At the 2026 Society of Financial Examiner’s (SOFE) Career Development Seminar in Orlando, several of Baker Tilly’s insurance industry specialists attended the seminar and hosted educational sessions covering a variety of popular insurance topics. They discussed topics ranging from information technology (IT) developments and the Model Audit Rule (MAR) to changes in artificial intelligence (AI) regulations and NAIC requirements. A breakdown of what we discussed in each Baker Tilly-hosted session is below.
If you have any questions or comments on these session insights, feel free to reach out to one of our specialists.
During this session, Baker Tilly insurance specialists Kelsey Barlow and Clarissa Crisp focused on practical strategies for improving examination efficiency without compromising regulatory rigor. The discussion explored common causes of examination delays, opportunities to streamline planning and communication, and techniques for reducing company burden while maintaining high-quality examination outcomes. Some main takeaways include:
- Plan smarter: Early planning measures will improve exam scope and efficiencies.
- Communicate proactively: A “no surprises” approach helps support a faster, smoother, closing conference.
- Document efficiently: Establish clear documentation expectations to improve workpaper quality and support a structured review process.
- Respect company time: Manage requests to ensure clear communication, reduce follow-up requests, and avoid delays in response time.
- Collaborate: Leverage work performed to the extent feasible to gain efficiencies and support exam conclusions.
- Stay risk-focused: A well-defined, risk-focused scope helps examination teams target what matters most, improving both examination quality and efficiency.
The session emphasized that examination efficiency is not about doing less work but about focusing effort where it matters most. Long examination cycle times can create challenges for regulators, companies, and policyholders alike by increasing resource demands, delaying corrective action, and reducing the timeliness of regulatory oversight. Common drivers of delays include scope creep, unclear document requests, staffing changes, communication breakdowns, and workpaper bottlenecks. Recognizing and addressing these issues early can help examination teams maintain momentum and avoid unnecessary rework.
Several best practices were discussed for improving examination planning and coordination. Effective exam teams leverage prior examination findings, financial analysis results, ORSA reports, and other available work products to inform risk-focused scoping decisions. Clear documentation of scope, consolidated document request lists, defined milestone calendars, and early role assignments help establish expectations before fieldwork begins. The session also highlighted the value of coordinating with financial analysts, lead states, and other stakeholders early in the process to avoid duplication of effort and better target examination resources.
Communication was identified as one of the most important factors influencing examination efficiency. Strong practices include conducting structured kickoff meetings, maintaining regular status discussions, using shared open-item trackers, and discussing developing findings throughout the examination rather than waiting until the closing conference. The presenters stressed the importance of a “no surprises” approach, whereby regulators and companies maintain open communication regarding expectations, requests, and emerging issues throughout the examination lifecycle.
The session also addressed documentation efficiency and reducing company burden. Examination teams can improve workpaper quality by establishing reviewer expectations upfront, documenting conclusions as testing is performed, using templates appropriately, and implementing structured review processes. At the same time, regulators can reduce company burden through organized document requests, clear communication regarding information needs, secure information-sharing tools, and appropriate reliance on validated work already performed by others. These practices help improve efficiency while preserving the quality and supportability of examination conclusions.
Ultimately, the session reinforced that quality and efficiency are not competing objectives. Well-planned, well-communicated, and risk-focused examinations are often both more effective and more efficient. By investing in planning, maintaining clear communication, documenting decisions in real time, and respecting company resources, regulators can shorten examination timelines while continuing to support strong solvency oversight and policyholder protection.
This session, hosted by Baker Tilly’s Russ Sommers, Jessie Adamson and Dennis Schaefer, focused on helping insurance examiners respond effectively when information technology general controls (ITGCs) are determined to be ineffective while maintaining examination quality and regulatory compliance. The discussion covered common IT examination findings, recurring control issues, compensating controls, and practical approaches for adapting examination procedures. Key takeaways include:
- Assess risk thoughtfully: Not every IT finding results in an ineffective ITGC conclusion. Consider the nature, scope, and significance of deficiencies.
- Evaluate compensating controls: ITGC and process level controls may reduce the impact of identified weaknesses.
- Address recurring issues: Documentation, governance, technical, and resource challenges can indicate broader control environment concerns.
- Collaborate across teams: Coordination between IT and financial examiners improves consistency and examination effectiveness.
- Adapt testing as needed: When ITGCs are ineffective, increase substantive testing and validate the accuracy and completeness of system-generated information.
This session emphasized that ineffective ITGCs require a risk-based, evidence-driven response rather than a default conclusion. By evaluating compensating controls, addressing recurring issues, and tailoring substantive procedures to identify risks, examination teams can maintain high-quality, efficient examinations while obtaining sufficient audit evidence.
