top of page
Search

NAIC Model Audit Rule Compliance: What Your MAR Team Needs to Know About the Annual Process and the Financial Examination

8 minutes ago
6 min read


For an insurance company subject to the NAIC Model Audit Rule (MAR), compliance should not be viewed as a once-a-year certification project.


A strong MAR program is an ongoing internal-control and regulatory-readiness process.

That distinction becomes particularly important when the state insurance department conducts its periodic financial condition examination.


The NAIC's Financial Condition Examiners Handbook provides regulators with a risk-focused framework for conducting financial examinations. The Handbook addresses the entire examination process and provides guidance for the individual phases of an examination.


For members of the MAR Compliance Team, there is an important practical lesson:


The work you perform every year may become important evidence when the financial examiners arrive.


MAR Is More Than an Annual Filing

The NAIC Annual Financial Reporting Model Regulation—commonly called the Model Audit Rule or MAR—establishes requirements involving audited statutory financial statements, independent auditors, audit committees, communications concerning internal-control matters, and, for insurers meeting the applicable requirements, management reporting on internal control over financial reporting.


Under Section 17 of the NAIC model regulation, insurers meeting the applicable $500 million premium threshold generally must prepare management's report on internal control over financial reporting. The commissioner can also require the report under specified financial-risk circumstances.


For the MAR Compliance Team, however, the annual process should extend well beyond producing the final report.


The team needs to understand and support a control lifecycle that includes:


Risk → Process → Control → Testing → Deficiency Evaluation → Remediation → Management Reporting


Each step should produce defensible documentation.


What the MAR Compliance Team Should Understand Every Year

An effective annual MAR program begins with scope.


The team should understand which statutory financial statement accounts, disclosures, processes, systems and controls could materially affect statutory financial reporting.


That requires more than carrying forward last year's control matrix.


Changes during the year should be considered, including:

  • New products or lines of business

  • Acquisitions and reorganizations

  • New accounting requirements

  • Changes in statutory accounting practices

  • Significant changes in estimates or reserves

  • New or modified information systems

  • Outsourced processes and service organizations

  • Personnel and organizational changes

  • Control deficiencies identified by internal or external auditors

  • Regulatory findings

  • Cybersecurity and technology changes affecting financial reporting


The central question should be:


What changed this year that could change our financial-reporting risks or controls?


Understand the Difference Between a Risk and a Control

MAR teams can become too focused on control descriptions.


The better starting point is the underlying financial-reporting risk.


For every significant process, the team should be able to explain: What could go wrong?


Then determine which control or combination of controls addresses that risk.


For example, documenting that management reviews an investment reconciliation tells an examiner very little by itself.


The documentation should establish the financial-reporting risk being addressed, who performs the review, its frequency, the information reviewed, the criteria used to identify exceptions, how exceptions are investigated, what evidence demonstrates performance and why the control is capable of preventing or detecting a material error.


That is the difference between documenting a control activity and demonstrating a control system.


Design Effectiveness Comes Before Operating Effectiveness

A control can be performed exactly as designed every month and still be ineffective.


Why?


Because the control may not actually address the risk.


The MAR team therefore needs to consider two separate questions:


  • Design effectiveness: Is the control appropriately designed to prevent or detect the relevant financial-reporting risk?


  • Operating effectiveness: Did the control actually operate as designed during the period?


Testing operating effectiveness without first considering design can produce considerable documentation without providing meaningful assurance.


Your Documentation Should Tell the Story

A regulator or examiner who was not involved in your annual MAR process should be able to understand what management did.


Good documentation should allow another knowledgeable professional to follow the chain:


Significant Account → Financial Reporting Risk → Relevant Assertion → Business Process → Key Control → Control Owner → Testing → Exception → Evaluation → Remediation


If that linkage cannot be followed, the MAR program may have a documentation problem even when the underlying controls are functioning.


Then Comes the Financial Condition Examination

This is where MAR compliance and regulatory examination readiness intersect.


The NAIC describes the Financial Condition Examiners Handbook as guidance for state insurance departments in establishing an effective examination system. The Handbook uses a risk-focused examination approach intended not simply to verify financial statement balances, but also to evaluate risks, risk-management processes, controls, corporate governance and prospective financial concerns.


The broader NAIC risk-focused surveillance process is designed to identify insurers experiencing or potentially developing financial problems and support appropriate regulatory intervention.


This changes how a MAR Compliance Team should think about its work.


