Scrutineer · By framework
Model Audit Rule compliance software for NAIC insurers
The Model Audit Rule is the NAIC Annual Financial Reporting Model Regulation, Model #205, as your own state adopted it. Cross the premium thresholds and three separate obligations begin, on three different clocks: audit committee independence, an internal audit function, and a management report on internal control over financial reporting.
Scrutineer holds the control documentation behind that report. Every assertion traces to a control, an owner, a test date and the evidence, which is the record a financial condition examiner asks to see.
Control-mapped findings · linked evidence · you decide what to remediate
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with MAR compliance
Every guide quotes one $500 million threshold. Model #205 runs three tests, and they do not count the same premium
Read the model rather than the summaries and the single number falls apart. Section 14, audit committee independence, tiers on prior calendar year direct written and assumed premium: nothing below $300 million, a majority of independent members above $300 million, a supermajority of 75% or more above $500 million. Section 15, the internal audit function, exempts you below $500 million of direct written and unaffiliated assumed premium, and adds a second test: if you sit in a group, the group has to be below $1 billion too. Section 17, the management report on internal control over financial reporting, applies at $500 million or more of direct written and assumed premium. Both Section 15 and Section 17 exclude premium reinsured with the Federal Crop Insurance Corporation and the Federal Flood Program. Section 15 counts only unaffiliated assumed premium and Section 17 counts assumed premium generally, so an insurer carrying large affiliated assumptions can owe the ICFR report and still be exempt from the internal audit function. A small company inside a $1 billion group is the reverse case. Three tests, three definitions, and whether each one bites you is a question about how your premium is composed, not about whether you are over half a billion dollars.
No accountant ever opines on your ICFR assertion, which is exactly why the documentation is the whole job
This is the point where the comparison to Sarbanes-Oxley quietly breaks, and it is the one that decides how much work you are in for. Search the full text of Model #205 for the word attestation and it appears once, in the definitions, describing what makes an entity a SOX Compliant Entity. Nowhere in Section 17 is an independent accountant asked to examine or report on management’s assessment of internal control over financial reporting. Under SOX, an accelerated filer gets Section 404(b): the auditor tests the controls and issues an opinion, which is expensive and also tells you when you have done enough. The Model Audit Rule has no such backstop. Your chief executive and chief financial officer sign an assertion under Section 17D(7), and Section 17E says management shall document and make available, on financial condition examination, the basis on which those assertions were made. So nobody grades the work in the year you do it. The grading happens later, at examination, against whatever documentation you kept. Insurers who treat that as a lighter obligation are reading it backwards: an unaudited assertion with the file behind it is the only thing standing between the signature and the examiner.
If a parent files a SOX 404 report you may owe no Section 17 report at all, and the addendum is the part people miss
Section 17C is a genuine off-ramp and it is under-used. An insurer directly subject to Section 404, or whose parent is, or which is a SOX Compliant Entity, or which sits in a holding company system under one, may file that Section 404 report in satisfaction of Section 17. The condition is scope. The controls with a material impact on the preparation of the audited statutory financial statements, meaning the items in Sections 5B through 5G, have to have been inside the 404 report. Because 404 scoping is built around GAAP consolidated reporting and statutory reporting is a different basis, they frequently are not. That is why the model requires an addendum: a positive statement by management that no material statutory process was left out of the 404 report. If something was left out, you file the 404 report plus a Section 17 report covering only the processes it missed. Working out which statutory processes fell outside the 404 scope is a control mapping exercise, and it is the part that decides whether this route saves you a year of work or quietly understates your filing.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Maps one control library to the statutory processes behind Sections 5B through 5G, so the scope of the Section 17 report is a documented decision rather than an assumption
- Tracks all three Model #205 premium tests separately, because the audit committee tier, the internal audit exemption and the ICFR report threshold count premium differently
- Holds the basis for each management assertion, the control, the owner, the test performed and the date, which is what Section 17E requires you to make available on financial condition examination
- Flags unremediated material weaknesses against the Section 17D(5) rule that management may not conclude ICFR is effective while even one remains open
- Runs the Section 17C comparison for groups with a SOX parent: which statutory processes were inside the 404 scope and which need a Section 17 report of their own
- Keeps the control testing calendar aligned to the filing sequence, the audited financial report by June 1 and the management report with the Section 11 communication 60 days later
- Carries ITGC evidence for the systems that produce the statutory statements, the access reviews, change management and job monitoring an examiner traces first
- Gives the internal audit function required above the Section 15 thresholds a single record to test against, instead of a document hunt each cycle
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Model #205 threshold reference
Which Model Audit Rule obligation bites you, on what premium, and how long you have
Published guides run this as one list of requirements under one $500 million threshold with a two-year grace period. The model does not work that way. This table runs the axis that actually decides your position: which test each obligation applies, how it counts premium, how long the clock is once you cross, and whether anyone outside the company signs anything. Section and subsection references are to the NAIC Annual Financial Reporting Model Regulation, Model #205, which your state adopts with its own variations.
| Obligation | Threshold test | How the premium is counted | Clock once you cross | Does an outside accountant opine? |
|---|---|---|---|---|
| Audit committee: majority independent (Sec. 14H) | Over $300,000,000 up to $500,000,000 | Prior calendar year direct written and assumed premium | One year after the year the threshold is exceeded | No |
| Audit committee: supermajority, 75% or more independent (Sec. 14H) | Over $500,000,000 | Prior calendar year direct written and assumed premium | One year after the year the threshold is exceeded | No |
| Internal audit function (Sec. 15) | Insurer at $500,000,000 or more, or a group at $1,000,000,000 or more | Direct written and unaffiliated assumed premium, excluding FCIC and Federal Flood Program | One year after the year the threshold is exceeded | No |
| Management’s report on internal control over financial reporting (Sec. 17A) | $500,000,000 or more | Direct written and assumed premium, excluding FCIC and Federal Flood Program | Two years after the year the threshold is exceeded | No. There is no equivalent of SOX 404(b) |
| The same report, by order (Sec. 17B) | Any RBC level event, or deemed in hazardous financial condition, at any size | No threshold applies | At the commissioner’s direction | No |
| Filing a SOX 404 report instead (Sec. 17C) | Insurer or parent directly subject to Section 404, or a SOX Compliant Entity | No threshold. It is a scope test, not a size test | Follows the parent’s SOX calendar | Yes, on the 404 report. Management still signs the addendum |
| Communication of internal control matters (Sec. 11) | Every insurer that files an audited financial report | No threshold applies | Within 60 days of filing the audited financial report | Yes. The accountant prepares it |
Good questions
Questions about MAR compliance
Keep reading
Guides that go deeper on this framework
Best Model Audit Rule software compared
What each category of tool does with a statutory ICFR program, and where each one stops.
Read the guideSOX compliance requirements
The Section 404 program the Model Audit Rule borrows from, and the auditor opinion it leaves out.
Read the guideITGC controls explained
The IT general controls over the systems that produce your statutory statements, which examiners trace first.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification