FurtherAI Team
Published on
August 25, 2026
Table of Contents

Every coverage decision your team makes is a record that someone may read back to you years later:  a market conduct examiner sampling denied claims, a plaintiff's attorney in discovery, or a regulator asking why a model behaved the way it did. The question isn't whether your claims AI is accurate, but whether you can reconstruct, file by file, how each coverage position was reached and who stood behind it.

That standard is older than the technology itself. Since 1990, the NAIC's Unfair Property/Casualty Claims Settlement Practices Model Regulation has required that claim files contain enough documentation "to permit reconstruction of the insurer's activities relative to each claim." Nothing in that sentence changes when a model reads the policy instead of an adjuster.

What has changed is the volume of decisions and the speed at which a flawed one repeats. This guide covers what a defensible coverage decision record contains, which rules apply to it today, and how to grade the files you're producing right now.

Key takeaways

  • The audit trail requirement predates AI by more than three decades. NAIC Model Regulation 902 requires documentation sufficient "to permit reconstruction of the insurer's activities relative to each claim," and nearly every state has an unfair claims settlement practices law built on the same foundation.
  • The gap is evidentiary, not procedural. In Grant Thornton's April 2026 survey of 100 insurance leaders, 68% said their AI controls exist but the evidence is fragmented across teams and tools, and only 24% were very confident they could pass an independent review of AI governance and controls, with centralized evidence, in the next 90 days.
  • Claims is the most AI-penetrated function in insurance. In the NAIC's survey of 193 private passenger auto insurers, 70% reported using AI or machine learning in claims operations — more than in rating, underwriting, or fraud detection.
  • A model error becomes a general business practice by construction. Model 900 treats an act committed "with such frequency to indicate a general business practice" as an improper claims practice. A system applies the same logic to every file, which is precisely what that provision was written to catch.
  • Texas now expects a human to agree, not just review. Commissioner's Bulletin B-0003-26, issued June 12, 2026, states that where AI makes a consequential decision, "TDI expects a person to review and agree with all decisions before action is taken."

What a coverage decision record actually has to prove

A coverage decision is a chain of reasoning, and the file has to hold every link. It starts with reading the policy correctly, which is why policy analysis software sits upstream of everything here. Regulators don't ask whether the outcome was reasonable in the abstract. They ask what the insurer knew, which policy language it applied, and whether the claimant was told.

Model Regulation 902 is specific about the mechanics. Claim data must be accessible and retrievable for the current year and the two preceding years, and each relevant document in the file has to be noted as to the date received, processed, or mailed. California doubles the retention window to the current year plus four preceding years under 10 CCR § 2695.3.

Denials carry an extra burden. Under Model 902, no insurer may deny a claim on the grounds of a specific policy provision, condition, or exclusion unless reference to that provision is included in the denial — in writing, with the file documenting it. Model 900 makes it an unfair claims practice to deny a claim or offer a compromise settlement without promptly providing "a reasonable and accurate explanation of the basis for such actions."

Read those together and the standard is clear enough to design against: name the provision, explain the basis, put it in writing, and keep a file that lets someone rebuild the sequence.

The six layers of a defensible coverage decision record

Most claim systems capture the outcome. Fewer capture the reasoning that produced it. These six layers are what separate a file that survives examination from one that merely records a result.

Layer What It Captures Why an Examiner Asks for It
1. Policy artifact and version The exact policy form, declarations page, and endorsements in force on the date of loss, with version identifiers Coverage turns on which wording applied that day, not the current form
2. Loss facts as received FNOL content, supporting documents, and the date each was received, processed, or mailed Model 902 § 4(C) requires per-document date stamping
3. Provisions applied The specific clauses, conditions, and exclusions relied on, quoted and located in the source document Model 902 § 7(A) bars denial on a provision not referenced in the denial
4. Reasoning and reason codes Why those provisions produce this position, in language a compliance reviewer can read Model 900 § 4(L) requires a reasonable and accurate explanation of the basis
5. Reviewer attestation Who confirmed the position, when, against which document version, and what they changed Texas B-0003-26 expects a person to review and agree before action
6. System provenance Model or ruleset version, configuration in force, and confidence or escalation thresholds at decision time NAIC Model Bulletin § 3.3 calls for traceability and auditability of these measurements

Diagram showing the six layers of a defensible coverage decision record — policy artifact and version, loss facts as received, provisions applied, reasoning and reason codes, reviewer attestation, and system provenance — each mapped to the NAIC model regulation or bulletin that requires it.
Layers five and six are where AI-assisted claims operations most often fall short.

