Showing posts with label ERM. Show all posts
Showing posts with label ERM. Show all posts

Wednesday, 12 August 2015

Insurance Banana Skins in 2015 - PwC and CSFI

PwC and the CSFI guys have teamed up for another Insurance Banana Skins publication, a particularly useful doc for the BAU Risk world, and one which I have covered on the blog in years gone by (well, 2011's and 2013's anyway).

In particular, I always found it useful as a means of digging out the kinds of awkward cross-bred expressions which would invariably end up rolling out of 75-year-old INEDs’ mouths at the next Risk Committee meeting, probably due to someone trying to sell insurance cover for it, or a business journal doing a centre spread about it. On this basis, I was delighted to see “Cyber Risk” given prominence this time around, which is the highest new entry, and apparently a “new risk” - here’s the sales forum, and here’s the HBR white paper!

Sarcasm aside, given this pulled in over 800 responses from around the globe, and across the distribution and provision side of the industry, the content is worth poring over and briefing colleagues on if this is your day job. There are also plenty of quotes from the great and good wrapped up inside as well.

I’ve only jumped on a few of the findings below;
  • Regulation remains the top risk for the 3rd survey running, and for the 4th out of the 5 actually held. It did take a ‘world’s end’ scenario for investment returns to knock it off the top in 2009 though, which suggests that those surveyed are happy to bleat about regulatory concerns, regardless of the rest of the exogenous threats to insurance firms.
  • Much of the top ten is focused on investments and returns, whether it be interest ratesinvestment performance or guarantees.
  • Governance and management of insurance companies seen as an area of declining risk – does it therefore warrant the Banking industry-inspired whip that SIMR is about to introduce in the UK?
  • Similarly, Business Practices, incorporating misselling, is falling down the list – not sure a UK-only survey would be so generous!
  • Cyber Risk itself was only #6 on the list for Life Companies, while #1 for Non-Life – wonder why the guys who are selling cover rate it so highly? Of more interest, North America had it as #1 “by some margin” – this suggests the wave will be coming across the Atlantic in the next 12 months (a nice precursor of how that will emerge here)! It is written up nicely however, with cloud storage, and the richness of data held on customers, being elements which make insurers prime targets. It doesn’t dwell on the proliferation of legacy systems in insurers however, which always felt to me a good reason for criminals to ‘have a crack’.
  • Europe considered the interest rate environment, regulation and guarantees to be the top 3 banana skins, which given the aggressive tailoring applied to Solvency II in the drafting stages to negate country-specific difficulties in these areas (MA/VA/Transitionals), is no surprise.
Oh, to have a day job again…

Wednesday, 24 June 2015

CRO Forum on Risk Culture - comin' from the body heat?

Risk Culture
- need another hero?
A subject which is gathering more steam than Tina Turner's windows, Risk Culture has been given the kid gloves treatment by the CRO Forum in their paper, Sound Risk Culture in the Insurance Industry.

They say at the start that the topic has become "prominent in regulatory circles", which given EIOPA appear to be wining and dining the subject (here and here in the last couple of weeks alone), is something of an understatement. Their increased interest has no doubt been fuelled by the FSB's work on the subject from a year ago. In addition, the Financial Reporting Council took a shine to the topic in its last update of guidelines in late 2014 (point 27 in particular), while cultural failings have turned the FCA into a modern day Robin Hood (speech from inception time here).

As well as fiddling around the edges of definition, the paper expands on a few examples of where cultural change can be driven from, stealing from a few other industries (aviation in particular) and a couple of insurers (Zurich receiving particular attention).

They fundamental base they work from is pretty fair:
  • No "good" or "bad" culture, hence they talk about practices that encourage a "sound" risk culture throughout. Given that ropey culture does not necessarily prevent the achievement of strategic goals, this smart.
  • No "one-size-fits-all" concept of Risk Culture (i.e. don't look for one in this paper!)
That said, the definition used for the purposes of the paper from the NN Group CRO is actually a pretty good one - "shared philosophy of managing uncertainty" etc - though it does suggest that a failure in risk culture might simply be someone not sharing the philosophy, which I suspect is where a lot of your more pragmatic colleagues sit!

There are a number of sound inclusions throughout;
  • Emphasising the links between risk culture and conduct risk currently being force-fed to the industry by EIOPA (p3)
  • The chart on p6 showing survey results of essential elements of risk culture - senior management and Boards leading by example is evidently seen as more important than risk-based remuneration, despite the legislative attention the latter receives (including this week in the UK).
  • Zurich's internal 10 question survey on culture assessment - contains the gorgeous expression "organisational humility", as well as bringing some of the granular risk culture elements onto the table, such as treatment of whistleblowers.
  • Highlighting the "common phenomenon" of management teams containing people with the same personal attitudes - could benefit the creation of a "shared philosophy" without necessarily any of the benefits.
  • The illustration of NN Group's "Risk Culture Dashboard" (p11) - I don't have preference for it either way, but it does illustrate how much effort one can direct towards risk cultural identification, assessment and monitoring, which begs the question "is there that much value in it?" They seem to like it as a way of covenying the concept in the business in any case.
  • Pages 13-14 provide some good brain candy for those who have ambitions to educate or brief their colleagues on risk cultural matters. Zurich's "we are all risk managers" campaign looks like it probably has legs (more on it here).
There are a couple of mildly objectionable parts within;
  • Concepts of "Risk Vision" and "holistic" dropped in early doors and littered throughout, as well as a few extras such as "risk perspective" - the kind of obtuse terminologies which serve to divorce Risk functions from their colleagues
  • That firms should have a "clear vision" for their risk culture - why would something as opaque as culture be expected to be "clear". They don't even define it as a term in the paper!
  • Concerned that risk culture is "...only practiced by risk specialists" currently - how can this be if risk culture is "...an element that influences and is influence by various forces"?
  • Tha an organisation's corporate culture and risk culture "must be linked" - how are they not one and the same thing?
  • That Risk Appetite Statements are "effectively part of the business strategy" - as opposed to "actually"?
  • Use of the term Risk Profile as if it is unquantifiable, specifically that a firms who learn from their mistakes rather than chastise those who make them "tend to have a better risk profile". Not clever.

Tuesday, 2 June 2015

PWC's Risks in Review - White Paper, Black Sabbath...

A quick dive into the wider world of ERM, courtesy of one of our Big 4 friends, ambiguously titled Risks in Review.  PwC's document (short sign-up required) is US-centric and multi-industry, so for the Solvency II crowd you might need to sift for the goodies (a good illustration of which side of the Atlantic it leans towards is that CFO.com reported on its highlights), but for anyone in the ERM space, there should be something for you here.

