← Blog

AI Data Protection for Insurers Is Examined Against Your AIS Program

Parminder Singh
Parminder Singh··5 min read
Summarize with AI

The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted December 4, 2023, expects a written AIS Program covering governance, risk management controls and internal audit, and it lists the documentation a Department may request during an investigation or examination. This article maps those documentation items to the data protection controls an insurer has to evidence on its AI request path.

Industry Verticalsai-governanceai-complianceinsurancedata-protectionaudit
AI Data Protection for Insurers Is Examined Against Your AIS Program

The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers was adopted by the Executive Committee on December 4, 2023. It tells insurers that decisions affecting consumers which are made or supported by AI Systems must comply with applicable insurance laws, and it "advises Insurers of the type of information and documentation that the Department may request during an investigation or examination." AI data protection insurance work is most productive when it starts from that list, because the list is what an examiner will actually ask for.

Section 4 of the bulletin sets out the request categories. The recurring pattern is documentation that evidences a control operated, not documentation that describes a control existing.

TL;DR

  • The NAIC Model Bulletin expects a written AIS Program addressing "governance, risk management controls, and internal audit functions."
  • Section 4 lists the documentation a Department may request, including the written program, evidence of its adoption and records of monitoring and audit activities.
  • Third-party AI expectations include due diligence, contractual audit rights and cooperation with regulatory inquiries.
  • Per-request records naming identity, data class, destination and decision are what turn a policy statement into examinable evidence.

The bulletin asks for evidence of operation

The NAIC Model Bulletin states that the AIS Program "should address governance, risk management controls, and internal audit functions," with responsibility vested in senior management accountable to the board. Section 4 then lists information and documentation relating to or evidencing the program, including the written program itself, documentation evidencing its adoption and documentation of monitoring and audit activities respecting compliance.

For predictive models the bulletin names assessments covering interpretability, repeatability, reproducibility, traceability and model drift, and "the auditability of these measurements where appropriate." Traceability and auditability are the two items on that list that require a record of an individual interaction. The others can be satisfied at the model level.

The AI governance framework covers the program structure. The data protection question sits one level down, in what happens to policyholder information on its way to a model.

Where policyholder data leaves the control perimeter

Insurance workflows concentrate sensitive information. Medical history sits in the underwriting file. Incident narratives and loss photographs sit in claims. Complaints correspondence holds whatever the policyholder chose to write about their own circumstances.

Three paths take that information toward a model. An internal application calls a hosted model endpoint. An adjuster or underwriter uses a browser-based assistant. A third-party vendor processes submitted data inside its own platform. Each path needs a different evidence source, and only the first two produce HTTP traffic an enterprise control point can inspect.

Mapping the paths before writing the control narrative avoids the common failure, which is a program document that describes the first path thoroughly and never mentions the other two.

Four fields an examiner can test

A record of each AI request carries most of the data protection burden. The authenticated identity of the user or agent, taken from the enterprise directory rather than a shared service account. The classification of the content in the request, evaluated before it left. The resolved destination, which separates an approved model endpoint from anything else. The policy version and the outcome.

With those four, an examiner can sample a claims decision, trace which model received which data under which rule and read the decision that permitted it. Without the identity field, the sample stops at a service account and the trail ends.

An AIS Program that cannot produce a single sampled request record is a policy document with a governance chapter, and examiners have started asking for the sample. AI audit trail requirements by regulation covers the fields other regimes name.

Third-party expectations are contractual and testable

The bulletin addresses both third-party data and third-party AI Systems. It covers "due diligence and the methods employed by the Insurer to assess the third party," contract terms that "provide audit rights and/or entitle the Insurer to receive audit reports by qualified auditing entities" and terms requiring the third party "to cooperate with the Insurer with regard to regulatory inquiries and investigations."

Two practical consequences follow. First, a vendor that will not accept the cooperation clause is a regulatory exposure rather than a procurement preference. Second, audit rights that are never exercised produce no evidence, and the bulletin addresses "the performance of contractual rights regarding audits."

For AI vendors specifically, add a question about what the vendor records per request and whether that record can be produced for a named policyholder. AI security for insurance covers the wider control set.

Adverse Consumer Outcomes drive the control strength

The bulletin ties controls to "both the risk of Adverse Consumer Outcomes and the Degree of Potential Harm to Consumers." That proportionality rule gives a defensible way to decide where enforcement runs inline and where monitoring is sufficient.

An AI step that supports a declination, a rate, a rescission or a claim denial sits at the high end. An AI step that drafts an internal meeting summary sits at the low end. Write the tiering down with the reasoning, because an examiner is entitled to ask why a given control was considered proportionate.

Insurance AI underwriting under the EU AI Act covers the parallel European classification for insurers with EU exposure.

Retention and independence of the records

Records that the examined team can edit are weak evidence. Keep AI request records on a write path independent of the application that generated the traffic, set the retention period against the longest applicable requirement and document who can alter them.

The NIST AI Risk Management Framework covers the same ground under MEASURE and MANAGE, which both ask for dated artifacts. A described intention satisfies neither. AI gateway for insurance covers the enforcement point on the managed path.

DeepInspect

DeepInspect is a stateless proxy for authenticated HTTP traffic between enterprise users or agents and LLM endpoints. It evaluates application-supplied identity, request classification, approved destination and policy before forwarding, and every permit, redaction, reroute or block produces a signed per-decision record outside the calling application's write path.

For an insurer, those records supply the examinable layer underneath the AIS Program: which identity sent which class of policyholder data to which model under which rule. DeepInspect leaves model validation, actuarial review, unfair discrimination testing, vendor-native inference and state filing obligations with the insurer and its suppliers. Book a demo today.

Frequently asked questions

Is the NAIC Model Bulletin binding on my company?

The bulletin is a model that individual state departments adopt and issue themselves, so the binding instrument is your state's version. Check each state where you are authorized, note the adoption date and any state-specific additions, and build one program that satisfies the strictest adopted version. Maintaining a separate program per state multiplies the audit surface for no gain.

What does an examiner ask for first?

The written AIS Program and documentation evidencing its adoption, followed by documentation of monitoring and audit activities respecting compliance with it. Expect follow-up questions about pre-acquisition diligence, monitoring and auditing of third-party data or AI Systems, since the bulletin names those explicitly.

How do we evidence data protection for a browser-based assistant?

Through controls on the managed device and the network path rather than inside the vendor product. Record the AI-bound requests, the identity behind them and the classification of the content, then report that population separately from application-mediated traffic so the coverage claim stays honest.

Which AI uses need the strongest controls?

The ones whose output supports a decision with direct consumer effect, such as declination, rating, rescission, claims denial or fraud referral. The bulletin asks for controls commensurate with the risk of Adverse Consumer Outcomes and the Degree of Potential Harm, so document the tiering logic alongside the tiers themselves.