Industry & Portfolio Guides

Connected GRC for Insurance Companies

Learn how insurance companies can use Connected GRC to link ERM, ORSA, underwriting, claims, cyber, vendors, AI, evidence, issues, risk acceptance, and dashboards.
Category
Industry & Portfolio Guides
Stage
Govern
Product Group
GRC & Resilience

Insurance companies are built to manage risk.

But that does not mean their internal risk programs are always connected.

Enterprise risk teams manage risk appetite, ORSA, capital, and solvency.
Compliance teams track laws, regulations, market conduct requirements, and policies.
Cyber teams manage threats, vulnerabilities, data security, and incident response.
Claims teams manage claim handling, leakage, litigation, fraud, and customer experience.
Underwriting teams manage pricing, selection, risk appetite, appetite exceptions, and portfolio quality.
Actuarial teams manage reserving, pricing models, assumptions, and emerging loss trends.
Vendor risk teams manage TPAs, MGAs, cloud providers, data providers, claims vendors, adjusters, and outsourcing.
Privacy teams manage customer and policyholder data.
AI governance teams review predictive models, third-party data, underwriting automation, claims tools, and fraud models.
Finance and audit teams manage statutory reporting, internal controls, external audit, and management attestations.
Executives and boards need a clear view of risk, not ten disconnected reports.

Insurance risk is connected by nature.

A cyber incident can become a data security, claims, regulatory, customer, and board issue.
A vendor failure can affect claims service levels, policyholder experience, regulatory obligations, and operational resilience.
An AI underwriting model can affect fairness, compliance, pricing, customer outcomes, and reputational risk.
A claims control failure can affect leakage, reserves, litigation, market conduct, and customer trust.
A catastrophe event can affect claims operations, liquidity, vendor capacity, reinsurance, and board reporting.
A financial reporting control issue can affect statutory reporting, audit, solvency, and regulator confidence.

When the records are disconnected, leaders see fragments.

When the records are connected, leaders see the risk story.

That is why insurance companies need Connected GRC.

Not another compliance checklist.

A connected operating model that links risks, obligations, controls, evidence, policies, systems, data, vendors, claims, underwriting, models, incidents, issues, remediation, validation, risk acceptance, dashboards, and board decisions.

What is Connected GRC for insurance companies?

Connected GRC for insurance companies is an operating model that links enterprise risk, ORSA, solvency, compliance, cyber risk, claims governance, underwriting governance, model risk, AI governance, third-party risk, privacy, financial reporting controls, evidence, issues, remediation, risk acceptance, dashboards, and board reporting into one traceable system.

A connected insurance GRC model should help insurers answer:

  • Which risks affect policyholders, solvency, operations, claims, underwriting, or regulatory obligations?
  • Which legal entities, lines of business, products, jurisdictions, and distribution channels are affected?
  • Which controls manage those risks?
  • Which evidence proves the controls operate?
  • Which underwriting, claims, vendor, cyber, model, or data issues are open?
  • Which remediation actions are overdue?
  • Which remediation actions have been validated?
  • Which risk acceptances are active or expiring?
  • Which incidents changed the risk posture?
  • Which AI or predictive model risks need monitoring?
  • Which dashboards support management, regulators, audit committees, and boards?

A weak insurance GRC model says:

“ERM has ORSA, compliance has obligations, cyber has incidents, claims has audits, vendors have due diligence, and AI has intake forms.”

A strong Connected GRC model says:

“We can trace material insurance risks to controls, evidence, vendors, systems, data, claims processes, underwriting processes, models, incidents, issues, remediation, validation, risk acceptance, and board reporting.”

That is the difference.

Why insurance companies need Connected GRC

Insurers operate across many connected risk domains:

  • underwriting risk
  • claims risk
  • reserving risk
  • liquidity risk
  • market risk
  • credit risk
  • catastrophe risk
  • operational risk
  • cyber risk
  • data privacy risk
  • vendor and outsourcing risk
  • model and AI risk
  • conduct risk
  • fraud risk
  • legal and regulatory risk
  • financial reporting risk
  • reinsurance risk
  • customer experience risk

NAIC describes ORSA as a critical process for insurers and insurance groups to evaluate risk management and solvency positions, analyze material risks such as underwriting, credit, market, operational, and liquidity risks, and support risk and capital decisions as part of ERM.  

That is exactly the type of work Connected GRC supports.

ORSA should not be a standalone report.
ERM should not be a standalone risk register.
Cyber should not be a standalone dashboard.
Claims issues should not live only in claims operations.
AI governance should not live outside compliance, privacy, underwriting, claims, and model oversight.
Vendor risk should not sit apart from the products, processes, data, and customers vendors support.

Insurance companies need a GRC model that connects the operational facts to the enterprise risk view.

That is how risk management becomes decision-ready.

