Compliance Audit Checklist
Audit Scoping and Kickoff
List every state where the entity holds a certificate of authority or producer appointments. Each state DOI has its own market conduct posture — NY (Part 500), CA, FL, TX, and NAIC Data Security Model adopting states drive most of the work.
Retrieve the most recent state DOI market conduct exam report, financial exam report, and any open Corrective Action Plans. Repeat findings carry materially higher penalties at the next exam.
Producer Licensing and Appointments
Pull the current producer roster from the AMS (Applied Epic, AMS360, or equivalent) and reconcile NPNs against NIPR. Flag any producer bound business in a state where they hold a non-resident license but no carrier appointment.
CE hours and lines vary by state. A lapsed CE is a lapsed license — any business bound after the lapse is an unauthorized transaction subject to rescission and producer fines.
NY Insurance Reg 187 and CA SB 250 require written commission disclosure to mid-market commercial insureds. Sample 25 bound accounts from the past year and confirm the disclosure is on file.
Triggered only when unauthorized binds are found. Coordinate with the carrier on rescission of any out-of-authority bound policies and self-report to the affected state DOIs to reduce penalty exposure.
Data Security and Privacy
The Written Information Security Program is required by GLBA Safeguards and the NAIC Insurance Data Security Model Law. Confirm the named CISO is current, the program reflects this year's systems inventory, and the most recent risk assessment is attached.
NYDFS Part 500.12(b) requires MFA for any individual accessing internal networks from an external network — including third-party vendors with VPN access. Pull the IdP report and confirm contractor accounts are in scope, not just employees.
NAIC Insurance Data Security Model Law and NYDFS Part 500 both require 72-hour notification of cybersecurity events to the state DOI. Walk through a tabletop scenario and time the path from detection to draft notice.
Vendor scope under Part 500.11 includes TPAs, claims vendors, document destruction firms, and printers handling claim packets — not just IT vendors. Spot-check that each has a current SOC 2 Type II or equivalent attestation on file.
VT requires opt-in for non-affiliate sharing; CA requires CCPA/CPRA-aligned disclosures for personal-lines insureds. Form letters templated nationally fail state-specific tests.
Underwriting and Claims Controls
Pull a 30-file sample across ACORD 125, 130, and 140. Verify auto-populated fields (class codes, payroll, sales) match current insured operations. Multi-cycle drift in auto-populated fields is a frequent market conduct finding.
Texas Insurance Code Chapter 542 sets 15 business days to acknowledge FNOL, 15 business days to decision after all info, 60 days max. Each missed deadline triggers 18% statutory interest plus attorney's fees. Pull the claims TAT report and flag outliers.
Confirm reserves are reviewed at the carrier's defined 30/60/90-day cadence. Placeholder reserves left untouched contribute to IBNR drift and surface as findings in financial exams.
Many carriers screen at issuance but not at every claim payment. Confirm the screening runs at payment as well — claimants and assignees can be added to the SDN list mid-policy.
NY, CA, FL, NJ, OH, NM, KY, LA, and MN require periodic Anti-Fraud Plan filings. Acquired entities often inherit unfiled plans — verify the current plan is on file with each required DOI.
Financial Controls and Filings
Most states require producer-collected premium to be held in a fiduciary trust account separated from operating funds. Reconcile the trust account against the AMS premium ledger; commingling is a top-five state DOI finding.
For each in-scope state, confirm prior approval / file-and-use / use-and-file posture matches what was followed when rates were last changed. PA states require pre-approval — pushing rate live early creates unauthorized rates.
E&S policies require state-specific premium tax remittance and stamping office filings within 30–60 days post-bind. Compliance rests with the producer of record even when handled by the wholesale broker.
Required under the Insurance Holding Company System Regulatory Act for any insurer in a holding company structure. Confirm the registration was filed with the domiciliary state by the April 30 deadline.
Findings and Sign-Off
Each CAP needs a named owner, target remediation date, and verification method. Repeat findings carry materially higher penalties at the next market conduct exam — prioritize those.
