Showing posts with label CEIOPS. Show all posts
Showing posts with label CEIOPS. Show all posts

Monday, 13 October 2014

ORSA and Independent Review - Misunder-stud?

Independent review of ORSA
- banging the drum?
I listened in on a Solvency II readiness webcast a couple of weeks ago which pricked my ears like a low-budget high street beauty parlour. The specific theme was independent review of ORSA, and the broadcaster confidently included it in the list of "things we all need to do" in the Solvency II preparatory phase, both 2014 and 2015.

While most familiar with the topic would immediately cry "that got lobbied out in 2011", the speaker's argument was that, while EIOPA's Guidance no longer says firms should "independently" review its ORSA, it also doesn't not say it, therefore we must do it, and do it annually!

I would have chuckled and left it at that, but having read InsuranceERM's recent roundtable on preparations for Solvency II, the topic again reared its head, albeit in a more controlled manner, as a number of attendees explained how they have used Internal Audit (and dismissed the idea of using external firms) in reviewing their ORSA processes during the preparatory phase.

My problem is this - as an industry we were happy to, erm, relieve ourselves and moan when CEIOPS's first attempts at ORSA Guidance in 2010 included a guideline which compelled annual independent review of the ORSA Process (included in slide 32 of Mr Bernadino's pack here in Summer 2011, as I can't find the original CP anywhere).

This was lobbied-out by the time the re-badged EIOPA released their 2011 CP (here), and when their Final Report followed in June 2012, "independent review" was a distant memory.

Any compulsion to review the ORSA Process is now  covered only by EIOPA's System of Governance Guidelines (here), specifically Guideline 8 asking that a firm's SoG is regularly "internally reviewed on a regular basis" (5.11).

EIOPA continue in 5.11 that "...the review undertaken by the internal audit function on the system of governance as part of its responsibilities can provide input to this internal review" - i.e. this is not work considered to be performed automatically and exclusively by one's Internal Audit function.

In terms of frequency, EIOPA elaborate in section 4.26 of the Guidelines, namely that your AMSB, given your firm's nature, scale and complexity;
...determines the scope and frequency of the internal reviews of the system of governance
 So three things - no 'annual' requirement; AMSB's choice on frequency; and that this is internal review, not "independent", "external", or indeed any other word which gets me contracted past 2016!

Friday, 29 March 2013

EIOPA Preparatory Guidance - ORSA (or 'forward looking assessment of risks')

Forward-looking assessment of the undertakings own risks (based on ORSA principles) (plus explanatory text)

The ORSA preparatory guidelines* are not a massive burden for anyone busy rolling eggs down hills at the moment, coming in at 34 pages containing 25 guidelines, as well as 29 pages of explanatory text. In this instance, it is probably disappointing to any underprepared supervisors and insurers in that they may have preferred more!

More pointedly, the materials add little to what was already in existence from EIOPA in July 2012, and certainly will required little in the way of adaption in the UK's instance, who are already in a similar headspace and have been advising accordingly.

Of course the world and her husband have piped up with their opinion on what ORSA should cover and how it should be administered and documented (this post has a decent sweep at capturing most of them), so opinion on this matter is something we are not short on.

For me the headline points are:
  • ORSAs (well, 'overall solvency needs assessments', but let's be serious!) expected from 2014
  • Internal Models should be used by anyone in pre-application
  • Likely that most standard formula firms will have to qualitatively assess deviations between SF and their own Risk Profile at this time
  • Expectation of an internal ORSA report and a ORSA supervisory report
  • Records of the assessment expected to be documented and kept which must be "appropriate" - no prescription of what that means
  • ORSAs to be performed at least annually
The following points are either new, or worthy of reiteration for anyone whose preparations on this front are less than certain - for ease of reference I have used 'ORSA' where EIOPA use 'forward looking assessment of risk', and as with the other preparatory guidance papers I have looked at, I will assume there will be blanket application as written, with no dissent from industry or NCAs:

