Implementing the NAIC AI Model Bulletin at a mid-size carrier means building the same AI Systems Program a national insurer builds, in a sequence that fits a compliance team of two or three people instead of a dedicated AI governance function. Start with an inventory of every AI system touching underwriting, rating, claims, fraud, or marketing, assign one named owner for the program, then build governance, risk tiering, validation, vendor oversight, and documentation in that order over roughly nine to twelve months. The bulletin is principles-based and proportionate to harm, which is exactly the lever a small team needs: it does not require every AIS Program element built to the same depth on day one, only a program that can show its work.
This guide is for the Chief Compliance Officer, Chief Risk Officer, or VP of Compliance at a carrier writing somewhere between a few hundred million and a few billion dollars in premium, where “AI governance” is one more responsibility rather than a standing team. If you have not yet read what the bulletin itself requires, start with our NAIC AI Model Bulletin requirements explainer; this guide picks up from there and focuses on the build sequence, the ownership model, and the mistakes a smaller team makes taking this on alone.
Want to put this into practice? Use our AI system inventory generator.
Why implementation looks different at a mid-size carrier
A national carrier with a model risk function and a dedicated AI governance lead can stand up every AIS Program element in parallel. A mid-size carrier rarely has that bench: compliance is usually one to three people who also own privacy, vendor management, and market-conduct exam prep, underwriting and claims leadership own the AI use cases themselves, and legal counsel is often outside counsel engaged by the matter rather than in-house model risk expertise.
None of that reduces what the bulletin expects; it changes how a carrier gets there. Building every AIS Program component simultaneously at a three-person compliance shop produces a program that looks complete on paper and is not actually operating anywhere, the exact failure mode a market-conduct examiner is trained to spot: policies that exist but no one can point to the evidence behind them. Sequencing the build against the proportionality the bulletin already allows is what separates a real program from a binder.
The proportionality lever
The bulletin’s governance, testing, and third-party oversight expectations are explicitly scaled to “the nature and scope of the insurer’s use of AI systems” and the potential for consumer harm. That phrase does the real work for a resource-constrained team: a carrier does not owe a marketing-copy tool the same validation rigor it owes an AI system that denies or modifies a claim, so a program can be built outward from the highest-harm use cases rather than attempted everywhere at once.
Proportionality is a sequencing tool, not an excuse to skip elements. Every AI system still needs to land in the inventory and get a documented risk tier. Only the depth of governance, testing, and oversight that follows scales with harm potential, and that scaling is what lets a small team put its limited hours where an examiner looks first: underwriting, rating, and claims decisions that touch policyholders directly.
A phased build sequence for a mid-size carrier
This sequence is the practical answer to “where do we start.” It assumes a compliance lead working this alongside other duties, with business-unit support rather than a dedicated team, and it is built to produce a defensible program inside a year.
| Phase | Timeframe | What ships | Who owns it |
|---|---|---|---|
| 0: Inventory and ownership | Month 1 to 2 | Complete AI system inventory across underwriting, rating, claims, fraud, and marketing, including vendor and embedded AI, with a named owner per system | Compliance lead, with underwriting, claims, and IT confirming their own systems |
| 1: Governance and written program | Month 2 to 4 | Written AIS Program document, a named senior accountable owner, a short board or senior-management briefing | Compliance lead drafts; CEO, general counsel, or board committee approves |
| 2: Risk tiering | Month 3 to 5 | A simple three-tier standard applied to every inventoried system, prioritizing underwriting and claims decisions | Compliance lead with business-unit input on actual system use |
| 3: Validation and testing | Month 5 to 8 | Pre-deployment and ongoing testing for errors, drift, bias, and unfair discrimination on top-tier systems; lower tiers get a lighter annual check | Business owner with actuarial or data-science support; compliance reviews results |
| 4: Third-party AI oversight | Month 6 to 9 | Vendor AI inventory, due-diligence files, contract terms covering audit rights and data use for vendor AI touching underwriting, rating, or claims | Vendor management or compliance, extending the existing vendor-review process |
| 5: Documentation and exam-response pack | Month 8 to 10 | Document register mapping each AIS Program element to its evidence, retention schedule, and a dry-run exam-response exercise | Compliance lead, pulling artifacts the earlier phases produced |
| 6: Steady-state cadence | Month 10 onward | Annual re-tiering, testing on the phase 3 schedule, and a trigger list for mid-cycle reviews (new vendor, new use case, a bias finding) | Compliance lead; named system owners flag triggers |
The sequence front-loads what an examiner asks for first, the inventory and the governance document, because a program with neither is not a program yet. It defers the heaviest lift, full validation and testing, until the phase 2 tiering shows where that effort belongs, which is how a small team avoids spending six months validating a marketing chatbot while a claims-triage model with real consumer-harm exposure sits untested.
Worked example: a claims-triage vendor tool at a $2 billion carrier
A mid-size property carrier licenses a vendor tool that scores incoming claims to prioritize adjuster review. Phase 0 puts it in the inventory with the claims VP as business owner. Phase 2 tiers it high, since it directly affects how quickly a policyholder’s claim gets attention, unlike the marketing team’s AI copywriting tool, which tiers low. Phase 3 has the claims VP and an actuarial analyst run a quarterly check comparing the tool’s prioritization against actual claim outcomes, watching for a pattern tied to a protected characteristic or a geography proxy. Phase 4 confirms the vendor contract includes audit rights and a data-use clause, and logs the vendor in the AI vendor inventory. By phase 5, the file for this one system already contains everything an examiner would ask for: who owns it, why it is tiered where it is, what the testing found, and what the contract says. That one worked file, repeated across the handful of genuinely high-tier systems a mid-size carrier runs, is most of what the AIS Program needs to show.
Resourcing the program without a dedicated AI governance team
The honest resourcing question is not “who builds an AI governance function” but “which existing role picks up which piece.”
| AIS Program function | Who typically owns it | What that role produces |
|---|---|---|
| Program accountability | CCO or CRO, with board or senior-management sign-off | The written AIS Program, approved and dated |
| Inventory and risk tiering | Compliance lead, with each business unit confirming its systems | A current inventory and tier for every AI system |
| Validation and testing | The business owner (underwriting, claims, actuarial), not compliance itself | Test results, thresholds, remediation records |
| Vendor oversight | Existing vendor management, extended to AI-specific questions | Due-diligence files and AI-use contract terms |
| Documentation and exam readiness | Compliance lead, consolidating other functions’ output | A document register and exam-response pack |
Compliance owns the program’s structure and documentation, but it should not be the only function doing the testing. A compliance lead rarely has the actuarial or data-science background to validate a rating model for bias, and making that one role own both the paperwork and the technical testing is a common reason mid-size programs stall. Spreading the work to the people who already understand each system, with compliance coordinating, is what makes the sequence achievable without new headcount.
Common mistakes mid-size carriers make
- Building governance first and the inventory never. A written AIS Program with no current system inventory behind it is a document, not a program, and it is the first gap an examiner finds.
- Treating every system as high-tier, or every system as low-tier. Both extremes defeat the proportionality the bulletin allows; over-tiering burns capacity on low-harm systems, under-tiering leaves real exposure untested.
- Letting vendor AI ride on the vendor’s own certification. A vendor’s SOC 2 report or internal bias testing describes the vendor’s product, not how your carrier configured and relies on it. The insurer stays responsible either way.
- Skipping the dry run. A program never walked through as if an examiner asked for it tends to reveal gaps only during the actual exam, when there is no time left to close them.
- Assuming one state’s adoption text covers every state you write in. The bulletin binds only where a state has adopted it, and adopted text can vary. A multistate carrier should build one program that meets the expectation everywhere it operates.
What a market-conduct exam looks for once the program is live
Once the sequence above has run, the test is whether the program produces evidence on request, not whether the policy reads well. An examiner will typically ask for the system inventory, the risk-tiering rationale, validation results for the systems that matter most, the vendor due-diligence files, and proof the program has been reviewed since it was written. The full mapping from each AIS Program component to its evidence is in the NAIC AI Model Bulletin requirements guide.
What this guide is / What it is not
What it is: A practical build sequence for implementing an AI Systems Program under the NAIC AI Model Bulletin at a mid-size carrier without a dedicated AI governance function, including who should own each piece and the order that produces real evidence fastest.
What it is not: It is not legal advice, and it is not a statement of what any one state’s adopted bulletin text requires; confirm your state’s version before relying on this sequence for a specific filing or exam response. DSE prepares insurers for market-conduct examination and audit; we do not certify an AIS Program, and we do not guarantee any examination outcome.
FAQ
How long does it take a mid-size carrier to implement the NAIC AI Model Bulletin?
Most mid-size carriers can build a defensible AI Systems Program in nine to twelve months: inventory and ownership first, then governance, risk tiering, validation on the highest-tier systems, vendor oversight, and documentation last. Attempting every element in parallel with a small compliance team usually takes longer and produces a thinner result.
Do we need to hire a dedicated AI governance team to comply with the bulletin?
No. The bulletin does not specify a staffing model. Most mid-size carriers spread the work across existing roles: compliance owns the program’s structure and documentation, the business owner of each AI system runs its validation and testing, and vendor management extends its process to AI-specific questions. What matters is a named owner for each piece, not a new function to hold all of it.
Which AI systems should a mid-size carrier prioritize first?
Prioritize by potential for consumer harm, the bulletin’s own scaling factor. Systems that influence underwriting, rating, or claims decisions directly affecting a policyholder should be tiered highest and validated first. Internal tools and marketing or content-generation uses with no direct decision impact can follow a lighter, annual-only check.
Does using a vendor AI tool reduce what a mid-size carrier has to document?
No. The bulletin is explicit that an insurer remains responsible for a vendor’s AI use; the obligation does not transfer to the vendor. A mid-size carrier still needs a vendor AI inventory, due-diligence files, and contract terms covering audit rights and data use, and a vendor’s own certification does not substitute for that oversight.
What happens if our state has not adopted the NAIC AI Model Bulletin yet?
Confirm your state’s status on the NAIC’s adoption tracking before assuming the bulletin does not apply; by mid-2026 more than half of US jurisdictions had adopted it in full or substantially similar form. Even where a state has not adopted it, the underlying unfair-trade-practices and unfair-discrimination statutes the bulletin interprets already apply to AI-driven decisions, so building the AIS Program described here is defensible regardless of a single state’s status.
The Bottom Line
Implementing the NAIC AI Model Bulletin at a mid-size carrier is a sequencing problem more than a resourcing problem. The bulletin scales its expectations to a system’s potential for consumer harm, which gives a small compliance team a real lever: inventory everything, tier by harm, validate the highest-tier systems first, bring vendor AI under the same oversight the carrier already runs for other third parties, and document as you go. Spread the work across the roles that already understand each system, with compliance coordinating rather than carrying the program alone, and a defensible AI Systems Program is achievable in under a year without new headcount.
If you want help building that sequence against your own state footprint and use cases, an AI governance for insurers engagement turns this build plan into a program scoped to your carrier. Start with the AI Governance Checklist for the inventory fields and risk-tiering criteria, or see the finserv compliance overview for how this fits alongside your other regulatory obligations.
Key facts
- The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted December 4, 2023, is principles-based and does not set a program size or budget, so a mid-size carrier builds the same AI Systems Program elements as a national carrier, scaled to its own use cases (DSE, 2026).
- The bulletin directs that governance, testing, and third-party oversight be proportionate to a system's potential for consumer harm, which is the lever a mid-size carrier with a small compliance team uses to sequence its AI Systems Program build instead of building every element at once (DSE, 2026).