Fourteen components. Ten pages. One signature.
If you use external consumer data in a Colorado insurance practice, you owe a fourteen-component governance framework overseen by your board, an inventory of every model built on that data, and a ten-page report through SERFF signed by an officer. Life insurers have been filing since December 2024. Private passenger auto and health benefit plans came in on 15 October 2025. And if you do not use external consumer data — you still file.
There is no “the deadline”. There is yours.
Life ran two years ahead of the other two lines on every one of these dates, so a single deadline sentence is wrong for this regulation. Find your line.
- In scope from 14 November 2023
- Progress report 1 June 2024
- First compliance report 1 December 2024
- Then Annually from 1 December
- In scope from 15 October 2025
- Progress report 1 December 2025
- First compliance report 1 July 2026
- Then Annually from 1 July
- In scope from 15 October 2025
- Progress report 1 December 2025
- First compliance report 1 July 2026
- Then Annually from 1 July
- In scope from On the effective date
- Progress report Within one month
- First compliance report An officer attestation
- Then Annually on 1 December
Planning to start using ECDIS? The full compliance report is due before you start — not at your next annual date.
Four questions. Most insurers answer yes without knowing it.
The test is function, not format. Run each of your data sources down this list.
-
Does it supplement or supplant a traditional underwriting factor?
The first limb of the definition. If a source is doing work a traditional factor used to do, it is ECDIS regardless of what it is called or where it came from.
-
Or does it establish a lifestyle indicator used in an insurance practice?
The second limb. A source that never touches underwriting can still be ECDIS if it establishes a lifestyle indicator you use.
-
Did you or a vendor derive a risk score from it?
Any insurance risk score built from these sources — by you or by a vendor — is itself ECDIS. This is the question that catches the most people.
-
Is your line one of the three?
Individually issued life, private passenger automobile, or health benefit plans. Nothing else is in scope under the amended regulation yet.
Four yeses and the fourteen components are yours. Four noes and you still file — an officer-signed attestation that you do not use ECDIS, annually on 1 December, under Section 6.E.
The regulation names these by name
The categories are ours. Every example inside them is the Division’s.
Financial and credit
- Credit scores
- Purchasing habits
- Home ownership
- Civil judgments
Lifestyle and behaviour
- Social media habits
- Occupation with no direct mortality link
- Educational attainment
- Licensures
Location and public record
- Locations and geolocation
- Court records
- Public filings tied to an address
- Geographic risk proxies
Device, sensor and biometric
- Consumer-generated Internet of Things data
- Telematics (auto)
- Biometric data
- Wearable and app-derived signals
Five things that decide arguments
- The test is function, not format: a source is ECDIS if it supplements or supplants traditional underwriting factors, or establishes lifestyle indicators used in an insurance practice.
- Derived scores count. Any insurance risk score built from these sources — by you or by a vendor — is itself ECDIS.
- Telematics is named for private passenger auto, inside consumer-generated Internet of Things data.
- For health benefit plan insurers, ECDIS excludes an individual’s medical records. It does not exclude everything else about them.
- Internet of Things means networked objects collecting and exchanging data without direct human intervention — so a device a person actively fills in is outside that limb.
An insurance statute. Not an AI statute.
Which is exactly why insurers sit outside Colorado’s general automated-decision law.
SB 21-169 sits at §10-3-1104.9 C.R.S. Signed in 2021. It prohibits insurers from using external consumer data and information sources — ECDIS — or the algorithms and predictive models built on them, in a way that unfairly discriminates on the basis of race, colour, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity or gender expression.
The statute is broad. The implementation is not. The Division of Insurance gives it operational effect line by line, through rulemaking. Regulation 10-1-1 (3 CCR 702-10) took effect on 14 November 2023 for individually issued life insurance, and the amended regulation extended it to private passenger automobile and health benefit plan insurers from 15 October 2025.
What it asks for is a framework. Fourteen documented components, overseen by the board or a board committee. Once a year you summarise compliance in a report of no more than ten pages, an officer signs an attestation, and it goes through SERFF. If you cannot attest, you file a corrective action plan instead.
