Showing posts with label CEO. Show all posts
Showing posts with label CEO. Show all posts

Wednesday, 19 March 2014

Myners briefing on Governance at the Co-op - working class barred from the Board?

Wolf - step away from the door...
A corporate governance story that will echo in the eternity of MBA classes for years to come, the unravelling of the UK's Co-operative Group from the benign grocer-cum-divvy machine into a ying and yang shotgun conglomerate of opposites is proving to be a watershed moment for UK plc, with stakeholders attempting to balance myriad legal, political and ideological considerations in order to both keep the wolf from the door, and preserve the principle of mutuality for its membership.

There are no surprises that the crux of the Group's issues lies in its banking arm, nor that being acquisitive during the financial crisis (here, here and here) has proven to be poor strategy. Keeping the wolf from the door has therefore largely been delivered through the tried and tested combination of begging and borrowing, which the recently departed CEO appears to have delivered with some aplomb.

Governance structures
- choices choices...
However, the Group's hiring of Paul Myners back in December, a man with an extensive collection of t-shirts and hats, to independently review its governance arrangements, seems likely to deliver to the membership a menu of choices as unpalatable as a Sunday skip-dip.

Lord Myners has hurriedly delivered a briefing on his findings to-date, as well as performed some mainstream media duties (here and here), following the Group CEO's resignation last week. This early sighter was seemingly unscheduled, but the manner of the CEO's departure ("a tragedy" in Myners' words) meant that his findings to-date could not wait until May for its full publication date.

Myners has therefore naturally delivered a ruthless and scathing take-down of the governance structure and processes within the Co-operative, while calling out the Board member who are clearly well schooled in how to game the system, as well as the playground tactics/rabbit-in-a-hat tricks that turn "one-man-one-vote" into "one hundred men-all votes"!

Killer quotes
  • The group endures a significant "democratic deficit"
  • The future of my recommendations lies in the hands of around 100 elected individuals on the current Group and Regional boards, few of whom have any serious business experience and many of whom are drawing material financial benefits from their positions
  • There is a phrase frequently used in Co-operative Group circles that the Executive should be "on tap but not on top"
  • ...the Group Board has spent far too much time on transactions such as Somerfield and Britannia which have been breathtakingly value-destructive
Observations
  • The "exceptional skill and tireless efforts" of the Executive team are cited as the reason for the Group's survival in its current form
  • The current governance framework is variously referred to as "flawed", suffering from "acute systemic weaknesses" and having "consistently produced governors without the necessary qualifications and experience to provide effective Board leadership". Ouch...
  • That the Groups social goals are not aligned with its strategic and commercial objectives. This is of course less of a worry for its financial services competitors.
  • The the Group's "massive scale and complexity" means that a man-off-the-street approach to electing Board members, which may be sufficient for a farmer/grocer co-op, is not suitable.
  • Shatters the "myth" that the Group has always been run by lay members, as opposed to those with commercial experience.
  • The thought of creating a board of INEDs and lay members is disregarded due to the potential for creating "second-class citizenship"
  • Highlights that Co-op's core business of groceries is savagely competitive at the moment (just look at Morrison's and Sainsbury's), so continued ineffective governance could be devastating
  • Notes that there have been previously (disregarded) reviews of its governance architecture, which is "long known for its labyrinthine complexity and its disfunctionality"
  • Stresses that, due to the current voting structure, acceptance of  his recommendations "...potentially lie[s] in the hands of fewer than 50 elected members". It sounds like they haven't been shy to remind him of that either!
Recommendations
  • Halve the size of the Group Board, which will be subject to annual re-election
  • Independent Chair, with no previous association with Co-op
  • 6-7 INEDs and 2 Executive Directors
  • All with qualifications of a similar ilk to its (listed) competitors
  • Create a National Membership Council (NMC), with a 12-person executive committee to effectively represent the membership and co-operative principles and values
  • The Board to be subject to scrutiny by the NMC, who have the right to be consulted on "key strategic and operational intiatives"
  • "Arrangements" to be made to safeguard the confidentiality of information shared between the Board and the NMC (certainly not the case with current arrangements!)
The entire document feels drenched in class warfare and spectrum politics. That rather hideous take from the existing Board on their executive team ("on tap, but not on top") feels like the inspiration of Myners' recommendation for a professionalised, appointed Board, rather than the beer and sandwich brigade which currently exists.

That said, there is thought on the left-wing (here and here) who feel that mutuality and co-operation should remain unsullied by the commercial world, who remain unable to affect much in the way of democratic change in Boardrooms even after the raft of FRC-sponsored guidance released over the last couple of years (though PIRC are trying!). Is one failed attempt to democratise stakeholders best replaced by cherry-picking from a similarly deficient model?

On the basis that I have banged the drum for background diversity in Boardrooms (not just gender or race), and the existing Co-op Board is "diverse" in that respect, I'm left to wonder if I've been barking up the wrong tree. The Board delivered by their existing process is neither fit nor proper, and are able to outmanouevre their executive compatriots armed with little more than a working knowledge of provincial politics and a polyester suit.

