Skip to content

Evidence request lists

Solvency II

Evidence request list. 34 controls, 34 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Group Supervision

SOLVENCY-4
Group Supervision and Insurance Group Capital

Per Solvency II group: group supervision. Requirements include (a) Group supervision per Directive + (b) group SCR + own funds + (c) intra-group transactions + (d) college of supervisors + (e) maintain group reporting.

Artefacts an auditor will ask for
  • Solvency II evidence for SOLVENCY-4
Where this commonly fails
  • ORSA + IM + QRT partial

Long Term Guarantee Measures

SII-VA-20
Volatility adjustment and matching adjustment

Undertakings may apply a volatility adjustment to the risk-free rate to mitigate the effect of exaggerated bond spreads, or a matching adjustment for portfolios of long term insurance obligations backed by assigned assets, subject to supervisor approval and disclosure.

Artefacts an auditor will ask for
  • Supervisor approval for matching adjustment
  • Assigned asset portfolio identification and segregation
  • Cash flow matching tests
  • Volatility adjustment impact disclosure in SFCR
  • Annual review of continued eligibility
Where this commonly fails
  • Matching adjustment portfolio breached without immediate notification
  • Asset eligibility criteria not monitored
  • Disclosure of impact without VA or MA omitted

Pillar 1 Quantitative

SOLVENCY-1
Pillar 1 - Quantitative: SCR + MCR + Technical Provisions

Per Solvency II Pillar 1: quantitative. Requirements include (a) Solvency Capital Requirement (SCR) using Standard Formula or approved Internal Model + (b) Minimum Capital Requirement (MCR) floor at 25%-45% of SCR + (c) Technical Provisions at best estimate + risk margin + (d) Own Funds tiering + eligibility + (e) Loss Absorbing Capacity adjustments.

Artefacts an auditor will ask for
  • Solvency II evidence for SOLVENCY-1
Where this commonly fails
  • ORSA + IM + QRT partial

Pillar 2 Governance

SOLVENCY-2
Pillar 2 - Governance, ORSA, Internal Model Governance

Per Solvency II Pillar 2: governance + ORSA. Requirements include (a) System of Governance including Risk Management + Internal Audit + Compliance + Actuarial + (b) Own Risk and Solvency Assessment (ORSA) + (c) Internal Model Governance + (d) Fit and Proper persons + (e) Prudent Person Principle for Investments.

Artefacts an auditor will ask for
  • Solvency II evidence for SOLVENCY-2
Where this commonly fails
  • ORSA + IM + QRT partial

Pillar 2: System of Governance

SII-P2-01
General Governance Requirements

Effective system of governance providing sound and prudent management. Proportionate to nature, scale, and complexity. Clear organizational structure with transparent allocation of responsibilities (Articles 41-42).

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Risk register with treatment plans and owner sign-offs
  • Risk appetite statement approved by the board
  • Periodic risk review reports
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
  • Methodology documentation insufficient to support reproducibility
SII-P2-02
Fit and Proper Requirements

All persons who effectively run the undertaking or hold key functions must be fit (qualifications, knowledge, experience) and proper (good repute, integrity). Ongoing assessment required (Article 42).

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Risk register with treatment plans and owner sign-offs
  • Risk appetite statement approved by the board
  • Periodic risk review reports
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
  • Methodology documentation insufficient to support reproducibility
  • Renewal cycle for fit and proper assessments not consistently followed
SII-P2-03
Risk Management Function

Established risk management system to identify, measure, monitor, manage, and report risks on a continuous basis. Covers underwriting, ALM, investment, liquidity, concentration, operational risk, reinsurance (Article 44).

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Risk register with treatment plans and owner sign-offs
  • Risk appetite statement approved by the board
  • Periodic risk review reports
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
  • Methodology documentation insufficient to support reproducibility
SII-P2-04
Own Risk and Solvency Assessment (ORSA)

Mandatory forward-looking self-assessment of solvency needs linked to risk profile and business strategy. Board must actively participate. Performed regularly and after significant changes (Article 45).

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Risk register with treatment plans and owner sign-offs
  • Risk appetite statement approved by the board
  • Periodic risk review reports
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
  • Methodology documentation insufficient to support reproducibility
SII-P2-05
Internal Control System

Adequate internal control system including administrative and accounting procedures, internal control framework, and appropriate reporting arrangements (Article 46).

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Risk register with treatment plans and owner sign-offs
  • Risk appetite statement approved by the board
  • Periodic risk review reports
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
  • Methodology documentation insufficient to support reproducibility
SII-P2-06
Compliance Function

Advisory function on compliance with laws, regulations, and administrative provisions. Assess impact of changes in the legal environment and identify compliance risk (Article 46).

