Showing posts with label FRC. Show all posts
Showing posts with label FRC. Show all posts

Friday, 19 September 2014

FRC on Risk Management and Internal Control disclosure - insurers way ahead?

Muddy Waters
- public disclosure on Risk
The UK's Financial Reporting Council have released guidance on Risk Management, Internal Control and related reporting, just in time to help muddy the waters for UK insurers, who have no doubt finally got their risk, actuarial and compliance functions writing non-conflicting words with Solvency II preparation in mind!

Anyone who has written, peer-reviewed or socially read these sections of public reports (i.e. me, and any other geeks), will know they are normally;
  • Boiler-plate, and completely transferrable between industries, regardless of their disparate risk profiles
  • Aligned to the Strategy sections with a few anchor words, but otherwise divorced
  • Frequently unaligned with the ERM frameworks used internally - i.e. "this is what the City wants to read", not material on our actual risk profile!
Given that this is only guidance, and is further only directly relevant to LSE listed entities, readers may be inclined to take the content with a fistful of salt. There are a number of noteworthy aspects to this publication however which maybe show where the mindset of supervisory-types has got to in the eight or so years since the financial crisis commenced.

 I took the following general points from it;
  • Very little for listed insurers to be concerned about, if they have prepared adequately for ORSA and supervisory reporting (SFCR, RSR) - indeed, their reporting teams will be delighted with the amount of content crossover! Check out the (still not finalised) Delegated Acts of Solvency II in order to see why listed Insurers won't need to stretch to meet these.
  • Frequent references to "culture", as opposed to "risk culture". Checking the FSB's take on Risk Culture from April of this year, one can appreciate the FRC's desire to gemmy culture into these guidelines, if perhaps not the execution - one fears the "culture" words are likely to become a little weasely.
  • Multiple crossovers into ORSA language, in particular re-emphasising the importance of the alignment of risk management with business strategy.
  • Good work in section 4, bringing in the "IMMMR" concept from Solvency II, as well as assessment of current and emerging risks, and assessing exogenous and endogenous risks when doing so.
  • Recommend that risk assessments are performed at inherent and residual level, and that control effectiveness is also considered when arriving at one's final assessment
On the technical front, the following elements caught my eye
  • "Emerging principal risks" used as an expression - not sure if that stands up to scrutiny i.e. if something is emerging, can it be a "principal" anything? How would you measure it to gauge "principality"?
  • Reference to "high profile failures in risk management" in recent years, which feels a little finger-pointy - we could deconstruct every corporate failure to one of risk management failure
  • "Risk Appetite" put into inverted commas within the guidance, but not in the appendices - can't quite work out the aversion to definition given the FSB's work to date at the very least, but certainly EIOPA have similarly dodged it (p59), and looking at Appendix 1 of the Irish regulator's thought paper on Risk Appetite, one can see why!
  • "It is the role of management to implement and take day-to-day responsibility for board policies on risk management and internal control" - really? responsibility for their implementation, sure, but policy content?


Thursday, 19 September 2013

Financial Reporting Council - documenting 'principal risks' in Strategic Reports

I had recently spotted that the UK's Financial Reporting Council had issued draft guidance on the compilation of the Strategic Report for listed entities. This segment of a company's Annual Report and Accounts (currently called the 'Business Review') has been a rather ubiquitous and clunky affair regardless of industry, delivering little information to prospective and existing shareholders about how the company's risk profile, appetite, preferences etc. are catered for when executing its strategy.

Strategic reporting for UK companies 
- elimination of flannel?
Insurers have been prominent in efforts to improve this, though driven more by the need to pacify the FSA/PRA than by Parliament - see "risk appetite" break out from its box in  Aviva's AR&A between 2007 and 2012 for example - but the fact that a substantial piece of statutory reporting generally in the hands of executive management can potentially stray from the lexicon and structure of their increasingly professionalised Control Functions (and for banks and insurers, potentially their Internal Models), is clearly one that warrants some focus.