The Insurance Connected GRC Model

A practical Connected GRC model for insurance companies should connect 12 areas:

  1. Legal entities, lines of business, products, and jurisdictions
  2. ERM, ORSA, capital, solvency, and risk appetite
  3. Regulatory obligations, policies, and market conduct
  4. Underwriting, pricing, rating, and portfolio governance
  5. Claims, litigation, fraud, and customer outcomes
  6. Models, predictive analytics, and AI governance
  7. Policyholder data, privacy, and data security
  8. Cyber risk, systems, incidents, and operational resilience
  9. Vendors, TPAs, MGAs, reinsurers, and outsourcing
  10. Financial reporting, statutory reporting, audit, and ICFR
  11. Controls, evidence, testing, issues, and remediation validation
  12. Dashboards, risk acceptance, executive reporting, and board oversight

The value is not in tracking these areas separately.

The value is connecting them.

A claims process should link to policies, controls, evidence, complaints, litigation, vendors, fraud signals, market conduct requirements, and issues.

An underwriting model should link to product, data, risk tier, governance review, validation evidence, monitoring, adverse consumer outcome review, vendor data, and regulatory inquiry readiness.

A cyber incident should link to affected systems, policyholder data, vendors, data security obligations, notification assessment, remediation, validation, and board reporting.

An ORSA risk should link to controls, KRIs, incidents, issues, capital impact, risk acceptance, and management decisions.

That is Connected GRC for insurance.

1. Legal Entities, Lines of Business, Products, and Jurisdictions

Insurance companies often operate across multiple legal entities, states, countries, products, and distribution channels.

A connected model should represent:

  • legal entity
  • insurance group
  • line of business
  • product
  • jurisdiction
  • regulator
  • distribution channel
  • policy administration system
  • claims system
  • underwriting platform
  • data categories
  • vendors
  • risk owners
  • control owners
  • obligation owners
  • dashboard views

This matters because obligations and risks vary by:

  • state
  • country
  • product type
  • legal entity
  • policy form
  • distribution model
  • customer segment
  • claims process
  • underwriting approach
  • outsourced function

A property and casualty insurer, life insurer, health insurer, reinsurer, specialty insurer, and mutual insurer may all need different GRC views.

A national insurer may need state-specific compliance mapping.

A global insurer may need group-level risk and entity-level accountability.

A distribution partner, MGA, broker, or agent channel may create risks that are different from direct-to-consumer business.

Connected GRC should support both enterprise oversight and local accountability.

Legal entity and product checklist

QuestionYes / No
Are legal entities represented in the GRC model?
Are lines of business mapped?
Are products linked to obligations and risks?
Are jurisdictions documented?
Are regulators or supervisory bodies linked where relevant?
Are distribution channels mapped?
Are systems linked to products and lines of business?
Are vendors linked to products and channels?
Are owners assigned by entity, product, and process?
Can dashboards filter by entity, product, state, or line of business?

2. ERM, ORSA, Capital, Solvency, and Risk Appetite

Insurance ERM should connect risk, capital, operations, controls, and evidence.

A connected ERM model should include:

  • risk register
  • material risk categories
  • risk owner
  • inherent risk
  • residual risk
  • risk appetite
  • KRIs
  • ORSA linkage
  • capital or solvency impact
  • controls
  • stress scenarios
  • incidents
  • issues
  • risk acceptances
  • mitigation plans
  • board reporting

NAIC states that ORSA requires large and medium-size U.S. insurers and insurance groups to regularly conduct an ORSA and document results in an ORSA Summary Report, with ORSA intended to foster effective ERM and provide a group-level perspective on risk and capital.  

A Connected GRC model should make ORSA more than a reporting exercise.

It should connect ORSA risks to:

  • underwriting controls
  • claims controls
  • reserving controls
  • cyber controls
  • vendor controls
  • reinsurance risk
  • market and liquidity risk
  • operational resilience
  • KRIs
  • remediation
  • board decisions

Risk appetite should not be a document reviewed annually and forgotten.

It should appear in dashboards.

Leaders should know:

  • which risks are outside appetite
  • which KRIs are trending adversely
  • which issues affect risk appetite
  • which risk acceptances are active
  • which decisions require executive or board action

ERM and ORSA checklist

QuestionYes / No
Are material risks documented?
Are risk owners assigned?
Is risk appetite linked to risk records?
Are KRIs defined and monitored?
Are ORSA risks linked to controls and evidence?
Are stress scenarios linked to management actions?
Are capital or solvency implications documented where relevant?
Are incidents and issues linked to enterprise risks?
Are risk acceptances documented and time-bound?
Can dashboards show risk appetite and ORSA readiness?

3. Regulatory Obligations, Policies, and Market Conduct

Insurance compliance is broad.

Obligations may involve:

  • insurance laws and regulations
  • state filings
  • product approvals
  • rate and form requirements
  • claims handling rules
  • market conduct requirements
  • unfair trade practices
  • unfair claims settlement practices
  • producer licensing
  • privacy and data protection
  • cybersecurity
  • policyholder notices
  • complaint handling
  • financial reporting
  • statutory reporting
  • reinsurance requirements
  • solvency and capital reporting
  • AI and predictive model expectations
  • consumer protection requirements
  • board governance requirements

A connected obligation model should link:

  • obligation
  • source
  • jurisdiction
  • product
  • line of business
  • policy
  • control
  • owner
  • evidence
  • issue trigger
  • regulatory change
  • dashboard status

Market conduct is especially important for insurers.

