NAIC AI PRINCIPLES · MODEL BULLETIN · AIS PROGRAM

A policy is not a programme.

The NAIC adopted its five AI principles in August 2020 and a Model Bulletin on the use of AI systems by insurers in December 2023. The Bulletin does not ask for a policy — it asks for a written AIS Program, proportionate to your AI use and to the risk of adverse consumer outcomes, that survives a market conduct examination. The difference is that a programme produces records. We review yours against the Bulletin, section by section.


A document scanner on a desk feeding a printed cover sheet headed audit documents and stamped confidential, for authorised use only Illustrative materials
Most of the cost of an exam is finding things
FACTS principles Model Bulletin AIS Program Adverse consumer outcomes Vendor oversight
The instrument

The NAIC does not regulate you. Your state does.

Which makes whether the Bulletin applies to you a state-by-state question rather than a yes-or-no one — so it goes first.

Principles Adopted August 2020

The five FACTS principles — the NAIC's statement of what it expects from AI in insurance.

Bulletin Adopted December 2023

Model Bulletin on the Use of Artificial Intelligence Systems by Insurers.

Instrument Guidance, not law

A model bulletin. It binds you when your state adopts it.

Expectation A written AIS Program

Documented, proportionate to your AI use and to the risk of adverse consumer outcomes.

The Bulletin binds through your state

The NAIC does not regulate insurers. A model bulletin takes effect where a state insurance department issues it — so the question is never "has the NAIC adopted it" but "has my domiciliary state, and every state I write in".

Examinations have started asking

Market conduct examiners increasingly ask for the AIS Program by name, along with the documentation the Bulletin says regulators may request.

It reaches your vendors

Third-party AI systems and data are explicitly in scope. Buying a model or a score in does not move the expectation off the insurer.

It sits on top of existing law

Unfair trade practices, unfair claims settlement and rate filing requirements all still apply. The Bulletin says AI does not create an exemption from any of them.

No adoption count on this page, deliberately. A number of adopting states is the obvious thing to print here and the one thing this page will not: it changes without notice, it cannot be computed, and a stale count on a regulatory page is worse than no count. The mechanism above is stable; the count is not.

Readiness

What an examiner asks for. What most programmes hold.

Six places the gap usually sits. Read the middle column honestly — it is where most insurers actually are, and there is nothing unusual about being there.

Examination expectations against what most AI programmes currently hold
What is asked for What most programmes hold What closes the gap
The written AIS Program An AI policy of two or three pages A programme structured to the Bulletin's own sections, with proportionality reasoned on its face.
A complete AI inventory A list of the models the data team owns Every AI system touching a regulated practice, including vendor scores and embedded features.
Adverse-outcome testing Accuracy and lift metrics Testing designed around consumer harm, with populations and thresholds recorded.
Vendor evidence A signed vendor attestation Diligence records, contract terms covering audit and data, and your own residual testing.
Monitoring after deployment A dashboard someone looks at Thresholds, alerts, and a recorded response the last time one was crossed.
Documentation on request Files across four teams and three drives An indexed pack assembled against the examination section before the exam letter arrives.

This is a readiness check, not a vendor comparison. We do not publish claims about what another firm’s platform does, because we cannot verify them — and a page that scores its competitors is asking you to take its word for something it never had.

The principles

Five principles, adopted August 2020

The acronym is the NAIC’s own. These are the statement of expectations the Model Bulletin later turned into an operating requirement.

Fair and ethical

AI must not produce outcomes that are unfairly discriminatory, and insurers should be able to show how they know that.

  • Proactive testing for unfair discrimination
  • Compliance with existing unfair trade practice law
  • Consideration of impact on protected classes

Accountable

Insurers are responsible for the outputs of their AI, including AI they did not build.

  • Named ownership at senior level
  • Board or committee visibility
  • Responsibility not delegated to a vendor

Compliant

AI does not create an exemption from any obligation the insurer already had.

  • Rate, form and underwriting requirements
  • Unfair claims settlement practices
  • Privacy and data protection law

Transparent

Regulators and, in the right circumstances, consumers should be able to understand how a decision was reached.

  • Disclosure appropriate to the audience
  • Explanations of adverse decisions
  • Inquiry and complaint routes that work

Secure, safe and robust

Systems should be reliable, resilient, tested, and protected — over their whole life, not at launch.

  • Validation before and after deployment
  • Drift and performance monitoring
  • Data security and integrity controls
The programme

Four pillars. The fourth is where most insurers are thinnest.

What a documented AIS Program has to cover, and what the state regulators who have adopted the Bulletin will expect to see evidence of.

