Webinar
The AIRG for insurers
In a webinar for the Singapore College of Insurance, I walked insurers through the AI Risk Management Guidelines (AIRG) - not clause by clause, but what they are trying to achieve and how to navigate them from an insurance seat. I wrote the AIRG while leading AI risk supervision at the Monetary Authority of Singapore, and the short version for insurers is this: most of it you already know, a part of it is genuinely new, and the way to handle it is as a system, not a checklist. The full session is below; the main points follow.
Mostly model risk, in a new coat
If you have ever validated an actuarial, pricing or reserving model, you already recognise most of the AIRG. When I came back to the MAS to write it, a great deal of the thinking came from years of reviewing credit and market-risk models in banking, and actuarial and financial models are not radically different. Read the guidelines with a risk-modelling background and perhaps sixty to seventy per cent will feel familiar. The AIRG exists for the rest: the delta that AI adds on top of model risk, technology risk and third-party risk.
One model nearly sank an insurer. Now there are hundreds
Insurers of all people should take AI model risk seriously, because the 2008 crisis was, at its heart, a model failure, and an insurer was at the centre of it. The Gaussian copula used to price mortgage-backed products was too simple for what it was modelling; when it broke, the losses dwarfed what anyone had assumed, and AIG could not pay. One simple model almost no one truly understood helped trigger a global crisis. Now move to today. Insurers run machine-learning and deep-learning models, generative AI is in production, and agentic AI is next. We have gone from one model to hundreds, far more complex, each owned by someone who is sure they understand it. The risk has not grown in a straight line. That is why AI risk management is not optional.
AI is not one thing: the hamburger
The mistake I most want insurers to avoid is treating AI as a single thing you point at a problem, and treating the guidelines as a list to tick. I use a hamburger to make the point. A large language model is the soft bun: excellent with language, intent and synthesis, but fuzzy and variable, so it is the wrong tool for what you can already calculate precisely. The patty is everything you already trust and can explain: your actuarial models, your rules, your tested tools. The vegetables are the risk controls that hold it together: data quality, traceability, evaluation and testing, monitoring. Good AI design gives the language model the tools to do the exact work, and keeps the trusted models for what they are good at. This is also the answer to the worry that underwriting is an art that AI will flatten: you do not hand the whole judgement to a language model, you use each part for what it does well.
What agents change for insurers
Machine learning and deep learning give wrong answers; that is just error. Generative AI adds the kind of error where the system, asked for an answer it does not have, produces one anyway. Agentic AI changes the game again, because you move from a wrong answer to a wrong action, from a decision aid to something that acts on its own, and from one point of failure to many. For insurance that matters: an action can be irreversible, the impact radius can be real money and real customers, and when several agents act across many steps - some built in-house, some bought, owned by one person, overseen by another - accountability gets harder to pin down. So the questions for agents are about human oversight and who answers for the outcome, not just accuracy.
Proportionality, two ways
The AIRG does not ask every insurer to do everything, and it does not treat every use the same. Proportionality is built in twice. First, by integration: a small insurer whose use of AI is not deeply woven into its operations can work to a simpler, basic set of controls, so the requirements are not overbearing for an entity that does not need them. Second, by materiality. Rate each use on impact, complexity and reliance, and let the controls follow. Domain alone is not enough: the EU AI Act calls insurance and credit scoring high-risk by category, but picture two insurance systems - one a machine-learning model where an analyst reviews every one of about a hundred decisions a day, the other an agentic system auto-approving millions a month. Same domain, worlds apart. Rate on what the system does, not what it is called, or you will pour effort into the wrong places.
Where to start: inventory, proportionality, capability
From inspecting how firms actually manage AI model risk, the clearest sign of one doing it well is that it treats the inventory as a command centre, not a spreadsheet for the auditor: the place approvals, deployment, issue-tracking and monitoring are run from. So if you start anywhere, start with three things. Build an inventory that will let you scale as your AI multiplies. Use proportionality, because applying the same controls to everything gets you nowhere. And build capability - and by capability I do not mean prompt-engineering courses, but the judgement to use AI to improve real workflows and decisions. On third-party and cloud AI, the honest answer is that it is hard: lean on your existing outsourcing and technology-risk discipline, test the vendor's model on your own terms, and keep a fallback for anything mission-critical.
Watch the full webinar
The full session, including the Q&A on underwriting judgement, third-party and SaaS AI, cloud risk, and what internal auditors need to know, is on the Singapore College of Insurance channel. My thanks to the SCI for hosting.
Work with me
I train and advise insurers and other financial institutions on the AIRG and on turning it into a working system - see the AIRG in practice and AI risk management for risk and compliance. See the courses and workshops, or get in touch.