Financial Services Compliance
NY DFS AI Guidance: Model Risk and Third-Party Requirements
New York's Department of Financial Services has not issued a standalone AI regulation. Instead, two 2024 circular letters extend existing cybersecurity and insurance oversight rules to AI systems and the vendors that supply them.
What NY DFS Actually Issued
New York's Department of Financial Services (DFS) has not issued a standalone regulation governing artificial intelligence. Rather than build a new framework, DFS extended two existing supervisory instruments to cover AI: an October 2024 Circular Letter that applies established cybersecurity requirements to AI systems, and a separate 2024 Insurance Circular Letter addressing AI use in underwriting and pricing.
Both letters build on 23 NYCRR Part 500, the cybersecurity regulation already in force for DFS-regulated entities. The October 2024 letter does not create new legal obligations on its own; it clarifies that Part 500's existing risk assessment, third-party service provider policy, access control, and audit trail requirements apply when AI systems and AI vendor supply chains are in scope.
The table below summarizes how the two letters relate to the underlying regulation, and how far the mapping to federal model risk guidance actually goes.
| Reference | What it covers |
|---|---|
| October 2024 Circular Letter | Applies 23 NYCRR Part 500 cybersecurity obligations to AI systems and vendor supply chains |
| Insurance Circular Letter | Requires governance, bias testing, and documentation for AI and external consumer data use in underwriting |
| 23 NYCRR Part 500 | Existing cybersecurity regulation both letters build on, covering risk assessment, access control, and audit trail |
| SR 11-7 mapping | Interpretive only; DFS text does not adopt SR 11-7 terminology or its validation taxonomy |
Model Risk Management Expectations
For entities already operating a model risk management program, the October 2024 Circular Letter's expectations map onto familiar categories rather than introducing new ones. DFS expects a documented AI/ML system inventory, including vendor-sourced tools, that can be tied back to the applicable circular letter. It expects an audit trail capturing model version, input data lineage, and decision outputs that can be retrieved on examiner request. And it expects access controls and multifactor authentication applied to systems hosting AI models, including administrative and retraining interfaces, not just production endpoints.
For insurers specifically, the Insurance Circular Letter goes further, requiring a written AI governance policy that references validation, testing, and periodic review procedures, along with documented pre-deployment and ongoing testing for unfair discrimination in underwriting or pricing AI.
Third-Party AI Vendor Oversight
AI systems rarely run entirely on infrastructure an institution owns and operates itself. The October 2024 Circular Letter treats this as a natural extension of Part 500's third-party service provider requirements: the existing vendor risk assessment obligation now has to explicitly cover AI vendors and subcontracted data or model sources, not just traditional IT service providers.
In practice, this means vendor due diligence questionnaires, contract language, and ongoing monitoring processes built for general technology vendors need to be extended to cover model providers, data labeling vendors, and any subcontractor that touches model training or inference. The audit trail requirement applies here too: institutions need to be able to demonstrate which vendor tool produced which output, at what model version, for examiner review.
Where the Guidance Stops Short
The DFS text is interpretive rather than prescriptive on model validation. It does not adopt the terminology or validation taxonomy associated with the Federal Reserve's SR 11-7 guidance, so institutions mapping DFS expectations onto an SR 11-7-based model risk framework are doing so by analogy, not because DFS has endorsed that mapping.
Practical note
The bias testing and governance documentation requirements in the Insurance Circular Letter are scoped to insurers using AI and external consumer data in underwriting and pricing. DFS has not extended an equivalent, explicitly codified testing requirement to AI use outside that context. Treat the two circular letters as a floor built on existing Part 500 obligations, not a complete AI governance standard, and expect the framework to keep evolving.
Controls Examiners Look For
Regardless of institution type, examiners reviewing AI-related activity under these circular letters tend to focus on evidence, not intent. The following controls are the ones most consistently requested during review.
- Documented AI/ML system inventory, including vendor-sourced tools, mapped to the applicable circular letter
- Third-party service provider risk assessment explicitly covering AI vendors and subcontracted data or model sources
- Audit trail capturing model version, input data lineage, and decision outputs, retrievable on examiner request
- Access control and multifactor authentication applied to systems hosting AI models, including administrative and retraining interfaces
- Documented pre-deployment and ongoing testing for unfair discrimination in underwriting or pricing AI, for insurers
- Written AI governance policy referencing validation, testing, and periodic review procedures
Operationalizing DFS AI Obligations Requires Runtime Visibility
Meeting DFS documentation and audit trail expectations for AI systems depends on being able to evidence model version, access, and vendor tool activity at runtime, not just at policy sign-off.
Explore Runtime Governance