The Strategic Report will be compulsory content for Annual Reports and Accounts from October (Companies Act 2006 414C). The FRC's (non-mandatory) guidance regarding the incorporation of risk-related material into this section is to address the requirement on p2 that the Strategic Report;
...should include a description of the principal risks and uncertainties facing the company
The FRC's specific definition of Principal Risk is found on p35 of the draft guidance as;
A risk or combination of risks that can seriously affect the performance, future prospects or reputation of the entity. These should include those risks that affect the viability of an entity.
The draft guidance (p23) aims to tack on a few definitional aspects of how "risks and uncertainties" are reported in the context of strategy, most pointedly;
  • [The risks] should be limited to those considered by the entity’s management to be the most important to the future development, performance or position of the entity. They will generally be matters that the directors regularly monitor and discuss because of their likelihood, the magnitude of their potential effect on the entity, or a combination of the two
  • Principal risks or uncertainties with potential effects of such a magnitude that they may threaten the entity’s viability (ie its solvency and/or liquidity) should be explained fully and given due prominence
  • Directors should consider the full range of business risks including commercial, operational and financial risks
  • The descriptions...should be 
    sufficiently specific that a shareholder can understand why they are important to the 
    entity. This might include a description of the likelihood of the risk, an indication of when 
    the risk might be most relevant to the entity and its possible effects. Significant changes...
    such as a change in likelihood or possible effect, or the inclusion of new 
    risks, should be highlighted and explained. An explanation of how the principal risks and 
    uncertainties are managed or mitigated should also be included.

  • Where the risk or uncertainty is more generic, the description should make 
    clear how it might affect the entity specifically.
Prudential provide a good example here (from p72) of how this is currently done by an insurer - the fact that it is buried in 75 pages of 'Business Review' underlines why the streamlining of this work has become of statutory interest!

Interestingly, the FRC note that definition for "principal risks" has been developed/derived from previous FRC work, supplemented by work from the Sharman Inquiry - all of that therefore feels well divorced from anything produced by the IRM/Actuarial Profession/EIOPA around risk categorisation, and leads to the same bridging work I have been involved in previously; namely, reconciling how one manages and monitors risk within the business against what one reports externally. Might we have expected to see some kind of compulsory categorisation of "principal risks" in here that favours the financial services industry who arguably carry the largest set? 

Much of the other compulsory material in the Strategic Report (with exemptions) touches on other topical or sensitive matters such as;

  • Inclusion of key performance indicators in the report ("...where possible, they should be accepted and widely used")
  • Information on environmental matters, staff and social/community/human rights issues
  • Information on gender splits at Board, Senior Management and All-company level
I may throw some feedback in to the FRC on this paper- comments welcome until late November. Externally, the main change for insurers will be trimming down some of the fluff and flannel already produced in the space. Internally, aligning the concept of "principal risks" with existing ERM programme/Internal Model lexicon may be a bigger job for anyone operating on a shoestring.

Monday, 5 November 2012

Institute of Risk Management on Risk Culture - ABCs, Double S's and mercenaries

So I figured it might be worth seeing how the other half were living by reading something that didn't start with "Solvency II" and end with "indefinite delay"!

The IRM are endeavouring to produce white papers on some of the less tangible elements of a risk practitioner's day job, which one would hope contribute to more consistency in practitioner approaches and ultimately more credence in the concept of risk professionalism (indeed, their work around defending pure risk professionalism as a career, as opposed to loading risk functions with cross-over actuaries, was very much required in early 2011).

Having scrutinised their work on Risk Appetite in 2011 (lined up against some of the competing influencing bodies here), I figured it was only fair to take a punt at their new release on Risk Culture. It's fair to say that for politicians, regulators and fingers-caught-in-the-till employees, 'culture' or 'risk culture' appears to be a handy soundbite when explaining why they didn't fulfil their obligations to their stakeholders. The IRM are joined by Protiviti in producing this guidance, Protiviti themselves having delivered a survey based on UK insurers on this very topic in the summer, which was not shy about highlighting how little some organisations think of their Risk functions.

