No. 32674 (New Rule): R590-254. Annual Financial Reporting Rule  

  • DAR File No.: 32674
    Filed: 05/14/2009, 05:48
    Received by: NL

    RULE ANALYSIS

    Purpose of the rule or reason for the change:

    The purpose of this rule is to improve the commissioner's surveillance of the financial condition of insurers by requiring the submission of certain reports and documents.

    Summary of the rule or change:

    This rule sets requirements for: the filing and filing extension of an insurer's annual audited financial report and the contents of that report; for designated CPAs used by an insurer to prepare these reports; for the filing of a consolidated or combined audits; also sets the scope of the CPA's audit and report; sets requirements of the notification of adverse financial condition found in the insurer being audited; guidelines for the reporting of internal control related matters to the department; what is to be included in the accountants letter of qualification given to the insurer in an audit; requirements for the maintaining of the CPA's workpapers; the requirements of the audit committee; sets the standard of conduct of the insurer in the course of the audit; guidelines for the filing and contents of the report of internal controls over financial reporting that management of the insurer makes to the department; exemptions to this rule that the commissioner is allowed to make; and penalties for violations to this rule and related laws.

    State statutory or constitutional authorization for this rule:

    Sections 31A-2-201, 31A-2-203, and 31A-5-412

    Anticipated cost or savings to:

    the state budget:

    There will be no fiscal impact on the department or the state's budget as a result of this rule. Insurers will be required to file some reports with the department but these can be handled by existing staff. There will also be no change to the department's revenues.

    local governments:

    This rule will have no fiscal impact on local governments since it deals with the relationship between the department and its licensed insurers.

    small businesses and persons other than businesses:

    Small employer insurers will be exempted out of most of this rule. Some may be required to change the make-up of their board but this should not incur a cost to them.

    Compliance costs for affected persons:

    There could be some cost to larger insurers to do the report of internal controls, especially if weaknesses are found that will need to be corrected. And there may be a cost that comes with the requirement to rotate their external auditor every five years. Insurers with more than $500,000,000 in premium will have to have a management opinion done, which if subcontracted out would incur a cost to the insurer. So far only two to three insurers meet this requirement now. The estimated cost to have this done could be between $50,000 to $100,000, at least in the first year. This rule has been sent to the insurers with their main offices in Utah and none responded negatively to it. It is likely that any costs incurred by the insurers as a result of this rule will not be passed onto the consumer so that the insurers can remain competitive.

    Comments by the department head on the fiscal impact the rule may have on businesses:

    This rule follows the National Association of Insurance Commissioner Model regulation that was developed in numerous meetings consisting of state regulators and insurance industry representative. It has been presented again to insurers that have main offices in Utah. No complaints were heard. It is possible that the larger insurers could possibly incur a cost of $50,000 to $100,000 the first year to comply with this rule. D. Kent Michie, Commissioner

    The full text of this rule may be inspected, during regular business hours, at the Division of Administrative Rules, or at:

    Insurance
    Administration
    Room 3110 STATE OFFICE BLDG
    450 N MAIN ST
    SALT LAKE CITY UT 84114-1201

    Direct questions regarding this rule to:

    Jilene Whitby at the above address, by phone at 801-538-3803, by FAX at 801-538-3829, or by Internet E-mail at jwhitby@utah.gov

    Interested persons may present their views on this rule by submitting written comments to the address above no later than 5:00 p.m. on:

    07/01/2009

    Interested persons may attend a public hearing regarding this rule:

    6/23/2009 at 9:00 AM, State Office Building, behind the Capitol, Room 3112, Salt Lake City, UT 84114

    This rule may become effective on:

    07/08/2009

    Authorized by:

    Jilene Whitby, Information Specialist

    RULE TEXT

    R590. Insurance, Administration.

    R590-254. Annual Financial Reporting Rule.

    R590-254-1. Authority.

    This rule is promulgated by the Insurance Commissioner pursuant to Utah Insurance Code Sections:

    (1) 31A-2-201, which authorizes the commissioner to make rules to implement the provisions of Title 31A; and

    (2) 31A-2-203(6)(b)(ii)and 31A-5-412(2)(f), which authorize the commissioner to make rules pertaining to annual financial reporting requirements.

     

    R590-254-2. Purpose and Scope.

    (1) The purpose of this rule is to improve the commissioner's surveillance of the financial condition of insurers by requiring the submission of the following reports and documents:

    (a) an annual audit of financial statements reporting the financial position and the results of operations of insurers by independent certified public accountants,

    (b) communication of internal control related matters noted in an audit; and

    (c) management's Report of Internal Control over Financial Reporting.

    (2) This rule applies to every insurer, as defined in R590-254-3.

    (3) An insurer shall be exempt from this rule for the calendar year if an insurer:

    (a) has direct written premium of less than $1,000,000 written in this state in any calendar year; and

    (b) less than 1,000 policyholders or certificate holders of direct written policies nationwide at the end of the calendar year.

    (4) The exemption under R590-254-2(3)(a) and (b) shall apply unless:

    (a) the commissioner makes a specific finding that compliance is necessary for the commissioner to carry out statutory responsibilities; or

    (b) the insurer has assumed premiums pursuant to contracts and treaties, or both, of reinsurance of $1,000,000 or more.