The same operational issue can become a compliance, customer, claims, litigation, and regulatory issue.

For example:

  • delayed claims handling
  • inconsistent underwriting decisions
  • complaint handling failures
  • notice failures
  • producer oversight gaps
  • unfair discrimination concerns
  • AI-driven adverse consumer outcomes
  • claims settlement practice issues

Connected GRC should show how market conduct obligations are controlled and evidenced.

Obligation and market conduct checklist

QuestionYes / No
Are insurance obligations inventoried?
Are obligations mapped by jurisdiction and product?
Are market conduct obligations mapped to controls?
Are claims handling obligations mapped to controls?
Are underwriting and rating obligations mapped to controls?
Are producer or distribution obligations mapped where relevant?
Are policies linked to controls and evidence?
Are regulatory changes assessed for operational impact?
Are compliance gaps tracked as issues?
Can dashboards show market conduct readiness?

4. Underwriting, Pricing, Rating, and Portfolio Governance

Underwriting and pricing are core insurance risk areas.

A connected underwriting governance model should include:

  • product
  • underwriting guidelines
  • appetite statements
  • pricing models
  • rating factors
  • risk selection controls
  • exceptions
  • referrals
  • delegation authority
  • data sources
  • third-party data
  • producer or MGA involvement
  • portfolio monitoring
  • fairness or discrimination review
  • regulatory requirements
  • evidence
  • issues
  • risk acceptance

Underwriting controls should link to:

  • product
  • line of business
  • policy system
  • rating engine
  • data source
  • model
  • owner
  • evidence
  • exceptions
  • review
  • issues
  • dashboard status

Examples:

  • underwriting authority control
  • pricing model approval control
  • rate change approval control
  • exception review control
  • delegated underwriting review control
  • producer or MGA oversight control
  • portfolio performance monitoring
  • adverse selection monitoring
  • fairness or prohibited-factor review, where relevant

Underwriting governance becomes even more important when AI, third-party data, or predictive models are used.

NAIC’s AI topic page notes insurer AI use across insurance lifecycle areas and says the AI Model Bulletin sets expectations for governance and responsible use, including regulatory inquiry readiness.  

Underwriting should not be governed separately from AI, data, compliance, and evidence.

Underwriting governance checklist

QuestionYes / No
Are underwriting guidelines documented?
Are underwriting controls defined?
Are pricing and rating models linked to governance records?
Are data sources documented?
Are third-party data providers linked?
Are exception processes documented?
Are delegated underwriting arrangements monitored?
Are regulatory and market conduct obligations linked?
Are underwriting issues and complaints linked to remediation?
Can dashboards show underwriting risk by product and channel?

5. Claims, Litigation, Fraud, and Customer Outcomes

Claims governance is central to insurance trust.

Claims processes should connect to:

  • product
  • claim type
  • claims system
  • claims vendor or TPA
  • adjuster authority
  • litigation
  • fraud indicators
  • customer complaints
  • settlement guidelines
  • claims handling obligations
  • service levels
  • reserve impact
  • leakage metrics
  • evidence
  • issues
  • remediation
  • validation
  • dashboard status

Claims risk may involve:

  • delayed claim processing
  • inconsistent claim decisions
  • unfair claims settlement practices
  • poor documentation
  • fraud control gaps
  • litigation exposure
  • vendor or TPA performance issues
  • catastrophe surge capacity
  • payment errors
  • customer complaints
  • AI-assisted claims decisions
  • data security or privacy events

Claims controls should be testable.

Examples:

  • claims authority review
  • claim file documentation control
  • claims payment approval control
  • TPA oversight control
  • litigation escalation control
  • fraud referral control
  • complaint escalation control
  • catastrophe claims surge plan
  • claim closure review
  • AI claims tool monitoring

Claims incidents and complaints should not sit outside GRC.

They are signals.

Connected GRC should help insurers identify repeat claims issues, root causes, vendor performance problems, and customer outcome risks.

Claims governance checklist

QuestionYes / No
Are claims processes mapped by product or claim type?
Are claims controls defined?
Are claims authority and approval controls documented?
Are TPAs and claims vendors linked?
Are complaints linked to claims processes?
Are litigation issues linked to claims risk?
Are fraud controls linked to claims workflows?
Are claim file reviews evidenced?
Are claims issues linked to remediation and validation?
Can dashboards show claims risk and customer outcomes?

6. Models, Predictive Analytics, and AI Governance

Insurance companies use models throughout the insurance lifecycle.

Models and AI may support:

  • underwriting
  • pricing
  • rating
  • claims triage
  • claims severity estimation
  • fraud detection
  • subrogation
  • marketing
  • customer segmentation
  • lapse prediction
  • reserving
  • reinsurance analysis
  • catastrophe modeling
  • capital modeling
  • risk selection
  • customer service
  • operational analytics

NAIC’s Model Bulletin on AI use by insurers says an insurer’s AI systems program should address governance, risk management controls, internal audit functions, senior-management and board accountability, lifecycle management, vendor AI systems, monitoring, documentation, and use across insurance lifecycle areas such as product development, marketing, underwriting, rating, claims administration, payment, and fraud detection.  

A connected model and AI governance record should include:

  • model or AI use case
  • owner
  • business purpose
  • lifecycle stage
  • line of business
  • product
  • data sources
  • third-party data
  • vendor or model provider
  • risk tier
  • validation
  • monitoring
  • fairness or consumer-impact review
  • human oversight
  • documentation
  • approval
  • issues
  • incident history
  • risk acceptance
  • dashboard status

For insurers, AI governance cannot be a generic enterprise program.

It must connect to insurance practices.

An underwriting model creates different risks than an internal summarization tool.

A claims automation model creates different risks than a marketing model.

A fraud model creates different risks than a reserving model.

Connected GRC allows risk-based AI governance by use case.

Model and AI governance checklist

QuestionYes / No
Are models and AI use cases inventoried?
Are owners assigned?
Are use cases linked to insurance lifecycle stages?
Are data sources documented?
Are third-party data and model providers linked?
Is risk tier assigned?
Is validation evidence retained?
Is monitoring defined?
Are adverse consumer outcome risks assessed where relevant?
Are AI issues and incidents linked to remediation?

7. Policyholder Data, Privacy, and Data Security

Insurance companies hold sensitive personal, financial, health, driving, property, claims, and policyholder information.

A connected data model should show:

  • policyholder data categories
  • applicant data
  • claims data
  • health data, where relevant
  • financial data
  • driving data
  • property data
  • geolocation or telematics data
  • producer data
  • employee data
  • complaint data
  • AI prompts and outputs
  • data owner
  • system
  • vendor
  • model or AI use case
  • retention rule
  • access control
  • privacy review
  • incident linkage
  • evidence

NAIC’s Insurance Data Security Model Law requires licensed insurers and other entities to maintain an information security program, investigate cybersecurity events, and notify the state insurance commissioner of cybersecurity events.  

Policyholder data should connect to:

  • systems
  • vendors
  • claims processes
  • underwriting processes
  • privacy notices
  • data retention
  • cyber controls
  • incident response
  • regulatory notification
  • AI and model governance

If an insurer cannot quickly identify what data is in an affected system, cyber and privacy response slows down.

If a third-party data source supports underwriting, compliance and AI governance need visibility.

If claims data is used in a model, governance needs to know the data source, retention, access, and monitoring.

Data inventory is foundational to insurance Connected GRC.

Data and privacy checklist

QuestionYes / No
Are policyholder data categories documented?
Are claims, underwriting, and applicant data categories mapped?
Are data owners assigned?
Are systems linked to data categories?
Are vendors linked to data categories?
Are AI and predictive models linked to data sources?
Are access controls linked to systems containing sensitive data?
Are retention requirements documented?
Are privacy and cyber incidents linked to affected data?
Can dashboards show data risk by product, system, vendor, and model?

8. Cyber Risk, Systems, Incidents, and Operational Resilience

Insurance companies are technology-dependent.

They rely on:

  • policy administration systems
  • claims systems
  • underwriting platforms
  • rating engines
  • actuarial systems
  • data warehouses
  • customer portals
  • producer portals
  • payment systems
  • telematics platforms
  • cloud infrastructure
  • vendor platforms
  • AI tools
  • fraud tools
  • CRM systems
  • call center tools

Cyber risk should link to:

  • system
  • data
  • product
  • line of business
  • owner
  • vendor
  • vulnerability
  • control
  • incident
  • remediation
  • evidence
  • risk acceptance
  • dashboard

NYDFS Part 500 is a good example of how cybersecurity governance can become a regulated operating requirement for insurers operating under applicable New York authorization; DFS says covered entities include, among others, entities operating under the Insurance Law, and the resource center explains required annual certification or acknowledgment filings by April 15.  

Cyber incidents should link to:

  • affected systems
  • affected policyholder data
  • affected vendors
  • affected claims or underwriting operations
  • notification assessment
  • root cause
  • remediation
  • validation
  • regulator reporting
  • board reporting

Operational resilience should connect to:

  • critical services
  • catastrophe operations
  • claims surge capacity
  • call center operations
  • vendor dependencies
  • system recovery
  • business continuity plans
  • incident response
  • exercises
  • failed tests
  • issues
  • corrective actions

Insurers need to be able to continue serving policyholders during stress events.

Connected GRC helps link cyber, operations, claims, vendors, and resilience.

Cyber and resilience checklist

QuestionYes / No
Are critical systems inventoried?
Are systems linked to products and processes?
Are systems linked to policyholder data?
Are cyber controls mapped to systems and data?
Are vulnerabilities linked to business impact?
Are incidents linked to affected systems, data, and vendors?
Are business continuity plans linked to claims and policyholder services?
Are resilience tests evidenced?
Are cyber risk acceptances time-bound and monitored?
Can dashboards show cyber risk by business impact?

