Insurance Industry Entity-Level Controls: Building the Foundation for MAR Compliance
- John C. Blackshire, Jr.

- Aug 13
- 8 min read
When insurance organizations think about internal controls, attention often goes immediately to transaction-level controls.
Was the claim approved?
Was the journal entry reviewed?
Was the reconciliation completed?
Was access appropriately authorized?
Those controls matter.
But there is a more fundamental question:
What happens when the controls governing the entire organization are weak?
That is where Entity-Level Controls—ELCs become critical.
Entity-level controls establish the governance, accountability, risk management, monitoring, ethics, and oversight environment within which individual process controls operate.
For insurance organizations subject to the NAIC Model Audit Rule (MAR)—and for public organizations subject to Sarbanes-Oxley requirements—effective entity-level controls provide a foundation for reliable financial reporting and an effective system of internal control.
Corporate Compliance Seminars' Insurance Industry Entity Level Controls program is a focused 4-CPE training event designed to help insurance Internal Audit, Risk, Compliance, and Internal Control professionals assess, develop, implement, test, document, and monitor ELCs.
The next program is scheduled for Tuesday, October 13, 2026.
What Are Entity-Level Controls?
Entity-level controls operate broadly across an organization rather than within a single transaction or business process.
Think about the difference.
A control requiring approval of a claim payment is a process-level control.
A control requiring the Board and Audit Committee to oversee financial reporting and significant internal-control deficiencies is an entity-level control.
ELCs may address areas such as:
Governance
Management oversight
Ethical expectations
Risk assessment
Delegation of authority
Organizational accountability
Fraud-risk management
Internal Audit
Audit Committee oversight
Monitoring of internal controls
Communication of deficiencies
Corrective-action processes
CCS's program approaches ELCs specifically from the insurance industry's MAR and SOX compliance perspective, including assessment, implementation, testing, documentation, and reporting.
ELCs Create the Environment in Which Other Controls Operate
Consider a claims department with excellent written procedures.
Employees are required to obtain appropriate approval.
Segregation of duties is documented.
System access is restricted.
Management receives exception reports.
On paper, everything looks good.
But suppose senior management routinely overrides those controls whenever meeting a financial objective becomes difficult.
The process-level controls may be well designed.
The entity-level control environment is not.
This illustrates why auditors cannot evaluate internal control solely by looking at individual transactions.
The organization surrounding those transactions matters.
Start With the Control Environment
A strong entity-level control framework begins with the organization's control environment.
Questions include:
Does senior management demonstrate that internal control actually matters?
Are responsibilities clearly assigned?
Does the Audit Committee provide meaningful oversight?
Are ethical expectations communicated and enforced?
Are significant control deficiencies escalated?
Does management hold people accountable for corrective action?
These questions can be more consequential than whether someone initialed a checklist.
The control environment influences how employees behave when nobody is watching.
Tone at the Top Is an Internal Control
Organizations frequently state:
“We have a strong tone at the top.”
That statement needs evidence.
Internal Audit should consider what management actually does when:
A significant control deficiency is identified
Someone raises an ethical concern
A financial target is missed
A manager overrides a control
A regulatory issue emerges
Internal Audit reports bad news
The real tone at the top is demonstrated by behavior.
A Code of Conduct does not establish an ethical culture by itself.
The Audit Committee Is an Entity-Level Control
The Audit Committee can be one of an insurance organization's most important entity-level controls.
Its effectiveness depends on more than holding scheduled meetings.
A strong Audit Committee should receive meaningful information about:
Financial reporting
Internal controls
External Audit
Internal Audit
Significant deficiencies
Fraud risk
Regulatory matters
Corrective action
The CCS program emphasizes transparent reporting of control deficiencies to management and the Audit Committee as part of an effective ELC program.
The question should not simply be:
“Did the Audit Committee meet?”
Ask:
“Did the Audit Committee receive sufficient information to exercise effective oversight?”
That is a much stronger control question.
Entity-Level Controls and the NAIC Model Audit Rule
The Model Audit Rule places significant emphasis on governance and internal control over financial reporting.
That means insurance organizations need to think beyond isolated accounting controls.
