Abstract digital artwork of blue lines and dots on a black background

AI Data Governance in Insurance: How To Build a Compliant Framework

Artificial intelligence (AI) is rapidly becoming embedded across the insurance value chain, helping organizations improve underwriting accuracy, accelerate claims processing, enhance customer experiences and identify emerging risks. However, increased adoption also brings heightened regulatory scrutiny and growing expectations around responsible AI governance.

How Is AI Changing the Insurance Industry?

Insurers are harnessing AI at every stage of their business, from optimizing underwriting with predictive analytics to deploying generative AI chatbots that improve customer service and enable 24/7 support. These tools not only streamline internal processes but also enhance operational efficiency by automating complex tasks such as claims processing, identifying patterns in large datasets, and delivering real-time insights. 

2025 survey conducted by the National Association of Insurance Commissioners (NAIC) across 16 states revealed that 84% of health insurers were already utilizing AI and machine learning (ML) in some capacity, highlighting just how fast these technologies are becoming standard across the sector.

However, certain risks arise that must be managed carefully, such as ensuring regulatory compliance and guarding against algorithmic bias. As AI becomes more deeply integrated into insurance operations, governance can no longer be treated as a separate compliance exercise. Organizations must establish clear controls over data, models and decision-making processes to ensure AI systems remain transparent, fair and trustworthy.

Why Is Data Governance Important for AI Usage in the Insurance Industry? 

As insurers integrate AI into their operations, the adoption of advanced technologies is outpacing the development of comprehensive governance frameworks.

While AI can enhance operational processes, it must not compromise fairness or due process, especially in denial scenarios. AI models must be designed to avoid algorithmic and proxy biases, where seemingly neutral variables correlate with protected characteristics, which can result in inequitable outcomes that threaten regulatory compliance and consumer trust. Variables that appear neutral may serve as proxies for protected characteristics such as race, gender, age and other regulated factors. 

This requires robust oversight, especially of third-party administrators, to ensure that predictive models are not embedded with algorithmic biases that could lead to unintentional discrimination in underwriting or claims adjustments.

Many insurers rely on external providers, especially for pricing reasons. According to the NAIC’s Third-Party Data Models Task Force, state regulators agree that insurers should retain full responsibility for the data and models they use, regardless of whether they are internally developed or provided by a third party. This makes it critical to conduct thorough due diligence and establish contractual safeguards to ensure compliance with governance standards and further mitigate risks.

Insurers must develop and maintain governance frameworks that include meticulous inventorying, documentation, interpretability and auditability of all algorithms in use. This promotes transparency, supports regulatory reviews, and maintains accountability from internal development to third party integration.

Insurance Regulatory Compliance Concerns: The NAIC’s AI Governance Framework

The NAIC has taken a proactive stance, issuing governance principles and model bulletins to guide the ethical and effective use of AI in insurance operations. And while these principles are not legally binding, nearly 25 states have adopted the NAIC’s model bulletin, signaling a shift toward enforceable standards. States including California, Colorado, New York and Texas have enacted their own separate and distinct AI regulations for insurers.

The NAIC’s model bulletin on AI governance outlines a comprehensive framework built on five core principles: 

  1. Transparency: Insurers must ensure that AI systems are explainable and that decision-making processes are understandable to regulators and consumers.
  2. Accountability: Clear lines of responsibility must be established for AI-driven decisions, especially when outcomes affect policyholders. 
  3. Fairness and Equity: AI must be designed to avoid discriminatory outcomes, with mechanisms in place to detect and mitigate bias. 
  4. Privacy and Data Protection: Robust safeguards are required to protect sensitive consumer data used in AI models. 
  5. Safety and Reliability: AI systems should be rigorously tested to ensure consistent and safe performance.

These principles lay the groundwork for future regulatory initiatives, protect consumers and maintain industry integrity.

What Should an Effective Insurance AI Governance Framework Include?

Different types of insurance carriers employ AI in diverse ways, which means their AI governance frameworks might also vary from those outlined by the NAIC. Nevertheless, to meet regulatory expectations and operational goals, insurers need to invest in AI frameworks that are: 

  • Auditable: Systems should include logging and documentation to support internal audits and regulatory reviews. 
  • Bias-resistant: Regular testing for model drift and bias is essential. Many insurers now conduct equity audits and integrate human oversight into their AI decision-making processes.
  • Actively Monitored: AI models should be continuously validated and monitored throughout their lifecycle to detect model drift, performance degradation and unintended outcomes. Governance processes should include model validation, performance testing, and documentation requirements to help ensure AI systems continue operating as intended. 
  • Secure and Compliant: Data governance must align with privacy laws, such as HIPAA and emerging state-level AI regulations. 
  • Scalable and Modular: AI architectures should be flexible enough to adapt to evolving business needs and regulatory changes. 

