What an AI Governance Framework Actually Looks Like for an Insurer
How a NIST or ISO-based AI governance framework maps onto an insurer's AIS Program, NAIC Exhibits A to D, and third-party AI.
In this article
For Governance, compliance, and risk leads at state-regulated insurers who hold a NIST or ISO framework diagram and need to know which insurance document each part of it becomes.
Read if You have a generic AI governance framework and cannot tell which part of it answers the AIS Program, the bulletin's Section 4 request list, or Exhibits A to D.
Lay the NIST AI Risk Management Framework’s four-function diagram next to the NAIC Model Bulletin, and the word “governance” changes size. In NIST’s framework, governance is one of four functions, “designed to be a cross-cutting function to inform and be infused throughout the other three functions.”1 In the bulletin, “a governance framework for the oversight of AI Systems” is one component of a written AIS Program, listed after the general guidelines and ahead of risk management, internal controls, and third-party systems.2 Read against the bulletin, an AI governance framework in the generic sense a diagram uses corresponds to the whole AIS Program, and the bulletin’s governance section is one part of it. That is our reading of the two texts, and the mapping below rests on it.
For a state-regulated insurer, the difference decides which box on the diagram answers which request. Section 4 of the bulletin begins one sentence with “Regardless of the existence or scope of a written AIS Program,” and says insurers should expect the resulting inquiries to include “the Insurer’s governance framework, risk management, and internal controls.”2 The first item on its documentation list is “The written AIS Program.” None of the requests is phrased as Govern, Map, Measure, or Manage. What follows maps the generic framework onto what an insurer’s file actually holds: the parts of the AIS Program, the Section 4 request list, and the four exhibits of the NAIC’s draft evaluation tool. The regulatory map around those documents belongs to the AI governance in insurance hub.
Where NIST and ISO enter the bulletin
The bridge between the voluntary frameworks and an insurer’s regulatory file is a single guideline. Guideline 1.5 says the AIS Program “may be independent of or part of the Insurer’s existing Enterprise Risk Management (ERM) program.” The next sentence says it “may adopt, incorporate, or rely upon, in whole or in part, a framework or standards developed by an official third-party standard organization, such as the National Institute of Standards and Technology (NIST) Artificial Intelligence Risk Management Framework, Version 1.0.”2 NIST’s is the only outside framework the bulletin names.
On our reading, the wording makes reliance optional (“may”) and divisible (“in whole or in part”), and it runs one way: the program adopts or relies on the framework, so a department still receives the insurer’s own program. Section 4 asks for it, including “Information and documentation relating to or evidencing the adoption of the AIS Program.”2
Neither outside framework is an insurance requirement. NIST says its AI RMF “is intended for voluntary use,”3 and the framework document says it is intended to be “voluntary, rights-preserving, non-sector-specific, and use-case agnostic.”1 The bulletin does not mention ISO/IEC 42001 at all. ISO’s catalogue records that standard as published on December 18, 2023,4 two weeks after the NAIC adopted the bulletin. The “such as” in guideline 1.5 leaves the list open, and the bulletin recognizes that insurers may demonstrate compliance “through alternative means,”2 so the text does not rule out an ISO-based program. Where a state has issued the bulletin, the bulletin is the regulatory expectation, and the state tracker records which states have issued it and in what form.
The bulletin also gives the governance part of an AI framework a second insurance reader. Its legislative-authority list carries a placeholder for the state law corresponding to the Corporate Governance Annual Disclosure Model Act (#305).2 It says that law and its companion regulation “apply to elements of the Insurer’s corporate governance framework that address the Insurer’s use of AI Systems to support actions and decisions that impact consumers.”2 For an insurer that files that disclosure, the governance row has a place in the filing too.
