NAIC Model Audit Rule Compliance Is More Than an Annual Filing: Build an ICFR Program That Can Stand Up to Examination
- John Blackshire
- Aug 22
- 8 min read
NAIC Model Audit Rule Programs — September 22–24 and November 17–19, 2026
For insurance organizations, compliance with the NAIC Model Audit Rule (MAR) should not be treated as an annual paperwork exercise.
The real issue is whether the insurer has built a sustainable system of internal control over financial reporting (ICFR) that management understands, evaluates, monitors and improves.
That requires considerably more than documenting a few controls before year-end.
It requires an integrated approach involving:
Risk Assessment
→ Entity-Level Controls
→ Process-Level Controls
→ Information Technology Controls
→ Control Testing
→ Deficiency Evaluation
→ Management Assessment
→ Board Communication
→ Corrective Action
Corporate Compliance Seminars' NAIC Model Audit Rule Programs is an intensive three-day, 18-CPE program designed to help insurance professionals understand and implement that process. The program integrates the NAIC Model Audit Rule with the COSO 2013 Internal Control Framework, COSO ERM, COBIT and the NAIC Financial Condition Examiners Handbook.
Two upcoming sessions are:
Tuesday–Thursday, September 22–24, 2026
Tuesday–Thursday, November 17–19, 2026
The Model Audit Rule Should Be Viewed as a Control System
A weak approach to MAR compliance asks:
“What documentation do we need to produce?”
A stronger approach asks:
“How do we know that the controls supporting our financial reporting are properly designed and operating effectively?”
That distinction matters.
Documentation is evidence of the program.
Documentation is not the program.
The CCS course addresses establishing policies and procedures aligned with COSO, identifying and assessing ICFR risks, designing controls to mitigate those risks, monitoring control effectiveness, conducting annual assessments and communicating results to management and the board.
Start With Risk, Not With a List of Controls
One of the most common internal-control mistakes is starting with existing controls.
Management asks:
“What controls do we have?”
The better starting point is:
“What could prevent us from achieving reliable financial reporting?”
The progression should be:
Financial Reporting Objective
↓
Risk
↓
Financial Statement Assertion
↓
Control
↓
Control Owner
↓
Evidence of Performance
↓
Testing
↓
Conclusion
This risk-based approach is central to an effective ICFR program.
The CCS program specifically addresses developing a risk-based approach to ICFR and identifying financial-reporting risks using COSO's 17 principles.
Don't Forget Entity-Level Controls
Insurance organizations can spend enormous amounts of time documenting transactional controls while paying insufficient attention to the controls operating across the entire organization.
These entity-level controls (ELCs) can include:
Board and Audit Committee Oversight
Management's Control Philosophy
Organizational Structure
Assignment of Authority
Risk Assessment
Ethics and Compliance
Whistleblower Processes
Management Monitoring
Internal Audit
Corrective-Action Processes
CCS specifically includes identifying the ELCs contained within an NAIC Model Audit Rule program among its event highlights.
This is important because weak entity-level controls can undermine otherwise well-designed transactional controls.
COSO Provides the Internal-Control Architecture
A Model Audit Rule program should not become a disconnected collection of control descriptions.
COSO provides the architecture for understanding how those controls fit together.
The five familiar components are:
Control Environment
Risk Assessment
Control Activities
Information and Communication
Monitoring Activities
Underneath those components are COSO's 17 principles.
CCS's MAR Academy specifically incorporates COSO 2013 into its approach to establishing and evaluating internal controls and identifying risks to financial reporting.
The practical question becomes:
Can management demonstrate that the relevant COSO principles are present and functioning?
That requires evidence.
ITGCs Belong Inside the MAR Conversation
Insurance financial reporting is heavily dependent upon technology.
Policy administration systems.
Claims systems.
General ledgers.
Investment systems.
Billing.
Reinsurance systems.
Actuarial applications.
Interfaces.
Spreadsheets.
Data warehouses.
Financial-reporting applications.
That means an ICFR program cannot stop at manual accounting controls.
