Glossary
Plain-language definitions of the NAIC and insurance AI governance terms we use across the site.
A
- Accelerated Underwriting
- A life insurance underwriting process that uses external data and predictive models to classify applicants without medical exams or fluid tests.
- Full entry →
- Actuarial Justification
- The showing that an insurance rating or underwriting practice is supported by sound actuarial analysis and genuinely predictive of risk.
- Full entry →
- Adverse Action Notice
- A notice the law requires when a consumer is denied credit, insurance, or employment based on a consumer report. FCRA sets its form and timing.
- Full entry →
- Adverse Consumer Outcome
- A negative result for a consumer from an AI-supported insurance decision, such as a denial, higher premium, delayed claim, or reduced benefit.
- Full entry →
- Agentic AI
- AI that pursues goals autonomously over multiple steps, such as retrying, routing, or coordinating with other systems, raising new accountability concerns.
- Full entry →
- AI Disclosure
- The duty to tell consumers that an AI system played a material part in a decision that affects them.
- Full entry →
- AI Lifecycle
- The full span of an AI system from design, development, and deployment through monitoring, retraining, and retirement.
- Full entry →
- AI Systems (AIS) Program
- A written insurance AI governance program that assigns ownership, sets risk appetite, documents testing, and evolves with the company's AI use.
- Full entry →
- Algorithmic Bias
- Systematic errors in a model that skew outputs in ways that are wrong or unfair, often rooted in training data, feature selection, or model design.
- Full entry →
- Algorithmic Discrimination
- Unfairly different treatment of individuals or groups by an automated decision system, often through proxy variables or biased training data.
- Full entry →
- Alternative Data
- Data not traditionally used in underwriting, such as credit history, driving behavior, or digital signals. Often regulated as ECDIS when applied to consumers.
- Full entry →
- Audit Rights
- Contractual rights that let an insurer examine a vendor's AI systems, data practices, and compliance controls. Required for high-risk third-party AI.
- Full entry →
- Automated Decision System
- A system that uses AI or algorithms to make or materially influence decisions about consumers, such as coverage, pricing, or claims outcomes.
- Full entry →
B
- Bias Testing
- The process of testing an AI model for accuracy and outcome differences across groups, including protected classes and proxy variables.
- Full entry →
C
- Catastrophe Model
- Software that runs a large simulated catalog of catastrophe events to estimate portfolio losses. It gives probabilities, not a forecast of next year.
- Full entry →
- Claims Adjudication
- Reviewing, validating, and paying or denying insurance claims. AI used here is now a high-priority target for market conduct exams and litigation.
- Full entry →
- Colorado AI Act
- Colorado SB 24-205, a comprehensive algorithmic-discrimination law. In force since June 30, 2026; SB 26-189 supersedes it on January 1, 2027.
- Full entry →
- Colorado Quantitative Testing Rule
- A Colorado Division of Insurance draft regulation that would set quantitative testing standards for life underwriting models under SB 21-169. Not adopted.
- Full entry →
- Colorado SB 21-169
- A 2021 Colorado law barring insurers from using external data or models that unfairly discriminate, implemented by the Division of Insurance line by line.
- Full entry →
- Colorado SB 26-189
- A 2026 Colorado law that replaced SB 24-205 with a narrower disclosure-and-recourse framework for automated decision-making in insurance.
- Full entry →
- Consumer Recourse
- The rights consumers have to appeal, correct, or contest an AI-influenced insurance decision, a central feature of Colorado SB 26-189 and similar state laws.
- Full entry →
D
- Data Governance
- The framework for managing data quality, access, lineage, and compliance across the enterprise, including data used by AI systems.
- Full entry →
- Data Lineage
- The documented path data takes from source through transformation, model training, and final use. Essential for AI explainability and regulatory review.
- Full entry →
- Data Minimization
- The principle of collecting only the personal data needed for a specific purpose and deleting it when no longer necessary.
- Full entry →
- Department of Insurance
- The state agency that licenses insurers, reviews rates, and enforces insurance law. Every state has one, though several run it under another name.
- Full entry →
- Disparate Impact
- The disproportionately harmful effect a facially neutral practice has on a protected class. Insurance regulators address the same problem under other names.
- Full entry →
- Disparate Treatment
- Intentional discrimination in which similarly situated consumers are treated differently because of a protected characteristic.
- Full entry →
- Due Diligence
- The investigation an insurer performs before acquiring or deploying a third-party AI system, including assessment of the vendor, model, data, and risks.
- Full entry →
E
- Executive Order 14365
- A December 2025 Trump administration order that points federal agencies at state AI laws conflicting with the national AI policy it declares.
