ERM Risk Assessment for Insurance Organizations: Building a Risk Program That Management, the Board, and Regulators Can Actually Use
- John C. Blackshire, Jr.

- Aug 13
- 6 min read
Live CPE Webinar • Tuesday, October 20, 2026 • 4 CPE Credits
Insurance organizations exist to manage risk.
Yet many insurers still struggle to manage their own enterprise risks in a disciplined, integrated way.
That challenge is getting harder.
Insurance organizations must now evaluate not only traditional underwriting and financial risks, but also:
Operational risk
Strategic risk
Regulatory risk
Cybersecurity risk
Third-party risk
Technology risk
Capital and solvency risk
Governance risk
That is why Enterprise Risk Management should not be treated as a once-a-year exercise performed for a regulator.
It should be a management system.
Corporate Compliance Seminars’ ERM Risk Assessment for Insurance Organizations is a focused 4-CPE live program designed to help insurance professionals establish and maintain a practical ERM program while understanding key regulatory expectations involving the Model Audit Rule, Own Risk and Solvency Assessment, and NAIC Enterprise Risk Report—Form F. The next program is scheduled for Tuesday, October 20, 2026.
ERM Should Start With the Business
A risk register is not an ERM program.
A heat map is not an ERM program.
A Form F filing is not an ERM program.
Effective ERM begins with a much more fundamental question:
What are we trying to accomplish, and what could prevent us from accomplishing it?
For an insurance organization, those objectives may involve:
Maintaining adequate capital
Pricing risk appropriately
Paying claims accurately and timely
Protecting policyholder information
Meeting regulatory requirements
Maintaining strong distribution channels
Managing investments
Preserving reputation
Remaining financially resilient
The risk assessment should follow those objectives.
That creates a logical progression:
Objectives
↓
Risks
↓
Risk Assessment
↓
Risk Response
↓
Internal Controls
↓
Monitoring
↓
Reporting
That is much more valuable than starting with a generic list of risks.
Insurance ERM Has a Regulatory Dimension
Insurance organizations operate within a distinctive regulatory framework.
The CCS program specifically addresses ERM requirements and concepts associated with:
Model Audit Rule
Own Risk and Solvency Assessment
NAIC Enterprise Risk Report — Form F
These requirements are related but not identical.
The important point is that regulators increasingly expect insurers to demonstrate that enterprise risks are being:
Identified
Assessed
Governed
Monitored
Communicated
That makes ERM much more than a management preference.
It is also a governance and compliance discipline.
ORSA Forces Insurers to Think About Risk and Solvency Together
One of the most important insurance-specific ERM concepts is the Own Risk and Solvency Assessment—ORSA.
ORSA is intended to help insurers evaluate their own risk profile and determine whether their capital position remains appropriate in light of those risks.
The CCS course covers:
Purpose and objectives of ORSA
Key components of an ORSA program
The ORSA Summary Report
The NAIC continues to actively maintain and review the ORSA framework. In 2026, the NAIC’s ORSA Implementation Subgroup continued its work on ERM education for regulators and reviewed proposed changes to the ORSA Guidance Manual.
That reinforces an important point:
ORSA is not static.
Insurance organizations need ERM programs capable of adapting as risks and regulatory expectations evolve.
Form F Brings Enterprise Risk Into Regulatory Reporting
The NAIC Enterprise Risk Report—Form F is another important component of the insurance ERM framework.
Form F is intended to provide regulators with information about enterprise risks that could affect the insurer.
That can include risks arising from:
Affiliates
Holding-company relationships
Capital structure
Strategic initiatives
Operations
Financial exposures
The CCS program specifically includes Form F reporting and examples of effective risk reporting.
For Internal Audit and Risk Management, this raises an important question:
Does the regulatory filing accurately reflect what management and the Board actually understand about enterprise risk?
If the Board is discussing one set of major risks while Form F communicates something materially different, the organization may have a risk-governance problem.
Risk Assessment Is More Than a Heat Map
Risk assessments often end with a familiar matrix:
Likelihood × Impact
That can be useful.
But it is only the beginning.
A meaningful insurance risk assessment should also consider:
Velocity
Duration
Interdependencies
Control effectiveness
Residual risk
Capital implications
Regulatory consequences
Concentration risk
Consider cybersecurity.
A cyber event may have:
Financial impact
plus
Operational impact
plus
Regulatory impact
plus
Reputational impact.
One risk can affect multiple objectives.
That is why enterprise risk assessment needs to look across organizational silos.
Risk Identification Should Be Broad
CCS specifically focuses on financial, operational, strategic, and regulatory risks faced by insurance organizations.
Examples might include:
Financial Risk
Investment losses
Reserve uncertainty
Liquidity pressure
Capital deterioration
Operational Risk
Claims-processing failures
System outages
Third-party failures
Poor underwriting controls
Strategic Risk
Product strategy
Distribution disruption
Market changes
Acquisition risk
Regulatory Risk
NAIC requirements
State insurance laws
Cybersecurity regulations
Market conduct requirements
The purpose is not to create the longest risk inventory possible.
It is to identify the risks capable of materially affecting the organization's objectives.
