Enterprise AI Policy Design for an Insurance Carrier or Holding Company - NAIC Form B Implications
Enterprise AI policy at a rated carrier or holding company is not an HR document. It is the governance instrument that survives an AM Best rating meeting, a NAIC AI Systems Evaluation Tool response, a Colorado Reg 10-1-1 compliance report, a state DOI market-conduct exam, a NAIC Form B holding-company disclosure cycle, and the next reinsurance treaty renewal - all anchored to the same document and read consistently by every external validator. The policy stack at L5 covers seven distinct policy domains (AI usage, third-party AI, data governance, fairness, monitoring and validation, incident response, plus an AI ethics and conduct addendum), each with named owner, review cadence, escalation path, and the holding-company-level disclosure language that NAIC Form B requires when the carrier's AI program is material to the holding company's enterprise risk picture. This lesson is the enterprise AI policy design pattern: the seven-domain policy stack, the holding-company NAIC Form B implications, the sample policy document outline a rated-carrier general counsel will actually sign, the cross-policy integration with the chief actuary's ASOP-compliant work product and the chief compliance officer's regulatory calendar, the AISET Exhibits A/B/C/D mapping into the policy domains, the treaty-broker AI-clause linkage that turns the policy into a cession-language asset, and the periodic-refresh discipline that keeps the policy current rather than aspirational.
The Seven-Domain Enterprise AI Policy Stack
The enterprise policy stack is structured so each domain has a clear scope, a named executive owner, and a clean interface to adjacent domains without overlap. The seven domains:
Domain 1 - AI Usage Policy. Defines what AI capability is in scope for which use cases, which AI capabilities are prohibited, which require explicit chief AI officer approval, and which require CRO and chief compliance officer sign-off. Covers underwriting, claims, pricing, distribution, customer service, fraud, marketing, and internal operations. Named owner: Chief AI Officer. Review cadence: annually with quarterly amendments for new use cases.
Domain 2 - Third-Party AI Policy. Defines vendor evaluation framework, NAIC Model Bulletin §4 conformance requirements, vendor scorecard, concentration cap (28% per Lesson 1), contractual flow-downs of governance obligations, exit-clause requirements, data-portability requirements, vendor incident-response coordination. Named owner: Chief AI Officer with CRO co-authority on concentration risk. Review cadence: annually with vendor-by-vendor refresh quarterly.
Domain 3 - Data Governance Policy. Defines the data estate (policy data, claims data, third-party data including ECDIS, telematics, IoT, satellite, weather), data quality standards (ASOP-23 alignment), lineage documentation, retention, consent and privacy (GLBA Safeguards §314 (2023 Amended), HIPAA §164.502/504/400-414 for L&H, CCPA/CPRA and state privacy laws CPA, VCDPA, CTDPA, UCPA, TIPA), data-sharing agreements, ECDIS inventory under Colorado Reg 10-1-1. Named owner: Chief Data Officer. Review cadence: annually with quarterly inventory refresh.
Domain 4 - Fairness and Anti-Discrimination Policy. Defines bias-testing methodology, fairness pipeline, NY DFS Circular Letter 2024-7 (July 11, 2024) proxy test posture, Colorado SB 21-169 alignment, state anti-discrimination compliance (Connecticut MC-25-8, Nevada Bulletin 24-006, and the broader NAIC Model Bulletin §4.1-§4.4 expansion to 25+ jurisdictions by mid-2026), FCRA §615 adverse-action workflow for consumer lines, MHPAEA NQTL Tri-Agency 2024 final-rule analysis for L&H behavioral claims. Named owner: Head of Responsible AI or Chief Compliance Officer. Review cadence: semi-annually with model-specific retesting on change.
Domain 5 - Monitoring and Validation Policy. Defines model-card refresh cadence, drift monitoring, performance benchmarking, validation discipline before promotion to production, retirement criteria, champion-control parallel-run protocols, ASOP-56 modeling discipline alignment, ASOP-41 communication discipline for model outputs consumed by other functions. Named owner: MLOps Lead with Chief Actuary review. Review cadence: annually with quarterly model-by-model review.
Domain 6 - Incident Response Policy. Defines AI incident categories (model failure, data quality breach, vendor outage, regulatory action, customer-impact event, adverse media), incident-response runbook, tabletop exercise cadence (quarterly), communications discipline, regulator notification posture, board notification triggers. Named owner: Chief AI Officer with CRO co-authority. Review cadence: annually with tabletop after-action refinements.
Domain 7 - AI Ethics and Conduct Addendum. Defines acceptable-use principles, employee conduct on AI tools, customer-communication standards on AI use, brand and reputation considerations, leadership conduct on AI public statements. Named owner: General Counsel with Chief AI Officer input. Review cadence: annually.
