Own Risk and Solvency Assessment (ORSA): Turning Insurance Risk Management Into a Forward-Looking Solvency Discipline
Live CPE Webinar • Tuesday, September 29, 2026 • 2 CPE Credits
Insurance companies are in the business of assuming risk.
The critical question is whether the organization understands how much risk it has assumed, how those risks interact, and whether it has sufficient capital to withstand them.
That is the fundamental purpose of the Own Risk and Solvency Assessment—ORSA.
ORSA is not simply another regulatory report. The NAIC describes it as an integral component of an insurer's Enterprise Risk Management framework—a confidential internal assessment of material risks associated with the insurer's business plan and the sufficiency of capital resources to support those risks.
Corporate Compliance Seminars' Own Risk and Solvency Assessment (ORSA) Programs CPE webinar is designed to help insurance professionals understand how ORSA connects risk management, capital adequacy, scenario analysis, governance, internal controls, ERM, and regulatory reporting.
The next program is scheduled for Tuesday, September 29, 2026.
ORSA Asks a Fundamental Question
At its core, ORSA asks management:
Given the risks we are taking and the risks we reasonably expect to face, do we have the risk-management capabilities and capital necessary to remain financially sound?
That is a much bigger question than:
“Are we currently meeting our regulatory capital requirements?”
Solvency is inherently forward-looking.
An insurer can appear financially sound today and still have significant vulnerabilities associated with:
Underwriting risk
Credit risk
Market risk
Liquidity risk
Operational risk
Catastrophe risk
Cybersecurity risk
Strategic risk
Third-party risk
Concentration risk
The NAIC specifically describes ORSA as requiring analysis of reasonably foreseeable and relevant material risks that could affect an insurer's ability to meet its obligations to policyholders.
ORSA Is Not Just Another Annual Compliance Exercise
This distinction is critical.
An organization can technically produce an ORSA Summary Report without allowing ORSA to meaningfully influence management decisions.
That misses the point.
The NAIC describes ORSA as an ongoing process integral to ERM, not a one-time exercise.
A mature ORSA process should influence:
Strategy
↓
Business Planning
↓
Risk Assessment
↓
Capital Planning
↓
Stress Testing
↓
Management Decisions
↓
Board Oversight
↓
ORSA Summary Reporting
CCS specifically emphasizes integrating ORSA into business planning and budgeting rather than treating it as an isolated regulatory activity.
Start With the Risk Management Framework
ORSA cannot be stronger than the organization's underlying risk-management framework.
Before management can assess solvency, it must know:
What are our material risks?
That requires a disciplined process for:
Identifying risks
Assessing risks
Prioritizing risks
Monitoring risks
Managing risks
Reporting risks
The NAIC identifies fostering effective ERM as one of ORSA's two primary goals. Insurers should identify, assess, monitor, prioritize, and report their material and relevant risks using techniques appropriate to the nature, scale, and complexity of their businesses.
That concept—nature, scale, and complexity—matters.
ORSA should reflect the actual insurer.
It should not be a generic template.
Connect Objectives to Risks
A useful starting point is to identify what the insurance organization is trying to accomplish.
For example:
Maintain adequate capital
Meet policyholder obligations
Grow particular lines of business
Maintain liquidity
Achieve underwriting objectives
Protect information
Maintain regulatory compliance
Then ask:
What could prevent us from achieving those objectives?
That creates the foundation for a meaningful risk assessment.
Objectives → Risks → Risk Assessment → Risk Response → Controls → Residual Risk
ORSA then adds another critical dimension:
What does that residual risk mean for our current and future capital requirements?
Inherent Risk and Residual Risk Are Not the Same
An insurer may face substantial inherent risk but have sophisticated controls that reduce its exposure.
That creates an important distinction.
Inherent Risk is the exposure before considering management's controls and mitigation.
Residual Risk is what remains after those responses.
ORSA needs to help management understand what risk actually remains.
This becomes particularly important when evaluating whether the insurer's capital resources are sufficient.
Internal Controls Support the ORSA Framework
The CCS program specifically addresses the role of an effective internal-control system in supporting the insurer's risk-management framework.
That relationship is logical:
Risk
↓
Risk Response
↓
Internal Controls
↓
Residual Risk
↓
Capital Implications
If management believes a control substantially reduces a material risk, someone should have evidence that the control actually works.
