An AI risk assessment — also called an AI readiness assessment — measures how effectively you govern, manage, and document AI through an AI management system, typically against ISO 42001, the first international AI management system standard. For regulated firms, such an assessment is worth doing because regulators increasingly expect demonstrable AI governance, risk management, and oversight. ISO 42001 certification, however, is a separate, narrower decision.
Who This Is For
Chief information security officers, chief risk officers, chief compliance officers, chief actuaries, and model risk leaders at financial services and insurance firms who deploy AI in underwriting, claims, or lending decisions.
In Brief:
- Regulators hold AI deployers accountable under the NAIC Model Bulletin, New York’s DFS Circular Letter 2024-7, and existing fair lending duties — all of which are already in force.
- A readiness assessment measures your governance and documentation against ISO 42001 and identifies gaps before an examiner or a buyer finds them first.
- Certification is the narrower decision. It pays off mainly for firms that sell AI-enabled products or face procurement pressure from vendor questionnaires.
Twenty-four states and the District of Columbia have already adopted the National Association of Insurance Commissioners (NAIC)’s Model Bulletin on how insurers must govern AI use. And New York’s Department of Financial Services (DFS) currently expects proof of bias testing, not at some future compliance deadline. A regulator’s examiner might ask how you tested your AI underwriting model, or a prospect’s procurement team might send a vendor questionnaire with a line item for AI governance documentation. Either way, most mid-market insurers and banks can’t answer those questions yet.
An AI risk or readiness assessment shows where your organization stands relative to ISO 42001, the first international standard for managing AI. Whether that assessment should lead to formal ISO 42001 certification is a second, independent question, and for many organizations, building an effective AI governance program matters more than holding the certificate.
For financial services and insurance firms already operating under the NAIC Model Bulletin and New York’s Circular Letter 2024-7, the assessment is worth doing for almost everyone in scope. Below, we outline what the assessment evaluates, what regulators already expect, and how to tell whether you should also pursue certification.
What an AI Risk Assessment Evaluates, and Why ISO 42001 Is the Framework
An AI risk assessment is a gap analysis. It compares your AI governance, policies, controls, and documentation against a recognized standard, then produces prioritized recommendations for closing what’s missing.
The word “risk” undersells it, which is why some firms call the same exercise a readiness assessment. We use both terms interchangeably here. What gets evaluated goes well beyond risk in the traditional sense of likelihood and exposure: how AI decisions get made and reviewed, who holds authority to approve a model for production, what data feeds it, whether bias testing happens before deployment rather than after a complaint, and whether any of that is recorded. Readiness is the more accurate description of what you walk away knowing.
Together, the assessment and the standard provide a comprehensive framework for AI governance, compliance, and oversight in regulated industries. For these organizations, the standard is ISO 42001, the world’s first certifiable AI management system (AIMS) standard, published in December 2023.
ISO 42001 builds on the same management system structure as ISO 27001, so if you already hold that certification, the context, leadership, and planning clauses carry over largely unchanged. The new work sits in Annex A, comprised of 38 AI-specific controls covering everything from AI policy and internal organization to impact assessment, data governance, and third-party AI relationships. You can’t govern AI you haven’t inventoried, and shadow AI is often the first gap an assessment turns up. In short, ISO 42001 readiness comes down to closing those documentation gaps in practice.
The standard itself isn’t really the point — rather, it’s what an assessment against it tells you. Currently, most published information explains what ISO 42001 is, but little is offered about what a gap analysis against ISO 42001 reveals.
Mark Crabb, senior consultant with Centric Consulting’s Cyber, Risk, and Compliance Practice, says the documentation gaps are sometimes a greater challenge than control deficiencies. “Often, controls exist and are operating effectively,” he said. “However, a team can be performing the right activities every day and still face examination findings if those activities have not been formally documented.”
The assessment exists to find the gap between what your team actually does and what your team can prove it does. Sometimes, that gap is a genuinely missing control, and other times it’s a control that exists but was never documented well. You won’t know which you’re dealing with until someone checks. A framework is only worth measuring yourself against if someone is going to hold you to it. For regulated financial services and insurance firms, someone already is.
AI Governance in Regulated Industries: What You’re Already Accountable For
Insurance and banking regulators have long expected organizations to maintain documented governance, controls, and oversight for underwriting, pricing, and lending decisions. As AI enters those processes, regulators are extending the same expectations to AI systems. The mechanism is older than the technology, and AI hasn’t changed what a regulator can ask to see.
Insurance
The NAIC’s Model Bulletin on the Use of AI Systems by Insurers, adopted in December 2023, is in force in 24 states and the District of Columbia. It requires a written AI Systems Program covering governance, risk management, documentation, and internal audit — the same categories an ISO 42001 assessment measures. Behind the bulletin sits real examination machinery: The NAIC’s AI Systems Evaluation Tool is piloting across 12 states through 2026, giving examiners a standardized way to review how insurers govern AI.
