NAIC Just Wrote Your AI Governance Job Description · Solving Without a Full-Time Hire

NAIC AI Governance Rules

Market conduct exam letters do not announce themes. They enumerate. Somewhere between the request for complaint-handling logs and the request for producer licensing records, a paragraph now appears that did not exist three years ago. It asks for the company’s written program governing its use of artificial intelligence systems. It asks who within the organization is accountable for that program. It asks how the company oversees the third-party AI embedded in its underwriting, claims, and fraud operations, and it asks for the documentation showing that the oversight actually happens.

She walks the letter to your office not for reassurance but for a decision, because what it is really asking is a staffing question wearing a compliance costume: who owns this here?

Consider how that paragraph lands at a $220 million carrier. The compliance officer reads it twice. She is not alarmed by document requests; she has answered hundreds of them. She is alarmed because she has just searched the shared drive, and the document being requested is not there. There is a two-page AI acceptable-use policy the CIO drafted in 2024, mostly concerned with employees pasting things into chatbots. There is no program, no inventory of the models the company actually relies on, no named owner, no testing record. She walks the letter to your office not for reassurance but for a decision, because what it is really asking is a staffing question wearing a compliance costume: who owns this here?

The board version arrives more gently and lands in the same place. A director who also sits on a larger carrier’s board asks, between agenda items, who your equivalent is to the AI governance lead that carrier just named. The honest answer at most mid-market carriers today is: nobody, exactly.

This article is about that answer. It is not really about artificial intelligence, and it is not about the machinery of compliance. It is about the fact that insurance regulators have, over the past two and a half years, produced something that reads less like a regulation than like a job description, and about the arithmetic a mid-market carrier should run before filling it.

 

What the bulletin actually asks for

In December 2023, the NAIC adopted its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers. Treating it as a big-carrier problem was a reasonable read at the time. It was model guidance, not law; adoption was thin; the loudest early commentary concerned national carriers whose in-house data science teams were the obvious audience. If you filed it under “worth watching,” you were in good company, and you were right, then. That read has simply been overtaken by the adoption map. Roughly two dozen jurisdictions have now adopted the bulletin, a list that runs from Alaska to West Virginia and includes Illinois, Pennsylvania, Michigan, Washington, and most of New England. California, Colorado, New York, and Texas sit outside that count for the unreassuring reason that each has issued its own insurance-specific AI guidance rather than adopting the model text. A multi-state carrier now has to work to find a footprint the map does not touch.

What the bulletin asks for is best translated out of regulatory language into operating language, because the translation is where the staffing question becomes visible.

First, a written program. Not a policy statement, not a values paragraph in the employee handbook: a program for the responsible use of AI systems, covering governance, risk management, and internal controls, proportionate to how the company actually uses the technology. Written is the operative word. The program is an artifact an examiner can request by name, and its absence is a finding that no amount of good intention offsets.

Second, accountability with names attached. The bulletin expects a governance structure in which specific people, drawn from the disciplines the AI actually touches (actuarial, underwriting, claims, IT, compliance, legal), hold defined responsibility for the program and its decisions. “The organization takes this seriously” is not a governance structure. A chart with names on it is.

Third, and for mid-market carriers most consequentially, oversight of third parties. Most of the AI at a $200 million carrier did not come out of a data science team; it came shrink-wrapped inside vendor systems. The underwriting score, the claims triage model, the fraud flags: bought, not built. The bulletin anticipates exactly this arrangement, and it declines to let the vendor relationship function as an accountability shield. The insurer is expected to perform due diligence on the third-party models it relies on, to secure contract terms that permit audit and information access, and to answer for those models’ decisions as if they were its own. In the eyes of the policyholder and the regulator, they are.

Fourth, testing and documentation as a cadence rather than an event. Models are expected to be validated before deployment and retested as the models, the data, and the world drift, with records retained and producible. Not a binder assembled the week the exam letter arrives; a rhythm, with dates on it.

And the examination apparatus is catching up to the guidance. Twelve states, including several that never adopted the bulletin itself, have spent much of 2026 piloting a standardized NAIC evaluation tool for reviewing insurers’ AI systems and governance within market conduct and examination work, with adoption expected at the NAIC’s fall national meeting. The tool creates no new obligations. It does something more practical: it converts the bulletin’s expectations into a common set of questions that examiners everywhere can ask, in the same order, with the same expectations about what a complete answer looks like.

 

Read it again as a job posting

Now set those four expectations side by side and read them as duties rather than requirements. Someone must author the written program and keep it true as the portfolio changes. Someone must own the inventory: every model, internal or vendor-embedded, that touches rating, underwriting, claims, or fraud, each with its owner, its vendor, its purpose, and its last test date. Someone must interrogate vendors, which is a genuine skill: knowing what to ask a scoring provider about training data, drift monitoring, and disparate outcomes, and recognizing when the answer is polished evasion. Someone must run the testing calendar and make sure it produces records rather than reassurances. Someone must be able to sit across from an examiner and narrate the program without notes. And someone must stand in front of the board on schedule and report on all of it in the board’s language, not the technology’s.

That is not a committee’s charter. Committees do not author programs, own inventories, or sit for interviews. It is a role. Regulators did not need to say so explicitly, because the duties say it for them.

Large carriers read it that way some time ago. The titles vary, chief AI officer, head of AI governance, responsible AI lead, but the pattern does not: a senior executive, reporting high in the organization, with supporting staff. And the market for that executive is thin in exactly the way that makes it expensive. The role demands fluency in model risk, insurance regulation, vendor management, and boardroom communication simultaneously, a combination the industry has not been producing at volume. For a full-time hire with that profile, compensation sits where other C-suite technology leadership sits, $350,000 and up before the loaded costs and the supporting staff are counted, and searches run long because every carrier is drawing from the same shallow pool.

