bickford

The NAIC AI Model Bulletin: what it expects insurers to keep

Adopted by the NAIC on December 4, 2023 and, as of August 31, 2026, by 25 states and the District of Columbia. Here is what it expects, what it does not, and what examiners are now piloting on top of it.

The core expectation, in the Bulletin's words

"all Insurers authorized to do business in this state are expected to develop, implement, and maintain a written program (an "AIS Program") for the responsible use of AI Systems that make, or support decisions related to regulated insurance practices."

The program "should address governance, risk management controls, and internal audit functions," with senior management "accountable to the board or an appropriate committee of the board," proportionate to the insurer's use of AI, covering the whole insurance life cycle and the whole AI life cycle, including systems "developed by the insurer or embedded within an affiliate or third-party vendor process." It may sit inside enterprise risk management and "may adopt, incorporate or rely upon" the NIST AI Risk Management Framework 1.0.

The four sections of an AIS program

SectionWhat it coversWhat an examiner would ask to see
1. GeneralPurpose (mitigating adverse consumer outcomes), accountability, proportionality, scope, consumer notice that AI is in useThe written program and evidence of its adoption
2. GovernanceLife-cycle policies; documentation requirements "developed with Section 4 in mind"; committees and chains of command; "monitoring, auditing, escalation, and reporting protocols"; trainingMinutes, org charts, escalation records, training records
3. Risk management and internal controlsApprovals; data practices (currency, lineage, quality, integrity, bias analysis, suitability); model "inventories and descriptions"; "detailed documentation of the development and use"; assessments including "model drift, and the auditability of these measurements"; validation and retesting; nonpublic information; "data and record retention"The inventory, per-model documentation, test results with dates, retention policy, the decision records themselves
4. Third-party AI systems and dataDue diligence; contract terms for "audit rights and/or ... audit reports by qualified auditing entities" and cooperation with regulators; exercising those rightsDiligence files, contracts, SOC 2 or equivalent reports covering the AI

What it does not do

"The goal of the bulletin is not to prescribe specific practices or to prescribe specific documentation requirements." It creates no new law; it tells insurers what regulators expect under existing unfair-trade-practice, claims-settlement, corporate-governance and examination laws, and what they may ask for. States adopt it as a bulletin or notice (Pennsylvania's is Notice 2024-04, nearly word for word).

What is happening in 2026

Sources

Related