9. Vendors, TPAs, MGAs, Reinsurers, and Outsourcing

Insurers rely heavily on external parties.

These may include:

  • third-party administrators
  • MGAs and MGUs
  • brokers and producers
  • adjusters
  • claims vendors
  • legal panel firms
  • restoration vendors
  • medical review vendors
  • fraud vendors
  • data providers
  • telematics providers
  • cloud providers
  • IT service providers
  • call centers
  • reinsurance partners
  • payment processors
  • AI and model vendors
  • actuarial and analytics providers

A connected third-party record should show:

  • vendor type
  • owner
  • contract owner
  • services provided
  • products supported
  • lines of business supported
  • systems accessed
  • data processed
  • criticality
  • regulatory relevance
  • evidence
  • contract obligations
  • business continuity evidence
  • incidents
  • issues
  • remediation
  • renewal
  • risk acceptance
  • dashboard status

Third-party risk is not only a procurement concern.

A TPA may affect claims handling and market conduct.
An MGA may affect underwriting and pricing.
A data provider may affect AI, underwriting, and fairness.
A claims vendor may affect policyholder experience.
A cloud provider may affect cyber and resilience.
A reinsurer may affect capital, risk transfer, and reporting.

Connected GRC helps insurers see third-party risk in business context.

SmartSuite’s Third-Party Risk Management page describes linked vendors, risks, controls, evidence, issues, remediation, and dashboards across vendor onboarding and monitoring.  

Third-party risk checklist

QuestionYes / No
Are third parties inventoried by type?
Are TPAs, MGAs, MGUs, claims vendors, and data providers identified?
Are owners assigned?
Are contracts linked?
Are vendors linked to products and lines of business?
Are vendors linked to systems and data?
Are vendor controls and evidence tracked?
Are vendor incidents linked to GRC records?
Are vendor issues linked to renewals and risk acceptance?
Can dashboards show third-party risk by product, process, and criticality?

10. Financial Reporting, Statutory Reporting, Audit, and ICFR

Insurance companies manage financial reporting, statutory reporting, actuarial reporting, and audit requirements.

A connected reporting and audit model should include:

  • financial reporting process
  • statutory reporting obligations
  • annual statement process
  • actuarial opinion or reserving process, where relevant
  • audit requirements
  • internal controls over financial reporting
  • management assessment
  • evidence
  • test results
  • deficiencies
  • remediation
  • validation
  • audit committee reporting

NAIC’s Model Audit Rule revisions address auditor independence, corporate governance, and internal control over financial reporting, and the NAIC working-group page notes that insurers with $500 million or more in direct and assumed premium file management’s assessment of ICFR with the state insurance department.  

A connected audit and reporting model should link:

  • controls to evidence
  • evidence to tests
  • test failures to deficiencies
  • deficiencies to remediation
  • remediation to validation
  • status to audit committee or board reporting

Financial reporting controls should also connect to systems and vendors.

If a policy administration system supports premium reporting, it may be relevant to financial reporting.

If a claims system supports reserves and unpaid loss estimates, system controls matter.

If a vendor supports actuarial data or reporting, vendor risk matters.

Connected GRC reduces audit friction and improves management visibility.

Financial reporting and audit checklist

QuestionYes / No
Are statutory and financial reporting processes documented?
Are controls mapped to reporting processes?
Are systems supporting reporting linked?
Are actuarial or reserving controls documented where relevant?
Are evidence requirements defined?
Are test results linked to controls?
Are deficiencies linked to remediation?
Is validation required before closure?
Are audit committee materials source-record-backed?
Can dashboards show reporting control health?

11. Controls, Evidence, Testing, Issues, and Remediation Validation

Insurance companies need strong evidence because regulators, auditors, boards, and business leaders all rely on proof.

Evidence may support:

  • ORSA
  • ERM
  • solvency assessments
  • market conduct exams
  • cyber exams
  • claims reviews
  • underwriting reviews
  • vendor oversight
  • AI governance
  • statutory reporting
  • internal audit
  • external audit
  • control testing
  • data security programs
  • incident response
  • board reporting

A connected evidence record should include:

  • evidence type
  • control
  • owner
  • source system
  • period
  • scope
  • reviewer
  • acceptance status
  • issue, if rejected
  • remediation
  • validation
  • dashboard status

Issues may come from:

  • regulatory exams
  • internal audit
  • claims audits
  • underwriting audits
  • cyber incidents
  • vendor reviews
  • AI reviews
  • evidence rejections
  • control testing
  • complaints
  • market conduct findings
  • financial reporting testing
  • model validation

Every issue should link to:

  • source
  • owner
  • risk
  • control
  • product
  • process
  • system
  • vendor
  • evidence
  • root cause
  • remediation plan
  • due date
  • validation
  • residual risk
  • risk acceptance

Issue closure should require validation for material issues.

“Remediation complete” should not equal “risk reduced” until evidence proves it.

