Showing posts with label control functions. Show all posts
Showing posts with label control functions. Show all posts

Thursday, 27 November 2014

Approved Persons in UK under Solvency II - "SIMF-ly The Best"?

The UK prudential and conduct supervisors doubled-up this week with a barrage of paperwork regarding "Fit and Proper" assessment of senior staff members in Insurers under Solvency II.

This was already acknowledged as an area where intelligent copy-out wouldn't quite cut the mustard for UK plc, so no doubt the Compliance functions of insurance entities have been looking forward to these publications appearing. Given the light touch on the topic in the Directive (Art.42) and Delegated Acts (Art.273), this is very much welcome gristle.

Evidently "Proper" - but "Fit" enough?

While the maintream media has cranked out some comment already on both the FCA (here) and PRA approach (here, here and here), they are naturally broad with their brushes. I thought I would cut it up into my much more insular world of "what does it mean for Key Functions under Solvency II".



PRA Consultation Paper
  • The regulatory framework for individuals will be called the Senior Insurance Managers Regime (SIMR), and will come into force from 1st Jan 2016. 
  • The CP is targeted at ensuring fitness and propriety of individuals running an insurer, or performing a Key Function.
  • NED's have been left out of this paper, as there is a wealth of comment already provided on a separate joint FCA/PRA consultation from the Banking industry.
  • That said "...the regime for insurers should not be identical to the regime for banks". 
  • While Controlled Functions continues to exist as a PRA term, it will be interchangeable with the term Senior Insurance Management Functions ("SIMFs"), which I have used below.
Going into detail, we find the following;
  • CEO, CFO, CRO and Head of Internal Audit are all SIMFs, with Chief Actuary, WP Actuary and a couple of Lloyds-specific roles also lined up.
  • Some Group-specific SIMFs also created.
  • Any Solvency II "Key Function" holders who are not SIMFs will simply be assessed within the business, with the PRA having right to overturn. I thought this would include the Head of Compliance, but they are picked up by the FCA (below). Not sure who else could be Key Function but not a SIMF, unless some SIMF role-holders don't plan to also do a day job.
  • List of new Core Responsibilities provided which need to be allocated to one or more SIMFs (2.21). These include the old chestnuts of remuneration policy and "culture" in its broadest sense, as well as performance of ORSA.
  • A form will follow which needs to be completed by firms for all prospective SIMFs and Key Function holders containing "relevant information" on them - I suspect this will be a LinkedIn cut-and-paste job.
  • Obligation to make and maintain a "Governance Map" listing the positions and key functions which run the firm, the allocation of management responsibilities (including the new ones in 2.21 presumably) and relevant reporting lines. Oddly, the PRA think "...there will be some costs in compiling and maintaining the Governance Map", when it feels like a lazy Thursday morning for Company Secretarial to me...
  • Some reinforcement of Conduct standards for SIMFs and Key Function holders, with Key Function holders having an additional policyholder protection-related standard added to their armoury.
  • Emphasise that Fit and Proper needs to be assessed on an ongoing basis, as opposed to periodically, which effectively gives the regulator a get-out-of-jail when a bad apple SIMF mismanages a firm (i.e. "why didn't you pick it up internally first?").
  • Solvency II brings in a legal requirement for firms to satisfy themselves of a candidate's fitness and propriety before sending applications to the PRA. They therefore plan to assess whether firms recruitment processes are "appropriately rigorous", which feels like a step into the un-assessable (if that is even a word).
Proposed Supervisory Statements are appended to their document covering the assessment of fitness and propriety, and the application of new conduct standards. From those I would highlight;
  • "The norm" is for single individuals to perform SIMFs
  • That firms may add to the list of conventional Key Functions using a bullet-point checklist
  • Firms can "...freely decise how to organise each function in practice"
FCA Consultation Paper
  • The existing Approved Persons Regime will be adapted to fit Solvency II and PRA/EIOPA requirements, as well as existing application forms.
  • "Pre-approval" will therefore still exist in 2016.
  • While the PRA pick up approval of most Key Functions under Solvency II, the FCA keep hold of the approval of Compliance Function heads, which don't feature in the SIMF list.
  • Give themselves some leeway to impose approval and conduct obligations on "certain other functions" in insurers
  • Appear to be combing over conduct-related rules from their work with the banking industry
Frankly, the amount of crossover between prudential and conduct regulators, existing and new rulebooks, and banking and insurance industries, makes this particular topic an awkward read, which is why I don't work in Compliance!

Levity aside, the outcome of these consultation papers will have a significant effect on insurers existing onboarding and approval processes, content of executive job specifications, and indeed the fundamental operacy of governance systems, given the level of prescription involved. Now would be a good time to start briefing!

Tuesday, 22 October 2013

The PRA Consultation on EIOPA's Preparatory Guidance - priorities for 2014 and 2015

After 10 years, it's finally getting interesting - the PRA today have dropped out a consultation paper on applying EIOPA's preparatory guidelines to PRA-authorised firms (CP 9/13). You can get at the EIOPA materials through this post for convenience.

