Showing posts with label IRM. Show all posts
Showing posts with label IRM. Show all posts

Thursday, 28 May 2015

IRM on Internal Model Validation - Red Card or Green Card?

Cyclic Validation - Quelle horreur...
Just back from Paris, where I spent a weekend queueing behind selfie-taking tourists before taking out a second mortgage to buy bottled water. A beautiful place, though I found Depardieu was much quieter off-screen...

Onto the topic in hand, the PRA were pretty vicious back in the day on Validation efforts in their infancy, with Julian Adams lambasting both progress ("significantly behind") and validation scope ("narrow"). Given that the Solvency II sabbatical which bridged half of 2012 and all of 2013 gave firms time to catch up and widen, you might think that those with internal model ambitions would be pretty tidy by now. The PRA have even told firms how they believe "good" model application paperwork to look, carving out for themselves and the Validators of the world an easy-to-read "model reviewer" level of detail (p1).

In those salad days, Internal Model Validation felt to me like it would be the chernozem of the nascent Risk Management profession in insurers; a skill set that a quant or a non-quant could acquire, apply, and ultimately ease through the promotional path within insurance entities, given the depth and breadth of technical and strategic information the process challenges...

...but the moves never came. Despite the actuarial world themselves happily disassembling the complexities of quantitative modelling into easy-to-digest IM Validation themes, the non-quant world has waited patiently to see if anything of substance would emerge from one of its representative bodies.

And this week it arrived! The Institute of Risk Management has delivered, as part of its Internal Model Industry Forum (IMIF), a white paper on the validation cycle.

The IRM have been active in this area prior to the formation of the IMIF. I have covered an ERM in Insurance event at the start of 2014 here, while this more volumous slide pack featuring a number of the Billy and Betty Big Biscuits of the field emerged from summer of last year, when the IMIF seemed to come to fruition. This white paper itself appears to move along the concepts and ideas inside an IRM slide deck from last Christmas.

Given that the IRM is not-for-profit, there is always a likelihood that sponsors will unduly influence the products (indeed the IRM Chair notes in this that they rely on "enlightened industry support" to knock these documents out).

Sadly in this case, the sponsors include Three of the "Big 4" (with the fourth on the IMIF steering committee) , leaving the document dripping with consultancy hallmarks rather than pragmatic solutions to execute the tasks in hand.

That view is reinforced somewhat by this follow-on presentation to the IMIF from last week by this white paper's workstream lead and supporting consultant - one selected industry comment on slide 8 (presumably from a chocolate bar shortly before it ate itself) reads, "validators should really be experienced modellers"!

A few general points jump out of the white paper;
  • That a firm's IM is "...at the heart of risk and capital evaluation" - I thought it was supposed to "inform" this evaluation, not dominate it (slide 3 here, as well as Julian Adams's speech from a couple of years ago [p4]).
  • Is the insurance industry "...increasingly reliant on sophisticated models" - maybe in terms of AUM/Market Cap, but given the UK IMAP queue is down to approximately 40 firms out of over 400 (p4), and that number has steadily reduced over the last 3 years, feels a touch disingenuous. I've no doubt the firms represented on the Steering Group are "...increasingly reliant" though
  • The document claims to set out "best practice principles" - not sure if "practice" and "principle" share the same bed, but that aside, would anyone find it remotely acceptable to have the consultancy world fund a document which details "best practice" on IM Validation?

And a few stand out elements from the proposed Validation Cycle, which is heavily influenced by EIOPA's guidelines:
  • "Best practice now requires firms to demonstrate, with evidence, that the cycle...[is] being actively and effectively carried out" - how can best practice "require" anything from anyone?
  • "...resulting best practice that is emerging" (p4)  - how is any practice considered "best" at this stage of proceedings, when we are literally practising! Against what criteria?
  • References to "model risk impact assessment" and the "model risk assessment process" (p5) seem to come from nowhere. Alluding to something formal, but not very clear
  • Lot of coverage of "triggers" of IM Validation, which feels like a fishing expedition for the paper sponsors, rather than direct address of L2 Art 241 - the number of areas of "change" to consider as IM Validation triggers covers pretty much any change, anywhere, both inside and outside of an insurer (p8)! Most would also be ad-hoc ORSA triggers in my experience, so this potentially sets up insurers for a bucketload of work every time they hear a pin drop.
  • Formulaic and periodic IM Validation a "needless cost"? Surely periodic validation, no matter how badly executed, is compulsory (L1 Art 125)?
  • The Trigger Impact Assessment stage (p10) is barely legible - "The trigger impact assessment against model risk appetite stage" - and terminologically it is all well above legislative requirements.
  • "Unexpected triggers" (p12) get a mention. Again, not making sense to me - you either know your triggers or not.
  • "Model validation is complex" and "less than black and white" (p16) - certainly is if you try and follow this process! A focus on plain questions and less quant can only help the models non-expert users (slide 7).
  • If the validation cycle, processes and execution are "continuously evolving" (p18), are they reliable? Feels difficult to meet L2 Art 241.3, at least from a planning and execution perspective, if the process is constantly being tinkered with 
  • "Developing a communications strategy" (p20) as part of the validation scoping and planning stage feels terribly over-elaborate.
  • "Robust planning" expected to be common (p22), which doesn't necessarily marry up with the expectation of dynamic rather than cyclic validation in future (p10)
I think it is right to take the hump to a certain extent here. The PRA have been cunningly silent on capital add-ons to date, but given the implication that they will not be applied and renewed ICG-style (slide 13), there is likely to be many more less monied Partial IM applicants to follow over the next couple of years. Having the most influential consultancy firms decide on what is "best" in the validation world (and for it to have this many bells, whistles and legislative off-roads) feels like setting those firms up for either a fall, or another bill.

