Box Commons

Comment on NAIC BDAI Working Group: Exhibit B/D Mapping

Date April 8, 2026
Submitted to National Association of Insurance Commissioners
Docket BDAI Working Group
Type Formal Comment (US Federal)

Box Commons · 30 N Gould St Ste N, Sheridan WY 82801

Key Takeaways
  • The 12-state pilot has surfaced a structural compliance bottleneck: insurers cannot independently validate proprietary vendor AI systems they don't own and can't inspect.
  • Independent credentialing interposes a trusted intermediary — the vendor discloses to a certifier under NDA, the insurer relies on the credential, the regulator verifies via public registry.
  • The HITRUST precedent proves this pattern works: HITRUST CSF certifications are recognized by NAIC Model Law #668 as compliance mechanisms.
+ Jump to Section

I. Executive Summary

Box Commons recommends that the BDAI Working Group adopt a "Presumption of Conformity" framework within the AI Systems Evaluation Tool — permitting insurers to satisfy third-party vendor oversight obligations under Exhibit B (Governance and Oversight) and Exhibit D (AI Systems Model Data Details) by demonstrating that their vendors hold valid certifications from recognized, independent AI credentialing bodies.

This approach follows the proven regulatory pattern established by NAIC Insurance Data Security Model Law #668, where SOC 2, ISO/IEC 27001, and HITRUST CSF certifications serve as recognized compliance mechanisms for cybersecurity requirements.

II. The Compliance Bottleneck in Exhibits B and D

The 12-state pilot has surfaced a structural problem. Exhibit B requires insurers to document validation and testing procedures for third-party vendor AI systems — but insurers lack the technical capacity to independently validate proprietary algorithms, the legal rights to access vendor source code, and actuarial benchmarks for adequate AI validation.

Exhibit D requires granular disclosure of data types and analysis of how AI systems correlate with adverse consumer outcomes. Pilot feedback confirmed this is "exceptionally burdensome" for vendor-supplied systems where the insurer operates a black box.

The Third-Party Data and Models Working Group's proposed vendor registration framework drew broad industry opposition. The compliance bottleneck is structural, not procedural: no amount of questionnaire refinement will overcome the fact that regulators cannot inspect what vendors will not disclose, and insurers cannot audit what they do not own.

III. The Credentialing Solution

Independent credentialing resolves the information asymmetry by interposing a trusted intermediary. The vendor submits to a comprehensive audit by an accredited certifier, disclosing proprietary details under NDA. The insurer relies on the resulting credential to satisfy its vendor oversight obligations. The regulator verifies compliance by checking a publicly accessible registry — no inspection of proprietary models or trade secrets required.

This three-layer architecture (Standards Body → Accredited Certifiers → Certified Vendors) mirrors the structure that already works in cybersecurity through HITRUST and SOC 2.

IV. The HITRUST Precedent

The HITRUST precedent proves this pattern works. HITRUST CSF certifications are recognized by NAIC Model Law #668 as compliance mechanisms for cybersecurity requirements. The healthcare industry adopted HITRUST specifically because it resolved the same information asymmetry: covered entities needed to verify the security practices of business associates who would not disclose their proprietary security architectures.

The structural parallel is direct: replace "cybersecurity" with "AI behavioral safety," replace "business associate" with "AI vendor," and the compliance pattern transfers intact.

V. Proposed Evaluation Tool Language

We propose that the Working Group add the following framework: an insurer whose third-party AI vendor holds a valid, active certification from an independent credentialing body meeting defined governance criteria shall be deemed to have met the vendor oversight requirements of Exhibits B and D with respect to that vendor's certified AI systems.

The governance criteria should include: multi-stakeholder governance, published standards with public comment periods, accredited third-party certifiers independent from the standards body, a public credential registry, and a formal appeals process.


Contact:
Brice Love, Acting Executive Director
Box Commons
[email protected]

Content Integrity Notice: This comment was authored by the Box Commons Policy Working Group. Generative AI was used for research synthesis and drafting support. All policy positions, recommendations, and normative claims were formulated and reviewed by human authors.