NAIC AI Supplement v5: an insurer evidence checklist.
An insurer can have an AI policy and still struggle to answer a regulator's questions about a particular model. The useful preparation is to connect each answer to a current record, an accountable owner and the relevant insurance entity.
Regulatory snapshot
- Status: consultation draft following the August 31, 2026 working-group meeting, not a final adopted supplement.
- Effective date: no implementation date is established by this exposure notice.
- Purpose: optional exhibits supporting existing supervisory reviews of insurer AI use, as described in the version 5.0 draft (DOCX).
What changed in version 5
The NAIC's summary of changes makes the supplemental role more explicit: existing handbooks guide decisions about which insurers receive inquiries. It clarifies materiality and inherent risk, separates AI systems from models, and distinguishes direct consumer impact from material financial impact.
Exhibit A now expressly requests a model inventory. Exhibit B asks for document names and page references and adds questions about materiality and third-party models. The revisions also sharpen model and data questions in Exhibits C and D and add an agentic-AI definition. The operational implication is a more precise link between a response and the evidence supporting it.
What did not change
The draft does not replace applicable state law. Its instructions retain existing handbook authority and allow tailored inquiries. Exhibit B explicitly says its questions do not create new AIS Program requirements.
The separate NAIC Model Bulletin on insurer AI describes governance expectations grounded in existing insurance laws. A model bulletin is not itself uniform legislation in every state: check the relevant department's adopted text and legal authority. Our NAIC Model #668 adoption tracker covers insurance data-security laws, a different instrument that should not be used as a proxy for AI-bulletin adoption.
Who should prepare
This analysis is for insurer compliance, actuarial, model-risk and technology teams that may need to answer AI-related supervisory inquiries. The draft's exhibits cover AI usage, the AIS Program, high-risk models and model data. Actual inquiry scope depends on the regulator and the review; there is no basis here to assume every insurer must submit every exhibit.
For a group, the practical question is whether a shared model operates under different approvals or controls in different legal entities. Keep that distinction visible in the insurance compliance workflow instead of relying on a group-level policy alone.
Recommended evidence checklist
The following steps are Sia's operational recommendations, not additional NAIC requirements.
- Choose one live use case for a rehearsal. A claims-triage model is a useful example: identify who owns its deployment, who can change it and which legal entities use it. Give the record a stable identifier so later responses refer to the same system and model version.
- Write down the scoping decision before collecting documents. Record which entities, business activities and time period the rehearsal covers. Keep unresolved scope questions in a separate decision log for compliance or counsel; do not silently exclude a model because its documentation is difficult to obtain.
- Test whether an independent reviewer can reproduce the answer. Link a proposed response to a dated approval or test report and the relevant section. Ask the reviewer to explain what that record proves. A policy promising regular testing does not establish that the deployed version was tested.
- Reconcile the vendor handoff. Compare the version described in the supplier's assurance material with the version in production. Assign an owner to any missing information and agree how the insurer will review it. Keep contractual access questions separate from the technical assessment.
- Record weaknesses without smoothing them away. Distinguish evidence that exists but needs validation from a control that has not been implemented. Give each issue an owner, a target date and an escalation decision. Preserve that history when a replacement document arrives.
- Run a controlled response rehearsal. Have the business owner confirm factual accuracy and counsel review disclosure scope, confidentiality and the requesting authority. Record the approved response version and recipients. Set access permissions before assembling documents containing consumer information.
If the firm already uses the NIST AI Risk Management Framework, reuse its control records where they answer the question. Keep a separate applicability decision for state-specific requirements; a framework mapping is not a legal conclusion.
How Sia RegAI can support the workflow
Subject to source configuration and review, RegReview can support monitoring of NAIC publications and relevant state developments. RegMatcher can help relate selected questions or applicable obligations to policies and evidence, with gaps routed to owners. Draft questions should remain labelled separately from binding requirements. Compliance and counsel approve applicability, interpretations and submissions; technical reviewers assess the model evidence. These workflows do not guarantee regulatory acceptance. Discuss an insurer AI evidence review using one scoped use case.
What to watch next
Check the October 8 discussion and subsequent NAIC publications for revisions, adoption decisions or implementation guidance. Before responding to an actual inquiry, confirm its current scope directly with the requesting department. Preserve the draft version used in preparation so that later changes can be reviewed rather than silently overwritten.
Primary sources
- NAIC working-group page: exposure notice and meeting schedule
- AI Risk Evaluation Supplement v5.0: exposure draft (DOCX)
- NAIC summary of changes from version 4.0 (PDF)
- NAIC Model Bulletin: Use of Artificial Intelligence Systems by Insurers (PDF)
This analysis is general information, not legal advice. Status was checked on September 30, 2026. Confirm current NAIC materials, state-specific requirements and the authority and terms of any supervisory request.
