From Manual Attestations to Continuous Controls: Reinsurance Governance Under OSFI B-3
From Manual Attestations to Continuous Controls: Reinsurance Governance Under OSFI B-3
OSFI Guideline B-3 expects reinsurance governance to be demonstrable. A manual attestation signed quarterly proves that someone believed controls operated. A continuous control, running at transaction frequency with automated evidence generation, proves that they did. The shift from attestations to continuous controls is the difference between asserting governance and evidencing it.
Why does OSFI B-3 make manual attestations an insufficient governance tool?
OSFI B-3 makes manual attestations insufficient because the guideline emphasizes that reinsurance governance must be embedded in the firm's operations, not layered on top as a periodic sign-off. Attestations summarize a judgment; they do not produce the evidence that the judgment was based on. Regulators increasingly want to see the evidence, not the summary.
The regulatory direction is consistent across jurisdictions. OSFI B-3, like equivalent guidelines in other regimes, requires insurers to have documented reinsurance policies, risk-management processes, reinsurer due diligence, exposure monitoring, and controls over ceded reinsurance. The guideline does not mention attestations as a preferred control mechanism. It mentions controls that operate, that are tested, and whose effectiveness is reviewed.
A manual attestation process is the organizational equivalent of a quarterly fire drill. Every three months, control owners gather evidence, review spreadsheets, confirm that limits were not breached, treatises were complied with, and reinsurers remained creditworthy, and sign a statement to that effect. The statement goes into a file. The evidence is not retained in a structured form. When the supervisor reviews the file, the firm can show that attestations were signed but cannot show, with transaction-level specificity, that the controls actually operated.
What goes wrong when reinsurance governance depends on periodic manual attestations?
Five failures undermine manual attestation-based governance: attestations that rely on incomplete data, sign-offs made under time pressure without thorough review, exception detection that depends on the reviewer's diligence, evidence that is not retained for future review, and controls that look effective in aggregate but fail at the transaction level. Each failure weakens the governance the attestation was designed to prove.
The attestation model works when controls are simple, transaction volumes are low, and the control environment is stable. It breaks when reinsurance portfolios grow complex, treaties span multiple lines and jurisdictions, transaction volumes increase, and the time available for attestation review remains fixed.
1. Why do attestations rely on incomplete data?
Attestations rely on incomplete data because the control owner reviews what is available, not what is complete. If the exposure report for a specific treaty has not arrived, or the reinsurer's latest financials are not yet published, the attestation is signed on the assumption that the missing data would not have changed the conclusion.
That assumption is the vulnerability. A treaty that breached a limit in a bordereau that arrived late is not captured by the attestation. A reinsurer that was downgraded in the week before the sign-off but whose rating was not yet reflected in the internal system is not flagged. The attestation records a clean review; the underlying condition was not clean, and the data gap is discovered only when it causes a problem.
2. How does time pressure degrade attestation quality?
Time pressure degrades attestation quality because the attestation cycle compresses the review window. The control owner has a day, sometimes hours, to review exposure reports, treaty compliance checks, and reinsurer credit assessments across dozens of treaties before the sign-off deadline.
Under that pressure, the review becomes a scan rather than an analysis. The control owner looks for obvious exceptions and signs. Subtle breaches, slowly deteriorating credit quality, and small limit exceedances pass unnoticed. The attestation is signed, the governance looks effective, and the risk accumulates unseen until the next material event exposes it.
3. What does exception detection by human review miss?
Exception detection by human review misses trends that are visible only across multiple treaties, multiple periods, or multiple data sources. A single treaty exceeding a limit by a small margin may be noticed. A pattern of five treaties each approaching their limit may not be unless the reviewer is specifically looking for the pattern.
Continuous controls catch both. An automated limit check flags the single-treaty breach. An aggregated exposure check flags the five-treaty pattern. The human reviewer, focused on individual treaties and working under deadline, is far less likely to see the pattern that crosses treaties and lines of business.
4. Why does missing evidence weaken the governance record?
Missing evidence weakens the governance record because the supervisor who reviews the attestation file two years later cannot see the data the attestation was based on. The signed statement is present; the spreadsheets and reports that supported it are not. The supervisor cannot assess whether the attestation was well-founded.
Continuous controls solve this by generating evidence automatically. Every control run produces a log: what was checked, what the result was, whether an exception was generated, and what action was taken. The evidence exists independently of the control owner's file management. It is available to the supervisor, the internal auditor, and the board on demand.
5. How do aggregate controls mask transaction-level failures?
Aggregate controls mask transaction-level failures because they check totals, not individual transactions. A treaty-level limit compliance check that compares total ceded premium to the limit may pass while individual bordereaux within the treaty breach sub-limits that the aggregate check does not test.