The PRA actually delivered something with much less padding to the IRM back at the end of 2013, so I'm struggling to see why that has justifiably been turbo-charged. Given they have three of their finest involved with the IMIF, but are continuing to be directly vocal on this topic (as recently as March 2015), it sends a worrying message to the capital add-on brigade that the IMAP early birds will be setting disproportionately high bars for 2017 and beyond when they deliver their PIMs.

Ultimately, I was disappointed by the publication, which reads more like a flannel manual, and is certainly not the kind of Risk Profession contribution that the topic so badly needs if the PRA's dreams of Board's "directing" and "owning" the IM valdiation process (slide 9) are ever going to come true. The 200 page novella world of Validation Reporting feels closer than ever...

Monday, 18 August 2014

ORSA - Institute of Risk Management special interest group

Of course while I spent the last couple of months topping up my tan in, errrrr, the Isle of Man, some of the guys in the UK and further afield have been building up an endeavour-flavoured sweat on some of the more malleable elements of Solvency II preparation.

Raining 'Mann' - Glorious Manx summer
The IRM as ever have kept the ball rolling, in particular hosting an ORSA session last month. While you can pick your way through the guest speaker presentations for ideas and comfort (one company specific, one consultant generic, and one which S&ST/RST fans might like as a sense check), I was much more interested in the attendee survey.

A whopping 34 replies came in, via which the attendees have delivered a reasonable ORSA landscape mock-up, which may help some of you get matters shuffled in your priority lists, given where your peers claim to be.

I noted in particular;
  • ORSA Process overwhelmingly run by the Risk functions (over 90%)
  • Just over half going for annual frequency, the rest (who responded) naturally more frequent - doesn't instinctively feel representative, but not all of the smaller firms would send someone down to this!
  • Around two-thirds have their "Reports" at 50 pages or less - if we assume that by "report" we mean Supervisory as well as Internal, the PRA won't be too chuffed with that given their comments at the December industry seminar.
  • Only a third have submitted draft ORSA Reports to the PRA and received feedback
  • Coverage of emerging risk appears to be an area which not only do respondees think is lacking, but has received critical feedback from the PRA
That half have used external consultants in their ORSA work to-date is certainly no surprise. I'd be worried if that consultancy had more than a year's dust on it though, so think hard before you start submitting your 2014 gear!

Wednesday, 22 January 2014

Model Validation - benchmarks and best practices from the IRM, PRA and Lloyds

Models - seeking validation
Bearing in mind we have passed the 2013 financial year end, and all of the internal modellers amongst us will be trying out their new processes and technology in the production of a balance sheet for the first time, a few very timely pieces of material on internal model validation have been released, which should help anyone who is curious about what their neighbours are up to!

The Institute of Risk Management's rebadged Solvency II Special Interest Group held a get-together in December on IM Validation, and a couple of interesting documents have emerged.

One from a PRA Validation guru is particularly useful for anyone in the IMAP space who has any uncertainty about the PRA's approach to assessing the quality of one's validation processes and reports, covering;
  • The purpose of validation
  • The PRA's approach - Life and GI-specific SME groups
  • An overview of IMAP findings - 40+ reviews conducted to date, and they also state what your evidence "should" demonstrate
  • Their observations - Noting that Validation Reports are generally deficient
  • A schematic view of what they consider the Validation process to be
  • A bullet point list of how validation effectiveness can be demonstrated
I guess the odd thing for me is why this kind of material isn't presented/circulated more widely by the PRA, as it is surely of benefit to IMAP participants, who wouldn't always be in attendance at a pre-Christmas IRM event!

The other useful benchmarking item from this event is the survey on participants' experiences to date in the validation field. While the sample is small in absolute terms at 18, and is a touch heavy on the GI side (over half of respondents), this is as good a benchmarking aid as you will see for a while, so it is worth noting the following;
  • Just over half have transitioned Validation into BAU
  • Only 3 respondents had a Validation-specific steering committee to help govern the process, with others choosing to use existing committees or the CRO/Risk function
  • Over 80% use the SCR contribution of each risk driver to determine the depth of validation activity. Other determinants include regulator feedback, risk registers and previosu validation reports
  • Over 40% say that their independent validation work is identifying flaws in their "dependent" validation work, while over a quarter say that independent validation has been scaled back due to the quality of "dependent" work!
  • Less than a quarter say that validation of external models (ESGs etc) has been effective
  • Around two-thirds use peer review and sensitivity analysis to validate expert judgements. Horrifically, two respondents said they haven't been able to validate expert judgement at all!
  • Over half are still using external contractors/consultants for independent validation
  • Page 12 covers the popularity of certain sections of a Validation Report. Less than half include a section on benchmarking
  • Most are keeping the Validation Report to under 100 pages, with management feedback being the main catalyst for changing the length.
Finally, a survey from LCP Consulting was published this week covering the progress of Lloyds syndicates in their Validation activity. This was an area which Lloyds acknowledged as "work to do" back in May last year, particularly around validation testing and documentation.

