NC DOI Bulletin 24-B-19
The Use of Artificial Intelligence Systems in Insurance
24-B-19
TO:
All Insurers Licensed to Do Business In North Carolina (“Insurers”)
FROM: Mike Causey, Commissioner of Insurance
DATE: December 18, 2024
RE:
The Use of ArƟficial Intelligence Systems in Insurance
This bulleƟn is issued by the North Carolina Department of Insurance (Department) to remind
all Insurers that hold cerƟficates of authority to do business in the state that decisions or acƟons
impacƟng consumers that are made or supported by advanced analyƟcal and computaƟonal
technologies, including ArƟficial Intelligence (AI) Systems (as defined below), must comply with
all applicable insurance laws and regulaƟons, including those that address unfair trade pracƟces
and unfair discriminaƟon. This bulleƟn sets forth the Department’s expectaƟons as to how
Insurers will govern the development/acquisiƟon and use of certain AI technologies, including
the AI Systems described herein. This bulleƟn also advises Insurers of the type of informaƟon
and documentaƟon that the Department may request during an invesƟgaƟon or examinaƟon of
any Insurer regarding its use of such technologies and AI Systems.
SECTION 1: INTRODUCTION, BACKGROUND, AND LEGISLATIVE AUTHORITY
Background
AI is transforming the insurance industry. AI techniques are deployed across all stages of the
insurance life cycle, including product development, markeƟng, sales and distribuƟon,
underwriƟng and pricing, policy servicing, claim management, and fraud detecƟon.
AI may facilitate the development of innovaƟve products, improve consumer interface and
service, simplify and automate processes, and promote efficiency and accuracy. However, AI,
including AI Systems, can present unique risks to consumers, including the potenƟal for
inaccuracy, unfair discriminaƟon, data vulnerability, and lack of transparency and explainability.
Insurers should take acƟons to minimize these risks.
development of innovaƟve products, improve consumer interface and
service, simplify and automate processes, and promote efficiency and accuracy. However, AI,
including AI Systems, can present unique risks to consumers, including the potenƟal for
inaccuracy, unfair discriminaƟon, data vulnerability, and lack of transparency and explainability.
Insurers should take acƟons to minimize these risks.
Page 2 of 11
The Department encourages the development and use of innovaƟon and AI Systems that
contribute to safe and stable insurance markets. However, the Department expects that
decisions made, and acƟons taken by Insurers using AI Systems will comply with all applicable
federal and state laws and regulaƟons.
The Department recognizes the Principles of ArƟficial Intelligence that the NAIC adopted in
2020 as an appropriate source of guidance for Insurers as they develop and use AI systems.
Those principles emphasize the importance of the fairness and ethical use of AI; accountability;
compliance with state laws and regulaƟons; transparency; and a safe, secure, fair, and robust
system. These fundamental principles should guide Insurers in their development and use of AI
Systems and underlie the expectaƟons set forth in this bulleƟn.
LegislaƟve Authority
Insurers’ development and use of AI Systems must comply with all applicable insurance laws
and administraƟve rules. The regulatory expectaƟons and oversight consideraƟons set forth in
SecƟon 3 and SecƟon 4 of this bulleƟn primarily rely on the following laws, which are not an
exhausƟve lisƟng of all statutes and administraƟve rules that may be applicable to the use of Al
Systems in Insurance.
Unfair Trade PracƟces: Chapter 58, ArƟcle 63 of the North Carolina General Statutes defines
pracƟces that consƟtute unfair methods of compeƟƟon or unfair or decepƟve acts and pracƟces
in the business of insurance and prohibits the trade pracƟces so defined or determined
not an
exhausƟve lisƟng of all statutes and administraƟve rules that may be applicable to the use of Al
Systems in Insurance.
