Enterprise / high-volume plans available on request.
Anonymous users get 10 free calls/day without a key.
Free resource
NAIC AI Model Bulletin Checklist
25 states and DC have adopted the NAIC's AI Model Bulletin since December 2023, with a formal AI Systems
Evaluation Tool for examiners now piloting in 12 states ahead of a broader rollout. This checklist maps the
bulletin's requirements to what an examiner actually expects an insurer's AI Systems Program to show. Enter
your work email to unlock it; it prints cleanly to PDF from your browser.
Enter your work email to unlock the full checklist
Unlock above to view all 24 checklist items across 4 sections.
1 · Scope & Applicability
State adoption check — has your state of domicile (and every state you write business in) adopted the NAIC Model Bulletin, or does it operate under its own framework (California, Colorado, New York, and Texas each have their own insurance-specific AI rules)?
AI/predictive model inventory — a documented list of every AI or complex predictive model used in underwriting, rating, claims, marketing, or fraud detection, with owner and business purpose for each.
Third-party AI tool inventory — every vendor AI/ML tool in use, since the bulletin makes clear the insurer remains fully responsible for third-party AI behavior, not just internally built models.
Line-of-business mapping — which AI systems touch which regulated lines (auto, homeowners, life, health), since exam scrutiny concentrates on consumer-facing underwriting and claims decisions.
AI Systems Evaluation Tool readiness — the NAIC's new structured examiner questionnaire is piloting in 12 states; confirm whether your state is a pilot state and, if so, whether you've reviewed the tool's question set.
Prior exam history — documentation of any prior market conduct exam findings related to AI, algorithms, or automated underwriting, and remediation status.
2 · Written AI Systems Program
Board and senior-management accountability — documented evidence that AI governance responsibility sits with named senior individuals, not diffused across a team.
Written AI governance policy — a formal document describing how AI systems are developed, tested, approved, deployed, and retired, consistent with the bulletin's expectations.
Risk classification framework — a documented method for tiering AI systems by consumer impact and materiality, so oversight intensity matches actual risk.
Roles and responsibilities — clear documentation of who builds, who validates, and who approves each AI system, with segregation between those roles.
Consumer protection controls — documented safeguards against unfair discrimination in rating and underwriting outcomes, consistent with each state's unfair trade practices act.
Policy review cadence — a defined schedule for reviewing and updating the AI Systems Program itself, not just the models it governs.
3 · Model Testing & Validation
Pre-deployment testing — documented testing for accuracy and bias before a model goes into production, not just after a complaint or exam triggers review.
Bias and disparate-impact testing — a defined methodology for testing whether the model produces disparate outcomes across protected classes, with results retained as evidence.
Independent validation — testing performed or reviewed by someone independent of the model's development team.
Ongoing monitoring — a documented process for tracking model performance and outcome drift after deployment, on a defined cadence.
Explainability documentation — for underwriting and claims decisions, documentation sufficient to explain a specific outcome to a policyholder or examiner on request.
Re-validation triggers — defined criteria (model update, new data source, performance drift) that trigger re-testing before continued use.
4 · Third-Party Oversight & Documentation
Vendor due diligence file — documentation of what your firm independently verified about a vendor AI tool versus what you're relying on the vendor's own representations for.
Vendor contract AI provisions — contract language giving your firm audit rights, model change notification, and data access sufficient to meet your own oversight obligations.
Complaint and inquiry log — a record of consumer complaints or regulator inquiries tied to AI-driven decisions, with resolution documented.
Examiner-ready evidence package — the underlying test results, governance minutes, and monitoring records assembled in a form an examiner can review directly, not just a policy binder.
Cross-framework alignment — if you also operate under SR 11-7, EU AI Act, or another jurisdiction's AI governance regime, documentation showing how the NAIC program interacts with those rather than duplicating from scratch.
Named point of contact — a specific individual designated to respond to a market conduct exam request for AI Systems Program documentation.
Need this filled in, not just outlined?
We build the bias and accuracy test suite, run the validation, and write the report your AI Systems Program can cite — section 3 above, done for your specific model.
This checklist is educational, not legal advice — NAIC bulletin adoption and enforcement vary by state, and
several states run their own frameworks entirely. Confirm your specific state's requirements with qualified
counsel. See our disclaimer for more.