We use cookies to understand how this site is used. Privacy policy

    Skip to main content
    Kriv AI

    Insurance AI Governance

    Why Did Our AI Claims Model Get Flagged by State Regulators?

    State insurance regulators now treat undocumented AI claims governance as a compliance failure, not a technical detail.

    AI claims models get flagged because state regulators, following the NAIC Model Bulletin and laws like Colorado SB 21-169 and New York's Circular Letter 7, require documented AI governance programs, bias testing for proxy discrimination, and audit trails for claims decisions. Missing any of these during an exam or complaint review triggers a flag.

    cause

    The Real Reasons AI Claims Models Trigger Regulatory Flags

    No Documented AI Governance Program (AIS Program)

    The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted in December 2023, is the baseline nearly every state examiner now uses. It requires insurers to adopt, implement, and maintain a written AI governance program, called an AIS Program, that covers the full insurance lifecycle: underwriting, rating, marketing, fraud detection, and claim administration and payment. As of early 2026, 24 states have adopted the bulletin. If your claims model exists but your governance documentation does not, an examiner has grounds to flag the gap on its own, regardless of whether the model's outputs are actually biased.

    Examiners are not asking whether you used AI. They are asking whether you can produce a governance file: who owns the model, what data feeds it, how it was validated before deployment, and who signs off on changes. A claims model with no named accountable owner, no change log, and no board or senior management sign-off is a documentation failure before it is ever tested for bias.

    Untested Proxy Discrimination in Claims Outcomes

    A model can exclude race, sex, and other protected characteristics from its inputs entirely and still produce outcomes that correlate with them, because zip code, prior claim history, and repair-cost estimators can act as proxies. Colorado's SB 21-169 and its implementing regulation require life, auto, and health benefit insurers to run quantitative testing on algorithms and predictive models built on external consumer data, and to document the results. New York's Circular Letter 7, adopted July 11, 2024, goes further for underwriting and pricing models: insurers must assess for disproportionate adverse effects on protected classes, evaluate legitimate explanations for any differential effect, and search for less discriminatory alternatives, before deployment and at least annually after.

    A claims severity or fraud-flagging model that delays or downgrades payouts more often for policyholders in specific zip codes or demographic groups creates exactly this kind of adverse-impact exposure. Regulators do not need to prove intent. A pattern in the outcomes is enough to open an inquiry.

    Missing Audit Trail and Explainability for Claims Denials

    New York's guidance requires that any external data or AI system used in a covered decision have a clear, empirical, statistically significant, and rational relationship to the risk or outcome it is used to assess, and that the relationship not be unfairly discriminatory. In a claims context, that means a denial, a reduced payout, or a fraud referral produced or influenced by a model needs a defensible, documented reason, not just a score. If a claims adjuster cannot explain why the model flagged a claim, and the file contains no record of the model's validation or its limits, that is what a market conduct examiner writes up.

    This is also why vendor-built claims tools carry regulatory risk even when the insurer did not build the model. The NAIC bulletin explicitly extends AIS Program obligations to third-party AI, so an insurer cannot point to a vendor's black box as a reason it cannot produce documentation.

    Claims Handling Failures That Draw AI-Specific Scrutiny

    AI claims tools are increasingly the direct subject of investigations, not just a side issue. In November 2025, Los Angeles County opened a civil investigation into State Farm's handling of wildfire claims from the Eaton and Palisades fires, and its formal document request specifically sought records reflecting the insurer's use of AI tools in the review of claims. Separately, a California Department of Insurance market conduct examination of the same claims found 398 violations of state law across a sample of 220 claims, including failures to investigate, accept, or deny claims within required timeframes and unreasonably low settlement offers.

    That examination was not framed around AI specifically, but it illustrates the standard examiners apply to any claims process, human or automated: can the insurer show it followed a documented, defensible process for every claim, and can it produce that documentation on request. An AI claims model that cannot produce equivalent records is held to the same bar and fails it faster.

    evidence

    What Regulators Have Actually Found and Required

    The regulatory record on AI in insurance is no longer theoretical. The NAIC's Model Bulletin was adopted by member vote on December 4, 2023, following two public comment periods, and by early 2026 it had been adopted in some form by 24 states. NAIC Commissioner Kathleen Birrane described the effort as one meant to set 'clear expectations' while 'balancing the potential for innovation with the imperative to address unique risks.' A 12-state pilot of the NAIC's AI Systems Evaluation Tool, launched in early 2026, gives examiners a standardized way to score an insurer's AI governance, risk management, and model testing during an exam, which means claims models are now a routine line item in exam scope, not a special case.

    New York's Circular Letter 7 lays out a specific three-step bias test that examiners expect to see applied and documented: assess for disproportionate adverse effects on protected classes, evaluate whether a legitimate business explanation accounts for any difference, and search for a less discriminatory alternative that serves the same legitimate purpose. Colorado's Division of Insurance, under amended Regulation 10-1-1 effective October 15, 2025, requires life, auto, and health benefit insurers to inventory every algorithm and predictive model built on external consumer data, test it, and file compliance attestations, with life insurers' initial compliance reports already due in 2024.

