Scrutineer.ai

Scrutineer · By framework

Model Audit Rule compliance software for NAIC insurers

The Model Audit Rule is the NAIC Annual Financial Reporting Model Regulation, Model #205, as your own state adopted it. Cross the premium thresholds and three separate obligations begin, on three different clocks: audit committee independence, an internal audit function, and a management report on internal control over financial reporting.

Scrutineer holds the control documentation behind that report. Every assertion traces to a control, an owner, a test date and the evidence, which is the record a financial condition examiner asks to see.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with MAR compliance

Every guide quotes one $500 million threshold. Model #205 runs three tests, and they do not count the same premium

Read the model rather than the summaries and the single number falls apart. Section 14, audit committee independence, tiers on prior calendar year direct written and assumed premium: nothing below $300 million, a majority of independent members above $300 million, a supermajority of 75% or more above $500 million. Section 15, the internal audit function, exempts you below $500 million of direct written and unaffiliated assumed premium, and adds a second test: if you sit in a group, the group has to be below $1 billion too. Section 17, the management report on internal control over financial reporting, applies at $500 million or more of direct written and assumed premium. Both Section 15 and Section 17 exclude premium reinsured with the Federal Crop Insurance Corporation and the Federal Flood Program. Section 15 counts only unaffiliated assumed premium and Section 17 counts assumed premium generally, so an insurer carrying large affiliated assumptions can owe the ICFR report and still be exempt from the internal audit function. A small company inside a $1 billion group is the reverse case. Three tests, three definitions, and whether each one bites you is a question about how your premium is composed, not about whether you are over half a billion dollars.

No accountant ever opines on your ICFR assertion, which is exactly why the documentation is the whole job

This is the point where the comparison to Sarbanes-Oxley quietly breaks, and it is the one that decides how much work you are in for. Search the full text of Model #205 for the word attestation and it appears once, in the definitions, describing what makes an entity a SOX Compliant Entity. Nowhere in Section 17 is an independent accountant asked to examine or report on management’s assessment of internal control over financial reporting. Under SOX, an accelerated filer gets Section 404(b): the auditor tests the controls and issues an opinion, which is expensive and also tells you when you have done enough. The Model Audit Rule has no such backstop. Your chief executive and chief financial officer sign an assertion under Section 17D(7), and Section 17E says management shall document and make available, on financial condition examination, the basis on which those assertions were made. So nobody grades the work in the year you do it. The grading happens later, at examination, against whatever documentation you kept. Insurers who treat that as a lighter obligation are reading it backwards: an unaudited assertion with the file behind it is the only thing standing between the signature and the examiner.

If a parent files a SOX 404 report you may owe no Section 17 report at all, and the addendum is the part people miss

Section 17C is a genuine off-ramp and it is under-used. An insurer directly subject to Section 404, or whose parent is, or which is a SOX Compliant Entity, or which sits in a holding company system under one, may file that Section 404 report in satisfaction of Section 17. The condition is scope. The controls with a material impact on the preparation of the audited statutory financial statements, meaning the items in Sections 5B through 5G, have to have been inside the 404 report. Because 404 scoping is built around GAAP consolidated reporting and statutory reporting is a different basis, they frequently are not. That is why the model requires an addendum: a positive statement by management that no material statutory process was left out of the 404 report. If something was left out, you file the 404 report plus a Section 17 report covering only the processes it missed. Working out which statutory processes fell outside the 404 scope is a control mapping exercise, and it is the part that decides whether this route saves you a year of work or quietly understates your filing.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps one control library to the statutory processes behind Sections 5B through 5G, so the scope of the Section 17 report is a documented decision rather than an assumption
  • Tracks all three Model #205 premium tests separately, because the audit committee tier, the internal audit exemption and the ICFR report threshold count premium differently
  • Holds the basis for each management assertion, the control, the owner, the test performed and the date, which is what Section 17E requires you to make available on financial condition examination
  • Flags unremediated material weaknesses against the Section 17D(5) rule that management may not conclude ICFR is effective while even one remains open
  • Runs the Section 17C comparison for groups with a SOX parent: which statutory processes were inside the 404 scope and which need a Section 17 report of their own
  • Keeps the control testing calendar aligned to the filing sequence, the audited financial report by June 1 and the management report with the Section 11 communication 60 days later
  • Carries ITGC evidence for the systems that produce the statutory statements, the access reviews, change management and job monitoring an examiner traces first
  • Gives the internal audit function required above the Section 15 thresholds a single record to test against, instead of a document hunt each cycle
MAR compliance readiness_report
Readiness 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Every finding links to the evidence behind it