CCS's course specifically addresses regulatory requirements affecting ELCs, including the NAIC Model Audit Rule, NAIC corporate governance expectations, and SOX concepts applicable to organizations within its scope.
A mature MAR program should be able to connect:
Governance
↓
Financial Reporting Objectives
↓
Risks
↓
Entity-Level Controls
↓
Process-Level Controls
↓
Testing
↓
Deficiencies
↓
Corrective Action
↓
Management and Audit Committee Reporting
That creates a defensible internal-control architecture.
Risk Assessment Is an Entity-Level Control
Management should have a disciplined process for identifying and assessing risks affecting financial reporting.
That includes asking:
What could go wrong?
How significant could the impact be?
How likely is it?
What controls address the risk?
Who owns those controls?
What residual risk remains?
Without a sound risk-assessment process, organizations can accumulate controls without knowing whether those controls address the risks that actually matter.
That produces compliance activity rather than effective risk management.
Fraud Risk Belongs at the Entity Level
Fraud risk should not be confined to transaction testing.
The organization should consider broader questions involving:
Management override
Incentive structures
Conflicts of interest
Related-party relationships
Whistleblower mechanisms
Ethical culture
Investigation protocols
A transaction-level control might detect an inappropriate payment.
A strong entity-level control environment should also ask:
What conditions within our organization could allow inappropriate behavior to develop, continue, or remain concealed?
That is a governance question.
Management Override Can Defeat Excellent Controls
Management override deserves special attention because senior executives may possess the authority to bypass controls that work perfectly for everyone else.
Imagine an organization with a strong journal-entry approval process.
But a senior financial executive can instruct employees:
“Post it. I'll approve it later.”
The documented control still exists.
Employees may still perform it correctly under normal circumstances.
But management override changes the risk.
Entity-level controls should address whether overrides are:
Authorized
Documented
Visible
Reviewed
Escalated when necessary
A control environment that tolerates undocumented management override is fundamentally weaker.
The Five Human Behaviors That Can Undermine ELCs
Entity-level controls ultimately involve people.
That means insurance organizations should pay attention to behaviors such as:
Denial — “We don't have a problem.”
Rationalization — “There is a good reason we do it this way.”
Defensiveness — “You're criticizing me.”
Fear — “What happens if I tell you the truth?”
Resistance to Change — “We've always done it this way.”
These behaviors affect the control environment.
An organization can have excellent policies and still develop a weak control culture if employees learn that raising problems is discouraged or management override is tolerated.
Assess the Controls That Already Exist
CCS begins its practical ELC methodology by examining the organization's current controls and identifying financial-reporting areas relevant to the company.
That is important.
Do not immediately start creating new controls.
First determine:
What risks exist?
What controls already address them?
Which controls are important?
Where are the gaps?
Are existing controls properly designed?
Are redundant controls creating unnecessary work?
Adding another control is not automatically the answer.
Sometimes the better solution is improving an existing control.
Design Effectiveness Comes Before Operating Effectiveness
This distinction is critical.
Before asking whether a control operated, ask:
Is the control capable of accomplishing its objective?
Suppose management performs an annual review of the organization's Code of Conduct.
The review occurs every year.
It is documented.
It is signed.
That establishes operating consistency.
But does the control actually help management determine whether ethical expectations are understood and followed?
Maybe.
Maybe not.
Testing execution without first evaluating design can create false assurance.
Control Self-Assessment Can Strengthen Ownership
The CCS course specifically incorporates control self-assessment as a mechanism for regularly evaluating ELC effectiveness.
This can be valuable because management owns internal control.
A well-designed self-assessment process asks control owners to evaluate:
Whether the control remains relevant
Whether it operated
Whether evidence exists
Whether exceptions occurred
Whether changes are needed
Internal Audit can then independently evaluate that process rather than becoming the owner of the controls.
Documentation Is More Than a Compliance Exercise
A strong ELC program should create a traceable relationship among:
Risk → Control → Owner → Evidence → Testing → Conclusion → Corrective Action
That documentation becomes valuable when:
Management evaluates MAR compliance
Internal Audit performs testing
External auditors evaluate controls
Regulators conduct examinations
Audit Committees oversee deficiencies
CCS emphasizes maintaining detailed documentation covering the assessment, planning, implementation, testing, and subsequent updating of ELCs.