I've always felt that the 'culture' comfort blanket was one weasel word too many i.e. "there was a culture of greed" = "they were greedy ********", or "there was a culture of fear" = "scared of the gaffer", so I approached this doc with a pretty open mind, but tempered with a Manxman's natural scepticism. I found the following (sequentially);

What does a good risk culture look like?
  • Appears to have used examples of what a "bad" risk culture has recently led to, then flipped that on its head! Would have thought a clean slate approach is better for white papers, rather than reacting to zeitgeist incidents
  • Fair list of 10 criteria for anyone in the risk culture assessment space, though will always be a nightmare to codify/quantify.
  • The appearance of the dreaded "tone from the top" suggestion, which makes an appearance in the FRC's (p4), the FSA's and EIOPA's world (p10) - bearing in mind that the "top" is normally the problem when it comes to organisational catastrophe (Lehman, Northern Rock) as opposed to fat tail op risk loss events UBS/Credit Agricole/JP Morgan), I would be more inclined to call it "tone at the top".
What does risk culture mean?
  • I like the IRM's take on culture being "the repeated behaviour" of a group - very convincing definition in comparison to say the FSA in SYSC (p12), though the rest of the ABC approach is a tad woolly.
  • "Virtuous" versus "vicious" cycle sits nicely alongside this image of repetition, but nothing as such around how best to break a vicious one, either as a NED or a Head of Risk - perhaps that has been saved for the more extensive and expensive practitioner's guide!
Why is risk culture important?
  • Don't agree that risk culture affects the capability to take strategic decisions, rather it enhances or impairs the quality of those decisions. Immediately makes me think of ORSA, and how "playing" at it or "doing" it doesn't prevent strategic decisions from being made.
  • Also don't agree that "at worst" an inappropriate risk culture could lead to "serious reputational and financial damage" - I'm sure stockholders at Bear Stearns may say it can be a bit graver than that!
  • Nice emphasis on how risk culture can both stifle necessary risk-seeking behaviour at one extreme (smartly citing Eastman Kodak as a "too slow" corporate failure), as well as the more obvious "prison rules" which emerge from uncontrolled risk taking.
What can the board do?
  • Should they really ask themselves "what is the current risk culture"? If so, is that at a chinwag-type round table, or via some kind of evaluation survey issued by Risk function? Instinctively sounds like the kind of thing that would be squeezed into a Q1/Q3 board meeting at the point of a gun, which is as cynical as it is sad!
Understanding risk culture in an organisation
  • The meatier (i.e. costs money!) practitioner guide apparently contains some diagnostic tools to effectively indicate and track culture within an organisation. The flash we are given here reminds me of the psychometric testing for "what makes a great Risk Manager" that I looked at last year, but feels ultimately very high-end.
  • The "Double S" model is an intriguing addition to the mix, specifically the comment that low scores on either rating "create a barrier to the effective management of risk". Would love to see more of the research cited, as I've found that the odd mercenary firm can work wonders...
Changing a risk culture
  • Can a risk culture effectively be changed top-down without a change in personnel? Can't imagine an existing CEO being prepared to antagonise his board/exec team by declaring them culturally bankrupt unless he had carte blanche to do so, which is normally the case with regime change. I'm more inclined to think a decent CEO, partnered with Risk, could do it by stealth, rather than with a pricey change management programme which would inevitably rock a few boats.
  • "Risk culture is not a precise science" - does that make it an art?
10 questions a Board should ask itself
  • I would probably make it 11 questions, and frame the first one "Do we genuinely care about how culture impacts on our decision making, or only insofar as laws and regulations insist upon it?". If a Risk practitioner gets the answer to that directly from the Board/Exec, the other questions can be catered for with proportional vigour.
Thought provoking in the right ways, I guess it does what a good white-paper should - thanks to all concerned at the Institute.