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Risk register with treatment plans and owner sign-offs
  • Risk appetite statement approved by the board
  • Periodic risk review reports
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
  • Methodology documentation insufficient to support reproducibility
SII-P2-07
Internal Audit Function

Evaluate adequacy and effectiveness of the internal control system and other governance elements. Must be objective and independent from operational functions. Reports directly to the board (Article 47).

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Risk register with treatment plans and owner sign-offs
  • Risk appetite statement approved by the board
  • Periodic risk review reports
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • Internal audit coverage skews to financial controls rather than full scope
  • Log retention periods inconsistent across systems
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
SII-P2-08
Actuarial Function

Coordinate calculation of technical provisions, ensure appropriateness of methodologies and models, assess data sufficiency, inform the board on reliability of technical provisions (Article 48).

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Risk register with treatment plans and owner sign-offs
  • Risk appetite statement approved by the board
  • Periodic risk review reports
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
  • Methodology documentation insufficient to support reproducibility
SII-P2-09
Outsourcing Requirements

Outsourcing must not compromise quality of governance. Undertaking remains fully responsible. Critical functions require prior supervisory notification, written agreements, due diligence, exit plans (Article 49).

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Risk register with treatment plans and owner sign-offs
  • Risk appetite statement approved by the board
  • Periodic risk review reports
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • Vendor risk assessments not refreshed at the required cadence
  • Subcontractor flow-down clauses absent or weak in contracts
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
SII-P2-10
Supervisory Review Process

Supervisors review compliance, assess governance, evaluate risks, apply capital add-ons where the risk profile deviates significantly from SCR assumptions (Articles 36-38).

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Risk register with treatment plans and owner sign-offs
  • Risk appetite statement approved by the board
  • Periodic risk review reports
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
  • Methodology documentation insufficient to support reproducibility
SII-P2-11
Remuneration Policy

Remuneration policies consistent with sound risk management. Must not encourage risk-taking that exceeds risk tolerance (Article 41).

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Risk register with treatment plans and owner sign-offs
  • Risk appetite statement approved by the board
  • Periodic risk review reports
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
  • Methodology documentation insufficient to support reproducibility
  • Renewal cycle for fit and proper assessments not consistently followed
SII-P2-12
Written Policies

Written policies at minimum on: risk management, internal control, internal audit, outsourcing, remuneration, and continuity. Reviewed at least annually (Article 41).

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Risk register with treatment plans and owner sign-offs
  • Risk appetite statement approved by the board
  • Periodic risk review reports
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
  • Methodology documentation insufficient to support reproducibility
SII-P2-ACT-10
Actuarial function

The actuarial function shall coordinate the calculation of technical provisions, assess the sufficiency and quality of data, compare best estimates against experience, and express an opinion on underwriting policy and reinsurance arrangements.

Artefacts an auditor will ask for
  • Annual actuarial function report
  • Data quality assessment documentation
  • Back testing of best estimate vs actuals
  • Opinion on underwriting and reinsurance adequacy
  • Methodology and assumptions sign-off log
Where this commonly fails
  • Data quality dimensions not all assessed
  • Opinion on reinsurance limited to financial reinsurance
  • Experience analysis not linked to assumption changes
SII-P2-CMP-08
Compliance function

The compliance function shall advise the administrative body on compliance with laws and regulations, assess the possible impact of any changes in the legal environment, and identify and assess compliance risk.

Artefacts an auditor will ask for
  • Compliance policy and annual compliance plan
  • Regulatory horizon scanning log
  • Compliance breach register with remediation status
  • Compliance function reports to board
  • Training records for staff on regulatory obligations
Where this commonly fails
  • Compliance risk assessment not documented
  • Cross border activities not mapped to local rules
  • Breach root cause analysis superficial
SII-P2-FIT-12
Fit and proper requirements

Persons who effectively run the undertaking or hold key functions shall at all times possess adequate professional qualifications, knowledge and experience, and be of good repute and integrity.

Artefacts an auditor will ask for
  • Fit and proper policy
  • Initial and ongoing assessment files per individual
  • Criminal record and financial soundness checks
  • Continuing professional development records
  • Notifications to supervisor of appointments and departures
Where this commonly fails
  • Reassessment triggers not defined
  • Collective board competence not assessed
  • Foreign criminal record checks omitted
SII-P2-IA-09
Internal audit function

Internal audit shall evaluate the adequacy and effectiveness of the internal control system and other elements of the system of governance, operating in an objective and independent manner from operational functions.

Artefacts an auditor will ask for
  • Internal audit charter approved by board
  • Risk-based audit plan covering three to five year cycle
  • Audit reports with findings and management responses
  • Quality assurance and improvement programme
  • Internal audit function reporting line to board or audit committee
Where this commonly fails
  • Audit universe missing key functions
  • Findings remediation tracking weak
  • External quality assessment overdue
SII-P2-OUT-11
Outsourcing of critical functions

Undertakings remain fully responsible for outsourced functions and shall notify supervisors in a timely manner prior to outsourcing critical or important operational functions, with written agreements specifying rights of access and audit.

