meilynx

Reference · Insurance

Colorado Regulation 10-1-1: External Consumer Data, Algorithms, and Predictive Models in Insurance

3 CCR 702-10, Regulation 10-1-1, amended effective 15 October 2025

Last reviewed September 4, 2026

Colorado Regulation 10-1-1 sets governance and risk-management requirements for insurers that use external consumer data and information sources (ECDIS), or algorithms and predictive models that use ECDIS, in any insurance practice. It is promulgated under §§ 10-1-109 and 10-3-1104.9, C.R.S., the statute enacted by SB 21-169 on unfair discrimination in insurance. The regulation first took effect on 14 November 2023 for life insurers. The amendment effective 15 October 2025 extended it to private passenger automobile insurers and health benefit plan insurers, with their first evidence-on-request and reporting dates set at 1 July 2026.

Who it applies to

Section 3 applies the regulation to all insurers authorized in Colorado offering individually issued life insurance, private passenger automobile insurance, or health benefit plans. Section 5.A then attaches the framework obligations to those insurers that use ECDIS, or algorithms and predictive models that use ECDIS. Insurers that use none of these are exempt from Section 5 and instead file an officer-signed attestation to that effect, due within one month of the effective date and on 1 December each year (Section 6.E).

The regulation took effect twenty days before the NAIC adopted its Model Bulletin on 4 December 2023, and it operates as Colorado's own framework rather than as an adoption of the bulletin.

What counts as ECDIS

Section 4.D defines ECDIS, per line of business, as a data or information source used to supplement or supplant traditional underwriting factors or other insurance practices, or to establish lifestyle indicators used in insurance practices. The listed examples are credit scores, social media habits, locations, purchasing habits, home ownership, educational attainment, licensures, civil judgments, court records, consumer-generated Internet of Things data, biometric data, and any insurance risk scores derived by the insurer or a third party from such sources. For life insurers the list adds occupation without a direct relationship to mortality, morbidity, or longevity risk; for auto insurers it names telematics data; for health benefit plan insurers it excludes an individual's medical records.

The framework (Section 5)

Section 5.A requires a risk-based governance and risk management framework designed to determine whether the use of ECDIS, algorithms, and predictive models potentially results in unfair discrimination with respect to race, and to remediate it if detected through the quantitative testing requirements the Division establishes. Fourteen components are listed:

  • Documented governing principles (5.A.1), oversight by the board or a board committee (5.A.2), senior management responsibility and accountability with regular reporting (5.A.3), and a documented cross-functional governance group drawn from legal, compliance, risk, product, underwriting, actuarial, data science, marketing, and customer service (5.A.4).
  • For health benefit plan insurers, a provider acting on the insurer's behalf remains ultimately responsible for decisions to modify or deny prior-authorization or concurrent requests where ECDIS-based tools inform them (5.A.5).
  • Documented policies and procedures with assigned roles for design, development, testing, deployment, use, and ongoing monitoring, including a supervision and training program (5.A.6); complaint and inquiry protocols that give consumers what they need to act on an adverse decision (5.A.7); and risk assessment and prioritization processes (5.A.8).
  • A documented, up-to-date inventory with version control of all utilized ECDIS, algorithms, and predictive models, with a detailed description, clearly stated purpose, and the outputs generated (5.A.9), and a documented explanation of any material change in that inventory and its rationale (5.A.10).
  • A documented description of the quantitative testing conducted to detect unfair discrimination, including methodology, assumptions, results, and remediation steps (5.A.11), and of ongoing performance monitoring including accounting for model drift (5.A.12).
  • A documented process for selecting third-party vendors and other external resources, including the intended use of what they supply (5.A.13), and comprehensive annual reviews of the framework and its documentation (5.A.14).
  • Section 5.B keeps the insurer responsible for every Section 5.A requirement when third parties are involved, including production of documents the Division requests; vendors may supply those documents directly to the Division on the insurer's behalf.
  • Section 5.C makes every component available on request by the Division: for life insurers from 1 December 2024 and annually thereafter, and for auto and health benefit plan insurers from 1 July 2026 and annually thereafter.
Section 5 asks for documents, and Section 5.C puts a date on when each must exist. The framework is examined as a set of files the insurer can produce on the day the Division asks.

