NYDFS Circular Letter No. 7 and the AI Underwriting Proxy Test
NYDFS Circular Letter No. 7 is New York's AI guidance for insurers: proxy test, three-step assessment and the 15-day notice.
In this article
For Anyone writing New York business who touches underwriting or pricing: actuaries first, then the GC and compliance officers who defend it.
Read if Your underwriting or pricing touches AI or external consumer data in New York, and you need to know what Circular Letter No. 7 actually expects.
On July 11, 2024, the New York State Department of Financial Services (NYDFS) issued Insurance Circular Letter No. 7 (2024), “Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and Pricing.”1 The guidance formally explains how existing New York insurance law applies to ECDIS and AIS in underwriting and pricing decisions in New York. For any insurer authorized to write business in the state, it functions as a compliance roadmap for ECDIS and AIS in insurance underwriting and pricing.
Its reach turns on two definitions: ECDIS and AIS. The proxy test then determines what a carrier must examine before third-party data or an AI model enters underwriting or pricing.
What does NYDFS Circular Letter No. 7 cover?
NYDFS Circular Letter No. 7 applies to all insurers authorized to write insurance in New York State, including P&C, life, and health carriers, HMOs, Article 43 corporations, licensed fraternal benefit societies, and the New York State Insurance Fund.1 It governs the use of artificial intelligence systems (AIS) and external consumer data and information sources (ECDIS) in underwriting and pricing.
What distinguishes it is the form the expectations take. Section II.B writes the discrimination analysis out as a procedure rather than a principle: three numbered steps, a stated point at which the evaluation may end, a return path for each step that fails, and an annual repeat for the one branch that passes.1 Colorado has gone further in binding force, but by regulation rather than guidance, and its adopted rule reaches only life, private passenger auto, and health benefit plan insurers.2 We compare the two regimes in how disparate impact shapes AI pricing. The letter also treats artificial intelligence systems and external consumer data as a single risk vector when they affect underwriting or pricing. Both definitions turn on three uses:
- Used to supplement traditional underwriting or pricing.
- Used as a proxy for traditional underwriting or pricing.
- Used to identify “lifestyle indicators” that may contribute to an underwriting or pricing assessment of an applicant.1
The letter draws its own outer boundary once: it “is not intended to address phases of the insurance product lifecycle other than underwriting and pricing.”1 Claims handling, marketing, and fraud detection sit outside it on that reading, though the letter does not name them. It also does not apply to Child Health Plus, Essential Plan, or Medicaid managed care coverage.1
What are ECDIS and AIS in insurance underwriting and pricing?
ECDIS means external consumer data and information sources: data or information used, in whole or in part, to supplement traditional medical, property or casualty underwriting or pricing, to stand in as a proxy for it, or to identify lifestyle indicators feeding it. Credit-based scores, purchase history, social media activity, location data, and behavioral scores are the usual examples, though the letter names none of them. What it does name is four things ECDIS is not: an MIB Group member information exchange service, a motor vehicle report, prescription drug data, and a criminal history search. That last one carries its own separate rules under Executive Law § 296(16).1 A criminal history search is the input a reader would expect this letter to reach first. Under its definition it sits outside entirely.
AIS means artificial intelligence systems: any machine-based system designed to perform functions normally associated with human intelligence, such as reasoning, learning, and self-improvement, put to those same three uses.1 Importantly, the guidance applies to AIS even when the insurer does not use ECDIS. The Department says so directly, explaining that it kept the original definitions because it intended “to cover AIS utilization and models regardless of whether they leverage ECDIS.”1 If a carrier uses AI in underwriting or pricing, the letter’s core expectations apply.
This ECDIS and AIS framework matters because many carriers assume ECDIS and AIS are linked. They are not. A carrier using a proprietary machine-learning model on traditional data is squarely inside what Circular Letter No. 7 addresses.