The findings appear to be positive on the whole, with most firms saying they are at least halfway towards their "ideal process". Unsurprisingly, dependency modelling and validating expert judgement make the list of "key challenges" remaining.


Tuesday, 10 September 2013

Towers Watson - 'Risk Appetite revisited' (did we ever leave it?)

I have been doing a little work on Risk Appetite in the background recently, so was intrigued to have a read through this recent release by Towers Watson on the subject, seemingly targeted at North American and UK markets, but relevant to any practitioner in this space. Somehow I wasn't put off by p6 when, in response to the hypothetical question 'What is Risk Appetite', they responded with, "...we do not want to focus too much on the issue..."!
Appetite - second helpings?

I had blogged earlier this year on Risk Appetite, covering the expectations of EIOPA on the matter (which are few), as well as the more pokey/proddy stakeholders like the PRA/Central Bank of Ireland/S&P (which are several!), so the backdrop of risk appetite's practical significance to insurers doesn't need to be repeated here, more how consultants and practitioners are improving their game on the ground. Worth noting here that a few of the other consultancies have proffered their two cents on the matter over the last year or so (here, here, and here).

While interest in 'risk appetite' is currently piqued at governmental level thanks to the forensic examination of the banking industry's failings (multiple references in Parliamentary Commission evidence here and here for example), the driver of activity in the UK and Ireland is predominantly from the regulatory compliance perspective rather than expectations of bespoke, strategy-driving activity. In addition, we now see the emergence of Internal Audit as a party with a vested interest in the matter, which has the potential to draw the subject even more to a tidy, but ultimately superfluous documentation exercise.

With that in mind, Towers note that this paper is focused on "...enhancing risk appetite by improving its articulation, via clearer linkages to mission and strategy", and a rather derisive tone is therefore applied throughout regarding the familiar quantification methods preferred by regulators to monitor likelihood of insolvency in the next 12 months, giving equal billing to non-monetary capital and qualitative measurements. The paper also crosses some familiar ground, such as a lack of consistent terminology, which it tries to address (below).

Oddly, the document does not reference the FSB's thematic review of risk governance earlier this year, which will surely drive efforts in this space in the medium term, if only due to the paucity of certainty on the subject. That the FSB believe that regulators have "more work to do" is striking, and while they also bemoan the lack of common terminology, they don't let that prevent them from offering definitions of their own, as well as listing their "Key features" of a Risk Appetite Framework.

More obvious statements

  • "..clearer linkages are needed to mission and strategy for risk appetite to be effective"
  • "risk appetites must include boundary constraints"
  • "We suggested that greater clarity around the definition of risk is needed..."

Definitions
  • Risk - "In this context, risk should be defined in terms of those events and circumstances that may result in an insurer failing to deliver on its mission."
  • Risk appetite - "...the manner in which a company expresses an identified set of risk-trading opportunities, and sets boundaries on its risk-trading among those opportunities, aligned with successfully delivering on its mission."
  • Risk strategy - "The company’s risk strategy articulates how risk fits with the mission".
  • Risk tolerance - "Risk tolerances are a quantitative extension of the risk strategy...risk tolerances must be measurable...[and] place quantitative boundaries on the company’s strategy"
  • Risk limits - "Risk limits are more granular tolerance levels expressed for specific risk sources, business units, and/or products that are used to implement the risk tolerances."
  • Risk appetite statement - "...risk appetite statements should be taken as the combination of risk strategy tolerances and preferences, bringing together qualitative and quantitative enterprise perspectives on risk as both opportunity and threat."
  • Mission - "mission is the insurer’s unique multi-period and multi-stakeholder value creation proposition."
Technical suggestions

  • They promote four facets of risk assessment: size, likelihood, impact and significance.
  • For those working on statement content, they recommend "...since published mission statements can be fairly terse, the risk appetite may need to look beyond the explicit elements of the mission and consider elements that are implicit." Instinctively that feels unfair, but I guess the world of implicity is one for the second line to inhabit, while the first line concentrate on value-adding.
  • Concept of adaptive buffers sits nicely with me - the most visceral ones being economic capital and reinsurance/hedging/liquidity facilities, but TW attempt to expand that over qualitative areas of the risk appetite statement
  • Risk preference ranking of 0-4 depicted at the back is a handy schematic

Sore points

  • "Some take the view that risk appetite can be expressed as a single metric, or perhaps a small set of metrics, that capture the organisation’s willingness and ability to bear risk." - that 'some' would include the FSB, COSO, the Central Bank of Ireland and the IRM, so I wouldn't be too sniffy at efforts to-date
  • "Much of the work to-date on risk appetite statements has been driven by solvency supervision requirements, many statements tend to focus primarily on potential losses of capital"- a natural and by no means unwelcome by-product of having regulators in the box-seat, as opposed to stakeholders combining their efforts to establish compulsory risk appetite statement content?
  • "While most insurers have, by now, developed risk appetite policy statements and discussed them with their boards, many have expressed dissatisfaction with the exercise" - that feels a rather loose statement, and if true says more about the personnel charged with performing the work.

