Risk Attribute

Level of Automation

Expert-reviewed Updated: 2026-09-03 Expert-reviewed: 2026-09-04 (Guido Hesse, Hesse Group Holding AG) Version 0.1.0

Level of automation records the degree to which a site's processes are controlled by manual labour, semi-automated equipment or fully automated and networked systems, which shapes both physical loss potential and cyber-physical exposure.

Category
Operations
Data type
Enumeration
Risk drivers
Severity, Frequency, Accumulation
Underwriting impact
Premium, Condition/Warranty, Exclusion

Typical proposal-form questions

  • Are the core production processes manual, semi-automated or fully automated?
  • Are automated systems and industrial control systems (ICS/SCADA) connected to the corporate IT network or the internet?
  • What manual fallback or override procedures exist if the automated system fails or is compromised?

Evidence

  • Process flow diagram
  • IT/OT network architecture diagram
  • Risk engineering survey report

Why it matters for underwriting

The level of automation shapes risk in two directions at once. Highly automated processes reduce human error and can improve consistency and quality, lowering some liability and property loss frequencies, but they also concentrate exposure into fewer, more complex control points: a single control system fault, sensor failure or malicious cyber intrusion can now halt an entire line that previously would have kept running under manual control. Underwriters need to understand where a site sits on the automation spectrum to judge both traditional property/business interruption severity and the extent to which cyber incidents can translate into physical loss.

Capturing the attribute and evidence

Proposal forms ask whether core processes are manual, semi-automated or fully automated, whether industrial control systems (ICS/SCADA) are connected to the corporate network or the internet, and what manual override or fallback capability exists if automation fails. Underwriters review process flow diagrams, IT/OT network architecture documentation, and, for higher-hazard or highly networked sites, a dedicated risk engineering survey covering both physical safeguards and cyber-physical segmentation.

Effect on coverage, premium and conditions

Automated sites with well-segmented, properly patched control systems and credible manual fallback procedures are generally viewed favourably for property risk, though highly networked, poorly segmented operational technology can trigger cyber policy conditions, sublimits for contingent business interruption arising from a cyber event, or exclusions requiring separate affirmative cyber cover. Sites lacking any manual fallback for critical automated processes may face conditions requiring redundancy or additional risk engineering recommendations before binding.

Mitigation measures

Insurers and risk engineers typically recommend network segmentation between IT and operational technology (OT), maintained manual override procedures for critical automated processes, regular patching and vulnerability management for control systems, and periodic testing of fallback procedures to confirm they remain workable in practice.

Standards and codes

  • ISO 31000:2018 – Risk management, Guidelines