The content will, subject to any intense lobbying by industry, be adopted as a supervisory statement (section 233) to cover the 2014 and 2015 calendar years, with the expectation remaining that 2016 is our "go-live" date. It covers the following aspects of the preparatory phase;
  • The PRA's expectations of firms as they prepare for Solvency II;
  • The PRA's approach to implementing the guidelines; and
  • The PRA's interpretation of aspects of the guidelines.
They are at pains to highlight that these are "preparatory" guidelines, and provide the traditional spiel on "nature, scale and complexity", so incremental progress is to be expected during the period in question. What that means in practice is perhaps another thing - can you show measurable 'incremental progress' for materials which are only on an annual review cycle, for example? - but that aside, it's worth picking the bones out for your respective programmes, and perhaps most importantly, getting your feedback in by November 15th if you don't like it!

Perhaps the most noteworthy aspect of this CP is that in no way is it suggestive of the PRA rejecting any of EIOPA's guidance (remember, they have until the end of November to voice any protest). That of course makes preparatory work much easier to plan for, as the UK will seemingly be doing it all!

My thoughts on the specifics were as follows;


System of Governance (SOG)
  • Emphasise that the SFCR requirements around SOG are also catered for in EIOPA's work (3.7), so a smart move would be to factor that into your drafting plans during 2014
  • General governance requirements "largely consistent with SYSC", though individuals holding key functions might expect a personal visit in the next two years (3.10)
  • Similar position for Risk Management Systems (3.12), stressing the commonality of requirements with existing PRA obligations, but stressing in particular that firms should be "...including suitable mechanisms and methodology for connecting to their ORSAs and for carrying out regular stress and scenario tests" during the preparatory phase.
  • That Prudent Person Principle is not a new concept to the PRA, but firms would be expected to review investment strategies in line with PPP over the next couple of years. A concession is seemingly made regarding the provision and review of third-party data by investment functions for smaller firms. 
  • On the (new) requirement for a Capital Management Policy/Medium Term Capital Plan (3.16), they are not moving, despite the howls of protestation - "The PRA regards the development and implementation of such policies and plans as an integral part of sound risk and capital management for all firms, especially as their management and Boards assess the implications of the forthcoming Solvency II own funds and capital requirements"
  • On internal controls, they appear to be fishing for firms to analyse whether their existing framework is Solvency-II ready, and then piggy-back of that self-assessment (3.17)
  • Same for Internal Audit function readiness! (3.18)
  • Actuarial function get a more bespoke treatment (3.19), with all firms asked to "carefully consider" the functional structure to avoid conflicts of interest. They also reserve the right to "...review firms’ analysis of the areas required for improvement, and understand the actions the firm is taking to resolve these".
  • Outsourcing similarly gets additional treatment by the PRA (3.22), who are "particularly interested" in changes made specifically with Solvency II readiness in mind
Useful quotes
...the PRA articulates its expectations of firms in the preparatory period, including that firms should read, assess and implement the substantive provisions of the guidelines in order to achieve the intended outcomes (2.5)
The guidelines and this statement are designed to work towards a consistent and convergent approach in preparations for Solvency II and not its early implementation (2.6)
 The PRA expects firms, when asked, to be able to explain what governance changes they need to make to satisfy the guidelines, how they plan to make those changes, what progress there has been to date and any particular difficulties they face (3.4)
The PRA expects firms to be able to document their overall approach to outsourcing, including contingency plans in the event of a service provider failure, to ensure that the efficiency of the service remains unimpaired and uninterrupted. (3.22)
During the preparatory period, the work of the actuarial function will now focus on co-ordinating the calculation of technical provisions, providing an opinion on the underwriting policy and reinsurance arrangements and contributing to the development and performance of the internal model in the pre-application stage where relevant (3.19)
During the preparatory period, the PRA encourages firms to consider how to manage the transition to the new regime and to assess the impact on existing asset portfolios of Solvency II requirements. This need not necessarily mean that changes have to be made to firms’ investment strategies or portfolios but firms are encouraged to work on an incremental basis towards demonstrating that they meet the requirements of the PPP (3.14)
During the preparatory period firms should review their existing policy for assessing fitness and propriety and whether it needs updating in advance of Solvency II (3.11)

