Solvency II
Evidence request list. 34 controls, 34 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Group Supervision
Per Solvency II group: group supervision. Requirements include (a) Group supervision per Directive + (b) group SCR + own funds + (c) intra-group transactions + (d) college of supervisors + (e) maintain group reporting.
- Solvency II evidence for SOLVENCY-4
- ORSA + IM + QRT partial
Long Term Guarantee Measures
Undertakings may apply a volatility adjustment to the risk-free rate to mitigate the effect of exaggerated bond spreads, or a matching adjustment for portfolios of long term insurance obligations backed by assigned assets, subject to supervisor approval and disclosure.
- Supervisor approval for matching adjustment
- Assigned asset portfolio identification and segregation
- Cash flow matching tests
- Volatility adjustment impact disclosure in SFCR
- Annual review of continued eligibility
- Matching adjustment portfolio breached without immediate notification
- Asset eligibility criteria not monitored
- Disclosure of impact without VA or MA omitted
Pillar 1 Quantitative
Per Solvency II Pillar 1: quantitative. Requirements include (a) Solvency Capital Requirement (SCR) using Standard Formula or approved Internal Model + (b) Minimum Capital Requirement (MCR) floor at 25%-45% of SCR + (c) Technical Provisions at best estimate + risk margin + (d) Own Funds tiering + eligibility + (e) Loss Absorbing Capacity adjustments.
- Solvency II evidence for SOLVENCY-1
- ORSA + IM + QRT partial
Pillar 2 Governance
Per Solvency II Pillar 2: governance + ORSA. Requirements include (a) System of Governance including Risk Management + Internal Audit + Compliance + Actuarial + (b) Own Risk and Solvency Assessment (ORSA) + (c) Internal Model Governance + (d) Fit and Proper persons + (e) Prudent Person Principle for Investments.
- Solvency II evidence for SOLVENCY-2
- ORSA + IM + QRT partial
Pillar 2: System of Governance
Effective system of governance providing sound and prudent management. Proportionate to nature, scale, and complexity. Clear organizational structure with transparent allocation of responsibilities (Articles 41-42).
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Risk register with treatment plans and owner sign-offs
- Risk appetite statement approved by the board
- Periodic risk review reports
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- Stress scenarios narrow and not reverse-engineered from board risk appetite
- Methodology documentation insufficient to support reproducibility
All persons who effectively run the undertaking or hold key functions must be fit (qualifications, knowledge, experience) and proper (good repute, integrity). Ongoing assessment required (Article 42).
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Risk register with treatment plans and owner sign-offs
- Risk appetite statement approved by the board
- Periodic risk review reports
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- Stress scenarios narrow and not reverse-engineered from board risk appetite
- Methodology documentation insufficient to support reproducibility
- Renewal cycle for fit and proper assessments not consistently followed
Established risk management system to identify, measure, monitor, manage, and report risks on a continuous basis. Covers underwriting, ALM, investment, liquidity, concentration, operational risk, reinsurance (Article 44).
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Risk register with treatment plans and owner sign-offs
- Risk appetite statement approved by the board
- Periodic risk review reports
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- Stress scenarios narrow and not reverse-engineered from board risk appetite
- Methodology documentation insufficient to support reproducibility
Mandatory forward-looking self-assessment of solvency needs linked to risk profile and business strategy. Board must actively participate. Performed regularly and after significant changes (Article 45).
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Risk register with treatment plans and owner sign-offs
- Risk appetite statement approved by the board
- Periodic risk review reports
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- Stress scenarios narrow and not reverse-engineered from board risk appetite
- Methodology documentation insufficient to support reproducibility
Adequate internal control system including administrative and accounting procedures, internal control framework, and appropriate reporting arrangements (Article 46).
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Risk register with treatment plans and owner sign-offs
- Risk appetite statement approved by the board
- Periodic risk review reports
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- Stress scenarios narrow and not reverse-engineered from board risk appetite
- Methodology documentation insufficient to support reproducibility
Advisory function on compliance with laws, regulations, and administrative provisions. Assess impact of changes in the legal environment and identify compliance risk (Article 46).
