Since the National Association of Insurance Commissioners adopted its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers on December 4, 2023, 24 states and the District of Columbia have adopted it as of the NAIC’s Spring 2026 National Meeting, with four more states issuing AI-specific insurance regulation. For a carrier writing across a national footprint, most of its premium now sits in bulletin states. The expectation is principle-based, but the examination machinery behind it is no longer theoretical: a multistate AI Systems Evaluation Tool entered a pilot in 2026. This guide turns the bulletin into a working checklist, then maps every item to the NIST AI Risk Management Framework and ISO/IEC 42001 so you can prove compliance once and satisfy three frameworks at the same time.
What the bulletin actually requires
The bulletin does not ban any AI use, and it does not hand you a control list to check off. It does something more demanding: it reminds insurers that any decision touching a consumer, whether made or merely supported by an AI System, still has to satisfy existing law, including the Unfair Trade Practices Act (#880) and the Unfair Claims Settlement Practices Model Act (#900). Then it sets an expectation for how you govern that risk: a written program.
That program is the AIS Program and it is the spine of the whole document. Section 3 expects every insurer to adopt, implement, and maintain a documented program covering three areas: governance, risk management and internal controls, and third-party AI systems and data. Section 4 then lists the information a regulator may request during an investigation or market conduct action. Read those two sections together and you have your checklist: Section 3 tells you what to build, Section 4 tells you what an examiner will ask you to produce.
| What most people get wrong: Teams treat Section 3 as the whole bulletin and skim Section 4. It is the reverse risk that bites. Section 4 is the examination section, and it is the part that lands on a regulator’s desk. If your governance is excellent but undocumented, you fail the only test that gets graded. |
The AIS Program readiness checklist
Use this as a gap assessment. Each item cites the bulletin area it answers to, so when an examiner references a section you already know which artifact satisfies it. Work top to bottom; the governance items gate everything below them.
Governance (Section 3)
- Written AIS Program adopted, with senior management accountable to the board or a board committee for oversight and strategy. NAIC §3 Governance
- A cross-functional accountability structure naming actuarial, data science, underwriting, claims, legal, compliance, and IT roles, each with defined authority. NAIC §3 Governance
- An AI strategy and risk-appetite statement tied into the existing enterprise risk management program. NAIC §3
- Policies that span every lifecycle stage where AI is used: product design, marketing, underwriting, rating and pricing, claims administration, and fraud detection. NAIC §3
- A current inventory of every AI System and predictive model in use, including third-party and embedded tools you did not build. NAIC §3 / §4
Risk management and internal controls (Section 3)
- Each AI System classified by its Degree of Potential Harm to Consumers, with control intensity scaled to the tier. NAIC §2 / §3
- Validation, testing, and retesting procedures documented per model and calibrated to whether the system is a predictive model or generative. NAIC §3 / §4
- Bias and unfair-discrimination testing performed, with the methodology, measurements, and thresholds recorded. NAIC §3 controls
- Data governance records: source, provenance, lineage, quality, integrity, and currency for both training and input data. NAIC §4
- Ongoing monitoring with defined model-drift thresholds and explicit re-validation triggers. NAIC §3 / §4
- An internal audit function that reviews the AIS Program independently of the people who built the models. NAIC §3
Third-party and vendor oversight (Section 3)
- Written standards for acquiring, using, and relying on third-party data, models, and AI Systems. NAIC §3 Third-Party
- Vendor due-diligence records covering the vendor’s testing, bias mitigation, and data sourcing. NAIC §3
- Contracts that include audit rights (or a qualified audit report), regulatory cooperation, and disclosure clauses. NAIC §3
- Documented evidence you reviewed each vendor’s validation and bias approach, because liability does not transfer through a procurement contract. NAIC §3
Consumer transparency (Section 3)
- A process to notify consumers that AI Systems are in use, with disclosure scaled to the lifecycle phase. NAIC §3 Consumer Notice
- Adverse-decision explanations available in plain language, including the data and the reasons behind the decision. NAIC §4
Documentation and examination readiness (Section 4)
- The written AIS Program, evidence of its adoption, and its scope (including any systems it does not cover) producible on request. NAIC §4 Item 1
- Training materials, policies, and governance records that show the program is implemented, not merely written. NAIC §4
- Per-model dossiers: development documentation, validation measurements and thresholds, and model-drift evaluation, ready for production. NAIC §4
| Pro tip: Order your inventory by Degree of Potential Harm before an exam, not alphabetically. The Evaluation Tool stalls on day one without a defensible inventory, and examiners open the highest-harm systems first. A fraud model that only flags claims for human review carries lighter obligations than an automated adverse underwriting decision; your evidence should reflect that. |
How the bulletin maps to NIST AI RMF and ISO 42001
The bulletin invites this directly. Section 3 says an AIS Program may rely on a framework from a recognized standards body, naming the NIST AI Risk Management Framework, Version 1.0. NIST organizes its work into four functions: Govern, Map, Measure, and Manage. ISO/IEC 42001:2023, the first certifiable AI management system standard, runs on the familiar management-system clause structure plus an Annex A control set. The practical payoff: build once, and a single control can answer to all three regimes. The table below lines them up at clause level.
