top of page
Search

Model Audit Rule Compliance Problems: What Insurance Companies Keep Getting Wrong

The NAIC Model Audit Rule Is Not Merely an Annual Filing Exercise


Insurance companies frequently approach the NAIC Model Audit Rule as a year-end compliance requirement.


Management prepares the annual audited financial statements. The external audit firm completes its work. Required reports are submitted to the state insurance department.


The organization then turns its attention to the next regulatory deadline.


That approach misses the primary purpose of the regulation.


The NAIC Annual Financial Reporting Model Regulation, commonly called the Model Audit Rule, is intended to strengthen regulatory surveillance through independent financial audits, Audit Committee oversight, auditor independence, communication of control deficiencies, and—when applicable—management’s assessment of Internal Control over Financial Reporting.


The rule is designed to create an operating system of governance and internal control, not simply a set of documents produced after year-end.


Over the past several years, insurance companies have continued to encounter compliance problems involving:

  • Failure to recognize when regulatory thresholds have been crossed

  • Weak Audit Committee independence

  • Inadequate internal audit functions

  • Auditor-independence conflicts

  • Incomplete ICFR scoping

  • Weak documentation of management review controls

  • Poor evaluation of control deficiencies

  • Overdue remediation

  • Insufficient information-technology controls

  • Late, incomplete, or inconsistent regulatory filings


Public enforcement information specifically labeled as a “Model Audit Rule violation” is limited. State financial examinations and supervisory communications involving individual insurers are not always public, and many compliance concerns are resolved through examination management letters, corrective-action plans, or confidential regulatory processes.


However, the requirements regulators examine—and the recurring implementation weaknesses that create the greatest exposure—are clear.


1. Companies Fail to Prepare Before Crossing a Regulatory Threshold

One of the most preventable Model Audit Rule problems occurs when an insurer grows into additional requirements without building the necessary compliance infrastructure.


An insurer may cross a threshold because of:

  • Organic premium growth

  • Acquisition of another insurer

  • Assumption of reinsurance

  • Consolidation within an insurance group

  • Expansion into new products or states

  • Changes in the way premiums are calculated for regulatory purposes


For insurers subject to the applicable state version of MAR, premium growth can trigger greater expectations involving Audit Committee independence, an internal audit function, and management reporting on ICFR.


A recent industry analysis noted that Model Audit Rule and Own Risk and Solvency Assessment obligations can become applicable during the same growth period, creating a compressed implementation timetable and potentially significant unexpected costs. It also cautioned that larger insurers may need a highly independent Audit Committee, an established internal audit function, and a management report on control effectiveness shortly after crossing the relevant thresholds.


The compliance mistake

Management waits until the threshold has already been crossed before asking:

  • Which requirements now apply?

  • When is the first report due?

  • Does the Audit Committee meet the independence requirement?

  • Is the internal audit function adequately staffed?

  • Is there enough evidence to support management’s ICFR conclusion?

  • Do the control owners understand their responsibilities?


At that point, the organization may have only months to construct processes that should have been developed over several years.


Better practice

Management should maintain a rolling three-year forecast of:

  • Direct written premium

  • Assumed premium

  • Acquisition activity

  • Regulatory thresholds

  • Required implementation dates

  • Staffing needs

  • External advisory costs

  • Audit Committee changes

  • ICFR documentation and testing requirements


Threshold monitoring should be part of strategic planning—not a year-end accounting exercise.


2. Audit Committee Independence Exists on Paper but Not in Practice

The Model Audit Rule increased the responsibility of insurance-company Audit Committees for the appointment, compensation, and oversight of the independent auditor. The NAIC’s adopted revisions also linked required levels of Audit Committee independence to an insurer’s premium volume.


Insurance companies can encounter compliance concerns when:

  • Committee members have significant management responsibilities.

  • The parent-company committee is used without evaluating whether it meets the insurer’s requirements.

  • Independence determinations are not documented.

  • Related-party relationships are not fully considered.

  • The committee relies heavily on the Chief Financial Officer to manage the external-audit relationship.

