How to Fill Out the NAIC ORSA Summary Report (w/Examples) + FAQs

The NAIC ORSA Summary Report is a confidential, high-level report that large and medium-size U.S. insurers and insurance groups file with their lead state insurance regulator to show how they identify, measure, and manage their material risks, and whether they hold enough capital to stay solvent today and over their business plan. It is built on the NAIC ORSA Guidance Manual (the current edition is dated December 2022) and is required by each state’s version of the Risk Management and Own Risk and Solvency Assessment Model Act, known as Model #505.

Unlike a tax form with numbered boxes, this report is a written document built around three required sections, so the “fields” you fill out are the section headings and the topics inside them. Getting a section thin or missing the chief risk officer’s signed attestation can trigger more regulatory scrutiny, follow-up questions, and a deeper risk-focused exam, which costs your team weeks of extra work. About 1 in 2 insurers told a Protiviti and St. John’s University study they were not comfortable that they had examined all possible risk outcomes in their stress tests, which shows how hard the assessment work really is.

Here is what you will learn in this guide:

  • 📋 What the ORSA Summary Report is, who must file it, and the premium thresholds that decide if you are exempt.
  • 🗂️ A line-by-line walkthrough of all three required sections and the topics inside each one.
  • 🧪 Three full filled-out examples that follow named insurers through the whole report.
  • 📨 How to file the report with your lead state, including the New York DFS Portal and the December 1 deadline.
  • ⚠️ The most common mistakes filers make and the exact consequences each one brings.

What the ORSA Summary Report Is and Who Must File It

The ORSA Summary Report is the written output of your Own Risk and Solvency Assessment, which the NAIC ORSA Guidance Manual defines as a confidential internal assessment of the material and relevant risks tied to an insurer’s current business plan and the sufficiency of capital to support those risks. The report does not replace your enterprise risk management (ERM) framework; it is a summary of it. Think of the ORSA as the ongoing risk and capital process, and the Summary Report as the once-a-year written picture of that process.

The report goes to your domiciliary regulator, which is the insurance department of the state where your insurer is chartered. For an insurance group, you file with the lead state commissioner, who coordinates oversight for the whole group. The legal authority is your state’s adoption of Model #505, and almost every state has now adopted a version of it.

You must file if you cross the premium thresholds in the model act. An individual insurer is generally subject to ORSA if its annual direct written and unaffiliated assumed premium is $500 million or more, and an insurance group is subject if its combined premium is $1 billion or more. These figures include international direct and assumed premium but exclude premiums reinsured with the Federal Crop Insurance Corporation and the Federal Flood Program. If you fall under both thresholds, you are usually exempt, but a regulator can still require a report from any insurer based on rapid growth, risk concentration, a risk-based capital company action level event, or a hazardous financial condition, as the NAIC explains in its ORSA topic page.

The penalty for non-compliance is not usually a flat fine printed on a schedule; it is regulatory action. A late, missing, or weak report invites a deeper risk-focused examination, formal requests for added information, and possible enforcement under your state insurance code. The report is confidential and protected from public records laws, so the sensitive risk and capital detail inside it stays out of public view.

Before You Start: Documents and Information You Need

Pull these items together before you open a blank report, because a missing piece forces you to stop mid-draft and chase down another department. Each item below feeds a specific part of the three sections.

  • Your written ERM framework and risk policies. These anchor Section 1, and without them you cannot describe risk culture, governance, or controls.
  • Your risk appetite statement, tolerances, and limits. Section 1 requires these, and a missing limit makes your appetite look undefined to the regulator.
  • Your risk register or list of material “Top Risks.” Section 2 is built around these, and leaving one out can look like a gap in risk identification.
  • Stress test and scenario results for normal and stressed conditions. Section 2 needs both views, and missing stressed results is the most common cause of follow-up questions.
  • Economic capital model outputs and model validation documentation. Section 3 relies on these, and no validation evidence weakens the credibility of your capital numbers.
  • Your current 2-to-5 year business plan and financial projections. Section 3 tests capital over this horizon, and without it you cannot show prospective solvency.
  • Group structure chart and inter-group transaction details. Section 3 must consider fungibility of capital and contagion risk across the group.
  • Risk-based capital (RBC) results and rating agency capital views. These support the multiple capital viewpoints regulators expect in Sections 2 and 3.
  • Board and committee meeting records showing the report was reviewed. The attestation states the board received a copy, so you need proof it did.
  • The name and title of your chief risk officer (CRO). The CRO must sign, and an unsigned report is treated as incomplete.