Governance

Who owns it, and how that is evidenced

  • A written AIS Program, approved and dated
  • Named senior accountability for AI outcomes
  • Board or committee oversight with a reporting line
  • Policies covering acceptable and prohibited uses
  • Documented decision rights over deployment

Risk management and internal controls

The controls, and the proof they operate

  • Inventory of AI systems and where each is used
  • Risk assessment proportionate to consumer impact
  • Model validation before and after deployment
  • Drift, performance and outcome monitoring
  • Documentation and record retention

Testing for adverse consumer outcomes

The Bulletin's central concern, stated plainly

  • Testing designed around consumer harm, not accuracy alone
  • Proxy and correlation analysis on rating and underwriting variables
  • Results recorded with the populations used
  • A route from a finding to a change
  • Re-testing after material model changes

Third-party vendor oversight

Where most insurers are thinnest

  • Diligence before a vendor system is used
  • Contract terms covering audit, data and cooperation
  • Evidence obtainable from the vendor on request
  • Ongoing performance review, not one-off diligence
  • Your own testing where the vendor's is not enough

A programme differs from a policy in the one way that matters to an examiner: it produces records on its own, rather than records produced for the exam.

Scope

Who it reaches, and the four questions that size the work

If you write policies, price risk, pay claims or sell AI into the insurance stack, you are in scope somewhere.

Who is covered

  • Life, health, P&C, auto and specialty insurers Any insurer licensed in an adopting state that uses AI systems in a regulated insurance practice.
  • Managing general agents and third-party administrators Where delegated authority means an AI system is shaping a regulated decision on the insurer's behalf.
  • Reinsurers with model inputs Where AI outputs feed decisions that reach a policyholder through the ceding insurer.
  • Insurtech and vendor platforms Not directly regulated, but contractually pulled in: the insurer has to evidence your system, so you have to be able to supply it.
  • Any regulated insurance practice Marketing, underwriting, rating, pricing, claims, fraud detection, servicing and renewal are all named territory.

Which states are you licensed in?

The Bulletin binds through state adoption, so the answer is the union of every state you write in — not just your domiciliary state.

Which of your uses are in scope?

Marketing, underwriting, rating, claims, fraud and servicing are all regulated insurance practices. A tool that only supports an internal process may not be.

Do you already have an AI inventory?

If not, that is the first deliverable. Almost every other answer in the programme is derived from it, and it is always larger than expected.

How much AI came from a vendor?

The higher that proportion, the more of your programme is evidence you have to obtain rather than evidence you can produce.

The answers set the size of the work far more than the number of models you run. Every AIS Program engagement starts with these four.

Section by section

The Model Bulletin, clause by clause

For insurers and legal teams who want the Bulletin translated into the concrete artefacts that discharge each section. One row per section, no hand-waving.

The section numbering below follows the Bulletin’s structure as we hold it, and has not been line-checked against the published text. On an engagement we work from the version your state has issued. Verify against the source before relying on a specific section reference.

Bulletin section Regulator expectation What it means in practice What iDharma produces
Section 1 Introduction and background The Bulletin applies to AI used in regulated insurance practices, and existing law is unaffected. Establish which of your practices are regulated and which AI touches them. Scope memo naming the practices in and out, with the reasoning per system.
Section 2 Definitions Defined terms including AI system, adverse consumer outcome, model drift and generative AI. Your internal vocabulary has to match the Bulletin's, or your evidence answers a different question. Definitions mapped onto your own terminology, with the mismatches flagged.
Section 3.1 AIS Program guidelines A written programme, proportionate to use and to the risk of adverse consumer outcomes. Proportionality is a judgement you have to record, not one an examiner will infer. The written programme, with the proportionality reasoning stated on its face.
Section 3.2 Governance Accountability, policies, oversight and defined roles across the AI lifecycle. Named owners with real authority, and a reporting line that has actually been used. Governance review against the org as it operates, not as it is drawn.
Section 3.3 Risk management and internal controls Inventory, validation, testing, monitoring, documentation and retention. Controls that produce records on their own, rather than records produced for the exam. Control-by-control gap list with the evidence each one should be generating.
Section 3.4 Third-party AI systems and data Diligence, contractual terms and ongoing oversight of vendor systems and data. You have to be able to evidence a system you did not build and cannot see inside. Vendor diligence review, contract-terms checklist and the residual-testing plan.
Section 4 Regulatory oversight and examinations The documentation and information regulators may request on examination. Most of the cost of an exam is finding things, not fixing them. Examination readiness pack, indexed against what the section lists.
Deliverables

Six artefacts, and what each one is for

Concrete deliverables with names and formats, generated from the work rather than assembled from a template.

