change.
What attracted me to the profession and increasingly fascinated me as my career progressed was that insurance sits at the intersection of economics, human behaviour and uncertainty. You are dealing with numbers, but behind every number there is an enterprise, an individual, an asset or a livelihood. You are making assessments about events that may never occur, while giving someone the confidence to continue investing, producing or simply living their life.
The industry I entered was very different. Processes were substantially manual. Information travelled slowly. The market was less segmented, technology played a very limited role and the competitive environment was altogether different.
Today we speak about analytics, algorithms, digital distribution, cyber risk, climate risk, parametric structures and artificial intelligence. Customers can compare products instantly and expect service almost immediately. The vocabulary of insurance has changed.
Yet the most interesting thing is how much has not changed. At its core, insurance remains a promise made today about an uncertain tomorrow.
Technology can improve how we price that promise, distribute it and fulfil it. Regulation can strengthen the framework around it. Competition can improve responsiveness. But the fundamental requirement remains trust.
After several decades in the profession, I would say that insurance has changed almost beyond recognition in its methods, while remaining remarkably constant in its purpose.
And perhaps that is why it has remained such an absorbing profession.
Your career has taken you through different responsibilities within the insurance ecosystem, including senior roles at Oriental Insurance, leading Health Insurance TPA of India as MD & CEO, and subsequently serving as Executive Director of United India Insurance. Which of these experiences most shaped the leader you eventually became?
I would find it difficult to isolate one assignment because leadership is usually formed cumulatively.
The early operating years teach you the business. You learn underwriting, claims, customers, intermediaries and, importantly, consequences. Decisions are not abstractions. A poorly understood exposure eventually becomes a claim.
Regional and senior operating responsibilities then teach you something else: businesses are ultimately run through people. You begin to understand that leadership is not merely knowing what should be done; it is creating the conditions in which hundreds or thousands of people can make sensible decisions when you are not present.
Leading Health Insurance TPA of India gave me another perspective because health insurance places service delivery very close to the human consequence of insurance. Processes, technology, hospitals, insurers and customers have to converge at precisely the moment when an individual may be under considerable stress. It reinforces the importance of execution and empathy.
And at Executive Director level, the perspective changes again. You are no longer considering individual decisions alone. You begin thinking in terms of the institution its capital, people, technology, customers, reputation and long-term resilience. Each stage removes a little certainty.
When we are younger, leadership can appear to be about having answers. With experience, you realise that the more senior the responsibility, the more frequently you are dealing with situations where several answers may be defensible.
Leadership then becomes the quality of the judgement with which you choose between them and the willingness to remain accountable for the choice.
You have witnessed Indian general insurance through liberalisation, the arrival of private-sector competition, digitisation and now AI. Which change has fundamentally altered the business of insurance the most and which has changed it less than people imagine?
Liberalisation fundamentally changed the industry because competition changes behaviour.
It compelled insurers to think much more sharply about customers, products, distribution, service standards, talent and efficiency. An industry that had previously operated within one kind of competitive structure had to learn to operate in another.
Competition is powerful because it makes comparison possible. Once customers experience different standards of service, the benchmark for everyone changes.
Digitisation has arguably been the second great transformation because it has compressed time. Activities that once required physical movement of documents and several interactions can increasingly happen in minutes. Data is much more accessible. Customers expect visibility. Claims can be tracked. Underwriting can draw on far more information.
AI could become another profound change, but the human element will never become obsolete. We have a tendency in every technological cycle to overestimate what technology changes immediately and underestimate what it changes over a decade.
AI will unquestionably improve pattern recognition, fraud detection, servicing, document analysis, pricing and many other functions. It may change the economics of several insurance processes.
What it will not eliminate is uncertainty. Insurance will become increasingly technological. But it will remain a business of judgement.
Insurance provides an unusual vantage point: you see organisations when risks materialise, not merely when they are being discussed in boardrooms. After decades of observing this, what do businesses repeatedly get wrong about risk?
The most common mistake is to confuse the absence of an event with the absence of risk.
If a factory has operated without a major fire for twenty years, people can unconsciously conclude that it is a safe factory. What the twenty years actually demonstrate is only that a major fire has not occurred during those twenty years.