In practical terms, and setting aside the four excluded sources above, ECDIS and AIS in insurance underwriting reach the data and the models that influence whether a policy is issued and at what price. Credit-based insurance scores, behavioral telemetry, aerial imagery, and social-media-derived signals all fall under ECDIS. A neural network trained only on traditional application data still counts as AIS. When ECDIS and AIS in insurance underwriting are combined, the compliance burden doubles: the insurer must validate both the external data source and the AI model that consumes it.
Why does New York regulate AI underwriting and pricing separately?
New York has long treated insurance underwriting and pricing as a distinct regulatory domain. Rather than adopting the NAIC Model Bulletin’s principles-based governance approach, NYDFS built Circular Letter No. 7 on existing state anti-discrimination statutes.1 This means AI underwriting New York is not governed by a voluntary framework; it is governed by existing insurance law, enforced through the NYDFS’s market conduct authority.
New York sits on top of the national baseline rather than inside it. A program that meets NAIC guidance may still fall short of Circular Letter No. 7, especially on the proxy test, the consumer-disclosure duties, and vendor audit rights. For the underwriting practices this lands on across all lines, see our AI in underwriting insurance analysis; the health lines carry their own overlay, mapped in AI in health insurance.
What is the proxy test Circular Letter No. 7 requires?
Two exercises sit at the center of the letter, and they are not the same one. The proxy assessment is the narrower of the pair, and it is the one that carries a “must.”
It applies to external data. Insurers “must be able to demonstrate that the ECDIS employed for underwriting and pricing are not prohibited by the Insurance Law or regulations promulgated thereunder.”1 To get into a position to make that demonstration, an insurer should evaluate how far its ECDIS correlate with status in a protected class. The letter’s own gloss on “correlated with” is “i.e., proxy for.” Carriers may calculate the correlation from information already in their possession or reasonably impute it with accepted statistical methods. If correlations turn up, the insurer should consider whether the use of that ECDIS is required by a legitimate business necessity.1
This paragraph confines the proxy assessment to ECDIS and leaves “legitimate business necessity” undefined. The phrase appears once with no attached test. The search for a less discriminatory alternative lives in Step 3 of the assessment in the next section.
Commenters asked the Department to drop the proxy provision. It declined. Its own account of what moved between the January draft and the July final is that the letter “clarifies what the proxy assessment may entail and the protected classes to which this provision applies.”1 The clarification narrows the scope while preserving the effort. Quantitative work is expected only where the insurer can identify or reasonably impute membership from available data, and insurers are not expected to collect additional information about individuals solely to run it.1
The three steps that come after
The proxy assessment measures correlation with a protected class. A separate numbered exercise evaluates whether the underwriting or pricing guideline is lawful, and that exercise covers ECDIS and AIS alike.
An insurer should not use either unless it can establish, through a comprehensive assessment, that the guidelines derived from them are not unfairly or unlawfully discriminatory under the Insurance Law. At a minimum that assessment runs three steps.1
Step 1 asks whether the use produces disproportionate adverse effects in underwriting or pricing for similarly situated insureds or insureds of a protected class, and only for protected classes whose membership the insurer can determine from available data or reasonably infer. No prima facie showing of such an effect, and the evaluation may end here.1
Step 2 asks whether a legitimate, lawful, and fair explanation or rationale accounts for the differential effect. If none does, the insurer should modify its use and begin again at Step 1.1
Step 3 is a documented search for a less discriminatory alternative variable or methodology that would reasonably meet the insurer’s legitimate business needs. Find one, and again the insurer should modify and return to Step 1. Find none, and the use continues under ongoing model risk management, with Step 3 repeated at least annually.1
Anyone who has worked a fair-lending file will recognize the shape: a prima facie showing, then a justification, then a search for something less discriminatory that does the same job. That is disparate-impact burden-shifting, borrowed whole. The letter itself never uses the phrase. Its term throughout is “disproportionate adverse effect,” and the only place anything like “disparately impacted” appears is a footnote quoting the American Academy of Actuaries.1 Carriers describing their program to a New York examiner are better off using the Department’s words than the ones from case law.
