The methodology behind the AI Insurance Readiness Score: domain architecture, the five-point maturity scale, the evidence model that underpins defensibility, the scoring approach, and the framework lineage that situates AIRS alongside NIST AI RMF, ISO/IEC 42001, the EU AI Act, and the NAIC Model Bulletin.
AIRS v1.1 was constructed to satisfy a single institutional requirement: produce, from observable evidence, a score that an underwriter can defend, a regulator can cite, and a counterparty can replicate. This page explains how each design choice in the specification serves that requirement.
Where the specification is the canonical reference, this methodology page is the institutional explanation: why five domains rather than three or seven, why a five-point maturity scale rather than a binary checklist, why the evidence model insists on artifacts rather than attestations, and how the composite score and tier mapping translate maturity into underwriting signal.
AIRS evaluates five thematic areas of AI security risk, each composed of five discrete factors. The domain set was chosen for disjoint coverage of the failure modes that drive insured loss in AI-dependent systems: model behavior, output liability, dependency exposure, regulatory posture, and continuity.
Whether the model itself behaves as the operator believes. Anchors the framework because every downstream domain inherits its assumptions from how the model was trained, versioned, and monitored.
Whether the operator can stand behind what the model produces. Maps directly to the loss vectors most frequently cited in early AI insurance claims: hallucination, bias, unauditable decisions, and unattributed content.
Whether the operator understands and controls the dependencies the model relies on. AI systems inherit risk from foundation-model providers, API surfaces, and sub-processors at a depth not contemplated by traditional third-party risk programs.
Whether the operator's posture aligns with the AI governance frameworks that carriers, reinsurers, and regulators are increasingly treating as the baseline of insurability. Designed to crosswalk cleanly to NIST AI RMF, ISO/IEC 42001, the EU AI Act, and emerging state AI laws.
Whether the operator has planned for the days when AI fails. Recovery architecture, drilled response plans, and continuity of AI-dependent workflows are the difference between an incident and a market-moving loss event.
Twenty-five factors total. Each evaluated on the five-point maturity scale defined in the next section.
Each of the twenty-five factors is rated on a five-point maturity scale rather than a binary checklist. Maturity scoring rewards the operational reality that a control's value scales with the discipline of its implementation: a documented policy is not the same as a tested process, and a tested process is not the same as a continuously monitored one.
No formal control. Activity is ad-hoc, informal, or absent.
Policy exists. Documented intent without consistent execution.
Control is in place and operating, with evidence of execution.
Control is tested, instrumented, and produces audit-grade output.
Control is continuously monitored and improved; failures are surfaced and remediated.
Maturity levels translate to factor scores of 1.0 through 5.0. Domain scores are the unweighted mean of their five factors.
The defensibility of an AIRS score rests on the artifacts that support it. Self-attestation alone is not sufficient evidence at any maturity level above two. The evidence model recognizes three categories of admissible artifact, and assessments must cite at least one from each category to claim a maturity level of three or higher.
Written policies, standards, model cards, data sheets, vendor contracts, and governance charters that specify the intent and design of a control. Documentation establishes that a control was contemplated and approved, but does not establish that it operates.
Technical artifacts that show the control is wired into the operating environment: code-level guardrails, infrastructure-as-code definitions, monitoring rules, IAM policies, and key-management configurations. Configuration evidence proves intent has been translated into the running system.
Records that demonstrate the control has produced outcomes under real conditions: incident logs, tabletop exercise reports, audit findings, red-team results, drift alerts that fired and were resolved, and remediation tickets that closed against SLA. Observed behavior is the highest grade of evidence.
The evidence model is the single most consequential design choice in AIRS. It is what makes a score citable in an underwriting file and admissible in a regulatory review.
AIRS produces a single composite score on a 0–100 scale. The scoring formula is intentionally legible: a regulator, auditor, or counterparty can reproduce it from the spec without proprietary tooling.
Composite = Σ (Domaini × Weighti) × 20
Where Domaini is the unweighted mean of its five factor scores (1.0–5.0), and weights sum to 1.00 across the five domains.