New York goes further. Circular Letter No. 7 is already in effect with no future compliance deadline attached. It applies to New York insurers using AI in underwriting and pricing, and it requires pre-use, disparate-impact and proxy testing, with documentation available on request. Insurers cannot rely on a vendor’s claim that its model doesn’t discriminate. As the deployer, you own that determination. Bias that surfaces in an adverse underwriting decision is exactly the kind of algorithmic bias DFS wants documented before it reaches a customer.
The same expectation carries into claims. An AI system that flags, delays, or denies a claim is still governed by unfair claims practice law. If a policyholder receives an automated, adverse decision, insurers should provide the same notice and explanation that a human adjuster would.
“Examiners aren’t asking insurers to prove their AI is flawless,” says Shane O’Donnell, who leads Centric’s Cybersecurity Practice. “They’re asking for the paper trail: that testing happened, someone reviewed the results, and someone with authority signed off. Firms that scramble usually have the testing. They just never wrote down who looked at it.”
Banking and Financial Services
Like insurers, lenders don’t need a new AI-specific law to be on the hook. Long-standing model risk management practice and fair lending duties already cover AI used in credit and lending decisions (including the adverse-action notice that lenders owe a declined applicant).
For firms with EU exposure, the calculus is shifting but not disappearing. The EU AI Act names credit scoring and insurance as Annex III high-risk uses. Under the Digital Omnibus agreement reached in May 2026, those obligations are deferred from August 2026 to December 2027, so this is a future obligation with a known date, not an urgent one. Still, completing an assessment takes time. We advise using this extra time wisely. Firms that start now arrive at December 2027 with room to address what the assessment finds, not just to file it.
Beyond IT, chief risk officers, chief actuaries, model risk teams, and compliance teams all have a stake, and NY DFS expects oversight of the governance framework by board or senior management.
If the expectation already applies to you, the question isn’t whether to perform an assessment, but what the assessment should lead to.
Do You Need the Certification or Just the Assessment?
Every firm in scope should perform an assessment. What it doesn’t automatically decide is whether you choose to pursue certification.
The assessment points you toward one of two outcomes, and it isn’t a binary sales pitch. Most mid-market insurers and banks land in the first group: They deploy AI in regulated decisions but don’t sell AI-enabled products, and the assessment closes the gaps regulators are already asking about. A smaller group sells AI-enabled products, already fields vendor questionnaires it can’t answer, or wants third-party-verified differentiation. For them, certification is the next step.
A few mechanics are worth knowing:
- An accredited third-party certification body, rather than the assessor, issues ISO 42001 certification. The certification remains valid for three years and is subject to annual surveillance audits.
- Certification also requires more than earning a badge. Expect several months of implementation work, as well as an internal audit and management review of your own AIMS, followed by external Stage 1 and Stage 2 audits. This is a significant undertaking that builds on the assessment, not a mere formality that follows it.
- If you already hold ISO 27001 certification, the management system clauses carry over. Your ISO 42001 readiness really comes down to the AI-specific Annex A, documented in a Statement of Applicability that shows which controls you adopted and why.
An assessment often reveals gaps in the broader AI governance program behind the certification question. That’s usually where AI governance consulting work begins in financial services and insurance.
An assessment isn’t the priority for every firm. If your AI use is narrow, low-stakes, and internal with no regulatory exposure — or if you’re mid-migration to a new AI platform — sequence the assessment for after that work settles.
Not sure which path you’re on? Ask yourself the following:
- Does your firm sell an AI-enabled product or service to other businesses?
- Are vendor questionnaires or procurement reviews already asking for AI governance evidence you can’t produce?
- Do you want independent, third-party proof instead of internal documentation alone?
- Would third-party verification change how buyers or partners see your firm?
Answer “yes” to any of these, and certification deserves a serious look. Answer “no” to all four, and an assessment is the right next step.
Conclusion
AI governance in financial services and insurance is still young enough that most firms are writing their playbook as they go. The firms that get ahead of it are those whose AI and compliance programs weren’t built as two separate entities in the first place.
That’s the harder version of this work, but it’s also the more durable. A framework tells you what to check. It doesn’t tell you whether your AI behaves the way your documentation says it does. That gap is where the next round of regulatory attention is headed, in insurance, in banking, and eventually wherever AI touches a consequential decision about a person.
Start with the assessment. It’s what tells you whether ISO 42001 certification belongs on your road map at all.
Here’s what comes next if you want to go further. Centric’s GRC Services team already performs cyber risk assessments against NIST CSF, ISO 27001, and CIS Controls. They apply that same approach to AI risk assessments against ISO 42001.