  • The committee approves reports without understanding significant judgments or deficiencies.


The compliance mistake

The Board assumes that calling a group of directors the “Audit Committee” is enough.


It is not.


The committee must have:

  • Properly qualified members

  • The required degree of independence

  • Defined authority

  • Appropriate financial and insurance knowledge

  • Access to Internal Audit and the external auditor

  • A documented record of oversight


Better practice

The annual governance review should verify:

  • Member independence

  • Conflicts of interest

  • Financial expertise

  • Attendance

  • Executive sessions

  • Oversight of the external auditor

  • Review of significant control deficiencies

  • Review of the management ICFR report

  • Monitoring of unresolved remediation


The minutes should demonstrate meaningful challenge—not merely receipt of management presentations.


3. The Internal Audit Function Is Too Small, Too Narrow, or Insufficiently Independent

The internal audit requirement is one of the areas that can create the greatest difficulty for growing insurers.


A company may technically establish an internal audit function but still fail to create an effective source of independent assurance.


Common weaknesses include:

  • One auditor covering an entire insurance group

  • Reporting relationships dominated by the CFO or Controller

  • An audit plan based primarily on management requests

  • Little or no coverage of actuarial, claims, investments, reinsurance, cybersecurity, or statutory reporting

  • Heavy dependence on outsourced providers without strong internal ownership

  • No formal Quality Assurance and Improvement Program

  • Inadequate communication with the Audit Committee


The Federal Reserve’s insurance-supervision framework similarly emphasizes that internal audit should independently assess governance, risk management, and internal controls and report findings to senior management and the Audit Committee. For less complex insurance organizations, it specifically points to the insurer’s domiciliary-state version of MAR or similar regulation when assessing internal audit effectiveness.


The compliance mistake

The organization treats internal audit as a required organizational box rather than a functioning assurance activity.


Better practice

The Audit Committee should evaluate whether Internal Audit has:

  • Organizational independence

  • Sufficient authority

  • Adequate staffing and expertise

  • Access to all relevant records and personnel

  • A risk-based audit plan

  • Insurance-specific technical competence

  • IT-audit capability

  • Direct communication with the committee

  • A process for tracking corrective actions

  • Appropriate external quality assessment arrangements


Outsourcing can supplement expertise. It does not eliminate management’s responsibility to establish and govern the function.


4. External-Auditor Independence Is Not Evaluated Broadly Enough

Insurance companies often engage their external accounting firms for services beyond the annual statutory audit.


Those services may involve:

  • Tax work

  • Accounting advice

  • System implementation assistance

  • Valuation

  • Actuarial support

  • Internal-control documentation

  • Internal audit assistance

  • Financial-statement preparation


The NAIC’s Model Audit Rule revisions restricted certain non-audit services and strengthened audit-partner rotation and independence expectations. Smaller insurers may seek limited exemptions under applicable state provisions, but an exemption should never be assumed.


The compliance mistake

Management asks only whether the CPA firm considers itself independent.


The insurer and Audit Committee have their own oversight responsibilities.


A prohibited or conflicting service may create:

  • A self-review threat

  • A management-participation threat

  • An advocacy threat

  • Questions about the credibility of the annual audit

  • Regulatory concern over Audit Committee oversight


Better practice

Before approving an additional service, the Audit Committee should document:

  1. The nature and scope of the service

  2. The applicable independence requirement

  3. Whether the auditor will evaluate its own work

  4. Whether the auditor is making management decisions

  5. Available safeguards

  6. Whether another provider should perform the work

  7. The basis for the committee’s approval


Auditor independence must be monitored throughout the relationship, not merely when the engagement letter is signed.


5. Management’s ICFR Report Is Treated as a Certification Form

Large insurers subject to the management-reporting provisions must assess and report on Internal Control over Financial Reporting.


The NAIC describes the report as including management’s conclusion about whether controls provide reasonable assurance regarding the reliability of statutory financial statements and disclosure of any unremediated material weaknesses. The external auditor considers that report during audit planning and performance.


