top of page
Search

Own Risk and Solvency Assessment (ORSA): Turning Insurance Risk Management Into a Forward-Looking Solvency Discipline

Aug 14
8 min read

Live CPE Webinar • Tuesday, September 29, 2026 • 2 CPE Credits


Insurance companies are in the business of assuming risk.


The critical question is whether the organization understands how much risk it has assumed, how those risks interact, and whether it has sufficient capital to withstand them.


That is the fundamental purpose of the Own Risk and Solvency Assessment—ORSA.

ORSA is not simply another regulatory report. The NAIC describes it as an integral component of an insurer's Enterprise Risk Management framework—a confidential internal assessment of material risks associated with the insurer's business plan and the sufficiency of capital resources to support those risks.


Corporate Compliance Seminars' Own Risk and Solvency Assessment (ORSA) Programs CPE webinar is designed to help insurance professionals understand how ORSA connects risk management, capital adequacy, scenario analysis, governance, internal controls, ERM, and regulatory reporting.


The next program is scheduled for Tuesday, September 29, 2026.


ORSA Asks a Fundamental Question


At its core, ORSA asks management:

Given the risks we are taking and the risks we reasonably expect to face, do we have the risk-management capabilities and capital necessary to remain financially sound?

That is a much bigger question than:

“Are we currently meeting our regulatory capital requirements?”

Solvency is inherently forward-looking.


An insurer can appear financially sound today and still have significant vulnerabilities associated with:

  • Underwriting risk

  • Credit risk

  • Market risk

  • Liquidity risk

  • Operational risk

  • Catastrophe risk

  • Cybersecurity risk

  • Strategic risk

  • Third-party risk

  • Concentration risk


The NAIC specifically describes ORSA as requiring analysis of reasonably foreseeable and relevant material risks that could affect an insurer's ability to meet its obligations to policyholders.


ORSA Is Not Just Another Annual Compliance Exercise

This distinction is critical.


An organization can technically produce an ORSA Summary Report without allowing ORSA to meaningfully influence management decisions.


That misses the point.


The NAIC describes ORSA as an ongoing process integral to ERM, not a one-time exercise.


A mature ORSA process should influence:

Strategy

Business Planning

Risk Assessment

Capital Planning

Stress Testing

Management Decisions

Board Oversight

ORSA Summary Reporting


CCS specifically emphasizes integrating ORSA into business planning and budgeting rather than treating it as an isolated regulatory activity.


Start With the Risk Management Framework

ORSA cannot be stronger than the organization's underlying risk-management framework.


Before management can assess solvency, it must know:

What are our material risks?

That requires a disciplined process for:

  • Identifying risks

  • Assessing risks

  • Prioritizing risks

  • Monitoring risks

  • Managing risks

  • Reporting risks


The NAIC identifies fostering effective ERM as one of ORSA's two primary goals. Insurers should identify, assess, monitor, prioritize, and report their material and relevant risks using techniques appropriate to the nature, scale, and complexity of their businesses.


That concept—nature, scale, and complexity—matters.


ORSA should reflect the actual insurer.


It should not be a generic template.


Connect Objectives to Risks

A useful starting point is to identify what the insurance organization is trying to accomplish.


For example:

  • Maintain adequate capital

  • Meet policyholder obligations

  • Grow particular lines of business

  • Maintain liquidity

  • Achieve underwriting objectives

  • Protect information

  • Maintain regulatory compliance


Then ask:

What could prevent us from achieving those objectives?

That creates the foundation for a meaningful risk assessment.


Objectives → Risks → Risk Assessment → Risk Response → Controls → Residual Risk


ORSA then adds another critical dimension:

What does that residual risk mean for our current and future capital requirements?

Inherent Risk and Residual Risk Are Not the Same

An insurer may face substantial inherent risk but have sophisticated controls that reduce its exposure.


That creates an important distinction.

  • Inherent Risk is the exposure before considering management's controls and mitigation.

  • Residual Risk is what remains after those responses.


ORSA needs to help management understand what risk actually remains.


This becomes particularly important when evaluating whether the insurer's capital resources are sufficient.


Internal Controls Support the ORSA Framework

The CCS program specifically addresses the role of an effective internal-control system in supporting the insurer's risk-management framework.


That relationship is logical:

Risk

Risk Response

Internal Controls

Residual Risk

Capital Implications


If management believes a control substantially reduces a material risk, someone should have evidence that the control actually works.


