Showing posts with label Risk Tolerance. Show all posts
Showing posts with label Risk Tolerance. Show all posts

Thursday, 30 April 2015

Love RAFs? CRO Forum's Risk Appetite survey

The CRO Forum have recently published the results of their 2014 survey on Risk Appetite development in insurance entities. It is perhaps the oldest drum in Risk Management Town, but one we are always happy to hear the beat of, and while we shouldn't expect a forum with such luminary members to deliver any shocking results, a careful sift through the carcass is always a smart idea.
The Cure - to tolerance breaches?
The final presenter at the PRA's recent NED briefing noted that Risk Appetite is "no longer an aspiration", a comment I felt was further behind the times than Nana wearing Juicy Couture. That said, on page 8 it suggests that less than a quarter of firms are "very satisfied" with their RAF maturity, and over a third feel they have "a lot of work to do", so perhaps he hit the nail half on the head...

This document should clarify whether that caution is justified, and with 48 responses from the top table, it should be a reliable benchmarking tool. Despite starting like a GCSE essay ("the topic of Risk Appetite has exploded"?), it contains some useful, if a little dry, benchmarks, such as;
  • Principles for a RAF (p3-4) - hard to argue with
  • Main goals - dominated by preserving capital, while only a third are looking to "improve shareholder value" or "optimise capital"
  • Main stakeholder list (p5) seems good in breadth and priority
  • Almost everyone is using regulatory capital in some way as a Risk Tolerance measure (p9)
  • Stress and Scenario testing is being used by 80% to set Risk Tolerance levels, which feels at the right end of expectations
  • 60% report quarterly, with most others slightly more or less frequent
It takes a few odd turns, in particular;
  • One of the main objectives cited (p4) seem to be centre around boiling down things into a single document. I appreciate that pressure, but surely we feel that a RAF has a more substantial objective that document consolidation?
  • "Development of a Risk Appetite Statement is an evolution" (p6) - don't agree at all, it is a task, otherwise it would never get done.
  • Coverage of Risk Appetite Statements as "regulatory requirements", in particular under Solvency II. Just because the industry is choosing to discharge its obligations in EIOPA's Guidelines (SoG 15 & 16) by producing a single statement document, it doesn't make a Risk Appetite Statement a requirement.
  • Less than half are using a "1-in-x" loss that would breach regulatory capital in their Risk Tolerances - just feels like a very obvious one to use, so suprised by that number
Some of the more practical issues faced by firms are well covered, for example;
  • Difficulties for Groups when setting risk appetite. Does the parent/head-office set overall appetite, and the children sub-divide it by business unit/risk category/Both? Do the children set their own appetites and feed them up for aggregation?
  • Listing Risk Concentration targets looks awkward across the board (p5). While firms seem to be able to quantify Liquidity and Capital targets in their Risk Appetite Statements, other categories are much less consistently quantified. Market, Credit and Insurance Risk appear to be quantified by less than a third of respondents, preferring to address these in separate policies/guidelines (a Solvency II by-product perhaps?).
  • Setting Risk Tolerance levels is highlighted as a "minor" improvement required by over 60% of respondents.
  • There is a veritable bombsite of Earnings at Risk metrics in use, which is healthy for the industry I guess (p10).
  • What does one do when Risk Tolerance level is breached? Around a third are not OK with limit breaches and demand immediate rectification, while two thirds allow for a "Cure Period" to return the Risk Profile to its required form. A "Cure Period" seems the fairest breach rectification approach to me - after all, I don't care if Monday's blue...
A worthy benchmarking document, so fill those boots.

Monday, 29 September 2014

CRO Forum's Principles on Operational Risk Measurement - "Quant touch this"...

Hammer Time?
Current efforts in Op Risk quantification
Despite practitioners efforts over the last few years, Operational Risk continues to live on starvation rations when it comes to considered quantification. Never treated as an alpha-topic by executives inside insurance institutions, it has been treated with similar indifference by legislators, culminating in the  "totally inadequate" take-a-percentage methodology for calculating Operational Risk capital in the Standard Formula.

Internal Modellers on the whole are not likely to be shaming that technique with their efforts either (basic summary of their problems here, while InsuranceERM cover struggles as a whole with a roundtable here). A paucity of operational risk event (and near miss) data within firms may be good news for ORIC as a vendor, but from a parameter and data uncertainty perspective, it leaves internal model operators and validators in an invidious position, particularly due to the quantum of insurers' capital likely to be involved (10%, give or take?).

It's not that the actuarial world hasn't taken a stab at it before (here), aren't fully aware of the data holes (here), or haven't used the word "Bayesian" in a sentence (here). However an activity which was "in its infancy" in the UK as far back as 2005, is surely now old enough to be working in the mines...

I was therefore happy to see the unprolific-yet-important CRO Forum bring a white paper to the table, Principles of Operational Risk Management and Measurement. It is an update to a 2009 version which takes into account Solvency II demands, as well as developing practice within insurers over the period, the suggestion being that 2009's efforts were a little too Banking Industry-influenced.