Evidence and issue checklist

QuestionYes / No
Are evidence requirements defined for key controls?
Are evidence owners assigned?
Is evidence accepted or rejected?
Are evidence gaps linked to issues?
Are issues linked to source records?
Is root cause required for material issues?
Is remediation plan documented?
Is validation required before closure?
Are repeat issues visible?
Can dashboards show evidence and issue health by product, process, and risk?

12. Dashboards, Risk Acceptance, Executive Reporting, and Board Oversight

Insurance leaders need dashboards that show risk in business context.

Useful dashboard views include:

  • enterprise risk and ORSA dashboard
  • risk appetite dashboard
  • solvency and capital risk dashboard
  • underwriting risk dashboard
  • claims risk dashboard
  • claims customer outcome dashboard
  • vendor and TPA risk dashboard
  • cyber and data security dashboard
  • AI and model governance dashboard
  • market conduct dashboard
  • evidence readiness dashboard
  • issue remediation and validation dashboard
  • risk acceptance dashboard
  • board and committee reporting dashboard

Risk acceptance should be explicit.

Insurance companies may accept temporary residual risk when:

  • a model issue has a compensating control
  • a claims vendor remediation is delayed
  • a cyber vulnerability cannot be fixed immediately
  • an underwriting control needs phased rollout
  • a TPA issue is under remediation
  • a regulatory gap is being addressed
  • a legacy system cannot meet a control immediately
  • AI monitoring is not yet automated but manual review exists

Accepted risk should include:

  • risk description
  • owner
  • approver
  • rationale
  • compensating controls
  • expiration
  • monitoring
  • evidence
  • dashboard visibility

Accepted risk should not hide in email.

It should appear in executive and board reporting where material.

Executive dashboard checklist

QuestionYes / No
Does the dashboard show risks outside appetite?
Does it show ORSA and ERM risk status?
Does it show underwriting and claims risk?
Does it show cyber and data security risk?
Does it show vendor and TPA exposure?
Does it show model and AI governance risk?
Does it show evidence readiness?
Does it show issue remediation and validation?
Does it show risk acceptances and expirations?
Does it show decisions needed?

Insurance Connected GRC Dashboards

A mature insurance Connected GRC program should support role-specific dashboards from the same connected data model.

ERM and ORSA dashboard

Shows:

  • material risks
  • risk appetite status
  • KRIs
  • capital and solvency indicators
  • mitigation plans
  • accepted risks
  • board reporting items

Underwriting governance dashboard

Shows:

  • underwriting controls
  • portfolio exceptions
  • pricing model status
  • delegated authority reviews
  • third-party data use
  • issues and remediation
  • monitoring trends

Claims governance dashboard

Shows:

  • claims controls
  • claim file review status
  • TPA performance
  • complaints
  • litigation trends
  • fraud referrals
  • claims issues
  • customer outcome signals

Cyber and data security dashboard

Shows:

  • data security controls
  • critical systems
  • vulnerabilities
  • cybersecurity events
  • incident response
  • evidence readiness
  • regulatory notification status

Vendor and TPA dashboard

Shows:

  • critical vendors
  • TPAs
  • MGAs/MGUs
  • data providers
  • claims vendors
  • evidence status
  • incidents
  • issues
  • renewals
  • risk acceptances

Model and AI governance dashboard

Shows:

  • predictive models
  • AI use cases
  • risk tiers
  • validation
  • monitoring
  • third-party models
  • adverse consumer outcome reviews
  • issues
  • regulatory inquiry readiness

Market conduct dashboard

Shows:

  • complaints
  • claims handling issues
  • underwriting issues
  • producer oversight
  • regulatory exam findings
  • remediation
  • validation

Financial reporting and audit dashboard

Shows:

  • ICFR controls
  • evidence status
  • test results
  • deficiencies
  • remediation
  • validation
  • audit committee reporting

Executive and board dashboard

Shows:

  • top risks
  • risk appetite status
  • incidents
  • critical issues
  • evidence readiness
  • remediation validation
  • risk acceptances
  • decisions needed

One source model.

Multiple oversight views.

Common Insurance GRC Mistakes

Mistake 1: Treating ORSA as a report instead of a connected process

ORSA should connect to risks, controls, KRIs, incidents, issues, capital implications, and board decisions.

Mistake 2: Keeping claims governance outside enterprise risk

Claims handling affects customer outcomes, litigation, market conduct, reserves, fraud, and reputation.

Mistake 3: Treating underwriting models as only actuarial assets

Underwriting and pricing models can affect compliance, fairness, customer outcomes, data governance, AI oversight, and regulatory exams.

Mistake 4: Separating cybersecurity from data and business impact

Cyber risk should link to policyholder data, systems, products, vendors, claims, underwriting, incidents, and notification obligations.

Mistake 5: Treating vendor risk as procurement administration

TPAs, MGAs, data providers, claims vendors, and cloud providers can affect core insurance operations and regulatory risk.

Mistake 6: Reporting evidence submitted instead of evidence accepted

Uploaded files do not prove control operation.

Accepted evidence does.

Mistake 7: Closing remediation without validation

Issues should close only after remediation evidence is reviewed and the fix is validated.

