top of page
Search

ITGCs for NAIC Model Audit Rule Programs: Why Technology Controls Are Critical to Insurance Financial Reporting

Live CPE Webinar • Tuesday, September 22, 2026 • 2 CPE Credits


Insurance companies increasingly depend on technology to support:

  • Financial reporting

  • Claims processing

  • Policy administration

  • Premium billing

  • Investments

  • Reinsurance

  • Regulatory reporting

  • General ledger processing

  • Management reporting


That makes Information Technology General Controls—ITGCs a critical part of the internal-control environment supporting compliance with the NAIC Model Audit Rule, formally known as the Annual Financial Reporting Model Regulation, Model #205. The NAIC continues to actively maintain Model #205 and its implementation guidance as part of its financial solvency and reporting framework.


Corporate Compliance Seminars' ITGCs for NAIC Model Audit Rule Programs is a focused two-hour CPE webinar designed specifically for insurance professionals responsible for IT controls, Internal Audit, compliance, and financial reporting. The next live event is scheduled for Tuesday, September 22, 2026. The program provides 2 NASBA-approved CPE credits and focuses on six core ITGC areas: access controls, change management, backup and recovery, program development and maintenance, IT operations, and IT security.


The Model Audit Rule Is Not Just an Accounting Department Requirement

Insurance companies sometimes approach MAR compliance primarily as a Finance or Accounting exercise.


That is too narrow.


Modern financial reporting depends on technology.


Consider a financial statement account generated through an insurance company's policy-administration system.


The financial control may depend on:

Data entered into an application

System processing

Automated calculations

Interfaces

Reports

Management review

Financial reporting


If the technology supporting that chain cannot be trusted, the financial controls sitting above it may also become unreliable.


That is why ITGCs matter.


CCS specifically designed this program to help insurance professionals understand how IT controls support the accuracy and reliability of financial reporting and how those controls should be incorporated into a Model Audit Rule compliance framework.


What Are IT General Controls?

ITGCs are controls that operate across an organization's technology environment and provide a foundation for systems, applications, automated controls, and electronic information.


Six areas are emphasized in the CCS program:

1. Access Controls

Who can access systems and information?

2. Change Management

Who can change applications, configurations, and systems?

3. Data Backup and Recovery

Can critical information be recovered after a failure?

4. Program Development and Maintenance

How are applications developed, modified, tested, and maintained?

5. IT Operations

Are systems operating reliably and exceptions being addressed?

6. IT Security

Is technology appropriately protected against unauthorized activity?


Each of these areas can directly affect financial reporting.


Access Controls: Who Can Do What?

One of the most important ITGC questions is simple:

Who has access to what?

Insurance organizations often operate multiple applications involving:

  • Policy administration

  • Claims

  • Billing

  • General ledger

  • Investments

  • Reinsurance

  • Actuarial information


Employees may need significant access to perform their jobs.


But inappropriate access can create risk.


Consider an employee who can:

  • Create or modify policyholder information

  • Change payment instructions

  • Approve transactions

  • Modify accounting data


The question becomes whether incompatible access allows one person to initiate and conceal an inappropriate transaction.


Strong access controls generally address:

  • New user provisioning

  • User transfers

  • Employee terminations

  • Privileged access

  • Periodic access reviews

  • Segregation of duties


The CCS program specifically addresses strategies for managing access permissions as a core MAR ITGC discipline.


Privileged Access Deserves Special Attention

Privileged users can sometimes:

  • Create other users

  • Change configurations

  • Reset passwords

  • Modify security settings

  • Access sensitive data

  • Alter system functionality


That creates concentrated risk.


Internal Audit and compliance professionals should ask:

Who has privileged access?
Why do they need it?
Who approved it?
Is privileged activity monitored?
Is access removed when no longer necessary?

A weak privileged-access environment can undermine multiple automated financial controls simultaneously.


Change Management: What Happens When the System Changes?

Insurance technology is continuously changing.


Organizations:

  • Update applications

  • Modify configurations

  • Install patches

  • Change interfaces

  • Implement new products

  • Correct defects


Every change creates risk.


A poorly controlled system change could affect:

  • Premium calculations

  • Claim reserves

  • Policy values

  • Financial interfaces

  • Regulatory reports


Strong change-management controls generally address:

Request

Approval

Development

Testing

Implementation

Post-implementation monitoring


CCS specifically identifies secure change handling as one of the fundamental ITGC capabilities participants will develop.


