Skip to content

Evidence request lists

Colorado Artificial Intelligence Act (proposed SB 24-205)

Evidence request list. 19 controls, 19 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Colorado AI Act: Consumer AI Disclosure (6-1-1704)

CO-AIA-1704
Disclosure of AI System to Consumers

Any deployer or developer that deploys, offers or makes available an AI system intended to interact with consumers must disclose to each consumer that they are interacting with an AI system, unless it would be obvious to a reasonable person.

Artefacts an auditor will ask for
  • Consumer-facing AI interaction disclosure (chatbot/assistant notice)
Where this commonly fails
  • No disclosure of AI interaction to consumers

Colorado AI Act: Defenses, Enforcement and Rules (6-1-1705 to 1707)

CO-AIA-1705
Affirmative Defense and Recognised Frameworks

A developer/deployer has an affirmative defense if it discovers and cures a violation through internal testing/red-teaming and is otherwise in compliance with the latest NIST AI Risk Management Framework, ISO/IEC 42001, or another nationally/internationally recognised framework (or an AG-designated framework).

Artefacts an auditor will ask for
  • Internal testing/red-teaming + cure records
  • Evidence of compliance with a recognised AI framework
Where this commonly fails
  • No internal testing or recognised-framework alignment
CO-AIA-1706
Enforcement by the Attorney General

The Attorney General has exclusive authority to enforce the Act; a violation is an unfair or deceptive trade practice under the Colorado Consumer Protection Act; there is no private right of action.

Artefacts an auditor will ask for
  • Awareness of AG exclusive enforcement + CCPA unfair-practice exposure
  • Cure-period procedures
Where this commonly fails
  • No legal-exposure assessment for AI deployment
CO-AIA-1707
Attorney General Rulemaking

The Attorney General may promulgate rules to implement and administer the Act (documentation, notices, impact-assessment content, risk-management requirements, rebuttable-presumption/affirmative-defense conditions).

Artefacts an auditor will ask for
  • Monitoring of AG implementing rules and updating controls accordingly
Where this commonly fails
  • No tracking of AG rulemaking

Colorado AI Act: Definitions and Scope (6-1-1701)

CO-AIA-1701-DISCRIM
Algorithmic Discrimination Definition

Algorithmic discrimination is any condition in which the use of an AI system results in unlawful differential treatment or impact that disfavours an individual/group on the basis of a protected classification under state or federal law.

Artefacts an auditor will ask for
  • Definition of algorithmic discrimination adopted
  • Bias/disparate-impact testing methodology
Where this commonly fails
  • No bias-testing for protected classes
CO-AIA-1701-HIGHRISK
High-Risk AI System and Consequential Decision Scope

A high-risk AI system is one that, when deployed, makes or is a substantial factor in making a consequential decision: a decision with a material legal/similarly significant effect on a consumer's access to or terms of education, employment, financial/lending services, an essential government service, healthcare, housing, insurance, or legal services.

Artefacts an auditor will ask for
  • Inventory of AI systems classified high-risk vs not
  • Mapping of consequential-decision use to the eight statutory domains
Where this commonly fails
  • High-risk classification not assessed
  • Consequential-decision use undocumented

Colorado AI Act: Deployer Duties (6-1-1703)

CO-AIA-1703-1
Deployer Duty of Reasonable Care

A deployer of a high-risk AI system must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination; compliance creates a rebuttable presumption of reasonable care.

Artefacts an auditor will ask for
  • Deployer reasonable-care program evidence
  • Rebuttable-presumption compliance file
Where this commonly fails
  • No deployer reasonable-care program
CO-AIA-1703-2
Risk Management Policy and Program

The deployer must implement a risk-management policy and program governing high-risk AI deployment, that is iterative, regularly reviewed/updated, and reasonable considering a nationally/internationally recognised AI risk-management framework such as the latest NIST AI Risk Management Framework or ISO/IEC 42001, or a framework designated by the Attorney General.

Artefacts an auditor will ask for
  • AI risk-management policy and program aligned to NIST AI RMF / ISO 42001
  • Periodic review/update records
Where this commonly fails
  • No AI risk-management program
  • Program not aligned to a recognised framework
CO-AIA-1703-3
Impact Assessment

The deployer must complete an impact assessment for each high-risk AI system annually and within 90 days after any intentional and substantial modification; the assessment must cover purpose, intended use, benefits, discrimination risks and mitigation, data categories processed, outputs, monitoring and transparency measures; retained for at least three years.

