Showing posts with label compliance. Show all posts
Showing posts with label compliance. Show all posts

Wednesday, 26 August 2015

PRA Final Notice on Co-op Bank - "cautious", with blurry lines...

"Two straws please"...
The PRA published a Final Notice last week regarding the numerous shortcomings of a UK bank over the last few years, which included the news of a colossal £121m fine which the PRA would have levied if the entity wasn't still losing wedge faster than a mojito in a cement mixer.

I'm sure some of us chortled at the Chrystal Methodist headlines a couple of years ago when the Non-Executive Chair of the UK's Co-operative Bank had his numerous vices sold to the highest tabloid bidder by a rented acquaintance. I covered some of the initial fallout on here, themed mostly around reputational risk and fit and proper persons, given the exponential effects of the exposé on the ultimate failure of the Group in its form at the time.

A document covering part of Co-op's demise, specifically its Bank, was released last week by the PRA,

The PRA's Final Notice to the Co-op Bank is issued publicly, and highlights where the firm breached what were at the time the FSA's Principles for Business, replaced since the PRA/FCA divorce by the PRA's Fundamental Rules.

Included in the Final Notice on this matter was a number of matters which risk practitioners should be salivating over, given the failures which led to this punishment include
  • Inappropriate culture,
  • Internal control framework failures,
  • Ineffective risk management policies, and, the jackpot,
  • A "three lines of defence" model "...flawed in both design and operation"!
The activities demonstrating this include a woeful suite of incomplete management information, three horrendously chancy accounting interpretations benefiting the balance sheet at the expense of real-world accuracy, and a suite of defensive line failures, all of which are followed through in forensic detail.

I have sectioned my notes below for my own use, particularly given the PRA goes on something of a limb here and provide usable definitions for certain terms which I suspect many practitioners would benefit from reading. The PRA (and EIOPA) generally try to dodge requests for definitions, so while the peg is square and the hole is round, it might be as good as you get!

Definitions and expressions
  • Three lines of defence - "This is a system which relies on there being an opportunity at three complementary and independent levels to identify and correct any control failures". 
  • Second line of defence - "Second line functions should support and challenge the management of risks firm-wide, by expressing views within a firm on the appropriateness of the level of risks being run"
  • The above is supplemented by the following: "Responsibility for risk should not be delegated to risk management and control functions" - amen brother!
  • Third line of defence - "Internal Audit should provide independent assurance over firms' internal controls, risk management and governance"
  • Risk Appetite - "A firm's stated risk appetite is an important factor in determining whether a firm's risk and control framework is commensurate with [the] nature of its business, and should be both integral to a firm's strategy and at the heart of its risk management system" - not far off a direct quote from last year's Approach Paper on Banking Supervision (p22), though it has moved from "foundation" to "heart" in this Final Notice. I know what I prefer to build on!
  • "Clearly-defined strategy" - they list "well-defined objectives, responsibilities and milestones" as expected
  • Policies - "The establishment of appropriate policies [and procedures] governing the conduct of a firm's activities is an essential component in the exercise of appropriate organisation and control of a firm's business"
  • "Good risk management culture" (p7) - interestingly an expression most bodies have avoided using, preferring "sound" to "good". They later go on to talk of culture more generically in terms of "right" and "inappropriate" (p33).
Observations
  • Interestingly, Co-op Bank never refer to operating "3LOD" until their 2012 Annual Report (p56 for the boilerplate and clearly untrue definitions), so any deficiencies in the model before that year might be for a good reason!
  • First line management oversight was seen as "inadequate" and "inappropriate" (p12)
  • Their second line managers "...repeatedly voiced concerns" about headcount (p29), which weren't addressed until the back end of the period under scrutiny. Hard to think post-2007 it would be hard to justify reinforcing that area of the business, which perhaps says a lot about the entity's culture. 
  • Second line not monitoring adherence to policies (p29) - quite hard to conceive of nobody in the second line doing this!
  • A clear distinction made more than once between "Risk Management Framework Policies" and "adequate policies and procedures" relating to operational matters (p5)
  • Some of the failure to follow 'internal policies' seems to have been sponsored by the acquisition of the Britannia book - perhaps a natural by-product of M&A activity, where the cultures and modus operandi clash (p21)
  • Second line criticised for not providing proper "independent challenge" - happy to see this, given the focus tends to be on second line oversight, which always feels like a bit of a jib-job.
  • Third line giving the business credit for proposed remedial action in its audit reports (p31) - even taking this into account, they were rolling over around 30% of recommended actions in their reports as "overdue"!
  • Head of Internal Audit reported to the Head of Risk
  • An implication that one may be permitted shortcomings in one's internal control framework, providing one's culture is "appropriate" (p5). 
  • An interesting slant on reputational risk emerges from one of the accounting interpretations used, specifically that while assuming a particular accounting treatment (on the Leek notes in this case) which benefits the entity at the expense of counterparty might benefit the immediate balance sheet, the long-term effect on being able to raise new capital must be considered (p16)
  • External Auditors using a 1-to-7 scale to assess how punitive/liberal the accounting treatments used by clients are. These assessments have bitten this particular client on the bum, given the PRA quote them in the document in the context of whether they align with a "cautious" risk taker!
Open ended questions
  • Is "cautious" a realistic appetite for risk at Entity level? More importantly, if one has a "cautious" risk appetite, is one obliged to manage its capital "cautiously"?
  • Management information was criticised for not being "sufficiently forward looking" - should it be (as opposed to mostly summarising positions at a point in time)?
  • Is the PRA allocating resources to firms based on their Risk Appetite Statements (p13)?
  • Is it possible for non-Accounting experts working in the second line to identify just how many ropey interpretations of UK GAAP/IFRS are being applied to a balance sheet? Is it plausible to leave such work to external audit firms who couldn't have a more vested interest in the grey areas of such legislation? The artificial boosting of the balance sheet listed in this notice would be subtle enough to trick an accountant or two I'd bet!
  • Can quant risks be effectively managed in a separate team from the qualitative world? Appreciating there is a shockingly blurry line in Co-op Bank's approach (p29), it certainly feels like Solvency II pressures might lead to similar pressures on the staffing front, particularly for modellers and small/medium sized firms where staff may wear more than one hat.