Should we therefore use the grey-area of "fit and proper" regulation to ban the contract plasterers, nurses and retired publishers of the world from financial service provider Boardrooms on the basis that they don't have an MBA, and count with their fingers? Or can one make a valid contribution to a financial services Board of directors regardless of the colour of their collar?

Wednesday, 20 November 2013

Financial Stability Board - Principles for an Effective Risk Appetite

Christmas has come early everyone - the Financial Stability Board have released their Principles for an Effective Risk Appetite Framework today, and I'm greedily ripping in to it before JC's birthday like a spoilt, yet handsome child...

FSB's RAF Principles published
send the car back lads...
There has been a reasonable amount of traffic on Risk Appetite this year (here, here and here for a start), after the FSB but announced their consultation earlier in the year, I've been on tenterhooks. This was following of the back of a thematic review on Risk Governance as a whole by the FSB, which they published back in February.

So where do they take this deep dive into Risk Appetite? Other than awkwardly shoehorning in the soup de jour of "SIFIs", they stick to the hard areas which will get every risk practitioners' attention (namely, Risk Appetite Framework, Risk Appetite Statements, Risk Limits and Roles and Responsibilities), though "for clarity and simplicity", they jettison the use of Risk Tolerance. Definitions are supplied on p2-3, which you may find useful as anchor references.

They somehow make room for anodyne flannel in this very short document, for example;

Risk Appetite Frameworks
  • Should "facilitate embedding risk appetite into the financial institution’s risk culture
  • Development and establishment is an "...iterative and evolutionary process that requires ongoing dialogue throughout the financial institution to attain buy-in across the organisation" (groan)
Risk Appetite Statements
  • "Risk appetite may not necessarily be expressed in a single document; however, the way it is expressed and the manner in which multiple documents form a “coherent whole” need to be carefully reviewed to ensure that the board obtains a holistic, but compact and easy to absorb, view of the financial institution’s risk appetite"
Risk Limits
  • "Having risk limits that are measurable can prevent a financial institution from unknowingly exceeding its risk capacity as market conditions change and be an effective defence against excessive risk-taking" - tell that to Lehmans!
However, the salient points for me were as follows;

Risk Appetite Frameworks

  • RAF "...sets the financial institution’s risk profile" - not convinced on that one, but may be semantic issue
  • "explicitly defines the boundaries within which management is expected to operate when pursuing the institution’s business strategy"
  • Should "be adaptable to changing business and market conditions" to allow for limit increases where appropriate


Risk Appetite Statements

  • "[should] address the institution’s material risks under both normal and stressed market and macroeconomic conditions"
  • "...should establish quantitative measures of loss or negative outcomes that can be aggregated and disaggregated"
  • "...include key background information and assumptions"
  • "...include quantitative measures that can be translated into risk limits"
  • "...be forward looking and, where applicable, subject to scenario and stress testing"

Risk Limits

  • "[should] be set at a level to constrain risk-taking within risk appetite"
  • "...should not be strictly based on comparison to peers or default to regulatory limits"
  • "[should] not be overly complicated, ambiguous, or subjective"

Roles and Responsibilities

The Board

  • ...must establish the institution-wide RAF and approve the risk appetite statement, which is developed in collaboration with the chief executive officer (CEO), chief risk officer (CRO) and chief financial officer (CFO)
  • FSB specifically comment that Boards who "receive" or "note" Risk Appetite Statements have a lower understanding of risk appetite (so don't sponsor it!)
  • " [should] regularly review and monitor the actual risk profile and risk limits against the agreed levels (e.g. by business line, legal entity, product, risk category), "including qualitative measures of conduct risk"
  • " [should] ensure risk management is supported by adequate and robust IT and MIS to 
  • enable identification, measurement, assessment and reporting of risk in a timely 
  • and accurate manner."
CEO should
  • "...be accountable, together with the CRO, CFO, and business lines for the integrity of the RAF"
  • "...ensure that the institution-wide risk appetite statement is implemented by senior management"
  • "...provide leadership in communicating risk appetite to internal and external stakeholders" 
  • "...establish a policy for notifying the board and the supervisor of serious breaches of risk limits and unexpected material risk exposures"

While there are specific sections for the obligations of CRO, CFO, Internal Audit and Business Unit Management, they don't necessarily expand much further than what I consider to be normal functional expectations, so I haven't elaborated on them.

One should certainly therefore expect a much more aggressive approach from supervisors in future off the back of this - combing through strategy and board papers for evidence of Risk Appetite in application, and making sure that Risk Appetite Statements are not just 'rubber stamped', for example.

I certainly don't see much in this for stakeholders. Nothing particularly new is brought to the table here, and if this is the results of peer review and shared experiences, then clearly there is concurrence on how an RAF should be constructed, what a RAS looks like, and who should do what in regard to continuous monitoring.

The skill will be for risk practitioners to convince their CEOs/NEDs that, this is no longer a sidecar activity in the ERM best practice space, but a nascent global minimum standard which will invariably surface in national regulations in the forthcoming moths and years.

