Factor-level crosswalks between the AI Insurance Readiness Score and the four anchor frameworks that institutional adopters are accountable to: NIST AI RMF, ISO/IEC 42001, the EU AI Act, and the NAIC Model Bulletin.
AIRS is intentionally derivative. It does not propose a new theory of AI risk; it operationalizes the institutional consensus that has already formed across the four anchor frameworks listed below, and translates that consensus into an underwriting-grade signal. The crosswalks on this page are the receipts.
Each AIRS factor is mapped to the most directly analogous control, function, or article in NIST AI RMF, ISO/IEC 42001, the EU AI Act, and the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers. Where a factor draws from multiple frameworks, the closest reference is shown; the AIRS specification contains the full multi-source map.
AIRS draws its defensibility from alignment with four frameworks that already enjoy regulatory, contractual, or supervisory standing across the jurisdictions that matter most to insurers and reinsurers.
The U.S. National Institute of Standards and Technology's Artificial Intelligence Risk Management Framework. Voluntary, but widely cited in U.S. federal procurement, supervisory examinations, and underwriting guidelines.
The international management-system standard for artificial intelligence. The conformance basis for AI assurance audits and the closest analog to ISO 27001 in security posture.
Regulation (EU) 2024/1689. The first horizontal AI law with binding obligations on providers and deployers of high-risk AI systems, including risk management, data governance, transparency, and post-market monitoring.
The Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted in 2023 and now reflected in guidance from a majority of state insurance regulators. The principal U.S. supervisory expectation for AI use within insurer operations.
The crosswalks below identify the most directly analogous control or article for each AIRS factor. They are intended to support institutional adoption, not to assert one-to-one equivalence.
The NIST AI Risk Management Framework organizes AI governance around four functions — Govern, Map, Measure, Manage — each broken into categories and subcategories. AIRS factors map most heavily to the Measure and Manage functions, with Govern referenced primarily in Domain 4. The Framework's cross-cutting concept of trustworthy AI characteristics (validity, reliability, safety, security, accountability, transparency, explainability, privacy, fairness) underpins the AIRS factor selection.
| AIRS | Factor | NIST AI RMF Reference | Mapping Rationale |
|---|---|---|---|
| 1.1 | Adversarial robustness testing | MEASURE 2.7 | AI system security and resilience are evaluated and documented. AIRS 1.1 operationalizes this subcategory at the artifact level. |
| 1.2 | Output validation and guardrails | MANAGE 2.3 | Mechanisms are in place to supersede, disengage, or deactivate AI systems. AIRS 1.2 verifies the existence and exercise of validation mechanisms. |
| 1.3 | Model behavior monitoring | MEASURE 2.4 | Functionality and behavior of the AI system and its components are monitored when in production. |
| 1.4 | Drift and degradation detection | MEASURE 4.2 | Measurement results regarding AI system trustworthiness in deployment are informed by input from operators, users, and other domain experts. |
| 1.5 | Human oversight controls | GOVERN 3.2 | Policies and procedures define and differentiate roles and responsibilities for human-AI configurations and oversight. |
| 2.1 | Output disclosure and labeling | MEASURE 2.8 | Risks associated with transparency and accountability — as identified in the MAP function — are examined and documented. |
| 2.2 | Bias and fairness assessment | MEASURE 2.11 | Fairness and bias — as identified in the MAP function — are evaluated and results are documented. |
| 2.3 | Incident response and remediation | MANAGE 4.3 | Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents are followed and documented. |
| 2.4 | Data lineage and provenance | MAP 2.3 | Scientific integrity and TEVV considerations are identified and documented, including those related to representativeness of training data. |
| 2.5 | Explainability and interpretability | MEASURE 2.9 | The AI model is explained, validated, and documented, and AI system output is interpreted within its context. |
| 3.1 | Third-party model and dependency inventory | MAP 4.1 | Approaches for mapping AI technology and legal risks of its components — including third-party software and data — are in place, followed, and documented. |
