# Who Owns the Evidence in Insurance AI Governance

> Insurance AI governance roles as an ownership matrix: which function prepares each piece of NAIC evidence, which one signs it, and who answers for it in an exam.

- Source: https://insureaiwire.com/ai-governance-roles-insurance/
- Publication: InsureAI Wire
- Author: Simon Li
- Updated: 2026-08-14

---
Section 2.3(a) of the NAIC Model Bulletin sketches governance accountability by example. It suggests committees "comprised of representatives from appropriate disciplines and units within the Insurer, such as business units, product specialists, actuarial, data science and analytics, underwriting, claims, compliance, and legal" [^1]. The common next move is to copy those eight into a charter, minute the committee as formed, and move on. For the wider program that committee sits inside, our [AI governance in insurance guide](/ai-governance-in-insurance/) maps the full framework.

An examination reaches further than the charter. Section 4 sets out what a department may request, and the list is made of documents rather than assurances [^1]. Four entries are the ones carriers expect: the written AIS Program with the record of its adoption, the inventories and descriptions of predictive models, the validation and audit records with model drift among them, and the third-party diligence files and vendor contracts. A fifth entry is the committee itself, worded as documentation evidencing the formation *and ongoing operation* of the insurer's coordinating bodies [^1]. A membership list satisfies the word "formation." Nothing in a charter speaks to "ongoing operation."

An insurance AI governance ownership matrix assigns each role three things: the evidence it prepares, the evidence it signs, and the question it answers when a regulator asks. It turns the Bulletin's example list of disciplines into a document-by-document map, so that every artifact leads to a named person rather than to a committee. The matrix set out below is an InsureAI Wire implementation template; where each duty finally sits is the carrier's design choice, and the Bulletin leaves it there.

## The eight disciplines and the evidence each one holds

Two pieces of wording keep the list open. Section 2.0 introduces its governance items with "should consider addressing," and 2.3(a) prefaces the disciplines with "such as" [^1]. A carrier can build a different structure and still meet the expectation. The constraint is narrower than the list itself: every governance artifact needs a home. The matrix below is a working template. Adapt it to your structure, and fill every cell. The [market conduct exam documentation playbook](/market-conduct-exam-ai-docs-ready/) covers what an empty cell costs once an exam is already running.

**Table [row-headers]:** Insurance functions and their preparation, sign-off, and examination responsibilities

| Function | Prepares | Signs | Answers for |
|---|---|---|---|
| Business units | Use-case descriptions, consumer-impact assessments, override logs | Business-line owner attestation | "What does this model do, and why does it touch a consumer?" |
| Product specialists | Product-specific AI use cases, feature documentation, customer-facing notices | Product owner sign-off on consumer notice language | "How does AI change what the customer sees or gets?" |
| Actuarial | Model validation memos, rate-impact analyses, reserve-impact assessments | Chief Actuary or appointed actuary | "Is the model actuarially sound, and was it tested before it set price?" |
| Data science | Model cards, training data documentation, drift monitoring logs | Head of data science or model risk officer | "How was the model built, and how do we know it still works?" |
| Underwriting | Underwriting guidelines that reference AI, exception handling procedures, human review thresholds | Chief Underwriting Officer | "When does the model decide, and when does a person decide?" |
| Claims | Claims AI workflows, denial-review logs, adjuster override records | Head of Claims | "Can we reproduce what the model recommended and what the human decided?" |
| Compliance | AIS Program document, regulatory change tracking, exam response files | Chief Compliance Officer | "Does the program exist, is it current, and can we produce it on demand?" |
| Legal | Vendor contract review, regulatory interpretation, litigation risk assessment | General Counsel | "Are we contractually protected, and are we interpreting the rules correctly?" |

No function on this list reports to another. The governance committee sits above the matrix, and its work is the handoffs: actuarial knowing what data science built, compliance knowing what legal reviewed, the business unit knowing what underwriting approved.

### Two rows, filled in

A template does nothing until names and dates go into it. Below is an actuarial row as a carrier might complete it for one system. The names, dates, and systems in both tables are illustrative, not a real company's data.