NIST AI RMF vs ISO 42001 for an insurer
For an insurer, NIST AI RMF vs ISO 42001 is mostly a choice of shape, because the bulletin expects a written program and leaves the choice of outside framework to the insurer. NIST’s AI RMF is a free, voluntary catalogue of outcomes in four functions, GOVERN, MAP, MEASURE, and MANAGE, each broken into categories and subcategories whose actions “do not constitute a checklist, nor are they necessarily an ordered set of steps.”1 ISO/IEC 42001 is a paid international standard for a management system. ISO’s page says it “specifies requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS),” and describes implementing it as putting policies and procedures in place “using the Plan-Do-Check-Act methodology.”4
| Point of comparison | NIST AI RMF 1.0 | ISO/IEC 42001:2023 |
|---|---|---|
| Issued by | NIST, U.S. Department of Commerce; released January 26, 20233 | ISO/IEC JTC 1/SC 42; published December 2023, edition 14 |
| Form | Outcomes in four functions, with categories and subcategories1 | Requirements for an AI management system, using Plan-Do-Check-Act4 |
| Access | Free of charge1 | Sold by ISO; 51 pages4 |
| Sector | ”non-sector-specific, and use-case agnostic”1 | Described by ISO as applicable across all industries4 |
| In the NAIC bulletin | Named in guideline 1.5 as an example a program may rely on2 | Not mentioned2 |
| Change status | Being revised under the White House AI Action Plan, per NIST’s page3 | Published, ISO stage 60.604 |
As we read them, NIST supplies a vocabulary of outcomes that can be laid against what the bulletin asks a program to address, and ISO supplies the machinery around a program. A crosswalk listed on NIST’s AI Resource Center quotes clause titles such as “Determining the scope of the AI management system,” “Leadership and commitment,” “Internal audit programme,” and “Nonconformity and corrective action.”5 Those titles line up, in our reading, with the bulletin’s guideline that the AIS Program “should address governance, risk management controls, and internal audit functions.”2 NIST’s listing names Microsoft as the crosswalk’s provider, and the document maps RMF subcategories to the ISO/IEC FDIS 42001 text, the final draft before publication, rather than to the published edition.56 The listing adds that inclusion “does not imply NIST endorsement of the resource the AI RMF is mapped to, nor does it imply that either resource comprehensively covers the contents of the other.”6 This article describes ISO/IEC 42001 only from ISO’s public page and the titles and labels quoted in that crosswalk; the standard’s text is sold by ISO and is not quoted here.
Neither framework, as its publisher describes it, supplies an insurance definition of harm. NIST states that the AI RMF “does not prescribe risk tolerance” and notes that “Some sectors or industries may have established definitions of harm or established documentation, reporting, and disclosure requirements.”1 ISO’s page describes ISO/IEC 42001 as applicable across all industries and says that “Rather than looking at the details of specific AI applications, it provides a practical way of managing AI-related risks and opportunities across an organization.”4 For a state-regulated insurer, the bulletin supplies the definition and a list of what a department may request. It defines an Adverse Consumer Outcome as an insurer’s decision, subject to regulatory standards that the Department enforces, whose adverse impact on the consumer violates those standards, and it scales controls to the “Degree of Potential Harm to Consumers.”2 In the mapping below, that definition occupies the slot NIST reserves for organizational risk tolerance, MAP 1.5.
The AI governance framework, cell by cell
The table follows nine groups of NIST AI RMF outcomes into the bulletin’s program guidelines (Section 3), its request list (Section 4), and the draft evaluation tool.127 Row labels come from NIST, cell contents from the NAIC documents, and the pairings are InsureAI Wire’s analysis; neither NIST nor the NAIC publishes this crosswalk. Exhibit references are to version 4.0 of the tool, and every page of that version is marked DRAFT.
| NIST AI RMF outcome | Where it sits in the AIS Program (Section 3) | What a department may request (Section 4) | Where Evaluation Tool 4.0 reads it |
|---|---|---|---|
| GOVERN 1: policies, processes, and procedures | 1.0 general guidelines; 2.1 policies for each life-cycle stage; 2.2 documentation requirements | 1.1(a) and (b): the written AIS Program and evidence of its adoption | Exhibit B checklist item 1: adoption of a written program, its date, and the “frequency of review for updating” |
| GOVERN 2: accountability structures | 1.3 senior management accountable to the board; 2.3 committees, decision rights, independence, escalation, training | 1.3(a): formation and ongoing operation of coordinating bodies | Exhibit B checklist item 2 (board or management role); narrative item 1 (governance framework) |
| GOVERN 1.6, MAP 1, and MAP 2: inventory, context, categorization | 3.3(a) inventories and descriptions of Predictive Models; 1.6 uses across the insurance life cycle | 1.3(c)(i): inventories and descriptions of models and AI Systems that make or support decisions that can result in Adverse Consumer Outcomes | Exhibit A: counts and use cases by operational area |
