Build an Insurance AI Governance Program - The NAIC Model Bulletin §4 Framework
The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers - adopted in some form by 25+ jurisdictions through mid-2026 - does not actually tell a carrier how to build an AI governance program. It tells a carrier what the program must contain: a written AI program approved at a senior level, accountable governance with named executive ownership, third-party AI controls, testing and validation, and documentation that survives a market-conduct exam. The bulletin's §4 framework is the spine; the AI Systems Evaluation Tool (AISET) Exhibit B is the regulator's read-out of that spine. Carriers that build the governance program to satisfy Exhibit B mechanically - board-approved charter, four-axis program structure, named accountable executives mapped to RACI, escalation paths into the existing risk taxonomy - pass the exam without theater. Carriers that build the program as a memo without the org-chart, the cadence, and the decision-rights survive the first cycle and fail the second. This lesson is the governance-program build: the AI committee charter, the membership and cadence that maps to the CRO / CCO / Chief Actuary / Chief Claims Officer reality, the four §4 program elements built into operational artifacts, and the Exhibit B mapping that turns the program into a regulator-ready response packet.
The NAIC §4 Framework as an Operating Spine
NAIC Model Bulletin §4 articulates four governance program elements: (1) a written AI Systems Program approved by senior management, with governance principles, accountability, and oversight; (2) governance and risk management controls covering the AI Systems Program lifecycle, including the carrier's own use and the use of third-party AI; (3) third-party AI Systems standards for diligence, contracting, monitoring, and incident response; and (4) testing and validation requirements appropriate to the risk classification of each AI System. Carriers that read §4 as four sections of a memo miss the point - §4 is the operating spine for the program, and each element corresponds to specific artifacts and decisions that recur monthly or quarterly inside the AI committee.
Element 1 (Written Program) is the foundational artifact: a 20-30 page document approved by the board's risk committee or audit committee, refreshed annually, that names the carrier's AI Systems definition, risk classification taxonomy, accountable executives, committee structure, decision rights, escalation paths, training requirements, documentation standards, and incident response interfaces. The Written Program is what AISET Exhibit B references in its narrative request; it is what a Colorado DOI examiner asks for first; it is what the Appointed Actuary references in the ASOP No. 56 peer-review chain. Element 2 (Governance and Risk Management) operationalizes the Written Program: the AI committee cadence (typically monthly), the algorithm registry refresh cycle (quarterly minimum), the fairness and drift testing schedule (varies by risk tier), and the integration with existing enterprise risk management (NAIC ORSA, COSO ERM, ISO 31000). Element 3 (Third-Party AI Standards) covers the vendor lifecycle - Cytora, Federato, Akur8, Earnix, Shift, Tractable, CCC, Hi Marley, Five Sigma, Coalition - including diligence (the §4 attestation), contracting (BAA / DPA / sub-processor disclosure / model-update notification / audit rights), monitoring (vendor scorecard refresh), and incident response (joint runbook). Element 4 (Testing and Validation) is the risk-tiered testing program: high-risk Tier 1 models get quarterly fairness testing, drift monitoring with PSI and calibration metrics, peer review under ASOP No. 56; Tier 2 gets semi-annual; Tier 3 gets annual.
The AI Committee Charter - Membership, Cadence, Authority
The AI committee is the operational engine of the governance program. The charter document - typically 6-8 pages - defines purpose, membership, decision rights, meeting cadence, escalation paths, and reporting lines to the board's risk committee. The committee is not a discussion forum; it is a decision body with documented authority over algorithm registry additions and retirements, model risk tier classifications, vendor approvals and exits, incident response activation, and exceptions to the Written Program. Without documented decision rights, the committee is theater and the §4 program fails Exhibit B's governance narrative test.