    (5) A foreign or alien insurer filing an audited financial report in another state, pursuant to that state's requirement for filing of audited financial reports, which has been found by the commissioner to be substantially similar to the requirements in this rule, is exempt from R590-254 Sections 4 through 13 if:

    (a) a copy of the audited financial report, Communication of Internal Control Related Matters Noted in an Audit, and the Accountant's Letter of Qualifications that are filed with the other state are filed with the commissioner in accordance with the filing dates specified in R590-254 Sections 4, 11 and 12, respectively; or

    (b) a Canadian insurer may submit accountants' reports as filed with the Office of the Superintendent of Financial Institutions, Canada; and

    (c) a copy of any Notification of Adverse Financial Condition Report filed with the other state is filed with the commissioner within the time specified in R590-254-10.

    (6) A foreign or alien insurer required to file a Management's Report of Internal Control over Financial Reporting in another state is exempt from filing the Report in this state provided the other state has:

    (a) substantially similar reporting requirements; and

    (b) the report is filed with the commissioner of the other state within the time specified.

    (7) This rule shall not prohibit, preclude or in any way limit the commissioner from ordering or conducting or performing examinations of insurers under the rules, practices and procedures of the department.

     

    R590-254-3. Definitions.

    The terms and definitions contained in this rule are intended to provide definitional guidance as the terms are used within this rule. In addition to the definitions in Sections 31A-1-301, the following definitions shall apply for the purpose of this rule:

    (1) "Accountant" or "independent certified public accountant" means an independent certified public accountant or accounting firm in good standing:

    (a) with the American Institute of Certified Public Accountants (AICPA); and

    (b) in all states in which he or she is licensed to practice;

    (c) for Canadian and British companies, it means a Canadian-chartered or British-chartered accountant.

    (2) An "affiliate" of, or person "affiliated" with, a specific person, is a person that directly, or indirectly through one or more intermediaries, controls, or is controlled by, or is under common control with, the person specified.

    (3) "Audit committee" means a committee, or equivalent body, established by the board of directors of an entity for the purpose of overseeing the accounting and financial reporting processes of an insurer or group of insurers, and audits of financial statements of the insurer or group of insurers.

    (a) The audit committee of any entity that controls a group of insurers may be deemed to be the audit committee for one or more of these controlled insurers solely for the purposes of this rule at the election of the controlling person pursuant to R590-254-14(6).

    (b) If an audit committee is not designated by the insurer, the insurer's entire board of directors shall constitute the audit committee.

    (4) "Audited financial report" means and includes those items specified in R590-254-5.

    (5) "Indemnification" means an agreement of indemnity or a release from liability where the intent or effect is to shift or limit in any manner the potential liability of the person or firm for failure to adhere to applicable auditing or professional standards, whether or not resulting in part from knowing of other misrepresentations made by the insurer or its representatives.

    (6) "Independent board member" has the same meaning as described in R590-254-14(4).

    (7) "Insurer" means a licensed insurer as defined in Subsections 31A-1-301(90)(a) and 31A-1-301(98) or an authorized insurer as defined in Subsection 31A-1-301(163)(b).

    (8) "Group of insurers" means those licensed insurers:

    (a) included in the reporting requirements of Chapter 31A-16, Insurance Holding Companies; or

    (b) a set of insurers as identified by management, for the purpose of assessing the effectiveness of internal control over financial reporting.

    (9) "Internal control over financial reporting" means a process effected by an entity's board of directors, management and other personnel designed to provide reasonable assurance regarding the reliability of the financial statements, i.e., those items specified in R590-254-5(2)(b) through (g) and includes those policies and procedures that:

    (a) pertain to the maintenance of records that, in reasonable detail, accurately and fairly reflect the transactions and dispositions of assets;

    (b) provide reasonable assurance that transactions are recorded as necessary to permit preparation of the financial statements, i.e., those items specified in R590-254-5(2)(b) through (g) and that receipts and expenditures are being made only in accordance with authorizations of management and directors; and

    (c) provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use or disposition of assets that could have a material effect on the financial statements, i.e., those items specified in R590-254-5(2)(b) through (g).

    (10) "SEC" means the United States Securities and Exchange Commission.

    (11) "Section 404" means Section 404 of the Sarbanes-Oxley Act of 2002 and the SEC's rules and regulations promulgated thereunder.

    (12) "Section 404 Report" means management's report on "internal control over financial reporting" as defined by the SEC and the related attestation report of the independent certified public accountant as described in R590-254-3(1).

    (13) "SOX compliant entity" means an entity that either is required to be compliant with, or voluntarily is compliant with, all of the following provisions:

    (a) the preapproval requirements of Section 201 of the Sarbanes-Oxley Act of 2002, under Section 10A(i) of the Securities Exchange Act of 1934,

    (b) the audit committee independence requirements of Section 301 of the Sarbanes-Oxley Act of 2002, under Section 10A(m)(3) of the Securities Exchange Act of 1934; and

    (c) the internal control over financial reporting requirements of Section 404 of the Sarbanes-Oxley Act of 2002, under Item 308 of SEC Regulation S-K.

     

    R590-254-4. General Requirements Related to Filing and Extensions for Filing of an Annual Audited Financial Report and Audit Committee Appointment.

    (1) All insurers shall have an annual audit by an independent certified public accountant and shall file an audited financial report with the commissioner on or before June 1 for the year ended December 31 immediately preceding. The commissioner may require an insurer to file an audited financial report earlier than June 1 with 90 days advance notice to the insurer.

