Audit Preparation Checklist
Audit Scope and Kickoff
Confirm whether this is a Model Audit Rule (MAR) financial audit, a state DOI market-conduct exam, a SOC 2 Type II review, or an internal audit. Each has different scope, evidence expectations, and statutory deadlines — getting this wrong upstream means producing the wrong workpapers.
Map each item on the auditor's prepared-by-client (PBC) list to a named owner — finance, claims, underwriting, IT, legal. Set internal due dates two weeks ahead of the auditor's deadline so reviewers have buffer.
Financial Documentation
Pull the balance sheet, income statement, cash flow statement, and statutory annual statement (Schedules F, P, and T for P&C carriers) covering the full audit period. Include comparative prior-year figures and tie-outs to the trial balance.
Reconcile every premium-trust, claims, and operating account through the audit period-end. Document any reconciling items older than 30 days — stale items are a recurring auditor finding and a state DOI premium-trust concern.
Reconcile written-premium and earned-premium balances between the GL and the policy admin system (Guidewire PolicyCenter, Duck Creek, or Applied Epic). Variances over the carrier's materiality threshold need a written explanation before the auditor sees them.
Summarize case reserves, IBNR, and ALAE/ULAE by line of business, with the actuarial memo supporting the booked reserve. Include the prior-year development triangle — auditors will compare booked reserves to actuarial central estimate and flag any material divergence.
Document recoverables by reinsurer with A.M. Best ratings and any disputed balances. Treaty cessions should tie to the cedant's underwriting and claim records — following-form mismatches are a common Schedule F adjustment.
Compliance and Legal
Run a NIPR report for every producer who bound business during the audit period. Confirm NPN, resident-state license, non-resident appointments in every state where the producer bound, and current CE. Lapsed CE means unauthorized transactions during the lapse window.
For every state and line written, confirm the filing posture (prior approval, file-and-use, use-and-file) and that the implemented rates/forms match what's on file in SERFF. A rate change pushed live before PA-state approval is the classic market-conduct finding.
Any Covered Entity doing insurance business in NY needs the CISO certification, MFA evidence, biennial risk assessment, and vendor risk program documentation ready. Determine whether Part 500 is in scope before deciding which artifacts to assemble in the next step.
Pull the most recent CISO report to the board, biennial risk assessment, annual penetration test, MFA enforcement evidence (including third-party VPN access under §500.12), and the vendor risk inventory under §500.11. Include the 72-hour incident notification log even if empty.
Include the current written information security program, the most recent annual privacy notice mailing, and state-specific opt-out handling — Vermont opt-in, California CCPA/CPRA disclosures for personal lines.
Provide outside counsel's audit response letter, a schedule of pending bad-faith and coverage suits, and any open ROR letters. Tie reserved amounts back to the GL.
Internal Controls and Procedures
Sample 25 bound policies across the audit period and trace each to the producer's binding-authority document — line of business, hazard grade, limit, and premium size. Out-of-authority binds are the most common UW control finding.
Sample open and closed claims to confirm reserves were updated on the carrier's 30/60/90-day cadence and that settlement payments were within the assigned adjuster's authority. Document any Texas Chapter 542 prompt-payment exceptions.
The person who sets up a payee should not be the person who approves the payment. Pull the system access matrix and flag any user who has both. This is a top-five SOX/MAR finding when missed.
Many carriers screen at policy issuance but skip claim-payment screening. Pull the OFAC scan log for a sample of claim payees and confirm SDN-list checks ran within 24 hours of payment release.
NY, CA, FL, NJ, OH, NM, KY, LA, and MN all require periodic Anti-Fraud Plan filings. Confirm the most recent filing matches the SIU's actual operating procedures — acquired books often inherit unfiled or stale plans.
Provide evidence of a successful backup restore test within the audit period and the most recent quarterly access review for PolicyCenter, ClaimCenter, and the AMS. Untested backups and stale terminated-employee accounts are recurring SOC 2 and Part 500 findings.
Final Review and Sign-Off
Walk the CFO, General Counsel, and CISO through the assembled package. Surface any known issues now — auditors respond better to a self-disclosed weakness with a remediation plan than to one they discover.