Membership pattern at a mid-size specialty carrier ($500M-$2B premium): Chief Risk Officer (chair), Chief Compliance Officer (vice-chair), Chief Actuary or Appointed Actuary, Chief Claims Officer, Chief Underwriting Officer, Chief Information Security Officer, Chief Data Officer or Head of Data Science, General Counsel or designee, and a rotating business-line head (personal lines, commercial lines, L&H, specialty). The CRO chairs because the committee's accountability is enterprise risk; the CCO co-chairs because the §4 program is regulator-facing and compliance owns external posture. Membership pattern at a brokerage or MGA differs - Agency Principal or CEO chairs, with the CCO, Head of Producer Operations, IT/Data lead, and outside counsel cycling in. Cadence: monthly standing meeting (90 minutes) with quarterly deep-dive (3 hours). Annual session: Written Program refresh, board-committee report-out preparation, Colorado Reg 10-1-1 compliance report sign-off, AISET response packet sign-off.
Decision-rights pattern (documented in the charter): committee approves algorithm registry additions and risk-tier classifications; committee approves vendor entries and exits; committee approves incident response activation above defined materiality threshold; committee approves exceptions to the Written Program for individual use cases. Below the threshold, the algorithm owner (named in the registry entry) has operating authority. Above the threshold, escalation goes to the CEO and the board risk committee. Without the threshold defined, every decision flows to the committee and the committee chokes; with the threshold defined, the committee handles the material 10-15% of decisions and the rest flow through the registered owners.
Accountable Executive Mapping - CRO, CCO, Chief Actuary, Chief Claims Officer
NAIC §4 requires named senior-management accountability. Generic accountability ("the senior leadership team owns AI") fails the Exhibit B narrative test; specific accountability with documented RACI mapping passes. The pattern at a typical mid-size carrier: CRO is the accountable executive for the AI Systems Program overall (charter sign-off, board reporting, enterprise risk integration); CCO is accountable for regulatory posture (state DOI bulletins, AISET response, Colorado Reg 10-1-1 compliance report, FCRA adverse-action workflow); Chief Actuary is accountable for pricing-and-reserving model governance (ASOP No. 56 peer review, rate filing memorandum and bias exhibit, Statement of Actuarial Opinion narrative as it touches AI outputs); Chief Claims Officer is accountable for claims AI governance (Tractable, CCC, Shift, Hi Marley, Five Sigma program-level oversight); Chief Underwriting Officer is accountable for underwriting AI (Cytora, Federato, Convr, Indico submission workflow); CISO is accountable for AI security and data protection; General Counsel is accountable for E&O posture and discovery readiness.
The RACI mapping is published as an appendix to the Written Program and refreshed annually. Each algorithm registry entry references the named accountable executive - not the title, the named person - and the accountable executive personally attests to the §4 attestation at least annually. Personal attestation matters: a Colorado examiner asking "who is accountable for the Akur8 personal auto pricing model" expects a name, a date of last attestation, and the documented decision chain that produced the last fairness test result. "The Chief Actuary's team" is an unsatisfactory answer; "Jane Smith, Chief Actuary, attestation dated March 15 2026, last fairness test February 28 2026 documented in registry entry AK-PL-AUTO-001" is the satisfactory answer.
Written AI Program - The 20-30 Page Board-Approved Document
The Written Program is the document the board's risk or audit committee approves annually. Section structure: (1) Purpose and scope - define AI Systems for the carrier, including third-party AI; (2) Governance principles - fairness, transparency, accountability, safety, robustness, privacy (mapping to NAIC §3 principles); (3) AI committee charter (cross-referenced); (4) Risk classification taxonomy (Tier 1/2/3 with examples); (5) Accountable executive RACI; (6) Algorithm registry standard (cross-referenced to inventory document); (7) Third-party AI standards (diligence, contracting, monitoring, incident response); (8) Testing and validation program (fairness, drift, bias, calibration by tier); (9) Documentation standards (model cards, file notes, prompt logs, reason codes); (10) Training requirements (CPCU, AIC, AIAI, CAS, SOA mapping); (11) Incident response (cross-referenced to runbook); (12) Reporting (committee, board, regulator); (13) Exception management; (14) Annual review and refresh schedule.
