01
Daily watch on state insurance departments
Bulletins, circular letters and adopted regulations from the jurisdictions where you hold a license, read at the source.
Insurance · carriers, MGAs and insurtechs
Insurance compliance software keeps one register of the rules your company answers to across 56 NAIC jurisdictions and tells you when one of them moves. ComplianceOfficer reads the primary sources daily: state insurance department bulletins, NAIC model law adoptions, NYDFS Part 500 and the new state AI rules for underwriting and pricing. Each change arrives with the citation and the policy it affects, for $149 a month.
Insurance is preselected. Add the frameworks you already answer to, like SOC 2 or HIPAA for a health carrier, and run it. The register comes back with each obligation's source and, if you tick the box, what changed in the last 12 months. Nothing you pick is stored.
§ Live · Compliance scan
One free run. Nothing you pick is stored.
Insurance, US · what a scan returns
What moved in insurance regulation
Six sets of rules account for most of the change hitting US insurers right now. Each is adopted state by state, on its own schedule, which is why a spreadsheet of "what applies where" goes stale inside a quarter. Figures are from NAIC's own adoption charts and the regulation text.
| Rule | Where it applies | What it asks for | Dates that matter |
|---|---|---|---|
| NAIC Insurance Data Security Model Law (Model 668) | 28 jurisdictions on NAIC's Summer 2026 chart: 27 states plus Puerto Rico | Written information security program, annual risk assessment, oversight of third-party service providers | Notice to the commissioner within 72 hours; domestic insurers certify by February 15 each year |
| NAIC Model Bulletin on the Use of AI Systems by Insurers | 25 jurisdictions (24 states and DC) as of April 1, 2026 | A written AI systems program, governance, and oversight of third-party models and data | Adopted by NAIC on December 4, 2023; each state sets its own effective date |
| NYDFS 23 NYCRR Part 500 | Every insurer licensed under New York Insurance Law | Cybersecurity program, CISO, MFA for all users, complete asset inventory | 72-hour incident notice; certification by April 15; MFA and asset inventory required since November 1, 2025 |
| NYDFS Circular Letter No. 7 (2024) | Insurers authorized in New York using AI or external consumer data in underwriting or pricing | Proxy and quantitative testing for unfair discrimination, risk-based governance | Issued July 11, 2024 |
| Colorado SB21-169 and Regulation 10-1-1 | Life insurers, and since the 2025 amendment private passenger auto and health benefit plan insurers | Governance and risk management framework for external consumer data, algorithms and predictive models | Amended rule effective October 15, 2025 |
| NAIC Market Conduct Annual Statement (MCAS) | 13 lines of business, from private passenger auto to pet and travel; New York joined for the 2025 data year | Annual market conduct data by state and line | April 30 for most lines; May 31 for health lines |
The pattern that catches insurers out is adoption drift. A carrier licensed in 30 states can be under Model 668 in some, under Part 500 in New York, under a home-grown AI rule in Colorado and under nothing yet in the rest, and each of those changes when a legislature or commissioner acts. ComplianceOfficer tracks the adoption itself, so the register changes when the map does.
What the software does
01
Bulletins, circular letters and adopted regulations from the jurisdictions where you hold a license, read at the source.
02
When another state adopts Model 668 or the AI bulletin, the obligation appears in your register for that state, with the effective date.
03
Each change is explained for an insurer, with the citation attached, so a reviewer can check it in one click.
04
Your information security, vendor oversight and AI governance policies are checked against the rule, and stale ones get a drafted update.
05
February 15 certifications, April 15 in New York, MCAS by April 30. One calendar across every state you write in.
06
Every alert, review and sign-off is logged and exportable, which is what a market conduct or financial examiner asks to see.
How it works
Run the scan for insurance and the states you are licensed in, then save it as your register.
Upload the policies that answer each obligation: information security, vendor oversight, AI use, claims.
We watch the regulators behind every line daily and email you when one moves, with the source.
Review the flagged policy, accept or edit the drafted change, and the sign-off lands in the audit trail.
Three different products
Tracking every agent's license, line of authority and appointment by state. These tools sync with NIPR, which adds a $5.60 transaction fee on top of state fees for a renewal. AgentSync is the best-known name here. We do not do this job.
Preparing filings and submitting them through SERFF, where the NAIC transaction fee rose from $19.58 to $21.00 for transactions from January 2, 2026. Filing tools and outside filing services own this. We do not replace them.
Knowing which rules apply in which state, when they change, and whether your policies still meet them. This is the job ComplianceOfficer does, and it is the one most insurers still run on email alerts and a shared spreadsheet.
One more meaning turns up in search. For a business that hires contractors, "insurance compliance" often means checking that every vendor carries the coverage the contract requires, and that is a job for certificate of insurance tracking software, not a regulatory tool. If you are an insurer, the rest of this page is about your regulators.
What it costs
Most vendors in this space publish no price. Where a number exists, here it is, read on 29 September 2026. Vendr figures are signed contracts reported by buyers, not quotes.
| Tool or service | Job | Price |
|---|---|---|
| AgentSync | Producer licensing | Vendr median $4,042 a year, range $1,500 to $96,000; no public price |
| Wolters Kluwer | Compliance content and software across many products | Vendr median $10,612 a year across all its products, range $3,087 to $32,200 |
| NAMIC Legislative and Regulatory Tracking | Bill and bulletin tracking, 450+ topics, 50 states and DC, updated nightly | Member benefit, no separate price |
| Comply (thecomply.ai) | Insurance ad review, filings, regulatory impact | Demo only, no public price |
| SERFF | Filing submission | $21.00 per transaction from January 2, 2026 |
| ComplianceOfficer | Regulatory tracking, policy gaps, audit trail | $149 a month or $894 a year, published |
Enterprise GRC suites also sell into insurance, usually as a module inside a much larger contract. The category-wide numbers are on compliance software pricing, and dedicated rule-watch vendors are compared on regulatory change management software pricing.
Who uses it
A compliance team of two or three covering a dozen states, with a February 15 certification due to the home-state commissioner where Model 668 is law.
Carrier partners audit your controls. A current register and audit trail answers their questionnaire in an afternoon.
The AI bulletin, Circular Letter No. 7 and Colorado's rule all ask for governance you can show. Track each state's version in one place.
HIPAA and state health privacy law on top of insurance rules. The same register holds both, see HIPAA compliance software.
Questions buyers ask
Most US insurers run three kinds of compliance software side by side: producer licensing and appointment tools that sync with NIPR, rate and form filing tools that submit through SERFF, and a regulatory compliance system that tracks state and federal rules, cybersecurity obligations and policies. The third is the one that watches all 56 NAIC jurisdictions for changes.
Insurance compliance means meeting the laws, regulations and bulletins of every state insurance department where a carrier, MGA or agency is licensed, plus federal and cross-sector rules. It covers licensing, rate and form filings, market conduct, claims handling, data security under laws based on NAIC Model 668, and AI governance where states have adopted the NAIC AI bulletin.
It depends on which job hurts. For producer licensing, tools like AgentSync that connect to NIPR lead. For filings, SERFF-connected filing tools. For tracking what state insurance departments publish and mapping it to your own policies and controls, a regulatory compliance tool such as ComplianceOfficer, which publishes its price at $149 a month, is the better fit.
Recorded contracts on Vendr, read 29 September 2026, put the median AgentSync licensing contract at $4,042 a year, with deals from $1,500 to $96,000. Wolters Kluwer contracts across all its products have a $10,612 median. Most insurance regulatory tracking vendors publish no price. ComplianceOfficer costs $149 a month or $894 a year.
NAIC's Summer 2026 state chart for Model 668 lists 28 adopting jurisdictions: 27 states plus Puerto Rico, with Tennessee adopting portions of the model. New York is not counted as an adopter because its own cybersecurity regulation, 23 NYCRR Part 500, already covers licensed insurers.
Yes. Part 500 covers any person operating under a license, registration, charter or similar authorization under New York's Banking Law, Insurance Law or Financial Services Law. Covered insurers must notify DFS within 72 hours of determining a cybersecurity incident occurred and file an annual compliance certification by April 15.
NAIC's map, with status as of April 1, 2026, shows 25 jurisdictions that adopted the Model Bulletin on the Use of Artificial Intelligence Systems by Insurers: 24 states and the District of Columbia. California, Colorado, New York and Texas have their own insurance-specific AI rules or guidance instead.
Your register, every state you write in, watched daily for $149 a month. The engine behind it is described on regulatory change management software, and the wider product on regulatory compliance software.