Compyl
Industry · InsuranceCarriers · MGAs · insurtech

One program, every state.

Insurers protect policyholder PII and claims data under a patchwork of state data-security laws built on the NAIC model, plus GLBA, the Model Audit Rule, and PCI. Compyl maps one control library to all of them, so you stay exam-ready across every state from a single program.

Last reviewed September 2026 by the Compyl GRC team
Every state adoption125+ integrationsRisk in dollars
Your regulatory year · insuranceLive evidence status · every control checked hourly
JanFebMarAprMayJunJulAugSepOctNovDec
Feb 15State cybersecurity certificationsNAIC model law adoptions14 states · current
MarModel Audit Rule control testingICFR · $500M+ premiumDue in 30 days
Apr 15NYDFS annual certification23 NYCRR 50094% evidenced
JunMarket-conduct examState insurance departmentPack ready
AugSOC 2 Type II windowPartner assuranceEvidence current
OctGLBA risk assessmentSafeguards RuleScheduled
Always on · 72-hour cybersecurity-event notification, TPA and broker monitoring, and access reviewsContinuous monitoring, not a year-end scramble
The challenge

Why GRC is harder in insurance

One model law, dozens of state variations, deeply sensitive data, and SOX-style control testing every year.

One model, a patchwork of state adoptions

State adoptions of the NAIC model security law differ in timing and detail, so multi-state insurers track overlapping but non-identical requirements.

Policyholder PII and claims data

You hold deeply sensitive personal, financial, and health-adjacent data that regulators and customers expect you to protect and prove.

Model Audit Rule controls

The Model Audit Rule brings SOX-style financial-reporting control requirements that must be evidenced and tested each year.

Who you answer to

Every regulator that governs insurance

State laws, federal rules, card networks, and assurance frameworks, one control library. Each tile shows who enforces it, what it asks, and the shared control Compyl evidences once.

NAIC Model Law

State
State insurance departments

Information security program, risk assessment, oversight, and event notification, adopted state by state.

Shared controlRisk assessment · MFA · encryption
Certify by Feb 15

GLBA Safeguards

Federal
State insurance regulators

A written information security program protecting customer financial data.

Shared controlRisk assessment · access controls
§314.4 elements

Model Audit Rule

State
State insurance departments

Internal controls over financial reporting, with a management ICFR report at $500M+ premium.

Shared controlChange management · access reviews
Annual testing

NYDFS 23 NYCRR 500

State
New York DFS

Cybersecurity program, CISO, MFA for all users since Nov 2025, and an annual certification or acknowledgment.

Shared controlMFA (§500.12) · access privileges
Certification due Apr 15

PCI DSS v4.0.1

Card networks
PCI SSC

Protect cardholder data for premium payments.

Shared controlMFA · encryption · logging
Annual SAQ or ROC

HIPAA

Sector
HHS · OCR

Health plans and health-adjacent claims data.

Shared controlAccess control · audit logs
Where applicable

SOC 2

Assurance
AICPA

Partner and reinsurer assurance that controls operate as described.

Shared controlShared with every regime above
Type I / Type II

NIST CSF 2.0

Framework
NIST

The reference model many state examiners map to.

Shared controlShared across every regime above
Recognized practices
One control library

Map one control library to every state and framework

Define controls once and cross-map them to the NAIC model law, GLBA, NYDFS, the Model Audit Rule, and PCI, evidence collected once satisfies every adoption.

  • No duplicate work across states or regulators
  • New state adoptions reuse controls you already have
  • Every artifact mapped to every requirement it satisfies
  • Coverage visible per state, not buried in spreadsheets
One control library · every state and frameworkCross-mapped automatically
Encryption of policyholder dataPulled automatically from AWS / Azure
5requirements
NAIC Model Law§4(D)
Satisfied
GLBA Safeguards§314.4
Satisfied
NYDFS 500§500.15
Satisfied
Model Audit RuleITGC
Satisfied
PCI DSS v4.0.1Req 3.5
Satisfied
SOC 2CC6.6
Also covered
New state adoptions reuse controls you already haveNo duplicate work
Exam readiness

Stay continuously exam-ready

Integrations pull evidence from your policy admin, cloud, and identity systems around the clock, and Evidence Health flags stale proof before a market-conduct or financial exam.