- Full entry →
- Exhibit A
- The first exhibit of the NAIC AI Systems Evaluation Tool: a count of how many AI systems an insurer runs in each operational area, and what they are used for.
- Full entry →
- Exhibit B
- The NAIC AI Evaluation Tool's governance exhibit, answered as a narrative or a checklist, asking where an insurer's framework already covers each listed item.
- Full entry →
- Exhibit C
- The high-risk model section of the NAIC AI Systems Evaluation Tool: what each high-risk model is, how it was validated, and when it was last tested.
- Full entry →
- Exhibit D
- The data section of the NAIC AI Systems Evaluation Tool: a checklist of data-element categories, asking which ones feed your models and where each came from.
- Full entry →
- Explainability
- The degree to which a model's decision can be understood and explained in human terms, a core requirement for AI governance and consumer recourse.
- Full entry →
- External Consumer Data and Information Sources
- Data about consumers from outside an insurer's own records, such as credit reports, public records, and behavioral data. Heavily regulated in insurance.
- Full entry →
F
- Fair Credit Reporting Act
- A federal law governing consumer reports and adverse-action notices, including how insurers use credit data, tenant-screening reports, and similar information.
- Full entry →
- Federal Preemption
- When federal law displaces state law. Insurance runs the other way: McCarran-Ferguson protects state regulation unless Congress legislates about insurance.
- Full entry →
- First Notice of Loss
- The moment a claim is first reported. NAIC model regulation calls it notification of claim and starts an acknowledgment clock from it, whatever took the report.
- Full entry →
- Foundation Model
- A general-purpose AI model trained on broad data and adapted to many downstream tasks, including many LLMs and image models used in insurance applications.
- Full entry →
G
- Generative AI
- AI that creates new content such as text, images, or code. In insurance it aids drafting, summarization, and service, but raises accuracy and privacy concerns.
- Full entry →
- Governance Committee
- A cross-functional group that oversees AI risk, approves deployments, and reviews testing. Must meet regularly and have authority to pause AI systems.
- Full entry →
- Gramm-Leach-Bliley Act
- A federal law requiring financial institutions, including insurers, to protect customer data privacy and notify consumers about information-sharing practices.
- Full entry →
H
- Human-in-the-Loop
- A design where a human reviews or approves an AI system's output before it is acted on. Regulators expect it for adverse decisions; a few statutes require it.
- Full entry →
I
- Insurance Practices
- The activities insurers engage in that are subject to state insurance law, including underwriting, pricing, claims, marketing, and fraud investigation.
- Full entry →
- Internal Controls
- Policies and procedures that ensure AI systems operate as intended, including access controls, change management, and testing approvals.
- Full entry →
L
- Large Language Model
- A type of generative AI trained on vast amounts of text to understand and produce human-like language. Powers chatbots, drafting tools, and search systems.
- Full entry →
- Less-Discriminatory Alternative
- A model, variable, or practice that meets the same business purpose with less adverse effect on a protected class. Step 3 of the NYDFS comprehensive assessment.
- Full entry →
M
- Market Conduct Exam
- A state insurance regulatory examination of an insurer's business practices, including sales, claims handling, underwriting, and now AI governance and fairness.
- Full entry →
- Market Regulation Handbook
- The NAIC publication examiners work from. It standardizes how a market conduct exam is scoped, sampled, and documented, which is where AI files get requested.
- Full entry →
- McCarran-Ferguson Act
- A 1945 statute leaving regulation of the business of insurance to the states. A later federal law overrides it only by specifically relating to that business.
- Full entry →
- Medical Necessity
- Whether a service is clinically warranted enough to be covered. In California and in Medicare Advantage, a licensed clinician has to make that call, not a tool.
- Full entry →
- Medicare Advantage
- Medicare Part C: private plans delivering Medicare benefits under CMS contract. AI-assisted denials there answer to federal rules, not only state law.
- Full entry →
- Model Card
- A short document reporting what a model is for, how it was evaluated, and where it performs worse. An industry convention, not an NAIC requirement.
- Full entry →
- Model Drift
- The degradation of a model's performance over time as real-world data or behavior changes away from the data it was trained on.
- Full entry →
- Model Inventory
- A documented list of all models and AI systems in use, including their purpose, owners, risk tier, and validation status.
- Full entry →
- Model Law
- A template statute the NAIC drafts for states to adopt as binding law. Unlike a Model Bulletin, it has the force of law once a state legislature adopts it.
- Full entry →
- Model Risk Management
- The discipline of identifying, measuring, and controlling risks from models, including AI models used in insurance decisions.
- Full entry →
- Model Validation
- The process of testing a model for accuracy, fairness, stability, and fitness for its intended use before and after deployment.
- Full entry →
N
- NAIC
- The National Association of Insurance Commissioners, the U.S. standard-setting and coordination body for state insurance regulators.