Otherwise, the organization may underestimate residual risk.
That could ultimately distort its view of capital adequacy.
Scenario Analysis Is Where ORSA Gets Interesting
The future rarely unfolds according to the base-case forecast.
That is why ORSA includes scenario analysis and stress testing as important components of the assessment. CCS specifically covers both in its ORSA curriculum.
Management needs to ask:
What happens if our assumptions are wrong?
Potential scenarios might involve:
Severe catastrophe losses
Investment-market deterioration
Significant underwriting losses
Rapid claims inflation
Liquidity stress
Cyber disruption
Failure of a major third party
Multiple risks occurring simultaneously
The purpose is not to predict exactly what will happen.
The purpose is to understand:
How vulnerable are we if something materially different happens?
Stress Testing Should Challenge Management's Optimism
Management forecasts often begin with a most-likely scenario.
ORSA needs to go further.
Suppose management expects:
Stable investment performance
Moderate claims growth
Normal catastrophe activity
Continued premium growth
ORSA should ask:
What happens if two or three of those assumptions fail simultaneously?
That is where stress testing can reveal concentrations and dependencies that ordinary budgeting may miss.
Risk Correlation Matters
Risks do not always arrive individually.
A severe event might simultaneously create:
Claims Pressure + Liquidity Pressure + Investment Losses + Operational Disruption
Evaluating those risks independently could understate the true exposure.
That is one reason enterprise-wide risk assessment is so important.
Management needs to understand not only individual risks but also how those risks could interact.
Capital Adequacy Is More Than a Number
CCS includes capital adequacy assessment as a central ORSA component.
The question is not simply:
“How much capital do we have?”
It is:
“How much capital do we need given our business strategy and risk profile?”
That means capital analysis should connect directly to risk.
A company pursuing aggressive growth in a volatile line of business may face a different future capital requirement than an organization maintaining a mature, stable portfolio.
The capital analysis needs to follow the business.
ORSA Should Influence Strategic Decisions
This is where ORSA becomes genuinely useful.
Imagine management is considering:
Entering a new market
Introducing a new insurance product
Making a major acquisition
Increasing catastrophe exposure
Changing reinsurance arrangements
Increasing investment risk
The ORSA framework can help management evaluate:
How does this decision change our risk profile?
What happens to capital requirements?
Does it create concentrations?
What happens under stress?
Are we still operating within risk appetite?
Now ORSA is supporting management.
It is no longer simply supporting compliance.
Risk Appetite Should Connect to ORSA
An effective ERM program should help leadership establish how much risk the organization is prepared to accept in pursuit of its objectives.
ORSA provides an opportunity to connect that risk appetite to actual capital consequences.
Management should understand situations where:
Risk Exposure > Risk Appetite
When that occurs, management has choices.
It can:
Reduce the risk
Transfer the risk
Increase controls
Increase capital
Change the strategy
Accept the exposure through appropriate governance
The important point is that the decision should be conscious.
Board Oversight Is Essential
CCS specifically includes the role of the Board of Directors and senior management within the ORSA program.
That is appropriate because ORSA involves some of the most fundamental governance questions facing an insurance company:
What risks are we taking?
How much risk are we willing to accept?
What could threaten our solvency?
Do we have enough capital?
What happens under severe stress?
These cannot be delegated entirely to a risk-management department.
The Board does not need to perform the models.
It needs to understand their implications.
The Board Needs More Than a Heat Map
A red-yellow-green risk dashboard can be useful.
It can also oversimplify complicated exposures.
For significant risks, the Board may need to understand:
Risk description
Risk trend
Risk appetite
Current exposure
Controls and mitigation
Residual exposure
Stress scenarios
Capital implications
Management actions
The objective is not to give directors more data.
It is to give them better information for decision-making.
The ORSA Summary Report Should Tell the Risk Story
CCS devotes part of the program to the ORSA Summary Report, including its purpose and key elements.
The report should not simply be a regulatory compilation.
It should tell a coherent story about:
The Business
↓
Its Material Risks
↓
How Those Risks Are Managed
↓
How They Are Assessed
↓
What Happens Under Stress
↓
Whether Capital Is Adequate
The NAIC describes the ORSA Summary Report as a confidential, high-level report provided annually to the appropriate regulator for insurers subject to ORSA requirements.