Segregation of Duties Applies to IT Too

Suppose the same programmer can:

  1. Develop a system change.

  2. Test the change.

  3. Approve it.

  4. Move it directly into production.


That may be efficient.


It may also represent a serious internal-control problem.


The same principle auditors use in financial processes applies to technology:

Do not allow one person to control incompatible parts of a high-risk process without appropriate oversight.

That is why change management and access control frequently need to be evaluated together.


Backup and Recovery Controls Matter Because Financial Information Must Survive

Backup is sometimes treated as purely a disaster-recovery concern.


For an insurance organization, it is also a financial-reporting concern.


What happens if:

  • Policy data are lost?

  • Claim information is corrupted?

  • General ledger information becomes unavailable?

  • Regulatory reporting data cannot be restored?


CCS includes backup and recovery as one of its six critical ITGC categories and specifically addresses effective data-recovery procedures.


The auditor should not simply ask:

“Are backups performed?”

The better questions are:

Can they actually be restored?
When was recovery last tested?

A backup that cannot be restored is not much of a control.


Program Development and Maintenance Can Affect Financial Reporting

Insurance companies frequently develop or customize applications.


That creates another important control area.


Auditors should consider whether:

  • Development requirements are documented

  • Changes are appropriately tested

  • Users approve functionality

  • Security requirements are addressed

  • Financial calculations are validated


CCS specifically addresses program-development controls designed to prevent errors and vulnerabilities.


A system may perform exactly as programmed.


The problem occurs when it was programmed incorrectly.


IT Operations Keep the Control Environment Running

IT operations include the routine activities necessary to keep systems functioning.


Examples include:

  • Batch processing

  • Interfaces

  • Scheduled jobs

  • Exception management

  • Incident handling

  • System monitoring


Suppose an interface transfers claim information into the general ledger.


What happens if the interface fails?


Does anyone know?


Who investigates?


How does Finance determine whether every transaction transferred successfully?


A technical problem can quickly become a financial reporting problem.


That is why IT operations belong inside the MAR control environment.


IT Security Is Also a Financial Reporting Issue

Cybersecurity and financial reporting are increasingly connected.


An attacker—or malicious insider—who gains inappropriate system access could potentially:

  • Modify financial information

  • Alter payment instructions

  • Change policy data

  • Manipulate transactions

  • Disable controls


Therefore, IT security cannot always be separated from financial-reporting control.


CCS includes IT security as one of the six core control categories addressed in its MAR ITGC program.


ITGCs Support Internal Control Over Financial Reporting

The central relationship is:

ITGCs

Reliable Systems

Reliable Application Controls and Reports

Reliable Financial Processes

Reliable Financial Reporting


CCS explicitly identifies the role of ITGCs in supporting internal control over financial reporting as part of the course agenda.


That is why ITGCs should not be treated as a separate technology project disconnected from MAR.


They are part of the control architecture supporting financial reporting.


The NAIC Continues to Focus on IT General Controls

The importance of ITGCs is not merely theoretical. The NAIC's Examination Oversight Task Force states that part of its mission is to maintain an effective approach to reviewing information technology general controls as part of the insurance regulatory examination process.


That provides a clear message for insurers:

Technology controls are part of the regulatory control environment.

Insurance organizations should expect their IT control frameworks to withstand scrutiny from internal auditors, external auditors, and regulators.


Testing Design Effectiveness Comes First

Before testing whether an ITGC operated, determine whether it is properly designed.


Consider:

“Management reviews privileged access quarterly.”

That sounds reasonable.


But ask:

  • Who performs the review?

  • Is the reviewer independent?

  • Is the access list complete?

  • What constitutes inappropriate access?

  • What happens when an exception is identified?


If the control is incapable of identifying inappropriate access, testing four quarterly signatures accomplishes very little.


The first question is:

Could this control actually address the risk?

Then test whether it operated.


Operating Effectiveness Requires Evidence

Once the control is appropriately designed, the auditor needs evidence that it actually operated.


Possible evidence may include:

  • Access approval records

  • User-access reviews

  • Change tickets

  • Testing documentation

  • System logs

  • Backup reports

  • Incident records

  • Recovery tests


CCS specifically includes techniques for testing and monitoring ITGC processes and preparing for MAR compliance assessments.


The workpaper should demonstrate more than:

“Control tested.”