State rules may also authorize regulators to require an ICFR report from insurers below the ordinary premium threshold when financial-condition concerns exist. Virginia’s current regulation, for example, permits the commission to require the report when an insurer is in an RBC-level event or meets hazardous-financial-condition criteria.


The compliance mistake

Management signs the report without a sufficiently disciplined support process.


Weak support may include:

  • An outdated risk-control matrix

  • Little evidence of control testing

  • No clear evaluation framework

  • Incomplete IT coverage

  • Unresolved exceptions

  • Reliance on external-audit testing

  • No documented disclosure committee or executive review

  • Unsupported statements that controls were effective


Better practice

The annual report should be supported by a documented management process addressing:

  • ICFR scope

  • Material accounts and disclosures

  • Relevant assertions

  • Significant business processes

  • Key controls

  • Entity-Level Controls

  • IT General Controls

  • Testing methods

  • Identified deviations

  • Compensating controls

  • Deficiency evaluation

  • Remediation status

  • Management’s final conclusion


The report is the end product. The compliance obligation is the process supporting it.


6. ICFR Scope Omits Important Insurance Processes

Insurance ICFR is substantially more complex than a conventional general-ledger control program.


Material financial reporting may depend on:

  • Policy administration

  • Premium billing

  • Claims processing

  • Loss-reserve data

  • Actuarial models

  • Reinsurance systems

  • Investment accounting

  • Third-party administrators

  • Data warehouses

  • Regulatory reporting software

  • Numerous interfaces and end-user computing tools


The compliance mistake

The organization scopes ICFR by starting with its existing control inventory rather than identifying where material statutory misstatements could occur.


That approach may omit:

  • Key actuarial controls

  • Data transferred between operational and financial systems

  • Spreadsheet-based calculations

  • Third-party information

  • Model governance

  • Reinsurance recoverables

  • Management estimates

  • System-generated reports


Better practice

ICFR scoping should follow this sequence:

  1. Identify significant statutory accounts and disclosures.

  2. Identify relevant financial-statement assertions.

  3. Map the processes and systems producing those amounts.

  4. Identify risks of material misstatement.

  5. Identify the controls addressing those risks.

  6. Evaluate whether the control operates with enough precision.

  7. Test the information used by the control.


Starting with the risks produces a defensible control population. Starting with last year’s spreadsheet usually produces a stale one.


7. Management Review Controls Are Poorly Documented

Insurance companies rely heavily on management review controls because many financial figures involve complex estimates and professional judgment.


Examples include reviews of:

  • Loss and claim reserves

  • Investment valuations

  • Reinsurance balances

  • Financial-statement fluctuations

  • Risk-based capital calculations

  • Actuarial reports

  • Statutory schedules

  • Premium and claims trends


The compliance mistake

The evidence consists of a signature, an email stating “reviewed,” or meeting minutes showing that a report was discussed.


That does not demonstrate:

  • What the reviewer examined

  • What threshold was used

  • What questions were asked

  • Which exceptions were investigated

  • What evidence supported resolution

  • Whether the reviewer possessed appropriate competence

  • Whether the review could detect a material error


Better practice

A management review control should document:

  • The report and data reviewed

  • The expected level of precision

  • Established thresholds

  • Significant variances

  • Questions raised

  • Supporting analysis

  • Resolution of exceptions

  • Reviewer identity and competence

  • Date of completion


A checkmark proves that someone touched the document. It does not prove that the control worked.


8. IT General Controls Are Underestimated

Financial reporting at an insurance company may depend on hundreds of automated calculations, interfaces, reports, and system configurations.


Model Audit Rule compliance becomes questionable when management cannot demonstrate effective control over:

  • User access

  • Privileged access

  • Program changes

  • System development

  • Interfaces

  • Batch processing

  • Data conversion

  • Report generation

  • Cybersecurity incidents

  • Third-party technology providers


The compliance mistake

The organization documents business-process controls but assumes the underlying systems are reliable.


If system access, changes, operations, or data integrity are weak, automated controls and system-generated reports may not be dependable.


