Business colleagues reviewing documents and laptop data together during a compliance meeting at a conference table.

How Can Insurance Agencies Prepare for Compliance Reviews and Security Audits?

by | Aug 2, 2026

Insurance agencies should prepare for compliance reviews and security audits by documenting policies, validating technical controls, organizing evidence, reviewing user access, testing backups, and assigning clear ownership. For agencies with 15 to 30 employees, preparation should begin before a questionnaire or audit notice arrives. A practical process includes a risk review, control validation, evidence collection, remediation, and leadership approval. Regulatory compliance cannot be proven by saying that security tools are installed. The agency must be able to show that controls are active, monitored, reviewed, and supported by documented procedures.


The 5-Stage Compliance Readiness Framework

Insurance agencies should prepare through five stages:

  1. Identify requirements

  2. Validate controls

  3. Collect evidence

  4. Correct gaps

  5. Maintain readiness

This process reduces last-minute confusion and improves the accuracy of responses.


Stage 1 – Identify the Applicable Requirements

The agency should determine who is requesting the review and what standard applies.
Requests may come from:

  • Regulators

  • Cyber insurance carriers

  • Business partners

  • Clients

  • Vendors

  • Legal counsel

  • Internal leadership

  • Acquisition partners

  • Industry associations

The agency should ask:

  • What information is being requested?

  • What deadline applies?

  • Is the request legal, contractual, insurance-related, or internal?

  • Which systems and offices are in scope?

  • What evidence is acceptable?

  • Who is responsible for each answer?

Cyber insurance requirements and regulatory compliance may overlap, but they are not identical.


Stage 2 – Validate Technical Controls

The agency should verify that technical controls are operating as described.
Common review areas include:

  • MFA

  • Microsoft 365 security

  • EDR

  • Antivirus

  • Patch management

  • Backups

  • Email security

  • Security awareness training

  • Administrative access

  • User onboarding and offboarding

  • Remote access

  • Firewalls

  • Logging

  • Incident response

  • Vendor access

Validation should include the actual environment.
For example:

  • Confirm every user is covered by MFA

  • Confirm every managed endpoint has EDR

  • Review backup results

  • Test file recovery

  • Review former employee accounts

  • Confirm security training completion

  • Check administrative roles

  • Review mailbox forwarding rules

  • Identify unsupported systems


Stage 3 – Collect Evidence

Evidence may include:

  • Policy documents

  • Screenshots

  • Security reports

  • Backup reports

  • Training records

  • Asset inventories

  • User access reviews

  • Incident response plans

  • Vendor contracts

  • Ticket history

  • Audit logs

  • Patch compliance reports

  • Penetration test results

  • Risk assessments

  • Leadership approvals

The evidence should be current, organized, and understandable.
A screenshot without context may not be enough.
The agency should label:

  • What the evidence proves

  • Which system it applies to

  • When it was collected

  • Who reviewed it

  • Which requirement it supports


Stage 4 – Correct Gaps

The review may identify:

  • Missing MFA

  • Unsupported operating systems

  • Weak email protection

  • Incomplete documentation

  • Backup failures

  • Old user accounts

  • Excessive administrative access

  • Inconsistent patching

  • No incident response plan

  • Missing employee training

  • Unreviewed vendor access

The agency should rank gaps by:

  • Business risk

  • Compliance impact

  • Security impact

  • Time required

  • Cost

  • Dependency on vendors

Not every gap can be fixed immediately.
Leadership should understand which risks remain and document accepted risk where appropriate.


Stage 5 – Maintain Continuous Readiness

Compliance should not be treated as a once-a-year project.
A continuous process may include:

  • Monthly service audits

  • Quarterly access reviews

  • Annual policy review

  • Regular backup testing

  • Ongoing security training

  • Patch review

  • Incident response exercises

  • Vendor reviews

  • Security control reporting

  • Leadership updates

Continuous readiness makes future questionnaires easier and improves actual security.


Microsoft 365 Evidence

Microsoft 365 is often central to a compliance review.
The agency may need to demonstrate:

  • MFA enforcement

  • Conditional access

  • Administrative account separation

  • Login monitoring

  • Mailbox auditing

  • External sharing controls

  • User offboarding

  • Security alert handling

Microsoft 365 security controls should be documented clearly enough that an auditor can understand how identities, email, and cloud data are protected.


Essentials, Complete, and Compliance

The Essentials package protects devices and data through:

  • Antivirus

  • EDR

  • Unified device backup

  • Datto SaaS Protection where applicable

The Complete package adds:

  • Inky email security

  • BullPhish ID training

  • Dark Web ID monitoring

  • SaaS Alerts

  • Microsoft 365 management

The Complete package is the standard recommendation for most organizations because compliance reviews frequently examine user, identity, email, and cloud risks.
The Essentials and Complete security packages address different control areas, and insurance agencies should understand which package supports their audit requirements.


