---
title: "AI literacy in insurance: why actuarial competence isn't enough"
url: https://zerofive.ai/en/blog/compliance/ai-literacy-insurance-companies-training
canonical: https://zerofive.ai/en/blog/compliance/ai-literacy-insurance-companies-training
language: en
published: 2026-06-30
updated: 2026-09-23
author: "ZeroFive.AI"
tags: AI literacy, insurance, clause 7, agency network, IVASS
abstract: "The three roles needing individual evidence, the agency network as forgotten perimeter, and what to reuse from mandatory professional development."
---

# AI literacy in insurance: why actuarial competence isn't enough

**In short.** In an insurance company, AI training meets a workforce that already works with models, and that creates a false sense of coverage: actuaries know models, but the competence clause 7 requires concerns specific AI systems and how they affect people. The three roles needing individual evidence are those pricing life and health, those exercising human oversight, and those approving adoption. The agency network is the perimeter almost everyone forgets.

Insurance companies start ahead of other sectors, because a culture of modelling has always existed. That's also why AI training gets undersized: if there are actuaries in the building, the competence seems to be there already.

## Why actuarial competence doesn't cover the requirement

An actuary knows models better than anyone else in the company, and that doesn't answer what the standard asks. Clause 7 of ISO/IEC 42001 and Article 4 of the AI Act look at a different competence: knowing what a specific AI system does, recognising when its output needs checking, knowing who to report it to.

The gap shows on three points. The first is the perimeter of models: many systems in use today don't originate in the actuarial function, they arrive inside purchased software or from external suppliers. The second is the effect on the individual, which is the AI Act's lens rather than that of actuarial technique. The third is documentation, because competence has to be demonstrated with evidence tied to roles, and professional experience is not in itself evidence under clause 7.

## The three roles needing individual evidence

For most staff, awareness is enough. For three roles the evidence has to be named and tied to the specific system.

**Those working on life and health pricing.** Annex III of the AI Act classifies risk assessment and pricing in these lines as high risk. Anyone operating on those processes must recognise when the model sits outside its validity range and how a departure gets documented.

**Those exercising human oversight.** The Article 4 relief introduced by the Digital Omnibus concerns the general literacy level and doesn't touch competence obligations for these roles. Their evidence has to show the ability to intervene on that system, not attendance at a generic course.

**Those approving adoption.** Management, the risk committee, the actuarial function that validates. A signature without understanding moves the finding from clause 7 to clause 5 on leadership.

## The agency network, the forgotten perimeter

Clause 7.3 speaks of people working under the organisation's control, and in insurance that perimeter is wider than the payroll. Agents, sub-agents, agency staff and contracted brokers use quotation and support tools that embed AI, often supplied by the company itself.

Almost no training plan covers them, because the HR system the plan is built from stops at employees. The auditor notices indirectly, spotting that someone met during the visit appears in no record.

Two instruments work here: competence requirements in network agreements, and including the network in the professional development paths already required by IVASS rules for intermediaries, where an AI module can be grafted on without creating a new framework.

## What to reuse and what to build

| Element | Already present in an insurer | What's missing for AI |
|---|---|---|
| Modelling culture | Yes, in the actuarial function | Extension beyond the actuarial function |
| Professional development for the network | Yes, under IVASS requirements | A specific module on systems in use |
| Model governance | Yes, for internal models | Extension to third-party models |
| Training on health data | Yes, through GDPR | Link to the AI systems processing it |
| Effectiveness verification | Quiz-based tests | Practical cases on real systems |

The heaviest row is the third. Many pricing and fraud models come from suppliers, and on those the company is a deployer with its own obligations, including ensuring whoever uses them has the competence to do so.

## The module no vendor can write

The useful part of the training requires information only the company holds: which systems are in production, which decisions they affect, which edge cases have emerged, who the contact is for anomalies, what happens after a report.

Thirty or forty minutes per system, prepared by whoever knows that system. It's also the material that shows, in an inspection or in litigation, that human oversight genuinely existed rather than living in procedures.

## Where to start

The prerequisite is the [AI system inventory](/en/blog/compliance/ai-system-inventory-iso-42001), which in an insurer has to be built looking at actuarial models already in use too, because the regulation's definition of an AI system is broader than commonly assumed.

From there you build the roles-competence matrix, described in [a roles-competence matrix for AI](/en/blog/compliance/roles-competence-matrix-ai), and separate awareness from verifiable competence. The full clause requirements are in [clause 7 explained without jargon](/en/blog/compliance/clause-7-iso-42001-explained).

The sector's regulatory picture is on the [AI governance for insurance companies](/en/sectors/insurance) page.

Our approach to building role-based tracks is on the [AI Training](/en/services/ai-training) page. To review your company's plan, you can [book an assessment meeting](https://calendly.com/fabiolalli/zerofive).
