Scrutineer.ai

Scrutineer · By framework

NAIC Insurance Data Security Model Law software

The NAIC Insurance Data Security Model Law, Model 668, is enacted in about half the states. Licensees need a written security program, vendor oversight, an incident response plan and a commissioner notice within 72 hours. Domestic insurers also certify compliance every February 15.

Scrutineer maps each obligation to controls you already evidence for SOC 2, ISO 27001 or NYDFS Part 500. Compliance software, not legal advice.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with NAIC model 668

The small-licensee exemption covers Section 4 only. The 72-hour clock still applies

The most common misreading of Model 668 at small agencies is that fewer than ten employees means the law does not apply. Section 9A(1) exempts a licensee with fewer than ten employees, counting independent contractors, from Section 4 of the Act, which is the information security program. It does not exempt that licensee from Section 5, the duty to investigate a cybersecurity event, or from Section 6, the duty to notify the commissioner within 72 hours. So a nine-person agency can skip the written program under the model text and still owes a prompt investigation, five years of event records and a notice containing up to thirteen named data elements. Losing the exemption is not instant either: under Section 9B a licensee that stops qualifying has 180 days to comply. Adopting states have changed details like this, so read your own state's enacted text, but the structure of the exemption is the part most summaries get wrong.

Nonpublic Information is wider than a breach law, and the clock starts at determination

Most state breach notification laws turn on consumer identifiers. Model 668 defines Nonpublic Information to include business related information of the licensee whose tampering, unauthorized disclosure, access or use would cause a material adverse impact to the business, operations or security of the licensee. A ransomware event that encrypts your rating models or claims system, with no consumer record touched, can therefore still be a cybersecurity event you investigate and, where it is reasonably likely to materially harm a material part of your normal operations, report. The 72 hours in Section 6A run from a determination that a cybersecurity event has occurred, not from first alert, which is why the investigation record matters: it shows when you knew. The notice then carries a continuing obligation to update and supplement, so the same record keeps growing after the first filing.

One control library can carry several states, NYDFS and HIPAA at once

The model was written to sit alongside frameworks insurers already run. Its drafting note says a licensee in compliance with NYDFS Part 500 is also in compliance with the Act, and Section 9A(2) treats a HIPAA covered licensee with a maintained information security program as meeting Section 4, provided it submits a written statement certifying that compliance. The controls overlap heavily with SOC 2 and ISO 27001: access control, encryption of Nonpublic Information in transit over external networks and on portable devices, secure development, monitoring, audit trails and secure disposal. Where they diverge, the model is often the softer text. Multi-factor authentication appears as a control that "may include" MFA, while amended Part 500 requires MFA for anyone accessing your information systems. Build to the strictest version once, then evidence each state from the same controls instead of running one program per regulator.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps each Section 4 obligation, from the risk assessment in 4C to the incident response plan in 4H, onto the controls you already evidence for SOC 2, ISO 27001 or NYDFS Part 500, and flags which are net new
  • Schedules the annual assessment of key controls that Section 4C(5) requires, so the effectiveness test happens every year whether or not an outside auditor is booked
  • Drafts the written annual board report Section 4E asks for from live data: program status, risk decisions, third-party service provider arrangements, test results and cybersecurity events
  • Runs third-party service provider due diligence at selection and keeps a record that each provider is contractually required to protect Nonpublic Information, as Section 4F requires
  • Holds the records, schedules and data supporting the February 15 certification for five years, plus the documented remediation plans for anything that needs material improvement
  • Keeps an investigation record for each cybersecurity event, including events at a vendor, with the determination time that starts the 72-hour notice clock
  • Tracks the thirteen notice data elements in Section 6B so the first commissioner filing and every later update draw from one record
  • Covers several adopting states, NYDFS Part 500 and HIPAA from one library, so a multistate agency or carrier evidences once and reports many times
NAIC Model 668 readiness_report
Readiness 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Every finding links to the evidence behind it

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

What your existing program already covers

Model 668 obligations against what SOC 2 and ISO 27001 already give you

Most write-ups of the Insurance Data Security Model Law list the sections. This table answers the next question a security team asks: which of these do we already evidence, and what is genuinely new. Section numbers follow the NAIC model text; your state may renumber them.

