insurance-compliance
Validate insurance agency workflows against state insurance department requirements and NAIC model laws. Use when designing a workflow for a new state market or when conducting a compliance review of existing agency operations.
What this skill does
# Insurance Agency Compliance Checklist Validate insurance agency workflows against state insurance department (DOI) requirements and applicable NAIC model laws. This skill produces a compliance checklist organized by regulatory domain, with specific statutory or regulatory citation for each requirement. ## Inputs Required Before running this checklist, identify: - States of operation (resident state + all non-resident states) - Lines of business placed (personal auto, homeowners, commercial, GL, professional liability, workers comp, life, surplus lines, etc.) - Entity type (agency / MGA / TPA / carrier) - Whether surplus lines authority is held --- ## Section 1: Producer Licensing **Resident license requirements:** - [ ] Agency holds a valid resident insurance agency license in the state of domicile - [ ] All licensed producers have current individual resident licenses in their resident state - [ ] Lines of authority match the lines of business being transacted (cannot place beyond licensed LOB) - [ ] License expiration dates tracked with renewal alerts at 90 and 30 days before expiration - [ ] License numbers on file and searchable in AMS for each producer **Non-resident license requirements:** - [ ] Non-resident licenses obtained for each state where the agency transacts business - [ ] Non-resident license in each state covers all LOBs transacted in that state - [ ] Reciprocity rules applied: verify each state recognizes resident state's license - [ ] Non-resident license applications filed within state-required window when business commences - [ ] Non-resident licenses renewed timely (renewal dates tracked by state) **Continuing education (CE):** - [ ] CE requirements tracked per producer per state - [ ] CE completion documented before each license renewal - [ ] Ethics CE requirements met (most states require 3+ hours of ethics per cycle) - [ ] Flood insurance CE met if placing NFIP policies (6 hours per FEMA requirement) - [ ] CE records maintained for [N] years (varies by state; use most conservative) **Citation framework:** NAIC Producer Licensing Model Act (adopted in modified form by most states); each state's insurance code Chapter on producer licensing (e.g., Texas Insurance Code §4001; California Insurance Code §1625). --- ## Section 2: Surplus Lines Compliance *(Skip if agency does not hold surplus lines authority)* **Diligent search requirements:** - [ ] At least [N] admitted carrier declinations documented for each surplus lines risk (number varies by state: TX = 1, CA = 3, FL = 3, NY = 3) - [ ] Declinations documented with: carrier name, date of declination, reason (or "unable to quote") - [ ] Diligent search conducted by licensed surplus lines agent (not the standard resident agent) - [ ] Written documentation of search maintained in file **Filing and stamping requirements:** - [ ] Surplus lines affidavit prepared for each placement - [ ] Affidavit filed with the appropriate stamping office (ELANY for NY; SLTX for TX; FSLSO for FL; other states vary) - [ ] Stamping fees paid and included in premium remittance - [ ] Stamping office confirmation receipt stored in client file **Premium tax:** - [ ] Surplus lines premium tax calculated at correct state rate (varies: typically 2–5%) - [ ] Premium tax paid to state within filing deadline (typically 30–60 days of policy effective) - [ ] Surplus lines agent is responsible for premium tax remittance (not the insured) **Insured disclosure:** - [ ] Signed disclosure to insured that: policy is placed with a non-admitted carrier; the carrier is not subject to state licensing regulation; the policy is NOT covered by the state guaranty fund - [ ] Disclosure language meets state-specific requirements (some states have prescribed language) - [ ] Disclosure obtained before binding **Citation framework:** NAIC Non-Admitted Insurance Model Act; each state's surplus lines chapter (e.g., Texas Insurance Code Chapter 981; California Insurance Code §1760 et seq.; New York Insurance Law Article 21). --- ## Section 3: Client Disclosure Requirements **Required disclosures at point of sale (varies by state and LOB):** - [ ] **Privacy Notice (GLBA):** Delivered at inception and annually; describes information sharing practices - [ ] **MAIP/FAIR Plan eligibility:** If declining personal lines risk, disclose availability of assigned risk plan or FAIR plan in states that require it - [ ] **Coverage summary:** Some states require a written coverage summary at delivery of policy - [ ] **Claims process notice:** Some states require written notice at inception of how to file a claim - [ ] **Flood insurance disclosure:** Required for property owners in flood zones; must offer NFIP or private flood and document declination if not purchased **Auto-specific disclosures (personal lines):** - [ ] Named operator exclusion disclosure (if applicable — state law determines when permitted) - [ ] Uninsured/underinsured motorist coverage offered and acknowledged (most states require written declination if UM/UIM not purchased) - [ ] Medical payments coverage offered and acknowledged (some states) - [ ] PIP requirements met (no-fault states) **Commercial lines disclosures:** - [ ] Risk management and loss control recommendations documented where provided - [ ] Cyber liability exposure discussion if not placing