LawQi

Module 7.2 · Topic 3

Best Practices for Maintaining Coverage

Bottom Line Up Front: Coverage maintenance is an action problem, not a knowledge problem. Your insurer does not care what you know about AI risk; they care what you do about it. Implement documented practices for…

3.1 Protection Strategies and Documentation

Insurance carriers increasingly condition coverage on evidence of documented protection strategies. You must be able to show that you have thought through AI risks in your practice and implemented systematic responses. Here is the documentation process carriers expect:

  1. Document Your AI Use Policy: Create a written policy describing which AI tools your firm uses, which are prohibited, and under what circumstances AI use is permitted. The policy should address: permitted tools and use cases, prohibited tools or contexts (e.g., "no generative AI for confidential client information without explicit approval"), training requirements, verification requirements, and disclosure obligations. This document is your foundation; insurers will ask for it at renewal.
  2. Create Verification Procedures by Context: Define verification procedures for high-risk uses (e.g., legal research outputs, citation verification, fact statements) and lower-risk uses. For high-risk uses, your procedure should specify: review steps, quality checkpoints, approval workflows, and escalation criteria. Document that these procedures are in place and provide examples of how they are applied.
  3. Document Training and Competence: Maintain records of AI competence training delivered to your team, including dates, content, attendees, and competence assessments. Insurers look for evidence that your team understands AI capabilities and limitations before relying on AI in client work. Create an annual training cycle, not a one-time event.
  4. Maintain Client Engagement Records: When you use AI in client work, document your disclosure to the client. This might be a checkbox on your engagement letter ("we may use AI-assisted research and drafting, subject to our verification procedures"), a project-specific disclosure, or a consent form. The point is to create a record that you disclosed AI use and the client understood the context.
  5. Create a Data Governance Map: For each AI tool you use, document: what client data enters the system, what data governance agreements you have with the vendor, what happens to data after use (deletion, retention, reuse), and what access controls protect the tool from unauthorized use. This map demonstrates that you understand your confidentiality obligations.
  6. Track and Review Incidents: If an AI system produces an error that you catch in your verification process, document it: what was the error, how did you catch it, what did you do to prevent recurrence? This incident log demonstrates that your verification process works and that you learn from near-misses. Insurers value firms that track and remediate incidents.

3.2 Risk Assessment Frameworks for Insurance Compliance

Carriers increasingly look for evidence that you assess AI risks using recognized frameworks. Two frameworks have emerged as carrier-acceptable standards for legal practice: the NIST AI Risk Management Framework and ISO/IEC 42001. Understanding these frameworks helps you structure your risk assessment in a way that carries credibility with insurers.

Framework Core Structure Carrier Acceptance
NIST AI Risk Management Framework (AI RMF) Four functions: Map (identify AI systems and risks), Measure (assess risks quantitatively), Manage (implement controls), and Monitor (track effectiveness). The framework emphasizes continuous iteration and documentation of risk management decisions. Widely recognized by carriers. If you can document that you have mapped your AI systems, identified risks, implemented corresponding controls, and monitor effectiveness, you demonstrate the maturity carriers expect. The framework is non-prescriptive, so you can apply it at a scale appropriate to your firm.
ISO/IEC 42001 An international standard for AI management systems. It requires organizations to identify AI-related risks, implement controls, and maintain documentation of the management system. It includes requirements for roles, responsibilities, competence, and governance. Growing carrier acceptance, especially for larger firms. Certification under ISO/IEC 42001 signals to carriers that your AI governance is auditable and externally verified. Small firms may find formal certification expensive but can adopt the framework's structure informally.
Internal Risk Register (Firm-Specific) A documented inventory of AI risks your firm faces, mapped against the controls you implement. The register should identify: AI systems in use, business context (which practice areas), identified risks, implemented controls, residual risk, and responsibility assignments. Highly acceptable to all carriers. A clear, firm-specific risk register demonstrates that you have thought through the risks and taken specific action. This is often more persuasive to carriers than adopting an external framework, because it shows that you understand your own risk profile.

3.3 Verification Workflows That Satisfy Carrier Requirements

Demonstrating a verification workflow is increasingly a condition of coverage. The workflow must be documented, systematic, and proportionate to the risk. Here is how to create and apply a verification prompt that carriers recognize as adequate:

Logic behind this approach:

Verification is not binary (you either verify or you don't). It is contextual. High-risk outputs (citations in legal research, fact statements, legal analysis) require rigorous verification. Lower-risk outputs (organizational drafts, brainstorms, explanations of concepts) may require only spot-checking. A documented workflow that matches verification intensity to risk demonstrates competent risk management and is what carriers expect to see.

