NAIC privacy models keep data rights jurisdiction-specific
The regulator association's topic record organizes model laws and modernization work, while enacted state law still controls each insurance obligation.
The operating record for policy, claims, and insurance change.
Source-backed reporting and analysis connected to the companies, capabilities, authorities, and operating domains it affects.
The regulator association's topic record organizes model laws and modernization work, while enacted state law still controls each insurance obligation.
The NAIC Insurance Data Security Model Law places third-party service providers inside the licensee’s risk assessment, safeguards, due diligence, contract, oversight, incident response, and reporting framework. Outsourcing a core or claims function does not turn the provider’s security program into the insurer’s complete evidence.
ACORD maintains different standards families for P&C, life and annuity, reinsurance and large commercial, and digital services. A standards label can narrow an exchange contract, but it does not decide which system owns policy, claim, accounting, or settlement truth.
The model bulletin connects AI-supported underwriting, pricing, claims, fraud, and service decisions to applicable insurance law, governance, testing, monitoring, and documentation.
The regulation's application raises the buyer standard for ICT governance, incidents, testing, third-party dependencies, contracts, recovery, and evidence across policy and claims services.
Phased requirements place more emphasis on governance, access, monitoring, incident response, business continuity, and covered-entity accountability.
The April 2026 map reinforces why insurance security obligations must stay attached to enacted state text, covered entities, events, dates, and evidence.