Insurance and Financial Services Compliance
AI in Underwriting: Governing Algorithmic Credit and Insurance Decisions Post-Colorado
Algorithmic underwriting governance is the set of technical and operational controls that let an enterprise demonstrate, on an ongoing basis, which model version, inputs, and rules produced a given credit or insurance decision. Colorado's two AI-relevant statutes, SB 21-169 (insurance-specific) and the Colorado AI Act, SB 24-205, impose outcome-based obligations around discrimination, risk management, and disclosure, but neither prescribes the logging, monitoring, or audit architecture needed to meet them. That gap is where governance programs succeed or fail.
Two Distinct Statutes, Frequently Conflated
Enterprises building compliance programs around "the Colorado AI Act" for underwriting often treat it as a single law. It is not. SB 21-169, passed in 2021, is an insurance-specific statute prohibiting insurers from using external consumer data, algorithms, or predictive models that unfairly discriminate based on race or other protected classes. The Colorado Division of Insurance implemented this through Regulation 10-1-1, which requires insurers to establish a risk management framework and testing protocol for algorithms and predictive models, with life insurance as the initial scope.
The Colorado AI Act, SB 24-205, passed in 2024, is a separate and broader consumer-protection statute. It creates a duty of reasonable care for developers and deployers of high-risk AI systems to protect consumers from algorithmic discrimination in consequential decisions, explicitly including lending, financial services, and insurance. A given underwriting model may be subject to one, both, or neither statute depending on the product line and decision type. Governance programs that collapse these two regimes into a single compliance checklist risk misapplying obligations, timelines, and evidentiary requirements.
What Each Statute Actually Requires
SB 21-169's obligations run through Regulation 10-1-1: insurers must maintain a documented risk management framework and testing protocol for algorithms and predictive models, phased in by insurance line. SB 24-205 layers on additional requirements for deployers of high-risk AI systems: a risk management policy and program, periodic impact assessments addressing foreseeable risks of algorithmic discrimination, and consumer notice when AI is used in a consequential decision affecting them.
Neither statute specifies a required logging format, telemetry standard, or audit-trail architecture. Both are written as outcome-based obligations, meaning the enterprise is responsible for demonstrating non-discrimination and risk management, but the technical means of doing so is left to the deployer. SB 24-205's original effective date was set for February 1, 2026, and subsequent Colorado legislative action has delayed implementation, though the exact revised timeline has continued to shift through amendment. Governance programs should track the current status directly rather than anchor to a fixed date.
Why This Is a Runtime Problem, Not Just a Legal One
The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers instructs insurers to be able to document and explain to regulators how AI systems are developed, tested, monitored, and used in decisions affecting consumers. That lifecycle language, developed, tested, monitored, used, implies traceability across the full model lifecycle: training data lineage, validation records, and production monitoring logs, not just a point-in-time fairness test.
This is where many programs fall short. Pre-deployment fairness testing validates a model against known protected-class disparities before it goes into production. It does not capture what happens afterward: model drift, retraining events, vendor model updates, or human overrides of automated recommendations. Both Colorado regimes reference ongoing risk management, not one-time certification, which means the evidentiary burden extends into production.
What to Instrument at the Model and Decision Layer
Building Continuous Compliance Evidence
- Confirm which statute, SB 21-169, SB 24-205, or both, applies to each underwriting use case before designing controls, since scope and evidentiary requirements differ.
- Track the current effective date and amendment status of SB 24-205 directly, given reported delays since its original February 2026 target.
- Obtain contractual and technical documentation from vendors for any third-party underwriting model, sufficient to meet deployer-level accountability under NAIC guidance.
- Distinguish pre-deployment fairness testing artifacts from continuous production monitoring evidence, and be able to produce both on request.
- Coordinate legal and technical teams so consumer disclosure language under SB 24-205 accurately reflects current system behavior, not the behavior at initial launch.
Where Runtime Governance Fits
Trussed AI provides runtime governance and policy enforcement for AI systems in production, including audit logging, agent identity, and permissioning controls that support the kind of decision-level traceability described above. For underwriting workloads, this means the ability to enforce policy at the point of decision execution and maintain an audit record of model version, inputs, and any overrides, rather than relying solely on documentation produced before deployment. This does not substitute for legal analysis of which Colorado statute applies to a given product line, but it addresses the operational gap both statutes leave open: how to produce continuous, defensible evidence of what the system actually did.
Two Colorado Regimes, One Runtime Governance Requirement
| Regulation | What it requires |
|---|---|
| SB 21-169 (2021) | Insurance-specific law prohibiting unfair discrimination from external data, algorithms, and predictive models used by insurers. |
| Regulation 10-1-1 | Colorado Division of Insurance rule requiring a risk management framework and testing protocol, beginning with life insurance. |
| SB 24-205 (2024) | The Colorado AI Act, imposing a duty of reasonable care on developers and deployers of high-risk AI used in credit and insurance decisions. |
| NAIC Model Bulletin | Directs insurers to maintain a governance framework covering accountability, testing, and monitoring of AI and third-party models. |
Move From Point-in-Time Testing to Continuous Governance Evidence
Understand how runtime governance and audit logging support decision-level traceability for underwriting AI systems operating under Colorado's overlapping regulatory regimes.
Explore Runtime Governance