ORSA, ERM and MAR Should Not Live in Separate Silos
One of the strongest aspects of the CCS course is its attention to the relationship among:
ORSA
Enterprise Risk Management
Model Audit Rule
CCS specifically addresses the benefits of integrating these programs.
That integration makes sense.
ERM identifies and manages enterprise risks.
ORSA evaluates those risks in relation to current and future solvency and capital.
MAR addresses internal control over financial reporting and related governance requirements.
The programs have different purposes, but they should not operate as disconnected compliance islands.
Internal Audit Has an Important ORSA Role
Internal Audit should not own ORSA.
Management owns risk management and the ORSA process.
But Internal Audit can provide valuable independent assurance over elements supporting ORSA.
Internal Audit might evaluate:
Risk identification
Governance
Data integrity
Internal controls
Risk reporting
Model governance
Scenario-development processes
Corrective actions
One of Internal Audit's most valuable questions is:
What evidence supports management's assumptions?
That question is particularly important when assumptions materially affect conclusions about risk and capital.
ORSA Should Be Challenged
A strong risk-management culture should welcome challenge.
Questions should include:
Are we missing a material risk?
Are our assumptions too optimistic?
Are our stress scenarios severe enough?
Are correlations properly considered?
Are we relying on controls that have not been adequately tested?
Has the business changed since the risk assessment was performed?
The purpose of challenge is not to prove management wrong.
It is to improve the quality of the assessment.
Emerging Risks Belong in ORSA
Risk profiles change.
Current and emerging issues can include:
Artificial intelligence
Cybersecurity
Climate and catastrophe exposure
Third-party concentration
New technologies
Economic volatility
Changing customer behavior
Regulatory developments
A mature ORSA program should have a mechanism for identifying significant emerging risks before they become losses.
The NAIC itself continues to review the effectiveness of Model #505 and the ORSA Guidance Manual and consider revisions as necessary, underscoring that ORSA remains an evolving regulatory discipline.
The NAIC Guidance Is Continuing to Evolve
This is particularly relevant for the September 29, 2026 program.
The NAIC's ORSA Implementation Subgroup has continued working on revisions and clarifications to ORSA guidance during 2026. Its current work includes continued ERM education for regulators and review of the effectiveness of the Risk Management and ORSA Model Act and Guidance Manual.
Recent guidance work has addressed issues such as international premium volume, captive insurers, first-time filing expectations after exceeding applicable thresholds, and consideration of an insurance group's ability to service existing debt when evaluating group-wide capital adequacy.
That is another reason insurance professionals need to keep their ORSA knowledge current.
What Participants Will Learn
CCS's ORSA Programs CPE Training addresses the complete ORSA landscape, including regulatory requirements, risk-management frameworks, scenario analysis and stress testing, capital adequacy, documentation and reporting, annual ORSA processes, the ORSA Summary Report, Board and senior-management responsibilities, and integration among ORSA, ERM, and MAR.
Participants will learn how to move beyond understanding the acronym and begin understanding how an effective ORSA program actually works.
Who Should Attend?
The program is particularly relevant for:
Risk Managers
Compliance Officers
Internal Auditors
Internal Control professionals
ERM leaders
Insurance professionals responsible for regulatory compliance
Professionals involved with ORSA preparation or review
CCS classifies the program at the Intermediate to Advanced level, with no prerequisites or advance preparation required.
The Bottom Line
ORSA should answer a question that every insurance company's leadership should care about:
Do we understand the risks we are taking, and do we have the financial capacity to survive them?
Getting there requires more than preparing an annual report.
It requires:
Effective ERM
Risk Identification
Internal Controls
Scenario Analysis
Stress Testing
Capital Adequacy Assessment
Management Challenge
Board Oversight
Continuous Monitoring
That is what turns ORSA from a regulatory requirement into a management tool.
Corporate Compliance Seminars' Own Risk and Solvency Assessment (ORSA) Programs event on Tuesday, September 29, 2026 is designed to help insurance professionals understand that complete process—and, more importantly, understand how ORSA, ERM, MAR, capital management, and governance should work together rather than as separate compliance exercises.

Comments