You are reading Part 9 of our 12-part Insurance Agency Authority Series.
Insurance agencies should prepare for compliance reviews and security audits by documenting policies, validating technical controls, organizing evidence, reviewing user access, testing backups, and assigning clear ownership. For agencies with 15 to 30 employees, preparation should begin before a questionnaire or audit notice arrives. A practical process includes a risk review, control validation, evidence collection, remediation, and leadership approval. Regulatory compliance cannot be proven by saying that security tools are installed. The agency must be able to show that controls are active, monitored, reviewed, and supported by documented procedures.
The 5-Stage Compliance Readiness Framework
Insurance agencies should prepare through five stages:
- Identify requirements
- Validate controls
- Collect evidence
- Correct gaps
- Maintain readiness
This process reduces last-minute confusion and improves the accuracy of responses.
Stage 1 – Identify the Applicable Requirements
The agency should determine who is requesting the review and what standard applies.
Requests may come from:
- Regulators
- Cyber insurance carriers
- Business partners
- Clients
- Vendors
- Legal counsel
- Internal leadership
- Acquisition partners
- Industry associations
The agency should ask:
- What information is being requested?
- What deadline applies?
- Is the request legal, contractual, insurance-related, or internal?
- Which systems and offices are in scope?
- What evidence is acceptable?
- Who is responsible for each answer?
Cyber insurance requirements and regulatory compliance may overlap, but they are not identical.
Stage 2 – Validate Technical Controls
The agency should verify that technical controls are operating as described.
Common review areas include:
- MFA
- Microsoft 365 security
- EDR
- Antivirus
- Patch management
- Backups
- Email security
- Security awareness training
- Administrative access
- User onboarding and offboarding
- Remote access
- Firewalls
- Logging
- Incident response
- Vendor access
Validation should include the actual environment.
For example:
- Confirm every user is covered by MFA
- Confirm every managed endpoint has EDR
- Review backup results
- Test file recovery
- Review former employee accounts
- Confirm security training completion
- Check administrative roles
- Review mailbox forwarding rules
- Identify unsupported systems
Stage 3 – Collect Evidence
Evidence may include:
- Policy documents
- Screenshots
- Security reports
- Backup reports
- Training records
- Asset inventories
- User access reviews
- Incident response plans
- Vendor contracts
- Ticket history
- Audit logs
- Patch compliance reports
- Penetration test results
- Risk assessments
- Leadership approvals
The evidence should be current, organized, and understandable.
A screenshot without context may not be enough.
The agency should label:
- What the evidence proves
- Which system it applies to
- When it was collected
- Who reviewed it
- Which requirement it supports
Stage 4 – Correct Gaps
The review may identify:
- Missing MFA
- Unsupported operating systems
- Weak email protection
- Incomplete documentation
- Backup failures
- Old user accounts
- Excessive administrative access
- Inconsistent patching
- No incident response plan
- Missing employee training
- Unreviewed vendor access
The agency should rank gaps by:
- Business risk
- Compliance impact
- Security impact
- Time required
- Cost
- Dependency on vendors
Not every gap can be fixed immediately.
Leadership should understand which risks remain and document accepted risk where appropriate.
Stage 5 – Maintain Continuous Readiness
Compliance should not be treated as a once-a-year project.
A continuous process may include:
- Monthly service audits
- Quarterly access reviews
- Annual policy review
- Regular backup testing
- Ongoing security training
- Patch review
- Incident response exercises
- Vendor reviews
- Security control reporting
- Leadership updates
Continuous readiness makes future questionnaires easier and improves actual security.
Microsoft 365 Evidence
Microsoft 365 is often central to a compliance review.
The agency may need to demonstrate:
- MFA enforcement
- Conditional access
- Administrative account separation
- Login monitoring
- Mailbox auditing
- External sharing controls
- User offboarding
- Security alert handling
Microsoft 365 security controls should be documented clearly enough that an auditor can understand how identities, email, and cloud data are protected.
Essentials, Complete, and Compliance
The Essentials package protects devices and data through:
- Antivirus
- EDR
- Unified device backup
- Datto SaaS Protection where applicable
The Complete package adds:
- Inky email security
- BullPhish ID training
- Dark Web ID monitoring
- SaaS Alerts
- Microsoft 365 management
The Complete package is the standard recommendation for most organizations because compliance reviews frequently examine user, identity, email, and cloud risks.
The Essentials and Complete security packages address different control areas, and insurance agencies should understand which package supports their audit requirements.
The Role of Compliance Manager
Compliance Manager may be offered separately.
It may help organize:
- Requirements
- Policies
- Control mappings
- Evidence
- Risk items
- Remediation tasks
- Reporting
If the agency declines Compliance Manager, the associated risk and responsibility should be acknowledged.
