Insurance authority and standards record
Each record preserves the issuing authority, jurisdiction, instrument or authority type, legal or operating status, version and application dates, affected audience, workflow mapping, source link, and interpretation boundary.
NAIC Insurance Data Security Model Law
The model law addresses information-security programs, cybersecurity-event investigation, and notice expectations for covered insurance licensees.
NAIC Insurance Information and Privacy Protection Model Act
The model addresses collection, use, disclosure, access, and correction of insurance information within its model scope.
NAIC Privacy Model Regulation
The model regulation addresses privacy notices and treatment of nonpublic personal financial and health information in insurance operations.
NAIC Insurance Fraud Prevention Model Act
The model act provides a model statutory structure for insurance fraud prevention, reporting, investigation, and related authority.
NAIC Market Conduct Surveillance Model Law
The model law provides a model framework for market analysis, examinations, regulatory response, and insurer information in market-conduct oversight.
NAIC AI Model Bulletin
The model bulletin reminds insurers that AI-supported consumer decisions remain subject to applicable insurance law and describes governance and documentation regulators may request.
New York DFS Cybersecurity Regulation
Part 500 establishes cybersecurity requirements for covered entities and has phased requirements under its second amendment.
Digital Operational Resilience Act (DORA)
DORA establishes a harmonized framework for ICT risk management, incident reporting, resilience testing, third-party risk, and oversight across in-scope financial entities including insurance.
IFRS 17
IFRS 17 sets principles for recognition, measurement, presentation, and disclosure of insurance contracts and replaces IFRS 4.
FASB LDTI
LDTI changes measurement, assumptions, discount rates, market risk benefits, deferred acquisition costs, and disclosures for long-duration insurance contracts.
ACORD insurance data standards
ACORD maintains insurance data standards and architectures used to support structured exchange across market participants and lines.
NIST CSF 2.0
CSF 2.0 provides a taxonomy of cybersecurity outcomes organized around Govern, Identify, Protect, Detect, Respond, and Recover.
NIST AI RMF
The AI RMF organizes voluntary AI risk-management work around Govern, Map, Measure, and Manage.
PCI DSS v4.0.1
PCI DSS provides security requirements for account data within its defined payment-card scope.
ISO/IEC 27001:2022
ISO/IEC 27001 specifies requirements for an information-security management system.
ISO 22301:2019
ISO 22301 specifies requirements for establishing, implementing, maintaining, and improving a business-continuity management system.
FTC Safeguards Rule
The Safeguards Rule requires covered financial institutions to develop, implement, and maintain an information-security program with specified elements.
How to read the library
Binding requirements, official guidance, technical standards, implementation guides, program rules, and authority data are not interchangeable. Each page names the source class and states what it can and cannot establish about an organization or product.