| 3.2 | Vendor and supplier security review | MAP 4.2 | Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented. |
| 3.3 | Open-source and pre-trained model controls | MEASURE 3.2 | Risk tracking approaches are considered for settings where AI risks are difficult to assess using currently available measurement techniques or where metrics are not yet available. |
| 3.4 | Data supply chain integrity | MEASURE 2.10 | Privacy risk of the AI system — as identified in the MAP function — is examined and documented, with explicit attention to upstream data provenance. |
| 3.5 | Continuity and substitutability of AI components | MANAGE 2.4 | Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use. |
| 4.1 | AI governance program and accountability | GOVERN 1.1 | Legal and regulatory requirements involving AI are understood, managed, and documented. |
| 4.2 | Policy, standard, and control framework | GOVERN 1.2 | The characteristics of trustworthy AI are integrated into organizational policies, processes, procedures, and practices. |
| 4.3 | Risk register and treatment | MANAGE 1.2 | Treatment of documented AI risks is prioritized based on impact, likelihood, and available resources or methods. |
| 4.4 | External communication and disclosure | GOVERN 4.1 | Organizational policies and practices are in place to foster a critical thinking and safety-first mindset in the design, development, and deployment of AI systems. |
| 4.5 | Audit, assessment, and review cadence | MANAGE 4.1 | Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors. |
| 5.1 | Resilience to upstream provider disruption | MANAGE 2.2 | Mechanisms are in place and applied to sustain the value of deployed AI systems, including continuity considerations for foundational dependencies. |
| 5.2 | Concentration risk assessment | MAP 5.1 | Likelihood and magnitude of each identified impact on individuals, groups, communities, organizations, and society are documented, including impacts arising from concentrated dependencies. |
| 5.3 | Failover, degradation, and recovery procedures | MANAGE 4.2 | Measurable activities for continual improvements are integrated into AI system updates and include regular engagement with interested parties. |
| 5.4 | Tabletop exercise and incident rehearsal | MANAGE 4.3 | Incidents and errors are communicated to relevant AI actors, with evidence of exercised response. |
| 5.5 | Lessons-learned and continual improvement | GOVERN 6.1 | Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues, with continual improvement. |
ISO/IEC 42001 is structured as a management-system standard, mirroring the architecture of ISO 27001. Annex A enumerates 38 controls organized into nine themes. AIRS factors map most directly to Annex A controls, with the management-system clauses (Clauses 4–10) supporting AIRS Domain 4 (Regulatory Compliance) at the program level. The maturity scale used in AIRS borrows the continual-improvement structure of the ISO management-system pattern.
| AIRS | Factor | ISO/IEC 42001 Reference | Mapping Rationale |
|---|---|---|---|
| 1.1 | Adversarial robustness testing | A.6.2.4 | AI system verification and validation. Adversarial testing is the verification activity required by AIRS 1.1. |
| 1.2 | Output validation and guardrails | A.6.2.6 | AI system operation and monitoring. Output guardrails are the operational control that prevents nonconforming output from being released. |
| 1.3 | Model behavior monitoring | A.8.3 | Reporting of concerns. AIRS 1.3 verifies the existence and exercise of behavior-monitoring channels. |
| 1.4 | Drift and degradation detection | A.6.2.7 | AI system performance monitoring. Drift detection is the operational expression of performance monitoring. |
| 1.5 | Human oversight controls | A.9.3 | Processes for responsible use of AI systems. Human oversight is the principal responsible-use control under ISO 42001. |
| 2.1 | Output disclosure and labeling | A.7.4 | Information for interested parties. Disclosure of AI involvement to affected parties is the principal transparency obligation. |
| 2.2 | Bias and fairness assessment | A.7.3 | Documented impact assessment. Bias assessment is a core component of AI system impact assessment. |
| 2.3 | Incident response and remediation | Clause 10.2 | Nonconformity and corrective action. Incident response is the operational form of corrective action under the management system. |
| 2.4 | Data lineage and provenance | A.7.2 | Resources for AI systems — data. Lineage is the form of data resource control most directly cited in regulatory examination. |
| 2.5 | Explainability and interpretability | A.6.2.8 | AI system technical documentation, including the documentation needed to explain the model to relevant audiences. |
