Insurance compliance
Insurance compliance — state DOI rate filings, NAIC AI bulletin, GLBA, ECOA/Fair Housing, HIPAA (health lines), audit retention.
Insurance regulation is state-led with federal overlays — the regulatory frame for AI in insurance is the most fragmented of any major industry. NAIC coordinates model bulletins; each state DOI adopts, adapts, or supplements them.
Regulatory frame
State DOI rate filings
Any rating, underwriting, or claims-decision AI
Filed-factor citation per decision, retention with the rate filing
NAIC Model Bulletin on AI
Adopted by ~25 states (and growing) as of 2026
Governance documentation; bias monitoring; inventory of consequential AI
NY DFS Insurance Circular Letter No. 7 (2024)
Insurers operating in NY using AI/ECDIS in underwriting
Quantitative disparate-impact analysis; fairness testing across protected classes
CO SB21-169
Insurers using external consumer data and algorithms in CO
Annual testing for unfair discrimination; testing methodology disclosure to division
GLBA / Safeguards Rule
All non-public personal information processing
Data protection program; incident reporting; vendor diligence
HIPAA
Health-line carriers (group health, supplemental)
PHI handling, BAA in place, audit logs
ECOA / Fair Housing Act
Credit-tied insurance products and homeowners
Adverse-action notices, disparate-impact testing
State unfair-claims-practice acts
All claims handling
Audit retention; documented basis for denial
State DOI rate filings
Most consequential surface for insurance AI:
Premium varying more than ~1.25× across otherwise similar applicants without filed factor → DOI flag
Rate filings must include the model methodology and the variables used
Some states (NY, CO, CA) require ongoing post-deployment monitoring evidence
Stratix evaluation evidence supports rate-filing compliance:
Filed-factor citation per premium — every recommendation cites a variable in the filing
Disparate-impact ratio computed per cohort — frozen at filing, tracked in production
Audit log retained for the same period as the rate filing (typically 5 years; some states longer)
NAIC Model Bulletin on the Use of AI Systems by Insurers
Adopted in some form by Alabama, Connecticut, Illinois, Iowa, Kentucky, Louisiana, Maryland, Massachusetts, Michigan, Nevada, New Hampshire, New Jersey, North Dakota, Pennsylvania, Rhode Island, Vermont, Virginia, Washington, West Virginia, others as of 2026. Common elements:
Written AI Systems Program ("AIS Program") covering governance, risk management, internal controls
Inventory of "consequential" AI systems
Pre- and post-deployment testing for accuracy, bias, drift
Ongoing monitoring with documented thresholds
Third-party AI vendor diligence
Stratix evaluation evidence aligns with AIS Program requirements:
Pre- and post-deployment scenario suite with frozen baselines
Drift monitoring on judge scores and rule pass rates
Vendor diligence package — Stratix tenant isolation, security review on request
NY DFS Insurance Circular Letter No. 7 (2024)
NY DFS has the strictest current operationalization. Insurers using "external consumer data and information sources" (ECDIS) and AI systems in underwriting and pricing must:
Conduct quantitative testing for unfair or unlawful discrimination
Document data sources, data lineage, and the proxy-discrimination analysis
Maintain ongoing testing, not just a one-time validation
Stratix evaluation evidence shape:
Group-fairness scorers run on every underwriting evaluation; results retained
Drift report on disparate impact ratio over time
Source-of-data labels on every input feature in trace metadata
CO SB21-169 Insurance regulation
Colorado was first to enact algorithmic-fairness legislation for insurance. Effective regulations require:
Insurers to test their algorithms and external data for unfair discrimination
Disclosure of testing methodology to the Colorado Division of Insurance
Annual reporting
Stratix evaluation evidence shape:
Annual fairness audit pulled from frozen scenario suite + production sampled traces
Rule-engine config version locked at filing time
GLBA Safeguards Rule
Modernized GLBA Safeguards Rule (effective 2023) requires:
Designated qualified individual responsible for the security program
Risk assessments documented in writing
Access controls; encryption of NPI in transit and at rest
Service-provider oversight
Incident response with notification to FTC for breaches > 500 consumers
Stratix supports:
Encryption at rest, TLS in transit
Audit trail of who accessed what
DPA available with security commitments and breach notification clauses
HIPAA (health insurance lines)
For group health, supplemental health, dental, vision lines processing PHI:
BAA required between carrier and Stratix (Enterprise tier)
Tenant isolation enforced
BYOK custom models for PHI processing recommended
ECOA, Fair Housing Act
For credit-scored insurance and homeowners products:
Adverse-action notice must include specific reasons; AI-generated reasons must be human-readable
Disparate-impact testing required
Records retained for at least 25 months (ECOA) or 24 months (FHA) — longer per state
Unfair-claims-practice acts
Every state has one. Common requirements:
Prompt acknowledgment of claims
Documented basis for any denial
Good-faith claim handling
Records retained typically 3-7 years post-claim closure
Recommended setup
Enterprise tier with executed DPA + BAA where health lines apply
SSO with role-based access; underwriter / adjuster / SIU role separation
State-aware deployment — rate filing-specific evaluation suites per state
Citation-existence hard gate on every customer-facing output
Audit retention matching the longest applicable state requirement (default to 7 years)
Annual fairness audit with documented methodology aligned to NY DFS / CO SB21-169 standards
AI inventory maintained per NAIC Model Bulletin
See also
Last updated
Was this helpful?