Scrutineer.ai
All posts
Comparison

Best Model Audit Rule software for insurers

Model Audit Rule software compared, plus the three NAIC premium tests, the three compliance clocks and why no auditor ever signs your ICFR assertion.

By the Scrutineer team

September 2026 · 8 min read

Try it while you read

No account, nothing to install.

Pick a framework or a vendor and run a scrutiny. You get per-control statuses, the evidence behind each one, and a prioritized gap list.

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

The best Model Audit Rule software is whatever holds the evidence behind your management assertion, because nobody outside the company ever audits that assertion. Unlike SOX Section 404(b), the NAIC Annual Financial Reporting Model Regulation asks for no independent accountant opinion on internal control over financial reporting. Your chief executive and chief financial officer sign, and the file you kept is what a financial condition examiner reads two years later.

That single difference should drive the whole buying decision, and almost no comparison in this category mentions it. Below is what each type of tool is built for, where the MAR evidence actually comes from in each, and where each one stops.

What is the best Model Audit Rule software?

There is no product category called Model Audit Rule software. What exists is SOX and ICFR tooling that insurers point at a statutory reporting basis, internal audit platforms that serve the Section 15 function, and statutory reporting platforms that produce the filings themselves. They solve different thirds of the same program.

ToolBuilt forWhere the MAR evidence comes fromPublishes pricingWhere it stops
WorkivaConnected statutory and regulatory reporting, including NAIC filings alongside SOX 302 and 404Linked data in the reporting documents themselvesNoStrongest on producing the filing. The control testing record is a separate discipline
Optro (formerly AuditBoard)ICFR control testing and internal audit workflow at large filersA controls register with testing cycles and issue trackingNoBuilt around the public company SOX calendar, which is not the June 1 statutory one
Wolters Kluwer TeamMateThe internal audit function itself, which Section 15 requires above the thresholdsAudit plans, workpapers and findingsNoIt documents the audits. Management still has to assemble its own Section 17 basis
DiligentBoard and audit committee governance plus enterprise GRCBoard materials, policies and a control libraryNoCommittee oversight is one Section 14 duty of several. The control evidence sits elsewhere
OnspringConfigurable GRC where one control library maps to several frameworksA mapped control library with workflow built on topNoConfiguration is the product. Somebody has to decide the statutory scope first
Spreadsheets plus your audit firmMost insurers crossing the threshold for the first timeA shared drive, and the memory of whoever ran it last yearNot applicable. The firm bills hourlyIt works until the person leaves or the examiner asks how a conclusion was reached
ScrutineerMapping controls to the statutory processes in scope and holding the evidence behind each assertionThe control record: owner, test performed, date, evidenceYes, in fullDoes not produce the statutory filing, and issues no attestation or certification

Those positions come from each vendor's own published product descriptions. None of them publishes a Model Audit Rule price, so treat any figure you have been quoted as specific to your scope and confirm it directly.

What are the Model Audit Rule requirements?

Every licensed insurer, at any size, owes the same baseline. An annual audit by an independent certified public accountant, an audited financial report filed with the commissioner on or before June 1 for the year ended the previous December 31, a letter from the accountant confirming awareness of the state insurance code, and a written communication of any unremediated material weaknesses that the accountant prepares within 60 days of that filing.

Above the premium thresholds, three more obligations attach: independent audit committee membership, an internal audit function reporting to that committee, and management's report of internal control over financial reporting. That last one is Section 17 of the current model. Plenty of published guidance still calls it Section 16, which was its number before the internal audit requirement was inserted as a new Section 15 in the 2014 revision, effective January 1, 2016. Everything below it moved down by one. Section 16 today is the prohibition on misleading the accountant.

What is the Model Audit Rule threshold?

This is where the summaries do the most damage. There is no single $500 million threshold. Model #205 runs three separate tests and they do not count premium the same way.

Audit committee independence tiers on prior calendar year direct written and assumed premium: no minimum below $300 million, a majority of independent members above $300 million, a supermajority of 75% or more above $500 million. The internal audit function exempts you below $500 million of direct written and unaffiliated assumed premium, and adds a group test at $1 billion. The management report applies at $500 million or more of direct written and assumed premium generally. Both of the latter two exclude premium reinsured with the Federal Crop Insurance Corporation and the Federal Flood Program.

Follow that through and you get combinations the one-number version cannot explain. An insurer carrying large affiliated assumptions can owe the ICFR report while remaining exempt from the internal audit function, because Section 15 ignores affiliated assumed premium and Section 17 does not. A modest company inside a $1 billion group is the mirror image: it needs the internal audit function and may owe no report. Work out your position from how your premium is composed, not from whether you are over half a billion dollars.

One more trigger gets missed entirely. Section 17B lets the commissioner require the report from any insurer, at any premium volume, that is in an RBC level event or meets the standards for being deemed in hazardous financial condition. Premium size is the usual door into this rule. It is not the only one.

What is the difference between the Model Audit Rule and SOX?

Three things, and only one of them is the one people name.