Continuous controls at the transaction level test every bordereau, every recoverable, every reinsurer credit event against its applicable rule. The aggregate is still checked, but the transaction-level checks catch what the aggregate check cannot see. The granularity of control is what converts governance from an assertion into a demonstrable fact.
Move beyond attestations with Insurnest's continuous controls technology for reinsurance governance
Visit Insurnest to learn how we help cedents, reinsurers, and groups automate treaty compliance, exposure monitoring, and reinsurer oversight under OSFI B-3 and equivalent frameworks.
What do heads of internal audit actually expect from reinsurance governance controls?
Heads of internal audit expect controls that run at the frequency of the underlying risk, that detect exceptions in real time rather than retrospectively, that produce evidence of their own operation, that are independently testable, and that reduce the audit effort required to provide assurance on reinsurance governance.
James is the head of internal audit at a Canadian multiline insurer with a substantial ceded reinsurance program covering property, casualty, and specialty lines. His team audits the reinsurance governance framework annually, testing the design and operating effectiveness of controls over treaty compliance, exposure monitoring, reinsurer due diligence, and ceded premium reconciliation. Every year, the audit findings are the same: controls exist on paper, but the evidence of their operation is inconsistent and incomplete.
The attestation file contains signed quarterly statements from control owners. The supporting evidence varies by quarter and by control owner. Some attach spreadsheets; some attach narrative descriptions; some attach nothing beyond the signature. Testing operating effectiveness requires reconstructing the evidence that should have been present when the attestation was signed, which consumes more than half of the audit's budgeted hours and still produces findings he cannot defend to the audit committee with full confidence.
He wants controls that prove their own operation, that produce a testable evidence trail, and that reduce his team's time on evidence reconstruction and increase it on control design assessment. His asks below define the governance environment he can provide assurance on.
- Controls that run at transaction frequency, not at attestation frequency." "A treaty limit control that checks four times a year leaves nine months of exposure unchecked. A control that runs every time a bordereau is processed checks every transaction. I can provide assurance on the second; I can only report a limitation on the first." Frequency determines the assurance scope.
- Automated exception detection with alert routing." "When a treaty breaches a limit or a reinsurer falls below the credit threshold, the control must detect the breach and alert the responsible person immediately, not at the next quarterly review." Real-time detection converts control from detective to preventative.
- Evidence of control operation generated and retained automatically." "Every control run must produce a log: what was checked, what the result was, and what action was taken if an exception was found. The log is the evidence I test. Without it, I am testing recollections." Evidence automation supports audit testing.
- Independent testability without reliance on control-owner testimony." "I must be able to test whether a control operated by examining the system logs, not by asking the control owner whether they reviewed the right report. If the evidence is only testimonial, I cannot provide positive assurance." System-generated evidence enables objective testing.
- A governance record that demonstrates control design, operation, and exception handling." "The supervisor and the audit committee want to see not only that controls exist but that they operated effectively, that exceptions were handled, and that the control environment improved over time." The full governance narrative requires the full control record.
- Board and audit-committee reporting drawn from control-operation data." "The quarterly governance report to the audit committee should summarize the control environment from the actual control runs: how many checks were performed, how many exceptions were detected, and what was done about them." Data-driven reporting replaces narrative reporting.
- Integration with the three-lines-of-defense model." "Continuous controls are the first line. Risk-based monitoring by the compliance and risk functions is the second line. My audit work is the third line. Each line must have access to the control-operation evidence to perform its role." Control transparency enables the governance model.
- A framework for control-rule maintenance and versioning." "When treaty terms change, the control rules must change. The rule changes must be approved, versioned, and tested. I must be able to see who changed what rule and when." Rule governance is a control in its own right.
- Exception-tracking from detection to resolution." "Every exception must have a lifecycle: detected, assigned, investigated, resolved, or accepted with rationale. An open exception log is a risk register. A closed exception log is governance evidence." Exception management completes the control loop.
- Auditability of historical control states." "When I test the control environment as at a past date, I must be able to see the control rules, the control logs, and the exception records as they existed on that date. The system must preserve point-in-time control state." Temporal auditability supports both internal and external audit.
James frames his business case in audit terms. Continuous controls reduce the audit hours spent on evidence reconstruction. They increase the assurance he can provide on reinsurance governance. They produce findings that are defensible to the audit committee and the regulator. The audit efficiency argument alone justifies the investment.
How can reinsurers build a continuous controls environment under OSFI B-3?
