SECTOR GUIDANCE

Insurance Sector Guidance

GAISSF implementation guidance for AI systems and assurance programmes in the insurance sector.

ODA3 Institute™

GAISSF™ Insurance Sector Implementation Guide

SEC-039 | Version 1.0 | Controlled Pre-Release Draft for Peer Review

Operational guidance for secure, resilient, fair and evidence-based use of AI across insurance

FieldValue
Document IDSEC-039
Version1.0
Publication date30 June 2026
PublisherODA3 Institute
CategorySector Implementation Guide
Priority / Launch PhaseHigh / Phase 2
Publication licenceGEL v1.0
Publication channelsWebsite / GitHub
StatusControlled Pre-Release Draft for Peer Review - qualified legal/regulatory review and approval records remain open
Normative status SEC-039 is informative. It does not amend GAISSF, create independent certification requirements, or replace applicable law, regulation, actuarial judgement, contractual duties or policyholder protections.

Document hierarchy and precedence

  • Applicable law and binding regulatory or supervisory direction.
  • GAISSF-NOR-001 Framework Standard and other applicable GAISSF normative documents.
  • Approved GAISSF interpretations and assessment rules.
  • This informative sector guide.
  • Organisational policies and procedures.

Where requirements conflict, the organisation should record the conflict, obtain qualified advice, escalate through governance, and preserve the rationale. Unresolved interpretation must not be silently converted into a control conclusion.

Normative language

SHALL and SHALL NOT appear only when quoting or accurately restating verified GAISSF normative requirements. SHOULD indicates recommended sector practice; MAY indicates permission; CAN indicates capability or possibility. Conformity is determined against governing normative requirements, not this guide alone.

Executive summary

Insurance AI influences eligibility, price, coverage, claims, fraud investigation, reserving, catastrophe exposure, customer communication and operational resilience. The same model failure can therefore create policyholder harm, balance-sheet effects, conduct exposure and cyber loss. SEC-039 provides the operational layer between GAISSF controls and insurance practice.

  • Classify systems by decision authority, policyholder impact, financial consequence, reversibility, data sensitivity, scale and dependency concentration.
  • Treat model risk, cybersecurity, actuarial validation, conduct risk, privacy and operational resilience as one evidence system.
  • Retain accountability when models, data, platforms or decisions are outsourced.
  • Make human oversight timely, competent, informed and authorised; ceremonial review is not effective oversight.
  • Monitor outcomes, overrides, appeals, complaints, incidents, drift and vendor changes together.
  • Preserve decision traceability sufficient to reconstruct material outcomes and support challenge.

1. Introduction

This guide supports insurers, reinsurers, brokers, insurtechs, third-party administrators and material service providers applying GAISSF to insurance operations. It translates control objectives into sector interpretations, evidence and implementation patterns without creating new normative obligations.

1.1 How to use this guide

  • Start with the system inventory and classification.
  • Map applicable GAISSF controls using the verified 59-control register.
  • Select function-specific interpretations and evidence.
  • Record legal, actuarial and jurisdiction-specific obligations separately.
  • Use the workbook to assign owners, collect evidence and track remediation.
  • Retain open issues and Notably Absent statements with the assessment record.

2. Scope

Included organisations: life, health, property and casualty, general, commercial and specialty insurers; reinsurers; brokers and distributors; insurtech platforms; TPAs; claims, underwriting, data and analytics providers. Included systems span predictive, generative, computer-vision, graph, optimisation, rules-plus-model and agentic systems across acquisition, development, procurement, deployment, operation, change and retirement.

Excluded: legal or actuarial opinions; product approval; rate filing decisions; insurance coverage interpretation; certification conclusions; universal numerical thresholds; and jurisdiction-specific applicability determinations.

3. Insurance operating context

ActorPrimary accountabilityTypical AI dependencyKey evidence
InsurerPolicyholder outcomes, risk acceptance, claims, governance and complianceModels, SaaS, data, decision enginesInventory, approvals, validation, monitoring, incidents
ReinsurerPortfolio exposure, treaty analytics and risk transferCatastrophe and accumulation modelsModel/version records, assumptions, stress tests
Broker / agentAdvice, suitability, disclosure and submission qualityRecommendation and submission toolsTraining, approved content, conversation records
TPA / claims providerOperational claims handling within delegated authorityTriage, document, fraud and settlement toolsAuthority matrix, QA, logs, escalation
Insurtech / vendorService security, model operation and contractual evidenceHosted model/API/platformAssurance, change notices, incident and subprocessor records
Data providerData provenance, quality, rights and update integrityEnrichment, telematics, health, property and cyber dataLineage, contracts, quality and correction records

Insurance decisions may have long-tail consequences. Errors can remain latent until claims emerge, portfolios mature or catastrophe events expose correlated assumptions. Legacy systems and rules engines can also materially alter model outputs; assessment scope should include the complete decision chain.

4. Sector risk landscape

Risk domainDescriptionImpact pathwaysGAISSF domainsIndicative evidence
Underwriting and pricingUnstable or discriminatory risk classification, proxy effects, unapproved variables, model drift, historical-data bias and correlated portfolio errors.Coverage denial, unaffordable pricing, adverse selection, underpricing, complaints and remediation.D1, D6, D7, D8Model inventory; feature approval; actuarial validation; subgroup analysis; drift reports; override logs.
ClaimsIncorrect denial, suppression or prioritisation; fraud false positives; synthetic evidence; deepfakes; hallucinated summaries; automation bias.Delayed or denied benefits, leakage, litigation, vulnerable-customer harm and operational backlog.D1, D2, D5, D6, D7Decision trace; evidence integrity checks; manual-review criteria; appeal records; outcome monitoring.
Policyholder and consumer harmUnfair treatment, inadequate notice or explanation, inaccessible appeal, misleading communications and vulnerable-customer impacts.Financial exclusion, loss of trust, remediation, supervisory action and reputational damage.D5, D6, D7, D8Impact assessment; notices; explanation tests; accessibility review; complaint and appeal metrics.
DataWeak provenance, inaccurate broker data, sensitive health or financial data misuse, retention failures, proxy variables and training-data rights.Privacy harm, unreliable decisions, legal exposure, model contamination and rework.D1, D4, D6, D7, D8Data register; lineage; consent/purpose basis; quality controls; access logs; deletion evidence.
Cybersecurity and adversarialPrompt injection, poisoning, evasion, extraction, API abuse, credential compromise, insider misuse and vendor compromise.Fraud losses, data exfiltration, service disruption, manipulated decisions and IP loss.D1, D2, D3, D4Threat model; red-team results; IAM evidence; runtime telemetry; incident exercises; DLP records.
Model and decisionPoor specification, uncontrolled updates, non-reproducibility, overfitting, weak thresholds, rules/model interaction and unsupported overrides.Systematic pricing or claims errors, reserving distortion and audit failure.D1, D6, D8Independent validation; model cards; version control; approval record; threshold rationale; rollback test.
Third-party ecosystemOpaque vendor models, weak audit rights, subprocessor exposure, update risk, concentration and exit limitations.Correlated failures, service outage, lock-in, evidentiary gaps and regulatory access problems.D4, D6, D8Due diligence; contract clauses; audit reports; dependency map; exit test; concentration assessment.
Prudential and systemicCommon model/vendor concentration, tail-risk underestimation, catastrophe-model dependency, cyber accumulation and claims surge.Capital, reserving, liquidity, reinsurance dispute and sector-wide operational impacts.D4, D6, D8Scenario analysis; accumulation map; stress test; board risk appetite; contingency and reinsurance review.

4.1 Underwriting and pricing

Unstable or discriminatory risk classification, proxy effects, unapproved variables, model drift, historical-data bias and correlated portfolio errors. Affected functions should assess business, policyholder, security, compliance and prudential consequences separately. Typical impacts include coverage denial, unaffordable pricing, adverse selection, underpricing, complaints and remediation.

Control focus: D1, D6, D7, D8. Evidence: Model inventory; feature approval; actuarial validation; subgroup analysis; drift reports; override logs.

Limitations: risk likelihood and materiality are entity-, product-, portfolio- and jurisdiction-specific; examples are not exhaustive safe harbours.

4.2 Claims

Incorrect denial, suppression or prioritisation; fraud false positives; synthetic evidence; deepfakes; hallucinated summaries; automation bias. Affected functions should assess business, policyholder, security, compliance and prudential consequences separately. Typical impacts include delayed or denied benefits, leakage, litigation, vulnerable-customer harm and operational backlog.

Control focus: D1, D2, D5, D6, D7. Evidence: Decision trace; evidence integrity checks; manual-review criteria; appeal records; outcome monitoring.

Limitations: risk likelihood and materiality are entity-, product-, portfolio- and jurisdiction-specific; examples are not exhaustive safe harbours.

4.3 Policyholder and consumer harm

Unfair treatment, inadequate notice or explanation, inaccessible appeal, misleading communications and vulnerable-customer impacts. Affected functions should assess business, policyholder, security, compliance and prudential consequences separately. Typical impacts include financial exclusion, loss of trust, remediation, supervisory action and reputational damage.

Control focus: D5, D6, D7, D8. Evidence: Impact assessment; notices; explanation tests; accessibility review; complaint and appeal metrics.

Limitations: risk likelihood and materiality are entity-, product-, portfolio- and jurisdiction-specific; examples are not exhaustive safe harbours.

4.4 Data

Weak provenance, inaccurate broker data, sensitive health or financial data misuse, retention failures, proxy variables and training-data rights. Affected functions should assess business, policyholder, security, compliance and prudential consequences separately. Typical impacts include privacy harm, unreliable decisions, legal exposure, model contamination and rework.

Control focus: D1, D4, D6, D7, D8. Evidence: Data register; lineage; consent/purpose basis; quality controls; access logs; deletion evidence.

Limitations: risk likelihood and materiality are entity-, product-, portfolio- and jurisdiction-specific; examples are not exhaustive safe harbours.

4.5 Cybersecurity and adversarial

Prompt injection, poisoning, evasion, extraction, API abuse, credential compromise, insider misuse and vendor compromise. Affected functions should assess business, policyholder, security, compliance and prudential consequences separately. Typical impacts include fraud losses, data exfiltration, service disruption, manipulated decisions and ip loss.

Control focus: D1, D2, D3, D4. Evidence: Threat model; red-team results; IAM evidence; runtime telemetry; incident exercises; DLP records.

Limitations: risk likelihood and materiality are entity-, product-, portfolio- and jurisdiction-specific; examples are not exhaustive safe harbours.

4.6 Model and decision

Poor specification, uncontrolled updates, non-reproducibility, overfitting, weak thresholds, rules/model interaction and unsupported overrides. Affected functions should assess business, policyholder, security, compliance and prudential consequences separately. Typical impacts include systematic pricing or claims errors, reserving distortion and audit failure.

