Showing posts with label benchmarking. Show all posts
Showing posts with label benchmarking. Show all posts

Wednesday, 26 August 2015

PRA Final Notice on Co-op Bank - "cautious", with blurry lines...

"Two straws please"...
The PRA published a Final Notice last week regarding the numerous shortcomings of a UK bank over the last few years, which included the news of a colossal £121m fine which the PRA would have levied if the entity wasn't still losing wedge faster than a mojito in a cement mixer.

I'm sure some of us chortled at the Chrystal Methodist headlines a couple of years ago when the Non-Executive Chair of the UK's Co-operative Bank had his numerous vices sold to the highest tabloid bidder by a rented acquaintance. I covered some of the initial fallout on here, themed mostly around reputational risk and fit and proper persons, given the exponential effects of the exposé on the ultimate failure of the Group in its form at the time.

A document covering part of Co-op's demise, specifically its Bank, was released last week by the PRA,

The PRA's Final Notice to the Co-op Bank is issued publicly, and highlights where the firm breached what were at the time the FSA's Principles for Business, replaced since the PRA/FCA divorce by the PRA's Fundamental Rules.

Included in the Final Notice on this matter was a number of matters which risk practitioners should be salivating over, given the failures which led to this punishment include
  • Inappropriate culture,
  • Internal control framework failures,
  • Ineffective risk management policies, and, the jackpot,
  • A "three lines of defence" model "...flawed in both design and operation"!
The activities demonstrating this include a woeful suite of incomplete management information, three horrendously chancy accounting interpretations benefiting the balance sheet at the expense of real-world accuracy, and a suite of defensive line failures, all of which are followed through in forensic detail.

I have sectioned my notes below for my own use, particularly given the PRA goes on something of a limb here and provide usable definitions for certain terms which I suspect many practitioners would benefit from reading. The PRA (and EIOPA) generally try to dodge requests for definitions, so while the peg is square and the hole is round, it might be as good as you get!

Definitions and expressions
  • Three lines of defence - "This is a system which relies on there being an opportunity at three complementary and independent levels to identify and correct any control failures". 
  • Second line of defence - "Second line functions should support and challenge the management of risks firm-wide, by expressing views within a firm on the appropriateness of the level of risks being run"
  • The above is supplemented by the following: "Responsibility for risk should not be delegated to risk management and control functions" - amen brother!
  • Third line of defence - "Internal Audit should provide independent assurance over firms' internal controls, risk management and governance"
  • Risk Appetite - "A firm's stated risk appetite is an important factor in determining whether a firm's risk and control framework is commensurate with [the] nature of its business, and should be both integral to a firm's strategy and at the heart of its risk management system" - not far off a direct quote from last year's Approach Paper on Banking Supervision (p22), though it has moved from "foundation" to "heart" in this Final Notice. I know what I prefer to build on!
  • "Clearly-defined strategy" - they list "well-defined objectives, responsibilities and milestones" as expected
  • Policies - "The establishment of appropriate policies [and procedures] governing the conduct of a firm's activities is an essential component in the exercise of appropriate organisation and control of a firm's business"
  • "Good risk management culture" (p7) - interestingly an expression most bodies have avoided using, preferring "sound" to "good". They later go on to talk of culture more generically in terms of "right" and "inappropriate" (p33).
Observations
  • Interestingly, Co-op Bank never refer to operating "3LOD" until their 2012 Annual Report (p56 for the boilerplate and clearly untrue definitions), so any deficiencies in the model before that year might be for a good reason!
  • First line management oversight was seen as "inadequate" and "inappropriate" (p12)
  • Their second line managers "...repeatedly voiced concerns" about headcount (p29), which weren't addressed until the back end of the period under scrutiny. Hard to think post-2007 it would be hard to justify reinforcing that area of the business, which perhaps says a lot about the entity's culture. 
  • Second line not monitoring adherence to policies (p29) - quite hard to conceive of nobody in the second line doing this!
  • A clear distinction made more than once between "Risk Management Framework Policies" and "adequate policies and procedures" relating to operational matters (p5)
  • Some of the failure to follow 'internal policies' seems to have been sponsored by the acquisition of the Britannia book - perhaps a natural by-product of M&A activity, where the cultures and modus operandi clash (p21)
  • Second line criticised for not providing proper "independent challenge" - happy to see this, given the focus tends to be on second line oversight, which always feels like a bit of a jib-job.
  • Third line giving the business credit for proposed remedial action in its audit reports (p31) - even taking this into account, they were rolling over around 30% of recommended actions in their reports as "overdue"!
  • Head of Internal Audit reported to the Head of Risk
  • An implication that one may be permitted shortcomings in one's internal control framework, providing one's culture is "appropriate" (p5). 
  • An interesting slant on reputational risk emerges from one of the accounting interpretations used, specifically that while assuming a particular accounting treatment (on the Leek notes in this case) which benefits the entity at the expense of counterparty might benefit the immediate balance sheet, the long-term effect on being able to raise new capital must be considered (p16)
  • External Auditors using a 1-to-7 scale to assess how punitive/liberal the accounting treatments used by clients are. These assessments have bitten this particular client on the bum, given the PRA quote them in the document in the context of whether they align with a "cautious" risk taker!
Open ended questions
  • Is "cautious" a realistic appetite for risk at Entity level? More importantly, if one has a "cautious" risk appetite, is one obliged to manage its capital "cautiously"?
  • Management information was criticised for not being "sufficiently forward looking" - should it be (as opposed to mostly summarising positions at a point in time)?
  • Is the PRA allocating resources to firms based on their Risk Appetite Statements (p13)?
  • Is it possible for non-Accounting experts working in the second line to identify just how many ropey interpretations of UK GAAP/IFRS are being applied to a balance sheet? Is it plausible to leave such work to external audit firms who couldn't have a more vested interest in the grey areas of such legislation? The artificial boosting of the balance sheet listed in this notice would be subtle enough to trick an accountant or two I'd bet!
  • Can quant risks be effectively managed in a separate team from the qualitative world? Appreciating there is a shockingly blurry line in Co-op Bank's approach (p29), it certainly feels like Solvency II pressures might lead to similar pressures on the staffing front, particularly for modellers and small/medium sized firms where staff may wear more than one hat.