| MAP 1.5 and MAP 5: risk tolerance and impacts | Section 3’s five proportionality factors; 1.4 scope aligned with the Degree of Potential Harm to Consumers | 1.1(d): how the program is tailored and proportionate | Exhibit C, whose risk criteria are set by the insurance company; checklist item 3k on quantifying risk levels |
| MEASURE 2: testing, validity, fairness, production monitoring | 2.4 methods to detect errors and unfair discrimination; 3.4 validating, testing, and retesting | 1.3(d): validation, testing, and auditing, including Model Drift | Exhibit C items 8 and 9: testing, validation, monitoring, last test date |
| MAP 2.3 and MEASURE 2.10: data and privacy | 3.2 data practices, including lineage, quality, and bias analysis; 3.5 protection of non-public information | 1.3(b) data practices; 1.3(c)(ii)(2) data source and provenance for a specific model | Exhibit D: data elements used in development and whether each is sourced internally or from a named third party |
| MANAGE 1.1 and GOVERN 1.7: go or no-go, decommissioning | 3.1 oversight and approval for development, adoption, or acquisition; 1.7 life cycle through retirement | 1.1(e)(i): processes for development, adoption, or acquisition | Exhibit B checklist item 3e: whether systems remain suitable for their intended use |
| MEASURE 3.3 and MANAGE 4.3: feedback, appeal, incidents | 1.9 notice to impacted consumers and access to information | No numbered item on the request list | Exhibit B checklist items 3m (AI-related complaints) and 3n (consumer awareness) |
| GOVERN 6, MAP 4, and MANAGE 3: third parties | 1.8 systems built by the insurer or a vendor; 4.1 to 4.3 diligence, contract terms, audits | 1.2 third-party diligence and oversight; part 2, items 2.1 to 2.4 | Exhibit B narrative items 3 and 4, checklist item 3l; Exhibit C item 4; Exhibit D vendor column |
The inventory row shows that a framework element and an evaluation exhibit are different objects: the inventory is the bulletin’s guideline 3.3(a), while Exhibit A asks for counts and use cases by operational area.27 The consumer row shows a gap running the other way. Guideline 1.9 makes notice to impacted consumers part of the program, and the tool asks about complaints and consumer awareness, yet none of the numbered items in Section 4 names consumer notices.27 Section 4 does say inquiries include “the considerations identified in Section 3,”2 so the question can still be asked, and a framework copied from the numbered items alone would have no row for it.
A program built on ISO/IEC 42001 would face the same rows, because they come from the NAIC documents; only the reference labels in the first column would change. Which function prepares and signs the evidence in each cell is a separate question, taken up in the AI governance roles guide.
Exhibits A to D read the framework back
The NAIC’s evaluation tool describes itself as “Optional Supplemental Exhibits for State Regulators” and says it is “designed to supplement” the market conduct, financial analysis, and financial examination procedures regulators already use to review AI Systems.7 What an insurer builds is the framework each exhibit reads from.
When Exhibit A asks for its counts, it treats models “that augment or automate decision making related to consumers” as having direct consumer impact.7 The counting criterion comes with the tool. What the insurer needs in order to answer Exhibit A is a model-by-model record that applies that criterion, and the counts are read off that record. Exhibit B’s checklist asks the company to “Reference the processes and procedures of the Company AI Governance Framework.”7 Before its questions, Exhibit B’s narrative form states that they “are not intended to be interpreted as creating new requirements for AI Systems Governance Risk Assessments.”7 The tool, in other words, calls what it is reading a governance framework and asks where it is written down. Exhibit C covers high-risk systems, and “AI System risk criteria are set by the insurance company.”7 Exhibit D asks which data elements went into developing AI models and whether each came from an internal source or a named third party.7
On our reading, the four exhibits are the framework’s evidence surface rather than a second system to build. The decisions under their questions are the ones in the table, and when those decisions are already on paper, answering an exhibit is a matter of retrieval. The tool also expects to be used selectively. It suggests that regulators “may wish to first use Exhibit A and based on the information provided, determine if further inquiry is necessary.”7
The newer draft points the same way. In the version 5.0 exposure draft, which has not been adopted, Exhibit B is retitled “AIS Program (Two Options: Narrative or Checklist).”8 Exhibit A in that draft adds a request for the model inventory itself, and a company that already keeps one may suggest submitting it in place of completing Exhibit A.8 The evaluation tool explainer tracks where that draft stands.
This article stops at what the framework looks like. How to implement it so that it can answer Exhibit B, element by element and with a self-audit worksheet, is the subject of the Exhibit B implementation guide.
