Showing posts with label best practice. Show all posts
Showing posts with label best practice. Show all posts

Wednesday, 12 August 2015

Insurance Banana Skins in 2015 - PwC and CSFI

PwC and the CSFI guys have teamed up for another Insurance Banana Skins publication, a particularly useful doc for the BAU Risk world, and one which I have covered on the blog in years gone by (well, 2011's and 2013's anyway).

In particular, I always found it useful as a means of digging out the kinds of awkward cross-bred expressions which would invariably end up rolling out of 75-year-old INEDs’ mouths at the next Risk Committee meeting, probably due to someone trying to sell insurance cover for it, or a business journal doing a centre spread about it. On this basis, I was delighted to see “Cyber Risk” given prominence this time around, which is the highest new entry, and apparently a “new risk” - here’s the sales forum, and here’s the HBR white paper!

Sarcasm aside, given this pulled in over 800 responses from around the globe, and across the distribution and provision side of the industry, the content is worth poring over and briefing colleagues on if this is your day job. There are also plenty of quotes from the great and good wrapped up inside as well.

I’ve only jumped on a few of the findings below;
  • Regulation remains the top risk for the 3rd survey running, and for the 4th out of the 5 actually held. It did take a ‘world’s end’ scenario for investment returns to knock it off the top in 2009 though, which suggests that those surveyed are happy to bleat about regulatory concerns, regardless of the rest of the exogenous threats to insurance firms.
  • Much of the top ten is focused on investments and returns, whether it be interest ratesinvestment performance or guarantees.
  • Governance and management of insurance companies seen as an area of declining risk – does it therefore warrant the Banking industry-inspired whip that SIMR is about to introduce in the UK?
  • Similarly, Business Practices, incorporating misselling, is falling down the list – not sure a UK-only survey would be so generous!
  • Cyber Risk itself was only #6 on the list for Life Companies, while #1 for Non-Life – wonder why the guys who are selling cover rate it so highly? Of more interest, North America had it as #1 “by some margin” – this suggests the wave will be coming across the Atlantic in the next 12 months (a nice precursor of how that will emerge here)! It is written up nicely however, with cloud storage, and the richness of data held on customers, being elements which make insurers prime targets. It doesn’t dwell on the proliferation of legacy systems in insurers however, which always felt to me a good reason for criminals to ‘have a crack’.
  • Europe considered the interest rate environment, regulation and guarantees to be the top 3 banana skins, which given the aggressive tailoring applied to Solvency II in the drafting stages to negate country-specific difficulties in these areas (MA/VA/Transitionals), is no surprise.
Oh, to have a day job again…

Wednesday, 24 June 2015

CRO Forum on Risk Culture - comin' from the body heat?

Risk Culture
- need another hero?
A subject which is gathering more steam than Tina Turner's windows, Risk Culture has been given the kid gloves treatment by the CRO Forum in their paper, Sound Risk Culture in the Insurance Industry.

They say at the start that the topic has become "prominent in regulatory circles", which given EIOPA appear to be wining and dining the subject (here and here in the last couple of weeks alone), is something of an understatement. Their increased interest has no doubt been fuelled by the FSB's work on the subject from a year ago. In addition, the Financial Reporting Council took a shine to the topic in its last update of guidelines in late 2014 (point 27 in particular), while cultural failings have turned the FCA into a modern day Robin Hood (speech from inception time here).

As well as fiddling around the edges of definition, the paper expands on a few examples of where cultural change can be driven from, stealing from a few other industries (aviation in particular) and a couple of insurers (Zurich receiving particular attention).

They fundamental base they work from is pretty fair:
  • No "good" or "bad" culture, hence they talk about practices that encourage a "sound" risk culture throughout. Given that ropey culture does not necessarily prevent the achievement of strategic goals, this smart.
  • No "one-size-fits-all" concept of Risk Culture (i.e. don't look for one in this paper!)
That said, the definition used for the purposes of the paper from the NN Group CRO is actually a pretty good one - "shared philosophy of managing uncertainty" etc - though it does suggest that a failure in risk culture might simply be someone not sharing the philosophy, which I suspect is where a lot of your more pragmatic colleagues sit!

There are a number of sound inclusions throughout;
  • Emphasising the links between risk culture and conduct risk currently being force-fed to the industry by EIOPA (p3)
  • The chart on p6 showing survey results of essential elements of risk culture - senior management and Boards leading by example is evidently seen as more important than risk-based remuneration, despite the legislative attention the latter receives (including this week in the UK).
  • Zurich's internal 10 question survey on culture assessment - contains the gorgeous expression "organisational humility", as well as bringing some of the granular risk culture elements onto the table, such as treatment of whistleblowers.
  • Highlighting the "common phenomenon" of management teams containing people with the same personal attitudes - could benefit the creation of a "shared philosophy" without necessarily any of the benefits.
  • The illustration of NN Group's "Risk Culture Dashboard" (p11) - I don't have preference for it either way, but it does illustrate how much effort one can direct towards risk cultural identification, assessment and monitoring, which begs the question "is there that much value in it?" They seem to like it as a way of covenying the concept in the business in any case.
  • Pages 13-14 provide some good brain candy for those who have ambitions to educate or brief their colleagues on risk cultural matters. Zurich's "we are all risk managers" campaign looks like it probably has legs (more on it here).
There are a couple of mildly objectionable parts within;
  • Concepts of "Risk Vision" and "holistic" dropped in early doors and littered throughout, as well as a few extras such as "risk perspective" - the kind of obtuse terminologies which serve to divorce Risk functions from their colleagues
  • That firms should have a "clear vision" for their risk culture - why would something as opaque as culture be expected to be "clear". They don't even define it as a term in the paper!
  • Concerned that risk culture is "...only practiced by risk specialists" currently - how can this be if risk culture is "...an element that influences and is influence by various forces"?
  • Tha an organisation's corporate culture and risk culture "must be linked" - how are they not one and the same thing?
  • That Risk Appetite Statements are "effectively part of the business strategy" - as opposed to "actually"?
  • Use of the term Risk Profile as if it is unquantifiable, specifically that a firms who learn from their mistakes rather than chastise those who make them "tend to have a better risk profile". Not clever.

Thursday, 4 June 2015

Solvency II Updates and Corporate Governance in Financials - PRA "Back for Good"?

A few releases of note out of the UK regulator over the last working week or so means I had some catching up to do - sometimes it feels like "All I do each night is PRA"...

They started off with a Director's Letter just before the bank holiday weekend. A general unwillingness to crack whips was present throughout this doc, even at this late stage, with a few references to "inform your supervisor" as opposed to "just do it".