| 3.1 | Third-party model and dependency inventory | A.10.2 | Allocation of responsibilities — third-party relationships. The inventory is the prerequisite for any allocation of responsibility. |
| 3.2 | Vendor and supplier security review | A.10.3 | Suppliers. Security review is the principal supplier-management control for AI dependencies. |
| 3.3 | Open-source and pre-trained model controls | A.10.4 | Customer (and component) information. Controls over pre-trained components flow from the supplier-relationship clauses. |
| 3.4 | Data supply chain integrity | A.7.5 | Resources — assigning roles. Data supply integrity is the operational outcome of clearly assigned data-resource ownership. |
| 3.5 | Continuity and substitutability of AI components | A.6.2.5 | AI system deployment, including the substitutability and continuity considerations applicable at deployment. |
| 4.1 | AI governance program and accountability | Clause 5.1 | Leadership and commitment. Accountability for the management system rests with leadership under ISO 42001. |
| 4.2 | Policy, standard, and control framework | Clause 5.2 | AI policy. The policy clause is the canonical home for the policy-and-standard architecture. |
| 4.3 | Risk register and treatment | Clause 6.1 | Actions to address risks and opportunities. The risk register is the operational record of this clause. |
| 4.4 | External communication and disclosure | Clause 7.4 | Communication. External disclosure is the externally directed branch of the communication clause. |
| 4.5 | Audit, assessment, and review cadence | Clause 9.2 | Internal audit, supplemented by Clause 9.3 (management review) for the cadence dimension. |
| 5.1 | Resilience to upstream provider disruption | A.10.3 | Suppliers. Resilience is the continuity branch of supplier management. |
| 5.2 | Concentration risk assessment | A.5.3 | AI risk assessment. Concentration is a specific risk class within the assessment requirement. |
| 5.3 | Failover, degradation, and recovery procedures | A.6.2.5 | AI system deployment. Failover and recovery procedures are deployment-time controls. |
| 5.4 | Tabletop exercise and incident rehearsal | A.9.4 | Intended use evaluation. Tabletop exercises validate that intended-use boundaries hold under stress. |
| 5.5 | Lessons-learned and continual improvement | Clause 10.1 | Continual improvement. The continual-improvement clause is the structural source of the AIRS maturity scale. |
The EU AI Act imposes binding obligations on providers and deployers of high-risk AI systems. AIRS factors map most directly to the high-risk obligations of Chapter III (Articles 8–17) — risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, cybersecurity, quality management, post-market monitoring, and serious incident reporting. The general-purpose AI obligations of Chapter V (Articles 51–55) inform AIRS Domain 3.
| AIRS | Factor | EU AI Act Reference | Mapping Rationale |
|---|---|---|---|
| 1.1 | Adversarial robustness testing | Art. 15 | Accuracy, robustness and cybersecurity. Adversarial testing is the principal evidence of robustness. |
| 1.2 | Output validation and guardrails | Art. 15 | Accuracy and robustness, with reference to the technical solutions required to address foreseeable failures. |
| 1.3 | Model behavior monitoring | Art. 72 | Post-market monitoring by providers. Behavior monitoring is the operational core of the post-market obligation. |
| 1.4 | Drift and degradation detection | Art. 72 | Post-market monitoring with explicit attention to performance changes after deployment. |
| 1.5 | Human oversight controls | Art. 14 | Human oversight. AIRS 1.5 verifies the existence and exercise of the oversight measures required by Article 14. |
| 2.1 | Output disclosure and labeling | Art. 50 | Transparency obligations for providers and deployers, including disclosure of AI involvement and content labeling. |
| 2.2 | Bias and fairness assessment | Art. 10 | Data and data governance, including examination of possible biases that are likely to affect health, safety, or fundamental rights. |
| 2.3 | Incident response and remediation | Art. 73 | Reporting of serious incidents. AIRS 2.3 maps to the operational structure required to support Article 73 reporting. |
| 2.4 | Data lineage and provenance | Art. 10 | Data and data governance, with explicit obligations on data origin, collection, and preparation. |
| 2.5 | Explainability and interpretability | Art. 13 | Transparency and provision of information to deployers, including the interpretability characteristics relevant to deployer use. |
