INSURANCE AI COMPLIANCE · EU AI ACT · 1-4 WEEKS

AI in underwriting, pricing and claims. Audited once.

Two are in force today, the third has a date, and none accepts a supplier's assurance.


A reviewer with a beard, in a navy blazer, a closed notebook at the edge of the desk, seated at a dark stone desk by a window in a warm, low-lit office, signing a printed page with further papers and a stoneware cup beside them.
Three instruments, and all three ask the carrier
EU AI Act Annex III NY DFS 2024-5 Colorado SB 21-169 Proxy testing

Our promise

“Three regimes. One examination. One gap register.”

Every finding is tagged with the instrument it answers — and written so it can go to a regulator as it stands. The fee starts at $5,000, and nothing is charged until you approve it.

Request this insurance AI audit
The case file

Insurance AI, in three chapters

The Stack

Three instruments reach the same rating model. The EU AI Act names insurance underwriting and pricing as high-risk access to essential services. New York DFS asks what the insurer assessed. Colorado asks what the insurer tested. Two of the three are asking it today; the third has a date on it.

The Gap

The rating engine was bought, the external data was bought, and the fraud score arrives finished. Each came with an assurance that compliance is handled - and every one of the three instruments addresses its question to the carrier whose filing it is, not to the vendor who sold it.

The Office

We are the independent reviewer all three have in mind. iDharma tests every rating feature for proxy effect, weighs each external source on its own terms, and reports claims and fraud outcomes by group - once, against all three, in a single gap register any one of them can be handed.

What we audit

AI systems in scope for insurance

Every model that decides who is covered, and at what price.

The models in scope № 01
  • Underwriting and risk-classification AI
  • Pricing and rating algorithms
  • Claims approval, denial and settlement AI
  • Fraud-detection and referral models
Insurance AI · iDharma · Presented for assay
When the duty bites № 02
  • Now - DFS and Colorado already ask what you tested
  • Before every rate filing the model stands behind
  • Whenever the model is re-fitted or the data refreshed
  • From 2 December 2027 for the Annex III high-risk limb
Insurance AI · iDharma · Presented for assay
Whose duty is it

The model is theirs. The filing is yours.

You

The carrier

Every one of the three attaches to the insurer. NY DFS asks what the insurer assessed, Colorado asks what the insurer tested, and the EU AI Act binds you as deployer. The filing has your name on it, and so does the decision the model produced. Neither can be signed by a supplier.

Your vendor

The people who built the model

Carries duties under the EU AI Act where it is the provider, and effectively none under the two US instruments. A rating engine, an external data feed and a fraud score all arrive with assurances. Those assurances are contractual, and a contract is not a regulator. The regulator asks you instead.

The catch

Their compliance is not your defence

"The vendor handles compliance" has not succeeded as a defence in any enforcement action that we have reviewed. The question asked is what YOU assessed and what YOU tested - and an answer that only names a supplier is an answer that has not been given at all. That testing has to be your own.

What most carriers assume

“The vendor handles compliance, so we’re covered.”

What the question is

Not what they handled. What you tested.

It has not worked as a defence in any action we have reviewed.

  • Who it is for
  • Personal lines carriers
  • Commercial & specialty
  • Insurtech & MGAs
  • Actuarial & pricing
  • Claims & SIU
Why this sector stands out

Insurance at a glance

A pair of hands at a desk under a single low lamp, one holding a fountain pen over a printed rate table with bar charts and a grid of factors, read closely and late.
01 Two of the three are already in force. New York DFS and Colorado both ask what the insurer tested - and neither question is answered by naming a supplier.
02

Annex III names insurance underwriting and pricing as access to essential services. Obligations apply from 2 December 2027.

03

No headline insurance-AI fine has been issued yet. The early-mover advantage is real, and it is the thing with an expiry date.

04

A proxy finding takes a rating cycle to fix. Found under supervision, that cycle is no longer yours to schedule.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. A starting point, not a determination.

0 of 3

A model decides -

A bought score still counts. A rating engine, an external data feed and a fraud score are all models deciding something, whoever built them and whatever they are called on the invoice.

Proxy tested -

This is the Colorado question. Not whether a feature is actuarially justified - whether you know how much of a protected characteristic it carries, and whether something comparably predictive carries less.

External data assessed -

This is the DFS question. It asks about the sources, not only the model on top of them - including the ones that arrive as a finished score you cannot see inside.

