December 12, 2025

Federal Reserve’s Annual Report Highlights Industry Leverage, IAIS Activities

The Federal Reserve released its 2024 Annual Report in late November 2025. The report commented on large life insurance company leverage again being above the historical average, with a “substantial” share of assets allocated to “less liquid” assets. The report also took note that the International Association of Insurance Supervisors (IAIS) adopted the Insurance Capital Standard (ICS) and deemed the Aggregation Method (AM) a basis for implementation to achieve comparable outcomes.

  Staff Contact - Sean McKenna

IAIS & FSB Updates

On November 25, 2025, the International Association of Insurance Supervisors (IAIS) published for consultation revised versions of (1) the Application Paper on resolution powers, preparations and plans and (2) the Application Paper on recovery planning. Both papers are open for public comment until February 25.

Also on November 25, the Financial Stability Board (FSB) released a list of 17 insurers subject to resolution planning standards in accordance with the FSB’s Key Attributes of Effective Resolution Regimes for Financial Institutions. While the FSB is willing to utilize the IAIS’ Holistic Framework as a tool for systemic risk monitoring in the insurance sector (see below), it has not given up its mandate as the global watchdog of systemic risk across all financial sectors, including insurance. Part of that mandate includes monitoring jurisdictional implementation of the Key Attributes, including resolution planning. Thus, member jurisdictions are required to report to the FSB insurers that are subject to resolution planning and resolvability assessments, in compliance with the Key Attributes. The FSB is simply compiling and publishing the list of insurers that—according to member authorities’ assessment and self-reporting—are subject to resolution planning and resolvability assessments consistent with the Key Attributes. The FSB is not designating which companies appear on the list.

The FSB has reserved the right to express its views on the “appropriateness and sufficiency” of the list of reported insurers. It has also published a consultation version of draft guidance to help authorities assess which insurers should be subject to recovery and/or resolution planning; comments are due February 6.

In other news, the FSB assessed the IAIS’ Holistic Framework after three years and continues to view it as an effective means for monitoring systemic risk in the insurance sector. As a result, on November 25, the FSB reaffirmed its decision to discontinue the previous annual identification of global systemically important insurers. The IAIS will continue to report annually to the FSB the outcomes of the Global Monitoring Exercise (GME), and the Holistic Framework remains subject to review every three years.

The updated GME document was published by the IAIS on November 25, reflecting the outcome of the 2023–2025 review, including changes to the Individual Insurer Monitoring (IIM) assessment methodology that were subject to consultation over the summer. These changes are in effect for the 2026–2028 GME cycle.

In addition, the IAIS published the final Ancillary Risk Indicators in the GME. The report (1) introduces new ancillary indicators on credit risk, derivatives, and reinsurance; and (2) adjusts the liquidity metrics. Ancillary risk indicators are used in the IIM to help assess trends and potential systemic risk, but they do not impact the total quantitative scores—they are simply meant to provide supervisors with additional context.

On December 2, the IAIS published its 2025 Global Insurance Market Report (GIMAR). The report expands upon the GME’s key macroprudential themes that were identified in the mid-year report: (1) the impact of geoeconomic fragmentation on insurers’ management of assets and liabilities; (2) insurers’ increasing investments in private credit; and (3) insurers’ adoption and governance of artificial intelligence.

As noted in an earlier issue of the NOLHGA Wire, the IAIS recently launched three consultations to incorporate insurance capital standard (ICS)–related elements into ComFrame: Insurance Core Principle (ICP) CF 9.4 on supervisory reporting, ICP CF 20.10 on public disclosure, and a new paragraph 47 of the ComFrame Assessment Methodology. Notably, the IAIS has made clear that it anticipates public disclosure of ICS ratios by internationally active insurance groups (IAGs). An initial review of the consultations suggests that the information IAIGs will be required to report confidentially to their group-wide supervisor does not materially differ from what is expected to be disclosed publicly (note that the materials for the December 9 NAIC Aggregation Method Implementation Working Group meeting indicated that the reporting and disclosure requirements in ComFrame will also apply to the Aggregation Method). The IAIS held a stakeholder session on the consultations on December 11.

  Staff Contact - Sean McKenna

NAIC Updates

The RBC Model Governance Task Force met on December 3, 2025, to discuss the latest draft of RBC principles and hear feedback from commenters. Of note, the “RBC purpose and use” discussion—previously held at the Capital Adequacy Task Force—is now part of the principles discussion, with two new additions.