Use this template in Manifestly
- Annual Insurance Review Checklist
- Risk Management Checklist
- Commercial Policy Renewal Checklist
- Customer Inquiry Checklist
- Insurance Compliance Checklist
- Cyber Security Checklist
- Claims Investigation Checklist
- Complaint Resolution Checklist
- Financial Audit Checklist
- Data Security Checklist
- Risk Mitigation Checklist
- Customer Service Request Handling Checklist
- Disaster Recovery Checklist
- Policy Renewal Checklist
- Customer Retention Checklist
- Policy Issuance Checklist
- Sales Proposal Checklist
- Claims Auditing Checklist
- Policy Cancellation Checklist
- Customer Onboarding Checklist
- Insurance Training and Development Checklist
- Anti-Money Laundering Checklist
- Training Evaluation Checklist
- Insurance Producer Performance Review
- Cybersecurity Incident Response Checklist
- Office Opening Checklist
- Training Needs Assessment Checklist
- Insurance Committee Meeting Planning Checklist
- Skills Development Checklist
- Audit Preparation Checklist
- Network Security Checklist
- Premium Billing and Collection Checklist
- IT Asset Inventory Management Checklist
- Annual Budgeting Checklist
- Financial Reporting Checklist
- Insurance Agency Lead Generation Checklist
- Commercial Underwriting Checklist
- Policyholder Feedback Cycle
- Insurance Project Planning Checklist
- Tax Compliance Checklist
- Insurance Agency Office Closing Checklist
- Client Engagement Checklist
- Data Protection Checklist
- Insurance Agency Employee Onboarding
- Enterprise Risk Assessment Checklist
- Training Materials Checklist
- Anti-Fraud Checklist
- Policy Endorsement Checklist
- Quarterly Risk Monitoring Checklist
- Expense Management Checklist
- Insurance IT Security Review Checklist
- Insurance Account Cross-Sell Checklist
- Insurance Project Closure Checklist
- Insurance Marketing Campaign Checklist
- Statutory Financial Reporting Checklist
- Claim Processing Checklist
- Policy Administration Checklist
- Risk Management Checklist
- Regulatory Compliance Checklist
- Quarterly Internal Control Review Checklist
- Sales Tax Reporting Checklist
- Legal Entity Management Checklist
- Employee File Audit Checklist
- Anti-Money Laundering Compliance Checklist
- SOX Compliance Checklist
- GDPR Compliance Review Checklist
- IT Security Audit Checklist
- HR Compliance Checklist
- Payroll Processing Checklist
- Building Code Compliance Checklist
- Employee Records Management Checklist
- Legal Document Storage Checklist
- Security Audit Checklist
- Property Risk Assessment Checklist
- Property Safety Inspection Checklist
- Cybersecurity Protocol Checklist
- Fair Housing Compliance Checklist
- Legal Compliance Checklist for New Properties
- Lease Agreement Checklist
- Software Licensing Compliance Checklist
- PCI DSS Compliance Checklist
- Real Estate Legal Compliance Checklist
- HIPAA Compliance Checklist
- MLS Listing Review Checklist
- Real Estate License Renewal Checklist
- GDPR Compliance Checklist
- Real Estate Contract Review Checklist
- Fair Housing Compliance Audit
- Listing Agreement Intake Checklist
- ISO/IEC 27001 Compliance Checklist
- HR Compliance Checklist
- Real Estate Ethics & Compliance Review
- Brokerage Trust Account Management Checklist
- Real Estate Professional Development Checklist
- Brokerage Technology Inventory Audit
- Real Estate Website Audit Checklist
- Continuing Education Checklist
- Employee Termination Checklist
- Employee Records File Audit
- Regulatory Compliance Checklist
- Brokerage HR Policy Compliance Checklist
- Employee Handbook Annual Review
- Employee Termination Checklist
- Data Privacy Compliance Checklist
- Risk Management Checklist
- Insurance Compliance Checklist
- Complaint Resolution Checklist
- Financial Audit Checklist
- Data Security Checklist
- Risk Mitigation Checklist
- Claims Auditing Checklist
- Quarterly Industry Standards Compliance Review
- Insurance Training and Development Checklist
- Anti-Money Laundering Checklist
- Training Evaluation Checklist
- Manufacturing Regulatory Compliance Checklist