Mistake 8: Letting AI governance sit outside market conduct

AI and predictive models should connect to consumer outcomes, insurance lifecycle use, data, vendors, controls, monitoring, and regulatory inquiry readiness.

A 90-Day Connected GRC Plan for Insurance Companies

Days 1–15: Choose the first connected workflow

Start with one high-value workflow:

  • ORSA risk to controls and KRIs
  • claims issue to remediation validation
  • cyber event to data security and notification workflow
  • vendor and TPA risk workflow
  • AI and predictive model governance workflow
  • underwriting control and evidence workflow
  • market conduct issue workflow
  • financial reporting control evidence workflow

Choose the workflow with the highest regulatory, operational, or board-reporting value.

Days 16–30: Build the minimum source-record model

Define records for:

  • risk
  • product
  • line of business
  • obligation
  • control
  • evidence
  • issue
  • claims process
  • underwriting process
  • system
  • data category
  • vendor
  • model or AI use case
  • incident
  • remediation
  • validation
  • risk acceptance
  • dashboard

Days 31–45: Clean ownership and relationships

Assign:

  • risk owners
  • product owners
  • claims owners
  • underwriting owners
  • control owners
  • evidence owners
  • data owners
  • system owners
  • vendor owners
  • model owners
  • issue owners
  • validation owners
  • dashboard owners

Map:

  • risks to controls
  • controls to evidence
  • products to obligations
  • vendors to data and processes
  • systems to policyholder data
  • models to data and business use
  • incidents to issues
  • issues to remediation and validation

Days 46–60: Launch the workflow

Build workflow for:

  • intake
  • assessment
  • evidence collection
  • evidence review
  • issue creation
  • remediation
  • validation
  • risk acceptance
  • escalation
  • dashboard update

Days 61–75: Pilot with real records

Use real examples:

  • one ORSA risk
  • one claims issue
  • one cyber event
  • one TPA
  • one underwriting model
  • one evidence gap
  • one risk acceptance
  • one board-reporting item

Days 76–90: Measure and expand

Measure:

  • evidence acceptance rate
  • overdue issue reduction
  • validation completion
  • risk appetite visibility
  • vendor review completeness
  • claims issue trends
  • model governance readiness
  • manual reporting reduction
  • board decision clarity

Then expand to the next connected workflow.

Connected GRC should scale through proof.

Not bureaucracy.

A Practical Test for Insurance Connected GRC

Pick one insurance risk.

For example:

  • claims handling risk
  • underwriting fairness risk
  • data security incident
  • TPA performance issue
  • predictive model governance issue
  • regulatory exam finding
  • cyber vulnerability affecting policyholder data
  • reserving process control issue
  • catastrophe claims surge risk
  • market conduct issue

Ask whether your GRC model can show:

  • risk owner
  • affected product or line of business
  • affected jurisdiction
  • affected process
  • affected system
  • affected policyholder data
  • affected vendor or TPA
  • applicable obligation
  • control
  • evidence
  • latest test result
  • open issues
  • remediation plan
  • validation status
  • risk acceptance
  • dashboard status
  • executive or board reporting status

If answering those questions requires ORSA files, compliance trackers, claims audits, underwriting documents, vendor files, cyber tools, model documentation, evidence folders, and meetings, insurance GRC is not connected enough.

That is common.

It is also the opportunity.

Final Thought

Insurance companies understand risk.

But understanding risk is not the same as connecting risk.

Insurance GRC becomes stronger when the operating model links the real work of the insurer:

Products.
Claims.
Underwriting.
Pricing.
Models.
Data.
Vendors.
Cybersecurity.
Policyholder experience.
Regulatory obligations.
Financial reporting.
Incidents.
Controls.
Evidence.
Issues.
Remediation.
Validation.
Risk acceptance.
Board reporting.

That is Connected GRC for insurance companies.

Not another compliance repository.

A better way to show how risk is identified, governed, controlled, evidenced, remediated, accepted, monitored, and reported.

For insurers, that connection matters because the promise of insurance is trust.

Connected GRC helps prove the organization is governing the risks behind that promise.

Table of Contents
Related Product Areas

Linked Articles

GRC & Resilience
Connected GRC for Financial Services

Learn how financial services firms can use Connected GRC to link risk, controls, evidence, vendors, cyber, resilience, privacy, AI, audit, and board reporting.

Read Article
arrow_forward
GRC & Resilience
Connected GRC for Public Companies

Learn how public companies can use Connected GRC to link SOX, disclosure controls, cyber risk, audit, evidence, issues, remediation, and board reporting.

Read Article
arrow_forward
GRC & Resilience
Connected GRC for Financial Technology Companies

Learn how fintech companies can use Connected GRC to link compliance, product risk, cyber, vendors, bank partners, payments, privacy, AI, evidence, issues, and dashboards.

Read Article
arrow_forward
GRC & Resilience
What Is Connected GRC? A Practical Guide to Risk, Compliance, Audit, and Resilience Working Together

Connected GRC links risk, compliance, audit, cyber, third-party risk, privacy, AI governance, ESG, SOX, and resilience into shared workflows, data, and accountability.

