Twenty-three comment letters reached the NAIC by February 6, 2026, and they agreed on the gap even where they disagreed on the fix: state regulators have no direct channel to the vendors whose models price and underwrite millions of consumer policies. The Third-Party Data and Models Working Group's vendor registry, up for an August 12 decision at the Summer National Meeting in Columbus, is the first regulatory structure built to close it.

Key Takeaways

  • Six required elements in the proposed registration filing: model description and intended use, training data sources and date ranges, testing methodology with bias results by protected class, known limitations, change management practices, and a regulator contact.
  • 23 comment letters on the December 9, 2025 exposure draft pushed back hardest on scope, and the Working Group has since narrowed the initial mandate to pricing and underwriting only.
  • 29 states have approved ZestyAI's Severe Convective Storm models for carrier filings, yet the supporting documentation sits with each carrier rather than in any shared regulator-accessible record.
  • Registration is disclosure, not licensure. A registered vendor is on file, not approved, and the carrier remains answerable for the model's behavior under the 2023 Model Bulletin adopted by roughly 24 states.
  • One hour, 11:45 to 12:45, is what the August 12 session gets, which is enough to settle the mandatory question and not enough to finalize a model law.

What the Registry Would Actually Require

The exposure draft released December 9, 2025 structures registration as a disclosure regime. That distinction carries the legal architecture: registration creates regulatory visibility, not state approval of the model, and an annual attestation of compliance with the vendor's own governance program keeps the registration live rather than letting a one-time filing age.

The six components are a model description and intended use, training data sources and date ranges, testing methodology including bias testing results by protected class where applicable, known limitations, change management practices, and a designated contact for regulator inquiries. Registration filings receive the same confidentiality protection state departments already extend to proprietary and trade secret material, which answers the objection raised most often in the comment letters.

The original draft reached six insurer functions with direct consumer impact across property/casualty, health and life: pricing, underwriting, claims, utilization review, marketing and fraud detection. That breadth drew the bulk of the criticism, and at the March 23 Spring session in San Diego the Working Group signaled the framework would apply initially to pricing and underwriting only.

For a property and casualty actuary that narrowing lands on a specific roster: Verisk rating algorithms and loss costs, ZestyAI property risk scores, Cape Analytics condition data, CCC Intelligent Solutions vehicle valuation, EagleView roof data. Agency tiering and predictive triage tools that shape which risks get written without appearing in a filing exhibit sit in an unresolved definitional gap.

The Asymmetry the Registry Creates in a Rate Filing

The consequential part is not the vendor's compliance burden. It is what registration status does to the filing that relies on the model. ZestyAI's models are approved in 29 states, each approval preceded by some form of state review, but the documentation supporting each one is held by the carrier that filed it. A state reviewing a second carrier's use of the same model starts over.

A registered vendor gives the certifying actuary something that does not exist today: a governance record regulators have already accepted as an adequate minimum. Reliance still has to be assessed for the stated use, and responsibility for the work product does not move, but it rests on a documented baseline instead of a user guide and a carrier-side validation summary.

An unregistered vendor's model has no such anchor, so the filing has to carry the whole evidentiary weight itself. In an adopting state that means substantively heavier supporting documentation for the same model, purely as a function of the vendor's filing status.

That gap has commercial force in one direction. A carrier that finds mid-filing that a three-year incumbent vendor has not registered can document adequacy independently or move to a registered alternative, and the second path is cheaper. The framework never states that vendor registration status is a rate filing prerequisite. The asymmetry between the two documentation burdens produces the same result.

The size of the gap varies sharply by vendor type. Verisk methodology is extensive and familiar from decades of filing practice, so registration adds an attestation without changing what an actuary receives. Specialist machine learning vendors typically supply outputs and intended use but not bias results segmented by protected class, monitoring metrics, or a change log detailed enough to confirm that the model version in a filing is the version the carrier validated.

Whether Regulators Can Reach the Vendors at All

The framework's central unresolved question is not scope but authority. The American Council of Life Insurers argued in its comment letter that mandatory registration is "not necessary" and proposed a voluntary alternative, on the grounds that a mandate reduces vendor competition and falls hardest on smaller vendors without multi-state compliance infrastructure.

Several letters added a sharper objection: state insurance departments may lack statutory authority to impose registration directly on third-party vendors, as opposed to enforcing vendor governance indirectly through carrier licensing conditions. That is the constraint the Working Group cannot resolve by drafting. A carrier can be required to hold model governance documentation as a license condition. A vendor that holds no license in the state stands on different footing, and the question of whether a department can reach it directly may be settled in court rather than in Columbus.

The Working Group has been firm that registration stays mandatory, on the basis that a voluntary system cannot identify and track providers. Its charge references a risk-based framework, which points toward tiering by vendor size or market impact rather than toward abandoning the mandate.

Timing compounds the authority problem. The August 12 session runs one hour, 11:45 to 12:45, which fits a mandatory-versus-voluntary decision and a revised draft for a second comment period, not a finished model law. The 2023 Model Bulletin took more than a year to reach meaningful state adoption and imposed no vendor-facing obligation at all; a framework that does will need enabling legislation in some states. First adoption is realistically a 2027 event, and the annual attestation cycle means a carrier's documentation anchor can lapse between filings without warning when a vendor is acquired, reorganizes, or deprioritizes compliance during growth.

Further Reading

Sources

  1. NAIC Third-Party Data and Models (H) Working Group Committee Page
  2. NAIC Third-Party Regulatory Framework Exposure Draft (December 9, 2025)
  3. NAIC Spring 2026 Third-Party Data and Models Working Group Meeting Materials (March 23, 2026)
  4. NAIC Summer 2026 National Meeting Tentative Agenda (August 11-14, Columbus)
  5. Mondaq: NAIC Spring 2026 Third-Party Data and Models Working Group (March 23, 2026)
  6. Mondaq: NAIC Fall 2025 Third-Party Data Working Group Exposure (December 2025)
  7. Sidley Data Matters: NAIC Spring 2026 National Meeting Regulatory Update (April 2026)
  8. Swept AI: The 2026 NAIC Third-Party Model Law Vendor Registry
  9. BeInsure: ZestyAI SCS Risk Models Approved in 29 States (April 2026)