Titles vary, so map functions. The business owner is usually the chief underwriting officer, the chief claims officer, or the head of distribution or operations, depending on which work your product changes. The technology owner is the insurance CIO or CTO. Finance or procurement usually handles the contract.
The rules explain the long list of reviewers. The NAIC's AI model bulletin (adopted December 4, 2023) says an insurer's AI program should vest responsibility "with senior management accountable to the board or an appropriate committee of the board" (section 1.3) and gives, as one example of governance, committees drawn from "business units, product specialists, actuarial, data science and analytics, underwriting, claims, compliance, and legal" (section 2.3(a)). New York's Circular Letter No. 7 (July 11, 2024) says the board, a committee of it, or senior management through delegated authority "should review and approve the insurer's ECDIS and AIS-related policies and procedures at least annually". (ECDIS means external consumer data and information sources; AIS means AI systems.)
The catch is that the people who can stop a deal are often unclear inside the carrier too. In a study by Alvarez & Marsal with InsurTech NY (March 2026), A&M found that "Decision rights are unclear across business, IT, strategy, finance, and control functions." Ask early who makes the go or no-go call. Our buying committee entry covers how to map one.
Who shapes a software decision at a carrier (functions, not universal titles)
| Function | Usual part in the deal | What it rests on |
|---|
| Business owner: underwriting, claims, distribution or operations | Wants the outcome, sponsors the pilot, owns its targets | McKinsey (2025-05-12): core change needs business and technology "shared ownership" |
| CIO or CTO | Accepts the product into the architecture | Same McKinsey article |
| Senior management and the board | Accountable for the AI program and AI strategy | NAIC AI bulletin section 1.3 (2023); NY Circular Letter No. 7 (2024) |
| AI governance committee, where the carrier has one | Part of the oversight and approval process before an AI tool is adopted | NAIC AI bulletin sections 2.3(a) and 3.1, where a state issued it |
| Information security | Third-party due diligence and periodic assessment | 23 NYCRR 500.11 (amended, effective 2023-11-01) |
| Compliance and legal | Contract terms: audit rights, regulator cooperation, data security | NAIC AI bulletin section 4.2; NY Circular Letter No. 7 |
| Finance or procurement | Commercial terms and the contract | Typical role; no public rule sets it |