Thursday, 27 November 2014

Approved Persons in UK under Solvency II - "SIMF-ly The Best"?

The UK prudential and conduct supervisors doubled-up this week with a barrage of paperwork regarding "Fit and Proper" assessment of senior staff members in Insurers under Solvency II.

This was already acknowledged as an area where intelligent copy-out wouldn't quite cut the mustard for UK plc, so no doubt the Compliance functions of insurance entities have been looking forward to these publications appearing. Given the light touch on the topic in the Directive (Art.42) and Delegated Acts (Art.273), this is very much welcome gristle.

Evidently "Proper" - but "Fit" enough?

While the maintream media has cranked out some comment already on both the FCA (here) and PRA approach (here, here and here), they are naturally broad with their brushes. I thought I would cut it up into my much more insular world of "what does it mean for Key Functions under Solvency II".



PRA Consultation Paper
  • The regulatory framework for individuals will be called the Senior Insurance Managers Regime (SIMR), and will come into force from 1st Jan 2016. 
  • The CP is targeted at ensuring fitness and propriety of individuals running an insurer, or performing a Key Function.
  • NED's have been left out of this paper, as there is a wealth of comment already provided on a separate joint FCA/PRA consultation from the Banking industry.
  • That said "...the regime for insurers should not be identical to the regime for banks". 
  • While Controlled Functions continues to exist as a PRA term, it will be interchangeable with the term Senior Insurance Management Functions ("SIMFs"), which I have used below.
Going into detail, we find the following;
  • CEO, CFO, CRO and Head of Internal Audit are all SIMFs, with Chief Actuary, WP Actuary and a couple of Lloyds-specific roles also lined up.
  • Some Group-specific SIMFs also created.
  • Any Solvency II "Key Function" holders who are not SIMFs will simply be assessed within the business, with the PRA having right to overturn. I thought this would include the Head of Compliance, but they are picked up by the FCA (below). Not sure who else could be Key Function but not a SIMF, unless some SIMF role-holders don't plan to also do a day job.
  • List of new Core Responsibilities provided which need to be allocated to one or more SIMFs (2.21). These include the old chestnuts of remuneration policy and "culture" in its broadest sense, as well as performance of ORSA.
  • A form will follow which needs to be completed by firms for all prospective SIMFs and Key Function holders containing "relevant information" on them - I suspect this will be a LinkedIn cut-and-paste job.
  • Obligation to make and maintain a "Governance Map" listing the positions and key functions which run the firm, the allocation of management responsibilities (including the new ones in 2.21 presumably) and relevant reporting lines. Oddly, the PRA think "...there will be some costs in compiling and maintaining the Governance Map", when it feels like a lazy Thursday morning for Company Secretarial to me...
  • Some reinforcement of Conduct standards for SIMFs and Key Function holders, with Key Function holders having an additional policyholder protection-related standard added to their armoury.
  • Emphasise that Fit and Proper needs to be assessed on an ongoing basis, as opposed to periodically, which effectively gives the regulator a get-out-of-jail when a bad apple SIMF mismanages a firm (i.e. "why didn't you pick it up internally first?").
  • Solvency II brings in a legal requirement for firms to satisfy themselves of a candidate's fitness and propriety before sending applications to the PRA. They therefore plan to assess whether firms recruitment processes are "appropriately rigorous", which feels like a step into the un-assessable (if that is even a word).
Proposed Supervisory Statements are appended to their document covering the assessment of fitness and propriety, and the application of new conduct standards. From those I would highlight;
  • "The norm" is for single individuals to perform SIMFs
  • That firms may add to the list of conventional Key Functions using a bullet-point checklist
  • Firms can "...freely decise how to organise each function in practice"
FCA Consultation Paper
  • The existing Approved Persons Regime will be adapted to fit Solvency II and PRA/EIOPA requirements, as well as existing application forms.
  • "Pre-approval" will therefore still exist in 2016.
  • While the PRA pick up approval of most Key Functions under Solvency II, the FCA keep hold of the approval of Compliance Function heads, which don't feature in the SIMF list.
  • Give themselves some leeway to impose approval and conduct obligations on "certain other functions" in insurers
  • Appear to be combing over conduct-related rules from their work with the banking industry
Frankly, the amount of crossover between prudential and conduct regulators, existing and new rulebooks, and banking and insurance industries, makes this particular topic an awkward read, which is why I don't work in Compliance!

Levity aside, the outcome of these consultation papers will have a significant effect on insurers existing onboarding and approval processes, content of executive job specifications, and indeed the fundamental operacy of governance systems, given the level of prescription involved. Now would be a good time to start briefing!

