Pennsylvania Insurance Notice 2024-04: the AI documentation checklist
Section 4 of the Notice lists what the Pennsylvania Insurance Department "may request during an investigation or examination" of an insurer's use of AI. Here is that list as a checklist you can tick, item by item, with the Notice's own numbering.
What the Notice is
Published April 6, 2024 (54 Pa.B. 1910), signed by the Insurance Commissioner, adopting the NAIC Model Bulletin on insurers' use of artificial intelligence systems. It covers every "insurer" in the broad statutory sense: insurance companies, exchanges, HMOs, PPOs, hospital and professional health plan corporations, fraternal benefit societies and beneficial associations. It says its guidelines "are not intended to be binding upon insurers," and that its goal "is not to prescribe specific practices or to prescribe specific documentation requirements." It also says, in Section 4, that an insurer "can expect to be asked" for the documents below "in the context of an investigation or market conduct action or at any time determined necessary by the Insurance Commissioner." That last phrase is Pennsylvania's addition; it is not in the NAIC model.
The checklist (Section 4)
Wording in quotes is the Notice's. Tick what you could hand over this week.
1.1 The program itself
- ☐ 1.1(a) "The current written AIS program."
- ☐ 1.1(b) "Information and documentation relating to or evidencing the adoption of the AIS program" (board or committee minutes, approvals).
- ☐ 1.1(c) "The scope of the insurer's AIS program, including any and all AI systems and technologies whether or not included in or addressed by the AIS program."
- ☐ 1.1(d) How the program is "tailored to and proportionate with" the insurer's use of AI, the risk, and the potential harm.
- ☐ 1.1(e) "The policies, procedures, guidance, training materials and other information relating to the adoption, implementation, maintenance, monitoring and oversight of the insurer's AIS program," including data governance, model "measurements, standards, or thresholds," and protection of nonpublic information.
1.2 Third-party diligence
- ☐ "Information and documentation relating to the insurer's pre-acquisition/pre-use diligence, monitoring, oversight and auditing of data or AI systems developed by a third party."
1.3 Governance and the models
- ☐ 1.3(a) "Documentation relating to or evidencing the formation and ongoing operation of the insurer's coordinating bodies for the development, use and oversight of AI systems."
- ☐ 1.3(b) Data-practice documentation: lineage, quality, integrity, bias analysis, suitability, data currency.
- ☐ 1.3(c)(i) "The insurer's inventories and descriptions of predictive models, and AI systems used by the insurer to make or support decisions that can result in adverse consumer outcomes."
- ☐ 1.3(c)(ii) For a specific model under examination: "(1) Documentation of compliance with all applicable AIS program policies, protocols and procedures"; "(2) Information about data used ... including the data source, provenance, data lineage"; "(3) Information related to the techniques, measurements, thresholds and similar controls used by the insurer."
- ☐ 1.3(d) "Documentation related to validation, testing and auditing, including evaluation of model drift."
2. Third-party AI systems, models and data
- ☐ 2.1 "Due diligence conducted on third parties and their data, models or AI systems."
- ☐ 2.2 "Contracts with third-party AI system, model or data vendors, including terms relating to representations, warranties, data security and privacy, data sourcing, intellectual property rights, confidentiality and disclosures, and/or cooperation with regulators."
- ☐ 2.3 "Audits or confirmation processes, or both, performed regarding third-party compliance."
- ☐ 2.4 "Documentation pertaining to validation, testing and auditing, including evaluation of model drift."
What most small and mid-size insurers find
The items that exist are usually 1.1(a) in draft, 2.2 (contracts, though rarely with AI-specific terms), and some of 1.3(c)(i) in a spreadsheet. The items that are usually missing are the ones that need records rather than policies: 1.3(c)(ii)(1), compliance evidenced per decision; 1.3(d), testing and drift with dates; and the "measurements, standards, or thresholds" in 1.1(e). Vendor tools for rating, claims triage or fraud scoring count; the Notice covers AI "whether developed by the insurer or embedded within an affiliate or third-party vendor process."
Sources
- Pennsylvania Bulletin, 54 Pa.B. 1910 (April 6, 2024), Insurance Notice 2024-04: pacodeandbulletin.gov
- NAIC Model Bulletin: Use of Artificial Intelligence Systems by Insurers (adopted December 4, 2023): naic.org
Related
- The NAIC AI Model Bulletin: what it expects insurers to keep
- What "Not evidenced" means, and why it is scored like a gap
- How to verify an AI decision log, and prove nobody edited it
- The AI Workflow Evidence Pack: find out which of these you can evidence today, from one decision-log export.