It survived the churn in Colorado’s general AI law untouched. When SB 26-189 replaced the repealed Colorado AI Act in May 2026, it deferred to this one: an insurer complying with §10-3-1104.9 is treated as compliant for its insurance practices — but not for employment decisions.
The amended regulation, covering all three lines. Life has been in scope since 14 November 2023.
Annual, through SERFF, addressing Sections 5.A.1–5.A.13 and signed by an officer.
Who needs to comply
-
Life insurers
Authorised in Colorado and offering individually issued life insurance. First in scope — the framework has been enforceable against them since November 2023.
-
Private passenger auto insurers
Brought in by the amended regulation from 15 October 2025. Telematics is named in the ECDIS definition for this line specifically.
-
Health benefit plan insurers
Also from 15 October 2025 — with an extra duty: a provider acting for the insurer must be ultimately responsible for prior-authorisation decisions ECDIS informs.
-
Insurers that do NOT use ECDIS
Not exempt from filing. You owe an officer-signed attestation that you do not use it, annually on 1 December.
-
Insurers planning to start
If you did not use ECDIS at the effective date but intend to, the full compliance report is due before you start — not at the next annual date.
-
Anyone relying on a vendor model
Section 5.B keeps the accountability with the insurer. A vendor may send documents to the Division on your behalf; it cannot hold the obligation for you.
Fourteen components, in the numbering the Division reads them in
The numbering is load-bearing. Section 6.D requires the annual report to address 5.A.1 through 5.A.13 in ten pages, so the report is structured on this list — and a component with a drifted number is a component the reviewer cannot find.
Governing principles
Documented values and objectives ensuring ECDIS and the models built on it are designed, used and monitored under effective oversight, and are reasonably designed to prevent unfair discrimination.
Board oversight
The governance structure and risk management framework must be overseen by the board of directors or a committee of the board. Not delegable to a working group.
Senior management accountability
Named responsibility for strategy and direction, clear lines of communication, delegated decision authority, and regular reporting on performance and risk.
Cross-functional governance group
Documented, and drawn from legal, compliance, risk, product development, underwriting, actuarial, data science, marketing and customer service as applicable.
Provider accountability
Health benefit plan insurers only: a provider acting for the insurer must be ultimately responsible for decisions to modify or deny prior or concurrent authorisation informed by ECDIS.
Health onlyLifecycle policies and training
Documented policies and roles across design, development, testing, deployment, use and monitoring — plus an ongoing internal supervision and training programme for relevant staff.
Complaints and adverse decisions
Documented handling of applicant, policyholder, beneficiary and covered-person enquiries, giving the person what they need to take meaningful action after an adverse decision. Existing grievance procedures may be used.
Risk assessment and prioritisation
Documented processes for assessing and ranking the risks of deploying ECDIS in insurance practices, with reasonable regard to the impact on the people affected.
Inventory with version control
An up-to-date inventory of every ECDIS, algorithm and predictive model, each with a description, a clearly stated purpose and the outputs it generates.
Material change log
A documented explanation of any material change to the inventory, and the rationale for it. The rationale is the part most inventories omit.
Quantitative testing
A documented description of the testing conducted under Division requirements to detect unfair discrimination — methodology, assumptions, results and remediation. See the status section below.
See the statusOngoing monitoring
A documented description of how model performance is monitored over time, explicitly accounting for model drift.
Third-party selection
A documented description of how external resources and vendors supplying ECDIS or models are selected, including the intended use of each.
Annual review
A documented comprehensive annual review of the governance structure and the framework, with the documentation updated to keep it accurate and relevant.
Outside the 10-page reportThirteen of the fourteen go in the report. Section 6.D names 5.A.1 through 5.A.13. Section 5.A.14 — the comprehensive annual review of the whole structure, with the documentation updated — sits outside that range, and it is the component that proves the other thirteen are still true.
The duty is live. The method is not.
This is the question we are asked most, and the one most often answered wrong. Written as a status rather than as a rule, because that is what it is.
Is quantitative bias testing required yet?
Four answers, because the question has four halves.
