Compliance Alerts

Colorado Amends 3 CCR 702-10

Written by AAIS | Oct 28, 2025

Colorado has amended 3 CCR 702-10, which, among other provisions, establishes governance and risk management requirements for private passenger automobile insurers that use external consumer data and information sources (ECDIS).

 

The regulation requires insurers that use ECDIS, as well as algorithms and predictive models that use ECDIS, in any insurance practice, to establish a risk-based governance and risk management framework to determine whether their use potentially results in unfair discrimination, if detected through quantitative testing requirements established by the Colorado Division of Insurance (DOI). The regulation lists components that must be included in the governance and risk management framework.

 

Additionally, private passenger automobile insurers that are using ECDIS, algorithms, and/or predictive models that use ECDIS must submit a narrative report to the DOI summarizing the progress made toward creating a governance and risk management framework by December 1, 2025. These insurers must also submit a report summarizing compliance with the requirements on July 1, 2026, and annually thereafter.

 

Please see 3 CCR 702-10 for more information.