Wednesday, 12 August 2015

Insurance Banana Skins in 2015 - PwC and CSFI

PwC and the CSFI guys have teamed up for another Insurance Banana Skins publication, a particularly useful doc for the BAU Risk world, and one which I have covered on the blog in years gone by (well, 2011's and 2013's anyway).

In particular, I always found it useful as a means of digging out the kinds of awkward cross-bred expressions which would invariably end up rolling out of 75-year-old INEDs’ mouths at the next Risk Committee meeting, probably due to someone trying to sell insurance cover for it, or a business journal doing a centre spread about it. On this basis, I was delighted to see “Cyber Risk” given prominence this time around, which is the highest new entry, and apparently a “new risk” - here’s the sales forum, and here’s the HBR white paper!

Sarcasm aside, given this pulled in over 800 responses from around the globe, and across the distribution and provision side of the industry, the content is worth poring over and briefing colleagues on if this is your day job. There are also plenty of quotes from the great and good wrapped up inside as well.

I’ve only jumped on a few of the findings below;
  • Regulation remains the top risk for the 3rd survey running, and for the 4th out of the 5 actually held. It did take a ‘world’s end’ scenario for investment returns to knock it off the top in 2009 though, which suggests that those surveyed are happy to bleat about regulatory concerns, regardless of the rest of the exogenous threats to insurance firms.
  • Much of the top ten is focused on investments and returns, whether it be interest ratesinvestment performance or guarantees.
  • Governance and management of insurance companies seen as an area of declining risk – does it therefore warrant the Banking industry-inspired whip that SIMR is about to introduce in the UK?
  • Similarly, Business Practices, incorporating misselling, is falling down the list – not sure a UK-only survey would be so generous!
  • Cyber Risk itself was only #6 on the list for Life Companies, while #1 for Non-Life – wonder why the guys who are selling cover rate it so highly? Of more interest, North America had it as #1 “by some margin” – this suggests the wave will be coming across the Atlantic in the next 12 months (a nice precursor of how that will emerge here)! It is written up nicely however, with cloud storage, and the richness of data held on customers, being elements which make insurers prime targets. It doesn’t dwell on the proliferation of legacy systems in insurers however, which always felt to me a good reason for criminals to ‘have a crack’.
  • Europe considered the interest rate environment, regulation and guarantees to be the top 3 banana skins, which given the aggressive tailoring applied to Solvency II in the drafting stages to negate country-specific difficulties in these areas (MA/VA/Transitionals), is no surprise.
Oh, to have a day job again…

Tuesday, 11 August 2015

2015 FTSE Interim Reporting and Solvency II costs - forewarned and forearmed?

Solvency II costs - impressed?
I always liked to keep an eye on the FTSE lads’ Interim and Full Year pronouncements on the Solvency II front back in the day, but given the legslative delays and sporadic cost reporting over the last couple of years, plus the internal model hokey-cokey, disclosures on the topic have been “Slim Pickens” to say the least.

For those interested, the sweep I did last year is here, and while a few of the firms featured have attempted to expand out, they have largely disclosed the same information as last year (Boiler-plate disclosures? Never!).

However, a few of the great and good have chirped up some extras about Solvency II on the home straight, none more revealing than the Canary-supporting egg-chasers at AvivaThey dished up the basics as a matter of  course;
  • Solvency II costs of £46m for the half year (£39m for last half year)
  • Submitted Solvency II internal model in June and expect approval in December. – must be a good one, Hannover Re-style!
  • Currently operating within our expected Solvency II target range, regardless of any changes in economic capital surplus quantum and composition driven by Solvency II
The InsuranceERM lads expanded on that, having presumably dialled in to associated conference call! In a suit-and-tie version of Surprise Surprise (R.I.P Cilla), the CEO shocked listeners with the following statements;
  • "[Solvency II] has taken an inordinate amount of management time and I'd really like that time back"
  • "It has cost us in the region of £400m [$620m]. This figure does not impress me one little bit…” – to my shame I did do the countback on published costs, as if a CEO couldn’t count to £400m, and it does add up!
  • Solvency II costs of £14m for the half year (same as last half-year)
  • “…application for Internal Model approval under Solvency II has been submitted and we target a positive outcome by year end
  • "…current Internal Model for Solvency II shows higher coverage ratios than our ECA model.”
Old Mutual does its best to treat the SAM/Solvency II imposters the same in its reporting, but in recent times has been light on our side. There was a bit more in the bag this time round though, particularly;
  • "Based on the current underlying timetable and regulation of Solvency II, we estimate the total cost of completion will be up to £20 million, of which £10 million will be incurred in H2 2015, and the balance running into H1 2016".
  • "The Solvency II regime will introduce a different lens through which to look at Group capital. It will use a more conservative 1 in 200 stress scenario in determining capital requirements and apply a more rules-based determination of capital fungibility and transferability"
  • Given their tone on the “inherent conservatism” of Solvency II and their loving gazes at the existing FGD treatment of capital fungibility, can we read some indifference to their current treatment as a Group by the PRA, perhaps?
  • "During July 2015, we completed our initial reporting to regulators under the interim arrangements of Solvency II"
I suppose the biggest surprises continue to be the (potential) absence of compulsion to internally model for entities such as Old Mutual (confirmed as “out” of IMAP on p82 here). Given the PRA’s pronouncements on Standard Formula appropriateness and capital add-ons, you might expect them to be marched down the aisle before too long.

