Exhibit B asks who governs the AI.
Exhibit C asks what it did.
The NAIC’s AI Risk Evaluation Supplement (version 5.0, the continuation of the AI Systems Evaluation Tool piloted by twelve states this year) is the questionnaire state examiners will use to check what the 2023 Model Bulletin asked insurers to do. This page is what it asks for, in plain words, for the insurers, MGAs, mutuals, pools, and TPAs who don’t have a model-risk team, and what a record has to contain so the answer is a query instead of a project.
Last checked September 12, 2026 · sources linked below · not legal advice
Adopted in 24 states and D.C.
Next: the questionnaire.
The Model Bulletin on the Use of Artificial Intelligence Systems by Insurers was adopted by the NAIC on December 4, 2023. Per the NAIC implementation map dated April 1, 2026, 24 states and the District of Columbia have adopted it (most recently Hawaii, December 10, 2025), and California, Colorado, New York, and Texas operate under their own insurance-specific AI guidance.
The examiner’s tool followed. The AI Systems Evaluation Tool was piloted by twelve states from March 2026. After the Big Data and Artificial Intelligence (H) Working Group’s August 31, 2026 meeting it was re-exposed as the AI Risk Evaluation Supplement, version 5.0, with written comments due September 29, 2026 and a public call on October 8. The working group anticipates a further short exposure and then adoption at the Fall National Meeting, November 14–17, 2026. A separate framework for third-party data and model vendors in property and casualty pricing and underwriting was exposed this summer with comments through August 5.
What this means for a program: the questions are written. Your carrier will be asked them on exam, and the Bulletin’s third-party section means it will ask you.
What you will be asked to produce.
Two of these are documents you write. Two are evidence a system has to generate. Most programs have neither, and the gap is not the writing.
The inventory.
Every AI system and model in use, above a materiality threshold, including the ones inside vendors’ products: what it is, where it is used, what it influences. Version 5.0 makes the inventory explicit.
Who governs it, and how.
The written program the Bulletin asked for: governance, accountability, risk management, controls, explainability, and, newly explicit, oversight of third parties who use AI on your behalf.
What each system does, and what it did.
For each material model: purpose, inputs, outputs, testing, monitoring, and the decisions it influenced. This is the exhibit that turns into a reconstruction project when the question is about one decision from March.
Which data, for which model.
Version 5.0 keeps and revises the data exhibit: a model-to-dataset mapping, room for line-of-business customization, and the possibility of a data dictionary request.
The inventory and the program are yours to write. The evidence should never be.
Five steps. None of them a model-risk team.
One person, accountable.
The Bulletin wants accountability, not a committee. A compliance lead or the COO, named in the program, is enough.
Including your vendors’.
The rater vendor’s scoring, the claims platform’s triage, the intake tool’s extraction, your own agents. What it decides or influences, and who oversees it. This is Exhibit A.
Governance, controls, third parties.
What you use AI for, what you won’t, who approves a new use, how outcomes are checked, how vendors are overseen. This is Exhibit B.
Exhibits C and D, by construction.
If the operation writes its own receipt (actor, authority, model, inputs, checks, approver) then per-model detail and data lineage are queries. If it doesn’t, they are projects, every exam. How Haltere does this for insurers
Once a year, with the questionnaire.
Pull the four exhibits as if the letter arrived. What took a query is fine. What took a week is your next build.
Ask your programs now.
Your third-party oversight answer in Exhibit B is only as good as what your MGAs and TPAs can produce. Send them this page.
What a receipt does,
and what it doesn’t.
A Haltere receipt records a governed change to software and a governed decision by software: who asked, what ran, what it saw, what checks passed, who approved, what changed. It does not write your AI systems program, set your materiality threshold, or decide which uses of AI are acceptable. It makes the evidence for all of those a query. We say this out loud because the exhibit that fails is rarely the one you wrote; it is the one you had to reconstruct.
What a program will want to know.
Does the Supplement apply to an MGA or a TPA?
It is written as an examiner’s tool for insurers. It reaches you through the carrier: the Model Bulletin asks insurers to oversee third parties that act for them, and version 5.0 of the Supplement adds explicit third-party oversight questions. Expect the carrier’s compliance team to ask you the same questions the examiner asks them.
Is it adopted yet?
Not as of September 12, 2026. Version 5.0 is exposed for comment through September 29, 2026, with a public call on October 8. The working group has said adoption is anticipated at the NAIC Fall National Meeting, November 14–17, 2026, after at least one more short exposure. Check the working group page before relying on any of this.
What is the difference between the Model Bulletin and the Supplement?
The Bulletin (adopted December 4, 2023) tells insurers what regulators expect: a written AI systems program, governance, risk management, third-party oversight, and documentation available on request. The Supplement is the questionnaire an examiner uses to check it, exhibit by exhibit. The Bulletin sets the expectation; the Supplement is what you have to produce.
What do we actually have to produce on request?
Read literally, four things: an inventory of the AI systems and models you use (Exhibit A), your written AI systems program and the governance around it (Exhibit B), per-model detail on what each system does, its inputs, outputs, testing and monitoring (Exhibit C), and the data behind the models (Exhibit D). The inventory and the program are yours to write. The evidence that you follow them is what a record has to produce.
We only use vendors’ AI. Do we still need an inventory?
Yes. The Bulletin’s third-party section covers AI systems and data you obtain from vendors, and Exhibit A asks for systems and models regardless of who built them. A list of the vendor AI you rely on, what it decides, and how you oversee it is the minimum.
Rehearse the exam with us.
Bring the questionnaire and the workflow you would hate to reconstruct. A 15-minute call is enough to know whether a governed first build turns Exhibits C and D into queries for you.
No newsletter. No drip sequence. Every request gets a real reply within one business day, from someone who can answer it.