Artefacts an auditor will ask for
  • Impact assessments (annual + post-modification) with the 1703(3) content
  • Three-year retention of assessments
Where this commonly fails
  • No/late impact assessments
  • Assessments missing discrimination-risk analysis
CO-AIA-1703-4
Consumer Pre-Decision Notice

Before, or as soon as feasible after, a high-risk AI system makes or is a substantial factor in a consequential decision, the deployer must notify the consumer that AI is used, describe the system and the nature of the decision, provide contact information and instructions to access the public statement, and (where applicable) the right to opt out of profiling.

Artefacts an auditor will ask for
  • Consumer notice template + delivery records before consequential decisions
Where this commonly fails
  • No pre-decision consumer notice
CO-AIA-1703-5
Adverse Decision Explanation, Correction and Appeal

If a consequential decision is adverse to the consumer, the deployer must provide the principal reasons (including how the AI system contributed and the data used), an opportunity to correct incorrect personal data, and an opportunity to appeal for human review where technically feasible.

Artefacts an auditor will ask for
  • Adverse-decision explanation statements
  • Data-correction + human-review appeal mechanism
Where this commonly fails
  • No explanation/appeal for adverse AI decisions
CO-AIA-1703-6
Deployer Public Statement

The deployer must publish a clear, readily available statement summarising the types of high-risk AI systems currently deployed and how it manages known or foreseeable risks of algorithmic discrimination.

Artefacts an auditor will ask for
  • Published deployer high-risk-AI statement
Where this commonly fails
  • No public deployer statement
CO-AIA-1703-7
Deployer Disclosure of Algorithmic Discrimination to AG

On discovering that a deployed high-risk AI system has caused algorithmic discrimination, the deployer must notify the Attorney General without unreasonable delay, no later than 90 days.

Artefacts an auditor will ask for
  • Discrimination-discovery + 90-day AG notification procedure
  • Disclosure records
Where this commonly fails
  • No AG notification process for discrimination
CO-AIA-1703-8
Small Deployer Exemption

A deployer with fewer than 50 full-time employees that does not use its own data to train the high-risk AI system, and that meets the other statutory conditions, is exempted from the risk-management-program, impact-assessment and public-statement duties.

Artefacts an auditor will ask for
  • Headcount + data-use determination supporting any small-deployer exemption
Where this commonly fails
  • Exemption claimed without meeting the conditions

Colorado AI Act: Developer Duties (6-1-1702)

CO-AIA-1702-1
Developer Duty of Reasonable Care

On and after the effective date a developer of a high-risk AI system must use reasonable care to protect consumers from known or reasonably foreseeable risks of algorithmic discrimination arising from intended and contracted uses; compliance creates a rebuttable presumption of reasonable care.

Artefacts an auditor will ask for
  • Evidence of reasonable-care measures across the AI lifecycle
  • Rebuttable-presumption compliance file
Where this commonly fails
  • No documented reasonable-care program
CO-AIA-1702-2
Developer Documentation and Disclosures to Deployers

The developer must make available to deployers: a general statement of foreseeable and harmful/inappropriate uses; documentation of training-data summaries, known limitations and discrimination risks, purpose, intended uses; how the system was evaluated for performance and discrimination; data-governance measures; intended outputs; mitigations; and how the system should be used, not used and monitored.

Artefacts an auditor will ask for
  • Developer documentation package / model card to deployers covering 1702(2) elements
  • Evaluation + data-governance records
Where this commonly fails
  • Incomplete developer documentation
  • No evaluation/data-governance disclosure
CO-AIA-1702-3
Impact-Assessment Support Artifacts

The developer must make available, to the extent feasible, documentation through artifacts such as model cards, dataset cards or impact assessments necessary for the deployer (or its third party) to complete an impact assessment under 6-1-1703(3).

Artefacts an auditor will ask for
  • Model cards / dataset cards / impact-assessment inputs provided to deployers
Where this commonly fails
  • Deployer unable to complete impact assessment due to missing developer artifacts
CO-AIA-1702-4
Developer Public Statement

The developer must publish a clear, readily available statement (website or public use-case inventory) summarising the types of high-risk AI systems it develops/modifies and how it manages known or foreseeable risks of algorithmic discrimination; updated within 90 days of a substantial modification.

Artefacts an auditor will ask for
  • Published developer high-risk-AI statement
  • Update log within 90 days of modification
Where this commonly fails
  • No public statement / not kept current
CO-AIA-1702-5
Developer Disclosure of Algorithmic Discrimination

On discovering (through testing/analysis or a credible deployer report) that its high-risk AI system has caused or is reasonably likely to have caused algorithmic discrimination, the developer must disclose to the Attorney General and known deployers without unreasonable delay, no later than 90 days.

Artefacts an auditor will ask for
  • Discrimination-discovery monitoring + 90-day AG/deployer notification procedure
  • Disclosure records
Where this commonly fails
  • No process to detect/report discrimination within 90 days
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Colorado Artificial Intelligence Act (proposed SB 24-205) framework page.