Three instruments reach the same rating model. The EU AI Act names insurance underwriting and pricing as high-risk access to essential services. New York DFS asks what the insurer assessed. Colorado asks what the insurer tested. Two of the three are asking it today; the third has a date on it.
AI in underwriting, pricing and claims. Audited once.
Two are in force today, the third has a date, and none accepts a supplier's assurance.
Our promise
“Three regimes. One examination. One gap register.”
Every finding is tagged with the instrument it answers — and written so it can go to a regulator as it stands. The fee starts at $5,000, and nothing is charged until you approve it.
Request this insurance AI auditInsurance AI, in three chapters
The rating engine was bought, the external data was bought, and the fraud score arrives finished. Each came with an assurance that compliance is handled - and every one of the three instruments addresses its question to the carrier whose filing it is, not to the vendor who sold it.
We are the independent reviewer all three have in mind. iDharma tests every rating feature for proxy effect, weighs each external source on its own terms, and reports claims and fraud outcomes by group - once, against all three, in a single gap register any one of them can be handed.
AI systems in scope for insurance
Every model that decides who is covered, and at what price.
- Underwriting and risk-classification AI
- Pricing and rating algorithms
- Claims approval, denial and settlement AI
- Fraud-detection and referral models
- Now - DFS and Colorado already ask what you tested
- Before every rate filing the model stands behind
- Whenever the model is re-fitted or the data refreshed
- From 2 December 2027 for the Annex III high-risk limb
The model is theirs. The filing is yours.
The carrier
Every one of the three attaches to the insurer. NY DFS asks what the insurer assessed, Colorado asks what the insurer tested, and the EU AI Act binds you as deployer. The filing has your name on it, and so does the decision the model produced. Neither can be signed by a supplier.
The people who built the model
Carries duties under the EU AI Act where it is the provider, and effectively none under the two US instruments. A rating engine, an external data feed and a fraud score all arrive with assurances. Those assurances are contractual, and a contract is not a regulator. The regulator asks you instead.
Their compliance is not your defence
"The vendor handles compliance" has not succeeded as a defence in any enforcement action that we have reviewed. The question asked is what YOU assessed and what YOU tested - and an answer that only names a supplier is an answer that has not been given at all. That testing has to be your own.
“The vendor handles compliance, so we’re covered.”
Not what they handled. What you tested.
It has not worked as a defence in any action we have reviewed.
- Who it is for
- Personal lines carriers
- Commercial & specialty
- Insurtech & MGAs
- Actuarial & pricing
- Claims & SIU
Insurance at a glance
Annex III names insurance underwriting and pricing as access to essential services. Obligations apply from 2 December 2027.
No headline insurance-AI fine has been issued yet. The early-mover advantage is real, and it is the thing with an expiry date.
A proxy finding takes a rating cycle to fix. Found under supervision, that cycle is no longer yours to schedule.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a determination.
Your scope check
Four moments, and the first one is now.
Only the third is a future date. The first is a question two regulators already ask — and none of the four can be added to another.
-
Test
AlreadyNY DFS and Colorado ask today what you assessed and tested. That limb is not waiting for anything.
-
File
Before every filingA rate filing is a statement about how the price was arrived at. The model behind it is part of the answer.
-
Comply
2 December 2027Annex III high-risk obligations apply from that date. The conformity package behind them is a year of work.
-
Re-test
On every re-fitA refreshed model is a new model. New data, new weights, new proxies - and the last test described the old one.
Carriers plan backwards from December 2027 and treat the state limb as the same project on a longer runway. It is not: DFS and Colorado ask the question today, and a proxy finding takes a rating cycle to fix. Found on your own schedule that is a re-fit. Found under supervision it is a re-fit with a deadline somebody else set.
What the three ask, what we ship
12 obligations across three instruments, and the artefact that discharges each one. Each row names which is speaking — and two of the three are speaking already.
- Which regimes reach you Lines written, states filed, EU market presence
- A written determination of which of the three bind which model, so nothing is tested twice and nothing is missed.
- Reliance on your vendor Contractual assurance is not a regulatory answer
- An assessment of what a supplier's assurance covers for you and what you must be able to evidence yourself.
- Proxy discrimination Colorado SB 21-169; NY DFS 2024-5 - in force now
- Every rating feature tested for how much of a protected characteristic it carries, ranked by contribution.
- External consumer data NY DFS - the data sources, not only the model
- Each external and behavioural source assessed on its own, including the ones bought in as a finished score.
- Geodemographic proxies Territory is the oldest proxy in the book
- Territory, postcode and neighbourhood features tested against protected characteristics rather than assumed neutral.
- Claims-decision disparity A denial rate is an outcome like any other
- Approval, denial and settlement outcomes by protected class, for automated and human-reviewed decisions alike.
- Fraud-model false positives A referral is a harm before it is a finding
- False-positive rates by demographic group - a higher rate for one group is a liability, not a model-quality note.
- High-risk classification EU AI Act Annex III - access to essential services
- Each system classified against Annex III with the reasoning stated, including the ones we conclude are out.
- Conformity assessment EU AI Act - before the system is placed in service
- The assessment run and evidenced, with the gaps that would stop it named before you are committed to a date.
- Human oversight EU AI Act - effective, not nominal
- Referral and override paths tested as underwriters and adjusters actually use them, with the rates measured.
- Technical documentation EU AI Act Annex IV; state filing support
- One package built to carry both, rather than a technical file and a filing exhibit saying the same thing twice.
- Ongoing monitoring Drift moves the proxy as well as the price
- The monitoring you have, the monitoring each regime expects, and the thresholds that should trigger a re-test.