The shape matters more than the individual steps. There is no terminal box marked “prohibited in New York.” Every failing branch routes back to Step 1 with a modified model, and the branch that passes still comes back once a year. A carrier that treats this as a gate to clear before launch has read it as the wrong shape.
What counts as unfair discrimination in AI underwriting under New York law?
Circular Letter No. 7 does not define “unfair” or “unlawful” discrimination. It points instead to the statutes already on the books, and names them: Insurance Law Article 26, sections 4224(a)–(b), 3221(q)(3), and 4305(k)(3), the Executive Law, the General Business Law, and the federal Civil Rights Act.1 For insurers, that means the concepts already embedded in New York insurance law control the analysis. Unfair discrimination in AI underwriting generally refers to rate or underwriting distinctions that are not justified by the risk being insured.3
The letter does not define “legitimate business necessity” either, and it is worth resisting the urge to fill that blank in. A variable that correlates with a protected class and cannot be tied to a business necessity is not, by the letter’s own text, thereby unlawful. What it is, is a variable the carrier has to take back through the three steps. The prohibition it may eventually run into sits in the Insurance Law rather than in the circular letter: section 2303 for property and casualty rates,3 and section 4224 for unfair discrimination between individuals of the same class in life and accident and health coverage.4
What does an insurer need in place before using ECDIS or AIS?
Circular Letter No. 7 expects the governance framework to exist before deployment. Its New York-specific cadence belongs in the operating calendar: test before an AIS goes into production, retest regularly, and test again after a material change to the ECDIS or AIS.1 Written policies need defined accountability and at least annual approval by the board, a committee, or senior management acting under delegated authority.1
The letter also calls for role-specific training and for the internal audit function required by 11 NYCRR § 89.16 to assess the framework, including potential bias in the data.1 The underlying inventory, documentation, and monitoring records belong in the insurer’s wider governance implementation framework rather than a separate New York register.
What notice should an insurer give after an adverse AI underwriting decision in New York?
Two duties sit here, and they are easy to run together. Only one of them carries a clock.
The general disclosure duty, with no deadline attached. For any declination, limitation, rate differential, or other adverse underwriting or pricing decision, the reasons given to the consumer should include details about all of the information the insurer based that decision on, including the source of the specific information it relied on. The notice should also carry three disclosures: that the insurer uses AIS in underwriting or pricing, that it uses data about the person obtained from external vendors, and that the person may request the specific data behind the decision. That last one comes with contact details for making the request.1
The 15-day notice, which attaches to one narrow determination. Where the ECDIS or AIS underwriting process concludes that an applicant cannot be approved through it, and can be insured only through a process that does not use ECDIS or AIS, the letter says that “within 15-days of such a determination an insurer should provide notice to the applicant in writing,” identifying the reasons that applicant could not be underwritten using those tools.1 Two things ride along with that clock and are easy to miss: the non-automated underwriting process should keep running during the notice period, and failing to send the notice at all may be treated as an unfair trade practice under Insurance Law Article 24.1
Where that determination rests on specific external data, a third duty attaches at the same moment: the applicant gets a process for reviewing those data for accuracy, offered when the applicant is told the application cannot be processed through the automated route.1
The distinction matters operationally. Reading the 15-day clock onto every adverse decision builds a deadline the letter does not impose, and it can pull attention away from the disclosure duty that actually covers the ordinary declination or surcharge.
One sentence here is not phrased as an expectation at all. An insurer “may not rely on the proprietary nature of a third-party vendor’s algorithmic processes to justify the lack of specificity related to an adverse underwriting or pricing action.”1 That closes off the answer carriers most often get from a scoring vendor when they ask what drove a particular decline.