Monday, 30 September 2013

System of Governance - EIOPA's FINAL preparatory guidance for national supervisors

Based on feedback received since their initial consultation paper was released, EIOPA make the following generic clarifications/statements in the preamble of their guidance doc for System of Governance preparations;

  • That proportionality will not be defined or presented as examples in the guideline text (p5-6)
  • That NCAs are "expected to...review and evaluate the quality of the information provided to them" - bad news for the PRA, who were clinically uninterested in reviewing Solvency II reporting attempts according to one blogger (p6)
  • The emergence of a new ORSA acronym, "FLAOR", which looks more like something an amused teenager would write on Facebook (p6)
  • The expectation that 2015 will see submissions of (2014) ORSAs to NCAs (p7)
  • While there is no generic take on what enforcement action should take place in this interim period, firms are expected to (a) Discuss any negative findings from their ORSA/Governance systems with their supervisor, and (b) To produce SCRs using information of appropriate quality. Enforcement action in the absence of this WILL NOT consist of capital add-ons, apparently (p7)
  • That the submission date calendar for all of the information expected will be reviewed at the end of this year, so that EIOPA can take Omnibus II progress into account (p8)
  • That the explanatory text in each set of guidance is NOT part of "Comply or Explain" (p9)
  • That the reasons behind a negative "Comply or Explain" decision from any country will be kept secret as standard (p10, and disgraceful, frankly).
They then go on to focus on some of the larger bones of contention within the 52 guidelines provided. The following generic points stand out for me as a practitioner;
  1. There is almost no discernible movement in EIOPA's position, even after a volumous lobbying effort;
  2. That explanations for the inclusion of contentious content are generally forthcoming, though on a number of occasions, flimsy;
  3. That planning for 2014 full-year mothballing of Solvency II programmes is not an option, particularly for ICAS+ candidates - some may get away with a few months of inertia, depending on the quality of their paperwork (strategies, policies, process guides/maps, terms of reference, charters etc).
The following supporting arguments for EIOPA's final view were, in my mind at least, poorly formulated, regardless of whether the end result is still agreeable;

3.48 (Guideline 6)
- Refused to add more definition around what constitutes a "significant decision", which is poor form.

3.58 (All of Chapter III)
- That the expectations of Risk Management in insurers  "...comprise risk management standards which are considered to be matter-of-course and wide spread activities" - extraordinarily loose, considering the lack of a majority-accepted global, or indeed pan-European standard on the subject (IRM/ISO/COSO/FERMA/FSB's efforts notwithstanding)

3.65 (Guideline 19)
- That, while it is "not an easy task", Operational Risks should be quantifiable, and therefore subject to tolerance limits - I don't think it would have hurt to suggest (or even compel the use of) a method if it is that difficult.

3.68 (Guideline 25)
- That firms should maintain Investment Risk-related KRIs outside of what might be provided by normal parties (for example, ratings agencies), which would help "...increase overall risk management" - not entirely convinced that a generic "increase" is any kind of worthy ambition. 

3.74 (Guideline 31)
- That a capital management policy and capital management plan is both necessary (though for not entirely convincing reasons when tying back to the Directive)

3.78 (Chapter VI [Internal Control])
- That there is already plenty of clarification on what the Compliance function is charged with. I would agree in principle, but have heard evidence to the contrary in practice.

3.81 (Chapter VII [Internal Audit])
- That they neither wish to mandate or discourage rotation of Internal Audit staff or whistleblowing direct to NCAs - in which case, why mention it!

3.110
- A bizarre comment in response to a suggestion that a public statement should be released by the AMSB annually regarding the discharge of responsibilities around the system of governance that the Directive "...only deals with internal governance, not corporate governance" - think I know what they are fishing at, but terribly worded.

3.144
- Justify their decision not to define risk appetite and risk tolerance in the context of these guidelines

They have however provided some more defendable clarifications, for example;

3.51 (Guideline 11)
- Clarified that the gold-plated "Fit and Proper" requirements apply to AMSB/Control Function staff only, as well as specify what is expected from Outsourcers.

3.57 (Chapter III [Risk Management])
- That in the context of separating the duties of the Risk and Actuarial functions, the Directive is abundantly clear and that undertakings "...cannot deviate from [the Directive's] distribution of tasks"

3.62 (All "Policy"-related guidelines)
- That efforts should be targeted towards drafting the required documents during the preparatory phase. I would imagine this would be "re-working" in the UK, where such activity is most probably long done.

3.67 (Guideline 19)
- That there is no compulsion for firms to operate an electronic database to store operational risk events

3.85 (Chapter VIII [Actuarial])
- That, regardless of the absence of a valuation framework for TPs, the processes behind their co-ordination and calculation justify early activity, rather than "wait and see" on Pillar 1.

3.124
- Regarding Op Risk, activity will have to include "...identifying all operational risks that have crystallised and their near misses" (my emphasis)

Relatively easy in summary then - if it was a gap/issue in your system of governance in March, it probably still is, so go and fix it!

Monday, 9 September 2013

Deloitte on 'regulatory uncertainty in Europe' - embedding a new modus operandi (?)

In a wonderful example of predicting the present, Deloitte have released a white paper (sign-up required) giving their take on regulatory uncertainty in the European insurance industry, and how the volume of new regulations (and their inability to land on time) is driving emerging best practices in the consideration of regulatory risk at Board level.

New Modus Operandi - alloy wheels optional?
Of course, it is always best to wait for such matters to emerge before proselytising, and the current cup of omni-postponed over-elaborate regulations is running over (Sol II, IFRS 4 Phase II, FATCA, etc), naturally causing difficulties for all those responsible for preparing for them, as well as the execs who take the topics into the boardroom every quarter, only to say "it's been delayed again, can I have more money"...

From my perspective, it was particularly interesting to see that proactivity is recommended regardless of nature/scale/complexity, bearing in mind the first time I spoke to a Board of Directors at a tiny insurer regarding Solvency II preparations was in 2009 - only consultants could comfortably suggest that an new executive-level role is established, and Board agenda time is regularly set aside, only to explain the latest delays in multi-jurisdictional regulations (I certainly know what my old CEO would have said to that!)