**Table [row-headers]:** Illustrative completed ownership record for an actuarial AI system

| Field | Entry |
|---|---|
| Function | Actuarial |
| System | Personal auto rating model v4.2 |
| Prepares | Validation memo dated 2026-03-14; rate-impact analysis dated 2026-03-20 |
| Signs | R. Okonkwo, Chief Actuary, signed 2026-03-28 |
| Answers for | "Was the model tested before it set price, and by whom?" |
| Last confirmed by owner | 2026-03-28 |

The row you learn most from is the one you cannot complete. Write the gap into the cell rather than leaving it blank: what is missing, why, who owns closing it, and what protects the policyholder in the meantime.

**Table [row-headers]:** Illustrative ownership record showing an unresolved validation gap

| Field | Entry |
|---|---|
| Function | Underwriting |
| System | Small-commercial submission scoring model v1.6 |
| Prepares | Underwriting guidelines reference the model; **human review threshold never documented** |
| Signs | Chief Underwriting Officer, unsigned pending the threshold decision |
| Why | Model went live in 2025 under a pilot exception that was never converted to standing guidance |
| Gap owner | Chief Underwriting Officer |
| Due | 2026-Q4 |
| Interim control | Every declination from the model routed to a senior underwriter for sign-off until the threshold is written and approved |

A row left unsigned but carrying an owner, a reason, and a due date still tells a reader where the program stands. A blank cell reads as an unmanaged gap, which is the more expensive of the two answers.

## Who prepares, who signs, who answers

The three columns are three separate jobs. Preparation assembles evidence. Signing puts accountability on it. Answering is what happens on the day. One person can hold two of the three. When one name holds all three, the function has a bottleneck; when a column has no name at all, it has a gap.

Data science may write the [model card](/glossary/model-card/), and until the chief actuary signs the validation memo the document stays internal work product rather than governance evidence. An examiner asks who approved it, and "the team" closes no loop.

A chief underwriting officer who signs AI guidelines without reading the exception logs is vouching for a routine no one has checked. A signature carries whatever the preparation behind it carries.

The person who takes the regulator's call should be the one who prepared the document or the one who signed it. "Let me find out who handles that" is itself a finding.

## The governance committee's real job

Section 2.3 does not stop at membership. Its remaining items ask for scope of responsibility and authority, chains of command and decisional hierarchies, the independence of decision-makers across successive stages of the AI system life cycle, and monitoring, auditing, escalation and reporting protocols [^1]. Section 3.1 adds an oversight and approval process for developing, adopting, or acquiring AI systems, alongside the constraints and controls placed on automation [^1]. Read together, those items describe a body that can decline. A group that reviews models only after they are live holds that authority on paper, and the minutes are where the difference shows. The [NAIC Model Bulletin explainer](/naic-model-bulletin/) walks through Section 2.3 and the committee expectation in full.

A model that travels from data science to underwriting to claims crosses three rows of the matrix. Tracing that path and naming the owner at each step is the work the committee exists to do.

## Assign one artifact before Friday

Three passes. Each one fits in an afternoon.

First, open your current AIS Program or governance charter and find the list of committee members. Put each name against a row of the matrix. A row with no name is your first gap.

Second, pick one AI system that is live today. Trace its path: who prepared the model card, who signed the validation, who approved the deployment, who reads the drift log now. Write those four names into the matrix. Any cell you cannot fill from a file is your second gap.

Third, circulate the matrix as a dated one-page appendix to the AIS Program, and ask each function to confirm or correct its own row. Expect corrections, and treat them as the output rather than as noise. A row rewritten by its owner is a row that owner has agreed to answer for.

The download below is the same matrix with blank cells for your names, dates, and gap entries.

<div><a class="download-cta" href="/downloads/ai-governance-roles-ownership-matrix.xlsx" download><span class="dl-label">Download the ownership matrix worksheet</span><span class="dl-ext">XLSX</span></a></div>

One limit is worth naming before you circulate it. The matrix records where accountability sits, and it cannot create the authority to put it there. The officer who signs for a function often does not control that function's headcount or budget, so a row that stays unsigned across two quarters is usually reporting a resourcing decision taken somewhere above the committee. The matrix will surface that accurately and will not resolve it. Escalating it belongs to whoever the AIS Program names as accountable to the board.

[^1]: NAIC Model Bulletin, "Use of Artificial Intelligence Systems by Insurers," adopted December 4, 2023: https://content.naic.org/sites/default/files/inline-files/2023-12-4%20Model%20Bulletin_Adopted_0.pdf