VaulithNine questions, free
Resources · how the engine decides

Every verdict comes from the estate behind the answer.

Each verdict comes from the models, documents and policies you record, not from the wording of your answers. A question left blank escalates on that alone, because a reviewer raises it. A complete answer and a survivable answer are different things, and the number measures the second.

24rules, each one shown with its reasoning and its fix
25questions, each with the paragraph of the instrument it comes from
0people between your answers and your result, unless you ask the founding team to read them
01
The Reviewer Model

One fact, one rule, one finding, and the questions it blocks.

Twenty rules written from the carrier side of the table, each one a fact, the rule it triggers, the finding a reviewer writes down, and the item it blocks. This is the first rule, on the first question, as the engine derives it; the explorer below runs the worst nine answers through all of them.

  1. FactA third-party model, and no approved record names the provider
  2. RuleR-SUBPROCESSOR
  3. FindingProvider not named in an approved record for the system you described
  4. VerdictStop
  5. BlocksAIS-4.2, critical weight 3
The Reviewer Model: twenty rules written from the carrier side of the table, each one a fact, the rule it triggers, the finding a reviewer writes down, and the item it blocks. This is the first rule, on the first question, as the engine derives it.

6 findings from the worst nine answers. Arrow keys move.

It clears the moment one fact changes.Does anything in your product run on a third-party or fine-tuned model? Or: If a carrier asked today, could you send them a document that names your AI providers?
R-SUBPROCESSOR

Provider not named in an approved record for the system you described

One model (the system you described) runs on a third-party provider that is not named in any approved record. "A leading commercial provider" is not an answer a reviewer can write down. The carrier has to name every third party in its own examination response, so an unnamed provider makes your gap their finding, and a reviewer who cannot close a question in their own file will stop and ask rather than accept it. A provider you cannot name is also one whose security posture and data retention you cannot answer for, which is why the questions on those follow this one.

To fix: Name every model provider, hosting region, and data processor that touches insurer data, with contract reference and an accountable owner. A single approved table is enough, as long as it is kept current.

What it does to the examination
  • AIS-4.2blockedcritical, weight 3Identify all third parties whose AI systems, models, or model outputs are incorporated into the products or services provided to the insurer, including processing location.NAIC AI model bulletin, Section 4 ¶2.1 · 23 NYCRR 500.11(a)(1)
  • AIS-4.1degradedstandard, weight 2Describe the due diligence performed on third parties whose models or data are incorporated into the service.NAIC AI model bulletin, Section 3 ¶4.1 and Section 4 ¶2.1
  • AIS-4.3degradedstandard, weight 2Describe contractual provisions governing the third party’s use of insurer data for model training.NAIC AI model bulletin, Section 3 ¶4.2 and Section 4 ¶2.2
  • AIS-2.1degradedcritical, weight 3Provide a complete inventory of AI systems used in delivering the service, including the insurance function each supports.NAIC AI model bulletin, Section 3 ¶3.3(a) · AI Systems Evaluation Tool (pilot)
  • SEC-1.1degradedstandard, weight 2Describe the information security controls applicable to the insurer’s nonpublic information held or processed by the third party.23 NYCRR 500.11(a)
  • SEC-5.1degradedcontextual, weight 1Confirm the retention period applied to insurer nonpublic information after contract termination.23 NYCRR 500.13(b)

Answer the nine for your own estate, free, in your browser.

Weighted credit ÷ available weight21.4 ÷ 52
Base score41.2
Uncited assertions, 9 × 1.2− 10.8
Readiness30 / 100

The whole calculation, on the page. Credit per verdict is fixed, pass 1.00, questioned 0.60, escalate 0.20, stop 0.00, multiplied by the weight the question carries in an examination. No model decides your score. The same facts produce the same number every time, which is the only kind of number that survives being questioned by a CISO.

An unanswered item earns nothing and still takes the citation penalty, so a profile cannot be improved by deleting an inconvenient answer.

02
Against the category

Where this wins, and where it does not try to.

Read from the public sites of the leading products in each category on 18 and 20 September 2026. Two rows below say no on our side. They are there because a buyer checks.

Compliance automation platformsTrust-centre and questionnaire toolsAnalyst-led questionnaire servicesVaulith
Time to a first resultFour to twelve weeks, after a demo and integrationsA kickoff call, a document upload, then a trial periodSame day to twelve hours per questionnaire, after onboarding and a knowledge libraryNinety seconds free; about thirty minutes paid
The price, on the websiteNot shown; get a demoA free tier and "custom"Not shown; three tiers, get a demo$499, stated, paid by card
What is scoredControl completeness against a frameworkNothing is scored; documents are servedNothing is scored; answers are drafted by AI and verified by analystsA reviewer's reaction to each answer, with the arithmetic shown
The questions it scores againstFramework control listsNot applicableWhatever the questionnaire in front of them asksTwenty-five, published, each with its authority
Policy checked against practiceNoNoNoYes: what your policy promises against what your estate shows
What a carrier reviewer receivesA trust centre behind an access requestA trust centre with badges and gated documentsA completed questionnaire, and a trust centre with NDA gating and watermarkingA link with cited answers, the security posture, what changed since their last visit, and no account
Continuous monitoring and integrationsYesSomeHundreds of integrationsNo, by design: it reads what you tell it
Evidence collected from your systemsYesNoThrough integrations and a knowledge libraryNo, by design: you describe your documents, and nothing scans them
03
The canon

The twenty-five questions a carrier's AI review turns on.

Grouped by topic, each with the obligation it discharges. A reviewer who can see which obligation an answer closes can close it in their own file, and an item they can close is an item that does not become a phone call. The Vaulith team drew the twenty-five from the NAIC AI model bulletin, the NAIC AI Systems Evaluation Tool and the third-party provisions of 23 NYCRR 500, and every item is published with the paragraph it comes from. None of the three categories in the table above publishes the questions it scores against.