The calendar

Four moments, and the first one is now.

Only the third is a future date. The first is a question two regulators already ask — and none of the four can be added to another.

  1. Test

    Already

    NY DFS and Colorado ask today what you assessed and tested. That limb is not waiting for anything.

  2. File

    Before every filing

    A rate filing is a statement about how the price was arrived at. The model behind it is part of the answer.

  3. Comply

    2 December 2027

    Annex III high-risk obligations apply from that date. The conformity package behind them is a year of work.

  4. Re-test

    On every re-fit

    A refreshed model is a new model. New data, new weights, new proxies - and the last test described the old one.

The trap

Carriers plan backwards from December 2027 and treat the state limb as the same project on a longer runway. It is not: DFS and Colorado ask the question today, and a proxy finding takes a rating cycle to fix. Found on your own schedule that is a re-fit. Found under supervision it is a re-fit with a deadline somebody else set.

Requirement & coverage

What the three ask, what we ship

12 obligations across three instruments, and the artefact that discharges each one. Each row names which is speaking — and two of the three are speaking already.

Which regimes reach you Lines written, states filed, EU market presence
A written determination of which of the three bind which model, so nothing is tested twice and nothing is missed.
Reliance on your vendor Contractual assurance is not a regulatory answer
An assessment of what a supplier's assurance covers for you and what you must be able to evidence yourself.
Proxy discrimination Colorado SB 21-169; NY DFS 2024-5 - in force now
Every rating feature tested for how much of a protected characteristic it carries, ranked by contribution.
External consumer data NY DFS - the data sources, not only the model
Each external and behavioural source assessed on its own, including the ones bought in as a finished score.
Geodemographic proxies Territory is the oldest proxy in the book
Territory, postcode and neighbourhood features tested against protected characteristics rather than assumed neutral.
Claims-decision disparity A denial rate is an outcome like any other
Approval, denial and settlement outcomes by protected class, for automated and human-reviewed decisions alike.
Fraud-model false positives A referral is a harm before it is a finding
False-positive rates by demographic group - a higher rate for one group is a liability, not a model-quality note.
High-risk classification EU AI Act Annex III - access to essential services
Each system classified against Annex III with the reasoning stated, including the ones we conclude are out.
Conformity assessment EU AI Act - before the system is placed in service
The assessment run and evidenced, with the gaps that would stop it named before you are committed to a date.
Human oversight EU AI Act - effective, not nominal
Referral and override paths tested as underwriters and adjusters actually use them, with the rates measured.
Technical documentation EU AI Act Annex IV; state filing support
One package built to carry both, rather than a technical file and a filing exhibit saying the same thing twice.
Ongoing monitoring Drift moves the proxy as well as the price
The monitoring you have, the monitoring each regime expects, and the thresholds that should trigger a re-test.
Our methodology

How an iDharma audit works

One pass over the model. Three regimes answered.

  1. Request and scope

    Which models, which lines, which states. Priced and approved before anything is charged.

  2. Test once, map three ways

    One pass over the rating and claims models, scored against the EU AI Act, NY DFS and Colorado together. One to four weeks.

  3. Sign off and report

    You see the draft first. Then the conformity package and one gap register - ranked, dated and signed.

Request an insurance AI audit
An auditor in a rust-brown trouser suit and cream blouse, standing against a warm pale wall and pointing into the open space alongside.
We do not accept vendor documentation as evidence. That is what you are buying.
Struck in your favour

Why carriers choose iDharma to review their models

Genuinely independent

We build, resell and rate no insurance models, and we take no fee tied to what the audit finds.

Three regimes, one pass

One examination of the model, scored against all three - not three workstreams meeting at the end.

Proxy analysis by default

External and behavioural data is tested for proxy effect in the base scope, not sold on as an extra.

Filing-ready output

Written so it can go to a regulator as it stands, rather than be translated by somebody first.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

Insurance AI audit report

The full review: scope, method, every model examined, and the findings written so an examiner, an actuary and your board can each read the part they need - each finding tagged with the instrument it answers, every rating feature scored for proxy effect, and claims and fraud outcomes reported by protected class.

Signed by a named independent reviewer with no role in building, selling or rating the models, and no fee tied to the finding. One pass over the estate, scored against all three regimes rather than three times over.

Analysis

Proxy analysis

Every rating feature ranked by how much of a protected characteristic it carries, with the ones worth removing or replacing called out.

