AI Governance Documents to Prepare for a Market Conduct Exam
The insurance AI exam documentation to have ready for a market conduct exam: an insurer-built readiness file of eight evidence categories, and how to record a gap.
In this article
For For compliance officers, CROs, and legal teams at insurers who have received an exam notice or expect one.
Read if You have a market conduct exam coming and need to know what AI documentation to pull, who owns it, and what to do when you cannot produce it.
A market conduct exam notice does not arrive with a syllabus. It arrives with a date, a scope, and a list of document requests that may or may not use the word AI. The NAIC AI Model Bulletin still places an insurer’s AI use inside the market conduct machinery the regulator already runs. It says the department may ask for the AIS Program, model documentation, and vendor files 1. The Evaluation Tool then shows the shape those questions take on paper 2.
Market conduct examinations are the state’s standing mechanism for inspecting how an insurer actually treats consumers, run by the departments under the NAIC’s Market Regulation Handbook 3. If the process itself is new to you, what a market conduct exam is and how it runs covers the triggers, the sampling, and the timeline; this piece assumes it and goes straight to the AI files. AI did not get its own proceeding. It got folded into that one. So the useful question is narrow: name the eight files, name who in the building can produce each, and name what happens on the ones nobody can. For the wider governance program these documents sit inside, see our AI governance in insurance guide.
The exam sequence
A market conduct exam follows a recognizable sequence, but no national timetable governs the phases below. This is an InsureAI Wire planning model. The department’s notice, scope, and instructions control the actual dates and deliverables.
| Phase | Planning cue | Key action | Owner | Deliverable |
|---|---|---|---|---|
| Exam notice received | Immediately | Log receipt, acknowledge to regulator, open exam file | Compliance officer | Acknowledgment letter + internal exam file |
| Kickoff call | After initial review | Confirm scope, document requests, timeline, contacts | Compliance + legal | Kickoff minutes + confirmed document list |
| Document collection | After scope is confirmed | Pull AIS Program, inventories, validation records, vendor contracts | Compliance + IT + actuarial | Document index with Bates numbers |
| Internal review | Before submission | Gap check against the request and applicable authorities | Compliance + legal | Gap list with owners and remediation dates |
| Submission | By the department’s deadline | Deliver documents, log transmittal, confirm receipt | Compliance officer | Transmittal letter + delivery confirmation |
| On-site or interview | If requested | Prepare witnesses, run mock interviews, document Q&A | Compliance + business leads | Interview prep memo + Q&A log |
| Findings response | After findings issue | Draft response and corrective action plan if needed | Legal + compliance + CRO | Response letter + CAP |
The worksheet below mirrors this table with editable columns for your own deadlines and owners.
An eight-part readiness file
We organize AI exam readiness into eight evidence categories: the written AIS Program and its adoption record, the AI system inventory, high-risk system documentation, data records, vendor contracts and due diligence, consumer notices and complaint records, governance minutes, and incident or override records. This is a preparation framework assembled from the Model Bulletin and Evaluation Tool. It is not a uniform request list, and an examiner may ask for fewer, more, or different materials.
Items 3 and 4 line up with the Evaluation Tool’s Exhibits C and D, the closest published list of what a regulator may ask about a model. Item 2 is the register behind Exhibit A: it supports the counts in version 4.0 2, and the version 5.0 draft asks for the model inventory directly 4. The remaining categories come from the Model Bulletin’s program expectations, including its call for inventories and descriptions of the models themselves 1. Every one of them is something a person can hold in hand and read a date off.
| # | Documentation item | What the examiner sees | What counts as solid | Gap sign |
|---|---|---|---|---|
| 1 | AIS Program document | A written AI Systems Program with adoption date, review frequency, and board approval | Dated minutes showing board or committee adoption; annual review entries | Undated document, or one with no review history |
| 2 | AI inventory (feeds Exhibit A) | A list of every AI system, with operational area, owner, vendor flag, and last validation date. Exhibit A in version 4.0 asks for counts and use cases by operational area rather than the list itself, and the version 5.0 draft adds the model inventory to its requests. Either way the answer starts from the list | Each entry has a named owner and a validation date inside your stated revalidation interval | Systems listed without owners, or validation dates with no interval to measure them against |
| 3 | High-risk system documentation (Exhibit C) | Per model: name and version, type, implementation date, built or bought and by which vendor, risk classification, known risks and limitations, whether it automates, augments, or only supports, how it was validated and is monitored, last test date, and any regulatory action taken over it | Dated validation reports, bias and unfair-discrimination test results, a last-testing date that is not years old | Validation reports with no dates, or bias testing that says “N/A” |
| 4 | Data records (Exhibit D) | Not a free-text lineage narrative: a fixed list of data-element categories: age, gender, ethnicity/race, geocoding, geo-demographics, education, income, criminal convictions, facial analysis and the rest: where you mark which ones feed your models and whether each came from inside the company or from a named third party | A defensible answer for every category you checked, and a data dictionary behind it | Data sources listed as “various internal systems” with no further detail |
| 5 | Vendor contracts and due diligence | Contracts with audit rights, model documentation clauses, monitoring provisions | Signed contracts with specific AI audit clauses; due-diligence files with dates | Contracts signed before AI was added, with no amendment covering AI |
| 6 | Consumer notice and complaint log | Records of AI-related consumer disclosures and any complaints or appeals | Notice templates, mailing or portal logs, complaint register with AI flag | No AI-specific complaint category, or complaints handled in general queue only |
| 7 | Governance meeting minutes | Minutes from AI governance committee or risk committee meetings | Dated minutes with AI agenda items, attendance, and action items | Minutes with no AI items, or attendance that does not include the model owner |
| 8 | Incident and override log | Records of AI incidents, near-misses, and human overrides | Dated entries with root-cause analysis and remediation | Empty log, or entries that say “no issues found” without detail |
Rows 2 and 3 are the two that get pulled first, and each is a whole exercise on its own: row 2 rests on the inventory built in our Exhibit A inventory playbook, and the validation and drift records behind row 3 in the AI model monitoring playbook.