I'll take a look at the diversity of definition in the risk appetite space across different bodies in a separate post - for now, just enjoy this tidy piece of work for what it is.


Tuesday, 9 July 2013

Actuarial profession and the Risk Function - from 'land grab' to 'colonisation'?

Back in the early days of this Blog I used to post frequently on the Solvency II-sponsored creep towards Risk functions in insurers being 'Chiefed' by members of the actuarial profession as a matter of course rather than choice (here, here and here for a start). It was even a thread in a presentation I delivered to ILAG in late 2012 around areas of control function crossover, in particular that the actuarial profession was acknowledging that there were professional deficiencies in their ability to address the basics of an actuarial function under Solvency II, yet preferred the ambition of conquering a newer (less arduous?) space ahead of remedying them.

Whilst a quant is no doubt a decent fit for such a task, it was an evident snub to the nascent Risk Management 'profession', who took umbridge at the implication of such compulsion from the UK regulator in April 2011, though with seemingly little impact. However, limits to the amount of time and money bodies such as the IRM and FERMA can throw at developing a one-size-fits-all Risk Management qualification package that can appeal to quants and non-quants alike, plus some furious inter-squabbling in the ISO 31000 world, are certainly not lending any credence to "Risk Management" as a profession in its own right as we stand.

Risk and Actuarial professions - 'Poles' apart?
Over in Ireland, the opportunity for the Actuarial profession to secure an additional control function has been pursued so rabidly that the SAI incoming and outgoing presidents were recently able to congratulate themselves on having busted into "the new frontier" of Risk, and are now moving on into "colonisation mode" (p2)! In the UK, the Institute and Faculty of Actuaries already seem to consider that area of influence secured judging by the new president's remarks recently, indicating a desire to influence more mainstream debates than those around risk management systems and corporate governance.

The UK and Ireland don't appear to be the only ones afflicted by the perception of compulsory quants in Risk functions. Munich Re's excellent Knowledge Series delivers a Germanic take that there is "no doubt" that professional mathematicians will be needed for tomorrow's Risk functions.

When considering the history of the Actuarial profession (beautifully summarised here), there should be no reason why Risk Management cannot achieve a similar position given time, regardless of the disparity in existing approaches from representative bodies. A modular qualification which can prepare a 'risk professional' for their favoured activity (insurance buying/continuity management/financial risk/op risk/ERM) is surely an ambition which those bodies can harbour in concert? My concern would naturally be that I probably don't have another 50-100 years to wait for the that convergence to happen and enhance my own career prospects!

Or maybe I do - does anyone know an expert in longevity?

Monday, 10 June 2013

Institute of Risk Management's latest on ORSA - presentations and surveys

I haven't kept too much of an eye on the IRM's Solvency II Special Interest Group activity, which during 2011/12 was prolific, but with the disappearance of the finishing line, I suspected there may have been some fall off. There has certainly been a Partidge-esque rebadging of it (now called 'ERM in Insurance'), which I suspect helps most attendees justify to their bosses, in the face of interminable Solvency II delays, taking half a day off to attend these shindigs!
Rebadged - IRM's Solvency II SIG

A recent one on the incorporation of ORSA into the business planning process is worth highlighting, being focused (at least on the face of it) on the more visceral elements of the ORSA process rather than the theory. While the Kiln CRO seemingly had more to say than was put on his slides, the Allianz UK Head of Op Risk noted a few things which those working in the field would benefit from benchmarking against;

  • Risk department seemingly responsible for ORSA report production
  • 'Record of ORSA Process' documentation - shooting for around 60 pages, which feels light to me as a "record" (about par for a "report" perhaps?)
  • ORSA Board report - summarised from the 60 pages referenced above, so again light
  • Lists some 'example' ORSA triggers, which are good for peer comparison
  • Seemingly will be validating their ORSA process, despite it not being a regulatory requirement.

The IRM's related survey also produced some notable material, particularly around participation levels - only 14 participants, compared to 22 back in 2011 and 33 this time last year, showing perhaps the extent of the fatigue on the matter. With the tiny sample also heavy in GI firms, one might take any revelations with a pinch of salt, however, I spotted;

  • Frequency - A quarter are planning to run the ORSA process quarterly, most going annually
  • Preparedness - Areas such as data quality, ORSA validation, ORSA record keeping and the forward-looking assessment are all lagging
  • Projection length - 80% going for 3 years, though the GI heaviness of the sample will have skewed this for sure
  • Projection technique - around half doing future years in isolation, and half doing multi-year (dependent) projections
  • Forward looking assessment - All respondents are factoring in expected risk profile changes into their FLAs
  • Stress & Scenario Testing - All respondents using scenarios with interdependencies, while two are not using reverse stress testing at all.



Monday, 5 November 2012

Institute of Risk Management on Risk Culture - ABCs, Double S's and mercenaries

So I figured it might be worth seeing how the other half were living by reading something that didn't start with "Solvency II" and end with "indefinite delay"!

The IRM are endeavouring to produce white papers on some of the less tangible elements of a risk practitioner's day job, which one would hope contribute to more consistency in practitioner approaches and ultimately more credence in the concept of risk professionalism (indeed, their work around defending pure risk professionalism as a career, as opposed to loading risk functions with cross-over actuaries, was very much required in early 2011).

