Vendor Credentials
What Certifications Should an AI Governance Consultant Have for Insurance Clients?
A grounded look at which professional certifications and standards actually signal AI governance competence for insurance work, and which ones are marketing.
No regulator names a single required personal certification for AI governance consultants serving insurers. NAIC's Model Bulletin instead requires a documented governance program run by qualified personnel. The credentials that most credibly demonstrate that qualification today are IAPP's AIGP, ISACA's AAIA and AAIR designations, and EXIN's AI Compliance Professional, which maps to ISO/IEC 42001 and the EU AI Act.
regulatory context
What Insurance Regulators Actually Require
No state insurance department and no NAIC model act names a required personal certification for the person overseeing an insurer's AI governance work. What they require instead is a documented program. The NAIC's Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted by the NAIC in December 2023 and since adopted in similar form by more than a dozen state insurance departments, directs insurers to maintain a written AI program with accountable senior management, documented risk management practices, and ongoing monitoring of AI systems used in underwriting, pricing, claims, and marketing.
That structure matters for how to read a consultant's credentials. The bulletin asks for qualified personnel and a governance program that can withstand a market conduct exam, not a specific badge. The certifications below are the closest things the market has produced to a credible, third-party-verified signal of that qualification, and each is worth understanding for what it actually tests, not just its name.
certifications
The Certifications That Actually Map to This Work
IAPP's AIGP (Artificial Intelligence Governance Professional)
The IAPP, a policy-neutral nonprofit founded in 2000 that also administers the CIPP and CIPM privacy certifications, launched AIGP as a dedicated credential covering AI governance frameworks, risk assessment, and cross-border AI regulation. It is the closest thing to a generalist AI governance credential with real exam rigor and a maintained study guide, and it is the one most consultants advising on the NAIC bulletin's accountability and documentation requirements are likely to hold.
ISACA's AAIA, AAIR, and AAISM
ISACA, the body behind the long-established CISA and CRISC audit and risk certifications, has added three narrower AI credentials: AAIA (Advanced in AI Audit), AAIR (Advanced in AI Risk), and AAISM (Advanced in AI Security Management). For a consultant whose insurance work centers on auditing a model's controls or scoring third-party AI vendor risk, an ISACA AI credential signals depth in that specific lane rather than AI governance generally.
EXIN's AI Compliance Professional (AICP)
EXIN markets AICP as the certification that directly integrates the EU AI Act, ISO/IEC 42001, and the NIST AI Risk Management Framework into lifecycle-based compliance work, aimed at roles including AI compliance officers, risk managers, and data protection officers. For a US insurer with any EU exposure or a group-wide AI policy, a consultant holding AICP demonstrates fluency across the three frameworks most often referenced in a governance program document.
standards
ISO/IEC 42001 Certifies the Organization, Not the Consultant
ISO/IEC 42001 is an AI management system standard, the AI-specific counterpart to ISO 27001 for information security, and organizations pursue certification against it through accredited bodies such as BSI. That certification belongs to the insurer's own management system, not to an individual consultant. A consultant can be trained or lead-auditor qualified against ISO/IEC 42001, which is a legitimate and relevant credential to ask about, but a claim that a person is themselves personally ISO 42001 certified, in the way an organization is certified, should be treated as a red flag rather than a qualification.
industry fluency
Insurance-Specific Credentials Exist, But Check What They Actually Test
A newer category of insurance-specific AI credentials has entered the market. The Certified AI Insurance Credential (CAIC), launched in 2026 by a private company at getcaic.org, is a practitioner-fluency designation built around a nine-module curriculum, a capstone project, and a continuously refreshed curriculum, priced at $997 per individual. It is explicitly positioned as AI adoption fluency for insurance professionals, evaluating vendors and redesigning workflows, not as an accredited audit, risk, or compliance credential in the ISACA or IAPP sense, and it carries no accreditation body behind it.
That distinction matters when vetting a consultant. A fluency credential is a reasonable signal that someone has structured knowledge of how AI is being adopted in insurance specifically. It is not a substitute for the accredited governance, audit, or compliance credentials above when the engagement's real deliverable is a program document that has to survive a state market conduct exam.
evaluation questions
What to Actually Ask a Consultant Before Hiring
1. Which specific credential do they hold, and what does it actually test?
AIGP, AAIA, AAIR, AAISM, and AICP each test a different slice: general governance, audit, risk, security, or lifecycle compliance. Ask which one and why it fits your engagement, not just whether they are AI certified.