The CCS program incorporates COBIT and IT governance alongside COSO, specifically recognizing the importance of technology controls within the compliance environment.
An important question for every MAR program is:
Which financial-reporting controls depend upon information technology, and what gives us confidence that those systems and data are reliable?
Designing a Control Is Only Half the Job
Suppose management identifies a risk and designs a control.
The procedure says that a manager reviews a reconciliation monthly.
Excellent.
But now there are two different questions:
Design Effectiveness
If performed as designed, could the control reasonably address the identified risk?
Operating Effectiveness
Did the control actually operate as designed during the period under review?
Those are not the same thing.
A perfectly performed control can still be useless if it was badly designed.
Conversely, an excellent control design provides little protection if employees don't actually perform it.
An effective MAR program needs to consider both.
A Signature Does Not Prove an Effective Review
This deserves particular attention in ICFR programs.
Suppose a reconciliation contains the initials: JB — Reviewed 7/15/26
What does that establish?
It may establish that someone initialed the document.
It does not necessarily establish:
What did the reviewer examine?
What criteria did the reviewer apply?
What discrepancies were investigated?
What threshold triggered follow-up?
What evidence demonstrates the depth of review?
Could the review detect the financial-reporting error the control was designed to prevent or detect?
Internal-control testing needs to move beyond:
“Is there a signature?”
toward:
“Is there sufficient evidence that an effective review control actually operated?”
Management Owns the MAR Program
This distinction should remain clear.
Internal Audit can evaluate controls.
External Audit can audit.
Consultants can advise.
Compliance can coordinate.
But:
Management owns the controls.
Management owns the risks.
Management operates the business.
Management is responsible for the reliability of financial reporting.
The CCS program is therefore particularly relevant to CFOs, Controllers and financial executives, as well as compliance professionals and Internal and External Auditors involved in MAR assessments.
MAR should not become “the Internal Audit project.”
Internal Audit provides independent assurance.
Management needs to own the control environment.
The Financial Condition Examiners Handbook Matters
An insurer should not evaluate its MAR program solely from its own perspective.
There is another important perspective:
How will insurance regulators evaluate the organization?
CCS therefore incorporates the NAIC Financial Condition Examiners Handbook (FCEH) into the program.
The course addresses using FCEH guidance to improve compliance efficiency and aligning MAR processes with the expectations relevant to insurance examinations.
This creates a useful mindset:
Don't just ask:
“Do we think this control is adequate?”
Also ask:
“What would an examiner expect to see?”
Build the Program Before the Examiner Arrives
A regulatory examination is the wrong time to discover that:
Control owners cannot explain their controls.
Risk assessments are outdated.
Control descriptions don't match actual procedures.
Evidence cannot be located.
IT dependencies were ignored.
Testing was inconsistent.
Deficiencies were never followed up.
Management cannot explain its conclusions.
A mature MAR program should be capable of producing a clear trail:
Risk
→ Control
→ Owner
→ Evidence
→ Testing
→ Exception
→ Evaluation
→ Corrective Action
→ Retesting
→ Conclusion
If that trail is difficult for management to follow, it may also be difficult for an examiner to follow.
Internal Audit Should Challenge the MAR Program
Internal Audit can provide significant value by asking uncomfortable questions.
For example:
Are all significant financial-reporting risks included?
Are key controls actually linked to those risks?
Are control descriptions accurate?
Are controls sufficiently precise?
Are system-generated reports reliable?
Are management review controls supported by evidence?
Are exceptions being investigated?
Are deficiencies evaluated consistently?
Are corrective actions actually correcting root causes?
Are repeat findings occurring?
These questions move Internal Audit beyond documentation compliance and toward assurance over program effectiveness.
Corrective Action Is Part of Internal Control
Finding a deficiency is not the end of the process.
The CCS program specifically addresses corrective actions and follow-up for identified compliance gaps.
An effective remediation process should answer:
What failed?
Why did it fail?
What risk resulted?
What needs to change?
Who owns the corrective action?
When will it be completed?
How will management know it worked?