Risk classification taxonomy is the engine of the Written Program. Tier 1 (high risk): consumer-adverse decisions that produce adverse-action obligations or rate impact (Akur8 pricing models in production, Munich Re or Swiss Re accelerated UW knockouts, Shift fraud-referral models with SIU consequences, Tractable estimate models on total-loss decisions). Tier 1 requires quarterly fairness testing, peer review under ASOP No. 56, monthly drift monitoring, annual third-party model validation, dual-attestation by accountable executive and algorithm owner. Tier 2 (moderate risk): decision-support without direct consumer-adverse outcome (Cytora submission triage scoring, Federato appetite scoring, Convr enrichment, Hi Marley sentiment classification on claims comms, Five Sigma coverage-summary drafting). Tier 2 requires semi-annual fairness review, quarterly drift, annual attestation. Tier 3 (lower risk): productivity tools without consumer-touching decisions (loss-run summarization for internal use, draft generation for human-reviewed output, transcription for note-taking). Tier 3 requires annual review and registry entry; no formal fairness testing required but periodic spot-check recommended.
Third-Party AI Standards - The Vendor Lifecycle
NAIC §4 explicitly extends governance obligations to third-party AI. A carrier that uses Cytora, Federato, Akur8, Earnix, Shift, Tractable, CCC, Hi Marley, Five Sigma, or Coalition cannot delegate §4 responsibility to the vendor - the carrier remains responsible for the AI System's compliance posture. The third-party AI standards section of the Written Program defines the four-stage lifecycle: diligence, contracting, monitoring, exit.
Diligence stage: vendor §4 attestation (vendor confirms they meet equivalent governance standards), SOC 2 Type II report review, model documentation review (model card, training data lineage, fairness test results, drift monitoring posture), sub-processor disclosure (foundation-model providers - OpenAI, Anthropic, Google, AWS Bedrock - and their data residency, training-use posture, audit rights), reference checks with three peer carriers using the vendor. Diligence is owned by the algorithm owner with CCO and CISO sign-off; documented in vendor onboarding packet stored in vendor management system.
Contracting stage: master service agreement with §4-aligned clauses - BAA for L&H vendors touching PHI, GLBA-compliant data processing agreement, sub-processor disclosure and prior-consent for changes, model-update notification with defined evaluation window (typically 30 days), audit rights (annual at minimum), incident notification (24-72 hours depending on severity), data residency (US-only for GLBA NPI), exit clause with data return and deletion obligation. Standard MSA clause library maintained by General Counsel; vendor-specific deviations require AI committee approval.
Monitoring stage: vendor scorecard refreshed quarterly - KPI performance against SLA, model-update notifications received and evaluated, sub-processor changes, incident history, contract renewal status, concentration analysis (no vendor above 25% of critical decision flow without committee approval). Monitoring is owned by algorithm owner; scorecard reviewed at quarterly AI committee deep-dive.
Exit stage: documented exit plan including data return, model retention or deletion, algorithm registry update, regulatory notification if material. Exit triggers: vendor §4 non-conformance, material incident, contract non-renewal, business case withdrawal. Exit plan documented in algorithm registry entry; review annually.
Escalation Paths and the Board Reporting Line
Escalation paths are the §4 element most often underbuilt. The Written Program defines three escalation tiers: tier-1 (algorithm-owner level - drift exceeding threshold, fairness test failure within tolerance, single vendor incident); tier-2 (AI committee level - material drift, fairness test failure outside tolerance, multi-vendor pattern, regulatory inquiry); tier-3 (CEO + board risk committee - adverse-action pattern, market-conduct exam findings, consumer harm, vendor §4 non-conformance, material model failure). Each tier defines the notification SLA, the documentation requirement, and the decision authority.