Unfair Trade PracƟces: Chapter 58, ArƟcle 63 of the North Carolina General Statutes defines
pracƟces that consƟtute unfair methods of compeƟƟon or unfair or decepƟve acts and pracƟces
in the business of insurance and prohibits the trade pracƟces so defined or determined. AcƟons
taken by Insurers in the state must not violate the provisions of ArƟcle 63, regardless of the
methods the Insurer used to determine or support its acƟons. As discussed below, Insurers are
expected to adopt pracƟces, including governance frameworks and risk management protocols,
that are designed to ensure that the use of AI Systems does not result in unfair trade pracƟces,
or unfair claims seƩlement pracƟces, as defined in N.C. Gen. Stat. § 58-63-15.
Corporate Governance Annual Disclosure Requirements: Chapter 58, ArƟcle 10, Part 11 of the
North Carolina General Statutes requires Insurers to report on governance pracƟces and to
provide a summary of the Insurer’s corporate governance structure, policies, and pracƟces and
sets forth the content, form, and filing requirements for Corporate Governance Annual
Disclosure (CGAD) informaƟon. The requirements of Part 11 of ArƟcle 10 apply to elements of
the Insurer’s corporate governance framework that address the Insurer’s use of AI Systems to
support acƟons and decisions that impact consumers.
Insurance Rate Requirements: Insurers must comply with North Carolina laws and
administraƟve rules regarding rates, raƟng plans, raƟng rules, pracƟces, and standards, referred
to in this bulleƟn as the “RaƟng Laws.” For example, some RaƟng Laws mandate that insurance
rates are not excessive, inadequate, or unfairly discriminatory (e.g., NC.G.S. §§ 58-40-20, 58-51-
95, 58-51-131, 58-65-40, and 58-47-110)
Rate Requirements: Insurers must comply with North Carolina laws and
administraƟve rules regarding rates, raƟng plans, raƟng rules, pracƟces, and standards, referred
to in this bulleƟn as the “RaƟng Laws.” For example, some RaƟng Laws mandate that insurance
rates are not excessive, inadequate, or unfairly discriminatory (e.g., NC.G.S. §§ 58-40-20, 58-51-
95, 58-51-131, 58-65-40, and 58-47-110). The requirements of the RaƟng Laws apply regardless
of the methodology that the Insurer used to develop rates, raƟng rules, and raƟng plans subject
to those provisions. That means that an Insurer is responsible for assuring that rates, raƟng
rules, and raƟng plans that are developed using AI techniques and PredicƟve Models that rely
Page 3 of 11
on data and Machine Learning do not result in excessive, inadequate, or unfairly discriminatory
insurance rates with respect to all forms of casualty insurance—including fidelity, surety, and
guaranty bond—and to all forms of property insurance—including fire, marine, and inland
marine insurance, and any combinaƟon of any of the foregoing.
Market Conduct ExaminaƟons and InvesƟgaƟons: An Insurer’s conduct in the state, including its
use of AI Systems to make or support acƟons and decisions that impact consumers, is subject to
invesƟgaƟon, including market conduct acƟons. SecƟon 4 of this bulleƟn provides guidance on
the kinds of informaƟon and documents that the Department may request in the context of an
AI-focused invesƟgaƟon, including a market conduct acƟon.
SECTION 2: DEFINITIONS
For the purposes of this bulleƟn the following terms are defined:
“Adverse Consumer Outcome” refers to a decision by an Insurer that is subject to insurance
regulatory standards enforced by the Department that adversely impacts the consumer in a
manner that violates those standards.
“Algorithm” means a clearly specified mathemaƟcal process for computaƟon; a set of rules
that, if followed, will give a prescribed result
bulleƟn the following terms are defined:
“Adverse Consumer Outcome” refers to a decision by an Insurer that is subject to insurance
regulatory standards enforced by the Department that adversely impacts the consumer in a
manner that violates those standards.
“Algorithm” means a clearly specified mathemaƟcal process for computaƟon; a set of rules
that, if followed, will give a prescribed result.
“AI System” is a machine-based system that can, for a given set of objecƟves, generate outputs
such as predicƟons, recommendaƟons, content (such as text, images, videos, or sounds), or
other output influencing decisions made in real or virtual environments. AI Systems are
designed to operate with varying levels of autonomy.
“ArƟficial Intelligence (AI)” refers to a branch of computer science that uses data processing
systems that perform funcƟons normally associated with human intelligence, such as reasoning,
learning, and self-improvement, or the capability of a device to perform funcƟons that are
normally associated with human intelligence such as reasoning, learning, and self-improvement.
This definiƟon considers machine learning to be a subset of arƟficial intelligence.
“Degree of PotenƟal Harm to Consumers” refers to the severity of adverse economic impact
that a consumer might experience as a result of an Adverse Consumer Outcome.
“GeneraƟve ArƟficial Intelligence (GeneraƟve AI)” refers to a class of AI Systems that generate
content in the form of data, text, images, sounds, or video, that is similar to, but not a direct
copy of, pre-exisƟng data or content.
“Machine Learning (ML)” Refers to a field within arƟficial intelligence that focuses on the ability
of computers to learn from provided data without being explicitly programmed.
“Model DriŌ” refers to the decay of a model’s performance over Ɵme arising from underlying
changes such as the definiƟons, distribuƟons, and/or staƟsƟcal properƟes between the data
used to train the model and the data on which it is deployed.
” Refers to a field within arƟficial intelligence that focuses on the ability
of computers to learn from provided data without being explicitly programmed.
“Model DriŌ” refers to the decay of a model’s performance over Ɵme arising from underlying
changes such as the definiƟons, distribuƟons, and/or staƟsƟcal properƟes between the data
used to train the model and the data on which it is deployed.
Page 4 of 11
“PredicƟve Model” refers to the mining of historic data using algorithms and/or machine
learning to idenƟfy paƩerns and predict outcomes that can be used to make or support the
making of decisions.
“Third Party” for purposes of this bulleƟn means an organizaƟon other than the Insurer that
provides services, data, or other resources related to AI.
SECTION 3: REGULATORY GUIDANCE AND EXPECTATIONS
Decisions subject to regulatory oversight that are made by Insurers using AI Systems must
comply with the legal and regulatory standards that apply to those decisions, including unfair
trade pracƟce laws. These standards require, at a minimum, that decisions made by Insurers are
not inaccurate, arbitrary, capricious, or unfairly discriminatory. Compliance with these standards
is required regardless of the tools and methods Insurers use to make such decisions. However,
because, in the absence of proper controls, AI has the potenƟal to increase the risk of
inaccurate, arbitrary, capricious, or unfairly discriminatory outcomes for consumers, it is
important that Insurers adopt and implement controls specifically related to their use of AI that
are designed to miƟgate the risk of Adverse Consumer Outcomes.
Consistent therewith, all Insurers authorized to do business in this state are strongly encouraged
to develop, implement, and maintain a wriƩen program (an “AIS Program”) for the responsible
use of AI Systems that make, or support decisions related to regulated insurance pracƟces
controls specifically related to their use of AI that
are designed to miƟgate the risk of Adverse Consumer Outcomes.
Consistent therewith, all Insurers authorized to do business in this state are strongly encouraged
to develop, implement, and maintain a wriƩen program (an “AIS Program”) for the responsible
use of AI Systems that make, or support decisions related to regulated insurance pracƟces. The
AIS Program should be designed to miƟgate the risk of Adverse Consumer Outcomes, including,
at a minimum, the statutory provisions set forth in SecƟon 1 of this bulleƟn.
The Department recognizes that robust governance, risk management controls, and internal
audit funcƟons play a core role in miƟgaƟng the risk that decisions driven by AI Systems will
violate unfair trade pracƟce laws and other applicable exisƟng legal standards. The Department
also encourages the development and use of verificaƟon and tesƟng methods to idenƟfy errors
and bias in PredicƟve Models and AI Systems, as well as the potenƟal for unfair discriminaƟon in
the decisions and outcomes resulƟng from the use of PredicƟve Models and AI Systems.
The Department further advises that the controls and processes that an Insurer adopts and
implements as part of its AIS Program should be reflecƟve of, and commensurate with, the
Insurer’s own assessment of the degree and nature of risk posed to consumers by the AI
Systems that it uses, considering: (i) the nature of the decisions being made, informed, or
supported using the AI System; (ii) the type and Degree of PotenƟal Harm to Consumers
resulƟng from the use of AI Systems; (iii) the extent to which humans are involved in the final
decision-making process; (iv)the transparency and explainability of outcomes to the impacted
consumer; and (v) the extent and scope of the insurer’s use or reliance on data, PredicƟve
Models, and AI Systems from third parƟes
using the AI System; (ii) the type and Degree of PotenƟal Harm to Consumers
resulƟng from the use of AI Systems; (iii) the extent to which humans are involved in the final
decision-making process; (iv)the transparency and explainability of outcomes to the impacted
consumer; and (v) the extent and scope of the insurer’s use or reliance on data, PredicƟve
Models, and AI Systems from third parƟes. Similarly, controls and processes should be
commensurate with both the risk of Adverse Consumer Outcomes and the Degree of PotenƟal
Harm to Consumers.
Page 5 of 11
As discussed in SecƟon 4, the decisions made as a result of an Insurer’s use of AI Systems are
subject to the Department’s examinaƟon to determine that the reliance on AI Systems are
compliant with all applicable exisƟng legal standards governing the conduct of the Insurer.
AIS Program Guidelines
1.0
General Guidelines
1.1
The AIS Program should be designed to miƟgate the risk that the Insurer’s use of
an AI System will result in Adverse Consumer Outcomes.
1.2
The AIS Program should address governance, risk management controls, and
internal audit funcƟons.
1.3
The AIS Program should vest responsibility for the development, implementaƟon,
monitoring, and oversight of the AIS Program and for seƫng the Insurer’s strategy for AI
Systems with senior management accountable to the board or an appropriate commiƩee of the
board.
1.4
The AIS Program should be tailored to and proporƟonate with the Insurer’s use
and reliance on AI and AI Systems. Controls and procedures should be focused on the miƟgaƟon
of Adverse Consumer Outcomes and the scope of the controls and procedures applicable to a
given AI System use case should reflect and align with the Degree of PotenƟal Harm to
Consumers with respect to that use case.
1.5
The AIS Program may be independent of or part of the Insurer’s exisƟng
Enterprise Risk Management (ERM) program
ems. Controls and procedures should be focused on the miƟgaƟon
of Adverse Consumer Outcomes and the scope of the controls and procedures applicable to a
given AI System use case should reflect and align with the Degree of PotenƟal Harm to
Consumers with respect to that use case.
1.5
The AIS Program may be independent of or part of the Insurer’s exisƟng
Enterprise Risk Management (ERM) program. The AIS Program may adopt, incorporate, or rely
upon, in whole or in part, a framework or standards developed by an official third-party
standard organizaƟon, such as the NaƟonal InsƟtute of Standards and Technology (NIST)
ArƟficial Intelligence Risk Management Framework, Version 1.0.
1.6
The AIS Program should address the use of AI Systems across the insurance life
cycle, including areas such as product development and design, markeƟng, use, underwriƟng,
raƟng and pricing, case management, claim administraƟon and payment, and fraud detecƟon.
1.7
The AIS Program should address all phases of an AI System’s life cycle, including
design, development, validaƟon, implementaƟon (both systems and business), use, on-going
monitoring, updaƟng and reƟrement.
1.8
The AIS Program should address the AI Systems used with respect to regulated
insurance pracƟces whether developed by the Insurer or a third-party vendor.