    (2) Extensions of the June 1 filing date may be granted by the commissioner for 30 day periods upon a showing by the insurer and its independent certified public accountant of the reasons for requesting an extension and determination by the commissioner of good cause for an extension. The request for extension must be submitted in writing not less than 10 days prior to the due date in sufficient detail to permit the commissioner to make an informed decision with respect to the requested extension.

    (3) If an extension is granted in accordance with the provisions in R590-254-4(2), a similar extension of 30 days is granted to the filing of Management's Report of Internal Control over Financial Reporting.

    (4) Every insurer required to file an annual audited financial report pursuant to this rule shall designate a group of individuals as constituting its audit committee, as defined in R590-254-3. The audit committee of an entity that controls an insurer may be deemed to be the insurer's audit committee for purposes of this rule at the election of the controlling person.

     

    R590-254-5. Contents of an Annual Audited Financial Report.

    (1) An annual audited financial report shall report the financial position of the insurer as of the end of the most recent calendar year and the results of its operations, cash flows and changes in capital and surplus for the year then ended in conformity with statutory accounting practices prescribed, or otherwise permitted, by the department of insurance of the state of domicile.

    (2) The annual audited financial report shall include the following:

    (a) report of independent certified public accountant;

    (b) balance sheet reporting admitted assets, liabilities, capital and surplus;

    (c) statement of operations;

    (d) statement of cash flow;

    (e) statement of changes in capital and surplus;

    (f) notes to financial statements:

    (i) these notes shall be those required by the appropriate NAIC Annual Statement Instructions and the NAIC Accounting Practices and Procedures Manual;

    (ii) the notes shall include a reconciliation of differences, if any, between the audited statutory financial statements and the annual statement filed pursuant to Sections 31A-4-113 and 31A-4-113.5 with a written description of the nature of these differences;

    (g) the financial statements included in the audited financial report;

    (i) shall be prepared in a form and using language and groupings substantially the same as the relevant sections of the annual statement of the insurer filed with the commissioner; and

    (ii) shall be comparative, presenting the amounts as of December 31 of the current year and the amounts as of the immediately preceding December 31:

    (A) the comparative data may be omitted in the first year in which an insurer is required to file an audited financial report.

     

    R590-254-6. Designation of Independent Certified Public Accountant.

    (1) Each insurer required by this rule to file an annual audited financial report must within 60 days after becoming subject to the requirement, register with the commissioner in writing the name and address of the independent certified public accountant or accounting firm retained to conduct the annual audit set forth in this rule.

    (2) Insurers not retaining an independent certified public accountant on the effective date of this rule shall register the name and address of their retained independent certified public accountant not less than six months before the date when the first audited financial report is to be filed.

    (3) The insurer shall obtain a letter from the accountant, and file a copy with the commissioner stating that the accountant is aware of the provisions of the insurance code and the rules of the insurance department of the state of domicile that relate to accounting and financial matters and affirming that the accountant will express his or her opinion on the financial statements in terms of their conformity to the statutory accounting practices prescribed or otherwise permitted by that insurance department, specifying such exceptions as he or she may believe appropriate.

    (4) If an accountant who was the accountant for the immediately preceding filed audited financial report is dismissed or resigns, the insurer shall:

    (a) within five business days notify the commissioner of this event;

    (b) furnish the commissioner with a separate letter within 10 business days of the above notification stating whether in the 24 months preceding such event there were any disagreements with the former accountant on any matter of accounting principles or practices, financial statement disclosure, or auditing scope or procedure; which disagreements, if not resolved to the satisfaction of the former accountant, would have caused him or her to make reference to the subject matter of the disagreement in connection with his or her opinion:

    (i) the disagreements required to be reported in response to this section include both those resolved to the former accountant's satisfaction and those not resolved to the former accountant's satisfaction.

    (ii) disagreements contemplated by this section are those that occur at the decision-making level, i.e., between personnel of the insurer responsible for presentation of its financial statements and personnel of the accounting firm responsible for rendering its report.

    (c) in writing request the former accountant to furnish a letter addressed to the insurer stating whether the accountant agrees with the statements contained in the insurer's letter and, if not, stating the reasons for which he or she does not agree; and the insurer shall furnish the response letter from the former accountant to the commissioner together with its own.

     

    R590-254-7. Qualifications of Independent Certified Public Accountant.

    (1) The commissioner shall not recognize a person or firm as a qualified independent certified public accountant if the person or firm:

    (a) is not in good standing with the AICPA and in all states in which the accountant is licensed to practice, or, for a Canadian or British company, that is not a chartered accountant; or

    (b) has either directly or indirectly entered into an agreement of indemnity or release from liability, collectively referred to as indemnification, with respect to the audit of the insurer.

    (2) Except as otherwise provided in this rule, the commissioner shall recognize an independent certified public accountant as qualified as long as he or she conforms to the standards of his or her profession, as contained in the Code of Professional Ethics of the AICPA and Rules and Regulations and Code of Ethics and Rules of Professional Conduct of the Utah Division of Occupational and Professional Licensing for Accountancy, or similar code.

    (3) A qualified independent certified public accountant may enter into an agreement with an insurer to have disputes relating to an audit resolved by mediation or arbitration. However, in the event of a delinquency proceeding commenced against the insurer under Chapter 31A-27a, the mediation or arbitration provisions shall operate at the option of the statutory successor.

    (4)(a) The lead, or coordinating, audit partner, having primary responsibility for the audit, may not act in that capacity for more than five consecutive years.

    (i) The person shall be disqualified from acting in that or a similar capacity for the same company or its insurance subsidiaries or affiliates for a period of five consecutive years.

