top of page
Search

ERM Risk Assessment for Insurance Organizations: Building a Risk Program That Management, the Board, and Regulators Can Actually Use

Live CPE Webinar • Tuesday, October 20, 2026 • 4 CPE Credits


Insurance organizations exist to manage risk.


Yet many insurers still struggle to manage their own enterprise risks in a disciplined, integrated way.


That challenge is getting harder.


Insurance organizations must now evaluate not only traditional underwriting and financial risks, but also:

  • Operational risk

  • Strategic risk

  • Regulatory risk

  • Cybersecurity risk

  • Third-party risk

  • Technology risk

  • Capital and solvency risk

  • Governance risk


That is why Enterprise Risk Management should not be treated as a once-a-year exercise performed for a regulator.


It should be a management system.


Corporate Compliance Seminars’ ERM Risk Assessment for Insurance Organizations is a focused 4-CPE live program designed to help insurance professionals establish and maintain a practical ERM program while understanding key regulatory expectations involving the Model Audit Rule, Own Risk and Solvency Assessment, and NAIC Enterprise Risk Report—Form F. The next program is scheduled for Tuesday, October 20, 2026.


ERM Should Start With the Business

A risk register is not an ERM program.


A heat map is not an ERM program.


A Form F filing is not an ERM program.


Effective ERM begins with a much more fundamental question:

What are we trying to accomplish, and what could prevent us from accomplishing it?

For an insurance organization, those objectives may involve:

  • Maintaining adequate capital

  • Pricing risk appropriately

  • Paying claims accurately and timely

  • Protecting policyholder information

  • Meeting regulatory requirements

  • Maintaining strong distribution channels

  • Managing investments

  • Preserving reputation

  • Remaining financially resilient


The risk assessment should follow those objectives.


That creates a logical progression:

Objectives

Risks

Risk Assessment

Risk Response

Internal Controls

Monitoring

Reporting


That is much more valuable than starting with a generic list of risks.


Insurance ERM Has a Regulatory Dimension

Insurance organizations operate within a distinctive regulatory framework.


The CCS program specifically addresses ERM requirements and concepts associated with:

  • Model Audit Rule

  • Own Risk and Solvency Assessment

  • NAIC Enterprise Risk Report — Form F


These requirements are related but not identical.


The important point is that regulators increasingly expect insurers to demonstrate that enterprise risks are being:

  • Identified

  • Assessed

  • Governed

  • Monitored

  • Communicated


That makes ERM much more than a management preference.


It is also a governance and compliance discipline.


ORSA Forces Insurers to Think About Risk and Solvency Together

One of the most important insurance-specific ERM concepts is the Own Risk and Solvency Assessment—ORSA.


ORSA is intended to help insurers evaluate their own risk profile and determine whether their capital position remains appropriate in light of those risks.


The CCS course covers:

  • Purpose and objectives of ORSA

  • Key components of an ORSA program

  • The ORSA Summary Report


The NAIC continues to actively maintain and review the ORSA framework. In 2026, the NAIC’s ORSA Implementation Subgroup continued its work on ERM education for regulators and reviewed proposed changes to the ORSA Guidance Manual.


That reinforces an important point:

ORSA is not static.

Insurance organizations need ERM programs capable of adapting as risks and regulatory expectations evolve.


Form F Brings Enterprise Risk Into Regulatory Reporting

The NAIC Enterprise Risk Report—Form F is another important component of the insurance ERM framework.


Form F is intended to provide regulators with information about enterprise risks that could affect the insurer.


That can include risks arising from:

  • Affiliates

  • Holding-company relationships

  • Capital structure

  • Strategic initiatives

  • Operations

  • Financial exposures


The CCS program specifically includes Form F reporting and examples of effective risk reporting.


For Internal Audit and Risk Management, this raises an important question:

Does the regulatory filing accurately reflect what management and the Board actually understand about enterprise risk?

If the Board is discussing one set of major risks while Form F communicates something materially different, the organization may have a risk-governance problem.


Risk Assessment Is More Than a Heat Map

Risk assessments often end with a familiar matrix:


Likelihood × Impact


That can be useful.


But it is only the beginning.


A meaningful insurance risk assessment should also consider:

  • Velocity

  • Duration

  • Interdependencies

  • Control effectiveness

  • Residual risk

  • Capital implications

  • Regulatory consequences

  • Concentration risk


Consider cybersecurity.


A cyber event may have:

Financial impact

plus

Operational impact

plus

Regulatory impact

plus

Reputational impact.


One risk can affect multiple objectives.


That is why enterprise risk assessment needs to look across organizational silos.


Risk Identification Should Be Broad

CCS specifically focuses on financial, operational, strategic, and regulatory risks faced by insurance organizations.


Examples might include:

Financial Risk

  • Investment losses

  • Reserve uncertainty

  • Liquidity pressure

  • Capital deterioration

Operational Risk

  • Claims-processing failures

  • System outages

  • Third-party failures

  • Poor underwriting controls

Strategic Risk

  • Product strategy

  • Distribution disruption

  • Market changes

  • Acquisition risk

Regulatory Risk

  • NAIC requirements

  • State insurance laws

  • Cybersecurity regulations

  • Market conduct requirements


The purpose is not to create the longest risk inventory possible.


It is to identify the risks capable of materially affecting the organization's objectives.


Risk Appetite Turns ERM Into Decision-Making

One of the most important components of a mature ERM program is a risk appetite statement.


CCS includes developing risk appetite statements among the program’s implementation best practices.


A risk appetite helps management answer:

How much risk are we willing to accept while pursuing our objectives?