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Risk register with treatment plans and owner sign-offs
- Risk appetite statement approved by the board
- Periodic risk review reports
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- Stress scenarios narrow and not reverse-engineered from board risk appetite
- Methodology documentation insufficient to support reproducibility
Evaluate adequacy and effectiveness of the internal control system and other governance elements. Must be objective and independent from operational functions. Reports directly to the board (Article 47).
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Risk register with treatment plans and owner sign-offs
- Risk appetite statement approved by the board
- Periodic risk review reports
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- Internal audit coverage skews to financial controls rather than full scope
- Log retention periods inconsistent across systems
- Stress scenarios narrow and not reverse-engineered from board risk appetite
Coordinate calculation of technical provisions, ensure appropriateness of methodologies and models, assess data sufficiency, inform the board on reliability of technical provisions (Article 48).
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Risk register with treatment plans and owner sign-offs
- Risk appetite statement approved by the board
- Periodic risk review reports
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- Stress scenarios narrow and not reverse-engineered from board risk appetite
- Methodology documentation insufficient to support reproducibility
Outsourcing must not compromise quality of governance. Undertaking remains fully responsible. Critical functions require prior supervisory notification, written agreements, due diligence, exit plans (Article 49).
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Risk register with treatment plans and owner sign-offs
- Risk appetite statement approved by the board
- Periodic risk review reports
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- Vendor risk assessments not refreshed at the required cadence
- Subcontractor flow-down clauses absent or weak in contracts
- Stress scenarios narrow and not reverse-engineered from board risk appetite
Supervisors review compliance, assess governance, evaluate risks, apply capital add-ons where the risk profile deviates significantly from SCR assumptions (Articles 36-38).
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Risk register with treatment plans and owner sign-offs
- Risk appetite statement approved by the board
- Periodic risk review reports
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- Stress scenarios narrow and not reverse-engineered from board risk appetite
- Methodology documentation insufficient to support reproducibility
Remuneration policies consistent with sound risk management. Must not encourage risk-taking that exceeds risk tolerance (Article 41).
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Risk register with treatment plans and owner sign-offs
- Risk appetite statement approved by the board
- Periodic risk review reports
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- Stress scenarios narrow and not reverse-engineered from board risk appetite
- Methodology documentation insufficient to support reproducibility
- Renewal cycle for fit and proper assessments not consistently followed
Written policies at minimum on: risk management, internal control, internal audit, outsourcing, remuneration, and continuity. Reviewed at least annually (Article 41).
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Risk register with treatment plans and owner sign-offs
- Risk appetite statement approved by the board
- Periodic risk review reports
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- Stress scenarios narrow and not reverse-engineered from board risk appetite
- Methodology documentation insufficient to support reproducibility
The actuarial function shall coordinate the calculation of technical provisions, assess the sufficiency and quality of data, compare best estimates against experience, and express an opinion on underwriting policy and reinsurance arrangements.
- Annual actuarial function report
- Data quality assessment documentation
- Back testing of best estimate vs actuals
- Opinion on underwriting and reinsurance adequacy
- Methodology and assumptions sign-off log
- Data quality dimensions not all assessed
- Opinion on reinsurance limited to financial reinsurance
- Experience analysis not linked to assumption changes
The compliance function shall advise the administrative body on compliance with laws and regulations, assess the possible impact of any changes in the legal environment, and identify and assess compliance risk.
- Compliance policy and annual compliance plan
- Regulatory horizon scanning log
- Compliance breach register with remediation status
- Compliance function reports to board
- Training records for staff on regulatory obligations
- Compliance risk assessment not documented
- Cross border activities not mapped to local rules
- Breach root cause analysis superficial
Persons who effectively run the undertaking or hold key functions shall at all times possess adequate professional qualifications, knowledge and experience, and be of good repute and integrity.
- Fit and proper policy
- Initial and ongoing assessment files per individual
- Criminal record and financial soundness checks
- Continuing professional development records
- Notifications to supervisor of appointments and departures
- Reassessment triggers not defined
- Collective board competence not assessed
- Foreign criminal record checks omitted
Internal audit shall evaluate the adequacy and effectiveness of the internal control system and other elements of the system of governance, operating in an objective and independent manner from operational functions.