1.9
The AIS Program should include processes and procedures providing noƟce to
impacted consumers that AI Systems are in use and provide access to appropriate levels of
informaƟon based on the phase of the insurance life cycle in which the AI Systems are being
used.
ess the AI Systems used with respect to regulated
insurance pracƟces whether developed by the Insurer or a third-party vendor.
1.9
The AIS Program should include processes and procedures providing noƟce to
impacted consumers that AI Systems are in use and provide access to appropriate levels of
informaƟon based on the phase of the insurance life cycle in which the AI Systems are being
used.
Page 6 of 11
2.0
Governance
The AIS Program should include a governance framework for the oversight of AI Systems used
by the Insurer. Governance should prioriƟze transparency, fairness, and accountability in the
design and implementaƟon of the AI Systems, recognizing that proprietary and trade secret
informaƟon must be protected. An Insurer may consider adopƟng new internal governance
structures or rely on the Insurer’s exisƟng governance structures; however, in developing its
governance framework, the Insurer should consider addressing the following items:
2.1
The policies, processes, and procedures, including risk management and internal
controls, to be followed at each stage of an AI System life cycle, from proposed development to
reƟrement.
2.2
The requirements adopted by the Insurer to document compliance with the AIS
Program policies, processes, procedures, and standards. DocumentaƟon requirements should
be developed with SecƟon 4 in mind.
2.3
The Insurer’s internal AI System governance accountability structure, such as:
a)
The formaƟon of centralized, federated, or otherwise consƟtuted
commiƩees comprised of representaƟves from appropriate disciplines
and units within the Insurer, such as business units, product specialists,
actuarial, data science and analyƟcs, underwriƟng, claims, compliance,
and legal.
b)
Scope of responsibility and authority, chains of command, and decisional
hierarchies.
c)
The independence of decision-makers and lines of defense at successive
stages of the AI System life cycle.
d)
Monitoring, audiƟng, escalaƟon, and reporƟng protocols and
requirements
iness units, product specialists,
actuarial, data science and analyƟcs, underwriƟng, claims, compliance,
and legal.
b)
Scope of responsibility and authority, chains of command, and decisional
hierarchies.
c)
The independence of decision-makers and lines of defense at successive
stages of the AI System life cycle.
d)
Monitoring, audiƟng, escalaƟon, and reporƟng protocols and
requirements.
e)
Development and implementaƟon of ongoing training and supervision of
personnel.
2.4
Specifically with respect to PredicƟve Models: the Insurer’s processes and
procedures for designing, developing, verifying, deploying, using, updaƟng, and monitoring
PredicƟve Models, including a descripƟon of methods used to detect and address errors,
performance issues, outliers, or unfair discriminaƟon in the insurance pracƟces resulƟng from
the use of the PredicƟve Model.
Page 7 of 11
3.0
Risk Management and Internal Controls
The AIS Program should document the Insurer’s risk idenƟficaƟon, miƟgaƟon, and management
framework and internal controls for AI Systems generally and at each stage of the AI System life
cycle. Risk management and internal controls should address the following items:
3.1
The oversight and approval process for the development, adopƟon, or
acquisiƟon of AI Systems, as well as the idenƟficaƟon of constraints and controls on automaƟon
and design to align and balance funcƟon with risk.
3.2
Data pracƟces and accountability procedures, including data currency, lineage,
quality, integrity, bias analysis and minimizaƟon, and suitability.
3.3
Management and oversight of PredicƟve Models (including algorithms used therein),
including:
a)
Inventories and descripƟons of the PredicƟve Models.
b)
Detailed documentaƟon of the development and use of the PredicƟve
Models.
c)
Assessments such as interpretability, repeatability, robustness, regular
tuning, reproducibility, traceability, model driŌ, and the auditability of
these measurements where appropriate
t of PredicƟve Models (including algorithms used therein),
including:
a)
Inventories and descripƟons of the PredicƟve Models.
b)
Detailed documentaƟon of the development and use of the PredicƟve
Models.
c)
Assessments such as interpretability, repeatability, robustness, regular
tuning, reproducibility, traceability, model driŌ, and the auditability of
these measurements where appropriate.