That distinction sounds elementary, but it is fundamental. Human beings learn heavily from recent experience. If nothing has gone wrong for a long time, risk controls begin to appear expensive. Maintenance can be postponed. Redundancies look inefficient. Insurance limits are questioned. Contingency arrangements seem unnecessary. Then an event occurs and suddenly the value of everything that appeared excessive becomes obvious.
A second mistake is examining risks individually when modern businesses increasingly experience them as systems.
A cyber incident can become an operational disruption. An operational disruption can become a supply-chain problem. A supply-chain problem can become a contractual issue. A contractual issue can become a reputational one. The organisation may have excellent specialists responsible for each risk and still miss the relationship between them.
The third mistake is believing that risk management means eliminating risk.
No successful enterprise can do that. Business itself is an act of risk-taking. The purpose of risk management is to understand which risks you are taking, whether you can absorb the consequences, which risks should be reduced or transferred, and which risks are necessary to create value.
The dangerous risks are often not the dramatic ones discussed in presentations. They are the ordinary vulnerabilities that have gradually become normal.
As you moved into increasingly senior leadership positions, did your understanding of risk change when you became accountable for institutional decisions rather than simply evaluating or managing individual risks?
Very much so. At an operating level, risks often have relatively clear boundaries. You can examine a proposal, an underwriting exposure, a claim or an operational problem and attempt to make the best possible decision.
Institutional leadership is different because almost every significant decision creates more than one form of risk.
A conservative underwriting decision may protect the balance sheet but weaken market relevance. An aggressive growth decision may improve premium income but deteriorate portfolio quality. A large technology investment brings implementation risk, but delaying investment creates strategic risk. A process designed to prevent fraud may unintentionally make life difficult for genuine customers.
The question therefore changes from “What is the risk?” to “Which risks are we prepared to accept in pursuit of which outcomes?”
That is a far more demanding question. Senior leadership also teaches you that inaction is a decision with a risk profile of its own. Organisations sometimes believe that postponing a difficult decision preserves optionality. Often it merely allows the environment to make the decision for them. My understanding of risk consequently became less about avoidance and more about balance.
A leader must protect the institution, but also enable it to move. Excessive caution can become as damaging as excessive aggression if it prevents adaptation. The objective is not to build an institution in which nothing can go wrong. It is to build an institution capable of making considered decisions, absorbing setbacks, learning rapidly and continuing to move forward.
That, ultimately, is resilience.
Models, data and increasingly AI can quantify risks with extraordinary sophistication. Yet consequential decisions still ultimately require human judgement. What has experience taught you about making decisions when the data does not provide a clear answer?
One of the misconceptions about experience is that it gives you certainty. In fact, it often does the opposite.
Experience exposes you to enough exceptions to become suspicious of easy certainty.
Data is indispensable. Good leadership should never romanticise intuition at the expense of evidence. Models can identify relationships that an individual may never detect. Technology allows us to process information at a scale no human being can replicate.
But data has boundaries. A model can tell you what happened across thousands of comparable situations. It cannot always tell you whether the situation immediately before you are genuinely comparable. When information is incomplete, I think experience contributes three things. The first is pattern recognition. You recognise similarities with circumstances encountered before. The second is proportionality. Not every uncertainty warrants the same response. Experience helps distinguish the risks that can be corrected tomorrow from those where one wrong decision can have irreversible consequences. And the third is humility.
You learn to ask: What would have to be true for my judgement to be wrong? That is an extremely useful question because it forces you to test your own assumptions. Good judgement is therefore not instinct operating without evidence. It is evidence interpreted through context, experience and an appreciation of consequences. And when uncertainty cannot be eliminated, the quality of a decision often depends upon whether you have preserved sufficient room to recover if you are wrong.
Looking across Indian enterprise today, are you more concerned about the risks companies fail to recognise or the opportunities they fail to pursue because they have become too risk-averse?
Both concern me because they are ultimately manifestations of the same problem: misunderstanding risk. An organisation that fails to recognise emerging risk can become reckless.
An organisation that sees risk everywhere can become immobile. Neither is good risk management.
India today is in a period of considerable economic and technological opportunity. Enterprises are expanding internationally, adopting new technologies, creating digital business models and investing in infrastructure and manufacturing. It would be unfortunate if risk management became an argument for not participating in that opportunity.
The purpose of a good risk function should not be to stand outside the business explaining why something cannot be done. It should help the organisation determine how something worth doing can be done responsibly.
That requires a subtle change in mindset. The best risk professionals are not necessarily those who say “no” most frequently. Nor are they those who facilitate every proposal.
