top of page

NAIC AI Risk Evaluation Supplement v5.0: What Insurers Need to Know About the Former AI Systems Evaluation Tool

  • Writer: Bart Layton
    Bart Layton
  • 1 day ago
  • 19 min read

By Bart Layton, CEO, AI Guardian — LinkedIn Published September 4, 2026 · Last updated September 4, 2026

The NAIC AI Risk Evaluation Supplement, formerly known as the NAIC AI Systems Evaluation Tool, is the structured set of inquiries state insurance regulators use to evaluate how insurers deploy and govern artificial intelligence. Version 5.0 was exposed for public comment on August 31, 2026, following a meeting of the NAIC’s Big Data and Artificial Intelligence (H) Working Group. Comments are due by close of business Tuesday, September 29, 2026.

Version 5.0 is the first version published under the new name. Version 4.0 was the last one issued as the AI System Evaluation Tool. The rename is not cosmetic – it tracks a clarification the NAIC made in the document itself, which now states more forcefully that this is a supplement to existing market conduct, financial analysis, and financial examination procedures rather than a freestanding AI examination regime.

None of which changes the practical picture for carriers. Regulators have a steadily more granular framework for asking how you inventory, govern, classify, test, and monitor your AI systems and the models inside them. And because there is no filing date attached to any of it, the request arrives when it arrives. Readiness has to exist beforehand.

NAIC AI Risk Evaluation Supplement: Current Status

Current name

NAIC AI Risk Evaluation Supplement

Former name

NAIC AI Systems Evaluation Tool / AI System Evaluation Tool

Current version

Version 5.0

v5.0 exposure date

August 31, 2026

v5.0 comment deadline

September 29, 2026 (close of business)

Prior version

AI System Evaluation Tool v4.0

Status

Exposure draft; multistate pilot underway

Pilot

12 states, March – September 2026

Developed by

NAIC Big Data and Artificial Intelligence (H) Working Group

Next public meeting

Thursday, October 8, 2026, 11:00 a.m. ET

Anticipated adoption vehicle

Version 7.0, Fall National Meeting, Nov 14–17, 2026

Last updated: September 4, 2026. We update this guide as the NAIC publishes subsequent versions of the AI Risk Evaluation Supplement.

What Is the NAIC AI Risk Evaluation Supplement?

The NAIC AI Risk Evaluation Supplement is the current name for the regulatory resource previously known as the NAIC AI Systems Evaluation Tool. It was developed by the NAIC’s Big Data and Artificial Intelligence (H) Working Group under a charge from the Innovation, Cybersecurity, and Technology (H) Committee, and it gives insurance regulators a common structure for evaluating an insurer’s use of AI systems, its AI Systems Program, its individual models, and the data feeding those models.

Version 5.0 is built around four exhibits, each aimed at a different layer:

  • Exhibit A – AI Systems. Quantifies the insurer’s overall use of AI and helps the regulator decide whether anything deeper is warranted.

  • Exhibit B – AIS Program. Examines the governance program itself – “AIS” stands for Artificial Intelligence Systems – through either a narrative response or a detailed checklist.

  • Exhibit C – AI Models. Requests model-level detail, with particular attention to models carrying greater inherent risk or consumer and financial consequence.

  • Exhibit D – AI Model Data. Examines the data behind those models, including sources and third-party suppliers.

The Supplement does not replace the Market Regulation Handbook, the Financial Condition Examiners Handbook, or the Financial Analysis Handbook. Version 5.0 says so more explicitly than v4.0 did, and it goes a step further: decisions about who receives Supplement-related inquiries are now expected to be governed by Handbook guidance rather than by the Supplement itself. That is a meaningful concession to a comment the industry made repeatedly, and it is worth understanding correctly. The Supplement standardizes the questions. It does not expand the authority to ask them.

Was the NAIC AI Systems Evaluation Tool Renamed?

NAIC Working Group Documents tab listing AI System Evaluation Tool 4.0 clean and tracked-changes versions and the pilot project summary
The Documents tab still lists AI System Evaluation Tool 4.0, the last version published under the old name. Captured from content.naic.org, September 4, 2026.

Yes. The document previously published as the NAIC AI Systems Evaluation Tool is now published as the AI Risk Evaluation Supplement.

