CLAIMS CORELEDGER

The operating record for policy, claims, and insurance change.

Coverage desk

Regulation & Data

Source-backed reporting and analysis connected to the companies, capabilities, authorities, and operating domains it affects.

NAIC third-party data framework closes comments without becoming adopted policy

The NAIC Third-Party Data and Models Working Group exposed a proposed framework for a 28-day public-comment period that ended August 5, 2026, with discussion scheduled for August 12. Closing comments advances the working-group process; it does not by itself adopt a model law, model bulletin, accreditation standard, state rule, or binding insurer requirement.

FTC Safeguards Rule scope does not follow an insurance product label

FTC guidance says coverage turns on an entity's financial activities and regulatory jurisdiction—not how the company or software market is categorized. Insurance-core buyers need an authority map before converting the rule into product requirements.

NAIC Model 668 keeps third-party access inside the insurer’s security program

The NAIC Insurance Data Security Model Law places third-party service providers inside the licensee’s risk assessment, safeguards, due diligence, contract, oversight, incident response, and reporting framework. Outsourcing a core or claims function does not turn the provider’s security program into the insurer’s complete evidence.

ACORD data standards define transaction scope—not core-system ownership

ACORD maintains different standards families for P&C, life and annuity, reinsurance and large commercial, and digital services. A standards label can narrow an exchange contract, but it does not decide which system owns policy, claim, accounting, or settlement truth.

DORA turns insurance-core resilience into an operating record

The regulation's application raises the buyer standard for ICT governance, incidents, testing, third-party dependencies, contracts, recovery, and evidence across policy and claims services.