3.4
ValidaƟng, tesƟng, and retesƟng as necessary to assess the generalizaƟon of AI
System outputs upon implementaƟon, including the suitability of the data used to develop,
train, validate and audit the model. ValidaƟon can take the form of comparing model
performance on unseen data available at the Ɵme of model development to the performance
observed on data post-implementaƟon, measuring performance against expert review, or other
methods.
3.5
The protecƟon of non-public informaƟon, parƟcularly consumer informaƟon,
including unauthorized access to the PredicƟve Models themselves.
3.6
Data and record retenƟon.
3.7
Specifically with respect to PredicƟve Models: a narraƟve descripƟon of the
model’s intended goals and objecƟves and how the model is developed and validated to ensure
that the AI Systems that rely on such models correctly and efficiently predict or implement
those goals and objecƟves.
4.0
Third-Party AI Systems and Data
The Department strongly encourages that an AIS Program address the Insurer’s process for
acquiring, using, or relying on (i) third-party data to develop AI Systems; and (ii) AI Systems
and how the model is developed and validated to ensure
that the AI Systems that rely on such models correctly and efficiently predict or implement
those goals and objecƟves.
4.0
Third-Party AI Systems and Data
The Department strongly encourages that an AIS Program address the Insurer’s process for
acquiring, using, or relying on (i) third-party data to develop AI Systems; and (ii) AI Systems
Page 8 of 11
developed by a third party, which may include, as appropriate, the establishment of standards,
policies, procedures, and protocols relaƟng to the following consideraƟons:
4.1
Due diligence and the methods employed by the Insurer to assess the third party
and its data or AI Systems acquired from the third party to ensure that decisions made or
supported from such AI Systems that could lead to Adverse Consumer Outcomes will meet the
legal standards imposed on the Insurer itself.
4.2
Where appropriate and available, the inclusion of terms in contracts with third
parƟes that:
a)
Provide audit rights and/or enƟtle the Insurer to receive audit reports by
qualified audiƟng enƟƟes.
b)
Require the third party to cooperate with the Insurer with regard to
regulatory inquiries and invesƟgaƟons related to the Insurer’s use of the
third-party’s product or services.
4.3
The performance of contractual rights regarding audits and/or other acƟviƟes to
confirm the third-party’s compliance with contractual and, where applicable, regulatory
requirements.
SECTION 4: REGULATORY OVERSIGHT AND EXAMINATION CONSIDERATIONS
The Department’s regulatory oversight of Insurers includes oversight of an Insurer’s conduct in
the state, including its use of AI Systems to make or support decisions that impact consumers
regarding audits and/or other acƟviƟes to
confirm the third-party’s compliance with contractual and, where applicable, regulatory
requirements.
SECTION 4: REGULATORY OVERSIGHT AND EXAMINATION CONSIDERATIONS
The Department’s regulatory oversight of Insurers includes oversight of an Insurer’s conduct in
the state, including its use of AI Systems to make or support decisions that impact consumers.
Regardless of the existence or scope of a wriƩen AIS Program, in the context of an invesƟgaƟon
or market conduct acƟon, an Insurer can expect to be asked about its development,
deployment, and use of AI Systems, or any specific PredicƟve Model, AI System or applicaƟon
and its outcomes (including Adverse Consumer Outcomes) from the use of those AI Systems, as
well as any other informaƟon or documentaƟon deemed relevant by the Department.
Insurers should expect those inquiries to include the Insurer’s governance framework, risk
management, and internal controls (including the consideraƟons idenƟfied in SecƟon 3). In
addiƟon to conducƟng a review of any of the items listed in this bulleƟn, a regulator may also
ask quesƟons regarding any specific model, AI System, or its applicaƟon, including requests for
the following types of informaƟon and/or documentaƟon:
1.0
InformaƟon and DocumentaƟon RelaƟng to AI System Governance, Risk Management,
and Use Protocols
1.1.