Presented by insurance specialists Kelsey Barlow and Jessie Adamson, this session focused on how regulators can use Own Risk and Solvency Assessment (ORSA) reports to better understand insurer risk, solvency concerns and enterprise risk management (ERM) maturity.
The importance of understanding ORSA as both a process and a report:
- ORSA as an internal process: Insurers use ORSA to identify, assess, and manage risks that could affect their ability to meet policyholder obligations.
- ORSA Summary Report: The report provides regulators with a window into the insurer’s own view of its risks, capital position, and ERM practices.
- Regulatory expectations: ORSA should be conducted at least annually, integrated into strategic planning and capital management, reviewed at the board level and supported by company-specific stress scenarios.
- Three key report sections: Section 1 addresses the risk management framework, Section 2 identifies risk exposures, and Section 3 evaluates group risk capital and prospective solvency.
- Regulatory review focus: Regulators should look for consistency between the ORSA, financial statements, exam findings, RBC trends, and observable business conditions.
Best practices for reviewing ORSA reports include assessing whether the report is company specific, whether risk appetite is measurable, whether stress scenarios are severe enough to create meaningful capital pressure, and whether management can explain the assumptions behind the report.
The session emphasized that ORSA should not sit on a file until the next exam. Regulators can use ORSA findings to inform exam planning, prioritize scope areas, validate governance representations, and support ongoing risk-focused surveillance. A strong ORSA can signal a mature ERM culture, while a weak, boilerplate or overly optimistic ORSA may itself be an important risk indicator.
Effective use of ORSA helps regulators see what insurers are worried about before problems emerge, connect risk management practices to solvency oversight, and make more informed decisions about examination priorities and supervisory strategy.
Presented by insurance regulatory specialists John Romano and Clarissa Crisp, this session explored how NAIC Model Audit Rule 205 requires management's own report on Internal Control over Financial Reporting (ICFR), what makes that assertion credible, and how regulators can read it to decide where to rely and where to test. Some main takeaways include:
- The assertion stands on its own. For insurers above $500 million in direct written and assumed premiums, Section 16 of Model #205 requires management to report whether the company's ICFR was effective as of the prior Dec. 31. Unlike a Sarbanes-Oxley filer, a MAR filer does not require external auditor attestation, so credibility rests entirely on management's own process, documentation, and judgment.
- The support is the report. The conclusion is one sentence and almost always says "effective." A regulator does not assess the report by reading the report. The real assessment happens in the scoping, the testing, the deficiency log, and the certifications that sit behind the signature.
- One bright line cannot be crossed. Management cannot conclude that internal control is effective if even one material weakness remains unremediated as of the reporting date. A report that claims effectiveness with a known material weakness still open is not aggressive. It is wrong.
- Quality drives the exam. A strong file makes the assertion easy to rely on and lets an examiner narrow scope. A thin file, a confident conclusion with little behind it, forces the examiner to perform the work management claims was already done.
What quality looks like across four domains
A management assertion is only as good as the program behind it. The same four domains that build the assertion are where its quality shows, and where an examiner can confirm it.
- Materiality, scoping, and control environment: Quality starts with covering the right things. Look for a documented materiality threshold with defined high, moderate, and low tiers, a separate preparer and reviewer, and a clear line that runs from materiality to financial reporting risks to the key controls that address them. Scoping changes are signed off, entity-level controls are reviewed on a set cadence, and the materiality file reconciles to the annual and quarterly statements. A program that cannot trace that line is asserting effectiveness over a scope it never confirmed.
- Setup and planning: Strong programs run the MAR cycle like a project, not a year-end scramble. The signals are a documented timeline, a real kickoff with business owners, and narratives and risk-control matrices that are version-controlled and signed off. Add a training cadence for the business, rotational coverage so every key area is reached over time, and a governance tool or controlled repository that houses the work. Organized, repeatable evidence is what lets a conclusion hold up a year later.
- Fieldwork: The deepest domain, and the one that most often separates a credible assertion from a hollow one. Quality means annual walkthroughs and design testing on every key control with a preparer and a reviewer, a stated sampling methodology with exceptions documented honestly and at least one marked-up example per control, and a formal deficiency process that ranks gaps as deficiencies, significant deficiencies, or material weaknesses on consistent criteria, with owners, remediation dates, and a second round of testing before anything is called closed. The evidence produced here is what the signature actually rests on.
- Monitoring and reporting: A conclusion no one governs is not worth much. Quality means deficiencies and remediation reported to the audit committee or board, controls reassessed when the business changes through acquisitions or system upgrades, and functional-area certifications that roll up to the CEO and CFO behind the management report. Governance and certification are what turn a stack of testing into a defensible assertion.