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Model #205 threshold reference

Which Model Audit Rule obligation bites you, on what premium, and how long you have

Published guides run this as one list of requirements under one $500 million threshold with a two-year grace period. The model does not work that way. This table runs the axis that actually decides your position: which test each obligation applies, how it counts premium, how long the clock is once you cross, and whether anyone outside the company signs anything. Section and subsection references are to the NAIC Annual Financial Reporting Model Regulation, Model #205, which your state adopts with its own variations.

Obligation Threshold test How the premium is counted Clock once you cross Does an outside accountant opine?
Audit committee: majority independent (Sec. 14H) Over $300,000,000 up to $500,000,000 Prior calendar year direct written and assumed premium One year after the year the threshold is exceeded No
Audit committee: supermajority, 75% or more independent (Sec. 14H) Over $500,000,000 Prior calendar year direct written and assumed premium One year after the year the threshold is exceeded No
Internal audit function (Sec. 15) Insurer at $500,000,000 or more, or a group at $1,000,000,000 or more Direct written and unaffiliated assumed premium, excluding FCIC and Federal Flood Program One year after the year the threshold is exceeded No
Management’s report on internal control over financial reporting (Sec. 17A) $500,000,000 or more Direct written and assumed premium, excluding FCIC and Federal Flood Program Two years after the year the threshold is exceeded No. There is no equivalent of SOX 404(b)
The same report, by order (Sec. 17B) Any RBC level event, or deemed in hazardous financial condition, at any size No threshold applies At the commissioner’s direction No
Filing a SOX 404 report instead (Sec. 17C) Insurer or parent directly subject to Section 404, or a SOX Compliant Entity No threshold. It is a scope test, not a size test Follows the parent’s SOX calendar Yes, on the 404 report. Management still signs the addendum
Communication of internal control matters (Sec. 11) Every insurer that files an audited financial report No threshold applies Within 60 days of filing the audited financial report Yes. The accountant prepares it

