Risk Mitigation Checklist
Risk Assessment and Identification
NYDFS Part 500.09 requires biennial at minimum but expects continuous reassessment after material changes (new product, acquisition, major vendor). Cover underwriting, claims, cyber, vendor, and compliance risk domains. Annual-only programs are out of compliance if a material change occurred mid-year.
Pull underwriting, claims, IT, compliance, and finance into one working session. Underwriters surface appetite drift; claims surfaces reserve cadence and litigation trends; IT owns Part 500 controls; compliance owns SERFF filings and DOI exam posture.
Pull 5-year loss runs from PolicyCenter / ClaimCenter or the AMS. Look for IBNR drift, reserve adequacy by line, and recurring causes of loss. LexisNexis CLUE and ISO data can supplement carrier-internal patterns.
Use a likelihood × impact matrix tied to the carrier's risk appetite statement. Tag each risk with owner, domain, and current control. Risks rated high or critical drive the policy and crisis-plan updates downstream.
Watch NAIC bulletins, NYDFS guidance, and state DOI circular letters. Common emergents: AI underwriting bias guidance, third-party ransomware exposure, climate-driven property aggregation, and surplus-lines tax rule changes.
Policy Development and Implementation
Refresh the GLBA Safeguards Rule WISP and binding-authority grids per appointed carrier. Producers binding outside line, hazard grade, or limit authority is a recurring E&O driver. Version-stamp every change.
Map each policy to the applicable model: NAIC Insurance Data Security Model Law, NYDFS 23 NYCRR 500, state Unfair Claim Settlement Practices Acts, Anti-Fraud Plan filings (NY, CA, FL, NJ, OH, NM, KY, LA, MN). Confirm Texas Chapter 542 prompt-pay timing is reflected in claims SOPs.
If policy changes touch rates, rules, or forms, confirm the state's filing posture — prior approval, file-and-use, use-and-file, or no-file. Pushing a PA-state rate live before SERFF approval creates unauthorized rates.
File via NAIC SERFF for each state where the rate, rule, or form change applies. Track approval status by state — prior-approval states block implementation until disposition. Hold implementation until the slowest state clears.
Cover the actual changes — not generic compliance slides. Use real fact patterns: an indication being mistaken for a quote, an OFAC hit at claim payment, a missed Part 500 §500.12(b) MFA scope. Track completion in the LMS.
Monitoring and Review
Standard KRIs: loss ratio by line, reserve development by accident year, quote-to-bind ratio, producer CE lapse count, OFAC false-positive rate, vendor SOC 2 expiration runway, NYDFS Part 500 control exception count.
Reconcile the AMS roster against NIPR. Any producer with lapsed CE or missing state appointment for a state where they bound is an unauthorized-transaction exposure. Carriers can rescind affected policies.
Scope is not IT-vendor-only. TPAs, claims vendors, document destruction firms, and printers handling NPI all qualify. Pull each vendor's most recent SOC 2 Type II and confirm coverage period has not lapsed.
Required cadence varies by carrier size and Model Audit Rule applicability. Independent review surfaces the items internal teams normalize — reserve cadence drift, premium audit dispute backlog, retention schedule violations.
Each finding gets a named owner, target date, and severity. High and critical findings become inputs to the next quarter's risk assessment.
Track each finding through to closure with target dates aligned to the carrier's audit response standard. Reopen patterns become next quarter's KRIs.
Crisis Management and Response
NAIC Insurance Data Security Model Law and NYDFS Part 500 require notification to the state DOI within 72 hours of a cybersecurity event. Many plans default to the GLBA or HIPAA window and miss the shorter DOI clock — fix that explicitly.
Pick a scenario tied to a top risk: ransomware on the policy admin system, a TPA data breach, a CAT event triggering claim surge. Time the team against the 72-hour DOI notification clock and the carrier's reinsurance treaty notification triggers.
Verify outside counsel, forensic IR vendor, cyber carrier, reinsurance broker, and DOI contacts. Test the after-hours numbers — stale contacts surface during the actual event.
Most excess policies require notice of any matter reasonably likely to involve the layer; carriers commonly use 50% of primary as the practical trigger. Following-form treaties may not align with policy form coverage triggers — confirm the gap is documented.
CRO or compliance officer signs off and files the package for the next market conduct or financial exam. Retain per the carrier's record retention schedule (typically 5–7 years P&C, longer for WC).