Gather acronym definitions and a glossary too, because the New York DFS asks filers to define every acronym they use. Missing this makes reviewers guess at your meaning and slows the review.

Where to Get the Format and How to Access It

There is no downloadable government form for the ORSA Summary Report, and this trips up first-time filers who go looking for a numbered PDF. Instead, the structure comes from the NAIC ORSA Guidance Manual, which tells you the three sections and the topics each one must cover. You build the report as your own document, usually as a searchable PDF, following that structure.

Always confirm you are using the current edition of the manual. The edition in force is dated December 2022, and a proposed 2025 edition has been circulated for comment, so check the NAIC ORSA topic page before you begin to make sure you have the latest version. Citing the revision date near the top of your report helps your reviewer confirm you used the right guidance.

Each state may layer its own rules on top of the manual. New York, for example, sets out its requirements in Section 82.3 of Regulation 203 and accepts the report through the DFS Portal. Check your domiciliary state’s insurance department page for the exact submission method, because the manual sets the content while the state sets the channel and deadline.

Because the manual is a “living document,” the NAIC can update it without each state re-adopting it. That means the content expectations can shift year to year even when your state statute stays the same, so a quick yearly check of the manual protects you from building this year’s report on last year’s guidance.

Step-by-Step: How to Fill Out the ORSA Summary Report Section by Section

The report has three required sections, and the manual says each one should be sized to the nature, scale, and complexity of your business. Below, each section and its key topics get their own walkthrough so you know what to write, what an answer looks like, and where filers slip.

Cover Page and Filing Information

What it asks in plain English. Before the three sections, you add a cover page that identifies who is filing, for which entities, and as of what date.

How to answer it. List the name of the filing entity, the NAIC company name or names, the NAIC company codes, the NAIC group code, the report date, and a contact person’s name, email, and phone number, exactly as the New York DFS instructs. Use plain block text and keep it on the first page.

A specific example answer. Sandra Pell, CRO of Cardinal Mutual Insurance Company, writes the filing entity as Cardinal Mutual Insurance Company, the NAIC code as NAIC #12345, the report date as 09/30/2026, and her own contact line.

A nuance or edge case. If you file one report for a whole group, list every NAIC company code in the group, not just the lead insurer, so the regulator can map the report to each legal entity.

A common mistake and its consequence. Filers leave off the NAIC group code, and the lead state then cannot link the report to the right group file, which delays the review and may prompt a resubmission request.

A misconception about this field. Some filers think the cover page is optional because the manual focuses on three sections; in practice, states like New York treat the cover details as required filing information.

Section 1 – Description of the Insurer’s Risk Management Framework

What it asks in plain English. Section 1 asks you to describe how your company manages risk overall, in clear language a regulator can follow.

How to answer it. Write a high-level summary organized around the five framework principles in the Guidance Manual: risk culture and governance, risk identification and prioritization, risk appetite, tolerances and limits, risk management and controls, and risk reporting and communication. Keep it appropriate to your size and reference deeper internal policies you can produce on request.

A specific example answer. Cardinal Mutual writes that its Risk Committee reports to the full board quarterly, that it uses a risk register reviewed twice a year, and that its board-approved risk appetite caps net catastrophe loss at 15% of surplus.

A nuance or edge case. If you outsource part of your risk function, name the third party and explain how you oversee it, because the regulator still expects you to own the framework.

A common mistake and its consequence. Filers describe risk culture in vague terms with no link to the board, and the regulator reads this as weak governance, which raises the depth of the risk-focused exam.

A misconception about this field. Many believe Section 1 should be a long, detailed manual; the guidance says it is not intended to be lengthy and can reference internal documents instead.

Section 1A – Risk Culture and Governance

What it asks in plain English. This topic asks who is responsible for risk and how the “tone at the top” works.