Good questions

Questions about MAR compliance

The Model Audit Rule is the NAIC Annual Financial Reporting Model Regulation, Model #205. It requires every US insurer to file an audited statutory financial report, and it layers corporate governance and internal control duties on larger insurers: audit committee independence, an internal audit function, and a management report on internal control over financial reporting. It is state law, adopted state by state, not a federal rule.
Every insurer files an audited financial report by June 1 and an accountant communication on unremediated material weaknesses within 60 days of that filing. Above the premium tiers you also need independent audit committee members, an internal audit function reporting to that committee, and management’s report on internal control over financial reporting signed by the chief executive and chief financial officer.
Section 17 in the current model. A great deal of published commentary still cites Section 16, which was its number before the internal audit function was added as a new Section 15 in the 2014 revision, effective January 1, 2016. That insertion pushed everything below it down by one. Section 16 today is the prohibition on misleading the accountant. Cite the requirement by name to avoid the confusion.
There is no single threshold. Audit committee independence tiers at $300 million and $500 million of prior calendar year direct written and assumed premium. The internal audit function exemption sits at $500 million for the insurer and $1 billion for the group, counting unaffiliated assumed premium only. The ICFR report applies at $500 million of direct written and assumed premium. The three tests count premium differently.
Section 17D lists seven items: that management is responsible for ICFR, that management established it plus an assertion whether it is effective, a description of the approach used to evaluate it, a description of the scope and any exclusions, disclosure of any unremediated material weaknesses, a statement on the inherent limitations of internal control, and the signatures of the chief executive officer and chief financial officer.
No. Unlike SOX Section 404(b), Model #205 asks no independent accountant to examine or report on management’s ICFR assertion. The word attestation appears once in the whole model, in the definitions, describing a SOX Compliant Entity. Management asserts and signs alone, and the documentation supporting the assertion is reviewed later, during a financial condition examination.
SOX applies to public registrants and reports on GAAP financial statements; the Model Audit Rule applies to licensed insurers and reports on statutory financial statements. The bigger practical difference is the auditor opinion. SOX 404(b) buys an external opinion on your controls. The Model Audit Rule has no such provision, so the burden of proving the assertion sits entirely with management and its documentation.
It depends which obligation. Section 18F gives one year after the year the audit committee independence threshold is exceeded. Section 18H gives one year for the internal audit function. Section 18G gives two years for the management report on internal control over financial reporting. The widely quoted two-year grace period is only the ICFR report; the other two clocks are half as long.
The audited financial report is due on or before June 1 for the year ended the previous December 31. Management’s report of internal control over financial reporting is filed along with the Section 11 accountant communication, which the accountant prepares within 60 days after that filing. In practice that puts the management report at the start of August, and it speaks as of December 31 immediately preceding.
Yes, under Section 17C, if the controls with a material impact on preparing the audited statutory financial statements were inside the scope of that 404 report. You attach an addendum: a positive statement by management that no material statutory process was excluded. If something was excluded, you file the 404 report plus a Section 17 report covering just the processes it missed.
An insurer with $500 million or more of annual direct written and unaffiliated assumed premium, or one that sits in a group at $1 billion or more, both excluding premium reinsured with the Federal Crop Insurance Corporation and the Federal Flood Program. The function must be organizationally independent, headed by someone with direct and unrestricted access to the board, and must report to the audit committee at least annually.
Section 7D(1) says the lead or coordinating audit partner with primary responsibility for the audit may not serve in that capacity for more than five consecutive years, and is then disqualified from that or a similar role for the same company or its insurance subsidiaries and affiliates for five consecutive years. Relief can be requested from the commissioner for unusual circumstances, at least 30 days before year end.
It is the industry name for the letter required by Section 6B; the model itself never uses the phrase. The insurer obtains a letter from its accountant, and files a copy with the commissioner, stating that the accountant is aware of the insurance code and department regulations relating to accounting and financial matters, and affirming the opinion will be expressed in terms of conformity to statutory accounting practices.
Yes. Section 17B lets the commissioner require Management’s Report of Internal Control over Financial Reporting from any insurer, regardless of premium volume, if the insurer is in an RBC level event or meets one or more of the standards for being deemed in hazardous financial condition. Premium size is the usual trigger, not the only one, which is worth knowing before you conclude the rule does not reach you.
No. Section 17E(2) says the report, and any documentation provided in support of it during a financial condition examination, shall be kept confidential by the state insurance department. That is the opposite of SOX, where management’s internal control report is published in the annual report on Form 10-K and read by anyone who wants it.
None specifically. Section 17E(1) gives management discretion over the nature of the framework and over the nature and extent of the documentation, so the assertion can be made cost effectively, including by assembling or referencing documentation you already keep. Most insurers use COSO because examiners recognize it, but the model does not name it.
Parts of it apply to every licensed insurer: the annual independent audit, the June 1 filing, the accountant qualification and rotation rules, and the Section 11 communication of internal control matters. What the premium thresholds control is the additional governance layer, meaning audit committee independence, the internal audit function and the ICFR report. Adoption and thresholds vary by state.

Keep reading

Guides that go deeper on this framework

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification