The exam-ready toolkit for everyone building, operating, and answering for AI in insurance
The exam is coming for your AI. Be ready to answer with your evidence.
If you build, run, or answer for AI anywhere in insurance, an exam is coming for it. State examiners now work from a common set of questions, the NAIC AI Risk Evaluation Supplement, and the answers have to be yours to produce. The reach is wide: it is addressed to carriers, but Exhibit B, question 4 asks them to describe the AI their MGAs, programs, and vendors run. So whether you build the model, sell it, or answer for it, the same test applies: can you prove it, with evidence you own and can export? Renting the AI is fine. This toolkit is the working answer: a scoring methodology, the engineering build behind it, a state-by-state tracker, and a changelog that moves when the regulation moves.
Where you put the probabilistic components decides your tier, your cost, and your exam. The map and the controls are for you.
The exhibits are addressed to you. Q3 and Q4 ask you to describe the AI your vendors and delegated operators run. You need one schema for the whole book.
You are the service provider in Q4. Your carrier answers with your evidence, or restricts what you can do.
Exhibit C and D name you. Q3b asks how you were validated. A separate vendor framework is in draft; your buyers will send you the contract schedule.
If a model touches quote, bind, or servicing on your side, you are in the chain, at whatever tier your systems occupy.
The Supplement in 60 seconds
The references throughout this guide ("Exh C 8", "checklist 3m") link to those items on the reference page. The Supplement is a set of questions examiners may ask. It is not a law, a certification, or a score.
The guide
Six parts, each anchored to the Supplement, each with its verified-versus-Nolte's-read ledger.
Nolte AI Readiness Methodology
A readiness rubric that turns the Supplement's four exhibits into five scorable pillars for anyone building or operating AI in insurance.
Part 2Building AI Systems That Survive an Exam
The nine engineering controls that produce the artifacts an exam asks for, what each costs, and what happens without it.
Part 3Tiering: which controls your system actually needs
A four-input scheme that sorts every AI system into four tiers, so you spend controls where the risk actually is.
Part 4Renting AI: what to ask for, and what to put in the contract
A nine-section evidence checklist and a fourteen-clause contract schedule for any AI you rent.
Part 5Where the guessing is allowed to happen
Where deterministic, probabilistic, and human placement belongs across the insurance stack, step by step.
Part 6Reporting: the AI governance bordereaux
The AI governance bordereaux: a monthly evidence flow that answers Exhibit B Q4 before an examiner asks.
State tracker
Every jurisdiction, three facts: has it adopted the NAIC model bulletin, does it run its own AI rule, and is it in the Supplement pilot.
Check your readiness
25 questions in five sections, about four minutes. You get a live score, the pillars you are weakest on, and the control that closes each gap. Answers stay in your browser; only an anonymous score is logged.
Check your readinessRead the methodologyChangelog
The part that makes this documentation living rather than published. Full changelog.
Self-assessment and orientation only. Nothing here is legal advice, a certification, or a compliance determination. Nolte is not affiliated with or endorsed by the NAIC. Exhibit references are paraphrased from Supplement draft 4.0; the wording that counts is the NAIC's. Corrections: j@nolte.io.