- Internal audit charter approved by board
- Risk-based audit plan covering three to five year cycle
- Audit reports with findings and management responses
- Quality assurance and improvement programme
- Internal audit function reporting line to board or audit committee
- Audit universe missing key functions
- Findings remediation tracking weak
- External quality assessment overdue
Undertakings remain fully responsible for outsourced functions and shall notify supervisors in a timely manner prior to outsourcing critical or important operational functions, with written agreements specifying rights of access and audit.
- Outsourcing policy
- Register of all outsourced critical or important functions
- Due diligence files per provider
- Outsourcing contracts with audit, exit, and SLA clauses
- Pre-outsourcing supervisor notifications
- Intragroup outsourcing treated as exempt
- Cloud provider concentration not assessed
- Exit plans not tested
- Sub-outsourcing not tracked
Undertakings shall implement an effective system of governance providing for sound and prudent management, including transparent organisational structure, segregation of responsibilities, written policies, and four key functions covering risk management, compliance, internal audit, and actuarial.
- Organisational chart with reporting lines for four key functions
- Written policies on risk management, internal control, audit, outsourcing, fit and proper
- Key function holder appointment letters
- Fit and proper assessments for board and key function holders
- Annual review minutes of governance system effectiveness
- Combined functions without documented independence safeguards
- Fit and proper reassessments overdue
- Policies not reviewed annually
- Outsourcing register incomplete
Pillar 3 Reporting
Per Solvency II Pillar 3: reporting. Requirements include (a) Solvency and Financial Condition Report (SFCR) public disclosure + (b) Regular Supervisory Report (RSR) + (c) Quantitative Reporting Templates (QRT) + (d) integration with IFRS 17 + (e) align with EIOPA.
- Solvency II evidence for SOLVENCY-3
- ORSA + IM + QRT partial
Pillar 3: Reporting and Disclosure
Public annual disclosure with five sections: A. Business and Performance, B. System of Governance, C. Risk Profile, D. Valuation for Solvency Purposes, E. Capital Management. Published on the undertaking's website (Articles 51-56).
- Published disclosure documents with version history
- Regulatory submission records and acknowledgements
- Internal review and sign-off workflow evidence
- ORSA report with stress and scenario analyses
- Actuarial function activity report and opinions
- Capital adequacy calculation working papers
- Report content inconsistent with internal management information
- Submission timelines met but evidence trail not retained
- Stress scenarios narrow and not reverse-engineered from board risk appetite
- Methodology documentation insufficient to support reproducibility
Confidential report to the supervisor. Submitted in full at least every three years, summary form annually. Covers same five areas as SFCR with more granular detail (Article 35).
- Internal audit charter and annual audit plan
- Audit working papers and finding registers
- Supervisory correspondence and response logs
- Published disclosure documents with version history
- Regulatory submission records and acknowledgements
- Internal review and sign-off workflow evidence
- Report content inconsistent with internal management information
- Submission timelines met but evidence trail not retained
- Stress scenarios narrow and not reverse-engineered from board risk appetite
- Methodology documentation insufficient to support reproducibility
Standardized annual templates covering balance sheet, own funds, SCR, MCR, technical provisions, assets, reinsurance. Submitted in XBRL format. Due 16 weeks after year-end.
- Published disclosure documents with version history
- Regulatory submission records and acknowledgements
- Internal review and sign-off workflow evidence
- ORSA report with stress and scenario analyses
- Actuarial function activity report and opinions
- Capital adequacy calculation working papers
- Report content inconsistent with internal management information
- Submission timelines met but evidence trail not retained
- Stress scenarios narrow and not reverse-engineered from board risk appetite
- Methodology documentation insufficient to support reproducibility
Subset of quarterly templates covering key financial and solvency data. More limited scope than annual QRTs.
- Published disclosure documents with version history
- Regulatory submission records and acknowledgements
- Internal review and sign-off workflow evidence
- ORSA report with stress and scenario analyses
- Actuarial function activity report and opinions
- Capital adequacy calculation working papers
- Report content inconsistent with internal management information
- Submission timelines met but evidence trail not retained
- Stress scenarios narrow and not reverse-engineered from board risk appetite
- Methodology documentation insufficient to support reproducibility
Description of business, underwriting performance, investment performance, and performance of other activities. Material transactions with shareholders and group entities.