  • Principle 1: Purpose – The purpose of RBC requirements is to identify potentially weakly capitalized companies.
  • Principle 2: Use – RBC requirements are primarily used to facilitate regulatory action against weakly capitalized companies. While RBC requirements may be used for other purposes, these uses must not distort or redefine their primary purpose.
The notes to Principle 2 also suggest a possible addition to the RBC preamble—a disclosure statement to be used whenever an insurer reports RBC information.

The Equal Capital for Equal Risk (ECER) principle was revised to clarify that, although RBC should generally follow ECER, substantial differences in business models (e.g., life vs. P&C) may justify alternative treatments.

A few commenters noted that not all of their suggestions were reflected, but the meeting materials indicate the drafting group reviewed all comments. Some commenters proposed including these notes alongside the principles. No further modifications were proposed at the meeting, and the task force planned to vote on the principles at the NAIC’s Fall National Meeting (we will have an extensive report on activity at the Fall National Meeting in the next week or two). The task force also plans to provide updates regarding next steps and its path forward to execute on its charges in 2026.

After years of work, the Restructuring Mechanisms Working Group recently adopted both a white paper and best practices document related to restructuring mechanisms (namely insurance business transfers and corporate divisions). The latest round of edits reflect changes since the publication of the initial draft white paper. The best practices document will be sent to the Financial Analysis Solvency Tools Working Group (FASTWG) for review and possible inclusion in the Financial Analysis Handbook. Questions remain on whether regulators will be required to use the best practices when reviewing a proposed restructuring transaction. Commissioner Mulready (OK - Chair) opposed making the use of the best practices an accreditation standard.

The Receivership and Insolvency Task Force (RITF) met on December 1 to receive updates on international resolution projects and the uniform data standard (UDS) 3.0. Bob Wake (ME) highlighted the application papers on recovery planning and resolution powers and planning that were exposed following the IAIS Annual Meeting. The IAIS Resolution Working Group has received considerable input from the NAIC on these two papers, and comments are due February 25. Wake also noted that the Financial Stability Board (FSB) has reaffirmed its decision to discontinue its annual identification of global systemically important insurers and instead rely on the IAIS’s Holistic Framework to assess and mitigate systemic risk in the insurance sector (see “IAIS & FSB Updates,” above)

Mike Ulmer (NCIGF) updated task force members on the work of the technical support group that has been developing a more efficient way to transfer data in a receivership. The group is proposing a variable length format designed to future-proof the UDS and is soliciting feedback from technical staff. Finally, Jacob Stuckey (IL - Chair) encouraged states to consider including (1) the continuation of essential services changes to the Holding Company Act and (2) recent cybersecurity and restructuring mechanisms changes to the P&C Guaranty Association Model Act in their next legislative package.

  Staff Contact - Sean McKenna

Privacy Updates

Indiana Attorney General Todd Rokita, in connection with the Indiana Data Privacy & Identity Theft Unit, published a Data Consumer Bill of Rights detailing consumer data rights under the Indiana Consumer Data Protection Act. The Bill of Rights comes ahead of the Act’s January 1, 2026, effective date. While it is focused on the rights of consumers, it notes that the Act generally does not apply to, among others, financial institutions and HIPAA-covered entities.

The Cybersecurity & Infrastructure Security Agency recently released updated guidance on mobile communications best practices. The new guidance provides general protection practices to secure private messaging applications. The updated guidance was crafted in response to identified cyber espionage by the People’s Republic of China that targeted commercial telecommunications infrastructure, as well as other malicious cyber threat actors that targeted encrypted communications of highly targeted individuals, including those in senior government, military, and political positions.

California Attorney General Bonta announced a settlement with Jam City, Inc., resolving alleged violations of the California Consumer Privacy Act for failing to offer consumers methods to opt-out of the sale or sharing of their personal information. Pursuant to the settlement, Jam City will pay $1.4 million in civil penalties, provide methods for consumers to opt out of the sale or sharing of their data, and agree not to sell or share the personal information of consumers between 13 and 16 years old without their affirmative “opt-in” consent.

CalPrivacy issued a decision requiring ROR Partners LLC, a Nevada-based marketing firm, to pay $56,600 in fines and past-due fees for violating California’s Delete Act by failing to register as a data broker. The decision states that a “business cannot bypass the CCPA’s and the Delete Act’s requirements by selling personal information as part of a larger suite of products and services it offers.” In addition to the payment of fines and past-due fees, the decision requires ROR Partners to timely register as a data broker for any future years it operates as a data broker, and to notify CalPrivacy, before the deadline to register as a data broker, if it ceases operating as a data broker.

  Staff Contact - Sean McKenna

© 2001-2025 All Rights Reserved | Terms Of Use | Site Help