How to answer it. Describe the board’s role, the committees involved, the reporting lines, and how risk ownership flows from the C-suite down to business units. Name the bodies and how often they meet.

A specific example answer. Marcus Reed, Chief Risk Officer of Liberty Crest Life Group, writes that the Enterprise Risk Committee meets monthly and escalates to the board’s Risk Oversight Committee each quarter.

A nuance or edge case. In a group, explain whether risk governance is centralized at the holding company or shared with legal entities, since this shapes how the regulator reads Section 3.

A common mistake and its consequence. Filers list committees but never show how risk decisions reach the board, and the regulator then questions whether the board truly oversees risk.

A misconception about this field. Some think governance means an org chart alone; the manual expects a description of behavior and accountability, not just boxes and lines.

Section 1B – Risk Identification and Prioritization

What it asks in plain English. This topic asks how you find your risks and decide which ones matter most.

How to answer it. Explain your process for spotting risks across categories such as credit, market, liquidity, underwriting, and operational risk, and how you rank them by materiality. Describe how often you refresh the list.

A specific example answer. Liberty Crest writes that it scores each risk on a 1-to-5 likelihood and impact scale and flags any risk scoring 16 or higher as a Top Risk.

A nuance or edge case. Include emerging risks, such as climate or cyber, even if you cannot yet measure them, because leaving them out looks like a blind spot.

A common mistake and its consequence. Filers list only easy-to-measure financial risks and skip operational and reputational ones, which makes the risk inventory look incomplete to the reviewer.

A misconception about this field. Some think only quantifiable risks belong here; the manual expects qualitative risks too when numbers are not feasible.

Section 1C – Risk Appetite, Tolerances, and Limits

What it asks in plain English. This topic asks how much risk your company is willing to take and the hard limits it sets.

How to answer it. State your board-approved risk appetite, the tolerances around it, and the specific limits that control day-to-day risk taking. Tie each limit to a metric you actually track.

A specific example answer. Aisha Benard, CRO of Summit Health Plans, writes that the board limits single-state membership concentration to 40% of total enrollment.

A nuance or edge case. If you have breached a limit during the year, disclose it and explain the corrective action, because hiding a breach is worse than reporting one.

A common mistake and its consequence. Filers write a vague appetite statement with no numeric limits, and the regulator cannot tell whether risk taking is actually controlled, which weakens the whole framework.

A misconception about this field. Some believe appetite and tolerance mean the same thing; appetite is the broad willingness, while tolerances and limits are the measurable guardrails.

Section 1D – Risk Management and Controls

What it asks in plain English. This topic asks how you actually manage and mitigate the risks you have identified.

How to answer it. Describe the controls, hedging, reinsurance, and mitigation actions you use, and how you test that they work. Connect each major risk to the control that manages it.

A specific example answer. Cardinal Mutual writes that it cedes 50% of its property catastrophe exposure through a reinsurance treaty renewed each January.

A nuance or edge case. If a key control depends on one person or one vendor, note the concentration, since regulators care about key-person and continuity risk.

A common mistake and its consequence. Filers describe controls but never say how they test effectiveness, and the regulator then doubts the controls actually work.

A misconception about this field. Some think buying reinsurance alone counts as risk management; the manual expects a full control environment, not a single transfer.

Section 1E – Risk Reporting and Communication

What it asks in plain English. This topic asks how risk information moves through the company and reaches decision makers.

How to answer it. Explain what risk reports you produce, who receives them, and how often. Show that the board and senior management see the same risk picture used in the report.

A specific example answer. Liberty Crest writes that its quarterly risk dashboard goes to the board and mirrors the metrics used in this report.

A nuance or edge case. If escalation rules trigger faster reporting when a limit is breached, describe that path, because regulators want to see timely escalation.

A common mistake and its consequence. Filers describe reporting that does not match what the board actually receives, and any inconsistency the regulator finds undercuts the report’s credibility.

A misconception about this field. Some think reporting means the annual ORSA report alone; the manual expects ongoing internal reporting, not a once-a-year document.