| 3.1 | Third-party model and dependency inventory | Art. 25 | Responsibilities along the AI value chain, requiring identification of upstream providers and components. |
| 3.2 | Vendor and supplier security review | Art. 25 | Value-chain responsibilities, including the assurance arrangements required between providers and downstream deployers. |
| 3.3 | Open-source and pre-trained model controls | Art. 53 | Obligations for providers of general-purpose AI models, including the documentation that flows downstream to deployers. |
| 3.4 | Data supply chain integrity | Art. 10 | Data and data governance, with provenance and integrity expectations applied across the supply chain. |
| 3.5 | Continuity and substitutability of AI components | Art. 16 | Obligations of providers of high-risk AI systems, with continuity expectations implied by the conformity assessment regime. |
| 4.1 | AI governance program and accountability | Art. 17 | Quality management system. Article 17 is the structural anchor for an AI governance program. |
| 4.2 | Policy, standard, and control framework | Art. 17 | Quality management, including the documented policies, procedures, and instructions required. |
| 4.3 | Risk register and treatment | Art. 9 | Risk management system. The register and treatment plan are the operational outputs required by Article 9. |
| 4.4 | External communication and disclosure | Art. 13 | Transparency and provision of information to deployers and, by extension, downstream affected parties. |
| 4.5 | Audit, assessment, and review cadence | Art. 43 | Conformity assessment, with audit and review activities required to maintain conformity over time. |
| 5.1 | Resilience to upstream provider disruption | Art. 25 | Value-chain responsibilities, including the continuity expectations implicit in upstream-provider relationships. |
| 5.2 | Concentration risk assessment | Art. 9 | Risk management system. Concentration is a risk class that the system must identify, assess, and treat. |
| 5.3 | Failover, degradation, and recovery procedures | Art. 15 | Accuracy and robustness, with the explicit expectation that systems are resilient to errors, faults, or inconsistencies. |
| 5.4 | Tabletop exercise and incident rehearsal | Art. 73 | Serious incident reporting, presupposing the existence of an exercised response capability. |
| 5.5 | Lessons-learned and continual improvement | Art. 72 | Post-market monitoring, with the continual-improvement loop required to feed back into the system over its lifecycle. |
The NAIC Model Bulletin sets supervisory expectations for U.S. insurers using AI systems. It is structured around four pillars: governance and risk management; testing and validation; data; and third-party AI systems and data. AIRS Domain 4 maps most heavily to the governance pillar, while Domains 1, 2, and 3 operationalize the testing, data, and third-party pillars respectively. The Bulletin is the principal supervisory frame for AIRS adoption by U.S.-domiciled insurers.
| AIRS | Factor | NAIC Reference | Mapping Rationale |
|---|---|---|---|
| 1.1 | Adversarial robustness testing | §4 Testing | Testing and validation pillar. Adversarial robustness is a specific testing modality required to evidence model integrity. |
| 1.2 | Output validation and guardrails | §4 Testing | Testing and validation, with explicit attention to the controls applied at decision boundaries. |
| 1.3 | Model behavior monitoring | §4 Ongoing Monitoring | Ongoing monitoring expectations within the testing and validation pillar. |
| 1.4 | Drift and degradation detection | §4 Ongoing Monitoring | Drift and degradation are specifically identified as monitorable post-deployment risks. |
| 1.5 | Human oversight controls | §3 Governance | Governance pillar, including the human-in-the-loop expectations applied to consequential decisions. |
| 2.1 | Output disclosure and labeling | §3 Consumer Protection | Consumer-protection expectations within the governance pillar, including disclosure of AI involvement. |
| 2.2 | Bias and fairness assessment | §3 Fair Treatment | Fair-treatment expectations are the principal NAIC anchor for bias and fairness assessment. |
| 2.3 | Incident response and remediation | §3 Risk Management | Risk-management expectations including incident-response procedures within the governance pillar. |
| 2.4 | Data lineage and provenance | §5 Data | Data pillar, including expectations on data sources, preparation, and lineage. |
| 2.5 | Explainability and interpretability | §4 Validation | Validation expectations include interpretability sufficient to support consumer-protection and fair-treatment review. |
