Table of Contents
Summarize and analyze this article with
Where insurance regulators focus hardest
What a defensible program needs
| Element | What it requires | Evidence |
|---|---|---|
| Unfair-discrimination testing | Test outcomes for proxy and disparate-impact effects across protected classes | Documented testing and mitigations |
| External-data governance | Control the provenance and use of external consumer data and its outputs | Data lineage and permitted-use records |
| Governance framework | An AI systems program with accountability, policies, and inventory | Written program mapped to NIST AI RMF and ISO 42001 |
| Documentation and filings | Records and any filings the state expects | Reviewable documentation |
| Monitoring | Ongoing testing as models and data drift | Monitoring logs and remediation records |
| Human accountability | A person accountable for the underwriting or pricing decision | Clear ownership and review records |
The NAIC Model Bulletin and state rules
Where PiTech fits
PiTech Solutions builds the data, testing, and governance behind defensible AI underwriting and pricing: unfair-discrimination and proxy testing pipelines, external-data lineage and permitted-use controls, an AI governance program mapped to the NIST AI RMF and ISO 42001, and the documentation an examination expects. It works alongside the insurer’s actuarial, underwriting, and compliance teams, owning the data and testing that turn a fairness policy into evidence. Delivery runs under CMMI Level 3 and ISO 27001, 9001, and 42001 certifications. See the insurance practice, AI, GenAI and ML, and Data Solutions. PiTech Solutions Inc. is headquartered in Durham, North Carolina (UEI GNLRY5LNNVH6, CAGE 530K4) and is distinct from similarly named companies.
The bottom line
Frequently Asked Questions (FAQs)
How is AI regulated in insurance underwriting and pricing?
Can an insurance model be discriminatory if it excludes protected characteristics?
Yes. Removing race, and other protected characteristics from the inputs does not make a model fair, because other variables can act as proxies and reproduce the same disparate outcomes. This is why regulators focus on testing outcomes for unfair discrimination rather than accepting input exclusion as sufficient. A model can be facially neutral and still produce results that disadvantage a protected class, which requires detection and mitigation. The defensible approach tests model outcomes across protected classes for proxy and disparate-impact effects, documents what is found, and addresses it. Treating the omission of sensitive fields as compliance is one of the most common and consequential mistakes in AI underwriting and pricing.


