Step 5 of 5Evidence
05 · Practitioner output · Insurance

Create the RMF release recommendation

Demo mode — sign in to save your work

Your recommendation should show whether customer harm, fraud controls and redress evidence are strong enough for approval.

PRACTICE MODELoading

Restoring your saved mode and lab work…

INSURANCE WORKING CONTEXT

Write the insurance decision record

AI supports pricing, claims or fraud activity where errors can delay payment, increase cost or unfairly flag customers.

Evidence bar
  • Decision memo
  • Risk acceptance
  • Post-launch customer-outcome review
REVIEW CHECKPOINTS

NIST AI RMF Assessment

NIST AI RMF Assessment

Complete the fields against the insurance operating context. Your work saves automatically in this browser.

Write at least 20 characters of your own answer to unlock the review guide.

Write at least 20 characters of your own answer to unlock the review guide.

Write at least 20 characters of your own answer to unlock the review guide.

Write at least 20 characters of your own answer to unlock the review guide.

Write at least 20 characters of your own answer to unlock the review guide.

Loading saved answers…

ASSURANCE WORKPAPER

Test whether the controls actually operate

Move beyond policy design: define a population, select a defensible sample, test evidence, document exceptions and write the conclusion an audit committee would need.

01Define

Objective, population and period.

02Sample

Risk-based and representative items.

03Test

Inspect, observe and reperform.

04Conclude

Rate findings and communicate.

STRUCTURED ARTEFACT

Risk → control → evidence traceability

Build an auditable decision trail. A risk without a control—or a control without evidence—remains visible as a gap.

No traceability rows yet. Add the first priority risk and connect it to a control, test and evidence.

SCENARIO INJECT

The situation has changed

Choose an event and update the governance response as if the system were already operating.

NEW EVENT

Unannounced model change

The supplier upgrades the underlying model and cannot confirm whether prior validation remains representative.

The business wants to keep the original approval because users have not complained.

Write at least 40 characters to unlock the response criteria.

PRACTITIONER MATURITYLevel 1 · Initial

Work has started, but material evidence and ownership are missing.

Why this level?
  • Workflow is 0% complete.
  • Worksheet answer coverage is 0%.
  • No complete risk-control-evidence row is ready for review.
  • Rubric ratings are not yet consistently strong or competent.
READINESS GATENot ready
Workflow
0%
Answers
0%
Traceability
0 rows
Why this gate?
  • Workflow completion is 0%.
  • Answer coverage is 0%.
  • Add at least one traceability row marked ready for review.
TRAINER FEEDBACK

What to strengthen next

  • Name the affected people and explain the pathway from system behaviour to impact.
  • Assign an accountable human role; responsibility cannot sit with the AI system.
  • Define the evidence and acceptance criteria needed to support the conclusion.
  • Add post-deployment monitoring, escalation thresholds and a reassessment trigger.
SELF-ASSESS BEFORE EXPORT

Practitioner quality rubric

Rate the work honestly. “Needs revision” is a useful result when it identifies what to strengthen before review.

Context and scope

Strong: States the system, decision, actors, people affected, boundaries and material assumptions.

Improve: Avoid generic statements or conclusions that depend on unstated facts.

Risk reasoning

Strong: Links a credible cause and event to a specific impact, then assesses likelihood, severity and uncertainty.

Improve: Do not list harms without explaining how they could arise in this scenario.

Proportionate controls

Strong: Selects preventive, detective and corrective controls that address the identified risks and assigns owners.

Improve: Avoid control lists with no connection to a risk, trigger or responsible role.

Evidence and decision

Strong: Defines testable evidence, acceptance criteria, residual risk and a clear, conditional recommendation.

Improve: A confident conclusion is not defensible when evidence, thresholds or escalation routes are missing.

EVIDENCE-QUALITY GATES
Practitioner evidence pack

RMFAI

Harbour Mutual Insurance · Insurance overlay · NIST AI RMF risk workshop

Prepared by
Learner name not added
Course coverage
Weeks 5–9
Training simulation only · Fictional scenario and data

Executive assignment

Harbour Mutual Insurance is piloting an AI assistant that analyses claim details and property images, then recommends fast-track, standard review or specialist investigation. Claims handlers review the recommendation and retain authority over payment and investigation decisions.

In simple terms: The insurer wants AI to sort home-insurance claims into the right queue. A claims handler decides what happens next, but a false fraud signal or poor image assessment could delay payment.

Assignment: Produce a NIST AI RMF assessment and risk treatment recommendation for the pilot gate.

Sector overlay: Insurance

Decision pressure: The steering committee meets in 10 working days. The launch slot will be lost if the decision is deferred beyond this meeting.

Ownership gap: Product, Risk and Operations each believe another function owns final residual-risk acceptance. The governance charter is silent.

Known facts

  • The assistant processes claim forms, property images and fraud indicators
  • A third party provides the image-analysis model
  • The system recommends a claim-handling route but does not settle claims
  • Claims handlers can override the route and record a reason
  • Historical fraud labels and vulnerable-customer outcomes have not been independently validated

GOVERN Mapping

Governance and ownership
Not completed
Risk appetite and tolerance
Not completed
Supplier governance
Not completed
Approval gates and exceptions
Not completed

MAP Context Assessment

Intended use and business objective
Not completed
Foreseeable misuse
Not completed
People, legal, social and deployment context
Not completed
Priority risk scenarios
Not completed
Assumptions and dependencies
Not completed

Testing & Treatment Plan

Testing and evaluation plan
Not completed
Acceptance criteria
Not completed
Primary risk treatment
Not completed
Release controls
Not completed
Residual risk and owner
Not completed

NIST AI RMF Assessment

Pilot recommendation
Not completed
RMF assessment summary
Not completed
Model card release record
Not completed
Priority actions and dates
Not completed
Monitoring and improvement
Not completed

Assurance testing workpaper

Assurance objective
Not completed
Population and period
Not completed
Sampling approach
Not completed
Test procedure
Not completed
Exceptions and root cause
Not completed
Finding and severity
Not completed
Management action
Not completed
Board / audit summary
Not completed

Quality review and sign-off

Reviewer: Enterprise risk committee

Decision challenge: Can the NIST GOVERN, MAP, MEASURE and MANAGE trail support a real release decision?

Context and scope
Not rated
Risk reasoning
Not rated
Proportionate controls
Not rated
Evidence and decision
Not rated

Reviewer sign-off: ____________________   Date: __________   Version: 1.0

Prepared as a learning artefact. Validate legal and regulatory conclusions against current authoritative sources before real-world use.
TRAINER REVIEW

Sign in to submit this evidence

Demo work stays in this browser. A registered account can submit a fixed version to a cohort trainer.

Sign in or create account