See how Trussed maps to your regulation in minutes

    No generic demo, just the controls relevant to your program.

    Book a session
    Insurance Compliance

    Colorado Regulation 10-1-1 Compliance Guide for Life Insurers

    A practitioner-level breakdown of quantitative testing, ECDIS governance, and attestation obligations under Colorado Division of Insurance Regulation 10-1-1 and SB21-169.

    Colorado Regulation 10-1-1 requires life insurers that use external consumer data, algorithms, or predictive models in underwriting to build a governance and risk management framework, run quantitative testing for unfair discrimination, and submit periodic attestations to the Division of Insurance documenting testing methodology, results, and governance controls.

    Regulation 10-1-1 at a Glance

    Legal Basis

    Adopted by the Colorado Division of Insurance under SB21-169 (2021).

    Core Obligation

    Establish a risk management framework and quantitatively test underwriting models for unfair discrimination.

    Reporting

    Periodic attestations to the Commissioner on governance and testing results, phased by premium volume.

    What Regulation 10-1-1 Requires

    Regulation 10-1-1 (3 CCR 702-10) was adopted by the Colorado Division of Insurance to implement SB21-169, which prohibits insurers from using external consumer data, algorithms, or predictive models in a way that unfairly discriminates on the basis of protected characteristics such as race, color, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity, or gender expression. The regulation translates that statutory prohibition into an operational requirement: life insurers must establish a governance and risk management framework (RMF) covering their use of external consumer data and information sources (ECDIS), algorithms, and predictive models in underwriting.

    The RMF is not a one-time filing. It is expected to function as an ongoing control structure, meaning testing, documentation, and oversight need to persist as models and data sources change, not just at initial rollout.

    Data and Systems in Scope

    The regulation’s scope covers ECDIS, algorithms, and predictive models used specifically in underwriting and related rating decisions for life insurance. ECDIS includes external data sources brought into underwriting workflows that are not directly collected from the applicant. This scope extends beyond the outputs of a model to the inputs themselves, which means insurers need to trace data lineage from the original source, through any scoring or predictive model, to the final underwriting decision.

    Vendor-developed and third-party predictive models used in underwriting also fall within scope. Insurers cannot treat a purchased or licensed model as outside the RMF simply because it was not built internally. Sufficient documentation must be obtained from vendors to support the insurer’s own testing and attestation obligations, since the regulatory responsibility sits with the insurer regardless of who developed the model.

    Quantitative Testing Process

    Regulation 10-1-1 requires quantitative testing to identify unfair discrimination in underwriting outcomes tied to ECDIS, algorithms, and predictive models. Because insurers generally do not collect applicants’ race directly, initial testing is scoped to race using an accepted imputation methodology. The Division has referenced Bayesian Improved First Name Surname Geocoding (BIFSG) for imputing race and ethnicity to support required testing.

    Testing should be defined in a documented protocol that covers methodology, cadence, decision thresholds, and remediation triggers. As data sources and models change, testing is expected to operate as a periodic control rather than a single point-in-time validation.

    Build documentation so it can extend if testing requirements expand beyond race to additional protected classes covered under SB21-169.

    Documentation, Recordkeeping, and Attestation

    Insurers subject to Regulation 10-1-1 must submit periodic attestations or reports to the Commissioner describing their RMF, governance structure, and testing results. This places a practical burden on compliance teams to translate technical testing output into a reporting format the Division can review, and to retain records sufficient to withstand examination of testing methodology, data sources, and any remediation actions taken.

    Governance accountability should be defined at the senior management or board level, not limited to the technical teams running the tests, since the RMF is a governance obligation as much as a technical one.

    Elements of an Internal Compliance Program

    An effective internal program ties inventory, testing, vendor oversight, and executive accountability into a single operating rhythm.

    • A complete, maintained inventory of ECDIS sources and predictive models used in underwriting
    • A documented testing protocol covering methodology, cadence, thresholds, and remediation triggers
    • A compliance calendar reflecting the insurer’s phased deadline based on Colorado life premium volume
    • Vendor agreements or documentation requirements that support testing and attestation of third-party models
    • A reporting workflow that compiles RMF governance details and testing outcomes into attestation format
    • Defined senior management or board accountability for the risk management framework

    Frequently Asked Questions

    Does Regulation 10-1-1 apply to models built by third-party vendors?

    Yes. Vendor-developed or third-party predictive models used in underwriting fall within scope. Insurers must obtain sufficient documentation from vendors to support their own testing and attestation obligations, since regulatory responsibility remains with the insurer.

    Is the compliance deadline the same for every insurer?

    No. Compliance and initial reporting deadlines are phased based on the insurer’s volume of Colorado life insurance premium, with larger insurers required to comply earlier than smaller carriers.

    Why does testing rely on imputed race rather than collected data?

    Insurers generally do not collect applicants’ race directly. The Division has referenced Bayesian Improved First Name Surname Geocoding (BIFSG) as an accepted methodology for imputing race and ethnicity to support the required testing.

    Is quantitative testing a one-time requirement?

    No. The risk management framework concept implies testing is expected to function as an ongoing, periodic control rather than a single point-in-time validation, since underlying data sources and models change over time.

    Support Ongoing Regulation 10-1-1 Compliance

    Runtime governance, audit logging, and policy enforcement can help compliance teams maintain the ongoing testing and documentation evidence that Regulation 10-1-1’s risk management framework expects.

    Learn About AI Agent Security