The letter states that the PRA were due to publish some of their findings from their balance sheet review work by the end of the month - not done as yet, hopefully turns out to be money well spent

Regarding Standard Formula appropriateness:
  • They stress that firms must identify deviations from Standard Formula from their risk profiles, and include an assessment of the significance of that deviation in their ORSAs (emphasised in their October industry presentation from p6)- is the implication here that firms are not doing this at all at the moment, or just not reporting it in ORSA?
  • Highlight that "supplementary information" used to explain such deviations will also be assessed by the PRA. Does this add significance to one's qualitative commentary around Standard Formula/Risk Profile deviations? Can a good explanation be the difference between having to IM/PIM at the earliest opportunity against being given a couple of years of capital add-on breathing room?
  • The PRA note that, "...where a firm's conclusion on this question is not appropriate", it will intervene. It is not clear how a firm's conclusions about its deviation between SF and its Risk Profile could be considered "not appropriate", but I imagine that anything which attempts to dodge USPs/PIM/IM ONCE the divergence hits the limits in the Delegated Acts (276-287) would be frowned upon. There is certainly no appetite at the PRA for renewing capital add-ons in perpetuity (slide 13), which given the UK's familiarity with ICA and ICG, might be a desperado's first chance saloon.
  • The PRA are planning "specific interventions" on this front (detailed here), but not necessarily in time to correct before 2016.
Regarding Internal Models
  • Not happy with "wide variation in quality of IM Change policies. Sounds like firms are doing their best to avoid change criteria that results in frequent submissions for reapproval, which one would expect!
  • IMAP Submissions
    - Everything Changes
  • PRA seemingly expecting firms to have not only taken on board their feedback, but also had their IMs revalidated, before submitting their IM application. Given that validation will be chalked down as a 'once-a-year' job at the moment (despite the IRM's efforts), that seems highly unlikely. They give themselves a get-out-of-jail-free card though by stating that firms must be confident that any changes in their IMs both address PRA feedback and meet the tests and standards for model approval.
  • They appear to advise against submitting applications if you have a material change in the pipeline.
  • Heavily critical of Board involvement in validation. Here they look for evidence of Boards "overseeing and influencing" the validation process, whereas previous PRA presentation slides  did not have such expectations of Boards (slide 8 here), or indeed expected more (slide 9 here)!
  • The expression "internal management loadings" appeared in my life for the first time, which sounds to a non-technical person like myself that firms are effectively "dumbing-up" the capital requirement currently delivered by their IM in order to plaster over mathematical or data weaknesses. PRA certainly not impressed by industry suggestions to date.
  • Given the number of firms who must have dropped out of looking for Day 1 approval, they still shake the pineapple tree here in order to remind applicants that contingency plans should be ready in the case of application failures. "Many firms still have a considerable amount of work to do" sounds to me like some applicants are being pre-warned of their imminent failure!

The PRA also released a consultation paper entitled Corporate Governance: Board Responsibilities, which has the rather light ambition of identifying "key aspects of good board governance to which the PRA attaches particular importance in the conduct of its supervision".

A few straggler items in it;

  • That failures in governance and/or risk management have been a key factor in "many" financial sector failures - as opposed to "all"
  • That they consider the FRC's Corporate Governance Code, amongst others, a "comprehensive guide to good corporate governance" - given the firms experiencing the financial sector failures were most probably complying with it, not a great advert!
  • "Culture is the collective responsibility of the Board" - a bit of a nowhere comment, but instinctively, I don't see how this can be right. They can be accountable to both supervisors and shareholders/members for cultural failings, but where could such a responsibility materialise into demonstrable actions? 
  • "...the Board is responsible for the oversight of, but not for managing the business" - in relation to my comment directly above, can both statement be correct?
  • "The Risk Control Framework should flow from the Board's Risk Appetite" - I'll work on the premise that this is missing the word "statement" at the end of the line
  • Section 11 on remuneration expects that incentives are aligned with "prudent risk taking" - what if prudence is too conservative for one's risk appetite?
Into some of the expected themes;
  • Strategy to be "owned by the Board as a whole"
  • They wed Culture and Remuneration "...to encourage and enforce the kind of behaviours the Board wished to see"
  • They want a "well articulated and measurable" Risk Appetite Statement which can also be "...readily understood by employees throughout the business". Doesn't seem feasible, given the metrics commonly used in risk appetite statements are not exactly Finance 101 (Solvency/Liquidity/Earnings-related),
  • "It is the responsibility of the Board to ensure that the effectiveness of the Risk Control framework is kept actively under review" - has at least an air of COSO about it, don't think it was deliberate
  • Big section (6) on responsibilities and accountabilities of exec and non-exec directors.
  • Followed in 7.1 with "...non-executives should not simply delegate responsibility for major decisions to individuals among them who are considered specialist in the area" - this has internal models written all over it (p5-6)!
Happy to see this second document, though I don't know what it adds to firms' understanding about what is "good and bad".




Tuesday, 2 June 2015

PWC's Risks in Review - White Paper, Black Sabbath...

A quick dive into the wider world of ERM, courtesy of one of our Big 4 friends, ambiguously titled Risks in Review.  PwC's document (short sign-up required) is US-centric and multi-industry, so for the Solvency II crowd you might need to sift for the goodies (a good illustration of which side of the Atlantic it leans towards is that CFO.com reported on its highlights), but for anyone in the ERM space, there should be something for you here.

A bizarre stat is laid out at the beginning in that 73% of the 1,200+ senior executive[s] and Board members respondents to the survey agreed that "risks to their companies are increasing". Whether this be in reference to the number of risks faced, increases in the likelihood/severity of one's existing risk universe, or their perceptions on emerging risks, it certainly suggests that exogenous and endogenous concerns have not abated in the minds of corporate leaders. However, given the risk immaturity within firms that the rest of the document serves to highlight, the lack of definition is rather unhelpful.

Appetite - For Risk or Bats?
As the survey covers multiple industries, it has the more generic risk classifications in mind (i.e all major quantitative risk balled up into "Financial Risk"), which will no doubt gnaw at anyone on the financial services side, but at the same time, it's not all about you!

The pat on the back for those surveyed is the sobriquet of "true risk management leaders", handed out to 12% of respondents. It frankly doesn't feel like a valid aspiration for an entity, more that being a "risk management leader" would be an implicit part of the make up of any firm which successfully delivers on its strategic objectives.

That aside, the Leaders (of which financial services companies "...represent a sizeable portion" of!) are congratulated for;
  • Aligning RM Programs with their businesses.
  • Communicating Risk Appetite and Risk Tolerance through the business - nothing on hard risk limits in the paper though
  • Being "able to take greater business risks" - I don't necessarily make the link between being "good" at risk management equating to taking greater risks, unless that is part of the business strategy one has aligned the RM Program with.
  • Take aggregated views of risk over multiple areas
  • Using techniques such as emerging risk identification/forecasting, scenario planning and stress testing
Laggards on the other hand
  • Have no formal Risk Appetite Framework (only 38% of respondents do)
  • Don't integrate Risk Management Strategy with business strategy (only 31% do)
They also hook the leadership qualities of risk management to some quantitative "value of good risk management" work on p5 (a topic which Towers Watson recently tiptoed around due to a lack of quant), namely that their profit margins and margin growth will outstrip peers. The growth of profit margins might be a bum steer, as the macroeconomic environment is perhaps less kind to industries other than financial services, who of course would have seen margins peak comparably faster over recent years due to the size of the trough in 2006/08!