Control focus: D1, D6, D8. Evidence: Independent validation; model cards; version control; approval record; threshold rationale; rollback test.

Limitations: risk likelihood and materiality are entity-, product-, portfolio- and jurisdiction-specific; examples are not exhaustive safe harbours.

4.7 Third-party ecosystem

Opaque vendor models, weak audit rights, subprocessor exposure, update risk, concentration and exit limitations. Affected functions should assess business, policyholder, security, compliance and prudential consequences separately. Typical impacts include correlated failures, service outage, lock-in, evidentiary gaps and regulatory access problems.

Control focus: D4, D6, D8. Evidence: Due diligence; contract clauses; audit reports; dependency map; exit test; concentration assessment.

Limitations: risk likelihood and materiality are entity-, product-, portfolio- and jurisdiction-specific; examples are not exhaustive safe harbours.

4.8 Prudential and systemic

Common model/vendor concentration, tail-risk underestimation, catastrophe-model dependency, cyber accumulation and claims surge. Affected functions should assess business, policyholder, security, compliance and prudential consequences separately. Typical impacts include capital, reserving, liquidity, reinsurance dispute and sector-wide operational impacts.

Control focus: D4, D6, D8. Evidence: Scenario analysis; accumulation map; stress test; board risk appetite; contingency and reinsurance review.

Limitations: risk likelihood and materiality are entity-, product-, portfolio- and jurisdiction-specific; examples are not exhaustive safe harbours.

5. Insurance AI system classification

ClassDecision / impact profileExamplesMinimum governance response
Low-impact assistiveNo direct adverse decision; reversible; low sensitivityDrafting internal text or summarising non-sensitive materialStandard access, logging, output review and acceptable-use controls.
Material operationalSupports important workflow or material volumesClaims document classification; broker submission extractionFormal owner, validation, monitoring, fallback and change control.
High-impact policyholder decisionInfluences eligibility, price, coverage, claim or adverse actionLife underwriting score; claim denial recommendationIndependent validation, fairness testing, meaningful human review, explanation and appeal.
Prudentially significantCan materially affect reserves, capital, accumulation or reinsuranceCatastrophe aggregation or reserving supportActuarial and risk validation, stress testing, concentration analysis and board oversight.
Critical claims or underwritingFailure creates immediate large-scale customer or operational harmAutomated claims triage during catastrophe eventResilience, manual fallback, surge testing, incident playbook and executive escalation.

Classification is an implementation aid. It does not replace GAISSF applicability rules or any legal definition of high-risk AI. Escalate classification where one factor is extreme even if other factors are moderate.

6. Control interpretation by insurance function

FunctionAI useKey risksGAISSF domainImplementationEvidenceHuman oversightNotably absent
UnderwritingRisk selection and coverage recommendationProxy discrimination, drift, manipulation, weak explainabilityD1, D6, D7Feature governance, actuarial validation, adverse-decision reviewModel validation, feature register, override logMandatory for adverse or borderline outcomesNo safe-harbour assumption that model approval establishes lawfulness, actuarial adequacy or rate-filing compliance in every jurisdiction.
PricingPremium or discount recommendationUnapproved variables, unfair differentiation, optimisation instabilityD1, D6, D7, D8Rate governance, subgroup and stability tests, filing alignmentPricing test pack, approval, monitoringRequired for material exceptions and adverse outcomesNo assumption that predictive accuracy establishes actuarial fairness, filing acceptability or absence of proxy discrimination.
ClaimsTriage, estimation, settlement or denial supportDeepfakes, false negatives, hallucinations, automation biasD1, D2, D5, D7Evidence integrity, confidence thresholds, escalation and appealsDecision trace, image checks, review recordMandatory for denial, vulnerability and high valueNo assumption that a fraud flag proves fraud, or that automated triage may deny, suppress or delay a claim without effective review and contestability.
Fraud detectionFraud score or investigation prioritisationFalse positives, evasion, bias, feedback loopsD1, D2, D7Adaptive testing, investigator review, outcome feedback controlsPrecision/recall, subgroup results, case outcomesInvestigator confirmation before adverse actionNo safe-harbour assumption; legal and actuarial applicability remains separate.
ReservingReserve estimation supportTail error, regime shift, opaque assumptionsD1, D6, D8Actuarial ownership, scenario testing, reconciliationValidation report, assumptions, back-testingActuarial sign-offNo assumption that model validation removes tail, accumulation, capital, accounting or reinsurance risk.
Catastrophe modellingExposure and loss estimationVendor concentration, climate shift, tail underestimationD1, D4, D6, D8Model plurality, version governance, stress and dependency analysisVendor evidence, model-change assessment, stress resultsExpert review for material capital/reinsurance useNo assumption that model validation removes tail, accumulation, capital, accounting or reinsurance risk.
Policy administrationData extraction and workflow automationRecord corruption, unauthorised changes, privacy leakageD2, D3, D6Transaction controls, segregation, reconciliation, rollbackAudit trail, access record, reconciliationApproval for policy-changing actionsNo safe-harbour assumption; legal and actuarial applicability remains separate.
Distribution and intermediary supportAgent recommendations and sales supportMis-selling, unsuitable recommendations, prompt leakageD3, D5, D7Approved knowledge, suitability checks, constrained toolsConversation logs, content tests, complaint dataHuman agent accountability retainedNo safe-harbour assumption; legal and actuarial applicability remains separate.
Customer serviceChatbot or virtual assistantHallucinated coverage, misleading advice, accessibility failureD2, D5, D7Grounding, disclaimers, escalation, transcript retentionEvaluation set, escalation metrics, transcriptsHuman handoff for disputes and material decisionsNo safe-harbour assumption; legal and actuarial applicability remains separate.
ReinsurancePortfolio analytics and treaty supportData mismatch, concentration, reporting errorD1, D4, D6, D8Data reconciliation, dependency mapping, expert validationReconciliation, model inventory, approvalSpecialist review for treaty/capital decisionsNo safe-harbour assumption; legal and actuarial applicability remains separate.
Cyber-insuranceSecurity posture scoring and accumulation analysisGaming, stale signals, correlated vendor riskD1, D4, D6, D8Signal provenance, adversarial testing, accumulation scenariosData lineage, red-team, scenario reportUnderwriter reviewNo safe-harbour assumption; legal and actuarial applicability remains separate.
Health and life insuranceMortality, morbidity or care-related decision supportSensitive data, proxy discrimination, irreversible harmD1, D6, D7, D8Strict data governance, clinical/actuarial input, contestabilityDPIA, fairness analysis, review recordMandatory qualified human reviewNo safe-harbour assumption; legal and actuarial applicability remains separate.
Telematics and IoTBehaviour-based risk and loss preventionSensor spoofing, surveillance, physical safetyD1, D2, D7, D9Device security, consent, calibration, fallbackDevice inventory, security tests, consent recordsReview where data materially changes price/coverageNo safe-harbour assumption; legal and actuarial applicability remains separate.
Generative AIDrafting, summarisation, retrieval and agentic workflowPrompt injection, hallucination, leakage, unsafe toolsD2, D3, D5RAG controls, tool allowlists, output validation, DLPPrompt tests, retrieval logs, red-team resultsRequired for external or decision-relevant outputNo provider assurance treated as a substitute for insurer testing, output controls, traceability and human accountability.
Internal corporate useProductivity and analysisConfidentiality leakage, shadow AI, inaccurate work productD2, D4, D6Approved tools, data classification, usage logging, trainingAcceptable-use records, DLP, inventoryReviewer accountable for work productNo safe-harbour assumption; legal and actuarial applicability remains separate.

7. Governance and accountability

Accountability remains with the insurance entity and accountable business owner. Outsourcing changes evidence sources, not accountability. Governance should integrate board risk appetite, executive ownership, actuarial and model validation, CISO controls, compliance/conduct review, privacy, procurement, resilience and internal audit.

DecisionAccountableConsulted / responsibleEscalation
System approvalBusiness ownerAI governance, CISO, model risk, complianceBoard/committee for material systems
Risk classificationAI governanceBusiness, model risk, legal, actuarialCRO
Data approvalData ownerPrivacy, security, actuarial/model riskAI governance
Model validationIndependent validation / actuarialCISO, business ownerCRO / validation committee
Security testingCISOEngineering, vendor, red teamAI governance
Deployment approvalBusiness ownerCISO, model risk, compliance, operationsExecutive committee for critical systems
MonitoringSystem ownerModel risk, claims/underwriting, securityCRO
Incident escalationIncident commanderLegal, compliance, business, privacyExecutive / board by severity
Customer notificationCompliance / legalClaims or product ownerAccountable executive
Model retirementSystem ownerRecords, vendor, security, business continuityAI governance

8. Human oversight

Meaningful oversight exists only where the reviewer acts before harm becomes irreversible, has relevant competence and contextual information, can disagree without penalty, can access source evidence, and has authority and time to intervene. A nominal approval click, post-event sampling or blind reliance on a confidence score is ceremonial oversight.

TriggerOversight modelReviewerRequired record
Coverage denial or material exclusionHuman-in-commandQualified underwriter / claims decision-makerSources, model output, rationale, alternative considered, approval
High-value or vulnerable claimantMandatory manual reviewSenior claims professionalVulnerability and escalation record
Fraud flag causing adverse actionHuman-in-the-loopTrained investigatorEvidence reviewed, disposition, feedback label
Medical/health-related decisionQualified human reviewAppropriate clinical/actuarial/claims professionalCompetence, sources, rationale, appeal route
Agentic action affecting policy/claimDual approval or constrained authorityBusiness owner and control functionTool calls, authority, approvals, rollback

9. Data governance

The data register should identify source, owner, legal basis or permitted purpose, provenance, sensitivity, quality controls, known limitations, protected-characteristic or proxy risk, update frequency, retention and downstream use. Broker-submitted and third-party enrichment data require correction and challenge mechanisms.

Data IDSourceUseSensitivityProvenance / rightsQuality controlsProxy riskRetentionOwner
DATA-001Policy administration systemUnderwriting historyConfidential personalInternal authoritative recordCompleteness and reconciliationGeography and occupationPer records scheduleData owner
DATA-002Telematics providerBehaviour-based pricingLocation / behaviouralContract and device lineageCalibration, freshness, spoofing checksSocioeconomic and disabilityPurpose-limitedProduct owner

10. Security architecture

Reference architecture: identity-aware channels feed an API gateway and policy enforcement layer; input validation, malware/media integrity and prompt-injection controls precede model or decision services; retrieval is isolated by tenant, purpose and access; tools are allowlisted with least privilege and transaction limits; outputs pass confidence, policy, safety and data-loss checks; material decisions are recorded with model, prompt, data, rule, reviewer and outcome identifiers; telemetry feeds security, model-risk and business-outcome monitoring; tested manual fallback supports critical operations.