The Working Group made the change around the NAIC’s 2026 Summer National Meeting, held August 11–14 in Columbus, Ohio, where the group met on August 13 to provide an update on the project. The stated reason was to reduce confusion about the document’s purpose – “tool” implied something self-contained, and regulators were tired of correcting the impression that a new AI examination framework was being stood up alongside the existing ones.

The NAIC’s Working Group page currently reflects both names at once. AI Risk Evaluation Supplement version 5.0 sits under Exposure Drafts; AI System Evaluation Tool 4.0 sits under Related Documents a few inches below it. So if you are reading a law firm alert from March that discusses the NAIC AI Evaluation Tool, a vendor page about the AI Systems Evaluation Tool, and the NAIC’s own posting of the AI Risk Evaluation Supplement, all three are describing the same evolving document.

The 12-State Pilot


Map of the twelve states piloting the NAIC AI Risk Evaluation Supplement: California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia, and Wisconsin
Twelve states are using the Supplement during the pilot period. Source: NAIC AI Systems Evaluation Tool Pilot Project Summary.

Version 5.0 did not emerge from a comment file alone. It came out of a live multistate pilot running from March 2026 through September 2026, with twelve participating states: California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia, and Wisconsin.

Pilot states have been selecting domestic insurers across property/casualty, life, and health, sending inquiries under existing examination authority, and meeting monthly to compare notes and avoid duplicative requests. The NAIC has been clear that participation in the pilot does not stop a state from taking other AI regulatory action, and that regulators may adapt the document to their own jurisdictional needs.

Two things follow from that for carriers outside the twelve. First, the questions being refined right now are the questions your examiner is likely to arrive with later. Second, several of the v5.0 changes described below exist specifically because a real company struggled to answer something during the pilot. The revisions are field-tested, not theoretical, which is a decent argument for reading them closely even if you have not received anything.

What Changed From the AI Systems Evaluation Tool v4.0 to the AI Risk Evaluation Supplement v5.0?

The NAIC published a Summary of Changes alongside v5.0. It runs to roughly two pages and covers intent, instructions, machine learning, materiality, risk assessment, all four exhibits, and the definitions section. Several changes deserve more attention than they are getting.

1. The Model Inventory request is now explicit

Prior versions contained a number of implied information requests. Version 5.0 makes them explicit, and the NAIC singles out the Model Inventory as the most notable of them.

This is the change with the longest tail. Knowing which vendors and platforms you use is no longer sufficient; the inquiry now reaches the individual models operating inside those systems, including models embedded in third-party products you did not build and may not be able to see. For most carriers, that is a finer grain than vendor management or IT asset inventory was ever designed to produce.

2. Exhibit A now separates consumer impact from financial impact

Version 5.0 splits Exhibit A’s reporting so that model information is gathered separately for AI Models with Direct Consumer Impact and AI Models with Material Financial Impact. Both terms are now defined in the document. The columns were also revised to collect more detail on model type, and the exhibit now distinguishes clearly between AI Systems and AI Models, which v4.0 blurred.

The purpose is triage. If a company’s AI use turns out to be confined to a particular model type, the regulator can stop there rather than working through Exhibits B, C, and D.

3. Materiality got a definition, and it borrows from the exam handbook

Materiality is now defined in the Supplement, aligned to the Financial Condition Examiners Handbook, with additional language explaining how the concept operates inside the document. Exhibit A pairs this with a practical mechanic: either the regulator specifies the materiality threshold for responding, or the company specifies the threshold it used and discloses it.

That second option is more consequential than it looks. A company setting its own threshold is making a judgment it will have to defend, in writing, to an examiner who can see exactly where the line was drawn.

Risk assessment language was clarified in parallel. Regulators are looking at inherent risk – risk before mitigating controls are considered – and the definition of inherent risk was tightened to match the Financial Condition Examiners Handbook as well.

4. GLMs and machine learning get explicit treatment

Version 5.0 adds guidance explaining machine learning and uses generalized linear models as a worked example. GLMs have been standard equipment in actuarial pricing and underwriting for decades, and their appearance here closes off a comfortable argument: that a model sits outside an AI inquiry because it predates the current wave and looks like ordinary statistics.

The regulator is not asking whether you call it AI. The regulator is asking whether it falls inside the population you are being asked to identify and govern. Notably, the same guidance also gives regulators room to limit further inquiry once Exhibit A responses come back, so a carrier whose footprint is genuinely narrow can benefit from answering this precisely.