FLAOR/ORSA
  • PRA only planning to review assessments "...on a proportionate basis" during preparatory phase - they elaborate further by stating "Due to the high number of ORSAs which will be submitted, the PRA expects that it may have to stagger its review of these during the preparatory period in a way that is risk based and proportionate". Does that mean "Top Ten & Lloyds & IMAP" get the works, with everyone else getting a lite-touch?
  • Expectation that improvements are identifiable between the 2014 and 2015 FLAORs - the PRA will contact firms individually if they are within the threshold limits which enact guidelines 14-16.
  • On ORSA documentation, "...firms should recognise the need for effective documentation and record keeping", for both Policy and Report (4.7)
  • Note that the Board's involvement in ORSA is "...far more extensive than setting risk appetites and tolerances", and leave an open threat to go through Board packs/agendas to ensure this is the case (4.8)
  • Smaller firms get permission to use their internal ORSA Report as the ORSA Supervisory Report, provided it has enough detail. Larger/riskier firms may conversely be asked to supplement whatever they submit. (4.10)
  • PRA actually considering issuing a "summary sheet" to firms in order to help gather information consistently (4.11). Here comes the ORSA Template!
  • Expectation that 2014 projection work is done on existing basis, and 2015 (ideally) on Solvency II basis (4.15)
Useful quotes
The preparatory period is a time of development for firms in designing, compiling and trialling these assessments (4.3)
To help capture [ORSA] data and information in a consistent way from firms and facilitate review the PRA is considering whether it may be beneficial to provide a summary sheet to firms (4.11)
The PRA does not intend to prescribe when firms should submit their ORSA...Firms should inform the PRA when their ORSA will be submitted well in advance of the submission date (4.19)
The PRA expects the Board to play an active part at various stages, providing initial steering on how the ORSA should be designed and documented, challenging on risk identification and mitigation along the way and culminating in the Board approving and communicating the finished product. (4.8)
The PRA expects all firms to develop a qualitative process to develop an ORSA which can be documented and reviewed by the PRA in line with its overall proportionate approach.(4.6)

Submission of Information
  • Confirms that XBRL is required prior to 2016 as submission format for QRTs (5.7)
  • Suggest that policies and procedures around reporting in firms may need "potentially significant revision" in light of Solvency II. (5.15)
  • Rather obscurely, they write, "The PRA does not expect that preparatory reporting will be subject to a requirement for external audit but it may draw upon audited inputs" - as I recall the participation of external auditors in QRT-type reporting has been a massive bone of contention in Brussels (indicated within these IRSG comments from last year, but I'm sure there's a more recent story), but potentially not a welcome development.

Internal Model Pre-Application
  • They isolate the Model Change policy as an example of something which should already be tested for its appropriateness (6.5)
  • Still expect firms to come forward and brief them on "significant" changes during pre-application.
  • Surprisingly, very little else,
Useful quotes
...it is important that where models are sufficiently stable, firms are beginning to demonstrate their use and continue to refine their models with the benefits of experience (6.5)
I may fire some feedback in, but ultimately I suspect this lady is not for changing...



Monday, 30 September 2013

System of Governance - EIOPA's FINAL preparatory guidance for national supervisors

Based on feedback received since their initial consultation paper was released, EIOPA make the following generic clarifications/statements in the preamble of their guidance doc for System of Governance preparations;

  • That proportionality will not be defined or presented as examples in the guideline text (p5-6)
  • That NCAs are "expected to...review and evaluate the quality of the information provided to them" - bad news for the PRA, who were clinically uninterested in reviewing Solvency II reporting attempts according to one blogger (p6)
  • The emergence of a new ORSA acronym, "FLAOR", which looks more like something an amused teenager would write on Facebook (p6)
  • The expectation that 2015 will see submissions of (2014) ORSAs to NCAs (p7)
  • While there is no generic take on what enforcement action should take place in this interim period, firms are expected to (a) Discuss any negative findings from their ORSA/Governance systems with their supervisor, and (b) To produce SCRs using information of appropriate quality. Enforcement action in the absence of this WILL NOT consist of capital add-ons, apparently (p7)
  • That the submission date calendar for all of the information expected will be reviewed at the end of this year, so that EIOPA can take Omnibus II progress into account (p8)
  • That the explanatory text in each set of guidance is NOT part of "Comply or Explain" (p9)
  • That the reasons behind a negative "Comply or Explain" decision from any country will be kept secret as standard (p10, and disgraceful, frankly).
They then go on to focus on some of the larger bones of contention within the 52 guidelines provided. The following generic points stand out for me as a practitioner;
  1. There is almost no discernible movement in EIOPA's position, even after a volumous lobbying effort;
  2. That explanations for the inclusion of contentious content are generally forthcoming, though on a number of occasions, flimsy;
  3. That planning for 2014 full-year mothballing of Solvency II programmes is not an option, particularly for ICAS+ candidates - some may get away with a few months of inertia, depending on the quality of their paperwork (strategies, policies, process guides/maps, terms of reference, charters etc).
The following supporting arguments for EIOPA's final view were, in my mind at least, poorly formulated, regardless of whether the end result is still agreeable;

3.48 (Guideline 6)
- Refused to add more definition around what constitutes a "significant decision", which is poor form.

3.58 (All of Chapter III)
- That the expectations of Risk Management in insurers  "...comprise risk management standards which are considered to be matter-of-course and wide spread activities" - extraordinarily loose, considering the lack of a majority-accepted global, or indeed pan-European standard on the subject (IRM/ISO/COSO/FERMA/FSB's efforts notwithstanding)

3.65 (Guideline 19)
- That, while it is "not an easy task", Operational Risks should be quantifiable, and therefore subject to tolerance limits - I don't think it would have hurt to suggest (or even compel the use of) a method if it is that difficult.

