Market Conduct Examinations, Explained
A market conduct exam is how state regulators inspect how insurers treat consumers: what triggers one, what examiners ask for, and how it differs from a financial exam.
For Newcomers to insurance regulation who hear "exam" and think of a financial audit, plus anyone facing a first market conduct notice.
Read if The market conduct exam keeps turning up as the answer to "how is this rule enforced," and you want to see the proceeding itself.
Market conduct examinations are how state insurance departments check whether a company is treating its policyholders the way the law requires. A market conduct exam reaches pricing, sales, claims payment, and complaint handling: the department sets a scope, the company produces documents, examiners read the files against the state’s rules, and a finding gets written down at the end.
People arriving from other industries tend to hear “exam” and picture a financial audit, or a rare event like a raid. It is neither of those. This is routine supervision, with its own paperwork and its own way of turning a suspicion into a finding, and knowing how it runs explains a good deal of what else happens in insurance regulation. If the state-by-state system underneath it is also new to you, how U.S. insurance regulation actually works covers the structure this proceeding sits inside.
The other half of state supervision
State insurance regulation splits into two channels. One watches solvency: whether the company holds enough money to pay its claims. That is the financial examination, run on actuarial schedules and accounting statements. The other watches behavior: whether the company charges fair rates, sells honestly, pays valid claims promptly, and handles complaints the way the law says it must. That is market conduct regulation, and per the NAIC’s own description, it “inspects the manner in which insurers and producers interact with consumers, fulfill contractual obligations, and adhere to state laws and regulations, in contrast to solvency regulation.”1
The market conduct examination is that second channel’s on-site form, and it is where most of AI governance in insurance stops being a policy document and starts being evidence someone reads. A team of examiners, from one state or several acting together, selects a company, defines a scope, and reviews how the company operated inside that scope. The output is a set of findings about practices, and findings carry consequences: corrective action plans, restitution to policyholders, fines, consent orders. Where state law makes the final report public, an exam is also how a company’s claims-denial pattern or complaint history becomes a matter of record.
One distinction matters before anything else. An exam is supervision; enforcement is a separate step that may or may not follow, and plenty of exams close with findings resolved as recommendations or required corrections. But the same machinery is what an enforcement case is built from, so the line between “routine exam” and “the beginning of something worse” is drawn by what the examiners find, not by which form letter opened the file.
What triggers one
Exams are not random, and they are not purely scheduled either. They run on a mix of three triggers.
The first is data. Regulators collect standardized information that lets them spot outliers before anyone files a complaint. The main instrument is the Market Conduct Annual Statement, which collects uniform claims and underwriting data across lines of business and lets a department compare one company’s patterns against the industry’s.2 A carrier whose claim denials or non-renewals run well outside the band is a carrier someone will want to look at.
The second is complaints. Consumer complaint monitoring is one of the standing oversight methods state departments run, and the NAIC keeps national databases that track complaints and regulatory actions across jurisdictions.1 A cluster of similar complaints, say, a pattern of delayed claim payments after a storm, is the classic exam trigger.
The third is targeting. A state can simply decide to examine a practice across several companies at once: how the industry handles a new kind of claim, whether a new underwriting variable is being used fairly. These targeted exams are how regulators respond to something new before complaint patterns have time to form.
What the examiners read
The scope letter defines the territory, but the method is consistent: sample the files, read the procedures, compare the two.
A typical exam pulls a sample of claim files and reads them end to end, from first notice to payment or denial, checking each step against the state’s claims-handling rules. It works through the complaint log to see whether each complaint was acknowledged, investigated, and answered on the required clock. It sets the policy forms and advertising against what the company actually sells, testing whether the two match. And it reads the procedure manuals against the files themselves, because the gap between what a company says it does and what its files show is where findings live.
The working framework for all of this is the NAIC’s Market Regulation Handbook, which standardizes how exams are scoped, sampled, and documented across states.3 That handbook is why an exam in one state looks structurally like an exam in another, even though each state’s law underneath it differs.
The timeline, in plain terms
An exam runs in a fixed order. It opens with a notice and a document request list. The company produces, the examiners review and sample, and follow-up requests narrow in on whatever the first round surfaced. At the end, the company gets a draft of the findings and a window to respond before the report is finalized and, where state law provides for it, published.
Two properties of that timeline deserve respect. The first is that the document requests arrive on deadlines, and “we cannot find it” is itself a finding: the Handbook’s general examination standards ask whether a company’s records are “adequate, accessible, consistent and orderly,” and whether it “cooperates on a timely basis with examiners.”3 Both are scored. The second is that the response window at the draft stage is the company’s best chance to correct factual errors and shape the record. Companies that treat the draft report as a formality usually regret it.
