The Questions Before the Policy · Part 1 of 2
Why Underwriters Price the Company
With almost no loss history to price against, AI underwriters price the company instead of the risk, and the renewal questionnaire is where that judgment is made.
Joel R. Singh
Underwritten
The Empty Table
An underwriter pricing a risk is, at heart, a person reading a table. The table records how often a given thing has gone wrong in the past, and by how much, across enough cases that the pattern stops being a story and becomes a rate. A century of house fires produces a rate. A hundred years of automobile collisions produces a rate. From that rate the underwriter derives a premium, and the whole apparatus of modern insurance rests on the assumption that the future will resemble the past closely enough for the table to keep working.
When an underwriter is asked to price artificial intelligence, they reach for that table out of long habit, and their hand closes on almost nothing. Large-scale deployment of these systems is only a few years old, the harms are still surfacing, and many of them surface slowly, hidden inside decisions that looked perfectly reasonable at the moment they were made. The table an AI underwriter would most like to consult has barely begun to fill.
This is not a small inconvenience to be worked around with a wider confidence interval. It cuts to the foundation of how a price gets made, because the machinery of pricing was built to extrapolate from a record, and here the record does not yet exist. An underwriter faced with this vacuum has only two honest options:
- They can decline to write the risk at all, as much of the market did at first and still does.
- Or they can find some available signal that stands in for the missing loss data and lets them form a judgment about the risk they can actually see.
The whole subject of this essay is that second option, and what it now demands of any business that wants to be insured.
They price the company instead
The substitute the market has settled on is not a substitute for the risk itself, which cannot be conjured out of thin data. It is a substitute for the record. When an underwriter cannot price the AI, they price the company that operates it. They look for evidence that the organization understands what it has deployed, that it watches the system in operation, that it has thought in advance about how the system fails and what it will do when it does.
Where a mature line of insurance asks the risk to speak for itself through a hundred years of claims, an emerging line asks the operator to speak for the risk through the discipline of how it is governed. The governance becomes the proxy, standing in for the loss history that has not yet accumulated. This is the shift that reorganizes everything a buyer needs to do, and it is worth being precise about why it happened, because a buyer who mistakes it for a passing demand will prepare for the wrong thing.
When an underwriter cannot price the AI, they price the company that operates it.The underwriting proxy
Two applicants, one measurable difference
Consider the plainest version of the underwriter's problem. Two companies apply for the same AI liability coverage on the same day. Both deploy a large language model in a customer-facing role with real financial stakes attached to its answers.
One of them can produce, on request, a current inventory of every model it runs and what each one touches, a written record of where a human reviews the machine's output before it reaches a customer, the results of testing the system for bias and for the ways an adversary might push it off the rails, and a plan for what happens in the first hour after something goes wrong.
The other company can produce a slide deck and a feeling of confidence. To an underwriter with no loss table to fall back on, these two applicants are not close. The difference between them is the only difference the underwriter can actually measure, and so it becomes the difference that sets the terms, or that decides whether terms are offered at all.
None of this is a courtesy the market extends to well-organized firms. It is a necessity the market has backed into because the alternative is to price blind, and because it is a necessity it hardens quickly into a requirement. The soft language of best practice becomes the hard language of a condition on the policy, and the documentation a thoughtful company might have kept anyway becomes the documentation it must keep in order to buy coverage at any price it can stomach. The rest of this series is about what that documentation is, why each piece answers a specific fear the underwriter carries, and how a buyer builds the file before the questions arrive rather than after.
The Renewal Questionnaire Is the Real Exam
The document where all of this becomes concrete is the application, and then, year after year, the renewal questionnaire. It arrives looking like paperwork, and it is easy to treat it as paperwork, a set of boxes to fill on the way to a quote. That treatment is a mistake. The questionnaire is the exam, and the whole grade rides on it, because in the absence of a loss table the questionnaire is very nearly the only instrument the underwriter has for forming a view of the risk. Every question in it is a probe for a specific piece of the governance record, and every answer either produces the document behind it or reveals that the document does not exist. The buyer who understands this reads the questionnaire not as a form to complete but as a checklist of artifacts to have built, ideally long before the form ever arrives.
What the specialty AI underwriters ask has converged, across a still-young market, on a recognizable core. Each question is a probe for one document, and each document answers one fear.
Above all, increasingly, they want to see the whole apparatus mapped onto a recognized framework, so that the governance reads as an implementation of a standard the underwriter already trusts.