Having scrutinised their work on Risk Appetite in 2011 (lined up against some of the competing influencing bodies here), I figured it was only fair to take a punt at their new release on Risk Culture. It's fair to say that for politicians, regulators and fingers-caught-in-the-till employees, 'culture' or 'risk culture' appears to be a handy soundbite when explaining why they didn't fulfil their obligations to their stakeholders. The IRM are joined by Protiviti in producing this guidance, Protiviti themselves having delivered a survey based on UK insurers on this very topic in the summer, which was not shy about highlighting how little some organisations think of their Risk functions.

I've always felt that the 'culture' comfort blanket was one weasel word too many i.e. "there was a culture of greed" = "they were greedy ********", or "there was a culture of fear" = "scared of the gaffer", so I approached this doc with a pretty open mind, but tempered with a Manxman's natural scepticism. I found the following (sequentially);

What does a good risk culture look like?
  • Appears to have used examples of what a "bad" risk culture has recently led to, then flipped that on its head! Would have thought a clean slate approach is better for white papers, rather than reacting to zeitgeist incidents
  • Fair list of 10 criteria for anyone in the risk culture assessment space, though will always be a nightmare to codify/quantify.
  • The appearance of the dreaded "tone from the top" suggestion, which makes an appearance in the FRC's (p4), the FSA's and EIOPA's world (p10) - bearing in mind that the "top" is normally the problem when it comes to organisational catastrophe (Lehman, Northern Rock) as opposed to fat tail op risk loss events UBS/Credit Agricole/JP Morgan), I would be more inclined to call it "tone at the top".
What does risk culture mean?
  • I like the IRM's take on culture being "the repeated behaviour" of a group - very convincing definition in comparison to say the FSA in SYSC (p12), though the rest of the ABC approach is a tad woolly.
  • "Virtuous" versus "vicious" cycle sits nicely alongside this image of repetition, but nothing as such around how best to break a vicious one, either as a NED or a Head of Risk - perhaps that has been saved for the more extensive and expensive practitioner's guide!
Why is risk culture important?
  • Don't agree that risk culture affects the capability to take strategic decisions, rather it enhances or impairs the quality of those decisions. Immediately makes me think of ORSA, and how "playing" at it or "doing" it doesn't prevent strategic decisions from being made.
  • Also don't agree that "at worst" an inappropriate risk culture could lead to "serious reputational and financial damage" - I'm sure stockholders at Bear Stearns may say it can be a bit graver than that!
  • Nice emphasis on how risk culture can both stifle necessary risk-seeking behaviour at one extreme (smartly citing Eastman Kodak as a "too slow" corporate failure), as well as the more obvious "prison rules" which emerge from uncontrolled risk taking.
What can the board do?
  • Should they really ask themselves "what is the current risk culture"? If so, is that at a chinwag-type round table, or via some kind of evaluation survey issued by Risk function? Instinctively sounds like the kind of thing that would be squeezed into a Q1/Q3 board meeting at the point of a gun, which is as cynical as it is sad!
Understanding risk culture in an organisation
  • The meatier (i.e. costs money!) practitioner guide apparently contains some diagnostic tools to effectively indicate and track culture within an organisation. The flash we are given here reminds me of the psychometric testing for "what makes a great Risk Manager" that I looked at last year, but feels ultimately very high-end.
  • The "Double S" model is an intriguing addition to the mix, specifically the comment that low scores on either rating "create a barrier to the effective management of risk". Would love to see more of the research cited, as I've found that the odd mercenary firm can work wonders...
Changing a risk culture
  • Can a risk culture effectively be changed top-down without a change in personnel? Can't imagine an existing CEO being prepared to antagonise his board/exec team by declaring them culturally bankrupt unless he had carte blanche to do so, which is normally the case with regime change. I'm more inclined to think a decent CEO, partnered with Risk, could do it by stealth, rather than with a pricey change management programme which would inevitably rock a few boats.
  • "Risk culture is not a precise science" - does that make it an art?
10 questions a Board should ask itself
  • I would probably make it 11 questions, and frame the first one "Do we genuinely care about how culture impacts on our decision making, or only insofar as laws and regulations insist upon it?". If a Risk practitioner gets the answer to that directly from the Board/Exec, the other questions can be catered for with proportional vigour.
Thought provoking in the right ways, I guess it does what a good white-paper should - thanks to all concerned at the Institute.

Saturday, 31 March 2012

IRM Solvency II Special Interest Group - Risk Comittee effectiveness

Bit of an odd one this presentation, on the basis that the survey clearly contains a mixture of genuine Board-delegated Risk Committees, and some executive risk committees, but it contains some insights which may be of use regarding membership, agenda content, meeting regularity and methods of assessing effectiveness. In addition, one of the IRM Directors pitches in with a presentation on the topic, which is good food for thought, in particular if your Boards have delegated any matters to the Risk Committee for Solvency II.

IRM Solvency II Special Interest Group - making Risk Function more relevant

The IRM guys always put on a good show with their Special Interest Group activity for Solvency II, and generally has relevance outside of the Insurance industry. Couple of interesting subject matters for the last two, my notes below.

