Solvency II Pillar 2 is the set of qualitative requirements in Section 2 of Chapter IV of Directive 2009/138/EC, headed "System of governance" and running from Article 41 to Article 49. Every insurance and reinsurance undertaking in the EU must run an effective system of governance that includes a risk management system, an own risk and solvency assessment (ORSA), an internal control system with a compliance function, an internal audit function, an actuarial function, fit and proper people in the roles that matter, and controlled outsourcing. Nothing in Pillar 2 is calculated. It is tested, through the supervisory review process in Article 36, and a supervisor that finds the system wanting can require it to be improved or, in exceptional cases, set a capital add-on under Article 37.
The text is changing. Directive (EU) 2025/2, published in the Official Journal on 8 January 2025, amends several of these articles. Member States must transpose it by 29 January 2027 and apply the new rules from 30 January 2027. Where an amendment touches a requirement below, it is flagged.
| Requirement | Article | What it asks for |
|---|---|---|
| Ultimate responsibility | Art. 40 | The administrative, management or supervisory body (AMSB) holds ultimate responsibility for the undertaking's compliance with the Directive. |
| System of governance | Art. 41 | A transparent structure with clear allocation and segregation of responsibilities, written policies approved by the AMSB and reviewed at least annually, contingency plans, and regular internal review. |
| Fit and proper | Art. 42 | Everyone who effectively runs the undertaking or holds a key function has adequate qualifications, knowledge and experience, and is of good repute and integrity. Changes are notified to the supervisor. |
| Risk management | Art. 44 | A risk management system covering at least six named areas, supported by a risk management function. |
| ORSA | Art. 45 | An assessment of overall solvency needs, continuous compliance with capital requirements and technical provisions, and how far the risk profile deviates from the SCR assumptions. |
| Internal control | Art. 46 | Administrative and accounting procedures, an internal control framework, reporting arrangements at all levels, and a compliance function. |
| Internal audit | Art. 47 | An objective, independent function that evaluates the internal control system and the rest of the system of governance, reporting to the AMSB. |
| Actuarial function | Art. 48 | Coordinates the calculation of technical provisions, opines on underwriting policy and reinsurance, and contributes to the risk management system. |
| Outsourcing | Art. 49 | The undertaking stays fully responsible for what it outsources, and notifies the supervisor before outsourcing critical or important functions. |
What is Solvency II Pillar 2?
Solvency II is organised in three pillars. Pillar 1 is the quantitative layer: technical provisions, own funds, the Solvency Capital Requirement and the Minimum Capital Requirement. Pillar 3 is disclosure and supervisory reporting. Pillar 2 is everything between the two: how the undertaking is run, how it identifies and manages risk, and how the supervisor reviews that. Article 41(2) makes the whole of it proportionate to the nature, scale and complexity of the undertaking's operations, which is why two insurers can both be compliant with governance systems of very different weight.
Three layers of law sit behind it. The Directive sets the obligations. Commission Delegated Regulation (EU) 2015/35 fills in the detail in Articles 258 to 275. EIOPA's Guidelines on System of Governance (EIOPA-BoS-14/253) explain how supervisors are expected to apply both, and state that they are based on Articles 40 to 49, 93, 132 and 246 of the Directive and Articles 258 to 275 of the Delegated Regulation. National law then transposes the Directive, so the wording a supervisor quotes at you will be the national version.
What does the system of governance in Article 41 require?
Article 41(1) requires an effective system of governance that provides for sound and prudent management, with at least an adequate and transparent organisational structure, a clear allocation and appropriate segregation of responsibilities, and an effective system for transmitting information. The system must be subject to regular internal review.
Article 41(3) is the part most often audited. Undertakings must have written policies on at least risk management, internal control, internal audit and, where relevant, outsourcing. Those policies must be implemented, reviewed at least annually, approved in advance by the AMSB, and adapted whenever there is a significant change in the system or the area concerned. Article 41(4) adds continuity: reasonable steps to ensure the regular performance of activities, including contingency plans. Article 41(5) gives supervisors the powers to require the system to be improved and strengthened.
From 30 January 2027, the internal review in Article 41(1) must also assess the composition, effectiveness and internal governance of the AMSB, and undertakings must have a policy promoting diversity in that body, including individual quantitative objectives on gender balance.
What must the risk management system cover?
