Your AI Is Creating New Risks. Is Your Auditor Looking for Them?

By Johnsey John, Security Analyst

Audit
Digital Services
Insights

September 3, 2026

Share this page

AI is already embedded across re/insurance business processes, often through tools used every day by employees, suppliers and third parties. That creates a new challenge for insurers: can they demonstrate that their use of AI is governed, controlled and auditable?

Step in ISO/IEC 42001:2023 – the world’s first certifiable international AI management system standard – which is providing an invaluable benchmark. Crucially, it does not tell organisations how to build AI; it would be out of date as soon as it was published if it did. Instead, it defines how AI should be governed. For auditors, the focus is therefore not on understanding algorithms or interrogating code. It is on governance, process and evidence. 

Importantly, ISO/IEC 42001 does not separately distinguish between large language models (LLMs) and agentic AI. It frames its requirements around AI systems more broadly. An organisation can define the scope of its AI Management System (AIMS) to include LLM-based systems, agentic AI systems, both together, or selected AI use cases according to its business context. 

The standard therefore applies collectively across the AI systems that fall within that defined scope, while the controls applied to individual systems should reflect their particular risks, impacts and use cases. An autonomous or agentic AI system, for example, may require different levels of oversight and control from a conventional generative AI tool, but both sit within the same overarching governance framework. 

For re/insurers, that changes the audit conversation: you need to know whether AI risk is understood. We test whether it is. AI introduces risks that conventional control frameworks may not have been designed to address in that specific technology context: bias, inaccuracy, misuse, inappropriate autonomy and dependency on third-party providers.  ISO/IEC 42001 requires organisations to assess AI-related risks and perform AI impact assessments where appropriate, with greater depth and scrutiny applied to higher-risk AI systems. 

More than a tick-box exercise 

An AI policy on its own is not enough. Auditors need evidence that the risks have been identified, ownership is clear and controls operate in practice. Re/insurers need control over AI before it reaches production – and we look for evidence of that. 

Governance has to survive contact with the real world. That means looking at how AI systems were assessed before deployment, implementing documented controls, managing AI throughout their lifecycle and scrutinising external AI providers. 

Significantly, ISO/IEC 42001 puts supplier and third-party oversight within the operational control environment. For insurers increasingly dependent on technology ecosystems, that provides a useful framework for a recurring challenge and reinforces an important principle: procuring an AI capability from a supplier does not transfer accountability for governance, risk management or regulatory compliance. 

As part of third-party vendor and supplier due diligence, organisations should establish whether a provider uses AI systems to deliver its services, including subcontracted, embedded or downstream AI tools. They should understand whether company or client data is processed by those systems and, critically, whether that data is stored, retained, shared or used to train, fine-tune or otherwise improve AI models. 

That due diligence should be backed by clear contractual controls covering data protection, confidentiality, retention and deletion, use of subprocessors, incident notification and restrictions on unauthorised AI use. 

For auditors, the evidence should be tangible. For example, an auditor can review the organisation’s vendor or supplier due-diligence template to confirm that it asks whether AI is used in service delivery, whether company data is processed by AI systems, what happens to that data, and what contractual and technical safeguards are in place. Where AI is identified, auditors can then test whether the organisation has appropriately assessed the associated risks and followed through with proportionate controls. 

Re/insurers also need to know what their AI can see. The critical role that audit plays is to actively challenge who can access what – and whether they should. After all, AI tools are only as safe as the data they can reach. 

Access should therefore follow least-privilege principles. Permissions need regular review. Role-based access controls should ensure that user permissions are aligned to business roles and reviewed regularly. And client data should not be accessible to consumer or unapproved AI tools by default. 

For agentic AI, this question becomes even more important. An agent may be able not only to access information but also to take actions across connected systems. Auditors should therefore consider what permissions an agent has, what actions it can perform, where human approval is required, how its activity is logged and whether effective safeguards exist to prevent unintended or unauthorised actions. 

This is not theoretical AI governance. It is fundamental data and access control. Re/insurers also need visibility over the AI they did not approve. We look for what sits outside the framework. 

Shadow AI: a modern reality 

Perhaps the most uncomfortable risk is shadow AI. ISO/IEC 42001 governs AI within a defined scope. If employees use unapproved AI tools outside that scope, those systems may operate outside established governance, risk management and monitoring processes. 

The same issue can arise where AI is embedded inside a supplier’s service without the organisation being fully aware of it. That is why visibility across both internal and third-party AI use is so important. 

Auditors should be asking whether organisations maintain approved-tool registers, enforce acceptable-use policies, deploy controls to detect unapproved tools, assess AI use within their supply chain and record AI-related incidents. 

That is the real shift. AI is not just changing how insurers operate. It is changing the scope of what needs to be audited. Whether the technology is an LLM, an agentic AI system or an AI capability embedded deep within a supplier’s service, the fundamental question remains the same: how confidently can you say that your AI estate is visible, governed and controlled? 

Pro Global brings the audit discipline to find out. Get in touch to have a conversation: getintouch@pro-global.com 

Get in touch

To speak to the Pro Global team please feel free to reach out to us at:

Lysander PR

To contact our PR team directly please use the link below

Pro Global Contact Form

Please fill out the following form so that we can connect you with the specialists best suited to your enquiry.

Pro Global Newsletter

By filling in the following form you are agreeing to receive our newsletter and industry relevant communications