ITGCs for NAIC Model Audit Rule Programs: Why Technology Controls Are Critical to Insurance Financial Reporting
- John C. Blackshire, Jr.

- Aug 13
- 8 min read
Live CPE Webinar • Tuesday, September 22, 2026 • 2 CPE Credits
Insurance companies increasingly depend on technology to support:
Financial reporting
Claims processing
Policy administration
Premium billing
Investments
Reinsurance
Regulatory reporting
General ledger processing
Management reporting
That makes Information Technology General Controls—ITGCs a critical part of the internal-control environment supporting compliance with the NAIC Model Audit Rule, formally known as the Annual Financial Reporting Model Regulation, Model #205. The NAIC continues to actively maintain Model #205 and its implementation guidance as part of its financial solvency and reporting framework.
Corporate Compliance Seminars' ITGCs for NAIC Model Audit Rule Programs is a focused two-hour CPE webinar designed specifically for insurance professionals responsible for IT controls, Internal Audit, compliance, and financial reporting. The next live event is scheduled for Tuesday, September 22, 2026. The program provides 2 NASBA-approved CPE credits and focuses on six core ITGC areas: access controls, change management, backup and recovery, program development and maintenance, IT operations, and IT security.
The Model Audit Rule Is Not Just an Accounting Department Requirement
Insurance companies sometimes approach MAR compliance primarily as a Finance or Accounting exercise.
That is too narrow.
Modern financial reporting depends on technology.
Consider a financial statement account generated through an insurance company's policy-administration system.
The financial control may depend on:
Data entered into an application
↓
System processing
↓
Automated calculations
↓
Interfaces
↓
Reports
↓
Management review
↓
Financial reporting
If the technology supporting that chain cannot be trusted, the financial controls sitting above it may also become unreliable.
That is why ITGCs matter.
CCS specifically designed this program to help insurance professionals understand how IT controls support the accuracy and reliability of financial reporting and how those controls should be incorporated into a Model Audit Rule compliance framework.
What Are IT General Controls?
ITGCs are controls that operate across an organization's technology environment and provide a foundation for systems, applications, automated controls, and electronic information.
Six areas are emphasized in the CCS program:
1. Access Controls
Who can access systems and information?
2. Change Management
Who can change applications, configurations, and systems?
3. Data Backup and Recovery
Can critical information be recovered after a failure?
4. Program Development and Maintenance
How are applications developed, modified, tested, and maintained?
5. IT Operations
Are systems operating reliably and exceptions being addressed?
6. IT Security
Is technology appropriately protected against unauthorized activity?
Each of these areas can directly affect financial reporting.
Access Controls: Who Can Do What?
One of the most important ITGC questions is simple:
Who has access to what?
Insurance organizations often operate multiple applications involving:
Policy administration
Claims
Billing
General ledger
Investments
Reinsurance
Actuarial information
Employees may need significant access to perform their jobs.
But inappropriate access can create risk.
Consider an employee who can:
Create or modify policyholder information
Change payment instructions
Approve transactions
Modify accounting data
The question becomes whether incompatible access allows one person to initiate and conceal an inappropriate transaction.
Strong access controls generally address:
New user provisioning
User transfers
Employee terminations
Privileged access
Periodic access reviews
Segregation of duties
The CCS program specifically addresses strategies for managing access permissions as a core MAR ITGC discipline.
Privileged Access Deserves Special Attention
Privileged users can sometimes:
Create other users
Change configurations
Reset passwords
Modify security settings
Access sensitive data
Alter system functionality
That creates concentrated risk.
Internal Audit and compliance professionals should ask:
Who has privileged access?
Why do they need it?
Who approved it?
Is privileged activity monitored?
Is access removed when no longer necessary?
A weak privileged-access environment can undermine multiple automated financial controls simultaneously.
Change Management: What Happens When the System Changes?
Insurance technology is continuously changing.
Organizations:
Update applications
Modify configurations
Install patches
Change interfaces
Implement new products
Correct defects
Every change creates risk.
