NYDFS Circular Letter No. 7 (2024): AI in Underwriting and Pricing
9 min read · updated August 11, 2026
Circular Letter No. 7 (2024) does not ban anything. It shifts the burden of proof: an insurer using external consumer data or an AI system in underwriting or pricing must be able to show, quantitatively, that it does not produce unfair discrimination — before the Department asks.
The instrument and who it binds
The New York Department of Financial Services issued Circular Letter No. 7 on 11 July 2024, under the title “Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and Pricing”. A proposed version was published for comment on 17 January 2024 and the final text followed the comment period. It is addressed to all insurers authorised to write insurance in New York, licensed fraternal benefit societies, article 43 corporations and health maintenance organisations. Circular letters are the Department’s statement of how it will apply existing law; they are not regulations, but they are the basis on which market conduct examinations proceed. The text is on the DFS circular letters page.
Two defined terms carry the scope. External consumer data and information sources (ECDIS) means data used to supplement or supplant traditional underwriting or pricing factors — the examples given include credit scores, purchasing habits, geographic and social data — excluding data such as an MVR or claims history already used in the ordinary course. AI systems is defined broadly enough to catch machine-learning models applied to internal data as well. Notably the circular applies whether or not the ECDIS itself is processed by AI: either limb brings you in.
The unfair discrimination duty it enforces
The circular does not create the prohibition. It applies existing New York Insurance Law: sections 2303 and 2314 on rates that are unfairly discriminatory, section 4224 on discrimination in life and accident and health insurance, and Article 26’s unfair claims and trade practice provisions, alongside federal and state anti-discrimination law. What the circular adds is the position that an insurer cannot rely on the absence of a protected characteristic from the model’s inputs. A proxy achieves the prohibited result by other means, and the Department states that using ECDIS or an AI system that produces a disparate impact on a protected class is unlawful unless the insurer can establish a legitimate actuarial basis and that no less discriminatory alternative was reasonably available.
That last clause is the demanding one. It is not enough to show the model is predictive; the insurer is expected to have looked for a variant that is comparably predictive and less disparate, and to be able to say what it found. This is the same structure as disparate impact analysis in employment, imported into rate regulation.
The quantitative assessment it expects
The circular asks for a comprehensive assessment that is both qualitative and quantitative, conducted before deployment and repeated at regular intervals. On the quantitative side it expects the insurer to have measured outcomes by protected class, and it refers to recognised statistical approaches — adverse impact ratio, standardised mean differences, marginal effects analysis and drivers of disparity — without mandating one. It also expects the insurer to have confronted the practical problem that it usually does not hold race or ethnicity data, and notes that inference methodologies such as Bayesian Improved First Name Surname Geocoding are used for this purpose, while leaving the choice of method to the insurer along with the obligation to document its limitations.
Deliberately not prescribing a single test is a design decision with a consequence: two insurers can both comply and produce incomparable numbers, and there is at present no safe harbour attached to any particular metric threshold. An insurer that adopts a metric should record why that metric, what threshold it treats as a signal, and what it does when the threshold is crossed — because the file, not the number, is what gets examined.
Governance, board accountability and vendors
The governance section is where the circular is most concrete. It expects a formal governance framework with board and senior management accountability, written policies and procedures covering the full lifecycle from data acquisition to retirement, documented model risk management including validation independent of the developers, and internal audit coverage. The board is expected to have a working understanding sufficient to exercise oversight — a phrasing that echoes the effective challenge idea from banking model risk guidance.
On vendors the position is unambiguous: an insurer remains responsible for the ECDIS and AI systems it uses even when a third party supplies them. The insurer is expected to conduct due diligence on the vendor, to have contractual rights to the information needed to perform its own testing, and to have terms addressing audit and cooperation with regulatory enquiries. “The vendor will not tell us” is not an answer the circular contemplates, which in practice means the right to the data must be negotiated at purchase and not discovered at examination. See the audit clause you need in the contract.
Transparency runs in two directions. Insurers must disclose to consumers that ECDIS or an AI system was used, and where an adverse underwriting decision follows, must provide the specific reason or reasons — in plain language, with enough specificity that the consumer can identify the data that drove it and seek correction.
What the circular does not decide
Three things are open and it is worth saying so. It does not set a numeric threshold at which a disparity becomes unlawful, so whether a given adverse impact ratio is defensible remains a judgement that has not been tested in a New York enforcement proceeding at the time of writing. It does not resolve the tension between inferring protected characteristics to test for bias and the privacy and legal constraints on holding that data — it acknowledges the tension and leaves it with the insurer. And it addresses underwriting and pricing, not claims handling, marketing or fraud detection, which are governed by other provisions and by the Department’s general authority rather than by this circular. Do not read it as a general AI rulebook for insurers; read it as a rate and underwriting instrument that happens to be about models.