Article 44(1) asks for strategies, processes and reporting procedures that identify, measure, monitor, manage and report risks on a continuous basis, at individual and aggregated level, together with their interdependencies. Article 44(2) then names the areas the system must cover as a minimum: underwriting and reserving; asset and liability management; investment, in particular derivatives and similar commitments; liquidity and concentration risk management; operational risk management; and reinsurance and other risk mitigation techniques. The written risk management policy in Article 41(3) must contain a policy for each of those six areas. Article 44(4) requires a risk management function structured to make the system work, and Article 44(5) gives that function extra tasks where an internal model is used.
Directive (EU) 2025/2 rewrites point (e) as "operational risk management, including cybersecurity", defined by reference to the Cybersecurity Act, Regulation (EU) 2019/881. It also requires sustainability risks to be assessed over the short, medium and long term. For insurers already inside DORA, the ICT risk management framework they built there is the obvious evidence for the cybersecurity half of point (e).
What does the ORSA have to include?
Article 45(1) sets three minimum elements. First, the overall solvency needs of the undertaking, taking into account its specific risk profile, approved risk tolerance limits and business strategy. Second, compliance on a continuous basis with the capital requirements and with the requirements on technical provisions. Third, the significance with which the undertaking's risk profile deviates from the assumptions underlying the Solvency Capital Requirement, whether calculated with the standard formula or an internal model.
The rest of Article 45 is what makes it a process rather than a report. Article 45(4) makes the ORSA an integral part of the business strategy, taken into account on an ongoing basis in strategic decisions. Article 45(5) requires it to be performed regularly and without any delay following any significant change in the risk profile. Article 45(6) has the results reported to the supervisor as part of the regular supervisory reporting under Article 35. Article 45(7) says plainly that the ORSA shall not serve to calculate a capital requirement.
From 30 January 2027 the list in Article 45(1) grows. New points require consideration of the macroeconomic situation and possible macroeconomic and financial market developments, consideration of macroprudential concerns where the supervisor makes a reasoned request, and an assessment of the undertaking's overall capacity to settle its obligations to policyholders and other counterparties when they fall due, even under stressed conditions. Small and non-complex undertakings are not obliged to run the macroprudential analysis. A new Article 45a adds climate change scenario analysis: every undertaking must assess whether it has material exposure to climate change risk, and those that do must specify at least two long-term scenarios, one where global warming stays below two degrees Celsius and one where it is significantly higher, analyse their impact in the ORSA at intervals no longer than three years, and review the scenarios at least every three years.
What are the four key functions?
The Directive never uses the phrase "four key functions", but four functions are named and treated as key throughout. The risk management function in Article 44(4) runs the risk management system. The compliance function in Article 46 sits inside the internal control system and advises the AMSB on compliance with the laws adopted under the Directive, assesses the possible impact of changes in the legal environment, and identifies and assesses compliance risk. The internal audit function in Article 47 evaluates the adequacy and effectiveness of the internal control system and the other elements of the system of governance; it must be objective and independent from the operational functions, and its findings go to the AMSB, which decides what to do and ensures it is done. The actuarial function in Article 48 coordinates the calculation of technical provisions, checks the methods, models, assumptions and data behind them, compares best estimates against experience, informs the AMSB on the reliability of the calculation, gives an opinion on the overall underwriting policy and on the adequacy of reinsurance arrangements, and contributes to the risk management system.
Article 42 attaches the fit and proper test to everyone who effectively runs the undertaking or holds one of these functions: adequate professional qualifications, knowledge and experience on the fit side, good repute and integrity on the proper side. Changes in who holds those roles are notified to the supervisor, as is any replacement made because someone no longer meets the test.
The 2025 amendments add a new Article 41(2a). Undertakings must appoint different persons to carry out the risk management, actuarial, compliance and internal audit functions, and each must be performed independently of the others. Small and non-complex undertakings, and undertakings with prior supervisory approval, may combine the first three with other roles, but never with internal audit, and only if conflicts of interest are properly managed.
What do the outsourcing rules require?
Article 49(1) is the principle: the undertaking remains fully responsible for all of its obligations under the Directive when it outsources functions or activities. Article 49(2) sets four things that outsourcing of critical or important functions must never do: materially impair the quality of the system of governance, unduly increase operational risk, impair the supervisor's ability to monitor compliance, or undermine continuous and satisfactory service to policyholders. Article 49(3) requires timely notification to the supervisor before outsourcing critical or important functions, and of any subsequent material development. Where the outsourced service is ICT, DORA's contractual and register requirements sit on top, which is why insurers tend to run one outsourcing register that serves both.
