Own Risk and Solvency Assessment (ORSA) - NAIC Model Act
Section 1 ERM Framework

Own Risk and Solvency Assessment (ORSA) - NAIC Model Act ORSA-S1: Guidance Manual Section 1: Description of the insurer's risk management framework

Section 1 of the Summary Report summarises at a high level the ERM framework principles the insurer has: risk culture and governance with defined roles and accountability; risk identification and prioritisation owned and overseen by the risk function; a formal risk appetite statement with tolerances and limits understood by the board; risk management and controls operating at many levels; and risk reporting and communication that make risk-taking decisions transparent. It also sets out the goals of the business strategy for all in-scope insurance and non-insurance operations, how material risks are identified, categorised and managed, how risks are monitored, the risk appetite statements, how tolerances relate to how much risk capital there is and of what quality, and the feedback tools used to react to economic, operational or strategic change.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 154 controls across 66 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration
  • 27557-6.3 Privacy risk assessment
  • 27557-6.4 Privacy risk treatment
  • 27557-6.6 Recording and reporting
  • 27557-7.3 Risk-based privacy program implementation

ISO/IEC 23894:2023 · 6 controls

  • ISO23894-5.1 Leadership and Commitment
  • ISO23894-5.2 AI Risk Management Integration
  • ISO23894-5.5 Framework Evaluation
  • ISO23894-6.3 AI Risk Assessment
  • ISO23894-6.3.1 AI Risk Identification
  • ISO23894-6.3.3 AI Risk Evaluation

NIST SP 800-53 Rev 5 · 6 controls

  • IS.D.OR.205 Information Security Risk Assessment
  • IS.D.OR.210 Information Security Risk Treatment
  • IS.I.OR.205 Information Security Risk Assessment
  • IS.I.OR.210 Information Security Risk Treatment
  • IS.I.OR.220 Information Security Risk Management
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement

API 1164 · 3 controls

  • API1164-07 Remote Access
  • API1164-21 TSA Pipeline Security Directive Alignment
  • API1164-24 Vulnerability assessment for critical systems

BSI IT-Grundschutz · 3 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy
  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning
  • 60601-1.4.1 General requirements
  • 60601-1.4.2 Risk management process
  • 60601-1.5.1 General requirements for testing
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning
  • IEC62304-7.4 Risk Management of Software Changes

IEC 62443 · 3 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-21 Supply chain risk management for critical components
  • IEC62443-24 Vulnerability assessment for critical systems

ISO/IEC 27003:2017 · 3 controls

  • ISO27003-6.1 Actions to address risks and opportunities
  • ISO27003-8.2 Information security risk assessment
  • ISO27003-8.3 Information security risk treatment

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-21 Supply chain risk management for critical components
  • ISO27019-24 Vulnerability assessment for critical systems

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure

NIST SP 1800-32 · 3 controls

  • CRM-1 AML/CFT Compliance
  • CRM-3 Risk Management Framework
  • CRM-4 Business Risk Assessment
  • AMLCTF-82 Part A Compliance
  • AMLCTF-PartA-RiskAssess ML/TF Risk Assessment

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • BS65000-RM-01 Resilience Journey
  • BS65000-RM-02 Integrated Approach
  • CJIS-17 Risk Assessment
  • CJIS-19 Supply Chain Risk Management
  • CAT-D1-2 Risk management
  • CAT-ML-2 Evolving
  • Sapin2-Pillar3-Risk-Mapping Pillar 3 - Corruption Risk Mapping (Cartographie des Risques)
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain

OSFI B-13 · 2 controls

  • OSFIB13-1 Governance, Risk Management, and Three Lines of Defense
  • OSFIB13-4 Third-Party Risk Management and Cloud
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan
  • IM8-SEC.4 Vulnerability Management
  • IM8-TPM.4 Supply Chain Risk Management

South Korea ISMS-P · 2 controls

  • ISMSP-MS-02 Risk Management
  • ISMSP-SYS-04 Vulnerability Management
  • CH-FADP-21 Data protection impact assessments
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • AS9100D-8.1 Operational Planning and Control
  • 4.3.1 Risk Assessment and Impact Analysis
  • ACQS-8-4 Risk Management

Bahrain PDPL · 1 control

  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)

GDPR · 1 control

  • ISO-20400-4.5 Key considerations for sustainable procurement
  • ISO-22313-8.2 Business impact analysis and risk assessment

ISO 22320:2018 · 1 control

  • ISO-22320-4.3 Risk-based approach
  • ISO-26262-3-7 Hazard analysis and risk assessment (HARA)

ISO 27799:2025 · 1 control

  • ISO27799-06 Security management process and risk analysis
  • ISO28001-SA-04 Security Risk Treatment Planning

ISO/IEC 27031:2011 · 1 control

  • 27031-7.2 Resource Requirements

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture
  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring

NIST SP 800-190 · 1 control

  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children

Privacy Act 2020 · 1 control

  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design
  • PSPF24-1 Security Culture, Governance, Risk Management
  • AIGF-1.1 Risk Management and Internal Controls

South Korea PIPA · 1 control

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33

Turkey KVKK · 1 control

  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • CPSC-RA.3 Lifecycle Risk Assessment
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • VIETNAMCYBER-4 Incident Reporting and Cooperation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 154 it maps to, and the evidence behind each claim, over MCP and REST.