A bizarre stat is laid out at the beginning in that 73% of the 1,200+ senior executive[s] and Board members respondents to the survey agreed that "risks to their companies are increasing". Whether this be in reference to the number of risks faced, increases in the likelihood/severity of one's existing risk universe, or their perceptions on emerging risks, it certainly suggests that exogenous and endogenous concerns have not abated in the minds of corporate leaders. However, given the risk immaturity within firms that the rest of the document serves to highlight, the lack of definition is rather unhelpful.

Appetite - For Risk or Bats?
As the survey covers multiple industries, it has the more generic risk classifications in mind (i.e all major quantitative risk balled up into "Financial Risk"), which will no doubt gnaw at anyone on the financial services side, but at the same time, it's not all about you!

The pat on the back for those surveyed is the sobriquet of "true risk management leaders", handed out to 12% of respondents. It frankly doesn't feel like a valid aspiration for an entity, more that being a "risk management leader" would be an implicit part of the make up of any firm which successfully delivers on its strategic objectives.

That aside, the Leaders (of which financial services companies "...represent a sizeable portion" of!) are congratulated for;
  • Aligning RM Programs with their businesses.
  • Communicating Risk Appetite and Risk Tolerance through the business - nothing on hard risk limits in the paper though
  • Being "able to take greater business risks" - I don't necessarily make the link between being "good" at risk management equating to taking greater risks, unless that is part of the business strategy one has aligned the RM Program with.
  • Take aggregated views of risk over multiple areas
  • Using techniques such as emerging risk identification/forecasting, scenario planning and stress testing
Laggards on the other hand
  • Have no formal Risk Appetite Framework (only 38% of respondents do)
  • Don't integrate Risk Management Strategy with business strategy (only 31% do)
They also hook the leadership qualities of risk management to some quantitative "value of good risk management" work on p5 (a topic which Towers Watson recently tiptoed around due to a lack of quant), namely that their profit margins and margin growth will outstrip peers. The growth of profit margins might be a bum steer, as the macroeconomic environment is perhaps less kind to industries other than financial services, who of course would have seen margins peak comparably faster over recent years due to the size of the trough in 2006/08!

As ever, the lexicon used in papers such as this takes a dip in the lake of dubiosity, for example:
  • That companies should "...treat risk management strategically" - as opposed to what, "operationally"? This kind of expression suggests that risk is not already considered in strategy, which feels unfair and unrealistic, even on the immature firms surveyed. That there isn't a functional ERM Framework to enhance that work does not mean it isn't done at all.
  • Risk Appetite Framework should have "buy-in" from senior management and the Board. Why "buy-in"? They should be deeply involved in the construction of an RAF, and their successes or failures as management should be inextricably linked to operating in line with it, not asked to nod in approval at the next Board/EXCO
  • "Having a clearly defined risk appetite framework allows companies to quickly assess strategic decisions in the context of risk" - that of course was not a given...
  • They also follow the tactic used in the Towers Watson paper in referring to risk management "programs" as opposed to "systems" or "frameworks- again, I'm not trying to labour the sematics of it, but a Programme for me has an end, and the work of a risk management function simply does not. This is perhaps just a psychological angle being worked here to drill into prospective clients that Programs can be boosted with a burst of external advice, but I find it increasingly disagreeable, particularly given the risk management leadership traits highlighted in this document, which most certainly do not lend themselves to the workings of a transient Programme.
Other stand out points would include
  • Alignment of RM Programmes against each business function (p9) - horrible result for Sales & Marketing, even for Leaders, and suggests it is an area for us all to redouble our efforts
  • Similar to Towers, talk of firms "drowning in data" - cannot fathom this for the life of me, but perhaps that's because I can use pivot tables and SQL server!
  • GE Capital's approach to administering Risk Appetite (p16) - very clean, and in a manner which the CRO Forum would appreciate.
  • Finally, a really nice section on p19 which shows the discrepancies between executives and risk professionals regarding their own firms' prospects. The Fannie Mae CRO suggests that Risk Management staff are "paraniods by profession" which given his employer's recent history, doesn't mean people aren't out for you!

Tuesday, 19 May 2015

Towers Watson's Global ERM Survey - Knowing ERM, Knowing You...

A couple of treats from two of the powerhouses of the 'writing things down' industry on the practical use of ERM to drive decision making, rather than simply accompany it.

Towers Watson are targeting the Solvency II audience (at least on this side of the Atlantic) with a timely release of the results of their 8th Biennial Global ERM Survey. I say the results, as there is no sign of the full survey itself - any closer to their chest, it would be an areola's backpack...

As ever, these kinds of publications oscillate between flannel and insight, so while I cover those below, feel free to read the infographic and call it quits!

General observations from the main press release include;
  • Three-quarters of (the almost 400) respondents say they are viewed as "important strategic partners" by the Board and Executive - I'm less inclined to see that as a mark of superiority, given that risk functions in some firms won't have the ambition or aptitude to achieve that status
  • Implication that some respondents do not have a risk appetite framework in place - very worrying, unless this is just bad wording.
  • Some firms said to be only "...using ERM for regulatory compliance". It may depend on jurisdiction, but I'm not inclined to agree that is even possible.
  • The "ultimate vision" for a firm's ERM capabilities is referred to, which is a brow furrer, even conceptually. TW seem to bundle up risk culture, risk monitoring and risk tolerance into the "Vision" bucket, in case that term takes your fancy.
  • The expression "very strategic approach" appears in print for the first time!
Getting Value from ERM?
- "Kiss my Face"
From the more elaborate Q&A document, we find the main granular material which TW were prepared to publish. Fortunately for readers this side of the Atlantic, the EMEA Director Mike Wilkinson holds sway over much of that conversation, including his tale of the firm who recently had an ERM/Business Strategy-inspired "Aha" moment.

That session contains a fair bit of contention, such as;
  • Asking the questions "What's the purpose of risk management" or indeed the "purpose of your ERM Program" in the Q&A - if these had been directed to the respondents themselves, it would have contextualised a number of the seemingly negative responses i.e. If the purpose of your ERM Program is "don't get shut down", you are probably less bothered about being a "strategic partner"!
  • That the business should "...challenge the risk group to create reports that help them make decisions" - Excel Jockey is hardly the work of a strategic partner...
  • In a similar vein, that insurers are "drowning in data, drowning in metrics" - hardly a new phenomenon, and doesn't give any credit to the critical faculties of employees to filter what they do have.
  • "...many [internal capital] models have matured" - a sharp intake of breath can be heard down at Moorgate!
  • That "...an ERM Program can't properly be assessed until it has been in place for a while" - pretty sure the S&P crowd wouldn't hold off assessing you while you "embed"
Mike in particular does manage to keep a good focus throughout the Q&A on maximising trade-offs between risk and return being the big differentiator between Risk functions who are capable of influencing strategic decision making, and those who are perhaps more likely to be tabling red-amber-green reports tracking the outcomes of decisions which have already been made.

