Artificial intelligence is becoming embedded across the insurance enterprise, supporting activities ranging from marketing and underwriting to claims, customer service, fraud detection and financial management. As adoption expands, state insurance regulators are moving beyond broad discussions of responsible AI and developing more structured ways to evaluate how insurers identify, govern and control the risks associated with these systems.
The National Association of Insurance Commissioners’ draft Artificial Intelligence Risk Evaluation Supplement is an important development in that evolution. Created by the NAIC Big Data and Artificial Intelligence Working Group, the supplement is intended to help regulators identify and assess consumer and financial risks associated with insurers’ use of AI systems. It is designed to supplement existing market conduct, financial analysis and financial examination procedures, not replace the authoritative handbooks or establish an entirely separate examination framework.
The draft is also expressly structured as a flexible, risk-based resource. Regulators may customize their inquiries, limit requests to specific operational areas and determine that additional review is unnecessary when an insurer’s AI use is limited or presents low inherent risk.
The NAIC has also published a summary of changes to the AI Risk Evaluation Supplement, explaining how feedback from the pilot informed revisions to the document’s intent, instructions, materiality guidance and individual exhibits.
While the supplement remains in draft, it gives insurers a valuable view into the information insurance regulators may seek when evaluating AI-related risk.
From AI Principles to Demonstrable Oversight
Much of the regulatory conversation surrounding AI has focused on principles such as fairness, accountability, transparency and governance. The supplement translates many of those principles into specific questions and documentation requests.
The supplement builds on governance expectations reflected in the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, while giving regulators a more structured way to request and evaluate supporting information. The supplement expressly draws definitions from the Model Bulletin where available.
In practical terms, insurers may need to demonstrate more than the existence of an AI policy or governance committee. They may be asked to show where AI is used, how systems are classified by risk, which controls apply, how performance is tested and monitored, and what evidence supports management’s conclusions.
This distinction matters. A governance framework may describe what an organization intends to do. An examination-ready program must also provide evidence that the framework has been implemented and is operating effectively.
The supplement organizes this inquiry through four exhibits:
- Exhibit A: Quantify the regulated entity’s use of AI systems
- Exhibit B: Evaluate the insurer’s AI Systems Program through a narrative or checklist
- Exhibit C: Review high-risk AI models
- Exhibit D: Examine the data used by AI models
Together, the exhibits create a structured path from enterprise-level discovery to more focused examination of governance, individual models and underlying data. identify whether an activity is investment-related, whether it involves firm customers and whether it could reasonably be viewed as part of the firm’s business.
Exhibit A: Building a Defensible AI Inventory
Exhibit A begins with a foundational question: Where and how is the insurer using AI?
The draft asks for information about AI systems and models used across operational areas such as marketing, premium quotes and discounts, underwriting and eligibility, ratemaking, claims, customer service, utilization review, fraud detection, investments, reserves, catastrophe triage and reinsurance. It separates models with direct consumer impact from those with material financial impact and asks insurers to identify associated use cases.
The breadth of these categories illustrates why AI inventory management should not be confined to the technology organization. Relevant systems may be deployed or procured across business units, subsidiaries and lines of business, sometimes without a centralized view of their purpose, ownership or risk.
An insurer with an existing AI systems inventory may suggest submitting it instead of completing parts of Exhibit A. The draft also contemplates requests for a model inventory that includes each model’s name, use, broader use case, operational area, inherent risk classification, consumer impact and financial impact.
For insurers, this makes inventory completeness and consistency a key readiness consideration. An effective inventory should make it possible to connect each material AI system or model to:
- A defined business owner
- Its intended use and operational context
- Consumer and financial impacts
- An inherent risk assessment
- Applicable policies and controls
- Internal or third-party development sources
- Supporting validation and monitoring records
The goal is not simply to create a list. It is to establish a reliable system of record that supports governance, risk assessment and regulatory response.
Exhibit B: Making the AI Systems Program Examinable
Exhibit B focuses on the insurer’s AI Systems Program, defined in the draft as the controls and processes adopted to ensure the responsible use of AI systems. The program may include governance guidelines, risk management, internal controls and third-party oversight.
The exhibit offers narrative and checklist formats and addresses a broad range of governance topics, including:
- Board and management involvement
- Assignment of responsibility
- Risk identification, mitigation and remediation
- Integration with enterprise risk management and, where applicable, the Own Risk and Solvency Assessment
- Compliance with state and federal laws
- Data privacy and consumer protection
- Employee training and prohibited practices
- Consumer complaint tracking
- Testing, validation and ongoing monitoring
- Transparency and explainability
- Standards for AI vendors
- Governance of vendor-developed systems
The draft states that these questions are not intended to create new AI Systems Program requirements. Nevertheless, the level of detail provides insurers with a practical guide to the governance areas regulators may examine.
One notable feature is the emphasis on documentation. The checklist allows insurers to reference the document and page where a policy, process or control is addressed. If it is not documented in the AI Systems Program, the insurer may be asked to provide an explanation directly in its response.
This structure makes policy management and control evidence particularly important. Insurers should be able to locate the current policy, identify its owner and approval history, connect it to the applicable AI risks, and produce evidence that required reviews, tests or attestations occurred.
Exhibit C: Greater Scrutiny of High-Risk Models
Exhibit C moves from enterprise governance to individual in-production models considered high risk. The draft describes these as models that could cause adverse consumer outcomes, material financial impact, material consumer impact or material financial reporting impact. The insurer establishes its model-risk criteria, with materiality considered in determining the level of risk.