How an iDharma audit works
One pass over the model. Three regimes answered.
-
Request and scope
Which models, which lines, which states. Priced and approved before anything is charged.
-
Test once, map three ways
One pass over the rating and claims models, scored against the EU AI Act, NY DFS and Colorado together. One to four weeks.
-
Sign off and report
You see the draft first. Then the conformity package and one gap register - ranked, dated and signed.
Why carriers choose iDharma to review their models
Genuinely independent
We build, resell and rate no insurance models, and we take no fee tied to what the audit finds.
Three regimes, one pass
One examination of the model, scored against all three - not three workstreams meeting at the end.
Proxy analysis by default
External and behavioural data is tested for proxy effect in the base scope, not sold on as an extra.
Filing-ready output
Written so it can go to a regulator as it stands, rather than be translated by somebody first.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
Insurance AI audit report
The full review: scope, method, every model examined, and the findings written so an examiner, an actuary and your board can each read the part they need - each finding tagged with the instrument it answers, every rating feature scored for proxy effect, and claims and fraud outcomes reported by protected class.
Signed by a named independent reviewer with no role in building, selling or rating the models, and no fee tied to the finding. One pass over the estate, scored against all three regimes rather than three times over.
Proxy analysis
Every rating feature ranked by how much of a protected characteristic it carries, with the ones worth removing or replacing called out.
Outcome tables
Approval, pricing, denial and referral rates by protected class in a workbook, so your own actuaries can reproduce every figure cell by cell.
External-data assessment
Each third-party and behavioural source assessed on its own terms, including the ones that arrive as a finished score you cannot see inside.
Conformity package
The EU AI Act Annex III and Annex IV material assembled and evidenced, structured so a filing exhibit can be cut from the same source.
Gap register
Every gap in one list, ordered by exposure across all three regimes at once - so the first thing you fix is the costliest, not the easiest.
Vendor-assurance assessment
What your supplier's compliance assurance actually covers for you, what it does not, and precisely which tests you must be able to show yourself.
Real numbers, upfront.
- Scope
- Agreed with you, then fixed
- Data
- Your own policy and claims records
- Re-review
- On every model re-fit - $3,000 against your known baseline
Three regimes over an estate only you can size, so the fee is quoted rather than listed - and nothing is charged until you have approved it.
Request an insurance AI audit- EU AI Act, NY DFS and Colorado in one pass
- Proxy testing on every rating feature
- Claims and fraud outcomes by protected class
- One gap register, ranked by exposure
Four things you have to be able to produce
None of the three is graded on intent. Each of these is either in your hand on the day an examiner asks, or it is not.
The test,
on your rates
Every rating feature scored for how much of a protected characteristic it carries. Colorado asks what you tested; a description of your intent is not an answer to that question.
The data,
assessed
Each external and behavioural source assessed on its own terms, including the ones bought in as a finished score. DFS asks about the sources, not just the model above.
The outcomes,
by group
Approval, pricing, denial and referral rates by protected class. A fraud model with a higher false-positive rate for one group is a harm before it is called one.
The override,
exercised
Evidence that the underwriter or adjuster holding the referral can actually change the outcome, measured on real decisions rather than read off an authority grid.
Four cards, and the model version on each one is part of the card.
Plain answers
Scope, timing, what we test, the engagement. Answered straight.
Request this auditOur vendor says they handle compliance. Are we covered?
Not in any enforcement action we have reviewed. NY DFS asks what the insurer assessed and Colorado asks what the insurer tested - and an answer naming a supplier is not an answer to either.
Which of these three actually reach us?
It turns on the lines you write, the states you file in and whether you touch the EU market. Most carriers we scope find at least one applies and at least one does not - which is why the first deliverable is a written determination.
No insurance AI fine has been issued. Why now?
Because two of the three already ask the question - DFS and Colorado are in force today - and the third has a fixed date. The window is what is open, not the obligation.
What exactly do you test?
Every rating feature for proxy effect, external and behavioural data sources on their own terms, claims and fraud outcomes by protected class, referral and override in practice, and the Annex III classification and conformity evidence.
How long does it take, and what does it cost?
One to four weeks for most engagements. Scope and price are agreed and approved before any work begins, and nothing is charged until you approve what the engagement covers.
Using AI in underwriting, pricing or claims?
Tell us what decides, and we come back with a scope and a price within one business day.
What we need from you
Nothing you do not already have. Most of this is your model inventory and one extract of policy and claims records, and we name the documents in writing first.
- Which models decide, and for which lines
- Which states you file in, and whether the EU is touched
- Policy and claims records for the period, with outcomes
- Any proxy testing already done, and by whom
- Your target date for a read, if you have one
What happens next
- You send the five items we need.
- We call to scope it within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- Regulation (EU) 2024/1689 - the AI Act
- NY DFS CL 2024-5; Colorado SB 21-169
- State limb
- In force today
- Last read
- 9 September 2026
What it means
- General information about what these three instruments require — not legal advice, and no professional relationship arises from reading it. It determines nothing about your own models or filings.
- Where a proxy finding is genuinely arguable, or the three pull in different directions, our reports say so rather than pick the convenient reading.
Scope & limitation
- Do not rest a binding decision on it; engage qualified counsel.
- Use it as a starting point for a scoping conversation, not as your final word.
- State insurance regulation moves quickly and varies by line and by state. We verify current scope at the point of engagement rather than relying on a date printed on a page — including this one.
Something on this page out of date?
Tell usFrom Insights
Related reading
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Auditing AI Underwriting for Fairness: What Gets Measured
Proxy discrimination does not need the protected characteristic as an input. What a defensible test measures, why the fairness definition is a governance choice, and what carriers are asked t