Otherwise, the organization may underestimate residual risk.


That could ultimately distort its view of capital adequacy.


Scenario Analysis Is Where ORSA Gets Interesting

The future rarely unfolds according to the base-case forecast.


That is why ORSA includes scenario analysis and stress testing as important components of the assessment. CCS specifically covers both in its ORSA curriculum.


Management needs to ask:

What happens if our assumptions are wrong?

Potential scenarios might involve:

  • Severe catastrophe losses

  • Investment-market deterioration

  • Significant underwriting losses

  • Rapid claims inflation

  • Liquidity stress

  • Cyber disruption

  • Failure of a major third party

  • Multiple risks occurring simultaneously


The purpose is not to predict exactly what will happen.


The purpose is to understand:

How vulnerable are we if something materially different happens?

Stress Testing Should Challenge Management's Optimism

Management forecasts often begin with a most-likely scenario.


ORSA needs to go further.


Suppose management expects:

  • Stable investment performance

  • Moderate claims growth

  • Normal catastrophe activity

  • Continued premium growth


ORSA should ask:

What happens if two or three of those assumptions fail simultaneously?

That is where stress testing can reveal concentrations and dependencies that ordinary budgeting may miss.


Risk Correlation Matters

Risks do not always arrive individually.


A severe event might simultaneously create:


Claims Pressure + Liquidity Pressure + Investment Losses + Operational Disruption


Evaluating those risks independently could understate the true exposure.


That is one reason enterprise-wide risk assessment is so important.


Management needs to understand not only individual risks but also how those risks could interact.


Capital Adequacy Is More Than a Number

CCS includes capital adequacy assessment as a central ORSA component.


The question is not simply:

“How much capital do we have?”

It is:

“How much capital do we need given our business strategy and risk profile?”

That means capital analysis should connect directly to risk.


A company pursuing aggressive growth in a volatile line of business may face a different future capital requirement than an organization maintaining a mature, stable portfolio.


The capital analysis needs to follow the business.


ORSA Should Influence Strategic Decisions

This is where ORSA becomes genuinely useful.


Imagine management is considering:

  • Entering a new market

  • Introducing a new insurance product

  • Making a major acquisition

  • Increasing catastrophe exposure

  • Changing reinsurance arrangements

  • Increasing investment risk


The ORSA framework can help management evaluate:

How does this decision change our risk profile?
What happens to capital requirements?
Does it create concentrations?
What happens under stress?
Are we still operating within risk appetite?

Now ORSA is supporting management.


It is no longer simply supporting compliance.


Risk Appetite Should Connect to ORSA

An effective ERM program should help leadership establish how much risk the organization is prepared to accept in pursuit of its objectives.

ORSA provides an opportunity to connect that risk appetite to actual capital consequences.


Management should understand situations where:


Risk Exposure > Risk Appetite


When that occurs, management has choices.


It can:

  • Reduce the risk

  • Transfer the risk

  • Increase controls

  • Increase capital

  • Change the strategy

  • Accept the exposure through appropriate governance


The important point is that the decision should be conscious.


Board Oversight Is Essential

CCS specifically includes the role of the Board of Directors and senior management within the ORSA program.


That is appropriate because ORSA involves some of the most fundamental governance questions facing an insurance company:

What risks are we taking?
How much risk are we willing to accept?
What could threaten our solvency?
Do we have enough capital?
What happens under severe stress?

These cannot be delegated entirely to a risk-management department.


The Board does not need to perform the models.


It needs to understand their implications.


The Board Needs More Than a Heat Map

A red-yellow-green risk dashboard can be useful.


It can also oversimplify complicated exposures.


For significant risks, the Board may need to understand:

  • Risk description

  • Risk trend

  • Risk appetite

  • Current exposure

  • Controls and mitigation

  • Residual exposure

  • Stress scenarios

  • Capital implications

  • Management actions


The objective is not to give directors more data.


It is to give them better information for decision-making.


The ORSA Summary Report Should Tell the Risk Story

CCS devotes part of the program to the ORSA Summary Report, including its purpose and key elements.


The report should not simply be a regulatory compilation.


It should tell a coherent story about:

The Business

Its Material Risks

How Those Risks Are Managed

How They Are Assessed

What Happens Under Stress

Whether Capital Is Adequate


The NAIC describes the ORSA Summary Report as a confidential, high-level report provided annually to the appropriate regulator for insurers subject to ORSA requirements.