That aside, they suggest that two major problems need to be overcome; that few insurers have a single view of regulatory risk; and that regulatory insight is poorly represented in the strategic workings of insurers, both of which are easy to agree with purely on circumstantial evidence.

Whilst this frequently reads like a paper written to justify bringing consultants in to compensate for failing in risk and compliance professionals' armoury, Deloitte make the following noteworthy assertions/recommendations in it;

Trends

  • That most insurers prefer to 'wait and see' rather than be 'first mover' when it comes to regulatory preparations - after the Solvency II experience, does that surprise anyone?
  • That "...Deloitte's view is that regulation can be regarded as a 'structural' driver of the insurance industry"
  • That "...Deloitte's considers a regulatory dividend can and should be sought", which is not necessarily my experience of consultancies when on site, who (presumably for legal reasons) prefer to promote a gold-plated complaince approach to regulation-driven projects.
  • Cost of compliance is now materially diluting return on equity in EU insurers
  • That Conduct Risk is likely to become high profile across Europe over a longer period of time than its current flavour of the month feel, thanks to IMD2/PRIPS/MIFID
  • National regulators are increasingly impeding on day-to-day running - examples given (all of which have a whiff of IMAP requirements about them), include documentation improvements and influencing risk appetite/capital allocation work.
Costs and volume

  • Regulation prep cost the European insurance industry €4.2-€4.7bn in 2012 - they go on to expand that to €8.1-€9.2bn over the last 3 years.
  • UK industry will be subject to 29 new pieces of legislation of the next 5 years (surprisingly lower than the French at 35, and the Germans at 32!)
  • That the "cost of doing nothing" while waiting for regulatory clarity may be significant - as significant as consultancy spend preparing for something which never arrives perhaps?
  • That compliance functions are naturally struggling to cope with the current volume of initiatives
Solvency II-specific
  • They extrapolate an estimated €550m cost of Solvency II compliance preparations in 2012 into a €1.5bn-€1.8bn 'top 40 insurers' number, and a €2.4-€2.9bn figure for the whole industry - feels a bit light, bearing in mind 'UK plc' must have done the best part of £1bn on Solvency II alone in 2012.
  • They quote one strategy director as saying that "Solvency II is killing European M&A..." - p10
Their recommendations (from p19) are too woolly in aggregate to help a normal practitioner - they are probably targeted more towards programme directors and managers - but the recommendation  to establish a Regulatory Assessment and Response Executive with a suitable remit is a smart idea, even if from a practical perspective this might need to either be balled in with the responsibilities of an existing executive, or only be a mid/senior management role, in smaller companies. 

These recommendations also include the marvellous suggestion to "embed a new modus operandi" - an expression normally reserved for profilers of serial killers, and perhaps the hardest sell since Isle of Man beach holidays.

PS I apparently missed the memo where the oft-ridiculed speech of Donald Rumsfeld used to support war against Iraq became de rigeur in risk management/insurance white papers. If there is one "known known" in this world, it is that I will never use that expression on the job!

Friday, 2 August 2013

Central Bank of Ireland - Corporate Governance Code refresh

The Irish approach to corporate governance in financial services, at least up until the onset of the financial crisis in 2006/07, resembled something of an all-you-can-grasp buffet for a select number of executive golf club pals and octogenarian ex-politico Non-Executive Directors (NEDs), having their voting arms operated a la Weekend at Bernies.

Ireland pre-2007 - Waking NED?
The new FSA-flavoured approach brought in by Matthew Elderfield in 2009 (elaborated on here) fortified by the findings of a devastating 2011 report summarising the truly horrid governance practices in the Irish banking industry, has led to a change of regulatory tack at the Central Bank of Ireland that represents the biggest volte-face in Europe since the Macarena.

Alongside PRISM, a piece of revolutionary work in the assessment of financial institutions by supervisory bodies, the CBoI also made substantial changes in areas such as Annual Compliance Statements, Fitness and Probity of directors, Risk Appetite Statements.

All of this ran off the back of Mr Elderfield's first major gig in 2010, a full revamp of the Corporate Governance Code, which could hitch a ride off the back of the work of the FSA and CEIOPS (at the time!) and deliver a more substantial suite of obligations to a cabal of directors who, after feasting on carrots for years, desperately needed the stick.

This makes the release of yesterday's consultation on the Corporate Governance code a touch baffling, as the ink is barely dry on 2010's effort - it perhaps reflects that the regulator has reached optimum staffing levels if they can review it so regularly! Having said that, the level of divergence from accepted CG practices in the UK was flagged by Grant Thornton back in 2011 as being substantial, so a point-in-time revamp should not be so unwelcome, regardless of the proximity to the last one, and of course, all of this activity was too late to prevent Quinn Insurance from going down.

They emphasise that this review takes into account developments in the Solvency II space, as well as on-the-ground experience and publications from other parties of interest. Of particular note was their emphasis that, where national regulations are not as stringent as relevant EU or international one (or indeed vice versa?), the most onerous one should be complied with. In a number of instances around corporate governance, this will mean the CBoI outranking Solvency II as the more onerous of the two!

