Model Audit Rule Compliance Problems: What Insurance Companies Keep Getting Wrong
- John Blackshire
- 4 days ago
- 11 min read
The NAIC Model Audit Rule Is Not Merely an Annual Filing Exercise
Insurance companies frequently approach the NAIC Model Audit Rule as a year-end compliance requirement.
Management prepares the annual audited financial statements. The external audit firm completes its work. Required reports are submitted to the state insurance department.
The organization then turns its attention to the next regulatory deadline.
That approach misses the primary purpose of the regulation.
The NAIC Annual Financial Reporting Model Regulation, commonly called the Model Audit Rule, is intended to strengthen regulatory surveillance through independent financial audits, Audit Committee oversight, auditor independence, communication of control deficiencies, and—when applicable—management’s assessment of Internal Control over Financial Reporting.
The rule is designed to create an operating system of governance and internal control, not simply a set of documents produced after year-end.
Over the past several years, insurance companies have continued to encounter compliance problems involving:
Failure to recognize when regulatory thresholds have been crossed
Weak Audit Committee independence
Inadequate internal audit functions
Auditor-independence conflicts
Incomplete ICFR scoping
Weak documentation of management review controls
Poor evaluation of control deficiencies
Overdue remediation
Insufficient information-technology controls
Late, incomplete, or inconsistent regulatory filings
Public enforcement information specifically labeled as a “Model Audit Rule violation” is limited. State financial examinations and supervisory communications involving individual insurers are not always public, and many compliance concerns are resolved through examination management letters, corrective-action plans, or confidential regulatory processes.
However, the requirements regulators examine—and the recurring implementation weaknesses that create the greatest exposure—are clear.
1. Companies Fail to Prepare Before Crossing a Regulatory Threshold
One of the most preventable Model Audit Rule problems occurs when an insurer grows into additional requirements without building the necessary compliance infrastructure.
An insurer may cross a threshold because of:
Organic premium growth
Acquisition of another insurer
Assumption of reinsurance
Consolidation within an insurance group
Expansion into new products or states
Changes in the way premiums are calculated for regulatory purposes
For insurers subject to the applicable state version of MAR, premium growth can trigger greater expectations involving Audit Committee independence, an internal audit function, and management reporting on ICFR.
A recent industry analysis noted that Model Audit Rule and Own Risk and Solvency Assessment obligations can become applicable during the same growth period, creating a compressed implementation timetable and potentially significant unexpected costs. It also cautioned that larger insurers may need a highly independent Audit Committee, an established internal audit function, and a management report on control effectiveness shortly after crossing the relevant thresholds.
The compliance mistake
Management waits until the threshold has already been crossed before asking:
Which requirements now apply?
When is the first report due?
Does the Audit Committee meet the independence requirement?
Is the internal audit function adequately staffed?
Is there enough evidence to support management’s ICFR conclusion?
Do the control owners understand their responsibilities?
At that point, the organization may have only months to construct processes that should have been developed over several years.
Better practice
Management should maintain a rolling three-year forecast of:
Direct written premium
Assumed premium
Acquisition activity
Regulatory thresholds
Required implementation dates
Staffing needs
External advisory costs
Audit Committee changes
ICFR documentation and testing requirements
Threshold monitoring should be part of strategic planning—not a year-end accounting exercise.
2. Audit Committee Independence Exists on Paper but Not in Practice
The Model Audit Rule increased the responsibility of insurance-company Audit Committees for the appointment, compensation, and oversight of the independent auditor. The NAIC’s adopted revisions also linked required levels of Audit Committee independence to an insurer’s premium volume.
Insurance companies can encounter compliance concerns when:
Committee members have significant management responsibilities.
The parent-company committee is used without evaluating whether it meets the insurer’s requirements.
Independence determinations are not documented.
Related-party relationships are not fully considered.
The committee relies heavily on the Chief Financial Officer to manage the external-audit relationship.
The committee approves reports without understanding significant judgments or deficiencies.
The compliance mistake
The Board assumes that calling a group of directors the “Audit Committee” is enough.
It is not.
The committee must have:
Properly qualified members
The required degree of independence
Defined authority
Appropriate financial and insurance knowledge
Access to Internal Audit and the external auditor
A documented record of oversight
Better practice
The annual governance review should verify:
Member independence
Conflicts of interest
Financial expertise
Attendance
Executive sessions
Oversight of the external auditor
Review of significant control deficiencies
Review of the management ICFR report
Monitoring of unresolved remediation
The minutes should demonstrate meaningful challenge—not merely receipt of management presentations.
