The American Property Casualty Insurance Association told the NAIC's Third-Party Data and Models (H) Working Group that members find its vendor oversight plan unworkable, one of 23 comment letters filed on the December exposure (NAIC Spring National Meeting minutes, March 2026). The July 8 revision shows how far the letters carried: mandatory registration is gone, a voluntary NAIC-hosted registry replaces it, and the leverage now sits inside the rate filing.

actuary.info has tracked this framework through three prior pieces: the December draft's supply-chain structure, the carrier accountability clause that survived the Spring National Meeting, and the registered-versus-unregistered documentation asymmetry in filing work. This piece is about the letters: who filed, which objections carry actuarial substance rather than lobbying reflex, what the rewrite conceded, and what remains contested. The revised text, narrowed to Property and Casualty Pricing and Underwriting Data and Models, went out July 8 with a 28-day comment period ending August 5, 2026 (NAIC, July 2026). The working group walked through it on a July 16 call and holds an hour of discussion, not an adoption vote, in Columbus on August 12 (NAIC Summer National Meeting agenda, July 2026).

What the Comment File Contains

The working group posted the letters in a single compilation, and the objections are far less uniform than the "industry opposes" framing suggests. APCIA's letter, signed by Kristin Abbott and Dave Snyder, is the sharpest: "Many expressed that the framework is unworkable and would yield outcomes counter to its objectives" (APCIA letter to the NAIC, February 6, 2026). The letter warns that the cumulative requirements would leave insurers with limited access to third-party models and datasets because many vendors "may be unwilling or unable to comply," that the requirements "may be more expansive than necessary," and that requiring registration for each dataset or model could duplicate existing oversight, including the Fair Credit Reporting Act's insurance support organization regime. One APCIA member observed that, as drafted, even a free internet search could fall within scope.

ACLI, whose 275 member companies hold 94% of U.S. life industry assets (ACLI letter, February 2026), called a compulsory framework "not necessary" and stated it is not aware of language in any insurance code that allows a new registration regime for third-party vendors. Its letter carries the trade-association stack's only actuarial signature: chief life actuary Brian Bayerle co-signed. AHIP pressed regulators to monitor outcomes rather than processes, and asked to exempt general-purpose model providers, naming OpenAI's ChatGPT and Google's Gemini as tools health plans would lose if those firms declined to register. The American InsurTech Council listed nine objections, including that fixed compliance costs would create a class of "too small to succeed" startups, and proposed safe harbors for vendors already under federal oversight or deriving less than 25% of revenue from insurance. The Committee of Annuity Insurers, 33 companies writing roughly 80% of U.S. annuity business (CAI letter, February 2026), asked for a voluntary program and for clarity on who gets sanctioned when a vendor fails to register.

The vendors wrote too, and none of them threatened to leave. Verisk's Insurance Services Office asked to narrow scope to underwriting and rating and to centralize registration in a single multistate process. LexisNexis noted that some state insurance departments already accept direct third-party filings. MIB, the mortality data bureau life underwriters query, requested a carve-out for consumer reporting agencies because the FCRA already imposes a "maximum possible accuracy" standard and 30-day reinvestigation timelines (MIB letter, February 2026). The NAIC's consumer representatives pushed the other way: broaden registration to any vendor doing business with an insurer, in a single NAIC-maintained database.

CommenterCore ask, February 2026Where the July 8 draft landed
APCIARethink the framework; scope and definitions too broadScope cut to P&C pricing and underwriting, phase one
ACLIVoluntary registration; drop data vendorsRegistration voluntary; data vendors still in
AHIP, MicrosoftExclude general-purpose AI model providersDefinitions tied to pricing and underwriting use, not tool type
AITCSafe harbors; protect small vendors from fixed costsNo tiering yet; registration burden now optional
ISO/VeriskCentral multistate registration; stronger confidentialitySingle NAIC-hosted registry; NAIC holds submissions
MIBFCRA carve-out for consumer reporting agenciesRegistry labels vendors by existing status, no carve-out
Consumer representativesBroaden registration to all insurer vendors; NAIC databaseNAIC database adopted; scope narrowed instead of broadened

No actuarial membership body appears in the posted file. The American Academy of Actuaries, the CAS, and the SOA filed nothing on a framework that will decide how models enter rate filings, and the strongest actuarial idea in the docket came from a regulator: Connecticut's Wanchin Chou told the Spring session that a CEO may lack the credentials to sign a governance attestation; a chief actuary or chief data scientist would have them (NAIC Spring minutes, March 2026).

What the July 8 Draft Conceded

The December draft required vendors to register with state insurance departments before insurers could use their products, with a three-step status ladder running from "Applied" through "Applied with governance approval" to "Registered" (NAIC exposure draft, December 2025). The July 8 text abandons that structure in its first substantive bullet: vendors would be "encouraged to voluntarily register through a shared multi-state registry" hosted at the NAIC (NAIC revised framework, July 2026). One sentence delivers ACLI's voluntary program, ISO's central multistate process, and the consumer representatives' NAIC database, while dropping the mandate itself.