They are the people who can distinguish between a risk whose downside threatens the institution and one whose downside is manageable in relation to the opportunity. In many organisations, recognised risks actually receive considerable attention. The more dangerous ones can be the assumptions nobody has labelled as risks at all.
So, if I had to choose, I would remain particularly alert to risks organisations have normalised or simply failed to recognise. But I would never advocate caution as a philosophy.
The objective of understanding uncertainty is not to become frightened of the future. It is to participate in the future with greater confidence.
When you look at the next generation of insurance and risk professionals, what qualities will they need that perhaps mattered less when your own generation entered the industry?
Technical competence will remain fundamental, but it will no longer be sufficient. The next generation will need to be unusually comfortable working across disciplines. A risk professional may need to understand insurance, finance and regulation, but also technology, cybersecurity, climate, data, supply chains and increasingly artificial intelligence.
No individual will be an expert in all of these subjects. The important capability will therefore be knowing enough to ask the right questions and being sufficiently intellectually open to listen to people who know more.
They will also need the ability to translate.
One of the great weaknesses of specialist professions is that expertise can become inaccessible to the people who need it. The ability to explain a complex risk clearly to a chief executive, entrepreneur or customer is itself a leadership skill.
Ethical judgement will become even more important. As data becomes richer and technology becomes more powerful, organisations will increasingly be able to do things before society has necessarily decided whether they ought to do them. Privacy, algorithmic fairness and the appropriate use of customer information will not be peripheral issues.
And finally, I would emphasise curiosity. The shelf life of expertise is shortening. When I entered the industry, one could reasonably expect a body of accumulated professional knowledge to remain relevant for a long period. Today’s professionals will repeatedly have to relearn portions of their profession.
The most valuable person in the room may therefore not be the one who knows the most today. It may be the person most capable of learning tomorrow.
After spending a career studying what can go wrong, has experience made you more cautious about taking risks or more comfortable with them?
More comfortable but perhaps more discriminating. When we are younger, we can sometimes divide decisions too neatly into safe and risky. Experience teaches you that there is no risk-free position.
Remaining where you are carries risk. Changing carries risk. Investing carries risk. Not investing carries risk. Technology adoption carries risk; technological obsolescence does too. So the objective cannot be to avoid risk.
What experience gives you is a greater appreciation of asymmetry. There are risks where the potential upside is meaningful and the downside is recoverable. Those are often worth taking.
There are other risks where the upside may appear attractive, but the downside threatens something fundamental solvency, reputation, trust or institutional integrity. One should be much more cautious there.
I also think experience changes the emotional relationship with setbacks. You eventually realise that not every adverse outcome means the original decision was wrong. A well-considered decision can produce a bad outcome because uncertainty is real. Equally, a poor decision can occasionally produce an excellent outcome. Leadership requires the discipline not to confuse outcome with decision quality.
So I would not describe myself as more cautious after a career in risk. I would say I have become more respectful of consequences and less intimidated by uncertainty. Understanding risk should not reduce one’s appetite for action. It should improve the quality of the risks one chooses to take.
What is the one thing about risk that experience teaches you, but textbooks cannot?
That risk is rarely experienced in the neat categories in which we study it. Textbooks necessarily separate things. There is underwriting risk, operational risk, market risk, technology risk, liability risk, reputational risk and many others. Those classifications are useful because they allow us to understand complex subjects. Real life has no obligation to respect them. When something significant goes wrong, risks collide.
A technology problem becomes an operational problem. The operational problem affects customers. The customer problem becomes reputational. Reputation creates financial consequences. Suddenly a risk that belonged to one department belongs to the entire institution.
Experience also teaches you something more human. The true test of risk management begins after the event that was not supposed to happen has happened. At that moment, models matter, processes matter and insurance matters. But so do temperament, institutional memory, communication and the willingness of people to accept responsibility rather than search for someone to blame.
Perhaps the greatest lesson of my professional life is therefore that risk cannot be separated from judgement, and judgement cannot be separated from character.
You can teach frameworks. You can teach probability. You can teach underwriting principles and risk matrices. But experience teaches you how people and institutions behave when certainty disappears. That is where resilience is ultimately revealed.
And after spending a career in insurance, I would say this: the purpose of understanding risk is not to predict the future perfectly. It is to remain capable of acting wisely when the future refuses to behave as predicted.
