Skip to content

Evidence request lists

NAIC Insurance Data Security Model Law (MDL-668)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Cross-State Compliance

NAIC-8
NY DFS 23 NYCRR 500 Alignment and State Adoption Variances

Maintain awareness of New York DFS 23 NYCRR Part 500 Cybersecurity Regulation alignment (which NAIC Model Law substantively adopted in 2017 plus 2024 amendments adding ransomware payment notification + extortion payment disclosure + chief information security officer (CISO) reporting requirements). Track state-by-state variances including Connecticut 90-day vs 72-hour notification + South Carolina early adopter framework + Ohio safe harbor incentives + Mississippi inclusion of insurance group privacy + Indiana annual filing date variation. Implement multi-state controls capable of meeting the strictest state requirements per multi-licensed insurer compliance matrix.

Artefacts an auditor will ask for
  • NY DFS 500 + NAIC alignment matrix
  • State adoption tracker (24+ states)
  • Multi-state variance compliance matrix
  • Annual notification calendar
  • NYDFS CISO certification
  • Ransomware payment notification process
Where this commonly fails
  • No state adoption tracker
  • Missing multi-state variances
  • No NYDFS alignment
  • No ransomware notification process

Governance Oversight

NAIC-4
Board and Senior Management Oversight - Section 4(F)

Designate one or more employees, an affiliate, or an outside vendor to be responsible for the Information Security Program. Require the Board of Directors (or appropriate committee) or senior management to receive an annual written report from the ISP designee covering: overall status of the Program + material matters relating to the Program including issues such as risk assessment + risk management and control decisions + service provider arrangements + results of testing + cybersecurity events or violations and management response + recommendations for material changes. File annual cybersecurity certification with state insurance commissioner by 15 February following the calendar year covered.

Artefacts an auditor will ask for
  • ISP designee appointment letter
  • Annual board report
  • Board meeting minutes
  • Senior management committee minutes
  • 15 February annual certification filing
  • Material matters log
Where this commonly fails
  • No designated ISP owner
  • No annual board report
  • Missing 15 February certification
  • Inadequate board engagement

Governance and Scope

NAIC-1
NAIC Model Law Adoption, Scope, and Licensee Definitions

Comply with the NAIC Insurance Data Security Model Law (Model Law 668) as adopted by the licensees state-of-domicile insurance department (24+ states have adopted as of 2025 including South Carolina first, Ohio, Michigan, Mississippi, Alabama, Connecticut, Delaware, Indiana, New Hampshire, Louisiana, Virginia, Iowa, Hawaii, Minnesota, North Dakota, Maryland, Wisconsin, Tennessee, Kentucky, Vermont, Maine, Illinois, New Mexico, Alaska, Oklahoma). Establish program scope across all licensees including insurers, producers, third party administrators (TPAs), independent adjusters, and other entities licensed by the state insurance department. Maintain exemption analysis (HIPAA covered entities + small licensee fewer than 10 employees + reinsurers subject only at cedent level + employees of licensee not separately licensed).

Artefacts an auditor will ask for
  • State-of-domicile adoption confirmation
  • Licensee scope analysis
  • Exemption qualification documentation
  • Affiliate consolidation analysis
  • Reinsurer scope analysis
  • Annual scope review
Where this commonly fails
  • Outdated state adoption tracking
  • Unclear licensee classification
  • Missing exemption documentation
  • No affiliate analysis

Incident Response

NAIC-6
Cybersecurity Event Investigation and Notification - Sections 6 and 7

Establish a written Incident Response Plan to respond to and recover from a Cybersecurity Event. Investigate Cybersecurity Events to determine scope + Nonpublic Information involved + impact of the Event + reasonable measures to restore the security of the Information Systems compromised. Notify the state insurance commissioner of the state-of-domicile within 72 hours of determining a Cybersecurity Event has occurred (if at least one of the threshold conditions is met). Notify affected consumers as required by state-specific consumer notification laws. Notify reinsurers and ceding insurers. Investigate Third-Party Service Provider Cybersecurity Events.

