{{item.title}}
{{item.text}}
{{item.text}}
Over the past 15 years, banking regulatory guidance, particularly SR 11-7, has influenced model risk management (MRM) practices in the US insurance industry, even though most insurers were not directly subject to it. With the release of SR 26-2 in April 2026, that reference point changed, creating an opportunity for insurers to rethink how they govern models. The updated guidance provides a basis to align oversight with the specific decisions each model supports.
With SR 26-2, there’s an opportunity for insurers to rethink how they govern models.
Interpretations of banking MRM have shaped how insurers built model inventories, established model governance policies, documented models, and conducted validations, often emphasizing fixed review cycles and uniform procedures by model risk rating category. While this helped establish much-needed governance structures, it didn’t account for a defining characteristic of many legacy insurance models: a single model often supports multiple use cases (model-based decisions). Attempting to ensure a model is fit for purpose for all use cases at once is a time-consuming process that often feels disproportionate to the value it delivers. Since model governance frameworks emerged in the 2010s, the rapid and ever-increasing deployment of AI-enabled models has further complicated the model ecosystem.
The model landscape within insurance is strongly influenced by actuarial functions—pricing, reserving, capital, reinsurance, asset-liability management (ALM), and forecasting. The models underlying these functions can determine significant estimates on the insurer’s balance sheet but also inform decisions that impact customers, risk exposure, and strategic direction. In 2019, the American Academy of Actuaries issued Actuarial Standard of Practice No. 56, Modeling (ASOP No. 56), a principle-based guidance emphasizing model life cycle, materiality, intended purpose, and professional judgment.
ASOP No. 56 gave actuaries working with models a framework that reflected how models should be built, maintained, and reviewed within insurance. At the same time, however, it added tension with the more prescriptive interpretations of SR 11-7 that many insurers had already adopted. This created a disconnect for insurers trying to reconcile the two frameworks. Although SR 11-7 acknowledged the concept of materiality, many insurers built rigid governance procedures that resulted in fatigue and ultimately diminished their effectiveness. ASOP No. 56, in contrast, asked actuaries to exercise judgment based on materiality and purpose. SR 26-2 changes the reference point.
The updated guidance supersedes SR 11-7 and moves away from detailed supervisory expectations toward a more principle-based, risk-tailored approach. It places greater responsibility on organizations to determine how MRM should apply based on model purpose, exposure, complexity, and risk. For insurers, the importance of this shift is that SR 26-2 offers an opportunity to reassess MRM frameworks that were influenced by SR 11-7.
Updated guidance moves away from detailed supervisory expectations toward a more principle-based, risk-tailored approach.
Banking MRM guidance is now more closely aligned with principles insurers already recognize through ASOP No. 56. SR 26-2 doesn’t eliminate the expectation that companies assess individual models and it retains model-level oversight as foundational. What it shifts focus to is how much governance a given model warrants. That determination should center on the significance of the decisions the model supports, who owns those decisions, what influences them, and how outcomes are monitored. When one model serves multiple use cases carrying different emphasis at different times, this creates explicit room to differentiate validation depth and frequency based on decision impact (use case) rather than validating or revalidating the full model with all its use cases at once.