Artefacts an auditor will ask for
  • Outsourcing policy
  • Register of all outsourced critical or important functions
  • Due diligence files per provider
  • Outsourcing contracts with audit, exit, and SLA clauses
  • Pre-outsourcing supervisor notifications
Where this commonly fails
  • Intragroup outsourcing treated as exempt
  • Cloud provider concentration not assessed
  • Exit plans not tested
  • Sub-outsourcing not tracked
SII-P2-SYS-06
System of governance

Undertakings shall implement an effective system of governance providing for sound and prudent management, including transparent organisational structure, segregation of responsibilities, written policies, and four key functions covering risk management, compliance, internal audit, and actuarial.

Artefacts an auditor will ask for
  • Organisational chart with reporting lines for four key functions
  • Written policies on risk management, internal control, audit, outsourcing, fit and proper
  • Key function holder appointment letters
  • Fit and proper assessments for board and key function holders
  • Annual review minutes of governance system effectiveness
Where this commonly fails
  • Combined functions without documented independence safeguards
  • Fit and proper reassessments overdue
  • Policies not reviewed annually
  • Outsourcing register incomplete

Pillar 3 Reporting

SOLVENCY-3
Pillar 3 - Reporting and Disclosure (SFCR + RSR + QRT)

Per Solvency II Pillar 3: reporting. Requirements include (a) Solvency and Financial Condition Report (SFCR) public disclosure + (b) Regular Supervisory Report (RSR) + (c) Quantitative Reporting Templates (QRT) + (d) integration with IFRS 17 + (e) align with EIOPA.

Artefacts an auditor will ask for
  • Solvency II evidence for SOLVENCY-3
Where this commonly fails
  • ORSA + IM + QRT partial

Pillar 3: Reporting and Disclosure

SII-P3-01
Solvency and Financial Condition Report (SFCR)

Public annual disclosure with five sections: A. Business and Performance, B. System of Governance, C. Risk Profile, D. Valuation for Solvency Purposes, E. Capital Management. Published on the undertaking's website (Articles 51-56).

Artefacts an auditor will ask for
  • Published disclosure documents with version history
  • Regulatory submission records and acknowledgements
  • Internal review and sign-off workflow evidence
  • ORSA report with stress and scenario analyses
  • Actuarial function activity report and opinions
  • Capital adequacy calculation working papers
Where this commonly fails
  • Report content inconsistent with internal management information
  • Submission timelines met but evidence trail not retained
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
  • Methodology documentation insufficient to support reproducibility
SII-P3-02
Regular Supervisory Report (RSR)

Confidential report to the supervisor. Submitted in full at least every three years, summary form annually. Covers same five areas as SFCR with more granular detail (Article 35).

Artefacts an auditor will ask for
  • Internal audit charter and annual audit plan
  • Audit working papers and finding registers
  • Supervisory correspondence and response logs
  • Published disclosure documents with version history
  • Regulatory submission records and acknowledgements
  • Internal review and sign-off workflow evidence
Where this commonly fails
  • Report content inconsistent with internal management information
  • Submission timelines met but evidence trail not retained
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
  • Methodology documentation insufficient to support reproducibility
SII-P3-03
Quantitative Reporting Templates (QRTs) - Annual

Standardized annual templates covering balance sheet, own funds, SCR, MCR, technical provisions, assets, reinsurance. Submitted in XBRL format. Due 16 weeks after year-end.

Artefacts an auditor will ask for
  • Published disclosure documents with version history
  • Regulatory submission records and acknowledgements
  • Internal review and sign-off workflow evidence
  • ORSA report with stress and scenario analyses
  • Actuarial function activity report and opinions
  • Capital adequacy calculation working papers
Where this commonly fails
  • Report content inconsistent with internal management information
  • Submission timelines met but evidence trail not retained
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
  • Methodology documentation insufficient to support reproducibility
SII-P3-04
Quantitative Reporting Templates (QRTs) - Quarterly

Subset of quarterly templates covering key financial and solvency data. More limited scope than annual QRTs.

Artefacts an auditor will ask for
  • Published disclosure documents with version history
  • Regulatory submission records and acknowledgements
  • Internal review and sign-off workflow evidence
  • ORSA report with stress and scenario analyses
  • Actuarial function activity report and opinions
  • Capital adequacy calculation working papers
Where this commonly fails
  • Report content inconsistent with internal management information
  • Submission timelines met but evidence trail not retained
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
  • Methodology documentation insufficient to support reproducibility
SII-P3-05
SFCR Section A: Business and Performance

Description of business, underwriting performance, investment performance, and performance of other activities. Material transactions with shareholders and group entities.

