AI risk management for insurers
Abstract
Artificial intelligence (AI) is rapidly reshaping the UK insurance sector, offering significant opportunities for efficiency, innovation, and improved customer outcomes. At the same time, AI introduces complex and fast-moving risks relating to model opacity, bias, data protection, consumer fairness, operational resilience, and third party dependency. This paper argues that AI does not constitute a wholly new category of risk for insurers; rather, it acts as a powerful amplifier of existing enterprise risks, increasing their speed, scale, connectedness, and potential impact. Drawing on regulatory guidance, industry practice, and emerging AI risk frameworks, the paper examines divergent stakeholder perspectives on AI adoption, including those of insurers, regulators, and consumers. It highlights a growing consensus that organisations must act now to integrate AI risk considerations into established enterprise risk management (ERM) frameworks, rather than relying on parallel or siloed AI governance structures. The paper proposes a principles-based practical approach for embedding AI risk within existing taxonomies, registers, and control environments, with particular emphasis on identifying where AI amplified prudential, conduct, data protection, resilience, reputational, and third party risks. Particular attention is given to the role of data protection impact assessments (DPIAs) as a critical governance mechanism for identifying and managing AI-amplified risks, aligned with UK regulatory expectations and international developments such as the National Institute of Standards and Technology (NIST) AI Risk Management Framework (RMF) and the forthcoming European Union (EU) Artificial Intelligence Act (AI Act). The paper concludes that insurers which proactively integrate AI governance into core ERM processes, supported by cross-functional collaboration between risk, compliance, data protection, and technology teams, will be best positioned to realise AI’s benefits while maintaining consumer trust, regulatory compliance, and resilience. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
The full article is available to subscribers to the journal.
Author's Biography
Dr Martha Phillips is Enterprise Risk Director for AXA UK. She specialises in enterprise risk management and operational risk, with a particular interest in risk culture, resilience, and artificial intelligence (AI) risk within regulated financial services environments. Martha is a recognised advocate for inclusive leadership, and her work bridges academic research and practical risk implementation within complex, consumer-facing organisations.
Michelle Gabay is Data Protection Officer at AXA UK, with over 25 years’ experience working in complex regulatory and compliance environments across financial services, pharmaceuticals, and local government. Michelle specialises in UK and European Union (EU) data protection law, privacy governance, and the implementation of sustainable compliance frameworks, including for artificial intelligence (AI) and emerging technologies. She is a regular speaker at industry forums and is recognised for her pragmatic, risk-based approach to privacy and regulatory change.
Citation
Phillips, Martha and Gabay, Michelle (2026, September 1). AI risk management for insurers. In the Journal of Risk Management in Financial Institutions, Volume 19, Issue 4. https://doi.org/10.69554/PWIL2278.Publications LLP