- Training Needs Assessment Checklist
- Skills Development Checklist
- Audit Preparation Checklist
- Network Security Checklist
- Employee Offboarding Checklist
- IT Asset Inventory Management Checklist
- Regulatory Reporting Checklist
- Insurance Program Initiation Checklist
- Insurance Program Launch Project Monitoring Checklist
- Training Materials Checklist
- Quarterly Risk Monitoring Checklist
- System Backup Checklist
- Employee Benefits Checklist
- Insurance Program Launch Execution Checklist
- Insurance Marketing Campaign Checklist
- Email Compliance Checklist
- Law Firm Compliance Checklist
- Anti-Money Laundering Compliance Checklist
- Law Firm Compliance Checklist
- Professional Responsibility Compliance Review
- Data Privacy Compliance Checklist
- Law Firm Risk Management Checklist
- HR Audit Checklist
- HR Compliance Checklist
- Email Deliverability Checklist
- Law Firm Ethics Compliance Review
- Document Retention Policy Checklist
- Employee File Audit Checklist
- Law Firm Risk Management Checklist
- Cloud Security Checklist
- User Access Review Checklist
- IT Regulatory Compliance Review
- Compliance Audit Checklist
- Security Audit Checklist
- Business Continuity Checklist
- Employee Termination Checklist
- Quarterly Operations and Compliance QA Review
- Expense Management Checklist
- Advisor and Employee Onboarding Checklist
- Client Satisfaction Survey Checklist
- Operational Risk Checklist
- Know Your Customer (KYC) Checklist
- Litigation Preparation Checklist
- Contract Review Checklist
- New Hire Onboarding Checklist
- Client Onboarding Checklist
- Contract Review Checklist
- Regulatory Compliance Checklist
- Monthly Financial Reporting Checklist
- Regulatory Reporting Checklist
- Intellectual Property Management Checklist
- Internal Audit Checklist
- Lead Generation Checklist
- Annual Financial Reporting Checklist
- Annual Compliance Program Review
- Annual Risk Assessment Checklist
- Data Security Review Checklist
- Quarterly Performance Measurement Checklist
- Financial Services Project Initiation Checklist
- IT Policy Review Checklist
- Data Protection Checklist
- E-commerce Sales Tax Reporting Checklist
- Project Execution Checklist
- Project Planning Checklist
- Project Monitoring Checklist
- Financial Statement Review Checklist
- Quarterly Compliance Monitoring Checklist
- Cybersecurity Risk Assessment Checklist
- Project Closure Checklist
- Financial Services IT Security Audit Checklist
- PCI DSS Compliance Checklist
- Advisor and Staff Onboarding Checklist
- Cybersecurity Incident Response Checklist
- E-commerce Risk Management Checklist
- CRM Data Entry Checklist
- Business Continuity Plan Checklist
- E-commerce Legal Compliance Checklist
- Vendor Contract Review Checklist
- Annual Risk Management Review Checklist
- Risk Assessment Checklist
- Agency Compliance and Risk Management Checklist
- Annual School Compliance Audit
- School First Aid and Emergency Medication Audit
- Motor Carrier TSA Security Compliance Checklist
- Internal Controls Checklist
- Client Communication Checklist
- Restaurant Permit and Licensing Renewal Checklist
- New Hire Paperwork Checklist
- Restaurant Policy Update Checklist
- Restaurant New Hire Checklist
- Annual Attorney Professional Conduct Review
- International Fuel Tax Agreement (IFTA) Quarterly Filing Checklist
- Restaurant Licensing Renewal Checklist
- Marketing Strategy Checklist
- Department of Transportation (DOT) Audit Checklist
- Retail Policy Update and Compliance Checklist
- Financial Statement Audit Checklist
- Audit Preparation Checklist
- Fixed Assets Audit Checklist
- External Audit Preparation Checklist
- Financial Audit Checklist
- Risk Assessment Checklist
- Post-Merger Audit Checklist
- Employee File Audit Checklist
- Engagement Risk Management Checklist
- Rent Roll Audit Checklist
- Financial Audit Checklist
- Quarterly Industry Standards Compliance Review
- Audit Preparation Checklist
- HR Audit Checklist
- Social Media Audit Checklist
Ready to take control of your recurring tasks?
Start Free 14-Day TrialUse Slack? Sign up with one click
