# How to Identify the High-Risk AI Systems Exhibit C Asks About

> Five screening lines that turn an existing AI inventory into a defensible list of the high-risk systems NAIC Exhibit C asks about, and the record behind it.

- Source: https://insureaiwire.com/identify-high-risk-ai-systems/
- Publication: InsureAI Wire
- Author: Simon Li
- Updated: 2026-08-27

---
Every insurer that answers [Exhibit C](/glossary/exhibit-c/) hands a regulator a list it wrote itself. The exhibit collects detail on high-risk AI system models, and its purpose line settles who decides which ones qualify: risk criteria for AI systems, it says, "are set by the insurance company."[^1] The example in that same line, automated decision-making with consumer or financial consequences, illustrates the class rather than defining entry to it.[^1] The document holding the exhibit is the NAIC's AI Risk Evaluation Supplement. [The August 13, 2026 meeting summary](/news/naic-aug-2026-meeting-rename/) records it under that name and puts the pilot in twelve participating states through September.[^3] On its own cover the instrument is optional supplemental exhibits for state regulators, and every page of the posted file carries a DRAFT watermark.[^1]

That makes the screen itself part of what gets examined. The supplement's Materiality and Risk Assessment section says Exhibit C "relies on company assessments of the risks and materiality of its AI System(s)," and tells regulators they "may request information on how a responding company assesses the concepts of AI risk and materiality."[^1] The record of how the screen was run goes in the [exam-readiness file for a market conduct exam](/market-conduct-exam-ai-docs-ready/).

What follows assumes the inventory exists. The walk through each exhibit belongs to our [guide to the NAIC AI Evaluation Tool exhibits](/naic-ai-evaluation-tool/); building the register that Exhibit A's counts are answered from belongs to the [inventory playbook](/ai-inventory-by-line-of-business/).

## The screen in five lines

The five lines below are InsureAI Wire's reading of the AI Risk Evaluation Supplement and the NAIC Model Bulletin adopted December 4, 2023.[^2] Neither document publishes a screen, and the risk criteria that decide the answer stay with the insurance company. Run every system on the inventory across the five rows. A system can clear four lines and belong in the class because of the fifth.

**Table [row-headers]:** Five InsureAI Wire screening lines to run against each AI system on the inventory

| Screening line | What to establish | What pushes it toward high risk | Where to look |
|---|---|---|---|
| 1. Consumer effect | What the output changes for a person | It decides or moves what a consumer gets | Supplement, Exhibit C purpose[^1]; bulletin, Section 3 introduction, factors (i) and (ii)[^2] |
| 2. Overturn | Whether a person can reverse it in time | The reversal leaves no trace in the file | Bulletin, Section 3 introduction, factor (iii)[^2]; supplement, the three autonomy bands[^1] |
| 3. Outside data | Which inputs come from outside, and from whom | An input nobody can trace to a source or a named vendor | Bulletin, Section 3 introduction, factor (v), and third-party guideline 4.1[^2]; supplement, Exhibit D[^1] |
| 4. Build or buy | Who developed it, and on what contract terms | No audit rights, no duty to cooperate | Supplement, Exhibit C item 4[^1]; bulletin, third-party guideline 4.2 and regulatory oversight section item 2.2[^2] |
| 5. Reversibility | Whether a wrong output can be taken back | The output has already reached the consumer or a financial statement | Supplement, Exhibit B narrative, suggested additional question 1g[^1] |

The last column says where to look for the passage behind each line.

<div><a class="download-cta" href="/downloads/exhibit-c-high-risk-screen.xlsx" download><span class="dl-label">Download the high-risk screening worksheet</span><span class="dl-ext">XLSX</span></a></div>

The worksheet is the same five lines as columns, one system per row.

## Screen one: what the output does to a consumer

Ask what each system's output changes for a person: eligibility, coverage, price, payment, timing. The harm named first in Exhibit C is an [Adverse Consumer Outcome](/glossary/adverse-consumer-outcome/), defined narrowly as an AI system decision by an insurer, subject to insurance regulatory standards the department enforces, that "adversely impacts the consumer in a manner that violates those standards."[^1] Two of the five considerations in the introduction to Section 3 of the NAIC Model Bulletin point the same way: factor (i), the nature of the decision being made, informed, or supported, and factor (ii), the type and degree of potential harm to consumers.[^2]

Ranking internal work queues changes nothing a policyholder receives; ranking them so some files get worked this week changes when a claim gets paid.

## Screen two: whether a person can overturn the result, and whether that shows

Ask whether a person could have reversed the output before the consumer saw it, and whether the file shows the option was real. Augmentation, in the supplement's definition, is an AI system that "suggests an answer and/or advises a human who is making a decision."[^1] A tool that fits that sentence raises the reversal question, whatever its internal label says.

Human involvement is factor (iii) in that same Section 3 list, next to explainability and third-party reliance; controls, the bulletin says, should be "reflective of, and commensurate with," the insurer's own assessment of the risk posed.[^2] That factor feeds the assessment as one input of five; the class a system lands in still comes from the criteria the company wrote.

Exhibit C has no override field, and the word appears nowhere in the supplement, so the evidence that review was real sits in the operational record.[^1] For claims systems, [the override test behind that record](/agentic-ai-in-claims/) has a guide of its own.

