Industry Intelligence provided by Clark Embedded Advisors.

A Vendor Diligence Scorecard for Embedded Insurance Platforms

By Clark Embedded Advisors

Choosing an embedded insurance platform is usually framed as a feature comparison: APIs, product configuration, speed to launch. Those matter. They are also what every vendor demonstrates well. The questions that decide whether the choice survives an exam, a cyber incident or a regulator's inquiry rarely come up in a demo.

This scorecard organizes those questions in six categories. Each is tied to published regulator or industry guidance. Score each vendor 0 to 3 per category with evidence, not assertions.

1. Access and data (regulatory anchor: NYDFS)

In October 2025 the New York Department of Financial Services issued guidance on managing risks from third-party service providers. It states that it imposes no new requirements, and clarifies existing ones under 23 NYCRR Part 500. It also reports that DFS found a need for more robust due diligence, contractual provisions, monitoring and oversight. Its due diligence list includes the type and extent of access to information systems and non-public information, the provider's cybersecurity history and financial stability, access controls and data handling including segmentation and encryption, incident response and continuity testing, independent assessments, and the provider's own selection of downstream providers ("fourth parties"). Score the vendor on whether it can answer each in writing.

2. Contract terms

The same guidance lists baseline contract provisions: access controls, encryption, cybersecurity event notification, compliance representations, data location and transfer restrictions, subcontractor disclosure and the right to reject certain subcontractors, and data use and exit obligations including deletion or migration of data on termination. It also suggests an AI clause on whether the carrier's data may be used to train models. Score the vendor's standard paper against that list. Where it falls short, record what the vendor agreed to change.

3. Concentration and exit

DFS recognizes that carriers may face constraints in selecting or leaving a provider because of limited vendor options or legacy dependencies. Its advice is to document the risks, apply compensating controls such as monitoring, segmentation and contract triggers, and reassess regularly. In embedded insurance, platform lock-in is the key risk. Ask for a tested data export, a definition of what "exit assistance" costs, and what happens to live policies and partner integrations during a transition.

4. AI and models (regulatory anchor: NAIC)

The NAIC adopted its Model Bulletin on the Use of Artificial Intelligence Systems by Insurers in December 2023. The NAIC notes it is not a model law or regulation. It sets expectations that decisions made or supported by advanced analytics and AI comply with insurance laws including unfair trade practices, and it addresses governance, risk management and third-party contracting. Separately, the NAIC's Third-Party Data and Models (H) Working Group is developing a framework for oversight of third-party data and predictive models, and its December 2025 draft outlines a risk-based approach to vendors engaged in pricing, underwriting, claims, utilization reviews, marketing and fraud detection. That draft is not final, so track it.

For vendor scoring: does the platform use models in pricing, underwriting, claims or marketing? Can the vendor give you documentation, testing and validation records, and audit access? Can you explain a decision to a regulator without the vendor in the room?

5. Configuration control and operations

BCG's 2025 analysis of embedded insurance technology emphasizes a flexible product engine that can go live rapidly and adjust products dynamically, real-time calculation and decision software, and workflow configuration that lets business users update products without developer involvement. We agree those capabilities matter. We add the control side: every setting that changes a price, limit or eligibility rule should be permissioned, logged and reversible. Speed without change control is how a pricing error reaches thousands of customers before anyone sees it.

6. Fit with the program structure

A platform does not exist apart from the carrier and MGA arrangement. Check that it can produce the records the carrier needs for oversight, supports the authority limits written into the MGA agreement, and keeps jurisdiction-specific rules, forms and disclosures under version control.

How to score

Weight the categories to your risk. A carrier with New York exposure will weight categories 1 to 3 heavily. An MGA using pricing models will weight category 4. Do not average away a zero: a zero in access, contract or exit is a reason to stop, not a deduction.

General information, not legal advice. The NYDFS guidance applies to DFS-regulated entities; other states' expectations differ. The NAIC AI bulletin's adoption varies by state.

Want the shortlist side of this? The Embedded Vendor Shortlist Workbook gives you sourced vendor details and the questions to ask each vendor: Embedded Vendor Shortlist Workbook.

Clark Embedded Advisors runs vendor selection for carriers, MGAs and platforms and builds scorecards tailored to the program. Book a call.

Sources

Choosing a provider or entering the US market?

30 minutes with Ty Clark, Clark Embedded Advisors.