Colorado's Algorithm Testing Rule for Insurers
10 min read · updated August 11, 2026
Most algorithmic-fairness rules tell a firm to test and leave the method open. Colorado’s insurance regulator did the opposite: it named a statistical technique, prescribed how to apply it, and requires the results to be reported. That makes it the most concrete algorithmic testing mandate in American law, and the most awkward, because it requires insurers to estimate the very characteristic they are forbidden to collect.
SB 21-169, the statute behind the rules
Senate Bill 21-169, “Protecting Consumers from Unfair Discrimination in Insurance Practices”, was enacted in Colorado in 2021 and is codified at C.R.S. § 10-3-1104.9. Its structure is worth understanding because it is unusual for an American anti-discrimination provision.
The statute reaches an insurer’s use of external consumer data and information sources — ECDIS — together with algorithms and predictive models that use them, across every line of insurance the Division regulates. It prohibits use that results in unfair discrimination on the basis of race, colour, national or ethnic origin, religion, sex, sexual orientation, disability, gender identity or gender expression. It then requires insurers to establish a risk management framework and to test for that outcome, and it directs the Commissioner of Insurance to adopt rules line by line, with stakeholder engagement.
Two features distinguish it from Title VII-style disparate impact. It is outcome-based rather than practice-based: there is no requirement to isolate a particular practice, because the statute asks whether the use of ECDIS results in unfair discrimination. And it puts an affirmative testing duty on the regulated firm rather than leaving detection to a complainant. An insurer that has never tested is not in a neutral position under this statute; it is out of compliance with the duty itself.
The governance regulation came first
The Division split implementation into two kinds of rule, and the order tells you how it thinks. Regulation 10-1-1, adopted in 2023, sets governance and risk-management framework requirements for life insurers’ use of ECDIS, algorithms and predictive models. It is qualitative: board and senior management accountability, a written framework, an inventory of ECDIS and models in use, documented policies, a designated responsible person, remediation processes, and an annual report to the Division attesting to the framework and describing changes.
If that sounds like the NAIC model bulletin, it is close kin — and unlike the bulletin, it is a regulation adopted through rulemaking, published in the Colorado Code of Regulations at 3 CCR 702-10, with the force that carries. The reporting is not on request during an examination; it is periodic and affirmative.
The second layer is the quantitative testing regulation, adopted for life insurance underwriting after 10-1-1. That is the one that names a method.
Estimating race in order to test for it
Insurers do not collect applicants’ race. In most contexts they are discouraged or prohibited from doing so. A statute that requires testing for racially disparate outcomes therefore has a data problem before it has a statistical one, and Colorado resolved it by requiring insurers to estimate.
The prescribed technique is Bayesian Improved First Name Surname Geocoding, or BIFSG. It is a published method that combines three sources of publicly available information:
- Surname. The US Census Bureau publishes a file of surnames occurring at least 100 times with the racial and ethnic distribution of people bearing each. This gives a prior for race given surname.
- First name. Published first-name distributions add a second signal, which matters most where surnames are weakly informative.
- Geography. The racial composition of the census block group or tract for the applicant’s address gives a location prior.
Bayes’ rule combines them into a probability vector across racial and ethnic categories for each individual. The insurer then computes outcome statistics — approval, rating, pricing — weighted by those probabilities rather than by a known label, and reports the disparities to the Division along with the modelling used.
The predecessor method, BISG, uses surname and geography only; BIFSG adds the first name and improves discrimination particularly for Black individuals, whose surname distributions overlap heavily with white surname distributions in the United States for historical reasons. Both methods are in wide use by federal regulators for fair-lending analysis, which is part of why Colorado could specify one: it is not a novel technique, it is an imported one.
What the imputation cannot tell you
This is the section to read before building the pipeline, because the method’s error structure is not uniform and treating a probability as a label produces wrong answers in a predictable direction.
- It is a probability, not a classification. Rounding each individual to their most likely category before aggregating introduces bias; the weighted-aggregate calculation is the correct one and is what the regulation contemplates. An engineer who “simplifies” by taking the argmax has changed the answer.
- Accuracy varies by group. The method is substantially better at identifying Hispanic and Asian individuals, where surnames are highly informative, than at separating Black from white individuals. A finding of no disparity is therefore weaker evidence than a finding of disparity.
- Geography carries the correlation you are testing for. Residential segregation is what makes the geographic prior informative. That same segregation means a model using any geographic feature will correlate with the imputed race by construction, and disentangling “the model uses geography because geography predicts mortality” from “the model uses geography as a proxy for race” is not something the testing statistic answers.
- It says nothing about causation or justification. The test detects a disparity. Whether that disparity is unfairly discriminatory under § 10-3-1104.9 is a legal determination the statistic feeds into, not one it makes.
There is also a genuine and unresolved policy objection, which honest treatment requires stating: constructing a per-applicant racial probability estimate creates a dataset that did not exist before, and the privacy and downstream-use questions about it are not settled. Industry commenters raised it during rulemaking; the Division’s position is that testing is impossible without it. Both things are true, and no court has resolved the tension.
Not the Colorado AI Act
Colorado has two separate algorithmic regimes and they are constantly confused. This one is insurance-specific, administered by the Division of Insurance under SB 21-169, in force, sector-limited, and quantitative. The other is the Colorado AI Act (SB 24-205), a general-purpose statute imposing duties of reasonable care on developers and deployers of high-risk AI systems across many sectors, whose effective date has been moved by later legislation — see the page tracking that date.
An insurer writing life business in Colorado can be subject to both, and they do not ask the same question. The insurance regime asks whether outcomes differ across estimated racial groups and requires the arithmetic. The AI Act asks whether the deployer exercised reasonable care to protect consumers from algorithmic discrimination and requires an impact assessment. A completed BIFSG testing report is evidence toward the second duty; it does not discharge it, because the two instruments define discrimination differently and cover different decisions.