Why this machinery keeps showing up in new places
Once the exam is understood as the standard instrument, a pattern in recent regulation makes sense: when a new consumer risk emerges, states do not invent a new proceeding for it. They extend the exam. Cybersecurity oversight moved into market conduct protocols. AI went the same way. The NAIC AI Systems Evaluation Tool is functionally an exam instrument: a structured way for an examiner to ask for an AI inventory, testing records, and vendor files inside the market conduct process that already exists.
So the practical reading of almost any new insurance consumer rule is the same. The obligation is new; the proceeding that tests it is old. What an exam reaches for when the subject is AI, the eight documents, the ownership question, and what to do with a gap you cannot close, is laid out in a companion playbook on AI documentation for a market conduct exam. This piece describes the proceeding. That one is the list of what to have on the table when it opens.
What this describes is the shape of the process, and the shape holds nationally because the Handbook standardizes it. What it cannot tell you is the part that decides outcomes: the claims-handling clocks, the record-retention periods, the penalty ranges, and the scope of the department’s authority all sit in your state’s own statutes and regulations, and they differ. Read this for the shape of the process, then read your state’s insurance code for the rules being tested inside it, starting from what your state has on the books for AI. The examiners work from both, and only one of them is the same everywhere.
Footnotes
-
NAIC, “Market Conduct Regulation,” insurance topics page, last updated May 15, 2025: market conduct regulation “inspects the manner in which insurers and producers interact with consumers, fulfill contractual obligations, and adhere to state laws and regulations, in contrast to solvency regulation,” and identifies the Market Regulation Handbook and the Market Conduct Annual Statement as the key instruments standardizing examinations. https://content.naic.org/insurance-topics/market-conduct-regulation ↩ ↩2
-
NAIC, “Market Conduct Annual Statement,” insurance topics page, last updated September 25, 2025: MCAS was developed in 2002 and now collects uniform claims and underwriting data across 13 lines of business; the NAIC’s market conduct regulation page records that it “has been adopted by nearly all states” and lets regulators “identify underwriting and claim payment patterns of individual companies and the industry as a whole.” https://content.naic.org/insurance-topics/market-conduct-annual-statement ↩
-
NAIC, Market Regulation Handbook: the standard reference examiners work from, setting out how market conduct examinations are scoped, sampled, conducted, and documented so that findings are comparable across states. The Handbook itself is a priced NAIC publication (product page: https://content.naic.org/prod_serv_marketreg.htm); the freely published companion, the 2025 Examination Standards Summary, is “a compilation of the market conduct examination standards found in the 2025 edition of the Market Regulation Handbook” and carries the Handbook’s own caveat that it “does not represent all examination standards, methodologies and areas of review that may be utilized by a department of insurance.” Chapter 20 (General Examination Standards, Operations/Management) is the source of the record-keeping standards quoted above, at standards 7 and 9. https://content.naic.org/sites/default/files/publication-mes-hb-market-handbook-examination.pdf ↩ ↩2
The Bottom Line
- A market conduct exam inspects conduct, not capital. The financial exam asks whether the insurer can pay. The market conduct exam asks whether it treats policyholders fairly while doing so.
- Exams run on triggers, not just calendars: complaint patterns, data flags like the Market Conduct Annual Statement, or a targeted scope aimed at one practice.
- The evidence is documents: sampled claim files, complaint logs, form filings, procedure manuals. The finding, if there is one, ends in a written report, a corrective plan, or a consent order.
- This is the machinery most insurance consumer rules actually move through, which is why new obligations keep arriving in market conduct form.
How Insurers Assess AI Vendor Risk
A practical NAIC-aligned checklist for AI vendor risk assessment: due-diligence questions, contract clauses, and the ongoing monitoring that stays with the insurer.
Continue →
Simon Li · Founding Editor
Much of his time goes into reading NAIC meeting papers, state bulletins, bills, court filings, and public comments. He also keeps the site's 51-jurisdiction tracker up to date.
Free · Weekly
Track these developments weekly
Get the InsureAI Wire dispatch in your inbox. Free, sourced, no spam.
Free weekly · No spam · Unsubscribe anytime
Related reading
AI Governance Documents to Prepare for a Market Conduct Exam
The insurance AI exam documentation to have ready for a market conduct exam: an insurer-built readiness file of eight evidence categories, and how to record a gap.
AI Model Monitoring After the Model Goes Live
A playbook for insurers on AI model monitoring, validation, drift detection, and retesting records that satisfy NAIC Model Bulletin and Exhibit C expectations.
Does AI Insurance Regulation Apply to You? A Plain-Language Self-Check
Five questions that flag when the AI regulations for insurance companies may reach your business, and what to review before treating the answer as settled.
The NAIC Insurance Data Security Model Law, Explained
NAIC Model Law 668 binds where a state enacts it: a written security program, third-party oversight, breach investigation, and notice to the insurance commissioner.
Information aggregation and analysis, not legal advice. See our disclaimer.