ORSA Review Template

General Instructions: This template is intended to be used to document a review and assessment of the ORSA Summary Report by the lead/domestic state. Regulators should document the results of their annual review of the ORSA and utilize the appendixes to track and communicate feedback to the company and procedures for regulatory follow-up. See VI.E. Group-Wide Supervision – Enterprise Risk Management Process Risks Guidance for additional guidance in completing this template.

Background Information
Summarize and assess background information provided in the report, where available. Key documentation elements are presented below.
1. Attestation:
2. Entities in Scope:
3. Accounting Basis:
4. Key Business Goals:
5. Changes from Prior Filing(s):
6. Planned ERM Enhancements:

Section I – Description of the Insurer's ERM Framework
Summarize and assess key information from Section I of the ORSA Summary Report for each of the five principles of a risk management framework.
1. Risk Culture and Governance:
2. Risk Identification and Prioritization:
3. Risk Appetite, Tolerances and Limits:
4. Risk Management and Controls:
5. Risk Reporting and Communication:

Overall Section 1 Assessment—After reviewing and considering each principle individually, develop an overall assessment of the group's/insurer's risk management framework including any concerns or areas requiring follow-up investigation or communication:

Section II – Insurer Assessment of Risk Exposures
Prepare documentation summarizing a review and assessment of information provided on the reasonably foreseeable and relevant material risks of the insurer/group.

THE FOLLOWING TABLE SHOULD BE COMPLETED FOR EACH KEY RISK
Risk Title/Description
Branded Risk(s)
Controls/Mitigation
Risk Limits
Assessment (QT/QL)
Normal Exposure
Stress Scenario(s)
Stressed Exposure
Inclusion on GPS/IPS

Regulator Review & Assessment:

Overall Section 2 Assessment—After reviewing and considering each key risk individually, develop an overall conclusion regarding the group's/insurer's process to assess key risk exposures including any concerns or areas requiring follow-up investigation or communication:

Section III – Assessment of Risk Capital and Prospective Solvency
Prepare documentation summarizing a review and assessment of key elements of the risk capital and prospective solvency process as follows.
1. Discussion of Capital Metric(s) Used:
2. Group Risk Capital (GRC) – By Risk and In Aggregate:
3. Impact of Diversification Benefit:
4. Available Capital:
5. Excess Capital:
6. Impact of Stresses on GRC:
7. Governance and Validation:
8. Prospective Solvency Assessment:

Overall Section III Assessment—After reviewing and considering each of the key elements individually, develop an overall assessment of the risk capital and prospective solvency of the insurer/group including any concerns or areas requiring follow-up investigation or communication:

Appendix A – Feedback to Insurer
Feedback to the insurer on the ORSA Summary Report is critical for the compliance and effectiveness of future filings. The purpose of this form is to help the lead/domestic state gather and provide constructive and practical feedback to the insurer.

Positive Attributes:
1.
2.
3.

Constructive Feedback:
1.
2.
3.

Requests for Additional Information:
1.
2.
3.

Appendix B – Recommended Exam Procedures/Areas for Follow-up Investigation
In completing a review of the ORSA Summary Report, the lead state/domestic regulator should consider whether certain elements could benefit from verification/testing in an examination or additional monitoring and follow-up investigation by the financial analyst. Such procedures and issues can be accumulated here for communication and tracking.

Background Information
1.
2.
3.

Section I - ERM Framework
1.
2.
3.

Section II - Risk Assessment
1.
2.
3.

Section III - Risk Capital and Prospective Solvency
1.
2.
3.

Financial Analysis Handbook
2018 Annual / 2019 Quarterly
VI.E. Group-Wide Supervision – Enterprise Risk Management Process Risks Guidance

Introduction
The process for assessing enterprise risk management (ERM) within the group will vary depending upon its structure and scale. Approximately 90 percent of the U.S. premium is subject to reporting an annual Own Risk and Solvency Assessment (ORSA) Summary Report. However, all insurers are subject to an assessment of risk management during the risk-focused analysis and examination, and this review is a responsibility of the lead state. In addition, all groups are required to submit the Form F - Enterprise Risk Report under the requirements of the NAIC Insurance Holding Company System Regulatory Act (#440). In addition, both the ORSA Summary Report and the Form F are subject to the supervisory review process, which contemplates both off-site and on-site examination of such information proportionate to the nature, scale and complexity of the insurer/group's risks. Those procedures are discussed in the following two sections. In addition, any risks identified throughout the entire supervisory review process are subject to further review by the lead state in either the periodic meeting with the insurer/group and/or any targeted examination work. When reviewing the ORSA and Form F, the lead state analyst should consider consistency between the documents, as well as information provided in the Corporate Governance Annual Disclosure.

ORSA Summary Report
The NAIC Risk Management and Own Risk and Solvency Assessment Model Act (#505) requires insurers above a specified premium threshold, and subject to further discretion, to submit a confidential annual ORSA Summary Report. Model #505 gives the individual insurer and the insurance group discretion as to whether the report is submitted by each individual insurer within the group or by the insurance group as a whole (See the NAIC Own Risk and Solvency Assessment Guidance Manual for further discussion).