The third-party cell reaches every layer
The bulletin returns to third parties in six separate places. They are the definition of “Third Party,” the fifth proportionality factor in Section 3, guideline 1.8, the three considerations under guideline 4.0, item 1.2 of the Section 4 request list, and the separate third-party AI request list, items 2.1 to 2.4, at the end of Section 4.2 The fifth factor is “the extent and scope of the insurer’s use or reliance on data, Predictive Models, and AI Systems from third parties.” Guideline 1.8 covers AI Systems “whether developed by the Insurer or a third-party vendor.”
NIST builds the same row from its side. GOVERN 6 reads “Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues,” and MAP 4 and MANAGE 3 carry third-party risk into mapping and management.1 The framework’s position is that “all parties and AI actors should manage risk in the AI systems they develop, deploy, or use as standalone or integrated components.”1 In the crosswalk on NIST’s resource center, both GOVERN 6 subcategories map to FDIS items labeled “Allocating responsibilities” (B.10.2) and “Suppliers” (B.10.3).5 NIST’s Generative AI Profile adds a risk it calls “Value Chain and Component Integration,” which includes “improper supplier vetting across the AI lifecycle.”9
In the tool, the row surfaces in Exhibit B’s vendor and service-provider questions, Exhibit C’s item on third-party development, and Exhibit D’s vendor column.7 A framework that treats vendors only as a procurement matter can still supply those names. The harder part is the record behind them. The Section 4 third-party list asks for due diligence “conducted on third parties and their data, models, or AI Systems” (2.1), vendor contracts and their terms on “data sourcing” (2.2), and documentation of “validation, testing, and auditing” (2.4).2 Guideline 4.0 frames the insurer’s third-party process in hedged terms, wording that the AI vendor risk assessment reads closely before building its vendor questions.
An AI governance framework example for one claims model
What follows is illustrative. The insurer, the model, and the vendor are invented to show how one system occupies the rows of the table, and nothing here describes a real company or an actual regulatory request.
A regional property insurer licenses a vendor model that reads photographs submitted with homeowners claims and suggests a damage estimate and a fast-track flag. An adjuster sees both and makes the decision.
The model enters the insurer’s framework as an inventory entry recording what it does, the vendor, and the claims operation it supports, which is GOVERN 1.6 in NIST’s terms and guideline 3.3(a) in the bulletin’s. Because it suggests an answer to an adjuster who is deciding a consumer’s claim, it augments that decision, and the tool’s Exhibit A instructions count augmenting models as having direct consumer impact.7 In Exhibit A the model is one unit in the Claims/Adjudication row’s counts.
Its risk tier comes from the insurer’s own criteria, which weigh, among other things, three of the bulletin’s five factors: the decision concerns a claim, a person makes the final call, and the model comes from a third party. Suppose those criteria put it in the high tier. If a regulator then sends Exhibit C, its thirteen items in version 4.0 reach this model, including whether it was developed internally or by a third party, with the vendor’s name (item 4). They also cover its AI type, here “augment” (item 7), and how it was validated before deployment and is monitored now (item 8).7 If the vendor trained the model on its own image library, the “Image/video Analysis” row of Exhibit D names that vendor as the third-party source. Exhibit B’s vendor question depends on which form is used: the checklist asks where the insurer’s standard for procuring AI vendors is written (item 3l), the narrative how vendor-supplied systems are validated and tested (item 3b).7
The version the bulletin names is being revised
Guideline 1.5 does not cite the AI RMF in general. It cites “Version 1.0.”2 NIST’s page now says that “The AI RMF 1.0 is being revised as part of the White House AI Action Plan,”3 and the framework document said that “a review with formal input from the AI community is expected to take place no later than 2028.”1 NIST’s page does not say what the revision will change or when it will be published. The NAIC side is also unsettled: version 4.0 of the evaluation tool is an optional draft, version 5.0 has been circulated for comment without adoption, and adoption of the bulletin itself varies by state.
Those moving parts favor one structural choice. It is our recommendation; the bulletin does not address how a framework map is organized. Key the framework map to the bulletin’s section numbers, the vocabulary in which a department’s requests are written, and carry the tool’s exhibit items, NIST subcategories, and any ISO/IEC 42001 clauses as reference columns beside them. When the revised RMF is published or the tool moves to a new version, those columns are what get updated, and the rows an examiner reads stay where they were.