While this document might feel at outset like an idiot's guide to "quanting" operational risk (and bearing in mind the number of prospective standard formula applicants - 9 out of 10 in UK - one may be needed soon!), the document touches on a number of noteworthy technical matters, in particular;
  • The Definition section doesn't read well, but they have attempted to include outcomes other than monetary loss into the Op Risk definition, which from experience will improve discourse within firms. Are they attempting to squeeze strategic and reputational risks into this box though?
  • Nice coverage of Boundary Events, and encouraging firms to consider them in their management of Op Risk.
  • Very specific treatment of Risk Tolerance throughout, using it in preference to Risk Appetite. This is because it cannot be avoided, and so tolerance levels should be used to trigger "RAG"-type reporting up the chain. Nice work, and well justified, but I have certainly seen the expression "Zero Appetite" used for Op Risk, so no doubt this is not an industry standard perspective yet! (p5-6)
  • No problems with their coverage of tried and tested techniques - "Top Down", RCSA's & Loss Event analysis (p9-10)
  • Nice turn of phrase regarding emerging risks on p9 - "...assess the proximity of new risks to the organisation". It may need to include an attempt to quantify to be fully useful for ORSA purposes.
  • Concept of residual risk arrives quite late in the day, but isn't omitted. Important, given how much qualitative, or spuriously quantitative, material is being promoted as aiding this measurement work (p10)
  • Seem to accept at the bottom of p10 that Internal Modellers must do more than curve fit on internal Op Risk Event data - good news I guess.
  • Internal Model validation pressures on current Op Risk quantification practices flagged directly (p16 in particular)
  • Guidelines on embedding Op Risk monitoring processes highlight just how much work some practitioners are managing to cover (p11). Quite disheartening for those with smaller budgets.
Ther are a few points to make on section B around quantification:
  • Pretty scathing on Standard Formula relevance. (p14)
  • Scenario Analysis sold as something of a panacea to cure the ills of incomplete Op Risk Event data sets, but no mention of the biases which seem to permeate the creation of the scenarios, which is sadly a hostage to the invitee list. (p14)
  • Expand more on scenario analysis, bringing the "severe but plausible" terminology to the table (p15)
As well as the following generic comments;
  • Is risk measurement - "a tool for embedding risk culture in the organisation"? I would say so, particularly in the Op Risk arena, where decision makers will need to be involved at scenario-compilation time.
  • That said, they then go on to reference "senior management sign-off" of scenario work, which is somewhat contradictory!
  • Overweight in references to "culture" and "tone at the top", like most white papers these days (see the FRC's efforts from the other week). Playing with fire as a profession by shoehorning references to "culture" into everything.
  • A couple of horror-show schematics used on pages 7 and 8 - the Forum must know how much time risk professionals lose walking non-experts through things like this. They serve no purpose, and detract from surrounding text.
  • Attempt on p9 to solicit business for ORIC?
It was Professor Jagger who accurately prophesised "You can't always get what you Quant" - I'd say the Risk profession concurs, based on these very welcome principles.

Wednesday, 20 November 2013

Financial Stability Board - Principles for an Effective Risk Appetite

Christmas has come early everyone - the Financial Stability Board have released their Principles for an Effective Risk Appetite Framework today, and I'm greedily ripping in to it before JC's birthday like a spoilt, yet handsome child...

FSB's RAF Principles published
send the car back lads...
There has been a reasonable amount of traffic on Risk Appetite this year (here, here and here for a start), after the FSB but announced their consultation earlier in the year, I've been on tenterhooks. This was following of the back of a thematic review on Risk Governance as a whole by the FSB, which they published back in February.

So where do they take this deep dive into Risk Appetite? Other than awkwardly shoehorning in the soup de jour of "SIFIs", they stick to the hard areas which will get every risk practitioners' attention (namely, Risk Appetite Framework, Risk Appetite Statements, Risk Limits and Roles and Responsibilities), though "for clarity and simplicity", they jettison the use of Risk Tolerance. Definitions are supplied on p2-3, which you may find useful as anchor references.

They somehow make room for anodyne flannel in this very short document, for example;

Risk Appetite Frameworks
  • Should "facilitate embedding risk appetite into the financial institution’s risk culture
  • Development and establishment is an "...iterative and evolutionary process that requires ongoing dialogue throughout the financial institution to attain buy-in across the organisation" (groan)
Risk Appetite Statements
  • "Risk appetite may not necessarily be expressed in a single document; however, the way it is expressed and the manner in which multiple documents form a “coherent whole” need to be carefully reviewed to ensure that the board obtains a holistic, but compact and easy to absorb, view of the financial institution’s risk appetite"
Risk Limits
  • "Having risk limits that are measurable can prevent a financial institution from unknowingly exceeding its risk capacity as market conditions change and be an effective defence against excessive risk-taking" - tell that to Lehmans!
However, the salient points for me were as follows;

Risk Appetite Frameworks

  • RAF "...sets the financial institution’s risk profile" - not convinced on that one, but may be semantic issue
  • "explicitly defines the boundaries within which management is expected to operate when pursuing the institution’s business strategy"
  • Should "be adaptable to changing business and market conditions" to allow for limit increases where appropriate