| AIS Program element | NAIC Model Bulletin | NIST AI RMF 1.0 | ISO/IEC 42001:2023 |
|---|---|---|---|
| Board / senior-management accountability | Section 3 (Governance) | GOVERN 1.1, 2.1 | Clauses 5.1, 5.3 |
| AI system inventory across the lifecycle | Section 3 (scope) | MAP 1.1-1.6 | Clause 8.1; Annex A.6 |
| Risk assessment and harm tiering | Section 2; Section 3 | MAP 5.1; MEASURE 2.1 | Clause 6.1.2; Annex A.5 |
| Bias / unfair-discrimination testing | Section 3 (controls) | MEASURE 2.11 | Annex A.5, A.7 |
| Ongoing monitoring and model drift | Section 3; Section 4 | MANAGE 4.1; MEASURE 2.4 | Clause 9.1; Clause 10 |
| Third-party / vendor oversight | Section 3 (Third-Party) | MAP 4.1; MANAGE 3.1 | Annex A.10 |
| Documentation and exam evidence | Section 4 (requests) | GOVERN 1.2 | Clause 7.5 |
| Consumer transparency / notice | Section 3 (notice) | GOVERN 5.1; MEASURE 3.2 | Annex A.8 |
Read the table as a reuse map, not a translation exercise. If you already run an ISO 42001 management system, your Clause 7.5 documented information and Annex A.10 supplier controls are most of what Section 4 and the vendor checklist demand. If you started with NIST, your MEASURE function already produces the bias evidence the bulletin’s internal controls expect. The bulletin is principle-based precisely so it can sit on top of either foundation.
Many insurers use NIST AI RMF implementation as the operational foundation for AI inventories, risk management, and continuous monitoring alongside NAIC guidance.
Calibrating controls to potential harm
The bulletin keeps repeating one phrase: controls should be commensurate with the Degree of Potential Harm to Consumers. That is not filler. It is the dial that decides how much governance each system needs, and it is where carriers either save effort or waste it. At its Spring 2026 National Meeting, NAIC staff floated a sample taxonomy sorting AI risk into four levels. It is a discussion draft, not adopted text, but it signals how examiners are starting to think.
| Harm tier | Typical insurance use | Control intensity |
|---|---|---|
| Unacceptable | Uses that produce unlawful or unfair discrimination | Do not deploy; remediate or retire |
| High | Automated adverse underwriting, rating, or claim denial | Full validation, bias testing, human oversight, drift monitoring |
| Medium | AI-assisted pricing, triage, or claims routing with human review | Documented testing, periodic monitoring, clear escalation |
| Low | Back-office efficiency tools with no consumer-facing decision | Inventory and basic oversight; lighter evidence burden |
The lesson holds regardless of whether this exact taxonomy is adopted: stop governing every model the same way. A tiering decision recorded against each inventory item is itself examination evidence, and it keeps your heaviest controls pointed at the systems that can actually harm a policyholder.
The Evaluation Tool: what examiners will open first
The single biggest 2026 development is operational, not legislative. The NAIC’s AI Systems Evaluation Tool is running as a multistate pilot across 12 states, scheduled from spring through September 2026, with an updated version targeted for adoption at the Fall 2026 National Meeting. It gives examiners a standardized way to interrogate an insurer’s AI governance during a market conduct exam. Principles are hardening into examinable expectations, and the tool is how that happens.
Based on the tool’s published structure, it is organized into four exhibits. Knowing the order tells you what to have ready before a notice arrives:
- Exhibit A: measures how extensively you use AI, which is why a clean inventory is the first deliverable.
- Exhibit B: evaluates your governance framework: the AIS Program, accountability, and policies.
- Exhibit C: examines high-risk systems, including agent-facing and increasingly agentic AI.
- Exhibit D: reviews data sources and probes for proxy discrimination.
| Why this matters now: Absence of enforcement is not absence of scrutiny. A market conduct exam that surfaces a poorly documented AI program can generate findings, recommendations, and consent orders that precede any formal action. The carriers that fare worst are the ones producing their program for the first time under examination pressure rather than before it. |
Insurance organizations promoting AI-powered products should also review this FTC AI claims compliance checklist to ensure marketing statements are supported by evidence.
Where the bulletin fits in the wider US patchwork
The bulletin is the common denominator, not the whole map. Two states run binding regimes that sit on top of or beside it. Colorado’s SB 21-169 restricts how insurers use external consumer data and the algorithms built on it, with a governance and testing regulation for life insurers and the broader SB 24-205 AI Act layered on. New York took a different route: DFS Circular Letter No. 7 (2024) governs AI and external data in underwriting and pricing, and requires quantitative proxy testing against protected classes. New York deliberately did not follow the NAIC framework; it built on existing anti-discrimination statutes instead.