A poorly controlled system change could affect:
Premium calculations
Claim reserves
Policy values
Financial interfaces
Regulatory reports
Strong change-management controls generally address:
Request
↓
Approval
↓
Development
↓
Testing
↓
Implementation
↓
Post-implementation monitoring
CCS specifically identifies secure change handling as one of the fundamental ITGC capabilities participants will develop.
Segregation of Duties Applies to IT Too
Suppose the same programmer can:
Develop a system change.
Test the change.
Approve it.
Move it directly into production.
That may be efficient.
It may also represent a serious internal-control problem.
The same principle auditors use in financial processes applies to technology:
Do not allow one person to control incompatible parts of a high-risk process without appropriate oversight.
That is why change management and access control frequently need to be evaluated together.
Backup and Recovery Controls Matter Because Financial Information Must Survive
Backup is sometimes treated as purely a disaster-recovery concern.
For an insurance organization, it is also a financial-reporting concern.
What happens if:
Policy data are lost?
Claim information is corrupted?
General ledger information becomes unavailable?
Regulatory reporting data cannot be restored?
CCS includes backup and recovery as one of its six critical ITGC categories and specifically addresses effective data-recovery procedures.
The auditor should not simply ask:
“Are backups performed?”
The better questions are:
Can they actually be restored?
When was recovery last tested?
A backup that cannot be restored is not much of a control.
Program Development and Maintenance Can Affect Financial Reporting
Insurance companies frequently develop or customize applications.
That creates another important control area.
Auditors should consider whether:
Development requirements are documented
Changes are appropriately tested
Users approve functionality
Security requirements are addressed
Financial calculations are validated
CCS specifically addresses program-development controls designed to prevent errors and vulnerabilities.
A system may perform exactly as programmed.
The problem occurs when it was programmed incorrectly.
IT Operations Keep the Control Environment Running
IT operations include the routine activities necessary to keep systems functioning.
Examples include:
Batch processing
Interfaces
Scheduled jobs
Exception management
Incident handling
System monitoring
Suppose an interface transfers claim information into the general ledger.
What happens if the interface fails?
Does anyone know?
Who investigates?
How does Finance determine whether every transaction transferred successfully?
A technical problem can quickly become a financial reporting problem.
That is why IT operations belong inside the MAR control environment.
IT Security Is Also a Financial Reporting Issue
Cybersecurity and financial reporting are increasingly connected.
An attacker—or malicious insider—who gains inappropriate system access could potentially:
Modify financial information
Alter payment instructions
Change policy data
Manipulate transactions
Disable controls
Therefore, IT security cannot always be separated from financial-reporting control.
CCS includes IT security as one of the six core control categories addressed in its MAR ITGC program.
ITGCs Support Internal Control Over Financial Reporting
The central relationship is:
ITGCs
↓
Reliable Systems
↓
Reliable Application Controls and Reports
↓
Reliable Financial Processes
↓
Reliable Financial Reporting
CCS explicitly identifies the role of ITGCs in supporting internal control over financial reporting as part of the course agenda.
That is why ITGCs should not be treated as a separate technology project disconnected from MAR.
They are part of the control architecture supporting financial reporting.
The NAIC Continues to Focus on IT General Controls
The importance of ITGCs is not merely theoretical. The NAIC's Examination Oversight Task Force states that part of its mission is to maintain an effective approach to reviewing information technology general controls as part of the insurance regulatory examination process.
That provides a clear message for insurers:
Technology controls are part of the regulatory control environment.
Insurance organizations should expect their IT control frameworks to withstand scrutiny from internal auditors, external auditors, and regulators.
Testing Design Effectiveness Comes First
Before testing whether an ITGC operated, determine whether it is properly designed.
Consider:
“Management reviews privileged access quarterly.”
That sounds reasonable.
But ask:
Who performs the review?
Is the reviewer independent?
Is the access list complete?
What constitutes inappropriate access?
What happens when an exception is identified?
If the control is incapable of identifying inappropriate access, testing four quarterly signatures accomplishes very little.
The first question is:
Could this control actually address the risk?
Then test whether it operated.
Operating Effectiveness Requires Evidence
Once the control is appropriately designed, the auditor needs evidence that it actually operated.