InformaƟon and documentaƟon related to or evidencing the Insurer’s AIS
Program, including:
a)
The wriƩen AIS Program.
gulator may also
ask quesƟons regarding any specific model, AI System, or its applicaƟon, including requests for
the following types of informaƟon and/or documentaƟon:
1.0
InformaƟon and DocumentaƟon RelaƟng to AI System Governance, Risk Management,
and Use Protocols
1.1.
InformaƟon and documentaƟon related to or evidencing the Insurer’s AIS
Program, including:
a)
The wriƩen AIS Program.
Page 9 of 11
b)
InformaƟon and documentaƟon relaƟng to or evidencing the adopƟon of
the AIS Program.
c)
The scope of the Insurer’s AIS Program, including any AI Systems and
technologies not included in or addressed by the AIS Program.
d)
How the AIS Program is tailored to and proporƟonate with the Insurer’s
use and reliance on AI Systems, the risk of Adverse Consumer Outcomes,
and the Degree of PotenƟal Harm to Consumers.
e)
The policies, procedures, guidance, training materials, and other
informaƟon relaƟng to the adopƟon, implementaƟon, maintenance,
monitoring, and oversight of the Insurer’s AIS Program, including:
i.
Processes and procedures for the development, adopƟon, or
acquisiƟon of AI Systems, such as:
(1)
IdenƟficaƟon of constraints and controls on automaƟon
and design.
(2)
Data governance and controls, any pracƟces related to
data lineage, quality, integrity, bias analysis and
minimizaƟon, suitability, and data currency.
ii.
Processes and procedures related to the management and
oversight of PredicƟve Models, including measurements,
standards, or thresholds adopted or used by the Insurer in the
development, validaƟon, and oversight of models and AI Systems.
iii.
ProtecƟon of non-public informaƟon, parƟcularly consumer
informaƟon, including unauthorized access to PredicƟve Models
themselves.
1.2.
InformaƟon and documentaƟon relaƟng to the Insurer’s pre-acquisiƟon/pre-use
diligence, monitoring, oversight, and audiƟng of data or AI Systems developed by a third party.
1.3
rer in the
development, validaƟon, and oversight of models and AI Systems.
iii.
ProtecƟon of non-public informaƟon, parƟcularly consumer
informaƟon, including unauthorized access to PredicƟve Models
themselves.
1.2.
InformaƟon and documentaƟon relaƟng to the Insurer’s pre-acquisiƟon/pre-use
diligence, monitoring, oversight, and audiƟng of data or AI Systems developed by a third party.
1.3.
InformaƟon and documentaƟon relaƟng to or evidencing the Insurer’s
implementaƟon and compliance with its AIS Program, including documents relaƟng to the
Insurer’s monitoring and audit acƟviƟes respecƟng compliance, such as:
a)
DocumentaƟon relaƟng to or evidencing the formaƟon and ongoing
operaƟon of the Insurer’s coordinaƟng bodies for the development, use,
and oversight of AI Systems.
Page 10 of 11
b)
DocumentaƟon related to data pracƟces and accountability procedures,
including data lineage, quality, integrity, bias analysis and minimizaƟon,
suitability, and data currency.
c)
Management and oversight of PredicƟve Models and AI Systems,
including:
i.
The Insurer’s inventories and descripƟons of PredicƟve Models,
and AI Systems used by the Insurer to make or support decisions
that can result in Adverse Consumer Outcomes.
ii.
As to any specific PredicƟve Model or AI System that is the subject
of invesƟgaƟon or examinaƟon:
(1)
DocumentaƟon of compliance with all applicable AI
Program policies, protocols, and procedures in the
development, use, and oversight of PredicƟve Models and
AI Systems deployed by the Insurer.