Use this template in Manifestly
- Annual Insurance Review Checklist
- Risk Management Checklist
- Commercial Policy Renewal Checklist
- Customer Inquiry Checklist
- Insurance Compliance Checklist
- Cyber Security Checklist
- Claims Investigation Checklist
- Complaint Resolution Checklist
- Financial Audit Checklist
- Data Security Checklist
- Customer Service Request Handling Checklist
- Disaster Recovery Checklist
- Policy Renewal Checklist
- Customer Retention Checklist
- Policy Issuance Checklist
- Sales Proposal Checklist
- Claims Auditing Checklist
- Policy Cancellation Checklist
- Customer Onboarding Checklist
- Insurance Training and Development Checklist
- Anti-Money Laundering Checklist
- Training Evaluation Checklist
- Insurance Producer Performance Review
- Cybersecurity Incident Response Checklist
- Office Opening Checklist
- Training Needs Assessment Checklist
- Insurance Committee Meeting Planning Checklist
- Skills Development Checklist
- Audit Preparation Checklist
- Network Security Checklist
- Premium Billing and Collection Checklist
- IT Asset Inventory Management Checklist
- Annual Budgeting Checklist
- Financial Reporting Checklist
- Insurance Agency Lead Generation Checklist
- Compliance Audit Checklist
- Commercial Underwriting Checklist
- Policyholder Feedback Cycle
- Insurance Project Planning Checklist
- Tax Compliance Checklist
- Insurance Agency Office Closing Checklist
- Client Engagement Checklist
- Data Protection Checklist
- Insurance Agency Employee Onboarding
- Enterprise Risk Assessment Checklist
- Training Materials Checklist
- Anti-Fraud Checklist
- Policy Endorsement Checklist
- Quarterly Risk Monitoring Checklist
- Expense Management Checklist
- Insurance IT Security Review Checklist
- Insurance Account Cross-Sell Checklist
- Insurance Project Closure Checklist
- Insurance Marketing Campaign Checklist
- Statutory Financial Reporting Checklist
- Claim Processing Checklist
- Policy Administration Checklist
- Risk Management Checklist
- Firm Insurance Renewal Checklist
- Treasury Risk Assessment Checklist
- Engagement Risk Management Checklist
- Annual Insurance Review Checklist
- Software Project Risk Management Checklist
- Engagement Risk Management Checklist
- Risk Management Checklist
- Enterprise Risk Assessment Checklist
- Quarterly Risk Monitoring Checklist
- Law Firm Risk Management Checklist
- Business Continuity Planning Checklist
- Law Firm Risk Management Checklist
- Annual Risk Assessment Checklist
- E-commerce Risk Management Checklist
- Annual Risk Management Review Checklist
- Business Continuity Planning Checklist
- Agency Compliance and Risk Management Checklist
- School Site Risk Management Checklist
- Restaurant Insurance Review Checklist
- Market Risk Checklist
- Annual Attorney Professional Conduct Review
- Restaurant New Hire Checklist
- Restaurant Policy Update Checklist
- Retail Policy Update and Compliance Checklist
- New Hire Paperwork Checklist
- Department of Transportation (DOT) Audit Checklist
- Restaurant Permit and Licensing Renewal Checklist
- Marketing Strategy Checklist
- E-commerce Risk Management Checklist
- E-commerce Legal Compliance Checklist
- CRM Data Entry Checklist
- Cybersecurity Incident Response Checklist
- Agency Compliance and Risk Management Checklist
- Advisor and Staff Onboarding Checklist
- New Hire Onboarding Checklist
- Financial Services IT Security Audit Checklist
- Litigation Preparation Checklist
- Internal Audit Checklist
- PCI DSS Compliance Checklist
- Contract Review Checklist
- Annual Financial Reporting Checklist
- Intellectual Property Management Checklist
- Annual Compliance Program Review
- Project Monitoring Checklist
- Operational Risk Checklist
- Client Onboarding Checklist
- Contract Review Checklist
- International Fuel Tax Agreement (IFTA) Quarterly Filing Checklist
- Regulatory Reporting Checklist
- Advisor and Employee Onboarding Checklist
- Quarterly Performance Measurement Checklist
- IT Policy Review Checklist
- Project Closure Checklist
- Monthly Financial Reporting Checklist
- Quarterly Operations and Compliance QA Review
- Cybersecurity Risk Assessment Checklist
- Know Your Customer (KYC) Checklist
- User Access Review Checklist