- Published disclosure documents with version history
- Regulatory submission records and acknowledgements
- Internal review and sign-off workflow evidence
- ORSA report with stress and scenario analyses
- Actuarial function activity report and opinions
- Capital adequacy calculation working papers
- Report content inconsistent with internal management information
- Submission timelines met but evidence trail not retained
- Stress scenarios narrow and not reverse-engineered from board risk appetite
- Methodology documentation insufficient to support reproducibility
- Ground segment cyber controls trail enterprise IT maturity
Description of governance structure, fit and proper requirements, risk management system including ORSA, internal control system, internal audit, actuarial function, outsourcing policy.
- Approved governance policy with documented scope and accountabilities
- Board or steering committee minutes evidencing oversight
- Roles and responsibilities matrix (RACI)
- Published disclosure documents with version history
- Regulatory submission records and acknowledgements
- Internal review and sign-off workflow evidence
- Policy document exists but lacks evidence of board approval or refresh cycle
- Accountabilities defined on paper but not reflected in performance objectives
- Report content inconsistent with internal management information
- Submission timelines met but evidence trail not retained
- Stress scenarios narrow and not reverse-engineered from board risk appetite
Description of each risk category, risk exposure, concentration, mitigation, and sensitivity analysis. Stress testing and scenario results.
- Published disclosure documents with version history
- Regulatory submission records and acknowledgements
- Internal review and sign-off workflow evidence
- ORSA report with stress and scenario analyses
- Actuarial function activity report and opinions
- Capital adequacy calculation working papers
- Report content inconsistent with internal management information
- Submission timelines met but evidence trail not retained
- Stress scenarios narrow and not reverse-engineered from board risk appetite
- Methodology documentation insufficient to support reproducibility
Bases, methods, and main assumptions for valuation of assets, technical provisions, and other liabilities. Material differences from financial statement valuations.
- Published disclosure documents with version history
- Regulatory submission records and acknowledgements
- Internal review and sign-off workflow evidence
- ORSA report with stress and scenario analyses
- Actuarial function activity report and opinions
- Capital adequacy calculation working papers
- Report content inconsistent with internal management information
- Submission timelines met but evidence trail not retained
- Stress scenarios narrow and not reverse-engineered from board risk appetite
- Methodology documentation insufficient to support reproducibility
Own funds structure by tier, amounts, quality. SCR and MCR amounts. Use of duration-based equity risk sub-module or simplified calculations.
- Published disclosure documents with version history
- Regulatory submission records and acknowledgements
- Internal review and sign-off workflow evidence
- ORSA report with stress and scenario analyses
- Actuarial function activity report and opinions
- Capital adequacy calculation working papers
- Report content inconsistent with internal management information
- Submission timelines met but evidence trail not retained
- Stress scenarios narrow and not reverse-engineered from board risk appetite
- Methodology documentation insufficient to support reproducibility
Groups must produce group SFCR and group QRTs. Due 22 weeks after year-end. Consolidation methodology, intragroup transactions, and group SCR calculation.
- Published disclosure documents with version history
- Regulatory submission records and acknowledgements
- Internal review and sign-off workflow evidence
- ORSA report with stress and scenario analyses
- Actuarial function activity report and opinions
- Capital adequacy calculation working papers
- Report content inconsistent with internal management information
- Submission timelines met but evidence trail not retained
- Stress scenarios narrow and not reverse-engineered from board risk appetite
- Methodology documentation insufficient to support reproducibility
The SFCR must be subject to an auditor opinion. Auditors verify consistency between the SFCR and the undertaking's financial statements and regulatory returns.
- Internal audit charter and annual audit plan
- Audit working papers and finding registers
- Supervisory correspondence and response logs
- Published disclosure documents with version history
- Regulatory submission records and acknowledgements
- Internal review and sign-off workflow evidence
- Internal audit coverage skews to financial controls rather than full scope
- Log retention periods inconsistent across systems
- Report content inconsistent with internal management information
- Submission timelines met but evidence trail not retained
- Stress scenarios narrow and not reverse-engineered from board risk appetite
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Solvency II framework page.