Search
By John Robinson
Colorado’s Department of Regulatory Agencies Division of Insurance (“Division”) becomes one of the first state agencies to establish governance and risk management requirements for life insurers that use external consumer data and information sources (ECDIS), as well as algorithms and predictive models that use ECDIS. The final release of the regulation became effective on November 14, 2023, and drastically increases insurer’s responsibility to ensure there is no discrimination in predictive models. Colorado’s law is the first of its kind and is viewed as a model that other states will likely follow as the industry works to regulate new artificial intelligence technologies.
If an insurer or the technology an insurer deploys uses ECDIS, then they must establish a risk-based governance and management framework that facilitates and supports policies, procedures, systems, and controls designed to determine whether the use of ECDIS, algorithms, and predictive models result in unfair discrimination with respect to race. The law’s governance and risk management requirements include:
Notes:
*Insurers that use a third party to manage customer data utilizing predictive models and algorithms remain responsible for the above requirements.
**All of the requirements listed above must be available on request of the Division.
Colorado has taken a significant step by being the first state to define base-level requirements qualifying life insurers must meet. Regulators have proven that AI regulation is a priority. European regulation like the “A.I. Act,” Senate subcommittee hearings on the “Oversite of A.I.,” and the recent Executive Order on AI Enforcement all show an international trend toward greater regulation. While Colorado is the first state to implement statewide regulation on insurers, Guidehouse believes others will follow. Below are a few immediate steps insurance companies can take to meet regulatory scrutiny.
As firms navigate the implications of the new Colorado regulation, it is beneficial to have a partner who can provide seasoned guidance and support. Guidehouse has a deep understanding of regulated industries and extensive experience in responsible AI.
Guidehouse can support an organization’s efforts to implement regulatory-driven change and maximize the predictive power from automated decision systems while implementing industry standards for data privacy and protection, model monitoring and risk mitigation, and the equitable and responsible use of AI.
Guidehouse is a global consultancy providing advisory, digital, and managed services to the commercial and public sectors. Purpose-built to serve the national security, financial services, healthcare, energy, and infrastructure industries, the firm collaborates with leaders to outwit complexity and achieve transformational changes that meaningfully shape the future.