- Full entry →
- NAIC AI Evaluation Tool
- Optional supplemental exhibits the NAIC built for state regulators, structuring what they ask an insurer about its AI systems. At v4.0, in a 12-state pilot.
- Full entry →
- NAIC Big Data and AI (H) Working Group
- The NAIC group that handles insurance AI. Its page is where the evaluation tool drafts, the bulletin adoption map, and the meeting materials are posted.
- Full entry →
- NAIC Model Bulletin
- The NAIC's non-binding guidance for state insurance regulators on how insurers should govern, document, and test their use of AI systems.
- Full entry →
- NYDFS
- The New York State Department of Financial Services, the state's combined insurance and banking regulator since 2011, which writes its own AI guidance.
- Full entry →
- NYDFS Circular Letter No. 7
- July 2024 NY DFS guidance setting the Department's expectations for insurers using AI and external consumer data in underwriting and pricing.
- Full entry →
O
- Ongoing Monitoring
- Regular observation of a model or AI system after deployment to catch drift, bias, accuracy degradation, and changing business conditions.
- Full entry →
P
- Predictive Model
- A model that estimates a future outcome or likelihood from historical data, such as the probability of a claim or the risk of a policyholder.
- Full entry →
- Prior Authorization
- A process where a health insurer must approve a treatment, service, or drug before covering it. AI has made this a focus of regulator and clinician scrutiny.
- Full entry →
- Producer
- The licensed person or entity that sells, solicits, or negotiates insurance. Agents and brokers are producers, and licensing law follows their AI tools.
- Full entry →
- Protected Class
- A group sharing a legally protected trait such as race, color, national origin, sex, religion, age, or disability. AI testing screens for proxy effects.
- Full entry →
- Proxy Discrimination
- Discrimination that happens when a neutral variable, such as zip code or credit data, correlates with a protected class and produces unfair outcomes.
- Full entry →
- Proxy Test
- The assessment NYDFS expects on external consumer data: does it correlate with protected-class status, and if so, does a business necessity require it?
- Full entry →
R
- Rate Filing
- The process of submitting proposed insurance rates or rating rules to a state regulator for review or approval before they can be used.
- Full entry →
- Rating Variable
- A factor used in pricing or underwriting to predict risk, such as age, location, or driving history. Regulators scrutinize these for proxy discrimination.
- Full entry →
- Redlining
- Discriminatory exclusion or higher pricing based on where a consumer lives, often via geographic variables in underwriting and pricing models.
- Full entry →
- Risk Adjustment
- Paying a health plan more for sicker enrollees. In Medicare Advantage the CMS-HCC risk score is built from submitted diagnoses, so coding accuracy is money.
- Full entry →
- Risk Appetite
- The amount and type of AI risk an insurer is willing to accept, expressed as thresholds for deployment, testing, and oversight.
- Full entry →
- Risk Tiering
- Classifying AI systems by the level of consumer harm they could cause, so governance and testing can match the risk.
- Full entry →
S
- Shadow AI
- AI tools or systems in use inside an organization that have not been logged, approved, or governed. They break AI inventories and create hidden regulatory risk.
- Full entry →
T
- Telematics
- In-vehicle or phone technology that records how a car is driven. Usage-based auto insurance prices from it, which turns driving data into a rating input.
- Full entry →
- Third-Party AI
- AI systems, models, or components built or operated by an outside vendor. The insurer stays responsible for outcomes even when the algorithm is rented.
- Full entry →
- Training Data
- The data used to teach a machine-learning model to make predictions. Its quality and representativeness directly affect fairness and accuracy.
- Full entry →
U
- Underwriting and Pricing
- Evaluating risk and setting premium rates. AI here is scrutinized for unfair discrimination and proxy effects across life, health, and property-casualty lines.
- Full entry →
- Unfair Claims Settlement Practices Act
- NAIC Model 900, the model law on claim investigation and settlement conduct. Most AI claims exposure lands here rather than in any AI-specific statute.
- Full entry →
- Unfair Discrimination
- An insurance practice that treats similar consumers differently based on protected traits, often through proxies like zip code or credit data.
- Full entry →
- Unfair Trade Practices
- State insurance laws barring deceptive, coercive, or harmful insurer practices, such as misrepresentation, twisting and rebating, and now some AI decisions.
- Full entry →
- Utilization Management
- The review of health care service use to control cost and quality. AI is widely used here and is now a major focus of state and federal insurance oversight.
- Full entry →
V
- Vendor Oversight
- An insurer remains answerable for AI a vendor built or runs, so the NAIC Model Bulletin folds third-party systems into the insurer's own AI Systems Program.
- Full entry →