The Cardinal Rule - Reason Codes, Not Vibes
In April 2026 a Colorado Division of Insurance market-conduct examiner opened the carrier's algorithm-inventory entry for the personal-auto pricing GLM and asked one question: "Show me the human-reviewable reason behind the +12% rate increase on policy A-7741390." The carrier's response listed the Akur8 model name, the SHAP attribution for territory and roof-age contribution, the disparate-impact ratio across protected-class proxies, and the model version. The examiner read it once, set the file down, and said: "That tells me what the model did. It doesn't tell me what the carrier decided. I'm going to need both." Section 4 of the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers - adopted by 25+ jurisdictions by mid-2026, operating as a binding standard everywhere it has been issued - is built around exactly that distinction. The model produces an output. The carrier owns the decision. Every adverse UW decision, every claim denial, every rate increase at renewal, every accelerated-UW knockout, every SIU referral, every adverse-action letter that touches a policyholder or claimant must trace to a documented, human-reviewable reason that names the variables driving the call and separates any protected-class proxies. The cardinal rule of this program - reason codes, not vibes - is the operational anchor every L2 verification checklist, every L3 workflow, every L4 governance memo, and every L5 board narrative builds on. This lesson is the rule walked through with the carrier examples that landed in 2026 DOI exams.
What NAIC Model Bulletin §4 Actually Says
The bulletin's section 4 is structured around four governance pillars that bind in every adopting jurisdiction. §4.1 covers program structure - the named accountable executive, the written AI policy, the inventory of deployed systems. §4.2 covers third-party AI assurance - vendor diligence, contractual representations, audit rights. §4.3 covers testing and validation - bias testing, drift monitoring, fairness assessment, model documentation. §4.4 covers documentation - the file-note and audit-trail expectations on every AI-touched adverse decision.
Section 4.4 is where the cardinal rule lives. The bulletin language directs carriers to produce documentation that allows a regulator, a court, or a license-board investigator to reconstruct how an AI-influenced decision was made - including the data inputs, the variables, the model's contribution, and the human's substantive role. The phrase that has become operational shorthand is "human-reviewable reason." The reason must be expressible in words a reviewer can read. The reason must name variables and facts, not model artifacts. The reason must be separable from any protected-class proxy that may have influenced the prediction.
What §4 does not say is that AI cannot produce the prediction. The Akur8 GLM can run. The Cytora appetite score can score. The Shift fraud signal can fire. The Five Sigma FNOL summary can draft. What the bulletin requires is that the documented reason behind any adverse outcome names the human-readable variables driving the call - and that the carrier can defend the chain in writing.
The Colorado Reg 10-1-1 Operational Expression
Colorado Reg 10-1-1 - amended effective October 15, 2025, with the first compliance report due July 1, 2026 - operationalizes the cardinal rule for life, private passenger auto, and health benefit plans. The regulation requires an algorithm inventory naming every in-scope model, an ECDIS inventory naming every third-party data source used in life UW, bias-testing per source and aggregate, a documented governance program, and consumer-facing disclosure for adverse routing.
The compliance report's substance, in operating terms: every model has a model card, every model has a bias-test exhibit, every adverse decision has a documented reason chain naming the variables driving the call (separate from any protected-class proxy), and the carrier has a named accountable executive who signs the compliance report. The July 1, 2026 first deadline turns the cardinal rule into a written deliverable.
The Colorado DOI's posture in 2026 examinations: the examiner reads the algorithm inventory, picks a specific deployed model (the personal-auto pricing GLM, the accelerated-UW knockout model, the homeowners renewal-rating model), picks a specific consumer-impacting decision in the past 12 months, and asks for the reason chain in writing. "Show me the variables driving the call on this specific policy or claim, and tell me which variables you tested for protected-class proxy effect." If the carrier cannot produce the chain on demand, the examination escalates.
The NY DFS Circular Letter 2024-7 Proxy Test
NY DFS Circular Letter 2024-7 (effective on issuance July 11, 2024) articulates the proxy test in writing. The carrier must document - in a memo, in the algorithm inventory, in the SERFF filing supporting material - whether any variable (or combination of variables) operates as a stand-in for a protected class. ZIP code is the canonical example: it correlates with race in many regions; using it as a model feature without explicit analysis of the correlation and its mitigation is a §4 violation under the bulletin and a Circular Letter 2024-7 violation under DFS.
