Compliance Guide · Insurance
Solvency II and AI Model Risk: What Insurers Must Document
Solvency II already requires insurers to validate, document, and continuously monitor internal models under Article 44 and Articles 112-127, and these obligations extend to AI-driven underwriting, pricing, claims, and reserving models. What changes is the evidence: AI and agentic systems require model inventories, validation records, change logs, and audit trails that capture training data provenance, tool-call activity, and decision rationale, not just formulae and assumptions, and ongoing monitoring needs to detect drift on a near-continuous basis rather than through annual cycles alone.
Mapping Runtime Evidence to Solvency II Validation Reports
Runtime evidence should be structured to feed directly into the sections a Solvency II validation report already requires, rather than creating a parallel documentation track.
- 1
Tamper-evident logging
Captures model or agent inputs, outputs, tool calls, and intermediate decisions in a retrievable format suitable for supervisory review.
- 2
Extended model inventory fields
Adds training data provenance, prompt or version control, and permitted tool or action scope to standard Solvency II model documentation.
- 3
Change management logging
Records retraining, prompt updates, and configuration changes with the same rigor as existing model change policies.
- 4
Access and permission documentation
Records what systems and actions an AI agent is authorized to touch, as part of the internal control environment.
Documentation Artifacts Supervisors and Internal Audit Will Expect
- AI model inventory entries that record training data provenance and the tool or action scope permitted to any agentic component.
- Independent validation records showing the validation function is structurally separate from the team that built or deployed the model.
- Change logs that capture retraining events, prompt updates, and configuration changes with the same rigor as traditional model change policies.
- The ability to reconstruct an individual AI-assisted decision on request, including tool calls and intermediate reasoning steps.
- Ongoing monitoring thresholds and escalation triggers defined for AI-specific conditions such as output drift or anomalous tool use.
- Non-technical documentation summaries suitable for board and risk committee review and sign-off.
The Existing Model Governance Baseline
Solvency II does not need a separate AI regime to reach AI-driven models. Article 44 of Directive 2009/138/EC requires insurers to maintain an effective risk management system with a risk management function that covers underwriting, reserving, and the decisions models produce. Articles 112 through 127 govern internal models specifically and impose a "use test," meaning a model must be widely used and play a genuine role in the insurer's system of governance rather than sit alongside decision-making as a reference tool. Commission Delegated Regulation (EU) 2015/35 adds detail to this, requiring validation standards that cover methodology, assumptions, data quality, and known limitations, and a documented model change policy under which material changes are logged and, where significant, escalated to the supervisor. None of this is new. What is new is the type of model these obligations now have to reach.
Where AI and Agentic Systems Strain the Existing Template
Solvency II's validation standards were built for statistical and actuarial models with stable parameters that change infrequently and predictably. LLM-based or agentic AI systems behave differently. Their outputs can be non-deterministic, their behavior can shift after deployment through retraining or configuration changes, and agentic systems make tool calls and intermediate decisions that a traditional validation report never had to describe. Model inventories designed for actuarial models typically have no field for prompt or version history, no record of which tools or actions an agent is permitted to invoke, and no structure for capturing the decision chain behind a specific output. Ongoing monitoring requirements, written with periodic (often annual) validation cycles in mind, do not map cleanly onto systems that can drift between one validation date and the next. The audit trail expectation embedded in existing governance, meaning a clear record of who approved what and on what evidence, has to extend to AI decision rationale and intermediate reasoning steps, not just the final underwriting, pricing, or claims outcome.
The Use Test and Validation Independence Do Not Relax for AI
The use test raises a specific accountability question for agentic systems. If an AI agent is making autonomous underwriting or claims decisions rather than producing advisory output for a human to review, insurers need to be able to show how that model is embedded in genuine business decision-making and who is accountable for its outputs. Validation independence requirements apply equally: the function validating an AI model must be structurally separate from the team that built or deployed it, which means insurers need to define, in practical terms, who is qualified to independently review data lineage, drift metrics, or agent action logs, since this is a different skill set from traditional actuarial sign-off. Board and risk committee oversight obligations under Solvency II's governance rules extend to AI model risk as well, which means documentation needs an accessible layer that a non-technical board member can actually use to exercise oversight, not only a technical validation report.
Runtime Governance as a Compliance Enabler
Much of the documentation gap described above is a runtime problem before it is a policy problem: the evidence supervisors expect (agent identity, tool permissions, decision rationale, audit logs) has to be captured at the point the AI system acts, not reconstructed afterward from incomplete logs. Runtime governance platforms, including Trussed AI, focus on capturing agent identity, tool call activity, and permission enforcement continuously, and on maintaining audit logs that can be retrieved when an examination or internal review requires reconstructing a specific decision. This does not replace actuarial validation or supervisory judgment. It provides the underlying evidence that validation teams and boards need in order to satisfy the documentation obligations Solvency II already imposes.
Frequently Asked Questions
Does Solvency II explicitly regulate AI models?
Solvency II does not name AI explicitly. It regulates internal models generally under Articles 112-127 and Delegated Regulation 2015/35, so AI-driven models fall under existing obligations. EIOPA's published AI governance principles add expectations around proportionality and human oversight but have not been confirmed to be updated in the past 12 months for agentic systems.
Who should validate AI-driven actuarial models?
The same independence requirement that applies to traditional internal models applies here: the validation function must be structurally separate from the team that built or deployed the model, with defined roles for reviewing AI-specific evidence such as data lineage, drift metrics, and agent action logs.
How often must AI models be monitored under Solvency II?
Solvency II text does not specify a frequency for AI-specific ongoing monitoring, and practical thresholds are left to supervisory interpretation. Given AI's capacity for post-deployment drift, continuous or near-real-time monitoring is increasingly relevant compared with periodic annual validation cycles.
Solvency II Obligations That Extend to AI Models
The same articles that govern traditional internal models already reach AI-driven underwriting, pricing, claims, and reserving systems.
Article 44 Risk Management
Requires an effective risk management function covering underwriting, reserving, and model-related decisions, including those made by AI systems.
Use Test (Articles 112-127)
AI models used in genuine decision-making must be demonstrably embedded in governance, not treated as advisory-only outputs.
Validation Standards
Delegated Regulation 2015/35 requires documented methodology, assumptions, data quality, and limitations, independent of the model's development team.
Model Change Policy
Material changes must be logged and, where significant, notified to or approved by the supervisor, a requirement that extends to retraining and prompt updates.
Close the AI Documentation Gap in Your Solvency II Model Inventory
See how runtime governance can capture the agent identity, tool activity, and audit evidence your validation function needs.
Explore Runtime Governance