While these are proposals rather than stitched-on changes at this point, the CBoI doesn't have a great track record for backtracking these days. Highlights for me were;

Risk Committees

  • Require a majority of NEDs on Risk Committees, and must be chaired by a NED
Committees in general
  • Require the Risk Committee and Audit Committee chairs to sit on each other's committees
  • Require the Remuneration Committee chair to sit on the Risk Committee
  • In High Impact firms, the Risk Committee and Audit Committee Chair may not be the same person
  • Must be at least 3 members of Risk Committees and Audit Committees
Chief Risk Officers
  • They note that it is "Generally accepted best practice" to have a CRO who, amongst other tasks, is charged with "...facilitating risk appetite setting by the Board". In addition;
  • All "High Impact" firms will be required to appoint a specialist CRO
  • Firms with a lower PRISM rating may have a CRO who is shared with another control function, "...provided that there is no conflict of interest between the two roles". Can't help but feel that this might rule out CRO/Chief Actuary dual roles, but allows for CRO/Head of Compliance and CRO/Head of Internal Audit, which would be to the chagrin of the Society of Actuaries in Ireland!
  • CRO to have direct access to the Chairman of the Board
Board Meeting frequency
  • Seem to acknowledge that the compulsory 11 meetings per year for High Impact firms may be a touch much, so are looking for comments
  • Also acknowledge that compulsory 1 meeting per calendar quarter is a bit constrictive for the smaller firms, so may relieve this to be pragmatic
Chairman and CEO
  • Some of the restrictions around number of roles held at any one time to be relieved for smaller firms, but seemingly only to populate inter-Group roles.
Board Diversity
  • Acknowledges that, while the debate in the EU is gender-centric, that diversity of all types is a worthy target for Boards, but falls short of compelling firms to do anything at national level, choosing to seek comments and wait for the supra-national activity to drive any compulsion. This seems to fit with the thinking of Irish directors published back in 2011 i.e. no "Golden Skirt" quotas.
Random
  • "...appropriate Risk Culture" makes its way in (6.3), perhaps cognisant of the FSB's proposals
  • Built in a piece which allows for video-conferencing rather than physical attendance at meetings (7.5)
  • Board responsibilities updated (13.1)
  • Compulsory Board skills matrix (14.9)

Monday, 18 February 2013

Munich Re on Solvency II Control Functions - an actuary for all seasons...

Munich Re have continued their infrequent-yet-valuable Solvency Knowledge Series with a piece on Key functions within the system of governance of insurers under Solvency II.

Of course to the grizzled old set of risk practitioners who have done the rounds for the last few years, the fundamentals of the directive's requirements on the four control functions are as basic as the ingredients list for a frozen lasagne. It naturally draws attention to the likelihood that there will be "some overlap" between the activities of Risk, Actuarial, Compliance and Internal Audit, as well as touching on outsourcing as "...an attractive way of meeting the wide range of requirements" for those

However I detected more than a whiff of controversy around the content of this particular publication (which I hasten to add is a smart read nevertheless), were one to take it at face value. In particular;
  • Their use of the three lines of defence model in the publication - while perceived to be good practice for segregating operations from risk advisory from risk assurance, it is certainly not cited in any existing materials at Level 1, 2 or 3, and the structure may be disproportionate at the small end of the insurer spectrum. On top of that is the Actuarial function's acknowledged dwelling over a grey area between the first and second lines, in particular if they haven't catered separately for the reporting lines of reserving, pricing and capital management actuaries (p8).
  • The comment that "The risk management function will no doubt have to include people with a professional scientific and mathematical background, ideally backed up by appropriate qualifications (eg actuaries)". Whilst, internal model or not, the Actuarial function will clearly have to provide "considerable support" to the Risk function, I don't see any reason at the small-to-medium level for the Risk function to include actuaries unless through choice, using the lever of proportionality.
  • That the Risk function "...shares responsibility for the risk strategy" - I think the implication is that it shares responsibility with the Board, but the statement doesn't help identify a) who authors and authorizes it and b) who gets fired for its poor deployment! I am more inclined to think the Risk function owns the risk management system and is responsible for monitoring and reporting on the implementation of the risk strategy which sits within it. The FSA define their requirements on this page in any case.
  • That the Risk function "...identify potential risks and recommend appropriate countermeasures to the Board" - as far as emerging risk/top-down risk assessment goes, I certainly expect the function to facilitate the emerging risk/scenario analysis/reverse stress test activities in this regard, but it is most certainly not a solo job.
  • That "The compliance function...will have to include staff with a legal background" - appreciating what the wording of Article 46 implies in particular, this is more a proportionality/outsourcing issue for me than anything. Having said that, I'm sure any existing compliance professionals out their who didn't take the Bar might feel slighted by this! 
  • That "all four functions have a direct reporting line to the Board" - not certain that this is so in the vast majority of cases. Certainly via Board committees the Risk and Internal Audit functions will be well catered for (and the FSB recommended even better than that for the Risk function last week), but I suspect an executive reporting line is as good as it gets for the other two functions in most firms.
Certainly plenty to engage the grey matt with regardless of your country of origin, even around control function crossover areas (which I presented on at the end of last year), so dig in.

Monday, 10 December 2012

Governance Matters at ILAG - Co-operation between control functions under Solvency II

Been a bit quiet on the Blog front - not because my country and I are licking our wounds after being opened up by HMRC like a Manx kipper, but because I had been asked to chip in with my two cents at an event hosted by the Investments and Life Assurance Group in London. It was an exceptionally well run event, with some interesting takes on the participation of Risk, Actuarial and Internal Audit functions in meeting not only the Directive requirements, but also the expectations of wider stakeholders and indeed policyholders.

My particular focus was on Control Function interaction, the inevitable areas of crossover and emerging skill gaps, and I also touched on some benchmarking papers as well.

My transcript is below and, conveniently enough, reads like a Blog Post. If you would like the slides with the script/hyperlinks embedded, either register with ILAG or drop me a line at allan@governance-matters.co.uk and I will send them on for the bargain price of...free!

