Skip to content

Software companies

NAIC AI model bulletin: what insurance software vendors must give carriers

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

The NAIC AI model bulletin sets expectations for insurers, not vendors, but carriers in adopting states pass its oversight duties down through contracts and due diligence. Insurance software vendors should expect requests for an AI system inventory, model documentation, training data provenance, testing results and audit and regulator cooperation rights, and should prepare them before the questionnaire arrives.

Key takeaways

  • The bulletin applies to insurers in states that adopt it; vendors feel it through carrier contracts and questionnaires.
  • Carriers need vendor documentation to show regulators they oversee third-party AI systems and data.
  • Training data provenance is the hardest request for vendors whose models learned from several carriers' records.
  • Negotiate the scope of audit and cooperation rights rather than refusing them.
  • State adoption varies and some states have separate rules, so map obligations to each carrier's states.

What does the NAIC AI model bulletin ask of insurers?#

The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers asks insurers to govern their use of AI so that decisions affecting consumers comply with existing insurance laws, including rules on unfair trade practices and unfair discrimination. It is a model: it takes effect in a state when that state's insurance regulator issues it, sometimes with changes.

The core expectation is a written program for AI systems, with governance, risk management and internal controls proportionate to how the insurer uses AI. The bulletin also expects insurers to manage AI systems and data they acquire from third parties, which is where software vendors come in.

Many states have adopted the bulletin in some form, and adoption continues. Rather than relying on a count from any summary, check the insurance department publications for each state where your carrier customers are domiciled or write business.

Why the bulletin reaches vendors through carrier contracts#

The bulletin reaches vendors indirectly because insurers remain responsible for decisions made with third-party tools. A carrier that uses your claims triage model, underwriting rules engine or fraud score cannot tell a regulator it does not know how the tool works; it needs documentation from you, and the contractual right to get more if a regulator asks.

That turns into three kinds of requests: due diligence questionnaires during procurement and renewal, new contract clauses on audit and cooperation, and ongoing reporting when your models change. Vendors that prepare one standard package can answer each carrier from it instead of starting over for every questionnaire.

Documents carriers commonly request#

Carrier requests vary, but the same documents come up again and again. Prepare them once, keep them versioned and share them under NDA.

Documents carriers commonly request
DocumentWhat it coversUsual owner at the vendor
AI system inventoryEach model or AI feature, its purpose and the carrier decisions it supportsProduct lead
Model documentationInputs, outputs, logic summary, limitations and intended useData science lead
Training data provenanceWhere training data came from and under what rightData lead with counsel
Testing and validation resultsAccuracy, drift monitoring and testing for unfair discriminationData science lead
Change management recordsVersion history and notice of material model changesEngineering lead
Human oversight designWhere people review, override or approve model outputsProduct lead
Data governance and privacyHandling of policyholder data, retention and access controlsSecurity and privacy lead
Third-party componentsFoundation models, data vendors and subcontractors in the pipelineEngineering lead with procurement
Incident and complaint logModel errors, complaints and remediationSupport and compliance

Training data provenance: the hardest request#

Training data provenance is the hardest request because many insurance software models learned from records supplied by several carriers under contracts that never mentioned AI. A carrier asking where your training data came from is also asking whether competitors' data shaped decisions about its policyholders, and whether its own data trained a model others use.

A provenance register answers that question source by source. The Data & Trust Alliance Data Provenance Standards offer a useful vocabulary: their metadata falls into Source, Provenance and Use groups, and the Use group includes elements such as consent documentation location, license to use, intended data use and privacy-enhancing technologies applied. You can borrow the structure without adopting the standard formally.

  • For each model: the datasets used, their date ranges and the carrier or other source of each.
  • The contract clause or consent that permitted the training use.
  • De-identification applied before training, and who performed it.
  • Whether any dataset has been withdrawn, and whether the model was retrained afterward.
  • Third-party or foundation models in the pipeline and their terms on training data.

Contract clauses to expect and how to negotiate them#

Carrier contract clauses tied to the bulletin usually cover audit rights, cooperation with regulators, notice of model changes and limits on data use. Refusing them outright tends to end a procurement; negotiating their scope is normal and expected.

