How to Map AI Controls to NAIC Model Bulletin Requirements
Mapping AI controls to the NAIC Model Bulletin means translating its five core expectations, governance accountability, lifecycle risk management, third-party oversight, testing, and documentation, into named internal owners, specific technical or procedural controls, and retrievable evidence artifacts. A working mapping ties each Bulletin provision to a control (such as a model inventory entry, runtime policy rule, or audit log) rather than treating compliance as a narrative exercise.
The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted in December 2023, sets out governance expectations rather than technical standards. It directs insurers to maintain an AI governance framework with oversight from senior management and, where applicable, the board, supported by written policies and clear accountability structures. It calls for a risk management framework spanning the full AI system lifecycle, including development or acquisition, testing, deployment, monitoring, and retirement. It requires documentation sufficient to demonstrate compliance to state regulators on request, and it states plainly that insurers remain responsible for compliance even when AI systems or data are obtained from or operated by third-party vendors. Notably, the Bulletin does not prescribe specific technical controls. It builds on existing corporate governance and market conduct frameworks already applicable to insurers rather than creating a new regulatory regime, which means the burden of interpretation, and the burden of proof, sits with the carrier.
Why a Narrative Compliance Approach Falls Short
Because the Bulletin describes principles rather than mandating specific tools or thresholds, many insurers respond with policy documents that restate the Bulletin's language without connecting it to operational evidence. This creates exposure during a market conduct exam or regulator inquiry, when the practical question is not whether a policy exists, but whether the carrier can produce risk assessments, testing records, and decision logs tied to a specific AI system. A control mapping approach addresses this gap directly: each Bulletin provision is assigned a named internal owner, a specific control, and an evidence artifact that can be retrieved on request. This is the same discipline already applied to other regulated processes in insurance, such as underwriting guideline documentation or claims audit trails, extended to AI systems.
Building the Control Mapping
A usable mapping treats the Bulletin as five discrete domains, each requiring its own owner, control, and evidence trail rather than a single blanket policy statement:
Governance
Senior management and board accountability structures.
Risk Management
Lifecycle oversight from development through retirement.
Third-Party Oversight
Vendor AI representations and ongoing assessment.
Testing
Unfair discrimination testing tied to existing trade practices law.
Documentation
Evidence sufficient for regulator and exam requests.
The Role of Audit Logging and Testing Evidence
Two Bulletin expectations depend heavily on technical evidence rather than policy language: testing and documentation. Because the Bulletin ties testing expectations to existing state unfair trade practices statutes, bias and fairness testing integrated into the model development pipeline is not a discretionary best practice, it is the mechanism by which an insurer demonstrates it has addressed unfair discrimination risk before a complaint or exam raises the question. Separately, audit logging of AI-driven decisions, including instances of human review or override, provides the evidentiary trail regulators may request. Change management and version control for model updates further support the lifecycle oversight the risk management framework calls for, since a regulator asking about a specific decision will often need to know which model version, and which policy configuration, was active at the time.
State Adoption Variance and Its Effect on Mapping
The Model Bulletin carries no independent federal force. Its enforceability depends on individual state insurance departments choosing to adopt, issue, or reference the model language, and a number of states have issued bulletins substantially adopting it since its release, with wording and effective dates that vary by state. For a multi-state carrier, this means a single control mapping built to satisfy the NAIC's baseline language may not fully satisfy a state that has modified or extended it. The practical approach is to build the mapping to the most stringent applicable state language, and to structure the mapping matrix so that state-specific variations can be layered on top of the baseline mapping without rebuilding it from scratch.
Practical Considerations for Governance Leaders
- Treat the mapping matrix as a living document tied to the model inventory, not a static compliance memo.
- Prioritize runtime evidence for high-impact use cases such as underwriting and claims before extending controls to lower-risk systems.
- Revisit vendor AI representations on a recurring schedule rather than at contract signing only.
- Keep documentation templates consistent across business units to support multi-state exam readiness.
- Assign explicit ownership for each Bulletin domain so accountability does not default to compliance alone.
Operationalize AI Governance for Insurance Compliance
Trussed AI provides runtime governance and policy enforcement that can support the auditability and accountability mechanisms insurers need to map internal controls to regulatory expectations like the NAIC Model Bulletin.
Request a Demo