Section 5.A.11 requires a documented description of quantitative testing conducted under requirements established by the Division. That component of the framework is live.
The Division circulated a draft quantitative-testing regulation for life underwriting in September 2023, built on Bayesian Improved First Name Surname Geocoding. It has not been adopted.
The Division waived the testing description for the annual reports due 1 December 2024 and 1 December 2025. The waiver was expressed as covering those reports only.
Build the data and cohort pipeline the draft would need — declination rates and premium per $1,000 of face amount, by estimated race and ethnicity — and hold the methodology open.
This is the one section on this page written from secondary reporting rather than off the regulation, and it is also the section a reader is most likely to act on. Re-check it before you rely on it — and if anyone tells you annual bias testing is simply required today, ask them which adopted regulation says so.
Small, specific, and where good programmes fail
Four facts about the document itself. Each one has failed a filing that had the framework behind it.
Filing type “Annual Report”, a separate filing per insurer, with the description citing Regulation 10-1-1.
A hard cap, including the executive summary, addressing Sections 5.A.1 through 5.A.13.
Signed by an officer attesting compliance. Titles and qualifications of each responsible individual are required; names are optional.
Not a missed filing. An insurer unable to attest must submit a plan instead — silence is the failure, not the gap.
What the regulation says. What we hand you.
Twelve obligations with their section references, and the artefact that discharges each one. Paired, so every claim on this page can be checked against the duty beside it.
- Scope determination Section 3 & 4.D
- A written call on whether each data source is ECDIS for your line, with the reasoning — including the sources you concluded are out.
- Governing principles Section 5.A.1
- A drafted principles document that says what your use of ECDIS is for and what it will not be used for.
- Board and management structure Sections 5.A.2–5.A.4
- Board or committee terms of reference, a senior-management RACI, and the charter for the cross-functional governance group.
- Lifecycle policy set Section 5.A.6
- Policies across design, development, testing, deployment, use and monitoring, plus the training programme and its completion record.
- Complaint and adverse-decision route Section 5.A.7
- A procedure mapped onto your existing grievance and appeal flow, and the wording that gives a person enough to act on.
- Model and data inventory Sections 5.A.9–5.A.10
- A versioned register with purpose and outputs per entry, and a change log that records the rationale as well as the change.
- Quantitative testing description Section 5.A.11
- The testing narrative — methodology, assumptions, results, remediation — drafted to the Division’s requirements as they stand when you file.
- Monitoring and drift Section 5.A.12
- A monitoring specification with thresholds, owners and a drift trigger that actually fires rather than a paragraph saying drift is monitored.
- Vendor selection and oversight Sections 5.A.13 & 5.B
- A selection and oversight process, a document-production route through the vendor, and the intended-use statement per model.
- Annual review Section 5.A.14
- A review calendar with owners, and the evidence pack that shows the last review happened and changed something.
- The SERFF filing Sections 6.B–6.G
- The ten-page report drafted against 5.A.1–5.A.13, the officer attestation, and the filing packaged for SERFF.
- Non-user attestation Section 6.E
- If you concluded you are out of scope: the attestation, and the written analysis that supports it if the Division asks.
Seven months, counted backwards from your filing date
Anchored to the filing rather than forward from a start date, because the deadline is fixed and the start is not. A reader arriving in month five can see what they have already lost.
Scope and inventory
Decide what is ECDIS, and prove it
- Every data source, model and derived score listed
- The in-or-out call written down per source
- Vendor models identified with their suppliers
- Line-of-business scope confirmed against Section 3
Build the framework
Fourteen components, in their own numbering
- Governing principles and board terms of reference
- Cross-functional group charter and RACI
- Lifecycle policies, training and monitoring specs
- Complaint and adverse-decision procedure
Testing and evidence
Make the documents true
- Testing methodology drafted and dry-run
- Drift thresholds set with owners and triggers
- Change log started, with rationale captured
- Vendor documentation collected and gaps chased
File and attest
Ten pages and a signature
- Report drafted against 5.A.1–5.A.13
- Responsible individuals’ titles and qualifications listed
- Officer walkthrough before signature
- SERFF filing packaged, or the corrective action plan
The phases overlap, and the framework outlives the filing. Section 5.A.14 requires a comprehensive annual review of the whole structure with the documentation updated, so month seven is the start of the next cycle rather than the end of this one. Insurers that treat the report as the deliverable rebuild it from scratch every year.