Standard Life,perhaps betraying where their strategic priorities lie (nicely covered here), did little more than state that they will “remain strong” on the capital front – nothing on costs, nothing on implications, and nothing on modelling (though they confirm here that they are “in” apparently!). “In”, but on the naughty step perhaps, or is the topic just unworthy of comment?

L&G were happy to talk technical, rather than cry about hundreds and millions of pounds of spilt milk – their release touched on the following;
  • Implementing a ‘capital-lite’ model for bulk annuity new business, by reinsuring out some of the risk (light detail here and here, more detail on p5 of the interims).
  • Solvency II internal model is being reviewed by the PRA, and “…It is anticipated that our Solvency II internal model will be approved in Q4 2015, ready for use on the Solvency II go live date - 1 January 2016”
  • Also have applications in for the use of transitionals, matching adjustments and using deduction and aggregation for its American business
  • “We expect the final outcome of Solvency II to result in a lower Group capital surplus and solvency ratio than the Economic Capital basis. Our Economic Capital model has not been reviewed by the Prudential Regulatory Authority (PRA), nor will it be.”
  • "We note recent clarification from the PRA to the effect that transitional capital will count as Tier One capital, including for assessments of dividend-paying capacity". This is particularly piquant given Sam Woods’ coverage of the “dividend” issue a few weeks ago when trying to reassure a room full of analysts that the insurance sector isn’t a busted flush from an investment perspective!
A busy reporting week for sure, with seemingly no horror stories come at the top-end of the UK Insurance Industry...Including a post-script from the Pru today.

They have revealed a miniscule spend of £17m on Solvency II costs in the year-to-date (against £28m for all of last year), as well as a few nuggets in the same vein as the competition;
  • "...we submitted our Solvency II internal model applications to the Prudential Regulation Authority in June 2015"
  • "We continue to seek opportunities to transfer longevity risk to reinsurers or to the capital markets and have transacted when terms are sufficiently attractive and aligned with our risk management framework."
  • "We also noted at the time that certain aspects of our economic capital methodology are different to those required under Solvency II and that the outcome under Solvency II would be lower than our reported economic capital level. This remains the case." - same issue as Old Mutual, one presumes?
They even dropped a Solvency II slide into this morning's presentation pack (slide 28). Interesting that they go to the trouble of highlighting that the transitionals and risk margin "broadly offset" on the UK Life book, as well as their distinct gripes in their Asian and US businesses. 

...and another post-script from Royal London (so I have everything on one page!)
  • Royal London will use the Solvency II standard formula approach initially and will consider seeking approval for its internal capital model in due course
  • We expect to meet the new Capital requirements without material adverse impact on policyholders but there are significant details which remain to be clarified about the new regime. It is possible the outcome from Solvency II will require insurance companies to hold more regulatory capital than is currently required. If Royal London was required to hold significantly increased capital, then the levels of Royal London Profit Share we are able to allocate to our participating members may need to be restricted

...and two more post scripts: firstly Admiral
  • "Admiral is developing an internal economic capital model which will be used to calculate regulatory capital requirements following approvals from the Group's regulators in the UK and Gibraltar. Such approval is not likely to be sought or granted before 2017."
  • "The Group's regulatory capital from January 2016 will, therefore, be based on the Solvency II Standard Formula, with a capital add-on agreed by the PRA to reflect recognised limitations in the Standard Formula with regards to Admiral Group's business (predominantly in respect of profit commission arrangements in co- and reinsurance agreements and risks arising from actual and potential Periodic Payment Order (PPO) claims)."
  • "The level of capital add-on and resulting Group capital requirement from January 2016 is expected to be confirmed by the PRA in the final quarter of 2015."
...and secondly Phoenix
  • "...submitted its application for regulatory approval of its Internal Model in June 2015"
  • "...Group capital position under Solvency II expected to be in excess [of current surplus]
  • "Over 2015, clarity on Solvency II regulations has improved but uncertainties remain in relation to the Group's IMAP and other Solvency II-related applications"


Wednesday, 24 June 2015

CRO Forum on Risk Culture - comin' from the body heat?

Risk Culture
- need another hero?
A subject which is gathering more steam than Tina Turner's windows, Risk Culture has been given the kid gloves treatment by the CRO Forum in their paper, Sound Risk Culture in the Insurance Industry.

They say at the start that the topic has become "prominent in regulatory circles", which given EIOPA appear to be wining and dining the subject (here and here in the last couple of weeks alone), is something of an understatement. Their increased interest has no doubt been fuelled by the FSB's work on the subject from a year ago. In addition, the Financial Reporting Council took a shine to the topic in its last update of guidelines in late 2014 (point 27 in particular), while cultural failings have turned the FCA into a modern day Robin Hood (speech from inception time here).

As well as fiddling around the edges of definition, the paper expands on a few examples of where cultural change can be driven from, stealing from a few other industries (aviation in particular) and a couple of insurers (Zurich receiving particular attention).

They fundamental base they work from is pretty fair:
  • No "good" or "bad" culture, hence they talk about practices that encourage a "sound" risk culture throughout. Given that ropey culture does not necessarily prevent the achievement of strategic goals, this smart.
  • No "one-size-fits-all" concept of Risk Culture (i.e. don't look for one in this paper!)
That said, the definition used for the purposes of the paper from the NN Group CRO is actually a pretty good one - "shared philosophy of managing uncertainty" etc - though it does suggest that a failure in risk culture might simply be someone not sharing the philosophy, which I suspect is where a lot of your more pragmatic colleagues sit!