  • Produce state certifications with current proof
  • Surface gaps weeks before an examiner asks
  • Schedule and evidence Model Audit Rule control tests
  • Drift becomes a tracked task with an owner and a deadline
Exam readinessContinuous control monitoring
State certifications14 states · current
NYDFS certificationApr 15 · 94%
MAR control testDue in 30 days
PCI SAQCurrent
Access reviews · policy admin systemGuidewire · Okta · 860 accounts reviewed
Current
Encryption · claims data storeAWS KMS · checked hourly
Current
MAR ITGC · change management testAnnual test scheduled · evidence 80% collected
Due 30d
Gaps surface weeks before an examiner asksEvidence Health 98
Risk in dollars

Report risk in dollars and watch every vendor

Quantify cyber and vendor risk in financial terms with FAIR for the board, and continuously monitor TPAs, brokers, and SaaS vendors that touch policyholder data.

  • FAIR-based risk quantification, board-ready
  • Continuous third-party monitoring and vendor risk
  • TPAs and brokers tiered by the data they touch
  • Expiring SOC 2 reports and contracts surface before they lapse
Third-party riskTPAs, brokers & vendors · FAIR
Claims TPAHandles claims and health-adjacent data · SOC 2 on file
Critical
Broker portalPolicyholder PII · questionnaire sent · monitored continuously
Medium
Analytics SaaSAggregated data only · annual review
Low
Loss exposure$2.9M → $1.2M
Top scenarioTPA breach
Risk in dollars for the board and regulatorsFAIR-based
Collect once, satisfy every regulator

One piece of evidence. Every state it satisfies.

Compyl maps each control and its evidence across every state adoption and framework that requires it, so a single artifact, pulled automatically from your stack, counts everywhere at once.

  • One control library mapped to 70+ frameworks and every state adoption
  • Collect evidence once and reuse it across every exam
  • See instantly how NYDFS work translates to the NAIC model law
  • Add the next state without starting over
One controlMFA enforced on all usersPulled automatically from Okta and Microsoft Entra ID · scored 98 by Evidence Health1 piece of evidence
Satisfies at once
NAIC Model Law§4(D)(2) Multi-factor authentication
Satisfied
GLBA Safeguards§314.4(c) Access controls
Satisfied
NYDFS 500§500.12 Multi-factor authentication
Satisfied
Model Audit RuleIT general controls · access
Satisfied
+ 70 more frameworks cross-mapped automatically
Coverage

Frameworks that govern insurance

All cross-mapped to one control library. Explore each, or see the full library of 70+.

NAIC Data Security Model LawGLBA Safeguards RuleModel Audit RuleNYDFS 23 NYCRR 500PCI DSSSOC 2ISO 27001NIST CSF70+ frameworks
Recognized by users on G2 · Rated a leader by the teams who use itG2 Momentum Leader, Summer 2026G2 High Performer Mid-Market, Summer 2026G2 Best Support Mid-Market, Summer 2026G2 Fastest Implementation Mid-Market, Summer 2026
50
States, one control library
125+
Native integrations feeding evidence automatically
Real-time
Evidence collection, no manual screenshots
Year-round
Exam readiness instead of a pre-exam scramble

“It has brought a sense of relief to my life because, for the first time, we have a real solution in place that is proactively keeping us protected.”

JSJon SeniorCTO · via G2
Why Compyl for insurance

Built for the way insurance GRC actually works

Plenty of tools store a policy. Compyl runs the whole program, controls, evidence, risk, and vendors, across every state and regulator you answer to.

01

One source of truth

Controls, evidence, risk, and vendors in one connected system, across every regulator you answer to.

02

Continuous, not point-in-time

Evidence refreshes automatically and is scored for health, so you are exam-ready every day of the year.

03

125+ integrations

Policy admin, claims, cloud, and identity systems feed evidence automatically.