3.68 (Guideline 25)
- That firms should maintain Investment Risk-related KRIs outside of what might be provided by normal parties (for example, ratings agencies), which would help "...increase overall risk management" - not entirely convinced that a generic "increase" is any kind of worthy ambition. 

3.74 (Guideline 31)
- That a capital management policy and capital management plan is both necessary (though for not entirely convincing reasons when tying back to the Directive)

3.78 (Chapter VI [Internal Control])
- That there is already plenty of clarification on what the Compliance function is charged with. I would agree in principle, but have heard evidence to the contrary in practice.

3.81 (Chapter VII [Internal Audit])
- That they neither wish to mandate or discourage rotation of Internal Audit staff or whistleblowing direct to NCAs - in which case, why mention it!

3.110
- A bizarre comment in response to a suggestion that a public statement should be released by the AMSB annually regarding the discharge of responsibilities around the system of governance that the Directive "...only deals with internal governance, not corporate governance" - think I know what they are fishing at, but terribly worded.

3.144
- Justify their decision not to define risk appetite and risk tolerance in the context of these guidelines

They have however provided some more defendable clarifications, for example;

3.51 (Guideline 11)
- Clarified that the gold-plated "Fit and Proper" requirements apply to AMSB/Control Function staff only, as well as specify what is expected from Outsourcers.

3.57 (Chapter III [Risk Management])
- That in the context of separating the duties of the Risk and Actuarial functions, the Directive is abundantly clear and that undertakings "...cannot deviate from [the Directive's] distribution of tasks"

3.62 (All "Policy"-related guidelines)
- That efforts should be targeted towards drafting the required documents during the preparatory phase. I would imagine this would be "re-working" in the UK, where such activity is most probably long done.

3.67 (Guideline 19)
- That there is no compulsion for firms to operate an electronic database to store operational risk events

3.85 (Chapter VIII [Actuarial])
- That, regardless of the absence of a valuation framework for TPs, the processes behind their co-ordination and calculation justify early activity, rather than "wait and see" on Pillar 1.

3.124
- Regarding Op Risk, activity will have to include "...identifying all operational risks that have crystallised and their near misses" (my emphasis)

Relatively easy in summary then - if it was a gap/issue in your system of governance in March, it probably still is, so go and fix it!

Sunday, 14 July 2013

Chartered Institute of Internal Auditors - final guidance on Effective Internal Audit for financial services

The Chartered Institute of Internal Auditors have followed up on their consultation earlier this year on Effective Internal Audit in the Financial Sector with this final set of recommendations.

Doesn't appear to have been any seismic changes as a result of the consultation, though the "need for proportionality" has been recognised, and clarification has been added that the content itself has not been mandated by the profession as best practice.

Interestingly, huge emphasis has been put on clarifying the primary role of Internal Audit as being the "protection" of a firms's assets, reputation and sustainability - does the profession feel well resourced and equipped to handle reputational defence? - while a few other elements sprung out at me;

  • A focus remains on IA challenging the "tone at the top", as if the expression now carries so much weight and definition that professional guidance can be hung from it.
  • "Risk Appetite" is again not defined, however IA are on the hook for assessing that it has been established and reviewed by senior management
  • Emphatically declares that "...the assurance map cannot be carved up between the Risk, Compliance and Internal Audit functions", stressing that IA will be expected to include the challenge of the work of other control functions in their audit plans
  • Built in some leeway around their earlier suggestion of compulsory attendance of IA function heads at Executive Committee meetings (ostensibly in order to understand strategy) - for insurers, one could anticipate that the advent of ORSA may take care of that knowledge gap 

Certainly the PRA/FCA have been fast to come out with support for the final version, so I guess all control functions had better make their peace with the content and prepare appropriately.

Thursday, 28 March 2013

EIOPA Preparatory Guidelines - System of Governance

Consultation on System of Governance preparatory guidance (plus explanatory text)

For a topic which has felt like a given for a number of years (certainly in UK and Ireland where we already ask a lot in this area), the System of Governance preparatory guidance is still 40 pages, comprising of 57 guidelines, accompanied by 60 pages of explanatory text.

A couple of things immediately grabbed at me when going through the guidance (again anticipating a conservative approach of the supervisors rolling over and applying all content as is)
  • That the Risk Management Policy (regardless of how one structures the component elements) is expected to contain procedure-level information about the management of each major risk category - this sounds hopelessly disproportionate, and almost impossible for supervisors to reasonably get through;
  • That it is "expected" that large or complex firms separate their four key control functions, and that others at the small/medium end may ultimately find it easier to do so than consider the range of controls/maintenance of independence required to have combined functions;
  • That an expectation that insurers' systems of governance require regular independent review, with the AMSB only retaining the ability to choose the performer;
  • That insurers will be expected to formally identify/analyse/report on Operational Risk Events
  • That EIOPA bottled out of defining Risk Appetite and Risk Tolerance, leaving national supervisors and insurers to fight it out amongst themselves.
Ultimately, the document reads like a checklist which practitioners or full-timers can run through against the suite of documentation no doubt already in existence which, if based on CEIOPS/EIOPA final advice and/or the Commission's Draft Level 2 measures, won't be miles away as it stands. On that premise, I've only listed elements which jump out for me.


