shipping production AI · since 2026 NAICS 541330 / 541511 / 541512 / 541519  ·  CMMC-aware
Refinery Report / AI Governance / post · arrier
AI GovernanceInsuranceNAICModel Risk Management

Implementing the NAIC AI Model Bulletin: Mid-Size Carriers

A phased build sequence for implementing the NAIC AI Model Bulletin at a mid-size carrier without a dedicated AI governance team: what ships in each phase, who owns it, and the evidence a market-conduct exam expects.

D
By the DSE practice team
Operator-led practice · how we research & review
October 1, 2026
11 min · 2,316 words

By the DSE practice team · published October 1, 2026 · reviewed October 1, 2026

Implementing the NAIC AI Model Bulletin at a mid-size carrier means building the same AI Systems Program a national insurer builds, in a sequence that fits a compliance team of two or three people instead of a dedicated AI governance function. Start with an inventory of every AI system touching underwriting, rating, claims, fraud, or marketing, assign one named owner for the program, then build governance, risk tiering, validation, vendor oversight, and documentation in that order over roughly nine to twelve months. The bulletin is principles-based and proportionate to harm, which is exactly the lever a small team needs: it does not require every AIS Program element built to the same depth on day one, only a program that can show its work.

This guide is for the Chief Compliance Officer, Chief Risk Officer, or VP of Compliance at a carrier writing somewhere between a few hundred million and a few billion dollars in premium, where “AI governance” is one more responsibility rather than a standing team. If you have not yet read what the bulletin itself requires, start with our NAIC AI Model Bulletin requirements explainer; this guide picks up from there and focuses on the build sequence, the ownership model, and the mistakes a smaller team makes taking this on alone.

Why implementation looks different at a mid-size carrier

A national carrier with a model risk function and a dedicated AI governance lead can stand up every AIS Program element in parallel. A mid-size carrier rarely has that bench: compliance is usually one to three people who also own privacy, vendor management, and market-conduct exam prep, underwriting and claims leadership own the AI use cases themselves, and legal counsel is often outside counsel engaged by the matter rather than in-house model risk expertise.

None of that reduces what the bulletin expects; it changes how a carrier gets there. Building every AIS Program component simultaneously at a three-person compliance shop produces a program that looks complete on paper and is not actually operating anywhere, the exact failure mode a market-conduct examiner is trained to spot: policies that exist but no one can point to the evidence behind them. Sequencing the build against the proportionality the bulletin already allows is what separates a real program from a binder.

The proportionality lever

The bulletin’s governance, testing, and third-party oversight expectations are explicitly scaled to “the nature and scope of the insurer’s use of AI systems” and the potential for consumer harm. That phrase does the real work for a resource-constrained team: a carrier does not owe a marketing-copy tool the same validation rigor it owes an AI system that denies or modifies a claim, so a program can be built outward from the highest-harm use cases rather than attempted everywhere at once.

Proportionality is a sequencing tool, not an excuse to skip elements. Every AI system still needs to land in the inventory and get a documented risk tier. Only the depth of governance, testing, and oversight that follows scales with harm potential, and that scaling is what lets a small team put its limited hours where an examiner looks first: underwriting, rating, and claims decisions that touch policyholders directly.

A phased build sequence for a mid-size carrier

This sequence is the practical answer to “where do we start.” It assumes a compliance lead working this alongside other duties, with business-unit support rather than a dedicated team, and it is built to produce a defensible program inside a year.

Phase Timeframe What ships Who owns it
0: Inventory and ownership Month 1 to 2 Complete AI system inventory across underwriting, rating, claims, fraud, and marketing, including vendor and embedded AI, with a named owner per system Compliance lead, with underwriting, claims, and IT confirming their own systems
1: Governance and written program Month 2 to 4 Written AIS Program document, a named senior accountable owner, a short board or senior-management briefing Compliance lead drafts; CEO, general counsel, or board committee approves
2: Risk tiering Month 3 to 5 A simple three-tier standard applied to every inventoried system, prioritizing underwriting and claims decisions Compliance lead with business-unit input on actual system use
3: Validation and testing Month 5 to 8 Pre-deployment and ongoing testing for errors, drift, bias, and unfair discrimination on top-tier systems; lower tiers get a lighter annual check Business owner with actuarial or data-science support; compliance reviews results
4: Third-party AI oversight Month 6 to 9 Vendor AI inventory, due-diligence files, contract terms covering audit rights and data use for vendor AI touching underwriting, rating, or claims Vendor management or compliance, extending the existing vendor-review process
5: Documentation and exam-response pack Month 8 to 10 Document register mapping each AIS Program element to its evidence, retention schedule, and a dry-run exam-response exercise Compliance lead, pulling artifacts the earlier phases produced
6: Steady-state cadence Month 10 onward Annual re-tiering, testing on the phase 3 schedule, and a trigger list for mid-cycle reviews (new vendor, new use case, a bias finding) Compliance lead; named system owners flag triggers

The sequence front-loads what an examiner asks for first, the inventory and the governance document, because a program with neither is not a program yet. It defers the heaviest lift, full validation and testing, until the phase 2 tiering shows where that effort belongs, which is how a small team avoids spending six months validating a marketing chatbot while a claims-triage model with real consumer-harm exposure sits untested.