5. Agentic AI is now defined

Version 5.0 adds a definition of agentic AI, alongside new definitions for AI Model (drawn from NIST and Executive Order language), AIS Program (drawn from the NAIC’s AI Model Bulletin), Direct Consumer Impact, Material Financial Impact, GLMs, and third parties (drawn from the Third Party Registration Framework). “Degree of Potential Harm to Consumers” was removed.

Adding agentic AI to a document that will not be adopted until late 2026 is the NAIC signaling that it does not intend to keep re-litigating scope every time the technology moves. That is the right instinct, though as discussed below, defining agentic AI and governing it are very different problems.

6. Exhibit B now asks where the document is

Exhibit B was reframed around the company’s AIS Program rather than the more diffuse “governance framework” language of v4.0, and its questions were rewritten using pilot feedback. Three additions matter:

  • The narrative version adds guidance for responding on models with direct consumer impact, and a new question on explainability and transparency.

  • The checklist version adds a question on materiality.

  • The checklist version adds a question on how the company oversees third-party models.

And a fourth change, quiet but sharp: the checklist now asks carriers to provide the document name and page number supporting their responses, so regulators can tie an answer back to the artifact behind it.

That is a different exercise than the one most AI governance programs were built for. “We handle that in our model risk committee” is not an answer to “which document, which page.”

7. Exhibits C and D got restructured

Exhibit C’s fields were reordered and sharpened. Field 1 was clarified to focus on the AI Model. The question about use case and purpose was moved forward. Model type now comes with example responses, the inquiry into how the model was developed was expanded, and the field that previously combined model risks and model limitations was split in two, with a high/moderate/low rating attached to the limitations side.

Exhibit D added a field identifying which AI models rely on each described data set, which allowed the NAIC to delete a redundant column, and clarified the column asking how the information is used. Two notes were added to the regulator instructions: that regulators may want to customize the exhibit by line of business, since the data elements listed are not all pertinent to every book, and that a regulator may ask for a data dictionary depending on the responses received.

What Does the Supplement Ask Insurers to Provide?

The four exhibits of the NAIC AI Risk Evaluation Supplement: AI Systems, AIS Program, AI Models, and AI Model Data
Exhibit A functions as a gate: version 5.0 lets regulators stop there when responses do not warrant further review.

Exhibit A – AI Systems

Exhibit A quantifies AI use and gives the regulator a first view of the footprint. It also functions as a gate. Version 5.0 gives regulators express flexibility to stop after Exhibit A when the responses do not warrant more, which makes it the highest-leverage part of the whole process. The completeness of your inventory and the defensibility of your classifications shape everything downstream, including whether there is a downstream.

Exhibit B – AIS Program

Exhibit B evaluates the AI Systems Program: policies, processes, controls, roles, and the governance mechanisms that manage AI risk. Carriers respond through a narrative or a checklist, and as noted above, the checklist now wants document names and page references.

Exhibit C – AI Models

Exhibit C drops from the system level to the model level, asking about purpose and use case, model type, how the model was developed, its risks, and its limitations.

This is where third-party dependence becomes visible. A carrier can know precisely which vendor platform it licenses without knowing how many models run inside it, who built them, how they were validated, or when they last materially changed.

Exhibit D – AI Model Data

Exhibit D examines the data underneath, including sources and third-party suppliers, and now links data sets to the specific models that consume them. For carriers with layered data ecosystems, this is a lineage problem more than an AI problem.

Does Every Insurer Have to Complete the Entire NAIC AI Supplement?

No. The Supplement is designed to support targeted inquiries, and a regulator may use only the portions relevant to a particular examination or review. Version 5.0 makes that flexibility more explicit than v4.0 did, and it adds an example of when a regulator might reasonably narrow the request.

This is worth saying plainly, because pilot experience has muddied it. During the pilot, companies frequently received several parts of the Supplement at once as part of field-testing the document. The NAIC has acknowledged that in practice, inquiries are likely to be more limited. Describing the Supplement as a nationwide AI questionnaire that every carrier will fill out in full is not what the document contemplates.

How the Supplement Relates to the NAIC AI Model Bulletin

The two are complements, and the relationship became more direct in v5.0.

The Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted by the NAIC in December 2023 and issued in some form by more than two dozen jurisdictions since, sets the expectation that every authorized insurer maintain a written Artificial Intelligence Systems Program – an AIS Program – governing the design, development, acquisition, and use of AI. It also tells insurers what a department may ask for during an investigation or examination. The Supplement is the instrument for asking.