As ever, the lexicon used in papers such as this takes a dip in the lake of dubiosity, for example:
  • That companies should "...treat risk management strategically" - as opposed to what, "operationally"? This kind of expression suggests that risk is not already considered in strategy, which feels unfair and unrealistic, even on the immature firms surveyed. That there isn't a functional ERM Framework to enhance that work does not mean it isn't done at all.
  • Risk Appetite Framework should have "buy-in" from senior management and the Board. Why "buy-in"? They should be deeply involved in the construction of an RAF, and their successes or failures as management should be inextricably linked to operating in line with it, not asked to nod in approval at the next Board/EXCO
  • "Having a clearly defined risk appetite framework allows companies to quickly assess strategic decisions in the context of risk" - that of course was not a given...
  • They also follow the tactic used in the Towers Watson paper in referring to risk management "programs" as opposed to "systems" or "frameworks- again, I'm not trying to labour the sematics of it, but a Programme for me has an end, and the work of a risk management function simply does not. This is perhaps just a psychological angle being worked here to drill into prospective clients that Programs can be boosted with a burst of external advice, but I find it increasingly disagreeable, particularly given the risk management leadership traits highlighted in this document, which most certainly do not lend themselves to the workings of a transient Programme.
Other stand out points would include
  • Alignment of RM Programmes against each business function (p9) - horrible result for Sales & Marketing, even for Leaders, and suggests it is an area for us all to redouble our efforts
  • Similar to Towers, talk of firms "drowning in data" - cannot fathom this for the life of me, but perhaps that's because I can use pivot tables and SQL server!
  • GE Capital's approach to administering Risk Appetite (p16) - very clean, and in a manner which the CRO Forum would appreciate.
  • Finally, a really nice section on p19 which shows the discrepancies between executives and risk professionals regarding their own firms' prospects. The Fannie Mae CRO suggests that Risk Management staff are "paraniods by profession" which given his employer's recent history, doesn't mean people aren't out for you!

Thursday, 28 May 2015

IRM on Internal Model Validation - Red Card or Green Card?

Cyclic Validation - Quelle horreur...
Just back from Paris, where I spent a weekend queueing behind selfie-taking tourists before taking out a second mortgage to buy bottled water. A beautiful place, though I found Depardieu was much quieter off-screen...

Onto the topic in hand, the PRA were pretty vicious back in the day on Validation efforts in their infancy, with Julian Adams lambasting both progress ("significantly behind") and validation scope ("narrow"). Given that the Solvency II sabbatical which bridged half of 2012 and all of 2013 gave firms time to catch up and widen, you might think that those with internal model ambitions would be pretty tidy by now. The PRA have even told firms how they believe "good" model application paperwork to look, carving out for themselves and the Validators of the world an easy-to-read "model reviewer" level of detail (p1).

In those salad days, Internal Model Validation felt to me like it would be the chernozem of the nascent Risk Management profession in insurers; a skill set that a quant or a non-quant could acquire, apply, and ultimately ease through the promotional path within insurance entities, given the depth and breadth of technical and strategic information the process challenges...

...but the moves never came. Despite the actuarial world themselves happily disassembling the complexities of quantitative modelling into easy-to-digest IM Validation themes, the non-quant world has waited patiently to see if anything of substance would emerge from one of its representative bodies.

And this week it arrived! The Institute of Risk Management has delivered, as part of its Internal Model Industry Forum (IMIF), a white paper on the validation cycle.

The IRM have been active in this area prior to the formation of the IMIF. I have covered an ERM in Insurance event at the start of 2014 here, while this more volumous slide pack featuring a number of the Billy and Betty Big Biscuits of the field emerged from summer of last year, when the IMIF seemed to come to fruition. This white paper itself appears to move along the concepts and ideas inside an IRM slide deck from last Christmas.

Given that the IRM is not-for-profit, there is always a likelihood that sponsors will unduly influence the products (indeed the IRM Chair notes in this that they rely on "enlightened industry support" to knock these documents out).

Sadly in this case, the sponsors include Three of the "Big 4" (with the fourth on the IMIF steering committee) , leaving the document dripping with consultancy hallmarks rather than pragmatic solutions to execute the tasks in hand.

That view is reinforced somewhat by this follow-on presentation to the IMIF from last week by this white paper's workstream lead and supporting consultant - one selected industry comment on slide 8 (presumably from a chocolate bar shortly before it ate itself) reads, "validators should really be experienced modellers"!

A few general points jump out of the white paper;
  • That a firm's IM is "...at the heart of risk and capital evaluation" - I thought it was supposed to "inform" this evaluation, not dominate it (slide 3 here, as well as Julian Adams's speech from a couple of years ago [p4]).
  • Is the insurance industry "...increasingly reliant on sophisticated models" - maybe in terms of AUM/Market Cap, but given the UK IMAP queue is down to approximately 40 firms out of over 400 (p4), and that number has steadily reduced over the last 3 years, feels a touch disingenuous. I've no doubt the firms represented on the Steering Group are "...increasingly reliant" though
  • The document claims to set out "best practice principles" - not sure if "practice" and "principle" share the same bed, but that aside, would anyone find it remotely acceptable to have the consultancy world fund a document which details "best practice" on IM Validation?

And a few stand out elements from the proposed Validation Cycle, which is heavily influenced by EIOPA's guidelines:
  • "Best practice now requires firms to demonstrate, with evidence, that the cycle...[is] being actively and effectively carried out" - how can best practice "require" anything from anyone?
  • "...resulting best practice that is emerging" (p4)  - how is any practice considered "best" at this stage of proceedings, when we are literally practising! Against what criteria?
  • References to "model risk impact assessment" and the "model risk assessment process" (p5) seem to come from nowhere. Alluding to something formal, but not very clear
  • Lot of coverage of "triggers" of IM Validation, which feels like a fishing expedition for the paper sponsors, rather than direct address of L2 Art 241 - the number of areas of "change" to consider as IM Validation triggers covers pretty much any change, anywhere, both inside and outside of an insurer (p8)! Most would also be ad-hoc ORSA triggers in my experience, so this potentially sets up insurers for a bucketload of work every time they hear a pin drop.
  • Formulaic and periodic IM Validation a "needless cost"? Surely periodic validation, no matter how badly executed, is compulsory (L1 Art 125)?
  • The Trigger Impact Assessment stage (p10) is barely legible - "The trigger impact assessment against model risk appetite stage" - and terminologically it is all well above legislative requirements.
  • "Unexpected triggers" (p12) get a mention. Again, not making sense to me - you either know your triggers or not.
  • "Model validation is complex" and "less than black and white" (p16) - certainly is if you try and follow this process! A focus on plain questions and less quant can only help the models non-expert users (slide 7).
  • If the validation cycle, processes and execution are "continuously evolving" (p18), are they reliable? Feels difficult to meet L2 Art 241.3, at least from a planning and execution perspective, if the process is constantly being tinkered with 
  • "Developing a communications strategy" (p20) as part of the validation scoping and planning stage feels terribly over-elaborate.
  • "Robust planning" expected to be common (p22), which doesn't necessarily marry up with the expectation of dynamic rather than cyclic validation in future (p10)
I think it is right to take the hump to a certain extent here. The PRA have been cunningly silent on capital add-ons to date, but given the implication that they will not be applied and renewed ICG-style (slide 13), there is likely to be many more less monied Partial IM applicants to follow over the next couple of years. Having the most influential consultancy firms decide on what is "best" in the validation world (and for it to have this many bells, whistles and legislative off-roads) feels like setting those firms up for either a fall, or another bill.