Use this template in Manifestly
- Annual Insurance Review Checklist
- Risk Management Checklist
- Commercial Policy Renewal Checklist
- Customer Inquiry Checklist
- Insurance Compliance Checklist
- Cyber Security Checklist
- Claims Investigation Checklist
- Complaint Resolution Checklist
- Financial Audit Checklist
- Data Security Checklist
- Risk Mitigation Checklist
- Customer Service Request Handling Checklist
- Disaster Recovery Checklist
- Policy Renewal Checklist
- Customer Retention Checklist
- Policy Issuance Checklist
- Sales Proposal Checklist
- Claims Auditing Checklist
- Policy Cancellation Checklist
- Customer Onboarding Checklist
- Insurance Training and Development Checklist
- Anti-Money Laundering Checklist
- Training Evaluation Checklist
- Insurance Producer Performance Review
- Cybersecurity Incident Response Checklist
- Office Opening Checklist
- Training Needs Assessment Checklist
- Insurance Committee Meeting Planning Checklist
- Skills Development Checklist
- Network Security Checklist
- Premium Billing and Collection Checklist
- IT Asset Inventory Management Checklist
- Annual Budgeting Checklist
- Financial Reporting Checklist
- Insurance Agency Lead Generation Checklist
- Compliance Audit Checklist
- Commercial Underwriting Checklist
- Policyholder Feedback Cycle
- Insurance Project Planning Checklist
- Tax Compliance Checklist
- Insurance Agency Office Closing Checklist
- Client Engagement Checklist
- Data Protection Checklist
- Insurance Agency Employee Onboarding
- Enterprise Risk Assessment Checklist
- Training Materials Checklist
- Anti-Fraud Checklist
- Policy Endorsement Checklist
- Quarterly Risk Monitoring Checklist
- Expense Management Checklist
- Insurance IT Security Review Checklist
- Insurance Account Cross-Sell Checklist
- Insurance Project Closure Checklist
- Insurance Marketing Campaign Checklist
- Statutory Financial Reporting Checklist
- Claim Processing Checklist
- Policy Administration Checklist
- Financial Statement Audit Checklist
- Audit Preparation Checklist
- Fixed Assets Audit Checklist
- External Audit Preparation Checklist
- Financial Audit Checklist
- Risk Assessment Checklist
- Post-Merger Audit Checklist
- Employee File Audit Checklist
- Engagement Risk Management Checklist
- Rent Roll Audit Checklist
- Financial Audit Checklist
- Quarterly Industry Standards Compliance Review
- Compliance Audit Checklist
- HR Audit Checklist
- Social Media Audit Checklist
- Risk Management Checklist
- Regulatory Compliance Checklist
- Quarterly Internal Control Review Checklist
- Sales Tax Reporting Checklist
- Legal Entity Management Checklist
- Employee File Audit Checklist
- Anti-Money Laundering Compliance Checklist
- SOX Compliance Checklist
- GDPR Compliance Review Checklist
- IT Security Audit Checklist
- HR Compliance Checklist
- Payroll Processing Checklist
- Building Code Compliance Checklist
- Employee Records Management Checklist
- Legal Document Storage Checklist
- Security Audit Checklist
- Property Risk Assessment Checklist
- Property Safety Inspection Checklist
- Cybersecurity Protocol Checklist
- Fair Housing Compliance Checklist
- Legal Compliance Checklist for New Properties
- Lease Agreement Checklist
- Software Licensing Compliance Checklist
- PCI DSS Compliance Checklist
- Real Estate Legal Compliance Checklist
- HIPAA Compliance Checklist
- MLS Listing Review Checklist
- Real Estate License Renewal Checklist
- GDPR Compliance Checklist
- Real Estate Contract Review Checklist
- Fair Housing Compliance Audit
- Listing Agreement Intake Checklist
- ISO/IEC 27001 Compliance Checklist
- HR Compliance Checklist
- Real Estate Ethics & Compliance Review
- Brokerage Trust Account Management Checklist
- Real Estate Professional Development Checklist
- Brokerage Technology Inventory Audit
- Real Estate Website Audit Checklist
- Continuing Education Checklist
- Employee Termination Checklist
- Employee Records File Audit
- Regulatory Compliance Checklist
- Brokerage HR Policy Compliance Checklist
- Employee Handbook Annual Review
- Employee Termination Checklist