The proxy-test memo is a real artifact. The actuary or model owner names the variable, computes its correlation with protected-class proxies, runs the disparate-impact analysis on the model's output by group, documents the mitigation (variable transformation, feature engineering, alternative feature, threshold adjustment, post-hoc calibration), and signs. The memo is a deliverable in every SERFF rate filing involving an AI-influenced rate, in every Reg 10-1-1 compliance report, and in every NAIC AI Systems Evaluation Tool Exhibit C high-risk-system response. The L2 actuarial chapter walks the drafting; the L1 cardinal rule sets the demand.
The FCRA §615 Adverse-Action Letter
Fair Credit Reporting Act §615 governs adverse-action notices when consumer-report data was used in the decision. For L&H accelerated-UW knockouts using MVR, Rx history (Milliman IntelliScript, ExamOne ScriptCheck, LexisNexis MedAdvisor), MIB code, or behavioral data, FCRA §615 requires a pre-notice (under §615(a)(2) where applicable) and an adverse-action letter naming the data source, the right to free disclosure from the consumer-reporting agency, and the right to dispute. For P&C lines using credit-based insurance scoring, similar notice obligations apply under state-specific law plus FCRA where credit is consulted.
The cardinal-rule expression on the FCRA adverse-action letter: the variable driving the decision is named (e.g., "credit-based insurance score below threshold"), the data source is named (e.g., "TransUnion / LexisNexis Risk Solutions"), the consumer is told how to dispute, the carrier preserves the algorithm-inventory entry that ties the consumer-impacting decision to the model and the variable. The L4 governance program owns the letter template; the L2 verification checklist confirms the letter accompanies every consumer-report-driven adverse action.
The Shift SIU Referral - The Fact Chain vs. The Score
The Atlanta auto claims adjuster's SIU referral on the third-party-medical-clinic cluster lives in the §4 territory. Shift Technology's fraud score is 0.87 - a high signal. The referral memo cannot say "Shift score 0.87" as the reason. The memo must enumerate: the third-party clinic appeared on five plaintiff-attorney-represented soft-tissue claims in the past 60 days; ISO ClaimSearch returned a prior-loss match on the named insured for a similar injury in 2023; the geographic clustering of the five claims falls within a single mile of the same intersection; the attorney representing all five claimants is the same name across the five files. Those facts are the reason chain.
The Shift score informs the adjuster's attention. The facts the adjuster enumerated, verified, and documented are the reason. The memo cites the facts; references the Shift score as a signal that triggered the review; names the human-reviewable inputs; preserves the audit chain. NAIC §4.4 is satisfied. The Colorado Reg 10-1-1 algorithm-inventory entry for the Shift deployment names the variables, the bias-test exhibit, and the SIU-manager review checkpoint.
The Accelerated-UW Knockout - Reason Codes on the L&H Path
A Munich Re risk-assessment platform deployment (or Swiss Re Magnum, RGA AURA NEXT, SCOR Velogica) on individual term life: the applicant is routed to a "decline" outcome after the platform integrates the MVR, the Rx history, the MIB code, the public records, and the behavioral data. The platform's output is a probabilistic risk score thresholded against the carrier's accelerated-UW knockout rules. The cardinal rule applies in full.
The knockout reason chain names the variable (e.g., "two prior DUI convictions on MVR within three years; Rx history of opioid medication beyond 90 days; combined risk score above accelerated-UW threshold"); separates protected-class proxies (the carrier's bias-test exhibit on the model demonstrates absence of disparate impact on the relevant geographic and demographic axes); names the data source (LexisNexis MVR, Milliman IntelliScript); attaches the FCRA pre-notice and the adverse-action letter naming the consumer-reporting agencies; documents the human reviewer (the senior L&H underwriter who reviewed the knockout before the letter went out); and stamps the algorithm-inventory entry with the model version. The Colorado Reg 10-1-1 ECDIS inventory documents each data source; the L4 NAIC AI Systems Evaluation Tool Exhibit C entry describes the high-risk system.
The Rate Impact on Renewal - Reason Codes on the P&C Path
A personal-auto renewal lands on the carrier's pricing system with a +12% rate impact driven primarily by the Akur8 GLM's territory factor refresh and a roof-age factor on the homeowners line. The policyholder calls the producer; the producer escalates to the carrier; the policyholder requests the reason for the increase. The cardinal rule applies.