Not all use cases are created equal, even within the same model |
|---|
Life insurance |
Let’s take a fixed indexed annuity (FIA) model hosted on a given actuarial platform. Often the FIA model has several use cases: CARVM statutory reserves, Market Risk Benefit (MRB) balances under GAAP, embedded value, and business plan. Historically, all use cases for a given model would be identified and all use cases would be governed and validated together. VM-22 is the new statutory valuation regulation replacing CARVM for nonvariable annuities issued as early as 2026, and insurers are preparing their models for implementation now. Under a decision-driven/use case approach, a company can prioritize the components of the model that drive the VM-22 use case, for example. Validation effort flows to the use case that needs assurance now, not the one whose turn came up on the calendar. |
P&C insurance |
Consider a property insurer’s catastrophe model. The same model may support pricing adequacy analysis, probable maximum loss (PML) estimates for reinsurance purchasing, and capital modeling for regulatory filings. Under a fixed validation cycle, all three use cases receive the same level of review. But if the company is approaching a reinsurance renewal and the PML estimates will directly inform how much coverage to buy, that use case carries more immediate decision weight than the others. A decision-driven approach directs validation effort to the reinsurance use case first—ensuring the model is fit for purpose before the placement decision is made. |
Insurers increasingly use AI models in the course of business, with AI influencing underwriting, pricing, claims, fraud detection, and marketing and communications, to name a few. Regulators are responding. A growing body of AI governance expectations is emerging at both the state and federal level. As AI becomes more embedded in decisions with customer impact, insurers will need to govern not only the AI models, but also the decisions they inform.
Consider an accelerated underwriting program that uses machine learning, where a predictive model scores life insurance applicants using prescription and medical history data, along with financial attributes, to determine eligibility for coverage without a paramedical exam. The governance focus isn’t simply on whether the scoring model was validated. It’s whether the decision to issue coverage without traditional medical evidence is governed, supportable, and monitored for adverse mortality experience over time. That’s the difference between governing a model and governing a model-based decision.
For generative AI (GenAI) and agentic AI, that discipline becomes even more important. Outputs may vary, explainability may be limited, and human review is essential. While SR 26-2 excludes GenAI and agentic AI from its scope, insurers are not without guidance. The rapidly expanding regulatory landscape offers insurers a solid basis for governing AI model enabled decisions.
For generative AI (GenAI) and agentic AI, modeling discipline becomes even more important.
The same principles that support modernized MRM for legacy insurance models—risk-based proportionality, professional judgment, life cycle oversight, and proportionate documentation—can also help insurers govern decisions informed by AI models. ASOP No. 56 provides guidance to actuaries relying on models, data, or outputs they did not develop, emphasizing that they remain accountable for how the model is used, monitored, and relied upon. It should include fit-for-purpose assessment, understanding of limitations, ongoing performance monitoring, issue escalation, and clear ownership for the business decision the model supports. What matters is asking the right questions. Where does the AI model enter the decision process? Who owns the decision? What influences the outcome? What evidence supports the decision? And how are outcomes monitored over time?
The convergence of SR 26-2 and actuarial guidance, combined with AI's rapid expansion of the models entering the decision ecosystem, gives insurers a timely opportunity to refine MRM around decision accountability. This doesn’t require abandoning existing model inventories, validation programs, or actuarial governance structures. Rather, it requires connecting those capabilities to the critical decisions they support.
Governance should follow the full decision lifecycle—from model design and development to assumption-setting, use, validation, monitoring, override, escalation, and change. The objective isn’t to reduce rigor but to apply it where it matters most and create clearer evidence that material model-informed decisions are governed, explainable, and monitored.
So, what should insurers do now?
Taken together, these actions move MRM from a model-by-model governance framework to an enterprise capability for decision accountability. The goal is to govern the decisions that matter most with the right level of visibility, ownership, challenge, evidence, and outcome monitoring.
The endgame is for MRM to move from a model-by-model governance framework to an enterprise capability for decision accountability.
Moving from a complex, full model-based governance framework to a model use case-driven approach requires organizational alignment. Executive management must buy into the case for change. Model owners need confidence that they’ll be focusing effort where it’s needed rather than simply facing additional burdens. Only then should MRM leaders overhaul model governance policies, roles and responsibilities, and guidance.
When governance moves beyond just procedural adherence to directly influencing decisions, carriers will move beyond compliance to engagement. These high-impact, model-informed decisions will have clear accountability, challenge protocols, and remediation paths. As a result, insurers can reduce governance burdens while strengthening oversight where model risk matters most.
{{item.text}}
{{item.text}}