The basis of accounting differs: SOX reports on GAAP financial statements, MAR on statutory ones prepared under the practices your domiciliary department prescribes or permits. The audience differs: a SOX internal control report is published in the Form 10-K and anyone can read it, while Section 17E(2) requires the state insurance department to keep the MAR report and its supporting documentation confidential.

The difference that costs money is the third. Search the full text of Model #205 for the word attestation and it appears once, in the definitions, describing what makes an entity a SOX Compliant Entity. No independent accountant is asked anywhere to examine or report on management's ICFR assessment. Under SOX 404(b) an accelerated filer buys an external opinion that is expensive and also tells you when the work is sufficient. MAR removes the cost and the signal together. Management asserts, signs under Section 17D(7), and Section 17E requires it to document and make available the basis for those assertions on financial condition examination.

Read that as a lighter obligation and you have it backwards. An unaudited assertion with a thin file behind it is a worse position than an audited one, because the grading happens years later, by an examiner, against whatever you kept. The same logic drives every SOX compliance software decision, except that here the discipline has to be self-imposed.

How long do you have to comply after crossing the threshold?

Three obligations, three clocks, and the commonly quoted answer covers only one of them. Section 18F gives one year after the year the audit committee independence threshold is exceeded. Section 18H gives one year for the internal audit function. Section 18G gives two years for the management report. The two-year grace period everybody cites is the ICFR report alone, and the two governance changes that have to be in place before it are each half as long.

That ordering is deliberate and it is worth planning around. A drafting note in the model observes that adoption of Section 14 is assumed to occur one year before Section 17 takes effect. The committee and the internal audit function are supposed to exist first, so that there is somebody independent to receive the findings by the time management has to assert anything.

Can we file a SOX 404 report instead of a Model Audit Rule report?

Often yes, and the condition is scope rather than size. Section 17C lets an insurer that is directly subject to Section 404, or whose parent is, or that qualifies as a SOX Compliant Entity, file that 404 report in satisfaction of Section 17. What has to be true is that the controls with a material impact on preparing the audited statutory financial statements, meaning the items in Sections 5B through 5G, were inside the scope of the 404 report.

They often are not, because 404 scoping is built around consolidated GAAP reporting and statutory reporting is a different basis with its own schedules. So the model requires an addendum: a positive statement by management that no material statutory process was excluded. If something was excluded, you file the 404 report plus a Section 17 report covering only the processes it missed.

Deciding which statutory processes fell outside the 404 scope is a control mapping exercise, and it is the single highest-value piece of work in a first-year program. Done properly it can remove most of the reporting burden. Done casually it produces an addendum that says nothing was missed when something was.

What does management's report have to contain?

Section 17D lists seven items, and they are worth checking against your draft line by line: management's responsibility for ICFR, a statement that management established it plus an assertion whether it is effective, a description of the approach used to evaluate effectiveness, a description of the scope and any exclusions, disclosure of any unremediated material weaknesses, a statement on the inherent limitations of internal control, and the signatures of the chief executive officer and chief financial officer.

Item five carries a hard rule that occasionally surprises people. Management is not permitted to conclude that internal control over financial reporting is effective while even one unremediated material weakness is open. There is no room to weigh it against everything that is working. Either it is remediated by December 31 or the assertion changes.

On framework, the model names none. Section 17E(1) gives management discretion over the nature of the framework and over how much documentation to produce, explicitly so the assertion can be made cost effectively, including by referencing documentation you already keep. Most insurers use COSO because examiners recognize it. Nothing requires it.

How to choose

Start by working out which third of the program is actually short. If the filing itself is the pain, a connected reporting platform earns its keep. If you have just crossed the Section 15 threshold and have no internal audit function, the tooling question is secondary to hiring. If the gap is that nobody can show why management concluded a control was effective, that is an evidence problem and more reporting software will not touch it.

Scope the transaction cycles before you buy anything, because the scope decision determines how much of the rest matters. Premium, reserving, investments, reinsurance and disbursements are the usual significant cycles, and the disbursements side is where first-year programs most often find the control gap, particularly where approvals still run through email rather than a system that keeps an approval trail on payables. The IT general controls under all of it get traced first by examiners, so your access reviews, change management and job monitoring want to be in order before anything else; the ITGC layer is usually where a thin file shows.

Then pick for evidence. In a regime with no external opinion, the software's real job is to make it obvious, in October, which assertions are not yet supportable, so that December 31 is not the first time anyone finds out. That is what Model Audit Rule compliance software should be doing, and it is a narrower and more useful test than any feature grid.

See Scrutineer scrutinize your posture

Connect your stack, and Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and returns a readiness report with per-control statuses, linked evidence and a prioritized gap list. AI scrutinizes, you decide.

Scrutinize on real evidence, not stale spreadsheets

Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and scores vendor risk continuously, and returns a readiness report with a prioritized gap list. AI scrutinizes, you decide.

Automated evidence · Per-control statuses · Prioritized gap list

Mapped controls · evidence-linked rationale for every status · an accredited auditor issues the attestation.