The PRA actually delivered something with much less padding to the IRM back at the end of 2013, so I'm struggling to see why that has justifiably been turbo-charged. Given they have three of their finest involved with the IMIF, but are continuing to be directly vocal on this topic (as recently as March 2015), it sends a worrying message to the capital add-on brigade that the IMAP early birds will be setting disproportionately high bars for 2017 and beyond when they deliver their PIMs.

Ultimately, I was disappointed by the publication, which reads more like a flannel manual, and is certainly not the kind of Risk Profession contribution that the topic so badly needs if the PRA's dreams of Board's "directing" and "owning" the IM valdiation process (slide 9) are ever going to come true. The 200 page novella world of Validation Reporting feels closer than ever...

Tuesday, 18 March 2014

PRA on General Insurer Technical Provisions under Solvency II - Taking the "TPs"?

Allow me to take a quantum leap outside of my comfort zone while I pick my way through the PRA's latest Insurance Industry aide memoire, via a consultation paper on the calculation of technical provisions in General Insurers.

This looks specifically at TP calculations with Solvency II in mind, and is aimed specifically at GI firms currently in IMAP. That said, the tone and technical matter covered is an excellent heads-up to Actuarial, Risk and model validation personnel currently active in this space about how the PRA approach to assessing Solvency II compliance is developing.

The document itself reads very much like their last consultation paper release on Deferred Tax Assets, insofar as it is a laundry list of "what not to do" - look at how many times the expression "should not" appears! They have leaned on their findings from both thematic reviews of TP calculations (Life and GI-specific Questionnaires were sent out a year ago) as well as from IMAP and ICAS, so their finding will be well supported by most recent practices in the UK.

The consultation window is pretty short as well, with a mid-April shut-down scheduled, so if you don't like the cut of their jib, you'd better speak soon.

Stand-out points for me included;

Generic

ENID - TP accommodation required
  • Expectations of Delegated Acts content are cited throughout, but in terms of the exact date of their public provision, they can only go with "Q3 2014". From what I have seen, there is nothing cited which isn't in the November 2011 draft.
  • The abandonment of the term "binary events", replacing it with "Events not in data" or "ENID" - the fait accompli of "binary" (that events which are not in a data set must therefore be extreme and/or rare) is confirmed as unacceptable.  The PRA don't appear to be wedded to the old term in any case, and while the actuarial profession used it liberally in the past (here and here for example), they began a transition away from it late last year (p45 of this).
  • "Any data that can have an impact on the outputs of the internal model should be considered to be 'used for the internal model'" (3.19) - important IMAP message across sectors I think!
  • There is evidently some concern that firms are thinking of relying on the work of external model providers to meet Solvency II standards, with the PRA confirming that firms may not rely on "...generic validation performed by the model vendor" (3.25). This means that the model validation relationship between IMAP candidates and their third-party providers needs to be much more invasive and aggressive, and needs to start pretty soon!
Technical Provision-Specific
  • A large number of points made in the paper relate to over-simplifications, which should help anyone who is struggling with the concepts of materiality and proportionality. These include methods relating to ENID, Risk Margin calculations, Approximations and  the emergence of risk over one year
  • Similarly a few tricks of the trade appear to have been scuppered, such as using optimistic business plans for setting provisions, "actuary in a box" methods and assuming improved underwriting performance
  • Some substantial focus around the quality and quantity of challenge applied to External Models (focused on third party Catastrophe models in this instance), in particular the challenge of  assumptions used by the provider (3.16-17 and 3.26-28)
  • The concept of "cumulative materiality" is introduced in the context of multiple approximations, a concept which I suspect many firms are still struggling with in the context of Internal Model change (2.9)
  • An interesting take on the justification of assumptions, with the PRA taking umbridge with firms using "industry standard" or "established good practice" as a supporting argument, rather than using their own risk profile as the basis for support (3.15)
  • A section which seems to advocate conservatism, if not prudency, in the setting of sensitive parameters (3.10), as well as advocating the use of stress and scenario testing to make up for ENID when setting parameters (3.2)
Certainly lessons for both Life and GI internal model applicants in here, and the PRA should be congratulated for getting this paper out in good time. I'm not necessarily convinced though that third-party providers of internal model inputs will happily acquiesce with the demands which the industry are being asked to make of them here.

Wednesday, 22 January 2014

Model Validation - benchmarks and best practices from the IRM, PRA and Lloyds

Models - seeking validation
Bearing in mind we have passed the 2013 financial year end, and all of the internal modellers amongst us will be trying out their new processes and technology in the production of a balance sheet for the first time, a few very timely pieces of material on internal model validation have been released, which should help anyone who is curious about what their neighbours are up to!

The Institute of Risk Management's rebadged Solvency II Special Interest Group held a get-together in December on IM Validation, and a couple of interesting documents have emerged.

One from a PRA Validation guru is particularly useful for anyone in the IMAP space who has any uncertainty about the PRA's approach to assessing the quality of one's validation processes and reports, covering;
  • The purpose of validation
  • The PRA's approach - Life and GI-specific SME groups
  • An overview of IMAP findings - 40+ reviews conducted to date, and they also state what your evidence "should" demonstrate
  • Their observations - Noting that Validation Reports are generally deficient
  • A schematic view of what they consider the Validation process to be
  • A bullet point list of how validation effectiveness can be demonstrated
I guess the odd thing for me is why this kind of material isn't presented/circulated more widely by the PRA, as it is surely of benefit to IMAP participants, who wouldn't always be in attendance at a pre-Christmas IRM event!

The other useful benchmarking item from this event is the survey on participants' experiences to date in the validation field. While the sample is small in absolute terms at 18, and is a touch heavy on the GI side (over half of respondents), this is as good a benchmarking aid as you will see for a while, so it is worth noting the following;
  • Just over half have transitioned Validation into BAU
  • Only 3 respondents had a Validation-specific steering committee to help govern the process, with others choosing to use existing committees or the CRO/Risk function
  • Over 80% use the SCR contribution of each risk driver to determine the depth of validation activity. Other determinants include regulator feedback, risk registers and previosu validation reports
  • Over 40% say that their independent validation work is identifying flaws in their "dependent" validation work, while over a quarter say that independent validation has been scaled back due to the quality of "dependent" work!
  • Less than a quarter say that validation of external models (ESGs etc) has been effective
  • Around two-thirds use peer review and sensitivity analysis to validate expert judgements. Horrifically, two respondents said they haven't been able to validate expert judgement at all!
  • Over half are still using external contractors/consultants for independent validation
  • Page 12 covers the popularity of certain sections of a Validation Report. Less than half include a section on benchmarking
  • Most are keeping the Validation Report to under 100 pages, with management feedback being the main catalyst for changing the length.
Finally, a survey from LCP Consulting was published this week covering the progress of Lloyds syndicates in their Validation activity. This was an area which Lloyds acknowledged as "work to do" back in May last year, particularly around validation testing and documentation.