    (ii) An insurer may make application to the commissioner for relief from the above rotation requirement on the basis of unusual circumstances.

    (iii) This application should be made at least 30 days before the end of the calendar year. The commissioner may consider the following factors in determining if the relief should be granted:

    (A) number of partners, expertise of the partners or the number of insurance clients in the currently registered firm;

    (B) premium volume of the insurer; or

    (C) number of jurisdictions in which the insurer transacts business.

    (b)(i) The insurer shall file, with its annual statement filing, the approval for relief from R590-254-7(4)(a) with the states that it is licensed in or doing business in and with the NAIC.

    (ii) If the nondomestic state accepts electronic filing with the NAIC, the insurer shall file the approval in an electronic format acceptable to the NAIC.

    (5) The commissioner shall neither recognize as a qualified independent certified public accountant, nor accept an annual audited financial report, prepared in whole or in part by, a natural person who:

    (a) has been convicted of fraud, bribery, a violation of the Racketeer Influenced and Corrupt Organizations Act, 18 U.S.C. Sections 1961 to 1968, or any dishonest conduct or practices under federal or state law;

    (b) has been found to have violated the insurance laws of this state with respect to any previous reports submitted under this rule; or

    (c) has demonstrated a pattern or practice of failing to detect or disclose material information in previous reports filed under the provisions of this rule.

    (6) The commissioner, as provided in Subsection 31A-2-201(4), may, as provided in Subsection 31A-2-201(5), hold a hearing to determine whether an independent certified public accountant is qualified and, considering the evidence presented, may rule that the accountant is not qualified for purposes of expressing his or her opinion on the financial statements in the annual audited financial report made pursuant to this rule and require the insurer to replace the accountant with another whose relationship with the insurer is qualified within the meaning of this rule.

    (7)(a) The commissioner shall not recognize as a qualified independent certified public accountant, nor accept an annual audited financial report, prepared in whole or in part by an accountant who provides to an insurer, contemporaneously with the audit, the following non-audit services:

    (i) bookkeeping or other services related to the accounting records or financial statements of the insurer;

    (ii) financial information systems design and implementation;

    (iii) appraisal or valuation services, fairness opinions, or contribution-in-kind reports;

    (iv) actuarially-oriented advisory services involving the determination of amounts recorded in the financial statements;

    (A) The accountant may assist an insurer in understanding the methods, assumptions and inputs used in the determination of amounts recorded in the financial statement only if it is reasonable to conclude that the services provided will not be subject to audit procedures during an audit of the insurer's financial statements.

    (B) An accountant's actuary may also issue an actuarial opinion or certification "opinion" on an insurer's reserves if the following conditions have been met:

    (I) neither the accountant nor the accountant's actuary has performed any management functions or made any management decisions;

    (II) the insurer has competent personnel, or engages a third party actuary, to estimate the reserves for which management takes responsibility; and

    (III) the accountant's actuary tests the reasonableness of the reserves after the insurer's management has determined the amount of the reserves;

    (v) internal audit outsourcing services;

    (vi) management functions or human resources;

    (vii) broker or dealer, investment adviser, or investment banking services;

    (viii) legal services or expert services unrelated to the audit; or

    (ix) any other services that the commissioner determines, by rule, are impermissible.

    (b) In general, the principles of independence with respect to services provided by the qualified independent certified public accountant are largely predicated on three basic principles, violations of which would impair the accountant's independence. The accountant:

    (i) cannot function in the role of management,

    (ii) cannot audit his or her own work; and

    (iii) cannot serve in an advocacy role for the insurer.

    (8) Insurers having direct written and assumed premiums of less than $100,000,000 in any calendar year may request an exemption from R590-254-7(7)(a).

    (a) The insurer shall file with the commissioner a written statement discussing the reasons why the insurer should be exempt from these provisions.

    (b) If the commissioner finds, upon review of this statement, that compliance with this rule would constitute a financial or organizational hardship upon the insurer, an exemption may be granted.

    (9) A qualified independent certified public accountant who performs the audit may engage in other non-audit services, including tax services, that are not described in R590-254-7(7)(a) or that do not conflict with R590-254-7(7)(b), only if the activity is approved in advance by the audit committee, in accordance with R590-254-7(10).

    (10)(a) All auditing services and non-audit services provided to an insurer by the qualified independent certified public accountant of the insurer shall be preapproved by the audit committee.

    (b) The preapproval requirement is waived with respect to non-audit services if the insurer is a SOX Compliant Entity or a direct or indirect wholly-owned subsidiary of a SOX Compliant Entity or:

    (i) the aggregate amount of all such non-audit services provided to the insurer constitutes not more than 5% of the total amount of fees paid by the insurer to its qualified independent certified public accountant during the fiscal year in which the non-audit services are provided;

    (ii) the services were not recognized by the insurer at the time of the engagement to be non-audit services; and

    (iii) the services are promptly brought to the attention of the audit committee and approved prior to the completion of the audit by the audit committee or by one or more members of the audit committee who are the members of the board of directors to whom authority to grant such approvals has been delegated by the audit committee.

    (11)(a) The audit committee may delegate to one or more designated members of the audit committee the authority to grant the preapprovals required by R590-254-7(10).

    (b) The decisions of any member to whom this authority is delegated shall be presented to the full audit committee at each of its scheduled meetings.