04

Agentic AI, human approved

AI drafts evidence, maps controls, and triages risk; your experts approve every decision.

05

Risk in dollars

FAIR-based quantification turns cyber and vendor risk into numbers a board can act on.

What does compliance for insurance require?

Insurers must protect policyholder PII and claims data under state data-security laws modeled on the NAIC Insurance Data Security Model Law (MDL-668), alongside the GLBA Safeguards Rule, the Model Audit Rule (financial-reporting controls), and PCI DSS for payments. Insurers operating in New York also fall under NYDFS 23 NYCRR 500. Compyl maps one control library across every state adoption and framework, with continuous evidence.

Obligations

What does each regulator expect you to prove?

The recurring obligations behind insurance compliance, with the regime that sets each one.

ObligationRegimeCadenceWith Compyl
Certify your information security programNAIC Model Law (state adoptions)Annually by Feb 15, in adopting statesCertifications produced from current evidence
Notify a cybersecurity eventNAIC Model Law · NYDFS 500Within 72 hours of determinationIncident workflow with the notification record
Test financial-reporting controlsModel Audit RuleAnnuallyControl testing scheduled, evidenced, and tracked
Certify NYDFS complianceNYDFS 23 NYCRR 500Annually, by April 15Certification produced from current evidence
Maintain a written security programGLBA Safeguards RuleContinuous, with periodic risk assessmentProgram, risk assessment, and controls in one place
Oversee third-party service providersNAIC Model Law · GLBAContinuousTPA and broker tiering, questionnaires, and monitoring
Insurance FAQ

Insurance questions, answered

What compliance do insurance companies need?

Insurers must protect policyholder data under state data-security laws based on the NAIC Insurance Data Security Model Law, plus the GLBA Safeguards Rule, the Model Audit Rule for financial-reporting controls, and PCI DSS for payments. Insurers in New York also fall under NYDFS 23 NYCRR 500. Compyl maps one control library to all of them.

How does Compyl handle different state adoptions of the NAIC model law?

Compyl maintains one control library and cross-maps it to each state’s adoption of the NAIC Insurance Data Security Model Law. Because the underlying controls overlap, evidence collected once satisfies every state where you operate, and new adoptions reuse controls you already have.

Does Compyl support the Model Audit Rule?

Yes. Compyl manages the IT general controls behind the Model Audit Rule, schedules and tracks control testing, and continuously collects evidence, so the annual MAR requirements are met with current proof instead of a year-end scramble.

Can one piece of evidence satisfy multiple insurance regulations?

Yes. With cross-mapping, evidence that MFA is enforced can satisfy the NAIC model law, GLBA Safeguards, NYDFS 500.12, the Model Audit Rule, SOC 2, and PCI DSS at once, collected a single time and counted everywhere it applies.

Does Compyl cover TPAs, brokers, and other vendors?

Yes. Compyl continuously assesses and monitors third-party administrators, brokers, and SaaS vendors that touch policyholder data, automates their security questionnaires, and quantifies exposure in dollars using the FAIR model.

Which states have adopted the NAIC Insurance Data Security Model Law?

Roughly half the states have adopted Model #668 or a close variant, while others rely on general breach and data security laws. In adopting states, domestic insurers typically certify compliance by February 15 and notify the commissioner of a cybersecurity event within 72 hours, so check NAIC’s current adoption chart for each state you operate in.

Does the FTC Safeguards Rule apply to insurance companies?

No. The FTC Safeguards Rule covers financial institutions under FTC jurisdiction that no other agency regulates. Insurers answer to state insurance regulators for GLBA, usually through data security laws modeled on NAIC Model #668, plus NYDFS Part 500 in New York.

Which states have adopted the NAIC AI Model Bulletin?

As of NAIC’s Spring 2026 meeting, 24 states and the District of Columbia had adopted the bulletin, and several more had their own insurance AI rules. It expects a written AI program with governance, risk controls and oversight of third-party AI vendors.

GRC your way

See Compyl mapped to your policyholder data

One control library, every state, continuous evidence, and agentic AI that removes the busywork, with your experts in control.

By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies