Two documents in one. The first is a checklist to run against any AI vendor before you sign, and against every vendor already on your stack. The second is a contract schedule you can hand to counsel. Neither is legal advice. The schedule was drafted by operators, not lawyers; it is jurisdiction-agnostic, the bracketed terms are starting positions rather than market standard, and it has not been reviewed by counsel as of this version. Both are what an MGA needs to have in hand so that its carrier can answer Exhibit B question 3b (“validation and testing procedures performed on third-party vendor-supplied AI Systems”) without inventing the answer.
Why the vendor question got harder in 2026
Three things happened.
- The Supplement asks the carrier to describe validation procedures on vendor-supplied AI, and to name the vendor on Exhibit C and Exhibit D. The carrier will ask you. You will ask your vendor.
- The model bulletin already expects insurers to hold contractual terms with AI vendors covering audit rights and cooperation with regulatory inquiries. Most vendor MSAs written before 2024 have neither.
- The NAIC is drafting a parallel framework for third-party data and model vendors in P&C pricing and underwriting. The July 2026 draft includes an enforcement lever: a regulator can prohibit a model from use in the state if the vendor does not respond to inquiries. Nolte’s read: once that lands, a vendor’s regulatory posture becomes a continuity risk to your book, not just a compliance question.
Meanwhile at least one underwriting AI vendor has published a third annual Responsible AI report describing a fairness test built for how language models are used in underwriting, validation of intermediate steps and tool use, customer-configured authority limits with pause points, and per-action records. Nolte’s read: that is the bar. It will become the procurement gate the way SOC 2 did. Ask every vendor where theirs is.
Part A: the vendor evidence checklist
Run this before signing, and annually against every AI vendor on the stack. Score each item: have it in hand, vendor says they can produce it, vendor cannot or will not. The third column is your finding.
A1. Identity and scope (Exhibit C refs 1 to 4, 7)
- Product name, version, and a versioning policy you can cite.
- Which model or models sit underneath, by provider and pinned identifier. If the vendor rents a foundation model, you need the provider name for Exhibit D column 5.
- What the system does in the Supplement’s terms: support, augment, or automate. In writing, per feature.
- The decision classes it touches: quote, bind, rate, underwrite, claim, fraud, service.
A2. Validation before deployment (Exhibit B Q3b, Exhibit C ref 8)
- A validation report, dated, for the version you are buying. Not a whitepaper. Method, data, results.
- The evaluation set description: size, source, how adverse and edge cases are represented.
- Fairness and unfair-discrimination testing: method, which protected classes or proxies, results, limitations stated. If the vendor built a method specific to LLM use, that is a strength; ask why they needed to.
- For agentic or multi-step systems: evidence that intermediate steps and tool calls are validated, not only final outputs.
A3. Monitoring in production (Exhibit C ref 8, “ongoing basis”)
- What is monitored: drift, accuracy or outcome rates, override rate, latency, cost.
- Who sees it: is there a customer-visible dashboard, or only vendor-internal?
- Alert thresholds and what happens when one trips, including whether you are told.
- Re-validation cadence and the date of the last one (Exhibit C ref 9).
A4. Traceability and your decision record (Control 4)
- Per-decision record: inputs reference, output, confidence, model version, prompt or policy version, timestamp, and for agents, each action taken.
- Can you export it, in bulk, in a documented format, on your schedule? If the log lives only in the vendor’s system, your Exhibit C answer depends on their uptime and goodwill.
- Retention: how long, and does it match your longest exam lookback.
A5. Authority and human oversight (Control 5)
- Can you set hard limits on what the system does without a human? Per decision class, per amount, per confidence.
- Pause points: where does the system stop and wait for approval, and can you move those?
- Are overrides recorded with the human’s role, and can you see the override rate?
A6. Change control (Control 2, 3, 8)
- Notice period before a model, prompt, or threshold change that could alter outputs. In days, in writing.
- Can you pin a version and decline an update for a defined period?
- Changelog access.
- Rollback: can the vendor revert you to the prior version, and how fast?
A7. Data (Exhibit D)
- Which of your data elements the system consumes, mapped to Exhibit D’s categories.
- Whether your data trains or tunes anything, for you or for other customers. Default should be no.
- Subprocessors: every downstream provider that sees your data, including the foundation model provider.
- Data residency, retention, and deletion on termination.
A8. Regulatory posture (bulletin third-party section; vendor framework draft)
- Will the vendor respond to a regulator inquiry routed through you, within a stated time?
- Has the vendor been the subject of any regulatory action related to the product (Exhibit C ref 13)?
- Published governance or responsible-AI documentation, current within twelve months.
- Security attestation (SOC 2 or equivalent) and its scope: does it cover the AI pipeline or only the web app?
A9. Continuity
- What happens to your decision records, configuration, and prompts on termination. Export format and window.
- Escrow or equivalent for anything you cannot replace.
- Concentration: which other vendors on your stack rent the same foundation model.
