VA Administrative Letter 2009-09
Risk-Focused Examination Approach
ALFRED W. GROSS
COMMISSIONER OF INSURANCE
STATE CORPORATION COMMISSION
BUREAU OF INSURANCE
STATE CORPORATION COMMISSION
BUREAU OF INSURANCE
P.O. BOX 1157
RICHMOND, VIRGINIA 23218
TELEPHONE: (804) 371-9741
TDD/VOICE: (804) 371-9206
http://www.scc.virginia.gov/division/boi
October 2, 2009
Administrative Letter 2009 - 09
To:
All Domestic Insurers Licensed in Virginia
Re:
Risk-Focused Examination Approach
The purpose of this administrative letter is to inform all Virginia domestic insurance
companies that a new risk-focused examination approach will be used beginning
with the 2010 financial examinations.
Background
In 2006, the National Association of Insurance Commissioners (âNAICâ) adopted
revisions to the Financial Condition Examinersâ Handbook (âHandbookâ) relating to
a revised risk-focused examination approach. This new examination approach will
be required for the NAIC Financial Regulation Standards and Accreditation
Program for all financial examinations beginning on or after January 1, 2010. The
revised approach is meant to broaden and enhance the identification of risk
inherent in an insurerâs operations and utilize that evaluation in formulating the
ongoing surveillance of an insurer.
The revisions incorporate a seven-phase
process, which will be required for all full scope examinations following the riskfocused surveillance examination approach.
In accordance with the revisions made to the Handbook, there will be a greater
focus placed upon a companyâs risk management culture, corporate governance
structure, risk assessment programs and control environment, which may change
some of the information requested from the insurer by the examiner. The changes
may include requests for interviews with key members of management and the
Board of Directors, requests for additional internal control documentation
(including any applicable compliance documentation), and an increased level of
importance in coordinating with external and internal auditors. It is anticipated that
N
Administrative Letter 2009-09
October 2, 2009
Page 2 of 4
the new exam approach will increase the overall effectiveness and efficiency of the
examination process.
Description of Risk-Focused Surveillance Examination Approach
The intent of the revised risk-focused process is to broaden and enhance the
identification of risk inherent in an insurerâs operations and utilize that evaluation in
formulating the ongoing surveillance of an insurer. The revised risk-focused
approach is designed to provide continuous regulatory oversight and extend the
examination process to not only encompass the risks present as of a specific
examination date, but to consider risks which extend or commence during the time
in which the examination was conducted, and risks which are anticipated to arise
or extend past the point of completion of the examination. The Handbook has
been revised to incorporate the following seven-phase process to conduct riskfocused examinations:
Phase 1: Understand the company and identify key functional activities to be
reviewed: In this phase, key activities and sub-activities are identified using
background information gathered on the company from various sources. The riskfocused surveillance process promotes the use of a âtop-downâ approach to
identify activities.
Phase 2: Identify and assess inherent risk in activities: Phase 2 requires the
examiner, with the assistance of the analysis staff to identify and document the
inherent risks of the insurer being examined. The examiner may identify risks from
the insurerâs own risk assessment, internal and external audit risk assessments,
filing requirements of the Securities and Exchange Commission (SEC) and the
Sarbanes-Oxley Act of 2002, interviews with management, and any other source.
Nine risk classifications have been identified to assist regulators in classifying the
inherent risks: Credit, Market, Pricing/Underwriting, Reserving, Liquidity,
Operational, Legal, Strategic and Reputational. Once the primary risks are
identified within the key business units, the examiner utilizes professional
judgment to assess the inherent risk by determining the probability of occurrence
and magnitude of impact to obtain the overall inherent risk assessment.
Phase 3: Identify and evaluate risk mitigation strategies/controls: Phase 3 requires
the examiner to identify and evaluate controls in place to mitigate inherent risk.
The overall assessment reflects the examinerâs determination on how well the
internal controls mitigate inherent risk.
Phase 4: Determine residual risk: Phase 4 requires the examiner to determine the
residual risk for identified sub-activities to arrive at an overall residual risk by key
activity. The assessment is made by determining how well controls reduce the
level of inherent risk of the sub-activity using probability, impact and professional
Administrative Letter 2009-09
October 2, 2009
Page 3 of 4
judgment. Assessing residual risk is the key to determining where the risks exist in
the insurerâs business. Once the riskier activities are identified the examiner may
use these results to determine where to focus examiner or analyst resources most
efficiently and to determine the nature and extent of testing.
Phase 5: Establish/conduct examination procedures: After completion of the risk
assessment for an activity, the nature and extent of examination procedures can
be determined.
Phase 6: Update prioritization and supervisory plan: Phase 6 requires relevant
material findings from the risk assessment effort and any other examination
activities to be utilized and incorporated into determining or validating the
assessed prioritization of the insurer as well as establishing the going-forward
supervisory plan.
Phase 7: Draft examination report and management letter based upon findings: In
this phase an examination report should be developed. A Management Letter may
also be developed to convey results and observations noted during the
examination that should not be contained in a public examination report.
This seven-phase approach will be required for all full scope examinations
following the risk-focused examination approach. This revised approach differs
from the previous examination approach in that the examiner will assess risk
throughout the organization on a prospective basis. In accordance with this
assessment, not every financial statement account may need to be tested.
However, the examiner will be required to provide assurance on the companyâs
financial statements. Overall, the use of the revised risk-focused approach will
lead examiners to focus on the areas of greatest risk at the insurer and to limit the
testing of areas with less risk. In addition, there will be an increased importance in
utilizing the insurerâs internal and external audit work already performed.
It should be noted that the examinations associated with the revised risk-focused
approach have enough flexibility to allow procedures to be added, modified,
supplemented or reduced, in accordance with the overall risk assessment of the
insurer. Therefore, it is anticipated that the scope of the examination and the
procedures associated with such an examination will be modified for small to
medium sized insurance companies. In some instances, companies may only
note minor changes to the procedures that have been utilized in previous financial
examinations.
We appreciate your cooperation in the transition to the new risk-focused
examination approach.
We believe that the risk-focused approach will be
beneficial to both regulators and industry partners in the years to come.
Administrative Letter 2009-09
October 2, 2009
Page 4 of 4
Any questions or concerns about the new regulatory examination approach may be
directed to:
David H. Smith
Chief Insurance Examiner
Financial Regulation Division, Bureau of Insurance
State Corporation Commission
P.O. Box 1157
Richmond, VA 23218
(804) 371-9061
david.smith@scc.virginia.gov
Cordially,
Alfred W. Gross
Commissioner of Insurance
AWG/rpm