NAIC Model Bulletin AI Compliance Checklist for Insurers
The NAIC Model Bulletin expects insurers to maintain a written, board-level AI governance program, apply risk-based controls to higher-impact uses like underwriting and claims, conduct due diligence on third-party AI vendors, and document testing, monitoring, and unfair discrimination checks. Because the bulletin is guidance rather than binding law, insurers must also track which states have formally adopted it to determine current applicability.
NAIC Model Bulletin Compliance Checklist
Use the items below to evaluate whether your organization's AI governance program, vendor oversight process, and audit documentation align with the bulletin's core expectations.
- Maintain a written AI program covering governance, risk management, and internal controls.
- Extend oversight of AI governance to senior management and, where appropriate, the board.
- Apply risk-based, tiered controls to higher-impact uses such as underwriting, rating, and claims.
- Track which states have formally adopted the Model Bulletin before assuming it applies.
- Build an AI-specific vendor due diligence process covering system design, training data, and known compliance risks.
- Seek technical visibility into vendor AI system behavior in production, not only onboarding documentation.
- Maintain a system of record for every AI or machine learning model, including its business purpose and risk classification.
- Retain audit trails covering model inputs, decision-logic changes, version history, and testing results.
- Produce dated, retained records of unfair discrimination testing tied to underwriting, rating, or claims outcomes.
- Verify current adoption status and compliance timelines directly against each relevant state insurance department.
Operationalizing These Controls
Translating the checklist above into day-to-day practice depends on a small set of underlying controls.
Agent and System Identity
Establish clear identity for each AI system and any autonomous agents involved in insurance workflows, so it is possible to demonstrate who or what can modify, deploy, or approve changes to production models.
Least Privilege Permissions
Restrict which users, systems, or agents can access or alter AI model configurations, aligning access controls with the bulletin's expectation of demonstrable internal controls.
Runtime Policy Enforcement
Apply enforceable policies at runtime that govern how AI systems behave in production, rather than relying solely on pre-deployment testing.
Continuous Audit Logging
Capture ongoing logs of AI system activity that support the bulletin's monitoring and documentation expectations without requiring manual reconstruction after the fact.
Bulletin Provisions at a Glance
| Provision | What It Covers |
|---|---|
| Governance Program | Written AI program with senior management or board oversight |
| Risk-Based Controls | Tiered rigor for underwriting, rating, and claims uses |
| Vendor Oversight | Due diligence on third-party AI system design and data |
| Documentation | Testing, monitoring, and unfair discrimination records |
What the NAIC Model Bulletin Requires
The National Association of Insurance Commissioners adopted the Model Bulletin on the Use of Artificial Intelligence Systems by Insurers in December 2023. It sets expectations, not statute, guiding state insurance regulators on how insurers should govern AI systems used across underwriting, rating, claims, and other functions. The bulletin directs insurers to establish a written AI program addressing governance, risk management, and internal controls, with oversight extending to senior management and, where appropriate, the board. This positions AI governance as an enterprise accountability function rather than a task delegated solely to IT or compliance teams. Because the bulletin is guidance, it only becomes applicable in a given state once that state's insurance department formally issues or adopts it, which means insurers operating across multiple jurisdictions may face inconsistent formal requirements depending on adoption status in each state.
Third-Party AI Vendor Oversight
A significant portion of insurers' AI exposure comes through vendor-supplied systems rather than internally built models. The bulletin is explicit that insurers remain responsible for compliance with applicable insurance laws even when AI systems or components are developed, licensed, or supplied by third parties. This shifts the operational burden onto the insurer to build a vendor oversight process specific to AI, distinct from general third-party risk management, that captures information about a vendor's system design, training data, and known compliance risks. Contractual assurances alone are unlikely to satisfy this expectation. Where feasible, insurers should seek technical visibility into how a vendor's AI system behaves in production, not only documentation provided at onboarding, since the bulletin's emphasis on ongoing monitoring implies vendor oversight does not end once a system is deployed.
Documentation, Monitoring, and Audit-Readiness
The bulletin's documentation expectations point toward maintaining a system of record for every AI or machine learning model in use, including its business purpose and risk classification, rather than relying on scattered project files. Audit trails should cover model inputs, changes to decision logic, version history, and testing results over time, so that an insurer can reconstruct how a given AI-driven decision was reached if a regulator requests it. This is a materially different standard than simply asserting that testing occurred. Insurers should be able to produce dated, retained records showing when a model was tested, what was tested, and what the results were, particularly for unfair discrimination checks tied to underwriting, rating, or claims outcomes.
State-by-State Adoption Status
Several state insurance departments have issued their own versions of the NAIC model bulletin following its December 2023 adoption, extending similar AI governance expectations to insurers licensed in those states. However, adoption is not uniform, and the bulletin does not apply automatically nationwide. Insurers should treat state adoption status as an operational variable that changes over time rather than a fixed fact, and should verify current adoption status and any associated compliance timelines directly against each relevant state insurance department's published guidance before finalizing compliance obligations for that jurisdiction.
Frequently Asked Questions
Is the NAIC Model Bulletin legally binding on insurers?
No. The bulletin is guidance issued by the NAIC. It becomes applicable to an insurer only when the relevant state insurance department formally issues or adopts it, so applicability varies by jurisdiction.
Who is accountable if a third-party AI vendor's system causes a compliance issue?
The insurer remains responsible for compliance with applicable insurance laws even when the AI system or component was developed, licensed, or supplied by a third-party vendor, according to the bulletin.
What AI use cases receive the most scrutiny under the bulletin?
The bulletin applies a risk-based approach, expecting more rigorous governance for AI uses with greater potential to affect consumers, such as underwriting, rating, and claims decisions.
How should a multi-state insurer track compliance obligations?
Insurers should monitor adoption status individually in each state where they operate, since the bulletin's formal applicability depends on state-by-state adoption rather than a single national deadline.
Assess Your AI Governance Readiness
Use this checklist to evaluate whether your organization's AI governance program, vendor oversight process, and audit documentation align with NAIC Model Bulletin expectations.
Explore Runtime Governance