Developing the Risk Function to be Board-relevant (under Solvency II) - international flavour in presenters, so bear that in mind when you look at the slides!
  • Jose Morago presentation - Aviva's EU Risk Director has a nice slide on educating and supporting the Board on risk responsibilities, but on the Risk function's "four distinct personalities", I would disagree that the function "leads the optimisation of the insurer's risk/capitalisation profile" (advises, certainly, but leads?). The personalities seem to be light on review and challenge activity as well, and there is a fair amount of risk jargon, which Boards are never keen on in my experience.
  • Kendra Felisky presentation - While Jose went with Risk function as "Officer, Business Leader, Teacher and Advisor", Kendra has the second line of defence as "Assess, Monitor, Support and Challenge", which I concur with, and goes on to comment that "Our job is to enable to Board to do their job", which I would also subscribe to. She has a rather dated slide showing what the Risk function was compared to what it is/needs to be (you'd need a time machine to remember the 'old' Risk function!), and a good slide on levels of participation in risk management, and MI requirements. The slide on how to talk to the Board recommends 'no jargon' (which cuts across Jose's terminology a bit!), and the section on Key Risk reporting seems to be focused on risk mitigation and elimination, rather than optimisation.
  • Pierre-Andre Camps presentation - Feels like a lot is lost in translation on these slides, so have a leaf through, but don't hang your hat on anything.
Survey findings on  making the Risk function Board relevant (35 participants, so small sample)
  • Only half have their CRO communicating directly with the Board on risk matters- surely explains the necessity of this event!
  • Horrifically, almost half said risk papers are "noted with a short discussion" at Boards - is the problem that all papers are not 'risk papers', hence it can be siloed as a talking point?
  • Half said the process of implementing Solvency II affects their ability to becoime relevant to the Board - that is definitely a bad development all round
  • Three-quarters said there is no action plan or training programme to aid the Risk function in communicating and presenting to Boards.
  • A third of attendees report to a CRO, while a quarter report to a CEO (I find that instinctively high)
  • Not surprised by smattering of risks not covered by the attendees' functions - smaller companies are unlikely to cover financial and non-financial categories, and the categories with least coverage tend to lean towards having expert ownership and established controls (ALM in particular).
  • Over half felt they had overlap with either Actuarial or Compliance
  • A worrying number are not directly delivering testing and validation of the internal model. Understandable on the design/implementation/documentation front, but surely testing and validation?

Sunday, 5 February 2012

COSO - understanding and communicating Risk Appetite

Hot on the heels of materials pushed out on the Irish front from both the regulator and the consultancies, as well as the IRM's efforts in autumn of last year, COSO have stepped up to the plate with their take on understanding and communicating Risk Appetite, a topic which will be spectacularly relevant to insurers over 2012 for ORSA purposes, and indeed for anyone in and around the Irish Sea for corporate governance compliance reasons.

Having had a good sniff through, I struggled to find anything controversial in COSO's take on things, and, whether by accident or by design, it treads the same path as Richard Anderson's paper from the IRM.

The following quotes provide some of the more salient points made by the authors;
  • "Risk appetite is the amount of risk, on a broad level, an organisation is willing to accept in pursuit of value" - not a bad way to think of it for an insurer (i.e. embedded value), though the 'broad level' add-on is unnecessarily and disconcertingly vague. This incidentally  runs against one of the IRM's key principles, namely that risk appetite must be measurable (p7).
  • Authors believe that "...when properly communicated, risk appetite provides a boundary around the amount of risk an organisation might pursue" - without splitting hairs, the definition of risk appetite above isn't especially black and white!
  • The three risk appetite steps of "Develop-Communicate-Monitor and update" are spot on, however, one might think that the "develop" piece is already done in most organisations (or why would the owners get up in the mornings?), and communicating it is the big issue.
  • Should create a Risk Appetite Statement which is "broad enough yet descriptive enough for organisational units to manage risks consistently within it" - good point, as of course some departments of a business would struggle without such breadth in their appetite statement (business continuity and marketing spring to mind)
  • Similarly, that statement should "balance brevity with the need for clarity"
  • Confidently states that "we all know the costs of failing to manage risk", but dished out some pretty generic examples, bearing in mind the zingers which have pitched up over the last three years
  • Exhibit 1 on considerations affecting risk appetite is a very smart schematic for provoking thought at executive level
  • Box on p5 has a rather definitive statement around there being a lack of risk appetite articulation which contributed to the current financial crisis - certainly wasn't a problem at Lehman's, more that it was a moveable feast!
  • Handy box on p7 which covers the tie-in between what rates as an "adequate" ERM Framework in the context of S&P's ratings methodology, and what management must be able to articulate on the Risk Appetite front.
  • Some very nice examples (p8-10) of risk appetite statements from different industries, and of risk tolerance statements anchored to associated risk appetite statements (p13-14).
  • The big one - differentiating Risk Appetite and Risk Tolerance - is on p11. Whether you agree with the COSO conclusion (i.e. that Risk Tolerances implement Risk Appetite within each operating unit's sphere of influence), it does at least try to square the circle, and the clarity should benefit practitioners. However, the statement "While Risk Appetite is broad, Risk Tolerance is tactical and operational" is poor - I'm guessing one could substitute "broad" for "strategic", or "tactical and operational" for "specific", and it makes sense.
  •  Interesting list on p16 of questions to facilitate Board-level discussions on Risk Appetite which I suspect is probably too wordy for many Boards to throw themselves into wholeheartedly.
  • Starts to peter out towards the end, which is normally the case with such guidance materials (once you start descending into 'performance models', communications strategies and risk culture, the ability to prescribe content and form to disparate organisations diminishes substantially).