Workbook

Outcome tables

Approval, pricing, denial and referral rates by protected class in a workbook, so your own actuaries can reproduce every figure cell by cell.

Memo

External-data assessment

Each third-party and behavioural source assessed on its own terms, including the ones that arrive as a finished score you cannot see inside.

Package

Conformity package

The EU AI Act Annex III and Annex IV material assembled and evidenced, structured so a filing exhibit can be cut from the same source.

Ranked

Gap register

Every gap in one list, ordered by exposure across all three regimes at once - so the first thing you fix is the costliest, not the easiest.

Memo

Vendor-assurance assessment

What your supplier's compliance assurance actually covers for you, what it does not, and precisely which tests you must be able to show yourself.

Format & fee

Real numbers, upfront.

Scope
Agreed with you, then fixed
Data
Your own policy and claims records
Re-review
On every model re-fit - $3,000 against your known baseline

Three regimes over an estate only you can size, so the fee is quoted rather than listed - and nothing is charged until you have approved it.

Request an insurance AI audit
Insurance AI · Scoped engagement $5,000 from
  • EU AI Act, NY DFS and Colorado in one pass
  • Proxy testing on every rating feature
  • Claims and fraud outcomes by protected class
  • One gap register, ranked by exposure
Show your hand

Four things you have to be able to produce

None of the three is graded on intent. Each of these is either in your hand on the day an examiner asks, or it is not.

The test,
on your rates

Every rating feature scored for how much of a protected characteristic it carries. Colorado asks what you tested; a description of your intent is not an answer to that question.

The data,
assessed

Each external and behavioural source assessed on its own terms, including the ones bought in as a finished score. DFS asks about the sources, not just the model above.

The outcomes,
by group

Approval, pricing, denial and referral rates by protected class. A fraud model with a higher false-positive rate for one group is a harm before it is called one.

The override,
exercised

Evidence that the underwriter or adjuster holding the referral can actually change the outcome, measured on real decisions rather than read off an authority grid.

Four cards, and the model version on each one is part of the card.

FAQ

Plain answers

Scope, timing, what we test, the engagement. Answered straight.

Request this audit
Our vendor says they handle compliance. Are we covered?

Not in any enforcement action we have reviewed. NY DFS asks what the insurer assessed and Colorado asks what the insurer tested - and an answer naming a supplier is not an answer to either.

Which of these three actually reach us?

It turns on the lines you write, the states you file in and whether you touch the EU market. Most carriers we scope find at least one applies and at least one does not - which is why the first deliverable is a written determination.

No insurance AI fine has been issued. Why now?

Because two of the three already ask the question - DFS and Colorado are in force today - and the third has a fixed date. The window is what is open, not the obligation.

What exactly do you test?

Every rating feature for proxy effect, external and behavioural data sources on their own terms, claims and fraud outcomes by protected class, referral and override in practice, and the Annex III classification and conformity evidence.

How long does it take, and what does it cost?

One to four weeks for most engagements. Scope and price are agreed and approved before any work begins, and nothing is charged until you approve what the engagement covers.

Get started

Using AI in underwriting, pricing or claims?

Tell us what decides, and we come back with a scope and a price within one business day.

What we need from you

Nothing you do not already have. Most of this is your model inventory and one extract of policy and claims records, and we name the documents in writing first.

  1. Which models decide, and for which lines
  2. Which states you file in, and whether the EU is touched
  3. Policy and claims records for the period, with outcomes
  4. Any proxy testing already done, and by whom
  5. Your target date for a read, if you have one

What happens next

  1. You send the five items we need.
  2. We call to scope it within one business day.
  3. Nothing is charged until you approve the scope.
Request an insurance AI audit
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • Regulation (EU) 2024/1689 - the AI Act
  • NY DFS CL 2024-5; Colorado SB 21-169
State limb
In force today
Last read
9 September 2026

What it means

  • General information about what these three instruments require — not legal advice, and no professional relationship arises from reading it. It determines nothing about your own models or filings.
  • Where a proxy finding is genuinely arguable, or the three pull in different directions, our reports say so rather than pick the convenient reading.

Scope & limitation

  • Do not rest a binding decision on it; engage qualified counsel.
  • Use it as a starting point for a scoping conversation, not as your final word.
  • State insurance regulation moves quickly and varies by line and by state. We verify current scope at the point of engagement rather than relying on a date printed on a page — including this one.

Something on this page out of date?

Tell us