The AISET Exhibits Mapped Into the Seven Domains
The NAIC AI Systems Evaluation Tool (AISET) carries four exhibits the carrier's policy must respond to. Exhibit A - program-level governance - pulls from Domains 1, 2, and 7. Exhibit B - talent and governance discipline including credentialed-staff progression and AI committee minutes - pulls from Domain 1 (governance overlay) and the annexes (AI committee charter, named-role definitions). Exhibit C - model-level evaluation - pulls from Domain 5 (model card, drift monitoring, validation) plus Domain 4 (fairness testing on the specific model). Exhibit D - incident and remediation history - pulls from Domain 6 (incident runbook, tabletop after-actions). The 12-state pilot through early 2026, the September-October 2026 re-exposure window, and the NAIC Fall National Meeting November 2026 adoption define the response calendar; the policy domains map to the response packet so the carrier assembles the AISET response from existing documents rather than building it ad hoc on request.
The NAIC Form B Holding-Company Disclosure Implications
NAIC Form B is the holding-company annual filing that documents the enterprise risk profile of the insurance holding-company system. When the carrier's AI program is material to enterprise risk, Form B disclosure language has to address: the scope of AI use across the holding-company system (which entities use AI for which functions), the governance posture (the seven-domain policy stack, AI committee structure, board oversight), material vendor relationships (third-party AI vendors that exceed materiality thresholds, including concentration disclosure), regulatory posture (AISET response status, Colorado Reg 10-1-1 (Oct 15, 2025 expansion; July 1, 2026 first compliance report), state DOI bulletin posture, FCRA workflow, MHPAEA workflow), incident history (material AI-related incidents in the disclosure year), and ORSA integration (how AI risk integrates with the carrier's Own Risk and Solvency Assessment).
The disclosure language is reviewed by the chief compliance officer, general counsel, chief AI officer, CRO, and chief financial officer before filing. The carrier's holding-company structure determines what level of detail is required - a top-tier holding company filing Form B for multiple insurance subsidiaries provides system-level disclosure; subsidiary-level filings provide entity-level detail. The discipline is consistency: the Form B disclosure has to align with the AM Best analyst narrative, the AISET response, the Colorado Reg 10-1-1 compliance report, and any state DOI bulletin responses, because regulators and analysts cross-reference these documents.
The Policy Document Outline the General Counsel Signs
The sample enterprise AI policy document is approximately 35-55 pages, structured to be read both as an integrated document and as separately-accessible domain policies. Outline:
Front matter (3-5 pages): executive summary, policy purpose and scope, governance structure overview (AI committee, executive roles, board oversight), definitions, applicability to holding-company entities, effective date, review cadence, document control (version, change log, owners).
Domain 1 - AI Usage (5-7 pages): permitted use cases by function (UW, claims, pricing, distribution, customer service, fraud, marketing, internal ops); prohibited use cases (autonomous customer-facing decisions in certain regulated contexts, customer impersonation, undisclosed AI generation in regulated communications); approval-required use cases with named approver; exception process; documentation requirements (algorithm inventory, model card, bias testing as applicable).
Domain 2 - Third-Party AI (5-7 pages): vendor evaluation framework with named criteria; NAIC Model Bulletin §4 conformance requirements; vendor scorecard and refresh cadence; concentration cap and compensating-control requirements; contract-clause requirements (change-of-control, data portability, audit rights, indemnification, SLAs, incident-response coordination); exit-clause requirements; substitute-vendor known-state discipline.
Domain 3 - Data Governance (5-7 pages): data estate inventory and classification; data quality standards (ASOP-23 alignment); lineage documentation; retention policy; consent and privacy posture (GLBA, HIPAA, state privacy laws); data-sharing agreement requirements; ECDIS inventory under Colorado Reg 10-1-1; cross-border data flow handling.
Domain 4 - Fairness and Anti-Discrimination (5-7 pages): bias-testing methodology and cadence; fairness pipeline; NY DFS Circular Letter 2024-7 proxy test discipline; Colorado SB 21-169 alignment; state-by-state anti-discrimination posture; FCRA adverse-action workflow for consumer lines; MHPAEA NQTL analysis for L&H; documentation requirements; remediation discipline if bias surfaces.
Domain 5 - Monitoring and Validation (4-6 pages): model card structure and refresh cadence; drift monitoring; performance benchmarking; champion-control parallel-run protocols; ASOP-56 modeling discipline alignment; model retirement criteria; observability requirements.
Domain 6 - Incident Response (4-6 pages): incident categories and severity tiers; runbook structure; notification triggers (internal escalation, board, regulators, customers); communications discipline; tabletop exercise cadence (quarterly); after-action documentation; vendor coordination.
Domain 7 - AI Ethics and Conduct (3-4 pages): acceptable-use principles; employee conduct; customer-communication standards on AI use; brand considerations; leadership AI public-statement protocol.