    (12)(a)(i) The commissioner shall not recognize an independent certified public accountant as qualified for a particular insurer if a member of the board, president, chief executive officer, controller, chief financial officer, chief accounting officer, or any person serving in an equivalent position for that insurer, was employed by the independent certified public accountant and participated in the audit of that insurer during the one-year period preceding the date that the most current statutory opinion is due.

    (ii) This section shall only apply to partners and senior managers involved in the audit.

    (iii) An insurer may make application to the commissioner for relief from the above requirement on the basis of unusual circumstances.

    (b)(i) The insurer shall file, with its annual statement filing, the approval for relief from R590-254-7(12)(a) with the states that it is licensed in or doing business in and the NAIC.

    (ii) If the nondomestic state accepts electronic filing with the NAIC, the insurer shall file the approval in an electronic format acceptable to the NAIC.

     

    R590-254-8. Consolidated or Combined Audits.

    An insurer may make written application to the commissioner for approval to file audited consolidated or combined financial statements in lieu of separate annual audited financial statements if the insurer is part of a group of insurance companies that utilizes a pooling or 100% reinsurance agreement that affects the solvency and integrity of the insurer's reserves and the insurer cedes all of its direct and assumed business to the pool. In such cases, a columnar consolidating or combining worksheet shall be filed with the report, as follows:

    (1) amounts shown on the consolidated or combined audited financial report shall be shown on the worksheet;

    (2) amounts for each insurer subject to this section shall be stated separately;

    (3) noninsurance operations may be shown on the worksheet on a combined or individual basis;

    (4) explanations of consolidating and eliminating entries shall be included; and

    (5) a reconciliation shall be included of any differences between the amounts shown in the individual insurer columns of the worksheet and comparable amounts shown on the annual statements of the insurers.

     

    R590-254-9. Scope of Audit and Report of Independent Certified Public Accountant.

    (1) Financial statements furnished pursuant to R590-254-5 shall be examined by the independent certified public accountant.

    (2) The audit of the insurer's financial statements shall be conducted in accordance with generally accepted auditing standards.

    (3) In accordance with AU Section 319 of the Professional Standards of the AICPA, Consideration of Internal Control in a Financial Statement Audit, the independent certified public accountant should obtain an understanding of internal control sufficient to plan the audit.

    (4) To the extent required by AU 319, for those insurers required to file a Management's Report of Internal Control over Financial Reporting pursuant to R590-254-16, the independent certified public accountant should consider, as that term is defined in Statement on Auditing Standards (SAS) No. 102, Defining Professional Requirements in Statements on Auditing Standards or its replacement, the most recently available report in planning and performing the audit of the statutory financial statements.

    (5) Consideration shall be given to the procedures illustrated in the Financial Condition Examiners Handbook promulgated by the National Association of Insurance Commissioners as the independent certified public accountant deems necessary.

     

    R590-254-10. Notification of Adverse Financial Condition.

    (1) The insurer required to furnish the annual audited financial report shall require the independent certified public accountant to report, in writing, within five business days to the board of directors or its audit committee any determination by the independent certified public accountant that the insurer has materially misstated its financial condition as reported to the commissioner as of the balance sheet date currently under audit or that the insurer does not meet the minimum capital and surplus requirement of the Utah insurance code as of that date.

    (a) An insurer that has received a report pursuant to this paragraph shall forward a copy of the report to the commissioner within five business days of receipt of the report and shall provide the independent certified public accountant making the report with evidence of the report being furnished to the commissioner.

    (b) If the independent certified public accountant fails to receive the evidence within the required five business day period, the independent certified public accountant shall furnish to the commissioner a copy of its report within the next five business days.

    (2) No independent certified public accountant shall be liable in any manner to any person for any statement made in connection with the above paragraph if the statement is made in good faith in compliance with R590-254-10(1).

    (3) If the accountant, subsequent to the date of the audited financial report filed pursuant to this rule, becomes aware of facts that might have affected his or her report, the commissioner notes the obligation of the accountant to take such action as prescribed in Volume 1, Section AU 561 of the Professional Standards of the AICPA.

     

    R590-254-11. Communication of Internal Control Related Matters Noted in an Audit.

    (1) In addition to the annual audited financial report, each insurer shall furnish the commissioner with a written communication as to any unremediated material weaknesses in its internal control over financial reporting noted during the audit.

    (a) Such communication shall be prepared by the accountant within 60 days after the filing of the annual audited financial report, and shall contain a description of any unremediated material weakness, as the term material weakness is defined by Statement on Auditing Standard 60, Communication of Internal Control Related Matters Noted in an Audit, or its replacement, as of December 31 immediately preceding, so as to coincide with the audited financial report discussed in R590-254-4(1), in the insurer's internal control over financial reporting noted by the accountant during the course of their audit of the financial statements.

    (b) If no unremediated material weaknesses were noted, the communication should so state.

    (2) The insurer is required to provide a description of remedial actions taken or proposed to correct unremediated material weaknesses, if the actions are not described in the accountant's communication.

     

    R590-254-12. Accountant's Letter of Qualifications.

    The accountant shall furnish the insurer in connection with, and for inclusion in, the filing of the annual audited financial report, a letter stating:

    (1) that the accountant is independent with respect to the insurer and conforms to the standards of his or her profession as contained in the Code of Professional Ethics and pronouncements of the AICPA and the Rules of Professional Conduct of the Utah Division of Occupational and Professional Licensing for Accountancy, or similar code;

    (2)(a) the background and experience in general, and the experience in audits of insurers of the staff assigned to the engagement and whether each is an independent certified public accountant.