There are a number of sound inclusions throughout;
  • Emphasising the links between risk culture and conduct risk currently being force-fed to the industry by EIOPA (p3)
  • The chart on p6 showing survey results of essential elements of risk culture - senior management and Boards leading by example is evidently seen as more important than risk-based remuneration, despite the legislative attention the latter receives (including this week in the UK).
  • Zurich's internal 10 question survey on culture assessment - contains the gorgeous expression "organisational humility", as well as bringing some of the granular risk culture elements onto the table, such as treatment of whistleblowers.
  • Highlighting the "common phenomenon" of management teams containing people with the same personal attitudes - could benefit the creation of a "shared philosophy" without necessarily any of the benefits.
  • The illustration of NN Group's "Risk Culture Dashboard" (p11) - I don't have preference for it either way, but it does illustrate how much effort one can direct towards risk cultural identification, assessment and monitoring, which begs the question "is there that much value in it?" They seem to like it as a way of covenying the concept in the business in any case.
  • Pages 13-14 provide some good brain candy for those who have ambitions to educate or brief their colleagues on risk cultural matters. Zurich's "we are all risk managers" campaign looks like it probably has legs (more on it here).
There are a couple of mildly objectionable parts within;
  • Concepts of "Risk Vision" and "holistic" dropped in early doors and littered throughout, as well as a few extras such as "risk perspective" - the kind of obtuse terminologies which serve to divorce Risk functions from their colleagues
  • That firms should have a "clear vision" for their risk culture - why would something as opaque as culture be expected to be "clear". They don't even define it as a term in the paper!
  • Concerned that risk culture is "...only practiced by risk specialists" currently - how can this be if risk culture is "...an element that influences and is influence by various forces"?
  • Tha an organisation's corporate culture and risk culture "must be linked" - how are they not one and the same thing?
  • That Risk Appetite Statements are "effectively part of the business strategy" - as opposed to "actually"?
  • Use of the term Risk Profile as if it is unquantifiable, specifically that a firms who learn from their mistakes rather than chastise those who make them "tend to have a better risk profile". Not clever.

Thursday, 4 June 2015

Solvency II Updates and Corporate Governance in Financials - PRA "Back for Good"?

A few releases of note out of the UK regulator over the last working week or so means I had some catching up to do - sometimes it feels like "All I do each night is PRA"...

They started off with a Director's Letter just before the bank holiday weekend. A general unwillingness to crack whips was present throughout this doc, even at this late stage, with a few references to "inform your supervisor" as opposed to "just do it".

The letter states that the PRA were due to publish some of their findings from their balance sheet review work by the end of the month - not done as yet, hopefully turns out to be money well spent

Regarding Standard Formula appropriateness:
  • They stress that firms must identify deviations from Standard Formula from their risk profiles, and include an assessment of the significance of that deviation in their ORSAs (emphasised in their October industry presentation from p6)- is the implication here that firms are not doing this at all at the moment, or just not reporting it in ORSA?
  • Highlight that "supplementary information" used to explain such deviations will also be assessed by the PRA. Does this add significance to one's qualitative commentary around Standard Formula/Risk Profile deviations? Can a good explanation be the difference between having to IM/PIM at the earliest opportunity against being given a couple of years of capital add-on breathing room?
  • The PRA note that, "...where a firm's conclusion on this question is not appropriate", it will intervene. It is not clear how a firm's conclusions about its deviation between SF and its Risk Profile could be considered "not appropriate", but I imagine that anything which attempts to dodge USPs/PIM/IM ONCE the divergence hits the limits in the Delegated Acts (276-287) would be frowned upon. There is certainly no appetite at the PRA for renewing capital add-ons in perpetuity (slide 13), which given the UK's familiarity with ICA and ICG, might be a desperado's first chance saloon.
  • The PRA are planning "specific interventions" on this front (detailed here), but not necessarily in time to correct before 2016.
Regarding Internal Models
  • Not happy with "wide variation in quality of IM Change policies. Sounds like firms are doing their best to avoid change criteria that results in frequent submissions for reapproval, which one would expect!
  • IMAP Submissions
    - Everything Changes
  • PRA seemingly expecting firms to have not only taken on board their feedback, but also had their IMs revalidated, before submitting their IM application. Given that validation will be chalked down as a 'once-a-year' job at the moment (despite the IRM's efforts), that seems highly unlikely. They give themselves a get-out-of-jail-free card though by stating that firms must be confident that any changes in their IMs both address PRA feedback and meet the tests and standards for model approval.
  • They appear to advise against submitting applications if you have a material change in the pipeline.
  • Heavily critical of Board involvement in validation. Here they look for evidence of Boards "overseeing and influencing" the validation process, whereas previous PRA presentation slides  did not have such expectations of Boards (slide 8 here), or indeed expected more (slide 9 here)!
  • The expression "internal management loadings" appeared in my life for the first time, which sounds to a non-technical person like myself that firms are effectively "dumbing-up" the capital requirement currently delivered by their IM in order to plaster over mathematical or data weaknesses. PRA certainly not impressed by industry suggestions to date.
  • Given the number of firms who must have dropped out of looking for Day 1 approval, they still shake the pineapple tree here in order to remind applicants that contingency plans should be ready in the case of application failures. "Many firms still have a considerable amount of work to do" sounds to me like some applicants are being pre-warned of their imminent failure!

The PRA also released a consultation paper entitled Corporate Governance: Board Responsibilities, which has the rather light ambition of identifying "key aspects of good board governance to which the PRA attaches particular importance in the conduct of its supervision".