Other strong points include;
  • In the context of Risk Tolerance, how to cater for the discretion required by an insurer's asset managers in handling investment portfolios.
  • Touches on a couple of pieces which stood out in the CRO Forum's Risk Appetite publication last month, namely around the increasing number of measures being used to run businesses other than capital, allowance of movement within risk tolerance levels, and whether firms have effectively articulated their organisation-wide Risk Appetite and Risk Tolerance limits down into its subsidiaries/departments.
One aspect which gnawed at me throughout this reading is the constant referrals to "ERM Programs" - I don't think I am bathing in semantics to suggest that Programs normally start and end, whilst ERM would surely constitute a Framework. You might choose to redecorate the Framework periodically with a Program (Solvency II a prime example), but you wouldn't expect a Program to "mature" or "evolve", you expect it to conclude!

Nitpicking?




Friday, 19 September 2014

FRC on Risk Management and Internal Control disclosure - insurers way ahead?

Muddy Waters
- public disclosure on Risk
The UK's Financial Reporting Council have released guidance on Risk Management, Internal Control and related reporting, just in time to help muddy the waters for UK insurers, who have no doubt finally got their risk, actuarial and compliance functions writing non-conflicting words with Solvency II preparation in mind!

Anyone who has written, peer-reviewed or socially read these sections of public reports (i.e. me, and any other geeks), will know they are normally;
  • Boiler-plate, and completely transferrable between industries, regardless of their disparate risk profiles
  • Aligned to the Strategy sections with a few anchor words, but otherwise divorced
  • Frequently unaligned with the ERM frameworks used internally - i.e. "this is what the City wants to read", not material on our actual risk profile!
Given that this is only guidance, and is further only directly relevant to LSE listed entities, readers may be inclined to take the content with a fistful of salt. There are a number of noteworthy aspects to this publication however which maybe show where the mindset of supervisory-types has got to in the eight or so years since the financial crisis commenced.

 I took the following general points from it;
  • Very little for listed insurers to be concerned about, if they have prepared adequately for ORSA and supervisory reporting (SFCR, RSR) - indeed, their reporting teams will be delighted with the amount of content crossover! Check out the (still not finalised) Delegated Acts of Solvency II in order to see why listed Insurers won't need to stretch to meet these.
  • Frequent references to "culture", as opposed to "risk culture". Checking the FSB's take on Risk Culture from April of this year, one can appreciate the FRC's desire to gemmy culture into these guidelines, if perhaps not the execution - one fears the "culture" words are likely to become a little weasely.
  • Multiple crossovers into ORSA language, in particular re-emphasising the importance of the alignment of risk management with business strategy.
  • Good work in section 4, bringing in the "IMMMR" concept from Solvency II, as well as assessment of current and emerging risks, and assessing exogenous and endogenous risks when doing so.
  • Recommend that risk assessments are performed at inherent and residual level, and that control effectiveness is also considered when arriving at one's final assessment
On the technical front, the following elements caught my eye
  • "Emerging principal risks" used as an expression - not sure if that stands up to scrutiny i.e. if something is emerging, can it be a "principal" anything? How would you measure it to gauge "principality"?
  • Reference to "high profile failures in risk management" in recent years, which feels a little finger-pointy - we could deconstruct every corporate failure to one of risk management failure
  • "Risk Appetite" put into inverted commas within the guidance, but not in the appendices - can't quite work out the aversion to definition given the FSB's work to date at the very least, but certainly EIOPA have similarly dodged it (p59), and looking at Appendix 1 of the Irish regulator's thought paper on Risk Appetite, one can see why!
  • "It is the role of management to implement and take day-to-day responsibility for board policies on risk management and internal control" - really? responsibility for their implementation, sure, but policy content?


Wednesday, 19 March 2014

Myners briefing on Governance at the Co-op - working class barred from the Board?

Wolf - step away from the door...
A corporate governance story that will echo in the eternity of MBA classes for years to come, the unravelling of the UK's Co-operative Group from the benign grocer-cum-divvy machine into a ying and yang shotgun conglomerate of opposites is proving to be a watershed moment for UK plc, with stakeholders attempting to balance myriad legal, political and ideological considerations in order to both keep the wolf from the door, and preserve the principle of mutuality for its membership.

There are no surprises that the crux of the Group's issues lies in its banking arm, nor that being acquisitive during the financial crisis (here, here and here) has proven to be poor strategy. Keeping the wolf from the door has therefore largely been delivered through the tried and tested combination of begging and borrowing, which the recently departed CEO appears to have delivered with some aplomb.

Governance structures
- choices choices...
However, the Group's hiring of Paul Myners back in December, a man with an extensive collection of t-shirts and hats, to independently review its governance arrangements, seems likely to deliver to the membership a menu of choices as unpalatable as a Sunday skip-dip.

Lord Myners has hurriedly delivered a briefing on his findings to-date, as well as performed some mainstream media duties (here and here), following the Group CEO's resignation last week. This early sighter was seemingly unscheduled, but the manner of the CEO's departure ("a tragedy" in Myners' words) meant that his findings to-date could not wait until May for its full publication date.

Myners has therefore naturally delivered a ruthless and scathing take-down of the governance structure and processes within the Co-operative, while calling out the Board member who are clearly well schooled in how to game the system, as well as the playground tactics/rabbit-in-a-hat tricks that turn "one-man-one-vote" into "one hundred men-all votes"!

Killer quotes
  • The group endures a significant "democratic deficit"
  • The future of my recommendations lies in the hands of around 100 elected individuals on the current Group and Regional boards, few of whom have any serious business experience and many of whom are drawing material financial benefits from their positions
  • There is a phrase frequently used in Co-operative Group circles that the Executive should be "on tap but not on top"
  • ...the Group Board has spent far too much time on transactions such as Somerfield and Britannia which have been breathtakingly value-destructive
Observations
  • The "exceptional skill and tireless efforts" of the Executive team are cited as the reason for the Group's survival in its current form
  • The current governance framework is variously referred to as "flawed", suffering from "acute systemic weaknesses" and having "consistently produced governors without the necessary qualifications and experience to provide effective Board leadership". Ouch...
  • That the Groups social goals are not aligned with its strategic and commercial objectives. This is of course less of a worry for its financial services competitors.
  • The the Group's "massive scale and complexity" means that a man-off-the-street approach to electing Board members, which may be sufficient for a farmer/grocer co-op, is not suitable.
  • Shatters the "myth" that the Group has always been run by lay members, as opposed to those with commercial experience.
  • The thought of creating a board of INEDs and lay members is disregarded due to the potential for creating "second-class citizenship"
  • Highlights that Co-op's core business of groceries is savagely competitive at the moment (just look at Morrison's and Sainsbury's), so continued ineffective governance could be devastating
  • Notes that there have been previously (disregarded) reviews of its governance architecture, which is "long known for its labyrinthine complexity and its disfunctionality"
  • Stresses that, due to the current voting structure, acceptance of  his recommendations "...potentially lie[s] in the hands of fewer than 50 elected members". It sounds like they haven't been shy to remind him of that either!
Recommendations
  • Halve the size of the Group Board, which will be subject to annual re-election
  • Independent Chair, with no previous association with Co-op
  • 6-7 INEDs and 2 Executive Directors
  • All with qualifications of a similar ilk to its (listed) competitors
  • Create a National Membership Council (NMC), with a 12-person executive committee to effectively represent the membership and co-operative principles and values
  • The Board to be subject to scrutiny by the NMC, who have the right to be consulted on "key strategic and operational intiatives"
  • "Arrangements" to be made to safeguard the confidentiality of information shared between the Board and the NMC (certainly not the case with current arrangements!)
The entire document feels drenched in class warfare and spectrum politics. That rather hideous take from the existing Board on their executive team ("on tap, but not on top") feels like the inspiration of Myners' recommendation for a professionalised, appointed Board, rather than the beer and sandwich brigade which currently exists.