The examiner is not necessarily interested only in whether you completed your MAR testing. The examiner wants to understand the risks facing the insurer and whether the insurer is effectively identifying, controlling and monitoring those risks.


Think Like a Financial Examiner

A well-prepared MAR Compliance Team should periodically look at its program from the examiner's perspective.


Questions may include:

  • What are the insurer's most significant activities?

  • What inherent risks arise from those activities?

  • What controls mitigate those risks?

  • How does management know those controls actually operate?

  • What residual risk remains after considering the controls?

  • What has changed since the previous examination?

  • What significant control deficiencies have been identified?

  • Were those deficiencies corrected?

  • How effective is corporate governance and management oversight?

  • How dependent are financial-reporting controls on information technology?


The NAIC examination framework specifically recognizes risk management, corporate governance and IT general controls as important elements of financial-condition examination work.


IT Controls Cannot Be an Afterthought

Modern statutory financial reporting is heavily dependent on information systems.

That means the MAR Compliance Team needs to understand the relationship between business-process controls and IT General Controls (ITGCs).


Critical areas can include:

  • User access

  • Privileged access

  • Segregation of duties

  • Change management

  • System development

  • Interfaces

  • Automated calculations

  • Data transfers

  • Report generation

  • Batch processing

  • Backup and recovery

  • Third-party systems


A beautifully documented business control may provide little assurance if the data underlying that control are generated by systems whose integrity cannot be supported.


The NAIC examination structure specifically maintains guidance relating to IT general controls as part of the financial examination process.


Deficiencies Matter—Including What Management Did About Them

Finding a control exception is not automatically evidence of a failed MAR program.


Failing to appropriately evaluate and address one can be much more significant.


The MAR Compliance Team should maintain a disciplined process for:


Identification → Investigation → Risk Assessment → Classification → Corrective Action → Retesting → Closure


Management should be able to demonstrate that identified problems do not simply disappear from the MAR documentation the following year.


A recurring deficiency can tell an examiner considerably more about the organization than a single isolated testing exception.


Don't Wait for the Examination Announcement

One of the weakest approaches to regulatory readiness is attempting to reconstruct several years of control history after receiving an examination request.


MAR documentation should instead create an annual institutional record.


The company should be able to retrieve prior-year risk assessments, narratives, flowcharts, risk-control matrices, testing documentation, deficiency evaluations, remediation evidence, management conclusions, external-auditor communications and significant changes to processes and systems.


That historical record allows management to explain how the control environment evolved, rather than simply showing examiners a snapshot of the current year.


The Annual MAR Process Should Build Examination Readiness

A mature MAR program therefore accomplishes two objectives simultaneously.


First, it supports management's annual responsibilities for internal control over statutory financial reporting.


Second, it creates a continuing body of evidence supporting the insurer's broader regulatory control environment.


That does not mean the MAR program should be designed solely to satisfy examiners.


It means management should recognize that the annual MAR process and the periodic financial examination are parts of the same broader regulatory ecosystem.


Five Questions Every MAR Compliance Team Member Should Be Able to Answer

At the end of each annual MAR cycle, every key member of the team should understand:

1. What are our significant statutory financial-reporting risks?

2. Which key controls address those risks?

3. What evidence demonstrates that those controls are properly designed and operating effectively?

4. What deficiencies were identified, and what did management do about them?

5. Could we explain and defend this entire process to a financial examiner several years from now?


If the answer to the fifth question is uncertain, the MAR program probably needs additional work.


MAR Compliance Is an Annual Process—Examination Readiness Is Continuous

The NAIC updates the Financial Condition Examiners Handbook annually, and its examination framework continues to emphasize risk-focused surveillance, corporate governance, risk management, financial condition and appropriate regulatory follow-up.


That makes an important point for MAR Compliance Teams: Passing this year's control testing is not the finish line.


The objective should be to establish a sustainable system in which risks are identified, controls are appropriately designed, operating effectiveness is supported by evidence, deficiencies are addressed, changes are incorporated into the risk assessment, and management can demonstrate the effectiveness of the process.


The best question for the MAR Compliance Team is therefore not:“Are we ready to complete this year's MAR report?”


It is: “If the financial examiners arrived tomorrow, could we demonstrate how our internal-control system has worked—and evolved—since the last examination?”


That is the standard of regulatory readiness insurers should be working toward.

 
 
 

Recent Posts

See All
How Mature Are Your Monitoring Activities?

Measuring Whether Management Knows When Internal Controls Stop Working Every organization has internal controls. But here is the more difficult question: How does management know those controls are s

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page