A few straggler items in it;

  • That failures in governance and/or risk management have been a key factor in "many" financial sector failures - as opposed to "all"
  • That they consider the FRC's Corporate Governance Code, amongst others, a "comprehensive guide to good corporate governance" - given the firms experiencing the financial sector failures were most probably complying with it, not a great advert!
  • "Culture is the collective responsibility of the Board" - a bit of a nowhere comment, but instinctively, I don't see how this can be right. They can be accountable to both supervisors and shareholders/members for cultural failings, but where could such a responsibility materialise into demonstrable actions? 
  • "...the Board is responsible for the oversight of, but not for managing the business" - in relation to my comment directly above, can both statement be correct?
  • "The Risk Control Framework should flow from the Board's Risk Appetite" - I'll work on the premise that this is missing the word "statement" at the end of the line
  • Section 11 on remuneration expects that incentives are aligned with "prudent risk taking" - what if prudence is too conservative for one's risk appetite?
Into some of the expected themes;
  • Strategy to be "owned by the Board as a whole"
  • They wed Culture and Remuneration "...to encourage and enforce the kind of behaviours the Board wished to see"
  • They want a "well articulated and measurable" Risk Appetite Statement which can also be "...readily understood by employees throughout the business". Doesn't seem feasible, given the metrics commonly used in risk appetite statements are not exactly Finance 101 (Solvency/Liquidity/Earnings-related),
  • "It is the responsibility of the Board to ensure that the effectiveness of the Risk Control framework is kept actively under review" - has at least an air of COSO about it, don't think it was deliberate
  • Big section (6) on responsibilities and accountabilities of exec and non-exec directors.
  • Followed in 7.1 with "...non-executives should not simply delegate responsibility for major decisions to individuals among them who are considered specialist in the area" - this has internal models written all over it (p5-6)!
Happy to see this second document, though I don't know what it adds to firms' understanding about what is "good and bad".




Tuesday, 2 June 2015

PWC's Risks in Review - White Paper, Black Sabbath...

A quick dive into the wider world of ERM, courtesy of one of our Big 4 friends, ambiguously titled Risks in Review.  PwC's document (short sign-up required) is US-centric and multi-industry, so for the Solvency II crowd you might need to sift for the goodies (a good illustration of which side of the Atlantic it leans towards is that CFO.com reported on its highlights), but for anyone in the ERM space, there should be something for you here.

A bizarre stat is laid out at the beginning in that 73% of the 1,200+ senior executive[s] and Board members respondents to the survey agreed that "risks to their companies are increasing". Whether this be in reference to the number of risks faced, increases in the likelihood/severity of one's existing risk universe, or their perceptions on emerging risks, it certainly suggests that exogenous and endogenous concerns have not abated in the minds of corporate leaders. However, given the risk immaturity within firms that the rest of the document serves to highlight, the lack of definition is rather unhelpful.

Appetite - For Risk or Bats?
As the survey covers multiple industries, it has the more generic risk classifications in mind (i.e all major quantitative risk balled up into "Financial Risk"), which will no doubt gnaw at anyone on the financial services side, but at the same time, it's not all about you!

The pat on the back for those surveyed is the sobriquet of "true risk management leaders", handed out to 12% of respondents. It frankly doesn't feel like a valid aspiration for an entity, more that being a "risk management leader" would be an implicit part of the make up of any firm which successfully delivers on its strategic objectives.

That aside, the Leaders (of which financial services companies "...represent a sizeable portion" of!) are congratulated for;
  • Aligning RM Programs with their businesses.
  • Communicating Risk Appetite and Risk Tolerance through the business - nothing on hard risk limits in the paper though
  • Being "able to take greater business risks" - I don't necessarily make the link between being "good" at risk management equating to taking greater risks, unless that is part of the business strategy one has aligned the RM Program with.
  • Take aggregated views of risk over multiple areas
  • Using techniques such as emerging risk identification/forecasting, scenario planning and stress testing
Laggards on the other hand
  • Have no formal Risk Appetite Framework (only 38% of respondents do)
  • Don't integrate Risk Management Strategy with business strategy (only 31% do)
They also hook the leadership qualities of risk management to some quantitative "value of good risk management" work on p5 (a topic which Towers Watson recently tiptoed around due to a lack of quant), namely that their profit margins and margin growth will outstrip peers. The growth of profit margins might be a bum steer, as the macroeconomic environment is perhaps less kind to industries other than financial services, who of course would have seen margins peak comparably faster over recent years due to the size of the trough in 2006/08!

As ever, the lexicon used in papers such as this takes a dip in the lake of dubiosity, for example:
  • That companies should "...treat risk management strategically" - as opposed to what, "operationally"? This kind of expression suggests that risk is not already considered in strategy, which feels unfair and unrealistic, even on the immature firms surveyed. That there isn't a functional ERM Framework to enhance that work does not mean it isn't done at all.
  • Risk Appetite Framework should have "buy-in" from senior management and the Board. Why "buy-in"? They should be deeply involved in the construction of an RAF, and their successes or failures as management should be inextricably linked to operating in line with it, not asked to nod in approval at the next Board/EXCO
  • "Having a clearly defined risk appetite framework allows companies to quickly assess strategic decisions in the context of risk" - that of course was not a given...
  • They also follow the tactic used in the Towers Watson paper in referring to risk management "programs" as opposed to "systems" or "frameworks- again, I'm not trying to labour the sematics of it, but a Programme for me has an end, and the work of a risk management function simply does not. This is perhaps just a psychological angle being worked here to drill into prospective clients that Programs can be boosted with a burst of external advice, but I find it increasingly disagreeable, particularly given the risk management leadership traits highlighted in this document, which most certainly do not lend themselves to the workings of a transient Programme.
Other stand out points would include
  • Alignment of RM Programmes against each business function (p9) - horrible result for Sales & Marketing, even for Leaders, and suggests it is an area for us all to redouble our efforts
  • Similar to Towers, talk of firms "drowning in data" - cannot fathom this for the life of me, but perhaps that's because I can use pivot tables and SQL server!
  • GE Capital's approach to administering Risk Appetite (p16) - very clean, and in a manner which the CRO Forum would appreciate.
  • Finally, a really nice section on p19 which shows the discrepancies between executives and risk professionals regarding their own firms' prospects. The Fannie Mae CRO suggests that Risk Management staff are "paraniods by profession" which given his employer's recent history, doesn't mean people aren't out for you!