________________________________________________________________________________


So back in my former life of BAU busy-ness, my interests in Control Function optimisation were generally led by budget (or lack of it), in particular;
     Professional standards – were there enough bodies, and were they sufficiently skilled or motivated, to perform the fundamentals required (bearing in mind corporate governance code reforms both in the UK (2010 changes BTW, not 2012’s!) and Ireland meant that some system of governance work had to jump the Solvency II queue regardless)
     Proportionality – would the lack of definition around the proportionality principle (Lloyds take a stab on p2) lead to companies being woefully underprepared once the national regulators inevitably bared their teeth post-2009. The impact of misinterpreting Article 41.2 genuinely put the fear in me!
     Multiple roles per person/outsourcing – Whilst some common sense calls were made at the smaller end by merging Risk and Compliance functions, the more operationally substantial calls around merging risk and actuarial functions, outsourcing internal audit/compliance advisory services and recently the march towards outsourcing independent model validation and data quality assessments all posed questions.
Of course, having now worked with one of the biggest, my natural curiosities are not piqued by the unavailability of resource and budget, more by the complexity of wading through the reams of opinion and material that large budgets generate! In particular, I have been monitoring;
     The ability to get bang for buck out of programme spend, with most Tier 1 firms having comfortable broken 3 figures despite, from a Pillar 2 perspective at least, having something akin to “textbook” governance systems at outset
     Whether the “Consultant writes/BAU implements” will be proven to be a successful method of preparing for Solvency II, or whether the plethora of Pillar 2 material outputs will, once unsupported by its transient authors, die a little death
     Control functions in Groups, and perceptions of which countries’ governance is considered superior/inferior in the world of supervisory colleges
But you lucky guys in the UK already have a decent amount of written word around what your control functions are up to, with GENPRU, INSPRU, SYSC, SUP and the Corporate Governance Code all building cases for functional remits and appropriate governance structures
     So we know our friendly actuarial function will be knocking out the sums which end up in our pricing and reserving worlds, produce the EV and capital calcs that (hopefully) keep the wolf from the door, thus quantifying any risks which lend themselves to being quantified, and all the while self-policing the suite of models, methodologies and assumptions that aid them in doing so…
     We know our compliance function will be focused on monitoring and assessing the effectiveness of an entity to comply with prevailing laws and regulations, at a micro and macro level…
     We know our beloved IA function will be assessing the effectiveness of risk management, internal controls and governance processes…
However, the one rather raggedy looking function out of the existing set up is my one, the humble Risk function! While SYSC21 has beefed up the significance of Risk in the prevailing regs, the other SYSC tasks attributed make it feel a bit powder puff functionally by comparison.
In fact, both Risk and Compliance don’t especially feel enormously catered for in the prevailing set up as opposed to Actuarial and IA – not sure whether this is due to the consistency of their development as professions dwelling in the more certain lines either side of the second or not, but it’s certainly my feel as an outsider looking in…
…but thanks to Sol II (or at least the veiled threat of its implementation before I retire), we are now looking at control functions in reasonably neat packages complete with instructions!
One of the biggest problems that I’m sure all present have easily surmounted over the last couple of years is the ambiguities in the language of the Directive and Implementing Measures.
As a man who is married to a wonderful French woman, I am used to following instructions, but of course we are frequently confronted with flowery language such as “covers”, “advises”, “provides an opinion”, “liaises”, which is a consultant’s dream come true, but doesn’t help BAU demarcate and co-operate with any great certainty.
That said, the long and short of it ends with;
Risk
Risk come out with a pretty wide-ranging remit which mostly sits in the FSA’s Dream Function world of advisory, co-ordination, challenge and monitoring, though its ability to monitor “the general risk profile” is clearly reliant on the Actuarial function. Not assuming all present are part of IMAP, but the big ownership piece comes of course with the Risk function taking on responsibility for compliance with the internal model requirements on its design, implementation, testing, validation, documentation and weakness and limitation reporting. Clearly a massive undertaking and, certainly at the small/medium end, not one that can be naturally chalked off with an existing compliment of staff.
Actuarial
Actuarial function requirements include requiring knowledge of actuarial and financial maths but leaving an “other standards” clause in to help out the less well-policed countries! They do also however get some wriggle room on responsibility where it would otherwise be assumed (at least by me!), and so ”co-ordinate” TP calcs, “express opinions” on reinsurance arrangements and the underwriting policy, or “contribute to” implementation of the risk management system.
Compliance
Compliance are not burdened with a laundry list of tasks as such, however to advise the AMSB on compliance with Solvency II is a pretty unenviable one (particularly now!). Perhaps the biggest challenge looking at the remit impartially is the depth and breadth of coverage that the function will need to provide, not just on Level 1, 2 and 3 and SOLPRU, but also be able to challenge the adequacy of the vastly expanded internal policy suite
Internal Audit
IA get the unimaginable luxury of having a relatively unchanged remit, particularly in this neck of the woods where risk-based internal auditing and planning is de rigeur.
Outsourcing
The aggression in the wording around the Outsourcing requirements suggests that the days of outsourcing control functions being a “write a cheque, then dusting-of-the-hands” job are at an end!

Now the legislative ambiguities just mentioned leave ample room for control function bun-fighting due to the inevitable crossovers of skillsets for certain tasks and, perhaps most pointedly, who takes precedence in such instances.
ORSA
Probably the biggest area of convergence and potential toe-stepping-on is of course the ORSA space (covered here on the blog) which in the crossover context it is more about who performs which sub-processes, under whose authority, and who “holds the pen” when collating the record of the ORSA performance.
More by process of elimination than by legislative direction, ORSA oversight seems to sit at the door of Risk, a concession even made by the SAI over in Dublin whilst simultaneously illustrating how little they are required in the ORSA Process! Is this therefore real or nominal oversight, or even worse, a PMO-type record collection role.
One other crossover area comes from the removal of the requirement (after pre-consultation) of an independent assessment of the ORSA Process – whilst losing the compulsion should be welcomed on principle, is there a danger that the IA function, through risk-based planning, may under or over-Audit the ORSA space? Just a thought...
Risk IMMMR/Advisory/Challenge
The world of risk identification/measurement/management/monitoring/reporting also becomes one with potential for friction, through the merger of the worlds of the Risk function’s qualitative risk register-type approach and the actuarial function’s established risk quantification methods, into what ultimately comprises the “general risk profile” as per the Directive text – one of the Big 4 suggested that the P&L Attribution is, for actuaries, “the real risk profile” for example, and perhaps some of you concur!
Regardless, the twin horrors of agreeing with Actuarial quantification methodologies for hard-to-quantify risks, while fostering a dependence on them for measurement, monitoring and reporting facilities around financial and insurance risks suggests more of a one-sided dependence rather than “close co-operation” between the functions.
Compliance risk
This works similarly for the world of compliance risk identification/assessment, nominally in the remit of the Compliance function - are they being dragged somewhere nearer the first line if they are producing this work for the Risk function? Just feels a bit blurry…
Emerging Risk
For emerging risks, my main concern is the robustness of the top-down/emerging risk identification process filtering its way into some quantified element within the ORSA and/or internal model – Risk is chalked down for identifying and assessing emerging risks, but their ultimate measurement isn’t catered for.
For internal Modellers
And into the internal model space, the “close co-operation” between the Risk and Actuarial functions, at firms big and small, has the potential to cause all manner of difficulties, in pure process efficiency terms as well as the cost implications of IMAP failure,. One CRO referred to this as having to “solve the risk management team/actuarial team conflict” in a recent presentation on model governance! Clearly though there is quite a gap to bridge between how this governance worked under ICA and the demands of Solvency II.
Establishing an “independent” team for regular validation, regardless of headcount seems to be something of a holy grail, with a growing trend towards “bringing someone in”, if only for the comfort of benchmarking against one’s neighbours. This also helps a company stay in line with Mr Cardoni from the FSA’s call that “individuals performing the validation must possess the necessary skills, knowledge, expertise and experience”, but does little for self-sufficiency, as well as leaving the Risk function with the job of relationship manager during validation exercises.
The approaches available for the Risk function to discharge its other responsibilities around the internal model requirements, in particular around model design and implementation, of course crossover into terra firma for the actuarial function – would be interesting to know how any modelers in the room have approached this, as a cursory sign-off from Risk on a suite of model development and implementation paperwork doesn’t feel in keeping with the spirit of the regs, though an IRM survey from March suggested at least 11 IMAP applicants were doing something along these lines!
So even if Sol II doesn’t directly ask for enhanced skill sets, we in all functions can all see the iceberg coming if we don’t fix up and look sharp. As ever, the most fascinating movements are in the actuarial space as they meander over towards the risk in what is lined up to be the biggest land grab since Enclosure!
There is certainly plenty of encouragement, in a profession which one of its own was happy to recently decry is “trained to deal principally in numbers and statistics”, to branch out into Risk, with the CERA qualification – “the most comprehensive and rigorous demonstration of ERM expertise available” – perhaps leading the way. While the profession is quick enough to highlight the weaknesses and limitations of an Actuarial CRO, does this additional qualification do enough to bridge the gap?
Certainly the GCAE suggest in their work that professional education may need further enhancement especially in relation to risk management. Over in Ireland however, the SAI are taking it one step further in their Strategic Plan for the profession, going as far as looking to partner up with a university to develop a risk programme for anyone “who wants to skill up quickly in the area”. Can’t say I’m sure what the rush is, other than opportunity knocking!
On the Risk front, the IRM were very quick to respond to the FSA’s Dream Function presentation back in April 11 with a vigorous defence of the appropriateness of non-Actuarial heads-of-risk, noting that the two professions were “extremely complimentary while different”, whilst mockingly emphasizing that the very concept of CERA highlighted that “Core [actuarial] qualifications do not give sufficiently broad training”.
That said, while the IRM have focused attention on some big ticket items such as Risk Appetite and Risk Culture  over the last 18 months, is it fair to say that training or certification touching on capital measurement and management, modeling, financial and insurance risks and their strategic application would have been a welcome addition to the qualification roster (notwithstanding what is available elsewhere through GARP’s FRM designation)? I rather embarrassingly had to answer a question from a colleague the other day about “how did you get qualified for Solvency II” – I won’t tell you how I answered!
For IA, there is a brave new world for anyone with the chops to upskill or expand their horizons. While the ever-moving implementation date maybe postpones any programme assurance work that IA could have picked up on the run-in to go-live, there is clearly an expectation at the FSA that they will contribute to activity such as internal model validation and data quality assessments, though I’m not seeing anything in the world of training to aid them in doing this (hence the consultancies are doing so well out of it I suspect!).
Deloitte do present a nice picture of some of the additional skills that IA may fall short on, in particular a natural aversion to covering non-Operational risks, despite their relatively higher contribution to the risk profile of insurers. One other thing I had in mind, knowing the IA profession’s predeliction for COSO was changes in the world of Insurer ERM since the last refreshes of COSO’s ERM work, particularly COSO’s latest take on risk assessment – instinctively feels like there may be some catch-up work to do in the IA field, but may be wrong.
For the compliance guys, is it fair to say that you already have your work cut out swallowing Level 1, 2 and 3 paperwork as well as any handbook changes which will emerge at the end of the PRA/FCA divorce. Interested to know if anyone getting roped into other activities!
The last thing I was going to mention was that, in the absence of rapid upskilling, and the wind-down/mothballing of organisation’s Solvency II Programmes, has anyone worked out whose BAU budgets any outsourcing will come out of for the next couple of years?
Moving on to how people are doing on the functional operation and indeed co-operation front, there is a reasonable amount of intel and ideas out there, which you may have clocked on its way through, but maybe makes a bit more sense in aggregate.
Risk function effectiveness
As far as Risk function effectiveness goes, the IRM straw-polled their Solvency II SIG this year, and identified some worrying trends from a Sol II readiness perspective, in particular;
Only half have their CRO communicating directly with the Board on risk matters – breathes some life into the quote from Axa’s Life CRO that risk management is too important to leave to the risk management department”…
     Nearly half said risk papers are "noted with a short discussion" at Boards
     A number of risks were not covered by the respondees' risk functions – ALM and strategic risk in particular
     Over half felt they had overlap with either Actuarial or Compliance, and a quarter with IA
     As mentioned before, a decent number of risk functions are not directly delivering documentation, testing and validation of the internal model.
     Half said the process of implementing Solvency II affects their ability to become relevant to the Board
The IRM also very recently performed a survey (with a reduced quantum due to the subject) on Internal Model Governance trends, which highlighted that;
     Risk is “responsible” for IM governance (with no exceptions in the survey), but Actuarial are “involved”, but with no further details
     And many respondents feel “real decisions” continue to be made outside of IM Governance framework, in particular around stress testing, back testing, model change and expert judgement – makes one wonder if an Actuarial CRO could counter that governance leakage?
Risk appetite design and application
There was a paper released by our hosts this year which emphasized the differences in design and implementation of Risk Appetite Frameworks between Risk and Actuarial functions, noting that a quant heavy actuarial approach gets more traction and quicker! This doesn’t augur well for the new ORSA world of “everything must be quantified”, as it is the qualitative risks that need the most attention.
Reporting lines
The world of reporting lines remains a pretty hot topic, with KPMG putting out a decent paper which recommended, amongst other things, that the Actuarial function should consider a formal demarcation between risk taking and risk assessing/measuring actuaries, which would negate the trend of shoehorning capital actuaries through the Head of Risk, keeping them all reporting through the AFH. They also added that at least half of the respondees were not yet at their desired end-state regarding the basic new Actuarial function requirements around underwriting and reinsurance adequacy opinion provision.
IM Validation
In the model validation space, as early as the end of last year we saw KPMG reporting that half of the IM production staff were also involved in the validation process, emphasizing the practical difficulties in functional separation whilst in Programme mode – would love to see how those numbers have moved since. 
Having seen the FSA’s feedback in May on what had been observed at that point in time (in particular that independence from model development and being “sufficiently competent” went hand in hand), one can imagine that IA’s role in the activity will be marginalized in future at the ongoing expense of bringing in the Big Guns every year.
Things a Risk function could be doing
And finally, while I have touched repeatedly on activities which a Risk function may find cannibalized by their ravenous Actuarial counterparts, as well as responsibilities bestowed upon it that it may not be equipped to discharge, I have seen a few pieces around activities that the Risk function would probably love to be doing more of, given half a chance.
A recent piece by Accenture got my engine running, around the future of data analytics – I definitely feel that, with the appropriate informational power at their hands, the risk function can provide a massively enhanced IMMMR and advisory services at little additional cost (the main cost of course already being sunk into data  quality and data warehousing projects independent of the function)
One lovely piece, pitched in the context of why Equitable failed, reads like a list of things a CRO should be focused on, such as NED ambivalence and underperformance, or executive hubris, while a Towers Watson presentation on prepping for the future draws out the most practical big ticket activities such as superior understanding of model weaknesses and limitations and tail risk, rather than a more general clutch at the full bag of responsibilities bestowed on the function by Sol II.
A research piece from the CII (sadly no longer free!) compliments that, suggesting that a “balance between modeling and judgement” must be struck by Risk departments in order to breath relevance into a function that the author was outspokenly critical of in his research.

