Colorado passed SB 21-169 in 2021 and put it at section 10-3-1104.9 C.R.S. It prohibits insurers from using external consumer data — or any model built on it — in a way that unfairly discriminates against a protected class. On its own it states a prohibition rather than a programme.
Even if you use no ECDIS at all, there is still an annual filing.
Regulation 10-1-1 binds the insurer, not the vendor - fourteen components, filed every year, and you file even if you use no ECDIS.
Our promise
“An attestation is a letter. The testing is evidence.”
Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.
- Each additional system
- $3,000
- Re-audit, same scope
- $8,000
- Renewal, every twelve months
- $10,500 locked
This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.
Request this auditColorado’s insurance rule, in three chapters
The Division of Insurance gives it effect line by line. Regulation 10-1-1 took effect for life in November 2023, and the amended regulation brought auto and health benefit plans in on 15 October 2025. Every duty starts there, not in the statute above it, which names no filing and sets no date.
Once a year the framework is summarised in ten pages, signed by an officer of the company and filed through SERFF. If you cannot attest, you file a corrective action plan instead. And if you do not use ECDIS at all, you still file — an officer attestation saying so, on 1 December.
Data that decides before you do.
A source that supplements or supplants an underwriting factor, or establishes a lifestyle indicator.
- Credit scores, purchasing habits, home ownership
- Social media habits, education, licensures, occupation
- Locations, court records and public filings tied to an address
- Consumer-generated IoT data, telematics, biometrics
- Derived scores count — yours or a vendor’s, both are ECDIS
- Telematics is named for private passenger auto specifically
- For health plans it excludes the medical record, nothing else
- A device filled in by hand is outside the Internet of Things
The duty is yours. The model is theirs.
The insurer that uses the data
Regulation 10-1-1 places every requirement on the insurer authorised to do business in Colorado. The governing principles, the board oversight, the inventory, the testing description, the annual review and the officer-attested report are all yours. None of them can be discharged by somebody else.
The people who built the model
Carries no obligation of its own under this regulation. Many model vendors document their work well, and that documentation is genuinely useful. What it is not is a substitute: a vendor may send papers to the Division on your behalf, and the duty stays with the insurer whose filing it is.
Not using ECDIS is still a filing
Section 6.E asks an insurer that does not use external consumer data for an officer-signed attestation saying so, annually on 1 December. And if you did not use it at the effective date but intend to start, the full compliance report is due before you start rather than at the next annual date.
“Our vendor built it, so the papers are theirs.”
The vendor may send the papers. You still owe them.
It is the most common finding we write up.
- Who it is for
- Chief actuaries
- Compliance & regulatory affairs
- Underwriting leadership
- Model risk & data science
- General counsel
- Vendor management
A cease and desist order stops the practice — which, for a model already running in production, is the sanction that actually hurts.
The regulation names no per-violation figure at all. Any page quoting one for Regulation 10-1-1 is quoting a different statute entirely.
Material filed through SERFF is protected under §10-3-1104.9(3)(d) — which is a protection, and not an exemption from having to file it.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a determination.
Your scope check
Four lines, and not one deadline.
Life ran two years ahead of auto and health on every date in the regulation - so “the deadline” is a sentence this rule cannot support.
-
Life
Every 1 DecemberIndividually issued life. In scope 14 November 2023, first report 1 December 2024 - well ahead of the rest.
Next: 1 December 2026 in 9 weeks
-
Auto
Every 1 JulyPrivate passenger auto. In scope 15 October 2025, first report 1 July 2026. Telematics is named.
Next: 1 July 2027 in 40 weeks
-
Health
Every 1 JulyHealth benefit plans, on the same dates as auto - with the provider still answerable for prior authorisations.
Next: 1 July 2027 in 40 weeks
-
Non-users
Every 1 DecemberAn officer attestation that you do not use ECDIS. Not an exemption - a different document, same clock.
