Risk Assessment Checklist
Operational Risk Assessment
Inventory the workflows that have to keep running for the business to function: submission intake, bind, policy issuance, FNOL, reserve setting, claim payment. Note the system of record for each (Guidewire PolicyCenter / ClaimCenter, Duck Creek, Applied Epic, AMS360) and the named owner. Attach the process inventory.
For each critical system, document the maximum tolerable downtime against the carrier's RTO. A four-hour PolicyCenter outage during a renewal cycle has different financial exposure than the same outage at month-end. Pull last year's incident records from the IT ticketing system as your baseline.
List every TPA, MGA, MGU, and binding-authority partner with delegated authority. Confirm current SOC 2 Type II reports, binding-authority limits, and reporting cadence. Lapsed SOC 2s and stale binding agreements are a recurring market-conduct exam finding.
Run a tabletop on a ClaimCenter outage during business hours. Confirm the manual FNOL fallback (paper ACORD intake, claim-number reservation, reserve placeholder rules) and the catch-up procedure once systems are restored. Texas Chapter 542 acknowledgement clocks do not stop for system outages.
Financial Risk Evaluation
Calculate the company action level RBC ratio for the current year and the prior two annual statements. Note any movement toward the 200% company action level threshold; trending matters more than a single point in time.
Run the recoverables-by-reinsurer report. Flag any reinsurer holding more than 10% of total recoverables and confirm A.M. Best rating, collateral posted, and treaty wording. Following-form treaty mismatches against the underlying form are the gap that surfaces during a recovery dispute.
Reconcile case reserves to actuarial indications by line of business. Watch for reserve cadence drift — placeholder reserves left untouched past the 30/60/90 review cadence are the leading source of IBNR surprise and a market-conduct finding.
Pull the agency-bill and direct-bill aging from the AMS. Anything over 60 days needs a producer-balance review; anything over 90 days needs an authority discussion. Stale producer balances mask credit risk on the producer of record.
Read the most recent A.M. Best credit report and rationale. Document any rating outlook changes (negative, under review) and the drivers Best cites — capital adequacy, operating performance, business profile, ERM. Distribution partners watch this.
Regulatory Compliance Review
Run the NIPR PDB report for every appointed producer. Confirm active license, lines of authority, CE compliance, and appointment status in each state where they have bound business this year. A producer binding outside their state appointment exposes the carrier to rescission.
Pull market conduct and financial exam reports issued in the last 36 months. Confirm every cited finding has a documented remediation closed by the DOI. Open findings carry into the next exam cycle and compound.
For each writing state, reconcile filed rates and forms to what is actually live in PolicyCenter. Note the filing posture per state — prior approval, file-and-use, use-and-file — and verify any pending PA filings have been approved before the rate goes live. Pushing a rate live in a PA state ahead of approval creates unauthorized rates.
Pull a sample of policies issued and claim payments made this year. Confirm OFAC SDN screening fired at policy issuance and again at every claim payment. Many carriers screen at issuance but not at payment — claimants and assignees can be added to the SDN list mid-policy.
NY, CA, FL, NJ, OH, NM, KY, LA, and MN require Anti-Fraud Plan filings. Confirm each is on file with the most recent SIU staffing, training, and case-referral data. Acquired books often inherit unfiled or stale plans.
Cybersecurity and Data Protection
Walk the 23 NYCRR 500 control matrix: CISO designation, written cybersecurity policy, risk-based access controls, encryption of NPI in transit and at rest, annual penetration test, biennial risk assessment. The biennial-minimum is the floor — material changes (new product, acquisition, new vendor) trigger an interim assessment.
Part 500.12(b) requires MFA for any individual accessing internal networks from an external network — including TPA staff, document-handling vendors, and contractor VPN accounts. Treating MFA as employee-only is the most common Part 500 finding.
Engage a qualified third party to test PolicyCenter, ClaimCenter, the AMS, and any externally-facing producer or insured portals. Capture the executive summary and the remediation plan for any high or critical findings.
NYDFS Part 500 and the NAIC Insurance Data Security Model Law both require notification within 72 hours of a determined cybersecurity event. Confirm the IR runbook reflects 72 hours — not the GLBA absence-of-deadline or the HIPAA 60-day window — and walk through who notifies which state DOI.
Section 500.11 covers any vendor handling NPI — TPAs, claims vendors, document destruction firms, print shops. Confirm each has a current security questionnaire, contractual security terms, and a SOC 2 or equivalent on file. IT-vendor-only programs miss the operational vendor scope.
Risk Register and Sign-Off
Roll every finding from operational, financial, regulatory, and cyber into the enterprise risk register with inherent rating, control rating, and residual rating. The register is what the board risk committee reviews and what the next exam team will request first.
Assign each high or critical finding from the pen test to a named owner with a target close date. High findings open past 30 days are themselves a Part 500 finding at the next exam.
Submit appointments, terminations, or CE remediation through NIPR. Pause binding authority on any producer with a state gap until cleared. An unauthorized-transaction finding will surface every prior bind in that state.
The CRO and CISO sign off on the assessment, the residual risk rating, and the remediation plan. The signed package goes to the board risk committee and is retained as evidence of the Part 500 §500.09 / NAIC Model Law biennial risk assessment.
