Showing posts with label CRO Forum. Show all posts
Showing posts with label CRO Forum. Show all posts

Wednesday, 24 June 2015

CRO Forum on Risk Culture - comin' from the body heat?

Risk Culture
- need another hero?
A subject which is gathering more steam than Tina Turner's windows, Risk Culture has been given the kid gloves treatment by the CRO Forum in their paper, Sound Risk Culture in the Insurance Industry.

They say at the start that the topic has become "prominent in regulatory circles", which given EIOPA appear to be wining and dining the subject (here and here in the last couple of weeks alone), is something of an understatement. Their increased interest has no doubt been fuelled by the FSB's work on the subject from a year ago. In addition, the Financial Reporting Council took a shine to the topic in its last update of guidelines in late 2014 (point 27 in particular), while cultural failings have turned the FCA into a modern day Robin Hood (speech from inception time here).

As well as fiddling around the edges of definition, the paper expands on a few examples of where cultural change can be driven from, stealing from a few other industries (aviation in particular) and a couple of insurers (Zurich receiving particular attention).

They fundamental base they work from is pretty fair:
  • No "good" or "bad" culture, hence they talk about practices that encourage a "sound" risk culture throughout. Given that ropey culture does not necessarily prevent the achievement of strategic goals, this smart.
  • No "one-size-fits-all" concept of Risk Culture (i.e. don't look for one in this paper!)
That said, the definition used for the purposes of the paper from the NN Group CRO is actually a pretty good one - "shared philosophy of managing uncertainty" etc - though it does suggest that a failure in risk culture might simply be someone not sharing the philosophy, which I suspect is where a lot of your more pragmatic colleagues sit!

There are a number of sound inclusions throughout;
  • Emphasising the links between risk culture and conduct risk currently being force-fed to the industry by EIOPA (p3)
  • The chart on p6 showing survey results of essential elements of risk culture - senior management and Boards leading by example is evidently seen as more important than risk-based remuneration, despite the legislative attention the latter receives (including this week in the UK).
  • Zurich's internal 10 question survey on culture assessment - contains the gorgeous expression "organisational humility", as well as bringing some of the granular risk culture elements onto the table, such as treatment of whistleblowers.
  • Highlighting the "common phenomenon" of management teams containing people with the same personal attitudes - could benefit the creation of a "shared philosophy" without necessarily any of the benefits.
  • The illustration of NN Group's "Risk Culture Dashboard" (p11) - I don't have preference for it either way, but it does illustrate how much effort one can direct towards risk cultural identification, assessment and monitoring, which begs the question "is there that much value in it?" They seem to like it as a way of covenying the concept in the business in any case.
  • Pages 13-14 provide some good brain candy for those who have ambitions to educate or brief their colleagues on risk cultural matters. Zurich's "we are all risk managers" campaign looks like it probably has legs (more on it here).
There are a couple of mildly objectionable parts within;
  • Concepts of "Risk Vision" and "holistic" dropped in early doors and littered throughout, as well as a few extras such as "risk perspective" - the kind of obtuse terminologies which serve to divorce Risk functions from their colleagues
  • That firms should have a "clear vision" for their risk culture - why would something as opaque as culture be expected to be "clear". They don't even define it as a term in the paper!
  • Concerned that risk culture is "...only practiced by risk specialists" currently - how can this be if risk culture is "...an element that influences and is influence by various forces"?
  • Tha an organisation's corporate culture and risk culture "must be linked" - how are they not one and the same thing?
  • That Risk Appetite Statements are "effectively part of the business strategy" - as opposed to "actually"?
  • Use of the term Risk Profile as if it is unquantifiable, specifically that a firms who learn from their mistakes rather than chastise those who make them "tend to have a better risk profile". Not clever.

Tuesday, 19 May 2015

Towers Watson's Global ERM Survey - Knowing ERM, Knowing You...

A couple of treats from two of the powerhouses of the 'writing things down' industry on the practical use of ERM to drive decision making, rather than simply accompany it.

Towers Watson are targeting the Solvency II audience (at least on this side of the Atlantic) with a timely release of the results of their 8th Biennial Global ERM Survey. I say the results, as there is no sign of the full survey itself - any closer to their chest, it would be an areola's backpack...

As ever, these kinds of publications oscillate between flannel and insight, so while I cover those below, feel free to read the infographic and call it quits!