  • Separate development, validation and production environments.
  • Protect model registries, prompts, retrieval corpora, rules, thresholds and secrets as controlled assets.
  • Use strong identity, privileged-access management, segmentation, encryption, key management, API security and immutable logging.
  • Test backup, rollback, provider outage, manual fallback and catastrophe surge procedures.
  • Detect unauthorised AI use and prevent sensitive data exfiltration through DLP and approved-tool controls.

11. Model validation and testing

Test familyInsurance focusEvidence
Independent validationFitness for use, assumptions, data, reproducibility and limitationsValidation report and issue closure
Actuarial validationRate, reserve, mortality, morbidity, severity or frequency relevanceActuarial review and sign-off
Security / adversarialPoisoning, evasion, extraction, prompt injection, abuse and tool misuseThreat model, test cases and remediation
Fairness / outcomeSubgroups, proxies, adverse outcomes and vulnerable customersDefined metrics, rationale, limitations and actions
Stress / scenarioRegime shift, catastrophe surge, vendor outage and tail eventsScenario design, results and decision record
Operational acceptanceLatency, capacity, integration, rollback and manual fallbackUAT, resilience and fallback test

Universal numerical thresholds are intentionally absent. Thresholds should be justified against use, harm severity, legal requirements, portfolio characteristics, baseline performance and escalation capacity.

12. Monitoring and change management

Metric / changeFrequencyOwnerEscalation approach
Performance and calibrationRisk-based; at least per approved monitoring planModel ownerDeviation from approved tolerance or unexplained trend
Fairness and adverse outcomesAligned to decision volume and harmCompliance / model riskMaterial subgroup disparity or deterioration
Overrides, appeals and complaintsMonthly or more frequently for high-impact usesBusiness ownerConcentration, reversal trend or vulnerable-customer signal
Security events and abuseContinuous where technically feasibleCISOConfirmed compromise, injection, exfiltration or privilege misuse
Vendor/model updateBefore acceptance and after material changeVendor ownerUnassessed change, regression or evidence gap
Data/feature changeBefore productionData/model ownerLineage, rights, quality or proxy-risk change

13. Incident management

SeverityPolicyholder / financial impactExamplesEscalationEvidence preservation
S1 CriticalWidespread or severe harm; material financial/prudential impactSystemic denial/pricing error, major breach, critical claims outageImmediate executive, legal, regulator-assessment and board escalationFreeze versions, logs, data, rules, prompts, communications and decisions
S2 HighMaterial cohort or product impactDiscriminatory outcome, vendor compromise, material claim errorIncident command and senior control functionsPreserve decision and vendor evidence
S3 ModerateLimited reversible impactLocal drift, contained data exposure, repeat hallucinationOwner and control-function remediationRetain samples, root cause and closure
S4 LowNo material external impactNear miss or minor control deviationNormal issue managementDocument lesson and control update

Notification timeframes are jurisdiction-specific and intentionally not stated as universal rules. The legal/regulatory assessment should identify applicable clocks and triggering facts.

14. Third-party and supply-chain management

  • Assess provider security, model documentation, data rights, validation, subcontractors, incident history, resilience, geographic processing and regulatory access before contract.
  • Contract for change notice, audit/access rights, incident notification, evidence retention, secure deletion, continuity, portability, exit support and material subprocessor control.
  • Map fourth parties and concentration across cloud, foundation models, catastrophe models, data and claims services.
  • Test exit and fallback; a contractual right without operational feasibility is weak evidence.

15. Policyholder transparency, explanation and contestability

Notices and explanations should match the decision, audience and harm. They should identify the material basis of the outcome, meaningful factors, applicable limitations, correction and appeal routes, and whether qualified human review is available. Trade-secret or security constraints may limit technical detail but do not remove the need for a meaningful, lawful explanation.

16. Assurance and evidence catalogue

EvidenceCategoryPurposeOwnerSourceRetentionControl linkageReliabilityCommon deficiency
Approved AI policy, risk appetite and committee decisionsGovernanceDemonstrate design and operating effectivenessBoard / CROAuthoritative system or signed recordRisk-based; preserve applicable legal holdRelevant mapped controlsApprover authority, approval date, challenge record and exception completeness.Generic policy without system-level operating evidence
System classification and impact assessmentRiskDemonstrate design and operating effectivenessAI governanceAuthoritative system or signed recordRisk-based; preserve applicable legal holdRelevant mapped controlsPrefer T1 operating evidence; corroborate with T2 independent review and T3 simulation. T4 evidence is supplementary only.Generic policy without system-level operating evidence
Lineage, rights, quality and proxy analysisDataDemonstrate design and operating effectivenessData ownerAuthoritative system or signed recordRisk-based; preserve applicable legal holdRelevant mapped controlsSource quality, rights, lineage completeness, validation status and operating period.Generic policy without system-level operating evidence
Model card, validation, limitations and version historyModelDemonstrate design and operating effectivenessModel riskAuthoritative system or signed recordRisk-based; preserve applicable legal holdRelevant mapped controlsValidation independence, test coverage, version linkage and documented limitations.Generic policy without system-level operating evidence
Threat model, tests, IAM and runtime telemetrySecurityDemonstrate design and operating effectivenessCISOAuthoritative system or signed recordRisk-based; preserve applicable legal holdRelevant mapped controlsTesting currency, scope, independence and linkage to the production configuration.Generic policy without system-level operating evidence
Approval, release, configuration and rollback evidenceDeploymentDemonstrate design and operating effectivenessSystem ownerAuthoritative system or signed recordRisk-based; preserve applicable legal holdRelevant mapped controlsPrefer T1 operating evidence; corroborate with T2 independent review and T3 simulation. T4 evidence is supplementary only.Generic policy without system-level operating evidence
Performance, outcomes, drift, complaints and overridesMonitoringDemonstrate design and operating effectivenessBusiness / model ownerAuthoritative system or signed recordRisk-based; preserve applicable legal holdRelevant mapped controlsPrefer T1 operating evidence; corroborate with T2 independent review and T3 simulation. T4 evidence is supplementary only.Generic policy without system-level operating evidence
Timeline, containment, impact, notification and lessonsIncidentDemonstrate design and operating effectivenessIncident commanderAuthoritative system or signed recordRisk-based; preserve applicable legal holdRelevant mapped controlsCompleteness, timeliness, preserved evidence, root cause and remediation closure.Generic policy without system-level operating evidence
Due diligence, contract, assurance and change recordsVendorDemonstrate design and operating effectivenessThird-party riskAuthoritative system or signed recordRisk-based; preserve applicable legal holdRelevant mapped controlsPrefer T1 operating evidence; corroborate with T2 independent review and T3 simulation. T4 evidence is supplementary only.Generic policy without system-level operating evidence
Reviewer competence, intervention and override recordsOversightDemonstrate design and operating effectivenessBusiness ownerAuthoritative system or signed recordRisk-based; preserve applicable legal holdRelevant mapped controlsReviewer competence, timing, authority and record completeness.Generic policy without system-level operating evidence
Notices, explanations, appeals and accessibility testsPolicyholderDemonstrate design and operating effectivenessComplianceAuthoritative system or signed recordRisk-based; preserve applicable legal holdRelevant mapped controlsPrefer T1 operating evidence; corroborate with T2 independent review and T3 simulation. T4 evidence is supplementary only.Generic policy without system-level operating evidence
Testing, findings, remediation and limitationsAuditDemonstrate design and operating effectivenessInternal auditAuthoritative system or signed recordRisk-based; preserve applicable legal holdRelevant mapped controlsPrefer T1 operating evidence; corroborate with T2 independent review and T3 simulation. T4 evidence is supplementary only.Generic policy without system-level operating evidence

17. Insurance implementation profiles

ProfileOperating modelPriority controlsConstraints
Large composite insurerMultiple lines, jurisdictions and legacy platformsPortfolio inventory, federated governance, concentration and shared-service controlsFragmented ownership and evidence
Life insurerLong-duration products and sensitive mortality/health dataUnderwriting fairness, actuarial validation, long-tail drift and contestabilitySparse outcomes and legacy assumptions
Property and casualty insurerHigh-volume claims, images, catastrophe and telematicsClaims integrity, surge resilience, computer vision and accumulationCatastrophe regime shift and vendor concentration
Health insurerSensitive data and high-impact benefit decisionsPurpose limitation, qualified review, fairness, explanation and appealClinical context and jurisdictional complexity
ReinsurerPortfolio aggregation, catastrophe and treaty analyticsModel plurality, concentration, assumptions and stress testingOpaque cedant data and common-model dependency
Insurtech / digital insurerCloud-native, vendor-heavy and rapid changeSecure SDLC, third-party controls, monitoring and evidence automationResource constraints and dependency lock-in

18. Practical implementation roadmap

PhaseIndicative timeframeObjectiveActivitiesExit evidence
Phase 00-30 daysMobilisation and scopeSponsor, owner, boundaries, sources, approval gatesCharter and scoped plan
Phase 130-60 daysInventory and classificationSystems, models, data, vendors, decision authority and impactApproved inventory and tiers
Phase 260-100 daysRisk and control mappingMap 59 controls, obligations, evidence and gapsStatement of applicability and gap register
Phase 3100-180 daysRemediation and governanceImplement priority technical, process and contractual controlsClosed critical gaps and operating evidence
Phase 4180-240 daysValidation and assuranceIndependent validation, red team, fairness, resilience and auditAssurance report with limitations
Phase 5OngoingOperational monitoringOutcomes, drift, incidents, complaints, vendor and change monitoringDashboards and issue records
Phase 66-12 monthsContinuous improvementThematic review, concentration, lessons and maturityImprovement plan and readiness decision

19. Worked scenarios

19.1 AI-assisted life insurance underwriting

ElementImplementation interpretation
ContextApplicant data, medical and financial indicators support risk classification.
Threats and failure modesProxy discrimination; sensitive-data misuse; drift; opaque adverse decisions.
Control interpretationIndependent actuarial/model validation; restricted features; subgroup testing; meaningful underwriter review; explanation and appeal evidence.
Required evidenceSystem classification; data lineage; threat model; validation; approval; monitoring; oversight and incident records proportionate to risk.
MonitoringPerformance, outcomes, overrides, complaints, incidents, vendor/model changes and drift.
Incident triggersMaterial decision error, security compromise, unexplained disparity, loss of traceability, vendor change or failure of manual fallback.
Residual risksData limitations, regime shift, human error, unknown attacks and jurisdiction-specific obligations remain.
Notably absentNo assumption that model approval establishes lawfulness or actuarial adequacy in every jurisdiction.