Ultimately, while the document is of considerable use for anyone who needs a reputable crutch on the topic (and is perhaps outside of financial services), it is probably too generic to be of great use as an aide-memoire to any Solvency II-covered insurers, and I would stick with the IRM's take ("those risks that [an organisation] actively wants to engage with" when scripting a Risk Appetite Statement. 


Chapeau for the good parts nevertheless...

Wednesday, 18 January 2012

IRM Solvency II SIG Presentations from January - Stress Testing

For anyone who is working on firming up their approach to stress testing and its cousins for Solvency II purposes, I would recommend taking a look at the outputs from this month's IRM Solvency II Special Interest Group.

The presentation has some worth, although I guess you needed to be there to get the full gist. The survey however is of much more use for justifying any approaches you currently have in play (who is responsible for what, and indeed what varieties of stress testing are actually used). Small sample as you might expect for a SIG at 28 respondents, but worthy nonetheless.

Wednesday, 19 October 2011

Institute of Risk Management - presentations on Risk Culture and embedding risk management

Delivered last week at the Solvency II Special Interest Group were a couple of presentations regarding embedding risk management and "risk culture". I generally think that "culture" is something you find in a yoghurt pot, but to be fair there is some good stuff in the materials below;

IRM Chair's presentation - some nice elements in this, such as
  • Risk culture being "at its simplest...how 'risk management' is factored into decision making" - I would go further and make this the most complex definition, rather than elaborate
  • Nice transposed diagrams of how certain risk cultures need to implement ERM in certain ways
Survey on risk culture and embedding risk management - remember at 28 participants it is a small sample, but flags the following;
  • Around half are lumping "risk culture" and "embedding risk management" into their (Risk?) Solvency II Workstream (i.e weren't planning for it otherwise)
  • Quarter had no sponsor for risk culture work
  • Around 30% cited "lack of access to management time" as a challenge
  • No real favoured technique for assessing risk cultures or embedding risk management - number of options cited
  • None of the 9 relevant participants had received a "poor" rating from S&P for their ERM structure
  • Not many outliers on the questions regarding risk governance, risk resources, risk transparency and responding to bad news - most were 2/3 out of 4
  • Few more outliers in questions on risk competence, making risk decisions and rewarding risk taking - suggests that, while companies are relatively competent at 'playing at doing risk', at the sharp end the relevant skills and attributes are by no means compulsory
Not exactly my cup of tea this subject, but this is still useful stuff.

Tuesday, 20 September 2011

IRM principles on Risk Appetite and lessons from UBS

Pretty interesting finish to last week, with UBS getting spanked for a cool $2.3bn through the now-typical route of a back office know-it-all getting promoted to the trading desk and circumventing the plethora of internal controls designed to stop the very activity they and they alone know how to take to the n-th degree.

I thought of this when looking through the IRM's risk appetite and tolerance paper released at the end of last week (separate post to follow incidentally, only so many hours in the day!), specifically whether there was anything being promoted/supported by the institute which may have averted this rather grim result for the boys from Berne.

6 IRM principles to start with;
  1. Risk appetite can be complex - don't try to dumb it down if it isn't justifiable
  2. Risk appetite needs to be measurable
  3. Risk appetite is not a single fixed concept
  4. Risk appetite should be developed in the context of an organisation's risk management capability
  5. Risk appetite must take into account views at strategic, tactical and operational level
  6. Risk appetite must be integrated with the control culture of the company
Sadly for the profession, the risk governance set up at UBS is paper-perfect in this regard, so I dare say the CRO may feel obliged to hand in his cards. This despite the fact that, as with the Leeson and Kerviel cases beforehand, if you personally know the gaps (and the reward is great enough) the rogue trader is nigh on unstoppable by the second line of defence in these kinds of organisations. However, it looks more of a "should have done better" case for the second line, and should categorically be used as a counter argument to the dismissive tones of management when discussing risk limits and qualitative tolerances.

Some great quotes below from their website (highlights are for my benefit);


High Level – Risk Management and Internal Control
The [risk controls]framework is dynamic and continuously adapted as our businesses and the market environment evolve. It includes clearly defined processes to deal with new business initiatives as well as large and complex transactions.

Risk assessment and management oversight performed by the BOD considers evolving best practice and is intended to confirm to statutory requirements
 
Risk Appetite
Our risk appetite framework establishes risk appetite objectives in respect of earnings and capital levels that we seek to maintain, even after experiencing severe losses over a defined time horizon.
Our risk appetite is approved by the BoD. Risk appetite is based on our risk capacity, which is in turn based on our capital and forecasted earnings resources. Our overall risk appetite is set as an upper limit covering the aggregate risk exposure for each risk appetite objective, taking into account inherent limitations in the precision of risk exposure measures that focus on extreme market and economic events. Comparison of the firm's risk exposure with our risk capacity under prevailing operating conditions as well as prospective business plans serves as an input to the risk limit framework. This comparison is also a key tool to support management decisions on potential adjustments to the risk profile of our firm.
 