An entity scoring an average of 4.0 across all five domains produces a domain-weighted mean of 4.0. Multiplied by 20, the composite score is 80 — the threshold for Tier 1, AI Insurance Ready. An entity averaging 3.25 across all domains produces a composite of 65 — the threshold for Tier 2, Conditionally Insurable. Scores below 30 fall into Tier 5, Uninsurable, where the entity is not eligible for coverage at the current assessment and is provided a roadmap to reach a higher tier. The minimum theoretical score is 20, achieved when every factor sits at maturity level 1.
See Section 7 of the specification for the complete formula, edge-case treatment, and the conformance criteria that govern how factor scores are derived from evidence.
Composite scores map to five rating tiers. The tier structure is the methodology's translation layer between maturity assessment and underwriting decision — designed to align with the decision architecture of institutional carriers and reinsurers.
| Score Range | Tier | Classification | Underwriting Signal |
|---|---|---|---|
| 80–100 | Tier 1 | AI Insurance Ready | Standard underwriting; preferred terms |
| 65–79.99 | Tier 2 | Conditionally Insurable | Coverage available with conditions or sub-limits |
| 50–64.99 | Tier 3 | Elevated Risk | Coverage requires remediation milestones or premium loading |
| 30–49.99 | Tier 4 | Remediation-Track | Conditional binder pending defined remediation |
| 0–29.99 | Tier 5 | Uninsurable | Not eligible for coverage at this assessment |
The theoretical minimum AIRS score is 20 (all factors at maturity level 1). Tier thresholds are fixed in the specification and do not vary by industry, jurisdiction, or assessor. Domain floor rule (v1.1): T1 requires a minimum domain score of 3.5; T2, 2.5; T3, 1.5. A subject entity cannot reach a tier whose domain floor is unmet on any single domain, regardless of composite. Boundary scores resolve to the higher tier.
AIRS is intentionally derivative. It does not propose a new model of AI risk; it operationalizes the consensus that the established AI governance frameworks have already produced, and translates that consensus into an underwriting-grade signal. The framework lineage is the methodology's defensibility argument.
AIRS Domain 4 (Regulatory Compliance) maps directly to NIST AI RMF. Multiple domain-1 and domain-2 factors operationalize specific RMF subcategories at the control level.
AIRS factors 4.2, 5.1–5.5, and the maturity scale itself draw on ISO/IEC 42001's AI management-system controls and continuous-improvement structure.
AIRS readiness factors crosswalk to the conformity assessment, transparency, and risk-management obligations imposed on high-risk AI systems under the Act.
The NAIC's expectations for AI use within insurer operations are directly reflected in AIRS factors 2.1–2.4 and the governance architecture of Domain 4.
AIRS distinguishes between three levels of assessment, each appropriate to a different institutional purpose. The specification defines the conformance criteria that govern when an AIRS score may be cited externally and what artifacts must be retained.
The free public calculator. Suitable for internal benchmarking, gap analysis, and remediation planning. Self-assessed scores must not be cited externally as conformant AIRS results.
A score produced by a qualified third-party assessor following the specification's evidence requirements. Suitable for underwriting submission and counterparty review.
A score that may be cited externally as an AIRS result. Requires Level-B assessment plus retention of evidence artifacts for the specification's audit period.
Section 9 of the specification defines the full conformance criteria, including assessor qualifications, evidence retention requirements, and the disclosure language required when citing an AIRS score externally.
AIRS is published as an open standard. Organizations may freely reference, implement, and build upon the methodology for internal risk assessment, underwriting, regulatory compliance, and academic research, provided that attribution is given and the standard version is cited.
AIRS Standards Body. (2026). AI Insurance Readiness Score Open Standard Specification (AIRS v1.1, Document Version 1.1). Editorial stewardship and methodology administered by AI Security Intelligence LLC. https://www.aisecurityintelligence.com/airs-v1-specification
(AIRS Standards Body, 2026, AIRS v1.1)
Reproduction or redistribution of the specification document in its entirety requires prior written permission from AI Security Intelligence LLC.
The methodology is published in full and free to reference, cite, and implement. The Standards Body receives correspondence from carriers, reinsurers, regulators, brokers, and peer bodies directly.
standards@aisecurityintelligence.com