General observations from the main press release include;
  • Three-quarters of (the almost 400) respondents say they are viewed as "important strategic partners" by the Board and Executive - I'm less inclined to see that as a mark of superiority, given that risk functions in some firms won't have the ambition or aptitude to achieve that status
  • Implication that some respondents do not have a risk appetite framework in place - very worrying, unless this is just bad wording.
  • Some firms said to be only "...using ERM for regulatory compliance". It may depend on jurisdiction, but I'm not inclined to agree that is even possible.
  • The "ultimate vision" for a firm's ERM capabilities is referred to, which is a brow furrer, even conceptually. TW seem to bundle up risk culture, risk monitoring and risk tolerance into the "Vision" bucket, in case that term takes your fancy.
  • The expression "very strategic approach" appears in print for the first time!
Getting Value from ERM?
- "Kiss my Face"
From the more elaborate Q&A document, we find the main granular material which TW were prepared to publish. Fortunately for readers this side of the Atlantic, the EMEA Director Mike Wilkinson holds sway over much of that conversation, including his tale of the firm who recently had an ERM/Business Strategy-inspired "Aha" moment.

That session contains a fair bit of contention, such as;
  • Asking the questions "What's the purpose of risk management" or indeed the "purpose of your ERM Program" in the Q&A - if these had been directed to the respondents themselves, it would have contextualised a number of the seemingly negative responses i.e. If the purpose of your ERM Program is "don't get shut down", you are probably less bothered about being a "strategic partner"!
  • That the business should "...challenge the risk group to create reports that help them make decisions" - Excel Jockey is hardly the work of a strategic partner...
  • In a similar vein, that insurers are "drowning in data, drowning in metrics" - hardly a new phenomenon, and doesn't give any credit to the critical faculties of employees to filter what they do have.
  • "...many [internal capital] models have matured" - a sharp intake of breath can be heard down at Moorgate!
  • That "...an ERM Program can't properly be assessed until it has been in place for a while" - pretty sure the S&P crowd wouldn't hold off assessing you while you "embed"
Mike in particular does manage to keep a good focus throughout the Q&A on maximising trade-offs between risk and return being the big differentiator between Risk functions who are capable of influencing strategic decision making, and those who are perhaps more likely to be tabling red-amber-green reports tracking the outcomes of decisions which have already been made.

Other strong points include;
  • In the context of Risk Tolerance, how to cater for the discretion required by an insurer's asset managers in handling investment portfolios.
  • Touches on a couple of pieces which stood out in the CRO Forum's Risk Appetite publication last month, namely around the increasing number of measures being used to run businesses other than capital, allowance of movement within risk tolerance levels, and whether firms have effectively articulated their organisation-wide Risk Appetite and Risk Tolerance limits down into its subsidiaries/departments.
One aspect which gnawed at me throughout this reading is the constant referrals to "ERM Programs" - I don't think I am bathing in semantics to suggest that Programs normally start and end, whilst ERM would surely constitute a Framework. You might choose to redecorate the Framework periodically with a Program (Solvency II a prime example), but you wouldn't expect a Program to "mature" or "evolve", you expect it to conclude!

Nitpicking?




Thursday, 30 April 2015

Love RAFs? CRO Forum's Risk Appetite survey

The CRO Forum have recently published the results of their 2014 survey on Risk Appetite development in insurance entities. It is perhaps the oldest drum in Risk Management Town, but one we are always happy to hear the beat of, and while we shouldn't expect a forum with such luminary members to deliver any shocking results, a careful sift through the carcass is always a smart idea.
The Cure - to tolerance breaches?
The final presenter at the PRA's recent NED briefing noted that Risk Appetite is "no longer an aspiration", a comment I felt was further behind the times than Nana wearing Juicy Couture. That said, on page 8 it suggests that less than a quarter of firms are "very satisfied" with their RAF maturity, and over a third feel they have "a lot of work to do", so perhaps he hit the nail half on the head...

