The NAIC adopted five AI principles in August 2020, and in December 2023 a Model Bulletin that turns them into an expectation: a written AI Systems Program, proportionate to your use of AI and to the risk of adverse consumer outcomes. It binds you where your state has issued it.
The NAIC model bulletin is guidance — until your state issues it.
What it asks for is a written AIS Program, proportionate to your use of AI and to the risk of adverse consumer outcomes it carries.
Our promise
“A bulletin asks. The AIS programme is evidence.”
Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $6,500, and nothing is charged until you approve it.
- Each additional tool
- $1,500
- Re-audit, same scope
- $4,200
- Renewal, every twelve months
- $5,500 locked
This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.
Request this auditThe NAIC’s AI expectations, in three chapters
Most insurers hold an AI policy of two or three pages, a list of the models the data team owns, accuracy metrics rather than harm testing, and a signed vendor attestation. Every one is the right subject and the wrong artefact: a programme produces records, a policy does not.
Our review builds the programme an examiner reads in their own order. We inventory every AI system touching a regulated practice, check the controls against the records they actually generate, and design the testing around consumer harm rather than around accuracy alone.
Five principles, one written programme.
The principles say what good looks like. The Bulletin says to write it down.
- Fair and ethical — no discriminatory outcomes, shown
- Accountable — named ownership, including bought-in AI
- Compliant — AI is no exemption from a duty you had
- Transparent and Secure — explained, then monitored
- Life, health, P&C and auto insurers in adopting states
- MGAs and TPAs shaping a decision on your behalf
- Reinsurers whose outputs reach a policyholder
- Insurtech and vendor platforms, by contract
The model is theirs. The programme is yours.
The insurer using the system
The Bulletin sets its expectation on the licensed insurer. The written programme, the inventory, the testing for adverse consumer outcomes and the documentation an examiner may request are all yours, and none of them can be discharged by a vendor holding those papers on your behalf.
The people who built the model
Carries no expectation of its own here - the Bulletin is addressed to the licensed insurer. Many vendors document well and will supply what they have. The difficulty is not the quality of that work; it is that it stops at the edge of what they are prepared to show, and they are the ones who set that edge.
Buying it in does not move it
Third-party AI systems and data are expressly in scope, and the responsibility stays with the insurer. You have to evidence a system you did not build and cannot see inside - diligence before use, contract terms that let you obtain the evidence, and testing of your own on top of whatever theirs shows.
“The model is the vendor’s, so the evidence is too.”
Their systems are in scope. The duty stays yours.
It is the thinnest limb of most programmes we review.
- Who it is for
- Chief risk & compliance
- Chief actuaries
- Model risk & data science
- Claims and underwriting
- General counsel
- Vendor management
Market conduct examiners increasingly ask for the AIS Program by name, and for the records the Bulletin says they may request.
Third-party AI systems and data are expressly in scope. Buying a model or a score in does not move the expectation off the insurer.
It sits on top of existing law. Unfair trade practices, claims settlement and rate filing all still apply — AI is an exemption from none.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a determination.
Your scope check
Four moments, and only one is yours.
Two of these already happened, one happens without asking you, and the fourth is the only one you can be ready for.
-
Principles
August 2020The five FACTS principles: fair and ethical, accountable, compliant, transparent, and secure, safe, robust.
-
Bulletin
December 2023The Model Bulletin operationalises them, asking for a written AIS Program proportionate to your use.
-
Adoption
When your state actsThe NAIC does not itself regulate insurers. The Bulletin binds you where a state department issues it.
-
Production
On examinationMarket conduct examiners ask for the programme by name, and for the records the Bulletin says they may want.
Nothing here falls due, so nothing prompts anybody — and the first prompt is usually the examination letter. Most of the cost of an exam is finding the documents rather than producing them, which is why the readiness pack is assembled before anyone has asked for it.
What the Bulletin asks, what we ship
12 expectations, and the artefact that answers each one. Section numbering unverified.
- Introduction and background Section 1 - existing law is unaffected by AI
- A scope memo naming the practices in and out, with the reasoning recorded system by system.
- Definitions Section 2 - AI system, adverse consumer outcome, drift
- The Bulletin's terms mapped onto your own vocabulary, with every mismatch flagged rather than smoothed over.
- AIS Program guidelines Section 3.1 - proportionate, and written
- The written programme, with the proportionality judgement reasoned on its face rather than left to be inferred.
- Governance Section 3.2 - accountability, policies, oversight
- A governance review against the organisation as it operates, not as the chart draws it.
- Risk management and internal controls Section 3.3 - inventory, validation, monitoring
- A control-by-control gap list naming the evidence each control should be generating on its own.
- Third-party AI systems and data Section 3.4 - diligence, contracts, oversight
- Vendor diligence review, a contract-terms checklist, and the residual-testing plan for what they will not show.
- Regulatory oversight and examinations Section 4 - what regulators may request
- An examination readiness pack, indexed against what that section lists, assembled before the letter arrives.
- A complete AI inventory Most hold a list of the models the data team owns
- Every AI system touching a regulated practice, vendor scores and embedded features included.
- Testing for adverse outcomes Most hold accuracy and lift metrics
- Testing designed around consumer harm, with the populations and thresholds recorded alongside the result.
- Vendor evidence Most hold a signed vendor attestation
- Diligence records, contract terms covering audit and data, and your own testing over what is left.