Obligation Section What SOC 2 or ISO 27001 usually already covers The net-new work Clock
Written information security program based on a risk assessment 4A to 4D An ISMS or SOC 2 control set with policies and a risk assessment Scoping to Nonpublic Information, which includes your own business information, and folding cybersecurity risk into enterprise risk management One year after your state's effective date
Annual assessment of key controls 4C(5) Type 2 testing or ISO 27001 internal audit, if you run one A yearly effectiveness assessment owned by the licensee, required even with no external audit Every year
Board oversight 4E ISO 27001 management review A written report to the board or a committee at least annually, covering vendor arrangements, test results and cybersecurity events Every year
Third-party service provider oversight 4F Vendor security reviews and questionnaires Due diligence at selection and a contractual requirement that each provider protect Nonpublic Information Two years after your state's effective date
Incident response plan 4H SOC 2 CC7 incident criteria, ISO 27001 incident controls A written plan covering seven named areas, including decision-making authority and revision after each event Continuous
Annual certification to the domiciliary commissioner 4I Nothing comparable A written statement of compliance from each domestic insurer, with five years of supporting records and documented remediation plans February 15
Investigation of a cybersecurity event 5 Incident management records Confirming and documenting that a vendor completed the investigation steps for an event in its systems, and keeping event records five years Promptly, per event
Notice to the commissioner 6A and 6B Nothing comparable A notice with up to thirteen named data elements and a continuing duty to update it 72 hours from determination

Good questions

Questions about NAIC model 668

It is Model 668, adopted by the National Association of Insurance Commissioners in the fourth quarter of 2017 as a template for state legislatures. It sets standards for insurance licensees to protect Nonpublic Information, investigate cybersecurity events and notify the insurance commissioner. It only binds a licensee once its state enacts a version, often under a name like the Insurance Data Security Act.
About half the states have enacted a version, beginning with South Carolina in 2018, and the list keeps growing. Enacted versions carry state names such as the Pennsylvania or Virginia Insurance Data Security Act. The NAIC publishes an adoption map, and New York regulates insurers separately through NYDFS Part 500. Confirm your own state's enacted text and effective date.
It applies to licensees: any person licensed, authorized to operate or registered under the state's insurance laws. That covers carriers, and also agencies, producers, public adjusters and similar licensees. Vendors are reached indirectly, because Section 4F makes each licensee oversee its third-party service providers and contractually require them to protect Nonpublic Information.
A licensee must notify the commissioner as promptly as possible and no later than 72 hours after determining a cybersecurity event occurred, when its state is the insurer's domicile or the producer's home state, or when the event involves 250 or more of the state's consumers and is either reportable elsewhere or reasonably likely to cause material harm.
Partly. Under the model, a licensee with fewer than ten employees, counting independent contractors, is exempt from Section 4, the written information security program. It is not exempt from investigating a cybersecurity event or from the 72-hour commissioner notice. Some states changed the threshold, so check your enacted version.
Section 4I requires each insurer domiciled in the state to submit a written statement by February 15 each year certifying compliance with Section 4. The insurer keeps the supporting records, schedules and data for five years, and documents any areas needing material improvement along with the remediation planned and underway.
For Section 4 it can. The model treats a licensee subject to HIPAA that maintains an information security program under it as meeting Section 4, provided the licensee is compliant with HIPAA and submits a written statement certifying so. The investigation and 72-hour commissioner notice duties in Sections 5 and 6 still apply.
The model's drafting note says a licensee compliant with NYDFS Part 500 is also in compliance with the Act, and Part 500 is generally the stricter text, for example on multi-factor authentication. Adopting states do not all carry that note into law, so treat Part 500 as a strong base and still confirm each state's notice and certification mechanics.
No. Scrutineer keeps the evidence, the investigation record and the thirteen notice data elements ready, and drafts the board report from live data. Your compliance officer signs the certification and files the notice through the channel your commissioner specifies. Scrutineer is readiness software, not legal advice and not a regulator filing service.

Keep reading

Guides that go deeper on this framework

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification