Selling to carriers

How to sell software to insurance companies: who decides at a carrier

Carriers buy software through the business owner of the process and the CIO or CTO, while security, compliance, legal, actuarial and data science review it. Deals slow down in reviews the carrier has to run and when nobody clearly owns the go or no-go call.

Book a demo

The short answer

To sell software to an insurance carrier, win the business owner of the process and the CIO or CTO, then get through the reviews: third-party security due diligence, which New York requires, and AI vendor oversight where states issued the NAIC bulletin (25 states plus DC as of August 31, 2026). Send documents early. Clean finds carriers with a real reason to buy.

Key takeaways

  • The business owner of the process and the CIO or CTO decide; security, compliance, legal, actuarial and data science review.
  • In one March 2026 insurtech survey, 58% of responses rated insurer due diligence low, the worst of eight areas.
  • Vendor security review is a legal duty in New York: 23 NYCRR 500.11 requires third-party policies and due diligence.
  • AI tools face a second review where states issued the NAIC bulletin: 25 states plus DC as of August 31, 2026.
  • Core systems take more than half of large insurers' IT budgets, per a 2026 Datos Insights survey of 38.
01

How do you sell software to an insurance company?

You sell to an insurance carrier through two owners and a set of reviewers. The business owner of the process you change (underwriting, claims, distribution or operations) has to want it, and the CIO or CTO has to accept it into the architecture. Security, compliance, legal, actuarial and data science then review it, and in states that issued the NAIC's AI bulletin, responsibility for the insurer's AI program sits with senior management accountable to the board.

That is why carrier deals feel slow. Much of the delay sits in reviews the carrier is required to run, and in go or no-go calls nobody clearly owns. A seller can't skip those reviews. You can choose who you reach first, how early reviewers see your documents, and whether the pilot has an owner with a target before it starts.

Selling to agencies or MGAs instead? They buy differently: see how to sell to insurance agencies and how MGAs buy software. The rules quoted on this page are context, not legal or compliance advice. Check each rule's own text and talk to your counsel.

02

Who decides at a carrier, and who can stop the deal

Titles vary, so map functions. The business owner is usually the chief underwriting officer, the chief claims officer, or the head of distribution or operations, depending on which work your product changes. The technology owner is the insurance CIO or CTO. Finance or procurement usually handles the contract.

The rules explain the long list of reviewers. The NAIC's AI model bulletin (adopted December 4, 2023) says an insurer's AI program should vest responsibility "with senior management accountable to the board or an appropriate committee of the board" (section 1.3) and gives, as one example of governance, committees drawn from "business units, product specialists, actuarial, data science and analytics, underwriting, claims, compliance, and legal" (section 2.3(a)). New York's Circular Letter No. 7 (July 11, 2024) says the board, a committee of it, or senior management through delegated authority "should review and approve the insurer's ECDIS and AIS-related policies and procedures at least annually". (ECDIS means external consumer data and information sources; AIS means AI systems.)

The catch is that the people who can stop a deal are often unclear inside the carrier too. In a study by Alvarez & Marsal with InsurTech NY (March 2026), A&M found that "Decision rights are unclear across business, IT, strategy, finance, and control functions." Ask early who makes the go or no-go call. Our buying committee entry covers how to map one.

Who shapes a software decision at a carrier (functions, not universal titles)

FunctionUsual part in the dealWhat it rests on
Business owner: underwriting, claims, distribution or operationsWants the outcome, sponsors the pilot, owns its targetsMcKinsey (2025-05-12): core change needs business and technology "shared ownership"
CIO or CTOAccepts the product into the architectureSame McKinsey article
Senior management and the boardAccountable for the AI program and AI strategyNAIC AI bulletin section 1.3 (2023); NY Circular Letter No. 7 (2024)
AI governance committee, where the carrier has onePart of the oversight and approval process before an AI tool is adoptedNAIC AI bulletin sections 2.3(a) and 3.1, where a state issued it
Information securityThird-party due diligence and periodic assessment23 NYCRR 500.11 (amended, effective 2023-11-01)
Compliance and legalContract terms: audit rights, regulator cooperation, data securityNAIC AI bulletin section 4.2; NY Circular Letter No. 7
Finance or procurementCommercial terms and the contractTypical role; no public rule sets it
03

Why do insurance carriers take so long to buy software?

The clearest picture comes from one study. InsurTech NY's committee surveyed 120+ insurtech founders (155 responses), and Alvarez & Marsal analyzed the results and added 20 interviews with insurance transformation leaders (March 2026). Respondents rated insurers from 1 to 7 on eight areas. Due diligence drew the most low ratings (4 or below): 58% of responses on "How difficult or onerous was the insurer's due diligence process?" Business and IT alignment came next at 51%, then financial and commercial negotiation at 48% and decision speed at 46%.

A&M's own estimates show where the time goes: "Six- to twelve-month 'limbo' periods following pilots" when funding is not lined up behind the pilot, and cycle times that rise by 40 to 60% when decision rights are fragmented. Risk, legal, compliance and procurement typically get pulled in late, according to the same study. These are A&M estimates and interview findings, not market averages.

So how long does a carrier deal take? No public source we could verify as of 2026-10-06 measures a typical carrier sales cycle, and we will not invent one. McKinsey's three to five years (2025-05-12) is the time to implement a packaged core platform at a P&C carrier: delivery time, not time to signature.

04

What security checks do insurers run on software vendors?

For a carrier regulated by New York's Department of Financial Services, vendor security review is a legal duty. 23 NYCRR 500.11 (as amended, effective November 1, 2023) requires written policies for third-party service providers that address their identification and risk assessment, the "minimum cybersecurity practices required to be met by such third-party service providers in order for them to do business with the covered entity", due diligence on those practices, and periodic assessment. They must include guidelines on access controls and multi-factor authentication, encryption, notice of cybersecurity events, and representations and warranties.

DFS's own FAQs (opened 2026-10-06) are blunt about who carries the risk: carriers "are ultimately responsible for protecting their Information Systems and the Nonpublic Information on those systems and therefore are expected to ensure Third Party Service Providers implement the controls needed to protect such systems and information." DFS also says a plan to move key business processes, workloads or data to a third-party service provider "will very likely constitute a material change" that calls for a review and potential update of the carrier's risk assessment. If your product will hold carrier data, expect that review. The same FAQs say merging with or acquiring another company very likely counts as a material change too; for how that plays out when a platform buys an agency, see insurance agency acquisitions.

Outside New York, the NAIC Insurance Data Security Model Law (#668) says a licensee "shall exercise due diligence in selecting its Third-Party Service Provider" and must require the provider to put appropriate administrative, technical and physical measures in place (Section 4F). As of the NAIC's August 8, 2025 status, 28 jurisdictions had implemented the model, and state versions differ.

05

Do insurers have to review their AI vendors?

Where a state has issued the NAIC's AI model bulletin, insurers are expected to. It is a bulletin, not a model law, and applies only where a state issues it: 25 states plus the District of Columbia had done so as of August 31, 2026, according to the NAIC's map. Four more states have their own insurance-specific AI rules or guidance.

For a carrier deal, that means a second review track next to security. The bulletin's written AI program covers AI systems "whether developed by the Insurer or a third-party vendor" (1.8) and includes "The oversight and approval process for the development, adoption, or acquisition of AI Systems" (3.1). Expect due diligence on you and your data (4.1) and, "Where appropriate and available", contract asks for audit rights or audit reports and for cooperation with regulatory inquiries (4.2). In New York, Circular Letter No. 7 (July 11, 2024) adds its own expectations, for underwriting and pricing only.

This guide gives AI review one section. Which states adopted the bulletin, what a regulator can ask an insurer about your product, New York's testing expectations and the NAIC's draft vendor framework are covered in our NAIC AI model bulletin guide.

06

What a seller controls: get ready before the reviews start

The A&M study also shows what moves faster. Leading insurers "cap POCs at ~60 days". One carrier cut its average proof of concept "from six months to two" by mapping every governance step in advance and running reviews in parallel. At the leading carriers, "What had taken four to six months was reduced to weeks" (A&M interview findings, March 2026). That is mostly the carrier's work, but a seller can push for it:

  • Get a named business owner and a written success target before the pilot starts. A pilot with no owner is the one that sits in limbo.
  • Ask for the full review map early (security, privacy, AI governance, legal, procurement) and offer to run your parts in parallel.
  • Send your security and AI documents before anyone asks; the table lists what the rules point to.
  • Reach the business owner and the technology owner together. A product only one side wants stalls with the other.

The reviews a vendor will face, the rule behind each, and what to prepare (rules as of 2026-10-06)

ReviewWhat the carrier must or is expected to checkRule behind itWhat to have ready
Security (New York)Your security practices, access controls and MFA, encryption, incident notice23 NYCRR 500.11Questionnaire answers, MFA and encryption details, incident notice terms you will sign
Risk assessment update (New York)Whether moving key processes, workloads or data to you is a material change to its cyber riskDFS Cybersecurity FAQs (risk assessment, 500.9)A plain list of the carrier data your product will hold and the processes it will run
Security (states with a #668 version)Due diligence in selecting you; your administrative, technical and physical measuresNAIC Model #668, Section 4F, as the state adopted itThe same security package, checked against that state's version
AI governanceOversight and approval before adoption; due diligence on you and your dataNAIC AI bulletin 3.1 and 4.1, where issuedA plain description of the model, its data, testing and monitoring
AI contract termsAudit rights or audit reports, and cooperation with regulators, where appropriate and availableNAIC AI bulletin 4.2; NY Circular Letter No. 7Your position on both clauses before redlines start
07

Where carrier IT budgets go in 2026

The best recent read on insurance IT spending is a small one: Datos Insights surveyed 38 insurer CIO and technology leaders (Q4 2025 to Q1 2026; report published 2026-04-07, summarized 2026-06-30). "The average IT spend ratio reached 4.6% of direct written premium, up from 4.5% in 2025 and 3.7% a decade ago." Core systems dominate: "For large insurers, core represents more than half the total IT budget. For midsize, it's roughly half." Two-thirds of large carriers in the survey are planning or continuing policy administration replacements in 2026, against roughly a third of midsize carriers for core replacements. Top priorities: core policy administration, AI-enabled processing, BI and data infrastructure, and underwriting workbenches.

Two things follow for a seller. If your product touches the core, the core program sets your calendar. McKinsey (2025-05-12) puts packaged core platforms for P&C carriers at "implementation within three to five years" and in-house builds at five to ten. That is implementation time, not a sales cycle, but it shows how long the teams and budget stay tied up. If you sell around the core (migration, integration, testing, AI on top), a replacement program is the project that work attaches to.

For the global view of insurance technology trends, Gartner forecasts (2025-10-27) that the global insurance industry's IT spending "will increase by 9.4% in 2026 to reach $256.8 billion". It is a global forecast, not a US measurement.

08

Moments that open a decision at a carrier

A carrier buys when something changes who owns a problem or what its systems have to do. These moments have public research behind them, each with its limit. Treat each one as a reason to ask, not proof of a project (see buying moment).

  • A new business or technology leader takes the seat: a new CIO, CTO, chief underwriting officer, chief claims officer or head of distribution. New owners review how their process runs. Limit: no public figure shows how often a new leader changes vendors.
  • A core system replacement or modernization program. Replacing the system of record pulls integration, migration, testing and AI work with it; in the Datos survey of 38, two-thirds of large carriers are planning or continuing a policy administration replacement in 2026. Limit: a program tells you work is coming, not which vendors are already chosen.
  • A state issues AI rules. Insurers there are expected to keep a written AI program covering vendor AI and contracts. Limit: this is market-level. It changes what carriers in that state ask you, not whether any one is buying.
  • Expansion into new states or lines. New products need rating, forms and partner connections. Limit: no verified figure shows how often expansion ends in a software purchase.
09

How Clean helps you find carriers with a real reason to buy

A carrier deal starts with the right business owner and technology owner, not a list of carrier names. Clean finds agencies, brokerages, MGAs and carriers with a real reason to buy what you sell, shows the evidence behind each one, names the people to reach, and shows who in your network can introduce you. You tell Clean who to look for by industry, size, region and what you sell, and who to leave out, such as current customers.

Every reason comes with the evidence behind it, so your team can check it. What Clean cannot confirm stays marked unknown. Clean is not a list vendor, a contact database, intent data or an AI SDR, and it does not send messages for you. Your team decides who to contact and what to say.