This document should clarify whether that caution is justified, and with 48 responses from the top table, it should be a reliable benchmarking tool. Despite starting like a GCSE essay ("the topic of Risk Appetite has exploded"?), it contains some useful, if a little dry, benchmarks, such as;
  • Principles for a RAF (p3-4) - hard to argue with
  • Main goals - dominated by preserving capital, while only a third are looking to "improve shareholder value" or "optimise capital"
  • Main stakeholder list (p5) seems good in breadth and priority
  • Almost everyone is using regulatory capital in some way as a Risk Tolerance measure (p9)
  • Stress and Scenario testing is being used by 80% to set Risk Tolerance levels, which feels at the right end of expectations
  • 60% report quarterly, with most others slightly more or less frequent
It takes a few odd turns, in particular;
  • One of the main objectives cited (p4) seem to be centre around boiling down things into a single document. I appreciate that pressure, but surely we feel that a RAF has a more substantial objective that document consolidation?
  • "Development of a Risk Appetite Statement is an evolution" (p6) - don't agree at all, it is a task, otherwise it would never get done.
  • Coverage of Risk Appetite Statements as "regulatory requirements", in particular under Solvency II. Just because the industry is choosing to discharge its obligations in EIOPA's Guidelines (SoG 15 & 16) by producing a single statement document, it doesn't make a Risk Appetite Statement a requirement.
  • Less than half are using a "1-in-x" loss that would breach regulatory capital in their Risk Tolerances - just feels like a very obvious one to use, so suprised by that number
Some of the more practical issues faced by firms are well covered, for example;
  • Difficulties for Groups when setting risk appetite. Does the parent/head-office set overall appetite, and the children sub-divide it by business unit/risk category/Both? Do the children set their own appetites and feed them up for aggregation?
  • Listing Risk Concentration targets looks awkward across the board (p5). While firms seem to be able to quantify Liquidity and Capital targets in their Risk Appetite Statements, other categories are much less consistently quantified. Market, Credit and Insurance Risk appear to be quantified by less than a third of respondents, preferring to address these in separate policies/guidelines (a Solvency II by-product perhaps?).
  • Setting Risk Tolerance levels is highlighted as a "minor" improvement required by over 60% of respondents.
  • There is a veritable bombsite of Earnings at Risk metrics in use, which is healthy for the industry I guess (p10).
  • What does one do when Risk Tolerance level is breached? Around a third are not OK with limit breaches and demand immediate rectification, while two thirds allow for a "Cure Period" to return the Risk Profile to its required form. A "Cure Period" seems the fairest breach rectification approach to me - after all, I don't care if Monday's blue...
A worthy benchmarking document, so fill those boots.

Monday, 29 September 2014

CRO Forum's Principles on Operational Risk Measurement - "Quant touch this"...

Hammer Time?
Current efforts in Op Risk quantification
Despite practitioners efforts over the last few years, Operational Risk continues to live on starvation rations when it comes to considered quantification. Never treated as an alpha-topic by executives inside insurance institutions, it has been treated with similar indifference by legislators, culminating in the  "totally inadequate" take-a-percentage methodology for calculating Operational Risk capital in the Standard Formula.

Internal Modellers on the whole are not likely to be shaming that technique with their efforts either (basic summary of their problems here, while InsuranceERM cover struggles as a whole with a roundtable here). A paucity of operational risk event (and near miss) data within firms may be good news for ORIC as a vendor, but from a parameter and data uncertainty perspective, it leaves internal model operators and validators in an invidious position, particularly due to the quantum of insurers' capital likely to be involved (10%, give or take?).

It's not that the actuarial world hasn't taken a stab at it before (here), aren't fully aware of the data holes (here), or haven't used the word "Bayesian" in a sentence (here). However an activity which was "in its infancy" in the UK as far back as 2005, is surely now old enough to be working in the mines...

I was therefore happy to see the unprolific-yet-important CRO Forum bring a white paper to the table, Principles of Operational Risk Management and Measurement. It is an update to a 2009 version which takes into account Solvency II demands, as well as developing practice within insurers over the period, the suggestion being that 2009's efforts were a little too Banking Industry-influenced.