2. Can they name the NAIC bulletin's actual requirements, not just AI governance in general?
A consultant fluent in your regulatory exposure should be able to describe the accountable-officer, documentation, and monitoring requirements in the bulletin your state adopted, not a generic AI governance framework.
3. If they cite ISO/IEC 42001, whose certification is it?
The certification applies to a management system, typically the insurer's or a vendor's. A consultant should be clear about whether they hold personal training against the standard or are proposing to help your organization pursue certification against it.
4. Is a fluency credential being presented as a compliance credential?
A credential like CAIC is a legitimate insurance-AI-fluency signal, but if it is the only credential offered for governance, audit, or compliance work, ask what accredited credential backs the actual deliverable.
kriv fit
Where Kriv AI Fits
Kriv AI is a boutique AI governance and implementation firm, not a credentialing body, and we do not claim a personal certification we have not earned. Our engagements are built to satisfy the substance behind the credentials above: a documented AI governance program with accountable ownership, risk classification, and monitoring that maps to the NAIC bulletin your state has adopted, drawing on the same frameworks, ISO/IEC 42001, the NIST AI RMF, and the EU AI Act where relevant, that AIGP, the ISACA AI credentials, and AICP are built around.
See our companion pages on AI governance consulting for insurance companies and NAIC AI model governance for how that program work is structured end to end.
get a quote
How to Get a Real Quote
Engagement cost depends on how many AI systems and lines of business are in scope and whether the work is a one-time governance-program build or ongoing oversight. Kriv AI's enterprise and regulated engagements start at a $200 per hour floor, with specialized model-risk and compliance advisory at $400 to $700 per hour, against an $8,000 minimum engagement. See our AI governance consulting cost breakdown for the full rate structure, or book a discovery call to scope your specific lines of business.
Sources
Cited sources
- NAIC, Model Bulletin on the Use of Artificial Intelligence Systems by Insurers
- IAPP, AIGP: Artificial Intelligence Governance Professional certification
- ISACA, AAIA (Advanced in AI Audit) certification
- EXIN, Artificial Intelligence Compliance Professional (AICP) certification
- BSI, ISO/IEC 42001 Artificial Intelligence Management System
- Certified AI Insurance Credential (CAIC)
Straight answers
Frequently asked questions about What Certifications Should an AI Governance Consultant Have for Insurance Clients?
What certifications should an AI governance consultant have for insurance clients?
No regulator names one required certification. NAIC's Model Bulletin requires a documented governance program run by qualified personnel, and the credentials that most credibly demonstrate that qualification today are IAPP's AIGP, ISACA's AAIA and AAIR designations, and EXIN's AI Compliance Professional.
Is ISO/IEC 42001 a personal certification a consultant can hold?
No. ISO/IEC 42001 is an AI management system standard that an organization, not an individual, gets certified against through an accredited body such as BSI. A consultant can be trained against the standard, but should not claim to be personally ISO 42001 certified.
What does ISACA's AAIA credential actually test?
AAIA, Advanced in AI Audit, tests the ability to audit AI systems' controls, consistent with ISACA's longer-standing CISA and CRISC audit and risk credentials. ISACA also offers AAIR for AI risk and AAISM for AI security management.
Is the Certified AI Insurance Credential (CAIC) a compliance certification?
No. CAIC is a private, for-profit fluency credential for insurance professionals adopting AI, covering vendor evaluation and workflow redesign. It is not an accredited audit, risk, or compliance credential in the way ISACA's or IAPP's designations are.
Does the NAIC Model Bulletin require a specific certification?
No. It requires insurers to maintain a documented AI governance program with accountable senior management and ongoing monitoring. It does not name a required personal certification for the people running that program.
How much does AI governance consulting cost for insurers?
Kriv AI's enterprise and regulated engagements start at a $200 per hour floor, with specialized model-risk and compliance advisory at $400 to $700 per hour, against an $8,000 minimum engagement.
Talk to the team that would do the work
Bring your requirements to a working session with the person who'll actually deliver.
Book a Discovery Call