Two other duties are written as flat requirements. Complaint records involving AIS or ECDIS must be kept in line with 11 NYCRR 243 and produced to the Department on request. And insurers must have procedures ready to receive and answer consumer complaints about AI and external data use.1
Those are the exceptions. Almost everywhere else the register is “should,” and the letter describes its own purpose as identifying the Department’s expectations.1 Optional is the wrong thing to read into that. The letter is an account of how the Department thinks existing New York insurance law already reaches these tools. What a carrier answers for is that law, and the examiner arrives holding the letter.
What are the third-party vendor requirements?
An insurer may not rely only on a third party’s non-discrimination claim or proprietary process; responsibility remains with the carrier.1 Where appropriate and available, the contract should provide audit rights or qualified audit reports and require cooperation with regulatory inquiries.1 Those clauses came from the NAIC Model Bulletin.
NYDFS does not expect the carrier to understand every technical detail inside a vendor’s AIS. It does expect risk-proportionate due diligence and oversight.1 The AI vendor risk assessment covers how to implement that contract and review process.
Does NYDFS Circular Letter No. 7 apply to AI without external data?
Yes. This was the single most contested point in the comment file, and the Department did not move on it. Commenters encouraged it to limit the guidance to AIS that draw on external data. It kept the original definitions instead, for the reason quoted earlier: covering AI systems is the point, whether or not external data is anywhere near them.1 The final letter therefore preserves the draft’s reach. Its governance, testing, and documentation expectations follow an AIS used for those decisions whether the inputs are proprietary or third-party.1
What is the relationship between NYDFS Circular Letter No. 7 and the NAIC Model Bulletin?
The NAIC Model Bulletin supplies a governance baseline; Circular Letter No. 7 ties a New York procedure to the state laws listed in its header.1 The Department borrowed the Bulletin’s vendor-contract clause, but the proxy assessment, three-step assessment, and notice duties remain New York-specific. A NAIC-aligned program therefore does not substitute for this review. The New York state page sets out each of those departures with its source text and locator.
What should insurers do next?
The execution order follows the tests above: identify the New York ECDIS and AIS population, run the ECDIS proxy assessment, complete the three-step assessment for the resulting guidelines, connect each outcome to the correct consumer notice, and confirm the vendor audit route. Training and annual governance review support that sequence rather than creating a separate workstream.
What Circular Letter No. 7 settles
NYDFS Circular Letter No. 7 states its expectations as a procedure: numbered steps, a stopping point, a return path 1. It does not ban ECDIS or AIS. It expects insurers to show, through documented testing, that their use of these tools does not produce unfair discrimination. The consumer-disclosure and vendor-audit expectations give the guidance teeth.
New York-licensed insurers retain responsibility for the AI and external data used in underwriting, regardless of who built the model.
The Department has not revised the letter.1 Its December 16, 2025 testimony to the New York State Assembly, at a hearing on the use of AI systems in insurance underwriting and pricing, restated the letter’s premise.5 Legislators were told that “many of the laws that DFS enforces are technology-agnostic, meaning the core regulatory obligations are the same for manual processes as they are for AI models and systems.”5 The Department added that there might be room for specific AI requirements as new risks arise, but that it had not taken that approach as of that hearing.5
The letter’s force is borrowed. Circular Letter No. 7 is guidance, and what makes it enforceable is the New York anti-discrimination law it was built on, not the letter’s own text.1 We checked again on September 4, 2026: the Department’s posted insurance enforcement actions still do not identify an action brought on Circular Letter No. 7.6 That scan covers the public titles and linked action list, not every possible reference inside every consent order. Insurers are reading a regulator’s stated expectation ahead of settled public enforcement practice about how far it reaches.
