Insurers protect policyholder PII and claims data under a patchwork of state data-security laws built on the NAIC model, plus GLBA, the Model Audit Rule, and PCI. Compyl maps one control library to all of them, so you stay exam-ready across every state from a single program.
One model law, dozens of state variations, deeply sensitive data, and SOX-style control testing every year.
State adoptions of the NAIC model security law differ in timing and detail, so multi-state insurers track overlapping but non-identical requirements.
You hold deeply sensitive personal, financial, and health-adjacent data that regulators and customers expect you to protect and prove.
The Model Audit Rule brings SOX-style financial-reporting control requirements that must be evidenced and tested each year.
State laws, federal rules, card networks, and assurance frameworks, one control library. Each tile shows who enforces it, what it asks, and the shared control Compyl evidences once.
Information security program, risk assessment, oversight, and event notification, adopted state by state.
A written information security program protecting customer financial data.
Internal controls over financial reporting, with a management ICFR report at $500M+ premium.
Cybersecurity program, CISO, MFA for all users since Nov 2025, and an annual certification or acknowledgment.
Protect cardholder data for premium payments.
Health plans and health-adjacent claims data.
Partner and reinsurer assurance that controls operate as described.
The reference model many state examiners map to.
Define controls once and cross-map them to the NAIC model law, GLBA, NYDFS, the Model Audit Rule, and PCI, evidence collected once satisfies every adoption.
Integrations pull evidence from your policy admin, cloud, and identity systems around the clock, and Evidence Health flags stale proof before a market-conduct or financial exam.
Quantify cyber and vendor risk in financial terms with FAIR for the board, and continuously monitor TPAs, brokers, and SaaS vendors that touch policyholder data.
Compyl maps each control and its evidence across every state adoption and framework that requires it, so a single artifact, pulled automatically from your stack, counts everywhere at once.
All cross-mapped to one control library. Explore each, or see the full library of 70+.
“It has brought a sense of relief to my life because, for the first time, we have a real solution in place that is proactively keeping us protected.”
Plenty of tools store a policy. Compyl runs the whole program, controls, evidence, risk, and vendors, across every state and regulator you answer to.
Controls, evidence, risk, and vendors in one connected system, across every regulator you answer to.
Evidence refreshes automatically and is scored for health, so you are exam-ready every day of the year.
Policy admin, claims, cloud, and identity systems feed evidence automatically.
AI drafts evidence, maps controls, and triages risk; your experts approve every decision.
FAIR-based quantification turns cyber and vendor risk into numbers a board can act on.
Insurers must protect policyholder PII and claims data under state data-security laws modeled on the NAIC Insurance Data Security Model Law (MDL-668), alongside the GLBA Safeguards Rule, the Model Audit Rule (financial-reporting controls), and PCI DSS for payments. Insurers operating in New York also fall under NYDFS 23 NYCRR 500. Compyl maps one control library across every state adoption and framework, with continuous evidence.
The recurring obligations behind insurance compliance, with the regime that sets each one.
| Obligation | Regime | Cadence | With Compyl |
|---|---|---|---|
| Certify your information security program | NAIC Model Law (state adoptions) | Annually by Feb 15, in adopting states | Certifications produced from current evidence |
| Notify a cybersecurity event | NAIC Model Law · NYDFS 500 | Within 72 hours of determination | Incident workflow with the notification record |
| Test financial-reporting controls | Model Audit Rule | Annually | Control testing scheduled, evidenced, and tracked |
| Certify NYDFS compliance | NYDFS 23 NYCRR 500 | Annually, by April 15 | Certification produced from current evidence |
| Maintain a written security program | GLBA Safeguards Rule | Continuous, with periodic risk assessment | Program, risk assessment, and controls in one place |
| Oversee third-party service providers | NAIC Model Law · GLBA | Continuous | TPA and broker tiering, questionnaires, and monitoring |
Insurers must protect policyholder data under state data-security laws based on the NAIC Insurance Data Security Model Law, plus the GLBA Safeguards Rule, the Model Audit Rule for financial-reporting controls, and PCI DSS for payments. Insurers in New York also fall under NYDFS 23 NYCRR 500. Compyl maps one control library to all of them.
Compyl maintains one control library and cross-maps it to each state’s adoption of the NAIC Insurance Data Security Model Law. Because the underlying controls overlap, evidence collected once satisfies every state where you operate, and new adoptions reuse controls you already have.
Yes. Compyl manages the IT general controls behind the Model Audit Rule, schedules and tracks control testing, and continuously collects evidence, so the annual MAR requirements are met with current proof instead of a year-end scramble.
Yes. With cross-mapping, evidence that MFA is enforced can satisfy the NAIC model law, GLBA Safeguards, NYDFS 500.12, the Model Audit Rule, SOC 2, and PCI DSS at once, collected a single time and counted everywhere it applies.
Yes. Compyl continuously assesses and monitors third-party administrators, brokers, and SaaS vendors that touch policyholder data, automates their security questionnaires, and quantifies exposure in dollars using the FAIR model.
Roughly half the states have adopted Model #668 or a close variant, while others rely on general breach and data security laws. In adopting states, domestic insurers typically certify compliance by February 15 and notify the commissioner of a cybersecurity event within 72 hours, so check NAIC’s current adoption chart for each state you operate in.
No. The FTC Safeguards Rule covers financial institutions under FTC jurisdiction that no other agency regulates. Insurers answer to state insurance regulators for GLBA, usually through data security laws modeled on NAIC Model #668, plus NYDFS Part 500 in New York.
As of NAIC’s Spring 2026 meeting, 24 states and the District of Columbia had adopted the bulletin, and several more had their own insurance AI rules. It expects a written AI program with governance, risk controls and oversight of third-party AI vendors.
One control library, every state, continuous evidence, and agentic AI that removes the busywork, with your experts in control.