Insurer AI Attestation and Annual Filing Requirements
An insurer AI attestation is a formal confirmation, required or expected by state insurance regulators, that an insurer maintains documented governance, risk controls, and oversight over the AI and algorithmic systems it uses in underwriting, claims, pricing, and marketing. There is no single national annual filing form; requirements stem from the NAIC Model Bulletin and vary by state.
Insurer AI Attestation at a Glance
NAIC Model Bulletin
Adopted December 2023, directing insurers to maintain a written AI Systems governance program.
State-Level Variation
States adopt or adapt the model bulletin independently; some, like Colorado, impose specific testing and documentation rules.
No Uniform Form
Most states expect documentation to be produced on request or examination rather than filed on a fixed annual form.
What an Insurer AI Attestation Is
An insurer AI attestation is a representation, made to a state insurance regulator, that the insurer has established governance and risk management controls over the AI and algorithmic systems it uses in regulated functions. The concept is grounded in the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted in December 2023, which directs insurers to establish a written AI Systems (AIS) program covering governance, risk management, and internal controls for AI and machine learning systems that affect consumers.
The bulletin is a model, not binding law on its own. Individual states choose whether to adopt it, adapt its language, or issue separate rules, which is why attestation expectations differ by jurisdiction. Colorado provides the clearest example of a state moving beyond general expectations into specific filing obligations. Under SB21-169, the Colorado Division of Insurance adopted an Algorithm and Predictive Model Governance Regulation for life insurers, requiring a governance and risk management framework and documentation, including quantitative testing results, submitted to the Division.
Why Regulators Are Requiring This
The underlying concern is unfair discrimination arising from predictive models and algorithmic tools used in consumer-facing insurance decisions. The NAIC Model Bulletin identifies underwriting, rating, claims, and marketing as the key functions subject to AI governance expectations, reflecting where model outputs most directly affect consumer outcomes.
This is not limited to generative AI; the framework applies broadly to predictive models and machine learning systems already embedded in underwriting and claims workflows, whether built in-house or supplied by third-party vendors. Rather than creating a new AI-specific penalty regime, most states are relying on existing enforcement tools, primarily market conduct examination authority and unfair trade practices statutes, to act on governance gaps. This means an attestation gap is not treated as a standalone violation category in most jurisdictions but as evidence considered within existing regulatory processes.
What an Attestation Filing Typically Must Cover
Because there is no single standardized national form, the substance of what an insurer must be able to demonstrate matters more than a specific document format. The NAIC Model Bulletin expects insurers to be prepared to produce documentation showing AI governance practices to regulators upon examination or request. In practice, this centers on:
- A written governance program
- An inventory of AI and predictive systems in use
- Accountability structures for oversight
- Monitoring results addressing bias or unfair discrimination
Colorado’s regulation goes further for life insurers, specifically referencing quantitative testing methodologies for external consumer data and information sources used in underwriting, with documentation expected to be available to the Division of Insurance. Insurers operating in multiple states need to treat attestation readiness as an ongoing documentation discipline rather than a once-a-year filing exercise, since the underlying evidence regulators may request does not have a fixed submission date in most jurisdictions.
Where Runtime Governance and Monitoring Fit
Attestation accuracy depends on continuous, auditable records of AI system behavior and governance controls, not documentation compiled reactively when a regulator asks. Governance program requirements imply an ongoing capability to trace model decisions, version changes, and override actions, even where a bulletin does not itemize audit logging explicitly.
This is where runtime governance and monitoring become operationally relevant to compliance teams. Runtime policy enforcement, agent permissions, and audit logging generate the kind of decision-level records that support attestation evidence, because they capture what an AI system actually did in production rather than what it was designed to do. For insurers managing multiple AI and algorithmic systems across underwriting, claims, and pricing, having runtime controls and audit logging in place reduces the burden of reconstructing evidence after the fact and supports a more defensible response when regulators request documentation under existing market conduct or examination authority.
Internal Capabilities Needed to Support an Accurate Attestation
Compliance teams should be able to demonstrate the following capabilities when regulators request AI governance documentation.
- A centralized inventory of AI and machine learning systems used across underwriting, claims, pricing, and marketing
- A designated AI governance officer or committee with documented accountability, consistent with NAIC bulletin expectations
- Documented oversight procedures for third-party and vendor-supplied AI tools, distinct from internally developed models
- Retained testing and monitoring results for bias or unfair discrimination, retrievable rather than assembled only at exam time
- Audit trail records of model decisions, version changes, and override actions tied to specific systems
- A jurisdiction-by-jurisdiction mapping of which states have adopted the NAIC bulletin or issued their own AI governance rules
Common Questions on Insurer AI Attestation
Is there one national insurer AI attestation form?
No. The NAIC Model Bulletin sets baseline expectations, but individual states decide whether to adopt it, adapt it, or issue their own rules, so filing format and timing vary by state.
What happens if an insurer cannot produce required AI governance documentation?
Most states do not have a distinct AI-specific penalty. Gaps are typically addressed through existing market conduct examination and unfair trade practices enforcement authority.
Do third-party AI vendor tools need separate attestation evidence?
Yes. NAIC bulletin guidance distinguishes internally developed models from vendor-supplied AI tools, expecting insurers to document oversight of both categories separately.
Build Defensible Evidence for AI Governance Attestations
Compliance teams supporting insurer AI attestation need continuous, auditable evidence of AI system governance, not point-in-time documentation. See how runtime governance and monitoring support that evidence trail.
Request a Demo