Risk Appetite Statements

  • "[should] address the institution’s material risks under both normal and stressed market and macroeconomic conditions"
  • "...should establish quantitative measures of loss or negative outcomes that can be aggregated and disaggregated"
  • "...include key background information and assumptions"
  • "...include quantitative measures that can be translated into risk limits"
  • "...be forward looking and, where applicable, subject to scenario and stress testing"

Risk Limits

  • "[should] be set at a level to constrain risk-taking within risk appetite"
  • "...should not be strictly based on comparison to peers or default to regulatory limits"
  • "[should] not be overly complicated, ambiguous, or subjective"

Roles and Responsibilities

The Board

  • ...must establish the institution-wide RAF and approve the risk appetite statement, which is developed in collaboration with the chief executive officer (CEO), chief risk officer (CRO) and chief financial officer (CFO)
  • FSB specifically comment that Boards who "receive" or "note" Risk Appetite Statements have a lower understanding of risk appetite (so don't sponsor it!)
  • " [should] regularly review and monitor the actual risk profile and risk limits against the agreed levels (e.g. by business line, legal entity, product, risk category), "including qualitative measures of conduct risk"
  • " [should] ensure risk management is supported by adequate and robust IT and MIS to 
  • enable identification, measurement, assessment and reporting of risk in a timely 
  • and accurate manner."
CEO should
  • "...be accountable, together with the CRO, CFO, and business lines for the integrity of the RAF"
  • "...ensure that the institution-wide risk appetite statement is implemented by senior management"
  • "...provide leadership in communicating risk appetite to internal and external stakeholders" 
  • "...establish a policy for notifying the board and the supervisor of serious breaches of risk limits and unexpected material risk exposures"

While there are specific sections for the obligations of CRO, CFO, Internal Audit and Business Unit Management, they don't necessarily expand much further than what I consider to be normal functional expectations, so I haven't elaborated on them.

One should certainly therefore expect a much more aggressive approach from supervisors in future off the back of this - combing through strategy and board papers for evidence of Risk Appetite in application, and making sure that Risk Appetite Statements are not just 'rubber stamped', for example.

I certainly don't see much in this for stakeholders. Nothing particularly new is brought to the table here, and if this is the results of peer review and shared experiences, then clearly there is concurrence on how an RAF should be constructed, what a RAS looks like, and who should do what in regard to continuous monitoring.

The skill will be for risk practitioners to convince their CEOs/NEDs that, this is no longer a sidecar activity in the ERM best practice space, but a nascent global minimum standard which will invariably surface in national regulations in the forthcoming moths and years.

Tuesday, 10 September 2013

Towers Watson - 'Risk Appetite revisited' (did we ever leave it?)

I have been doing a little work on Risk Appetite in the background recently, so was intrigued to have a read through this recent release by Towers Watson on the subject, seemingly targeted at North American and UK markets, but relevant to any practitioner in this space. Somehow I wasn't put off by p6 when, in response to the hypothetical question 'What is Risk Appetite', they responded with, "...we do not want to focus too much on the issue..."!
Appetite - second helpings?

I had blogged earlier this year on Risk Appetite, covering the expectations of EIOPA on the matter (which are few), as well as the more pokey/proddy stakeholders like the PRA/Central Bank of Ireland/S&P (which are several!), so the backdrop of risk appetite's practical significance to insurers doesn't need to be repeated here, more how consultants and practitioners are improving their game on the ground. Worth noting here that a few of the other consultancies have proffered their two cents on the matter over the last year or so (here, here, and here).

While interest in 'risk appetite' is currently piqued at governmental level thanks to the forensic examination of the banking industry's failings (multiple references in Parliamentary Commission evidence here and here for example), the driver of activity in the UK and Ireland is predominantly from the regulatory compliance perspective rather than expectations of bespoke, strategy-driving activity. In addition, we now see the emergence of Internal Audit as a party with a vested interest in the matter, which has the potential to draw the subject even more to a tidy, but ultimately superfluous documentation exercise.

With that in mind, Towers note that this paper is focused on "...enhancing risk appetite by improving its articulation, via clearer linkages to mission and strategy", and a rather derisive tone is therefore applied throughout regarding the familiar quantification methods preferred by regulators to monitor likelihood of insolvency in the next 12 months, giving equal billing to non-monetary capital and qualitative measurements. The paper also crosses some familiar ground, such as a lack of consistent terminology, which it tries to address (below).

Oddly, the document does not reference the FSB's thematic review of risk governance earlier this year, which will surely drive efforts in this space in the medium term, if only due to the paucity of certainty on the subject. That the FSB believe that regulators have "more work to do" is striking, and while they also bemoan the lack of common terminology, they don't let that prevent them from offering definitions of their own, as well as listing their "Key features" of a Risk Appetite Framework.

More obvious statements

  • "..clearer linkages are needed to mission and strategy for risk appetite to be effective"
  • "risk appetites must include boundary constraints"
  • "We suggested that greater clarity around the definition of risk is needed..."

