Reference
Supplement reference
Every reference in this guide links here. Items are paraphrased from Supplement draft 4.0 for orientation only. The wording that counts is the NAIC's, at content.naic.org. Nolte is not affiliated with or endorsed by the NAIC.
Exhibit A: how much AI you use
- Exhibit A
- For each operational area (marketing, quotes, underwriting, rating, claims, customer service, utilization review, fraud, investment, legal, producer services, reserves, catastrophe triage, reinsurance, other): number of models in use, number with direct consumer impact, number with material financial impact, number implemented in the past 12 months, and the use cases.
Exhibit B: how you govern it
Two formats. Narrative questions Q1 to Q5, or a checklist with items 1 to 3n.
- B Q1
- Provide the governance framework: who maintains it (a), board reporting and frequency (b), how it is integrated and remediated (c), how effectiveness is assessed (d), how responsibility is assigned (e), integration with ORSA and ERM (f), how autonomy, reversibility and reporting impact are assessed (g).
- B Q2
- Describe AI uses that generate material financial transactions, material consumer impact, financial-statement information, or risk and control assessments, and how material systems were developed and tested.
- B Q3
- Policy for vendors, model design and testing: validation of internally developed systems (a), validation of vendor-supplied systems (b), and the frequency, scope and method of testing (c).
- B Q4
- Policy for, and oversight of, AI systems used by professional service providers including actuarial, claim, MGA and audit providers; and the testing and verification performed (a).
- B Q5
- Anything else about framework design and evaluation, including which unit is responsible and how often it assesses.
- checklist 1
- Has the company adopted a written AI program; when; how often is it reviewed.
- checklist 2
- Were the board or management involved in adopting it, and what is their role.
- checklist 3
- Where the framework addresses each of: 3a unfair trade practice risk, 3b legal compliance, 3c adverse consumer outcomes, 3d privacy, 3e suitability for intended use, 3f ERM, 3g ORSA, 3h the software development lifecycle, 3i financial reporting impact, 3j training and prohibited practices, 3k quantifying risk levels, 3l vendor procurement standards, 3m complaint tracking, 3n consumer disclosure.
Exhibit C: detail on each high-risk model
- C 1
- Model name and version.
- C 2
- Model type.
- C 3
- Implementation date.
- C 4
- Developed internally or by a third party; vendor name.
- C 5
- Risk classification (high, medium, low).
- C 6
- Known risks and limitations.
- C 7
- Autonomy: automate, augment, or support.
- C 8
- How outputs are tested (drift, accuracy, unfair trade practices, unfair discrimination, degradation), how the model was validated before deployment, and how it is monitored on an ongoing basis.
- C 9
- Last date of model testing.
- C 10
- Use cases and purpose.
- C 11
- Effect on financial statements, risk assessment, or controls.
- C 12
- How the model is reviewed for compliance with state and federal law, including unfair trade practices and unfair claims settlement laws.
- C 13
- Any regulatory action taken concerning the model.
Exhibit D: what data feeds the models
- Exhibit D
- For each of 25 data categories (aerial imagery; age, gender, ethnicity; risk scores; crime statistics; criminal convictions; driving behaviour; education; facial or body analysis; geocoding; geo-demographics; household composition; image and video analysis; income; job history; loss experience; medical and biometric; natural catastrophe hazard; social media; personal financial information; accommodations requested; telematics; vehicle data; voice analysis; weather; other non-traditional): the type of AI system using it, how it is used across operations, whether sourced internally, and the third-party vendor name if external.
Glossary
Plain-English definitions for the terms used across this guide.
- Bordereaux
- A periodic, line-by-line report a delegated party (an MGA, program, or TPA) sends its carrier: policies written, premiums, claims. The AI governance bordereaux in Part 6 applies the same idea to model activity.
- MGA (managing general agent)
- A party a carrier delegates underwriting authority to. It can bind and price on the carrier's paper, so its AI is the carrier's exam exposure (Exhibit B, question 4).
- TPA (third-party administrator)
- A party that runs a function, usually claims, on the carrier's behalf without taking underwriting risk. Its AI is in scope the same way an MGA's is.
- Fronting partner
- A licensed carrier that issues policies on behalf of another risk-bearer (often a program or reinsurer). The fronting carrier answers the Supplement, using its programs' evidence.
- Carrier
- The licensed insurer that holds the policy obligation. The Supplement is addressed to the carrier, which is why delegated parties answer it with their evidence.
- Program administrator
- An MGA-like party that runs a defined book (a "program") for a carrier, with delegated underwriting and often claims authority.
- Exhibit (A to D)
- The four data schedules of the AI Risk Evaluation Supplement: A (AI use by function), B (governance), C (high-risk model detail), D (data feeds).
- Checklist item (1 to 3n)
- The itemized checklist form of Exhibit B's governance questions; 3a through 3n enumerate the specific program elements an examiner may ask about.
Self-assessment and orientation only. Nothing here is legal advice, a certification, or a compliance determination. Nolte is not affiliated with or endorsed by the NAIC. Exhibit references are paraphrased from Supplement draft 4.0; the wording that counts is the NAIC's. Corrections: j@nolte.io.