ND| North Dakota Insurance & Securities Bulletin 2026-2, effective October 5, 2026, states that every insurer licensed in North Dakota remains responsible for ensuring that consumer-impacting decisions made or supported by algorithms, predictive models, big data, machine learning, or other AI systems comply with applicable insurance law. The Department emphasizes that AI use does not change the underlying legal standards: insurer actions must not be arbitrary, capricious, unfairly discriminatory, or otherwise constitute unfair trade or claims-settlement practices. Although the bulletin frames many operational expectations as guidance rather than prescriptive mandates, it makes clear that insurers’ AI governance, documentation, and vendor oversight may be scrutinized in examinations, investigations, and market-conduct actions.
- Establish a risk-based AI Systems (AIS) Program. Insurers are encouraged to adopt and maintain a written AIS Program proportionate to their AI use, the significance of consumer decisions involved, potential consumer harm, human involvement, and dependence on third-party data, models, or systems. The program should address the entire insurance and AI lifecycle—from product development, marketing, underwriting, rating, and claims through fraud detection—and should be approved by the board or an appropriate board committee, with senior management responsible for implementation and oversight
- Implement documented governance, controls, and model oversight. The Department expects governance structures that prioritize transparency, fairness, and accountability; clearly assign roles across business, actuarial, data science, compliance, and legal functions; provide training, escalation, monitoring, auditing, and reporting; and maintain controls over data lineage, quality, integrity, suitability, bias analysis and minimization, privacy, security, retention, model validation, benchmarking, interpretability, reproducibility, and drift monitoring. Predictive models should have documented objectives, development and validation records, and methods to detect and address errors or unfair discrimination.
- Treat third-party AI as the insurer’s compliance risk. For vendor-provided data, models, or AI systems, insurers should perform pre-use due diligence and ongoing oversight, obtain contractual rights to audit vendors and receive qualified audit reports, require vendors to maintain comparable AI governance standards, and require cooperation with regulators. In an examination or investigation, the Department may request the AIS Program, board-adoption evidence, model and system inventories, data provenance and bias documentation, testing and audit results, vendor diligence materials, contracts, and records demonstrating compliance with the insurer’s own policies and applicable legal requirements.