    (b) Nothing within this rule shall be construed as prohibiting the accountant from utilizing such staff as he or she deems appropriate where use is consistent with the standards prescribed by generally accepted auditing standards;

    (3) that the accountant understands the annual audited financial report and his opinion thereon will be filed in compliance with this rule and that the commissioner will be relying on this information in the monitoring and regulation of the financial position of insurers;

    (4) that the accountant consents to the requirements of R590-254-13 of this rule and that the accountant consents and agrees to make available for review by the commissioner, or the commissioner's designee or appointed agent, the workpapers, as defined in R590-254-13;

    (5) a representation that the accountant is properly licensed by an appropriate state licensing authority and is a member in good standing in the AICPA; and

    (6) a representation that the accountant is in compliance with the requirements of R590-254-7 of this rule.

     

    R590-254-13. Definition, Availability and Maintenance of Independent Certified Public Accountants Workpapers.

    (1)(a) Workpapers are the records kept by the independent certified public accountant of the procedures followed, the tests performed, the information obtained, and the conclusions reached pertinent to the accountant's audit of the financial statements of an insurer.

    (b) Workpapers, may include audit planning documentation, work programs, analyses, memoranda, letters of confirmation and representation, abstracts of company documents and schedules or commentaries prepared or obtained by the independent certified public accountant in the course of his or her audit of the financial statements of an insurer and which support the accountant's opinion.

    (2)(a) Every insurer required to file an audited financial report pursuant to this rule, shall require the accountant to make available for review by insurance department examiners, all workpapers prepared in the conduct of the accountant's audit and any communications related to the audit between the accountant and the insurer, at the offices of the insurer, at the insurance department or at any other reasonable place designated by the commissioner.

    (b) The insurer shall require that the accountant retain the audit workpapers and communications until the insurance department has filed a report on examination covering the period of the audit but no longer than seven years from the date of the audit report.

    (3)(a) In the conduct of the aforementioned periodic review by the insurance department examiners, it shall be agreed that photocopies of pertinent audit workpapers may be made and retained by the department.

    (b) Such reviews by the department examiners shall be considered investigations and all working papers and communications obtained during the course of such investigations shall be afforded the same confidentiality as other examination workpapers generated by the department.

     

    R590-254-14. Requirements for Audit Committees.

    (1) This section shall not apply to foreign or alien insurers licensed in this state or an insurer that is a SOX Compliant Entity or a direct or indirect wholly-owned subsidiary of a SOX Compliant Entity.

    (2) The audit committee shall be directly responsible for the appointment, compensation and oversight of the work of any accountant, including resolution of disagreements between management and the accountant regarding financial reporting, for the purpose of preparing or issuing the audited financial report or related work pursuant to this rule. Each accountant shall report directly to the audit committee.

    (3) Each member of the audit committee shall be a member of the board of directors of the insurer or a member of the board of directors of an entity elected pursuant to R590-254-14(6) and R590-254-3(3).

    (4) In order to be considered independent for purposes of this section, a member of the audit committee:

    (a) may not, other than in his or her capacity as a member of the audit committee, the board of directors, or any other board committee, accept any consulting, advisory or other compensatory fee from the entity or be an affiliated person of the entity or any subsidiary of the entity; or

    (b) if law requires board participation by otherwise non-independent members, that law shall prevail and such members may participate in the audit committee and be designated as independent for audit committee purposes, unless they are an officer or employee of the insurer or one of its affiliates.

    (5) If a member of the audit committee ceases to be independent for reasons outside the member's reasonable control, that person, with notice by the responsible entity to the state, may remain an audit committee member of the responsible entity until the earlier of the next annual meeting of the responsible entity or one year from the occurrence of the event that caused the member to be no longer independent.

    (6) To exercise the election of the controlling person to designate the audit committee for purposes of this rule, the ultimate controlling person shall provide written notice to the commissioners of the affected insurers.

    (a) Notification shall be made timely prior to the issuance of the statutory audit report and include a description of the basis for the election.

    (b) The election can be changed through notice to the commissioner by the insurer, which shall include a description of the basis for the change.

    (c) The election shall remain in effect for perpetuity, until rescinded.

    (7)(a) The audit committee shall require the accountant that performs for an insurer any audit required by this rule to timely report to the audit committee in accordance with the requirements of SAS 61, Communication with Audit Committees, or its replacement, including:

    (i) all significant accounting policies and material permitted practices;

    (ii) all material alternative treatments of financial information within statutory accounting principles that have been discussed with management officials of the insurer, ramifications of the use of the alternative disclosures and treatments, and the treatment preferred by the accountant; and

    (iii) other material written communications between the accountant and the management of the insurer, such as any management letter or schedule of unadjusted differences.

    (b) If an insurer is a member of an insurance holding company system, the reports required by R590-254-14(7)(a) may be provided to the audit committee on an aggregate basis for insurers in the holding company system, provided that any substantial differences among insurers in the system are identified to the audit committee.

    (8) The proportion of independent audit committee members shall meet or exceed the following criteria:

     

    TABLE
    Prior Calendar Year Direct Written and Assumed Premiums


    $0 - $300,000,000
    No minimum Requirements. See also Note A and B.

    Over $300,000,000 - $500,000,000
    Majority (50% or more) of members shall be independent. See
    also Note A and B.

    Over $500,000,000
    Super majority of members (75% or more) shall be independent.
    See also Note A.

