Artificial intelligence is becoming increasingly embedded across the insurance value chain, creating significant opportunities for innovation, efficiency and improved decision-making. At the same time, AI introduces new governance, operational, conduct and third-party risks that require effective oversight.

This CRO Forum paper offers guidance on AI governance and compliance for insurers. It considers the implications of the EU AI Act alongside leading international frameworks, including NIST, ISO/IEC 42001, MAS FEAT and Hong Kong supervisory expectations, and translates these requirements into practical governance considerations for the insurance sector.

Building on established risk management principles rather than specific technologies, the paper examines key topics such as AI risk classification, lifecycle governance, the role of the Three Lines Model, Board oversight, AI risk appetite, agentic AI, third-party dependencies and the growing use of AI within the risk management function itself.

The paper is intended as a governance, compliance and risk management guide for CROs and risk professionals seeking to support the responsible adoption of AI while maintaining appropriate oversight, operational resilience and customer protection.

A separate CRO Forum best practice paper, providing more detailed implementation guidance, practical examples and lessons learned for insurers, is planned for publication at a later stage.

Download publication(s)