Version 5.0 tightened the seam by pulling its AIS Program definition from the Model Bulletin. If your state has adopted the Bulletin, the program the Bulletin expects you to have is the program Exhibit B is written to inspect.

When Will the NAIC AI Risk Evaluation Supplement Be Adopted?

Timeline of NAIC AI Risk Evaluation Supplement versions 4.0 through 7.0, showing the v5.0 exposure and the September 29, 2026 comment deadline
Solid line: published versions. Dashed: the Working Group's anticipated schedule.

Not yet, and not in the form now on the table.

Version 5.0 is under a 30-day comment period ending September 29, 2026. The Working Group’s stated process anticipates a Version 6.0 exposure with a shorter, 14-day comment window, after which Version 7.0 would be the version considered for adoption at the 2026 Fall National Meeting, held November 14–17 in Grapevine, Texas. The Working Group’s next public Webex is October 8, 2026, to continue discussion of the Supplement. The NAIC has not yet published dates for the Version 6.0 exposure, and the arithmetic is tight: a 14-day window that closes in time for a November 14 adoption vote means exposing v6.0 by roughly the end of October, leaving about three weeks to process the v5.0 comment file. There is precedent for slippage. The predecessor draft was exposed in July 2025 for 30 days and then extended another 30.

A fair amount of coverage has compressed this into “the NAIC tool will be adopted nationwide in November.” That skips two exposure drafts and a comment cycle, and it also overstates what adoption does. Adoption makes the Supplement available to every department as a standardized resource; it does not, by itself, require any state to use it or create a new obligation for insurers. States were already free to ask these questions under existing exam authority, which is exactly what the twelve pilot states have been doing since March.

Waiting for November is still the wrong read, though, for a reason that has nothing to do with adoption. Twelve departments have spent six months building institutional experience with these inquiries. That experience does not evaporate if v7.0 stalls.

How to submit a comment

NAIC exposure drafts notice for AI Risk Evaluation Supplement version 5.0, showing the 30-day comment period ending September 29, 2026 and contacts Scott Sobel and Miguel Romero
The NAIC's exposure notice for version 5.0. Captured from content.naic.org, September 4, 2026.

Written comments on Version 5.0 go to Scott Sobel (ssobel@naic.org) or Miguel Romero (maromero@naic.org) at the NAIC by close of business on September 29, 2026. If your organization has a view on the third-party model provisions in particular, this is the window.

Where the Real Exposure Sits for Insurers

Read the exhibits back to back and the sharpest operational risk turns out not to be technological. It sits in the space between the carrier and everyone the carrier depends on.

Third-party AI risk starts with contracts

The Supplement can ask a carrier for information about models running inside a third-party product, and for an explanation of how vendor-supplied AI is governed, assessed, and validated. Exhibit B’s new question on third-party model oversight makes that explicit rather than implied.

The difficulty is that most vendor agreements in force today were negotiated before anyone thought to ask for model documentation access, testing results, or change notification. A carrier can be asked for information its contract does not entitle it to obtain, test, or disclose.

You cannot fix that after the request arrives. Contract renewals are the natural opening – regulatory disclosure rights, testing and validation information, audit rights, model-change notification, incident reporting, and data use provisions all belong in that conversation. The work is identifying which agreements have the gap before the renewal window, not discovering it when an examiner asks.

Complaint attribution cannot be rebuilt after the fact

If a carrier does not flag AI involvement at the moment a complaint is received, reconstructing a trailing history later means manual work across complaint records, systems, business units, and vendors. Some of it will simply be unrecoverable. Complaint classification belongs in the prospective column, not the remediation column.

Documentation is becoming literal

The Exhibit B checklist asks for document name and page number. That produces an unusually clean readiness test: if the answer is not written down somewhere that can be located and produced, how confidently can you tell a regulator the control exists?

Governance that lives in meetings, institutional memory, and a shared drive nobody has curated since 2024 does not survive that question well.

Embedded AI creates a visibility problem

A carrier may show one vendor and one platform in its inventory while that platform runs several models doing different jobs at different risk levels. The problem extends upstream, too. TPAs, MGAs, actuarial firms, claims administrators, and technology providers all introduce AI into carrier operations, and foundation models add another layer behind them. An inventory that stops at the organizational boundary is not an inventory of your exposure.