3. The Internal Audit Function Is Too Small, Too Narrow, or Insufficiently Independent
The internal audit requirement is one of the areas that can create the greatest difficulty for growing insurers.
A company may technically establish an internal audit function but still fail to create an effective source of independent assurance.
Common weaknesses include:
One auditor covering an entire insurance group
Reporting relationships dominated by the CFO or Controller
An audit plan based primarily on management requests
Little or no coverage of actuarial, claims, investments, reinsurance, cybersecurity, or statutory reporting
Heavy dependence on outsourced providers without strong internal ownership
No formal Quality Assurance and Improvement Program
Inadequate communication with the Audit Committee
The Federal Reserve’s insurance-supervision framework similarly emphasizes that internal audit should independently assess governance, risk management, and internal controls and report findings to senior management and the Audit Committee. For less complex insurance organizations, it specifically points to the insurer’s domiciliary-state version of MAR or similar regulation when assessing internal audit effectiveness.
The compliance mistake
The organization treats internal audit as a required organizational box rather than a functioning assurance activity.
Better practice
The Audit Committee should evaluate whether Internal Audit has:
Organizational independence
Sufficient authority
Adequate staffing and expertise
Access to all relevant records and personnel
A risk-based audit plan
Insurance-specific technical competence
IT-audit capability
Direct communication with the committee
A process for tracking corrective actions
Appropriate external quality assessment arrangements
Outsourcing can supplement expertise. It does not eliminate management’s responsibility to establish and govern the function.
4. External-Auditor Independence Is Not Evaluated Broadly Enough
Insurance companies often engage their external accounting firms for services beyond the annual statutory audit.
Those services may involve:
Tax work
Accounting advice
System implementation assistance
Valuation
Actuarial support
Internal-control documentation
Internal audit assistance
Financial-statement preparation
The NAIC’s Model Audit Rule revisions restricted certain non-audit services and strengthened audit-partner rotation and independence expectations. Smaller insurers may seek limited exemptions under applicable state provisions, but an exemption should never be assumed.
The compliance mistake
Management asks only whether the CPA firm considers itself independent.
The insurer and Audit Committee have their own oversight responsibilities.
A prohibited or conflicting service may create:
A self-review threat
A management-participation threat
An advocacy threat
Questions about the credibility of the annual audit
Regulatory concern over Audit Committee oversight
Better practice
Before approving an additional service, the Audit Committee should document:
The nature and scope of the service
The applicable independence requirement
Whether the auditor will evaluate its own work
Whether the auditor is making management decisions
Available safeguards
Whether another provider should perform the work
The basis for the committee’s approval
Auditor independence must be monitored throughout the relationship, not merely when the engagement letter is signed.
5. Management’s ICFR Report Is Treated as a Certification Form
Large insurers subject to the management-reporting provisions must assess and report on Internal Control over Financial Reporting.
The NAIC describes the report as including management’s conclusion about whether controls provide reasonable assurance regarding the reliability of statutory financial statements and disclosure of any unremediated material weaknesses. The external auditor considers that report during audit planning and performance.
State rules may also authorize regulators to require an ICFR report from insurers below the ordinary premium threshold when financial-condition concerns exist. Virginia’s current regulation, for example, permits the commission to require the report when an insurer is in an RBC-level event or meets hazardous-financial-condition criteria.
The compliance mistake
Management signs the report without a sufficiently disciplined support process.
Weak support may include:
An outdated risk-control matrix
Little evidence of control testing
No clear evaluation framework
Incomplete IT coverage
Unresolved exceptions
Reliance on external-audit testing
No documented disclosure committee or executive review
Unsupported statements that controls were effective
Better practice
The annual report should be supported by a documented management process addressing:
ICFR scope
Material accounts and disclosures
Relevant assertions
Significant business processes
Key controls
Entity-Level Controls
IT General Controls
Testing methods
Identified deviations
Compensating controls
Deficiency evaluation
Remediation status
Management’s final conclusion
The report is the end product. The compliance obligation is the process supporting it.
6. ICFR Scope Omits Important Insurance Processes
Insurance ICFR is substantially more complex than a conventional general-ledger control program.
Material financial reporting may depend on:
Policy administration
Premium billing
Claims processing
Loss-reserve data
Actuarial models
Reinsurance systems
Investment accounting
Third-party administrators
Data warehouses
Regulatory reporting software
Numerous interfaces and end-user computing tools
The compliance mistake
The organization scopes ICFR by starting with its existing control inventory rather than identifying where material statutory misstatements could occur.
