Own Risk and Solvency Assessment (ORSA) - NAIC Model Act
Section 1 ERM Framework
Own Risk and Solvency Assessment (ORSA) - NAIC Model Act ORSA-S1: Guidance Manual Section 1: Description of the insurer's risk management framework
Section 1 of the Summary Report summarises at a high level the ERM framework principles the insurer has: risk culture and governance with defined roles and accountability; risk identification and prioritisation owned and overseen by the risk function; a formal risk appetite statement with tolerances and limits understood by the board; risk management and controls operating at many levels; and risk reporting and communication that make risk-taking decisions transparent. It also sets out the goals of the business strategy for all in-scope insurance and non-insurance operations, how material risks are identified, categorised and managed, how risks are monitored, the risk appetite statements, how tolerances relate to how much risk capital there is and of what quality, and the feedback tools used to react to economic, operational or strategic change.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 154 controls across 66 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33