GENERAL GOVERNANCE REQUIREMENTS

Guideline 3
  • Evidence should be collected of the AMSB "proactively" seeking information from committees/key functions
Guideline 5
  • No more detail than an expectation that the AMSB "appropriately implements" their key functions - in the explanatory text, it goes on to say that larger companies will be "expected" to fully separate Risk/Actuarial/Compliance/IA, with a series of measures expected to preserve functional independence if smaller companies choose to combine some.
Guideline 7
  • Expectation that both AMSB decisions, and how information generated from the Risk Management System (RMS) influences them, is "appropriately documented" - compulsion for Board Decision Logs?
Guideline 8
  • Regular System of Governance reviews appear to be expected, which are documented and reported back to the AMSB - the AMSB retains the right to choose who performs it 
Guideline 9 - All policies must include:
  • Goal of policy
  • Tasks to be performed and by whom (person or role, unlike for validation, where person/s was specified)
  • Associated processes and reporting procedures
  • Obligations of affected operational teams to inform control functions of "relevant facts" at all times
Guideline 10
  • Contingency plans are expected for areas which are "especially vulnerable" - this pushes outside of what one would consider a conventional contingency plan for operational emergencies.

FIT AND PROPER

Guideline 11
  • Must have a Fit and Proper persons policy
  • It must be equally applicable to both hired staff and outsourced functions

RISK MANAGEMENT

Guideline 15 - AMSB is "ultimately responsible" for:
  • RMS effectiveness
  • Setting Risk Appetite and Risk Tolerance Limits
  • Approving Risk Management strategies and policies
Guideline 16 - Risk Management Policy must cover at least
  • Risk categories used and measurement methods
  • How each category/grouping of risks is managed
  • Risk tolerance limits for all categories in line with Risk Appetite
  • Linkage of both SCR and ORSA to risk tolerance limits
  • Frequency and content of regular stress tests, and circumstances for additional testing
In addition, the associated guidelines touch on the risk categories within one's Risk Management Policy. There is an expectation for pretty much every category that procedure-level information is included in the policy documents themselves, as well as hard limits, which is unlikely to be the case as it stands.

Guideline 18 - Insurance Risk Policy
  • Expected to cover types of acceptable insurance risks, how premiums will cover claims/expenses, as well as how product design accounts for investment restrictions and formal risk mitigation techniques
Guideline 19 - Op Risk Policy
  • Expectation that Operation Risk Events will be formally identified/analysed/reported in insurers, and that a system for collecting and monitoring them should be in place.
  • Operational Risk Scenarios should be developed and used, based on failures of key persons/processes/systems and external events
Guideline 23 - Investment Risk Policy
  • Buzzphrase introduced of managing the level of "security, quality, liquidity, profitability and availability" of one's asset portfolio

OWN FUND REQUIREMENTS AND THE SYSTEM OF GOVERNANCE

Guideline 32
  • Concept of a "medium term capital management plan" introduced which covers; planned capital issuances, maturities and distribution policies - not sure how that works for mutuals, but I can see what they're fishing for

INTERNAL CONTROLS

Guideline 33
  • "All personnel [should be] aware of their role in the Internal Control system
  • The Internal Control system should be "commensurate to the risks arising from the activities and processed to be controlled" - this line should hopefully avoid overkill

INTERNAL AUDIT FUNCTION

Guideline 36
  • The Internal Audit policy should include the procedure for informing supervisors [of whistleblowing-level wrongdoing I guess]

ACTUARIAL FUNCTION

Guideline 44
  • "Material"deviations of Best Estimate Liabilities should be back-tested for by the Actuarial function, reported on, and remedial changes proposed
Guideline 46
  • The Actuarial function is expected to "contribute to" specifying the risk coverage in the internal model, as well as the dependency structure - this feels like areas where, even in larger insurers, the function probably already leads, so will they be asked to take a step back?

Monday, 18 February 2013

Munich Re on Solvency II Control Functions - an actuary for all seasons...

Munich Re have continued their infrequent-yet-valuable Solvency Knowledge Series with a piece on Key functions within the system of governance of insurers under Solvency II.