Better practice

The ICFR program should identify:

  • Financially significant applications

  • Supporting infrastructure

  • Key interfaces

  • Critical reports

  • Relevant IT dependencies

  • Applicable IT General Controls

  • Control owners

  • Testing requirements

  • Identified deficiencies


Regulators undertaking risk-focused financial examinations review insurer-prepared Model Audit Rule or SOX work, CPA workpapers, internal audit activity, Audit Committee oversight, and risk-mitigation strategies. Pennsylvania’s examination guidance expressly describes that coordinated approach.


IT controls are not a separate technical appendix. They are part of the evidence supporting financial reporting reliability.


9. Control Deficiencies Are Corrected but Not Properly Evaluated

A failed control requires more than a replacement signature or an updated reconciliation.


Management must evaluate:

  • The cause

  • Duration

  • Frequency

  • Accounts and assertions affected

  • Likelihood of misstatement

  • Potential magnitude

  • Compensating controls

  • Related deficiencies

  • Whether the problem is systemic

  • Whether the issue must be reported


The compliance mistake

The company closes the exception without determining whether it represents a significant deficiency, material weakness, broader control problem, or reporting matter.


A process failure may appear small in isolation while revealing:

  • Management override

  • Inadequate competency

  • Weak governance

  • Systemic data problems

  • Repeat control failure

  • Unreliable financial reporting


Better practice

Use a formal deficiency-evaluation process that documents:

  1. The identified condition

  2. Applicable control objective

  3. Cause

  4. Actual and potential consequences

  5. Likelihood and magnitude

  6. Compensating controls

  7. Aggregation with other deficiencies

  8. Required communication

  9. Remediation plan

  10. Final disposition


The quality of deficiency evaluation is often more important than the number of exceptions identified.


10. Remediation Is Slow and Repeat Findings Accumulate

Insurance companies frequently identify deficiencies but struggle to correct them.


Common causes include:

  • Legacy systems

  • Resource shortages

  • Competing regulatory projects

  • Unclear ownership

  • Dependence on vendors

  • Weak executive sponsorship

  • Inadequate root-cause analysis

  • Corrective actions that address symptoms only


The compliance mistake

Management repeatedly moves the completion date while continuing to report that remediation is in progress.

An overdue finding eventually becomes a governance issue.


Better practice

The Audit Committee should receive reporting that identifies:

  • Original due date

  • Revised due date

  • Responsible executive

  • Current status

  • Reason for delay

  • Interim controls

  • Residual risk

  • Validation requirements

  • Repeat-findings history


A corrective action should not be closed until the new control is implemented, has operated for an appropriate period, and has been validated.


11. Annual Audited Financial Reports and Related Filings Are Late or Incomplete

State versions of MAR generally establish specific filing dates and procedures for extensions.


Virginia, for example, requires the annual audited financial report by the applicable due date and permits extensions of up to 30 days when the insurer and accountant make a timely written request demonstrating good cause.


Massachusetts similarly requires filing by June 1 and treats the audited report as part of the insurer’s annual-statement filing, subject to statutory penalties for noncompliance.


The compliance mistake

The company treats an extension request as routine or waits until the deadline is imminent before communicating a problem.


Other filing weaknesses include:

  • Missing required statements

  • Failure to reconcile audited figures to the annual statement

  • Incomplete disclosure of intercompany activity

  • Late internal-control communications

  • Inconsistent information across regulatory submissions

  • Failure to document state-specific exemptions


Better practice

Use a regulatory filing calendar that identifies:

  • Each required report

  • Applicable jurisdiction

  • Legal due date

  • Internal due date

  • Responsible owner

  • Required approvals

  • Supporting evidence

  • Extension procedures

  • Final proof of filing

Model Audit Rule is a model regulation. The enforceable requirement is the version adopted by the applicable state.


12. Insurance Groups Assume One State’s Requirements Apply Everywhere

The NAIC publishes a Guide to Compliance with State Audit Requirements specifically because state requirements differ. The guide summarizes key state provisions based on MAR and related correspondence obligations.


