Design Partner ProgramWe're accepting applications for the next cohort of design partners in finance, insurance, healthcare, and HR. Apply now →

meilynx
← All posts

The NAIC AI Systems Evaluation Tool: What a Chief Compliance Officer Should Have Ready

The NAIC's AI questionnaire for insurers is planned for adoption in November 2026. What it asks, and the records a compliance officer should have ready.

Cassio MeloCassio MeloCo-Founder5 min readCompliance

If your state insurance department sent the NAIC's AI questionnaire tomorrow, how long would your organization need to answer it? Insurers in twelve states have already found out. They received drafts of it during the 2026 pilot, and a final version is planned for adoption in November.

What the tool is

The AI Systems Evaluation Tool is a set of four questionnaires, called exhibits, that state regulators can use in market conduct exams, financial exams and financial analysis. It asks how an insurer uses AI and how it governs that use. The NAIC's Big Data and Artificial Intelligence (H) Working Group drafts it, and by July 2026 had renamed it the AI Risk Evaluation Supplement. Version 5.0 was exposed for public comment on 31 August.

The Working Group's plan is one more draft for comment, then a version 7.0 presented for adoption at the NAIC Fall National Meeting, 14 to 17 November 2026 in Dallas. In February it described the goal as states using the tool on a voluntary basis in 2027. The pilot states, the timeline and every source are on our reference page for the NAIC AI Systems Evaluation Tool.

Why to prepare before the vote

The questions are public. Every version is posted on the Working Group's page, so there is no guessing what an examiner will ask.

The pilot showed how it will be used. California, Colorado, Connecticut, Florida, Iowa, Louisiana, Maryland, Pennsylvania, Rhode Island, Vermont, Virginia and Wisconsin each chose their own domestic insurers and sent the tool as a formal examination, a survey or data call, or a mix of the two. Before the pilot began, the Working Group's chair said he believed participation would not be voluntary for an insurer that was selected.

It formalizes the Model Bulletin. If your state has issued the NAIC Model Bulletin on the Use of AI Systems by Insurers, its Section 4 already lists what a department may request in an investigation or market conduct action. The supplement turns that list into fixed questions, defines its terms by the bulletin where it can, and adds what financial examiners care about: enterprise risk management, the ORSA, financial reporting and materiality.

What it asks

The supplement suggests starting with Exhibit A and going further only where the answers warrant it.

  • Exhibit A counts AI Systems in use and recently implemented, and AI models with a direct consumer impact or a material financial impact, split into generalized linear models, generative or agentic AI, and other machine learning. It runs across operations from marketing and underwriting to claims, fraud, reserves and reinsurance, and asks for the model inventory, materiality calculation and risk assessment behind the numbers.
  • Exhibit B asks for the AIS Program, as a narrative or a checklist. The checklist wants the document name and page for each process, from unfair trade practices and consumer complaints to vendor oversight. The narrative asks about board reporting, independent validation, explainability, and, for uses with a direct consumer impact, whether a person is in the loop.
  • Exhibit C goes model by model through the high-risk models in production: version, use case, how it was built and by whom, risks and limitations, validation and monitoring, the date of the last test, and any regulatory action taken over it.
  • Exhibit D maps the data behind each model, from aerial imagery and risk scores to age, gender, ethnicity or race, and asks whether each element comes from inside the insurer or from a named vendor.

The evidence an examiner will look for

A chief compliance officer preparing for the supplement should be able to produce:

  • An inventory of AI Systems and models, by operation area and model type, with impact flags, that reproduces the Exhibit A counts on demand.
  • A documented materiality threshold and a risk assessment that rates inherent risk before controls. A regulator may set the threshold or ask for yours.
  • The written AIS Program, its adoption date and review cycle, indexed to the Exhibit B checklist by document and page.
  • For each high-risk model, the version in production, pre-deployment validation, ongoing monitoring for drift, accuracy and unfair discrimination, and dated test results.
  • For generative AI and agents that affect consumers, the record of human review, how errors are caught and resolved, and how a decision can be explained.
  • For third-party AI and data, the vendor behind each model and data element, the procurement standard applied, and how vendor-built systems are monitored and tested.
  • The complaint-handling and consumer-notice records that show how AI-related complaints are tracked and how consumers learn AI Systems are in use.

If the same information has already gone to this or another state's department, the response can say so, and the regulator may accept the earlier submission while it is still current.

Where insurers come up short

Counts that will not reconcile. An inventory assembled by survey produces a different number each time. Exhibit A asks for the counts and the inventory behind them, and the two must agree.

Generative AI left out. Exhibit A gives generative and agentic AI their own columns. An assistant that summarizes a claim file for an adjuster supports a claims decision and belongs in the count.

Vendor detail missing. Exhibit C asks who built each model and whether the insurer can change it. Contracts that restrict disclosure make that harder, and a Working Group vice chair said the question is for the examination staff and the insurer to discuss.

For the LLM and agent slice of an AI inventory, Meilynx records every model call routed through it, with the controls applied, as examination-ready evidence. The Insurance AI framework page shows how that maps to the bulletin.

This post summarizes public NAIC material and is not legal advice. Check the Working Group's page for the current draft before relying on any date.

More from the blog

Regulatory updates

When a regulator changes what an AI examination asks for, hear about it first.

Short notes on SR 26-2, NYDFS 500, FINRA, the NAIC bulletin, the EU AI Act, and the employment-AI statutes, plus what we ship. A few emails a month.