We use cookies to understand how this site is used. Privacy policy

    Skip to main content
    Kriv AI

    Insurance Regulatory Governance

    NAIC AI Model Governance Consulting for Insurers

    What NAIC-aligned AI model governance actually means for a carrier building underwriting, claims, and pricing systems, and why the Model Bulletin's principles-based language leaves most of the hard implementation work to the insurer.

    Kriv AI provides NAIC-aligned AI model governance consulting for insurers: an outside team that inventories every AI system touching underwriting, claims, pricing, and marketing, builds the governance program a state insurance department's AI Model Bulletin exam expects, and validates model outputs against unfair-discrimination and fairness standards before an examiner asks for it.

    provides naic ai

    Who Provides NAIC AI Model Governance Consulting for Insurers

    Kriv AI provides NAIC-aligned AI model governance consulting for insurers: an outside team that inventories every AI system touching underwriting, claims, pricing, and marketing, builds the governance program a state insurance department's AI Model Bulletin exam expects, and validates model outputs against unfair-discrimination and fairness standards before an examiner asks for it.

    The work centers on the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted by NAIC membership in December 2023 and since issued as a bulletin by a growing list of state insurance departments. It is not a single federal rule. Each state's department of insurance decides whether and how to issue it, so a carrier licensed in multiple states is really managing a family of closely related state bulletins rather than one national standard.

    The bulletin's core expectation is straightforward to state and hard to operationalize: any decision or action affecting a consumer, taken or supported by a predictive model, algorithm, or AI system, has to comply with existing unfair trade practices and unfair discrimination law, and the insurer has to be able to show a regulator how it governs that. That is the gap this practice fills, turning the bulletin's principles into an inventory, a testing protocol, a governance structure, and documentation that survives a market conduct exam.

    naic model governance

    Why NAIC Model Governance Is So Hard to Implement for AI

    NAIC model governance is hard to implement for AI because the bulletin is deliberately principles-based rather than a technical checklist, because it is adopted state by state with small variations instead of once nationally, and because the systems it covers span underwriting, claims, and marketing teams that have never shared a common model inventory or a common definition of what counts as AI.

    The bulletin tells an insurer to have a governance framework proportionate to the risk of its AI use, but it does not specify a bias-testing method, a documentation template, or a validation cadence the way a technical standard would. That is intentional, so it can cover everything from a simple rules-based rating factor to a generative underwriting assistant, but it means two carriers can both be technically compliant with very different levels of actual rigor, and an examiner has real discretion in what they consider adequate.

    State-by-state adoption compounds this. A multi-state carrier is tracking which departments have issued the bulletin, whether any have layered on their own examination guidance, and keeping one governance program that satisfies all of them at once rather than rebuilding it per state.

    The organizational problem is usually the bigger one. Actuarial and pricing teams, claims operations, marketing, and compliance each run their own models and vendor tools, often without a shared inventory. A model governance program has to reach across all of those groups, assign a single accountable owner, and get third-party and vendor-built models (which insurers frequently cannot fully inspect) into the same inventory and testing regime as models built in-house. Most of the effort in a real engagement goes into that cross-functional coordination, not into the regulatory reading.

    insurers implement naic

    How Insurers Implement NAIC AI Governance, Step by Step

    Insurers implement NAIC AI governance by working through a fixed sequence: build a complete AI system inventory, assign risk tiers, put named accountable owners and a governance committee in place, define testing and validation appropriate to each tier, document the program for exam readiness, and monitor it on an ongoing basis rather than treating it as a one-time project.

    1. 1. Build the AI system inventory

      Catalog every model, algorithm, and AI system that touches a consumer-facing decision: underwriting and rating, claims triage and fraud scoring, marketing and lead scoring, and any vendor or third-party tool used in those processes. Vendor-built models go in the inventory too, even when the insurer cannot see inside them.

    2. 2. Risk-tier each system

      Rank systems by how directly they affect a consumer outcome and how much human review sits between the model's output and the final decision. A fully automated adverse underwriting decision sits in a higher tier than a marketing recommendation a human reviews before acting on it.

    3. 3. Assign accountable ownership

      Name a single accountable executive and a cross-functional governance committee spanning actuarial, compliance, claims, IT, and legal, so no system sits in a gap between departments.

    4. 4. Define testing and validation by tier

      Set the testing protocol for each risk tier: fairness and unfair-discrimination testing against protected classes and their proxies, output accuracy checks, and, where the system is a large language model rather than a traditional predictive model, structured output review and red-teaming instead of classical backtesting.

    5. 5. Document for exam readiness

      Write the governance framework, inventory, and testing results into the form a market conduct exam expects: what the system does, who owns it, how it was tested, and what the results showed, in language a non-technical examiner can follow.

    6. 6. Monitor and re-certify

      Re-test higher-tier systems on a set cadence, re-certify the inventory when a system changes or a new one is deployed, and keep the governance committee meeting on a schedule so the program does not go stale between exams.

    responsible ai means

    What Responsible AI Means for Insurance Underwriting

    Responsible AI for insurance underwriting means the rating variables and model logic behind an underwriting decision have been tested for proxy discrimination, an adverse decision can be explained to the consumer and to a regulator in plain language, a human reviews or can override automated declines and non-standard pricing, and every step of that process is documented as it happens rather than reconstructed after a complaint.

