Model Audit Rule: What insurance companies need to know
- The Model Audit Rule (MAR) strengthens financial reporting oversight for insurance companies. MAR requires annual independent financial statement audits, internal control oversight, audit committee governance and reporting to state insurance regulators to help ensure accurate financial reporting and protect policyholders.
- Compliance requirements increase as an insurer grows. While insurers with more than $1 million in premiums must obtain an annual CPA audit, larger insurers are subject to additional obligations, including management assessments of internal controls and stricter audit committee independence requirements.
- Internal controls and governance are central to MAR compliance. Insurers must document, test and monitor internal controls over financial reporting, address material weaknesses and establish audit committees that provide independent oversight of financial reporting and audits.
- MAR and SOX share similar goals but differ in scope and regulatory oversight. MAR applies to insurance companies under state regulatory frameworks, while SOX applies to public companies under federal securities laws. MAR places additional emphasis on statutory financial reporting and insurance solvency oversight.
- Proactive compliance practices reduce risk and audit challenges. Regular risk assessments, effective control testing, thorough documentation, cross-functional collaboration and continuous monitoring can help insurers avoid common compliance mistakes and maintain a strong MAR compliance posture.
Most insurance companies are in scope for MAR. The rule includes detailed financial reporting requirements, the need to potentially implement complex controls and has applicability thresholds that impact what actions your business is required to take.
Keep reading to learn what MAR requires of your business and actions you can take to improve your compliance posture.
What is the Model Audit Rule?
The Model Audit Rule, known formally as the Annual Financial Reporting Model Regulation, was co-developed by the American Institute of Certified Public Accountants and the National Association of Insurance Commissioners (NAIC). It was first issued by the NAIC with revisions in 2006 and adopted in 2010. The rule was designed to give state insurance regulators greater confidence in the accuracy of insurers’ financial statements and to help identify financial reporting risks before they become larger concerns.
The rule requires insurers to obtain an annual independent financial statement audit, maintain effective internal controls over financial reporting and provide regulators with documentation for those controls. In addition, the rule establishes requirements related to auditor independence, audit committee oversight and the communication of significant internal control deficiencies identified during the audit process.
Who does the Model Audit Rule apply to?
The Model Audit Rule applies to insurance companies, but not agents. Since the NAIC is not a federal agency, the rule is adopted on a state-by-state basis.
What are the Model Audit Rule requirements?
Model Audit Rule requirements vary depending on the size of your insurance company. All insurers with more than $1 million in premiums must submit an annual financial statement audited by an independent CPA. Additional requirements depend on your company’s size.
Annual financial statements by an independent CPA
Annual financial statements must be filed by June 1 following a December 31 year-end. The financial statements must include:
- An independent auditor’s report
- A balance sheet
- Statement of operations
- Statement of cash flows
- Statement of changes in capital and surplus
- Notes to the financial statements
The external auditor under the Model Audit Rule must be independent and is liable for the statements made in the audit. In addition, the lead partner must be rotated after a five-year consecutive period, and the auditor must not perform non-audit services, including serving in a management role, auditing their own work or serving in an advocacy role.
Communication of internal control-related matters noted in the audit
Under the Model Audit Rule, the external auditors must issue a report on internal control weaknesses (unremediated material weaknesses) that are outstanding at the close of the audit and provide it to the state insurance commissioner. The report must describe the unremediated material weakness, actions taken (or planned on) to remediate the weakness going forward and must coincide with the most recent annual financial statements.
Management’s report on internal control over financial reporting
Insurers with $500 million or more in premiums must provide a management’s report on internal control over financial reporting (ICFR). In this report, company leadership assesses and attests to the effectiveness of key financial controls.
Key elements of the report include:
- Control framework: Identifies the evaluation framework used to assess the controls (for example, the widely used COSO Framework).
- Assessment of effectiveness: Provides a conclusion on whether the ICFR is effective.
- Material weakness disclosures: Identifies and discloses any material weaknesses. Controls cannot be deemed effective if a single material weakness exists.
Audit committee requirements
Insurers must establish an audit committee to oversee the financial reporting process, the annual independent audit and the insurer’s system of internal controls. The audit committee serves as the intermediary between management and the independent CPA and is responsible for assessing the auditor’s independence and objectivity.
The Model Audit Rule also imposes audit committee independence requirements based on your insurance company’s size.
- Insurers with between $300 million and $500 million in direct written and assumed premiums must have at least 50% independent audit committee members.
- Insurers with more than $500 must have at least 75% independent members.
An independent member cannot be an officer or employee of the insurer or its affiliates and must be free from relationships that could impair objective judgment.
MAR reporting requirements
The annual audited financial report insurers submit must include the following information:
- Report on the independence of the CPA firm
- Balance sheet reporting admitted assets, liabilities, capital and surplus
- Statement of operations
- Statement of cash flow
- Statement of changes in capital and surplus
How the Model Audit Rule compares to SOX
In many ways, the Model Audit Rule mirrors the federal Sarbanes-Oxley Act (SOX), which applies to all public companies and is enforced by the Public Company Accounting Oversight Board.