Footnotes
-
New York State Department of Financial Services, Insurance Circular Letter No. 7 (2024), “Use of Artificial Intelligence Systems and External Consumer Data and Information Sources in Insurance Underwriting and Pricing,” July 11, 2024. Sections referenced in the text above: Purpose and Background, Scope, Definitions, Fairness Principles, Proxy Assessment, Unlawful or Unfair Discrimination, Governance Framework, Transparency (Disclosure and Notice), and Third-Party Vendors. Text reviewed September 4, 2026 against the Department’s posted version, with no revision found: https://www.dfs.ny.gov/industry-guidance/circular-letters/cl2024-07 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31 ↩32 ↩33 ↩34 ↩35 ↩36 ↩37 ↩38 ↩39
-
Colorado Division of Insurance, “SB21-169: Protecting Consumers from Unfair Discrimination in Insurance Practices” (Amended Regulation 10-1-1, “Governance and Risk Management Framework Requirements for Life Insurers’, Private Passenger Automobile Insurers, and Health Benefit Plan Insurers’ Use of External Consumer Data and Information Sources, Algorithms, and Predictive Models,” effective October 15, 2025; the quantitative testing regulation remains a draft released for informal comment September 28, 2023): https://doi.colorado.gov/for-consumers/sb21-169-protecting-consumers-from-unfair-discrimination-in-insurance-practices ↩
-
New York Insurance Law § 2303 (unfair discrimination): https://www.nysenate.gov/legislation/laws/ISC/2303 ↩ ↩2
-
New York Insurance Law § 4224 (unfair discrimination between individuals of the same class in life and accident and health insurance): https://www.nysenate.gov/legislation/laws/ISC/4224 ↩
-
New York State Department of Financial Services, “Statement by DFS Acting Superintendent Kaitlin Asrow at the NYS Assembly Hearing on the Use of Artificial Intelligence Systems in Insurance Underwriting and Pricing,” December 16, 2025: https://www.dfs.ny.gov/reports_and_publications/press_releases/pr20251216 ↩ ↩2 ↩3
-
New York State Department of Financial Services, “Insurance Enforcement Actions” (reviewed September 4, 2026: the posted list still contains no action titled on Circular Letter No. 7; this title-level scan does not establish that no consent order mentions the guidance): https://www.dfs.ny.gov/industry_guidance/enforcement_actions_Insurance ↩
The Bottom Line
- Circular Letter No. 7 explains how the Department reads existing New York insurance law against AI and external consumer data in underwriting and pricing. The letter itself is guidance.
- It does not ban external data or AI systems. It sets out two separate exercises: a proxy assessment for external data, and a three-step assessment of disproportionate adverse effects that covers external data and AI alike.
- The consumer-disclosure and vendor-audit expectations give the guidance teeth. The 15-day clock is narrower than it is usually quoted: it attaches to applicants who cannot be underwritten with these tools at all.
- The carrier remains responsible for the AI and external data it uses in New York, regardless of who built the model.
How Insurers Assess AI Vendor Risk
A NAIC-aligned AI vendor risk assessment checklist: a twenty-question due-diligence questionnaire, contract clauses, and the monitoring that stays with the insurer.
Continue →
Simon Li · Founding Editor
I write InsureAI Wire and maintain its 51-jurisdiction tracker. Most of the work is reading: NAIC working group papers, state bulletins, bills, court filings, and public comment letters. Every claim on the site carries the document it came from, so you never have to take my word for it.
Free · Weekly
Track these developments weekly
Get the InsureAI Wire dispatch in your inbox. Free, sourced, no spam.
Free weekly · No spam · Unsubscribe anytime
Related reading
How to Identify the High-Risk AI Systems Exhibit C Asks About
Five screening lines that turn an existing AI inventory into a defensible list of the high-risk systems NAIC Exhibit C asks about, and the record behind it.
Who Owns the Evidence in Insurance AI Governance
Insurance AI governance roles as an ownership matrix: which function prepares each piece of NAIC evidence, which one signs it, and who answers for it in an exam.
AI Governance Documents to Prepare for a Market Conduct Exam
The insurance AI exam documentation to have ready for a market conduct exam: an insurer-built readiness file of eight evidence categories, and how to record a gap.
AI Model Monitoring After the Model Goes Live
A playbook for insurers on AI model monitoring, validation, drift detection, and retesting records that satisfy NAIC Model Bulletin and Exhibit C expectations.
Information aggregation and analysis, not legal advice. See our disclaimer.