That said, there is thought on the left-wing (here and here) who feel that mutuality and co-operation should remain unsullied by the commercial world, who remain unable to affect much in the way of democratic change in Boardrooms even after the raft of FRC-sponsored guidance released over the last couple of years (though PIRC are trying!). Is one failed attempt to democratise stakeholders best replaced by cherry-picking from a similarly deficient model?

On the basis that I have banged the drum for background diversity in Boardrooms (not just gender or race), and the existing Co-op Board is "diverse" in that respect, I'm left to wonder if I've been barking up the wrong tree. The Board delivered by their existing process is neither fit nor proper, and are able to outmanouevre their executive compatriots armed with little more than a working knowledge of provincial politics and a polyester suit.

Should we therefore use the grey-area of "fit and proper" regulation to ban the contract plasterers, nurses and retired publishers of the world from financial service provider Boardrooms on the basis that they don't have an MBA, and count with their fingers? Or can one make a valid contribution to a financial services Board of directors regardless of the colour of their collar?

Thursday, 28 November 2013

Accenture Insurance Sector research - Global Risk Management survey

Flood Risk?
A nice generic risk management benchmarking piece from the guys and girls at Accenture came out this week, and after I spent last week at the Leicester rugby game, I was happy to see another 15 "tigers", albeit this time scattered throughout the survey paper itself, presumably as a subtle metaphor for "death by tiger" risk...

It is made up of 98 C-suite respondents (nicely spread across disciplines), is Insurance sector-specific, and Global in coverage (one-third Europe, half N.America), so should be useful to any reader for trend-spotting and Board briefing.

From the document itself, I've pulled out the following;

Risk Governance
  • 98% have their "risk management owner" reporting to the CEO
  • 96% have a senior executive (regardless of title) as "risk management owner"
  • 80% have their "risk management owner" report regularly to the Board
  • 55% had a titled CRO
  • A number of those stats (whilst improved since their last survey) are a poor reflection on the Global insurance industry, but perhaps reflect where corporate culture is outside of the EU/US axis
  • Of the governance bodies, I was surprised to see only 60% of Life companies have an operational risk committee
Solvency II/Non EU equivalent legislation-specific
  • Over 80% of Life and P&C respondents seem happy that they are preparing well for their regulatory initiatives (Solvency II or local equivalent).
  • Other than Internal Model development, the main outstanding issues for Life insurers to be prepared for Solvency II/equivalent is IT architecture and Data Management/Integration. For P&C, documenting risk processes and developing a meaningful Use Test are also worrying at least half of respondents.
  • Issues such as training and education, risk culture and risk governance documentation are relatively low on the priority list.
  • Conversely, when asked on a 1-5 scale about specific areas of risk governance, respondents were more positive about their Data preparations than their risk governance - go figure!
  • Use Test preparation remains a laggard throughout.

Generic

  • Top external pressure was Legal risk, and by a good distance. Regulatory risks relatively low on the list, perhaps reflecting Europe's low weighting in the quantum surveyed.
  • Risk Management seemingly well integrated with strategic deployment, but not with product development or reward.
  • Poor statistics around embedding risk management into core functions.
  • Two thirds of Life respondents noting that a lack of "early warning capabilities" impedes emerging risk management.
  • Over half of Life companies said investment benefits ("above and beyond" continued compliance with regulations) would come from better reporting and better integration of Risk and Finance.
There is some of the softer stuff on aspirational elements of risk management thinking at the back, but if you just want to check against your peers, you can save that for a rainy day.


Wednesday, 23 October 2013

Standard and Poors on European ERM - momentum lost after Solvency II delays?

S&P released these pearls of wisdom regarding ERM within European insurers, specifically whether the additional breathing space offered to Solvency II may put the brakes on developments.

There's certainly no sitting on the fence with them - they start with the following as a statement of fact;
...the delayed start date of Solvency II has prompted some insurers in the region to reduce their efforts in developing ERM
Unsupported, but probably fair! They are also overwhelmingly positive on Solvency II on the whole, for example;
Solvency II remains a major driver of ERM improvements in Europe
the Directive has firmed up insurers' approaches to risk appetite, risk governance, and risk reporting
The introduction of the Own Risk and Solvency Assessment (ORSA) process...has helped to embed risk appetite in insurers' operations
Solvency II has brought risk management to the fore in insurers' strategic planning 
Easy to take any of those comments to task in the UK and Ireland, where national corporate governance code revisions, listing requirements, IAIS considerations and developments in both the actuarial and  nascent Risk professions are all taken very seriously by the respective industries, all the while cognisant of the shadow cast by Solvency II. In addition, the disciplines espoused by S&P's ERM assessments are practiced to a decent extent in existing ICA/FCR processes/reports, regardless of how 'ORSA-fied' they have become over the last couple of years.

This potential slight to the Western world is remedied on p7 however, where the research acknowledges that Western Europe effectively leads the way on ERM, and in the appendix (p8-12) where the league tables sit Germany and the UK firmly at the top of the ratings class.

They ultimately get to the real crux of their fears with this;
We would view negatively any evidence of a reduced role for economic capital in insurers' capital management arising from the delay
They are also gunning for insurers who continue to sell uneconomical products in the face of sustained low interest rates (p4), and validation standards in internal modelling (p5).

One would hope that, certainly in the UK with ICA, ICA+, and a supervisor who is continuing to staff pre-application for internal models adequately, that momentum around using economic capital in decision making will not be lost during 2014, particularly now that the PRA have as good as said that they accept EIOPA's preparatory guidance.

So give this a read if you want to know where your firm lies in the S&P ERM rating table, and if their opinion matters to your bottom line, be sure to quote this material when your Programme sponsors try to take the pace of 2014 Solvency II activity!