19.2 Automated motor claims triage

ElementImplementation interpretation
ContextImages and claim data prioritise cases and estimate complexity.
Threats and failure modesAdversarial images; deepfakes; misclassification; catastrophe surge failure.
Control interpretationMedia integrity checks; confidence thresholds; surge testing; high-value/vulnerable escalation; manual fallback.
Required evidenceSystem classification; data lineage; threat model; validation; approval; monitoring; oversight and incident records proportionate to risk.
MonitoringPerformance, outcomes, overrides, complaints, incidents, vendor/model changes and drift.
Incident triggersMaterial decision error, security compromise, unexplained disparity, loss of traceability, vendor change or failure of manual fallback.
Residual risksData limitations, regime shift, human error, unknown attacks and jurisdiction-specific obligations remain.
Notably absentNo autonomous denial based solely on triage output.

19.3 Fraud detection using network analytics

ElementImplementation interpretation
ContextGraph analytics identify suspicious claimant, provider or broker relationships.
Threats and failure modesFalse positives; feedback loops; evasion; group bias.
Control interpretationInvestigator confirmation; outcome feedback; precision/recall and subgroup monitoring; feature provenance.
Required evidenceSystem classification; data lineage; threat model; validation; approval; monitoring; oversight and incident records proportionate to risk.
MonitoringPerformance, outcomes, overrides, complaints, incidents, vendor/model changes and drift.
Incident triggersMaterial decision error, security compromise, unexplained disparity, loss of traceability, vendor change or failure of manual fallback.
Residual risksData limitations, regime shift, human error, unknown attacks and jurisdiction-specific obligations remain.
Notably absentA fraud flag is not proof of fraud.

19.4 Property damage assessment using computer vision

ElementImplementation interpretation
ContextImages estimate damage severity or repair scope.
Threats and failure modesImage manipulation; poor generalisation; geographic bias; hidden damage.
Control interpretationCapture controls; tamper detection; uncertainty reporting; adjuster review for material settlements.
Required evidenceSystem classification; data lineage; threat model; validation; approval; monitoring; oversight and incident records proportionate to risk.
MonitoringPerformance, outcomes, overrides, complaints, incidents, vendor/model changes and drift.
Incident triggersMaterial decision error, security compromise, unexplained disparity, loss of traceability, vendor change or failure of manual fallback.
Residual risksData limitations, regime shift, human error, unknown attacks and jurisdiction-specific obligations remain.
Notably absentNo claim that image-only assessment is universally sufficient.

19.5 Health insurance decision support

ElementImplementation interpretation
ContextAI supports benefit, risk or utilisation decisions.
Threats and failure modesSensitive health data; discrimination; clinical context loss; irreversible harm.
Control interpretationStrict purpose limitation; qualified human review; explanation; appeal; clinical and actuarial validation.
Required evidenceSystem classification; data lineage; threat model; validation; approval; monitoring; oversight and incident records proportionate to risk.
MonitoringPerformance, outcomes, overrides, complaints, incidents, vendor/model changes and drift.
Incident triggersMaterial decision error, security compromise, unexplained disparity, loss of traceability, vendor change or failure of manual fallback.
Residual risksData limitations, regime shift, human error, unknown attacks and jurisdiction-specific obligations remain.
Notably absentNo medical advice or clinical approval is provided by this guide.

19.6 Dynamic or behaviour-based pricing

ElementImplementation interpretation
ContextTelematics or behavioural signals influence premium.
Threats and failure modesSurveillance, consent limits, sensor spoofing, unfair differentiation.
Control interpretationSignal provenance; device security; proxy analysis; customer notice; correction process.
Required evidenceSystem classification; data lineage; threat model; validation; approval; monitoring; oversight and incident records proportionate to risk.
MonitoringPerformance, outcomes, overrides, complaints, incidents, vendor/model changes and drift.
Incident triggersMaterial decision error, security compromise, unexplained disparity, loss of traceability, vendor change or failure of manual fallback.
Residual risksData limitations, regime shift, human error, unknown attacks and jurisdiction-specific obligations remain.
Notably absentNo endorsement of legality or fairness of any variable.

19.7 Generative AI claims assistant

ElementImplementation interpretation
ContextLLM summarises evidence and drafts communications.
Threats and failure modesHallucination; prompt injection; confidential-data leakage; misleading coverage statements.
Control interpretationGrounded retrieval; citation to source records; prohibited-action controls; human approval; transcript logging.
Required evidenceSystem classification; data lineage; threat model; validation; approval; monitoring; oversight and incident records proportionate to risk.
MonitoringPerformance, outcomes, overrides, complaints, incidents, vendor/model changes and drift.
Incident triggersMaterial decision error, security compromise, unexplained disparity, loss of traceability, vendor change or failure of manual fallback.
Residual risksData limitations, regime shift, human error, unknown attacks and jurisdiction-specific obligations remain.
Notably absentNo direct claim denial or binding coverage interpretation without qualified review.

19.8 Cyber-insurance risk scoring

ElementImplementation interpretation
ContextExternal security telemetry and questionnaires support underwriting.
Threats and failure modesGaming; stale data; concentration; weak causal assumptions.
Control interpretationSource assurance; freshness controls; adversarial testing; underwriter override; portfolio accumulation analysis.
Required evidenceSystem classification; data lineage; threat model; validation; approval; monitoring; oversight and incident records proportionate to risk.
MonitoringPerformance, outcomes, overrides, complaints, incidents, vendor/model changes and drift.
Incident triggersMaterial decision error, security compromise, unexplained disparity, loss of traceability, vendor change or failure of manual fallback.
Residual risksData limitations, regime shift, human error, unknown attacks and jurisdiction-specific obligations remain.
Notably absentNo representation that a score predicts breach with certainty.

19.9 Catastrophe modelling dependency

ElementImplementation interpretation
ContextVendor models inform aggregation, reinsurance and capital decisions.
Threats and failure modesVendor concentration; model change; tail underestimation; correlated market use.
Control interpretationMulti-model challenge; change impact; stress/scenario testing; exit and continuity plan.
Required evidenceSystem classification; data lineage; threat model; validation; approval; monitoring; oversight and incident records proportionate to risk.
MonitoringPerformance, outcomes, overrides, complaints, incidents, vendor/model changes and drift.
Incident triggersMaterial decision error, security compromise, unexplained disparity, loss of traceability, vendor change or failure of manual fallback.
Residual risksData limitations, regime shift, human error, unknown attacks and jurisdiction-specific obligations remain.
Notably absentNo assumption that vendor validation transfers accountability.

19.10 Third-party foundation model in customer service

ElementImplementation interpretation
ContextExternal model answers policyholder questions using approved knowledge.
Threats and failure modesProvider update; retention; prompt injection; hallucinated coverage; outage.
Control interpretationContract controls; version monitoring; RAG isolation; evaluation; escalation; fallback.
Required evidenceSystem classification; data lineage; threat model; validation; approval; monitoring; oversight and incident records proportionate to risk.
MonitoringPerformance, outcomes, overrides, complaints, incidents, vendor/model changes and drift.
Incident triggersMaterial decision error, security compromise, unexplained disparity, loss of traceability, vendor change or failure of manual fallback.
Residual risksData limitations, regime shift, human error, unknown attacks and jurisdiction-specific obligations remain.
Notably absentNo provider assurance treated as substitute for insurer testing.