Model Audit Rule regulations impose submission requirements on insurance companies that go beyond those of SOX. These include:
- An annual financial statement audit by an independent CPA
- Communication of internal control-related matters noted in the audit
- Management report of internal control over financial reporting
While there is significant overlap between MAR and SOX, here are some of the key differences:
| MAR | SOX | |
|---|---|---|
| Scope | Applies to insurance companies, generally based on state adoption and insurer size/premium thresholds. | Applies primarily to publicly traded companies regulated by the SEC. |
| Regulatory authority | Administered by state insurance departments under the NAIC Model Audit Rule framework. | Enforced by the SEC and overseen in part by the PCAOB. |
| Primary objective | Strengthens insurer financial reporting and protects policyholders through enhanced governance and internal controls. | Protects investors by improving the accuracy and reliability of public company financial reporting. |
| Internal control requirements | Requires management to report on internal controls over financial reporting in accordance with NAIC-prescribed standards. | Requires management to assess internal controls over financial reporting under Section 404, with specific requirements from the SEC and the PCAOB. |
| External audit attestation | Auditor attestation requirements depend on insurer size and the state’s adoption of the Model Audit Rule. | Independent auditor attestation of internal controls is required for many public companies, subject to applicable exemptions. |
| Governance requirements | Requires audit committee oversight tailored to insurance companies and state regulatory expectations. | Includes detailed requirements for audit committee independence, auditor independence, and executive certifications. |
| Reporting framework | Supports internal controls over both GAAP financial reporting and statutory financial statements filed with state insurance regulators. | Primarily supports GAAP financial statements filed with the SEC. |
| Compliance Driver | Driven by state insurance regulation, insurer solvency oversight, and policyholder protection. | Driven by federal securities laws and the need for investor confidence and capital market transparency. |
How to achieve Model Audit Rule compliance
Insurance companies can improve their Model Audit Rule compliance posture by implementing a structured governance, risk management and internal control framework. The following steps can help insurers meet MAR requirements while enhancing the reliability and accountability of financial reporting:
Establish an independent audit committee
The insurer’s board of directors must designate a formal audit committee comprised of members who are independent of the insurer’s management. The committee is responsible for directly hiring and overseeing the independent CPA who conducts the annual financial statement audit.
Conduct annual CPA audits
Insurers must submit an annual audited financial report certified by an independent CPA that includes a balance sheet, an income statement and a statement of cash flows. The audited statements must be filed annually by June 1 for the preceding year ending December 31.
Implement an internal audit function
If your company meets the premium threshold, you must establish a dedicated internal audit function that provides objective assurance to the audit committee and management regarding the company’s risk management, internal controls and governance processes.
Document and certify internal controls
Management at large insurers must report on the effectiveness of internal control over financial reporting. Be sure your controls are documented and run tests to determine if they are working as designed.
Common Model Audit Rule compliance mistakes
Mistakes insurance companies often make that can create a more difficult path to MAR compliance include:
- Treating compliance as reactive: Many organizations only focus on MAR compliance when the audit is imminent, leading to last-minute scrambling for data and a failure to maintain consistent, day-to-day internal controls.
- Using generic templates: Applying “one-size-fits-all” templates often creates misaligned policies that do not match the company’s actual day-to-day operating procedures.
- Relying on manual processes: Manually tracking records, overrides and timestamps dramatically increases the risk of human error and makes audit trails difficult to trace.
- Poor cross-functional collaboration: Compliance isn’t just a finance issue. Failing to coordinate with IT, HR, legal and operational departments leads to communication gaps and incomplete reporting.
- Failing to perform a risk assessment: Skipping formal risk assessments can cause companies to focus too much on low-risk areas while leaving true financial reporting risks exposed.
MAR compliance best practices
To make Model Audit Rule compliance less burdensome, your company should implement these practices:
- Perform regular risk assessments: Identify financial reporting risks and prioritize areas where stronger internal controls are needed.
- Align controls with financial reporting risks: Map internal controls to significant financial statement accounts and management assertions to help ensure key risks are effectively addressed.
- Evaluate control effectiveness: Test both the design and operating effectiveness of internal controls through walk-throughs, documentation reviews and periodic testing.
- Prioritize preventive controls: Implement controls that prevent errors before they occur while supplementing them with detective controls to identify issues promptly.
- Focus on key controls: Maintain a streamlined control environment by emphasizing controls that mitigate the most significant financial reporting risks.
- Maintain thorough documentation: Keep policies, procedures, risk assessments and testing results well documented to support management certifications and regulatory examinations.
- Continuously monitor and improve: Regularly review internal controls, address deficiencies and update compliance processes as business operations and regulatory requirements evolve.
How Wipfli can help
When you’re seeking information or a fresh perspective about the requirements of the Model Audit Rule, Wipfli's risk advisory services team can help. We also offer co-sourced and outsourced services for internal audits, as well as one-off engagements for specialized audit areas or projects. Start a conversation.