Independent Research & Regulatory Compliance Monitor
Statutory Benchmarks: NY Ins. Law §§ 2601, 4224 · NY DFS Circular Letter No. 7 (2024)

Regulatory Blueprint · State Insurance Department Guidance

NY DFS Circular Letter No. 7 Compliance Blueprint: Insurer AI Governance, Unfair Bias Testing & Third-Party Vendor Liability

An exhaustive legal analysis of New York State’s landmark directive on artificial intelligence systems, establishing mandatory testing protocols, board oversight duties, and strict vendor indemnification.

Regulatory Mandate Summary

On July 11, 2024, the New York State Department of Financial Services (DFS), led by Superintendent Adrienne A. Harris, issued Circular Letter No. 7 (2024). This document represents the most comprehensive state insurance regulatory standard in the country, explicitly requiring insurers to implement formal governance programs, independently audit algorithms for proxy discrimination, and conduct rigorous verification before deploying third-party commercial AI tools.

The Core Statutory Pillars of Circular Letter No. 7

The DFS directive is grounded in long-standing statutory prohibitions under New York Insurance Law:

  • Unfair Discrimination (NY Ins. Law §§ 2606, 4224): Prohibits making or permitting any unfair discrimination between individuals of the same class and of essentially the same hazard.
  • Unfair Claims Settlement Practices (NY Ins. Law § 2601): Bars insurers from committing or performing with such frequency as to indicate a general business practice any unfair claim settlement practice, including misrepresenting facts or failing to adopt reasonable standards for prompt investigation.

Circular Letter No. 7 clarifies how these statutory duties apply to modern algorithmic architectures, specifically targeting two components: Artificial Intelligence Systems (AIS) and External Consumer Data and Information Sources (ECDIS).

Proxy Discrimination: Beyond Simple Protected Attribute Exclusion

The DFS explicitly rejects the common defense that an AI model is non-discriminatory simply because protected demographic attributes (e.g., race, national origin, religion) were omitted from model training.

Instead, the Circular Letter defines proxy discrimination as the use of an algorithm or data source that is not transparently justified by valid actuarial principles and results in a disproportionate adverse effect on protected classes. Insurers must proactively test whether non-traditional data variables—such as consumer shopping behavior, credit proxy scores, social media metrics, or telematics device metadata—serve as statistical proxies for protected groups.

Compliance Domain NY DFS Requirement Standard Insurtech Vendor Practice Market Conduct Audit Gap
Board Governance Direct oversight by Board of Directors or dedicated committee Delegated to IT or data science teams without board review NON-COMPLIANT
Third-Party Model Audits Mandatory independent pre-deployment bias audits Acceptance of vendor marketing whitepapers without code access NON-COMPLIANT
Proxy Testing Disparate impact testing across demographic intersections No external demographic validation data utilized ELEVATED RISK
Adverse Action Notices Specific, granular rationale provided to consumers Generic explanation citing proprietary scoring algorithm NON-COMPLIANT

Third-Party Insurtech Vendor Liability: The End of “Proprietary Black-Box” Excuses

In Section IV of Circular Letter No. 7, the DFS issues an unmistakable warning to carrier general counsels regarding third-party vendors:

“An insurer may not rely on a vendor’s claim of non-discrimination or proprietary software as a substitute for the insurer’s own independent validation and governance. The insurer remains solely responsible for compliance with all New York Insurance Laws and regulations.”

This mandate dismantles the standard vendor contract architecture wherein insurtech vendors refuse to share model weights or training distributions under trade secret protections. Under NY DFS rules, if an insurer cannot obtain full auditability and verification data from an AI vendor, the carrier is legally prohibited from deploying the software in New York.

The Five-Step Carrier AI Governance Blueprint

To avoid severe regulatory sanctions, license revocations, or state attorney general civil rights investigations, carriers writing policies in New York must execute the following protocol:

  1. Inventory All Deployed AI Models: Establish an enterprise-wide model catalog tracking every internal and vendor-provided model in underwriting, pricing, and claims.
  2. Contractual Audit Rights: Amend vendor agreements to mandate audit rights, continuous bias monitoring, and full indemnification for statutory compliance violations.
  3. Implement Documented Adverse Action Notices: Provide consumers with precise, actionable explanations detailing exactly what factual data points influenced adverse claims or underwriting determinations.
  4. Annual Senior Executive Certification: Require the Chief Compliance Officer and Chief Risk Officer to formally certify that all active AI systems have completed annual disparate impact testing.

Frequently Asked Questions on NY DFS AI Regulation

What does NY DFS Circular Letter No. 7 require regarding AI in claims?

It requires insurers to maintain formal board-approved governance frameworks, test claims algorithms for proxy discrimination and unfair bias, independently audit third-party vendor software, and provide specific reasons to consumers when adverse decisions are made.

Can an insurance company blame its AI vendor for discriminatory outcomes?

No. New York DFS rules explicitly state that insurers bear full, non-delegable legal liability for all automated tools and third-party models they deploy. A vendor's proprietary secrecy claim is not a legal defense.

How does New York's regulation compare to Colorado SB 21-169?

Both frameworks aggressively target algorithmic discrimination. While Colorado's SB 21-169 focuses heavily on life insurance and testing methodologies, New York Circular Letter No. 7 applies comprehensively across all lines of insurance, including property, casualty, auto, life, and commercial lines.