Next: 1 December 2026 in 9 weeks
Bias testing is half in force. Section 5.A.11 requires a documented description of quantitative testing — but the methodology it points at has been in draft since September 2023, built on Bayesian Improved First Name Surname Geocoding, and the Division waived the description for the reports due 1 December 2024 and 1 December 2025. Build the data and the cohorts now. Hold the methodology open.
What the regulation says, what we ship
12 obligations across the fourteen components, each with the artefact that discharges it.
- Scope determination Sections 3 and 4.D - and the sources you rule out
- A written call on whether each data source is ECDIS for your line, with the reasoning - including the sources you concluded are out.
- Governing principles Section 5.A.1
- A drafted principles document that says what your use of ECDIS is for, and what it will not be used for.
- Board and management structure Sections 5.A.2 to 5.A.4
- Board or committee terms of reference, a senior-management RACI, and the charter for the cross-functional governance group.
- Provider accountability Section 5.A.5 - health benefit plans only
- The written line of responsibility putting a provider, not a model, behind a decision to modify or deny prior authorisation.
- Lifecycle policy set Section 5.A.6
- Policies across design, development, testing, deployment, use and monitoring, plus the training programme and its completion record.
- Complaint and adverse-decision route Section 5.A.7
- A procedure mapped onto your existing grievance and appeal flow, and the wording that gives a person enough to act on.
- Risk assessment and ranking Section 5.A.8
- A documented assessment that ranks deployments by their effect on the people they touch, rather than by their effect on you.
- Model and data inventory Sections 5.A.9 and 5.A.10
- A versioned register with purpose and outputs per entry, and a change log that records the rationale as well as the change.
- Quantitative testing description Section 5.A.11 - see the trap on the calendar
- The testing narrative - methodology, assumptions, results, remediation - drafted to the Division's requirements as they stand when you file.
- Monitoring and drift Section 5.A.12
- A monitoring specification with thresholds, owners and a drift trigger that actually fires, rather than a paragraph saying drift is monitored.
- Vendor selection and oversight Sections 5.A.13 and 5.B
- A selection and oversight process, a document-production route through the vendor, and the intended-use statement per model.
- Annual review and the filing Section 5.A.14 and Sections 6.B to 6.G
- A review calendar with owners, the ten-page report drafted against 5.A.1 to 5.A.13, and the officer attestation packaged for SERFF.
Insurance models, independently reviewed
From a credit attribute to a vendor risk score.
-
Scope
Which sources are ECDIS for your line, and which you concluded are not.
-
Build
All fourteen components, drafted in the section numbering the Division reads.
-
Sign off and file
You see the draft first. Then the ten pages, the attestation and the SERFF pack.
Why insurers choose iDharma for Regulation 10-1-1
We read the regulation
The dates and components here come off Amended Regulation 10-1-1 itself, not off a summary.
Independent of vendors
We resell no models and take no fee from the firms supplying the ones in your practices.
One build, three lines
Life, auto and health scope into one framework, so three filings do not become three programmes.
Artefacts, not a deck
The register, the framework and the ten pages - in the form the Division actually reads them.
Four marks, struck on every review.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
ECDIS readiness review
The full review in one document: every source and model with its in-or-out call for the lines you write, the fourteen components tested against what you actually hold, and a ranked list of what has to exist before the officer signs - dated, and written to the section numbering the regulation itself uses.
ECDIS and model inventory
Every source, model and derived score with its purpose, outputs, owner and vendor, in a register your own teams can keep current after we go.
Scope determination memo
The ECDIS call for each source, written with its reasoning - including the ones you ruled out, which is the half a reviewer asks about.
Governance framework pack
Principles, board terms of reference, the group charter, the lifecycle policies and the training programme - drafted in the regulation's own numbering.
Bias-testing readiness
The cohorts, the data and the pipeline the draft methodology would need - built so the description can be written the week the rule lands.
Adverse-decision pack
The complaint route, the explanation wording and the escalation path that give an applicant something they can actually act on.
