The examiner’s next questionnaire

Exhibit B asks who governs the AI.
Exhibit C asks what it did.

The NAIC’s AI Risk Evaluation Supplement (version 5.0, the continuation of the AI Systems Evaluation Tool piloted by twelve states this year) is the questionnaire state examiners will use to check what the 2023 Model Bulletin asked insurers to do. This page is what it asks for, in plain words, for the insurers, MGAs, mutuals, pools, and TPAs who don’t have a model-risk team, and what a record has to contain so the answer is a query instead of a project.

Last checked September 12, 2026 · sources linked below · not legal advice

Where it stands

Adopted in 24 states and D.C.
Next: the questionnaire.

The Model Bulletin on the Use of Artificial Intelligence Systems by Insurers was adopted by the NAIC on December 4, 2023. Per the NAIC implementation map dated April 1, 2026, 24 states and the District of Columbia have adopted it (most recently Hawaii, December 10, 2025), and California, Colorado, New York, and Texas operate under their own insurance-specific AI guidance.

The examiner’s tool followed. The AI Systems Evaluation Tool was piloted by twelve states from March 2026. After the Big Data and Artificial Intelligence (H) Working Group’s August 31, 2026 meeting it was re-exposed as the AI Risk Evaluation Supplement, version 5.0, with written comments due September 29, 2026 and a public call on October 8. The working group anticipates a further short exposure and then adoption at the Fall National Meeting, November 14–17, 2026. A separate framework for third-party data and model vendors in property and casualty pricing and underwriting was exposed this summer with comments through August 5.

What this means for a program: the questions are written. Your carrier will be asked them on exam, and the Bulletin’s third-party section means it will ask you.

The four exhibits, as exposed in version 5.0

What you will be asked to produce.

Two of these are documents you write. Two are evidence a system has to generate. Most programs have neither, and the gap is not the writing.

Exhibit A · AI systems and models

The inventory.

Every AI system and model in use, above a materiality threshold, including the ones inside vendors’ products: what it is, where it is used, what it influences. Version 5.0 makes the inventory explicit.

What you write: the list and the threshold. What the record supplies: which model actually ran on which operation, from the receipts, so the inventory is checked against reality instead of memory.
Exhibit B · The AI systems program

Who governs it, and how.

The written program the Bulletin asked for: governance, accountability, risk management, controls, explainability, and, newly explicit, oversight of third parties who use AI on your behalf.

What you write: the program, two pages if you are forty people. What the record supplies: evidence the program is followed: who authorized each system, what it was allowed to do, who approved outcomes. Receipts do not write your program; they prove you run it.
Exhibit C · Per-model detail

What each system does, and what it did.

For each material model: purpose, inputs, outputs, testing, monitoring, and the decisions it influenced. This is the exhibit that turns into a reconstruction project when the question is about one decision from March.

What the record supplies: a decision receipt per operation: the actor and their authority, the model and prompt that ran, the inputs verified back to source, the checks that passed, the trace. The format is public
Exhibit D · Data

Which data, for which model.

Version 5.0 keeps and revises the data exhibit: a model-to-dataset mapping, room for line-of-business customization, and the possibility of a data dictionary request.

What you write: the dictionary. What the record supplies: the data each governed operation actually used, named on its receipt, so “which dataset fed this decision” is a query.

The inventory and the program are yours to write. The evidence should never be.

A program you can run at forty people

Five steps. None of them a model-risk team.

01 · Name an owner

One person, accountable.

The Bulletin wants accountability, not a committee. A compliance lead or the COO, named in the program, is enough.

02 · List the AI you use

Including your vendors’.

The rater vendor’s scoring, the claims platform’s triage, the intake tool’s extraction, your own agents. What it decides or influences, and who oversees it. This is Exhibit A.

03 · Write the two-page program

Governance, controls, third parties.

What you use AI for, what you won’t, who approves a new use, how outcomes are checked, how vendors are overseen. This is Exhibit B.

04 · Make the record automatic

Exhibits C and D, by construction.

If the operation writes its own receipt (actor, authority, model, inputs, checks, approver) then per-model detail and data lineage are queries. If it doesn’t, they are projects, every exam. How Haltere does this for insurers

05 · Rehearse the exam

Once a year, with the questionnaire.

Pull the four exhibits as if the letter arrived. What took a query is fine. What took a week is your next build.

For carriers

Ask your programs now.

Your third-party oversight answer in Exhibit B is only as good as what your MGAs and TPAs can produce. Send them this page.

Calibration

What a receipt does,
and what it doesn’t.

A Haltere receipt records a governed change to software and a governed decision by software: who asked, what ran, what it saw, what checks passed, who approved, what changed. It does not write your AI systems program, set your materiality threshold, or decide which uses of AI are acceptable. It makes the evidence for all of those a query. We say this out loud because the exhibit that fails is rarely the one you wrote; it is the one you had to reconstruct.

Questions

What a program will want to know.

Does the Supplement apply to an MGA or a TPA?

It is written as an examiner’s tool for insurers. It reaches you through the carrier: the Model Bulletin asks insurers to oversee third parties that act for them, and version 5.0 of the Supplement adds explicit third-party oversight questions. Expect the carrier’s compliance team to ask you the same questions the examiner asks them.

Is it adopted yet?

Not as of September 12, 2026. Version 5.0 is exposed for comment through September 29, 2026, with a public call on October 8. The working group has said adoption is anticipated at the NAIC Fall National Meeting, November 14–17, 2026, after at least one more short exposure. Check the working group page before relying on any of this.

What is the difference between the Model Bulletin and the Supplement?

The Bulletin (adopted December 4, 2023) tells insurers what regulators expect: a written AI systems program, governance, risk management, third-party oversight, and documentation available on request. The Supplement is the questionnaire an examiner uses to check it, exhibit by exhibit. The Bulletin sets the expectation; the Supplement is what you have to produce.

What do we actually have to produce on request?

Read literally, four things: an inventory of the AI systems and models you use (Exhibit A), your written AI systems program and the governance around it (Exhibit B), per-model detail on what each system does, its inputs, outputs, testing and monitoring (Exhibit C), and the data behind the models (Exhibit D). The inventory and the program are yours to write. The evidence that you follow them is what a record has to produce.

We only use vendors’ AI. Do we still need an inventory?

Yes. The Bulletin’s third-party section covers AI systems and data you obtain from vendors, and Exhibit A asks for systems and models regardless of who built them. A list of the vendor AI you rely on, what it decides, and how you oversee it is the minimum.

Rehearse the exam with us.

Bring the questionnaire and the workflow you would hate to reconstruct. A 15-minute call is enough to know whether a governed first build turns Exhibits C and D into queries for you.

No newsletter. No drip sequence. Every request gets a real reply within one business day, from someone who can answer it.