Every verdict comes from the estate behind the answer.
Each verdict comes from the models, documents and policies you record, not from the wording of your answers. A question left blank escalates on that alone, because a reviewer raises it. A complete answer and a survivable answer are different things, and the number measures the second.
One fact, one rule, one finding, and the questions it blocks.
Twenty rules written from the carrier side of the table, each one a fact, the rule it triggers, the finding a reviewer writes down, and the item it blocks. This is the first rule, on the first question, as the engine derives it; the explorer below runs the worst nine answers through all of them.
- FactA third-party model, and no approved record names the provider
- RuleR-SUBPROCESSOR
- FindingProvider not named in an approved record for the system you described
- VerdictStop
- BlocksAIS-4.2, critical weight 3
6 findings from the worst nine answers. Arrow keys move.
Provider not named in an approved record for the system you described
One model (the system you described) runs on a third-party provider that is not named in any approved record. "A leading commercial provider" is not an answer a reviewer can write down. The carrier has to name every third party in its own examination response, so an unnamed provider makes your gap their finding, and a reviewer who cannot close a question in their own file will stop and ask rather than accept it. A provider you cannot name is also one whose security posture and data retention you cannot answer for, which is why the questions on those follow this one.
To fix: Name every model provider, hosting region, and data processor that touches insurer data, with contract reference and an accountable owner. A single approved table is enough, as long as it is kept current.
- AIS-4.2blockedcritical, weight 3Identify all third parties whose AI systems, models, or model outputs are incorporated into the products or services provided to the insurer, including processing location.NAIC AI model bulletin, Section 4 ¶2.1 · 23 NYCRR 500.11(a)(1)
- AIS-4.1degradedstandard, weight 2Describe the due diligence performed on third parties whose models or data are incorporated into the service.NAIC AI model bulletin, Section 3 ¶4.1 and Section 4 ¶2.1
- AIS-4.3degradedstandard, weight 2Describe contractual provisions governing the third party’s use of insurer data for model training.NAIC AI model bulletin, Section 3 ¶4.2 and Section 4 ¶2.2
- AIS-2.1degradedcritical, weight 3Provide a complete inventory of AI systems used in delivering the service, including the insurance function each supports.NAIC AI model bulletin, Section 3 ¶3.3(a) · AI Systems Evaluation Tool (pilot)
- SEC-1.1degradedstandard, weight 2Describe the information security controls applicable to the insurer’s nonpublic information held or processed by the third party.23 NYCRR 500.11(a)
- SEC-5.1degradedcontextual, weight 1Confirm the retention period applied to insurer nonpublic information after contract termination.23 NYCRR 500.13(b)
Answer the nine for your own estate, free, in your browser.
The whole calculation, on the page. Credit per verdict is fixed, pass 1.00, questioned 0.60, escalate 0.20, stop 0.00, multiplied by the weight the question carries in an examination. No model decides your score. The same facts produce the same number every time, which is the only kind of number that survives being questioned by a CISO.
An unanswered item earns nothing and still takes the citation penalty, so a profile cannot be improved by deleting an inconvenient answer.
Where this wins, and where it does not try to.
Read from the public sites of the leading products in each category on 18 and 20 September 2026. Two rows below say no on our side. They are there because a buyer checks.
| Compliance automation platforms | Trust-centre and questionnaire tools | Analyst-led questionnaire services | Vaulith | |
|---|---|---|---|---|
| Time to a first result | Four to twelve weeks, after a demo and integrations | A kickoff call, a document upload, then a trial period | Same day to twelve hours per questionnaire, after onboarding and a knowledge library | Ninety seconds free; about thirty minutes paid |
| The price, on the website | Not shown; get a demo | A free tier and "custom" | Not shown; three tiers, get a demo | $499, stated, paid by card |
| What is scored | Control completeness against a framework | Nothing is scored; documents are served | Nothing is scored; answers are drafted by AI and verified by analysts | A reviewer's reaction to each answer, with the arithmetic shown |
| The questions it scores against | Framework control lists | Not applicable | Whatever the questionnaire in front of them asks | Twenty-five, published, each with its authority |
| Policy checked against practice | No | No | No | Yes: what your policy promises against what your estate shows |
| What a carrier reviewer receives | A trust centre behind an access request | A trust centre with badges and gated documents | A completed questionnaire, and a trust centre with NDA gating and watermarking | A link with cited answers, the security posture, what changed since their last visit, and no account |
| Continuous monitoring and integrations | Yes | Some | Hundreds of integrations | No, by design: it reads what you tell it |
| Evidence collected from your systems | Yes | No | Through integrations and a knowledge library | No, by design: you describe your documents, and nothing scans them |
The twenty-five questions a carrier's AI review turns on.
Grouped by topic, each with the obligation it discharges. A reviewer who can see which obligation an answer closes can close it in their own file, and an item they can close is an item that does not become a phone call. The Vaulith team drew the twenty-five from the NAIC AI model bulletin, the NAIC AI Systems Evaluation Tool and the third-party provisions of 23 NYCRR 500, and every item is published with the paragraph it comes from. None of the three categories in the table above publishes the questions it scores against.