Of course to the grizzled old set of risk practitioners who have done the rounds for the last few years, the fundamentals of the directive's requirements on the four control functions are as basic as the ingredients list for a frozen lasagne. It naturally draws attention to the likelihood that there will be "some overlap" between the activities of Risk, Actuarial, Compliance and Internal Audit, as well as touching on outsourcing as "...an attractive way of meeting the wide range of requirements" for those

However I detected more than a whiff of controversy around the content of this particular publication (which I hasten to add is a smart read nevertheless), were one to take it at face value. In particular;
  • Their use of the three lines of defence model in the publication - while perceived to be good practice for segregating operations from risk advisory from risk assurance, it is certainly not cited in any existing materials at Level 1, 2 or 3, and the structure may be disproportionate at the small end of the insurer spectrum. On top of that is the Actuarial function's acknowledged dwelling over a grey area between the first and second lines, in particular if they haven't catered separately for the reporting lines of reserving, pricing and capital management actuaries (p8).
  • The comment that "The risk management function will no doubt have to include people with a professional scientific and mathematical background, ideally backed up by appropriate qualifications (eg actuaries)". Whilst, internal model or not, the Actuarial function will clearly have to provide "considerable support" to the Risk function, I don't see any reason at the small-to-medium level for the Risk function to include actuaries unless through choice, using the lever of proportionality.
  • That the Risk function "...shares responsibility for the risk strategy" - I think the implication is that it shares responsibility with the Board, but the statement doesn't help identify a) who authors and authorizes it and b) who gets fired for its poor deployment! I am more inclined to think the Risk function owns the risk management system and is responsible for monitoring and reporting on the implementation of the risk strategy which sits within it. The FSA define their requirements on this page in any case.
  • That the Risk function "...identify potential risks and recommend appropriate countermeasures to the Board" - as far as emerging risk/top-down risk assessment goes, I certainly expect the function to facilitate the emerging risk/scenario analysis/reverse stress test activities in this regard, but it is most certainly not a solo job.
  • That "The compliance function...will have to include staff with a legal background" - appreciating what the wording of Article 46 implies in particular, this is more a proportionality/outsourcing issue for me than anything. Having said that, I'm sure any existing compliance professionals out their who didn't take the Bar might feel slighted by this! 
  • That "all four functions have a direct reporting line to the Board" - not certain that this is so in the vast majority of cases. Certainly via Board committees the Risk and Internal Audit functions will be well catered for (and the FSB recommended even better than that for the Risk function last week), but I suspect an executive reporting line is as good as it gets for the other two functions in most firms.
Certainly plenty to engage the grey matt with regardless of your country of origin, even around control function crossover areas (which I presented on at the end of last year), so dig in.

Friday, 15 February 2013

Chartered Institute of Internal Auditors - recommendations for UK financial services

The Chartered Institute of Internal Auditors recently created a sub-committee to provide professional guidance "...designed to be a benchmark for effective internal audit in financial services in the UK", and they have just reported back with this feast of fun, which is a vital read for anyone working in control functions within financial services. The opinions they have used to create this guidance have been purloined not only from the profession itself, but also from other professions, regulatory bodies and executive/non-executive directors

They note in summary that there is "strong support for an unrestricted scope for internal audit", while drawing attention to disparity of opinion around matters such as: IA directly challenging strategy; IA reporting to Risk Committees (rather than audit committees) in certain instances; compulsory attendance of Chief Internal Auditors at Executive Committees; and the direction of managerial reporting lines.

The proposed guidance reads very much like the Corporate Governance Code, and is relatively light. It is broken into the following sections, where I have noted anything I found new or controversial alongside (my focus being predominantly scope creep into the Risk function's activity):

  1. Role and Mandate of IA - increased focus on risk assessment and risk coverage adequacy
  2. Scope and Priorities of IA - unrestricted scope ultimately advised; expected to "independently determine" key risks, and assess "the setting of, and adherence to, risk appetite"; assess the "risk and control culture"; allows for potential involvement of IA on "real time basis" in key corporate events (mergers, disposals, new lines of business etc)
  3. Reporting results - factors in reporting obligations to both Risk and Audit Committees where appropriate, and builds in an expectation of an annual independent assessment of governance (which covers off one of the FSB's recommendations covered yesterday!)
  4. Interaction with Risk, Compliance and Finance functions - nothing new
  5. Independence and Authority - Chief Internal Auditor expected to be executive committee-equivalent, have the right to attend Excom, access to all MI, and report directly to either the Chairman of the Board, Audit Committee or at a push, Risk Committee. A secondary line to an executive director should only go to CEO
  6. Resources - all resourcing decisions effectively divorced from the business, to reside with the Chief Internal Auditor and the Audit Committee
  7. Quality assessment - external assessment of the function recommended periodically.
  8. Relationships with regulators - nothing new
  9. Wider considerations - expectation that the "tone at the top" of a firm should be what fosters acceptance of IA
Any controversy? Perhaps around the seniority of the Chief Internal Auditor, and their assessment of the setting of and adherence to Risk Appetite. I think my main concern as a risk practitioner would be the potential for differences of opinion around what constitutes "adequate" risk management, given the Internal Audit predeliction for COSO on all things risk-related, against the IRM or ISO31000. 

Let battle commence?