20. Verified GAISSF control mapping

Control IDControl titleInsurance interpretationFunctionsExample implementationEvidenceOwnerAssessmentCaveatNotably absent
D1-CTL-01DATASET PROVENANCE & POISONING PREVENTIONProtect insurance data, models, features and validation against poisoning, extraction, drift and adversarial manipulation.Underwriting; pricing; claims; fraud; reserving; catastrophe modellingApply dataset provenance & poisoning prevention to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Data lineage, source contracts, feature approvals and poisoning controls; [T2] independent actuarial/MRM validation; [T3] contaminated-data and proxy-variable tests.Chief Actuary / Head of Model RiskTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D1-CTL-02MODEL EXTRACTION RESISTANCEProtect insurance data, models, features and validation against poisoning, extraction, drift and adversarial manipulation.Underwriting; pricing; claims; fraud; reserving; catastrophe modellingApply model extraction resistance to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] API telemetry, rate limits and access logs; [T2] penetration-test report; [T3] model-extraction simulation.Chief Actuary / Head of Model RiskTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D1-CTL-03BEHAVIORAL DRIFT DETECTIONProtect insurance data, models, features and validation against poisoning, extraction, drift and adversarial manipulation.Underwriting; pricing; claims; fraud; reserving; catastrophe modellingApply behavioral drift detection to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Automated drift/outcome logs and alerts; [T2] MRM or actuarial review; [T3] out-of-distribution and catastrophe-regime stress tests.Chief Actuary / Head of Model RiskTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D1-CTL-04FEDERATED LEARNING POISONING PREVENTIONProtect insurance data, models, features and validation against poisoning, extraction, drift and adversarial manipulation.Underwriting; pricing; claims; fraud; reserving; catastrophe modellingApply federated learning poisoning prevention to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Versioned model/data records and monitoring logs; [T2] independent MRM/Appointed Actuary validation; [T3] adversarial, stress and challenger-model tests.Chief Actuary / Head of Model RiskTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D1-CTL-05EMBEDDING SPACE ROBUSTNESSProtect insurance data, models, features and validation against poisoning, extraction, drift and adversarial manipulation.Underwriting; pricing; claims; fraud; reserving; catastrophe modellingApply embedding space robustness to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Versioned model/data records and monitoring logs; [T2] independent MRM/Appointed Actuary validation; [T3] adversarial, stress and challenger-model tests.Chief Actuary / Head of Model RiskTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D1-CTL-06POST-QUANTUM MODEL SIGNING & CRYPTO HARDENINGProtect insurance data, models, features and validation against poisoning, extraction, drift and adversarial manipulation.Underwriting; pricing; claims; fraud; reserving; catastrophe modellingApply post-quantum model signing & crypto hardening to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Versioned model/data records and monitoring logs; [T2] independent MRM/Appointed Actuary validation; [T3] adversarial, stress and challenger-model tests.Chief Actuary / Head of Model RiskTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D1-CTL-07LORA/ADAPTER INTEGRITY VERIFICATIONProtect insurance data, models, features and validation against poisoning, extraction, drift and adversarial manipulation.Underwriting; pricing; claims; fraud; reserving; catastrophe modellingApply lora/adapter integrity verification to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Versioned model/data records and monitoring logs; [T2] independent MRM/Appointed Actuary validation; [T3] adversarial, stress and challenger-model tests.Chief Actuary / Head of Model RiskTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D1-CTL-08MODEL MERGE ATTACK DETECTIONProtect insurance data, models, features and validation against poisoning, extraction, drift and adversarial manipulation.Underwriting; pricing; claims; fraud; reserving; catastrophe modellingApply model merge attack detection to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Versioned model/data records and monitoring logs; [T2] independent MRM/Appointed Actuary validation; [T3] adversarial, stress and challenger-model tests.Chief Actuary / Head of Model RiskTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D1-CTL-09QUANTIZATION BACKDOOR SCREENINGProtect insurance data, models, features and validation against poisoning, extraction, drift and adversarial manipulation.Underwriting; pricing; claims; fraud; reserving; catastrophe modellingApply quantization backdoor screening to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Versioned model/data records and monitoring logs; [T2] independent MRM/Appointed Actuary validation; [T3] adversarial, stress and challenger-model tests.Chief Actuary / Head of Model RiskTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D2-CTL-01DIRECT PROMPT INJECTION PREVENTIONSecure production inference, APIs, prompts, retrieval, identities, logging, monitoring and runtime containment.Claims platforms; customer portals; APIs; GenAI assistants; decision enginesApply direct prompt injection prevention to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Input/output policy logs, tool-call traces and blocked-attempt telemetry; [T2] security review; [T3] direct, indirect and cross-agent injection tests.CISO / Security OperationsTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D2-CTL-02INDIRECT PROMPT INJECTION PREVENTIONSecure production inference, APIs, prompts, retrieval, identities, logging, monitoring and runtime containment.Claims platforms; customer portals; APIs; GenAI assistants; decision enginesApply indirect prompt injection prevention to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Input/output policy logs, tool-call traces and blocked-attempt telemetry; [T2] security review; [T3] direct, indirect and cross-agent injection tests.CISO / Security OperationsTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D2-CTL-03JAILBREAK RESISTANCE TESTINGSecure production inference, APIs, prompts, retrieval, identities, logging, monitoring and runtime containment.Claims platforms; customer portals; APIs; GenAI assistants; decision enginesApply jailbreak resistance testing to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] IAM, runtime, API and security telemetry; [T2] control-effectiveness review; [T3] attack, abuse and failover exercises.CISO / Security OperationsTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D2-CTL-04MULTI-MODAL INJECTION DEFENSESecure production inference, APIs, prompts, retrieval, identities, logging, monitoring and runtime containment.Claims platforms; customer portals; APIs; GenAI assistants; decision enginesApply multi-modal injection defense to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] IAM, runtime, API and security telemetry; [T2] control-effectiveness review; [T3] attack, abuse and failover exercises.CISO / Security OperationsTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D2-CTL-05FUNCTION CALL/TOOL CALL INJECTION PREVENTIONSecure production inference, APIs, prompts, retrieval, identities, logging, monitoring and runtime containment.Claims platforms; customer portals; APIs; GenAI assistants; decision enginesApply function call/tool call injection prevention to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Agent identity, delegation, tool-call and transaction logs; [T2] accountable-owner approval; [T3] loop, privilege and agent-to-agent authentication tests.CISO / Security OperationsTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D2-CTL-06CROSS-CONTEXT HIJACKING MITIGATIONSecure production inference, APIs, prompts, retrieval, identities, logging, monitoring and runtime containment.Claims platforms; customer portals; APIs; GenAI assistants; decision enginesApply cross-context hijacking mitigation to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] IAM, runtime, API and security telemetry; [T2] control-effectiveness review; [T3] attack, abuse and failover exercises.CISO / Security OperationsTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D3-CTL-01LEAST AGENCY ENFORCEMENTConstrain delegated authority, tools, transactions and autonomous actions in claims, underwriting and customer operations.Agentic claims; workflow automation; broker support; autonomous triageApply least agency enforcement to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Control configuration, operating logs and approvals; [T2] independent review; [T3] controlled simulation/red-team evidence; [T4] vendor or industry claims only as supplementary context.AI Governance / Business OwnerTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D3-CTL-02INTER-AGENT COMMUNICATION SECURITYConstrain delegated authority, tools, transactions and autonomous actions in claims, underwriting and customer operations.Agentic claims; workflow automation; broker support; autonomous triageApply inter-agent communication security to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Agent identity, delegation, tool-call and transaction logs; [T2] accountable-owner approval; [T3] loop, privilege and agent-to-agent authentication tests.AI Governance / Business OwnerTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D3-CTL-03AGENTIC PROMPT CHAINING DETECTIONConstrain delegated authority, tools, transactions and autonomous actions in claims, underwriting and customer operations.Agentic claims; workflow automation; broker support; autonomous triageApply agentic prompt chaining detection to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Agent identity, delegation, tool-call and transaction logs; [T2] accountable-owner approval; [T3] loop, privilege and agent-to-agent authentication tests.AI Governance / Business OwnerTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D3-CTL-04EMBODIED AI SAFETY CONTROLSConstrain delegated authority, tools, transactions and autonomous actions in claims, underwriting and customer operations.Agentic claims; workflow automation; broker support; autonomous triageApply embodied ai safety controls to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Control configuration, operating logs and approvals; [T2] independent review; [T3] controlled simulation/red-team evidence; [T4] vendor or industry claims only as supplementary context.AI Governance / Business OwnerTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D3-CTL-05MULTI-AGENT TRUST CHAIN ATTESTATIONConstrain delegated authority, tools, transactions and autonomous actions in claims, underwriting and customer operations.Agentic claims; workflow automation; broker support; autonomous triageApply multi-agent trust chain attestation to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Agent identity, delegation, tool-call and transaction logs; [T2] accountable-owner approval; [T3] loop, privilege and agent-to-agent authentication tests.AI Governance / Business OwnerTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D3-CTL-06PERSISTENT MEMORY EXFILTRATION PREVENTIONConstrain delegated authority, tools, transactions and autonomous actions in claims, underwriting and customer operations.Agentic claims; workflow automation; broker support; autonomous triageApply persistent memory exfiltration prevention to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Control configuration, operating logs and approvals; [T2] independent review; [T3] controlled simulation/red-team evidence; [T4] vendor or industry claims only as supplementary context.AI Governance / Business OwnerTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D3-CTL-07SECURE MEMORY LIFECYCLE MANAGEMENTConstrain delegated authority, tools, transactions and autonomous actions in claims, underwriting and customer operations.Agentic claims; workflow automation; broker support; autonomous triageApply secure memory lifecycle management to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Control configuration, operating logs and approvals; [T2] independent review; [T3] controlled simulation/red-team evidence; [T4] vendor or industry claims only as supplementary context.AI Governance / Business OwnerTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D4-CTL-01AI BILL OF MATERIALS (AI BOM) MAINTENANCEGovern insurtech, cloud, data-broker, catastrophe-model, foundation-model and fourth-party dependencies.All outsourced models, data, SaaS, cloud, TPA and reinsurer analyticsApply ai bill of materials (ai bom) maintenance to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Due diligence, AI/SBOM, dependency map, contracts and incident/change notices; [T2] independent vendor assurance; [T3] exit, outage and concentration tests.Head of Third-Party Risk / ProcurementTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D4-CTL-02MODEL FILE & ARTIFACT SCANNINGGovern insurtech, cloud, data-broker, catastrophe-model, foundation-model and fourth-party dependencies.All outsourced models, data, SaaS, cloud, TPA and reinsurer analyticsApply model file & artifact scanning to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Control configuration, operating logs and approvals; [T2] independent review; [T3] controlled simulation/red-team evidence; [T4] vendor or industry claims only as supplementary context.Head of Third-Party Risk / ProcurementTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D4-CTL-03MODEL HUB & REGISTRY VETTINGGovern insurtech, cloud, data-broker, catastrophe-model, foundation-model and fourth-party dependencies.All outsourced models, data, SaaS, cloud, TPA and reinsurer analyticsApply model hub & registry vetting to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Control configuration, operating logs and approvals; [T2] independent review; [T3] controlled simulation/red-team evidence; [T4] vendor or industry claims only as supplementary context.Head of Third-Party Risk / ProcurementTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D4-CTL-04MCP SERVER BEHAVIORAL MONITORINGGovern insurtech, cloud, data-broker, catastrophe-model, foundation-model and fourth-party dependencies.All outsourced models, data, SaaS, cloud, TPA and reinsurer analyticsApply mcp server behavioral monitoring to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Control configuration, operating logs and approvals; [T2] independent review; [T3] controlled simulation/red-team evidence; [T4] vendor or industry claims only as supplementary context.Head of Third-Party Risk / ProcurementTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D4-CTL-05THIRD-PARTY AI API SECURITY ASSESSMENTGovern insurtech, cloud, data-broker, catastrophe-model, foundation-model and fourth-party dependencies.All outsourced models, data, SaaS, cloud, TPA and reinsurer analyticsApply third-party ai api security assessment to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Due diligence, AI/SBOM, dependency map, contracts and incident/change notices; [T2] independent vendor assurance; [T3] exit, outage and concentration tests.Head of Third-Party Risk / ProcurementTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D4-CTL-06SHADOW AI DISCOVERY & GOVERNANCEGovern insurtech, cloud, data-broker, catastrophe-model, foundation-model and fourth-party dependencies.All outsourced models, data, SaaS, cloud, TPA and reinsurer analyticsApply shadow ai discovery & governance to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Control configuration, operating logs and approvals; [T2] independent review; [T3] controlled simulation/red-team evidence; [T4] vendor or industry claims only as supplementary context.Head of Third-Party Risk / ProcurementTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D4-CTL-07AI SOFTWARE COMPOSITION ANALYSIS (SCA)Govern insurtech, cloud, data-broker, catastrophe-model, foundation-model and fourth-party dependencies.All outsourced models, data, SaaS, cloud, TPA and reinsurer analyticsApply ai software composition analysis (sca) to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Due diligence, AI/SBOM, dependency map, contracts and incident/change notices; [T2] independent vendor assurance; [T3] exit, outage and concentration tests.Head of Third-Party Risk / ProcurementTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D5-CTL-01HARMFUL CONTENT BLOCKINGBlock, constrain and escalate hallucinated, misleading, unsafe or unauthorised outputs in policyholder communications, claims summaries, underwriting support and agent-facing content.Customer communications; claim summaries; policy documents; recommendationsApply harmful content blocking to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Output-policy configuration, blocked-output logs and complaint/correction records; [T2] conduct