While this document might feel at outset like an idiot's guide to "quanting" operational risk (and bearing in mind the number of prospective standard formula applicants - 9 out of 10 in UK - one may be needed soon!), the document touches on a number of noteworthy technical matters, in particular;
  • The Definition section doesn't read well, but they have attempted to include outcomes other than monetary loss into the Op Risk definition, which from experience will improve discourse within firms. Are they attempting to squeeze strategic and reputational risks into this box though?
  • Nice coverage of Boundary Events, and encouraging firms to consider them in their management of Op Risk.
  • Very specific treatment of Risk Tolerance throughout, using it in preference to Risk Appetite. This is because it cannot be avoided, and so tolerance levels should be used to trigger "RAG"-type reporting up the chain. Nice work, and well justified, but I have certainly seen the expression "Zero Appetite" used for Op Risk, so no doubt this is not an industry standard perspective yet! (p5-6)
  • No problems with their coverage of tried and tested techniques - "Top Down", RCSA's & Loss Event analysis (p9-10)
  • Nice turn of phrase regarding emerging risks on p9 - "...assess the proximity of new risks to the organisation". It may need to include an attempt to quantify to be fully useful for ORSA purposes.
  • Concept of residual risk arrives quite late in the day, but isn't omitted. Important, given how much qualitative, or spuriously quantitative, material is being promoted as aiding this measurement work (p10)
  • Seem to accept at the bottom of p10 that Internal Modellers must do more than curve fit on internal Op Risk Event data - good news I guess.
  • Internal Model validation pressures on current Op Risk quantification practices flagged directly (p16 in particular)
  • Guidelines on embedding Op Risk monitoring processes highlight just how much work some practitioners are managing to cover (p11). Quite disheartening for those with smaller budgets.
Ther are a few points to make on section B around quantification:
  • Pretty scathing on Standard Formula relevance. (p14)
  • Scenario Analysis sold as something of a panacea to cure the ills of incomplete Op Risk Event data sets, but no mention of the biases which seem to permeate the creation of the scenarios, which is sadly a hostage to the invitee list. (p14)
  • Expand more on scenario analysis, bringing the "severe but plausible" terminology to the table (p15)
As well as the following generic comments;
  • Is risk measurement - "a tool for embedding risk culture in the organisation"? I would say so, particularly in the Op Risk arena, where decision makers will need to be involved at scenario-compilation time.
  • That said, they then go on to reference "senior management sign-off" of scenario work, which is somewhat contradictory!
  • Overweight in references to "culture" and "tone at the top", like most white papers these days (see the FRC's efforts from the other week). Playing with fire as a profession by shoehorning references to "culture" into everything.
  • A couple of horror-show schematics used on pages 7 and 8 - the Forum must know how much time risk professionals lose walking non-experts through things like this. They serve no purpose, and detract from surrounding text.
  • Attempt on p9 to solicit business for ORIC?
It was Professor Jagger who accurately prophesised "You can't always get what you Quant" - I'd say the Risk profession concurs, based on these very welcome principles.

Wednesday, 13 June 2012

ORSA guidance materials from CRO Forum and Lloyds - any help?

It is always nice to get a bit of friendly steer around ORSA when the powers that be stubbornly refuse to give us boxes to tick!

Released over the last week or so came two such documents, one from Lloyds of London and the other from the CRO Forum.

The Lloyds effort is of course tailored for their syndicates, but the areas they emphasise clearly have merit for any organisation which is embarking on the ORSA adventure, whether sponsored by Solvency II, IAIS ICPs, the NAIC, or indeed any other random acronym! In particular I liked;
  • Clearly set out an explanation to cover difference between regulatory and economic capital measures
  • That while the ORSA Report would be expected to set out the impact of shocks over the medium term, this does not imply that a multi-year model is required (anyone struggling to keep it stochastic after year 1 would be relieved to hear that!)
  • Small set of simple questions which one might like to ask their Board after they review the report in order to establish use
  • No specification on size!
The tables which make up the bulk of the document should be a useful reference point for anyone with an inferiority complex, as it highlights gaps which have been identified during their own QA work, as well as suggesting remediation. Appreciating ORSA is only required for IMAP from a use test evidence perspective (which they comment on in the Q&A in the appendix), any chance that these gaps contributed to the delay in their submission?

The CRO Forum paper on the other hand tries to cater for both the poachers and the gamekeepers by summarising observable best practices from regulatory-themed bodies (who I suppose will ultimately determine what's hot and what's not on the matter). From their doc, I noted the following;
  • Potential divergence between what lobbyists said about ORSA supervisory report when feeding back on Level 3 (i.e shouldn't differ from that presented to the AMSB, otherwise what would supervisors be considering it against) and the CRO Forum (who expect it to be a "summary of the results of the ORSA assessment") - doesn't feel like semantics the more I read it, so worth highlighting
  • Value of the ORSA Report for the AMSB is covered in a few paragraphs, which is always handy for board/senior management briefing
  • Strange bit around internal approval of ORSA reports, stating that the AMSB should review but not approve the ORSA Report, and that this is as per Level 3 - worth some attention if you have structured your ORSA governance around Board sign-offs of the associated reporting
  • An "illustrative purposes only" ORSA Report structure, which has no more or less merit than any others you may have seen, other than it is less granular than some which have emerged publicly from consultancies etc
  • Tips the hat towards leveraging RSR and ORSA administrative efforts in order to reduce duplication.
Whether or not you gain something from reading these materials, it's always nice to know someone is having a go!

Thursday, 26 April 2012

Geneva Association 7th Chief Risk Officer Assembly - Axa and the ORSA

Sadly my schedule doesn't allow me trot down to Switzerland any more than the next man, but the Geneva Association have just published some materials from their CRO Forum from back in November - one in particular that caught the eye was from Axa's Mr Menioux on the ORSA.

While the first section is fixated with the reporting side of ORSA as opposed to the creation of the continuous processes which ultimately crystallise in a report (sadly par for course I would say), the second section goes on to cover Axa's ORSA schedule from now until 2013.

As the French only have around 3 models to approve (c'est une blague, 4, peut-etre?) it is less of a surprise that they are waiting until their year-end 2013 ORSA Report has been approved before submitting their model application, but it is interesting that the FSA with their 70+ applicants stated that they would not be looking for ORSA reporting in IMAP specifically!

They also mix model validation and ORSA together at the back to state that they are bringing in PwC and Mazars to assist with independent validation, as well as using internal audit. They finally tell us the structure and length of their ORSA Report (shooting for around 50 pages at Group level, with localised ORSAs as well.

Good intelligence for anyone knee-deep in this particular Pillar 2 game...

Sunday, 5 February 2012

Reactions Magazine - CRO Risk Forum pullout (if they fix the link)

Some really nice pieces in January's CRO Risk Forum paper from Reactions magazine (you should be able to grab the paper from the link, but it does appear to be faulty at the time of writing).

A number of major CROs have contributed (Munich Re, Nationwide (US), Zurich, Scor), and they cover some juicy material on the Solvency II front, as well as some generic ERM matters and CRO role development. Pieces that particularly piqued my interest were;

Zurich's Lehmann on the role of the CRO
  • Opines that, a decade ago, the CRO role was considered to be covered by the Chief Actuary in insurance undertakings
  • Stresses that a CRO needs to have direct access to the CEO - though that did little for Paul Moore of course, or indeed as reported only last week, Michael Roseman at MF Global.
  • Speaks supportively of the CRO Forum's Emerging Risk Initiative - strangely, as a subject so fluid and topical, the section of the website dedicated to this is sparser than my hairline!
  • States that "...advanced companies have a risk function that defines the risk strategy and clearly sets risk appetite limits" - this is a pretty breathtaking thing to say, which I can only assume has lost something in interpretation, as the question it responds to relates to underwriting. In the context of my last post on Risk Appetite, I would never see myself as a second line function setting the limits of risk appetite.
  • States that "[A company's ERM Framework] defines its risk culture" - hate to go all 'chicken and egg', but would a company's risk culture not determine their ERM Framework requirements?
  • Tries to associate the Insurance industry's relatively safe passage through 2008-2011 on ERM advances, where I would be more inclined to attribute much of it to the 'unique features' of the industry that the CEA like to bandy around when lobbying for SIFI exemptions".
Nationwide's Mahaffey on the USA's new CRO Council
  • Emphasises that the US-version of Europe's CRO Forum is not just dedicated to Solvency issues ("at the cost of engaging with other issues"), citing ratings agencies, emerging risks and federal/international developments as other agenda items. I suspect the European guys may find that snipe slightly harsh, regardless of Solvency II being the big fish right now.
RSA's MacDonald on ORSA
  • Talks throughout interchangeably about ORSA process and ORSA report. Doesn't help when he goes on to state "Identifying who owns the ORSA is of primary importance" - Articles 44 (4) and 45 (1) would tend to identify the process owner, but the unconcentrated chatter in the Level 3 doesn't uncontrovertably assign document ownership (or indeed what the significance of "owning" the ORSA Report may be). 
  • Piece on alignment with internal strategic or operational planning process very sensible - no point in shifting dates which are probably carved in stone, if you can fit the ORSA process around them
  • Identifies most of the company bar the tea lady as 'stakeholders' for engagement - I suspect there are that many customers/end users of the output, but frankly most could make themselves scarce during process construction and not be missed.
Scor's Trainar on Solvency II progress
  • Suggests that Solvency II in its entirety should "...bring enterprise risk management in the industry up to standard" - doesn't quite tally with his CRO Forum colleague above, who seemed to think the standard helped keep it afloat during the crisis!
  • Worried about the size of the Solvency II challenge should it be served up "...with a heavy and indigestible bureaucratic sauce" - truly sparkling wordsmithery!
  • States that "Solvency II is an excellent micro-economic reform but a mediocre macro-economic one" - hence the delay mon ami!
Towards the back are a couple of nice case study/example pieces which you might enjoy from a benchmarking perspective.

Wednesday, 15 June 2011

Barnier Letter to CEA/CRO Forum/CFO Forum - full text

Bit late, but for my own records I'm just making sure I have Michel Barnier's full response to the lobbying forums on the blog (previously only had an abridged version).

Few notes;
  • Solvency II "has been subject to more consultation and impact studies than any other piece of legislation I am aware of" - referenced like a badge of honour, as opposed to any negative connotations
  • "Not surprising" that surplus capital has declined - is the implication that the industry is undercapitalised
  • Commission is not convinced by lobbyists argument on contract boundaries in particular