How to Write an AI Governance Policy for a Small or Regional Insurer
An AI governance policy for a small or regional insurer should align to the NAIC Model Bulletin's accountability and risk-tiering expectations, assign a single named owner rather than a dedicated AI risk team, maintain a centralized use-case inventory covering both internal and vendor-supplied systems, and include a defined path for reviewing and enforcing the policy as AI use cases change.
Why AI Governance Cannot Wait for a Larger Compliance Team
Small and regional insurers are deploying AI in underwriting, claims, and customer service at a pace similar to larger carriers, but without the dedicated AI risk management functions those carriers use to manage exposure. Regulatory guidance published over the past year, including the NAIC's Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, does not distinguish between insurers by size when describing governance expectations. The accountability, documentation, and oversight requirements apply the same way to a regional carrier running two or three AI-enabled tools as they do to a national insurer running dozens. The practical response for a smaller organization is not to attempt a scaled-down replica of enterprise governance, but to build a policy that meets the same regulatory expectations using existing staff and simpler documentation practices.
What Current Regulatory Guidance Actually Requires
The NAIC adopted its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers in December 2023, and multiple state insurance departments have since referenced or adopted it directly in bulletins issued to insurers operating in their states. The bulletin calls for insurers to maintain a written AI program with defined accountability at the board or senior management level, to apply a risk-based approach that tiers AI use cases by potential consumer impact, and to conduct due diligence and ongoing oversight of third-party AI and machine learning tools used in operations. None of these expectations require a dedicated AI risk function; they require a documented program with clear ownership. Separately, NIST's AI Risk Management Framework, published in January 2023, organizes governance activities into four functions, Govern, Map, Measure, and Manage, and is explicitly designed to scale to organizations without dedicated AI risk teams. For insurers writing life insurance products, Colorado's regulation under SB21-169 adds a specific requirement to test external consumer data and algorithms used in underwriting for unfair discrimination, a requirement that should be confirmed for applicability rather than assumed to extend to other lines of business.
| Governance expectation | Right-sized implementation approach |
|---|---|
| Written AI program | Document the policy, the accountable owner, the review path, and the inventory process in a form that existing compliance, legal, and business teams can maintain. |
| Defined accountability | Assign responsibility to a single named compliance or legal officer, with visibility into every AI use case in the organization. |
| Risk-based approach | Tier AI use cases by potential consumer impact, rather than treating every internal tool as though it requires the same level of review. |
| Third-party oversight | Include vendor-supplied AI and machine learning tools in the same centralized inventory and oversight process as internally built systems. |
Core Components to Include in the Policy Document
The policy should be practical enough for the insurer's actual resources, while still addressing accountability, risk tiering, use-case inventory, vendor oversight, review, and enforcement. A smaller insurer does not need to build a scaled-down replica of an enterprise AI risk function, but it does need a written program that makes ownership, documentation, and oversight clear.
- Risk-tiered use-case inventory: Catalog AI systems by business function and consumer impact rather than building a full model risk registry.
- Named accountable owner: Designate one compliance or legal officer as the accountable party in place of a dedicated AI risk team.
- Vendor oversight documentation: Apply the same governance expectations to vendor-supplied AI and machine learning tools as to internally built systems.
- Runtime enforcement path: Move governance from a static document into ongoing monitoring and control of how AI systems actually operate.
Assigning Accountability Without a Dedicated AI Risk Team
A common obstacle for smaller insurers is that the NAIC Model Bulletin's accountability expectation reads as though it assumes a formal risk management structure. In practice, a single compliance or legal officer can serve as the accountable owner, provided the policy documents that role explicitly and gives that person visibility into every AI use case in the inventory, not just the ones their department directly manages. Where underwriting, claims, and customer service each use different AI tools, the accountable owner needs a defined channel for learning about new deployments before they go live, since governance gaps most often appear when a business unit adopts a tool without informing compliance. A small oversight committee, drawing one representative from underwriting, claims, and IT alongside the accountable compliance owner, can meet on an as-needed basis when new use cases are proposed, without requiring a standing governance function.
Enforcing the Policy Beyond the Document
From written policy to operational control
A written AI governance policy sets expectations. Runtime governance is what enforces them across the AI agents and tools your teams actually use in underwriting, claims, and customer service.
Move From Policy to Enforcement
A written AI governance policy sets expectations. Runtime governance is what enforces them across the AI agents and tools your teams actually use in underwriting, claims, and customer service.
Explore Runtime Governance