The findings appear to be positive on the whole, with most firms saying they are at least halfway towards their "ideal process". Unsurprisingly, dependency modelling and validating expert judgement make the list of "key challenges" remaining.


Wednesday, 18 December 2013

PRA on "good" and "bad" documentation for IMAP - restart or refresh?

As an welcome aside from the PRA's activity day on the 12th, they also delivered on a promise to provide examples of what constitutes "good" and "bad" documentation in the context of the internal model approval process (IMAP). Bearing in mind it has been quite some time since the PRA publicly pronounced on the matter - indeed, they were called something else the last time they did - the industry welcomed this in like a lottery-winning prodigal son.

Bad documentation
- reform or execute?
There have certainly been enough apocryphal tales spewed out by the industry over the last couple of years to suggest that the production of documentation to support participation in IMAP had transformed from a small cottage industry into something of a palatial Georgian Mansion house with a granny annex.

Whether or not this kind of advice is therefore timely enough to save the Solvency II Programmes of the UK from using documentation in their revitalised IMAP preparations that is neither good for man nor beast is another thing, bearing in mind there is three years worth of accumulated flotsam currently kicking around the servers of UK insurers which, given this message, will need to be revisited as a matter of urgency.

Regardless, as the UK still appear to hold the whip hand in EIOPA's model sub-committee, the PRA's views on model documentation are relevant to readers across the continent, so the document is well worth a read for anyone in pre-application.

I took the following from it;
  • They have 3 principles of "good documentation" - accessibility, evidence and quality control
  • "It is helpful to have a clear separation of policy, methodology and results"
  • The document refers throughout to giving consideration to "the reader". Feels a little disingenuous if they mean "the PRA", and after reading their document a couple of times, I can't imagine who else they have in mind.
  • Following on from that point, a reference to a bad example suggests that "...the author is not thinking carefully about the audience" - it is equally fair to suggest that the author may be assuming a level of technical/commercial knowledge at the PRA end which is lacking?
  • The PRA are evidently not happy to have to "seek clarification" on matters, which suggests the time allocated to assessments is tightly planned, or indeed the level of technical knowledge held by the assessors is limited.
  • Interested to know if these principles hold firm for Standard Formula firms if viewed conversely e.g. does paperwork for the justification to not use an internal model need to be of a similar standard?
  • The reiteration that the PRA "...will rely, in large part, on the submitted documents" when assessing the model - just in case your friendly executive committee reckon they can talk their way in!
  • A lofty aim to improve "accessibility" of documentation, by having levels covering; executive summaries; model reviewer/validator level info; and model user/operator level technical documentation. The PRA only want the first two levels as a matter of course, which would suggest that procedures and technical documentation should be used as supporting evidence only.
  • Tabling up references to the Directive and Implementing Measures within documents is viewed favourably.
  • Their "useful rule of thumb" feels instinctively unwieldy - they suggest better documents contain one-third 'what has been done' with the rest covering 'why and how'. That said, expert judgements are clearly not being evidenced anywhere near the level desired.
  • A convoluted and potentially frightening reference to "self-validation" testing, which the PRA view favourably, but which seems to point towards a preference to see suites of documentary evidence for each assumption applied in the modelling process. 
  • To conclude, readers are redirected to Julian Adams's letters from  mid- 2012 (here and here) - important to note that this guidance remains relevant, regardless of the passing of time.
I suspect that most model applicants will find they have re-work to do off the back of this, both with the pen and with the sickle. Expert judgement and assumptions documentation remain the unquenchable thirst though, so one's best endeavours would be well spent in that field in early 2014.

Thursday, 28 November 2013

Accenture Insurance Sector research - Global Risk Management survey

Flood Risk?
A nice generic risk management benchmarking piece from the guys and girls at Accenture came out this week, and after I spent last week at the Leicester rugby game, I was happy to see another 15 "tigers", albeit this time scattered throughout the survey paper itself, presumably as a subtle metaphor for "death by tiger" risk...

It is made up of 98 C-suite respondents (nicely spread across disciplines), is Insurance sector-specific, and Global in coverage (one-third Europe, half N.America), so should be useful to any reader for trend-spotting and Board briefing.

From the document itself, I've pulled out the following;

Risk Governance
  • 98% have their "risk management owner" reporting to the CEO
  • 96% have a senior executive (regardless of title) as "risk management owner"
  • 80% have their "risk management owner" report regularly to the Board
  • 55% had a titled CRO
  • A number of those stats (whilst improved since their last survey) are a poor reflection on the Global insurance industry, but perhaps reflect where corporate culture is outside of the EU/US axis
  • Of the governance bodies, I was surprised to see only 60% of Life companies have an operational risk committee
Solvency II/Non EU equivalent legislation-specific
  • Over 80% of Life and P&C respondents seem happy that they are preparing well for their regulatory initiatives (Solvency II or local equivalent).
  • Other than Internal Model development, the main outstanding issues for Life insurers to be prepared for Solvency II/equivalent is IT architecture and Data Management/Integration. For P&C, documenting risk processes and developing a meaningful Use Test are also worrying at least half of respondents.
  • Issues such as training and education, risk culture and risk governance documentation are relatively low on the priority list.
  • Conversely, when asked on a 1-5 scale about specific areas of risk governance, respondents were more positive about their Data preparations than their risk governance - go figure!
  • Use Test preparation remains a laggard throughout.

Generic

  • Top external pressure was Legal risk, and by a good distance. Regulatory risks relatively low on the list, perhaps reflecting Europe's low weighting in the quantum surveyed.
  • Risk Management seemingly well integrated with strategic deployment, but not with product development or reward.
  • Poor statistics around embedding risk management into core functions.
  • Two thirds of Life respondents noting that a lack of "early warning capabilities" impedes emerging risk management.
  • Over half of Life companies said investment benefits ("above and beyond" continued compliance with regulations) would come from better reporting and better integration of Risk and Finance.
There is some of the softer stuff on aspirational elements of risk management thinking at the back, but if you just want to check against your peers, you can save that for a rainy day.


Tuesday, 10 September 2013

Towers Watson - 'Risk Appetite revisited' (did we ever leave it?)

I have been doing a little work on Risk Appetite in the background recently, so was intrigued to have a read through this recent release by Towers Watson on the subject, seemingly targeted at North American and UK markets, but relevant to any practitioner in this space. Somehow I wasn't put off by p6 when, in response to the hypothetical question 'What is Risk Appetite', they responded with, "...we do not want to focus too much on the issue..."!
Appetite - second helpings?

I had blogged earlier this year on Risk Appetite, covering the expectations of EIOPA on the matter (which are few), as well as the more pokey/proddy stakeholders like the PRA/Central Bank of Ireland/S&P (which are several!), so the backdrop of risk appetite's practical significance to insurers doesn't need to be repeated here, more how consultants and practitioners are improving their game on the ground. Worth noting here that a few of the other consultancies have proffered their two cents on the matter over the last year or so (here, here, and here).