Reporting (Section 6)

  • A narrative progress report on Section 5 compliance, identifying areas still under development, difficulties encountered, and expected completion dates: due 1 June 2024 for life insurers and 1 December 2025 for auto and health benefit plan insurers (6.A).
  • An annual compliance report summarizing compliance with Section 5 and naming the title and qualifications of each individual responsible, with the specific Section 5 requirements each covers: from 1 December 2024 for life insurers (6.B) and from 1 July 2026 for auto and health benefit plan insurers (6.C).
  • The annual report is signed by an officer attesting to compliance, runs no more than ten pages including an executive summary, and addresses Sections 5.A.1 through 5.A.13. An insurer unable to attest submits a corrective action plan instead (6.D).
  • All reports are filed in SERFF as an Annual Report filing type, one filing per insurer (6.G). Documents disclosed under the regulation are confidential under § 10-3-1104.9(3)(d), C.R.S. (Section 7).
  • Noncompliance may draw civil penalties, cease and desist orders, or suspension or revocation of license (Section 9).

Control mapping

What a reviewer expects to be able to see.

ObligationWhat the system must doEvidence a reviewer expects
Inventory with version control (5.A.9)Keep an up-to-date inventory of every ECDIS, algorithm, and predictive model with description, purpose, outputs, and versionsThe inventory, its version history, and the date of last update
Material changes (5.A.10)Document each material change to the inventory and the rationale for itChange log with dates, approvers, and stated rationale
Quantitative testing (5.A.11)Describe the testing conducted under the Division's requirements, with methodology, assumptions, results, and remediationTesting reports and remediation records per model
Ongoing monitoring (5.A.12)Describe ongoing performance monitoring of algorithms and predictive models, accounting for model driftMonitoring procedure and its operating records
Third parties (5.A.13, 5.B)Document vendor selection and oversight and retain the ability to produce vendor documentation on requestSelection records, contracts, and the documentation vendors have supplied
Annual officer-attested report (6.B to 6.D)File the ten-page report in SERFF on the line-of-business date, signed by an officer, or a corrective action planSERFF filing record, signed attestation, and the responsible-individual list

Key dates

  • 14 November 2023Regulation 10-1-1 takes effect for life insurers.
  • 4 December 2023NAIC adopts the Model Bulletin on the Use of AI Systems by Insurers.
  • 1 June 2024Life insurers' narrative progress report due.
  • 1 December 2024Life insurers: framework available on request and first annual officer-attested report due.
  • 15 October 2025Amended regulation takes effect, adding private passenger auto insurers and health benefit plan insurers.
  • 1 December 2025Auto and health benefit plan insurers' narrative progress report due.
  • 1 July 2026Auto and health benefit plan insurers: framework available on request and first annual officer-attested report due.

Primary sources

Common gaps

Where insurers most often fall short when the Division asks.

  • An inventory without version control. Section 5.A.9 names version control. A list of models with no record of which version was in use when is half the requirement.
  • Changes with no rationale. Section 5.A.10 asks for the rationale behind each material change, not only the change itself. A change log copied from a deployment system records the what and misses the why.
  • Monitoring that cannot describe drift. Section 5.A.12 names model drift explicitly. A monitoring description that covers uptime and error rates and omits performance decay leaves the named item unanswered.
  • Vendor documentation the insurer cannot produce. Section 5.B keeps the insurer responsible for production. If the vendor holds the documentation and the contract gives no route to it, the request lands on the insurer regardless.
  • Auto and health insurers still on the life timetable. The 1 July 2026 date for auto and health benefit plan insurers has passed. Their framework is now available on request and their annual report cycle has begun.

Last reviewed September 4, 2026. This reference summarises publicly available regulatory guidance and is provided for general information. It is not legal advice. Obligations depend on an institution's charter, registration status, size, and activities. Verify against the primary sources cited above and consult counsel before relying on any summary here.

Regulatory updates

When a regulator changes what an AI examination asks for, hear about it first.

Short notes on SR 26-2, NYDFS 500, FINRA, the NAIC bulletin, the EU AI Act, and the employment-AI statutes, plus what we ship. A few emails a month.