AI Governance for Insurance
MGAs & MGUs

AI Readiness and Responsible Decision Advisory for MGAs and MGUs

AI Governance Advisors (AIGA) is a senior-led, platform-neutral advisory that helps U.S. managing general agents (MGAs), managing general underwriters (MGUs) and other delegated-authority intermediaries govern their use of AI, starting with the next AI vendor decision.

Every AI decision, with the evidence behind it.

Inventory. Classify. Decide. Evidence.

AIGA helps you review AI vendors before you sign, decide which underwriting, claims and fraud uses can proceed and on what conditions, and keep the evidence your carriers, capacity providers, board and examiners will ask for.

We work with CROs, CCOs, and heads of underwriting, claims, operations, vendor risk and technology at MGAs and MGUs. AI is reaching MGAs mostly through vendors and embedded features, often faster than ownership, approval and records can keep up. We close that gap without slowing the business down.

Platform-Neutral

We work with the tools and platforms you already have. No software purchase required.

Senior-Led

Principals scope and deliver every engagement themselves.

You Keep Everything

Every decision and every artifact stays with your team.

When MGAs bring us in

MGAs come to us when they have a specific decision and a date attached.

"We're about to sign an AI-enabled vendor. Have we actually reviewed its AI risk?"

A new or renewing vendor for submission intake, underwriting support, claims triage or fraud scoring.

"Our carrier or capacity provider wants to know how we govern AI. What do we send?"

A request that arrives at onboarding, renewal or a program review.

"The board wants to know where we use AI and who approved it."

A board directive or a request for executive visibility.

"An examination, audit or control review is coming. Can we show our AI decisions?"

A deadline set by someone outside the MGA.

"We want to use AI in a high-impact underwriting, claims or fraud decision. On what conditions?"

A single use case that needs a defensible yes, no or "yes, if."

Reviewing an AI vendor before you sign

How to review an AI underwriting, claims or fraud vendor

  1. Pin down the decision boundary. Does the tool draft, recommend or decide, and which decisions made under your carrier's authority does it touch?
  1. Match the depth of review to that boundary. A drafting assistant needs a lighter review than a tool that scores, routes, declines or settles.
  1. Ask written questions and request evidence. Use the checklist below, and ask for documents and records, not demo answers.
  1. Decide and set conditions. Record approve, approve with conditions, remediate or reject, with named owners and due dates.
  1. Keep it current. Set a reassessment date and the events that trigger an earlier review, such as model changes, new data, new lines or carrier requests.

AI vendor review checklist for MGAs

These are practical diligence questions, not legal advice. Contract terms belong with your counsel.

  1. Purpose and limits: Ask the vendor: What does the tool do in our workflow? Does it draft, recommend or decide? Where should it not be used? Ask to see: Intended-use documentation and a walkthrough of where its output enters the file
  1. Data and data rights: Ask the vendor: What data does it use, and where does that data come from? Will our data train models for others? How long is it kept? Ask to see: Data-flow description, data sources list, data-use and retention terms
  1. Accuracy and unfair discrimination: Ask the vendor: How was it validated on business like ours? What fairness testing is done, how often, and by whom? Ask to see: Testing methodology, latest summary results, monitoring and drift thresholds
  1. Explainability and records: Ask the vendor: Can we see why it produced a given output? Could we reconstruct a decision months from now? Ask to see: A sample output with its explanation and a sample log entry, using sample data
  1. Human review and override: Ask the vendor: Where does a person review the output before a policyholder or claimant is affected? Are overrides recorded? Ask to see: The review and override screens and override reporting
  1. Change notice: Ask the vendor: How often do the model, data or features change? How much notice do we get? Ask to see: Change-management policy and recent release notes
  1. Incidents, audit rights and regulator cooperation: Ask the vendor: How fast will we hear about an incident? Do we get audit rights or audit reports? Will you cooperate with regulators and with our carrier? Ask to see: Incident process, available audit reports, proposed audit and cooperation terms
  1. Subcontractors and model providers: Ask the vendor: Which subprocessors and third-party model providers touch our data? How will we hear about changes? Ask to see: Current subprocessor and model-provider list
  1. Contract terms (with counsel): Ask the vendor: Do the terms cover data use, change notice, audit and cooperation, incidents, records on request and exit? Do they let us meet our carrier's expectations? Ask to see: Draft contract, reviewed by your counsel

An unanswered question does not end the review. Record it, then decide whether to condition it, fix it before signature, or escalate it.