That becomes important when deciding:

  • How much capital to hold

  • Which markets to enter

  • Which products to offer

  • Which risks to insure

  • How much cybersecurity exposure is acceptable

  • Which third-party arrangements are appropriate


Without defined risk appetite, organizations can end up making inconsistent risk decisions.


Inherent Risk and Residual Risk Are Different

A useful ERM distinction is:

  • Inherent Risk — risk before considering controls.

  • Residual Risk — risk remaining after controls and mitigation.


Suppose ransomware represents a high inherent risk.


Management implements:

  • Multifactor authentication

  • Segmentation

  • Backups

  • Monitoring

  • Incident-response procedures


The residual risk may be lower.


But it is not zero.


The Board should understand the residual exposure it is accepting.


That is where ERM connects directly to governance.


Internal Controls Are One Risk Response—Not the Only One

CCS teaches several risk-management approaches, including:

  • Internal controls

  • Risk transfer

  • Risk acceptance


Organizations generally have four broad choices:

Avoid - Stop the activity.

Reduce - Implement controls.

Transfer - Use insurance, contracts, or other mechanisms.

Accept - Consciously retain the risk.


The important word is consciously.


Risk acceptance should not mean:

“Nobody fixed it.”

It should mean:

“Management understands the exposure and the appropriate authority has accepted it.”

The Board Has a Critical ERM Role

CCS places significant emphasis on Board and senior-management oversight.


That is appropriate because ERM cannot succeed as a Risk Management Department project.


Senior management and the Board should understand:

  • Major enterprise risks

  • Risk appetite

  • Risk concentrations

  • Emerging risks

  • Residual risk

  • Significant control failures

  • Corrective actions


The Board does not operate the controls.


But it should understand whether management has built an effective system for managing risk.


Internal Audit Has a Different Role

Internal Audit should not own ERM.


Management owns risk.


Risk Management may facilitate the process.


Internal Audit provides assurance.


Internal Audit can evaluate:

  • Risk-assessment methodology

  • Completeness of the risk universe

  • Governance

  • Risk reporting

  • Internal controls

  • Follow-up

  • Alignment with regulatory requirements


The key question is:

Can the Board rely on management's ERM process?

That is an assurance question.


Risk Reporting Must Be Useful

A risk report containing 150 risks can technically be complete and practically useless.


Senior management and Boards need clarity.


Useful reporting may show:

  • Top enterprise risks

  • Risk trend

  • Risk owner

  • Inherent risk

  • Residual risk

  • Controls

  • Mitigation

  • Status

  • Emerging issues


The CCS program specifically addresses ongoing monitoring, reporting, and communicating risk to stakeholders.


A good risk report should help someone make a decision.


If it does not, it may be reporting activity rather than managing risk.


Emerging Risk Requires Continuous Monitoring

Insurance risk changes continuously.


Examples include:

  • Cyber threats

  • AI adoption

  • Economic changes

  • Catastrophe exposure

  • Regulatory changes

  • Third-party concentration


The risk assessment performed in January may not adequately describe the environment in October.


That is why ERM requires ongoing monitoring.


The CCS course specifically emphasizes monitoring and reporting as core elements of an effective ERM program.


AI Creates a New ERM Challenge

Artificial intelligence creates both opportunity and risk for insurance organizations.


Potential applications include:

  • Underwriting

  • Claims

  • Fraud detection

  • Customer service

  • Risk modeling

  • Compliance


But management should also consider:

  • Data quality

  • Bias

  • Privacy

  • Cybersecurity

  • Model governance

  • Regulatory exposure

  • Human oversight


AI should therefore become part of the ERM risk universe.


The question is not simply:

“Are we using AI?”

It is:

“What enterprise risks does AI create, and how are those risks being governed?”

What Participants Will Learn

The ERM Risk Assessment for Insurance Organizations program covers major areas including:

  • ERM fundamentals

  • NAIC and ERM requirements

  • Risk-management frameworks

  • Internal control systems

  • ORSA

  • Board and senior-management oversight

  • Reporting and disclosure

  • ERM implementation

  • Risk identification and assessment

  • Risk mitigation

  • Form F reporting


The emphasis is practical: participants should be able to take the concepts back to their organizations and strengthen their own ERM processes.


Who Should Attend?

The program is designed for:

  • Risk Managers

  • Compliance Officers

  • Internal Auditors

  • Insurance professionals responsible for governance and risk

  • Professionals involved with MAR, ORSA, or Form F compliance


The Bottom Line

Enterprise Risk Management in an insurance organization should not be reduced to:

  • A risk register

  • A regulatory filing

  • An annual workshop

  • A heat map


The objective is much larger.


Management should be able to demonstrate:

  • We understand our objectives.

  • We know what could prevent us from achieving them.

  • We have assessed those risks.

  • We understand our risk appetite.

  • We have appropriate controls and mitigation.

  • We know the residual risk.

  • We monitor changes.

  • We communicate significant risks to leadership and the Board.


That is enterprise risk management.


Corporate Compliance Seminars’ ERM Risk Assessment for Insurance Organizations program is designed to help insurance professionals build that discipline while connecting practical risk management with the regulatory expectations surrounding MAR, ORSA, and Form F.


Join CCS on Tuesday, October 20, 2026, and strengthen the ERM framework your organization relies on to protect capital, support compliance, improve decision-making, and build long-term resilience.

 
 
 

Recent Posts

See All
How Mature Are Your Monitoring Activities?

Measuring Whether Management Knows When Internal Controls Stop Working Every organization has internal controls. But here is the more difficult question: How does management know those controls are s

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page