AI Model Governance for Insurance: Documentation a Committee Can Read
One plain page per model, an inventory that shows every one, and a person who answers for each.

AI model governance for insurance is the written program, model inventory and plain documentation that show a board committee and a state examiner what each model decides, who owns it, and whether anyone has checked it lately. KORE1 builds that documentation alongside consultant Khurram Tehseen and recruits the people who keep it current.
Last updated: October 6, 2026
Ask a carrier’s risk committee which decisions its models make and you usually get a binder. A thick one. The validation work inside is often good, written by modelers for other modelers, and the committee approves it on the strength of a two-paragraph cover memo. Nobody reads past it.
That held up while the models lived in actuarial. They don’t anymore. Claims triage, fraud scores, accelerated underwriting, a generative tool drafting adjuster notes and a vendor score tucked inside a rating engine all count now, and regulators have started asking for the list. KORE1 runs this work next to its insurance IT staffing practice, the life and annuity data operations engagements that rebuild the policy record underneath, and the wider IT staffing services desk that fills the seats.
An AI Model Inventory a Committee Can Read
Each spine is one model at an invented life carrier. The label is the part of the documentation that matters most, because it says what the model decides, who answers for it, and when someone last held it up against what actually happened. One spine has no label.
-
M-01
Lapse propensity
- Decides
- Which in-force policies get a retention call before the premium is due
- Owner
- Head of in-force management
- Last checked
- Against actual lapses, second quarter of 2026
-
M-02
Accelerated underwriting triage
- Decides
- Which applicants can skip the paramedical exam
- Owner
- Chief underwriter
- Last checked
- Against a holdout sent through full underwriting, first quarter of 2026
-
M-03
Claims fraud score, vendor built
- Decides
- Which claims go to the special investigations unit
- Owner
- SIU director, with an audit right in the vendor contract
- Last checked
- Vendor drift report, reviewed in house every quarter
-
M-04
Claim file summary, generative
- Decides
- Nothing on its own, but it drafts what the adjuster reads first
- Owner
- Claims operations lead
- Last checked
- Twenty summaries a month read against the full file
-
M-05
Agent lead routing
- Decides
- Which leads reach captive agents first
- Owner
- Distribution analytics manager
- Last checked
- Against placed policies, once a year
-
No label
A scoring macro in an underwriting spreadsheet
- Decides
- Unknown until the inventory found it on a shared drive
- Owner
- Nobody could say
- Last checked
- Never
Look at the sixth spine. Nobody owns it. It’s a spreadsheet that has been nudging underwriting decisions for years, built by someone who has since moved to another team, and it appears on no list because nobody ever thought of a spreadsheet as a model.
First counts turn these up. That’s the point of counting.

The thick file stays. The single page on top is the one a committee reads.
What the NAIC Bulletin Asks Insurers to Write Down
The NAIC adopted its AI systems bulletin for insurers on December 4, 2023. Its own adoption map, last updated August 31, 2026, counts 25 states plus the District of Columbia, Mississippi being the newest. That’s about half the country. California, Colorado, New York and Texas run insurance-specific rules or guidance of their own instead.
The core ask is a written program, an AIS Program in the bulletin’s terms, with senior management accountable to the board for it. Inside sit inventories and descriptions of predictive models, records of how each one was built and is used, and a narrative of what each model is meant to accomplish. Read that last item again. The regulator is asking for prose.
Vendor models get no pass. The bulletin expects due diligence on third-party systems and, where a carrier can get one, a contract right to audit the vendor. New York’s Circular Letter No. 7 is blunter, saying insurers retain responsibility for tools a vendor built, and it wants the board or senior management to review the AI policies at least annually. Annually is the floor.
The habit underneath all of it, writing down what a system does before anybody has to trust it, is the same one our regulated industry tech staffing desks screen for when they hire into securities, device and pharma teams.
The Numbers Behind AI Model Governance in Insurance
- 25 + DC States that have adopted the NAIC AI bulletin, plus the District NAIC adoption map, status as of August 31, 2026
- 4 States running insurance-specific AI rules of their own California, Colorado, New York and Texas
- 12 States piloting the NAIC’s AI evaluation tool for examiners The pilot started in March 2026
- 92% Of KORE1 placements still working the seat a year in Twelve-month retention, all KORE1 desks combined
Colorado set the firmest dates. Its amended Regulation 10-1-1 took effect October 15, 2025 and pulled private passenger auto and health benefit plan insurers in beside life carriers, with compliance due by July 1, 2026 and a report to the Division every year after that.
Every one of these asks the same thing in different words. Can someone who didn’t build the model say what it does?
Five Steps to Model Documentation a Committee Can Read
The count comes before any page gets written. Most of the exposure sits in the models nobody listed, so writing beautiful documentation for the five you already knew about solves the wrong half of the problem. Count first.
-
Step 1
Count every model
Actuarial, underwriting, claims, marketing and fraud, plus vendor scores, spreadsheet macros and the generative tools staff already use.
-
Step 2
Write one page per model
What it decides, what data it reads, who owns it, what it must never be used for, and when it was last checked.
-
Step 3
Tie each line to a file
Every statement on the page points to the validation, contract or test result behind it, so a reader can check it.
-
Step 4
Hold it against outcomes
Outputs compared with what really happened, and drift tracked over time, including for the scores a vendor supplies.
-
Step 5
Name the owner and the date
One person who answers for each model, and a review date the committee can see coming on its calendar.

One page, read in the room. The files stay closed unless someone asks.
One Page Per Model, Read in the Meeting
The page sits on top of the file, not in place of it. Validation reports still matter. The modelers who write them should keep writing them for each other.
What changes is the reader. A committee member gets the decision the model touches, the data it reads, the uses it’s barred from, and the last date its outputs were held up against real outcomes, which is the same comparison a model calibration study runs on underwriting cases and the same habit insurance has practiced for decades under the name experience study.
Generative tools belong on the shelf too. While Khurram headed the data function at a specialty finance investor, generative tools reached six functions in phases, each with written rules and role-based training before anyone touched a real file. When a model reads documents such as medical records or claim files, the page also says what it may read, the half of document automation governance tends to skip.
For the lighter, company-wide version, a one-page AI governance standard for mid-market firms sorts every use by who sees the output. A carrier needs that page and this shelf. You need both.
Who Keeps an Insurance Model Inventory Current
-
Owns the rules
Data governance analyst
Keeps the inventory, the field definitions and the review calendar, and chases down every blank spine.
-
Builds the checks
Machine learning engineer
Writes the monitoring that catches drift and keeps the test results each model page points back to.
-
Answers the examiner
Compliance analyst
Maps each model to the bulletin, the state rules and the annual review, then fields examiner requests.
-
Keeps the lineage
Data engineer
Traces every input from the admin system to the model, so the data line on each page stays true.
Most carriers start on contract staffing while the program is being written and move to direct hire once a seat has clearly earned a permanent line in the budget. Either works. Whether a carrier is ready for any of it comes down to who runs the work day to day, the argument behind treating AI readiness as an operations question.
Common Questions
What counts as AI model governance at an insurance carrier?
It means a written program that lists every AI and predictive model the carrier uses, documents what each one does, names an owner, and shows how each is tested. The NAIC calls that program an AIS Program. A good one is short enough that the board committee actually reads the parts written for it.
Does the NAIC AI bulletin apply to our company?
Probably, if you write business in one of the 25 states or the District of Columbia that had adopted it by the NAIC’s August 2026 map. California, Colorado, New York and Texas have their own rules, so a carrier licensed in many states usually answers to both kinds. Counsel should confirm which ones reach your licenses.
Do vendor models count as our models?
Yes. If a vendor score shapes an underwriting, pricing or claims decision, the carrier still answers for it, and New York’s Circular Letter No. 7 says so directly. The practical fix is contract language, meaning an audit right, cooperation on regulatory requests, and a drift report that somebody in house actually reads.
What goes on a one-page model document?
Five lines cover most of it. What the model decides, what data it reads, who owns it, what it must never be used for, and when its outputs were last compared with real outcomes. Each line points to the file that proves it.
Why does the first model inventory take longer than the writing?
Finding the models is the slow part. Spreadsheets, vendor features and generative tools rarely sit on any list, and each one needs a person who can say which decisions it touches. Once the count is done, the pages themselves go quickly. Counting is the work.
Do generative AI tools belong in the inventory?
They do, once they touch a regulated decision or a consumer’s file. A tool that drafts claim summaries shapes what the adjuster sees first, so it gets a page, an owner and a regular sample check like any other model.
Does KORE1 recruit for the seats that keep it running?
Yes, either on contract or direct. KORE1 recruits the data governance analysts, compliance analysts, machine learning engineers and data engineers who maintain a model inventory, and has been placing technical talent since 2005.
Count Your Models Before Anyone Asks
Tell us the models you know about and where you suspect the rest are hiding. We’ll say what a first inventory needs from your team. No deck.
If you’d rather start with Khurram Tehseen himself, he reads his messages on LinkedIn.