The confidentiality answer is equally direct. Vendors feared state open-records laws; the revised draft responds that registry submissions will be held at the NAIC, which "is not subject to open records laws in any state," and that designated-confidential material will be shared only with states that have authority to protect it. The attestation clause absorbed Chou's point: the annual sign-off must come from "a senior leader with relevant technical expertise" holding formal authority over data and model governance, which describes a chief actuary or chief data scientist, not a figurehead officer. Vendors must also notify the registry of material changes to a dataset or model, including decommissioning, the version-drift problem the site's workflow analysis flagged as the quiet risk in vendor reliance.

What the working group did not concede is leverage. The revised draft states that where a third-party model or dataset is used, it "must be filed in either the insurer's own filing or as a separate filing submitted directly to the regulator, as requested by the regulator," and that a vendor's failure to provide requested information "may result in the regulator prohibiting insurers from using the data and/or model" for any P&C product in the state (NAIC revised framework, July 2026). Registration became voluntary; cooperation did not. A vendor can decline the registry and still face the same production obligation the moment a regulator asks. The enforcement runs through the one channel where state authority is undisputed, the insurer's rate and underwriting filing. The statutory-authority objection that ACLI, AHIP, and APCIA all raised has been answered not by claiming authority over vendors but by routing around them.

One clause moved in the opposite direction from everything else. The registry will record not just who the vendors are but "which insurers have purchased data and/or models," and will label each vendor's existing status, such as insurance support organization or licensed advisory organization. Client lists are commercially sensitive in a way governance documents are not, and no February letter anticipated disclosing them. Expect the sharpest August 5 comments there.

How Deep Third-Party Inputs Run in P&C Pricing

APCIA's core warning, vendors walk away and insurers lose the toolset, deserves testing against the actual dependency structure. FICO estimates that roughly 95% of auto insurers and 85% of homeowners insurers use credit-based insurance scores where the factor is legally permitted (Illinois Department of Insurance, citing FICO). Catastrophe models sit under coastal property rate indications and reinsurance purchases; Karen Clark & Company's U.S. hurricane model Version 5.0 cleared certification by the Florida Commission on Hurricane Loss Projection Methodology in June 2025 (KCC, June 2025). ISO's own letter describes supplying statistics, actuarial analyses, and policy language across multiple P&C lines (ISO letter, February 2026). The life side, waiting in a later phase, shows the same shape through MIB's underwriting queries and the annuity block concentrated in 33 CAI member companies. Third-party inputs are not an add-on to the pricing stack. In personal lines they largely are the stack.

That penetration cuts against the walk-away threat as much as it supports it. A vendor whose score sits in most of a state's auto filings has revenue reasons to cooperate that a marginal supplier lacks. The February file bears this out: every insurance-native vendor that wrote in (ISO, LexisNexis, MIB) asked for narrower scope or better confidentiality, not for the framework to die. The credible exit threats came from the multi-industry edge, where Microsoft's own letter argued that general-purpose model providers lack knowledge of downstream insurance use, and where APCIA noted many vendors rely on platforms "that they do not control or cannot fully document" (APCIA letter, February 2026). The July 8 revision prices that distinction: insurance-native vendors stay inside a filing obligation they already live with, and firms that would sooner drop the market segment are no longer asked to register.

The same arithmetic constrains the regulators' new lever. Prohibiting use of a model that one carrier relies on is a routine filing objection; prohibiting one embedded in most of a state's market would disrupt the very policyholders the prohibition protects. The filing lever is strongest against narrowly deployed models and weakest against the systemically embedded ones, which is precisely backwards relative to where concentration risk lives. The registry's client-list field is the one instrument in the draft aimed at that inversion, letting a regulator see embeddedness before deciding how hard to pull.

Where Oversight Already Exists, and Where It Does Not

The duplication objection has more actuarial substance than most of the file. AITC told the working group that more than half the states already let third-party data vendors file the models carriers use in personal lines rating and underwriting directly for inspection (AITC letter, February 2026), and NAMIC told the Spring session that some jurisdictions already accept model filings from non-licensed entities through SERFF (NAIC Spring minutes, March 2026). Florida has run a standing review commission for hurricane loss models since 1995, and that commission now certifies flood models as well, having accepted KCC's flood model in November 2024 (Karen Clark & Company, November 2024). Credit-based scores flow through consumer reporting agencies that already answer to FCRA accuracy standards and dispute timelines. Licensed advisory organizations such as ISO are examined under state rating law, and the framework's own definitions concede the point by excluding any "licensee" from the third-party vendor category entirely.