Risk Appetite Turns ERM Into Decision-Making
One of the most important components of a mature ERM program is a risk appetite statement.
CCS includes developing risk appetite statements among the program’s implementation best practices.
A risk appetite helps management answer:
How much risk are we willing to accept while pursuing our objectives?
That becomes important when deciding:
How much capital to hold
Which markets to enter
Which products to offer
Which risks to insure
How much cybersecurity exposure is acceptable
Which third-party arrangements are appropriate
Without defined risk appetite, organizations can end up making inconsistent risk decisions.
Inherent Risk and Residual Risk Are Different
A useful ERM distinction is:
Inherent Risk — risk before considering controls.
Residual Risk — risk remaining after controls and mitigation.
Suppose ransomware represents a high inherent risk.
Management implements:
Multifactor authentication
Segmentation
Backups
Monitoring
Incident-response procedures
The residual risk may be lower.
But it is not zero.
The Board should understand the residual exposure it is accepting.
That is where ERM connects directly to governance.
Internal Controls Are One Risk Response—Not the Only One
CCS teaches several risk-management approaches, including:
Internal controls
Risk transfer
Risk acceptance
Organizations generally have four broad choices:
Avoid - Stop the activity.
Reduce - Implement controls.
Transfer - Use insurance, contracts, or other mechanisms.
Accept - Consciously retain the risk.
The important word is consciously.
Risk acceptance should not mean:
“Nobody fixed it.”
It should mean:
“Management understands the exposure and the appropriate authority has accepted it.”
The Board Has a Critical ERM Role
CCS places significant emphasis on Board and senior-management oversight.
That is appropriate because ERM cannot succeed as a Risk Management Department project.
Senior management and the Board should understand:
Major enterprise risks
Risk appetite
Risk concentrations
Emerging risks
Residual risk
Significant control failures
Corrective actions
The Board does not operate the controls.
But it should understand whether management has built an effective system for managing risk.
Internal Audit Has a Different Role
Internal Audit should not own ERM.
Management owns risk.
Risk Management may facilitate the process.
Internal Audit provides assurance.
Internal Audit can evaluate:
Risk-assessment methodology
Completeness of the risk universe
Governance
Risk reporting
Internal controls
Follow-up
Alignment with regulatory requirements
The key question is:
Can the Board rely on management's ERM process?
That is an assurance question.
Risk Reporting Must Be Useful
A risk report containing 150 risks can technically be complete and practically useless.
Senior management and Boards need clarity.
Useful reporting may show:
Top enterprise risks
Risk trend
Risk owner
Inherent risk
Residual risk
Controls
Mitigation
Status
Emerging issues
The CCS program specifically addresses ongoing monitoring, reporting, and communicating risk to stakeholders.
A good risk report should help someone make a decision.
If it does not, it may be reporting activity rather than managing risk.
Emerging Risk Requires Continuous Monitoring
Insurance risk changes continuously.
Examples include:
Cyber threats
AI adoption
Economic changes
Catastrophe exposure
Regulatory changes
Third-party concentration
The risk assessment performed in January may not adequately describe the environment in October.
That is why ERM requires ongoing monitoring.
The CCS course specifically emphasizes monitoring and reporting as core elements of an effective ERM program.
AI Creates a New ERM Challenge
Artificial intelligence creates both opportunity and risk for insurance organizations.
Potential applications include:
Underwriting
Claims
Fraud detection
Customer service
Risk modeling
Compliance
But management should also consider:
Data quality
Bias
Privacy
Cybersecurity
Model governance
Regulatory exposure
Human oversight
AI should therefore become part of the ERM risk universe.
The question is not simply:
“Are we using AI?”
It is:
“What enterprise risks does AI create, and how are those risks being governed?”
What Participants Will Learn
The ERM Risk Assessment for Insurance Organizations program covers major areas including:
ERM fundamentals
NAIC and ERM requirements
Risk-management frameworks
Internal control systems
ORSA
Board and senior-management oversight
Reporting and disclosure
ERM implementation
Risk identification and assessment
Risk mitigation
Form F reporting
The emphasis is practical: participants should be able to take the concepts back to their organizations and strengthen their own ERM processes.
Who Should Attend?
The program is designed for:
Risk Managers
Compliance Officers
Internal Auditors
Insurance professionals responsible for governance and risk
Professionals involved with MAR, ORSA, or Form F compliance
The Bottom Line
Enterprise Risk Management in an insurance organization should not be reduced to:
A risk register
A regulatory filing
An annual workshop
A heat map
The objective is much larger.
Management should be able to demonstrate:
We understand our objectives.
We know what could prevent us from achieving them.
We have assessed those risks.
We understand our risk appetite.
We have appropriate controls and mitigation.
We know the residual risk.
We monitor changes.
We communicate significant risks to leadership and the Board.
That is enterprise risk management.
Corporate Compliance Seminars’ ERM Risk Assessment for Insurance Organizations program is designed to help insurance professionals build that discipline while connecting practical risk management with the regulatory expectations surrounding MAR, ORSA, and Form F.
Join CCS on Tuesday, October 20, 2026, and strengthen the ERM framework your organization relies on to protect capital, support compliance, improve decision-making, and build long-term resilience.
Comments