Board reporting line: AI committee chair (CRO) reports to the board's risk committee quarterly with a 4-6 page summary covering algorithm registry status, incident history, regulatory developments, vendor scorecard summary, fairness and drift metrics, training and credentialing progress, AISET preparation status (when in scope), Colorado Reg 10-1-1 compliance report status (when in scope). Annual session: full Written Program refresh, multi-year roadmap, capital allocation alignment, board attestation of program adequacy. Board attestation is the §4 senior-management approval anchor - without it, the Written Program is unapproved and the carrier's AISET Exhibit B narrative cannot reference board-level governance.
AISET Exhibit B Mapping and Why the Mechanical Build Passes
The NAIC AI Systems Evaluation Tool Exhibit B is the regulator-facing read-out of the §4 governance program. The exhibit requests narrative responses covering: program existence and approval status, accountable executive mapping, committee structure and cadence, risk classification taxonomy, algorithm inventory linkage, testing and validation summary, third-party AI standards, incident response posture, training program, and continuous improvement. Carriers that built the governance program mechanically - Written Program with 14 named sections, charter with documented decision rights, RACI with named accountable executives, registry with risk-tier classifications, vendor lifecycle with documented stages - answer each Exhibit B question by extracting the relevant section. The mechanical build passes; the memo-without-operations build fails because the examiner asks follow-up questions ("show me the last committee meeting minutes; show me the last vendor scorecard; show me last quarter's fairness test results for the Akur8 pricing model") and the memo-only carrier cannot produce the artifacts.
The Exhibit B narrative is typically 15-25 pages with appendix; the underlying artifacts are 200-400 pages. Carriers that confuse the narrative for the program have built theater. Carriers that built the program first and extracted the narrative second pass the 12-state pilot information request without remediation. The forcing function is structural: AISET re-exposure September-October 2026 and adoption at the NAIC Fall National Meeting November 2026 mean the program needs to be operationally complete in 2026 H2, not 2027.
Key Takeaways
- NAIC §4 is an operating spine, not a memo. Four elements - Written Program, governance and risk management, third-party AI standards, testing and validation - correspond to specific monthly and quarterly artifacts. Carriers that read §4 as four memo sections fail the second exam cycle.
- AI committee charter is a decision body with documented authority, not a discussion forum. CRO chairs, CCO co-chairs, Chief Actuary / CUO / CCO / CISO / CDO members, monthly cadence with quarterly deep-dive. Decision rights documented: registry approvals, vendor approvals, incident activation, exception management.
- Accountable executive mapping is name-specific, not title-specific. "Jane Smith, Chief Actuary, attestation dated March 15 2026" passes the Colorado examiner question; "the Chief Actuary's team" does not.
- Risk classification taxonomy is the engine. Tier 1 (consumer-adverse - Akur8 pricing, Munich Re accelerated UW, Shift fraud referral, Tractable total-loss): quarterly fairness, monthly drift, ASOP 56 peer review, dual attestation. Tier 2 (decision support): semi-annual. Tier 3 (productivity): annual.
- Third-party AI lifecycle is four stages: diligence, contracting, monitoring, exit. §4 cannot be delegated to vendors; carrier remains responsible. Vendor scorecard refreshed quarterly; concentration limit 25% of critical decision flow.
- Escalation paths are three-tier: algorithm-owner, AI committee, CEO + board risk committee. Each tier has SLA, documentation requirement, decision authority. Board reporting line: CRO presents quarterly with annual full-program refresh and board attestation.
- AISET Exhibit B is the read-out of the §4 program. Mechanical build (Written Program with 14 sections, charter with decision rights, RACI with names, registry with tiers, vendor lifecycle with stages) answers every Exhibit B question by extraction. Memo-only build fails on the second examiner question.
- Board attestation is the §4 senior-management approval anchor. Without annual board risk-committee attestation of program adequacy, the Written Program is unapproved and the AISET narrative cannot reference board-level governance - a structural failure mode.
- Forcing function is structural and dated. AISET re-exposure September-October 2026; adoption at NAIC Fall National Meeting November 2026. Operationally complete program needed by 2026 H2, not 2027.
Skill.re