Definitions
  • Risk - "In this context, risk should be defined in terms of those events and circumstances that may result in an insurer failing to deliver on its mission."
  • Risk appetite - "...the manner in which a company expresses an identified set of risk-trading opportunities, and sets boundaries on its risk-trading among those opportunities, aligned with successfully delivering on its mission."
  • Risk strategy - "The company’s risk strategy articulates how risk fits with the mission".
  • Risk tolerance - "Risk tolerances are a quantitative extension of the risk strategy...risk tolerances must be measurable...[and] place quantitative boundaries on the company’s strategy"
  • Risk limits - "Risk limits are more granular tolerance levels expressed for specific risk sources, business units, and/or products that are used to implement the risk tolerances."
  • Risk appetite statement - "...risk appetite statements should be taken as the combination of risk strategy tolerances and preferences, bringing together qualitative and quantitative enterprise perspectives on risk as both opportunity and threat."
  • Mission - "mission is the insurer’s unique multi-period and multi-stakeholder value creation proposition."
Technical suggestions

  • They promote four facets of risk assessment: size, likelihood, impact and significance.
  • For those working on statement content, they recommend "...since published mission statements can be fairly terse, the risk appetite may need to look beyond the explicit elements of the mission and consider elements that are implicit." Instinctively that feels unfair, but I guess the world of implicity is one for the second line to inhabit, while the first line concentrate on value-adding.
  • Concept of adaptive buffers sits nicely with me - the most visceral ones being economic capital and reinsurance/hedging/liquidity facilities, but TW attempt to expand that over qualitative areas of the risk appetite statement
  • Risk preference ranking of 0-4 depicted at the back is a handy schematic

Sore points

  • "Some take the view that risk appetite can be expressed as a single metric, or perhaps a small set of metrics, that capture the organisation’s willingness and ability to bear risk." - that 'some' would include the FSB, COSO, the Central Bank of Ireland and the IRM, so I wouldn't be too sniffy at efforts to-date
  • "Much of the work to-date on risk appetite statements has been driven by solvency supervision requirements, many statements tend to focus primarily on potential losses of capital"- a natural and by no means unwelcome by-product of having regulators in the box-seat, as opposed to stakeholders combining their efforts to establish compulsory risk appetite statement content?
  • "While most insurers have, by now, developed risk appetite policy statements and discussed them with their boards, many have expressed dissatisfaction with the exercise" - that feels a rather loose statement, and if true says more about the personnel charged with performing the work.

I'll take a look at the diversity of definition in the risk appetite space across different bodies in a separate post - for now, just enjoy this tidy piece of work for what it is.


Friday, 29 March 2013

EIOPA Preparatory Guidance - ORSA (or 'forward looking assessment of risks')

Forward-looking assessment of the undertakings own risks (based on ORSA principles) (plus explanatory text)

The ORSA preparatory guidelines* are not a massive burden for anyone busy rolling eggs down hills at the moment, coming in at 34 pages containing 25 guidelines, as well as 29 pages of explanatory text. In this instance, it is probably disappointing to any underprepared supervisors and insurers in that they may have preferred more!

More pointedly, the materials add little to what was already in existence from EIOPA in July 2012, and certainly will required little in the way of adaption in the UK's instance, who are already in a similar headspace and have been advising accordingly.

Of course the world and her husband have piped up with their opinion on what ORSA should cover and how it should be administered and documented (this post has a decent sweep at capturing most of them), so opinion on this matter is something we are not short on.

For me the headline points are:
  • ORSAs (well, 'overall solvency needs assessments', but let's be serious!) expected from 2014
  • Internal Models should be used by anyone in pre-application
  • Likely that most standard formula firms will have to qualitatively assess deviations between SF and their own Risk Profile at this time
  • Expectation of an internal ORSA report and a ORSA supervisory report
  • Records of the assessment expected to be documented and kept which must be "appropriate" - no prescription of what that means
  • ORSAs to be performed at least annually
The following points are either new, or worthy of reiteration for anyone whose preparations on this front are less than certain - for ease of reference I have used 'ORSA' where EIOPA use 'forward looking assessment of risk', and as with the other preparatory guidance papers I have looked at, I will assume there will be blanket application as written, with no dissent from industry or NCAs:

