CLAIMS CORELEDGER

The operating record for policy, claims, and insurance change.

Authority library

Insurance authority and standards record

Each record preserves the issuing authority, jurisdiction, instrument or authority type, legal or operating status, version and application dates, affected audience, workflow mapping, source link, and interpretation boundary.

U.S. states that enact corresponding law · Model law

NAIC Insurance Data Security Model Law

The model law addresses information-security programs, cybersecurity-event investigation, and notice expectations for covered insurance licensees.

U.S. states adopting related provisions · Model law

NAIC Insurance Information and Privacy Protection Model Act

The model addresses collection, use, disclosure, access, and correction of insurance information within its model scope.

U.S. states adopting corresponding requirements · Model regulation

NAIC Privacy Model Regulation

The model regulation addresses privacy notices and treatment of nonpublic personal financial and health information in insurance operations.

U.S. states adopting corresponding provisions · Model act

NAIC Insurance Fraud Prevention Model Act

The model act provides a model statutory structure for insurance fraud prevention, reporting, investigation, and related authority.

U.S. states adopting corresponding provisions · Model law

NAIC Market Conduct Surveillance Model Law

The model law provides a model framework for market analysis, examinations, regulatory response, and insurer information in market-conduct oversight.

Adopting U.S. insurance jurisdictions · Model regulatory bulletin

NAIC AI Model Bulletin

The model bulletin reminds insurers that AI-supported consumer decisions remain subject to applicable insurance law and describes governance and documentation regulators may request.

Covered New York DFS-regulated entities · State financial-services regulation

New York DFS Cybersecurity Regulation

Part 500 establishes cybersecurity requirements for covered entities and has phased requirements under its second amendment.

In-scope EU financial entities and ICT third-party service providers · European regulation

Digital Operational Resilience Act (DORA)

DORA establishes a harmonized framework for ICT risk management, incident reporting, resilience testing, third-party risk, and oversight across in-scope financial entities including insurance.

Entities reporting insurance contracts under IFRS within scope · International financial-reporting standard

IFRS 17

IFRS 17 sets principles for recognition, measurement, presentation, and disclosure of insurance contracts and replaces IFRS 4.

Entities issuing long-duration insurance contracts within U.S. GAAP scope · U.S. accounting standard update

FASB LDTI

LDTI changes measurement, assumptions, discount rates, market risk benefits, deferred acquisition costs, and disclosures for long-duration insurance contracts.

Participating insurance markets and implementations · Insurance data standards

ACORD insurance data standards

ACORD maintains insurance data standards and architectures used to support structured exchange across market participants and lines.

Organizations managing cybersecurity risk · Voluntary cybersecurity framework

NIST CSF 2.0

CSF 2.0 provides a taxonomy of cybersecurity outcomes organized around Govern, Identify, Protect, Detect, Respond, and Recover.

Organizations designing, deploying, or using AI systems · Voluntary AI risk-management framework

NIST AI RMF

The AI RMF organizes voluntary AI risk-management work around Govern, Map, Measure, and Manage.

Entities within applicable PCI program scope · Payment-card data security standard

PCI DSS v4.0.1

PCI DSS provides security requirements for account data within its defined payment-card scope.

Organizations establishing an information-security management system · International management-system requirements standard

ISO/IEC 27001:2022

ISO/IEC 27001 specifies requirements for an information-security management system.

Organizations establishing a business-continuity management system · International management-system requirements standard

ISO 22301:2019

ISO 22301 specifies requirements for establishing, implementing, maintaining, and improving a business-continuity management system.

Covered financial institutions within FTC jurisdiction · Federal financial privacy and security rule

FTC Safeguards Rule

The Safeguards Rule requires covered financial institutions to develop, implement, and maintain an information-security program with specified elements.

How to read the library

Binding requirements, official guidance, technical standards, implementation guides, program rules, and authority data are not interchangeable. Each page names the source class and states what it can and cannot establish about an organization or product.