 
 

Wednesday, 7 August 2013

Deloitte's 8th Global Risk Management Survey - cause for concern?

A survey from Deloitte has recently hit the news stands, namely the 8th edition of their Global Risk Management Survey - I thought I'd postpone my August holidays to pick through the bones of it (?).

The data was gleaned from an online survey they sent out to CRO/equivalents back in Sept-Dec 2012, so is a bit dusty, and there were 86 respondents, so a half-decent sample. It isn't dominated by a particular sector or continent (p7), but there are more conglomerate/bank-heavy respondents than pure insurers.

There is an infographic for those of a short attention span with a few headline numbers, but having sifted through the larger doc, I found the following elements worthy of note;

Boards, Committees and Risk Management
  • 80% of Boards are reviewing and approving Risk Management Policies/ERM Frameworks and Risk Appetite Statements. Bearing in mind the types of organisation in the sample, that is disappointingly low.
  • 25% don't review individual risk policies
  • 23% don't review strategy against risk profile
  • Almost half don't invite CRO to EXCOM meetings
  • Almost two-thirds delegate risk oversight to satellite committees (and two-thirds of those delegate to a Risk Committee)
  • Only half have their Risk Committee chaired by an INED.
  • Use of specific management risk committees for individual risk types tends to cluster around the 40-60% bracket (for example, 60% have an ERM committee, while 44% have an Op Risk Committee). Heavily weighted by organisation size i.e. larger ones tend to have them! 
  • Emerging risk reporting not supplied to 30% of Boards
  • Model validation results not supplied to 70% of Boards!
  • 66% (of insurance respondents) have their Boards responsible for reviewing economic capital results
CRO and Risk Management Function
  • 97% of large respondents have a CRO, 81% of smaller firms 
  • 88% using "3 Lines of Defence" (almost all of the larger respondents do)
  • 62% have an "ERM Programme"
  • 58% increasing risk management budgets (still!)
  • In the list of tasks currently performed by CROs, the fact that only 63% are involved in the approval of new business lines/products is pretty telling, and not in a good way.
Other control functions

  • Almost half of respondents said that Internal Audit and the ERM Framework do not use common risk categories and language.
  • 33% do not have a independent model validation 'function' (remember, the banks are in these stats as well!) - most of those who have made provision park it in the Risk Management function.

Risk management techniques

  • 90% using some form of stress testing in the business, with most saying the outputs are used in business planning, strategy setting and identifying risk tolerance. More than half however don't use the outputs in the allocation of capital to lines of business.
  • 74% have some type of Stress Testing policy
  • Over 20% either do not have a Risk Appetite Statement, or only have a quantitative one
  • Almost 70% still use regulatory capital as one of their quantitative measures in their Risk Appetite Statements
  • Risk limits tending to be set at enterprise level, as opposed to business or desk/subsidiary level - stats are a little murky due to the emphasis towards banking sector.
  • Model risk and Liquidity risk seem to be the risk types least factored in to companies ERM programmes
Management of Key Risks
  • Full list on p24, with the percentage shown representing the number of respondents who thought their management of each risk was "extremely" or "very" effective - stand outs were that perceptions of the effectiveness of the management of Operational, Model, Outsourcing and Data risks appear to be much lower than one would hope, with Lapse risk management ranked unusually high.
  • Op Risk KRIs and Loss data only collected in 60% of respondents
  • Just over half are modelling Op Risk in some way - varying degrees of complexity experienced
  • Most are using stress testing and/or reserving to assess Insurance risk - over 40% not currently using EC, and over 50% not using VaR.

Risk and Reward

  • Almost 60% of remuneration schemes have no clawback provisions
  • Almost 70% of schemes do not align incentive payouts with the term exposure of the underlying risks

Solvency II-specific
  • 92% (of relevant responders) will focus resource on ORSA in next 12 months
  • 77% will focus resource on Data Quality in next 12 months
  • 69% will focus resource on Documentation and Reporting in next 12 months
  • Less than 25% rate their processes and systems for Data Governance extremely/very effective.
  • Declining trend of insurers who will be modelling economic capital (p19)
  • Only 80% actually calculate Economic Capital
  • Some very grim stats on p21 covering which risk types are modelled for EC purposes (underwriting risks seemingly very low on the list)
There are a number of areas touched on here which fall short of pending (or indeed actual) national/international regulations and codes, never mind "best practice". Perhaps we can account for the innate conservatism of CROs in their responses, and assume things aren't quite as bad as they have self-assessed here?

Friday, 17 May 2013

Internal Model Validation - the "desire for certainty"

Some useful snippets on the links here for anyone in the model validation space, whether if be the practical applications of Monte-Carlo simulation outside of the insurance industry, actuarial perspectives on model risks themselves such as parameter uncertainty and goodness of fit testing where "the problem is more often too many candidate distributions" as opposed to restrictions in choice.

This fantastic blog post from one of Willis's finest is about as blunt a critique of actuarial modelling activity and its potential for subsequent misuse as I have read, and I would strongly recommend it on to non-expert risk practitioners who may one day find themselves in the model validation/use test firing line. A few of the pearls of wisdom offered (focused on reinsurance industry, but relevant to all) include;
  • How the human "want to believe" and "desire for certainty" can lead to models making rather than guiding decisions
  • Reliance of models on "large numbers of heroic assumptions"
  • "Data is always limited and flawed"
  • That "models take combinations of assumptions and torture them to come to conclusions"
  • The revisiting of assumptions only when the answers don't fit expectations ("euphemistically called 'calibration'", hilarious!)
  • That using models for setting regulatory capital, rather than just informing decision making, has led to "extremely onerous" IMAP activity i.e. the limitations noted above are so well established that the regulators cannot ignore them at a granular level.

Then there this piece from Deloitte US on model validation, or more specifically, research into the quality of existing actuarial modelling controls, is an eye-opener for anyone working in the validation space. With RMORSA and associated capital modelling firmly on the agenda Stateside, it is interesting to watch how aggressively they approach validation, bearing in mind this work was commissioned by the Society of Actuaries, whose members may ultimately be charged with applying some of these recommendations!

This research in particular assesses current state versus best practice controls over the assumptions, inputs and outputs of actuarial models, and though the sample of respondents to the survey is relatively small (representing "30 unique companies"), the absence of suitable supporting documentation around model governance so evident in the UK's IMAP process appears to be a depressingly constant theme. This report at least includes recommendations as to how the US actuarial profession may bridge some of the gaps Deloitte identify.

In the NAIC's ORSA Manual, they ask that "ORSA Summary Report should provide a general description of the insurer’s process for model validation, including factors considered and model calibration" (p7), which I guess is what one expects to see in the EU (i.e. validation being a sub-process of the ORSA, which can be summarised in the ORSA reports). That said, the breadth of validation work performed over there will surely be driven by S&P expectations communicated in ERM Level III reviews, rather than profession-sponsored consultancy recommendations!