Third-party Vendor Oversight

Additionally, many insurers rely on external vendors for AI-enabled underwriting, claims management, fraud detection and customer service solutions. However, responsibility for regulatory compliance remains with the insurer, regardless of whether an AI system is developed internally or provided by a third party. Effective governance frameworks should include vendor due diligence, contractual safeguards, ongoing monitoring and periodic reviews to help ensure third-party AI systems align with organizational policies and regulatory expectations.

4 Strategies for Building AI Data Governance Frameworks in the Insurance Industry

To stay ahead, insurers should adopt a strategic approach to AI governance that not only fulfills compliance requirements but also fosters innovation and positions them as leaders in ethical AI deployment within the industry. When building their AI data governance framework, insurers should:

1. Guide Decision-making With Purpose

Anchor AI initiatives to clearly defined business objectives and risk tolerances, rather than implementing technology in response to isolated operational issues. With this approach, insurers can better ensure that data governance frameworks are not only compliant and robust, but also aligned with measurable long-term business value, thereby strengthening regulatory accountability. 

2Establish an AI Governance Committee

Successful frameworks depend on the engagement of functional and specialized personnel. While data stewards manage the actual data lineage, access controls, and quality assurance throughout the AI lifecycle, cross-functional teams comprising legal, IT and operational expertise on an AI governance committee oversee AI strategy, compliance and risk management. Involving these parties enables a more holistic approach by incorporating diverse perspectives and potential challenges other departments may not anticipate.

3Invest in Explainable AI (XAI)

XAI refers to a set of processes and methods that enable human users to comprehend and trust the outputs produced by ML algorithms. By implementing tools that demystify model behavior into data governance frameworks, insurers can foster trust with stakeholders and policyholders, as well as satisfy growing demands of regulators who want to understand the reasons behind certain decisions.

4. Engage With Regulators and Industry Advisors

Establishing a reliable and compliant AI governance framework for insurance organizations requires a coordinated approach between people, processes, technology and culture. Proactive dialogue with state insurance departments, participation in industry forums, and staying informed about regulatory trends can help shape practical and forward-looking AI policies. Most importantly, specialists who can interpret regulatory mandates (e.g., NAIC model bulletins, state-specific AI rules) are available to support contract management, due diligence and policy creation.

Why Work With Cherry Bekaert? 

Cherry Bekaert’s 2025 CFO Survey found that a quarter of all finance leaders ranked AI integration among their top three concerns, rising to 30% in the healthcare industry. While these findings reflect the growing importance of AI as a strategic priority, the survey also noted hesitation to integrate AI and automation, stemming from uncertainty about how and where to implement them. 

So, as insurance organizations explore new and expanded AI capabilities, governance considerations become increasingly critical. AI initiatives frequently require more planning than other IT projects, and project scopes often underestimate the impact of data readiness, integration, compliance and ongoing oversight.

Now, more than ever, it’s crucial to enlist a trusted advisor with extensive experience in the insurance industry and a deep understanding of the complex regulatory requirements and risks insurers face. Cherry Bekaert’s Insurance practice professionals work alongside insurance leaders to support informed AI decisionmaking grounded in business needs while helping organizations design and mature AI governance frameworks that align with industry requirements. 

Let Us Guide You Forward

Our team of Risk Advisory and Cybersecurity professionals can assist your insurance organization in effectively complying with incoming AI regulations. Through the implementation of robust governance frameworks, AI risk management controls, and internal audit functions, insurers can better mitigate risks associated with AI systems, promoting fairness, transparency and accountability within the industry. 

Connect With Us

Related Insights

Todd Rosenbaum headshot

Todd Rosenbaum

Insurance Industry Leader

Partner, Cherry Bekaert LLP
Partner, Cherry Bekaert Advisory LLC

Carole Sorensen Headshot

Carole Sorensen

Risk Advisory Services

Director, Cherry Bekaert Advisory LLC

Contributors

Connect With Us

Kurt Manske headshot

Kurt Manske

Cybersecurity Leader

Partner, Cherry Bekaert Advisory LLC

Audrey Magennis Headshot

Audrey Magennis

Cybersecurity

Director, Cherry Bekaert Advisory LLC

Recommended Insights