Possible evidence may include:
Access approval records
User-access reviews
Change tickets
Testing documentation
System logs
Backup reports
Incident records
Recovery tests
CCS specifically includes techniques for testing and monitoring ITGC processes and preparing for MAR compliance assessments.
The workpaper should demonstrate more than:
“Control tested.”
It should explain what evidence supports the conclusion.
Testing a Signature Is Not Testing the Control
This mistake occurs in IT controls just as it does in financial controls.
Suppose an IT manager signs a quarterly access review.
The auditor finds four signatures.
Did the control operate effectively?
Maybe.
The auditor still needs to understand:
What did the manager review?
What information was used?
Was it complete?
Which exceptions were identified?
What happened to inappropriate access?
A signature proves that someone signed something.
It does not automatically establish effective review.
MAR ITGC Compliance Requires Cooperation Across Functions
An effective ITGC program cannot be owned by one department.
It may require cooperation among:
Information Technology
Information Security
Finance
Compliance
Internal Audit
Risk Management
External Audit
Finance understands the reporting requirements.
IT understands the systems.
Information Security understands technology risk.
Compliance understands regulatory expectations.
Internal Audit provides independent assurance.
The program works when those functions understand their respective responsibilities.
Internal Audit Should Not Own the Controls
Internal Audit can:
Evaluate control design
Test operating effectiveness
Identify gaps
Recommend improvements
Monitor remediation
But Internal Audit should not become responsible for operating the ITGC program.
Management owns the controls.
That distinction protects independence.
ITGC Documentation Matters
A strong MAR ITGC framework should document:
Control objective
Risk
Control description
Control owner
Frequency
Evidence
Testing
Exceptions
Corrective action
This produces a clear audit trail:
Risk → Control → Evidence → Test → Conclusion
When external auditors or regulators ask how the organization knows an IT control is effective, the answer should be visible in the documentation.
Artificial Intelligence Makes ITGCs Even More Important
Insurance organizations are rapidly adopting AI for:
Claims analysis
Underwriting
Fraud detection
Customer service
Finance
Reporting
AI creates new technology-control questions:
Who can access the tool?
What data can be entered?
Who approves changes?
How are outputs validated?
How is confidential information protected?
Who monitors its use?
The technology may be new.
The control concepts are familiar:
Access.
Change.
Security.
Operations.
Monitoring.
Strong ITGC disciplines provide a useful foundation for governing new technology.
What Participants Will Learn
Corporate Compliance Seminars' ITGCs for NAIC Model Audit Rule Programs provides concentrated training in five major areas:
Introduction to the NAIC Model Audit Rule and ITGCs
Six key ITGC categories
Framework development and policy implementation
ITGC testing and MAR compliance readiness
Case studies and continuous improvement
Participants will learn how to:
Understand ITGCs supporting financial reporting
Develop practical ITGC frameworks
Manage system access
Control changes
Strengthen backup and recovery
Address program development
Evaluate IT operations
Improve IT security
Test and monitor IT controls
Prepare for MAR assessments and external audits
Who Should Attend?
The program is designed specifically for professionals working in the insurance industry, including:
Internal Auditors
IT Auditors
IT Professionals
Compliance Specialists
SOX/MAR professionals
Financial-reporting professionals
Professionals responsible for insurance IT controls
The Bottom Line
The Model Audit Rule is ultimately about reliable financial reporting, governance, accountability, and internal control.
In a technology-dependent insurance organization, those objectives cannot be achieved without strong IT controls.
Insurance companies should be able to answer:
Who has access to our systems?
Who can change them?
How are changes tested?
Can critical information be recovered?
Are system operations monitored?
Is financial information protected?
How do we know these controls actually work?
Those are ITGC questions.
They are also Model Audit Rule questions.
Corporate Compliance Seminars' ITGCs for NAIC Model Audit Rule Programs is designed to help insurance professionals connect the two and build technology-control frameworks that support reliable financial reporting, stronger internal control, and better regulatory readiness.
Join CCS on Tuesday, September 22, 2026, for this focused two-hour program and strengthen the technology foundation underneath your organization's Model Audit Rule compliance program.
Comments