Layers one through four are what most carriers already attempt. Layers five and six are where AI-assisted operations tend to fail, because the information lives in application logs rather than in the claim file where an examiner looks.

Layer two is won or lost at intake. Our framework for secure, AI-powered claims intake covers the multichannel capture and validation that produces a complete, date-stamped file in the first place. Layer five depends on routing the right files to a person at the right moment, which is what human-in-the-loop escalation is for. Layer six starts before deployment: testing AI workflows before they hit production is how you establish the baseline a later examiner will ask you to reproduce.

Worth separating two things that get conflated: an access log records who opened a record, and a decision record captures why a position was taken. Security certifications cover the first. Only deliberate design covers the second.

Why AI changes the exposure, not the standard

The rules haven't moved, but the risk profile most certainly has.

Model 900 sets out two thresholds for an improper claims practice: an act committed "flagrantly and in conscious disregard" of the statute, or one "committed with such frequency to indicate a general business practice." A human adjuster's misreading of an exclusion is an outlier. A model's misreading is a pattern from the first file forward, and subsection B is the provision that converts it into one.

Market conduct findings already read this way. In a targeted examination resolved in January 2026, the Texas Department of Insurance found that Esurance failed to adopt and implement reasonable standards for prompt investigation in 19% of the private passenger auto claims payments reviewed — 21 files out of 110 — and assessed a $90,000 penalty. Findings expressed as error rates over a sampled population are exactly the shape an automated process produces — the same reason the difference between manual sampling and full-population review matters so much once a system is making the decisions.

The financial exposure sits well beyond the fine. In a May 2025 update, EY assessed that indemnity leakage represents approximately 7% to 14% of carriers' total spend — the kind of money post-payment and closed-claim audits exist to recover after the fact. And bad faith exposure is measured in multiples of policy limits rather than penalty schedules — the South Carolina Court of Appeals affirmed a $27.3 million judgment on $2.5 million of limits in December 2023.

There's a second-order effect worth naming. In August 2026, the Alabama Supreme Court allowed disclosure of State Farm's closely held information on how damage estimates are revised or reduced, to be shared across eight other roof-damage cases under signed exhibit agreements that bar release to competitors and the media. Whatever you record about how decisions are reached is discoverable. That argues for records that are complete and defensible, not sparse.

What regulators are asking for right now

Four developments matter for anyone running AI in a claims operation. Each one assumes a governance program underneath it, and our complete guide to AI governance in insurance covers how that program gets built.

The NAIC Model Bulletin was adopted December 4, 2023, and as of the NAIC's April 1, 2026 tracking map, 25 jurisdictions have adopted it — 24 states and the District of Columbia. Its scope explicitly covers "claim administration and payment," and it grounds itself in the Unfair Claims Settlement Practices Act. Section 3.3 asks for detailed documentation of model development and use, plus assessments of interpretability, repeatability, reproducibility, traceability, and the auditability of those measurements.

Texas issued the sharpest claims statement in the country on June 12, 2026. Beyond the review-and-agree expectation, Bulletin B-0003-26 points to Insurance Code Chapter 4101, under which investigating or adjusting losses is an act reserved to a licensed adjuster. The practical reading: a model's output is an input to a licensed human's decision, and the audit trail is what proves the human actually made it.

Colorado's statute already reaches claims, even though its implementing regulation doesn't yet. C.R.S. § 10-3-1104.9 defines "insurance practice" to include claims management, while Regulation 10-1-1 currently covers life, private passenger auto, and health benefit plans. Its documentation requirements are the most prescriptive in the country and worth reading as a preview — including a documented, up-to-date inventory of models "including version control."