See how Clean works, or start from Clean for insurance. Book a demo to see carriers in your market with a real reason to buy, the evidence, and who to reach.

Common questions

Who approves software purchases at an insurance company?

At a carrier, the business owner of the process (underwriting, claims, distribution or operations) and the CIO or CTO usually decide, with finance or procurement on the contract. Security, compliance, legal, actuarial and data science review the product. For AI tools, in states that issued the NAIC AI model bulletin, it puts responsibility with senior management accountable to the board. Titles vary by carrier.

Why do insurance carriers take so long to buy software?

Mostly required reviews and unclear ownership. In one Alvarez & Marsal and InsurTech NY study (March 2026), 58% of responses from a survey of 120+ insurtech founders rated insurer due diligence low, the worst of eight areas. A&M estimates pilots can sit in six to twelve months of limbo, and that unclear decision rights add 40 to 60% to cycle times. No verified public figure gives a typical sales-cycle length.

What security checks do insurers run on software vendors?

In New York, 23 NYCRR 500.11 requires carriers to keep written third-party policies covering risk assessment, minimum cybersecurity practices, due diligence and periodic assessment, with guidelines on access controls, multi-factor authentication, encryption and incident notice. DFS says carriers are ultimately responsible for making sure providers have the controls needed. States that implemented the NAIC data security model require due diligence in selecting service providers.

Do insurers have to review their AI vendors?

Where a state has issued the NAIC AI model bulletin (25 states plus DC as of August 31, 2026), insurers are expected to cover third-party AI in a written program, run vendor due diligence and, where appropriate and available, seek audit rights and regulator cooperation in contracts. New York's Circular Letter No. 7 does similar for underwriting and pricing. These are expectations for insurers, not rules for vendors.

How do insurtech startups win their first carrier customers?

There is no verified formula, but one study points to what helps. Alvarez & Marsal's March 2026 research found that leading insurers cap proofs of concept at about 60 days, have business units confirm targets before the pilot, and map every review step in advance. A startup can push for the same: a named business owner, a written success target, the review map early, and security and AI documents sent unasked.

Sources

  1. 01From Experimentation to Execution Discipline (joint research paper on insurer and insurtech partnerships), Alvarez & Marsal with InsurTech NY, 2026-03; accessed 2026-10-06
  2. 02NAIC Model Bulletin: Use of Artificial Intelligence Systems by Insurers, NAIC, 2023-12-04; accessed 2026-10-06
  3. 03Implementation of NAIC Model Bulletin: Use of Artificial Intelligence Systems by Insurers (status as of August 31, 2026), NAIC, 2026-08-31; accessed 2026-10-06
  4. 04Insurance Circular Letter No. 7 (2024): Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and Pricing, New York State Department of Financial Services, 2024-07-11; accessed 2026-10-06
  5. 05N.Y. Comp. Codes R. & Regs. Tit. 23 § 500.11, Third-party service provider security policy, Legal Information Institute, Cornell Law School, 2023-11-01; accessed 2026-10-06
  6. 06Cybersecurity FAQs, New York State Department of Financial Services, Accessed 2026-10-06
  7. 07Insurance Data Security Model Law (#668), NAIC, 2017; accessed 2026-10-06
  8. 08The NAIC Insurance Data Security Model Law (government affairs brief, status as of August 8, 2025), NAIC, 2025-08; accessed 2026-10-06
  9. 09Third-Party Data and Models (H) Working Group, NAIC, Accessed 2026-10-06
  10. 10Insurer IT in 2026: Bigger Budgets, Bolder AI, and a Data Problem That Won't Wait, Datos Insights, 2026-06-30; accessed 2026-10-06
  11. 11Insurer IT Budgets and Projects, 2026 (survey of 38 insurer CIO and technology leaders), Datos Insights, 2026-04-07; accessed 2026-10-06
  12. 12How P&C insurers can successfully modernize core systems, McKinsey & Company, 2025-05-12; accessed 2026-10-06
  13. 13Forecast: Enterprise IT Spending for the Insurance Market, Worldwide, 2023-2029, 3Q25 Update, Gartner, 2025-10-27; accessed 2026-10-06

Next