Risk-based capital tells regulators something important about an insurer’s current capital position, but it cannot answer every forward-looking question. What happens if catastrophe losses increase, credit markets deteriorate, policyholder behavior changes, a major cyber event occurs, or several risks hit at the same time? ORSA is designed to force management to connect risk, strategy and capital before a solvency problem appears.
The NAIC introduced the U.S. ORSA framework as part of post-financial-crisis modernization of group supervision. Its Risk Management and Own Risk and Solvency Assessment Model Act (#505) became effective January 1, 2015.
What ORSA is—and what it is not
ORSA is not a single statutory ratio, a once-a-year spreadsheet or an external audit opinion. NAIC describes it as an ongoing internal process integrated into enterprise risk management (ERM). The insurer evaluates its own current and prospective risk profile and solvency position under stress scenarios.
It is “own risk” because the assessment should reflect the insurer’s actual business model, risk appetite, products, investments, reinsurance, operations and strategic plans—not just a generic regulator formula.
Who is generally subject to the NAIC ORSA framework?
NAIC states that ORSA applies to individual U.S. insurers with more than $500 million in annual direct written and assumed premium and to insurance groups with more than $1 billion in annual direct written and assumed premium. States implement the model through their own law, so a company must verify the applicable jurisdiction’s statute and filing requirements.
| ORSA element | Core question |
|---|---|
| Risk-management framework | How does the company identify, measure, monitor, manage and report material risks? |
| Risk exposure assessment | How significant are underwriting, market, credit, liquidity, operational and other material risks? |
| Capital adequacy | How much capital is needed now and prospectively under the business plan and stress scenarios? |
| Group perspective | How can affiliates and group-wide risks affect insurance entities and policyholder protection? |
What risks does an ORSA consider?
NAIC guidance identifies reasonably foreseeable and relevant material risks, including underwriting, credit, market, operational and liquidity risks. Depending on the insurer, the assessment can also need to address catastrophe, cyber, model, strategic, reputational, climate-related, concentration, third-party and affiliate risks.
The point is not to create the longest possible risk list. Management should identify risks that could materially affect the insurer’s ability to execute its plan and meet policyholder obligations.
ORSA and enterprise risk management
A mature ORSA starts with the ERM framework: governance, risk appetite, limits, ownership, escalation and reporting. If risk appetite says the insurer will tolerate a certain level of catastrophe PML, asset concentration or liquidity stress, ORSA should show how those limits connect to capital and strategic decisions.
This is why an ORSA report built only by a compliance department is weak. Underwriting, actuarial, finance, investments, reinsurance, operations, cyber/security and senior management all hold pieces of the risk picture.
ORSA vs. Risk-Based Capital (RBC)
RBC is a standardized regulatory capital framework that compares total adjusted capital with risk-based capital requirements. ORSA is broader and forward-looking: it evaluates the company’s own material risks and capital needs over the business planning horizon, including stress scenarios.
Read our Risk-Based Capital guide for the regulatory action levels and why a single RBC ratio should not be treated as a complete financial-strength score.
ORSA vs. financial-strength ratings
AM Best, S&P, Moody’s and Fitch are private rating organizations using their own methodologies. ORSA is a confidential regulatory and management process. A strong rating does not eliminate ORSA obligations, and an ORSA summary is not a public consumer rating. Our financial-strength ratings guide explains those separate systems.
ORSA vs. Form F
NAIC distinguishes ORSA from Form F, the Enterprise Risk Report. ORSA focuses on risks associated with insurance entities and their risk/capital framework, while Form F focuses on material risks arising from non-insurance entities in the holding-company system that could affect the insurer. The two tools can overlap but answer different supervisory questions.
What does an ORSA stress scenario look like?
A useful stress is severe enough to challenge the business plan but coherent enough to produce decision-useful results. For a property insurer, a scenario could combine a major catastrophe with reinsurance collectability stress and falling investment values. For a life insurer, a scenario might combine interest-rate movement, lapse behavior and credit deterioration. For a health insurer, medical trend and provider concentration could be central.
The output should not stop at “capital falls.” Management should ask what actions are available: reinsurance purchase, underwriting changes, asset repositioning, dividend limits, capital raising, expense reduction or product repricing—and whether those actions remain realistic under stress.
Why liquidity deserves separate attention
An insurer can appear solvent on an accounting basis yet face severe short-term liquidity demands. Catastrophe claim payments, collateral requirements, surrender activity or derivative calls can create timing pressure. NAIC’s current ORSA guidance emphasizes more detailed liquidity-risk discussion because solvency and liquidity are related but not identical.
The ORSA Summary Report is confidential
Covered insurers document the process and submit a confidential high-level ORSA Summary Report to the lead state commissioner or, upon request, the domiciliary regulator. Confidentiality matters because ORSA can contain sensitive risk appetite, scenario, capital and strategic information.
What regulators are looking for
- Risk governance that is actually used in decision-making.
- Clear ownership and escalation of material risks.
- Risk measurement that matches the insurer’s business model.
- Stress testing tied to strategic and capital decisions.
- Evidence that management understands concentrations and dependencies.
- Prospective capital analysis, not only historical ratios.
- Consistency among risk appetite, business plan, reinsurance and capital strategy.
Why ORSA matters even to readers outside compliance teams
ORSA is one of the reasons U.S. insurance solvency supervision goes beyond a single balance-sheet snapshot. It encourages insurers to examine how risks interact before losses occur. That perspective also helps explain other regulation topics, including guaranty systems, reinsurance credit and group supervision.
See our insurer failure and guaranty associations guide for what happens when prevention and supervision are not enough, and our NAIC model laws vs. state law guide for how Model #505 becomes binding in individual jurisdictions.
A practical ORSA governance checklist
- Confirm the current state-law filing requirement and deadline.
- Map material risks to accountable executives and board oversight.
- Update risk appetite and limits when strategy changes.
- Reconcile ORSA assumptions with the approved business plan.
- Test severe but plausible combinations of risks.
- Identify management actions and test whether they are executable.
- Document model limitations and expert judgment.
- Compare projected capital needs with available capital and liquidity.
- Escalate material breaches or emerging risks promptly.
- Use the ORSA process continuously rather than treating the report as an annual filing project.
Frequently asked questions
Is ORSA required for every U.S. insurer?
No. The NAIC framework includes premium thresholds, and states enact their own versions. Companies must check applicable state law.
Is ORSA the same as RBC?
No. RBC is a standardized capital framework; ORSA is a broader, forward-looking assessment of the insurer’s own risks, ERM and capital adequacy.
Is an ORSA report public?
The NAIC framework treats the high-level ORSA Summary Report submitted to regulators as confidential.
How often is ORSA conducted?
NAIC states that covered insurers conduct ORSA at least annually, but the underlying risk-management process is ongoing.
Sources and further reading
Reviewed October 5, 2026. ORSA requirements are implemented through state law. Insurers should verify current jurisdiction-specific thresholds, deadlines and regulator guidance.