Guideline 3
  • Overall Solvency Needs assessments will be expected from 2014 (i.e compliance with Article 45.1)
  • Minimum of 80% of the market must also assess whether they would comply with the Articles 45 (b) and (c) from 2014 - regardless of any Pillar 1 uncertainty.
  • Internal Models expected to be used in ORSAs if a company is in model approval pre-application
  • IF the standard formula is 'provided' by 2014, expectation that SF firms will assess deviation between the SF assumptions and their own Risk Profile - this excludes anyone outside of the magic 80% catchment figure mentioned above.
Guideline 6 - Documentation generated by ORSAs must include:
  • An ORSA Policy
  • An ORSA Record
  • An Internal ORSA Report
  • AN ORSA Supervisory Report
Guideline 7 - The ORSA Policy must include
  • Description of component ORSA processes and procedures
  • Consideration of the linkages between Risk Profile, Risk Tolerances and Overall Solvency Needs (OSN)
As well as information on
  • frequency on stress tests, scenario analyses and reverse stress tests; 
  • data quality standards; and 
  • the frequency of the assessment, justified in relation to Risk Profile, volatility of OSN relative to capital position, timing (from calendar perspective I guess) and circumstances for ad-hoc assessments
Guideline 8 - ORSA Record
  • Firms expected to "appropriately evidence" the assessment - no prescription as to what that means (logs, working papers, meeting minutes, e-mails)
Guideline 9 - Internal ORSA Report
  • AMSB must communicate results to "all relevant staff" post-approval, which includes the ORSA results and conclusions
Guideline 10 - ORSA Supervisory Report
  • 2 weeks after concluding ORSA, ORSA supervisory report must be submitted, which must include;
  • Quantitative and qualitative results, and conclusions drawn
  • Methods and main assumptions
  • Comparison between Own Funds, SCR and OSN
Guideline 11
  • Must quantitatively estimate the impact of different valuation bases (if used) when assessing OSN
Guideline 12
  • OSN must be quantified, supplemented by a qualitative description of all material risks
  • Expectation that these items are all stress/scenario tested
Guideline 17ORSA output to be used at least for;
  • Capital Management
  • Business Planning
  • Product Development
Guideline 18
  • ORSA to be performed at least annually

* So let's end with something fundamental, EIOPA - it is NOT useful to replace 'ORSA', as an acronym or indeed in full, with the expression "Forward-looking assessment of risk (based on ORSA principles)" 5 years down the road - I'm sure there is a rationale, just as sure as I am not going to like it (even the GCAE agree with me, going with 'ORSA-like')!

Thursday, 28 March 2013

EIOPA Preparatory Guidelines - System of Governance

Consultation on System of Governance preparatory guidance (plus explanatory text)

For a topic which has felt like a given for a number of years (certainly in UK and Ireland where we already ask a lot in this area), the System of Governance preparatory guidance is still 40 pages, comprising of 57 guidelines, accompanied by 60 pages of explanatory text.

A couple of things immediately grabbed at me when going through the guidance (again anticipating a conservative approach of the supervisors rolling over and applying all content as is)
  • That the Risk Management Policy (regardless of how one structures the component elements) is expected to contain procedure-level information about the management of each major risk category - this sounds hopelessly disproportionate, and almost impossible for supervisors to reasonably get through;
  • That it is "expected" that large or complex firms separate their four key control functions, and that others at the small/medium end may ultimately find it easier to do so than consider the range of controls/maintenance of independence required to have combined functions;
  • That an expectation that insurers' systems of governance require regular independent review, with the AMSB only retaining the ability to choose the performer;
  • That insurers will be expected to formally identify/analyse/report on Operational Risk Events
  • That EIOPA bottled out of defining Risk Appetite and Risk Tolerance, leaving national supervisors and insurers to fight it out amongst themselves.
Ultimately, the document reads like a checklist which practitioners or full-timers can run through against the suite of documentation no doubt already in existence which, if based on CEIOPS/EIOPA final advice and/or the Commission's Draft Level 2 measures, won't be miles away as it stands. On that premise, I've only listed elements which jump out for me.