The deeper point for insurers is that the value of the management report is not the assertion. It is the discipline required to make the assertion truthfully. A company that builds that discipline gets an early read on control breakdowns and a board that can sign with confidence. A company that treats the report as a year-end signature gets a document that says "effective" and a control environment no one has actually tested.
The signature is the easy part. Whether it should have been signed is the question the support answers.
This session provided a practical framework for financial examiners to assess insurers’ use of artificial intelligence (AI). Hosted by Russ Sommers and Dennis Schaefer, it explained why AI oversight has become a regulatory priority and demonstrates how existing insurance regulatory frameworks can be applied to AI governance, risk management, cybersecurity and even third-party oversight. Some key takeaways:
- This session prioritizes that AI is now widely used throughout the insurance industry for underwriting, pricing, claims processing, fraud detection, customer service and operational decision-making. As a result, financial examiners are expected to evaluate AI governance alongside traditional IT and operational controls.
- It is encouraged that examiners should leverage existing regulatory frameworks – particularly the NAIC AI Model Bulletin, NY DFS Circular Letter 7, NIST AI RMF, COSO, and Model Law 668 – to evaluate AI programs in a structured and consistent manner.
- Examiners should expect insurers to maintain a comprehensive inventory of AI systems that should cover both internally developed and vendor-provided AI systems, including generative AI tools use by employees.
- A mature AI governance program should include board oversight, written and defined AI policies, clearly assigned responsibilities, cross-functional governance committees, proper employee training, internal audit involvement and ongoing model validation and monitoring.
The central message from this session was that AI examinations are becoming a routine component of insurance financial condition examinations. Regulators do not expect insurers to eliminate AI risk, but they do expect robust governance, documented inventories, effective model oversight, independent validation, cybersecurity controls and clear accountability.
This session, presented by Kelsey Barlow and Jessie Adamson, explored how regulators can use NAIC financial analysis tools to identify solvency concerns, emerging risks, and early warning indicators before they develop into more serious issues. Some key takeaways include:
The importance of using financial analysis tools together as part of a broader risk surveillance framework:
- Annual statements: Provide the foundational financial data for analysis.
- FAST ratios: Serve as an early warning system by highlighting profitability, liquidity, reserve adequacy, capital, and leverage concerns.
- Risk-based capital (RBC): Helps regulators assess whether an insurer’s capital buffer is adequate, while also requiring deeper review of trends and risk components.
- Financial analysis handbook: Provides a structured workflow for profiling companies, prioritizing risk areas, conducting targeted analysis, documenting findings, and determining regulatory action.
- ORSA summary reports: Add management’s own perspective on risk, capital, and ERM maturity.
- Financial examinations: Verify or challenge what surveillance and analysis identify.
Financial analysts play a key role as the first line of regulatory defense. Their work helps prioritize companies for review, identify trends over multiple years, shape pre-exam intelligence, and support ongoing monitoring between exam cycles.
The session emphasized that ratios should be treated as questions, not answers. For example, a declining risk-based capital (RBC) ratio may be more concerning than the current percentage alone, and a FAST ratio outside the usual range requires context around business strategy, reinsurance, reserves, dividends, investments, and management explanations.
Early warning indicators discussed included deteriorating FAST trends, declining RBC ratios, excessive dividend extraction, rapid premium growth, management instability, restatements, audit issues, and emerging risks such as catastrophe exposure, cyber liability, long-term care experience, interest rate sensitivity, and concentration risk.
Robust financial analysis requires clear documentation of the company profile, analysis performed, findings, management context, risk rating, and recommended action. The session reinforced that “no action” is still a regulatory decision and should be documented.
Effective risk surveillance depends on using FAST, RBC, the Financial Analysis Handbook, ORSA and exam findings as an integrated system. The “magic” is not in any single number, but in the analyst’s ability to interpret trends, ask the right questions, document judgments, and translate findings into timely regulatory action.
We hope the above insights serve as a valuable resource for organizations looking to strengthen their governance frameworks, enhance risk management practices, and stay ahead of emerging regulatory and technology-driven developments. If you would like to discuss any of these topics or learn more about how these trends may impact your organization, please feel free to reach out. We welcome the opportunity to continue the conversation on important matters impacting the insurance industry and answer any questions you may have.
For more information on these topics and to stay on top of the latest SOFE updates, check out our insurance regulators webpage.
Related sections
- Actuarial Services
- Artificial Intelligence
- Cybersecurity
- Data Analytics
- Enterprise Risk Management
- Examination Readiness Services
- Financial Services
- Fraud & Forensic Investigations
- Insurance
- Insurance Regulators
- Insurtech
- Internal Audit
- IT Audit Solutions
- Model Audit Rule
- Risk Advisory
- Sarbanes-Oxley (SOX) Compliance
- System & Organization Controls (SOC) Reporting