Guideline 3
  • Overall Solvency Needs assessments will be expected from 2014 (i.e compliance with Article 45.1)
  • Minimum of 80% of the market must also assess whether they would comply with the Articles 45 (b) and (c) from 2014 - regardless of any Pillar 1 uncertainty.
  • Internal Models expected to be used in ORSAs if a company is in model approval pre-application
  • IF the standard formula is 'provided' by 2014, expectation that SF firms will assess deviation between the SF assumptions and their own Risk Profile - this excludes anyone outside of the magic 80% catchment figure mentioned above.
Guideline 6 - Documentation generated by ORSAs must include:
  • An ORSA Policy
  • An ORSA Record
  • An Internal ORSA Report
  • AN ORSA Supervisory Report
Guideline 7 - The ORSA Policy must include
  • Description of component ORSA processes and procedures
  • Consideration of the linkages between Risk Profile, Risk Tolerances and Overall Solvency Needs (OSN)
As well as information on
  • frequency on stress tests, scenario analyses and reverse stress tests; 
  • data quality standards; and 
  • the frequency of the assessment, justified in relation to Risk Profile, volatility of OSN relative to capital position, timing (from calendar perspective I guess) and circumstances for ad-hoc assessments
Guideline 8 - ORSA Record
  • Firms expected to "appropriately evidence" the assessment - no prescription as to what that means (logs, working papers, meeting minutes, e-mails)
Guideline 9 - Internal ORSA Report
  • AMSB must communicate results to "all relevant staff" post-approval, which includes the ORSA results and conclusions
Guideline 10 - ORSA Supervisory Report
  • 2 weeks after concluding ORSA, ORSA supervisory report must be submitted, which must include;
  • Quantitative and qualitative results, and conclusions drawn
  • Methods and main assumptions
  • Comparison between Own Funds, SCR and OSN
Guideline 11
  • Must quantitatively estimate the impact of different valuation bases (if used) when assessing OSN
Guideline 12
  • OSN must be quantified, supplemented by a qualitative description of all material risks
  • Expectation that these items are all stress/scenario tested
Guideline 17ORSA output to be used at least for;
  • Capital Management
  • Business Planning
  • Product Development
Guideline 18
  • ORSA to be performed at least annually

* So let's end with something fundamental, EIOPA - it is NOT useful to replace 'ORSA', as an acronym or indeed in full, with the expression "Forward-looking assessment of risk (based on ORSA principles)" 5 years down the road - I'm sure there is a rationale, just as sure as I am not going to like it (even the GCAE agree with me, going with 'ORSA-like')!

Thursday, 28 March 2013

EIOPA Preparatory Guidelines - System of Governance

Consultation on System of Governance preparatory guidance (plus explanatory text)

For a topic which has felt like a given for a number of years (certainly in UK and Ireland where we already ask a lot in this area), the System of Governance preparatory guidance is still 40 pages, comprising of 57 guidelines, accompanied by 60 pages of explanatory text.

A couple of things immediately grabbed at me when going through the guidance (again anticipating a conservative approach of the supervisors rolling over and applying all content as is)
  • That the Risk Management Policy (regardless of how one structures the component elements) is expected to contain procedure-level information about the management of each major risk category - this sounds hopelessly disproportionate, and almost impossible for supervisors to reasonably get through;
  • That it is "expected" that large or complex firms separate their four key control functions, and that others at the small/medium end may ultimately find it easier to do so than consider the range of controls/maintenance of independence required to have combined functions;
  • That an expectation that insurers' systems of governance require regular independent review, with the AMSB only retaining the ability to choose the performer;
  • That insurers will be expected to formally identify/analyse/report on Operational Risk Events
  • That EIOPA bottled out of defining Risk Appetite and Risk Tolerance, leaving national supervisors and insurers to fight it out amongst themselves.
Ultimately, the document reads like a checklist which practitioners or full-timers can run through against the suite of documentation no doubt already in existence which, if based on CEIOPS/EIOPA final advice and/or the Commission's Draft Level 2 measures, won't be miles away as it stands. On that premise, I've only listed elements which jump out for me.


GENERAL GOVERNANCE REQUIREMENTS

Guideline 3
  • Evidence should be collected of the AMSB "proactively" seeking information from committees/key functions
Guideline 5
  • No more detail than an expectation that the AMSB "appropriately implements" their key functions - in the explanatory text, it goes on to say that larger companies will be "expected" to fully separate Risk/Actuarial/Compliance/IA, with a series of measures expected to preserve functional independence if smaller companies choose to combine some.
Guideline 7
  • Expectation that both AMSB decisions, and how information generated from the Risk Management System (RMS) influences them, is "appropriately documented" - compulsion for Board Decision Logs?
Guideline 8
  • Regular System of Governance reviews appear to be expected, which are documented and reported back to the AMSB - the AMSB retains the right to choose who performs it 
Guideline 9 - All policies must include:
  • Goal of policy
  • Tasks to be performed and by whom (person or role, unlike for validation, where person/s was specified)
  • Associated processes and reporting procedures
  • Obligations of affected operational teams to inform control functions of "relevant facts" at all times
Guideline 10
  • Contingency plans are expected for areas which are "especially vulnerable" - this pushes outside of what one would consider a conventional contingency plan for operational emergencies.

FIT AND PROPER

Guideline 11
  • Must have a Fit and Proper persons policy
  • It must be equally applicable to both hired staff and outsourced functions

RISK MANAGEMENT

Guideline 15 - AMSB is "ultimately responsible" for:
  • RMS effectiveness
  • Setting Risk Appetite and Risk Tolerance Limits
  • Approving Risk Management strategies and policies
Guideline 16 - Risk Management Policy must cover at least
  • Risk categories used and measurement methods
  • How each category/grouping of risks is managed
  • Risk tolerance limits for all categories in line with Risk Appetite
  • Linkage of both SCR and ORSA to risk tolerance limits
  • Frequency and content of regular stress tests, and circumstances for additional testing
In addition, the associated guidelines touch on the risk categories within one's Risk Management Policy. There is an expectation for pretty much every category that procedure-level information is included in the policy documents themselves, as well as hard limits, which is unlikely to be the case as it stands.

Guideline 18 - Insurance Risk Policy
  • Expected to cover types of acceptable insurance risks, how premiums will cover claims/expenses, as well as how product design accounts for investment restrictions and formal risk mitigation techniques
Guideline 19 - Op Risk Policy
  • Expectation that Operation Risk Events will be formally identified/analysed/reported in insurers, and that a system for collecting and monitoring them should be in place.
  • Operational Risk Scenarios should be developed and used, based on failures of key persons/processes/systems and external events
Guideline 23 - Investment Risk Policy
  • Buzzphrase introduced of managing the level of "security, quality, liquidity, profitability and availability" of one's asset portfolio

OWN FUND REQUIREMENTS AND THE SYSTEM OF GOVERNANCE

Guideline 32
  • Concept of a "medium term capital management plan" introduced which covers; planned capital issuances, maturities and distribution policies - not sure how that works for mutuals, but I can see what they're fishing for

INTERNAL CONTROLS

Guideline 33
  • "All personnel [should be] aware of their role in the Internal Control system
  • The Internal Control system should be "commensurate to the risks arising from the activities and processed to be controlled" - this line should hopefully avoid overkill

INTERNAL AUDIT FUNCTION

Guideline 36
  • The Internal Audit policy should include the procedure for informing supervisors [of whistleblowing-level wrongdoing I guess]

ACTUARIAL FUNCTION

Guideline 44
  • "Material"deviations of Best Estimate Liabilities should be back-tested for by the Actuarial function, reported on, and remedial changes proposed
Guideline 46
  • The Actuarial function is expected to "contribute to" specifying the risk coverage in the internal model, as well as the dependency structure - this feels like areas where, even in larger insurers, the function probably already leads, so will they be asked to take a step back?

Monday, 11 March 2013

Aon Risk Maturity Index Report 2013

With the potential for early implementation of Pillar 2 on the horizon for Europe's insurers, Aon's release of their latest research on Risk Maturity Index is perhaps a timely one, particularly for anyone in the small-to-midsize bracket who wants to get a feel for the proportionality of their current approach (and for UK IMAP candidates, whether it might fold under ICA+ questioning in the next two years!)

Their claim that that the Risk Management Index fills the current "void" which prevents interested parties from benchmarking their risk management frameworks against those of their peers, and indeed reaching recommendations on how to further enhance them has a whiff of bolshiness about it, but nevertheless, the output is valid for practitioners in all industries.

Fundamentals behind the research, conducted in conjunction with Wharton Business School, are;
  • Aon's "Risk Maturity Index" is an online self assessment of risk management practices.
  • It asks 125 questions regarding 40 "key components" of risk management - all tied in to the following 10 characteristics of risk maturity:
 1. Board Understanding & Commitment to Risk Management
 2. Executive Level Risk Management Stewardship
 3. Risk Communication
 4. Risk Culture: Engagement & Accountability
 5. Risk Identification
 6. Stakeholder Participation in Risk Management
 7. Risk Information & Decision Making Processes
 8. Integrating Risk Management & Human Capital Processes
 9. Risk Analysis & Quantification to Understand Risk & Demonstrate Value
10.Risk Management Focus on Value Creation
  • Allows for a ranking between 1-5 across various sub-cuts of the data collected, and an assessment in aggregate of each firms "risk maturity"
  • Data was then analysed against over 100 listed companies from 20 industries, geographically spread, to see if "risk maturity", or a lack of it, translated into anything measurable
  • Over 500 companies have responded to the survey since 2011, this being its second periodic summarisation (results from first one summarised here).
The headline news was that a correlation was identified between organisations with superior risk maturity and stock price volatility, with a reduction of up to 50% potentially up for grabs between the 'best' and the 'worst' - a particularly visceral way to "derive and demonstrate financial value from...risk management frameworks" which, let's face it, is a hard sell for the best of us!

I observed some more general points from the white paper, namely;
  • The insurance industry was third only to Aviation and Consumer Goods in the assessment of risk maturity - something to be learnt from these industries (in particular around Op Risk maturity in Aviation)?
  • Only 15% of respondents were rated at 4+ out of 5, or "operational/advanced" in Aon's terminology
  • Lower revenues seem to translate into lower risk maturity on the whole
  • Responses from CRO's resulted in the best aggregate maturity scores, while Internal Auditor/CFO responses resulted in the worst aggregates - expected biases nicely exhibited
Of particular note though were the three areas of common differentiation between higher and lower rated firms which are worthy of more attention than might otherwise come from reviewing average maturity scores. 

Awareness of the complexity of risk - more mature organisations are able to demonstrate:
  • Risk adjusted return expectations by business unit/department
  • Documented and applied assumptions in forecasts/projections
  • Supporting forecasting ranges with applicable historical data
Agreement on [risk] strategy and action - more mature organisations stabilise their performance by:
  • Re-evaluating risk management strategy based on experience
  • Reviewing and validating risk tolerances based on external conditions
  • Evaluating strategic decisions with reference to quantified risk tolerances
Alignment to execute [the risk strategy]
  • Communicating negative results and predictions (nicely tied into Risk Culture by Aon)
  • Developing cross-functional risk understanding, and how organisational activity relates to overall risk management strategy 
  • Incorporating risk/return approaches into strategy, in particular recognising up-side potential in decision making, rather than loss minimisation

These are particularly interesting findings for the EU insurance industry, who will be waddling into Live ORSA territory in the coming weeks and months. Fair to say that Solvency II Pillar II accommodates much of what is covered here, so worth thinking about leveraging this benchmarking work in one's 2013 activities.




Friday, 15 February 2013

Financial Stability Board - Thematic review and recommendation on risk governance

The Financial Stability Board (FSB) have been sticky-beaking around systematically important financial institutions (SIFIs) with a relative unchecked remit ever since the financial crisis first reared its head. This week they have emerged with a very significant document for Risk practitioners across the globe, with a thematic review of Risk Governance (press release also available here). The participants were 36 banking and broker/dealer institutions of interest, as well as major supervisory bodies and NGOs.

On the basis that there isn't a single accepted global standard on the matter, the thematic review compares prevailing practices against an amalgamation of content from exising standards from the IAIS, OECD and other bodies. Of major interest to risk practitioners is the document's focus on areas which the IRM have covered recently, namely risk appetite/tolerance/limts/capacity and risk culture.

Bearing in mind the great and good from the prudential regulatory world are active participants in the FSB, the likelihood of their findings emerging in the regulatory principles of tomorrow are pretty high. Of course this research has been based on Non-Insurance SIFIs, and so insurers large and small who have been endeavouring to meet Solvency II Pillar II requirements will find themselves in a decent spot already.

On that basis, I noted the following;

General recommendations to supervisory bodies (p4)
  1. Formal requirements on the independence and skillsets of Boards
  2. Hold Boards directly accountable for risk governance, and whether or not their existing suite of risk MI is sufficient
  3. Formally elevate the stature, authority and independence of the CRO role
  4. Require an independent assessment of the effectiveness of the risk governance framework to be performed on an annual basis (a list of what Internal Audit would generally review in this context follows on page 24)
  5. Engage "more frequently" with Boards and management to assess risk culture
Sound practices list p30-34 - highlighted below are elements which may be new to the UK in particular, were they to be introduced
  • Boards - annual reviews of member qualifications, skills and time commitments; meet quarterly with regulators; "effectively inculcate" an appropriate risk culture
  • Risk Committee - annual approval of risk management policies
  • Risk Management function - CRO to have direct reporting lines to Board/Risk Committee as well as CEO; public disclosure of CRO firing/hiring; be "actively involved" in strategic decision making processes; meet quarterly with supervisors; stress testing "on demand" at the behest of the business
Risk culture and risk governance supervisory assessment
  • Notes that supervisors need to strengthen their ability to assess a firm's risk governance "...and more specifically its risk culture"
  • "More work is needed" on regulatory assessment of risk appetite frameworks
  • "Risk culture plays a critical role in ensuring effective risk governance practices through changing environments"
  • FSB have a working group exploring the potential for formal risk culture assessments, who are  reporting in September 2013
Risk management functions and CROs
  • Acknowledges that there have been "[raised] supervisory expectations for the risk management function" since the financial crisis
  • Highlights that "most firms note that the CRO has a direct reporting line to the CEO", though "access to the Board" apparently remains more of an expression than a vivid reality
  • "Good progress" has been made on enhancing the stature, authority, and independence of the CRO position
  • Rather non-descript comment that "the Chief Risk Officer and the risk management function are responsible for the firm's risk management across the entire organisation" - responsible for what element, not conduct surely?
Risk appetite/tolerance/limts/capacity
  • Acknowledge a "lack of common terminology for risk appetite, risk profile and risk capacity...within firms, across firms and across national authorities"
  • Definitions of appetite and capacity used by FSB largely line up with IRM's definitions (though the IRM use 'tolerance' rather than 'capacity')
  • "Key features of a Risk Appetite Framework" are listed on p22 - however even those firms considered best in breed commented that there are ongoing "operationalising" problems with RAF rollout
  • Suggest that breaches of 'risk limits' should lead to reductions in exposures (piii) - not sure why the alternative of increasing appetite is not acknowledged



Monday, 1 October 2012

FSA on ongoing appropriateness of internal models (which aren't appropriate yet...)

Ploughing on regardless like a John Deere with a lobotomised driver, the FSA continue to work on their plans for ongoing appropriateness of internal models after Solvency II goes live. Having put their initial ideas out for feedback in June, they have this week provided an update on responses received, which hinted at a few things;
  • IMAP Participant apathy - 10 responses (attrition rate is potentially rising these days, but we must still have 60-odd with skin in the IMAP game, so that feels pretty lousy)
  • That inappropriateness would only be to a firm's benefit, hence the supervisory response to its detection "in all but exceptional cases" will be a capital add-on (PS if 'inappropriateness' is a word, I'll mange my chapeau, but I'll stick with it for now).
  • That the early warning indicators planned will form part of the FSA's BAU Supervisory Review Process alongside "in particular" model validation results - any danger the early warning indicators may therefore be used informally in the pre-application work? They do go on to stress in the letter that they "do not intend" to use early warning indicators in the initial approval process, but bearing in mind no-one showed up for round 2 of the three-way today, we're all eating at a pretty moveable feast right now!
The link between early warning indicators and validation results is probably the big message in here - could verging on breaching the % tolerance, plus a negative validation report, lead to a capital add-on in 2014/2015/20XX?

Sunday, 5 February 2012

COSO - understanding and communicating Risk Appetite

Hot on the heels of materials pushed out on the Irish front from both the regulator and the consultancies, as well as the IRM's efforts in autumn of last year, COSO have stepped up to the plate with their take on understanding and communicating Risk Appetite, a topic which will be spectacularly relevant to insurers over 2012 for ORSA purposes, and indeed for anyone in and around the Irish Sea for corporate governance compliance reasons.

Having had a good sniff through, I struggled to find anything controversial in COSO's take on things, and, whether by accident or by design, it treads the same path as Richard Anderson's paper from the IRM.

The following quotes provide some of the more salient points made by the authors;
  • "Risk appetite is the amount of risk, on a broad level, an organisation is willing to accept in pursuit of value" - not a bad way to think of it for an insurer (i.e. embedded value), though the 'broad level' add-on is unnecessarily and disconcertingly vague. This incidentally  runs against one of the IRM's key principles, namely that risk appetite must be measurable (p7).
  • Authors believe that "...when properly communicated, risk appetite provides a boundary around the amount of risk an organisation might pursue" - without splitting hairs, the definition of risk appetite above isn't especially black and white!
  • The three risk appetite steps of "Develop-Communicate-Monitor and update" are spot on, however, one might think that the "develop" piece is already done in most organisations (or why would the owners get up in the mornings?), and communicating it is the big issue.
  • Should create a Risk Appetite Statement which is "broad enough yet descriptive enough for organisational units to manage risks consistently within it" - good point, as of course some departments of a business would struggle without such breadth in their appetite statement (business continuity and marketing spring to mind)
  • Similarly, that statement should "balance brevity with the need for clarity"
  • Confidently states that "we all know the costs of failing to manage risk", but dished out some pretty generic examples, bearing in mind the zingers which have pitched up over the last three years
  • Exhibit 1 on considerations affecting risk appetite is a very smart schematic for provoking thought at executive level
  • Box on p5 has a rather definitive statement around there being a lack of risk appetite articulation which contributed to the current financial crisis - certainly wasn't a problem at Lehman's, more that it was a moveable feast!
  • Handy box on p7 which covers the tie-in between what rates as an "adequate" ERM Framework in the context of S&P's ratings methodology, and what management must be able to articulate on the Risk Appetite front.
  • Some very nice examples (p8-10) of risk appetite statements from different industries, and of risk tolerance statements anchored to associated risk appetite statements (p13-14).
  • The big one - differentiating Risk Appetite and Risk Tolerance - is on p11. Whether you agree with the COSO conclusion (i.e. that Risk Tolerances implement Risk Appetite within each operating unit's sphere of influence), it does at least try to square the circle, and the clarity should benefit practitioners. However, the statement "While Risk Appetite is broad, Risk Tolerance is tactical and operational" is poor - I'm guessing one could substitute "broad" for "strategic", or "tactical and operational" for "specific", and it makes sense.
  •  Interesting list on p16 of questions to facilitate Board-level discussions on Risk Appetite which I suspect is probably too wordy for many Boards to throw themselves into wholeheartedly.
  • Starts to peter out towards the end, which is normally the case with such guidance materials (once you start descending into 'performance models', communications strategies and risk culture, the ability to prescribe content and form to disparate organisations diminishes substantially).

Ultimately, while the document is of considerable use for anyone who needs a reputable crutch on the topic (and is perhaps outside of financial services), it is probably too generic to be of great use as an aide-memoire to any Solvency II-covered insurers, and I would stick with the IRM's take ("those risks that [an organisation] actively wants to engage with" when scripting a Risk Appetite Statement. 


Chapeau for the good parts nevertheless...

Saturday, 14 May 2011

IRM - Risk Appetite and Risk Tolerance consultation

Only got the tip-off on this today, so still have some reading to do, but clearly the obligations of exec and non-exec directors have turned Appetite and Tolerance into fertile ground, hence this consultation from the IRM.

I am personally not against a prescriptive approach to these topics, provided no board members exempt themselves from learning new things - I may throw a few comments in, especially on Risk Appetite, which there is a distinct danger under Solvency II will become a documentation process which has the dust blown off it periodically, rather than enjoying pride of place on the decision-makers table.