review; [T3] hallucination and harmful-content tests.Conduct / Privacy / Legal / CISO, according to controlTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D5-CTL-02PII LEAKAGE PREVENTIONPrevent leakage of medical records, government identifiers, financial identifiers, claims data and telemetry through prompts, retrieval, generated outputs, logs and model-provider interfaces; apply redaction and output inspection before disclosure.Customer communications; claim summaries; policy documents; recommendationsApply pii leakage prevention to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] DLP/redaction configuration, leakage alerts and disclosure logs; [T2] DPIA/privacy review; [T3] prompt, retrieval and output exfiltration tests.Conduct / Privacy / Legal / CISO, according to controlTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D5-CTL-03COPYRIGHT DETECTIONVerify training, retrieval and reference-content provenance for generative underwriting and claims assistants; detect unauthorised use of proprietary actuarial models, policy wordings, manuals and third-party copyrighted material.Customer communications; claim summaries; policy documents; recommendationsApply copyright detection to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Training/retrieval provenance, licences and content-match alerts; [T2] legal/IP review; [T3] proprietary-content ingestion tests.Conduct / Privacy / Legal / CISO, according to controlTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D5-CTL-04AI WATERMARKING ROBUSTNESSApply provenance marking or watermarking where appropriate to insurer-generated synthetic media and communications, and operate detection and escalation pipelines for inbound deepfake or synthetically altered claims evidence.Customer communications; claim summaries; policy documents; recommendationsApply ai watermarking robustness to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Synthetic-media provenance, watermark configuration and detection alerts; [T2] communications/security review; [T3] watermark-removal and deepfake tests.Conduct / Privacy / Legal / CISO, according to controlTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D5-CTL-05PRIVACY-BY-DESIGN VERIFICATIONEmbed privacy requirements in insurance AI design, including purpose limitation, data minimisation, role-based access, retention, privacy testing and review of sensitive health, biometric, financial and telematics data.Customer communications; claim summaries; policy documents; recommendationsApply privacy-by-design verification to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Privacy requirements, data-flow map, minimisation/retention controls and technique parameters; [T2] DPIA or independent privacy validation; [T3] re-identification, inference and utility tests.Conduct / Privacy / Legal / CISO, according to controlTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D5-CTL-06PRIVACY-PRESERVING ML VALIDATIONValidate privacy-preserving techniques used in distributed or sensitive insurance analytics, including re-identification, inference and utility testing; do not assume anonymisation, federation or synthetic data eliminates privacy risk.Customer communications; claim summaries; policy documents; recommendationsApply privacy-preserving ml validation to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Privacy requirements, data-flow map, minimisation/retention controls and technique parameters; [T2] DPIA or independent privacy validation; [T3] re-identification, inference and utility tests.Conduct / Privacy / Legal / CISO, according to controlTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D6-CTL-01HUMAN-IN-THE-LOOP FOR HIGH-RISK ACTIONSEstablish accountable governance, classification, documentation, oversight, assurance and lifecycle decisions.Enterprise governance; model risk; actuarial; security; auditApply human-in-the-loop for high-risk actions to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Governance approvals, accountable-owner register and exceptions; [T2] second-line challenge; [T3] governance tabletop and decision reconstruction.Board / CRO / AI GovernanceTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D6-CTL-02AUDIT TRAIL COMPLETENESSEstablish accountable governance, classification, documentation, oversight, assurance and lifecycle decisions.Enterprise governance; model risk; actuarial; security; auditApply audit trail completeness to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Governance approvals, accountable-owner register and exceptions; [T2] second-line challenge; [T3] governance tabletop and decision reconstruction.Board / CRO / AI GovernanceTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D6-CTL-03AI MODEL CARD COMPLETENESSEstablish accountable governance, classification, documentation, oversight, assurance and lifecycle decisions.Enterprise governance; model risk; actuarial; security; auditApply ai model card completeness to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Governance approvals, accountable-owner register and exceptions; [T2] second-line challenge; [T3] governance tabletop and decision reconstruction.Board / CRO / AI GovernanceTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D6-CTL-04AI INCIDENT RESPONSE READINESSEstablish accountable governance, classification, documentation, oversight, assurance and lifecycle decisions.Enterprise governance; model risk; actuarial; security; auditApply ai incident response readiness to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Governance approvals, accountable-owner register and exceptions; [T2] second-line challenge; [T3] governance tabletop and decision reconstruction.Board / CRO / AI GovernanceTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D6-CTL-05MODEL DEPRECATION & DECOMMISSIONINGEstablish accountable governance, classification, documentation, oversight, assurance and lifecycle decisions.Enterprise governance; model risk; actuarial; security; auditApply model deprecation & decommissioning to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Governance approvals, accountable-owner register and exceptions; [T2] second-line challenge; [T3] governance tabletop and decision reconstruction.Board / CRO / AI GovernanceTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D6-CTL-06THIRD-PARTY AI VENDOR GOVERNANCEEstablish accountable governance, classification, documentation, oversight, assurance and lifecycle decisions.Enterprise governance; model risk; actuarial; security; auditApply third-party ai vendor governance to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Due diligence, AI/SBOM, dependency map, contracts and incident/change notices; [T2] independent vendor assurance; [T3] exit, outage and concentration tests.Board / CRO / AI GovernanceTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D6-CTL-07AI RESILIENCE & BUSINESS CONTINUITYEstablish accountable governance, classification, documentation, oversight, assurance and lifecycle decisions.Enterprise governance; model risk; actuarial; security; auditApply ai resilience & business continuity to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Recovery plans, fallback evidence and availability telemetry; [T2] resilience review; [T3] catastrophe-surge, outage and manual-fallback exercise.Board / CRO / AI GovernanceTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D7-CTL-H01AI-GENERATED PHISHING SIMULATIONPrevent discriminatory, privacy-invasive, deceptive or otherwise harmful policyholder and workforce outcomes.Underwriting; pricing; claims; marketing; health and life decisionsApply ai-generated phishing simulation to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Training, outcome and incident records; [T2] conduct/human-risk review; [T3] deepfake, phishing or harm simulation.Compliance / Conduct / PrivacyTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D7-CTL-H02DEEPFAKE DETECTION TRAININGPrevent discriminatory, privacy-invasive, deceptive or otherwise harmful policyholder and workforce outcomes.Underwriting; pricing; claims; marketing; health and life decisionsApply deepfake detection training to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Training, outcome and incident records; [T2] conduct/human-risk review; [T3] deepfake, phishing or harm simulation.Compliance / Conduct / PrivacyTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D7-CTL-H03OUT-OF-BAND AUTHENTICATIONPrevent discriminatory, privacy-invasive, deceptive or otherwise harmful policyholder and workforce outcomes.Underwriting; pricing; claims; marketing; health and life decisionsApply out-of-band authentication to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Training, outcome and incident records; [T2] conduct/human-risk review; [T3] deepfake, phishing or harm simulation.Compliance / Conduct / PrivacyTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D7-CTL-H04AI SOCIAL ENGINEERING IRPrevent discriminatory, privacy-invasive, deceptive or otherwise harmful policyholder and workforce outcomes.Underwriting; pricing; claims; marketing; health and life decisionsApply ai social engineering ir to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Training, outcome and incident records; [T2] conduct/human-risk review; [T3] deepfake, phishing or harm simulation.Compliance / Conduct / PrivacyTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D7-CTL-H05AI-ENHANCED EXTERNAL ATTACK DEFENSEPrevent discriminatory, privacy-invasive, deceptive or otherwise harmful policyholder and workforce outcomes.Underwriting; pricing; claims; marketing; health and life decisionsApply ai-enhanced external attack defense to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Training, outcome and incident records; [T2] conduct/human-risk review; [T3] deepfake, phishing or harm simulation.Compliance / Conduct / PrivacyTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D8-CTL-01EU AI ACT RISK TIER MAPPINGMaintain legal, regulatory, records, incident, resilience and jurisdiction-specific obligation management.Compliance; records; operational resilience; incident reporting; privacyApply eu ai act risk tier mapping to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Versioned model/data records and monitoring logs; [T2] independent MRM/Appointed Actuary validation; [T3] adversarial, stress and challenger-model tests.Chief Actuary / Head of Model RiskTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D8-CTL-02ISO 42001 GAP ANALYSISMaintain legal, regulatory, records, incident, resilience and jurisdiction-specific obligation management.Compliance; records; operational resilience; incident reporting; privacyApply iso 42001 gap analysis to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Versioned model/data records and monitoring logs; [T2] independent MRM/Appointed Actuary validation; [T3] adversarial, stress and challenger-model tests.Chief Actuary / Head of Model RiskTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D8-CTL-03GPAI TECHNICAL DOCUMENTATION VERIFICATIONMaintain legal, regulatory, records, incident, resilience and jurisdiction-specific obligation management.Compliance; records; operational resilience; incident reporting; privacyApply gpai technical documentation verification to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Versioned model/data records and monitoring logs; [T2] independent MRM/Appointed Actuary validation; [T3] adversarial, stress and challenger-model tests.Chief Actuary / Head of Model RiskTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D8-CTL-04DORA ICT INCIDENT REPORTING (FINANCIAL SECTOR)Maintain legal, regulatory, records, incident, resilience and jurisdiction-specific obligation management.Compliance; records; operational resilience; incident reporting; privacyApply dora ict incident reporting (financial sector) to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Versioned model/data records and monitoring logs; [T2] independent MRM/Appointed Actuary validation; [T3] adversarial, stress and challenger-model tests.Chief Actuary / Head of Model RiskTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D8-CTL-05NIST SP 800-218A COMPLIANCE CHECKMaintain legal, regulatory, records, incident, resilience and jurisdiction-specific obligation management.Compliance; records; operational resilience; incident reporting; privacyApply nist sp 800-218a compliance check to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Versioned model/data records and monitoring logs; [T2] independent MRM/Appointed Actuary validation; [T3] adversarial, stress and challenger-model tests.Chief Actuary / Head of Model RiskTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D9-CTL-01PHYSICAL HARM BOUNDARY ENFORCEMENTApply physical-AI safeguards where telematics, IoT, drones, vehicles, sensors or robotic inspection affect insured risks.Telematics; IoT; drones; image inspection; connected devicesApply physical harm boundary enforcement to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Control configuration, operating logs and approvals; [T2] independent review; [T3] controlled simulation/red-team evidence; [T4] vendor or industry claims only as supplementary context.Engineering / Safety / OperationsTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D9-CTL-02SAFE STATE AND GRACEFUL DEGRADATIONApply physical-AI safeguards where telematics, IoT, drones, vehicles, sensors or robotic inspection affect insured risks.Telematics; IoT; drones; image inspection; connected devicesApply safe state and graceful degradation to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Control configuration, operating logs and approvals; [T2] independent review; [T3] controlled simulation/red-team evidence; [T4] vendor or industry claims only as supplementary context.Engineering / Safety / OperationsTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D9-CTL-03HUMAN OVERRIDE AND EMERGENCY STOPApply physical-AI safeguards where telematics, IoT, drones, vehicles, sensors or robotic inspection affect insured risks.Telematics; IoT; drones; image inspection; connected devicesApply human override and emergency stop to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Control configuration, operating logs and approvals; [T2] independent review; [T3] controlled simulation/red-team evidence; [T4] vendor or industry claims only as supplementary context.Engineering / Safety / OperationsTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D9-CTL-04CYBER-PHYSICAL ATTACK DETECTIONApply physical-AI safeguards where telematics, IoT, drones, vehicles, sensors or robotic inspection affect insured risks.Telematics; IoT; drones; image inspection; connected devicesApply cyber-physical attack detection to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Control configuration, operating logs and approvals; [T2] independent review; [T3] controlled simulation/red-team evidence; [T4] vendor or industry claims only as supplementary context.Engineering / Safety / OperationsTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D9-CTL-05PHYSICAL ENVIRONMENT INTEGRITY MONITORINGApply physical-AI safeguards where telematics, IoT, drones, vehicles, sensors or robotic inspection affect insured risks.Telematics; IoT; drones; image inspection; connected devicesApply physical environment integrity monitoring to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Control configuration, operating logs and approvals; [T2] independent review; [T3] controlled simulation/red-team evidence; [T4] vendor or industry claims only as supplementary context.Engineering / Safety / OperationsTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D9-CTL-06ACTUATOR COMMAND VERIFICATIONApply physical-AI safeguards where telematics, IoT, drones, vehicles, sensors or robotic inspection affect insured risks.Telematics; IoT; drones; image inspection; connected devicesApply actuator command verification to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Control configuration, operating logs and approvals; [T2] independent review; [T3] controlled simulation/red-team evidence; [T4] vendor or industry claims only as supplementary context.Engineering / Safety / OperationsTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.
D9-CTL-07PHYSICAL INCIDENT EVIDENCE PRESERVATIONApply physical-AI safeguards where telematics, IoT, drones, vehicles, sensors or robotic inspection affect insured risks.Telematics; IoT; drones; image inspection; connected devicesApply physical incident evidence preservation to the complete insurance decision chain and document sector-specific threats, limits and fallbacks.[T1] Control configuration, operating logs and approvals; [T2] independent review; [T3] controlled simulation/red-team evidence; [T4] vendor or industry claims only as supplementary context.Engineering / Safety / OperationsTest design and operating effectiveness; sample material decisions; verify scopeInterpretation is informative; applicability and sufficiency remain entity-specific.No claim of regulatory equivalence or automatic certification.

