Business

What You May Know About a Customer, and What You May Price On It

Your growth function and your risk function are working opposite ends of one mechanism. A framework for what an enterprise may infer, and what it may price on.

Kevin Jogin · 24 Aug 2026 · 11 min read

The binding constraint on customer intelligence is no longer what an enterprise can discover about a person. It is what the enterprise can defend having priced on.

Two papers reach the same executive committee within a quarter of each other. The situation is hypothetical; the pattern is not.

The first comes from growth. It proposes individualised risk pricing. Rather than scoring an applicant against a thin file of conventional credit or claims history, the business would draw on behavioural and relational signals — the ordinary digital residue of a life, and the connections visible around it — to build a profile for exactly the customers the existing process scores badly or declines by default. Sharper discrimination between risks produces sharper pricing; sharper pricing wins volume the incumbent method cannot reach. The commercial logic is coherent.

The second comes from risk. It concerns algorithmic fairness, and it describes how models built on historical and behavioural data reproduce, and can amplify, patterns of disadvantage that nobody in the organisation would sign as policy if the pattern were written down as one.

Both papers are approved. Neither references the other. They describe the same mechanism from opposite ends, and nobody in the room says so.

This is a governance failure with a specific shape. The upside of customer inference is owned by one function and the downside by another, and there is no forum in which the two positions must be reconciled before anything reaches a customer. Each paper is competent inside its own mandate. What the enterprise has never asked is the question that spans them.

The Strategic Context

For most of the history of commercial segmentation, the limiting factor was data. Knowing more about a buyer cost money, and customising an offer to that knowledge cost more. Both costs have fallen, and the second has fallen further than most leadership teams have absorbed. Where a business once chose between four or five treatable segments, it can now, in principle, treat every customer as a segment of one.

That shift moves the constraint. When knowledge was scarce, the strategic question was how to get more of it. When it is abundant, the question is which parts of it the enterprise is prepared to convert into a decision that affects someone — a price, a limit, a rank, a decline. Those are different questions with different owners, and most operating models have built machinery only for the first.

The financial consequence is that inference has quietly become a pricing input without ever having been governed as one. An organisation that would require three levels of approval to change a published rate card can find that a model has changed the rate for a cohort of customers, on the basis of variables no committee has seen listed.

Three Misreadings That Keep the Two Papers Apart

That legality settles the matter. Legal permission to hold data is not commercial permission to act on it, and neither is the same as the ability to explain the action afterwards. Australian privacy, credit reporting and anti-discrimination obligations set a floor that requires professional verification in every specific case [FACT CHECK REQUIRED]; ERANORTH is not a law firm and nothing here substitutes for advice. But the floor is not the decision. Enterprises routinely hold data they would be unwilling to see named publicly as the reason a customer was priced where they were.

That the risk function's objection will arrive in time. It usually arrives after deployment, because that is when the outcome becomes visible. By then the enterprise is not deciding whether to use the mechanism; it is deciding whether to withdraw one that already carries a book, a budget and a set of commitments.

That the mechanism is symmetric across the customer base. It is not. The stated commercial appeal is the ability to price people the conventional process cannot score — those with thin files, short histories, irregular income or no assets. Those are also the customers with the least capacity to challenge a decision, the least visibility of the basis for it, and the most to lose from a mistake. The population where the technique adds most measurable lift is the population where an error is most consequential. That is not a coincidence to be managed; it is the structure of the opportunity.

Reframing the Issue

The useful move is to stop treating this as one question and separate it into three, each with a different test and a different owner.

What may we collect? A question of lawful basis, stated purpose, proportionality and custody. Most enterprises have built real capability here, largely because regulators and auditors ask about it.

What may we infer? A question about derivation. An inferred attribute — likely income band, likely household composition, likely health status, likely association — is not in the record; the enterprise manufactured it. Very few organisations maintain a register of what they infer, as distinct from what they hold.

What may we act on? A question about consequence. Which inferences are permitted to move a price, a limit, an eligibility test or a queue position, and under what conditions.

Governance almost always stops at the first. The commercial value, and nearly all of the exposure, sits in the third. The collection question is itself an operating-model decision rather than a technical one, and it is treated at length elsewhere [Related article: Your Data Pipeline Is an Operating-Model Decision, Not an IT Project]. What concerns us here is the step after collection — the moment an inference becomes a decision about a person.

The Inference Is the Product

It helps to be precise about what is being sold internally. The value in a hyper-segmentation case is not the data; data of this kind is broadly available, and availability is rising for every competitor at once. The value is the inference — the claim that a pattern of behaviour and association predicts something the conventional file does not capture.

That has two consequences leadership teams routinely miss.

The first is competitive. An advantage built on a widely available input, processed by widely available methods, has a short half-life. If the case rests on being first to price a cohort more finely, assume the window is measured in product cycles and ask what remains once competitors match it. The honest answer is often that the business will have re-priced its book, absorbed the cost of doing so, and arrived at the same relative position.

The second is evidential. The model does not observe risk. It observes legibility — how much of a person's life happens to be recorded in the sources available. A customer whose activity is heavily documented is not a better risk, only a more visible one. Where the enterprise treats legibility as risk, it misprices the invisible systematically, and will not detect the error from its own portfolio performance, because the customers it declined never generate a data point.

Network Signals Price the Association, Not the Applicant

The proposal to draw on a person's connections deserves separate treatment, because it changes what is being priced.

A person's network is substantially inherited and heavily clustered — by geography, by family, by language, by workplace, by the schools and suburbs a life passed through. Pricing on it prices those clusters. The enterprise may believe it has built a personal risk profile; what it has built is a proxy for the composition of a neighbourhood, expressed one customer at a time.