How is Pillar 2 enforced?
Through the supervisory review process. Article 36(2)(a) requires supervisors to review and evaluate the system of governance, including the ORSA, alongside technical provisions, capital requirements, investment rules and own funds. Article 37(1)(c) lets a supervisor set a capital add-on where the system of governance deviates significantly from the standards in Section 2. Article 41(5) is the everyday tool: the power to require the system to be improved and strengthened. Pillar 2 has no filing deadline of its own. It is examined whenever the supervisor chooses to look.
What the other results get wrong
The most common error is treating Pillar 2 as a synonym for the ORSA. The ORSA is one article out of nine, and Article 45(7) says it is not a capital calculation. An undertaking with a polished ORSA report and no evidence that its written policies were reviewed this year has a Pillar 2 problem.
The second is quoting the 2009 text as though it were final. Directive (EU) 2025/2 changes Articles 40, 41, 44 and 45 and inserts Article 45a, and those changes apply from 30 January 2027. A governance review scoped against the old text will miss the separate key function holders, cybersecurity in operational risk and climate scenarios.
The third is listing requirements without the article that creates them. A supervisor's question always has a legal basis. If your control library cannot answer "which article" for each item, you cannot show the supervisor where the evidence sits, and you cannot reuse that evidence across DORA, ISO 27001 or NIS2 without doing the mapping again.
Where do you stand?
Fill this in from your own records. A blank row is a finding waiting for a supervisor to make it.
| Question | Your answer | Article |
|---|---|---|
| When was each written policy last approved by the AMSB? | Art. 41(3): at least annually, prior approval | |
| Who holds each of the four key functions, and are they four different people? | Art. 41(2a) from 30 January 2027 | |
| Does the risk policy cover all six Article 44(2) areas, including cybersecurity? | Art. 44(2), as amended | |
| When did you last run the ORSA, and what change would trigger a rerun? | Art. 45(5) | |
| Have you assessed whether climate change risk is material, and set two scenarios if so? | Art. 45a from 30 January 2027 | |
| Did you notify the supervisor before your last critical or important outsourcing? | Art. 49(3) |
Our Solvency II ORSA and governance checklist scores all 45 items in a spreadsheet, and the Pillar 2 software buyer's guide explains which tool category actually covers this work. If you want a baseline first, a free compliance check tells you which rows above you will struggle with.
Frequently asked questions
Is Pillar 2 only about the ORSA?
No. The ORSA is Article 45. Pillar 2 also covers general governance in Article 41, fit and proper in Article 42, risk management in Article 44, internal control and compliance in Article 46, internal audit in Article 47, the actuarial function in Article 48 and outsourcing in Article 49, all resting on the AMSB's responsibility in Article 40.
Does Pillar 2 apply to small insurers?
Yes, proportionately. Article 41(2) scales the system of governance to the nature, scale and complexity of the business. From 30 January 2027, undertakings that meet the criteria in the new Article 29a can be classified as small and non-complex and use the proportionality measures the amended Directive attaches to that status.
Who has to be fit and proper?
Under Article 42, all persons who effectively run the undertaking or have other key functions. The 2025 amendments add to Article 40 that members of the AMSB must at all times be of good repute and collectively possess sufficient knowledge, skills and experience to perform their duties.
When do the Directive (EU) 2025/2 changes apply?
Member States must adopt and publish transposing measures by 29 January 2027 and apply them from 30 January 2027.
How does Pillar 2 overlap with DORA?
Two places. Operational risk in Article 44(2)(e), which from 2027 expressly includes cybersecurity, and outsourcing in Article 49, where ICT services are also subject to DORA's third party rules. Evidence once and map it to both, rather than maintaining two registers.
Primary sources
Requirements above are drawn from Articles 36, 37 and 40 to 49 of Directive 2009/138/EC, the amendments in Directive (EU) 2025/2 including its Article 4 on transposition, Articles 258 to 275 of Commission Delegated Regulation (EU) 2015/35, and EIOPA's Guidelines on System of Governance. National transposition may add detail. Confirm the current text before relying on a specific provision.