Tuesday, 19 May 2015

Towers Watson's Global ERM Survey - Knowing ERM, Knowing You...

A couple of treats from two of the powerhouses of the 'writing things down' industry on the practical use of ERM to drive decision making, rather than simply accompany it.

Towers Watson are targeting the Solvency II audience (at least on this side of the Atlantic) with a timely release of the results of their 8th Biennial Global ERM Survey. I say the results, as there is no sign of the full survey itself - any closer to their chest, it would be an areola's backpack...

As ever, these kinds of publications oscillate between flannel and insight, so while I cover those below, feel free to read the infographic and call it quits!

General observations from the main press release include;
  • Three-quarters of (the almost 400) respondents say they are viewed as "important strategic partners" by the Board and Executive - I'm less inclined to see that as a mark of superiority, given that risk functions in some firms won't have the ambition or aptitude to achieve that status
  • Implication that some respondents do not have a risk appetite framework in place - very worrying, unless this is just bad wording.
  • Some firms said to be only "...using ERM for regulatory compliance". It may depend on jurisdiction, but I'm not inclined to agree that is even possible.
  • The "ultimate vision" for a firm's ERM capabilities is referred to, which is a brow furrer, even conceptually. TW seem to bundle up risk culture, risk monitoring and risk tolerance into the "Vision" bucket, in case that term takes your fancy.
  • The expression "very strategic approach" appears in print for the first time!
Getting Value from ERM?
- "Kiss my Face"
From the more elaborate Q&A document, we find the main granular material which TW were prepared to publish. Fortunately for readers this side of the Atlantic, the EMEA Director Mike Wilkinson holds sway over much of that conversation, including his tale of the firm who recently had an ERM/Business Strategy-inspired "Aha" moment.

That session contains a fair bit of contention, such as;
  • Asking the questions "What's the purpose of risk management" or indeed the "purpose of your ERM Program" in the Q&A - if these had been directed to the respondents themselves, it would have contextualised a number of the seemingly negative responses i.e. If the purpose of your ERM Program is "don't get shut down", you are probably less bothered about being a "strategic partner"!
  • That the business should "...challenge the risk group to create reports that help them make decisions" - Excel Jockey is hardly the work of a strategic partner...
  • In a similar vein, that insurers are "drowning in data, drowning in metrics" - hardly a new phenomenon, and doesn't give any credit to the critical faculties of employees to filter what they do have.
  • "...many [internal capital] models have matured" - a sharp intake of breath can be heard down at Moorgate!
  • That "...an ERM Program can't properly be assessed until it has been in place for a while" - pretty sure the S&P crowd wouldn't hold off assessing you while you "embed"
Mike in particular does manage to keep a good focus throughout the Q&A on maximising trade-offs between risk and return being the big differentiator between Risk functions who are capable of influencing strategic decision making, and those who are perhaps more likely to be tabling red-amber-green reports tracking the outcomes of decisions which have already been made.

Other strong points include;
  • In the context of Risk Tolerance, how to cater for the discretion required by an insurer's asset managers in handling investment portfolios.
  • Touches on a couple of pieces which stood out in the CRO Forum's Risk Appetite publication last month, namely around the increasing number of measures being used to run businesses other than capital, allowance of movement within risk tolerance levels, and whether firms have effectively articulated their organisation-wide Risk Appetite and Risk Tolerance limits down into its subsidiaries/departments.
One aspect which gnawed at me throughout this reading is the constant referrals to "ERM Programs" - I don't think I am bathing in semantics to suggest that Programs normally start and end, whilst ERM would surely constitute a Framework. You might choose to redecorate the Framework periodically with a Program (Solvency II a prime example), but you wouldn't expect a Program to "mature" or "evolve", you expect it to conclude!

Nitpicking?




Thursday, 30 April 2015

Love RAFs? CRO Forum's Risk Appetite survey

The CRO Forum have recently published the results of their 2014 survey on Risk Appetite development in insurance entities. It is perhaps the oldest drum in Risk Management Town, but one we are always happy to hear the beat of, and while we shouldn't expect a forum with such luminary members to deliver any shocking results, a careful sift through the carcass is always a smart idea.
The Cure - to tolerance breaches?
The final presenter at the PRA's recent NED briefing noted that Risk Appetite is "no longer an aspiration", a comment I felt was further behind the times than Nana wearing Juicy Couture. That said, on page 8 it suggests that less than a quarter of firms are "very satisfied" with their RAF maturity, and over a third feel they have "a lot of work to do", so perhaps he hit the nail half on the head...

This document should clarify whether that caution is justified, and with 48 responses from the top table, it should be a reliable benchmarking tool. Despite starting like a GCSE essay ("the topic of Risk Appetite has exploded"?), it contains some useful, if a little dry, benchmarks, such as;
  • Principles for a RAF (p3-4) - hard to argue with
  • Main goals - dominated by preserving capital, while only a third are looking to "improve shareholder value" or "optimise capital"
  • Main stakeholder list (p5) seems good in breadth and priority
  • Almost everyone is using regulatory capital in some way as a Risk Tolerance measure (p9)
  • Stress and Scenario testing is being used by 80% to set Risk Tolerance levels, which feels at the right end of expectations
  • 60% report quarterly, with most others slightly more or less frequent
It takes a few odd turns, in particular;
  • One of the main objectives cited (p4) seem to be centre around boiling down things into a single document. I appreciate that pressure, but surely we feel that a RAF has a more substantial objective that document consolidation?
  • "Development of a Risk Appetite Statement is an evolution" (p6) - don't agree at all, it is a task, otherwise it would never get done.
  • Coverage of Risk Appetite Statements as "regulatory requirements", in particular under Solvency II. Just because the industry is choosing to discharge its obligations in EIOPA's Guidelines (SoG 15 & 16) by producing a single statement document, it doesn't make a Risk Appetite Statement a requirement.
  • Less than half are using a "1-in-x" loss that would breach regulatory capital in their Risk Tolerances - just feels like a very obvious one to use, so suprised by that number
Some of the more practical issues faced by firms are well covered, for example;
  • Difficulties for Groups when setting risk appetite. Does the parent/head-office set overall appetite, and the children sub-divide it by business unit/risk category/Both? Do the children set their own appetites and feed them up for aggregation?
  • Listing Risk Concentration targets looks awkward across the board (p5). While firms seem to be able to quantify Liquidity and Capital targets in their Risk Appetite Statements, other categories are much less consistently quantified. Market, Credit and Insurance Risk appear to be quantified by less than a third of respondents, preferring to address these in separate policies/guidelines (a Solvency II by-product perhaps?).
  • Setting Risk Tolerance levels is highlighted as a "minor" improvement required by over 60% of respondents.
  • There is a veritable bombsite of Earnings at Risk metrics in use, which is healthy for the industry I guess (p10).
  • What does one do when Risk Tolerance level is breached? Around a third are not OK with limit breaches and demand immediate rectification, while two thirds allow for a "Cure Period" to return the Risk Profile to its required form. A "Cure Period" seems the fairest breach rectification approach to me - after all, I don't care if Monday's blue...
A worthy benchmarking document, so fill those boots.