## Screen three: the outside data the system runs on

List what goes into the model that the insurer did not generate. Factor (v) in that same list is "the extent and scope of the insurer's use or reliance on data, Predictive Models, and AI Systems from third parties."[^2] The bulletin's third-party guideline 4.1 asks for diligence enough to show that decisions from an acquired system "that could lead to Adverse Consumer Outcomes will meet the legal standards imposed on the Insurer itself."[^2]

Exhibit D runs to twenty-five rows: twenty-four named data element categories, plus an open row asking for examples of any other non-traditional data elements. For each row used in training or testing it asks for the internal source or the name of the third-party vendor.[^1] A category nobody can trace to an internal source or a named vendor is itself a screening result; the field-by-field work sits in the [Exhibit D documentation playbook](/naic-ai-exhibit-d-checklist/).

## Screen four: who built it, and whether the vendor will answer

Item 4 of Exhibit C asks how the model was developed, internally or by a third party, and tells the company to include the vendor name.[^1] The screening question sits behind that: if a request about this model arrives next quarter, can the insurer answer without the vendor's permission?

The bulletin's third-party guideline, numbered 4.0, names the two terms that decide it. Section 4.2(a) covers terms giving the insurer audit rights, or audit reports "by qualified auditing entities."[^2] Section 4.2(b) covers terms requiring the third party "to cooperate with the Insurer with regard to regulatory inquiries and investigations."[^2] Both are hedged: the bulletin asks for them "where appropriate and available."[^2]

Read the missing clause the right way round. Elsewhere in the same document, the regulatory oversight and examination section headed SECTION 4 tells an insurer whose examination concerns a third-party system that it "should also expect the Department to request" the vendor contracts, including their terms on cooperation with regulators.[^2] Item 2.2 of that list, on page 9, is addressed to the insurer.[^2] Where a vendor will not permit the documentation, the gap that leaves is the insurer's, which is the case for tiering the model higher.

## Screen five: whether the error can be taken back

The primary document puts reversibility in [Exhibit B](/glossary/exhibit-b/). Its narrative form carries a suggested additional question at item 1g, naming reversibility beside autonomy and reporting impact as things a company should be able to say how it assesses.[^1] Borrowing it does not turn a suggestion into a requirement. The checklist form, on pages 9 and 10, asks at item 3k only that a company point at where its framework already addresses quantified AI risk levels.[^1] The sentence saying the exhibit's questions "are not intended to be interpreted as creating new requirements" sits in the preface to Exhibit B's narrative form, on page 7.[^1]

The distinction is between an error you can unwind and one you cannot. A quote priced wrong can be re-rated before the applicant sees it. A denial letter that has gone out, a claim closed and paid, a number carried into a financial statement: those have left the building, and what remains is a correction.

## Write the criteria down before you run them

Exhibit C's purpose line assigns the risk criteria to the insurance company, and reserves a follow-up: where a company has not already handed over its risk assessment and a model inventory, a regulator may ask for both to work out which models to question.[^1] Ownership carries a price. Under the heading Materiality and Risk Assessment, on page 2, the supplement puts the definition itself inside a reviewer's reach: as part of evaluating a company's responses, a regulator may ask what the company means by AI risk and materiality.[^1]

So the screen produces two artifacts: the list of systems that met the criteria, and the criteria themselves, dated and owned. Keep both in the exam-readiness file, and fold the criteria into the operating sequence in the [AI governance framework implementation guide](/ai-governance-framework-implementation/). The [map of insurance AI governance](/ai-governance-in-insurance/) shows where that sequence sits.

One outcome of the screen deserves naming: nothing. The supplement's instructions tell regulators that a company's AI use may be "so limited or low in inherent risk" that no further inquiry under the later exhibits is warranted.[^1] An empty list is an answer when the criteria behind it were written down and run.

## What the screen does not settle

The screen does not decide legal exposure. The supplement defines an Adverse Consumer Outcome by reference to a decision that "adversely impacts the consumer in a manner that violates" the standards a department enforces,[^1] and whether an output violates a standard is a reading of state law that belongs with counsel. Exhibit C assumes that reading has been done: item 12 asks how the model is reviewed for compliance with applicable state and federal laws, naming the unfair trade practices act and unfair claims settlement laws.[^1]

And the five lines are a method assembled here. The NAIC Model Bulletin says insurers may demonstrate compliance "through alternative means, including through practices that differ from those described in this bulletin," and that its goal "is not to prescribe specific practices or to prescribe specific documentation requirements."[^2] A different screen applied consistently answers the question as well. What does not work is writing the criteria after the letter arrives. The date on the document says which came first.

[^1]: NAIC, "Artificial Intelligence Systems Evaluation: Optional Supplemental Exhibits for State Regulators," posted as the clean AI Systems Evaluation Tool 4.0; every page carries a DRAFT watermark and a footer reading AI Systems Evaluation Tool, the old name; retrieved August 26, 2026: https://content.naic.org/sites/default/files/inline-files/AI%20Systems%20Evaluation%20Tool%204.0%20%28Clean%29.pdf

[^2]: NAIC, "Model Bulletin: Use of Artificial Intelligence Systems by Insurers," adopted December 4, 2023; retrieved August 26, 2026: https://content.naic.org/sites/default/files/inline-files/2023-12-4%20Model%20Bulletin_Adopted_0.pdf

[^3]: NAIC Big Data and Artificial Intelligence (H) Working Group, summary report for the 2026 Summer National Meeting, recording the August 13, 2026 session; retrieved August 26, 2026: https://content.naic.org/sites/default/files/national_meeting/2026-sunm-summary-h-bdaiwg.pdf