Contract clauses to expect and how to negotiate them
ClauseWhat carriers ask forReasonable vendor position
Audit rightsAccess to documentation, testing and personnelDocumentary review first, scheduled, under NDA, with cost rules for repeat audits
Regulator cooperationHelp responding to a regulator's inquiryAgree, with a defined process and protection for trade secrets
Model change noticeNotice before material changes to models used for the carrierDefine material change and agree on a notice process
Data use limitsNo use of the carrier's data to train models for othersClarify treatment of de-identified data, aggregate analytics and existing models
Testing resultsBias and accuracy testing outcomesShare summaries; protect proprietary methods
Flow-downThe same duties for your subcontractorsFlow down only what you can actually enforce

Where to start if a questionnaire is already open#

If a carrier questionnaire is already open, start with the documents that unblock the most questions rather than the longest ones. An honest, partial answer with a dated plan for the rest is easier to defend later than an overstated one.

  • Write the AI system inventory first, because every other answer refers back to it.
  • Draft the provenance register for the model this carrier actually uses, not every model you run.
  • Collect existing test results before commissioning new testing.
  • Mark answers that depend on counsel's review so the carrier does not treat them as final.
  • File the questionnaire, your answers and supporting documents together as the start of your standard package.

Illustrative: a claims triage vendor answers a carrier questionnaire#

Illustrative: a fictional vendor sells claims intake and triage software to regional property and casualty carriers. A new carrier customer sends a third-party AI questionnaire asking for a model inventory, training data provenance and testing results, plus a contract addendum with audit and regulator cooperation rights.

Building the provenance register reveals that the triage model was trained on claim notes from several carriers under an old services agreement that allowed the vendor to improve its services. Counsel advises that the clause is too thin to rely on when a carrier asks pointed questions. The vendor retrains the model on records from carriers that sign an explicit training consent, documents the change and narrows the audit clause to documentary review under NDA.

The carrier accepts the package, and the vendor reuses it, updated, for the next questionnaire.

How SourceX approaches carrier-sourced records#

The SourceX Evidence Packet has the same shape as a carrier's provenance request: provenance, licensing rights, permitted use, the privacy record and release authorization. When an insurance software vendor considers licensing records, SourceX applies that structure from the first step.

In the SourceX five-step transaction, the Rights step separates carrier-owned and policyholder data from the vendor's own records, such as support conversations, engineering issues and product decisions. Carrier data generally stays out unless the carrier has approved the use, and Preparation removes policyholder and claimant details from everything that remains.

Frequently asked questions

Is the NAIC model bulletin a law?

Not by itself. The NAIC writes models; a state insurance regulator gives the bulletin effect by issuing it, and it then sets expectations for insurers under that state's existing insurance laws. It does not regulate vendors directly, but carriers pass its expectations to vendors through contracts.

Do vendors of rules-based software need to respond?

Often, yes. Carriers may send the same questionnaire to every vendor whose tools influence underwriting, pricing, claims or fraud decisions. Describe your system accurately, including where it uses fixed rules rather than learned models, instead of declining to answer.

Does the bulletin stop us from training models on carrier data?

Not directly. Your carrier contracts, privacy laws and the carrier's own policies decide that. In practice, carriers responding to the bulletin often ask for limits on using their data to train models for other customers, so expect that clause at renewal.

Are there state rules beyond the bulletin?

Yes. Some states have their own statutes or regulations on insurers' use of external data, algorithms and predictive models. Check them alongside the bulletin for each state your carriers write business in, and ask carriers which rules they are applying to you.

How often should the vendor package be updated?

Whenever a model, training dataset or third-party component changes materially, and again at each contract renewal. Version the documents so a carrier can see what applied when a particular decision was made.

Sources

  • The Data & Trust Alliance Data Provenance Standards define dataset metadata in Source, Provenance and Use groups; the Use group includes consent documentation location, privacy-enhancing technologies applied, license to use and intended data use. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify