Skip to content

AI Risk Management

Statement

ClaimGuard's AI risk-management posture is straightforward today because the production system has no external generative-AI integration in current scope. The product's detection-side ML components are internal on-VM services — pattern detectors and classifiers — not generative AI.

If and when an external generative-AI integration is introduced, the controls documented below become live; until then, this page describes the process by which such an integration would be evaluated, governed, and disclosed.

Implementation

Detection-side ML risks (in scope today)

Even though the production system has no external generative-AI integration, detection-side ML still has its own risk surface:

Risk Mitigation
False positive / false negative on detection Human reviewer is the decision-maker on every claim; detection output is labelled advisory.
Model drift over time as adversarial techniques evolve Periodic re-evaluation of the detection models against held-out claim sets; documented as a roadmap item before SOC 2 fieldwork.
Bias in training data Out of scope at current claim volume; should be on the roadmap for a regulated-customer engagement.

Process for any future external generative-AI integration

If an external generative-AI integration is introduced into production:

  1. Vendor review per Vendor management: data-retention, training-use clauses, security posture.
  2. Data-exposure assessment — what customer data leaves the ClaimGuard environment and under what protections.
  3. Subprocessor disclosure — the new vendor is added to Subprocessors before going live in production, with at least thirty days' notice to affected customers.
  4. Privacy notice update — the customer-facing Privacy notice is updated with the new AI use disclosure.
  5. Risk inventory — this page is updated with the risks specific to the new integration (hallucination, prompt-scope creep, prompt injection, training-on-prompts, etc.) and the corresponding mitigations.
  6. Customer notification — per the customer's contract.

What does not exist today

  • No standalone AI risk register — not needed at present scope.
  • No AI-specific incident-response runbook — covered by general Incident response.
  • No periodic external-vendor model-evaluation cadence — not applicable today.

Status

implemented — verified 2026-05-10. Detection-side ML risk is inventoried and mitigated by the human-in-the-loop pattern. No external generative-AI integration in current scope; the disclosure process for any future integration is documented.

Roadmap

  • Detection-model evaluation cadence — quarterly re-evaluation against held-out claim sets, scheduled before SOC 2 fieldwork.
  • AI risk inventory population — to be done if and when an external generative-AI integration is introduced.
  • Fairness / bias evaluation — before the first regulated-customer engagement.