InsuranceExam-Ready ToolkitReadiness check

Readiness check

Check your readiness

Five sections, 25 questions, about four minutes. Your answers stay in your browser.

0 of 25 answered

Section 1 of 5

1. Inventory and classification

Can you name every AI system you run, including the ones inside platforms you rent, and say how risky each is? This is where an exam starts.

20% of the score · Exhibit A; Exhibit C ref 1 to 7
1.1You keep a written inventory of every AI system in production, including vendor-embedded models and features inside platforms you rent.
1.2Each system is tagged to an Exhibit A operational area (underwriting, claims, fraud, and the rest).
1.3Each system carries an autonomy level: support, augment, or automate.
1.4Each system carries a risk classification with a written rationale.
1.5You can produce version, implementation date, and a count of systems implemented in the past 12 months on demand.
Section 2 of 5

2. Governance and accountability

Is there a written, owned AI program that someone actually reviews, not a PDF filed once for a carrier questionnaire and never reopened?

20% of the score · Exhibit B narrative Q1, Q5; checklist 1 to 3
2.1A written AI program exists, dated, with a review cadence.
2.2A named role owns the AI program.
2.3The program addresses checklist items 3a through 3n, at least by reference.
2.4AI risk is a step in your software delivery process, not a separate document.
2.5The program has been reviewed at least once since adoption, and the review is documented.
Section 3 of 5

3. Validation and observability

The heaviest pillar. Are your models tested before launch and watched in production, with a last-test date you can produce on demand?

25% of the score · Exhibit B Q3; Exhibit C ref 8, 9
3.1Pre-deployment validation is documented per model, with the reference data source stated.
3.2Each high-risk model is monitored in production with drift detection and a threshold that triggers review.
3.3Every automate-level decision is logged with inputs, output, model version, and timestamp, so any single outcome can be reconstructed.
3.4Vendor-supplied models have a validation procedure that does not rely on the vendor's attestation alone.
3.5You can produce a last-test date for every high-risk model without asking an engineer to go look.
Section 4 of 5

4. Data provenance

Can you trace every data element feeding a model to its source and vendor, and justify any sensitive inputs?

20% of the score · Exhibit D; checklist 3d
4.1Every data element feeding a model is mapped to an Exhibit D category.
4.2Source is recorded per data element: internal, or third-party with the vendor named.
4.3Training and test data lineage is documented for internally developed models.
4.4Sensitive categories are absent from model inputs, or their use has a written justification and a proxy-discrimination check.
4.5The data map is versioned and updated when a model or a vendor changes.
Section 5 of 5

5. Consumer outcome controls

When AI touches an adverse decision, is there a human path, a complaint trail, and the disclosures your states require?

15% of the score · checklist 3a, 3c, 3m, 3n; Exhibit C ref 12, 13
5.1A human review path exists for adverse consumer decisions, with written triggers.
5.2Complaints are tagged to the AI system involved, and the tag is queryable.
5.3Consumer-facing disclosure of AI use exists where the state requires it.
5.4Each consumer-impacting model has a documented compliance review against unfair trade practice and claims settlement rules.
5.5A regulatory-action log exists per model, even if empty.
·/100

Your readiness

Answer the sections to see your score.

What to fix

Keep your results

A short, tailored memo from your answers: where you stand, the two or three gaps to close first, and what "exam-ready" looks like for your book. Built from your answers only, orientation not legal advice.

Self-assessment and orientation only. Nothing here is legal advice, a certification, or a compliance determination. Nolte is not affiliated with or endorsed by the NAIC. Exhibit references are paraphrased from Supplement draft 4.0; the wording that counts is the NAIC's. Corrections: j@nolte.io.