GENERAL GOVERNANCE REQUIREMENTS

Guideline 3
  • Evidence should be collected of the AMSB "proactively" seeking information from committees/key functions
Guideline 5
  • No more detail than an expectation that the AMSB "appropriately implements" their key functions - in the explanatory text, it goes on to say that larger companies will be "expected" to fully separate Risk/Actuarial/Compliance/IA, with a series of measures expected to preserve functional independence if smaller companies choose to combine some.
Guideline 7
  • Expectation that both AMSB decisions, and how information generated from the Risk Management System (RMS) influences them, is "appropriately documented" - compulsion for Board Decision Logs?
Guideline 8
  • Regular System of Governance reviews appear to be expected, which are documented and reported back to the AMSB - the AMSB retains the right to choose who performs it 
Guideline 9 - All policies must include:
  • Goal of policy
  • Tasks to be performed and by whom (person or role, unlike for validation, where person/s was specified)
  • Associated processes and reporting procedures
  • Obligations of affected operational teams to inform control functions of "relevant facts" at all times
Guideline 10
  • Contingency plans are expected for areas which are "especially vulnerable" - this pushes outside of what one would consider a conventional contingency plan for operational emergencies.

FIT AND PROPER

Guideline 11
  • Must have a Fit and Proper persons policy
  • It must be equally applicable to both hired staff and outsourced functions

RISK MANAGEMENT

Guideline 15 - AMSB is "ultimately responsible" for:
  • RMS effectiveness
  • Setting Risk Appetite and Risk Tolerance Limits
  • Approving Risk Management strategies and policies
Guideline 16 - Risk Management Policy must cover at least
  • Risk categories used and measurement methods
  • How each category/grouping of risks is managed
  • Risk tolerance limits for all categories in line with Risk Appetite
  • Linkage of both SCR and ORSA to risk tolerance limits
  • Frequency and content of regular stress tests, and circumstances for additional testing
In addition, the associated guidelines touch on the risk categories within one's Risk Management Policy. There is an expectation for pretty much every category that procedure-level information is included in the policy documents themselves, as well as hard limits, which is unlikely to be the case as it stands.

Guideline 18 - Insurance Risk Policy
  • Expected to cover types of acceptable insurance risks, how premiums will cover claims/expenses, as well as how product design accounts for investment restrictions and formal risk mitigation techniques
Guideline 19 - Op Risk Policy
  • Expectation that Operation Risk Events will be formally identified/analysed/reported in insurers, and that a system for collecting and monitoring them should be in place.
  • Operational Risk Scenarios should be developed and used, based on failures of key persons/processes/systems and external events
Guideline 23 - Investment Risk Policy
  • Buzzphrase introduced of managing the level of "security, quality, liquidity, profitability and availability" of one's asset portfolio

OWN FUND REQUIREMENTS AND THE SYSTEM OF GOVERNANCE

Guideline 32
  • Concept of a "medium term capital management plan" introduced which covers; planned capital issuances, maturities and distribution policies - not sure how that works for mutuals, but I can see what they're fishing for

INTERNAL CONTROLS

Guideline 33
  • "All personnel [should be] aware of their role in the Internal Control system
  • The Internal Control system should be "commensurate to the risks arising from the activities and processed to be controlled" - this line should hopefully avoid overkill

INTERNAL AUDIT FUNCTION

Guideline 36
  • The Internal Audit policy should include the procedure for informing supervisors [of whistleblowing-level wrongdoing I guess]

ACTUARIAL FUNCTION

Guideline 44
  • "Material"deviations of Best Estimate Liabilities should be back-tested for by the Actuarial function, reported on, and remedial changes proposed
Guideline 46
  • The Actuarial function is expected to "contribute to" specifying the risk coverage in the internal model, as well as the dependency structure - this feels like areas where, even in larger insurers, the function probably already leads, so will they be asked to take a step back?

EIOPA preparatory guidelines - pre-application for Internal Models

Consultation on Pre-application for internal models guidance  (plus explanatory text)

As staggering as it is frightening, and perhaps indicative of the diversity of approaches currently on parade across the Union, the pre-application for IMs preparatory guidance is 60 pages, comprising of 72 guidelines, accompanied by a whopping 144 pages of explanatory text. This accompanies the existing 82 pages of L3 guidance on the matter released by then-CEIOPS in 2010! A sub-group of EIOPA's IRSG has been assigned to deal with the nitty gritty of this element of the preparatory guidelines.