They also need a number you have to supply yourself. Row 2 turns on a revalidation interval and row 3 on how often bias testing repeats, and neither the Model Bulletin nor the Evaluation Tool sets one. Annual is a common working assumption for models that shape pricing or claims, but it is an example, not an authority. The interval is yours to set and defend, and the defensible version is written down in the AIS Program with a reason attached rather than inferred from whenever the last report happens to be dated.
The gap sign column is where most first passes stop being comfortable. That is the column doing the work. An examiner tests whether the program operates; the useful thing to be able to show is that you already know which parts do not, and since when.
Where to start before any notice arrives
The sequence table above starts at the notice. The readiness file does not, and neither does its gap sign column, which is built to be run against your own files at any time. The production test at the end tells you which of the eight you cannot produce today; this section is what to do with that answer. Sort the repairs by what a late start costs each item rather than by a calendar, because until a department supplies one there is none.
Start with the two where late costs everything. Items 1 and 2 fail differently from the rest. With no written AIS Program there is nothing to hand over and no smaller answer to give instead; the request lands on empty. Without the inventory, the counts Exhibit A wants can only be estimated. Both are mostly authoring work, which makes them cheap relative to what their absence costs. Writing the program now does not give it a review history, but it moves item 1 from missing to dated, and the history has to start somewhere.
Then the ones where late costs evidence you cannot buy back. Validation and monitoring records for the systems you have classified as high risk, governance minutes, and the incident and override log are worth whatever their history is worth, and nothing done later supplies the earlier dates. The complaint register belongs here too. The table wants an AI flag on the register, and flags get attached when the complaint is taken; a queue that never carried one can be re-read, but what comes out is dated to the reading rather than to the complaint. Item 5 sits upstream of the whole band, because the contract decides whether the validation records exist to be collected at all, and an amendment adding audit rights needs a vendor’s signature.
Leave the work that costs the same whenever it starts. The Exhibit D data-element answers, the data dictionary behind them, and the consumer notice templates are documentation exercises against systems you already run. Delivery logs come with them, provided the notices went out; if they did not, what is missing is the disclosure itself rather than the paperwork. None of it is quick, but waiting does not inflate it, which is why it should go last.
One limit sits under all of it. Priority ordering cannot conjure a record that only accumulates: a monitoring history reaching back years is either behind you or it is not, and resequencing will never supply the missing stretch. Backfilling the file after the fact is the one response that turns a documentation gap into a credibility problem. The gap record below is the form that case takes instead.
The gap record: what to do when you cannot produce it
Every carrier has gaps. The expensive version is discovering them in the same week the examiner does. The gap record is a worksheet for naming one first, in a form that reads as management rather than apology.
The two rows below are illustrative, not a real company’s data.
| Gap # | Exam request or finding | What we could not produce | Why | Interim control | Owner | Due date |
|---|---|---|---|---|---|---|
| G-01 | Produce validation records for the claims triage model | No validation performed since 2025 rebuild | Model rebuilt by vendor without a re-validation clause in the contract | Manual review of all triage decisions until validation completed | Chief Actuary | 2026-Q3 |
| G-02 | Show proxy-discrimination screening for geo score | No proxy screen documented | Geo score added in 2024, before proxy screening was part of the standard intake | Run the disparate-impact test now; document methodology and results | Model Risk | 2026-Q4 |
The pattern is the same for every gap: name it, explain why it exists, assign an interim control, name the owner, and set a due date. The interim control is the load-bearing column. “We are aware of the issue and are working on it” describes a feeling about the gap; “all triage decisions are manually reviewed until validation is completed” describes what happens to a policyholder in the meantime, which is the thing an examiner can test.