    Note A: The commissioner has authority afforded by state law
    to require the entity's board to enact improvements to the
    independence of the audit committee membership if the insurer
    is in an RBC action level event, meets one or more of the
    standards of an insurer deemed to be in hazardous financial
    condition, or otherwise exhibits qualities of a troubled insurer.
    Note B: All insurers with less than $500,000,000 in prior
    year direct written and assumed premiums are encouraged to
    structure their audit committees with at least a supermajority
    of independent audit committee members.
    Note C: Prior calendar year direct written and assumed
    premiums shall be the combined total of direct premiums and
    assumed premiums from non-affiliates for the reporting entities.

     

    (9)(a) An insurer with direct written and assumed premium, excluding premiums reinsured with the Federal Crop Insurance Corporation and Federal Flood Program, less than $500,000,000 may make application to the commissioner for a waiver from the R590-254-14 requirements based upon hardship.

    (b) The insurer shall file, with its annual statement filing, the approval for relief from R590-254-14 with the states that it is licensed in or doing business in and the NAIC. If the nondomestic state accepts electronic filing with the NAIC, the insurer shall file the approval in an electronic format acceptable to the NAIC.

     

    R590-254-15. Conduct of Insurer in Connection with the Preparation of Required Reports and Documents.

    (1) No director or officer of an insurer shall, directly or indirectly:

    (a) make or cause to be made a materially false or misleading statement to an accountant in connection with any audit, review or communication required under this rule; or

    (b) omit to state, or cause another person to omit to state, any material fact necessary in order to make statements made, in light of the circumstances under which the statements were made, not misleading to an accountant in connection with any audit, review or communication required under this rule.

    (2) No officer or director of an insurer, or any other person acting under the direction thereof, shall directly or indirectly take any action to coerce, manipulate, mislead or fraudulently influence any accountant engaged in the performance of an audit pursuant to this rule if that person knew or should have known that the action, if successful, could result in rendering the insurer's financial statements materially misleading.

    (3) For purposes of R590-254-15(2), actions that, "if successful, could result in rendering the insurer's financial statements materially misleading" include, but are not limited to, actions taken at any time with respect to the professional engagement period to coerce, manipulate, mislead or fraudulently influence an accountant:

    (a) to issue or reissue a report on an insurer's financial statements that is not warranted in the circumstances, due to material violations of statutory accounting principles prescribed by the commissioner, generally accepted auditing standards, or other professional or regulatory standards;

    (b) not to perform audit, review or other procedures required by generally accepted auditing standards or other professional standards;

    (c) not to withdraw an issued report; or

    (d) not to communicate matters to an insurer's audit committee.

     

    R590-254-16. Management's Report of Internal Control over Financial Reporting.

    (1)(a) Every insurer required to file an audited financial report pursuant to this rule that has annual direct written and assumed premiums, excluding premiums reinsured with the Federal Crop Insurance Corporation and Federal Flood Program, of $500,000,000 or more shall prepare a report of the insurer's or "group of insurers,'" "internal control" over financial reporting, as these terms are defined in R590-254-3.

    (b) The report shall be filed with the commissioner along with the Communication of Internal Control Related Matters Noted in an audit described under R590-254-11.

    (c) Management's Report of Internal Control over Financial Reporting shall be as of December 31 immediately preceding.

    (2) Notwithstanding the premium threshold in R590-254-16(1)(a), the commissioner may require an insurer to file Management's Report of Internal Control over Financial Reporting if the insurer is in any RBC level event, or meets any one or more of the standards of an insurer deemed to be in hazardous financial condition as defined in 31A-27a-207 and the NAIC Model Regulation to Define Standards and Commissioner's Authority for Companies Deemed to be in Hazardous Financial Condition.

    (3)(a) An insurer or a group of insurers that is:

    (i) directly subject to Section 404;

    (ii) part of a holding company system whose parent is directly subject to Section 404;

    (iii) not directly subject to Section 404 but is a SOX Compliant Entity; or

    (iv) a member of a holding company system whose parent is not directly subject to Section 404 but is a SOX Compliant Entity;

    (b) may file its or its parent's Section 404 Report and an addendum in satisfaction of R590-254-16(1), provided that those internal controls of the insurer or group of insurers having a material impact on the preparation of the insurer's or group of insurers' audited statutory financial statements, as included in R590-254-5(2)(b) through (g), were included in the scope of the Section 404 Report.

    (i) The addendum shall be a positive statement by management that there are no material processes with respect to the preparation of the insurer's or group of insurers' audited statutory financial statements, as included in R590-254-5(2)(b) through (g), excluded from the Section 404 Report.

    (ii) If there are internal controls of the insurer or group of insurers that have a material impact on the preparation of the insurer's or group of insurers' audited statutory financial statements and those internal controls were not included in the scope of the Section 404 Report, the insurer or group of insurers may either file:

    (A) a R590-254-16 report:, or

    (B) the Section 404 Report: and

    (I) a R590-254-16 report for those internal controls that have a material impact on the preparation of the insurer's or group of insurers' audited statutory financial statements not covered by the Section 404 Report.

    (4) Management's Report of Internal Control over Financial Reporting shall include:

    (a) a statement that management is responsible for establishing and maintaining adequate internal control over financial reporting;

    (b) a statement that management has established internal control over financial reporting and an assertion, to the best of management's knowledge and belief, after diligent inquiry, as to whether its internal control over financial reporting is effective to provide reasonable assurance regarding the reliability of financial statements in accordance with statutory accounting principles;

    (c) a statement that briefly describes the approach or processes by which management evaluated the effectiveness of its internal control over financial reporting;

    (d) a statement that briefly describes the scope of work that is included and whether any internal controls were excluded;

    (e)(i) disclosure of any unremediated material weaknesses in the internal control over financial reporting identified by management as of December 31 immediately preceding.

