Only 4 insurers had AI decision-making body last year

Just 3 disclosed AI governance information

Financial authorities revised AI guidelines in June

Korea Insurance Research Institute warns FSS may use framework as inspection benchmark

[Image generated with ChatGPT]
[Image generated with ChatGPT]

AI is playing an expanding role in insurance underwriting, premium calculation and claims decisions — yet fewer than one in 10 domestic insurers have a dedicated decision-making body to manage AI-related risks, a new report has found. With financial authorities having tightened AI rules for the sector in June to require enterprise-wide risk management frameworks, researchers are calling on insurers to raise their oversight standards, starting with functions that directly affect consumer rights.

The Korea Insurance Research Institute published the report, titled "Revision of AI Guidelines in the Financial Sector and Response Tasks for the Insurance Industry," by researcher Son Min-suk in its KIRI Insurance Law Review on Monday.

According to the report, domestic insurers are still in the early stages of building AI governance. Citing a Financial Supervisory Service probe, the report found that as of April last year, of 118 financial firms, those that had established a decision-making body for AI governance were limited to five banks (25 percent), four insurers (7.5 percent) and one securities firm (2.7 percent).

Son also reviewed DART filings as of Aug. 3 and found that only six of the 37 full members of the Life Insurance Association of Korea and the General Insurance Association of Korea — 20 life insurers and 17 non-life insurers — had published sustainability reports. Of those, only two life insurers and one non-life insurer disclosed information on AI risk management governance. The report cautioned, however, that the presence or absence of a decision-making body or public disclosure alone is insufficient to gauge the actual level of risk management.

Against this backdrop, regulators have raised the bar. The Financial Services Commission in early June released consolidated "Financial Sector AI Guidelines," merging three existing guidelines and incorporating recent developments, including responses to ultra-high-performance AI. The Financial Supervisory Service followed with its own "Financial Sector AI Risk Management Framework." The shift marks a paradigm change — from setting principles for individual AI services to requiring a comprehensive risk management system covering governance, risk assessment, tiered controls and post-deployment monitoring.

The guidelines set out seven core principles for financial AI, including governance, legality and the requirement that AI serve only as a supplementary tool, and stipulate that high-risk AI must be used solely to assist human decision-making. Under the risk management framework, AI services are scored numerically; those reaching 50 points or above are classified as high-risk and subject to additional controls, including prior approval from the top decision-making body and third-party evaluation. While the framework carries no legal force, the report expects it to serve as a benchmark for assessing the adequacy of internal controls during FSS inspections.

Given the breadth of AI use in insurance, the report argues that oversight levels should be calibrated by function, since the impact on policyholders varies significantly across tasks — from product recommendations and underwriting to premium calculation, claims review and fraud detection.

"It is necessary to differentiate the level of control by considering both the degree to which AI is involved in the judgment and decision-making of employees and the extent to which the outcomes affect policyholders," Son said. "For functions with a significant impact on policyholder rights — such as underwriting and claims payment — meaningful human intervention should be strengthened, and consumers must be guaranteed explanations of decisions and access to appeal procedures."


won@heraldcorp.com