How does your AI governance program compare?

    See where your program has gaps in less than 2 minutes.

    Take the assessment

    Compliance Guide

    NAIC AI Model Bulletin Compliance Checklist for Insurers

    The NAIC AI Model Bulletin, adopted December 4, 2023, directs insurers to implement a written AI Systems (AIS) Program covering governance, risk management, and internal controls for internal and third-party AI tools used in underwriting, pricing, claims, and marketing. Enforcement depends on individual state adoption, but insurers remain accountable for AI-driven outcomes under existing unfair trade practice and discrimination laws regardless of vendor involvement.

    Four Pillars of the NAIC AI Model Bulletin

    The bulletin's expectations for insurers fall into four connected areas of accountability.

    Governance Framework

    A documented AIS Program with defined roles and oversight responsibility, so accountability for AI decisions traces back to named individuals rather than a system alone.

    Risk Management Program

    Controls scaled to the risk and complexity of each AI use case, applied consistently whether the system is built internally or sourced from a vendor.

    Third-Party Oversight

    Accountability for vendor-supplied AI outcomes across underwriting, pricing, claims, and marketing, since responsibility does not transfer with the contract.

    Documentation and Testing

    AI inventories, risk classifications, and records of unfair discrimination testing that can be produced as evidence when a regulator asks.

    Core Compliance Checklist

    Use this checklist to translate the four pillars above into concrete, auditable practices.

    • Adopt a written AI Systems (AIS) Program with defined governance roles and senior-management oversight.
    • Maintain an inventory of AI systems used in underwriting, pricing, claims, and marketing.
    • Classify each AI use case by risk and scale controls to match that classification.
    • Document risk management procedures for both internally developed and third-party AI tools.
    • Establish vendor due diligence and monitoring procedures, since accountability stays with the insurer regardless of who built the system.
    • Test AI systems for unfair discrimination and retain records of testing methodology and results.
    • Track how individual states adopt or adapt the bulletin, since expectations are not uniform nationwide.
    • Keep documentation audit-ready and current, reflecting ongoing use rather than a single point-in-time review.

    What the NAIC AI Model Bulletin Requires

    The NAIC AI Model Bulletin, adopted December 4, 2023, sets out expectations for how insurers should govern the AI systems they build and buy. At its core, it calls for a written AI Systems (AIS) Program: a formal structure covering governance, risk management, and internal controls rather than informal or ad hoc oversight. This program is expected to apply broadly, covering both AI tools developed in-house and those licensed from third-party vendors.

    The bulletin's scope reaches into the functions where AI has the most direct effect on consumers: underwriting, pricing, claims handling, and marketing. Within that scope, the governance framework should assign clear roles and oversight responsibility, and the risk management program should apply controls proportional to the risk and complexity of each specific use case, rather than a single uniform standard applied everywhere.

    Guidance, Not Law: How Adoption Varies by State

    The bulletin itself is a model document from the NAIC, not a self-executing federal or state law. Its actual enforceability depends on whether, and how, individual state insurance departments choose to adopt it. Some states may adopt the bulletin closely as issued, others may adapt its language, and timing will vary across jurisdictions.

    For multi-state insurers, this means compliance cannot rely on a single national interpretation. Compliance and legal teams need to track adoption status state by state and be prepared for variation in how examiners apply the bulletin's expectations during market conduct reviews.

    Practical implication

    Because adoption is uneven, the safest posture is to build the AIS Program to the substance of the bulletin's expectations everywhere the insurer operates, then adjust for state-specific nuances as they emerge, rather than waiting for uniform national guidance before acting.

    Third-Party AI Vendor Oversight and Accountability

    A central theme of the bulletin is that outsourcing an AI system does not outsource responsibility for its outcomes. Insurers remain accountable for AI-driven decisions under existing unfair trade practice and discrimination laws regardless of whether the underlying model was built internally or licensed from a vendor.

    This places practical demands on vendor management: due diligence before onboarding an AI tool, contractual provisions that support the insurer's ability to monitor and test the system, and ongoing oversight rather than a one-time review at the point of purchase. The third-party oversight pillar of the bulletin exists precisely because vendor-supplied AI touches the same high-stakes functions, underwriting, pricing, claims, and marketing, as internally built systems.

    From Point-in-Time Attestation to Continuous Compliance Evidence

    The documentation and testing expectations in the bulletin, maintaining AI inventories, risk classifications, and records of unfair discrimination testing, point toward a standard of evidence that holds up over time, not just at the moment of an initial review or attestation.

    A written policy and a one-time fairness test satisfy a narrower reading of the requirements, but AI systems change as they are retrained, updated, or applied to new use cases. Compliance evidence that reflects only the system's state at launch can quickly become outdated. The more durable approach is to treat documentation and testing as an ongoing practice: refreshed inventories, periodic re-testing, and monitoring records that can demonstrate the AIS Program is functioning continuously, across both internal and third-party AI systems.

    Turn Governance Documentation Into Continuous Compliance Evidence

    Runtime governance and audit logging can help insurers generate the ongoing monitoring evidence that the NAIC AI Model Bulletin's framing expects, across internal and third-party AI systems.

    Explore Runtime Governance