21. Regulatory and standards landscape

External sources provide context, not automatic obligations or equivalence. Implementing organisations should verify current status, jurisdiction, adoption, effective dates, amendments and supervisory interpretation before reliance.

Source IDInstrumentIssuer / jurisdictionRelevanceStatus / limitation
SRC-02Application Paper on the Supervision of Artificial IntelligenceInternational Association of Insurance Supervisors / International supervisory guidanceInsurance supervision, governance and conduct contextApplication paper; not binding law and jurisdictional implementation varies.
SRC-03Opinion on Artificial Intelligence Governance and Risk ManagementEIOPA / European Union / EEA supervisory contextInsurance-sector governance and risk management principlesAddressed to national supervisors; applicability must be assessed.
SRC-04Model Bulletin: Use of Artificial Intelligence Systems by InsurersNAIC / United States state insurance regulation modelWritten AIS program, governance, consumer outcomes and regulator examination expectationsModel bulletin; adoption and wording vary by state.
SRC-05Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1NIST / United States / cross-sector voluntary frameworkCross-sector lifecycle risk managementVoluntary framework; not insurance-specific or a legal compliance standard.
SRC-06Artificial Intelligence Risk Management Framework: Generative AI Profile, NIST AI 600-1NIST / United States / cross-sector voluntary profileGenerative-AI risks and controlsProfile requires tailoring to insurance use cases and law.
SRC-07Artificial Intelligence Governance Principles: Towards Ethical and Trustworthy AI in the European Insurance SectorEIOPA Consultative Expert Group / European insurance sectorFairness, explainability, governance, data and resilience contextExpert-group report, not binding law.

22. Financial impact vectors

VectorImpact pathway
Claims leakageIncorrect estimation, weak fraud detection or uncontrolled settlement recommendations.
Incorrect claims denialFalse negatives or automation bias create remediation and litigation exposure.
Underpricing / overpricingModel or data errors distort premium adequacy or customer outcomes.
Adverse selectionPoor segmentation or drift changes portfolio risk mix.
Reserving errorModel assumptions or regime shifts distort liabilities and management information.
Capital and reinsurance impactsAccumulation or catastrophe-model error affects risk transfer and solvency decisions.
Regulatory and legal costExamination, remediation, penalties, disputes and record reconstruction.
Operational disruptionVendor outage, model compromise or claims surge impairs critical services.
Fraud lossesAdversarial evasion, synthetic evidence or compromised scoring increases leakage.
Reputation and attritionUnfair, opaque or inaccurate outcomes damage trust and distribution relationships.

These are pathways, not guaranteed outcomes. Quantification should use entity-specific exposure, decision volume, remediation cost, claims severity, capital and reinsurance assumptions.

23. Metrics and reporting

MetricDefinitionOwnerFrequencyInterpretation / gaming caveat
Inventory coverageMaterial systems recorded / systems identifiedAI governanceMonthlyUnknown shadow AI or stale records can distort metric
High-impact validation currencyHigh-impact systems with current validationModel riskQuarterlyA current report may still contain unresolved limitations
Adverse outcome rateAdverse decisions by product and subgroupCompliance / businessMonthlySmall samples and confounding require careful interpretation
Appeal reversal rateDecisions reversed after challengeClaims / underwritingMonthlyLow appeal access can artificially lower the rate
Override rate and reasonHuman overrides by system and outcomeBusiness ownerMonthlyTargeting low override rates can suppress appropriate challenge
Drift exceptionsOpen performance/data drift breachesModel ownerRisk-basedThreshold choice can conceal slow deterioration
Security abuse eventsInjection, extraction, evasion or unauthorised-use eventsCISOContinuous / monthly reportDetection coverage varies
Vendor concentrationCritical services sharing provider/model/cloudThird-party riskQuarterlyContract-level count may miss common fourth parties
Manual fallback readinessCritical systems with tested fallbackOperationsQuarterlyDocumented procedure is not proof of usable capacity

24. Notably Absent

  • No legal, regulatory, actuarial, financial, insurance or investment advice.
  • No regulator, actuarial or certification approval.
  • No guaranteed compliance, fairness, accuracy, security, resilience or insurability.
  • No universal risk, performance, fairness, confidence or notification threshold.
  • No substitute for independent validation, policyholder-impact assessment or jurisdiction-specific review.
  • No complete list of insurance threats, regulations, standards, vendors or use cases.
  • No endorsement of any model, vendor, technology, data source or methodology.
  • No determination that a particular insurance decision, variable, rate, claim outcome or coverage interpretation is lawful.
  • No universal definition of high-risk AI.
  • No presumption that human review, explainability or provider assurance is effective without operating evidence.

Appendix A - Terms and definitions

TermWorking definition
Adverse consumer outcomeA decision or process outcome that may unlawfully or unfairly disadvantage a policyholder, applicant, claimant or beneficiary.
Decision authorityThe degree to which an AI system recommends, determines, executes or constrains an insurance action.
Meaningful human oversightTimely review by a competent and authorised person with sufficient information and ability to intervene.
Insurance AI systemAn AI-enabled component or decision chain used in insurance operations, including models, rules, prompts, retrieval, tools and integrations.
Policyholder impactActual or reasonably foreseeable effect on eligibility, price, coverage, claim, service, privacy, dignity or ability to challenge.

Appendix B - Insurance AI System Inventory

Purpose: provide a controlled record supporting implementation, assessment and review. Instructions: complete all material fields, retain source evidence, identify assumptions and do not treat example entries as mandatory thresholds. Record owner and review frequency should be assigned according to risk and applicable retention requirements.

System IDNameBusiness ownerFunctionDecision authorityClassificationData sensitivityVendorGAISSF scopeStatus
EXAMPLE - illustrativeTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completed

Appendix C - Insurance AI Risk Assessment

Purpose: provide a controlled record supporting implementation, assessment and review. Instructions: complete all material fields, retain source evidence, identify assumptions and do not treat example entries as mandatory thresholds. Record owner and review frequency should be assigned according to risk and applicable retention requirements.

Risk IDSystem IDScenarioThreat/failurePolicyholder impactFinancial impactLikelihood rationaleControlsResidual riskOwnerAction
EXAMPLE - illustrativeTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completed

Appendix D - Control Interpretation Matrix

Purpose: provide a controlled record supporting implementation, assessment and review. Instructions: complete all material fields, retain source evidence, identify assumptions and do not treat example entries as mandatory thresholds. Record owner and review frequency should be assigned according to risk and applicable retention requirements.

Control IDControl titleApplicable?Insurance interpretationImplementationEvidenceOwnerTestGapStatus
EXAMPLE - illustrativeTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completed

Appendix E - Evidence Catalogue

Purpose: provide a controlled record supporting implementation, assessment and review. Instructions: complete all material fields, retain source evidence, identify assumptions and do not treat example entries as mandatory thresholds. Record owner and review frequency should be assigned according to risk and applicable retention requirements.

Evidence IDCategoryTitleControl linksOwnerSourcePeriodRetentionReliabilityLocation
EXAMPLE - illustrativeTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completed

Appendix F - Human Oversight Matrix

Purpose: provide a controlled record supporting implementation, assessment and review. Instructions: complete all material fields, retain source evidence, identify assumptions and do not treat example entries as mandatory thresholds. Record owner and review frequency should be assigned according to risk and applicable retention requirements.

DecisionTriggerOversight modelReviewer competenceInformation requiredAuthorityTime limitOverride recordEscalation
EXAMPLE - illustrativeTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completed

Appendix G - Vendor Due Diligence Questionnaire

Purpose: provide a controlled record supporting implementation, assessment and review. Instructions: complete all material fields, retain source evidence, identify assumptions and do not treat example entries as mandatory thresholds. Record owner and review frequency should be assigned according to risk and applicable retention requirements.

Question IDDomainQuestionEvidence requestedResponseRisk ratingReviewerAction
EXAMPLE - illustrativeTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completed

Appendix H - Incident Classification Matrix

Purpose: provide a controlled record supporting implementation, assessment and review. Instructions: complete all material fields, retain source evidence, identify assumptions and do not treat example entries as mandatory thresholds. Record owner and review frequency should be assigned according to risk and applicable retention requirements.

