AI Compliance for Insurance

Govern Underwriting, Pricing and Claims AI Before Your Regulator Asks

Insurance regulators now expect a written AI program, testing for unfair discrimination, and oversight of third-party data and models. Asenion turns those expectations into operational controls your actuarial, compliance and security teams can run and evidence.

Schedule a Call

30 minutes with our AI compliance team.

What market conduct exams will ask about

5 headline regulations and standards for AI in insurance

Few of these were written only for AI. All of them apply to it.

US · State regulation

NAIC Model Bulletin on the Use of AI Systems by Insurers

Adopted by the NAIC in December 2023 and since adopted by many state insurance departments.

For AI: A written AIS Program covering governance, risk management and internal controls across the AI lifecycle, including third-party AI systems and data.

US · Colorado

Colorado SB21-169 and Regulation 10-1-1

Colorado's law against unfair discrimination from external consumer data and information sources (ECDIS), algorithms and predictive models.

For AI: Life insurers must run a governance and risk management framework and test ECDIS-driven models for unfairly discriminatory outcomes.

US · New York

NYDFS Insurance Circular Letter No. 7 (2024)

NYDFS guidance on using AI systems and external consumer data in underwriting and pricing.

For AI: Show that data and models are not proxies for protected classes, test for disparate impact, and hold vendors to the same standard.

EU · AI regulation

EU AI Act

AI used for risk assessment and pricing in life and health insurance is high-risk. Under the AI Omnibus, those obligations apply from December 2027.

For AI: Risk management, data governance, documentation, human oversight and a fundamental rights impact assessment before deployment.

Canada · Model risk

OSFI Guideline E-23

OSFI's model risk guideline applies to federally regulated life and P&C insurers, effective May 1, 2027.

For AI: Pricing, reserving, claims and GenAI models need an inventory, a risk rating and governance across their lifecycle.

Use cases

Where AI meets these rules in insurance

The AI use cases we see most often, and the requirements that follow them.

Underwriting and pricing with external data

Third-party data and ML pricing models must be tested for proxy discrimination and documented well enough to support rate filings.

NAIC AI BulletinCO SB21-169NYDFS CL 7EU AI Act high-risk

Claims triage and fraud detection

Models that route, flag or deny claims affect policyholders directly. They need human review paths, explainability and monitoring for unfair outcomes.

NAIC AI BulletinUnfair Claims Settlement PracticesOSFI E-23

GenAI for agents, brokers and policyholders

Assistants that explain coverage must not misstate policy terms, must disclose AI use and must protect nonpublic personal information.

EU AI Act Art. 50NAIC Data Security Model LawNAIC AI Bulletin

AI agents in policy administration

Agents that update policies or process endorsements need least-privilege access, runtime guardrails and audit trails.

NYDFS Part 500NAIC Data Security Model LawOSFI B-13
How Asenion helps

From regulation to operational control

One set of controls, applied from model development through runtime, with evidence your actuaries, internal audit and examiners can rely on.

01 · CONTROLGEN

Policy Packs for insurance

Start from Policy Packs for the NAIC Bulletin, Colorado SB21-169, NYDFS Circular Letter 7, the EU AI Act and OSFI E-23, mapped to your AIS Program.

02 · VERIFY

Verify before release

Test underwriting, pricing and claims models for unfair discrimination and proxy variables, and GenAI assistants for hallucination and data leakage.

03 · WITNESS

Govern at runtime

Apply context-aware controls to AI agents in production and capture tamper-resistant evidence of what happened, which controls applied and whether they worked.

Using SAS® AI Navigator? Asenion policy content is available there too. Learn more →

Get your AI program ready for market conduct review

In 30 minutes we'll map your AI use cases to the rules above, show the controls that apply, and outline the gaps in your AIS Program.

Schedule a Call

No preparation needed.