Section 2 – Insurer’s Assessment of Risk Exposure

What it asks in plain English. Section 2 asks you to measure your risks in both normal and stressed conditions and show the results.

How to answer it. Document management’s quantitative assessment, or qualitative where numbers are not feasible, for each material risk category. Include the risks identified, the measurement approaches and assumptions, the quantification per category, the outcomes of plausible adverse scenarios, and the impact of stress on available capital across multiple capital viewpoints.

A specific example answer. Cardinal Mutual writes that a 1-in-200-year hurricane scenario would reduce surplus by $180 million, leaving an RBC ratio of 310%.

A nuance or edge case. Use stress tests built for your risk profile, since the manual says each insurer should use tests applicable to its own risks, not a generic set.

A common mistake and its consequence. Filers show only normal-environment numbers and skip the stressed view, and this is the single most common reason regulators send follow-up questions.

A misconception about this field. Some think Section 2 must quantify everything; the manual allows qualitative assessment when quantitative measurement is not feasible.

Section 2A – Risk Categories and Measurement Methods

What it asks in plain English. This topic asks which risks you measured and how you measured each one.

How to answer it. For each major category, name the measurement method, the key assumptions, and the metric you report. Cover credit, market, liquidity, underwriting, and operational risk at a minimum.

A specific example answer. Liberty Crest writes that it measures interest rate risk using a 200-basis-point shock applied to its asset-liability model.

A nuance or edge case. If you rely on a vendor model, disclose it and explain your validation, because regulators expect to see model validation and calibration.

A common mistake and its consequence. Filers list results without stating assumptions, and the regulator cannot judge whether the numbers are reasonable, which prompts a request for more detail.

A misconception about this field. Some think naming the software is enough; the manual wants the assumptions and validation behind the model, not just its name.

Section 2B – Stress Testing and Scenario Outcomes

What it asks in plain English. This topic asks what happens to your capital under bad-but-plausible scenarios.

How to answer it. Describe each scenario, the assumptions behind it, and the dollar impact on available capital, viewed through regulatory and, where relevant, rating agency lenses. Show a range of outcomes.

A specific example answer. Summit Health writes that a severe pandemic claims scenario would cut its RBC ratio from 480% to 250% over twelve months.

A nuance or edge case. Combine scenarios where risks are correlated, because a regulator wants to see that you considered events happening together, not in isolation.

A common mistake and its consequence. Filers run mild scenarios that never threaten capital, and the regulator reads this as a stress test that does not actually stress anything.

A misconception about this field. Some think one severe scenario is enough; the manual expects a meaningful suite of scenarios across a range of outcomes.

Section 3 – Group Risk Capital and Prospective Solvency Assessment

What it asks in plain English. Section 3 asks whether you have enough capital today and over your business plan to support all the risks you measured.

How to answer it. Combine the risk measures from Section 2 with your capital framework to show capital adequacy. Cover your definition of solvency, valuation regime, time horizon, risks modeled, quantification method, measurement metric, target capital level, and how you aggregate and diversify across the group.

A specific example answer. Cardinal Mutual writes that it targets economic capital at the 99.5% confidence level over a one-year horizon and holds $1.4 of available capital for every $1.0 required.

A nuance or edge case. Address fungibility of capital and contagion risk across the group, because trapped capital in one entity cannot always cover a loss in another.

A common mistake and its consequence. Filers report only point-in-time RBC and skip the forward-looking view, which means the report fails to show prospective solvency at all.

A misconception about this field. Some think regulatory RBC alone satisfies Section 3; the manual expects your own economic solvency view in addition to regulatory capital.

Section 3A – Group Assessment of Risk Capital

What it asks in plain English. This topic asks whether the group’s capital is adequate against its total, aggregated risk profile right now.

How to answer it. Show the group’s available capital, the capital required against the aggregate risk profile, and the methods used to aggregate risks across entities. Explain inter-group transactions and financing.

A specific example answer. Liberty Crest writes that the group holds $2.1 billion of available capital against $1.5 billion of required economic capital after diversification.

A nuance or edge case. Align the assessment with how management actually makes decisions, since the manual says internal processes should match your decision-making culture.

A common mistake and its consequence. Filers add up entity capital without adjusting for fungibility, and the regulator views the group capital as overstated.

A misconception about this field. Some think the group assessment sets a binding group capital requirement; the ORSA does not set one, though it does inform supervisory action.

Section 3B – Prospective Solvency Assessment

What it asks in plain English. This topic asks whether you will stay solvent over the next few years under your business plan.

How to answer it. Project capital and required capital over your 2-to-5 year planning horizon under normal and stressed conditions, and describe management actions if capital looks short, such as plan changes or raising new capital.

A specific example answer. Summit Health writes that under its base plan the RBC ratio stays above 400% through 2029, and that it would pause dividends if it ever fell below 300%.

A nuance or edge case. Include emerging risks that could change your future profile, because a forward view that ignores new risks looks incomplete.

A common mistake and its consequence. Filers project only the rosy base case, and the regulator cannot tell whether the plan survives stress, which triggers deeper review.

A misconception about this field. Some think projecting one year ahead is enough; the manual expects a multi-year business planning horizon.

The CRO Signature and Attestation

What it asks in plain English. This final block asks your chief risk officer to sign and attest to the report.

How to answer it. The CRO signs a statement that, to the best of their knowledge and belief, the insurer applies the ERM process described in the report and that a copy was provided to the board or the appropriate committee, as the Guidance Manual requires. In New York, this attestation language comes from Section 82.3(b)(3) of Regulation 203.

A specific example answer. Marcus Reed signs as Chief Risk Officer, Liberty Crest Life Group, dates it 11/15/2026, and confirms the board received a copy.

A nuance or edge case. If your company has no CRO title, another executive responsible for ERM oversight may sign, as the New York DFS allows.

A common mistake and its consequence. Filers submit the report before the board has actually seen it, which makes the attestation false and exposes the signer to regulatory risk.

A misconception about this field. Some think the CEO or CFO should sign; the manual specifically calls for the chief risk officer or the equivalent ERM executive.

Three Filled-Out Examples Using Real Scenarios

These three named insurers show how very different companies complete the same three-section report. Each table walks the filer through the major parts.

Scenario 1: Cardinal Mutual Insurance Company, a single-state P&C insurer filing for the first time near the threshold.

Form Section What Cardinal Mutual Enters
Cover Page Cardinal Mutual Insurance Company, NAIC #12345, report date 09/30/2026, contact Sandra Pell, CRO
Section 1 – Framework High-level summary tied to the five principles, references internal risk policy manual
Section 1C – Appetite Net catastrophe loss capped at 15% of surplus
Section 2 – Exposure Quantifies credit, market, underwriting, operational risk in normal and stressed views
Section 2B – Stress 1-in-200 hurricane cuts surplus by $180M, RBC ratio falls to 310%
Section 3A – Group Capital Single-entity assessment, $1.4 available capital per $1.0 required
Section 3B – Prospective Three-year projection showing RBC stays above 300%
Attestation Signed by Sandra Pell, CRO, confirms board received the report

Scenario 2: Liberty Crest Life Group, a multi-state life group filing through its lead state commissioner.

Form Section What Liberty Crest Enters
Cover Page Lists all NAIC company codes in the group plus group code, contact Marcus Reed
Section 1A – Governance Enterprise Risk Committee monthly, board Risk Oversight Committee quarterly
Section 1B – Identification 1-to-5 scoring scale, Top Risks flagged at score 16+
Section 2A – Methods Interest rate risk via 200-basis-point shock on ALM model
Section 3A – Group Capital $2.1B available vs. $1.5B required after diversification
Section 3 – Fungibility Explains trapped capital and contagion risk across legal entities
Section 3B – Prospective Five-year projection under base and stressed plans
Attestation Signed by Marcus Reed, CRO, one report covering the entire group

Scenario 3: Summit Health Plans, a health insurer that considers a waiver but still files.

Form Section What Summit Health Enters
Cover Page Summit Health Plans, NAIC code and group code, contact Aisha Benard, CRO
Exemption note Notes group premium exceeds $1B, so no exemption applies
Section 1C – Appetite Single-state membership concentration limited to 40% of enrollment
Section 2B – Stress Severe pandemic scenario cuts RBC from 480% to 250%
Section 2 – Qualitative Adds qualitative view of reputational and regulatory risk
Section 3A – Group Capital Aggregated health-entity capital adjusted for fungibility
Section 3B – Prospective RBC stays above 400% through 2029, dividends pause below 300%
Attestation Signed by Aisha Benard, CRO, confirms board copy provided

How to File the Completed Report

Filing rules are set by your domiciliary or lead state, while the content follows the NAIC manual. The report is confidential and is filed annually, and most states accept it through a secure online portal. Below are the channels you are most likely to use, with New York as a concrete example.

Online portal (most common). New York requires submission of the ORSA Summary Report through the DFS Portal, even if the insurer is not part of a holding company system. You create a portal account, use the “Ask for Apps” tab to request access to the Insurance Company and Fraternal Benefit Society Filings application, and upload a searchable OCR PDF. There is no filing fee for the ORSA report itself, and your proof of filing is the portal confirmation and timestamp you should save.

Deadline. In New York, Section 82.3 of Regulation 203 requires the report by December 1 each year, so build your internal review and board sign-off well before that date. Missing the deadline invites regulatory follow-up and signals weak controls.

By email to a bureau contact. Some questions and supplemental materials route to a specific bureau, such as the Life, Property & Casualty, or Health Bureau in New York, each with a named supervising examiner listed on the DFS page. Use these contacts for questions, not as the primary filing channel.

Format requirements. Submit the report as a searchable document, such as an OCR PDF, with the exception that the signature page need not be searchable, per New York guidance. Define every acronym, include a table of contents, and map any reference to an outside document like an SEC 10-K so the reviewer can find it. Keep a dated copy of exactly what you uploaded as your own proof of filing.

What Happens After You File

Once filed, your lead state regulator reviews the report and uses it to shape its supervisory plan. The NAIC says the report may help determine the scope, depth, and timing of risk-focused analysis and examination, so a strong report can actually reduce how often and how deeply you are examined. Insurers with ERM frameworks judged robust for their risk may face a lighter review than those with weaker frameworks.

Regulators often follow up with questions or requests for the internal documents your report references, such as risk policies or model validation files. Answering quickly and consistently keeps the review on track, while gaps or contradictions can expand the review into a full risk-focused exam. The lead state may also coordinate with other states where group entities are domiciled.

The report stays confidential and is protected from public records requests, so the sensitive detail inside it does not become public. Your team should then feed any regulator feedback back into next year’s ORSA, since the manual treats this as an ongoing process, not a one-time filing. Plan to refresh and refile annually, carrying forward improvements each cycle.

Mistakes to Avoid When Filling Out the Report

Each error below has burned real filers, so check your draft against this list before you submit.

  • Showing only normal-environment results in Section 2. The regulator sends follow-up questions because stressed results are missing.
  • Writing a vague risk appetite with no numeric limits. The reviewer cannot tell if risk taking is controlled, which weakens Section 1.
  • Skipping the forward-looking solvency view in Section 3. The report fails to demonstrate prospective solvency at all.
  • Forgetting the CRO signature or attestation. The report is treated as incomplete and may be returned.
  • Filing before the board has seen the report. The attestation becomes false and exposes the signer to enforcement risk.
  • Adding up entity capital without adjusting for fungibility. Group capital looks overstated and draws scrutiny.
  • Listing only financial risks and ignoring operational and reputational ones. The risk inventory looks incomplete.
  • Leaving acronyms undefined. Reviewers guess at meaning and the review slows down.
  • Running mild stress scenarios that never threaten capital. The regulator sees a test that does not actually stress anything.
  • Omitting the NAIC group code on the cover page. The lead state cannot map the report and may request a resubmission.
  • Using last year’s edition of the Guidance Manual. Your content may miss new expectations and look outdated.
  • Submitting a non-searchable scanned PDF. New York requires a searchable document, so a flat scan can be rejected.