Incident IDSystemDescriptionSeverityPolicyholder impactFinancial impactSecurity impactRegulatory assessmentOwnerStatus
EXAMPLE - illustrativeTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completed

Appendix I - Implementation Roadmap Tracker

Purpose: provide a controlled record supporting implementation, assessment and review. Instructions: complete all material fields, retain source evidence, identify assumptions and do not treat example entries as mandatory thresholds. Record owner and review frequency should be assigned according to risk and applicable retention requirements.

Task IDPhaseTaskOwnerStartDueDependencyEvidenceStatusCompletion %
EXAMPLE - illustrativeTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completed

Appendix J - Worked Scenario Record

Purpose: provide a controlled record supporting implementation, assessment and review. Instructions: complete all material fields, retain source evidence, identify assumptions and do not treat example entries as mandatory thresholds. Record owner and review frequency should be assigned according to risk and applicable retention requirements.

Scenario IDContextDataDecision authorityThreatsControlsEvidenceOversightMonitoringResidual risk
EXAMPLE - illustrativeTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completed

Appendix K - Source Register

Purpose: provide a controlled record supporting implementation, assessment and review. Instructions: complete all material fields, retain source evidence, identify assumptions and do not treat example entries as mandatory thresholds. Record owner and review frequency should be assigned according to risk and applicable retention requirements.

Source IDTitleIssuerJurisdictionDateTierURLSupported sectionsLimitationsStatus
EXAMPLE - illustrativeTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completed

Appendix L - Notably Absent Register

Purpose: provide a controlled record supporting implementation, assessment and review. Instructions: complete all material fields, retain source evidence, identify assumptions and do not treat example entries as mandatory thresholds. Record owner and review frequency should be assigned according to risk and applicable retention requirements.

Item IDExcluded claim/assumptionReasonAffected sectionOwnerReview date
EXAMPLE - illustrativeTo be completedTo be completedTo be completedTo be completedTo be completed

Appendix M - Document Review Checklist

Purpose: provide a controlled record supporting implementation, assessment and review. Instructions: complete all material fields, retain source evidence, identify assumptions and do not treat example entries as mandatory thresholds. Record owner and review frequency should be assigned according to risk and applicable retention requirements.

Check IDCategoryCheckOwnerStatusEvidence / note
EXAMPLE - illustrativeTo be completedTo be completedTo be completedTo be completedTo be completed

Appendix N - Open Issues and Deferred Decisions

Purpose: provide a controlled record supporting implementation, assessment and review. Instructions: complete all material fields, retain source evidence, identify assumptions and do not treat example entries as mandatory thresholds. Record owner and review frequency should be assigned according to risk and applicable retention requirements.

Issue IDDescriptionReason unresolvedOwnerDependencyRiskRequired decisionTarget stagePublication impactStatus
EXAMPLE - illustrativeTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completedTo be completed

Open issues register

IDIssueReasonOwnerDependencyRiskDecisionTargetImpactStatus
OI-001Jurisdiction-specific legal and regulatory reviewApplicability variesQualified counselTarget marketsUnsupported publication claimApprove or qualify referencesBefore final public releaseHighOpen - legal review required
OI-002Actuarial terminology and examplesRequires professional reviewQualified actuaryInsurance linesMisinterpretationApprove or reviseBefore final public releaseHighOpen - actuarial review required
OI-003Formal approval identitiesNamed approvers not providedDocument ownerApproval processIncomplete governance recordRecord approvalsBefore final public releaseMediumOpen
OI-004Final website and repository URLsPublication destinations not providedPublication ownerWebsite/GitHubBroken access or placeholderInsert verified URLsBefore final public releaseMediumOpen
OI-005Trademark-status wordingFinal status should be confirmed at releaseLegal ownerTrademark registerIncorrect noticeConfirm wordingBefore final public releaseMediumOpen - trademark confirmation required

Source register

IDTitleIssuerJurisdictionPublication dateTierURLSupportsLimitationsStatus
SRC-IAIS-01Application Paper on the Supervision of Artificial IntelligenceIAISGlobalJuly 2025T1https://www.iais.org/2025/07/the-iais-publishes-application-paper-on-the-supervision-of-artificial-intelligence/Governance; conduct; supervisionNon-binding application paper; jurisdictional applicability review requiredSource verified; applicability open
SRC-NAIC-01Model Bulletin: Use of Artificial Intelligence Systems by InsurersNAICUnited States / adopting jurisdictions4 December 2023T1https://content.naic.org/sites/default/files/inline-files/2023-12-4%20Model%20Bulletin_Adopted_0.pdfAIS programme; governance; consumer outcomes; third partiesAdoption and interpretation vary by jurisdictionSource verified; applicability open
SRC-EIOPA-01Opinion on Artificial Intelligence Governance and Risk ManagementEIOPAEuropean Union2025T1https://www.eiopa.europa.eu/publications/opinion-artificial-intelligence-governance-and-risk-management_enInsurance-sector AI governance and risk managementApply with EU and national lawSource verified; applicability open
SRC-EIOPA-02Artificial Intelligence Governance Principles: Towards Ethical and Trustworthy AI in the European Insurance SectorEIOPA Consultative Expert GroupEuropean UnionJune 2021T2https://www.eiopa.europa.eu/publications/artificial-intelligence-governance-principles-towards-ethical-and-trustworthy-artificial_enFairness; explainability; oversightExpert-group report; not binding lawVerified contextual source
SRC-SII-01Solvency II frameworkEuropean Commission / EIOPAEuropean UnionCurrent frameworkT1https://www.eiopa.europa.eu/browse/regulation-and-policy/solvency-ii_enPrudential and capital contextNo direct GAISSF equivalence; legal review requiredSource verified; applicability open
SRC-IFRS17-01IFRS 17 Insurance ContractsIASB / IFRS FoundationIFRS jurisdictionsEffective 1 January 2023 subject to adoptionT1https://www.ifrs.org/issued-standards/list-of-standards/ifrs-17-insurance-contracts/Financial reporting contextAccounting linkage to AI failures requires qualified reviewSource verified; applicability open

Final quality-control report

ReviewResultFinding
Structural reviewPassAll required sections, appendices, scenarios and registers included.
Normative-language reviewPassNo new mandatory sector requirements; verified GAISSF IDs used.
Cross-reference reviewPass with approval caveatControl IDs verified to GAISSF-NOR-001; named approval records remain open.
Citation/source reviewPass with applicability caveatAuthoritative sources listed; jurisdictional applicability requires qualified review.
Legal/regulatory reviewOpenQualified review required before public reliance in target jurisdictions.
Sector reviewOpenQualified insurance and actuarial review required.
Publication reviewPass with open release metadataFinal URLs and approval identities remain open.

Reader guide

ReaderPriority sectionsKey appendices / artifacts
Board, CFO, CRO and Appointed ActuaryExecutive summary; prudential and actuarial impact vectors; governance; Notably AbsentOpen issues; workbook dashboard and risk register
CISO and security architectureRisk landscape; security architecture; agentic AI; control mappingControl Mapping and Incident Register
Claims and underwriting leadersFunction interpretations; human oversight; worked scenariosHuman Oversight and Scenarios sheets
Compliance, conduct and privacyTransparency and contestability; data governance; incident managementSource Register and Evidence Register
Procurement and vendor riskThird-party management and concentrationVendor Assessment and AI/SBOM evidence

Prudential and actuarial impact vectors

The following table translates security and AI-control failures into potential balance-sheet, actuarial and prudential pathways. It does not assert that a control failure automatically creates an accounting, capital or regulatory breach.

GAISSF domainInsurance failure pathwayPotential prudential / actuarial consequence
D1 - Model integrityPricing or underwriting instability, poisoning or driftAdverse selection, margin erosion, reserve assumption distortion and rate-filing challenge.
D4 - Third-party AI securityCommon catastrophe, cloud, data or foundation-model dependency failureCorrelated portfolio error, accumulation underestimation, service interruption and reinsurance treaty dispute.
D5 - Output integrityMisleading claims, policy or financial-reporting contentClaims leakage, customer remediation, reporting control failure and audit qualification risk.
D6 - GovernanceWeak accountability, oversight or continuityOperational resilience failure, delayed catastrophe response and governance or supervisory findings.
D8 - Model riskInvalid reserving, capital or catastrophe-model assumptionsPotential IFRS 17 reporting misstatement, solvency-capital distortion and board risk-appetite breach; applicability requires qualified review.

Evidence quality tiers

  • T1: Primary verified operating evidence: automated logs, immutable decision/claims trails, access records, telemetry and approved source records.
  • T2: Independent or second-line verified evidence: MRM validation, Appointed Actuary sign-off, internal audit, privacy, legal or security review.
  • T3: Controlled simulation evidence: adversarial testing, deepfake-claim injection, stress testing, catastrophe surge, failover and out-of-distribution exercises.
  • T4: Anecdotal or unverified context: vendor benchmarks, surveys and generic white papers; insufficient alone for high-impact underwriting, pricing or claims conclusions.

Agentic AI in insurance workflows

Multi-agent insurance workflows can connect broker, insurer, reinsurer, claims, data and payment services. The decision boundary must include the full delegation chain rather than assessing each agent in isolation.

  • Agent-to-agent authentication failure between broker, insurer, reinsurer and service-provider agents
  • Compounding error in autonomous underwriting, claims adjustment or reinsurance placement
  • Orphaned execution loops that repeatedly request evidence, change reserves, issue communications or invoke payment tools
  • Delegation-chain ambiguity, excessive tool authority and inability to reconstruct which agent made or executed a decision

Minimum implementation controls:

  • Unique workload identity and mutual authentication for each agent
  • Explicit delegation scope, transaction limits, segregation of duties and expiry
  • Loop, cost, time and action-count circuit breakers
  • Human approval before binding coverage, denying claims, changing reserves, placing reinsurance or initiating payment
  • Complete agent-to-agent message, tool-call, model-version and approval trace

Maintenance plan

Review SEC-039 at least annually and after a material GAISSF revision, insurance supervisory development, significant sector incident, material technology change or substantiated practitioner feedback. Use minor versions for corrections and clarifications and major versions for substantive architecture or control-interpretation changes. Publish change notices through the official ODA3 Institute website and repository.

Publication-readiness declaration CONTROLLED PRE-RELEASE DRAFT FOR PEER REVIEW. The substantive implementation package and verified GAISSF control mapping are complete. Final public release is not authorised until qualified insurance/actuarial and jurisdiction-specific legal/regulatory applicability reviews, named approvals, trademark/legal-entity verification and final publication URLs are closed.

End of SEC-039 v1.0