While interest in 'risk appetite' is currently piqued at governmental level thanks to the forensic examination of the banking industry's failings (multiple references in Parliamentary Commission evidence here and here for example), the driver of activity in the UK and Ireland is predominantly from the regulatory compliance perspective rather than expectations of bespoke, strategy-driving activity. In addition, we now see the emergence of Internal Audit as a party with a vested interest in the matter, which has the potential to draw the subject even more to a tidy, but ultimately superfluous documentation exercise.

With that in mind, Towers note that this paper is focused on "...enhancing risk appetite by improving its articulation, via clearer linkages to mission and strategy", and a rather derisive tone is therefore applied throughout regarding the familiar quantification methods preferred by regulators to monitor likelihood of insolvency in the next 12 months, giving equal billing to non-monetary capital and qualitative measurements. The paper also crosses some familiar ground, such as a lack of consistent terminology, which it tries to address (below).

Oddly, the document does not reference the FSB's thematic review of risk governance earlier this year, which will surely drive efforts in this space in the medium term, if only due to the paucity of certainty on the subject. That the FSB believe that regulators have "more work to do" is striking, and while they also bemoan the lack of common terminology, they don't let that prevent them from offering definitions of their own, as well as listing their "Key features" of a Risk Appetite Framework.

More obvious statements

  • "..clearer linkages are needed to mission and strategy for risk appetite to be effective"
  • "risk appetites must include boundary constraints"
  • "We suggested that greater clarity around the definition of risk is needed..."

Definitions
  • Risk - "In this context, risk should be defined in terms of those events and circumstances that may result in an insurer failing to deliver on its mission."
  • Risk appetite - "...the manner in which a company expresses an identified set of risk-trading opportunities, and sets boundaries on its risk-trading among those opportunities, aligned with successfully delivering on its mission."
  • Risk strategy - "The company’s risk strategy articulates how risk fits with the mission".
  • Risk tolerance - "Risk tolerances are a quantitative extension of the risk strategy...risk tolerances must be measurable...[and] place quantitative boundaries on the company’s strategy"
  • Risk limits - "Risk limits are more granular tolerance levels expressed for specific risk sources, business units, and/or products that are used to implement the risk tolerances."
  • Risk appetite statement - "...risk appetite statements should be taken as the combination of risk strategy tolerances and preferences, bringing together qualitative and quantitative enterprise perspectives on risk as both opportunity and threat."
  • Mission - "mission is the insurer’s unique multi-period and multi-stakeholder value creation proposition."
Technical suggestions

  • They promote four facets of risk assessment: size, likelihood, impact and significance.
  • For those working on statement content, they recommend "...since published mission statements can be fairly terse, the risk appetite may need to look beyond the explicit elements of the mission and consider elements that are implicit." Instinctively that feels unfair, but I guess the world of implicity is one for the second line to inhabit, while the first line concentrate on value-adding.
  • Concept of adaptive buffers sits nicely with me - the most visceral ones being economic capital and reinsurance/hedging/liquidity facilities, but TW attempt to expand that over qualitative areas of the risk appetite statement
  • Risk preference ranking of 0-4 depicted at the back is a handy schematic

Sore points

  • "Some take the view that risk appetite can be expressed as a single metric, or perhaps a small set of metrics, that capture the organisation’s willingness and ability to bear risk." - that 'some' would include the FSB, COSO, the Central Bank of Ireland and the IRM, so I wouldn't be too sniffy at efforts to-date
  • "Much of the work to-date on risk appetite statements has been driven by solvency supervision requirements, many statements tend to focus primarily on potential losses of capital"- a natural and by no means unwelcome by-product of having regulators in the box-seat, as opposed to stakeholders combining their efforts to establish compulsory risk appetite statement content?
  • "While most insurers have, by now, developed risk appetite policy statements and discussed them with their boards, many have expressed dissatisfaction with the exercise" - that feels a rather loose statement, and if true says more about the personnel charged with performing the work.

I'll take a look at the diversity of definition in the risk appetite space across different bodies in a separate post - for now, just enjoy this tidy piece of work for what it is.


Monday, 9 September 2013

Deloitte on 'regulatory uncertainty in Europe' - embedding a new modus operandi (?)

In a wonderful example of predicting the present, Deloitte have released a white paper (sign-up required) giving their take on regulatory uncertainty in the European insurance industry, and how the volume of new regulations (and their inability to land on time) is driving emerging best practices in the consideration of regulatory risk at Board level.

New Modus Operandi - alloy wheels optional?
Of course, it is always best to wait for such matters to emerge before proselytising, and the current cup of omni-postponed over-elaborate regulations is running over (Sol II, IFRS 4 Phase II, FATCA, etc), naturally causing difficulties for all those responsible for preparing for them, as well as the execs who take the topics into the boardroom every quarter, only to say "it's been delayed again, can I have more money"...

From my perspective, it was particularly interesting to see that proactivity is recommended regardless of nature/scale/complexity, bearing in mind the first time I spoke to a Board of Directors at a tiny insurer regarding Solvency II preparations was in 2009 - only consultants could comfortably suggest that an new executive-level role is established, and Board agenda time is regularly set aside, only to explain the latest delays in multi-jurisdictional regulations (I certainly know what my old CEO would have said to that!)

That aside, they suggest that two major problems need to be overcome; that few insurers have a single view of regulatory risk; and that regulatory insight is poorly represented in the strategic workings of insurers, both of which are easy to agree with purely on circumstantial evidence.

Whilst this frequently reads like a paper written to justify bringing consultants in to compensate for failing in risk and compliance professionals' armoury, Deloitte make the following noteworthy assertions/recommendations in it;

Trends

  • That most insurers prefer to 'wait and see' rather than be 'first mover' when it comes to regulatory preparations - after the Solvency II experience, does that surprise anyone?
  • That "...Deloitte's view is that regulation can be regarded as a 'structural' driver of the insurance industry"
  • That "...Deloitte's considers a regulatory dividend can and should be sought", which is not necessarily my experience of consultancies when on site, who (presumably for legal reasons) prefer to promote a gold-plated complaince approach to regulation-driven projects.
  • Cost of compliance is now materially diluting return on equity in EU insurers
  • That Conduct Risk is likely to become high profile across Europe over a longer period of time than its current flavour of the month feel, thanks to IMD2/PRIPS/MIFID
  • National regulators are increasingly impeding on day-to-day running - examples given (all of which have a whiff of IMAP requirements about them), include documentation improvements and influencing risk appetite/capital allocation work.
Costs and volume

  • Regulation prep cost the European insurance industry €4.2-€4.7bn in 2012 - they go on to expand that to €8.1-€9.2bn over the last 3 years.
  • UK industry will be subject to 29 new pieces of legislation of the next 5 years (surprisingly lower than the French at 35, and the Germans at 32!)
  • That the "cost of doing nothing" while waiting for regulatory clarity may be significant - as significant as consultancy spend preparing for something which never arrives perhaps?
  • That compliance functions are naturally struggling to cope with the current volume of initiatives
Solvency II-specific
  • They extrapolate an estimated €550m cost of Solvency II compliance preparations in 2012 into a €1.5bn-€1.8bn 'top 40 insurers' number, and a €2.4-€2.9bn figure for the whole industry - feels a bit light, bearing in mind 'UK plc' must have done the best part of £1bn on Solvency II alone in 2012.
  • They quote one strategy director as saying that "Solvency II is killing European M&A..." - p10
Their recommendations (from p19) are too woolly in aggregate to help a normal practitioner - they are probably targeted more towards programme directors and managers - but the recommendation  to establish a Regulatory Assessment and Response Executive with a suitable remit is a smart idea, even if from a practical perspective this might need to either be balled in with the responsibilities of an existing executive, or only be a mid/senior management role, in smaller companies. 

