Manual evidence gathering breaks when insurers cannot reconstruct a defensible trail from source data to the final report. At that point, the issue is not only efficiency but proof: regulators need to see how each number was validated, transformed, approved, and retained, and a person-driven process is too fragile to guarantee that record.
Where Manual Evidence Gathering Breaks Down
Manual evidence gathering fails when the reporting team can no longer show a clean chain from source systems to the numbers in the Solvency II submission. The problem is not just that the work takes longer, it is that the control evidence becomes fragmented across spreadsheets, emails, and individual judgement, which makes the report hard to defend under regulatory review.
In practice, the weakest point is often traceability. If evidence is assembled after the fact, the team may still produce a filing, but it cannot reliably prove which source extract was used, which adjustment was applied, or why a review step was accepted. That leaves the organisation exposed to challenge even when the final figures are directionally correct.
Manual handling also creates version ambiguity. When several people touch the same evidence pack, the organisation may not know which file is authoritative, whether a supporting schedule changed after approval, or whether a control was performed consistently across quarters. EU Digital Operational Resilience Act (DORA) is relevant here because it reflects the broader expectation that regulated financial firms can evidence resilience, control, and reporting discipline, not just produce an output.
Why the Reporting Control Fails, Not Just the Process
Solvency II reporting depends on repeatability. A defensible process can be rerun, reviewed, and reconstructed, while a manual one often depends on memory and local conventions. That means the control failure is structural: the organisation cannot easily prove that the same rules were applied to the same data every time.
That matters because regulatory reporting is not only about the final number. It is also about the transformation path, the approval trail, the retention of working papers, and the ability to explain exceptions. When those elements live in disconnected human workflows, the reporting control becomes person-dependent instead of system-dependent.
Manual evidence gathering also makes exception handling weaker. Teams may know that a figure was adjusted for a legitimate reason, but unless the rationale is captured in a durable and searchable way, the explanation can disappear between the preparer, reviewer, and approver. EU NIS2 Directive is a useful adjacent reference because it reinforces the importance of governance, access control, and operational discipline when an organisation must prove that its controls are reliable.
What Good Evidence Architecture Must Preserve
A defensible Solvency II evidence chain should preserve four things: source provenance, transformation logic, approval history, and retention. If any one of those is missing, the report may still be deliverable, but the organisation will struggle to demonstrate control integrity during audit or supervisory challenge.
- Source provenance answers where the data came from and when it was extracted.
- Transformation logic shows how raw inputs became reported figures.
- Approval history identifies who reviewed, challenged, and signed off the result.
- Retention ensures the supporting record is still available when it is needed months later.
For teams that still use manual evidence packs, the practical test is whether a reviewer unfamiliar with the quarter could reconstruct the filing from the retained artefacts alone. If the answer is no, the process is not yet strong enough for regulatory-grade reporting. NIST SP 800-53 Rev 5 Security and Privacy Controls is a helpful control lens for this discipline because it maps naturally to auditability, integrity, and controlled handling of reporting evidence.
Risk and Threat Considerations
Manual evidence gathering increases the risk of incomplete, inconsistent, or unverifiable regulatory reporting. The exposure is not only operational, because weak evidence handling can also hide calculation mistakes, unauthorized edits, or late changes that are difficult to detect before submission.
Failure mechanism: evidence is stored in scattered documents and human memory rather than in a controlled record, so the organisation loses reconstruction quality, approval integrity, and reliable retention.
Impact: supervisors may question the accuracy of the filing, require remediation, or treat the reporting process as insufficiently controlled, which can increase remediation cost and undermine trust in the firm’s reporting governance.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while DORA and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| DORA | RC.RP-01 — Recovery Planning | Solvency II evidence failures expose operational resilience gaps in regulated reporting. |
| Recommendation — Test that reporting records and evidence can be reconstructed after disruption. | ||
| NIST SP 800-53 Rev 5 | AU-2 — Event Logging | Manual evidence gathering fails when reporting actions are not logged and traceable. |
| AU-10 — Non-repudiation | A defensible reporting trail requires proof of who approved and changed evidence. | |
| Recommendation — Capture reporting actions, approvals, and changes in auditable records. Use controls that preserve attribution for report preparation and sign-off. | ||
| ISO/IEC 27001:2022 | A.8.15 — Logging | Solvency II reporting needs retained logs and records to support later review. |
| Recommendation — Retain logging and evidence records for reporting processes and approvals. | ||
| NIST CSF 2.0 | GV.OV-01 — Oversight of Risk Management Strategy | Regulatory reporting needs oversight that verifies evidence quality and control performance. |
| Recommendation — Review reporting control outcomes and evidence quality at governance level. | ||
Practitioner Guidance
What to prioritise: start with the controls that make the filing reconstructable. The first objective is not automation for its own sake, but a complete audit trail from source extraction through final approval, with clear ownership for each stage.
What to verify: confirm that every material figure has an attributable source, a documented transformation step, and a retained approval record. If any one of those cannot be produced quickly, the control design is still too dependent on individuals.
Common mistake: treating a completed spreadsheet pack as evidence of control. A pack that can be assembled only by the person who created it is fragile, especially when key staff are absent or the regulator asks for prior-period reconstruction.
Practitioner takeaway: the real breakage point is when the organisation can no longer defend the path to the number, so the control target should be reconstructability first and efficiency second.
Related resources from NHI Mgmt Group
- What breaks when audit prep still depends on manual evidence gathering?
- What breaks when phishing reporting still depends on manual analyst review?
- What breaks when cloud compliance still depends on manual evidence packs?
- What breaks when regulatory reporting still depends on manual processes and legacy data structures?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org