Operational Risk-specific
Management and risk committees are the governing bodies responsible for oversight and active discussion of risk management activities, including the question of whether or not the cost of mitigating actions is adequately balanced against the acceptable level of operational risk. Management, in all functions, is responsible for establishing an appropriate operational risk management environment, including the establishment and maintenance of robust internal controls and a strong risk culture.
 
Material operational risks and significant internal control deficiencies are identified and reported at least quarterly to stakeholders, including the BoD, GEB, divisional/regional/local management, Group Internal Audit, external auditors and regulators.
 
We have developed a model for the quantification of our operational risk, which meets the regulatory capital standard specified by the Basel II advanced measurement approach (AMA). Our model has two main components. The expected loss component is a statistical measure based on our own historical loss experiences (collected since 2002), and is used primarily to determine the expected loss portion of our capital requirement. The unexpected loss component is based on a set of generic scenarios representing categories of operational risks that are relevant to the firm. The scenarios are reviewed extensively on an annual basis by internal experts, using internal and external event information, information about the prevailing business environment and our own internal control environment. This component is used to determine the unexpected loss portion of our capital requirement.
 
Risk and Reward

Thursday, 15 September 2011

IRM Risk Appetite Guidance released

Closely associated with the last post, the IRM have pushed out the results of their consultation on Risk Appetite. I'll pick through this next week, so help yourselves via the link in the meantime

Friday, 22 July 2011

IRM Solvency II SIG Presentations from July - Risk Appetite focused

The Institute for Risk Management's Solvency II Special Interest Group have published their July presentations, which were centred around the White Paper on Risk Appetite that they published back in April/May.

The survey on that white paper's content was quite telling - bearing in mind the sample is still relatively small (23 respondents), they were nicely split between agreement and ambivalence on;
  • Whether the white paper provided a "workable basis" for developing risk appetite and risk tolerance approaches
  • Whether there was sufficient guidance on the development of risk appetite in the doc
  • Whether there was sufficient guidance on board/risk committee oversight of risk appetite development
Seems to be general consensus on;
  • Organisations having "multiple risk appetites"
  • "Risk management maturity" being an appropriate concept to build appetite and tolerance from (large number of "partially agrees" however, which could mean anything!)
  • That more guidance is needed on the concept of "Risk mmanagement maturity"
  • That "propensity to take risk" and "propensity to exercise control" are appropriate concepts
  • That listed companies should consider shareholder value as an appropriate measure of risk appetite
  • That Risk Appetite should be measured
  • That there are (a range of ) critical elements missing from the paper (range of qualitative and quantitative suggestions provided)
  • That a short version would be appreciated for Board consumption
  • That the approach in the White Paper will be useful for Solvency II purposes
Two presentations have been published - one from Grant Thornton, which even in slide format looks like a decent stab at getting to the measurables of Risk Appetite, the other from Crowe Horwath which is a more meandering view with some nice touches (the idea of Capability versus Ability is very smart). They also cross-pollenate the Survey results with those of the ERM SIG, with some interesting divergences (namely that the ERM SIG are much more definitive in their responses, and rarely say "don't know"!)

Tuesday, 17 May 2011

More on IRM issues with Risk Function under Solvency II

The FSA presentation that appears to have caused the mild outrage with the IRM has actually already featured on this blog - at the time I didn't pick up any undercurrent of an attack on risk professionals in general, so I guess you had to be there.

Having reviewed the IRM's lobbying letter, it certainly has the tone of a rebuke ("recent debates have caused unnecessary confusion" being my favourite line). The presenter was a relatively big hitter at the FSA, so no reason to think this isn't the FSA party line.

What I noted from the rest of the letter was;
  • Felt that the directive is being interpreted to assume a CRO must have risk and actuarial skills
  • Rather harsh contention that the development of ERM-related actuarial qualifications shows that their profession does not provide "sufficiently broad training".
  • "Trend in the market" for hiring business-focused CRO's. Not substantiated, but having looked at the CVs of a couple of the CRO membership it does stack up.
  • Struggled to find an example where risk and actuarial have to collaborate at the moment, using Op Risk modelling as the easy case study.
  • Suggests that actuarial could not perform independent oversight of reserve risk, when via chinese walls or basic separation of duties one would think they could
  • "There have been suggestions that there are no suitable qualifications for risk management professionals" - this must have come verbally at the presentation, as I cannot establish this from the slides. If this was said or even insinuated it is pretty outrageous.
  • Ticklist of risk function attributes under Solvency II matches up largely with the Level 2 and 3 guidance
  • Strange comment that the IRM wants "further guidance" on what constitutes a fully effective risk function, presumably as the FSA and Solvency II views are perceived to have diverged.
I suspect there is a few miles left in this one...

Saturday, 14 May 2011

IRM - Risk Appetite and Risk Tolerance consultation

Only got the tip-off on this today, so still have some reading to do, but clearly the obligations of exec and non-exec directors have turned Appetite and Tolerance into fertile ground, hence this consultation from the IRM.

I am personally not against a prescriptive approach to these topics, provided no board members exempt themselves from learning new things - I may throw a few comments in, especially on Risk Appetite, which there is a distinct danger under Solvency II will become a documentation process which has the dust blown off it periodically, rather than enjoying pride of place on the decision-makers table.