Do’s and Don’ts

Do:

  • Do size each section to your company’s nature, scale, and complexity, because the manual expects proportionality, not bulk.
  • Do tie every risk in Section 2 back to a control in Section 1, so the report reads as one connected story.
  • Do disclose any limit breaches and your corrective action, since hiding a breach looks worse than reporting it.
  • Do include both regulatory and economic capital views, because Section 3 expects your own solvency view too.
  • Do get board review before the CRO signs, so the attestation is truthful.
  • Do keep your portal confirmation, because it is your proof of filing.

Don’t:

  • Don’t copy a generic stress test, because the manual wants tests built for your own risk profile.
  • Don’t treat the report as a one-time filing, since it is an annual, ongoing process.
  • Don’t make Section 1 a 100-page manual, because the guidance says it should not be lengthy.
  • Don’t let the report contradict what the board actually receives, because inconsistency destroys credibility.
  • Don’t ignore emerging risks like cyber and climate, since leaving them out looks like a blind spot.
  • Don’t assume you are exempt without checking both premium thresholds, because crossing either one can trigger the requirement.

Pros and Cons of Filing on Your Own vs. With Help

Many insurers debate whether to build the report fully in-house or bring in an actuarial or consulting firm. The table-free view below weighs both.

Pros of filing with your own ERM team:

  • You keep deep knowledge of your own risks in-house, which strengthens your framework long term.
  • You avoid consulting fees, which can run into six figures for a full build.
  • Your team learns the process, so each yearly filing gets easier and faster.
  • The report reflects your real culture, not an outside template, which regulators value.
  • You control the timeline and are not waiting on a vendor near the deadline.

Cons of filing on your own:

  • A first-time team may underestimate stress testing, which is the top reported challenge.
  • Economic capital modeling often needs an actuary or data scientist your team may lack.
  • An inexperienced draft risks gaps that trigger a deeper regulatory exam.
  • The group capital and prospective solvency work is technically demanding and easy to get wrong.
  • Internal teams may be too close to the business to spot blind spots an outsider would catch.

Frequently Asked Questions

Is the ORSA Summary Report a fixed government form with numbered boxes?

No. It is a written report built around three required sections from the NAIC ORSA Guidance Manual, so you create the document yourself rather than fill in a numbered PDF.

Do I have to file if my individual insurer writes less than $500 million in premium?

No. You are generally exempt if you write under $500 million and your group writes under $1 billion, though a regulator can still require a report based on unique circumstances.

Is the report confidential once I file it?

Yes. The filing is confidential and protected from public records laws, so the sensitive risk and capital detail inside it does not become public.

Does the chief risk officer have to sign the report in the attestation block?

Yes. The CRO, or another executive responsible for ERM oversight, must sign and attest that the company applies the described ERM process and that the board received a copy.

Do I write quantitative numbers for every risk in Section 2?

No. You quantify where feasible, but the manual allows qualitative assessment for risks like operational and reputational risk that cannot be easily measured.

Should Section 1 be long and detailed?

No. The Guidance Manual says Section 1 is not intended to be lengthy and can reference deeper internal policies you provide on request.

Do I list every NAIC company code on the cover page for a group filing?

Yes. List every entity’s NAIC code plus the group code so the lead state can map the single group report to each legal entity.

Does Section 3 require a forward-looking view, or just current capital?

Yes. Section 3 requires a prospective solvency assessment over your 2-to-5 year business plan, not just a point-in-time capital number.

Is regulatory RBC alone enough to satisfy Section 3?

No. The manual expects your own economic solvency view in addition to regulatory capital requirements.

Do I file one report for my whole group or a separate one per entity?

Yes, you file one report covering the entire system, submitted to the lead state commissioner, rather than a separate report for each insurer.

Should I submit the report as a scanned image PDF?

No. New York requires a searchable document such as an OCR PDF, though the signature page itself need not be searchable.

Is there a single national filing deadline for the report?

No. Deadlines are set by each state; New York requires the report by December 1 each year through the DFS Portal.

Does filing a strong report reduce my chance of a deep exam?

Yes. Regulators use the report to scope exams, and a robust ERM framework can lead to a lighter review than a weak one.

Can I rely on a vendor model without explaining it in Section 2?

No. You must disclose the model and demonstrate your model validation and calibration, even when a third party built it.