Use this template in Manifestly
- Risk Management Checklist
- Regulatory Compliance Checklist
- Quarterly Internal Control Review Checklist
- Sales Tax Reporting Checklist
- Legal Entity Management Checklist
- Employee File Audit Checklist
- Anti-Money Laundering Compliance Checklist
- SOX Compliance Checklist
- GDPR Compliance Review Checklist
- IT Security Audit Checklist
- HR Compliance Checklist
- Payroll Processing Checklist
- Building Code Compliance Checklist
- Employee Records Management Checklist
- Legal Document Storage Checklist
- Security Audit Checklist
- Property Risk Assessment Checklist
- Property Safety Inspection Checklist
- Cybersecurity Protocol Checklist
- Fair Housing Compliance Checklist
- Legal Compliance Checklist for New Properties
- Lease Agreement Checklist
- Software Licensing Compliance Checklist
- PCI DSS Compliance Checklist
- Real Estate Legal Compliance Checklist
- HIPAA Compliance Checklist
- MLS Listing Review Checklist
- Real Estate License Renewal Checklist
- GDPR Compliance Checklist
- Real Estate Contract Review Checklist
- Fair Housing Compliance Audit
- Listing Agreement Intake Checklist
- ISO/IEC 27001 Compliance Checklist
- HR Compliance Checklist
- Real Estate Ethics & Compliance Review
- Brokerage Trust Account Management Checklist
- Real Estate Professional Development Checklist
- Brokerage Technology Inventory Audit
- Real Estate Website Audit Checklist
- Continuing Education Checklist
- Employee Termination Checklist
- Employee Records File Audit
- Regulatory Compliance Checklist
- Brokerage HR Policy Compliance Checklist
- Employee Handbook Annual Review
- Employee Termination Checklist
- Data Privacy Compliance Checklist
- Risk Management Checklist
- Insurance Compliance Checklist
- Complaint Resolution Checklist
- Financial Audit Checklist
- Data Security Checklist
- Risk Mitigation Checklist
- Claims Auditing Checklist
- Quarterly Industry Standards Compliance Review
- Insurance Training and Development Checklist
- Anti-Money Laundering Checklist
- Training Evaluation Checklist
- Manufacturing Regulatory Compliance Checklist
- Training Needs Assessment Checklist
- Skills Development Checklist
- Audit Preparation Checklist
- Network Security Checklist
- Employee Offboarding Checklist
- IT Asset Inventory Management Checklist
- Regulatory Reporting Checklist
- Compliance Audit Checklist
- Insurance Program Initiation Checklist
- Insurance Program Launch Project Monitoring Checklist
- Training Materials Checklist
- Quarterly Risk Monitoring Checklist
- System Backup Checklist
- Employee Benefits Checklist
- Insurance Program Launch Execution Checklist
- Insurance Marketing Campaign Checklist
- Email Compliance Checklist
- Law Firm Compliance Checklist
- Anti-Money Laundering Compliance Checklist
- Law Firm Compliance Checklist
- Professional Responsibility Compliance Review
- Data Privacy Compliance Checklist
- Law Firm Risk Management Checklist
- HR Audit Checklist
- HR Compliance Checklist
- Email Deliverability Checklist
- Law Firm Ethics Compliance Review
- Document Retention Policy Checklist
- Employee File Audit Checklist
- Law Firm Risk Management Checklist
- Cloud Security Checklist
- User Access Review Checklist
- IT Regulatory Compliance Review
- Compliance Audit Checklist
- Security Audit Checklist
- Business Continuity Checklist
- Employee Termination Checklist
- Quarterly Operations and Compliance QA Review
- Expense Management Checklist
- Advisor and Employee Onboarding Checklist
- Client Satisfaction Survey Checklist
- Operational Risk Checklist
- Know Your Customer (KYC) Checklist
- Litigation Preparation Checklist
- Contract Review Checklist
- New Hire Onboarding Checklist
- Client Onboarding Checklist
- Contract Review Checklist
- Regulatory Compliance Checklist
- Monthly Financial Reporting Checklist
- Regulatory Reporting Checklist
- Intellectual Property Management Checklist
- Internal Audit Checklist
- Lead Generation Checklist
- Annual Financial Reporting Checklist
- Annual Compliance Program Review
- Annual Risk Assessment Checklist
- Data Security Review Checklist
- Quarterly Performance Measurement Checklist
- Financial Services Project Initiation Checklist
- IT Policy Review Checklist
- Data Protection Checklist
- E-commerce Sales Tax Reporting Checklist
- Project Execution Checklist
- Project Planning Checklist
- Project Monitoring Checklist
- Financial Statement Review Checklist
- Quarterly Compliance Monitoring Checklist
- Cybersecurity Risk Assessment Checklist
- Project Closure Checklist
- Financial Services IT Security Audit Checklist
- PCI DSS Compliance Checklist
- Advisor and Staff Onboarding Checklist
- Cybersecurity Incident Response Checklist
- E-commerce Risk Management Checklist
- CRM Data Entry Checklist
- Business Continuity Plan Checklist
- E-commerce Legal Compliance Checklist
- Vendor Contract Review Checklist
- Annual Risk Management Review Checklist
- Agency Compliance and Risk Management Checklist
- Annual School Compliance Audit
- School First Aid and Emergency Medication Audit
- Motor Carrier TSA Security Compliance Checklist
- Internal Controls Checklist
- Client Communication Checklist
- Restaurant Permit and Licensing Renewal Checklist
- New Hire Paperwork Checklist
- Restaurant Policy Update Checklist
- Restaurant New Hire Checklist
- Annual Attorney Professional Conduct Review
- International Fuel Tax Agreement (IFTA) Quarterly Filing Checklist
- Restaurant Licensing Renewal Checklist
- Marketing Strategy Checklist
- Department of Transportation (DOT) Audit Checklist
- Retail Policy Update and Compliance Checklist
Ready to take control of your recurring tasks?
Start Free 14-Day TrialUse Slack? Sign up with one click