    In practice this starts with the rating variables themselves. A variable that is facially neutral, such as a credit-based score, zip code proxy, or device or browsing signal, can still correlate with a protected class closely enough to function as an unlawful proxy. Responsible underwriting governance tests for that correlation directly rather than assuming a variable is safe because it does not name a protected class.

    It also means the model's reasoning is explainable at the level an adverse-action notice requires: an applicant who is declined or rated up has to be able to learn why in terms tied to their own application, not a model score with no underlying explanation. For any system where the underwriting decision is fully automated, a documented human review or override path has to exist for the higher-risk outcomes, and the governance program has to be able to show, after the fact, that the review actually happened.

    naic governance relates

    How NAIC Governance Relates to SR 26-2 and the NIST AI RMF

    Insurers are not directly subject to the Federal Reserve's model risk guidance, but most NAIC governance programs borrow its structure anyway, because the Model Bulletin sets expectations without specifying a method and the banking framework already solved that problem for a different regulator.

    SR 11-7, the Federal Reserve's original 2011 model risk management guidance, and its 2026 revision SR 26-2, apply to banking organizations, not insurers. But their three-part structure, robust model development, independent validation, and defined governance, maps cleanly onto what a NAIC examiner is actually looking for, and most carriers build their AI governance program on that same skeleton rather than inventing a new one.

    The NIST AI Risk Management Framework fills the technical layer the bulletin leaves open. Its four functions, govern, map, measure, and manage, give a carrier a concrete way to structure the inventory, risk-tiering, testing, and monitoring work the bulletin calls for in general terms, without requiring the insurer to invent its own taxonomy from scratch.

    kriv ai naic

    What a Kriv AI NAIC Governance Engagement Includes

    A typical engagement starts with the inventory and risk-tiering work, then builds the governance structure, testing protocol, and exam-ready documentation around it, and stays on as an advisory relationship through the carrier's first regulatory exam under the new program.

    The starting deliverable is always the same: a complete inventory of AI systems in production or pilot across underwriting, claims, pricing, and marketing, each one risk-tiered and assigned an accountable owner. From there the engagement builds the governance charter and committee structure, a testing and validation protocol matched to each tier, including fairness and proxy-discrimination testing, and the documentation packet a market conduct exam will actually ask to see.

    Because the bulletin's language is principles-based, the highest-value part of the engagement is usually translating it into artifacts a compliance team and an examiner can both use: a plain-language system description, a testing summary, and a change log, rather than a purely legal read of the regulation.

    rates work

    Rates for This Work

    Rates below are floors, not fixed quotes; final scope depends on the number of AI systems in the inventory and whether the engagement is a one-time buildout or an ongoing retainer.

    TrackHourly RateModelMinimum
    Enterprise/Regulated InsurerFrom $200/hrFixed-scope or retainer$8,000
    Fractional AI Governance Lead$300-$400/hrPart-time, ongoing$8,000
    Specialized Advisory$400-$700/hrHourly, per-sessionVaries

    get real quote

    How to Get a Real Quote

    A real quote needs the size of the AI system inventory and whether any exam or complaint is already in motion.

    Bring a rough count of the AI and predictive models already in production across underwriting, claims, and marketing, the states the carrier is licensed in, and whether a state department has already asked for governance documentation. That is enough to scope a fixed engagement or a retainer and quote it against the rates above rather than the floor.

    Straight answers

    Frequently asked questions about NAIC AI Model Governance Consulting for Insurers

    Who provides NAIC model governance consulting for insurers?

    Kriv AI provides NAIC-aligned AI model governance consulting for insurers, building the AI system inventory, risk-tiering, testing protocol, and exam-ready documentation a state insurance department's Model Bulletin expects, across underwriting, claims, pricing, and marketing AI systems.

    Why is NAIC model governance so hard to implement for AI?

    Because the Model Bulletin is principles-based rather than a technical checklist, is adopted state by state with small variations instead of as one national rule, and covers systems spread across actuarial, claims, marketing, and vendor tools that rarely share a common inventory before the governance work starts.

    How do insurers implement NAIC model governance for AI?

    By building a complete AI system inventory, risk-tiering each system, assigning a named accountable owner and governance committee, defining testing and validation matched to each tier, documenting the program for exam readiness, and monitoring and re-certifying it on an ongoing basis.

    What is responsible AI for insurance underwriting?

    Responsible AI for underwriting means rating variables are tested for proxy discrimination against protected classes, an adverse decision can be explained in plain language to the consumer and a regulator, a human can review or override higher-risk automated decisions, and each step is documented as it happens.

    What is the NAIC Model Bulletin on AI, exactly?

    It is the Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted by NAIC membership in December 2023, which sets expectations for how insurers govern AI and predictive models used in consumer-facing decisions and tells state departments what to ask for during an investigation or exam.

    Does the NAIC AI Model Bulletin apply in every state?

    No. The bulletin is a model document; each state insurance department decides independently whether to issue it and can layer on its own examination guidance, so a multi-state carrier is managing a family of related state-level bulletins rather than one uniform federal rule.

    How is NAIC AI governance different from SR 11-7 or SR 26-2?

    SR 11-7 and its 2026 revision SR 26-2 are Federal Reserve model risk guidance for banking organizations, not insurers. Insurers are not directly subject to either, but many build their NAIC governance program on the same development, validation, and governance structure because the bulletin itself does not specify a technical method.

    Talk to the team that would do the work

    Bring your requirements to a working session with the person who'll actually deliver.

    Book a Discovery Call