Annexes (5-8 pages): AI committee charter; named-role definitions; algorithm inventory template; model card template; vendor scorecard template; bias-testing protocol; incident response runbook; regulatory deadline calendar.
The Version Control and Change Log as Audit Evidence
The version control and change log inside the front matter is the audit evidence external reviewers expect when probing whether the policy is alive or aspirational. A document at version 2.4 with five logged quarterly amendments over the prior year - each tied to a named decision, an effective date, and the approving body (AI committee, board's risk/audit/technology committee, or chief AI officer authority depending on materiality) - reads as a managed policy. A document at version 1.0 dated eighteen months earlier with no changes reads as aspirational. The AM Best analyst, the AISET reviewer, the state DOI examiner, the internal auditor, and the reinsurance counterparty all read the change log first. The chief AI officer's job is to ensure the change log accurately reflects the program's evolution; the general counsel's signature on each amendment carries the legal weight.
Cross-Policy Integration With ASOP and the Regulatory Calendar
The enterprise AI policy integrates with the chief actuary's ASOP-compliant work product and the chief compliance officer's regulatory calendar at named touch-points. The chief actuary's ASOP-23 (data quality), ASOP-36 (Statement of Actuarial Opinion), ASOP-38 (catastrophe models), ASOP-41 (communications), ASOP-43 (P&C unpaid claims), and ASOP-56 (modeling) discipline lives at Domain 3 (data governance), Domain 5 (monitoring and validation), and indirectly in Domain 1 (AI usage in actuarial work). The chief compliance officer's regulatory calendar - AISET Exhibits A/B/C/D response, Colorado Reg 10-1-1 July 1 compliance report, NY DFS Circular Letter 2024-7 posture, state DOI bulletins, FCRA §615 adverse-action testing, MHPAEA NQTL Tri-Agency review, IRC §101(j) for COLI/BOLI, ERISA §503/§502(a) for ERISA-governed claims - lives at Domain 4 (fairness) and Domain 6 (incident response).
Cross-policy integration matters because regulators audit across domains: the AISET response covers governance (Domain 1), third-party (Domain 2), data (Domain 3), fairness (Domain 4), monitoring (Domain 5), and incident response (Domain 6); the Colorado Reg 10-1-1 report covers Domain 3 (ECDIS), Domain 4 (governance and fairness), and Domain 5 (monitoring); a state market-conduct exam covers Domain 4 (FCRA, MHPAEA), Domain 1 (claims handling AI), and Domain 6 (incident history). The L5 leader's job is to ensure the policy domains read consistently when regulators cross-reference them.
Board and AI Committee Oversight Structure
The board's risk/audit/technology committee receives quarterly reporting on the policy stack: policy review status, material changes since last meeting, incident history, regulatory developments, AI committee meeting summary, escalations from the AI committee. The board committee's role is enterprise oversight; the AI committee handles operational governance.
The AI committee structure under the policy: chaired by Chief AI Officer (or Head of Responsible AI in some structures), with named members including Chief Actuary, Chief Underwriter, Chief Claims Officer, Chief Distribution Officer, Chief Data Officer, Chief Compliance Officer, CRO, General Counsel, and (rotating) line-of-business representatives. Quarterly full meetings, monthly working sessions, escalation cadence to the board's risk/audit/technology committee. The committee charter is part of the policy stack annexes.
The CAIO Comp Package and the Rated-Carrier Market
Chief AI officer total compensation at rated carriers in 2026 runs $475K-$780K depending on carrier size, geography, and equity component. The role's market premium reflects the regulatory, governance, and strategic-influence breadth - the CAIO chairs the AI committee, owns Domains 1, 2, 6, and 7, signs the AISET response packet, attends the AM Best rating meeting, prepares the NAIC Form B disclosure language, and represents the carrier in NAIC and AAIS standards conversations. Carriers under-investing in CAIO compensation typically see role turnover inside 24 months and lose the institutional memory the policy stack depends on; carriers paying at market retain the CAIO across multiple regulatory cycles and produce more stable governance evidence at every external review surface.
The Periodic-Refresh Discipline
The policy is current only if it is refreshed on a documented cadence. Annual full review (typically Q1) with executive committee sign-off and board reporting. Quarterly amendments for new use cases, vendor additions, regulatory developments, and AI committee charter adjustments. Semi-annual fairness pipeline and bias-testing methodology refresh. Quarterly third-party vendor scorecard refresh. Quarterly tabletop exercise on incident response.
The refresh discipline is the audit-trail evidence regulators and AM Best analysts expect; without documented refresh, the policy is stale and the program loses credibility at external review. The L5 leader's job is to protect the refresh cadence against operating pressure that would defer it.