That approach may omit:
Key actuarial controls
Data transferred between operational and financial systems
Spreadsheet-based calculations
Third-party information
Model governance
Reinsurance recoverables
Management estimates
System-generated reports
Better practice
ICFR scoping should follow this sequence:
Identify significant statutory accounts and disclosures.
Identify relevant financial-statement assertions.
Map the processes and systems producing those amounts.
Identify risks of material misstatement.
Identify the controls addressing those risks.
Evaluate whether the control operates with enough precision.
Test the information used by the control.
Starting with the risks produces a defensible control population. Starting with last year’s spreadsheet usually produces a stale one.
7. Management Review Controls Are Poorly Documented
Insurance companies rely heavily on management review controls because many financial figures involve complex estimates and professional judgment.
Examples include reviews of:
Loss and claim reserves
Investment valuations
Reinsurance balances
Financial-statement fluctuations
Risk-based capital calculations
Actuarial reports
Statutory schedules
Premium and claims trends
The compliance mistake
The evidence consists of a signature, an email stating “reviewed,” or meeting minutes showing that a report was discussed.
That does not demonstrate:
What the reviewer examined
What threshold was used
What questions were asked
Which exceptions were investigated
What evidence supported resolution
Whether the reviewer possessed appropriate competence
Whether the review could detect a material error
Better practice
A management review control should document:
The report and data reviewed
The expected level of precision
Established thresholds
Significant variances
Questions raised
Supporting analysis
Resolution of exceptions
Reviewer identity and competence
Date of completion
A checkmark proves that someone touched the document. It does not prove that the control worked.
8. IT General Controls Are Underestimated
Financial reporting at an insurance company may depend on hundreds of automated calculations, interfaces, reports, and system configurations.
Model Audit Rule compliance becomes questionable when management cannot demonstrate effective control over:
User access
Privileged access
Program changes
System development
Interfaces
Batch processing
Data conversion
Report generation
Cybersecurity incidents
Third-party technology providers
The compliance mistake
The organization documents business-process controls but assumes the underlying systems are reliable.
If system access, changes, operations, or data integrity are weak, automated controls and system-generated reports may not be dependable.
Better practice
The ICFR program should identify:
Financially significant applications
Supporting infrastructure
Key interfaces
Critical reports
Relevant IT dependencies
Applicable IT General Controls
Control owners
Testing requirements
Identified deficiencies
Regulators undertaking risk-focused financial examinations review insurer-prepared Model Audit Rule or SOX work, CPA workpapers, internal audit activity, Audit Committee oversight, and risk-mitigation strategies. Pennsylvania’s examination guidance expressly describes that coordinated approach.
IT controls are not a separate technical appendix. They are part of the evidence supporting financial reporting reliability.
9. Control Deficiencies Are Corrected but Not Properly Evaluated
A failed control requires more than a replacement signature or an updated reconciliation.
Management must evaluate:
The cause
Duration
Frequency
Accounts and assertions affected
Likelihood of misstatement
Potential magnitude
Compensating controls
Related deficiencies
Whether the problem is systemic
Whether the issue must be reported
The compliance mistake
The company closes the exception without determining whether it represents a significant deficiency, material weakness, broader control problem, or reporting matter.
A process failure may appear small in isolation while revealing:
Management override
Inadequate competency
Weak governance
Systemic data problems
Repeat control failure
Unreliable financial reporting
Better practice
Use a formal deficiency-evaluation process that documents:
The identified condition
Applicable control objective
Cause
Actual and potential consequences
Likelihood and magnitude
Compensating controls
Aggregation with other deficiencies
Required communication
Remediation plan
Final disposition
The quality of deficiency evaluation is often more important than the number of exceptions identified.
10. Remediation Is Slow and Repeat Findings Accumulate
Insurance companies frequently identify deficiencies but struggle to correct them.
Common causes include:
Legacy systems
Resource shortages
Competing regulatory projects
Unclear ownership
Dependence on vendors
Weak executive sponsorship
Inadequate root-cause analysis
Corrective actions that address symptoms only
The compliance mistake
Management repeatedly moves the completion date while continuing to report that remediation is in progress.
An overdue finding eventually becomes a governance issue.
Better practice
The Audit Committee should receive reporting that identifies:
Original due date
Revised due date
Responsible executive
Current status
Reason for delay
Interim controls
Residual risk
Validation requirements
Repeat-findings history
A corrective action should not be closed until the new control is implemented, has operated for an appropriate period, and has been validated.
11. Annual Audited Financial Reports and Related Filings Are Late or Incomplete
State versions of MAR generally establish specific filing dates and procedures for extensions.