Both illustrative gaps above are vendor-shaped, which is the common case. The contract that governs whether you can get validation records out of a vendor at all is usually signed years before anyone asks, and our AI vendor risk assessment checklist covers the clauses that decide it. For the data-lineage side of row G-02, the NAIC Exhibit D data documentation playbook works through what naming a data source actually requires.
What the NAIC Evaluation Tool means for exam prep
What each exhibit of the NAIC’s AI evaluation tool asks, both in version 4.0, the text used in the twelve-state pilot running through September 2026 56, and in the version 5.0 draft put out for comment after August 31, is covered in our exhibit-by-exhibit guide to the supplement.
Run a 30-minute production test
If you have not received an exam notice, run the documentation checklist against your own files. Pick one item and try to produce it in 30 minutes. If you cannot, that is a gap. Write it down with an owner and a due date. Do this for all eight items. The result is your gap record, ready before the letter arrives.
If the notice has already arrived, read the dates in it first, then handle the two administrative deliverables: the acknowledgment letter and the internal exam file, then the kickoff minutes. Run the same 30-minute test anyway, on the items your confirmed scope actually reaches. Finding the hole during collection week costs you a gap record. Finding it during the interview costs you the answer.
A caution about the list itself: your exam’s scope is set by the department, not by this article. An exam can arrive pointed entirely at claims handling and never open the inventory, or it can start with the AIS Program and stay there for six weeks. Eight items is what the Bulletin and the Evaluation Tool make reachable. What actually gets reached is the examiner’s call.
Footnotes
-
NAIC Model Bulletin, “Use of Artificial Intelligence Systems by Insurers,” adopted December 4, 2023: https://content.naic.org/sites/default/files/inline-files/2023-12-4%20Model%20Bulletin_Adopted_0.pdf ↩ ↩2
-
NAIC, “AI Systems Evaluation Tool 4.0,” 2026: https://content.naic.org/sites/default/files/inline-files/AI%20Systems%20Evaluation%20Tool%204.0%20%28Clean%29.pdf ↩ ↩2
-
NAIC, “Market Conduct Regulation,” last updated May 15, 2025: https://content.naic.org/insurance-topics/market-conduct-regulation ↩
-
NAIC, “Artificial Intelligence (AI) Risk Evaluation Supplement,” version 5.0 exposure draft, Exhibit A Part Two: https://content.naic.org/sites/default/files/inline-files/ai-risk-evaluation-supplement-v5.0-clean.docx ↩
-
NAIC, “AI Systems Evaluation Tool Pilot: Pilot Project Background,” pp.1 to 2 (participating states, p.1; March to September 2026 window, p.2): https://content.naic.org/sites/default/files/inline-files/Pilot%20Project%20Summary_1.pdf ↩
-
NAIC Big Data and Artificial Intelligence (H) Working Group, materials for the August 31, 2026 meeting, p.11 (pilot slide summarizing changes from v4.0 to v5.0) and p.37 (ACLI letter of July 21, 2026, referring to “the version of the Tool used in the pilot (v4.0)”): https://content.naic.org/sites/default/files/call_materials/materials-bdaiwg083126.pdf ↩
The Bottom Line
- The eight-part readiness file and sequence in this playbook are InsureAI Wire's preparation framework. A department sets the actual scope, requests, and dates.
- The Model Bulletin expects insurers to have a written AIS Program, and tells them an examiner can ask about it. An undated program with no review history answers that question badly before anyone opens the inventory.
- An inventory entry without a named owner and a dated validation record cannot be defended in an exam, whatever validation interval you set.
- A document you cannot produce still has a defensible form: the gap written down with an owner, a due date, and an interim control that says what protects the policyholder in the meantime.
You have reached the evidence stage.
Return to the reading map to choose another route or business line.
Choose another reading path →
Simon Li · Founding Editor
I write InsureAI Wire and maintain its 51-jurisdiction tracker. Most of the work is reading: NAIC working group papers, state bulletins, bills, court filings, and public comment letters. Every claim on the site carries the document it came from, so you never have to take my word for it.
Free · Weekly
Track these developments weekly
Get the InsureAI Wire dispatch in your inbox. Free, sourced, no spam.
Free weekly · No spam · Unsubscribe anytime
Related reading
The NAIC AI Risk Evaluation Supplement, Exhibit by Exhibit
What each exhibit of the NAIC AI evaluation tool asks in version 5.0, the draft out for comment, and what changed from 4.0.
Inside the NAIC AI Model Bulletin
What the NAIC AI Model Bulletin is, how adoption works, what belongs in a written AIS Program, and which implementation guide to use next.
Model Data Documentation for NAIC Exhibit D
A playbook for insurers preparing NAIC Exhibit D responses: document the 25 data elements, show internal and third-party sources, and close the data gap before the exam.
How Insurers Assess AI Vendor Risk
A NAIC-aligned AI vendor risk assessment checklist: a twenty-question due-diligence questionnaire, contract clauses, and the monitoring that stays with the insurer.
Information aggregation and analysis, not legal advice. See our disclaimer.