Finally (and slightly off track), an odd piece from Towers Watson on validating ORSAs, pitched to a room full of Internal Auditors. Would be unfair to say there aren't some salient points throughout, but given that there is "no clear requirement" to validate ORSAs (there was something on the matter in the original CEIOPS ORSA pre-consultation, but it was dropped in the public consultation and the final advice), then you would think it could be covered in less than 30+ slides!

As it happens, the TW slide pack for internal model validation appears to have been raided and had the acronym 'ORSA' jemmied into the text for much of the second half of it.

Wednesday, 20 March 2013

Reactions magazine - CRO Risk Forum - Solvency II and ERM opinion

I covered the last one of these releases from Reactions magazine this time last year on the basis that it had some good all round coverage of ERM and Solvency II from Europe's highest profile risk executives, and again they haven't disappointed.

This recent release again has a veritable Who's Who of European CROs providing their take on a range of matters, so is definitely worth your time. It covers most of today's hot topics, including SIFIs, ERM, Solvency II, ORSA (in US), Internal Modelling and Emerging Risk.

I've taken the following from it;

Hannover Re CRO
  • "...experiencing increasing requirements for internal model approval" - strange one this, as they have already converted to a Societas Europaea, potentially driven by a wish to escape a more onerous challenge in this respect from Bafin and the FSA - doesn't therefore sound like that tactic is of much use!
  • Their internal model is currently S&P ECM III-approved - detail on the significance of that available here for those not familiar with their methodology etc, but of course a positive review of an ECM will impact both S&P's assessment of a company's ERM framework, as well as the amount of capital required to sustain a particular rating.
  • The CRO uses the cost of the Risk Function against the capital savings from an approved model as a demonstration of the function's value - in the absence of a range of alternatives, I guess it's worth a shot.
  • As CRO, has a veto of decision making at executive committee level
  • Comments in a rather peeved manner that current draft Level 3 proposals insist upon separately staffed and operationally independent compliance, risk and actuarial functions (they appear to have everything balled up into a second line of defence 'risk control unit'  - bit confused by this, but I'm guessing he has seen something behind closed doors, and rightly doesn't appreciate EIOPA determining how a company should be departmentally structured.
SCOR CRO
  • The financial crisis "...has shown that the diversification of financial risks disappears in extreme situations"
Kiln CRO
  • "Every generation of activity since [Level 1] has produced ever increasing requirements for documentation"
  • "We are wallowing in paperwork"
  • As with Hannover Re, they cite S&P internal model approval positively against the developing EIOPA/national requirements - only 40 pages required to evidence a standard sufficient for S&P 'model approval'
  • They differentiate between Strategic Risk and Emerging Risk, with the latter seen positively as product development opportunities.


Monday, 11 March 2013

Aon Risk Maturity Index Report 2013

With the potential for early implementation of Pillar 2 on the horizon for Europe's insurers, Aon's release of their latest research on Risk Maturity Index is perhaps a timely one, particularly for anyone in the small-to-midsize bracket who wants to get a feel for the proportionality of their current approach (and for UK IMAP candidates, whether it might fold under ICA+ questioning in the next two years!)

Their claim that that the Risk Management Index fills the current "void" which prevents interested parties from benchmarking their risk management frameworks against those of their peers, and indeed reaching recommendations on how to further enhance them has a whiff of bolshiness about it, but nevertheless, the output is valid for practitioners in all industries.

Fundamentals behind the research, conducted in conjunction with Wharton Business School, are;
  • Aon's "Risk Maturity Index" is an online self assessment of risk management practices.
  • It asks 125 questions regarding 40 "key components" of risk management - all tied in to the following 10 characteristics of risk maturity:
 1. Board Understanding & Commitment to Risk Management
 2. Executive Level Risk Management Stewardship
 3. Risk Communication
 4. Risk Culture: Engagement & Accountability
 5. Risk Identification
 6. Stakeholder Participation in Risk Management
 7. Risk Information & Decision Making Processes
 8. Integrating Risk Management & Human Capital Processes
 9. Risk Analysis & Quantification to Understand Risk & Demonstrate Value
10.Risk Management Focus on Value Creation
  • Allows for a ranking between 1-5 across various sub-cuts of the data collected, and an assessment in aggregate of each firms "risk maturity"
  • Data was then analysed against over 100 listed companies from 20 industries, geographically spread, to see if "risk maturity", or a lack of it, translated into anything measurable
  • Over 500 companies have responded to the survey since 2011, this being its second periodic summarisation (results from first one summarised here).
The headline news was that a correlation was identified between organisations with superior risk maturity and stock price volatility, with a reduction of up to 50% potentially up for grabs between the 'best' and the 'worst' - a particularly visceral way to "derive and demonstrate financial value from...risk management frameworks" which, let's face it, is a hard sell for the best of us!

I observed some more general points from the white paper, namely;
  • The insurance industry was third only to Aviation and Consumer Goods in the assessment of risk maturity - something to be learnt from these industries (in particular around Op Risk maturity in Aviation)?
  • Only 15% of respondents were rated at 4+ out of 5, or "operational/advanced" in Aon's terminology
  • Lower revenues seem to translate into lower risk maturity on the whole
  • Responses from CRO's resulted in the best aggregate maturity scores, while Internal Auditor/CFO responses resulted in the worst aggregates - expected biases nicely exhibited
Of particular note though were the three areas of common differentiation between higher and lower rated firms which are worthy of more attention than might otherwise come from reviewing average maturity scores. 

Awareness of the complexity of risk - more mature organisations are able to demonstrate:
  • Risk adjusted return expectations by business unit/department
  • Documented and applied assumptions in forecasts/projections
  • Supporting forecasting ranges with applicable historical data
Agreement on [risk] strategy and action - more mature organisations stabilise their performance by:
  • Re-evaluating risk management strategy based on experience
  • Reviewing and validating risk tolerances based on external conditions
  • Evaluating strategic decisions with reference to quantified risk tolerances
Alignment to execute [the risk strategy]
  • Communicating negative results and predictions (nicely tied into Risk Culture by Aon)
  • Developing cross-functional risk understanding, and how organisational activity relates to overall risk management strategy 
  • Incorporating risk/return approaches into strategy, in particular recognising up-side potential in decision making, rather than loss minimisation

These are particularly interesting findings for the EU insurance industry, who will be waddling into Live ORSA territory in the coming weeks and months. Fair to say that Solvency II Pillar II accommodates much of what is covered here, so worth thinking about leveraging this benchmarking work in one's 2013 activities.