Who will verify implementation?
Otherwise, organizations can spend years reporting the same problem under slightly different wording.
Communicating Results to the Board Matters
CCS also addresses communicating ICFR assessment results to management and the board.
That communication should not overwhelm directors with hundreds of control-testing details.
The board needs to understand:
Where are the significant risks?
What material control weaknesses or deficiencies were identified?
Are problems isolated or systemic?
What is management doing about them?
Are significant issues recurring?
Are corrective actions overdue?
Does management believe ICFR is operating effectively?
What does Internal Audit believe?
That is governance-level reporting.
The Triennial Risk Assessment Should Add Value
The CCS program also addresses triennial enterprise risk assessments and their relationship to the MAR compliance environment.
The value of risk assessment is not producing a large spreadsheet.
It is identifying what has changed.
Insurance organizations operate in an environment affected by:
Cybersecurity
Artificial Intelligence
Catastrophe Exposure
Claims Inflation
Third-Party Risk
Reinsurance
Investment Risk
Regulatory Change
Data Quality
Technology Transformation
A risk assessment copied from three years ago may satisfy a documentation process while completely missing the organization's current risk environment.
AI Is Becoming a MAR Control Issue
Artificial intelligence deserves particular attention.
Insurance organizations are increasingly exploring AI in underwriting, claims, customer service, fraud detection, analytics, finance and other operations.
That creates new control questions:
Which AI applications affect financial reporting?
What data feeds those systems?
Who validates AI-generated information?
Can outputs be reproduced?
Who approves changes?
What happens when the AI output is wrong?
Are appropriate access and cybersecurity controls operating?
Is human review sufficiently precise?
The technology may be new.
The internal-control logic isn't.
Objective → Risk → Control → Evidence → Monitoring
MAR programs need to evolve as the underlying business evolves.
Three Days to Examine the Entire MAR Framework
The CCS program is structured across three days.
Day One addresses MAR fundamentals, COSO, COBIT and development of a risk-based approach to ICFR.
Day Two moves into risk management, independence considerations, triennial enterprise risk assessments and the Financial Condition Examiners Handbook.
Day Three emphasizes practical application, reporting, case studies, communication of ICFR results, corrective action and follow-up.
This makes the program considerably more comprehensive than a short overview of the regulation.
Who Should Attend?
The course is designed for insurance professionals responsible for compliance and internal control, including:
Compliance Managers
CFOs
Controllers
Financial Executives
Internal Auditors
External Auditors
Risk Professionals
Professionals responsible for MAR assessments and ICFR.
The program is classified at the Basic level, requires no prerequisites or advance preparation, and provides 18 CPE credits across Auditing, Business Law, Business Management & Organization, Behavioral Ethics and Information Technology. Sessions run from 9:00 a.m. to 3:00 p.m. Central Time each day.
Two Opportunities to Attend in 2026
September 22–24, 2026
The September session provides an opportunity for insurance organizations to evaluate their MAR processes, ICFR documentation, testing and corrective actions as they move toward year-end.
November 17–19, 2026
The November session may be particularly valuable for organizations preparing for 2027 MAR compliance activities, risk assessments, control testing and regulatory examination readiness.
Both sessions provide the complete three-day, 18-CPE curriculum.
The Bottom Line: Build a MAR Program That Works All Year
The objective should not be:
“Get through the annual MAR compliance process.”
The objective should be:
“Build an internal-control system that management can rely upon and regulators can examine.”
That means connecting:
NAIC MAR
COSO
ICFR
Entity-Level Controls
ITGCs
Risk Assessment
Control Testing
Deficiency Evaluation
Corrective Action
Board Oversight
When those pieces work together, MAR becomes more than regulatory compliance.
It becomes part of the organization's system for producing reliable financial information and managing risk.
Corporate Compliance Seminars' NAIC Model Audit Rule Programs on September 22–24 and November 17–19, 2026 provides insurance professionals with three days to examine how those pieces fit together—and how to strengthen the program before weaknesses become regulatory examination issues.
Comments