Monday, 18 August 2014

ORSA - Institute of Risk Management special interest group

Of course while I spent the last couple of months topping up my tan in, errrrr, the Isle of Man, some of the guys in the UK and further afield have been building up an endeavour-flavoured sweat on some of the more malleable elements of Solvency II preparation.

Raining 'Mann' - Glorious Manx summer
The IRM as ever have kept the ball rolling, in particular hosting an ORSA session last month. While you can pick your way through the guest speaker presentations for ideas and comfort (one company specific, one consultant generic, and one which S&ST/RST fans might like as a sense check), I was much more interested in the attendee survey.

A whopping 34 replies came in, via which the attendees have delivered a reasonable ORSA landscape mock-up, which may help some of you get matters shuffled in your priority lists, given where your peers claim to be.

I noted in particular;
  • ORSA Process overwhelmingly run by the Risk functions (over 90%)
  • Just over half going for annual frequency, the rest (who responded) naturally more frequent - doesn't instinctively feel representative, but not all of the smaller firms would send someone down to this!
  • Around two-thirds have their "Reports" at 50 pages or less - if we assume that by "report" we mean Supervisory as well as Internal, the PRA won't be too chuffed with that given their comments at the December industry seminar.
  • Only a third have submitted draft ORSA Reports to the PRA and received feedback
  • Coverage of emerging risk appears to be an area which not only do respondees think is lacking, but has received critical feedback from the PRA
That half have used external consultants in their ORSA work to-date is certainly no surprise. I'd be worried if that consultancy had more than a year's dust on it though, so think hard before you start submitting your 2014 gear!

Wednesday, 19 March 2014

Myners briefing on Governance at the Co-op - working class barred from the Board?

Wolf - step away from the door...
A corporate governance story that will echo in the eternity of MBA classes for years to come, the unravelling of the UK's Co-operative Group from the benign grocer-cum-divvy machine into a ying and yang shotgun conglomerate of opposites is proving to be a watershed moment for UK plc, with stakeholders attempting to balance myriad legal, political and ideological considerations in order to both keep the wolf from the door, and preserve the principle of mutuality for its membership.

There are no surprises that the crux of the Group's issues lies in its banking arm, nor that being acquisitive during the financial crisis (here, here and here) has proven to be poor strategy. Keeping the wolf from the door has therefore largely been delivered through the tried and tested combination of begging and borrowing, which the recently departed CEO appears to have delivered with some aplomb.

Governance structures
- choices choices...
However, the Group's hiring of Paul Myners back in December, a man with an extensive collection of t-shirts and hats, to independently review its governance arrangements, seems likely to deliver to the membership a menu of choices as unpalatable as a Sunday skip-dip.

Lord Myners has hurriedly delivered a briefing on his findings to-date, as well as performed some mainstream media duties (here and here), following the Group CEO's resignation last week. This early sighter was seemingly unscheduled, but the manner of the CEO's departure ("a tragedy" in Myners' words) meant that his findings to-date could not wait until May for its full publication date.

Myners has therefore naturally delivered a ruthless and scathing take-down of the governance structure and processes within the Co-operative, while calling out the Board member who are clearly well schooled in how to game the system, as well as the playground tactics/rabbit-in-a-hat tricks that turn "one-man-one-vote" into "one hundred men-all votes"!