It should explain what evidence supports the conclusion.


Testing a Signature Is Not Testing the Control

This mistake occurs in IT controls just as it does in financial controls.


Suppose an IT manager signs a quarterly access review.


The auditor finds four signatures.


Did the control operate effectively?


Maybe.


The auditor still needs to understand:

  • What did the manager review?

  • What information was used?

  • Was it complete?

  • Which exceptions were identified?

  • What happened to inappropriate access?


A signature proves that someone signed something.


It does not automatically establish effective review.


MAR ITGC Compliance Requires Cooperation Across Functions

An effective ITGC program cannot be owned by one department.


It may require cooperation among:

  • Information Technology

  • Information Security

  • Finance

  • Compliance

  • Internal Audit

  • Risk Management

  • External Audit


Finance understands the reporting requirements.


IT understands the systems.


Information Security understands technology risk.


Compliance understands regulatory expectations.


Internal Audit provides independent assurance.


The program works when those functions understand their respective responsibilities.


Internal Audit Should Not Own the Controls

Internal Audit can:

  • Evaluate control design

  • Test operating effectiveness

  • Identify gaps

  • Recommend improvements

  • Monitor remediation


But Internal Audit should not become responsible for operating the ITGC program.


Management owns the controls.


That distinction protects independence.


ITGC Documentation Matters

A strong MAR ITGC framework should document:

  • Control objective

  • Risk

  • Control description

  • Control owner

  • Frequency

  • Evidence

  • Testing

  • Exceptions

  • Corrective action


This produces a clear audit trail:


Risk → Control → Evidence → Test → Conclusion


When external auditors or regulators ask how the organization knows an IT control is effective, the answer should be visible in the documentation.


Artificial Intelligence Makes ITGCs Even More Important

Insurance organizations are rapidly adopting AI for:

  • Claims analysis

  • Underwriting

  • Fraud detection

  • Customer service

  • Finance

  • Reporting


AI creates new technology-control questions:

  • Who can access the tool?

  • What data can be entered?

  • Who approves changes?

  • How are outputs validated?

  • How is confidential information protected?

  • Who monitors its use?


The technology may be new.


The control concepts are familiar:

  • Access.

  • Change.

  • Security.

  • Operations.

  • Monitoring.


Strong ITGC disciplines provide a useful foundation for governing new technology.


What Participants Will Learn

Corporate Compliance Seminars' ITGCs for NAIC Model Audit Rule Programs provides concentrated training in five major areas:

  1. Introduction to the NAIC Model Audit Rule and ITGCs

  2. Six key ITGC categories

  3. Framework development and policy implementation

  4. ITGC testing and MAR compliance readiness

  5. Case studies and continuous improvement


Participants will learn how to:

  • Understand ITGCs supporting financial reporting

  • Develop practical ITGC frameworks

  • Manage system access

  • Control changes

  • Strengthen backup and recovery

  • Address program development

  • Evaluate IT operations

  • Improve IT security

  • Test and monitor IT controls

  • Prepare for MAR assessments and external audits


Who Should Attend?

The program is designed specifically for professionals working in the insurance industry, including:

  • Internal Auditors

  • IT Auditors

  • IT Professionals

  • Compliance Specialists

  • SOX/MAR professionals

  • Financial-reporting professionals

  • Professionals responsible for insurance IT controls


The Bottom Line

The Model Audit Rule is ultimately about reliable financial reporting, governance, accountability, and internal control.


In a technology-dependent insurance organization, those objectives cannot be achieved without strong IT controls.


Insurance companies should be able to answer:

Who has access to our systems?
Who can change them?
How are changes tested?
Can critical information be recovered?
Are system operations monitored?
Is financial information protected?
How do we know these controls actually work?

Those are ITGC questions.


They are also Model Audit Rule questions.


Corporate Compliance Seminars' ITGCs for NAIC Model Audit Rule Programs is designed to help insurance professionals connect the two and build technology-control frameworks that support reliable financial reporting, stronger internal control, and better regulatory readiness.


Join CCS on Tuesday, September 22, 2026, for this focused two-hour program and strengthen the technology foundation underneath your organization's Model Audit Rule compliance program.

 
 
 

Recent Posts

See All
How Mature Are Your Monitoring Activities?

Measuring Whether Management Knows When Internal Controls Stop Working Every organization has internal controls. But here is the more difficult question: How does management know those controls are s

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page