A managed services agreement can support technical readiness, but compliance work may require additional tools, documentation, and outside legal or regulatory guidance.
The Role of Penetration Testing
A third-party penetration test may identify weaknesses that routine monitoring does not reveal.
West Texas IT Consulting offers third-party penetration testing through Vonahi as an a la carte service.
Testing may help evaluate:
- External exposure
- Internal vulnerabilities
- Weak credentials
- Misconfigurations
- Network segmentation
- Attack paths
A penetration test is not the same as antivirus, EDR, or vulnerability scanning.
The agency should understand the scope and purpose before deciding whether to accept or decline the service.
Example – Preparing for a Security Questionnaire
A 20-employee agency in Odessa receives a questionnaire from a business partner with a 30-day deadline.
The questionnaire asks about:
- MFA
- Backups
- EDR
- Employee training
- Incident response
- Vendor management
- Data encryption
- Access reviews
The agency initially plans to answer based on assumptions.
Instead, leadership and the IT provider validate each control.
They discover:
- MFA is missing on one shared account
- Two devices are not reporting to EDR
- Backup reports are current
- Training records are incomplete
- The incident response plan lists a former employee
- Vendor access has not been reviewed
The remediation plan includes:
- Remove the shared account
- Restore EDR coverage
- Complete training
- Update the incident response plan
- Review vendors
- Organize evidence
- Submit accurate answers
The agency completes the questionnaire with greater confidence and a stronger environment.
Common Audit Preparation Mistakes
Avoid:
Waiting for the Request
Preparation should be ongoing.
Answering Without Validation
Assumptions create inaccurate responses.
Treating Tools as Proof
A license does not prove the control is active.
Ignoring User Access
Old accounts and excessive privileges create risk.
Failing to Test Backups
A successful backup job does not prove recoverability.
Using Outdated Policies
Documents should match current operations.
Hiding Known Gaps
Leadership should understand and document remaining risk.
Treating Compliance as an IT-Only Responsibility
Compliance requires leadership, legal, operations, HR, vendors, and technical support.
What Should a Strong Audit File Include?
A centralized audit file may contain:
- Current policies
- Asset inventory
- Network documentation
- Microsoft 365 reports
- MFA evidence
- EDR coverage reports
- Patch reports
- Backup reports
- Recovery test records
- Training records
- Incident response plan
- Vendor list
- Insurance information
- Penetration test results
- Risk register
- Remediation plan
- Leadership approval
The file should be reviewed on a regular schedule.
How to Prepare 90 Days Before a Review
Days 90-61
- Identify requirements
- Assign owners
- Review prior findings
- Collect existing documentation
- Confirm scope
Days 60-31
- Validate controls
- Test backups
- Review user access
- Confirm EDR and patching
- Update policies
- Begin remediation
Days 30-1
- Collect final evidence
- Review answers
- Document exceptions
- Confirm approvals
- Submit materials
- Preserve a copy
- Add Text here
Compliance Reviews and Legacy Technology
Unsupported systems can create audit findings because they may lack:
- Security updates
- Current encryption
- Vendor support
- Modern logging
- Compatible security tools
- Reliable recovery options
Legacy technology can make compliance reviews more difficult because unsupported systems often cannot meet current security expectations.
Questions to Ask Your IT Provider
Ask:
- Which controls are included in the agreement?
- Which compliance services are separate?
- Can you provide evidence of MFA and EDR coverage?
- How are backups validated?
- How often are audits performed?
- How are policies maintained?
- How are former users removed?
- How is vendor access documented?
- Is penetration testing available?
- Is Compliance Manager available?
- How are risks accepted or declined?
- Who owns the final compliance decision?
Compliance Readiness Checklist
Confirm:
- Requirements are identified
- Scope is documented
- Owners are assigned
- MFA is enforced
- EDR coverage is complete
- Patching is current
- Backups are monitored
- Recovery is tested
- Microsoft 365 controls are documented
- Employee training is current
- Access reviews are complete
- Policies reflect current operations
- Incident response is current
- Vendor access is reviewed
- Evidence is organized
- Remaining risks are documented
Conclusion
Insurance agencies should prepare for compliance reviews by validating controls, organizing evidence, correcting gaps, and maintaining readiness throughout the year. A successful review depends on accurate answers and proof that the environment is actively managed.
For agencies in Midland, Odessa, Abilene, San Angelo, and the surrounding Permian Basin, a structured readiness process can reduce audit stress, improve security, and create clearer accountability.
Learn how managed services can support control validation, documentation, monitoring, and ongoing compliance readiness.