The Policy Stack and the AM Best Readiness Composite
The seven-domain policy stack maps directly to the AM Best readiness composite from Lesson 3. Data readiness (Domain 3); model governance (Domains 1, 5); talent (Annex with named-role definitions and AI committee charter); third-party AI risk (Domain 2); regulatory compliance (Domains 4, 6, Front Matter on regulatory deadline calendar). The composite scoring (5-25 across categories) is supported by policy-stack evidence; the analyst references both the score and the underlying policy artifacts. The 41% / ~60% headline numbers from the April 2026 Best's Special Report calibrate the carrier's framing - a carrier inside the 41% reports the policy stack as production-grade governance supporting active deployments; a carrier outside reports the policy stack as readiness-architecture supporting planned deployments.
The Treaty Broker Cession-Language Asset
The 2026 reinsurance treaty renewal cycle introduced explicit AI clauses in cession language for multiple major programs. The seven-domain policy stack becomes a cession-language asset because it provides the documented framework the treaty broker references when negotiating AI use-case disclosure clauses, governance-attestation clauses, incident-notification clauses, and audit-rights clauses with reinsurers at Munich Re, Swiss Re, SCOR, Hannover Re, Berkshire Hathaway Reinsurance, and Lloyd's syndicates. A carrier with the policy stack treats the clauses as ratifying existing practice and negotiates from strength; a carrier without the policy stack treats the clauses as new obligations and prices the additional governance burden into the treaty as a cost. The treaty broker's preparation pack includes the policy executive summary, the AI committee charter, and the most recent quarterly governance review minutes as the evidence supporting the cession language.
Key Takeaways
- Enterprise AI policy stack has seven domains: AI Usage, Third-Party AI, Data Governance, Fairness and Anti-Discrimination, Monitoring and Validation, Incident Response, AI Ethics and Conduct Addendum. Each domain has named owner, review cadence, escalation path.
- AISET Exhibits A/B/C/D map into the seven domains: Exhibit A (program governance) → Domains 1, 2, 7; Exhibit B (talent and governance) → Domain 1 + annexes; Exhibit C (model-level) → Domain 5 + Domain 4; Exhibit D (incident history) → Domain 6. AISET adoption window: 12-state pilot early 2026, September-October 2026 re-exposure, NAIC Fall National Meeting November 2026 adoption.
- NAIC Form B holding-company disclosure when AI is material covers scope of use, governance posture, material vendor relationships with concentration disclosure, regulatory posture (AISET, Colorado Reg 10-1-1 Oct 15, 2025 / July 1, 2026, state DOIs, FCRA, MHPAEA), incident history, ORSA integration. Reviewed by CCO, GC, CAIO, CRO, CFO before filing; aligned with AM Best, AISET, state DOI documents.
- Sample policy document is 35-55 pages structured by domain with front matter, seven domain sections, and annexes (AI committee charter, named-role definitions, algorithm inventory template, model card template, vendor scorecard template, bias-testing protocol, incident response runbook, regulatory deadline calendar). Version control and change log inside front matter is the audit evidence external reviewers read first.
- Cross-policy integration with ASOP and regulatory calendar at named touch-points. Chief actuary's ASOP-23/36/38/41/43/56 lives at Domains 3 and 5. CCO's regulatory calendar (AISET, Colorado Reg 10-1-1, NY DFS 2024-7, CT MC-25-8, NV 24-006, FCRA §615, MHPAEA NQTL, IRC §101(j), ERISA §503/§502(a), GLBA Safeguards §314, HIPAA §164.502/504/400-414, state privacy CCPA/CPRA/CPA/VCDPA/CTDPA/UCPA/TIPA) lives at Domains 4 and 6.
- Board's risk/audit/technology committee receives quarterly reporting; AI committee handles operational governance under quarterly full meetings and monthly working sessions. CAIO total comp $475K-$780K depending on carrier size, geography, and equity component; under-investment produces role turnover and loss of institutional memory.
- Periodic-refresh discipline: annual full review (Q1) with executive sign-off and board reporting; quarterly amendments for new use cases and vendors; semi-annual fairness pipeline refresh; quarterly vendor scorecard; quarterly incident-response tabletop. Refresh discipline is the audit-trail evidence regulators and AM Best expect.
- Seven-domain policy stack maps directly to AM Best readiness composite five categories: data readiness (Domain 3), model governance (Domains 1, 5), talent (annex), third-party AI risk (Domain 2), regulatory compliance (Domains 4, 6, regulatory calendar). Calibrated to April 2026 Best's Special Report's 41% deployment / ~60% transformation-horizon anchors.
- Policy stack is a treaty-broker cession-language asset. 2026 renewal cycle introduced explicit AI clauses; carriers with the policy stack ratify existing practice and negotiate from strength; carriers without it absorb governance burden as treaty cost. L5 leader protects refresh cadence against operating pressure that would defer it; stale policy fails at every external review surface.
Skill.re