- Monitoring after deployment Most hold a dashboard somebody looks at
- Thresholds, alerts, and a recorded response from the last time one of them was actually crossed.
- Documentation on request Most hold files across four teams and three drives
- One indexed pack assembled against the examination section, so the exam is spent answering rather than searching.
Insurance AI, independently reviewed
From a rating variable to a claims triage model.
-
Inventory
Every AI system touching a regulated practice, vendor systems included.
-
Test and assess
Adverse-outcome testing, and the controls checked against what they produce.
-
Sign off and hand over
You see the draft first. Then the programme, indexed for the examination.
Why insurers choose iDharma for the Bulletin
Genuinely independent
We build and resell no insurance models, and take no fee tied to what the review finds.
Written to the Bulletin
Every finding maps to the section it answers, so an examiner reads it in their own order.
Vendors are in scope
The thinnest part of most programmes is in the base scope here, not priced as an extra.
A programme, not a PDF
What lands produces records on its own - which is the difference the Bulletin turns on.
Four marks, struck on every programme.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
AIS Program package
The written programme itself, drafted to the Bulletin's own structure so an examiner can follow it in their own order: governance, risk management and internal controls, testing for adverse consumer outcomes and third-party oversight in one approved document, with the proportionality judgement reasoned on its face.
AI system inventory
Every AI system, where it is used in a regulated practice, who owns it, and whether it came from a vendor or was built in-house.
Adverse-outcome testing
Testing designed around consumer harm, with method, populations and thresholds stated so the numbers stay readable a year later.
Vendor evidence pack
What each third party supplied, what it declined to supply, and what you tested yourself to cover the gap the two of them leave.
Adverse-outcome route
How a finding becomes a change: escalation, decision, remediation and re-test, with a named owner and a due date at every one of them.
Examination readiness pack
The documentation the Bulletin says regulators may request, assembled and indexed before anybody has actually asked you for any of it.
State adoption position
Where the Bulletin has been issued across every state you write in, and what that union of answers means for the programme's scope.
Real numbers, upfront.
- Scope
- Set by the Bulletin, not by us
- Input
- Your systems and vendor evidence
- Re-review
- On material change — $5,500 against your known baseline
The Bulletin fixed the scope, so the fee is flat - nothing to meter, and nothing charged until you approve it.
Request this review- The written AIS Program package
- AI inventory across regulated practices
- Adverse-outcome testing, method stated
- Vendor evidence and the examination pack
Four things you have to be able to produce
The Bulletin prescribes no format. Each of these is either in your hand on the day an examination asks, or it is not.
The register,
whole
Every AI system touching a regulated practice, with its owner and its origin. A programme cannot be proportionate to a use that nobody has ever written down.
The plan,
dated
Governance, controls, testing and vendor oversight in one board-approved document, with the proportionality judgement reasoned on its own face and dated.
The testing,
by harm
Designed around adverse consumer outcomes rather than accuracy, with the populations and the thresholds recorded next to each result that they produced.
The vendors,
covered
What each third party supplied, what it would not, and what you tested yourself to cover the difference. This is the limb most programmes are missing.
Four cards, and the date on each one is part of the card.
Plain answers
Binding, scope, vendors, and what you hand over. Answered straight.
Request this reviewIs the Model Bulletin legally binding?
Not by itself. The NAIC does not regulate insurers - it publishes models that individual state insurance departments adopt. Once your state issues it, it is the standard you are examined against there.
What is an AIS Program?
The written AI Systems Program the Bulletin expects: governance, risk management and internal controls, and third-party oversight, proportionate to your use of AI. It is a programme, not a policy - a programme produces records.
Which of our uses are in scope?
AI used in a regulated insurance practice - marketing, underwriting, rating and pricing, claims, fraud detection, servicing and renewal. A model that only supports an internal process is a different conversation.
How does this apply to third-party vendors?
Directly, and it is where most programmes are weakest. Third-party AI systems and data are covered, and the responsibility stays with the insurer - diligence before use, contract terms that let you obtain evidence, and your own testing where theirs is not enough.
What documentation should we expect to hand over?
The programme itself, the inventory, model documentation, testing results, monitoring records, governance minutes and vendor materials. Most of the cost of an exam is locating those, not producing them.
Request an AIS Program review
Tell us where AI touches a regulated practice and we come back within one business day.
What we need from you
Nothing you do not already have. Most of this comes out of your model governance records in an afternoon, and we tell you exactly which extracts before you commit.
- The states you are licensed in and write business in
- Which of your uses sit in a regulated insurance practice
- Your AI inventory, if you already have one
- How much of your AI is a vendor’s, and what they sent
- Whether an examination is scheduled, and by which state
What happens next
- We agree the scope with you first.
- Four to eight weeks, longer for a big inventory.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- NAIC AI Principles
- Model Bulletin on AI Systems by Insurers
- Principles
- August 2020
- Bulletin
- December 2023
What it means
- General information about what the Bulletin expects — not legal advice, and no professional relationship.
- Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.
Scope & limitation
- Written from general knowledge of both documents, not line-checked against either.
- It covers the NAIC texts alone - state insurance law reaches the same systems too.
- Use it as a starting point for a scoping conversation; we work from your state’s version.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
ISO/IEC 42001, SOC 2 and NIST AI RMF: Which One Your Buyer Is Actually Asking For
One certifies an organisation, one is an opinion about controls over a window, one is a method with nothing to issue. What each covers — and what none of them answers.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.