Vendor Oversight
An insurer remains answerable for AI a vendor built or runs, so the NAIC Model Bulletin folds third-party systems into the insurer's own AI Systems Program.
Vendor oversight is the set of practices an insurer uses to manage AI risk that sits outside its direct control. It includes systems developed by vendors, hosted by vendors, or operated by vendors on the insurer’s behalf.
The NAIC Model Bulletin puts third-party systems inside the same program an insurer writes for its own. Section 4.0 tells the AIS Program to address the route by which outside data and outside AI systems enter the company, then lists standards and protocols the program may include, as appropriate:
- Due diligence on the vendor and on what it supplies, enough to establish that any decision its system makes or supports, where an adverse consumer outcome is possible, meets the legal standard the insurer itself is bound by.
- Contract terms that, where appropriate and available, give the insurer audit rights or entitle it to audit reports, and oblige the vendor to help when a regulator comes asking about the insurer’s use of its product.
- Actually exercising those rights, plus whatever other checks confirm the vendor is meeting its contractual and regulatory obligations.
Every one of those is hedged. The firmer edge sits in the bulletin’s examination section, which is addressed to the insurer: a department investigating a third-party model should be expected to ask for the diligence performed, the contracts signed including the cooperation terms, and the audits run. A vendor that will not cooperate becomes the insurer’s finding.
The NAIC AI Systems Evaluation Tool covers the same ground without adding to it. Exhibit B asks about validation testing of models a third party built and about the professional service providers a company leans on; Exhibit C asks, for each high-risk model, whether it was developed internally or bought, and for the vendor’s name. Our AI vendor risk assessment guide turns that into a practical checklist.