Footnotes
-
NIST, “Artificial Intelligence Risk Management Framework (AI RMF 1.0),” NIST AI 100-1, January 2023: https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11
-
NAIC, “NAIC Model Bulletin: Use of Artificial Intelligence Systems by Insurers,” adopted December 4, 2023, copy posted by the Big Data and Artificial Intelligence (H) Working Group: https://content.naic.org/sites/default/files/cmte-h-big-data-artificial-intelligence-wg-ai-model-bulletin.pdf.pdf ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18
-
NIST, “AI Risk Management Framework,” Information Technology Laboratory page, retrieved September 29, 2026: https://www.nist.gov/itl/ai-risk-management-framework ↩ ↩2 ↩3 ↩4
-
ISO, “ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system,” catalogue page, retrieved September 29, 2026: https://www.iso.org/standard/81230.html ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8
-
Microsoft (provider named on the NIST AI Resource Center crosswalk listing), “NIST AI RMF to ISO/IEC FDIS 42001 AI Management system Crosswalk,” hosted on NIST’s AI Resource Center, undated: https://airc.nist.gov/docs/NIST_AI_RMF_to_ISO_IEC_42001_Crosswalk.pdf ↩ ↩2 ↩3
-
NIST AI Resource Center, “Crosswalk Documents,” retrieved September 29, 2026: https://airc.nist.gov/airmf-resources/crosswalks/ ↩ ↩2
-
NAIC Big Data and Artificial Intelligence (H) Working Group, “Artificial Intelligence Systems Evaluation: Optional Supplemental Exhibits for State Regulators,” AI Systems Evaluation Tool 4.0 (clean), undated draft: https://content.naic.org/sites/default/files/inline-files/AI%20Systems%20Evaluation%20Tool%204.0%20%28Clean%29.pdf ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14
-
NAIC, “Artificial Intelligence (AI) Risk Evaluation Supplement,” version 5.0 exposure draft, not adopted, 2026: https://content.naic.org/sites/default/files/inline-files/ai-risk-evaluation-supplement-v5.0-clean.docx ↩ ↩2
-
NIST, “Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile,” NIST AI 600-1, July 2024: https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf ↩
The Bottom Line
- On our reading of the NAIC Model Bulletin, a generic AI governance framework corresponds to the whole written AIS Program, and the bulletin's own governance framework is one part of that program.
- NIST AI RMF 1.0 is voluntary and the bulletin never mentions ISO/IEC 42001. Guideline 1.5 lets a program rely on an outside framework in whole or in part, and neither framework replaces the written program a department can request.
- Exhibits A to D of the draft evaluation tool read back decisions a framework should already hold: the inventory behind the counts, the written processes Exhibit B asks the company to reference, the company's own risk criteria, and the data sources.
- Third-party AI appears in every layer, from the bulletin's fifth proportionality factor to Exhibit D's vendor column, and the Section 4 third-party items (due diligence, vendor contracts, validation and testing documentation) depend on material from or about third parties.
- The bulletin cites the AI RMF as Version 1.0, which NIST says is being revised. Our recommendation is to key the framework map to the bulletin's section numbers, with NIST and ISO references beside them, so that the revision can be absorbed without reorganizing.
How Insurers Can Implement an AI Governance Framework for NAIC Exhibit B
A practical guide to implementing an AI governance framework for NAIC Exhibit B, from AIS programs to vendor oversight and consumer evidence.
Continue →
Simon Li · Founding Editor
I write InsureAI Wire and maintain its 51-jurisdiction tracker. Most of the work is reading: NAIC working group papers, state bulletins, bills, court filings, and public comment letters. Every claim on the site carries the document it came from, so you never have to take my word for it.
Free · Weekly
Track these developments weekly
Get the InsureAI Wire dispatch in your inbox. Free, sourced, no spam.
Free weekly · No spam · Unsubscribe anytime
Related reading
How Insurers Can Implement an AI Governance Framework for NAIC Exhibit B
A practical guide to implementing an AI governance framework for NAIC Exhibit B, from AIS programs to vendor oversight and consumer evidence.
Inside the NAIC AI Model Bulletin
What the NAIC AI Model Bulletin is, how adoption works, what belongs in a written AIS Program, and which implementation guide to use next.
The NAIC AI Risk Evaluation Supplement, Exhibit by Exhibit
What each exhibit of the NAIC AI evaluation tool asks in version 5.0, the draft out for comment, and what changed from 4.0.
How Insurers Assess AI Vendor Risk
A NAIC-aligned AI vendor risk assessment checklist: a twenty-question due-diligence questionnaire, contract clauses, and the monitoring that stays with the insurer.
Information aggregation and analysis, not legal advice. See our disclaimer.