TwinEthosRequest access

Law

Colorado Insurance AI (SB21-169 / Reg 10-1-1)

Colorado Division of Insurance · Colorado (US-CO) · 1 provision encoded · verified against the official source as of 2026-09-27.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: www.sos.state.co.us.

Binding law — in force

Insurance algorithms must not unfairly discriminate via external data

3 CCR 702-10, Regulation 10-1-1, Section 5.A · official text · In force: applies since 14 Nov 2023 · Colorado (US-CO)

Colorado life insurers using external consumer data and information sources (ECDIS) or algorithms/predictive models that use ECDIS must establish a documented risk-based governance and risk-management framework to detect and remediate unfair discrimination (esp. by race): governing principles, board oversight, senior-management accountability, a cross-functional governance group, lifecycle policies with training, a consumer-complaint/adverse-decision process, a risk rubric, a versioned model inventory, discrimination testing, model-drift monitoring, vendor-selection processes, and annual reviews. Detect an insurance ECDIS/model decision path with no governance-framework or model-inventory artifact.

Who it applies to

  • Duty falls on: insurer
  • Systems covered: consequential decision
  • Sectors: insurance
  • All life insurers authorized to do business in Colorado that use ECDIS or algorithms/predictive models using ECDIS. Effective 2023-11-14; governance framework available to the Division on 2024-12-01 and annually. (Auto/health insurance rulemaking ongoing.)
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Build decision prompts and feature sets from an allowlist of decision-relevant fields, and redact protected attributes, known proxies, and free text before the model sees them.

At the prompt builder or feature-assembly step on the consequential-decision path, construct model inputs from an explicit allowlist (FEATURE_ALLOWLIST, APPROVED_FEATURES) instead of passing the whole person record or f-string interpolating its fields. Protected attributes (race, sex, religion, age, disability) and proxies (ZIP or postal code, surname, school, census tract) stay out unless a documented justification and a bias test exist, and free text (cover letters, notes, transcripts) goes through redaction (redact_pii, strip_protected_attributes) first. Log the features used and the model output per decision, and run disparity tests on outcomes; human review lowers the risk but does not replace the allowlist.

Where it goes: 1 application source code, 2 data models, 7 prompt construction, 13 tests and evals.

What this provision adds:

  • Keep a documented governance framework with board oversight, a versioned model inventory, discrimination testing (especially by race), model-drift monitoring, a consumer complaint and adverse-decision process, and annual reviews.
  • Make the governance framework available to the Division from 2024-12-01 and annually.

Example (Python + OpenAI SDK), before:

prompt = f"Applicant {a.last_name}, age {a.age}, zip {a.zip_code}.\nNotes: {a.applicant_notes}\nApprove the loan?"
resp = client.chat.completions.create(model=MODEL, messages=[{'role': 'user', 'content': prompt}])

After:

FEATURE_ALLOWLIST = ['income', 'debt_to_income', 'requested_amount', 'payment_history_months']

features = {k: getattr(a, k) for k in FEATURE_ALLOWLIST}
notes = strip_protected_attributes(a.applicant_notes)   # drops names, ages, places, etc.
messages = [{'role': 'system', 'content': LENDING_RUBRIC},
            {'role': 'user', 'content': json.dumps({'features': features, 'notes': notes})}]
resp = client.chat.completions.create(model=MODEL, messages=messages)
decision_log.record(a.id, features, resp.choices[0].message.content)

Control: Protected or proxy attribute reaches AI decision. The same guard addresses 4 items with binding law in 3 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id co-sb21-169.insurance-ecdis-unfair-discrimination · review status: primary source derived