On first read, this feels massively influenced by the UK's activities to date, and indeed anyone working in that space will recognise FSA pawprints all over the granular details contained within. This is fair I suppose - the InsuranceERM models map has the UK down for around 1/3rd of models currently in 'pre-application' across the continent.

Therefore bearing in mind the UK approach is already pretty well established, I have highlighted below areas which either diverge from what is currently being exercised on the ground, or which clarify (at least for me!) areas which were previously ripe for controversy or disproportionate/inconsistent application. Where it is common sense or continuez tout doit, I have ignored it.

Most importantly, I am reading it as a fait accompli - bearing in mind the short window of time between consultation end and period commencement, EIOPA's recent past on consultation responses (i.e. 'thanks but no thanks') and the UK's evident participation in the bulking of these guidelines, I don't see much room for lobbying swathes of this away, nor for the PRA to "explain" rather than "comply"!


GENERAL GUIDELINES
Guideline 3
  • As well as nature, scale and complexity, "design, scope and qualitative aspects" of the IM should be considered when allowing for proportionality 
Guideline 4
  • Any model changes pre-application look like they will be pored over by NCAs, including the associated change approval process 

MODEL CHANGES
Guideline 5 - Model Change Policy
  • Policy should, as well as SCR-related changes, include changes to: system of governance (around model change); compliance with Use Test requirements; appropriateness of technical specifications and changes in Risk Profile
Guideline 6
  • Approach to classifying "major" changes is expected to be objective
  • Must also take into account specificities of the company (so benchmarking percentage changes against your neighbours may not be that useful) 
Guideline 7
  • Aggregated change triggers must be considered, not just isolated changes
  • Offsetting positives and negatives won't be acceptable to avoid a "major change" trigger!
Guideline 8
  • Major/minor changes must be determined at Group and entity level

USE TEST
Guideline 9
  • "No complete and detailed list of specific [model] uses" will be supplied by NCAs.
Guideline 11
  • Granularity of the Risk Management System will need to match the IM in terms of categorisation
  • The "structure of decision making fora" will be assessed in ensuring the IM fits to the business - extraordinary!
  • Records expected to be available to show how IM outputs are designed
Guideline 12
  • Assessment of training, seminars, workshops, meetings and direct interviews "should be considered" in pre-application
Guideline 13
  • Will need to "ensure [IM] will be used" during pre-application, as opposed to "use it"
  • Expectation that, if other tools are used in decision making, IM is improved having assessed inconsistencies against said tools
Guideline 14
  • Evidence of prospective support and retrospective verification of decision making would be advisable for candidates
Guideline 15
  • Must document where model is not aligned to the decision ultimately made

ASSUMPTION SETTING/EXPERT JUDGEMENT
Guideline 19

  • "Materiality" in the context of assumptions will need to be both qualitatively and quantitatively assessed - should generate some healthy Risk/Actuarial function debate!
Guideline 20
  • A validated and documented process for assumption setting and expert judgement will be required
  • Sign-off on assumptions will need "sufficient seniority", up to and including AMSB
Guideline 21
  • A formal and documented feedback should be maintained between assumption setters and users
Guideline 22
  • On the transparency of assumption setting, point 1.64 here effectively asks for an Assumptions Register, as well as dictating what it expects to see in it.
Guideline 23
  • Process mapping of some kind expected for the validation of assumption setting
  • Independent assumption review is also expected - doesn't dictate whether this should be internal/external, but it will keep someone in clover no doubt.

METHODOLOGICAL CONSISTENCY
Guideline 26
  • Methodological consistency to be validated

P&L ATTRIBUTION
Guideline 37
  • Point 1.105 seems to confirm P&L attribution by risk driver is required
Guideline 39
  • P&L attribution must be used at least annually in the decision making process
Guideline 40
  • P&L attribution to be used in the validation process (specifically, old ones to be compared against  experience