Document set

AIS Program package

The written programme itself — governance, controls, testing and vendor oversight — drafted to the Bulletin's own structure so an examiner can follow it.

Register

AI system inventory

Every AI system, where it is used in a regulated practice, who owns it, and whether it came from a vendor.

Report

Bias and disparate-impact results

Testing for adverse consumer outcomes, with method, populations and thresholds stated so the numbers stay readable a year later.

Pack

Vendor evidence pack

What each third party supplied, what it did not, and what you tested yourself to cover the gap.

Procedure

Adverse-outcome route

How a finding becomes a change: escalation, decision, remediation and re-test, with owners at each step.

Index

Examination readiness pack

The documentation the Bulletin says regulators may request, assembled and indexed before anyone asks for it.

A kraft document envelope with a string closure on a dark surface, stamped confidential and marked for authorised personnel only
Illustrative materials

Indexed before the examination letter arrives

Questions

Frequently asked questions

What insurance legal, compliance and data-science teams ask when the Bulletin lands.

1 What it is
What is an AIS Program?

The written Artificial Intelligence Systems Program the Model Bulletin expects an insurer to maintain: governance, risk management and internal controls, and third-party oversight, documented and proportionate to how much AI you use and how much harm it could do to a consumer. It is a programme, not a policy — the distinction is that a programme produces records.

What are the NAIC AI Principles?

Five principles adopted in August 2020, known by the acronym FACTS: Fair and Ethical, Accountable, Compliant, Transparent, and Secure, Safe and Robust. They are the statement of expectations the Model Bulletin later operationalised.

Is the Model Bulletin legally binding?

Not by itself. The NAIC does not regulate insurers — it publishes models that individual state insurance departments adopt. Once your state issues it, it becomes the standard you are examined against there. Check every state you write in, not only your domiciliary state.

How does this relate to existing insurance law?

It sits on top of it. Unfair trade practices, unfair claims settlement, rate and form filing and privacy obligations all still apply in full. The Bulletin is explicit that using AI creates no exemption from any of them.

2 Scope and testing
Which of our uses are in scope?

AI used in a regulated insurance practice — marketing, underwriting, rating and pricing, claims, fraud detection, servicing and renewal. A model that only supports an internal process with no path to a consumer decision is a different conversation, and it is worth having that conversation on paper.

What is an "adverse consumer outcome"?

The Bulletin's own defined term, and the concept the whole document turns on: a decision by an insurer, reached through an AI system, that is adverse to the consumer and that violates legal standards — including unfair discrimination. Testing designed around accuracy will not find it; testing has to be designed around the outcome.

How is this different from NYC Local Law 144?

Different sector and different mechanism. Local Law 144 is a municipal statute about hiring tools with a prescribed calculation and a publication duty. The NAIC Bulletin is regulator guidance about insurance practices, adopted state by state, and it asks for a governance programme rather than a specific arithmetic.

Does it cover generative AI?

Yes — generative AI is among the Bulletin's defined terms, and a generative system used in a regulated practice sits in scope on the same footing as a predictive model. In practice the harder question is inventory: generative tools arrive through business teams rather than through the model pipeline.

3 Vendors and examinations
How does this apply to third-party vendors?

Directly, and it is where most programmes are weakest. Third-party AI systems and data are covered, and the responsibility stays with the insurer. Practically that means diligence before use, contract terms that let you obtain evidence, ongoing review rather than one-off approval, and your own testing wherever the vendor's is not enough.

What documentation should we expect to hand over?

The Bulletin sets out the information regulators may request on examination — the programme itself, the inventory, model documentation, testing results, monitoring records, governance minutes and vendor materials. Most of the cost of an exam is locating those, not producing them, which is why the readiness pack is assembled in advance.

What is the AIS Evaluation Tool?

A NAIC-developed instrument intended to support regulators in reviewing insurers' use of AI systems during market conduct work. Its status and use vary, so treat it as an indication of how examiners are being equipped to ask rather than as a fixed checklist — and build the programme to the Bulletin, which is stable.

How long does an AIS Program review take?

Typically four to eight weeks for an insurer with an existing model governance function, longer where the inventory turns out to be bigger than expected — which it usually does, and vendor systems are usually the reason. Scope is agreed with you before anything is charged.

Get started

Ready to stand up an AIS Program?

Spin up the framework, inventory your systems and vendors, and start producing the evidence an examiner will ask for — before the letter arrives.

This page is guidance on how we scope an AIS Program review, not legal advice. Where your state has issued its own version of the Bulletin, we work from that text. This summary has not been line-checked against the NAIC’s published Principles or Model Bulletin — verify any specific section reference against the source.