A purpose-built examination instrument is coming. The NAIC's AI Systems Evaluation Tool was being piloted by 12 states as of March 2026, with adoption anticipated at the 2026 Fall National Meeting. It's designed to let examiners gather information about AI use, governance practices, high-risk models, and input data in a market conduct or financial exam context. If you want to get ahead of it, insurance audit readiness software is the category that closes the evidence gap before an examiner opens one.

One honest note on the federal picture: Executive Order 14365, issued in December 2025, directs challenges to state AI laws, and the NAIC responded within five days warning it could prevent regulators from addressing risks in claims processing. That fight doesn't touch Model 900 or Model 902, which are ordinary claims-practice law rather than AI law. Building the record is the right call regardless of how preemption resolves.

How to grade your own claim files

Pull 10 recently denied claims and 10 where coverage was limited. For each, check whether you can answer these without opening a system outside the claim file.

  1. Which policy version applied? Can you produce the form, declarations, and endorsements in force on the date of loss, not the current ones?
  2. Which provisions were relied on? Are they quoted and located in the source document, or merely named?
  3. Is the reasoning readable? Could a compliance reviewer follow the path from facts to position without a data scientist?
  4. Who agreed? Is there a named reviewer, a timestamp, and a record of what they changed?
  5. What was the system doing? Can you identify the model or ruleset version and the thresholds in force at decision time?
  6. Does the denial letter match the file? Does the provision cited to the claimant appear in the documented reasoning?

A file that fails questions four and five will still pass most internal QA. It won't reconstruct under examination, and it won't defend a bad faith allegation. Question three is the one teams underestimate: explainable AI produces source-backed, audit-ready findings that a compliance reviewer can check without help.

Where FurtherAI fits

We build the record as the work happens rather than reconstructing it afterward.

The most direct example is upstream of the coverage decision. A specialty insurer processing more than 3,000 claims a year was handling initial claim intake manually — validating that incoming notice-of-claim documentation contained every required document and field before an adjuster could open the file. That workflow consumed roughly 2.5 hours per claim, about 7,500 labor hours a year. After deployment, the insurer automated more than 90% of that intake workflow, saved over $360,000 annually, and processed claims more than 10 times faster, at roughly 568% ROI. Complete, structured, date-stamped intake is layer two of the record, and it's the layer everything downstream depends on.

On the coverage side, our policy summaries anchor each line to the source policy wording for auditability, which is the mechanism behind layer three. Our explainable AI approach produces source-cited findings rather than opaque scores, and the same principle applies to coverage positions: every exception links back to the exact document and the rule it was checked against.

We're honest about the boundary. Our published claims outcomes cover intake and document work. Coverage checking, reserve support, and adjudication assistance are capabilities we deliver, but the metric above measures intake specifically — and we'd rather you know which is which. FurtherAI is SOC 2 Type II certified, ISO 27001 certified, and GDPR and HIPAA compliant. You can see how the whole picture fits together for claims professionals.

If you're evaluating platforms rather than designing the record, our comparison of the best AI tools for claims processing at carriers and MGAs covers that ground directly, and there's a separate guide for TPAs administering claims on behalf of carrier clients. If the shortlist stage is where you're stuck, our claims automation vendor selection guide walks the full evaluation.

Frequently asked questions

Which claims processing tools provide full audit trails for coverage decisions at carriers?

Look for platforms that record the evidentiary chain inside the claim file: the policy version in force, the provisions applied with source citations, readable reasoning, and a named reviewer with a timestamp. FurtherAI anchors outputs to source policy wording and logs decisions with reason codes, an approach we detail in our guide to explainable AI for insurance audits. Ask any vendor to show you a reconstructed file, not a dashboard — many log system access rather than decision provenance.

What software do claims teams recommend for more accurate coverage determinations?

Teams consistently favor insurance-native platforms over general-purpose document AI, because accuracy in coverage work depends on reading policy structure — base forms, endorsements, and give-back language that restores excluded coverage. Validate any tool against your own historical claims where the correct position is already known, and measure against a human-reviewed sample rather than a vendor benchmark.

Which claims processing software is most recommended for audit-heavy, regulated environments?