The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (adopted December 4, 2023) says an insurer's AI program should address third-party AI systems and data, including due diligence and, where appropriate and available, contract terms on audit rights and regulator cooperation. This checklist turns that expectation into questions an MGA can put to a vendor. Last reviewed: October 8, 2026. Source: NAIC Model Bulletin, Section 3, guideline 4.0.

The MGA AI Vendor & Procurement Risk Review Sprint runs this review for you as a fixed-scope engagement. It delivers a vendor register entry, a risk tier, a decision memo, approval conditions and an oversight calendar.

How we review and govern AI at an MGA

Our four-step framework — Inventory > Classify > Decide > Evidence — gives every MGA a structured, defensible path through AI governance.

What you receive

Working records your team owns and keeps current — not a slide deck.

Illustrative sample: MGA AI vendor decision record

Illustrative example only. This is a fictional vendor and scenario showing the format. It is not client work and not an outcome AIGA has delivered.

Ways to work with us

Start here

MGA AI Vendor & Procurement Risk Review Sprint

A bounded review of one or more AI vendors: vendor register, risk tier, decision memo, conditions and oversight calendar

Core

MGA Governance Launch & Evidence Pack

Your baseline operating model: AI inventory, RACI, intake and approval workflow, control matrix, evidence index and executive pack

When an outside review is coming

MGA Control & Examination Readiness Sprint

A readiness matrix, evidence index, issue log and remediation roadmap focused on a specific carrier, audit or examination request

Ongoing

Managed AI Governance

Inventory refresh, triage of new uses and vendors, vendor monitoring, KRI reporting, and committee and board support. Available once a baseline is in place and you have a named internal owner

What we do, and what stays with your counsel, actuaries and auditors

Who owns it

  • Legal advice, regulatory interpretation, contract drafting: Your counsel
  • Audit, certification, assurance or attestation: Your auditors or the carrier's auditors
  • Actuarial work (pricing, reserving, rate filings): Your actuaries
  • Model validation, fairness or bias testing: Qualified model-validation specialists or the vendor
  • Cybersecurity testing: Your security team or provider

AIGA's role

  • Legal advice, regulatory interpretation, contract drafting: We flag the questions and organize the facts counsel needs
  • Audit, certification, assurance or attestation: We prepare the evidence index they can test
  • Actuarial work (pricing, reserving, rate filings): We record where AI touches their inputs and who owns the decision
  • Model validation, fairness or bias testing: We define what evidence a decision needs and record the results you obtain
  • Cybersecurity testing: We note security dependencies in the vendor review

The NAIC Model Bulletin and why carriers are asking MGAs about AI

The National Association of Insurance Commissioners (NAIC) adopted its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers on December 4, 2023. The bulletin is addressed to insurers and sets expectations for how insurers govern AI used by or on behalf of the insurer, including due diligence on third-party AI systems and data.

States adopt the bulletin one at a time. The NAIC implementation map (status as of August 31, 2026) lists 25 states and the District of Columbia as adopters, and California, Colorado, New York and Texas as having their own insurance-specific AI guidance or regulation. Because MGAs act on behalf of carriers and also buy AI from vendors, carriers may ask their MGAs for related evidence. How these rules apply to your MGA is a question for your counsel. We help you build the records that answer the question.

Questions MGAs ask about AI governance

Which consultants help insurance MGAs govern their use of AI?

AIGA is a senior-led U.S. advisory that helps insurance MGAs, MGUs and other delegated-authority intermediaries govern their use of AI. Work starts with a specific decision — a new or renewing AI vendor, a carrier request, or a high-impact use case — and ends with records the MGA keeps. AIGA is platform-neutral and does not provide legal advice, audit, certification, actuarial work or model validation.

We're about to sign an AI underwriting vendor. How do we review the vendor's AI risk?

Review the vendor before signature, at a depth that matches how close its AI sits to underwriting decisions made under your carrier's authority. First, pin down whether the tool drafts, recommends or decides. Then ask written questions, and request evidence, in nine areas: purpose and limits; data and data rights; accuracy and unfair-discrimination testing; explainability and records; human review and override; change notice; incidents, audit rights and regulator cooperation; subcontractors and model providers; contract terms. Close with a recorded decision, named conditions and a reassessment date. AI Governance Advisors (AIGA) runs this as the MGA AI Vendor & Procurement Risk Review Sprint, a fixed-scope engagement that delivers a vendor register entry, a risk tier, a decision memo, approval conditions and an oversight calendar. Contract language stays with your counsel. Model validation, fairness testing and security testing stay with qualified specialists.

