Insurance
Colorado asks for an audit trail. Not a policy document.
SB 24-169 and the NAIC Model Bulletin both require a governance program you can evidence, not describe. When an AI agent touches underwriting, claims, or rating, the regulator’s question is what it did and under whose authority — and the answer has to come from something that is not the agent.
Three regulators, one requirement.
Each one landed separately and asks for the same underlying thing: a record of what an automated system decided, produced by something that can be examined independently of the system that decided it.
§10-3-1104.9(4) requires a risk management framework for external consumer data and predictive models. §10-3-1104.9(5) requires the audit trail that proves it operated.
§III.A requires an AI governance program, §III.B bias testing and audit, §III.C consumer disclosure. Adopted state by state, examined by your DOI.
Illinois requires demonstrable human oversight of AI-influenced decisions, and recordkeeping sufficient to reconstruct them.
None of them is satisfied by a monitoring dashboard. Each asks for evidence that survives being handed to someone who does not trust the vendor that produced it.
Mapped to the bulletins your DOI examines against.
Coverage stated honestly. Full where shipped capability satisfies the control. Partial where Behavry supplies the evidence layer but the obligation reaches into actuarial and disclosure work no platform discharges for you.
| Regime | Section | Control | Coverage |
|---|---|---|---|
| NAIC Model Bulletin | §III.A | AI Governance Program | Full |
| NAIC Model Bulletin | §III.B | Bias Testing & Audit | Partial |
| NAIC Model Bulletin | §III.C | Consumer Disclosure | Partial |
| Colorado SB 24-169 | §10-3-1104.9(4) | Risk Management Framework | Full |
| Colorado SB 24-169 | §10-3-1104.9(5) | Audit Trail | Full |
| IDFPR | Bulletin 2024-01 | Human Oversight | Full |
| IDFPR | Bulletin 2024-01 | Recordkeeping | Full |
What “mapped” means. Our shipped controls satisfy the named clauses today. It does not mean an independent auditor has certified them. Current status on the Trust Center. Full framework-to-control mapping with PDF export in the dashboard.
Oversight that leaves a record, not a checkbox.
“A human reviews AI decisions” is a claim. An escalation queue with an identified reviewer, a timestamp, and a signed outcome is evidence.
Every decision resolves three ways: allow, deny, or intercept. Intercept holds the action and routes it to a named human before anything executes — not after.
Human session governance binds the reviewing person to the decision. The record names who approved, not which service account.
High-risk actions are bounded before they run. The control is a constraint on what an agent can reach, not an alert after it reached it.
Behavioral baselining surfaces distributional change in what an agent is doing over time — an input to bias review, not a substitute for actuarial testing.
An audit trail your DOI can check without us.
Colorado asks for an audit trail. The useful question is who has to be trusted for it to mean anything.
Every event is Ed25519-signed and SHA-256 hash-chained to the one before it. Export bundles carry a Merkle root over the full timeline.
The per-tenant trust anchor is frozen at enrollment. An examiner verifies an evidence package with no Behavry service in the loop, no credentials, and no cooperation from us.
The record is produced by a control plane the agent cannot inspect or modify. The entity that acts is not the entity that attests.
SIEM export to Splunk, Sentinel, Chronicle, QRadar or syslog gives you a durable record outside Behavry’s control.
Bring the decision your examiner would ask about.
We will walk your agent surfaces, show where the record gets produced, and hand you a signed Decision Trace you can verify yourself.
Related: compliance · decision trace · trust center · financial services