These recommendations also include the marvellous suggestion to "embed a new modus operandi" - an expression normally reserved for profilers of serial killers, and perhaps the hardest sell since Isle of Man beach holidays.

PS I apparently missed the memo where the oft-ridiculed speech of Donald Rumsfeld used to support war against Iraq became de rigeur in risk management/insurance white papers. If there is one "known known" in this world, it is that I will never use that expression on the job!

Monday, 12 August 2013

PwC and CSFI's 2013 Insurance Banana Skins survey - "Conduct Risk" firmly a la mode

Following on from the 2011 version, PwC and the Centre for the Study of Financial Innovation have pumped out another version of their Insurance Banana Skins survey, identifying how well the insurance industry feels it is prepared to handle a list of pre-identified risks. The average response on a scale of 1 to 5 was 2.97, which rather unrevealingly suggests the industry is averagely prepared to manage its collective risk profile.

EU Legislative process - not for vegans
This survey was conducted during March/April 2013, and elicited 662 responses from 54 countries, with two-thirds of respondents coming the insurance industry (the rest consultants/brokers etc). Almost half were European, so no surprises that the risks emerging from the regulatory environment were top of the pops for the second survey in a row. Solvency II gets a particularly flavoursome mention, with reference to its struggles to get through the "Brussels Sausage Machine"...

Bearing in mind the exquisite pressures being applied by the EU machinery to quantify risk, this publication is a welcome return to horizon scanning, qualitative assessment and emerging risk, all of which is handy for the ORSA posse, who according to recent surveys, should be all over this during 2013.

Some very interesting snippets emerge from the report, in particular;

  • "Conduct Risk" - if ORSA was the new boy in 2012, then its 2013 counterpart is surely Conduct Risk, which I suspect didn't warrant a category of its own in many risk managers thinking until the return of twin peaks regulation in the UK. Conduct Risk has shot up the charts in its significance for insurers, now sitting 4th (from 18th last year)! Specifically, the suggestion that insurers are now "...looking beyond conduct risk as simply a compliance exercise" makes you wonder what some firms through were acceptable products in the last 10 years!
  • "Guaranteed Products" - was not listed last time around, now jumps to number 6
  • Actuarial Assumptions (which can easily mask the emergence of a number of the risks listed) unchanged at 12th
  • Capital availability down from 2nd last time to 16th this year - interim period been spent squirrelling capital away, or happy that the onerous elements of Solvency II are (thanks to Germany) in the distant future?
  • Reputational risk still in mid-table, at 14th
And sectoral/country specific;

  • Surprisingly, the Life sector doesn't have actuarial assumptions in its top ten concerns
  • Equally surprisingly, the non-life sector doesn't have regulation in its top ten concerns - clearly happy with their proposed Solvency II lot!
  • That reputation doesn't feature in reinsurer's top ten - with customers likely to be eager yet more discerning  under Solvency II, one would think this is an area for enhancement in order to stand out from the similarly-rated crowd
  • The quality of risk management appears to have spiked as a concern largely due to the emergence of emerging market firms into the space playing catch-up (on paper at least), as well as concerns that some firms are playing at risk management without making necessary adaptations to the prevailing risk culture.

Saturday, 10 August 2013

Moody's survey on Solvency II compliance preparedness - the chilly third pillar

So from what I can gather it has been a terrible week for the Girondins, with a freak hailstorm wreaking havoc in a thin strip along the vineyards of Bordeaux's Entre-deux-Mers appellation - my in-laws were seemingly spared further down the river, noting that it was merely "un peux froid".

On Ice - Solvency II programmes
and this year's white Bordeaux?
And speaking of a great deal of hard work getting aimlessly destroyed by an unpredictable European storm, Solvency II (do you see what I did there?) appears to have at least enough juice in the tank to have encouraged Moodys to survey practitioners on the preparedness of the industry to achieve compliance before the deadlines currently on everyone's lips (i.e. 2014-2015 for EIOPA Guidelines, 2016 for "go-live").

That survey is available here (short sign-up required, but worth it), with a very short summary here. The media have touched on the survey (here), but only seem to have read the summary, so I've picked through the whole shooting match to see what else was worth knowing.

The sample is small at 45 contributors, but they have all been interviewed one-on-one in Q4 2012/Q1 2013, so the responses are not too dated, particularly as many Solvency II programmes have been running on meagre rations since January of this year. Coverage of 12 EU countries is included in the 45 people, with a decent split of size and insurance type. Majority of respondents were CRO/equivalent, with a few accountants, actuaries and programme managers thrown in for good measure, and just over half are on Standard Formula.

Talking points for me were;

  • That 22% have frozen Pillar 3 activity, while 11% have frozen all Solvency II activity
  • Half are using Standard Formula to curb costs!
  • In addition to that, 20% say that the Use Test is a barrier to using models!
  • 27% are approaching Pillar 1 and Pillar 3 with a tick-box mentality (i.e. happy to use multiple manual processes/excel-based tactical solutions to deliver the balance sheet and reporting template elements), while 44% have worked exclusively on Pillar 1 at the expense of Pillar 3
  • Solvency II project investment levels are "considerably more" in the UK and France compared to Germany - makes you wonder why they have such a long face!
  • 67% have increased their control function staffing by 10% or more - 31% have increased by 50% or more.
  • Only 7% note "capital reduction" as a perceived benefit of Solvency II, with 33% selecting improved capital planning (regardless of quantum) as a benefit.
  • Only 6.7% say they are receiving "high" levels of support from their national supervisory authority.

Seemingly the stats are a hostage to the sample - I'm sure the PRA would be apoplectic if this was the position of Insurers of Britain plc, but for me the big story is the indiscriminate swelling of Risk/control functions in smaller organisations that evidently are only ticking boxes. Feels a tad disingenuous to pump the staff numbers up to demonstrate compliance, but I suppose it's not me they need to satisfy!






Wednesday, 7 August 2013

Deloitte's 8th Global Risk Management Survey - cause for concern?

A survey from Deloitte has recently hit the news stands, namely the 8th edition of their Global Risk Management Survey - I thought I'd postpone my August holidays to pick through the bones of it (?).

The data was gleaned from an online survey they sent out to CRO/equivalents back in Sept-Dec 2012, so is a bit dusty, and there were 86 respondents, so a half-decent sample. It isn't dominated by a particular sector or continent (p7), but there are more conglomerate/bank-heavy respondents than pure insurers.

