Skip to main content
    Kriv AI

    Insurance and Financial Services

    What Is Responsible AI for Insurance Underwriting?

    Insurers already run AI on pricing, risk selection, and claims. The rules for doing that responsibly are no longer voluntary in roughly half the country, and a life insurer and an auto insurer do not follow the same ones.

    Responsible AI for insurance underwriting means using AI systems for pricing, risk selection, and eligibility decisions under a written governance program that tests for unfair discrimination, documents data sources, and keeps human oversight over adverse outcomes. In the U.S. this is now enforced through the NAIC Model Bulletin, adopted by 24 states, and state-specific rules like Colorado's algorithm testing regulation.

    regulatory basis

    The NAIC Model Bulletin Is the Baseline

    Insurers already run AI and predictive models on underwriting, pricing, and claims decisions in production. The baseline rule for doing that responsibly in the United States is the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted by the National Association of Insurance Commissioners in December 2023. As of March 2025, 24 states had adopted the bulletin with little to no material changes, applying it to the AI systems insurers use for underwriting, rating, claims handling, marketing, and fraud detection.

    The bulletin does not introduce a new legal standard so much as make an existing one explicit: insurers using AI still have to comply with the insurance laws already on the books, including those addressing unfair trade practices and unfair discrimination. What is new is the expectation that insurers can document how they meet that standard, not just assert that they do.

    governance

    What the Bulletin Actually Requires of an Underwriting AI Program

    A Written AI Systems Program

    The bulletin's central requirement is a written AI systems program covering any AI system that makes or supports a regulated decision. Regulators expect the governance structure behind that program to include representatives from the disciplines actually touching the model, actuarial, data science, underwriting, compliance, and legal, each with defined responsibilities. Risk management controls have to scale with the type and degree of potential harm to a consumer, so a pricing model that can affect coverage draws more scrutiny than a marketing algorithm.

    Testing and validation obligations run through the AI system's entire lifecycle, not just at launch. Data quality, integrity, and bias have to be managed on an ongoing basis, and systems must be revalidated as they are retrained or as the population they score changes.

    Third-Party and Vendor Model Oversight

    Most of the AI insurers use for underwriting is licensed from a vendor, not built in house. The bulletin is explicit that buying a model from a vendor does not transfer away the underlying model risk: insurers stay responsible for vendor diligence, including how the vendor acquired and used the data underlying the model, even where the vendor's methodology is proprietary.

    state rules

    State Rules Layer On Top: Colorado's Algorithm Testing Regulation

    The NAIC bulletin is a floor, not a ceiling. Colorado's Division of Insurance, acting under its own statute, C.R.S. section 10-3-1104.9, went further with a quantitative testing requirement now in force under Regulation 10-1-1. The rule originally applied only to life insurers' use of external consumer data and information sources, algorithms, and predictive models. Colorado extended the same testing regime to private passenger automobile insurance and health benefit plans effective October 15, 2025.

    The core obligation is quantitative testing for disparate impact, applied to both facially neutral data and to full underwriting models, and insurers have to run that testing whether or not they have reason to believe discrimination is occurring. External consumer data and information sources, ECDIS for short, covers non-traditional data an insurer pulls in from outside its own underwriting file, such as credit-related attributes or other third-party inputs. Colorado's rule requires documentation of how each ECDIS source is used, with regular reporting to senior management.

    framework

    What a Responsible AI Underwriting Program Has to Cover

    1. 1. AI and Model Inventory

      A documented list of every AI system and predictive model touching underwriting, rating, or claims, detailed enough for a regulator to see what it does and what data feeds it.

    2. 2. Written Governance Program

      A program spanning actuarial, data science, underwriting, compliance, and legal stakeholders, with named accountability for each stage of a model's lifecycle.

    3. 3. Disparate-Impact and Bias Testing

      Quantitative testing of underwriting outcomes across protected classes and their proxies, run on a defined cadence rather than once at launch, expected regardless of whether discrimination is suspected.

    4. 4. Data and Vendor Provenance

      Documentation of where every data source, including third-party and external consumer data, comes from and how a vendor model was validated before deployment.

    5. 5. Documentation and Regulatory Reporting

      Records thorough enough to support the annual reporting some states, including Colorado, require, and to survive a market-conduct exam without reconstruction under deadline pressure.

    6. 6. Ongoing Monitoring and Revalidation

      A defined process for retesting and revalidating models as they are retrained, as the underlying population shifts, or as new state rules take effect.

    differentiation

    How Kriv AI Helps

    Kriv AI works with insurers to build the responsible AI underwriting program the NAIC Model Bulletin and state-specific rules like Colorado's actually require: AI system inventory, disparate-impact testing design, vendor and third-party data due diligence, and the documentation a state examiner or annual report expects to see. This is advisory and implementation work built directly into an insurer's underwriting process, not a framework workshop.

    Enterprise and regulated-industry engagements start at a $200 hourly floor, a fractional AI governance lead who owns the program on an ongoing basis runs $300 to $400 per hour, and specialized advisory work, including disparate-impact testing design, runs $400 to $700 per hour. All engagements carry an $8,000 minimum. See current rate detail on the pricing page, or book a discovery call to scope what your underwriting AI inventory and testing program actually needs.

    Straight answers

    Frequently asked questions about What Is Responsible AI for Insurance Underwriting?

    What is responsible AI for insurance underwriting?

    Responsible AI for insurance underwriting means using AI systems for pricing, risk selection, and eligibility decisions under a written governance program that tests for unfair discrimination, documents data sources, and keeps human oversight over adverse outcomes, as required by the NAIC Model Bulletin and state rules like Colorado's algorithm testing regulation.

    Does the NAIC Model Bulletin on AI apply in my state?

    The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers had been adopted by 24 states as of March 2025, generally with little to no material changes from the model text. Check your state insurance department for its specific adoption status and any local amendments.

    What does Colorado's AI regulation require for underwriting?

    Colorado's Division of Insurance requires quantitative testing for disparate impact under C.R.S. section 10-3-1104.9 and Regulation 10-1-1. Originally limited to life insurers' use of external consumer data, algorithms, and predictive models, the requirement expanded to private passenger automobile insurance and health benefit plans effective October 15, 2025.

    What is ECDIS in insurance AI regulation?

    ECDIS stands for external consumer data and information sources, non-traditional data such as credit-related attributes or other third-party inputs that an insurer uses alongside its own underwriting file. Colorado's regulation requires insurers to document how each ECDIS source is used and to report on it to senior management.

    Is responsible AI underwriting the same as bias testing?

    No. Bias and disparate-impact testing is one required component, but a complete program also covers AI system inventory, written governance with named accountability, vendor and data provenance documentation, and ongoing monitoring as models are retrained or regulations change.

    How does Kriv AI help insurers build a responsible AI underwriting program?

    Kriv AI builds AI system inventories, disparate-impact testing design, vendor and third-party data due diligence, and regulator-ready documentation for insurers. Enterprise engagements start at $200 per hour, a fractional AI governance lead runs $300 to $400 per hour, and specialized advisory work runs $400 to $700 per hour, with an $8,000 minimum engagement.

    Talk to the team that would do the work

    Bring your requirements to a working session with the person who'll actually deliver.

    Book a Discovery Call