---
title: "AI Rating in insurance: the gate is the perimeter, not the process"
url: https://zerofive.ai/en/blog/strategy/ai-rating-insurance-perimeter-gate
canonical: https://zerofive.ai/en/blog/strategy/ai-rating-insurance-perimeter-gate
language: en
published: 2026-07-06
updated: 2026-09-23
author: "ZeroFive.AI"
tags: AI Rating, insurance, AI maturity, model governance, Annex III
abstract: "Solid validation processes on too narrow a perimeter. The three categories of systems left outside and what each class means."
---

# AI Rating in insurance: the gate is the perimeter, not the process

**In short.** In insurance, AI Rating measures the same four dimensions as always, and the profile that emerges differs from banking: Delivery tends to be high thanks to existing model governance, while Risk stays exposed on one specific point, the systems that arrived from outside the actuarial function and never passed through validation. The gate blocking the class isn't a lack of processes, it's the perimeter those processes apply to.

Insurers come to AI maturity measurement with a control framework more mature than almost any other sector. The result often surprises them, because the score doesn't reflect that maturity.

## The four dimensions through an insurance lens

**Readiness** measures preparation, data, skills, infrastructure. In an insurer it is generally good on portfolio data and weaker on unstructured claims data, which is exactly where the most immediate use cases concentrate.

**Delivery** measures the ability to reach production and maintain. It is the dimension where insurers sit above average, because the model lifecycle exists and works. The limit is that it applies to models recognised as such.

**Risk** measures governance, compliance and ethics. The gap concentrates here. Annex III touches the core of the business, IVASS supervision is already present, and the data processed is often health data under Article 9 of the GDPR.

**Confidence** measures management commitment, user trust and perceived robustness. In insurers it is often high within the technical function and low across the network, which uses tools without knowing what they do.

## The gate that closes: the perimeter, not the process

The recurring profile is this: solid validation processes, applied to a narrower set of models than the regulation counts as AI systems.

Three categories fall outside. Models bought from suppliers, where the company is a deployer and often has neither technical documentation nor visibility on updates. AI features switched on inside management software already in use, which nobody ever classified. Tools adopted by individual functions without passing through an adoption process.

Until the inventory covers those three categories, the Risk dimension stays below threshold however good the validation of internal models is. And since the gates are non-compensable, the final class drops to the level of the constraint.

## Which actuarial models fall within the definition

The most debated point in insurance assessments concerns which actuarial models fall within the regulation's definition of an AI system.

The definition is broader than the one insurers use internally, and the practical consequence is that some models long treated as actuarial tools may fall inside the perimeter. Deferring that classification doesn't reduce the risk, it moves it: if the assessment gets made by an authority rather than by the company, it arrives with no room to prepare.

The reasonable answer is to classify in writing, with the reasoning, including the cases where the conclusion is that a model stays outside. That documented reasoning is worth more than the conclusion.

## What a class means in practice

| Class | Typical situation in an insurer | What's reasonable to do |
|---|---|---|
| D | Systems outside the actuarial function unmapped, no extended controls | Build the complete inventory before new adoptions |
| C | Solid validation of internal models, incomplete perimeter | Extend model governance to third-party systems |
| B | Complete perimeter, evidence in place, some areas exposed | Prepare for audit and control Annex III systems |
| A | Mature system verified across all dimensions | Reserved for verified assessments, not self-assessments |

On that last row it's worth being explicit: a self-assessment does not produce a class A, because that class presupposes a structured verification with checked evidence.

## Why measure before allocating

An insurer in class C allocating budget to bring AI onto pricing pays twice: once for the project that won't clear the controls, and again to redo it once the gates are closed.

The same money, spent first on extending the perimeter, produces an organisation able to absorb subsequent projects. This is why rating belongs at the start of the planning cycle rather than as a final check on decisions already taken.

## Where to start

The prerequisite is the [AI system inventory](/en/blog/compliance/ai-system-inventory-iso-42001), built around the three categories usually left outside. From there you verify the role for each system and extend the risk assessment.

The full model, with the four dimensions and the gate logic, is described on the [AI Rating](/en/services/ai-rating) page. The sector's regulatory picture is on the [AI governance for insurance companies](/en/sectors/insurance) page.

For an assessment of your company's position you can [book a meeting](https://calendly.com/fabiolalli/zerofive) or [start the self-assessment](/en/start-ai-rating).
