Step 1 of 5Brief
01 · Guided scenario · Insurance

Read the scenario brief

Demo mode — sign in to save your work

Treat the assignment as a claims, pricing or fraud-support decision where false positives, vulnerable customers and fair treatment are material.

PRACTICE MODELoading

Restoring your saved mode and lab work…

INSURANCE WORKING CONTEXT

Insurance operating brief

AI supports pricing, claims or fraud activity where errors can delay payment, increase cost or unfairly flag customers.

Evidence bar
  • False-positive analysis
  • Vulnerability and manual-review controls
  • Complaint, override and redress monitoring
WEEKS 5–9

NIST AI RMF risk workshop

Produce a NIST AI RMF assessment and risk treatment recommendation for the pilot gate.

Practical output
NIST AI RMF Assessment · GOVERN Mapping · MAP Context Assessment · MEASURE Testing Plan · MANAGE Risk Treatment Plan · Model Card
FICTIONAL OPERATING ENTITY
INSURANCE ENTITYHarbour Mutual InsuranceBase training lab: Harbour Mutual Insurance
Produce a NIST AI RMF assessment and risk treatment recommendation for the pilot gate.

Harbour Mutual Insurance is piloting an AI assistant that analyses claim details and property images, then recommends fast-track, standard review or specialist investigation. Claims handlers review the recommendation and retain authority over payment and investigation decisions.

IN SIMPLE TERMS

The insurer wants AI to sort home-insurance claims into the right queue. A claims handler decides what happens next, but a false fraud signal or poor image assessment could delay payment.

KNOWN FACTS
  • The assistant processes claim forms, property images and fraud indicators
  • A third party provides the image-analysis model
  • The system recommends a claim-handling route but does not settle claims
  • Claims handlers can override the route and record a reason
  • Historical fraud labels and vulnerable-customer outcomes have not been independently validated
COMMERCIAL SIMULATION FILE

Inspect the evidence before you advise

The documents contain incomplete, conflicting and potentially unreliable evidence. Treat each claim according to its source.

OPERATING CONTEXT

AI supports pricing, claims or fraud activity where errors can delay payment, increase cost or unfairly flag customers.

COMMERCIAL PRESSURE

Claims leakage is above target and the sponsor expects the pilot to recover its cost within six months.

EXPECTED EVIDENCE
  • False-positive and customer-outcome testing
  • Vulnerability and manual-review controls
  • Complaint, override and redress monitoring
STEERING MEETING BRIEF

Conflicting demands, limited time, unclear ownership

Decision deadline
The steering committee meets in 10 working days. The launch slot will be lost if the decision is deferred beyond this meeting.
Budget constraint
Only GBP 28,000 remains in the assurance budget. Full independent testing was quoted at GBP 46,000, so the team must prioritise risk-based work.
Ownership gap
Product, Risk and Operations each believe another function owns final residual-risk acceptance. The governance charter is silent.
Executive sponsor

Approve now with post-launch monitoring; delay threatens the business case.

Risk partner

Do not approve until critical evidence gaps and the unnamed risk owner are resolved.

Operations lead

The existing manual process is already failing service targets and creates its own harm.

Supplier account director

The product is proven in comparable organisations, but bespoke evidence requires a paid assurance package.

OwnerClaims DirectorClassificationInternal

Shows the reporting lines and decision rights relevant to the proposed AI use.

Executive sponsor
Claims Director owns the business outcome and has requested the team to produce a nist ai rmf assessment and risk treatment recommendation for the pilot gate. The decision must be judged against false-positive and customer-outcome testing.
Delivery chain
Claims Director -> Product Director -> AI Product Owner -> Data Science Lead -> Operations Manager. Procurement manages the supplier; Information Security and Data Protection are consulted.
Approval ambiguity
The Product Director believes Risk accepts residual risk. Risk states that the accountable business executive must accept it. No committee terms of reference name the final approver.
Three lines
First line operates the system; second line sets policy and challenges risk; Internal Audit has not included the system in its current plan.
YOUR REVIEWER

Enterprise risk committee

Can the NIST GOVERN, MAP, MEASURE and MANAGE trail support a real release decision?

Start with evidence, not assumptions.

Record unknowns explicitly. Do not convert a supplier claim into a fact merely because it appears in the business case.