Read Article
arrow_forward
GRC & Resilience
GRC vs IRM vs ERM: What Leaders Actually Need to Know

Learn the difference between GRC, IRM, and ERM, and how leaders can use Connected GRC to link governance, risk, compliance, controls, issues, evidence, and decisions.

Read Article
arrow_forward
GRC & Resilience
How to Build a Connected GRC Business Case

Learn how to build a Connected GRC business case by quantifying duplicate work, audit effort, evidence gaps, issue remediation, vendor risk, reporting friction, and executive value.

Read Article
arrow_forward
GRC & Resilience
How to Implement Connected GRC in 90 Days Without Boiling the Ocean

Learn how to implement Connected GRC in 90 days by starting with a focused workflow, linking risks, controls, evidence, issues, dashboards, and owners without overbuilding.

Read Article
arrow_forward
GRC & Resilience
The Connected GRC Data Model: The Records Every Program Needs

Learn the core records every Connected GRC program needs, including risks, obligations, controls, evidence, issues, vendors, incidents, assets, audits, and dashboards.

Read Article
arrow_forward
GRC & Resilience
How to Build a Risk Appetite Dashboard for Executives

Learn how to build a risk appetite dashboard for executives by connecting risk appetite, KRIs, thresholds, controls, issues, remediation, risk acceptance, and decisions.

Read Article
arrow_forward
GRC & Resilience
AI Governance: Connecting Model Risk, Policy, Controls, Evidence, and Accountability

Learn how AI Governance works in Connected GRC by linking AI inventories, model risk, policies, data, vendors, controls, evidence, issues, monitoring, and accountability.

Read Article
arrow_forward
GRC & Resilience
AI Vendor Risk: Contract, Data, Cyber, and Monitoring Questions to Ask

Learn what to ask AI vendors about contracts, data use, model providers, cyber controls, monitoring, evidence, incidents, retention, and risk acceptance.

Read Article
arrow_forward
GRC & Resilience
Privacy Incident vs Security Incident: How Connected GRC Keeps Them Aligned

Learn the difference between privacy incidents and security incidents, and how Connected GRC links incident intake, data impact, notification, evidence, issues, and remediation.

Read Article
arrow_forward
GRC & Resilience
Operational Resilience: Connecting Critical Services, Assets, Vendors, and Response Plans

Learn how Operational Resilience works in Connected GRC by linking critical services, impact tolerances, assets, vendors, incidents, BIAs, continuity plans, issues, and recovery evidence.

Read Article
arrow_forward
GRC & Resilience
GRC Dashboards: Reporting Risk, Controls, Issues, and Evidence Without Creating Noise

Learn how to design GRC dashboards that connect risks, controls, issues, evidence, audits, vendors, incidents, and decisions without overwhelming leaders.

Read Article
arrow_forward

Frequently Asked Questions

Answers to common questions about SmartSuite’s pricing models, plan options, and onboarding programs.

What is Connected GRC for insurance companies?

Connected GRC for insurance companies is an operating model that links enterprise risk, ORSA, solvency, compliance, cyber risk, claims governance, underwriting governance, model risk, AI governance, third-party risk, privacy, financial reporting controls, evidence, issues, remediation, risk acceptance, dashboards, and board reporting into one traceable system.

Why do insurance companies need Connected GRC?

Insurance companies need Connected GRC because risks across underwriting, claims, reserving, cyber, data security, vendors, models, AI, compliance, solvency, financial reporting, and customer outcomes are deeply connected.

How does Connected GRC support ORSA?

Connected GRC supports ORSA by linking material risks to risk appetite, KRIs, controls, evidence, incidents, issues, mitigation plans, capital or solvency implications, risk acceptances, and board reporting.

How does Connected GRC support insurance cybersecurity?

Connected GRC links cyber risks to systems, policyholder data, vulnerabilities, data security controls, cybersecurity events, vendor dependencies, regulatory notification workflows, remediation, validation, and dashboards.

How does Connected GRC support claims governance?

Connected GRC links claims processes to controls, claim file reviews, TPAs, complaints, litigation, fraud, evidence, issues, remediation, validation, market conduct obligations, and customer outcome dashboards.

How does Connected GRC support underwriting governance?

Connected GRC links underwriting guidelines, pricing and rating models, data sources, third-party data, exceptions, delegated authority, regulatory obligations, controls, evidence, issues, and portfolio monitoring.

How should insurers govern AI and predictive models?

Insurers should link AI and predictive models to products, lifecycle use, data sources, vendors, risk tiers, validation evidence, monitoring, adverse consumer outcome review, human oversight, regulatory inquiry readiness, issues, incidents, and dashboards.

What dashboards should insurance companies build?

Insurance companies should build dashboards for ERM and ORSA, underwriting governance, claims governance, cyber and data security, vendor and TPA risk, model and AI governance, market conduct, financial reporting controls, evidence readiness, issues, risk acceptance, and board reporting.

Put CRI Profile into action with SmartSuite

Map controls, collect evidence, run assessments, manage remediation, and report readiness - all from a single connected system.