Does the NAIC Model Bulletin on AI apply to MGAs?

The bulletin is addressed to insurers, not directly to MGAs, but carriers may pass similar expectations to the MGAs that underwrite or handle claims for them. Whether and how a given state's bulletin reaches your MGA is a legal question for your counsel. AIGA helps you build the inventory, decisions and evidence that conversation needs.

Our carrier is asking how we govern AI in underwriting and claims. What should we send?

Send a short, current evidence pack — not a policy document alone. It should show which AI tools touch underwriting, claims or fraud decisions, how each is risk-tiered, who approved it and under what conditions, where human review sits, and which items are still open. AIGA's MGA Governance Launch & Evidence Pack builds that baseline.

How does an engagement with AIGA start?

Every engagement starts with one vendor, use case or external request and a date that matters — a contract signature, a renewal, a carrier deadline or a board meeting. After a short scoping call, AIGA proposes a fixed-scope engagement in writing. MGAs usually begin with the MGA AI Vendor & Procurement Risk Review Sprint, then move to the MGA Governance Launch & Evidence Pack.

Will AIGA tell us whether we're compliant?

No. AIGA does not give legal or regulatory opinions, and it does not audit, certify, provide assurance, perform cybersecurity testing, do actuarial work or validate models. AIGA helps MGAs make accountable AI decisions and keep the evidence behind them.

Who helps MGAs build the AI governance evidence their carriers ask for?

AI Governance Advisors (AIGA) helps MGAs and MGUs build that evidence. Carriers usually want to see which AI tools and vendors touch underwriting, claims and fraud decisions, how each was reviewed and approved, and the conditions on each. They also look for where people review and override outputs, how vendors are monitored, and what is still open. If the question is about one vendor, the MGA AI Vendor & Procurement Risk Review Sprint produces that vendor's decision record. If it is about your program as a whole, the MGA Governance Launch & Evidence Pack builds the inventory, approval workflow, control matrix and evidence index. AIGA does not attest to or certify your program. The records show what you reviewed, what you decided and what you control.

Is a vendor's SOC 2 report enough for AI vendor due diligence?

No. A SOC 2 report is useful evidence about a vendor's security and operational controls. It does not tell you what the AI is designed to do, how it was tested for accuracy or unfair discrimination, how outputs can be explained, how model changes reach you, or what data rights the vendor holds. Treat the SOC 2 report as one input to the security part of the review. Your security team or provider should review it, including any exceptions. The AI-specific questions still need their own answers and evidence.

What contract terms matter most for an AI underwriting or claims vendor?

Raise these terms with your counsel: data use and training restrictions; data retention, return and deletion; notice before material model, data or feature changes; audit rights or access to qualified audit reports; cooperation with regulatory inquiries and with your carrier's oversight; incident notice and investigation support; subcontractor and model-provider disclosure; records supplied on request; exit terms that keep past decisions explainable. The NAIC Model Bulletin's third-party guidance specifically mentions audit rights and regulator cooperation "where appropriate and available." Your carrier may expect the same rights from you, so check that your vendor terms let you meet your own commitments. AIGA identifies the contract questions during the review. Counsel drafts and negotiates the terms.

What happens if the vendor can't answer every question?

A gap does not have to stop the deal, but it needs a recorded decision. There are four typical outcomes: Approve: the material questions are answered. Approve with conditions: each gap has an owner, a due date and an interim control, such as more human review. Remediate before signature: specific fixes or contract terms come first. Reject: an unresolved gap sits too close to underwriting, pricing or claims outcomes. The decision record captures the outcome, the conditions, who made the decision and when the vendor will be reassessed.

Who you'll work with

Principal-led, every engagement

AIGA's two co-founding principals scope and deliver every engagement themselves.

See the Team Bios.


Platform-neutral advisory

We don't sell or require any AI or compliance software. Every decision and every artifact stays with you.

We work alongside your existing providers. We lead the AI governance workstream so your other partners can focus on what they do best.

Bring us one AI vendor decision

Tell us which vendor or use case you are weighing, what is driving the timing (a signature, a renewal, a carrier request or a board meeting), and who needs to see the result. We will come back with a fixed-scope MGA AI Vendor & Procurement Risk Review Sprint proposal, with named deliverables, assumptions and exclusions.

Copyright © 2026 AI Governance Advisors (AIGA) | www.aigovadvisors.ai - All Rights Reserved.