VALIDATION
Guideline 41 - Validation Policy to contain at least
  • Process, methods and tools, and their purposes
  • Frequency of validation for each part of the IM, and triggers for ad-hoc validation
  • Persons (not roles) responsible for each task
  • Procedure to be followed where reliability of IM is questioned, and ensuing decision making process
Guideline 42
  • Shies away from touching Internal Model scope when talking of validation scope - great move!
Guideline 43
  • Evidence of sensitivity testing expected when determining materiality
Guideline 44
  • Must document known limitations of validation process, as well as circumstances where the process falls over
  • May even be asked to quantify the degree of uncertainty!
Guideline 45
  • A documented escalation path would be advised
Guideline 46
  • Risk Management function will be pressured, as the function with overall responsibility, to ensure all tasks are completed (if not directly performing them) - new skill set?
Guideline 47
  • Evidence of how the RM function ensures that the validation process remains independent of IM design and ops should be collected/enhanced
Guideline 49
  • A process will be expected to ensure the choice of validation tools used considers; complexity, nature, independence and knowledge of participants - feel this could be tricky for the smaller IMAP guys without leading to additional spend on consultants
Guideline 50
  • Must be able to document the appropriateness of the validation tools used accounting for; materiality of IM part, granularity of the data being tested, purpose of the task and the expected outcome

DOCUMENTATION
Guideline 53
  • Expectation of a "...clear referencing system [for IM documentation] which should be used in a documentation inventory"
Guideline 55
  • An overall summary of IM shortcomings, "consolidated into a single document" will be expected
  • This needs to cover at least; Risks not modelled, limitations in modelling, sources of uncertainty in results, data deficiencies, external models/data, IT limitations and governance limitations.
Guideline 56
  • Potential suggestion that there should be more than one level of IM documentation to suit other audiences/uses - IM for Dummies anyone?
Guideline 57
  • End-to-end User Manual expected which an Independent Knowledgeable Third Party could operate
Guideline 58
  • Stress that a single document containing all model outputs (as Use Test evidence) is not required - acceptable as single docs

EXTERNAL MODELS AND DATA
Guideline 60
  • Expectation that external data sets will be sense-checked against "other relevant sources"
Guideline 61
  • Understanding of external models must extend to technical and operational aspects, as well as assumptions
Guideline 64
  • "Material" assumptions of external models must be validated
  • In point 1.163, any potential for cherry-picking features/options of external models is constrained



Wednesday, 8 June 2011

European Economic and Social Committee paper on Solvency – 5th May

I do recall fishing for this and having no success, but the EESC Opinion Paper on Solvency II (agreed last month, but not sure when released) makes for fascinating reading.

As with most things relating to European bodies, I struggle to identify exactly what the purpose of it is, but the committee, at the behest of the European Council no less, make a number of substantial points;
  • Solvency II "should not result in market consolidation, especially in respect of small and medium insurers
  • Focus very hard on sustaining the provision of guaranteed long-term products, and therefore an "appropriate" interest rate term structure is indispensible in calculating SCR
  • That this is not just a technical issue, but also a political issue when involving provision for old age
  • Explains the reason for "implementing measures" becoming "delegated acts" at Level 2 (which I never knew the driver behind until today!)
  • Heavy on smoothing the transition between Solvency I and II, and states that the transition should cover "all three pillars"
  • Proper assessment of how transitional rules can be consistently linked with supervisory actions in cases of non-compliance post go-live date
  • "Transition should refer more explicitly to the upgraded Solvency I standard as an (optional) minimum level" - I may be wrong, but is Solvency I not a retrograde step for UK  plc, who are already knee deep in ICAS?
  • "Interest Rate term structure and illiquidity premium will not be determined by legislative bodies"
  • Timeframe for effective launch of Solvency II "particularly challenging" - "Insurance companies cannot be held accountable for instructions that are to be published at a later stage"
  • "The proposal that EIOPA develop draft implementing measure by 31 December 2011 at the latest would seem to be somewhat ambitious"!
  • Discourages developing more Level 3's where Level 2's already exist - "In case of any doubts, for individual implementing measures (Level 2), no additional technical standards (Level 3) should be provided for; eg Level 3 would not appear to be necessary in respect of own risk and solvency assessment (ORSA), the classification of Own Funds or ring-fenced funds" 
I honestly don't know how to read this - is it the start of the goalpost moving process, the issue of a public challenge to meet tight dealines, or a reprimand for CEIOPS/EIOPA for regurgitating most of Level 2 into Level 3? I guess there will be more to follow...