Artefacts an auditor will ask for
  • Written Incident Response Plan
  • Cybersecurity Event log
  • 72-hour Commissioner notification record
  • Consumer notification records
  • Reinsurer/cedent notification
  • Third-Party event investigation
  • Post-incident report
Where this commonly fails
  • No written IRP
  • Missed 72-hour notification
  • No consumer notification process
  • Missing third-party event handling

Information Security Program

NAIC-2
Information Security Program (ISP) - Section 4

Develop, implement, and maintain a comprehensive written Information Security Program (ISP) based on the licensees risk assessment that includes administrative, technical, and physical safeguards for protecting Nonpublic Information and the licensees information systems. Scale the ISP commensurate with size + complexity + nature + scope of activities + sensitivity of Nonpublic Information used + handled. Address Section 4(D) requirements covering nine specific controls: access controls + identification + authentication + change management + system monitoring + protective controls + physical security + business continuity + vendor oversight.

Artefacts an auditor will ask for
  • Written Information Security Program document
  • Section 4(D) control mapping (1-9)
  • Annual program review
  • Risk-based scaling justification
  • Program approval by senior official
  • ISP version history
Where this commonly fails
  • No written program
  • Missing Section 4(D) control coverage
  • No risk-based scaling
  • Outdated program

Personnel Security

NAIC-7
Employee Training, Awareness, and Personnel Security - Section 4(D)(7) and 4(E)

Provide cybersecurity awareness training to all personnel as part of the Information Security Program with frequency commensurate with risk + role-based training for personnel with privileged access + escalated training upon material change in risk + training records retention. Conduct background checks on employees with access to Nonpublic Information per state-specific requirements. Implement access provisioning and deprovisioning processes tied to HR lifecycle. Discipline personnel for security violations.

Artefacts an auditor will ask for
  • Annual training completion records
  • Role-based training curricula
  • Background check evidence
  • Access provisioning workflow
  • Deprovisioning records
  • Disciplinary action records
  • Training material approval
Where this commonly fails
  • No awareness training
  • Incomplete completion records
  • No role-based training
  • Missing access lifecycle tied to HR

Risk Assessment

NAIC-3
Risk Assessment and Risk Management - Section 4(B) and 4(C)

Conduct comprehensive risk assessments to identify reasonably foreseeable internal and external threats that could result in unauthorised access to or transmission, disclosure, misuse, alteration, or destruction of Nonpublic Information stored on the licensees information systems. Assess likelihood and potential damage. Reassess sufficiency of safeguards on a regular basis. Document risk treatment decisions including accept + mitigate + transfer + avoid. Update risk register on at least an annual basis or upon material change in operations or threat landscape.

Artefacts an auditor will ask for
  • Annual risk assessment report
  • Threat modelling output
  • Risk register with treatment decisions
  • Risk acceptance documentation
  • Reassessment trigger log
  • Senior official sign-off
Where this commonly fails
  • No documented risk assessment
  • Stale risk register
  • No reassessment cadence
  • Missing senior official sign-off

Third Party Management

NAIC-5
Third Party Service Provider Oversight - Section 4(F)(3) and Section 5

Exercise due diligence in selecting Third-Party Service Providers and require Third-Party Service Providers to implement appropriate administrative, technical, and physical measures to protect and secure the Information Systems and Nonpublic Information that are accessible to or held by Third-Party Service Providers. Conduct periodic assessment of Third-Party Service Providers based on the risk they present and the continued adequacy of their cybersecurity practices. Maintain contractual obligations including SOC 2 Type II reports + audit rights + notification on cybersecurity events + termination rights + return of data.

Artefacts an auditor will ask for
  • Third-Party inventory
  • Due diligence questionnaires
  • Vendor risk classification
  • Contract clauses (security + audit + notification)
  • SOC 2 Type II reports
  • Periodic vendor assessment
  • Termination/exit clauses
Where this commonly fails
  • No vendor inventory
  • Missing due diligence
  • No risk classification
  • No ongoing monitoring
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NAIC Insurance Data Security Model Law (MDL-668) framework page.