(2)
InformaƟon about data used in the development and
oversight of the specific model or AI System, including the
data source, provenance, data lineage, quality, integrity,
bias analysis and minimizaƟon, suitability, and data
currency.
pplicable AI
Program policies, protocols, and procedures in the
development, use, and oversight of PredicƟve Models and
AI Systems deployed by the Insurer.
(2)
InformaƟon about data used in the development and
oversight of the specific model or AI System, including the
data source, provenance, data lineage, quality, integrity,
bias analysis and minimizaƟon, suitability, and data
currency.
(3)
InformaƟon related to the techniques, measurements,
thresholds, and similar controls used by the Insurer.
d)
DocumentaƟon related to validaƟon, tesƟng, and audiƟng, including
evaluaƟon of Model DriŌ to assess the reliability of outputs that influence
the decisions made based on PredicƟve Models. Note that the nature of
validaƟon, tesƟng, and audiƟng should be reflecƟve of the underlying
components of the AI System, whether based on PredicƟve Models or
GeneraƟve AI.
2.0
Third-Party AI Systems and Data
In addiƟon, if the invesƟgaƟon or examinaƟon concerns data, PredicƟve Models, or AI Systems
collected or developed in whole or in part by third parƟes, the Insurer should also expect the
Department to request the following addiƟonal types of informaƟon and documentaƟon.
2.1
Due diligence conducted on third parƟes and their data, models, or AI Systems.
2.2
Contracts with third-party AI System, model, or data vendors, including terms
relaƟng to representaƟons, warranƟes, data security and privacy, data sourcing, intellectual
property rights, confidenƟality and disclosures, and/or cooperaƟon with regulators.
wing addiƟonal types of informaƟon and documentaƟon.
2.1
Due diligence conducted on third parƟes and their data, models, or AI Systems.
2.2
Contracts with third-party AI System, model, or data vendors, including terms
relaƟng to representaƟons, warranƟes, data security and privacy, data sourcing, intellectual
property rights, confidenƟality and disclosures, and/or cooperaƟon with regulators.
Page 11 of 11
2.3
Audits and/or confirmaƟon processes performed regarding third-party
compliance with contractual and, where applicable, regulatory obligaƟons.
2.4
DocumentaƟon pertaining to validaƟon, tesƟng, and audiƟng, including
evaluaƟon of Model DriŌ.
The Department recognizes that Insurers may demonstrate their compliance with the laws that
regulate their conduct in the state in their use of AI Systems through alternaƟve means,
including through pracƟces that differ from those described in this bulleƟn. The goal of the
bulleƟn is not to prescribe specific pracƟces or to prescribe specific documentaƟon
requirements. Rather, the goal is to ensure that Insurers in the state are aware of the
Department’s expectaƟons as to how AI Systems will be governed and managed and of the
kinds of informaƟon and documents about an Insurer’s AI Systems that the Department expects
an Insurer to produce when requested.
As in all cases, invesƟgaƟons and market conduct acƟons may be performed using procedures
that vary in nature, extent, and Ɵming in accordance with regulatory judgment. Work
performed may include inquiry, examinaƟon of company documentaƟon, or any of the
conƟnuum of market acƟons described in the NAIC’s Market RegulaƟon Handbook. These
acƟviƟes may involve the use of contracted specialists with relevant subject maƩer experƟse.
Nothing in this bulleƟn limits the authority of the Department to conduct any regulatory
invesƟgaƟon, examinaƟon, or enforcement acƟon relaƟve to any act or omission of any Insurer
that the Department is authorized to perform
uum of market acƟons described in the NAIC’s Market RegulaƟon Handbook. These
acƟviƟes may involve the use of contracted specialists with relevant subject maƩer experƟse.
Nothing in this bulleƟn limits the authority of the Department to conduct any regulatory
invesƟgaƟon, examinaƟon, or enforcement acƟon relaƟve to any act or omission of any Insurer
that the Department is authorized to perform.
Please refer any quesƟons regarding this bulleƟn to the Department’s Market RegulaƟon
Division at MRD_AI_Inquiries@ncdoi.gov.