Partnerships · D&O and cyber

AI governance as an underwriting signal

Applications ask whether the insured uses AI. They do not ask anything that distinguishes an insured with an inventory, a named owner and an incident path from one with none — and those two are not the same risk.

The gap

D&O and cyber policies are being written against AI exposure today. The underwriting question set has not caught up: most applications reach a single yes/no about AI use, which separates almost nobody from anybody.

Loss-control teams face the same problem from the other end. There is no accepted standard for what good AI governance looks like at a mid-market insured, so there is nothing to recommend, nothing to require at renewal, and nothing to measure improvement against.

Meanwhile the pressure is arriving from above. Reinsurers are beginning to ask for AI risk data that cedants cannot produce, because nobody collected it in a comparable form.

What NEUBoard has

  • A published instrument, not a proprietary black box

    The Fiduciary AI Scorecard™ scores five pillars across 22 criteria, each with observable levels. The rubric is published and travels with every report, because an underwriting signal that cannot be explained to the insured is not usable at renewal.

  • Board-oriented, which is where D&O exposure actually sits

    The instrument measures governance and oversight, not model quality. That is the layer a D&O claim turns on: what the board was told, when, and what it did.

  • Independent of every AI vendor

    NEUBoard sells no AI product and takes no vendor sponsorship. Where a commercial relationship exists with any party relevant to an assessment, it is disclosed before the engagement rather than discovered afterwards.

  • A two-week instrument, not a six-week one

    The Regulatory Exposure Snapshot produces a scored inventory and exposure map in two weeks at a fixed fee, which is the cadence loss control can actually work at.

Three ways this could work

Set out plainly so the conversation can start at the structure rather than at the introduction. None of these is running yet.

Referral

You recommend a Snapshot or Assessment to policyholders in AI-exposed sectors. The policyholder engages and pays; you may credit premium against it. Lowest friction, no contractual entanglement, and the insured owns their own findings.

No fee to the insurer Simplest to start

Loss control

You commission assessments of selected policyholders at underwriting or renewal. The assessment is yours; the policyholder receives a summary and a remediation list. Gives you comparable data across a book rather than anecdotes.

Per-assessment fee Book-level data

Instrument licence

You license the question set and rubric for your own application or loss-control process, with NEUBoard as the scoring engine and escalation route for complex risks. Highest integration, longest lead time.

Annual licence Longest to stand up

The pilot we would propose

ScopeTen policyholders in one AI-exposed sector, selected by you.
MethodA Snapshot on each: scored inventory, exposure map, Pillar 1 score. Identical instrument every time, so the ten are comparable to each other.
The questionDoes the Scorecard result correlate with what the insured told you on the application? If it does not, that is the finding, and it is worth more to you than a flattering result.
OutputAn anonymised comparison across the ten, each insured's own report to them, and a written view on whether the instrument is usable in your process.
CommercialsRun at cost. The data is what makes it worth doing for us, and we would want to publish the method — not the insureds — afterwards.

What we would want settled first

Independence. The instrument's value to you depends on it not being an AI vendor's marketing. We take no vendor sponsorship. Any commercial relationship bearing on an assessment is disclosed in advance, and we would expect that written into any agreement.

Who the assessment belongs to. Under referral it is the insured's. Under loss control it is yours and the insured gets a summary. That difference changes what people tell us, so it has to be decided before the first engagement rather than after.

What the score is and is not. It is an advisory assessment of governance practice against a published rubric. It is not a prediction of loss, not an audit, and not a legal opinion. Underwriting decisions remain yours — a score that influenced a declination would otherwise be challenged, and we would rather that argument never start.

Timelines. Insurance moves at treaty speed. We are not planning revenue against this in 2026 and would rather have the structural conversation properly than a fast one.

Worth a conversation?

The useful first call is thirty minutes on whether the instrument fits your process at all. If it does not, that is a short call and a useful one.