- Data Privacy Compliance Checklist
- Risk Management Checklist
- Insurance Compliance Checklist
- Complaint Resolution Checklist
- Financial Audit Checklist
- Data Security Checklist
- Risk Mitigation Checklist
- Claims Auditing Checklist
- Quarterly Industry Standards Compliance Review
- Insurance Training and Development Checklist
- Anti-Money Laundering Checklist
- Training Evaluation Checklist
- Manufacturing Regulatory Compliance Checklist
- Training Needs Assessment Checklist
- Skills Development Checklist
- Network Security Checklist
- Employee Offboarding Checklist
- IT Asset Inventory Management Checklist
- Regulatory Reporting Checklist
- Compliance Audit Checklist
- Insurance Program Initiation Checklist
- Insurance Program Launch Project Monitoring Checklist
- Training Materials Checklist
- Quarterly Risk Monitoring Checklist
- System Backup Checklist
- Employee Benefits Checklist
- Insurance Program Launch Execution Checklist
- Insurance Marketing Campaign Checklist
- Email Compliance Checklist
- Law Firm Compliance Checklist
- Anti-Money Laundering Compliance Checklist
- Law Firm Compliance Checklist
- Professional Responsibility Compliance Review
- Data Privacy Compliance Checklist
- Law Firm Risk Management Checklist
- HR Audit Checklist
- HR Compliance Checklist
- Email Deliverability Checklist
- Law Firm Ethics Compliance Review
- Document Retention Policy Checklist
- Employee File Audit Checklist
- Law Firm Risk Management Checklist
- Cloud Security Checklist
- User Access Review Checklist
- IT Regulatory Compliance Review
- Compliance Audit Checklist
- Security Audit Checklist
- Business Continuity Checklist
- Employee Termination Checklist
- Quarterly Operations and Compliance QA Review
- Expense Management Checklist
- Advisor and Employee Onboarding Checklist
- Client Satisfaction Survey Checklist
- Operational Risk Checklist
- Know Your Customer (KYC) Checklist
- Litigation Preparation Checklist
- Contract Review Checklist
- New Hire Onboarding Checklist
- Client Onboarding Checklist
- Contract Review Checklist
- Regulatory Compliance Checklist
- Monthly Financial Reporting Checklist
- Regulatory Reporting Checklist
- Intellectual Property Management Checklist
- Internal Audit Checklist
- Lead Generation Checklist
- Annual Financial Reporting Checklist
- Annual Compliance Program Review
- Annual Risk Assessment Checklist
- Data Security Review Checklist
- Quarterly Performance Measurement Checklist
- Financial Services Project Initiation Checklist
- IT Policy Review Checklist
- Data Protection Checklist
- E-commerce Sales Tax Reporting Checklist
- Project Execution Checklist
- Project Planning Checklist
- Project Monitoring Checklist
- Financial Statement Review Checklist
- Quarterly Compliance Monitoring Checklist
- Cybersecurity Risk Assessment Checklist
- Project Closure Checklist
- Financial Services IT Security Audit Checklist
- PCI DSS Compliance Checklist
- Advisor and Staff Onboarding Checklist
- Cybersecurity Incident Response Checklist
- E-commerce Risk Management Checklist
- CRM Data Entry Checklist
- Business Continuity Plan Checklist
- E-commerce Legal Compliance Checklist
- Vendor Contract Review Checklist
- Annual Risk Management Review Checklist
- Risk Assessment Checklist
- Agency Compliance and Risk Management Checklist
- Annual School Compliance Audit
- School First Aid and Emergency Medication Audit
- Motor Carrier TSA Security Compliance Checklist
- Internal Controls Checklist
- Client Communication Checklist
- Restaurant Permit and Licensing Renewal Checklist
- New Hire Paperwork Checklist
- Restaurant Policy Update Checklist
- Restaurant New Hire Checklist
- Annual Attorney Professional Conduct Review
- International Fuel Tax Agreement (IFTA) Quarterly Filing Checklist
- Restaurant Licensing Renewal Checklist
- Marketing Strategy Checklist
- Department of Transportation (DOT) Audit Checklist
- Retail Policy Update and Compliance Checklist
Ready to take control of your recurring tasks?
Start Free 14-Day TrialUse Slack? Sign up with one click