Worked example: a claims-triage vendor tool at a $2 billion carrier

A mid-size property carrier licenses a vendor tool that scores incoming claims to prioritize adjuster review. Phase 0 puts it in the inventory with the claims VP as business owner. Phase 2 tiers it high, since it directly affects how quickly a policyholder’s claim gets attention, unlike the marketing team’s AI copywriting tool, which tiers low. Phase 3 has the claims VP and an actuarial analyst run a quarterly check comparing the tool’s prioritization against actual claim outcomes, watching for a pattern tied to a protected characteristic or a geography proxy. Phase 4 confirms the vendor contract includes audit rights and a data-use clause, and logs the vendor in the AI vendor inventory. By phase 5, the file for this one system already contains everything an examiner would ask for: who owns it, why it is tiered where it is, what the testing found, and what the contract says. That one worked file, repeated across the handful of genuinely high-tier systems a mid-size carrier runs, is most of what the AIS Program needs to show.

Resourcing the program without a dedicated AI governance team

The honest resourcing question is not “who builds an AI governance function” but “which existing role picks up which piece.”

AIS Program function Who typically owns it What that role produces
Program accountability CCO or CRO, with board or senior-management sign-off The written AIS Program, approved and dated
Inventory and risk tiering Compliance lead, with each business unit confirming its systems A current inventory and tier for every AI system
Validation and testing The business owner (underwriting, claims, actuarial), not compliance itself Test results, thresholds, remediation records
Vendor oversight Existing vendor management, extended to AI-specific questions Due-diligence files and AI-use contract terms
Documentation and exam readiness Compliance lead, consolidating other functions’ output A document register and exam-response pack

Compliance owns the program’s structure and documentation, but it should not be the only function doing the testing. A compliance lead rarely has the actuarial or data-science background to validate a rating model for bias, and making that one role own both the paperwork and the technical testing is a common reason mid-size programs stall. Spreading the work to the people who already understand each system, with compliance coordinating, is what makes the sequence achievable without new headcount.

Common mistakes mid-size carriers make

What a market-conduct exam looks for once the program is live

Once the sequence above has run, the test is whether the program produces evidence on request, not whether the policy reads well. An examiner will typically ask for the system inventory, the risk-tiering rationale, validation results for the systems that matter most, the vendor due-diligence files, and proof the program has been reviewed since it was written. The full mapping from each AIS Program component to its evidence is in the NAIC AI Model Bulletin requirements guide.

What this guide is / What it is not

What it is: A practical build sequence for implementing an AI Systems Program under the NAIC AI Model Bulletin at a mid-size carrier without a dedicated AI governance function, including who should own each piece and the order that produces real evidence fastest.

What it is not: It is not legal advice, and it is not a statement of what any one state’s adopted bulletin text requires; confirm your state’s version before relying on this sequence for a specific filing or exam response. DSE prepares insurers for market-conduct examination and audit; we do not certify an AIS Program, and we do not guarantee any examination outcome.

FAQ

How long does it take a mid-size carrier to implement the NAIC AI Model Bulletin?

Most mid-size carriers can build a defensible AI Systems Program in nine to twelve months: inventory and ownership first, then governance, risk tiering, validation on the highest-tier systems, vendor oversight, and documentation last. Attempting every element in parallel with a small compliance team usually takes longer and produces a thinner result.

Do we need to hire a dedicated AI governance team to comply with the bulletin?

No. The bulletin does not specify a staffing model. Most mid-size carriers spread the work across existing roles: compliance owns the program’s structure and documentation, the business owner of each AI system runs its validation and testing, and vendor management extends its process to AI-specific questions. What matters is a named owner for each piece, not a new function to hold all of it.

Which AI systems should a mid-size carrier prioritize first?

Prioritize by potential for consumer harm, the bulletin’s own scaling factor. Systems that influence underwriting, rating, or claims decisions directly affecting a policyholder should be tiered highest and validated first. Internal tools and marketing or content-generation uses with no direct decision impact can follow a lighter, annual-only check.

Does using a vendor AI tool reduce what a mid-size carrier has to document?

No. The bulletin is explicit that an insurer remains responsible for a vendor’s AI use; the obligation does not transfer to the vendor. A mid-size carrier still needs a vendor AI inventory, due-diligence files, and contract terms covering audit rights and data use, and a vendor’s own certification does not substitute for that oversight.

What happens if our state has not adopted the NAIC AI Model Bulletin yet?

Confirm your state’s status on the NAIC’s adoption tracking before assuming the bulletin does not apply; by mid-2026 more than half of US jurisdictions had adopted it in full or substantially similar form. Even where a state has not adopted it, the underlying unfair-trade-practices and unfair-discrimination statutes the bulletin interprets already apply to AI-driven decisions, so building the AIS Program described here is defensible regardless of a single state’s status.

The Bottom Line

Implementing the NAIC AI Model Bulletin at a mid-size carrier is a sequencing problem more than a resourcing problem. The bulletin scales its expectations to a system’s potential for consumer harm, which gives a small compliance team a real lever: inventory everything, tier by harm, validate the highest-tier systems first, bring vendor AI under the same oversight the carrier already runs for other third parties, and document as you go. Spread the work across the roles that already understand each system, with compliance coordinating rather than carrying the program alone, and a defensible AI Systems Program is achievable in under a year without new headcount.

If you want help building that sequence against your own state footprint and use cases, an AI governance for insurers engagement turns this build plan into a program scoped to your carrier. Start with the AI Governance Checklist for the inventory fields and risk-tiering criteria, or see the finserv compliance overview for how this fits alongside your other regulatory obligations.

Key facts

Read next · AI Security & Governance

P
Founder · Principal Engineer
Data & AI engineer · 10+ yrs hands-on

Writes most of the long-form here. Lives in the codebase. Active on GitHub and LinkedIn.

§ Next step

Not sure which of these is you?

Tell us what's broken in a paragraph and a principal reads it directly, or walk the ladder from a low-commitment first engagement up to retained work.

One long-form a week. No marketing.

Subscribe to the Refinery Report. Practitioner deep-dives on AI engineering, security, and the realities of running production systems. Unsubscribe in one click.

~12 issues / quarter