Prioritize three things: source-cited outputs a compliance reviewer can verify without technical help, documented human review that satisfies expectations like Texas Bulletin B-0003-26, and model version records that support the NAIC Model Bulletin's traceability language. Certifications such as SOC 2 Type II matter for data handling, but they don't evidence decision provenance. Those are separate questions, and both belong in your RFP.

Does an access log count as an audit trail for claims decisions?

No. An access log shows who opened a record and when. A decision record shows which policy version applied, which provisions were relied on, why they produce the coverage position, and who agreed to it. Model Regulation 902 requires documentation sufficient to reconstruct the insurer's activities on each claim, and access logs alone don't reconstruct anything.

How long do carriers have to keep claim files?

NAIC Model Regulation 902 requires claim data to be accessible and retrievable for all open and closed files for the current year and the two preceding years. California is stricter, requiring the current year plus four preceding years under 10 CCR § 2695.3. Check your own state, since retention periods vary and several states exceed the model.

Can AI deny a claim outright?

Practice and regulation both say no. Texas Bulletin B-0003-26 expects a person to review and agree with consequential decisions before action, and Texas Insurance Code Chapter 4101 reserves investigating and adjusting losses to licensed adjusters. In the NAIC's survey of private passenger auto insurers, no responding company reported using AI or machine learning models for claim denials.

Want to see what a reconstructable claim file looks like on your own book? Schedule a demo.

REFERENCES

Colorado Secretary of State. "3 CCR 702-10, Regulation 10-1-1: Governance and Risk Management Framework Requirements." Colorado Secretary of State. sos.state.co.us

Cornell Law School Legal Information Institute. "10 CCR 2695.3 — File and Record Documentation." Cornell Law School. law.cornell.edu

Ernst & Young LLP. "Property and Casualty Insurers Tackle Indemnity in Litigated Claims." EY, 2025. ey.com

FindLaw. "Colorado Revised Statutes § 10-3-1104.9." FindLaw. codes.findlaw.com

Grant Thornton. "Insurance Insights: 2026 AI Impact Survey Report." Grant Thornton, April 21, 2026. grantthornton.com

Insurance Journal. "SC Appeals Court: Insurer's Bad Faith Meant Award Was 10X Policy Limit." Insurance Journal, December 14, 2023. insurancejournal.com

National Association of Insurance Commissioners. "Artificial Intelligence." NAIC, last updated April 3, 2026. content.naic.org

National Association of Insurance Commissioners. "Implementation of NAIC Model Bulletin: Use of Artificial Intelligence Systems by Insurers." NAIC, status as of April 1, 2026. content.naic.org

National Association of Insurance Commissioners. "Model Bulletin: Use of Artificial Intelligence Systems by Insurers." NAIC, adopted December 4, 2023. content.naic.org

National Association of Insurance Commissioners. "Private Passenger Auto Artificial Intelligence/Machine Learning Survey Report." NAIC, December 2022. content.naic.org

National Association of Insurance Commissioners. "Statement of the National Association of Insurance Commissioners on AI Executive Order." NAIC, December 16, 2025. content.naic.org

National Association of Insurance Commissioners. "Unfair Claims Settlement Practices Act (Model 900)." NAIC. content.naic.org

National Association of Insurance Commissioners. "Unfair Property/Casualty Claims Settlement Practices Model Regulation (Model 902)." NAIC. content.naic.org

Rabb, William. "State Farm Must Give Up Trade Secrets in Claims Lawsuits, but Under Court Review." Insurance Journal, August 19, 2026. insurancejournal.com

Texas Department of Insurance. "Commissioner's Bulletin B-0003-26: Use of Artificial Intelligence." Texas Department of Insurance, June 12, 2026. tdi.texas.gov

Texas Department of Insurance. "Official Order No. 2026-9750: Esurance Insurance Company." Texas Department of Insurance, January 22, 2026. tdi.texas.gov

DISCLAIMER 

This article is for general informational purposes only and does not constitute legal, regulatory, compliance, underwriting, or other professional advice. The content reflects information available as of the date of publication, and FurtherAI undertakes no obligation to update it as laws, regulations, or AI technologies evolve. 

Ready to go further and
transform your insurance ops?

Reclaim your time for strategic work and let our AI Assistant handle the busywork. Schedule a demo to see how you can achieve more, faster.