This is the mechanism the fairness paper described, arriving from the other direction. It also explains why removing a protected attribute from the feature set achieves so little: the attribute is redundantly encoded across dozens of ordinary variables, and a model reconstructs it without difficulty. Whether an enterprise's assurance testing can detect that encoding is a separate and prior question, and the answer is usually no [Related article: Masking the Attribute Does Not Remove It].

Two implications follow for the executive. Testing that relies on masking will report comfort in exactly the case that warrants concern. And an argument that "the model does not use that attribute" is not a defence anyone outside the organisation is obliged to accept.

What the Growth Case Does Not Price

Growth cases in this domain are usually built on incremental margin and acquisition cost. Four costs are typically absent.

Reversibility. A pricing mechanism applied across a book is not easily unwound. Withdrawal means re-pricing live contracts, explaining the change to customers and distributors, and accounting for decisions already made. Estimate the cost of exit before entry.

Discovery burden. An automated decision leaves a specification, a training set and an approval record. When the decision is questioned, those artefacts are producible, and the question becomes what was known and approved rather than what went wrong on the day.

Revenue quality. Margin earned from a mechanism the enterprise would not describe publicly is fragile margin. It is worth asking directly whether this revenue would survive disclosure of its basis, and pricing it accordingly.

Custody. Holding richer customer data raises the consequence of losing it, which is a board-level risk-appetite question rather than a technical hygiene matter [Related article: The Padlock Is Not the Control].

Regulatory expectations in this area continue to move; any specific claim about their current state requires verification before it reaches a board paper [FACT CHECK REQUIRED]. Figures also circulate about disparate rejection rates in algorithmically assisted lending. Those we have seen carry no stated methodology or attribution, and should not enter an enterprise decision without first checking what the underlying analysis measured [FACT CHECK REQUIRED].

Decision Framework

The reconciliation the two papers lacked can be built as a single gate, applied before any inferred attribute is permitted to affect a customer outcome.

PermissionQuestion it answersTest to passEvidence requiredAccountable owner
CollectMay we hold this?Lawful basis, stated purpose, proportionality, custodyCollection notice, retention rule, security classificationData owner, with privacy counsel
InferMay we derive this?Would the derivation be defensible if described to the person it concerns?Register entry naming the inference, its inputs and its intended useModel owner, with risk
ActMay this move a price, limit or eligibility?Explicability, distributional review, reversibility, exit costCohort outcome analysis, decision record, withdrawal planNamed executive in the product mandate

Three thresholds make the gate operable. First, a stated list of attributes and inferences the enterprise will not price on regardless of predictive lift — the point of writing it down is that it survives the quarter in which the lift is largest. Second, a class permitted only with explicit consent and a plain statement of use. Third, everything else, treated as business as usual and reviewed on a cycle.

The decisive question at the gate is not whether the inference improves accuracy. It is whether the enterprise could state the basis of the decision to the customer, to a distribution partner and to a regulator, in the same words.

From Strategy to Execution

Immediately, establish what is already in force. Most enterprises cannot produce a list of the inferred attributes currently influencing a customer-facing decision. Producing that list is a week of work and it is usually the most informative week of the programme. Pair it with the assurance evidence held for each.

Over the medium term, build the forum the two papers never met in. It needs a single accountable executive, joint membership from growth and risk, a standing evidence requirement, and the authority to refuse. Attach the register of inferences to the change-control process that already governs pricing, so a model change that moves a price is treated as what it is: a pricing change.

For long-term positioning, treat explicability as a commercial asset rather than a compliance overhead. Disclosure expectations tend to ratchet in one direction. An enterprise that can already state and demonstrate the basis of its pricing retains freedom of action when others are re-engineering under pressure, and can enter distribution arrangements that require exactly that evidence.

Signals to Monitor

A widening gap between modelled and realised loss experience in cohorts scored on inferred data usually indicates the model is measuring visibility rather than risk. Decline rates and complaint patterns clustered by geography or channel are the early form of the problem. Pricing changes that reach customers without passing the control that governs rate changes indicate the gate is being bypassed. Externally, watch distribution partners adding evidentiary requirements to their agreements: commercial counterparties often move before regulators do, and their contracts bind faster. Treat any internal claim that a fairness question has been resolved technically as a prompt to read the test.

Questions for the Leadership Team

  1. Which inferred attributes currently influence a price, a limit or an eligibility decision in this business, and who approved each one?
  2. If a customer asked why they were priced as they were, what would we say — and would we say the same thing to a regulator?
  3. Where our model outperforms the conventional process, is it measuring risk or measuring how much of the customer's life is documented?
  4. What would it cost us, in money and in time, to withdraw this mechanism after it has been applied across the book?
  5. Which attributes have we decided we will not price on regardless of predictive lift, and is that list written down?
  6. Where growth and risk disagree on this question, who decides, and where is that decision recorded?

Closing Perspective

The two papers were not in conflict because one function was reckless and the other cautious. They were in conflict because the enterprise had never located the decision that belongs to neither of them. Growth cannot authorise the acceptance of a risk it does not carry. Risk cannot authorise the pursuit of a return it does not own. The judgement about what the organisation is prepared to know about a person, and what it is prepared to do with that knowledge, sits above both.

That judgement will be made either deliberately or by default. Made by default, it is made by whichever model shipped first, and the enterprise discovers its own position on the question at the point where it is most expensive to change. Made deliberately, it becomes something rarer than a control: a statement of what this business is, expressed in the one place customers actually experience it, which is the price they are asked to pay.


About the author
Kevin Jogin is Founder & Principal Advisor at EraNorth. Meet the Founder.