    On the enforcement side, the Los Angeles County investigation into State Farm is a concrete example of a government body demanding an insurer's internal documentation of how its AI tools were used to review claims, not just its overall claims outcomes. A parallel California market conduct examination of State Farm's wildfire claims handling found violations in more than half of the 220 claims sampled. Whether or not AI narrowly caused any individual violation, the pattern of undocumented, unexplained claims decisions is exactly what triggers both types of inquiry.

    framework

    How to Self-Audit an AI Claims Model Before an Examiner Does

    Start with an inventory: list every model, script, or vendor tool that touches a claims decision, including severity scoring, fraud triage, damage estimation, and settlement recommendation tools, whether built in-house or licensed from a vendor. For each one, map it against the elements the NAIC AIS Program expects: a named accountable owner, a written risk assessment, a pre-deployment validation record, a monitoring and revalidation schedule, and a documented process for consumer inquiries or appeals of an AI-influenced decision.

    Next, run the quantitative test regulators actually ask for: calculate adverse impact ratios or similar statistical measures across protected classes on claims outcomes such as denial rate, payout amount, and processing time, not just on underwriting or pricing. If a disparity shows up, document the legitimate business explanation you evaluated and the less discriminatory alternative you considered, mirroring the three-step process New York's Circular Letter 7 describes. Finally, treat vendor-built claims tools the same way. Request the vendor's own testing and validation documentation in writing, because an examiner will ask for it and 'the vendor built it' is not an accepted answer under the NAIC bulletin or Colorado's regulation.

    differentiation

    How Kriv AI Helps

    Kriv AI builds and audits the documentation trail that state regulators are now asking for by name: AIS Program documentation aligned to the NAIC Model Bulletin, adverse impact testing on claims and underwriting outcomes, and vendor due diligence files that hold up under a market conduct exam. Work for regulated insurers is billed at Kriv AI's standard regulated-industry rate of $200 per hour, with fractional AI governance lead engagements at $300 to $400 per hour for carriers that need ongoing oversight rather than a one-time review. All engagements carry an $8,000 minimum.

    If your claims model has already drawn a regulator inquiry, or you want a documented governance program in place before one arrives, a discovery call is the fastest way to scope what an examiner would actually ask for, and where your current documentation would come up short.

    Straight answers

    Frequently asked questions about Why Did Our AI Claims Model Get Flagged by State Regulators?

    What specifically causes a state regulator to flag an AI claims model?

    Regulators most often flag an AI claims model for one of four reasons: no documented AI governance program covering claims processing, no quantitative testing for disproportionate impact on protected classes, no audit trail explaining individual claims decisions, or reliance on a vendor tool with no due diligence file. Any one of these can trigger a written finding in a market conduct exam.

    Does the NAIC Model Bulletin cover claims processing or just underwriting?

    The NAIC Model Bulletin, adopted in December 2023, explicitly covers the full insurance lifecycle, including claim administration and payment and fraud detection, not just underwriting and rating. An insurer's AIS Program is expected to address AI used anywhere in that lifecycle.

    Does Colorado SB 21-169 apply to claims models or only underwriting decisions?

    Colorado's law and its amended Regulation 10-1-1 focus primarily on underwriting and rating algorithms for life, auto, and health benefit insurers, with governance, testing, and attestation requirements tied to external consumer data and predictive models. Claims-specific quantitative testing requirements have been narrower so far, but the same governance expectations, documentation, inventories, and bias testing, are increasingly applied by examiners to claims models as a matter of practice.

    What is proxy discrimination in an AI claims model?

    Proxy discrimination happens when a model does not use a protected characteristic like race or sex directly, but relies on inputs, such as zip code, repair cost estimates, or prior claim history, that correlate closely enough with that characteristic to reproduce a similar disparity in outcomes. New York's Circular Letter 7 requires insurers to test for exactly this kind of disproportionate effect and to document their findings.

    What documentation should we have ready if a regulator asks about our AI claims model?

    Have the model inventory, a pre-deployment validation report, adverse impact testing results across protected classes, a change log showing who approved updates, vendor due diligence records if the model is licensed rather than built in-house, and a written explanation process for how an individual claims decision can be reviewed or appealed.

    How much does it cost to fix AI claims governance gaps with Kriv AI?

    Kriv AI's regulated-industry work starts at $200 per hour for standard engagements and $300 to $400 per hour for fractional AI governance lead roles, with an $8,000 minimum engagement. The scope, and the cost, depend on how many models are in scope and how much governance documentation already exists.

    Talk to the team that would do the work

    Bring your requirements to a working session with the person who'll actually deliver.

    Book a Discovery Call