    (ii) Management is not permitted to conclude that the internal control over financial reporting is effective to provide reasonable assurance regarding the reliability of financial statements in accordance with statutory accounting principles if there is one or more unremediated material weaknesses in its internal control over financial reporting;

    (f) a statement regarding the inherent limitations of internal control systems; and

    (g) signatures of the chief executive officer and the chief financial officer, or equivalent position/title.

    (5) Management shall document and make available upon financial condition examination the basis upon which its assertions, required in R590-254-16(4), are made.

    (a) Management may base its assertions, in part, upon its review, monitoring and testing of internal controls undertaken in the normal course of its activities.

    (b) Management shall have discretion as to the nature of the internal control framework used, and the nature and extent of documentation, in order to make its assertion in a cost effective manner and, as such, may include assembly of or reference to existing documentation.

    (c) Management's Report on Internal Control over Financial Reporting, required by R590-254-16(1), and any documentation provided in support thereof during the course of a financial condition examination, shall be kept confidential by the department.

     

    R590-254-17. Exemptions and Implementation Dates.

    (1) Upon written application of any insurer, the commissioner may grant an exemption from compliance with any and all provisions of this rule if the commissioner finds, upon review of the application, that compliance with this rule would constitute a financial or organizational hardship upon the insurer.

    (a) An exemption may be granted at any time and from time to time for a specified period or periods.

    (b) Within 10 days from a denial of an insurer's written request for an exemption from this rule, the insurer may request in writing a hearing on its application for an exemption.

    (c) The hearing shall be held in accordance with the rules of the department pertaining to administrative hearing procedures.

    (2) Domestic insurers retaining a certified public accountant on the effective date of this rule who qualify as independent shall comply with this rule for the year ending December 31, 2010 and each year thereafter unless the commissioner permits otherwise.

    (3) Domestic insurers not retaining a certified public accountant on the effective date of this rule who qualifies as independent may meet the following schedule for compliance unless the commissioner permits otherwise:

    (a) as of December 31, 2010, file with the commissioner an audited financial report; and

    (b) for the year ending December 31, 2010 and each year thereafter, such insurers shall file with the commissioner all reports and communication required by this rule.

    (4) Foreign insurers shall comply with this rule for the year ending December 31, 2010 and each year thereafter, unless the commissioner permits otherwise.

    (5) The requirements of R590-254-7(4) shall be in effect for audits of the year beginning January 1, 2010 and thereafter.

    (6) The requirements of R590-254-14 are to be in effect January 1, 2010.

    (a) An insurer or group of insurers that is not required to have independent audit committee members or only a majority of independent audit committee members, as opposed to a supermajority, because the total written and assumed premium is below the threshold and subsequently becomes subject to one of the independence requirements due to changes in premium, shall have one year following the year the threshold is exceeded, but not earlier than January 1, 2010, to comply with the independence requirements.

    (b) An insurer that becomes subject to one of the independence requirements as a result of a business combination shall have one calendar year following the date of acquisition or combination to comply with the independence requirements.

    (7) The requirements of R590-254-16 except for R590-254-14 covered above, are effective beginning with the reporting period ending December 31, 2010 and each year thereafter.

    (a) An insurer or group of insurers that is not required to file a report because the total written premium is below the threshold, and subsequently becomes subject to the reporting requirements, shall have two years following the year the threshold is exceeded, but not earlier than December 31, 2010, to file a report.

    (b) An insurer acquired in a business combination shall have two calendar years following the date of acquisition or combination to comply with the reporting requirements.

     

    R590-254-18. Canadian and British Companies.

    (1) In the case of Canadian and British insurers, the annual audited financial report shall be defined as the annual statement of total business on the form filed by such companies with their supervision authority duly audited by an independent chartered accountant.

    (2) For such insurers, the letter required in R590-254-6(3) shall state that the accountant is aware of the requirements relating to the annual audited financial report filed with the commissioner pursuant to R590-254-4 and shall affirm that the opinion expressed is in conformity with those requirements.

     

    R590-254-19. Penalties.

    A person found to be in violation of this rule shall be subject to penalties as provided under 31A-2-308.

     

    R590-254-20. Enforcement Date.

    The commissioner will begin enforcing this rule on the effective date of the rule.

     

    R590-254-21. Severability.

    If any provision of this rule or its application to any person or situation is held to be invalid, that invalidity shall not affect any other provision or application of this rule which can be given effect without the invalid provision or application, and to this end the provisions of this rule are declared to be severable.

     

    KEY: insurance company financial reporting

    Date of Enactment or Last Substantive Amendment: 2009

    Authorizing, and Implemented or Interpreted Law: 31A-2-201; 31A-2-203; 31A-5-412

     

     

Document Information

Effective Date:
7/8/2009
Publication Date:
06/01/2009
Filed Date:
05/14/2009
Agencies:
Insurance,Administration
Rulemaking Authority:

Sections 31A-2-201, 31A-2-203, and 31A-5-412

Authorized By:
Jilene Whitby, Information Specialist
DAR File No.:
32674
Related Chapter/Rule NO.: (1)
R590-254. Annual Financial Reporting Rule.