Direct comparison
Insurer AI Rules: NAIC vs Colorado vs NY DFS
Guidance, statute, supervisory expectation: how the NAIC Model Bulletin, Colorado SB 21-169 and NY DFS Circular Letter No. 7 each govern insurer AI.
Written and maintained by CASRAI Editorial Board
Last updated
Ask CASRAI · free to try
Ask about Insurer AI Rules: NAIC vs Colorado vs NY DFS
Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.
An AI assistant specialized in research administration. It cites the sources behind every answer, labels web answers and says when it can't answer.
Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
Works on this site and inside Claude, Cursor and the AI tools you already use.
Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.
How do NAIC Model Bulletin (Dec 2023), Colorado SB 21-169 (2021), NY DFS Circular Letter No. 7 (2024) compare side by side?
The table below compares NAIC Model Bulletin (Dec 2023), Colorado SB 21-169 (2021), NY DFS Circular Letter No. 7 (2024) across 12 procurement-relevant dimensions, from legal force through penalty attached.
Side-by-side comparison
| Dimension | NAIC Model Bulletin (Dec 2023) | Colorado SB 21-169 (2021) | NY DFS Circular Letter No. 7 (2024) |
|---|---|---|---|
| Legal force | Guidance. A model bulletin the NAIC adopted for states to issue; it restates existing obligations rather than creating new ones, and carries no penalty of its own. Force depends entirely on whether a given state department issues it. | Statute. Enacted law (signed 6 July 2021, effective 7 September 2021), binding on its own terms, with implementing rules adopted by the Commissioner of Insurance. | Supervisory expectation. A circular letter interpreting existing New York Insurance Law and regulation for AI and external data. It is not new statute, but it is the Department stating in advance what it will look for. |
| Who it applies to | Insurers licensed in whichever state issues the bulletin. The NAIC itself licenses nobody; adoption is state by state. | Insurers doing business in Colorado, across the insurance practices the Commissioner reaches by rule. | Named explicitly: insurers authorised to write in New York, Article 43 corporations, health maintenance organisations, licensed fraternal benefit societies, and the New York State Insurance Fund. |
| What it actually requires | A written AI Systems (AIS) Program covering governance, risk management and internal controls over AI use in underwriting, pricing, marketing and claims — proportionate to the insurer's use of AI. | Do not use an external consumer data and information source, algorithm or predictive model that results in unfair discrimination; maintain a risk-management framework reasonably designed to detect it; report on it; attest to it. | Run the three-step assessment on every ECDIS or AI system used in underwriting or pricing, document it, govern it at board level, test before deployment and on a recurring cadence, and disclose to the consumer. |
| Protected characteristics named | Not enumerated in the bulletin itself — it points back to whatever the state's own unfair-trade-practice and unfair-discrimination law already prohibits. | Enumerated in the statute: race, colour, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity, gender expression. | Protected classes under existing New York law; the letter frames the test around disproportionate adverse effect on similarly situated insureds and protected classes rather than adding its own list. |
| Is quantitative testing specified? | No. The bulletin sets the expectation that testing and validation happen and be documented; it does not name a statistic. | By delegation. The statute directs the Commissioner to adopt rules, by insurance practice and after stakeholder engagement, establishing how an insurer demonstrates its testing — so the arithmetic lives in the rules, not the statute, and arrived line of business by line of business. | Yes, and by name: adverse impact ratio, denials odds ratios, marginal effects, standardized mean differences, Z-tests and T-tests, plus analysis of the drivers of any disparity found. |
| The discrimination test itself | Not defined. The bulletin's concern is that the insurer can show a department how it guards against adverse consumer outcomes, not what test it ran. | Outcome-based prohibition: the question is whether use of the data source, algorithm or model results in unfair discrimination, with the framework existing to determine that "to the extent practicable". | Three explicit steps: (1) measure whether the tool produces a disproportionate adverse effect; (2) if it does, ask whether a legitimate, lawful and fair explanation accounts for it; (3) search for and analyse less discriminatory alternative variables or methodologies that still meet the business need. |
| Can you rely on a vendor's assurance? | The bulletin expects the AIS Program to cover AI systems and data acquired from third parties, including due diligence and contractual terms — but stops short of a prohibition on reliance. | The statute puts the duty on the insurer regardless of who built the model; a vendor-supplied predictive model is still the insurer's use of a predictive model. | Explicitly barred: "An insurer may not rely solely on a third-party's claim of non-discrimination or a proprietary third-party process to determine compliance with anti-discrimination laws." The letter also expects audit rights and vendor cooperation with regulatory inquiries in the contract. |
| Who signs off | Senior management and the board, through the AIS Program's governance structure. No named attesting officer. | The chief risk officer, by attestation that the risk-management framework has been implemented appropriately on a continuous basis — a named officer putting a signature on a continuing state of affairs, not a one-off filing. | The board provides strategic oversight and may delegate to committees; senior management owns day-to-day implementation and must pull in legal, compliance, risk, product, underwriting, actuarial and data science. No single attesting officer named. |