Two forces pull in opposite directions above the states. A December 2025 federal executive order is challenging state authority over AI, opening a preemption fight that will run through 2026. And for any carrier operating in Europe, the EU AI Act classifies AI used for risk assessment and pricing in life and health insurance as high-risk under Annex III. Under the Digital Omnibus agreement, those high-risk obligations were deferred from August 2026 to December 2, 2027, though the architecture is intact and the inventory work does not get easier by waiting.
The practical takeaway for a multistate insurer: do not bet on one trajectory. Build to the bulletin as your baseline, then layer the specific Colorado, New York, or EU obligations onto the states and markets where you actually write. A well-built AIS Program absorbs those additions; a state-by-state scramble does not.
From spreadsheet to system: building an exam-ready program
Most carriers start their AI register in a spreadsheet. It works until the third audit, when an examiner asks for version history, the evidence trail behind a bias test, and which bulletin section each control answers to. At that point the manual approach turns into a scramble, because the bulletin’s real burden is not writing the policy once but proving, on demand, that the policy is live across dozens of models and vendors.
A few moves separate the carriers that pass cleanly from those that don’t. First, make the inventory the source of truth and tier every system the day it enters. Second, attach evidence to each model, validation results, bias measurements, drift thresholds, vendor due-diligence, rather than storing it in scattered folders. Third, map each control to the framework clauses it satisfies, so one piece of evidence answers NAIC, NIST, and ISO at once.
This is where dedicated tooling earns its place. Govern365.ai’s AI model registry maps each system to its applicable NAIC bulletin sections, NIST AI RMF functions, and ISO/IEC 42001 controls, while its risk assessment and audit evidence features keep the documentation Section 4 demands in one exam-ready place. The point is not the tool for its own sake; it is that the evidence an examiner requests should be a query, not a fire drill.
Frequently asked questions
Is the NAIC AI Model Bulletin legally binding?
Not on its own. The NAIC is a standard-setting body, so the model bulletin only carries legal force once a state’s department of insurance adopts and issues it. As of the Spring 2026 National Meeting, 24 states and D.C. had done so. In those states, the existing unfair-trade and unfair-claims laws it rests on are fully enforceable, and your AI use must comply regardless of the bulletin’s principle-based tone.
Does the bulletin apply to AI systems built by third-party vendors?
Yes. You remain responsible for AI Systems used on your behalf, including vendor models, external consumer data, and tools embedded in platforms you did not build. The bulletin expects vendor due diligence, contractual audit and cooperation rights, and documented evidence that you reviewed the vendor’s testing and bias approach. Liability does not transfer through a procurement contract.
What documentation will a regulator actually request?
Section 4 is your guide. Expect requests for the written AIS Program, evidence of its adoption and scope, and the policies, training, and governance records that prove it is implemented. For any specific model under review, expect documentation of development, validation measurements and thresholds, data lineage and quality, and model-drift evaluation. Treat Section 4 as a checklist of what to keep production-ready.
What is the AI Systems Evaluation Tool?
It is a standardized framework the NAIC built to give market conduct examiners a consistent way to review insurer AI governance. It entered a multistate pilot across 12 states in 2026, with an updated version targeted for adoption at the Fall 2026 National Meeting. Its exhibits assess how extensively you use AI, your governance framework, your high-risk systems, and your data sources.
How does the bulletin relate to NIST AI RMF and ISO 42001?
The bulletin explicitly allows your AIS Program to rely on a recognized framework and names the NIST AI RMF 1.0. In practice, NIST’s Govern-Map-Measure-Manage functions and ISO/IEC 42001’s management-system clauses and Annex A controls satisfy most bulletin expectations. Building to one of those frameworks lets a single control answer to all three regimes, which is the efficiency the bulletin’s flexibility is designed to enable.
Do we need to test our models for bias?
Effectively, yes. The bulletin’s internal controls expect validation, testing, and bias analysis, and its anchor laws prohibit unfair discrimination. You do not need perfect outcomes; actuarially justified risk differentiation is allowed. You do need to demonstrate that you looked for disparate impacts and addressed them, with the methodology and thresholds documented. In New York, that extends to quantitative proxy testing against protected classes.
The bottom line for compliant AI
The shift in 2026 is not that the rules changed; it is that they became examinable. The bulletin’s legal standard was always there in unfair-trade and unfair-claims law. What changed is how thoroughly you now have to prove you meet it, through a written AIS Program, a tiered inventory, documented bias and drift evidence, and vendor oversight that survives an exam. Build it once against NIST or ISO and you answer all three frameworks at the same time.
Start with the inventory. If your carrier has never listed every AI System in use, including the ones embedded in vendor platforms, that single artifact is the gate to everything else on the checklist, and the first thing an examiner opens. Govern365.ai gives compliance teams the registry, risk assessment, and audit evidence to turn that checklist into a live program. Start your 14-day free trial and make your next exam a query, not a scramble.