SERFF filing pack
Ten pages against 5.A.1 to 5.A.13, the officer attestation, and - where the answer is not yet yes - the corrective action plan instead.
Real numbers, upfront.
- Scope
- Set by the regulation, not by us
- Output
- Ten pages, filed through SERFF
- Re-review
- Each filing year - $10,500 against your known baseline
The regulation fixed the scope, so the fee is flat - nothing to meter, and nothing charged until you approve it.
Request this review- ECDIS and model inventory, versioned
- Scope determination per source, reasoned
- All fourteen components, drafted
- The ten-page report and the attestation
Four things you have to be able to produce
Regulation 10-1-1 is not graded on intent. Each of these is either in your hand on the day the Division asks, or it is not.
The register,
kept
Every source, model and derived score, each with a description, a stated purpose and its outputs - plus a change log carrying the rationale, not only the change.
The board,
in charge
Fourteen components under board or board-committee oversight. Section 5.A.2 does not let that oversight be delegated down to a management working group.
The report,
ten pages
A summary of compliance addressing 5.A.1 through 5.A.13, an executive summary included, with the title and the qualifications of each responsible individual.
The filing,
signed
An officer's signature, filed through SERFF. Where you cannot honestly attest, a corrective action plan goes in its place - the silence is the failure here, not the gap itself.
Four cards, and the date on each one is part of the card.
Plain answers
Scope, filing, and the cost of getting it wrong. Answered straight.
Request this reviewIs this the same as the Colorado AI Act?
No, and they are constantly confused. SB 21-169 is insurance-specific and enforced by the Division of Insurance. The Colorado AI Act was SB 24-205, which never took effect and was repealed by SB 26-189 in May 2026.
What if we do not use ECDIS at all?
You still file. Section 6.E requires an officer-signed attestation that you do not use ECDIS, annually on 1 December. And if you later plan to start, the full compliance report is due before you start, not at the next annual date.
What counts as ECDIS?
A source used to supplement or supplant traditional underwriting factors, or to establish lifestyle indicators used in an insurance practice - plus any insurance risk score you or a vendor derive from one. The test is function, not format.
Is bias testing required yet?
The duty to describe testing is live at Section 5.A.11, but it points at requirements the Division has not adopted - the draft has been open since September 2023, and the description was waived for the 2024 and 2025 reports.
What are the penalties?
Section 9 exposes non-compliance to the sanctions available under Colorado insurance law: civil penalties, cease and desist orders, and suspension or revocation of licence, subject to due process. The regulation names no per-violation figure.
Request your ECDIS readiness review
Tell us what sits in your underwriting path and we come back with a scoping call.
What we need from you
Nothing you do not already have. Most of it comes out of your model risk and underwriting records in an afternoon, and we tell you which extracts before you commit.
- Which of the three lines you write in Colorado
- Every outside data source and model in the practice
- Which came from a vendor, and the documents you hold
- Your board or committee papers on model oversight
- Your next filing date, and whether you have filed before
What happens next
- You send the five items we need.
- We book a scoping call within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- SB 21-169 and §10-3-1104.9 C.R.S.
- Amended Regulation 10-1-1, 3 CCR 702-10
- Life in scope
- 14 November 2023
- Auto & health
- 15 October 2025
What it means
- General information about what the regulation requires — not legal advice, and no professional relationship arises from it. It determines nothing about your own systems.
- Where a scope question is arguable, our reports say so rather than the convenient one.
Scope & limitation
- The deadlines, the fourteen components and the ten-page cap were read off the amended regulation. The quantitative-testing status was not — it is secondary reporting, and it says so on the trap plate.
- It covers Regulation 10-1-1 alone — the ADMT statute and privacy law reach further.
- Use it as a starting point for a scoping conversation, not as your final word.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Colorado SB 26-189: Four Duties, and the One Nobody Budgets For
Notice before, disclosure after, human review on request, records for three years. Three are policy changes. The second is an engineering project, and it arrives late.