| 3.1 | Third-party model and dependency inventory | §6 Third-Party | Third-party AI systems and data pillar. Inventory is a prerequisite for the third-party diligence the Bulletin requires. |
| 3.2 | Vendor and supplier security review | §6 Third-Party | Third-party diligence expectations, including the security and resilience review of upstream AI providers. |
| 3.3 | Open-source and pre-trained model controls | §6 Third-Party | Third-party expectations applied to open-source and pre-trained dependencies, where the insurer cannot rely on a contractual counterparty alone. |
| 3.4 | Data supply chain integrity | §5 Data · §6 Third-Party | Joint anchor across the data pillar and third-party pillar, since data dependencies are typically third-party in practice. |
| 3.5 | Continuity and substitutability of AI components | §6 Third-Party | Third-party pillar, with continuity and substitutability identified as concentration-risk mitigants. |
| 4.1 | AI governance program and accountability | §3 Governance | Governance pillar — the AI Systems Program (AISP) framework that the Bulletin requires insurers to maintain. |
| 4.2 | Policy, standard, and control framework | §3 Written Program | Written AI program expectations within the governance pillar. |
| 4.3 | Risk register and treatment | §3 Risk Management | Risk-management expectations within the governance pillar, evidenced by the register and treatment plan. |
| 4.4 | External communication and disclosure | §3 Consumer Protection | Consumer-protection and disclosure expectations within the governance pillar. |
| 4.5 | Audit, assessment, and review cadence | §3 Audit | Audit and review expectations within the governance pillar, including the cadence applicable to consequential AI use. |
| 5.1 | Resilience to upstream provider disruption | §6 Third-Party | Third-party pillar — provider-disruption resilience as a concentration-risk control. |
| 5.2 | Concentration risk assessment | §6 Third-Party | Third-party pillar, with explicit attention to concentration of AI dependencies across the insurer book. |
| 5.3 | Failover, degradation, and recovery procedures | §3 Risk Management | Risk-management expectations within governance, including documented response and recovery procedures. |
| 5.4 | Tabletop exercise and incident rehearsal | §3 Risk Management | Risk-management expectations supplemented by the audit cadence under §3 Audit. |
| 5.5 | Lessons-learned and continual improvement | §3 Audit | Audit and review expectations, with continual improvement implicit in the periodic review cycle. |
Three notes on how to read these crosswalks correctly in an institutional setting.
A high AIRS score does not, by itself, demonstrate compliance with NIST AI RMF, ISO/IEC 42001, the EU AI Act, or the NAIC Model Bulletin. AIRS measures readiness against an underwriting-grade aggregation of common controls; conformity to any specific framework requires that framework's own assessment regime. The crosswalks are intended to make adoption efficient — an organization that has implemented one framework will recognize most of what AIRS asks for — and to make assessment defensible by showing the lineage of every factor.
The crosswalk tables identify the single most directly analogous control or article. In practice, most AIRS factors map to multiple subcategories or articles within a given framework, and the AIRS specification documents the full multi-source map. Where institutional adopters require a more granular crosswalk for an audit committee or supervisory submission, the specification is the canonical source.
AIRS deliberately limits its primary crosswalks to four frameworks chosen for jurisdictional reach, supervisory weight, and conceptual coherence with insurance underwriting. Sector-specific guidance — such as banking-regulator AI guidance, healthcare AI rules, or model regulator guidance below the NAIC Model Bulletin level — operationalizes the same control concepts AIRS measures, and is typically reachable through the four anchors. The decision not to publish state-level or sector-overlay crosswalks here keeps the standard portable.
AIRS is published as an open standard. The crosswalks may be referenced and reproduced in part for institutional risk assessment, regulatory submission, and academic research, with attribution.
Reproduction or redistribution of the crosswalks document in its entirety requires prior written permission from AI Security Intelligence LLC.
70 pages. Full methodology, scoring rubrics, five rating tiers (T1 AI Insurance Ready through T5 Uninsurable), domain-floor rule, assessment process, and the regulatory crosswalk represented above in interactive form. Free. No form. No email required.
Download AIRS v1.1 (PDF, 194 KB)