 

The arithmetic nobody wants to run aloud

Hold that job description up against the actual AI portfolio of a $150M–$400M carrier, and be honest about what is there. Two or three vendor-embedded models doing the consequential work in underwriting and claims. A fraud-detection service. Perhaps a policyholder-facing chatbot, a document-intake tool, and a handful of internal experiments in various states of ambition. It is real exposure, and it is exam-relevant exposure. It is not a research lab.

The obligation is binary while the workload is proportional, and a mid-market carrier sits on the wrong side of both curves at once.

Once the program is stood up, governing that portfolio well generates perhaps a day or two per week of genuinely senior work: the periodic vendor reviews, the testing cadence, inventory maintenance, board materials, the occasional assessment of a new system before it goes live. But here is the asymmetry that makes the arithmetic uncomfortable. The exam letter does not ask how large your portfolio is. It asks whether the program exists and who owns it. The obligation is binary while the workload is proportional, and a mid-market carrier sits on the wrong side of both curves at once.

The full-time hire fails the arithmetic within about a year, which is roughly how long the build takes. The program exists, the inventory is current, the cadence is running, and you now employ a $350,000 executive whose role has settled into two days a week of real work. Overqualified and underutilized is not a stable condition for senior people; they leave, and the program’s institutional memory leaves with them, quite possibly in the window between exams.

The side-duty assignment fails differently. Handing the program to the CIO or the compliance officer as an additional hat is the answer regulators have already watched fail elsewhere in insurance operations. The industry’s experience with part-time appointed officers, information security in the years before it matured into a real function is the instructive case, is a history of programs that exist on paper and stall in practice. The CIO also carries a structural conflict the bulletin’s logic quietly exposes: the person who selected the vendor systems is not the ideal person to interrogate them. Examiners read org charts. A program owned by someone whose actual job is something else reads as exactly what it is.

So the role is now required in substance; the full-time version cannot be justified by the workload; and the side-duty version is the known failure mode. That is the dilemma, stated cleanly. It is not a compliance emergency. It is a sizing problem.

 

The fractional resolution

Sizing problems have a familiar resolution in the mid-market, and it did not originate with AI. Carriers of this size have run for years on fractional CFOs and fractional CISOs, in each case for the same underlying reason: the accountability had to be senior while the workload was structurally part-time. AI governance has precisely that shape, and it may be the purest case of the three, because the bulletin defines the duties specifically enough that the engagement scopes itself.

In practice, senior fractional AI governance leadership looks like this. In the first quarter, the written program gets authored: fitted to the actual portfolio rather than adapted from a template, because examiners have read the templates too. The model and vendor inventory gets built, which at most carriers is the step that produces surprises: the AI provisions that turn out not to exist in vendor contracts, the scoring model nobody currently owns, the pilot that quietly became production. Vendor interrogation begins, with contract remediation wherever audit and information rights are missing.

Then the program shifts from construction to cadence: a testing and revalidation calendar with dates and owners attached, human oversight checkpoints at the decision points that actually affect policyholders (a discipline we have written about separately as real human oversight of AI), board reporting on schedule and in board language, and an exam narrative maintained continuously, so that responding to an interrogatory is an act of retrieval rather than archaeology. And when the letter arrives, the fractional executive is present: sitting for the interview, narrating the program, standing as the senior named owner the accountability expectation contemplates. The seniority is the point. A fraction of a genuinely senior executive satisfies the bulletin’s logic in a way a full-time junior hire never will.

This is the pattern we built our vCAIO practice around, and insurance is currently the vertical where the case makes itself, because it is the vertical where the duties are written down. The economics are what the CFO and CISO precedents would predict: a fraction of the loaded cost of the full-time executive, sized to the day or two per week the portfolio actually generates, expandable when the portfolio grows and contractible as the program matures.

 

One question for Monday

The bulletin’s requirements are not going to shrink; guidance of this kind accretes. The state adoption map is not going to reverse; adoption maps never do. And the standardized exam questions now being piloted will make the review of AI governance programs routine rather than novel, which is what regulators mean by maturity. None of this calls for alarm, and the carriers who respond with alarm will overbuy: a full-time executive for a two-day-a-week role, or a consulting engagement that produces a binder and departs. The carriers who treat the job description as an arithmetic problem will solve it cheapest, and will be the ones for whom the exam paragraph about artificial intelligence becomes the easy part of the letter.

You have discovered a job description, and those, at least, come with a known way to fill them.

One step is available this week, and it costs nothing. At your next leadership meeting, ask a single question: if the exam letter arrived Monday, who in this company would answer the AI governance interrogatories, and what, exactly, would they hand over? If the room produces a name and a document, you are ahead of most of your peer group. If it produces a silence, you have not discovered a crisis. You have discovered a job description, and those, at least, come with a known way to fill them.

More from our blog

NAIC Just Wrote Your AI Governance Job Description · Solving Without a Full-Time Hire

NAIC Just Wrote Your AI Governance Job Description · Solving Without a Full-Time Hire

Market conduct exam letters do not announce themes. They enumerate. Somewhere between the request for complaint-handling logs and the request…
Team "Still Not Ready for AI"? · Readiness Is Designed, Not Awaited

Team "Still Not Ready for AI"? · Readiness Is Designed, Not Awaited

  The Meeting Where the Question Settled Itself The scene has repeated itself in mid-market boardrooms with remarkable consistency over…
Orchestrating an AI team

Orchestrating an AI team

by John Bentley II, CTO Consultant The first version of my AI workflow looked like one assistant doing one job.…