AI governance for insurer diligence
Designed to support accountable human review.
Pipeline provides versioned technical product evidence covering AI-supported tasks, intended-use boundaries, human oversight, validation records, change history, and external-evidence gaps. NAIC and NIST references are informational mappings only.
Framework context
The evidence packet pins the adopted NAIC Model Bulletin and NIST AI RMF 1.0 as source references. Its mappings do not determine state applicability, legal obligations, customer implementation, or conformity. Those determinations require current external evidence and qualified review.
Model inventory
The packet identifies each AI-supported task, current allowlisted model family, provider route, input and output, material limitations, fallback status, and deterministic controls that sit outside the model. Optional providers are not approved for real customer documents by default.
Human oversight
Pipeline is decision support. Source-linked fields, extraction warnings, focused verification, reviewer dispositions, immutable versions, role-gated authority, and open-condition blockers keep consequential actions with authorized examiners and supervisors. The model cannot independently deny coverage, determine liability or fraud, authorize payment, send a binding offer, or execute a release.
Validation evidence
The packet can project fixed-category, count-only validation and review aggregates when the minimum cohort is met. Missing series remain planned or externally evidenced; the packet does not infer performance from raw claim records, runtime logs, or absent incident records.
Audit cooperation
The proposed contract schedule addresses documentation access, regulator-inquiry support, scoped audit mechanisms, material-change notice, findings and remediation, incident facts, record preservation, confidentiality, and protection of other tenants. These are negotiation terms until included in an executed agreement.
Data-flow truth
Raw PDFs and rendered images stay inside the application. Native text and OCR run locally; only locally deidentified text may cross the provider boundary, while the encrypted restoration map and key stay local. Low-confidence pages fail closed for human review. These controls do not establish HIPAA compliance. Production PHI remains gated on approved contracts, BAAs, service scopes, region, retention, IAM, logging, storage, security, purge, and customer authorization.
Diligence evidence
Review the control crosswalk with your claims, legal, and security teams.
Authorized customer users can preview current evidence and freeze exact JSON and Markdown exports. Statuses distinguish implemented controls, planned work, customer responsibilities, and external evidence required.