Reinsurers build a continuous controls environment by identifying the governable processes in the reinsurance lifecycle, automating the rule-based checks at transaction frequency, generating control-operation evidence automatically, establishing exception-management workflows, integrating the control environment with the three-lines-of-defense model, and maintaining control rules with version governance.
The transition from manual attestations to continuous controls is a program, not a switch. Each process moved from periodic attestation to automated checking reduces a specific governance risk and generates a specific evidence improvement. The six capabilities below describe the program's components.
1. How does process identification determine the continuous controls scope?
Process identification determines the continuous controls scope by mapping the reinsurance governance framework to the operational processes that execute it. Treaty compliance, exposure monitoring, reinsurer credit surveillance, ceded premium reconciliation, and recoverable aging are the starting set because they involve defined rules and material consequences.
Each process is assessed for control objectives, applicable rules, transaction frequency, and data availability. Processes with clear rules, high transaction volumes, and accessible data are automated first. Processes requiring significant judgment, such as reinsurer due diligence conclusions, are supported by automated data feeds but retain human decision points. The scope is pragmatic: automate what can be automated; structure what requires judgment.
2. Why must control automation run at the frequency of the underlying transaction?
Control automation must run at transaction frequency because the risk the control addresses operates continuously, not quarterly. A treaty limit breach can occur on any day. A reinsurer can be downgraded at any time. A recoverable can age past the collectability threshold between quarterly reviews. Quarterly attestation provides a rear-view assessment; continuous control provides a real-time one.
The shift from periodic to continuous changes the nature of the governance. The control-owner role shifts from periodic reviewer to exception manager. The review of ninety-nine compliant transactions is automated; the management of the one exception is where human attention is directed. The efficiency gain is in both the control's timeliness and the control owner's time allocation.
3. What does automated evidence generation deliver for governance assurance?
Automated evidence generation delivers a complete, consistent, and independent record of every control operation. Every time a control runs, the system logs the control identifier, the data checked, the rule applied, the result, and any exception generated. The log is immutable and retained for the governance record retention period.
This is the capability that directly answers the audit and supervisory expectation. The control does not rely on a person to evidence its operation; the evidence is a by-product of the control's execution. The auditability improvement over manual attestation is categorical. The supervisor reviewing the file two years later sees exactly what the control checked, what it found, and what was done.
4. How does exception-management workflow complete the control loop?
Exception-management workflow completes the control loop by providing a structured path for every control-generated exception: the exception is logged with its source control, assigned to an owner with a resolution deadline, investigated, resolved or accepted with documented rationale, and closed. The open-exception register and the closed-exception history form the governance record of how the firm handled control breaches.
The workflow is what distinguishes an automated control from an automated alert. An alert that arrives in an inbox and is ignored is not governance. A workflow that tracks the exception from detection to resolution, escalates overdue exceptions, and preserves the decision rationale is governance. The workflow structure is as important as the control automation.
5. What does three-lines integration with continuous controls look like?
Three-lines integration with continuous controls means each line of defense has access to the control-operation data it needs. The first line, operational management, sees real-time control results and manages exceptions. The second line, risk and compliance, sees aggregate control-effectiveness metrics and trends. The third line, internal audit, sees the complete control-operation history for testing.
The integration ensures that continuous controls operate within the existing governance model rather than alongside it. The controls are the first line's tools. The risk and compliance monitoring of control effectiveness is the second line's activity. The audit testing of control design and operation is the third line's. Each line's assurance work is informed by the same control-operation evidence.
6. How does control-rule maintenance with version governance sustain the environment?
Control-rule maintenance with version governance sustains the environment by ensuring that control rules are updated when treaty terms change, regulatory thresholds are revised, or business policies are amended. Every rule change is proposed, approved, tested, and versioned, and the change history is preserved for audit review.
Without version governance, control rules drift. A treaty limit that was changed at renewal but not updated in the control engine produces false exceptions or, worse, missed breaches. Rule maintenance is the discipline that keeps the control environment aligned with the business it governs, and the version governance is the evidence that the alignment is actively managed.
Transform reinsurance governance with Insurnest's continuous controls platform
Visit Insurnest to see how we help reinsurers, cedents, and groups automate treaty compliance, exposure monitoring, and governance controls under OSFI B-3 and equivalent frameworks.
What does an ideal continuous controls environment look like under OSFI B-3?
An ideal continuous controls environment operates at transaction frequency on every governable reinsurance process, generates evidence automatically, routes exceptions through structured resolution workflows, feeds control-effectiveness metrics to the second line and the board, and provides a complete, testable control-operation history to the third line and the supervisor.