The reason chain names the variables (territory factor refresh based on three-year cat experience in the policyholder's ZIP code; roof-age factor based on the inspection record showing the roof's age; absent any other rating-factor changes); cites the SERFF filing that authorized the territory factor change; references the model card and the SHAP attribution showing the variable contributions; documents the proxy-test memo demonstrating that the territory factor is not operating as a proxy for protected class beyond the actuarial justification; and produces a customer-facing notice that names the reasons in human-readable language. The L4 governance program owns the customer notice template; the L2 verification checklist confirms the chain is in place before the renewal lands.
The CGL Claim Denial - Reason Codes on the Coverage Path
The Atlanta adjuster's overdue Reservation-of-Rights on the CGL faulty-workmanship-exclusion question moves toward a denial. The cardinal rule attaches at the denial letter.
The reason chain names the policy form (ISO CG 00 01 04 13) and the controlling exclusion language (the actual quoted text from the policy, retrieved via RAG and verified by the adjuster); names the venue-state controlling case (Massachusetts SJC's 2019 Liberty Mutual v. ABC Construction is a placeholder - the actual venue case is the one retrieved and pasted into the LLM context, then verified by the adjuster); applies the Anti-Concurrent-Cause analysis with the carrier's claim-handling-manual position; documents the human reviewer (the senior adjuster, the supervisor, defense counsel if escalated); attaches the prompt log and model version for the LLM-drafted denial letter; preserves the file note. The denial letter survives a bad-faith examination under Texas Insurance Code §541, Florida §624.155, or California Cumis/Brandt because the chain is traceable.
The Fraud Cluster, the Bias Test, and the BISG Discipline
The 82% Hispanic-surname cluster from the previous lesson is the §4 violation case. The cardinal rule's discipline reverses the chain: the carrier proves there is no proxy effect on the model's output by group, computes the disparate-impact ratio per cluster, documents the mitigation if below threshold, and signs the algorithm-inventory entry. Bayesian Improved Surname Geocoding (BISG) - the technique that uses surname plus geographic data to estimate race - is defensible but careful: the Colorado Reg 10-1-1 implementation guidance treats it as permissible when paired with the bias-test exhibit; using it as an unweighted model feature without the test is a violation.
The L3 bias-detection workflow tests every deployed predictive model on protected-class proxies, computes the disparate-impact ratio per cluster, and remediates when below threshold. The L4 algorithm-inventory entry documents the variables, the bias-test exhibit, the mitigation. The L1 cardinal rule sets the demand: every AI-touched adverse outcome traces to a documented reason chain that names variables, separates proxies, and preserves the audit trail.
Reason Codes vs. Vibes - The Operational Distinction
The vernacular of "reason codes, not vibes" captures the operational distinction the bulletin demands. Vibes are the underwriter's gut, the adjuster's instinct, the producer's salesmanship, the actuary's intuition - and the model's probabilistic output presented as a finding. Reason codes are the documented, named, defensible chain that a regulator, a court, a license-board investigator, or a treaty reinsurer can read and verify.
A reason code on an adverse UW decision looks like: "Declined. Reason: building 14 (1962 six-story wood-frame) violates appetite criterion 'no frame habitational over four stories' per the 2024 appetite guide; loss-control report (4/2023, reference #LC-44892) flagged knob-and-tube wiring as a deferred-maintenance condition with no remediation documentation in the submission packet. Human reviewer: Senior Underwriter J. Martinez. Akur8 indication: not generated (out-of-appetite knockout precedes pricing). Algorithm-inventory entry: Cytora Autopilot triage v2.3, Federato RiskOps appetite-knockout module v1.8. Date: April 15, 2026."
A vibe on the same decision looks like: "Declined. The risk doesn't fit our book." Vibes do not survive a DOI examiner; reason codes do.
The same distinction holds across personas. The Atlanta adjuster's SIU referral is reason codes - the clinic, the prior-loss match, the geographic clustering, the shared attorney - not "Shift score was high." The Boston producer's BOR letter names the dates, the venue-state cooling-off rule, the signature authority. The pricing actuary's SERFF filing names the variables, the SHAP attribution, the bias-test exhibit, the proxy-test memo. Every persona, every artifact, every adverse outcome - the cardinal rule binds.
The MHPAEA NQTL Test on Behavioral-Health Claims
The Mental Health Parity and Addiction Equity Act's Non-Quantitative Treatment Limitation (NQTL) analysis is a parallel cardinal-rule expression for behavioral-health claims. The carrier's AI utilization-review tool denied 14 of 22 Intensive Outpatient Program requests in the prior quarter against a benchmark 4 of 22 medical/surgical denial rate - a disparate-rate signal that triggers the NQTL analysis.
The NQTL analysis demands the carrier articulate in writing the comparability of the utilization-review tool's design, application, and outcomes between behavioral-health and medical/surgical benefits. The carrier's claims handler - supported by L&H actuarial and compliance - documents the tool's variable selection, the training data, the decision thresholds, the outcome distributions, and the corrective action if disparate impact is established. The 60-day quantitative parity test, the documented mitigation, the consumer-facing notice on adverse determination, and the algorithm-inventory entry naming the tool and its variables are the operational expression. The cardinal rule binds at every step.
The Carrier Program That Survives an NAIC Exhibit B Review
The NAIC AI Systems Evaluation Tool's Exhibit B asks for the carrier's governance program. The cardinal rule defines what the program produces: a named accountable executive per AI deployment surface, a written policy that articulates how the human owns the decision and the AI informs it, a documented inventory of every model with its accountable owner, a bias-test exhibit per model, a proxy-test memo for any variable that may stand in for a protected class, an adverse-action chain template (FCRA §615 where applicable, state-specific where not), and an incident-response runbook for AI failures that produced adverse outcomes.
The 12-state pilot through September 2026 - California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia, Wisconsin - is the operational test. The carrier whose Exhibit B response names the cardinal rule's discipline in writing - variables, proxies, human reviewers, audit trail - passes the pilot. The carrier whose response describes tools without the chain returns material gaps and a follow-up examination.
Key Takeaways
- The cardinal rule of the entire program: reason codes, not vibes. NAIC Model Bulletin §4 - adopted by 25+ jurisdictions by mid-2026 - demands every adverse UW decision, claim denial, accelerated-UW knockout, rate impact, fraud referral, and adverse-action letter trace to a documented, human-reviewable reason that names the variables driving the call and separates any protected-class proxies. "The model said so" is never a reason code.
- §4 is structured around four pillars: §4.1 (program), §4.2 (third-party AI), §4.3 (testing and validation), §4.4 (documentation). §4.4 is where the cardinal rule lives - the file-note and audit-trail expectations on every AI-touched adverse decision.
- Colorado Reg 10-1-1 operationalizes the rule for life, private passenger auto, and health benefit plans. Amended October 15, 2025; first compliance report due July 1, 2026. Algorithm inventory, ECDIS inventory, bias-testing per source, named accountable executive, consumer-facing disclosure for adverse routing - all written deliverables.
- NY DFS Circular Letter 2024-7's proxy test (effective July 11, 2024) attaches at variable selection. The proxy-test memo names the variable, computes correlation with protected-class proxies, runs disparate-impact analysis on the model's output by group, documents the mitigation, and signs. The memo is a deliverable in every SERFF filing, every Reg 10-1-1 report, and every NAIC AI Systems Evaluation Tool Exhibit C response.
- FCRA §615 adverse-action letters apply to L&H accelerated-UW knockouts touching MVR, Rx history, MIB code, behavioral data, and P&C lines using credit-based insurance scoring. Pre-notice plus adverse-action letter naming the data source, the right to free disclosure, and the right to dispute. The L4 governance program owns the template; the L2 verification checklist confirms the letter accompanies every consumer-report-driven adverse action.
- The Shift SIU referral, the Munich Re / Swiss Re Magnum / RGA AURA NEXT / SCOR Velogica accelerated-UW knockout, the Akur8 rate impact at renewal, the LLM-drafted CGL denial, and the AI utilization-review tool's behavioral-health denial - each is a cardinal-rule application. Variables named, proxies separated, human reviewer documented, audit chain preserved.
- The MHPAEA NQTL analysis is the parallel cardinal-rule expression for behavioral-health benefits. The 14-of-22 IOP vs. 4-of-22 medical/surgical denial-rate disparity triggers the analysis; the carrier articulates comparability of design, application, and outcomes between behavioral and medical/surgical benefits; corrective action documented if disparate impact is established.
- The NAIC AI Systems Evaluation Tool Exhibit B governance memo across the 12-state pilot (California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia, Wisconsin) - running early 2026 through September 2026, re-exposure September-October 2026, adoption expected at the NAIC Fall National Meeting November 2026 - is the operational test of the cardinal rule. Programs that name the discipline in writing pass; programs that describe tools without the chain return material gaps.
Skill.re