NAIC Vendor Registry Draws Eleven Comment Letters, Then a Regulator-Only Revision Round
Eleven comment letters came in on the third-party framework that the NAIC’s Third-Party Data and Models (H) Working Group exposed July 8. The first comment on the record at its August 12 session in Columbus questioned the registry itself. Scott Harrison of the American InsurTech Council said the council is not wholly supportive of a registry. He gave four reasons: a new bureaucratic infrastructure, an unclear benefit to the vendor, a public registry naming the third parties carriers do business with, and an existing review process for property and casualty rating and underwriting that appears to work.
Michael McKenney of Pennsylvania and Gennady Stolyarov of Nevada answered that one in the room. A public registry should not be a problem, they said: which third parties an insurer uses in rating and underwriting is already public in the states, and the proprietary part of a model is what is treated as confidential. McKenney put a number on the gap the voluntary registry is meant to close. Pennsylvania takes 7,000 property and casualty rate filings, and the insurers making them are not privy to third parties’ data sets and model details. The framework exists, he said, to give regulators an avenue straight to the third party, and anything else would take legislation.
Kristin Abbott of the American Property Casualty Insurance Association called the draft a meaningful improvement, then questioned whether a voluntary registry would work that way in practice, and said insurers should not lose access to third-party tools because a vendor declines to participate. Iowa Insurance Commissioner Doug Ommen has a different problem: third-party vendors have been filing as advisory organizations, which they are not, leaving him to choose among revoking the registration, denying it, requiring withdrawal, or finding an alternative.
Laura Panesso of ISO Verisk asked that the annual attestation’s Section 3B be softened so the data and models are “reviewed in conjunction with” applicable insurance laws rather than certified to comply with them, since the insurer’s use decides which laws apply. Bryan Rehor of ZestyAI said a vendor officer cannot make that certification for every state where a customer deploys a score, because the vendor does not control which rating plan it enters. Wanchin Chou of Connecticut said regulators want vendors to sign off on what they built, because industry and vendors have staff regulators do not. What a vendor can attest to, Rehor said, is the solution as licensed. Chou agreed insurers carry their own responsibility, which is where a carrier’s own vendor diligence still sits.
Rehor said ZestyAI, which sells property analytics, supports most of the draft, prefers a single NAIC-hosted registry to the state-by-state patchwork, and endorses governance expectations tied to the NAIC’s AI Principles and Model Bulletin. One more ask was structural: Section 2b, which lets a regulator bar every insurer in a state from a vendor’s models, needs a materiality threshold, written notice and a cure period.
Duplication is the exchange we read as unresolved. Lindsey Stephani of NAMIC asked the working group to coordinate with the Market Conduct Regulation Modernization (D) Working Group, said the proposed frameworks duplicate existing filing rules and practices, and cited Arizona’s new advisory-organization-type category for data and model vendors. Chou asked NAMIC for a specific list, and said the absence of an NAIC framework made states creative. Stephani also said NAMIC members have not reported problems getting information from third parties, and that the gap is a communication pathway, since states do not consistently protect the proprietary material vendors hand over.
Chair Jason Lapham of Colorado handed the letters to the drafting group. Ideally, he said, a finalized framework would be ready for consideration at the Fall National Meeting, though that depends on the next three or four months of work. He reported to the Innovation, Cybersecurity, and Technology (H) Committee two days later. The letters ran to five general themes: an attestation covering compliance vendors do not control, uncertain confidentiality protections across states, whether registration is voluntary given the consequences of use restrictions, the need to define material change objectively, and duplication of existing state filing and oversight processes.
The August 12 minutes are stamped “Draft Pending Adoption” on every page, inside a Summer National Meeting packet the NAIC updated August 31. The working group’s next session is scheduled for September 16, closed, and listed for discussion of revisions to the “Third-Party Property/Casualty Pricing and Underwriting Regulatory Framework.” The stated reason: the discussion will involve “specific companies, entities or individuals.” The minutes record two earlier closed sessions on framework drafts, April 9 and June 29, under paragraph 3 of the NAIC’s Policy Statement on Open Meetings.
Regulators answered several of the objections at the meeting. The framework text has answered none of them, and the September 16 session is closed to the people who wrote the letters.
Official document
content.naic.org →The instrument itself, issued by a government, court, legislature, or standard-setting body.