Monday, 10 December 2012

Governance Matters at ILAG - Co-operation between control functions under Solvency II

Been a bit quiet on the Blog front - not because my country and I are licking our wounds after being opened up by HMRC like a Manx kipper, but because I had been asked to chip in with my two cents at an event hosted by the Investments and Life Assurance Group in London. It was an exceptionally well run event, with some interesting takes on the participation of Risk, Actuarial and Internal Audit functions in meeting not only the Directive requirements, but also the expectations of wider stakeholders and indeed policyholders.

My particular focus was on Control Function interaction, the inevitable areas of crossover and emerging skill gaps, and I also touched on some benchmarking papers as well.

My transcript is below and, conveniently enough, reads like a Blog Post. If you would like the slides with the script/hyperlinks embedded, either register with ILAG or drop me a line at allan@governance-matters.co.uk and I will send them on for the bargain price of...free!

________________________________________________________________________________


So back in my former life of BAU busy-ness, my interests in Control Function optimisation were generally led by budget (or lack of it), in particular;
     Professional standards – were there enough bodies, and were they sufficiently skilled or motivated, to perform the fundamentals required (bearing in mind corporate governance code reforms both in the UK (2010 changes BTW, not 2012’s!) and Ireland meant that some system of governance work had to jump the Solvency II queue regardless)
     Proportionality – would the lack of definition around the proportionality principle (Lloyds take a stab on p2) lead to companies being woefully underprepared once the national regulators inevitably bared their teeth post-2009. The impact of misinterpreting Article 41.2 genuinely put the fear in me!
     Multiple roles per person/outsourcing – Whilst some common sense calls were made at the smaller end by merging Risk and Compliance functions, the more operationally substantial calls around merging risk and actuarial functions, outsourcing internal audit/compliance advisory services and recently the march towards outsourcing independent model validation and data quality assessments all posed questions.
Of course, having now worked with one of the biggest, my natural curiosities are not piqued by the unavailability of resource and budget, more by the complexity of wading through the reams of opinion and material that large budgets generate! In particular, I have been monitoring;
     The ability to get bang for buck out of programme spend, with most Tier 1 firms having comfortable broken 3 figures despite, from a Pillar 2 perspective at least, having something akin to “textbook” governance systems at outset
     Whether the “Consultant writes/BAU implements” will be proven to be a successful method of preparing for Solvency II, or whether the plethora of Pillar 2 material outputs will, once unsupported by its transient authors, die a little death
     Control functions in Groups, and perceptions of which countries’ governance is considered superior/inferior in the world of supervisory colleges
But you lucky guys in the UK already have a decent amount of written word around what your control functions are up to, with GENPRU, INSPRU, SYSC, SUP and the Corporate Governance Code all building cases for functional remits and appropriate governance structures
     So we know our friendly actuarial function will be knocking out the sums which end up in our pricing and reserving worlds, produce the EV and capital calcs that (hopefully) keep the wolf from the door, thus quantifying any risks which lend themselves to being quantified, and all the while self-policing the suite of models, methodologies and assumptions that aid them in doing so…
     We know our compliance function will be focused on monitoring and assessing the effectiveness of an entity to comply with prevailing laws and regulations, at a micro and macro level…
     We know our beloved IA function will be assessing the effectiveness of risk management, internal controls and governance processes…
However, the one rather raggedy looking function out of the existing set up is my one, the humble Risk function! While SYSC21 has beefed up the significance of Risk in the prevailing regs, the other SYSC tasks attributed make it feel a bit powder puff functionally by comparison.
In fact, both Risk and Compliance don’t especially feel enormously catered for in the prevailing set up as opposed to Actuarial and IA – not sure whether this is due to the consistency of their development as professions dwelling in the more certain lines either side of the second or not, but it’s certainly my feel as an outsider looking in…
…but thanks to Sol II (or at least the veiled threat of its implementation before I retire), we are now looking at control functions in reasonably neat packages complete with instructions!
One of the biggest problems that I’m sure all present have easily surmounted over the last couple of years is the ambiguities in the language of the Directive and Implementing Measures.
As a man who is married to a wonderful French woman, I am used to following instructions, but of course we are frequently confronted with flowery language such as “covers”, “advises”, “provides an opinion”, “liaises”, which is a consultant’s dream come true, but doesn’t help BAU demarcate and co-operate with any great certainty.
That said, the long and short of it ends with;
Risk
Risk come out with a pretty wide-ranging remit which mostly sits in the FSA’s Dream Function world of advisory, co-ordination, challenge and monitoring, though its ability to monitor “the general risk profile” is clearly reliant on the Actuarial function. Not assuming all present are part of IMAP, but the big ownership piece comes of course with the Risk function taking on responsibility for compliance with the internal model requirements on its design, implementation, testing, validation, documentation and weakness and limitation reporting. Clearly a massive undertaking and, certainly at the small/medium end, not one that can be naturally chalked off with an existing compliment of staff.
Actuarial
Actuarial function requirements include requiring knowledge of actuarial and financial maths but leaving an “other standards” clause in to help out the less well-policed countries! They do also however get some wriggle room on responsibility where it would otherwise be assumed (at least by me!), and so ”co-ordinate” TP calcs, “express opinions” on reinsurance arrangements and the underwriting policy, or “contribute to” implementation of the risk management system.
Compliance
Compliance are not burdened with a laundry list of tasks as such, however to advise the AMSB on compliance with Solvency II is a pretty unenviable one (particularly now!). Perhaps the biggest challenge looking at the remit impartially is the depth and breadth of coverage that the function will need to provide, not just on Level 1, 2 and 3 and SOLPRU, but also be able to challenge the adequacy of the vastly expanded internal policy suite
Internal Audit
IA get the unimaginable luxury of having a relatively unchanged remit, particularly in this neck of the woods where risk-based internal auditing and planning is de rigeur.
Outsourcing
The aggression in the wording around the Outsourcing requirements suggests that the days of outsourcing control functions being a “write a cheque, then dusting-of-the-hands” job are at an end!