Killer quotes
  • The group endures a significant "democratic deficit"
  • The future of my recommendations lies in the hands of around 100 elected individuals on the current Group and Regional boards, few of whom have any serious business experience and many of whom are drawing material financial benefits from their positions
  • There is a phrase frequently used in Co-operative Group circles that the Executive should be "on tap but not on top"
  • ...the Group Board has spent far too much time on transactions such as Somerfield and Britannia which have been breathtakingly value-destructive
Observations
  • The "exceptional skill and tireless efforts" of the Executive team are cited as the reason for the Group's survival in its current form
  • The current governance framework is variously referred to as "flawed", suffering from "acute systemic weaknesses" and having "consistently produced governors without the necessary qualifications and experience to provide effective Board leadership". Ouch...
  • That the Groups social goals are not aligned with its strategic and commercial objectives. This is of course less of a worry for its financial services competitors.
  • The the Group's "massive scale and complexity" means that a man-off-the-street approach to electing Board members, which may be sufficient for a farmer/grocer co-op, is not suitable.
  • Shatters the "myth" that the Group has always been run by lay members, as opposed to those with commercial experience.
  • The thought of creating a board of INEDs and lay members is disregarded due to the potential for creating "second-class citizenship"
  • Highlights that Co-op's core business of groceries is savagely competitive at the moment (just look at Morrison's and Sainsbury's), so continued ineffective governance could be devastating
  • Notes that there have been previously (disregarded) reviews of its governance architecture, which is "long known for its labyrinthine complexity and its disfunctionality"
  • Stresses that, due to the current voting structure, acceptance of  his recommendations "...potentially lie[s] in the hands of fewer than 50 elected members". It sounds like they haven't been shy to remind him of that either!
Recommendations
  • Halve the size of the Group Board, which will be subject to annual re-election
  • Independent Chair, with no previous association with Co-op
  • 6-7 INEDs and 2 Executive Directors
  • All with qualifications of a similar ilk to its (listed) competitors
  • Create a National Membership Council (NMC), with a 12-person executive committee to effectively represent the membership and co-operative principles and values
  • The Board to be subject to scrutiny by the NMC, who have the right to be consulted on "key strategic and operational intiatives"
  • "Arrangements" to be made to safeguard the confidentiality of information shared between the Board and the NMC (certainly not the case with current arrangements!)
The entire document feels drenched in class warfare and spectrum politics. That rather hideous take from the existing Board on their executive team ("on tap, but not on top") feels like the inspiration of Myners' recommendation for a professionalised, appointed Board, rather than the beer and sandwich brigade which currently exists.

That said, there is thought on the left-wing (here and here) who feel that mutuality and co-operation should remain unsullied by the commercial world, who remain unable to affect much in the way of democratic change in Boardrooms even after the raft of FRC-sponsored guidance released over the last couple of years (though PIRC are trying!). Is one failed attempt to democratise stakeholders best replaced by cherry-picking from a similarly deficient model?

On the basis that I have banged the drum for background diversity in Boardrooms (not just gender or race), and the existing Co-op Board is "diverse" in that respect, I'm left to wonder if I've been barking up the wrong tree. The Board delivered by their existing process is neither fit nor proper, and are able to outmanouevre their executive compatriots armed with little more than a working knowledge of provincial politics and a polyester suit.

Should we therefore use the grey-area of "fit and proper" regulation to ban the contract plasterers, nurses and retired publishers of the world from financial service provider Boardrooms on the basis that they don't have an MBA, and count with their fingers? Or can one make a valid contribution to a financial services Board of directors regardless of the colour of their collar?

Tuesday, 18 March 2014

PRA on General Insurer Technical Provisions under Solvency II - Taking the "TPs"?

Allow me to take a quantum leap outside of my comfort zone while I pick my way through the PRA's latest Insurance Industry aide memoire, via a consultation paper on the calculation of technical provisions in General Insurers.

This looks specifically at TP calculations with Solvency II in mind, and is aimed specifically at GI firms currently in IMAP. That said, the tone and technical matter covered is an excellent heads-up to Actuarial, Risk and model validation personnel currently active in this space about how the PRA approach to assessing Solvency II compliance is developing.

The document itself reads very much like their last consultation paper release on Deferred Tax Assets, insofar as it is a laundry list of "what not to do" - look at how many times the expression "should not" appears! They have leaned on their findings from both thematic reviews of TP calculations (Life and GI-specific Questionnaires were sent out a year ago) as well as from IMAP and ICAS, so their finding will be well supported by most recent practices in the UK.

The consultation window is pretty short as well, with a mid-April shut-down scheduled, so if you don't like the cut of their jib, you'd better speak soon.

Stand-out points for me included;

Generic

ENID - TP accommodation required
  • Expectations of Delegated Acts content are cited throughout, but in terms of the exact date of their public provision, they can only go with "Q3 2014". From what I have seen, there is nothing cited which isn't in the November 2011 draft.
  • The abandonment of the term "binary events", replacing it with "Events not in data" or "ENID" - the fait accompli of "binary" (that events which are not in a data set must therefore be extreme and/or rare) is confirmed as unacceptable.  The PRA don't appear to be wedded to the old term in any case, and while the actuarial profession used it liberally in the past (here and here for example), they began a transition away from it late last year (p45 of this).
  • "Any data that can have an impact on the outputs of the internal model should be considered to be 'used for the internal model'" (3.19) - important IMAP message across sectors I think!
  • There is evidently some concern that firms are thinking of relying on the work of external model providers to meet Solvency II standards, with the PRA confirming that firms may not rely on "...generic validation performed by the model vendor" (3.25). This means that the model validation relationship between IMAP candidates and their third-party providers needs to be much more invasive and aggressive, and needs to start pretty soon!
Technical Provision-Specific
  • A large number of points made in the paper relate to over-simplifications, which should help anyone who is struggling with the concepts of materiality and proportionality. These include methods relating to ENID, Risk Margin calculations, Approximations and  the emergence of risk over one year
  • Similarly a few tricks of the trade appear to have been scuppered, such as using optimistic business plans for setting provisions, "actuary in a box" methods and assuming improved underwriting performance
  • Some substantial focus around the quality and quantity of challenge applied to External Models (focused on third party Catastrophe models in this instance), in particular the challenge of  assumptions used by the provider (3.16-17 and 3.26-28)
  • The concept of "cumulative materiality" is introduced in the context of multiple approximations, a concept which I suspect many firms are still struggling with in the context of Internal Model change (2.9)
  • An interesting take on the justification of assumptions, with the PRA taking umbridge with firms using "industry standard" or "established good practice" as a supporting argument, rather than using their own risk profile as the basis for support (3.15)
  • A section which seems to advocate conservatism, if not prudency, in the setting of sensitive parameters (3.10), as well as advocating the use of stress and scenario testing to make up for ENID when setting parameters (3.2)
Certainly lessons for both Life and GI internal model applicants in here, and the PRA should be congratulated for getting this paper out in good time. I'm not necessarily convinced though that third-party providers of internal model inputs will happily acquiesce with the demands which the industry are being asked to make of them here.