• Lead State: In the case where the insurance group chooses to submit one ORSA Summary Report for the group, it must be reviewed by the lead state. The lead state is to perform a detailed and thorough review of the information and initiate any communications about the ORSA with the group. The suggestions below set forth some possible considerations for such a review. At the completion of this review, the lead state should prepare a thorough summary of its review, which would include an initial assessment of each of the three sections. The lead state should also consider and include key information to share with other domestic states that are expected to place significant reliance on the lead state's review. The lead state should share the analysis of ORSA with other states that have domestic insurers in the group. The group ORSA review and sharing with other domestic states should occur within 120 days of receipt of the ORSA filing.

• Non-Lead State: Non-lead states are not expected to perform an in-depth review of the ORSA, but instead rely on the review completed by the lead state. The non-lead states' review of the lead state's ORSA review should be performed only for the purpose of having a general understanding of the work performed by the lead state, and to understand the risks identified and monitored at the group-level so the non-lead state may better monitor and communicate to the lead state when its legal entity could affect the group. Any concerns or questions related to information in the ORSA or group risks should be directed to the lead state.

• Single Insurer ORSA: In the case where there is only one insurer within the insurance group, or the group decides to submit separate ORSA Summary Reports for each legal entity, the domestic state is to perform a detailed and thorough review of the information, which would include an initial assessment of each of the three sections and initiate any communications about the ORSA directly with the legal entity. Such a review should also be shared with the lead state (if applicable) so it can develop an understanding of the risks within the entire insurance group. Single insurer ORSA reviews should be completed within 180 days of receipt of the ORSA filing.

Financial Analysis Handbook
2018 Annual / 2019 Quarterly
VI.E. Group-Wide Supervision – Enterprise Risk Management Process Risks Guidance

Throughout a significant portion of the remainder of this document, the term "insurer" is used to refer to both a single insurer for those situations where the report is prepared by the legal entity, as well as to refer to an insurance group. However, in some cases, the term group is used to reinforce the importance of the group-wide view. Similarly, throughout the remainder of this document, the term "lead state" is used before the term "analyst" with the understanding that in most situations, the ORSA Summary Report will be prepared on a group basis and, therefore reviewed by the lead state.

Background Information
To understand the appropriate steps for reviewing the ORSA Summary Report, regulators must first understand the purpose of the ORSA. As noted in the ORSA Guidance Manual, the ORSA has two primary goals:

1. To foster an effective level of (ERM) at all insurers, through which each insurer identifies, assesses, monitors, prioritizes and reports on its material and relevant risks identified by the insurer, using techniques that are appropriate to the nature, scale and complexity of the insurer's risks, in a manner that is adequate to support risk and capital decisions

2. To provide a group-level perspective on risk and capital, as a supplement to the existing legal entity view.

In addition, separately, the ORSA Guidance Manual discusses the regulator obtaining a high-level understanding of the insurer's ORSA, and discusses how the ORSA Summary Report may assist the commissioner in determining the scope, depth and minimum timing of risk-focused analysis and examination procedures.

There is no expectation with respect to specific information or specific action that the lead state regulator is to take as a result of reviewing the ORSA Summary Report. Rather, each situation is expected to result in a unique ongoing dialogue between the insurer and the lead state regulator focused on the key risks of the group. For this reason, as well as others, the lead state analyst may want to consider additional support in the form of a broader review team as necessary in reviewing the ORSA Summary Report, subject to the confidentiality requirements outlined in statute. In reviewing the final ORSA filing prior to the next scheduled financial examination, the analyst should consider inviting the lead state examiner or any other individual acting under the authority of the commissioner or designated by the commissioner with special skills and subject to confidentiality to participate on the review team. Regardless of which individuals are involved on a review team, the 120-day or 180-day timeliness standards are applicable to the review. Additionally, the lead state analyst and examiner may want to include the review team in possible ongoing dialogues with the insurer since the same team will be part of the ongoing monitoring of the insurer and an ORSA Summary Report is expected to be at the center of the regulatory processes. A joint review such as this prior to the lead state analyst documenting its summary of the ORSA Summary Report may be appropriate.

These determinations can be documented as part of each insurer's ongoing supervisory plan. However, the ORSA Guidance Manual also states that each insurer's ORSA will be unique, reflecting the insurer's business model, strategic planning and overall approach to ERM. As regulators review ORSA Summary Reports, they should understand that the level of sophistication for each group's ERM program will vary depending upon size, scope and nature of business operations. Understandably, less complex organizations may not require intricate processes to possess a sound ERM program. Therefore, regulators should use caution before using the results of an ORSA review to modify ongoing supervisory plans, as a variety of practices may be appropriate depending upon the nature, scale and complexity of each insurer.

Collectively, the goals above are the basis upon which the guidance is established. However, the ORSA Summary Report will not serve this function or have this direct impact until the lead state becomes fairly familiar and comfortable with evaluating each insurer's report and its processes. This could take more than a couple of years to occur in practice, since the lead state would likely need to review at least one or two ORSA Summary Reports to fully understand certain aspects of the processes used to develop the report.

Financial Analysis Handbook
2018 Annual / 2019 Quarterly
VI.E. Group-Wide Supervision – Enterprise Risk Management Process Risks Guidance

General Summary of Guidance for Each Section
The guidance that follows is designed to assist the lead state analyst in the review of the ORSA and to allow for effective communication of analysis results with the non-lead states. It is worth noting that this guidance is expected to evolve over the years, with the first couple of years focused on developing a general understanding of ORSA and ERM. It should be noted that each of the sections can be informative to the other sections. As an example, Section II affords an insurer the opportunity to demonstrate the robustness of