The NAIC Third-Party Data and Models Working Group settled on a registry rather than licensure at its March 23, 2026 Spring National Meeting. Vendors file disclosure information and update it on a cadence, regulators cannot approve or deny their right to operate, and signing actuaries retain full professional accountability regardless of a model's registry status. Three unresolved questions carry into the Summer 2026 agenda, and one of them is whether states can require registration at all.

Key Takeaways

  • Registry, not licensure. The framework facilitates transparency between regulators and providers rather than creating a licensure process, so no vendor can be denied market access for failing to register.
  • Scope narrowed from six functions to two. The first phase covers pricing and underwriting only, which places the entire opening compliance cycle inside the actuarial certification domain.
  • "Insurer accountability does not transfer to the registered vendor." Registration changes what a regulator can see; it changes nothing about who signs the rate filing.
  • Twenty-four states and the District of Columbia had adopted the 2023 AI Model Bulletin as of the Spring meeting, and that pool is the natural early-adopter set for anything that follows.
  • The material change notification requirement has no specified timeframe or recipient, which leaves the carrier's certification obligation after a mid-cycle model update undefined.

Registry, Not Licensure

The distinction the working group settled decides what a regulator can do about a non-compliant vendor. Licensure would let departments approve or deny the right to operate, condition market access on technical standards, and revoke access on a finding of non-compliance, the way a carrier's certificate of authority works. The working group declined that path, describing the registry's purpose as facilitating "transparency between regulators and third-party providers rather than creating a full licensure process."

The framework as drafted carries five substantive obligations:

  • Vendor registration, with documentation of model purpose, training data provenance, testing methodology, known limitations, and a designated regulatory contact.
  • Annual attestations that filed information remains accurate and governance practices still meet requirements.
  • Regulatory access for state departments to inspect vendor records and request supplemental documentation.
  • Material change notifications when a vendor substantially modifies a registered model's architecture, training data, or intended scope.
  • State-specific model filings, at individual state discretion, beyond the national baseline.

The entity definition is broad: any nongovernmental entity providing data, models, or outputs for insurance activities. That reaches rating agencies, data aggregators, AI platform providers, telematics scoring vendors, aerial imagery services, and insurtech platforms delivering underwriting recommendations. Comment-period objections focused on trade secrets, since disclosing training data sources, testing methodology, and change-management practices describes the operational blueprint of a commercial product. Commenters challenged "whether confidentiality and trade secret protections would be adequate," and the current draft does not fully answer that.

Scope was narrowed at the same session. The original proposal covered pricing, underwriting, claims handling, utilization review, marketing, and fraud detection; consensus limited phase one to pricing and underwriting.

The Certification Does Not Move

That narrowing puts the framework's first compliance cycle exactly where actuaries hold sign-off. It also makes the framework's central sentence load-bearing: "insurer accountability does not transfer to the registered vendor." The exposure draft phrased it more directly, saying insurers are still responsible for carrying the accountability tune.

Nothing in the registry changes the terminal point of the chain. A pricing actuary certifying an indication built on a registered vendor model is no more insulated by that registration than by a vendor's SOC 2 attestation. What registration adds is a factual marker that examinations and disputes will reference. Registry status becomes evidence about diligence, not evidence about the model.

The working group's own analogy makes the intended function explicit. It compared the registry to the NAIC Quarterly Listing of Alien Insurers, which cedents and brokers use to verify that a nonadmitted reinsurer is eligible for reinsurance credit on Schedule F and Schedule S. Departments treat listing as a baseline. The analogy also marks the limit: the alien insurer listing works because its use case is a single annual statement line item with a defined examination procedure, and the registry has no equivalent procedure yet.

The operational consequence for a signing actuary sits in the material change requirement. Rate indications are built on specific model versions. When a vendor reweights features, retrains on a new data window, or recalibrates outputs, the framework requires notification but does not set a timeframe, name the recipient, or say what the carrier's certification obligation becomes once notice arrives. The two carrier-facing layers do not close that gap either: the 2023 Model Bulletin requires third-party due diligence without reaching vendors, and the four-exhibit evaluation tool piloting in 12 states examines the carrier's documentation of third-party validation under Exhibit C, not the vendor's model governance.

Whether States Can Require It At All

The challenge that could slow adoption is jurisdictional rather than technical. State insurance codes license insurers and insurance-related entities. Verisk is not an insurer. LexisNexis is not an insurer. A telematics scoring platform is not an insurer.

Commenters raised exactly that, questioning "whether state insurance departments have sufficient legal authority to regulate third-party vendors directly, since those vendors are not licensed entities under state insurance codes." It is an administrative law question, and answering it in departments' favor needs either statutory amendment or a jurisdictional theory that has not yet been tested.

The workable response is indirect regulation: require carriers, who are plainly within jurisdiction, to use only enrolled vendors. That avoids the problem and changes the framework's character at the same time. The obligation lands on the carrier, and a vendor that declines to register simply shifts the compliance burden onto its clients rather than losing access to them.

Two enforcement gaps follow from the same design. A carrier using an unregistered vendor faces a violation that runs against the carrier. A vendor filing materially false registration information faces remediation through courts under general fraud doctrines rather than through regulatory proceedings. Neither consequence reaches the vendor through insurance regulation.

Adoption will therefore sort by how broadly each state construes its own authority, which points at a patchwork resembling the Model Bulletin's. The 25 jurisdictions already on the bulletin move first; states construing the commissioner's reach narrowly wait for legislation or a court. Whether New York, California, Texas, and Florida join decides whether this is a national market expectation or a compliance layer in part of the country.

Further Reading

Sources