Friday, 2 August 2013

Central Bank of Ireland - Corporate Governance Code refresh

The Irish approach to corporate governance in financial services, at least up until the onset of the financial crisis in 2006/07, resembled something of an all-you-can-grasp buffet for a select number of executive golf club pals and octogenarian ex-politico Non-Executive Directors (NEDs), having their voting arms operated a la Weekend at Bernies.

Ireland pre-2007 - Waking NED?
The new FSA-flavoured approach brought in by Matthew Elderfield in 2009 (elaborated on here) fortified by the findings of a devastating 2011 report summarising the truly horrid governance practices in the Irish banking industry, has led to a change of regulatory tack at the Central Bank of Ireland that represents the biggest volte-face in Europe since the Macarena.

Alongside PRISM, a piece of revolutionary work in the assessment of financial institutions by supervisory bodies, the CBoI also made substantial changes in areas such as Annual Compliance Statements, Fitness and Probity of directors, Risk Appetite Statements.

All of this ran off the back of Mr Elderfield's first major gig in 2010, a full revamp of the Corporate Governance Code, which could hitch a ride off the back of the work of the FSA and CEIOPS (at the time!) and deliver a more substantial suite of obligations to a cabal of directors who, after feasting on carrots for years, desperately needed the stick.

This makes the release of yesterday's consultation on the Corporate Governance code a touch baffling, as the ink is barely dry on 2010's effort - it perhaps reflects that the regulator has reached optimum staffing levels if they can review it so regularly! Having said that, the level of divergence from accepted CG practices in the UK was flagged by Grant Thornton back in 2011 as being substantial, so a point-in-time revamp should not be so unwelcome, regardless of the proximity to the last one, and of course, all of this activity was too late to prevent Quinn Insurance from going down.

They emphasise that this review takes into account developments in the Solvency II space, as well as on-the-ground experience and publications from other parties of interest. Of particular note was their emphasis that, where national regulations are not as stringent as relevant EU or international one (or indeed vice versa?), the most onerous one should be complied with. In a number of instances around corporate governance, this will mean the CBoI outranking Solvency II as the more onerous of the two!

While these are proposals rather than stitched-on changes at this point, the CBoI doesn't have a great track record for backtracking these days. Highlights for me were;

Risk Committees

  • Require a majority of NEDs on Risk Committees, and must be chaired by a NED
Committees in general
  • Require the Risk Committee and Audit Committee chairs to sit on each other's committees
  • Require the Remuneration Committee chair to sit on the Risk Committee
  • In High Impact firms, the Risk Committee and Audit Committee Chair may not be the same person
  • Must be at least 3 members of Risk Committees and Audit Committees
Chief Risk Officers
  • They note that it is "Generally accepted best practice" to have a CRO who, amongst other tasks, is charged with "...facilitating risk appetite setting by the Board". In addition;
  • All "High Impact" firms will be required to appoint a specialist CRO
  • Firms with a lower PRISM rating may have a CRO who is shared with another control function, "...provided that there is no conflict of interest between the two roles". Can't help but feel that this might rule out CRO/Chief Actuary dual roles, but allows for CRO/Head of Compliance and CRO/Head of Internal Audit, which would be to the chagrin of the Society of Actuaries in Ireland!
  • CRO to have direct access to the Chairman of the Board
Board Meeting frequency
  • Seem to acknowledge that the compulsory 11 meetings per year for High Impact firms may be a touch much, so are looking for comments
  • Also acknowledge that compulsory 1 meeting per calendar quarter is a bit constrictive for the smaller firms, so may relieve this to be pragmatic
Chairman and CEO
  • Some of the restrictions around number of roles held at any one time to be relieved for smaller firms, but seemingly only to populate inter-Group roles.
Board Diversity
  • Acknowledges that, while the debate in the EU is gender-centric, that diversity of all types is a worthy target for Boards, but falls short of compelling firms to do anything at national level, choosing to seek comments and wait for the supra-national activity to drive any compulsion. This seems to fit with the thinking of Irish directors published back in 2011 i.e. no "Golden Skirt" quotas.
Random
  • "...appropriate Risk Culture" makes its way in (6.3), perhaps cognisant of the FSB's proposals
  • Built in a piece which allows for video-conferencing rather than physical attendance at meetings (7.5)
  • Board responsibilities updated (13.1)
  • Compulsory Board skills matrix (14.9)

Tuesday, 4 October 2011

CRO to CEO - what's your skillset?

As flagged on the Reputability blog, Allianz Re have recently promoted their Chief Risk Officer to the top job. Fantastic news for those super-ambitiousin the function, and tactit recognition perhaps that the balanced skillset of the latter day CRO is coming the boil nicely. You will notice that the blogger doesn't prescribe to CRO-to-CEO promotion, seeing the role as a destination, not a hub.

As an avid follower of activity on the CRO front (in particular the sustained attack on the role from the Actuarial profession as an alternative avenue to the C-suite), and was delighted to see that his background was...errr...Actuarial! To all you "Riskies" reading, please see the earlier comments from the FERMA VP on upskilling...

A nice translated piece was published by Clifford Chance regarding CROs in the EU (specifically with Germany in mind) - covers the EC green paper angles on risk governance and risk executives, as well as correctly highlighting that "Solvency II is a key ally in institutionalising the new role of the CRO"