The compliance mistake

An insurance group develops one national checklist and assumes it satisfies every domiciliary and licensing jurisdiction.


Differences may involve:

  • Filing dates

  • Premium thresholds

  • Exemption procedures

  • Electronic filing

  • Required communications

  • Auditor qualifications

  • Audit Committee provisions

  • Management reporting

  • Penalties


Better practice

The compliance program should maintain a jurisdictional matrix showing:

  • State citation

  • Applicability

  • Threshold

  • Filing requirements

  • Due dates

  • Exemptions

  • Approval requirements

  • Responsible legal or compliance reviewer

  • Date of most recent confirmation


The matrix should be updated annually and after acquisitions, reorganizations, or significant growth.


What Regulators Are Really Looking For

State financial regulators are not merely checking whether a document was filed.


Risk-focused examination programs evaluate whether the insurer’s governance, risk management, and controls are credible and sustainable.


That evaluation may include:

  • Review of Model Audit Rule work

  • Review of CPA workpapers

  • Interviews with Internal Audit

  • Interviews with the Audit Committee chair

  • Interviews with executive management

  • Review of risk-mitigation strategies

  • Coordination with the external auditor

  • Identification of matters requiring continued monitoring


The insurer should therefore be prepared to demonstrate:

  • Who owns the process

  • How risks were identified

  • Why controls were selected

  • How controls were tested

  • What exceptions were found

  • How deficiencies were evaluated

  • What management concluded

  • How the Audit Committee exercised oversight

  • Whether remediation is sustainable


Documentation should tell that story without requiring regulators to reconstruct it.


Questions Every Insurance Audit Committee Should Ask

  1. Are we approaching any new Model Audit Rule thresholds?

  2. Does the committee meet applicable independence requirements?

  3. Has auditor independence been evaluated for every non-audit service?

  4. Is Internal Audit sufficiently independent, competent, and resourced?

  5. Does management’s ICFR scope include actuarial, reinsurance, investment, claims, and IT risks?

  6. Are management review controls supported by substantive evidence?

  7. Have all critical reports and spreadsheets been evaluated?

  8. Are deficiencies being assessed individually and in combination?

  9. Which findings are overdue or recurring?

  10. Has management considered state-specific requirements?

  11. Can the annual ICFR conclusion be reconstructed from the workpapers?

  12. Would the program withstand a risk-focused financial examination today?


A committee that cannot obtain clear answers should not assume the program is effective.


The Central Compliance Lesson

The most important Model Audit Rule failures rarely begin with the final filing.


They begin months or years earlier when:

  • Growth is not monitored.

  • Governance responsibilities are unclear.

  • Controls are inherited rather than risk-assessed.

  • IT is excluded.

  • Testing becomes mechanical.

  • Deficiencies are minimized.

  • Remediation is delayed.

  • Management assumes the external auditor owns the process.


The Model Audit Rule requires management ownership.


The external auditor provides independent assurance.


Internal Audit evaluates the system.


The Audit Committee provides oversight.


Regulators determine whether the entire structure is credible.


Strengthen Your Model Audit Rule Program

The three-day, 18-CPE program addresses:

  • MAR requirements

  • Internal Control over Financial Reporting

  • COSO’s five components and 17 principles

  • Entity-Level Controls

  • COBIT and IT controls

  • Annual management assessments

  • Deficiency evaluation

  • Enterprise risk management

  • Risk-focused examination readiness

  • Audit Committee reporting

  • Corrective action and program improvement


The best time to strengthen a Model Audit Rule program is before a regulator, external auditor, or material control failure exposes its weaknesses.

Compliance should not begin with the annual filing.


It should begin with governance, risk assessment, control ownership, evidence, and accountability.

 
 
 

Recent Posts

See All

Comments


Subscribe Form

Thanks for submitting!

479-200-4373

  • Facebook
  • Twitter
  • LinkedIn
  • Twitter
  • LinkedIn
  • Facebook

©2026 by The Accountware Group. Proudly created with Wix.com

bottom of page