There is an infographic for those of a short attention span with a few headline numbers, but having sifted through the larger doc, I found the following elements worthy of note;

Boards, Committees and Risk Management
  • 80% of Boards are reviewing and approving Risk Management Policies/ERM Frameworks and Risk Appetite Statements. Bearing in mind the types of organisation in the sample, that is disappointingly low.
  • 25% don't review individual risk policies
  • 23% don't review strategy against risk profile
  • Almost half don't invite CRO to EXCOM meetings
  • Almost two-thirds delegate risk oversight to satellite committees (and two-thirds of those delegate to a Risk Committee)
  • Only half have their Risk Committee chaired by an INED.
  • Use of specific management risk committees for individual risk types tends to cluster around the 40-60% bracket (for example, 60% have an ERM committee, while 44% have an Op Risk Committee). Heavily weighted by organisation size i.e. larger ones tend to have them! 
  • Emerging risk reporting not supplied to 30% of Boards
  • Model validation results not supplied to 70% of Boards!
  • 66% (of insurance respondents) have their Boards responsible for reviewing economic capital results
CRO and Risk Management Function
  • 97% of large respondents have a CRO, 81% of smaller firms 
  • 88% using "3 Lines of Defence" (almost all of the larger respondents do)
  • 62% have an "ERM Programme"
  • 58% increasing risk management budgets (still!)
  • In the list of tasks currently performed by CROs, the fact that only 63% are involved in the approval of new business lines/products is pretty telling, and not in a good way.
Other control functions

  • Almost half of respondents said that Internal Audit and the ERM Framework do not use common risk categories and language.
  • 33% do not have a independent model validation 'function' (remember, the banks are in these stats as well!) - most of those who have made provision park it in the Risk Management function.

Risk management techniques

  • 90% using some form of stress testing in the business, with most saying the outputs are used in business planning, strategy setting and identifying risk tolerance. More than half however don't use the outputs in the allocation of capital to lines of business.
  • 74% have some type of Stress Testing policy
  • Over 20% either do not have a Risk Appetite Statement, or only have a quantitative one
  • Almost 70% still use regulatory capital as one of their quantitative measures in their Risk Appetite Statements
  • Risk limits tending to be set at enterprise level, as opposed to business or desk/subsidiary level - stats are a little murky due to the emphasis towards banking sector.
  • Model risk and Liquidity risk seem to be the risk types least factored in to companies ERM programmes
Management of Key Risks
  • Full list on p24, with the percentage shown representing the number of respondents who thought their management of each risk was "extremely" or "very" effective - stand outs were that perceptions of the effectiveness of the management of Operational, Model, Outsourcing and Data risks appear to be much lower than one would hope, with Lapse risk management ranked unusually high.
  • Op Risk KRIs and Loss data only collected in 60% of respondents
  • Just over half are modelling Op Risk in some way - varying degrees of complexity experienced
  • Most are using stress testing and/or reserving to assess Insurance risk - over 40% not currently using EC, and over 50% not using VaR.

Risk and Reward

  • Almost 60% of remuneration schemes have no clawback provisions
  • Almost 70% of schemes do not align incentive payouts with the term exposure of the underlying risks

Solvency II-specific
  • 92% (of relevant responders) will focus resource on ORSA in next 12 months
  • 77% will focus resource on Data Quality in next 12 months
  • 69% will focus resource on Documentation and Reporting in next 12 months
  • Less than 25% rate their processes and systems for Data Governance extremely/very effective.
  • Declining trend of insurers who will be modelling economic capital (p19)
  • Only 80% actually calculate Economic Capital
  • Some very grim stats on p21 covering which risk types are modelled for EC purposes (underwriting risks seemingly very low on the list)
There are a number of areas touched on here which fall short of pending (or indeed actual) national/international regulations and codes, never mind "best practice". Perhaps we can account for the innate conservatism of CROs in their responses, and assume things aren't quite as bad as they have self-assessed here?

Sunday, 14 July 2013

Chartered Institute of Internal Auditors - final guidance on Effective Internal Audit for financial services

The Chartered Institute of Internal Auditors have followed up on their consultation earlier this year on Effective Internal Audit in the Financial Sector with this final set of recommendations.

Doesn't appear to have been any seismic changes as a result of the consultation, though the "need for proportionality" has been recognised, and clarification has been added that the content itself has not been mandated by the profession as best practice.

Interestingly, huge emphasis has been put on clarifying the primary role of Internal Audit as being the "protection" of a firms's assets, reputation and sustainability - does the profession feel well resourced and equipped to handle reputational defence? - while a few other elements sprung out at me;

  • A focus remains on IA challenging the "tone at the top", as if the expression now carries so much weight and definition that professional guidance can be hung from it.
  • "Risk Appetite" is again not defined, however IA are on the hook for assessing that it has been established and reviewed by senior management
  • Emphatically declares that "...the assurance map cannot be carved up between the Risk, Compliance and Internal Audit functions", stressing that IA will be expected to include the challenge of the work of other control functions in their audit plans
  • Built in some leeway around their earlier suggestion of compulsory attendance of IA function heads at Executive Committee meetings (ostensibly in order to understand strategy) - for insurers, one could anticipate that the advent of ORSA may take care of that knowledge gap 

Certainly the PRA/FCA have been fast to come out with support for the final version, so I guess all control functions had better make their peace with the content and prepare appropriately.

Monday, 10 June 2013

Institute of Risk Management's latest on ORSA - presentations and surveys

I haven't kept too much of an eye on the IRM's Solvency II Special Interest Group activity, which during 2011/12 was prolific, but with the disappearance of the finishing line, I suspected there may have been some fall off. There has certainly been a Partidge-esque rebadging of it (now called 'ERM in Insurance'), which I suspect helps most attendees justify to their bosses, in the face of interminable Solvency II delays, taking half a day off to attend these shindigs!
Rebadged - IRM's Solvency II SIG

A recent one on the incorporation of ORSA into the business planning process is worth highlighting, being focused (at least on the face of it) on the more visceral elements of the ORSA process rather than the theory. While the Kiln CRO seemingly had more to say than was put on his slides, the Allianz UK Head of Op Risk noted a few things which those working in the field would benefit from benchmarking against;

  • Risk department seemingly responsible for ORSA report production
  • 'Record of ORSA Process' documentation - shooting for around 60 pages, which feels light to me as a "record" (about par for a "report" perhaps?)
  • ORSA Board report - summarised from the 60 pages referenced above, so again light
  • Lists some 'example' ORSA triggers, which are good for peer comparison
  • Seemingly will be validating their ORSA process, despite it not being a regulatory requirement.

The IRM's related survey also produced some notable material, particularly around participation levels - only 14 participants, compared to 22 back in 2011 and 33 this time last year, showing perhaps the extent of the fatigue on the matter. With the tiny sample also heavy in GI firms, one might take any revelations with a pinch of salt, however, I spotted;

  • Frequency - A quarter are planning to run the ORSA process quarterly, most going annually
  • Preparedness - Areas such as data quality, ORSA validation, ORSA record keeping and the forward-looking assessment are all lagging
  • Projection length - 80% going for 3 years, though the GI heaviness of the sample will have skewed this for sure
  • Projection technique - around half doing future years in isolation, and half doing multi-year (dependent) projections
  • Forward looking assessment - All respondents are factoring in expected risk profile changes into their FLAs
  • Stress & Scenario Testing - All respondents using scenarios with interdependencies, while two are not using reverse stress testing at all.