Evidence Matters
Suppose management states:
“The Audit Committee provides effective oversight.”
What evidence supports that conclusion?
Possibilities could include:
Charter responsibilities
Meeting agendas
Materials provided
Minutes
Internal Audit reporting
External Audit communications
Deficiency tracking
Follow-up discussions
The existence of an Audit Committee is not evidence that the Audit Committee is effective.
The same principle applies throughout the ELC framework.
Monitoring Keeps ELCs From Becoming Stale
Organizations change.
Management changes.
Systems change.
Products change.
Regulations change.
Risks change.
An entity-level control assessment completed three years ago may no longer reflect today's organization.
That is why CCS emphasizes continuous monitoring and regular updates as part of maintaining an effective ELC framework.
The control environment needs to evolve with the business.
AI Is Becoming an Entity-Level Control Issue
Artificial intelligence makes ELCs even more important.
Insurance organizations are adopting AI for activities involving:
Underwriting
Claims
Fraud detection
Customer service
Finance
Compliance
Internal Audit
That raises entity-level governance questions:
Who approves AI use?
What uses are prohibited?
What information can employees enter?
Who owns AI risk?
How are outputs validated?
How are significant AI risks communicated to governance?
These are not merely application-level technology questions.
They are questions about governance, authority, risk management, monitoring, and accountability—the heart of entity-level control.
Reporting Deficiencies Is Part of the Control System
Identifying a deficiency is not enough.
The organization needs a process for determining:
Severity
Ownership
Corrective action
Due date
Escalation
Closure
Validation
CCS specifically includes monitoring and reporting deficiencies to management and the Audit Committee among the core actions covered by the program.
A deficiency that remains buried in a spreadsheet is not being effectively governed.
Repeat Findings Should Get Management's Attention
When the same control deficiency appears repeatedly, the organization should ask:
Why didn't the prior corrective action work?
Possibilities include:
Wrong root cause
Weak management ownership
Insufficient resources
Poorly designed corrective action
Lack of accountability
Resistance to change
A repeat finding can therefore reveal an entity-level weakness even when the original finding involved a transaction-level control.
Internal Audit Has an Important—but Independent—Role
Internal Audit can evaluate whether the organization's ELC framework is appropriately designed and operating effectively.
It can assess:
Governance
Risk assessment
Monitoring
Management oversight
Deficiency reporting
Corrective action
Control culture
But Internal Audit should not become management's control owner.
Management owns internal control.
Internal Audit independently evaluates it.
Maintaining that distinction strengthens the assurance provided to the Audit Committee.
What Participants Will Learn
CCS's Insurance Industry Entity Level Controls program takes participants through the complete ELC lifecycle: assessing current controls, developing a MAR-oriented control plan, implementing controls through processes, procedures, and systems, testing through control self-assessment, documenting the control framework, and monitoring and reporting deficiencies.
Participants will also examine regulatory requirements, testing and monitoring techniques, documentation practices, continuous improvement, and practical case studies.
Who Should Attend?
This program is particularly appropriate for:
Internal Auditors
Risk Management professionals
Internal Control professionals
Compliance Managers
MAR compliance professionals
Financial-reporting professionals
Professionals responsible for insurance governance and control programs
The program is classified as Intermediate to Advanced, and participants should have prior knowledge of internal-control frameworks.
The Bottom Line
Entity-level controls answer some of the biggest questions in an insurance organization's internal-control system:
Does management create an effective control environment?
Does governance receive the information it needs?
Does the organization systematically identify risk?
Are people held accountable for controls?
Can employees raise concerns?
Are deficiencies corrected?
Does the Audit Committee provide meaningful oversight?
A weak transaction-level control can create an isolated problem.
A weak entity-level control environment can undermine controls throughout the organization.
That is why ELCs deserve serious attention within an insurance company's Model Audit Rule compliance program.
Corporate Compliance Seminars' Insurance Industry Entity Level Controls program on Tuesday, October 13, 2026 is designed to help insurance professionals move beyond simply documenting controls and develop a framework for assessing, implementing, testing, monitoring, and improving the controls that govern the organization as a whole.
Comments