Model by model, then, the industry is right: almost everything important gets reviewed somewhere. What no existing mechanism provides is the cross-sectional view. The Florida commission audits a hurricane model's science; it does not know which Ohio homeowners writers depend on it. A SERFF filing shows one state one carrier's use; it does not show that forty carriers in thirty states run the same score. The revised draft's stated purpose, giving regulators "comprehensive awareness" of the third parties playing a material role in pricing and underwriting along with direct access, targets the aggregation gap rather than the review gap (NAIC revised framework, July 2026). Consumer advocate Eric Ellsworth countered the burden claims at the Spring session: lightweight registration mimics the client-onboarding forms vendors already complete (NAIC Spring minutes, March 2026). The honest summary is that the letters won on everything the existing system already does, and the working group held its ground on the one thing it does not.

Two Retreats in Seven Months, One Clause That Never Moved

This docket now supplies its own base rate for exposure drafts under fire. In December 2025, Fenwick's regulatory tracker anticipated "a model law on third-party oversight" in 2026, "potentially including licensing requirements for vendors" (Fenwick, December 2025). The December draft delivered mandatory registration across six insurance functions and all lines of business. By the March Spring meeting the six functions had become two and the lines had narrowed to property and casualty. By July 8 the mandate itself was gone. Two structural retreats in seven months, each traceable to specific letters, match the pattern from the 2023 AI bulletin cycle, when a contemplated model law on insurer AI use emerged as a principles bulletin instead, a history the site's December framework coverage traced.

The one provision that has survived every round is insurer accountability. The July draft restates it flatly: insurers must validate model suitability for their own book, secure contractual access to necessary information, and meet every pricing and underwriting requirement "even when using third-party data and/or models" (NAIC revised framework, July 2026). Working group vice chair Nicole Crockett's assurance in March that regulators do "not intend to disturb the marketplace" described the method, not a surrender: each concession has moved obligations off the vendor and onto the insurer's filing, where the working group never needed new authority in the first place. An actuary planning around this docket should assume the pattern continues. Whatever adoption looks like after Columbus, the compliance surface will be the rate filing and the people who sign it.

Positioning Before August 5

For plan-side pricing actuaries the operative sentence in the revised draft is the fallback for states with limited filing authority: where a state cannot approve a vendor's model as a separate filing, the model "will be evaluated as if it is part of an insurer's filing with the expectation that the insurer demonstrates the use of the data or model produces actuarially sound rates" (NAIC revised framework, July 2026). That sentence converts vendor opacity into the filing actuary's problem by construction. The preparation is unglamorous: inventory which rating-plan inputs come from licensees, which the framework leaves alone, versus unlicensed vendors, which it reaches; and use the current contract cycle to secure documentation access at filing-grade depth, as mapped in the site's compliance analysis. Carriers running vendor scores through MGA and program intake add the lineage problem covered in the submission-intake analysis: an input you cannot trace is an input you may have to defend.

Vendor-side actuaries should read the attestation and disclosure bullets as a job description. Someone with technical authority must annually attest that governance is implemented and effective and that supplied models comply with insurance law in every state where insurers deploy them. Material changes and decommissioning must be reported, regulator information requests carry committed response timeframes, and the registry will display the client list. Registration is voluntary in name only for any vendor whose business depends on staying usable in filings, because the production obligation and the prohibition backstop arrive with or without the registry entry. The framework's model documentation list reads as a product spec: purpose, assumptions, inputs, limitations, performance metrics, and validation processes. Vendor actuarial teams should staff it that way.

Comments on the revised draft close August 5, and letters on the revised text will post to the working group's materials as they arrive. The working group meets in Columbus on August 12 with discussion, not adoption, on the agenda. The professional bodies have one comment window left to say what "relevant technical expertise" should mean before someone else defines it for them. Twenty-three letters moved this framework twice. Silence will not move it a third time.

Further Reading

Sources

  1. NAIC, Third-Party Data and Models (H) Working Group (accessed July 2026)
  2. NAIC, Regulatory Framework for Third-Party Data and Model Vendors, P&C Pricing and Underwriting Data and Models, exposed July 8, 2026
  3. NAIC, Third-Party Regulatory Framework Comment Letter Compilation (February 2026)
  4. NAIC, Third-Party Data and Models Working Group Materials and Minutes, Spring 2026 National Meeting (March 23, 2026)
  5. NAIC, Third-Party Data and Models Working Group Agenda, 2026 Summer National Meeting (August 12, 2026)
  6. NAIC, Third-Party Regulatory Framework Exposure Draft (December 9, 2025)
  7. Illinois Department of Insurance, Credit: How Insurers Use It
  8. Karen Clark & Company, KCC US Hurricane Model Version 5.0 Certified by the Florida Commission on Hurricane Loss Projection Methodology (June 2025)
  9. Karen Clark & Company, KCC Flood Model Certified by Florida Commission on Hurricane Loss Projection Methodology (November 2024)
  10. Fenwick, Tracking the Evolution of AI Insurance Regulation (December 2025)