Three sanctions. No published figure.
Regulation 10-1-1 does not set its own penalty schedule. It opens the door to the sanctions already available under Colorado insurance law — which, for a model in production, is a sharper instrument than a fixed fine.
Civil penalties
Under the Colorado statutes governing the business of insurance, subject to due process.
Cease and desist orders
The Commissioner can stop the practice, which for a model in production is the sanction that actually hurts.
Licence suspension or revocation
The outer limit of Section 9, and the reason the officer attestation is not a formality.
Confidentiality
Material disclosed to the Division, including through SERFF, is subject to §10-3-1104.9(3)(d) C.R.S. — a protection, not an exemption from filing.
No per-violation figure appears on this page because Section 9 sets none — it points at the sanctions available under the Colorado statutes governing the business of insurance, subject to due process. Any dollar cap you see quoted for SB 21-169 belongs to a different statute.
Six workstreams, and what each one leaves behind
Each one is a change in how the business operates, not a document that lands and then ages.
ECDIS inventory and scoping
The register the whole regulation hangs off — every source, model and derived score, with the in-or-out call recorded against each one.
Governance framework build
All fourteen components drafted to the section numbering the Division reads them in, so the report writes itself from the framework.
Bias testing readiness
The data, the cohort definitions and the pipeline you would need to run race-proxy testing on declinations and rating — ready before the rule lands.
Adverse-decision workflow
The complaint route, the explanation wording and the escalation path that give an applicant something they can actually act on.
Vendor documentation chase
The questions to put to a model vendor, and the answers you need on file before the officer signs anything.
The SERFF filing pack
Ten pages against 5.A.1–5.A.13, the attestation, and — where the answer is not yet yes — the corrective action plan instead.
28 ready-to-use templates
Mapped to the fourteen components and to the report structure the Division reads them in.
Governance & oversight
- ECDIS Governing Principles
- Board Oversight Terms of Reference
- Governance Group Charter
- Senior Management RACI
- Annual Review Procedure
- Internal Training Programme
+ 3 more in this group
Model & data controls
- ECDIS & Model Inventory
- Material Change Log
- Model Lifecycle Standard
- Quantitative Testing Methodology
- Monitoring & Drift Standard
- Remediation Procedure
+ 4 more in this group
Consumers, vendors & filing
- Adverse Decision Explanation Pack
- Complaint & Enquiry Procedure
- Vendor Selection & Oversight
- Vendor Documentation Request
- Regulation 10-1-1 Report Template
- Officer Attestation & CAP Template
+ 3 more in this group
Frequently asked questions
Scope, ECDIS, testing and the filing itself.
What does SB 21-169 actually prohibit?
Using external consumer data and information sources, or algorithms and predictive models built on them, in a way that unfairly discriminates on the basis of race, colour, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity or gender expression. It is codified at section 10-3-1104.9 C.R.S. and applies to insurance practices generally; the Division implements it line by line through rulemaking.
Is this the same as the Colorado AI Act?
No, and they are constantly confused. SB 21-169 is insurance-specific and enforced by the Division of Insurance. The Colorado AI Act was SB 24-205, which never took effect and was repealed by SB 26-189 in May 2026. SB 26-189 in fact defers to this regime: an insurer complying with section 10-3-1104.9 is treated as compliant for its insurance practices — though not for employment decisions.
Which lines of business are in scope right now?
Individually issued life insurance, private passenger automobile insurance and health benefit plans. Life has been covered since 14 November 2023; auto and health were added by the amended regulation with effect from 15 October 2025.
What if we do not use ECDIS at all?
You still file. Section 6.E requires an officer-signed attestation that you do not use ECDIS or models built on it, annually on 1 December. And if you later plan to start, the full compliance report is due before you start using it, not at the next annual date.
What counts as ECDIS?