Wednesday, 20 February 2013

Protiviti - top risks for 2013

Nice piece of 'top risks' benchmarking for practitioners was pushed out this week by Protiviti - heavily US-centric, cross-industry (around 25% financial services, but all respondents are C-suite types), and the 'risks' are provided as a selection of 20 pre-written items, but the work has still got some mileage, even if I am far from convinved by the early statement that "...the first question an organisation seeks to answer in risk management is 'what are our most critical risks'" with no reference to their strategic objectives!

Let's take that as an editorial oversight, and pick through the highlights;
  • Unsurprisingly, economic conditions and regulatory change/scrutiny are top of the financial services hitlist of 'top risks' (and indeed other industries)
  • CROs and Chief Audit Executives were less likely to rate a risk "less significant" than their first-line counterparts - nest feathering or legitimate conservatism?
  • Financial services considerably more likely to deploy additional resource to enhance risk management capabilities in the next year
There is also a "suggested questions for Boards" list at the back, which covers (albeit in a rather flannel-y fashion) the kind of items which emerged in the FSB's risk governance recommendations from earlier in the week, such as;
  • Is the Board sufficiently involved in/informed of the risk assessment process regarding the implementation of strategy (mergers & acquisitions, new lines etc)?
  • Is the MI around the Risk Profile sufficient?
  • Is there an existing emerging risk management process?
  • Is the risk profile consistent with risk appetite?
A decent piece to run through your NEDs at the very worst, and potentially of some use for your emerging risk/reverse stress testing activities for 2013.

Friday, 15 February 2013

Financial Stability Board - Thematic review and recommendation on risk governance

The Financial Stability Board (FSB) have been sticky-beaking around systematically important financial institutions (SIFIs) with a relative unchecked remit ever since the financial crisis first reared its head. This week they have emerged with a very significant document for Risk practitioners across the globe, with a thematic review of Risk Governance (press release also available here). The participants were 36 banking and broker/dealer institutions of interest, as well as major supervisory bodies and NGOs.

On the basis that there isn't a single accepted global standard on the matter, the thematic review compares prevailing practices against an amalgamation of content from exising standards from the IAIS, OECD and other bodies. Of major interest to risk practitioners is the document's focus on areas which the IRM have covered recently, namely risk appetite/tolerance/limts/capacity and risk culture.

Bearing in mind the great and good from the prudential regulatory world are active participants in the FSB, the likelihood of their findings emerging in the regulatory principles of tomorrow are pretty high. Of course this research has been based on Non-Insurance SIFIs, and so insurers large and small who have been endeavouring to meet Solvency II Pillar II requirements will find themselves in a decent spot already.

On that basis, I noted the following;

General recommendations to supervisory bodies (p4)
  1. Formal requirements on the independence and skillsets of Boards
  2. Hold Boards directly accountable for risk governance, and whether or not their existing suite of risk MI is sufficient
  3. Formally elevate the stature, authority and independence of the CRO role
  4. Require an independent assessment of the effectiveness of the risk governance framework to be performed on an annual basis (a list of what Internal Audit would generally review in this context follows on page 24)
  5. Engage "more frequently" with Boards and management to assess risk culture
Sound practices list p30-34 - highlighted below are elements which may be new to the UK in particular, were they to be introduced
  • Boards - annual reviews of member qualifications, skills and time commitments; meet quarterly with regulators; "effectively inculcate" an appropriate risk culture
  • Risk Committee - annual approval of risk management policies
  • Risk Management function - CRO to have direct reporting lines to Board/Risk Committee as well as CEO; public disclosure of CRO firing/hiring; be "actively involved" in strategic decision making processes; meet quarterly with supervisors; stress testing "on demand" at the behest of the business
Risk culture and risk governance supervisory assessment
  • Notes that supervisors need to strengthen their ability to assess a firm's risk governance "...and more specifically its risk culture"
  • "More work is needed" on regulatory assessment of risk appetite frameworks
  • "Risk culture plays a critical role in ensuring effective risk governance practices through changing environments"
  • FSB have a working group exploring the potential for formal risk culture assessments, who are  reporting in September 2013
Risk management functions and CROs
  • Acknowledges that there have been "[raised] supervisory expectations for the risk management function" since the financial crisis
  • Highlights that "most firms note that the CRO has a direct reporting line to the CEO", though "access to the Board" apparently remains more of an expression than a vivid reality
  • "Good progress" has been made on enhancing the stature, authority, and independence of the CRO position
  • Rather non-descript comment that "the Chief Risk Officer and the risk management function are responsible for the firm's risk management across the entire organisation" - responsible for what element, not conduct surely?
Risk appetite/tolerance/limts/capacity
  • Acknowledge a "lack of common terminology for risk appetite, risk profile and risk capacity...within firms, across firms and across national authorities"
  • Definitions of appetite and capacity used by FSB largely line up with IRM's definitions (though the IRM use 'tolerance' rather than 'capacity')
  • "Key features of a Risk Appetite Framework" are listed on p22 - however even those firms considered best in breed commented that there are ongoing "operationalising" problems with RAF rollout
  • Suggest that breaches of 'risk limits' should lead to reductions in exposures (piii) - not sure why the alternative of increasing appetite is not acknowledged



Thursday, 7 February 2013

Towers Watson on US ORSA, Economic Capital and modelling trends

Towers have released a few decent bits of material of use to risk practitioners over the last couple of weeks which are worthy of comment. One on Economic Capital for Life Insurers is effectively a sales aid for their RiskAgility modelling software, but actually captures the drivers behind the UK's efforts to improve their ICA models to meet Solvency II requirements.

In particular the references to how firms ought to be making their model output 'useful' where they currently fall short (capital by business/risk/product, daily runs without running ALM models and ability to produce "what if" analysis) should be featuring highly on the agendas of both embedded use practitioners and AMSBs during 2013. Of course the sad part for any users of the software comes with the statement that RiskAgility is built "...specifically to deliver monte carlo simulation of 1 year VaR economic capital" - love to hear how the lack of multi-year is being dealt with in firm's ORSAs!

A second publication on ORSA preparedness in North America is also worth a read, even if only for us EU-based practitioners to have an opportunity to live vicariously through a country which will actually get it implemented! It is a relatively small quantum of respondents (mostly CFOs), and around half think they will be exempt on size grounds, but the perceptions which emerge are still valid, and one should be prepared to encounter this either side of the Atlantic;

  • 21% see it as a compliance exercise, while 60% think it will improve ERM and capital/strategic planning
  • Only 22% see their prevailing ERM frameworks tightly liked to strategic and capital planning
  • Only 40% are ready to implement an ORSA in the next 6-12 months
  • Concerns remain around resource requirements for educating "key personnel" and directors/C-suite - 45% and 66% respectively felt they have work to do in this area without necessarily having enough staff to do so.
  • 13% of respondents didn't see their risk management departments contributing to the ORSA process (I'll get my coat then...)
  • 3 year projection of capital requirements is the most common planning period envisaged
The same North American slant is then given to a financial modelling survey, which gives us another chance to peek over the fence. They found the following;
  • Reasonable amount of dissatisfaction around run-times
  • Around half planning to change their model governance processes in the near future
Looks like the NAIC/EIOPA covergence work should be a walk in the park then, at least on these topic...

Tuesday, 2 October 2012

Deloitte with more on the US-of-ORSA

Billed as a "regulatory guidepost to the future", Deloitte in the States have published their thoughts on ORSA developments, following on from recent activity in the space, most notably the NAIC's adoption of the RMORSA Act a few weeks back.

Hard to tell whether Deloitte have borrowed much from their European counterparts, who ponied up with the EIOPA-compliant equivalent document last week, but both documents ultimately point at the same end goal, namely getting the ORSA Process and ORSA Report content right.

Confidently declaring the first regulatory filing of an ORSA Report to be precisely, errr, "Sometime in 2015", the stateside plans are anchored more to ERM and, I guess by association, ratings agency implications. The document does help identify a couple elements which, with the Solvency II hat on, are easy to forget;
  • IAIS ICP 16 is bringing ORSA to the table of all signatories at some future juncture (which means I may get a job back home one day!)
  • Existing techniques for monitoring solvency, even in a jurisdiction of this size, are seemingly past their sell-by-date in terms of both content and turnaround time (p2) - holds true for many of the Solvency II-covered countries as well (plenty on that topic in here).
The rest of the document draws out the preparatory work which firms should be undertaking, despite the relative lack of certainty at this point in time, such as increasing real-time data availability and changes in reporting, management and governance structures. It also touches on suggested content, process implementation (more like formalisation from experience), and a checklist of operational considerations, resourcing (or even briefing/coaching) being highest priority in my mind in 2012.

Good document for you statesiders to pass round your friendly non-executive directors anyway, as an early socialising of the concept in this format goes a long way when you have tiny windows to educate them on the topic over the next 3 years - looks like you will be filing ORSA Reports before we are!

Interesting footnote is that AIG have been labelled as a potential SIFI today - ORSA may be 5 years too late to have saved the behemoth it once was, but let's hope it can help its slimmed down current-day version.

Monday, 20 August 2012

Deloitte and Forbes - the new world of Risk Management

This Deloitte/Forbes paper is sub-titled "Aftershock", which makes anyone of my age immediately recoil at the though of the world's most repulsive bar shooter - it is in fact a pretty decent stab at running on from the kinds of financial services-specific research which came off the back of the 2006-2008 mega-turbulence (these were mostly titled "We've broken the World, what are we going to do" :-( )

At 192 respondents it is a decent sample size, though is US-centric and non-Finance organisations, so not a great all-rounder for you global readers. However, the central message that risk management programmes and frameworks remain in a state of flux (hence the aftershock motif) is a worrying one when one examines the stats behind it:
  • 91% are reorganising and reprioritising approach to risk management in next 3 years, citing continued market volatility.
  • Only 37% had plans to provide additional training in that respect
  • Centralisation cited as more efficent way of bubbling risks to the top - interested to know if that is everyone's experience?
  • Around 50% retain primary responsibility for the "risk management approach" with CEO or CFO, with the CRO in third at 20% - should we be expecting that percentage to be moving up or down at this juncture (in particular, does a CRO need a seat at the top table to be responsible for ERM approach?).
  • Example cited of ERM being managed in the corporate strategy department, which I thought was an interesting development.
  • Biggest challenges included; 26% stating that incentives are not rewarding 'risk based decisions'; 22% struggling with the misalignment of the business operating model and the ERM model, and 23% suffering a lack of information to make risk based decisions. These three (there are of course more in the list!) struck me as common issues when preparing for Solvency II, so handy stats in that respect.
  • Staggeringly, Social Media is equal fourth on the list of "most important risk sources over the next 5 years" - equal with Financial Risk! Not to underplay the emergence of social media and its multiplier effect on reputational risk, but seriously?
  • Most "risk types" are monitored either periodically or continuously, though strategic and reputational risks seem to be most likely to be measured on an ad-hoc basis (something which you ORSA consultants out there will sympathise with!)
     
I say "worrying" at the top here from a professional perspective - is it reasonable after events as seismic as those experienced in the last 5 years for the risk profession to still be sliding in a mass of new parts into the ERM machine, as opposed to tinkering under the bonnet?

Bearing in mind this doesn't include the financial services industry, maybe the timelag is rational, as the other industries have had plenty of time to learn what not to do!

Wednesday, 20 June 2012

StoneRiver Financial Regulatory Survey - ERM and ORSA in the US

An interesting US perspective published today touching on the near term future of ERM and ORSA reporting in the States from the guys at StoneRiver (need to fill out a little form for the download).

They are of course attacking it from a "buy some reporting software" perspective so the questions are a touch loaded, but the findings from the survey (68 in the sample, majority of P&C insurers) are certainly sobering for the NAIC, namely;
  • Only a quarter were confident enough to state that they had a formal process for ERM, including reporting
  • 44% claim to have "in-house expertise" on ORSA, despite the requirements being in a state of flux (guess I'm not getting a green card anytime soon!)
  • Only 40% were confident that their existing software will efficiently handle ORSA reporting requirements
Bearing in mind when I blogged on the draft NAIC ORSA manual in November the regulatory filing aspect was heavily emphasised, the combination of undocumented ERM processes and software fallability may be cooking up an administrative nightmare for the insurance industry over there - welcome to our world!

Monday, 30 April 2012

Society of Actuaries in Ireland Newsletter, April 2012 - ERM and ORSA features

Always a riveting read, the SAI pushed out their latest newsletter, which generally provides enough consumable detail on actuarial concept to help relative novices like me!

Get stuck in to the sections on contract boundaries, and the reason for professional vs EIOPA divergence on p4, some ERM activity over the last couple of months on p9 (and slides from those both here for ERM and here for ORSA). Some brief analysis of the older presentation from Towers Watson on ORSA is also summarised.

Saturday, 10 March 2012

NAIC's Spring National Meeting - "Go ORSA, it's your birthday"

Kindly summarised by these lads, the NAIC's Spring National Meeting seems to have breathed life into the Stateside ORSA project, with the ORSA Manual (from p12) tabled in November now approved by the plenary, and a 15 company ORSA pilot group due to report at end of June. Feel free to drop me a line if you want any ideas! The legislative side of it (through an ORSA Model Act) is mooted to take a year, but from what point it is not clear - this article seems to have plenty of insight in this regard however.

Also relative was the NAIC's desire to set up an ERM training program for staff - sounds like a smart idea if ORSAs are in the offing, so should be interesting to see what they come up with