For each requested model, regulators may seek information including:
- Model name, version and implementation date
- Use case and purpose
- Model type
- Internal or third-party development source
- Risk classification and known limitations
- Potential consumer impact
- Whether the model automates, augments or supports decisions
- Pre-deployment validation
- Ongoing performance monitoring
- Testing for drift, accuracy, unfair discrimination and performance degradation
- Compliance review under applicable state and federal laws
- Relevant regulatory actions or remediation
This exhibit highlights the importance of maintaining a complete, current record throughout the model lifecycle. Testing results stored in one system, vendor documentation in another and approvals retained in email may make it difficult to produce a timely, coherent response.
Insurers should consider whether they can assemble a regulator-ready record for a high-risk model without launching a lengthy, organization-wide information search.
Exhibit D: Understanding the Data Behind AI Decisions
AI governance cannot be separated from data governance. Exhibit D asks insurers to identify data used in model development, training, testing and operations, explain how the data is used, and distinguish between internal and third-party sources.
The listed data elements include geocoding and geo-demographic data, driving behavior, social media information, personal financial information, medical and biometric data, facial or body recognition, image and video analysis, voice analysis, telematics, weather information and other non-traditional data.
These requests can help regulators assess risks related to adverse consumer impact, unfair trade practices, financial impact and financial reporting. Depending on the insurer’s response, a regulator may also request a data dictionary to develop a more complete understanding of the information used by a model.
When Exhibit D is read together with the NAIC Model Bulletin and Exhibit B, readiness may involve explaining why data is suitable for the model’s purpose, how data is governed and who is responsible for reviewing third-party data.
Third-Party AI Does Not Transfer Accountability
Vendor oversight is reflected across the AI Risk Evaluation Supplement and the NAIC Model Bulletin. Within the supplement, Exhibit B addresses the procurement, governance, monitoring, testing and transparency of vendor-developed AI systems. Exhibit C asks whether a model was purchased or developed for the insurer and whether the insurer can modify it, while Exhibit D asks firms to identify third-party data providers by name. Read together, these materials reinforce the importance of maintaining oversight of third-party AI systems, models and data.
Together, these questions reinforce a central consideration for insurers: Using a third-party model or data source does not eliminate the need for effective oversight.
Organizations should understand what evidence they can obtain from a vendor, which validation responsibilities remain with the insurer, how model changes are communicated and whether contractual provisions support regulatory information requests.
Five Recommended Steps Insurers Can Take Now
The supplement remains a draft, but insurers do not need to wait for a final version to evaluate their preparedness. The following actions can help strengthen AI governance and examination readiness:
1. Establish or validate the AI inventory
Identify AI systems and models across the enterprise, including third-party technologies and systems embedded within broader business platforms. Assign ownership and document the use case, risk classification, consumer impact and financial impact for each relevant application.
2. Map governance documentation to the draft questions
Compare existing policies, standards and procedures with the topics in Exhibit B. Record where each topic is addressed and identify areas where a control exists operationally but is not adequately documented.
3. Assemble model-level evidence
For higher-risk models, centralize development records, approvals, validation results, monitoring reports, drift testing, compliance reviews and remediation histories. The objective should be a cohesive record that explains both how the model works and how its risks are controlled.
4. Review third-party oversight
Evaluate AI vendors and data providers through a consistent risk-based process. Clarify documentation rights, validation responsibilities, change-notification requirements and access to information that may be needed during an examination.
5. Test the regulatory response process
Conduct a readiness assessment using the four exhibits as a mock information request. Assign response owners, identify source systems and assess whether supporting evidence can be collected, reviewed and approved efficiently.
The Emerging Standard: Examination-Ready AI Governance
The AI Risk Evaluation Supplement does not replace existing examination standards, and its questions are not presented as new AI Systems Program requirements. It does, however, provide a detailed view of the governance, inventory, model and data information that may support future regulatory inquiries.
NAIC working group materials from August 2026 state that the pilot began in March and involved 12 participating states. The materials also indicate that individual state pilots continued through June and July, with the broader pilot scheduled to continue through September.
For insurers, the primary takeaway is straightforward: Responsible AI will increasingly need to be demonstrable. Firms should be prepared to show where AI is used, who is accountable, how risks are assessed, how models and data are monitored, how vendors are governed and what evidence confirms that controls are working.
Organizations that build those capabilities now will be better positioned to respond consistently as regulatory expectations evolve.
How RegEd Can Help
Is your organization prepared to respond to an AI-related regulatory inquiry?
RegEd’s Regulatory Examination Management solution can help firms coordinate examination responses, centralize supporting documentation and evidence, assign and track response owners, and run mock audits to test readiness across the compliance lifecycle. RegEd’s educational courses can train and help prepare staff and employees, and our questionnaires and attestations solutions can collect data and document your agents’ understanding of firm policies.
Contact RegEd to learn how an integrated, workflow-enabled approach can strengthen regulatory examination readiness as AI oversight continues to evolve.
About RegEd
RegEd is the market-leading provider of RegTech enterprise solutions with relationships with more than 200 enterprise clients, including 80% of the top 25 financial services firms.
Established in 2000 by former regulators, the company is recognized for continuous regulatory technology innovation with solutions hallmarked by workflow-directed processes, data integration, regulatory intelligence, automated validations, business process automation and compliance dashboards. The aggregate drives the highest levels of operational efficiency and enables our clients to cost-effectively comply with regulations and continuously mitigate risk.
Trusted by the nation’s top financial services firms, RegEd’s proven, holistic approach to RegTech meets firms where they are on the compliance and risk management continuum, scaling as their needs evolve and amplifying the value proposition delivered to clients. For more information, please visit www.reged.com.