A data or information source used to supplement or supplant traditional underwriting factors, or to establish lifestyle indicators used in an insurance practice. The regulation names credit scores, social media habits, locations, purchasing habits, home ownership, educational attainment, licensures, civil judgments, court records, consumer-generated Internet of Things data and biometric data — plus any insurance risk score you or a vendor derive from them.
Are medical records ECDIS?
For health benefit plan insurers the regulation expressly excludes an individual’s medical records from ECDIS. That exclusion is narrow: it takes out the medical record, not everything else the insurer knows about the person.
Is telematics in scope?
For private passenger auto, yes — the definition for that line names telematics inside consumer-generated Internet of Things data. Note the Internet of Things definition excludes devices that require direct human intervention to collect and exchange data.
Does using a vendor model move the obligation?
No. Section 5.B keeps every Section 5.A requirement with the insurer, including producing whatever documents the Division asks for. A vendor may supply those documents to the Division on your behalf, and you must have a documented process for selecting and overseeing that vendor.
Who has to oversee the framework?
The board of directors or a board committee, under Section 5.A.2. Senior management holds strategy and accountability under 5.A.3, and a documented cross-functional group — legal, compliance, risk, product, underwriting, actuarial, data science, marketing, customer service — sits under 5.A.4.
Is bias testing required yet?
The duty to describe testing is in the framework at Section 5.A.11, but it points at requirements the Division establishes, and the quantitative-testing regulation for life underwriting has been in draft since September 2023 without adoption. The Division waived the testing description for the reports due 1 December 2024 and 1 December 2025. Treat the methodology as pending and the readiness work as due now.
What is BIFSG?
Bayesian Improved First Name Surname Geocoding — a statistical method developed by RAND for estimating race and ethnicity from a name and location. The draft testing regulation would use it to compare declination rates and premium per $1,000 of face amount across estimated groups. Its error rates are exactly what the actuarial objections have been about.
What does the annual report have to contain?
A summary of compliance with Section 5, plus the title and qualifications of each individual responsible and which requirements they own. Ten pages maximum including the executive summary, addressing Sections 5.A.1 through 5.A.13, signed by an officer attesting compliance.
How is it filed?
Through SERFF, using “Annual Report” as the filing type, one filing per insurer, with the description stating that it is submitted under Colorado Insurance Regulation 10-1-1.
What if we cannot honestly attest?
You file a corrective action plan instead. That is a route the regulation provides, not a failure state — the failure state is filing an attestation you cannot support, or filing nothing.
What are the penalties?
Section 9 exposes non-compliance to the sanctions available under Colorado insurance law: civil penalties, cease and desist orders, and suspension or revocation of licence, subject to due process. The regulation itself names no per-violation figure.
What does an iDharma readiness review cost and how long does it take?
It is scoped before you are charged. The variables are how many models and data sources sit in your insurance practices, how much vendor documentation you already hold, and whether you are filing for one line or three; we tell you the shape of all three after a short scoping call.
Do not take our word for it
The deadline table and the fourteen components on this page were read off the amended regulation. Where a scoping decision turns on the wording, go to it.
Primary sources
The bill, the Division and the Code of Colorado Regulations. External links.
Related on this site
The regimes that most often sit alongside SB 21-169 in the same scope.
- Colorado AI Law (SB 26-189) Disclosure duties for automated decision-making technology
- NAIC AI Principles Insurance-regulator expectations for AI governance
- NIST AI RMF Govern, Map, Measure and Manage, assessed end to end
- GDPR Where the same models touch personal data of people in the EU or UK
- Every framework we audit against The full catalog, by region and kind
Find out what your next filing asks of you
A scoping call, then a written scope. You get the ECDIS register with the in-or-out call per source, the fourteen components drafted in the Division’s own numbering, the testing pipeline ready for whenever the rule lands, and the ten-page report — scoped before you are charged.
This page is guidance on how we scope an SB 21-169 readiness review, not legal advice. The deadlines and components were read off the amended regulation; the quantitative-testing position is the Division’s to move, and we say so rather than pick the convenient answer.
From Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
Read the notesWhat Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
Read the notesWhat an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Read the guide