Virginia, for example, requires the annual audited financial report by the applicable due date and permits extensions of up to 30 days when the insurer and accountant make a timely written request demonstrating good cause.
Massachusetts similarly requires filing by June 1 and treats the audited report as part of the insurer’s annual-statement filing, subject to statutory penalties for noncompliance.
The compliance mistake
The company treats an extension request as routine or waits until the deadline is imminent before communicating a problem.
Other filing weaknesses include:
Missing required statements
Failure to reconcile audited figures to the annual statement
Incomplete disclosure of intercompany activity
Late internal-control communications
Inconsistent information across regulatory submissions
Failure to document state-specific exemptions
Better practice
Use a regulatory filing calendar that identifies:
Each required report
Applicable jurisdiction
Legal due date
Internal due date
Responsible owner
Required approvals
Supporting evidence
Extension procedures
Final proof of filing
Model Audit Rule is a model regulation. The enforceable requirement is the version adopted by the applicable state.
12. Insurance Groups Assume One State’s Requirements Apply Everywhere
The NAIC publishes a Guide to Compliance with State Audit Requirements specifically because state requirements differ. The guide summarizes key state provisions based on MAR and related correspondence obligations.
The compliance mistake
An insurance group develops one national checklist and assumes it satisfies every domiciliary and licensing jurisdiction.
Differences may involve:
Filing dates
Premium thresholds
Exemption procedures
Electronic filing
Required communications
Auditor qualifications
Audit Committee provisions
Management reporting
Penalties
Better practice
The compliance program should maintain a jurisdictional matrix showing:
State citation
Applicability
Threshold
Filing requirements
Due dates
Exemptions
Approval requirements
Responsible legal or compliance reviewer
Date of most recent confirmation
The matrix should be updated annually and after acquisitions, reorganizations, or significant growth.
What Regulators Are Really Looking For
State financial regulators are not merely checking whether a document was filed.
Risk-focused examination programs evaluate whether the insurer’s governance, risk management, and controls are credible and sustainable.
That evaluation may include:
Review of Model Audit Rule work
Review of CPA workpapers
Interviews with Internal Audit
Interviews with the Audit Committee chair
Interviews with executive management
Review of risk-mitigation strategies
Coordination with the external auditor
Identification of matters requiring continued monitoring
The insurer should therefore be prepared to demonstrate:
Who owns the process
How risks were identified
Why controls were selected
How controls were tested
What exceptions were found
How deficiencies were evaluated
What management concluded
How the Audit Committee exercised oversight
Whether remediation is sustainable
Documentation should tell that story without requiring regulators to reconstruct it.
Questions Every Insurance Audit Committee Should Ask
Are we approaching any new Model Audit Rule thresholds?
Does the committee meet applicable independence requirements?
Has auditor independence been evaluated for every non-audit service?
Is Internal Audit sufficiently independent, competent, and resourced?
Does management’s ICFR scope include actuarial, reinsurance, investment, claims, and IT risks?
Are management review controls supported by substantive evidence?
Have all critical reports and spreadsheets been evaluated?
Are deficiencies being assessed individually and in combination?
Which findings are overdue or recurring?
Has management considered state-specific requirements?
Can the annual ICFR conclusion be reconstructed from the workpapers?
Would the program withstand a risk-focused financial examination today?
A committee that cannot obtain clear answers should not assume the program is effective.
The Central Compliance Lesson
The most important Model Audit Rule failures rarely begin with the final filing.
They begin months or years earlier when:
Growth is not monitored.
Governance responsibilities are unclear.
Controls are inherited rather than risk-assessed.
IT is excluded.
Testing becomes mechanical.
Deficiencies are minimized.
Remediation is delayed.
Management assumes the external auditor owns the process.
The Model Audit Rule requires management ownership.
The external auditor provides independent assurance.
Internal Audit evaluates the system.
The Audit Committee provides oversight.
Regulators determine whether the entire structure is credible.
Strengthen Your Model Audit Rule Program
Corporate Compliance Seminars will present NAIC Model Audit Rule Programs from Tuesday through Thursday, September 22–24, 2026.
The three-day, 18-CPE program addresses:
MAR requirements
Internal Control over Financial Reporting
COSO’s five components and 17 principles
Entity-Level Controls
COBIT and IT controls
Annual management assessments
Deficiency evaluation
Enterprise risk management
Risk-focused examination readiness
Audit Committee reporting
Corrective action and program improvement
The best time to strengthen a Model Audit Rule program is before a regulator, external auditor, or material control failure exposes its weaknesses.
Compliance should not begin with the annual filing.
It should begin with governance, risk assessment, control ownership, evidence, and accountability.
Comments