MSCI Case Study Image

How MSCI secures its highest-risk AI agents with AIUC-1

Emil Lassen

When MSCI began deploying high consequence AI agents, CISO John Rogers needed a way to demonstrate that these agents could be trusted. He found that assurance in AIUC-1.

Challenge

  • MSCI developed a SecOps agent to streamline privileged access workflows that had potential implications for Sarbanes Oxley (SOX) compliance controls. MSCI needed to demonstrate that the agent could be trusted, not just a description of how it was meant to work.
  • Existing frameworks covered governance on paper. None tested how an agent actually behaved under pressure, or produced evidence an auditor could rely on.
  • MSCI expects to be running hundreds of AI agents within 18 months. To handle AI risk at this scale, Rogers needed an enterprise-wide framework based on risk tiers and calibrated assurance.

Solution

  • AIUC’s red team ran ~1,400 tests against the SecOps agent, validating its security, safety, and reliability against the AIUC-1 standard.
  • A signed evaluation attestation and detailed report were provided to MSCI’s external auditors as input to its 2026 SOX audit.
  • MSCI and AIUC developed a risk-tiering framework that maps AIUC-1 requirements to each tier, supporting a risk-based approach that focused controls in the right places.

MSCI’s indexes and portfolio analytics inform investment decisions at the world’s largest banks, asset managers and pension funds. Trillions of dollars are benchmarked to its indexes, and its roughly 6,000 employees work under the supervision of regulators in the US, UK and EU.

For a business like this, trust is the product. Failure in MSCI’s controls can create risk not only for MSCI, but for the regulated institutions that rely on it.

John Rogers is MSCI’s Chief Information Security Officer (CISO) and oversees its AI Governance Program, putting him at the center of how the company evaluates and manages the risks that come with AI adoption.

When an AI agent is in scope for SOX

In early 2026 Rogers' own team was running a dozen or so agents, reviewing firewall changes, approving local admin rights and triaging security alerts.

One agent that carried substantially more risk than the others was a SecOps Agent that reviews and approves requests for privileged access. An unauthorized approval means someone holds access they should not have. Once Rogers told his auditors that an agent was making decisions that could involve SOX systems, it went straight to the top of their collective agenda.

"We had an AI governance program, we were working on ISO 42001 and we had SOC 2 with an independent auditor,” said John Rogers, CISO at MSCI. “None of it answered the question I knew our auditors would ask. Not 'do you have a policy?' but 'does this agent actually do what the policy says, and can you prove it?'"

Why AIUC-1

What Rogers had not found elsewhere was a standard that tested the agent itself under adversarial conditions and produced evidence his auditors could examine. After joining the AIUC-1 Consortium to understand the standard and audit process, he chose MSCI’s SecOps Agent as the first test case.

AIUC scoped the agent with MSCI’s engineers, agreed grading criteria and validated sample tests before scaling up. In total, the SecOps Agent was subjected to ~1,400 tests across benign, social engineering and adversarial risks and included testing across 112 privileged roles.

The agent passed the evals with no major or significant vulnerabilities, reaffirming strong controls that were already in place. The remaining low-severity cases were timeouts, upstream platform controls, or the agent being stricter than required.

“AIUC delivered a comprehensive report covering the methodology, how the agent was tested and how it performed,” said John Rogers, CISO at MSCI. “That was exactly what we needed to to support our SOX program.”

A framework for the next thousand agents

One agent was now covered. But by summer Rogers' own team was running 40-plus agents, and MSCI expects hundreds more across the company within 18 months. Repeating the exercise agent by agent would never scale.Rogers still had to deliver the efficiency the business expected from agents without any of them putting financial data, client data or MSCI at risk. So, he worked with AIUC to build a risk-tiering framework that sets the level of assurance for every agent MSCI deploys based on what it can do.

Top-tier agents, such as those that are customer-facing or touching regulatory processes, HR data or client data, are planned to be certified against AIUC-1, with an independent auditor covering operational and legal controls. Lower tiers will apply a defined subset of AIUC-1 requirements at build time, with technical testing scaled to the risk.

"The point of the risk-tiering framework is that we're not starting from scratch with every agent,” said Rogers. “An internal, read-only agent gets a handful of controls. A client-facing one gets the full standard and an audit. And it's modular: if a more exposed agent comes online next year, we add the criteria for it rather than redesign the whole program."

Rogers’ advice to peers

Rogers’ advice to his fellow CISOs and risk leaders is very practical. “Pick one high-stakes agent you understand well and test it against AIUC-1 before your auditor asks. And build the inventory and the risk tiers early, so assurance stays proportionate to risk as the agent count grows. Governance, oversight and certification of agents is what’s going to help you move quickly.”

For MSCI, assurance is not a barrier to scaling AI. When built into the process early and matched to the risk of each agent, it helps make deploying thousands of agents possible.

About AIUC

The Artificial Intelligence Underwriting Company builds confidence infrastructure for AI adoption through certification, auditing, and insurance for AI agents. Founded by experts from Anthropic and McKinsey and developed with Orrick, the Cloud Security Alliance, and MITRE, AIUC-1 is the first security, safety, and reliability standard for AI agents. AIUC-1 is backed by a consortium of 250 CISOs and risk leaders from the Fortune 1000 and adopted by category leaders including Cursor, Harvey, ElevenLabs, Lovable, and KPMG.

For more information, visit aiuc-1.com