ORSA, ERM and MAR Should Not Live in Separate Silos

One of the strongest aspects of the CCS course is its attention to the relationship among:

  • ORSA

  • Enterprise Risk Management

  • Model Audit Rule


CCS specifically addresses the benefits of integrating these programs.


That integration makes sense.


ERM identifies and manages enterprise risks.


ORSA evaluates those risks in relation to current and future solvency and capital.


MAR addresses internal control over financial reporting and related governance requirements.


The programs have different purposes, but they should not operate as disconnected compliance islands.


Internal Audit Has an Important ORSA Role

Internal Audit should not own ORSA.


Management owns risk management and the ORSA process.


But Internal Audit can provide valuable independent assurance over elements supporting ORSA.


Internal Audit might evaluate:

  • Risk identification

  • Governance

  • Data integrity

  • Internal controls

  • Risk reporting

  • Model governance

  • Scenario-development processes

  • Corrective actions


One of Internal Audit's most valuable questions is:

What evidence supports management's assumptions?

That question is particularly important when assumptions materially affect conclusions about risk and capital.


ORSA Should Be Challenged

A strong risk-management culture should welcome challenge.


Questions should include:

Are we missing a material risk?
Are our assumptions too optimistic?
Are our stress scenarios severe enough?
Are correlations properly considered?
Are we relying on controls that have not been adequately tested?
Has the business changed since the risk assessment was performed?

The purpose of challenge is not to prove management wrong.


It is to improve the quality of the assessment.


Emerging Risks Belong in ORSA

Risk profiles change.


Current and emerging issues can include:

  • Artificial intelligence

  • Cybersecurity

  • Climate and catastrophe exposure

  • Third-party concentration

  • New technologies

  • Economic volatility

  • Changing customer behavior

  • Regulatory developments


A mature ORSA program should have a mechanism for identifying significant emerging risks before they become losses.


The NAIC itself continues to review the effectiveness of Model #505 and the ORSA Guidance Manual and consider revisions as necessary, underscoring that ORSA remains an evolving regulatory discipline.


The NAIC Guidance Is Continuing to Evolve

This is particularly relevant for the September 29, 2026 program.


The NAIC's ORSA Implementation Subgroup has continued working on revisions and clarifications to ORSA guidance during 2026. Its current work includes continued ERM education for regulators and review of the effectiveness of the Risk Management and ORSA Model Act and Guidance Manual.


Recent guidance work has addressed issues such as international premium volume, captive insurers, first-time filing expectations after exceeding applicable thresholds, and consideration of an insurance group's ability to service existing debt when evaluating group-wide capital adequacy.


That is another reason insurance professionals need to keep their ORSA knowledge current.


What Participants Will Learn

CCS's ORSA Programs CPE Training addresses the complete ORSA landscape, including regulatory requirements, risk-management frameworks, scenario analysis and stress testing, capital adequacy, documentation and reporting, annual ORSA processes, the ORSA Summary Report, Board and senior-management responsibilities, and integration among ORSA, ERM, and MAR.


Participants will learn how to move beyond understanding the acronym and begin understanding how an effective ORSA program actually works.


Who Should Attend?

The program is particularly relevant for:

  • Risk Managers

  • Compliance Officers

  • Internal Auditors

  • Internal Control professionals

  • ERM leaders

  • Insurance professionals responsible for regulatory compliance

  • Professionals involved with ORSA preparation or review


CCS classifies the program at the Intermediate to Advanced level, with no prerequisites or advance preparation required.


The Bottom Line

ORSA should answer a question that every insurance company's leadership should care about:

Do we understand the risks we are taking, and do we have the financial capacity to survive them?

Getting there requires more than preparing an annual report.


It requires:

Effective ERM


Risk Identification


Internal Controls


Scenario Analysis


Stress Testing


Capital Adequacy Assessment


Management Challenge


Board Oversight


Continuous Monitoring


That is what turns ORSA from a regulatory requirement into a management tool.

Corporate Compliance Seminars' Own Risk and Solvency Assessment (ORSA) Programs event on Tuesday, September 29, 2026 is designed to help insurance professionals understand that complete process—and, more importantly, understand how ORSA, ERM, MAR, capital management, and governance should work together rather than as separate compliance exercises.

 
 
 

Recent Posts

See All
How Mature Are Your Monitoring Activities?

Measuring Whether Management Knows When Internal Controls Stop Working Every organization has internal controls. But here is the more difficult question: How does management know those controls are s

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page