Tuesday, 18 September 2012

USA and ORSA - Let's do it baby!

Promising sounds from across the pond, as the NAIC make some definitive movements (detail here and here) towards the inclusion of Own Risk and Solvency Assessments as part of their regulatory reporting package - difficult to find the exact paperwork, but the summary of what was tabled by the ORSA subgroup at their August jamboree is here, while a statement to cover their adoption of the Risk Management and Own Risk and Solvency Assessment model act is available here.

I have touched on the movement of the US towards production of ORSAs in earlier blog posts, including recently on the preparedness of firms to meet ORSA reporting requirements,

From another earlier post, I can see the 15 volunteer company pilot which was mooted at the start of the year ultimately became 13 companies by the conclusion of the pilot (no word on who started, but couldn't be bothered finishing!). According to the Clearwater information, only 8 participants ORSA Reports were considered "complete", this despite the NAIC providing an ORSA Manual from which to work from.

Is this ratio of incompleteness indicative of what the 27 EU national regulators are likely to encounter in 2014, or is the lack of prescriptive guidance at Level 1 and Level 2 handy in this regard (i.e. ORSA Supervisory Reports will be "passed" regardless of quality, and regulatory arbitrage is back on the agenda).

Either way, Clearwater also note that 2015 is looking like the most likely time for imposition of ORSA reporting, so the guys will still have time to borrow from our experiences, as we can from theirs - suggested improvements  from the NAIC's sub-group to the participants (none of which would hurt anyone in the ORSA space over here!) include;
  • Include a summary of “significant changes” from prior year
  • Provide additional detail regarding risk managers and compensation
  • Include additional stress testing, specifically for liquidity
 Looking forward to the sub-group's next report, the approach over there appears to be relatively easy to follow and well led, which I guess it can afford to be if it isn't masquerading as something other than a filing requirement...