cyber coverage **Citation framework:** NAIC Privacy of Consumer Financial and Health Information Model Regulation; state unfair trade practices acts; each state's auto insurance disclosure requirements. --- ## Section 4: Privacy Compliance **GLBA Safeguards Rule:** - [ ] Written information security program (WISP) in place and reviewed annually - [ ] WISP designates a qualified individual responsible for information security - [ ] Risk assessment of foreseeable threats to customer information conducted - [ ] Safeguards implemented: access controls, encryption in transit and at rest, MFA for systems with customer data, vendor oversight, incident response - [ ] Service provider contracts include data protection requirements - [ ] Employee training on information security conducted annually **State privacy laws:** - [ ] CCPA/CPRA compliance if California residents are customers (see gdpr-review skill for detail) - [ ] State-specific privacy laws identified for each state of operation - [ ] Privacy notice updated to reflect current data sharing practices **Data breach notification:** - [ ] Written breach response plan in place - [ ] Notification trigger: unauthorized acquisition of customer personal information - [ ] Notification timing: state laws vary — 30 to 90 days; use most restrictive (30 days if multi-state) - [ ] Required notifications: affected individuals, state attorney general (some states), state DOI (some states), FTC (if >500 records) - [ ] Substitute notice procedures defined if direct notice is not feasible **Citation framework:** Gramm-Leach-Bliley Act; FTC Safeguards Rule (16 CFR Part 314, amended 2023); NAIC Insurance Data Security Model Law (adopted in 22+ states); state-specific notification statutes. --- ## Section 5: Claims Handling Regulations **Prompt payment laws (applies to carriers; agency should monitor for carrier compliance):** | State | Acknowledge Receipt | Accept or Deny | Pay After Acceptance | |-------|--------------------|-----------------|--------------------| | Texas | 15 business days | 15 business days | 5 business days | | California | 10 calendar days | 40 days | 30 days after proof of loss | | Florida | 14 days | 90 days | 20 days after agreement | | New York | [State-specific] | [State-specific] | [State-specific] | *(Complete this table for each state of operation — requirements vary significantly)* **Agency obligations in claims handling:** - [ ] Agency reports FNOL to carrier within [N] hours of receipt - [ ] Agency maintains copy of FNOL in client file with date/time stamp - [ ] Agency does not make coverage determinations on behalf of the car
Related in Code Review
gstack
IncludedFast headless browser for QA testing and site dogfooding. Navigate pages, interact with elements, verify state, diff before/after, take annotated screenshots, test responsive layouts, forms, uploads, dialogs, and capture bug evidence. Use when asked to open or test a site, verify a deployment, dogfood a user flow, or file a bug with screenshots. (gstack)
startup-due-diligence
IncludedLegal due diligence review for seed-stage and Series A startups (US, Delaware C-Corp focus). Supports both investor and founder perspectives. Capabilities include: (1) Interactive document review and issue spotting; (2) Document request list generation; (3) Cap table and SAFE/convertible note analysis; (4) Red flag identification with severity ratings; (5) Diligence report generation. TRIGGERS: due diligence, DD, startup investment, cap table review, Series A, seed round, investor diligence, legal review startup, SAFE analysis, convertible note, 409A, founder vesting.
interview-master
IncludedThis skill should be used when the user asks to "generate interview questions", "prepare for interview", "optimize resume", "conduct mock interview", "analyze git commits for resume", "generate resume from code", "review my resume", or mentions interview preparation, career assistance, or extracting project experience from git history. Provides comprehensive interview and career development guidance for both job seekers and interviewers.
fix-issue
IncludedFixes GitHub issues using parallel analysis agents for root cause investigation, code exploration, and regression detection. Reads issue context from gh CLI, searches codebase and memory for related patterns, generates a fix with tests, and links the resolution back to the issue via PR. Includes prevention analysis to avoid recurrence. Use when debugging errors, resolving regressions, fixing bugs, or triaging issues.
sf-apex
IncludedGenerates and reviews Salesforce Apex code with 150-point scoring. TRIGGER when: user writes, reviews, or fixes Apex classes, triggers, test classes, batch/queueable/schedulable jobs, or touches .cls/.trigger files. DO NOT TRIGGER when: LWC JavaScript (use sf-lwc), Flow XML (use sf-flow), SOQL-only queries (use sf-soql), or non-Salesforce code.
swift-development
IncludedComprehensive Swift development for building, testing, and deploying iOS/macOS applications. Use when Claude needs to: (1) Build Swift packages or Xcode projects from command line, (2) Run tests with XCTest or Swift Testing framework, (3) Manage iOS simulators with simctl, (4) Handle code signing, provisioning profiles, and app distribution, (5) Format or lint Swift code with SwiftFormat/SwiftLint, (6) Work with Swift Package Manager (SPM), (7) Implement Swift 6 concurrency patterns (async/await, actors, Sendable), (8) Create SwiftUI views with MVVM architecture, (9) Set up Core Data or SwiftData persistence, or any other Swift/iOS/macOS development tasks.