| Testing cadence | Ongoing monitoring and validation expected as part of the AIS Program; no fixed interval stated. | Ongoing monitoring is part of what must be reported, and the CRO attestation is to continuous implementation rather than a point in time. | Before production deployment, regularly thereafter, at least annually for model output and drift, and whenever a material update or change occurs. |
| What the consumer is told | Consumer-facing disclosure is left to the state's existing law; the bulletin's disclosure focus is toward the regulator. | Not the statute's primary mechanism — it works through the Commissioner and the framework rather than through a consumer notice requirement. | Notice that AI systems and external vendor data are in use, a right to request the specific data used, and — on an adverse underwriting determination — written notice within 15 days explaining the reasons and the information relied on, including data sources. |
| What the examiner actually asks for | This is the bulletin's real payload: it sets out the categories of information and documentation a department may request during an investigation or examination, so an insurer can assemble the file before anyone asks. | Identification of the external data sources used in developing the algorithm or model, an explanation of how each is deployed for the specific insurance practice, results demonstrating the framework works, and the actions taken to minimise unfair-discrimination risk including ongoing monitoring. | The documented three-step assessment with its numbers, the governance record showing who reviewed it, the vendor due diligence, and evidence of the pre-deployment and recurring testing. |
| Penalty attached | None of its own. Consequences come from the underlying state law the bulletin points at. | Statutory — non-compliance is a violation of the Colorado insurance code, enforceable through the Commissioner's existing authority. | No new penalty created; the letter operates through the Department's existing supervisory, market-conduct and enforcement powers under the laws it interprets. |
Common questions
Common questions about NAIC Model Bulletin (Dec 2023) vs Colorado SB 21-169 (2021) vs NY DFS Circular Letter No. 7 (2024)
Which of the three is most demanding in practice?
+
New York DFS Circular Letter No. 7, even though it is the least binding on paper. Colorado has the statute and the attestation, but the specific arithmetic sits in rules adopted line of business by line of business. CL7 names the metrics an insurer has to compute — adverse impact ratio, denials odds ratios, marginal effects, standardized mean differences — and requires the third step almost nobody else requires: an actual documented search for a less discriminatory alternative that still meets the business need. A general counsel reading only for enforceability will rank these in exactly the wrong order.
Does an insurer operating in all three states have to run three programmes?
+
No, but it does have to build to the ceiling. The NAIC bulletin's AI Systems Programme structure is a superset container that both other regimes fit inside; the practical approach is one AIS Programme, with the Colorado risk-management framework and CRO attestation as a named module and the CL7 three-step assessment as the testing methodology applied wherever ECDIS or AI touches underwriting or pricing. The incompatibility is not in the substance, it is in what each regulator will ask to see and in what form.
Is the NAIC bulletin binding anywhere?
+
Only where a state insurance department has issued it. The NAIC is a standard-setting organisation of state regulators, not a regulator: it licenses nobody and can enforce nothing. A model bulletin becomes operative when an individual commissioner adopts and issues it, which is why "NAIC requires" is always a misstatement — the correct form is "the states that have issued the NAIC model bulletin expect".
Is examination itself going to become uniform?
+
That is the point of the NAIC Big Data and Artificial Intelligence (H) Working Group's AI Systems Evaluation Tool, which is in pilot with 12 participating states and which the NAIC anticipates taking to broader adoption at its Fall 2026 National Meeting. It is the first attempt to standardise not the rule but the examination — what a regulator looks at when reviewing an insurer's AI operations, governance practices, high-risk models and data inputs. If it lands, the practical convergence will come from the exam procedure rather than from any of the three instruments above.
Does any of this reach a university?
+
In two ways, and neither is a stretch. First, directly: an academic medical centre that operates a health plan or HMO is a regulated entity — New York's circular letter names Article 43 corporations and health maintenance organisations on its face, so a provider-sponsored plan run out of a university health system is inside its scope, not adjacent to it. Second, methodologically: CL7's three-step test is the most concrete bias-testing methodology any US regulator has published, and university research-computing groups and IRBs evaluating clinical predictive models currently have nothing comparable to work from — OHRP has not issued an equivalent. Borrowing a supervisory methodology is not the same as being bound by it, and a research-compliance office should say which it is doing.
Does NIKOLAI have a term for the vendor-reliance problem?
+
The closest is Evaluator Independence and Conflict of Interest, an element on NIKOLAI's N8 transparency-and-review track, which records the declared financial, organisational and personal relationships between an evaluator and the developer being assessed, plus the independence verification applied. New York's refusal to let an insurer rest on a vendor's own claim of non-discrimination is the same structural concern in a different sector. Two cautions: NIKOLAI is CASRAI's own independent frontier-AI-safety dictionary and is not endorsed by anyone it names, and every crosswalk row on that element is a shadow mapping — CASRAI's reading of a published document — unless the organisation has filed a Mapping Declaration. No insurance regulator has filed one, and none of the three instruments on this page is mapped in NIKOLAI today.