The Role of Compliance Manager

Compliance Manager may be offered separately.
It may help organize:

  • Requirements

  • Policies

  • Control mappings

  • Evidence

  • Risk items

  • Remediation tasks

  • Reporting

If the agency declines Compliance Manager, the associated risk and responsibility should be acknowledged.
A managed services agreement can support technical readiness, but compliance work may require additional tools, documentation, and outside legal or regulatory guidance.


The Role of Penetration Testing

A third-party penetration test may identify weaknesses that routine monitoring does not reveal.
West Texas IT Consulting offers third-party penetration testing through Vonahi as an a la carte service.
Testing may help evaluate:

  • External exposure

  • Internal vulnerabilities

  • Weak credentials

  • Misconfigurations

  • Network segmentation

  • Attack paths

A penetration test is not the same as antivirus, EDR, or vulnerability scanning.
The agency should understand the scope and purpose before deciding whether to accept or decline the service.


Example – Preparing for a Security Questionnaire

A 20-employee agency in Odessa receives a questionnaire from a business partner with a 30-day deadline.
The questionnaire asks about:

  • MFA

  • Backups

  • EDR

  • Employee training

  • Incident response

  • Vendor management

  • Data encryption

  • Access reviews

The agency initially plans to answer based on assumptions.
Instead, leadership and the IT provider validate each control.
They discover:

  • MFA is missing on one shared account

  • Two devices are not reporting to EDR

  • Backup reports are current

  • Training records are incomplete

  • The incident response plan lists a former employee

  • Vendor access has not been reviewed

The remediation plan includes:

  • Remove the shared account

  • Restore EDR coverage

  • Complete training

  • Update the incident response plan

  • Review vendors

  • Organize evidence

  • Submit accurate answers

The agency completes the questionnaire with greater confidence and a stronger environment.


Common Audit Preparation Mistakes

Avoid:
Waiting for the Request
Preparation should be ongoing.
Answering Without Validation
Assumptions create inaccurate responses.
Treating Tools as Proof
A license does not prove the control is active.
Ignoring User Access
Old accounts and excessive privileges create risk.
Failing to Test Backups
A successful backup job does not prove recoverability.
Using Outdated Policies
Documents should match current operations.
Hiding Known Gaps
Leadership should understand and document remaining risk.
Treating Compliance as an IT-Only Responsibility
Compliance requires leadership, legal, operations, HR, vendors, and technical support.


What Should a Strong Audit File Include?

A centralized audit file may contain:

  • Current policies

  • Asset inventory

  • Network documentation

  • Microsoft 365 reports

  • MFA evidence

  • EDR coverage reports

  • Patch reports

  • Backup reports

  • Recovery test records

  • Training records

  • Incident response plan

  • Vendor list

  • Insurance information

  • Penetration test results

  • Risk register

  • Remediation plan

  • Leadership approval

The file should be reviewed on a regular schedule.


How to Prepare 90 Days Before a Review

Days 90-61

  • Identify requirements

  • Assign owners

  • Review prior findings

  • Collect existing documentation

  • Confirm scope

Days 60-31

  • Validate controls

  • Test backups

  • Review user access

  • Confirm EDR and patching

  • Update policies

  • Begin remediation

Days 30-1

  • Collect final evidence

  • Review answers

  • Document exceptions

  • Confirm approvals

  • Submit materials

  • Preserve a copy
  • Add Text here


Compliance Reviews and Legacy Technology

Unsupported systems can create audit findings because they may lack:

  • Security updates

  • Current encryption

  • Vendor support

  • Modern logging

  • Compatible security tools

  • Reliable recovery options

Legacy technology can make compliance reviews more difficult because unsupported systems often cannot meet current security expectations.


Questions to Ask Your IT Provider

Ask:

  • Which controls are included in the agreement?

  • Which compliance services are separate?

  • Can you provide evidence of MFA and EDR coverage?

  • How are backups validated?

  • How often are audits performed?

  • How are policies maintained?

  • How are former users removed?

  • How is vendor access documented?

  • Is penetration testing available?

  • Is Compliance Manager available?

  • How are risks accepted or declined?

  • Who owns the final compliance decision?


Compliance Readiness Checklist

Confirm:

  • Requirements are identified

  • Scope is documented

  • Owners are assigned

  • MFA is enforced

  • EDR coverage is complete

  • Patching is current

  • Backups are monitored

  • Recovery is tested

  • Microsoft 365 controls are documented

  • Employee training is current

  • Access reviews are complete

  • Policies reflect current operations

  • Incident response is current

  • Vendor access is reviewed

  • Evidence is organized

  • Remaining risks are documented


Conclusion

Insurance agencies should prepare for compliance reviews by validating controls, organizing evidence, correcting gaps, and maintaining readiness throughout the year. A successful review depends on accurate answers and proof that the environment is actively managed.
For agencies in Midland, Odessa, Abilene, San Angelo, and the surrounding Permian Basin, a structured readiness process can reduce audit stress, improve security, and create clearer accountability.
Learn how managed services can support control validation, documentation, monitoring, and ongoing compliance readiness.

Ready to Talk About Your IT?

If you’re running a company or organization in the Permian Basin and want IT that actually understands your environment, we’d be happy to talk!