Agentic AI raises the next question the Supplement has not answered

Version 5.0 defines agentic AI. Defining it is the easy part.

If an agent can call tools, hit APIs, touch systems and data, and trigger downstream workflows, knowing it exists barely starts the conversation. What is it permitted to access? What actions can it take, under what conditions? What requires a human in the loop? What happens when it operates outside those boundaries, and how would you know? The Supplement does not yet reach most of that, and I expect the gap to become uncomfortable well before v7.0 is a year old.

An Aside on What Makes a Rule Work

I want to be straightforward about where I come down on this, because I do not think the useful posture is reflexive opposition.

Insurance is one of the few industries where a badly governed model does not merely cost someone money. It decides whether a claim gets paid, whether a family stays covered, whether a person is priced out of protection they have a legal right to buy. Americans are entitled to a real answer about how those decisions get made. Regulators asking the question is not overreach. It is the job, and I would rather they ask it with a standardized document than with fifty divergent ones.

But a rule protects people only to the extent it can actually be followed, and feasibility is where v5.0 is still wobbling. Exhibit D wants data lineage. Exhibit B now wants an account of how you oversee third-party models. Both are fair questions. Neither fully reckons with the fact that the carrier being asked often has no contractual leverage to obtain the answer, and the vendor holding the answer has legitimate reasons to protect it. You cannot regulate a party into disclosing what a counterparty has every right to withhold, and no amount of examination pressure on the carrier changes the terms of an agreement signed in 2023. The wrong resolutions are the obvious two. Dropping the question leaves consumers without the transparency the whole exercise exists to produce. Forcing it through the carrier turns compliance into a demand that vendors surrender proprietary architecture as the price of selling into insurance – which will not produce better models, only fewer vendors and a slower market.

There is a workable middle, and it mostly involves routing the question to the party that can answer it. Vendor attestations against a defined standard. Independent third-party validation, where the validator sees the model and the regulator sees the validation. Regulator-direct disclosure under the confidentiality protections that already govern examination material, so the sensitive artifact never has to transit the carrier at all. The NAIC’s own Third Party Data and Models work is circling the same territory, and the two efforts should be talking to each other more than they currently appear to be.

What I would like to see out of the v6.0 revision is less breadth and more of that: fewer additional fields, and a clearer answer to who is actually in a position to fill them in. Transparency and intellectual property are not in genuine conflict here. They are in conflict only when the framework insists on obtaining one through a party that does not hold the other.

How Should Insurers Prepare for a Supplement Request?


Three tiers of NAIC AI Supplement readiness: foundation work that must start now, refinable work that builds on it, and irreversible gaps that depend on third parties
The sequence is a loop, not a checklist. Every pass raises the floor for the next one.

It helps to sort the work into three tiers, because they behave very differently under time pressure.


Tier one is foundation. A model-level inventory of AI systems, a written AIS Program, documented ownership for each system, and visibility into AI embedded inside third-party products. None of the rest of the Supplement is answerable without these. They are also the slowest to build from a standing start, because building them means going and finding out what is actually running across the organization and inside its vendors.

Tier two is refinable. Model classifications, materiality and impact assessments, version histories, and the work of packaging evidence so a control can be cited by document and page. These can improve quickly under examination pressure, but only on top of tier one. Classifying a model population you have not inventoried is not a fast exercise; it is a discovery exercise wearing a deadline.

Tier three is irreversible. Vendor contractual rights require negotiating with someone else, on their timeline. Historical complaint attribution depends on whether AI involvement was flagged at intake, and if it was not, some of it is simply gone. Third-party model information depends on a vendor’s willingness and ability to hand it over. Pre-deployment testing and validation evidence depends on work that needed to happen before the model went live.

The trap is treating tier one and tier two as things that can wait because they are technically improvable later. They can be improved later. They cannot be started later, at least not without doing all three tiers simultaneously while a regulator waits.

The practical shape of the work is a loop rather than a checklist: know what you run, rank what matters most, secure what cannot be recovered, then tighten and go again. Each pass raises the floor for the next one. The organizations that handle a Supplement request calmly are the ones already several turns into that cycle, so the request finds them closing gaps rather than discovering they have no floor to close them against.

The carriers in the strongest position when the questions arrive will not be the ones with the most sophisticated AI. They will be the ones that can demonstrate, on demand:

  • a current, model-level inventory of AI systems and models;

  • visibility into AI embedded within third-party products;

  • documented ownership and governance for each AI system;

  • risk and materiality classifications, with the reasoning behind the thresholds;

  • testing and validation evidence for internally and externally developed models;

  • AI-specific third-party due diligence;

  • contractual mechanisms for obtaining relevant vendor information;

  • traceable documentation supporting every governance control;

  • monitoring for model and vendor changes; and

  • a process for identifying AI involvement in consumer complaints and incidents.

That is the difference between having an AI governance policy and being able to prove the program operates.

The High-Level Takeaway

The Supplement is still moving, but its direction has been consistent across five versions. The former NAIC AI Systems Evaluation Tool is becoming a framework for understanding not whether an insurer uses AI, but which systems and models it relies on, how consequential they are, what data supports them, how third-party AI is governed, and whether the carrier can produce evidence that its controls actually function.

The gaps that will hurt are the ones that cannot be closed after a request lands.

Frequently Asked Questions About the NAIC AI Risk Evaluation Supplement

What is the NAIC AI Risk Evaluation Supplement?

The NAIC AI Risk Evaluation Supplement is a regulatory resource developed by the NAIC’s Big Data and Artificial Intelligence (H) Working Group to help state insurance regulators evaluate insurers’ use and governance of AI. It was previously known as the NAIC AI Systems Evaluation Tool.

Is the AI Risk Evaluation Supplement the same as the AI Systems Evaluation Tool?

Yes. It is the current name for the same evolving document. Version 4.0 was published as the AI System Evaluation Tool; Version 5.0 is the first published as the AI Risk Evaluation Supplement. The NAIC’s Working Group page currently hosts both.

What is the latest version of the NAIC AI Risk Evaluation Supplement?

As of September 4, 2026, the latest exposed version is Version 5.0, released August 31, 2026, with a comment period closing September 29, 2026.

What changed in Version 5.0?

The most significant changes are an explicit Model Inventory request, separate Exhibit A reporting for models with Direct Consumer Impact and Material Financial Impact, new definitions for materiality and agentic AI, machine-learning guidance covering GLMs, a new Exhibit B question on third-party model oversight, a requirement to cite document names and page numbers in the Exhibit B checklist, and restructured fields throughout Exhibits C and D.

Which states are piloting the NAIC AI Evaluation Tool?

Twelve: California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia, and Wisconsin. The pilot runs from March 2026 through September 2026.

Does every insurer have to complete all four exhibits?

No. Version 5.0 lets regulators tailor inquiries, and Exhibit A functions as a gate. If the responses do not warrant deeper review, the regulator may stop there.

Is the NAIC AI Risk Evaluation Supplement mandatory?

The Supplement does not itself determine which insurers receive an inquiry. It supplements existing examination and analysis procedures, and regulators rely on their existing authority and Handbook guidance to set the scope of a review. Version 5.0 makes that point more explicitly than prior versions.

When will the NAIC AI Risk Evaluation Supplement be adopted?

The current process anticipates a Version 6.0 exposure with a 14-day comment window after v5.0 comments are incorporated, with Version 7.0 the version likely to be considered for adoption at the 2026 Fall National Meeting, held November 14–17 in Grapevine, Texas.

How do I submit a comment on Version 5.0?

Send written comments to Scott Sobel (ssobel@naic.org) or Miguel Romero (maromero@naic.org) by close of business September 29, 2026.

How should insurers prepare?

Build and maintain a model-level AI inventory, document governance controls in a form that can be cited by document and page, identify AI embedded in third-party products, classify model risk and materiality, retain testing and validation evidence, review vendor contracts for disclosure and audit rights, and make sure complaints can be tied to the AI systems involved.

Primary NAIC Sources

About the author

Bart Layton is CEO of AI Guardian, which helps insurers inventory, govern, and document the AI systems they and their vendors run, so that governance evidence exists before a regulator asks for it. He previously led the HealthCare.gov product team through eight consecutive open enrollment periods involving more than 400 insurance company partners, led product and operations for a cybersecurity and third-party risk management platform serving dozens of the largest US carriers, and led technology integrations for a Fortune 10 insurer. Connect with him on LinkedIn.

Want to see how your AI governance program measures against the NAIC AI Risk Evaluation Supplement?

AI Guardian maintains the AI inventory, third-party oversight, governance documentation, and examination-ready evidence regulators increasingly expect.

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page