Latest News

Pinpoint Delivers Public Comment at NAIC Credit Rating Provider Working Group

This afternoon, Pinpoint Policy Institute Executive Director Eric Ventimiglia delivered remarks before the NAIC Credit Rating Provider (E) Working Group, at NAIC’s Summer National Meeting in Columbus, Ohio. His comments raise three core concerns with the Working Group’s proposed CRP Framework: legal authority, procedural safeguards, and data security, and called on the NAIC to pause and redesign the process prior to adoption.

The full text of his remarks is below.

Good afternoon, Chair Garn, Vice Chair Clements, and members of the Working Group. My name is Eric Ventimiglia, Executive Director of Pinpoint Policy Institute, a nonpartisan, pro-growth 501(c)(4) organization. I submitted written comments on July 3rd and appreciate the chance to address you directly today.

The Working Group’s underlying objective — confidence in the tools used to assign regulatory capital treatment to insurer investments — is legitimate. Pinpoint does not dispute that goal. We dispute whether this Framework, as designed, is the right vehicle.

Our written comments identify three independent defects. I’ll touch on each briefly.

First: the Framework assumes authority Congress withheld from even the SEC. Section 15E(c)(2) of the Exchange Act provides that neither the SEC nor any state may regulate the substance of credit ratings or the methodologies by which a nationally recognized statistical rating organization determines them. The Framework’s Section 3.2.1 proposes methodology walkthroughs, security-specific rating reviews, and NAIC judgments about the reasonableness of a CRP’s methodology. Labeling this “due diligence” does not change its substance.

That problem is compounded by undefined terms: “reasonable,” “material,” “equivalent,” “systematic disagreement.” When stakeholders asked the NAIC to define these, it declined, citing a need to preserve flexibility. A framework that can result in CRP de-admittance or asset class removal, while avoiding definitions for its own triggering standards, is not a framework. It is unchecked discretion.

Second: the Framework lacks the procedural safeguards that decisions with market-wide consequences demand. The Framework conflates five distinct objectives: rating equivalency, reasonableness, process integrity, investment risk, and consistency across CRPs. These require different analytical approaches and may lead to different outcomes. The NAIC owes the market a clear answer on which it is solving for.

On process: the NAIC is a private, tax-exempt organization, exempt from filing Form 990 since 1955. It does not operate under APA notice-and-comment, is not subject to judicial review, and its most consequential deliberations occur in regulator-only sessions closed to the public. Yet the Framework would allow removing an asset class from filing-exempt status, or de-admitting a CRP, without a documented cost-benefit analysis, a stated legal basis, or an external appeal mechanism.

No cost-benefit analysis has been performed, and the NAIC has not been required to perform one.

Third: the Framework would expand confidential data transfers to the NAIC at the moment its data-steward credibility is under scrutiny. On June 11th, an unauthorized party breached the NAIC’s environment through an Oracle PeopleSoft zero-day. The NAIC did not disclose the incident until June 17th — six days later. This, from an organization whose own Model Law #668 imposes a 72-hour standard on the entities it oversees. The data taken included CRP rating determinations of insurer investments — the same category of information this Framework proposes to expand. 

Our ask is straightforward. We are not asking the Working Group to abandon this effort. We are asking it to pause, answer the questions that remain unanswered, and come back with something the market can trust: define the problem; define the terms; coordinate with the SEC; publish a cost-benefit analysis; adopt enforceable data confidentiality commitments; and re-expose a redesigned framework for a full 60-day comment period before adoption.

Confidence in this process will be stronger, not weaker, if it rests on clear legal authority, objective standards, and durable procedural protections.