Beyond what the carriers say about themselves
The public evidence for this no longer rests on what carriers say about themselves. The Geneva Association, an insurance research body with no cover to sell, finds that insurers are tightening underwriting standards by scrutinising an insured's AI systems and governance practices, a process it compares to a technical audit, before granting coverage at all.[1] The safeguards it describes are the same ones the questionnaire probes for: human oversight, bias checks, contingency plans, model audits, third-party certification, and reporting obligations written into the policy terms.[1]
Carriers writing the cover say it in plainer commercial language. Armilla, which writes affirmative AI coverage, states that providers seeking cover must maintain documented AI governance policies with at least annual compliance testing, and warrant alignment with recognized frameworks including the NIST AI Risk Management Framework and the EU AI Act.[2]
At least one carrier now treats a formal management-system certification as a direct underwriting input. Armilla incorporates the signal from an ISO/IEC 42001 certification alongside its own technical evaluation, and says the result can be a clearer path to insurability and the potential for preferential terms.[3] Whether that hardens into market-wide practice is still open. As recently as mid-2025, no insurer was known to price the certification at all.[4]
Applications have been declined where governance and monitoring were too thin to support risk transfer, which tells you the questionnaire is not a formality with a foregone conclusion.[5]
The specialist carriers built for this risk underwrite the operator's discipline because the operator's discipline is what they can see. Lloyd's describes the first managing general agent and coverholder dedicated solely to AI liability as underwriting its exposures through independent model evaluation and regulatory-grade audits.[6] The Lloyd's Market Association puts the underwriter's central question in almost the same terms a buyer should expect on the form: whether the system decides what real-world actions to take, and whether it does so supporting a human decision-maker or replacing one without supervision.[7]
[1] The Geneva Association, Gen AI Risks for Businesses · [2] Armilla AI, AI Insurance Becomes a Procurement Requirement · [3] Armilla AI, From ISO/IEC 42001 Certification to Insurable AI · [4] Deploy Securely, AI governance and cyber insurance · [5] Armilla AI, From Paper Policies to Real Oversight · [6] Lloyd's of London, Lloyd's Lab · [7] Lloyd's Market Association
What the market now asks in writing
Documented AI governance with at least annual compliance testing, warranted alignment to recognized frameworks, and, increasingly, an ISO/IEC 42001 certification treated as a direct underwriting input that opens pathways to insurability and preferential terms. Applications have been declined outright for insufficient governance.
What your answers bind you to
There is a further reason to build the file well ahead of the deadline, and it has to do with what insurance law does with the answers you give. An insurance application is not a marketing document, and the statements a buyer makes on it are relied upon by the insurer in deciding whether and how to cover the risk.
A confident overstatement of controls that do not actually exist is a misrepresentation on the record that an insurer may later invoke, at the worst possible moment, when the claim it would have to pay is precisely the kind the overstated control was supposed to prevent. The questionnaire rewards a company that answers truthfully and completely, and it punishes, sometimes catastrophically and after the fact, a company that answers the way it wishes the truth were.
The only safe way to answer well is to have built the thing the question asks about, which is why the work of becoming insurable is done in advance and in earnest, not in the two weeks before renewal.
The questionnaire is the exam, and in a market with no loss table, it is very nearly the only instrument the underwriter has.The underwriting proxy
Where this leads next
If governance is the proxy, the file is the exam paper. Part 2 is the file itself.
The questionnaire probes for a recognizable set of documents, and they have converged on roughly nine. Part 2 walks through each one, what fear it answers, and the frameworks that turn a company's private habits into evidence an underwriter can price.
Continue with Part 2, The Underwriter's File. For the shape of the AI insurance market itself, read the companion essay Who Insures the Machine.
Works Cited
Every factual claim in this part is sourced below, with primary sources preferred. The numbers match the citation after each paragraph. Descriptions of the present-day AI underwriting market draw on published statements from carriers and specialty insurers writing this risk today.
- 1The Geneva Association, Gen AI Risks for Businesses: Exploring the Role for Insurance (2 October 2025). ↩ ↩ Authors Ruo Jia, Martin Eling and Tianyang Wang. The same research team set out these findings for practitioners in The Actuary Magazine (Society of Actuaries, October 2025); that article is the same body of work in another outlet, not a second independent confirmation.
- 2Armilla AI, Covering AI: AI Insurance Becomes a Procurement Requirement (15 May 2026). ↩ A carrier describing its own contract language. Cited as first-hand evidence of what one insurer requires, not as a survey of the market.
- 3Armilla AI, From ISO/IEC 42001 Certification to Insurable AI (17 December 2025). ↩ Describes Armilla's own underwriting, in partnership with A-LIGN.
- 4Joseph Breen, How effective AI governance can improve cyber insurance coverage, Deploy Securely (15 June 2025). ↩ States that no insurer was then known to offer terms tied to ISO 42001 or the NIST AI RMF. Predates source 3, so it marks the position before that offering existed rather than contradicting it.
- 5Armilla AI, From Paper Policies to Real Oversight: How AI Governance Is Becoming Insurable (14 January 2026). ↩
- 6Lloyd's of London, Lloyd's Lab Accelerator alumni: Armilla AI. ↩ Lloyd's describes Armilla as the first managing general agent and Lloyd's coverholder dedicated solely to AI liability insurance, underwriting through independent model evaluation and regulatory-grade audits.
- 7David Powell, Head of Technical Underwriting, Understanding artificial intelligence risk in insurance products: the challenges, Lloyd's Market Association (13 April 2025). ↩ The LMA also notes that underwriters do not yet know as much about AI systems as they might wish to, which is part of why the questionnaire carries so much weight.