The NAIC Third-Party Data and Models Working Group exposed a proposed framework for a 28-day public-comment period that ended August 5, 2026, with discussion scheduled for August 12. Closing comments advances the working-group process; it does not by itself adopt a model law, model bulletin, accreditation standard, state rule, or binding insurer requirement.
9 minThird-party data and model framework status analysis
FTC guidance says coverage turns on an entity's financial activities and regulatory jurisdiction—not how the company or software market is categorized. Insurance-core buyers need an authority map before converting the rule into product requirements.
The regulator association's topic record organizes model laws and modernization work, while enacted state law still controls each insurance obligation.
The NAIC Insurance Data Security Model Law places third-party service providers inside the licensee’s risk assessment, safeguards, due diligence, contract, oversight, incident response, and reporting framework. Outsourcing a core or claims function does not turn the provider’s security program into the insurer’s complete evidence.
ACORD maintains different standards families for P&C, life and annuity, reinsurance and large commercial, and digital services. A standards label can narrow an exchange contract, but it does not decide which system owns policy, claim, accounting, or settlement truth.
The model bulletin connects AI-supported underwriting, pricing, claims, fraud, and service decisions to applicable insurance law, governance, testing, monitoring, and documentation.
The regulation's application raises the buyer standard for ICT governance, incidents, testing, third-party dependencies, contracts, recovery, and evidence across policy and claims services.
The April 2026 map reinforces why insurance security obligations must stay attached to enacted state text, covered entities, events, dates, and evidence.