Sample prompt:

Review the following AI-generated legal research output. For each citation, fact statement, and legal conclusion, indicate: 1. Whether the cited source is a real, existing case, statute, or regulation (search the official source if uncertain) 2. Whether the page number cited, if specified, accurately locates the referenced material 3. Whether the factual summary is accurate to the source and not a hallucination 4. Whether the legal conclusion is supported by the cited source 5. Flag any statements that cannot be verified or that seem suspect Provide your verification checklist in the following format: [Citation/Fact]: [Source verified? Y/N] [Page accurate? Y/N] [Summary accurate? Y/N] [Conclusion supported? Y/N] [Notes] Use sources of record: official court databases, government websites, law.com, westlaw, lexisnexis, or direct source documents. Do not rely on the AI system's own citations or summaries for verification.

What to expect in reply:

The AI will produce a structured checklist identifying each element to be verified. Walk through the checklist manually for the most critical elements (final deliverables to clients, citations in court filings). For routine internal work, spot-check a sample. The point is that you have a systematic procedure, and you follow it. Document that you performed verification and maintain the verification checklist for your file. This documentation is what carriers want to see.

3.4 Communicating AI Practices to Insurers

Regular communication with your insurer about your AI practices keeps your coverage active and often unlocks better renewal terms. Here are the most effective communication approaches, with model tags indicating when each is best used:

  • Annual Compliance Report
    Fast/Chat

    Create a one-page summary (before renewal) documenting: AI tools your firm uses, verification procedures in place, training delivered during the year, and any incidents or near-misses your verification process caught. Send this proactively to your broker or insurer.

    Create a concise annual compliance report for our insurance broker summarizing our firm's AI use, risk management practices, and compliance actions during [year]. Include: (1) AI tools in current use and their business purpose, (2) verification procedures for high-risk AI outputs, (3) training completed and competence metrics, (4) security and data governance controls, (5) incidents or near-misses our verification caught, and (6) any changes planned for next year. Format as bullet points, maximum 1 page, audience: insurance broker.
  • Risk Assessment Template Exchange
    Thinking/Reasoner

    When your insurer proposes new conditions or a rider, respond by sending them your internal risk assessment (using NIST AI RMF or ISO/IEC 42001 framework) showing how your practices address the stated risks. This demonstrates sophistication and often shortens renewal negotiation.

    Using the NIST AI Risk Management Framework structure (Map-Measure-Manage-Monitor), create a concise summary of how our firm's AI risk management practices align with an insurer's stated concerns about verification procedures, data security, and training. For each concern the insurer raised, explain: (1) the risk they are concerned about, (2) the controls we have implemented, (3) how those controls are documented and monitored. Make it clear that we are managing the specific risks they care about, using a framework they recognize.
  • Policy Review & Renewal Questionnaire
    Fast/Chat

    Most insurers send a renewal questionnaire. Rather than providing minimal answers, use it as a communication opportunity. Provide detailed, documented answers that demonstrate your practices, and offer to provide supporting documentation (training records, policy excerpts, verification procedures). The thoroughness of your responses signals your maturity.

    Complete the following insurance renewal questionnaire thoroughly and with supporting documentation. For each question about AI use, verification, training, and security, provide: (1) a direct answer, (2) the specific practice or control you reference, (3) a supporting document (policy excerpt, training record, control checklist), and (4) contact information for anyone on your team the insurer might want to discuss further. Quality and specificity matter more than brevity.
  • Incident Reporting Protocol
    Fast/Chat

    If an AI error occurs (even if caught by your verification process), report it to your insurer promptly. Many insurers prefer early notice of near-misses over surprise claims later. This demonstrates transparency and often preserves better coverage terms.

    Draft a professional incident report for our insurance broker regarding a potential AI-related issue we identified and remediated. Include: incident date, AI tool involved, what happened, how we discovered it, what steps we took to prevent recurrence, and any client impact. Keep tone professional and factual, showing that we caught the issue, assessed it, and took corrective action.
  • Vendor Security Documentation Exchange
    Deep Research

    If your insurer asks about AI tools you use, provide documentation of your due diligence: data protection agreements with the vendor, security certifications, and your data governance procedures. This addresses carrier concerns about third-party risk.

    Compile vendor security documentation for our AI tools to provide to our insurance broker. For each AI tool in active use, gather: (1) data processing agreement or terms of service relevant to data security, (2) vendor security certifications (SOC 2, ISO 27001, etc.), (3) our internal data governance procedure for this tool, and (4) a summary of what client data, if any, enters this tool and how it is protected. Organize by tool, with a cover memo explaining your vendor risk management process.