The Questions Before the Policy, Part 2: The Underwriter's File, in brief
The short version of The Questions Before the Policy, Part 2: The Underwriter's File. Four minutes, same sources.
Joel R. Singh
Underwritten
Before you buy AI insurance, you need some papers ready. These papers help the insurer understand your business, how you use AI, and what could go wrong. This guide explains them in plain terms, so you know what to gather before the application lands on your desk.
Say you run a small business that uses AI for customer service or inventory. When you apply for AI insurance, the insurer wants to know how you use AI and what you do to prevent problems. They ask for specific documents that show how you manage your AI systems, and different insurers ask the same core questions in different words. Roughly nine documents come up again and again across the applications underwriters actually send out.
The first is a model inventory. This is a list of every AI model your business uses. It should show where each model came from, what it does, and which parts of your business it touches. Think of it as a map of every AI tool in your company.
The second is human oversight. This shows how people check and control your AI systems. It might name who reviews the AI's work before it reaches customers. The EU AI Act requires effective human oversight for high-risk AI uses.
The third is bias and red-team testing. This shows you have tested your AI systems for problems, including whether the AI treats groups of people fairly. The NIST AI RMF Playbook lists specific risks to check for in generative AI systems.
The fourth is an incident response plan. This says what your business will do if an AI system causes a problem: who to call, how to fix it, how to tell affected customers. The NIST SP 800-61r3 guide can help you build this plan.
The fifth is data governance and provenance. This shows where your AI data comes from, how it is protected, and how it moves through your systems. AI problems trace back to bad data more often than to bad models.
The sixth is a written AI usage policy. Think of it as a rulebook: what is allowed, who is responsible, what standard every AI system must meet before use. Insurance regulators expect insurers to run a written program like this for their own AI use.
The seventh is third-party and vendor AI risk. This lists the AI systems you use from outside suppliers, your contracts with them, and any checks you run on their systems. Underwriters increasingly want audit rights over a vendor's training data as a condition of cover.
The eighth and ninth are alignment to a recognized framework and evidence of independent assurance. These show your business follows an established standard, such as the NIST AI Risk Management Framework, and has been checked by an outside party. An ISO/IEC 42001 certificate is the clearest form of independent assurance, and it can win you better terms.
What to do this week
- Start your model inventory: list every AI model your business uses, where it came from, what it does, and which parts of your business it touches.
- Check your human oversight: write down who reviews the AI's work before it reaches customers, and set a clear rule for it.
- Plan your bias and red-team testing: decide how you will test for problems, using the NIST AI RMF Playbook as a guide.
- Create your incident response plan: write down who to call, how to fix a problem, and how to tell affected customers.
- Review your data governance: confirm where your AI data comes from and how it is protected, and keep records.
These nine documents make you insurable. Prepare them, and you can show an insurer your business uses AI safely.
Works Cited
- 1High-Level Summary of the AI Act — The EU Artificial Intelligence Act (project of the Future of Life Institute)
- 2NIST AI RMF Playbook — NIST Trustworthy & Responsible AI Resource Center
- 3Artificial Intelligence Risk Management Framework
- 4SP 800-61r3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management — National Institute of Standards and Technology
- 5Model Bulletin on the Use of Artificial Intelligence Systems by Insurers — National Association of Insurance Commissioners (adopted December 2023)
- 6Covering AI: AI Insurance Becomes a Procurement Requirement — Armilla AI
- 7AI Risk Management Framework — National Institute of Standards and Technology
- 8Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 — National Institute of Standards and Technology
- 9ISO/IEC 42001:2023 Artificial Intelligence Management System — BSI Group
- 10From ISO/IEC 42001 Certification to Insurable AI — Armilla AI
- 11Regulatory Framework on Artificial Intelligence — European Commission
- 12Insure AI: performance guarantee and affirmative AI coverage — Munich Re