- Data Protection Checklist
- Employee File Audit Checklist
- Email Deliverability Checklist
- HR Compliance Checklist
- Law Firm Ethics Compliance Review
- Internal Controls Checklist
- Client Communication Checklist
- Restaurant Licensing Renewal Checklist
- Motor Carrier TSA Security Compliance Checklist
- Risk Assessment Checklist
- School First Aid and Emergency Medication Audit
- Annual School Compliance Audit
- Annual Risk Management Review Checklist
- Vendor Contract Review Checklist
- Business Continuity Plan Checklist
- HR Audit Checklist
- Insurance Marketing Campaign Checklist
- Cloud Security Checklist
- Insurance Program Launch Project Monitoring Checklist
- Anti-Money Laundering Compliance Checklist
- System Backup Checklist
- Data Privacy Compliance Checklist
- Quarterly Risk Monitoring Checklist
- Insurance Program Initiation Checklist
- Law Firm Compliance Checklist
- Training Materials Checklist
- Professional Responsibility Compliance Review
- Employee Offboarding Checklist
- Network Security Checklist
- Regulatory Reporting Checklist
- IT Asset Inventory Management Checklist
- Manufacturing Regulatory Compliance Checklist
- Compliance Audit Checklist
- Training Needs Assessment Checklist
- Email Compliance Checklist
- Audit Preparation Checklist
- Skills Development Checklist
- Law Firm Compliance Checklist
- Financial Statement Review Checklist
- Employee Termination Checklist
- Project Planning Checklist
- Project Execution Checklist
- Security Audit Checklist
- Quarterly Compliance Monitoring Checklist
- Regulatory Compliance Checklist
- E-commerce Sales Tax Reporting Checklist
- Annual Risk Assessment Checklist
- Compliance Audit Checklist
- Client Satisfaction Survey Checklist
- Anti-Money Laundering Checklist
- Training Evaluation Checklist
- Financial Services Project Initiation Checklist
- Brokerage HR Policy Compliance Checklist
- Data Privacy Compliance Checklist
- Employee Handbook Annual Review
- Expense Management Checklist
- Financial Audit Checklist
- Data Security Checklist
- Regulatory Compliance Checklist
- Listing Agreement Intake Checklist
- Employee Records File Audit
- Employee Termination Checklist
- Law Firm Risk Management Checklist
- ISO/IEC 27001 Compliance Checklist
- Complaint Resolution Checklist
- IT Regulatory Compliance Review
- HR Compliance Checklist
- Business Continuity Checklist
- Lead Generation Checklist
- Insurance Program Launch Execution Checklist
- Employee Benefits Checklist
- Law Firm Risk Management Checklist
- Fair Housing Compliance Audit
- Real Estate Website Audit Checklist
- Real Estate Ethics & Compliance Review
- Software Licensing Compliance Checklist
- Property Risk Assessment Checklist
- Lease Agreement Checklist
- Security Audit Checklist
- Legal Compliance Checklist for New Properties
- Fair Housing Compliance Checklist
- IT Security Audit Checklist
- Claims Auditing Checklist
- Document Retention Policy Checklist
- Insurance Training and Development Checklist
- Quarterly Industry Standards Compliance Review
- Risk Management Checklist
- Employee Records Management Checklist
- Building Code Compliance Checklist
- GDPR Compliance Review Checklist
- Legal Entity Management Checklist
- SOX Compliance Checklist
- Quarterly Internal Control Review Checklist
- Legal Document Storage Checklist
- Anti-Money Laundering Compliance Checklist
- Regulatory Compliance Checklist
- Insurance Compliance Checklist
- Real Estate Contract Review Checklist
- Employee Termination Checklist
- GDPR Compliance Checklist
- Continuing Education Checklist
- Real Estate License Renewal Checklist
- MLS Listing Review Checklist
- HIPAA Compliance Checklist
- Real Estate Legal Compliance Checklist
- PCI DSS Compliance Checklist
- Real Estate Professional Development Checklist
- Brokerage Trust Account Management Checklist
- Cybersecurity Protocol Checklist
- HR Compliance Checklist
- Data Security Review Checklist
- Risk Management Checklist
- Sales Tax Reporting Checklist
- Property Safety Inspection Checklist
- Employee File Audit Checklist
- Brokerage Technology Inventory Audit
- Payroll Processing Checklist
Ready to take control of your recurring tasks?
Start Free 14-Day TrialUse Slack? Sign up with one click