In James's ideal environment, the quarterly audit of reinsurance governance begins differently. His team no longer requests attestation files and supporting evidence from control owners. Instead, they access the continuous-controls system and examine the control-operation logs for the audit period. Every control run is logged. Every exception is tracked. Every rule change is versioned. The testing of design effectiveness examines the control rules. The testing of operating effectiveness examines the control logs. Both tests are completed in less than half the hours the old attestation-based audit required.
The audit findings are different too. Instead of reporting limitations on evidence availability, the audit reports specific control exceptions with the firm's documented resolution. The audit committee receives a summary of control effectiveness drawn from system data, not from management's narrative account. The supervisor's review of the reinsurance governance file is efficient and raises no questions about whether the controls actually operated.
The governance improvement extends beyond the audit. The control owners, freed from the quarterly attestation scramble, direct their time to the exceptions that matter. The risk function analyzes control-effectiveness trends and identifies processes where the control rules need refinement. The board sees a governance report that is evidence-based, not assertion-based. The firm's reinsurance governance has moved from periodic belief to continuous proof.
Make reinsurance governance demonstrable with Insurnest's continuous controls technology
Visit Insurnest to learn how we help reinsurance organizations build automated control environments that prove governance.
Conclusion
For Canadian insurers and reinsurers operating under OSFI B-3, the regulatory direction is clear. Governance must be demonstrable, not merely documented. Manual attestations, signed quarterly and stored in policy files, are the minimum standard, and the minimum is increasingly insufficient as supervisors expect evidence of control operation rather than assertions about it.
Continuous controls, running at transaction frequency on treaty compliance, exposure monitoring, reinsurer credit surveillance, and ceded-premium processes, convert governance from a periodic administrative exercise into an embedded operational capability. The evidence they generate satisfies the supervisor, the internal auditor, and the board with a consistency that attestations cannot match.
For heads of internal audit, chief risk officers, and compliance leads, the transition path is defined. Identify the governable processes. Automate the rule-based checks. Build the evidence generation. Establish the exception-management workflow. Integrate with the three lines. Maintain the control rules. The supervisor will review the governance file. The firm's response should be a complete control-operation history, not a folder of signed attestations.
Frequently asked questions
What does OSFI B-3 require for reinsurance governance?
OSFI B-3 requires insurers to have a board-approved reinsurance policy, documented risk-management processes, due diligence on reinsurers, exposure monitoring, and controls over ceded reinsurance. The guideline emphasizes that governance must be demonstrable, not merely stated.
Why are manual attestations no longer sufficient for reinsurance governance?
Manual attestations prove that someone signed a statement, not that a control operated. Regulators expect evidence of operation, not periodic assertions that controls exist. Attestations are the weakest form of control evidence.
What is the difference between a manual attestation and a continuous control?
A manual attestation is a periodic signed statement of compliance. A continuous control is an automated check that runs at transaction frequency, detects exceptions in real time, and proves its own operation.
Which reinsurance processes benefit most from continuous controls?
Treaty compliance checks, exposure-limit monitoring, reinsurer credit-quality surveillance, ceded premium reconciliation, and recoverable aging all benefit because they involve high transaction volumes, defined rules, and material consequences for breaches.
How does OSFI B-3 guidance address outsourced reinsurance functions?
OSFI expects the cedent to retain accountability for outsourced reinsurance activities, to monitor the service provider's performance, and to have controls over the accuracy and completeness of the data received from the provider.
What evidence of control operation does a regulator expect under B-3?
Regulators expect to see that controls ran at the designed frequency, that exceptions were detected and escalated, that remediation actions were taken and tracked, and that the control environment was reviewed periodically for effectiveness.
How does continuous controls monitoring reduce attestation fatigue?
Continuous controls replace periodic reviews with automated checks. Individuals who previously spent days assembling attestation evidence instead review exception reports, focusing time on genuine issues rather than routine verification.
Can continuous controls coexist with existing governance frameworks?
Yes. Continuous controls can be embedded within the existing three-lines-of-defense model, with automated checks forming the first line, risk-based monitoring forming the second, and audit review of control design and operation forming the third.
About the author
Hitul Mistry is the Founder of Insurnest, an InsurTech company that engineers end-to-end technology exclusively for the insurance industry serving carriers, TPAs, MGAs, brokers, and reinsurers across India, the UAE, and the US. With more than a decade of insurance domain experience, he has built systems spanning underwriting automation, AI-powered underwriting intelligence, claims management, rating and quoting, broking and agency platforms, and reinsurance automation across Health/GMC, Group Life, Motor, P&C, and Reinsurance. Insurnest doesn't adapt generic software to insurance; it builds from the workflow up.
Connect with Hitul on LinkedIn.