Wednesday, 14 December 2011

Financial Reporting Council - Developments in corporate governance 2011

The FRC pushed this out today on progress in implementing the UK Corporate Governance Code (and of less interest to me, the Stewardship Code. Outside of the news of what is to come (more consultation in 2012 on Audit Committees, Risk Management and Internal Control elements of the code) some interesting trends are reported;
  • Code requirements on board and board committee composition all above 80% on the "comply" front - strangely the requirement for having at least half NEDS on the board was the worst area of compliance for FTSE 350 firms.
  • Still having "diversity" and "gender diversity" spoken of in the same breath - more to come on that subject from me another time
  • FRC are attributing some of the gripes from the industry on independence criteria and difficulty in recruiting good quality NEDs on their inability to look beyond "the usual suspects", and by doing so, they will enhance diversity.
  • 80% of boards put themselves up for re-election annually in their entirety (one of the more controversial elements of the last set of Code revisions).
  • Discussions regarding the expanded nature of the Board's responsibility for Risk (to essentially include consideration and setting of Risk Appetite) has led the FRC to schedule a revision to the old Turnbull guidance in 2012.
  • Still griping about "boiler plate" annual report text.
  • Some of the "explanations" given for non-compliance still said to be lacking
  • Chairman's Statement suggestions made by the FRC appear to be bearing fruit
  • Lack of consistency around the application and reporting of Board evaluations
  • Disclosure on business model, strategy and risk (massive for Solvency II disclosure policy/SFCR purposes) is, because of a lack of guidance, allowing companies to determine their own levels of disclosure. However, the FRC are expecting more from companies in this regard.
  • Very critical of the extent of reporting from the Audit Committee, hence the consultation due in early 2012. Also goes on to be untopically lightly critical of remuneration committee reporting in the same regard!

Friday, 2 September 2011

Financial Reporting Council - new guidance on company stewardship and public reporting

Just in case you UK insurers don't have enough to factor in to your next annual report and accounts (least of all commencing the alignment piece between SFCR/ORSA content and the risk/strategy/capital aspects of your existing reporting releases) , the Financial Reporting Council (FRC) have dropped a couple of grenades into to mix with this release on Effective Company Stewardship, and perhaps more significantly for our kind, the expanded commentary regarding Boards and Risk which was gleaned through a range of interviews.

The stewardship document obviously has some "comply or explain" regulatory relevance for UK readers, whereas the second is a phenomenally useful benchmarking tool to match up against your own board/executive/committee considerations of risk regardless of your jurisdiction.

The stewardship document then focuses more on reporting obligations, in particular Audit, and the associated consultation was triggered in Jan 2011. I was drawn to their findings on reporting "Strategy, Risk and Going Concern" which touch on communication of risk appetite, namely;
  • "differing views as to whether it is either necessary or possible for a board to apply a single, aggregated definition of its appetite for risk as a whole"
  • "when developing [the] strategy however, it is important for boards to agree their appetite or tolerance for individual key risks"
  • "reporting on the company's risk appetite was felt to be difficult, even if it could be defined, as risk appetite is not constant but varies depending on market conditions
The FRC's proposals were therefore (on the basis that the legal obligation is to report on "principle risks and uncertainties);
  • Focus reporting primarily on strategic risks (as opposed to those which occur without company action) and 
  • Disclose such risks to business model and the strategy for implementing said model
  • Not to "scatter" descriptions of the risks faced by the company throughout the document
All of this is a little plus ca change for insurers, who are already pretty good at these aspects!

The second document carried additional interest for me, bearing in mind it collates genuine opinion of the decision making bodies on their existing risk management obligations (and therefore could provide insight into future issues with Use Test evidence, ORSA processes and SFCR/RSR sign-offs). They reiterate that this is not guidance!

Obvious headline from this work is that the Turnbull Guidance will get a brush up in 2012, but I also picked out the following aspects;
  • Risk Committee should not be obligatory for all industries
  • Boards need to focus on risks that undermine strategy or long-term viability (i.e Reverse Stress Testing)
  • The "velocity of risk" meant that reputational risk requires greater attention
  • Essential that boards should focus on "gross" as well as "net" risk (inherent and residual in our lexicon)
  • Challenge of determining whether a particular risk should be brought to the board's attention remains one of the greatest challenges
  • Risk and Internal Audit should have clear reporting lines to board committees
  • Investors are seeking "more meaningful reporting on risk", much like that prescribed earlier
  • Risk categorisation terminology used is relatively crude (operational and strategic risks being the main distinction made)
I suspect most insurers would rest pretty easy if they benchmark their ERM frameworks against the contents of this paper.