Artefacts an auditor will ask for
  • Published disclosure documents with version history
  • Regulatory submission records and acknowledgements
  • Internal review and sign-off workflow evidence
  • ORSA report with stress and scenario analyses
  • Actuarial function activity report and opinions
  • Capital adequacy calculation working papers
Where this commonly fails
  • Report content inconsistent with internal management information
  • Submission timelines met but evidence trail not retained
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
  • Methodology documentation insufficient to support reproducibility
  • Ground segment cyber controls trail enterprise IT maturity
SII-P3-06
SFCR Section B: System of Governance

Description of governance structure, fit and proper requirements, risk management system including ORSA, internal control system, internal audit, actuarial function, outsourcing policy.

Artefacts an auditor will ask for
  • Approved governance policy with documented scope and accountabilities
  • Board or steering committee minutes evidencing oversight
  • Roles and responsibilities matrix (RACI)
  • Published disclosure documents with version history
  • Regulatory submission records and acknowledgements
  • Internal review and sign-off workflow evidence
Where this commonly fails
  • Policy document exists but lacks evidence of board approval or refresh cycle
  • Accountabilities defined on paper but not reflected in performance objectives
  • Report content inconsistent with internal management information
  • Submission timelines met but evidence trail not retained
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
SII-P3-07
SFCR Section C: Risk Profile

Description of each risk category, risk exposure, concentration, mitigation, and sensitivity analysis. Stress testing and scenario results.

Artefacts an auditor will ask for
  • Published disclosure documents with version history
  • Regulatory submission records and acknowledgements
  • Internal review and sign-off workflow evidence
  • ORSA report with stress and scenario analyses
  • Actuarial function activity report and opinions
  • Capital adequacy calculation working papers
Where this commonly fails
  • Report content inconsistent with internal management information
  • Submission timelines met but evidence trail not retained
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
  • Methodology documentation insufficient to support reproducibility
SII-P3-08
SFCR Section D: Valuation for Solvency Purposes

Bases, methods, and main assumptions for valuation of assets, technical provisions, and other liabilities. Material differences from financial statement valuations.

Artefacts an auditor will ask for
  • Published disclosure documents with version history
  • Regulatory submission records and acknowledgements
  • Internal review and sign-off workflow evidence
  • ORSA report with stress and scenario analyses
  • Actuarial function activity report and opinions
  • Capital adequacy calculation working papers
Where this commonly fails
  • Report content inconsistent with internal management information
  • Submission timelines met but evidence trail not retained
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
  • Methodology documentation insufficient to support reproducibility
SII-P3-09
SFCR Section E: Capital Management

Own funds structure by tier, amounts, quality. SCR and MCR amounts. Use of duration-based equity risk sub-module or simplified calculations.

Artefacts an auditor will ask for
  • Published disclosure documents with version history
  • Regulatory submission records and acknowledgements
  • Internal review and sign-off workflow evidence
  • ORSA report with stress and scenario analyses
  • Actuarial function activity report and opinions
  • Capital adequacy calculation working papers
Where this commonly fails
  • Report content inconsistent with internal management information
  • Submission timelines met but evidence trail not retained
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
  • Methodology documentation insufficient to support reproducibility
SII-P3-10
Group Reporting

Groups must produce group SFCR and group QRTs. Due 22 weeks after year-end. Consolidation methodology, intragroup transactions, and group SCR calculation.

Artefacts an auditor will ask for
  • Published disclosure documents with version history
  • Regulatory submission records and acknowledgements
  • Internal review and sign-off workflow evidence
  • ORSA report with stress and scenario analyses
  • Actuarial function activity report and opinions
  • Capital adequacy calculation working papers
Where this commonly fails
  • Report content inconsistent with internal management information
  • Submission timelines met but evidence trail not retained
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
  • Methodology documentation insufficient to support reproducibility
SII-P3-11
Audit Requirements

The SFCR must be subject to an auditor opinion. Auditors verify consistency between the SFCR and the undertaking's financial statements and regulatory returns.

Artefacts an auditor will ask for
  • Internal audit charter and annual audit plan
  • Audit working papers and finding registers
  • Supervisory correspondence and response logs
  • Published disclosure documents with version history
  • Regulatory submission records and acknowledgements
  • Internal review and sign-off workflow evidence
Where this commonly fails
  • Internal audit coverage skews to financial controls rather than full scope
  • Log retention periods inconsistent across systems
  • Report content inconsistent with internal management information
  • Submission timelines met but evidence trail not retained
  • Stress scenarios narrow and not reverse-engineered from board risk appetite
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Solvency II framework page.