How to read the result. A vendor with A2, A4, and A6 in hand is a vendor whose evidence you can forward to your carrier. A vendor missing A4 is one whose product you cannot govern from your side no matter what the contract says. A vendor missing A8 is a continuity risk once the third-party framework has teeth.
Part B: AI vendor schedule (contract template)
Attach as a schedule to the MSA or SaaS agreement. Bracketed terms are for negotiation. Counsel adapts to jurisdiction and to the carrier’s own DAA language, which will increasingly contain its own AI schedule that flows down to you; align the two.
Schedule [X]: Artificial Intelligence Systems
1. Definitions. “AI System” has the meaning given in the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers. “Material Change” means any change to a model, prompt, configuration threshold, training data, or decision logic that could reasonably alter the outputs of the AI System for Customer’s inputs. “Decision Record” means the per-transaction record described in section 4.
2. Inventory and disclosure. Vendor shall provide and maintain a written description of each AI System supplied under this Agreement, including: product version; underlying models by provider and identifier; the autonomy level (support, augment, automate) of each function; the categories of Customer data consumed, mapped to the NAIC AI Risk Evaluation Supplement Exhibit D categories; and all subprocessors with access to Customer data. Vendor shall update the description within [10] business days of any change.
3. Validation and testing. Prior to initial deployment and prior to any Material Change, Vendor shall perform and document validation of the AI System, including performance testing and testing for unfair discrimination, and shall provide the validation report to Customer on request. Vendor shall re-validate the AI System no less than [annually] and provide the date of last validation on request. For AI Systems that take multi-step or tool-using actions, validation shall cover intermediate steps and actions, not solely final outputs.
4. Decision Records. Vendor shall maintain a Decision Record for each output of the AI System affecting Customer’s business, including at minimum: a reference to inputs, the output, any confidence measure, the AI System version and configuration identifiers, the timestamp, any human review action and the role of the reviewer, and, for autonomous actions, each action taken. Vendor shall retain Decision Records for [seven] years or such longer period as Customer reasonably specifies to meet regulatory examination requirements, and shall make them available to Customer for export in a documented machine-readable format within [5] business days of request.
5. Customer authority controls. Vendor shall provide Customer the ability to configure limits on the actions the AI System may take without human approval, including by decision type, monetary amount, and confidence threshold, and to designate points at which the AI System must pause for human approval. Vendor shall record overrides and make override rates available to Customer.
6. Monitoring. Vendor shall monitor the AI System in production for performance degradation and drift and shall notify Customer within [5] business days of detecting any degradation reasonably likely to affect Customer’s outputs. Vendor shall make monitoring metrics available to Customer [on a dashboard / on request].
7. Change control. Vendor shall give Customer no less than [30] days’ written notice of any Material Change, including a description of the change and the validation performed. Customer may elect to remain on the prior version for up to [90] days after the change. Vendor shall maintain a changelog accessible to Customer. Vendor shall be able to revert Customer to the immediately prior version within [2] business days of request.
8. Data use. Customer data shall not be used to train, fine-tune, or improve any model for the benefit of any party other than Customer without Customer’s prior written consent. Vendor shall not permit any subprocessor to retain Customer data beyond the period necessary to provide the service.
9. Regulatory cooperation. Vendor shall cooperate with any inquiry, examination, or information request from an insurance regulator concerning the AI System, whether directed to Customer, to Customer’s carrier or capacity provider, or to Vendor, and shall respond to such requests routed through Customer within [10] business days. Vendor shall notify Customer within [5] business days of any regulatory inquiry or action concerning the AI System received directly by Vendor.
10. Audit. Customer, its carrier or capacity provider, and their regulators may audit Vendor’s compliance with this Schedule no more than [once annually] except where required by a regulator, on [30] days’ notice, at Customer’s expense unless the audit reveals material non-compliance.
11. Governance documentation. Vendor shall maintain and provide on request current documentation of its AI governance program, including its approach to fairness testing, human oversight, security of the AI pipeline, and incident response, refreshed no less than annually.
12. Incidents. Vendor shall notify Customer within [48 hours] of becoming aware of any incident in which the AI System produced outputs materially outside its validated behaviour, was subject to unauthorised modification, or exposed Customer data.
13. Continuity and termination. On expiry or termination, Vendor shall provide Customer with all Decision Records, configuration, prompts, and authority settings in a documented format within [30] days, and shall retain them for [90] days thereafter to permit verification. [Escrow terms for any component Customer cannot replace.]
14. Flow-down. Vendor acknowledges that Customer operates under delegated authority from one or more carriers and that obligations in this Schedule may be required by those carriers or their regulators. Vendor shall provide information reasonably required for Customer to satisfy those obligations.
How the two parts fit
Checklist first. If a vendor cannot produce A2, A4, and A6 today, the schedule will not fix it; it will only give you a breach to point at later. Use the checklist to decide whether to sign, and the schedule to make the evidence a contractual obligation rather than a favour.
Then keep both in the vendor register (Control 9). Every AI vendor: checklist score, schedule signed yes or no, date of last validation report received. That row is your Exhibit B Q3b answer.