Now the legislative ambiguities just mentioned leave ample room for control function bun-fighting due to the inevitable crossovers of skillsets for certain tasks and, perhaps most pointedly, who takes precedence in such instances.
ORSA
Probably the biggest area of convergence and potential toe-stepping-on is of course the ORSA space (covered here on the blog) which in the crossover context it is more about who performs which sub-processes, under whose authority, and who “holds the pen” when collating the record of the ORSA performance.
More by process of elimination than by legislative direction, ORSA oversight seems to sit at the door of Risk, a concession even made by the SAI over in Dublin whilst simultaneously illustrating how little they are required in the ORSA Process! Is this therefore real or nominal oversight, or even worse, a PMO-type record collection role.
One other crossover area comes from the removal of the requirement (after pre-consultation) of an independent assessment of the ORSA Process – whilst losing the compulsion should be welcomed on principle, is there a danger that the IA function, through risk-based planning, may under or over-Audit the ORSA space? Just a thought...
Risk IMMMR/Advisory/Challenge
The world of risk identification/measurement/management/monitoring/reporting also becomes one with potential for friction, through the merger of the worlds of the Risk function’s qualitative risk register-type approach and the actuarial function’s established risk quantification methods, into what ultimately comprises the “general risk profile” as per the Directive text – one of the Big 4 suggested that the P&L Attribution is, for actuaries, “the real risk profile” for example, and perhaps some of you concur!
Regardless, the twin horrors of agreeing with Actuarial quantification methodologies for hard-to-quantify risks, while fostering a dependence on them for measurement, monitoring and reporting facilities around financial and insurance risks suggests more of a one-sided dependence rather than “close co-operation” between the functions.
Compliance risk
This works similarly for the world of compliance risk identification/assessment, nominally in the remit of the Compliance function - are they being dragged somewhere nearer the first line if they are producing this work for the Risk function? Just feels a bit blurry…
Emerging Risk
For emerging risks, my main concern is the robustness of the top-down/emerging risk identification process filtering its way into some quantified element within the ORSA and/or internal model – Risk is chalked down for identifying and assessing emerging risks, but their ultimate measurement isn’t catered for.
For internal Modellers
And into the internal model space, the “close co-operation” between the Risk and Actuarial functions, at firms big and small, has the potential to cause all manner of difficulties, in pure process efficiency terms as well as the cost implications of IMAP failure,. One CRO referred to this as having to “solve the risk management team/actuarial team conflict” in a recent presentation on model governance! Clearly though there is quite a gap to bridge between how this governance worked under ICA and the demands of Solvency II.
Establishing an “independent” team for regular validation, regardless of headcount seems to be something of a holy grail, with a growing trend towards “bringing someone in”, if only for the comfort of benchmarking against one’s neighbours. This also helps a company stay in line with Mr Cardoni from the FSA’s call that “individuals performing the validation must possess the necessary skills, knowledge, expertise and experience”, but does little for self-sufficiency, as well as leaving the Risk function with the job of relationship manager during validation exercises.
The approaches available for the Risk function to discharge its other responsibilities around the internal model requirements, in particular around model design and implementation, of course crossover into terra firma for the actuarial function – would be interesting to know how any modelers in the room have approached this, as a cursory sign-off from Risk on a suite of model development and implementation paperwork doesn’t feel in keeping with the spirit of the regs, though an IRM survey from March suggested at least 11 IMAP applicants were doing something along these lines!
So even if Sol II doesn’t directly ask for enhanced skill sets, we in all functions can all see the iceberg coming if we don’t fix up and look sharp. As ever, the most fascinating movements are in the actuarial space as they meander over towards the risk in what is lined up to be the biggest land grab since Enclosure!
There is certainly plenty of encouragement, in a profession which one of its own was happy to recently decry is “trained to deal principally in numbers and statistics”, to branch out into Risk, with the CERA qualification – “the most comprehensive and rigorous demonstration of ERM expertise available” – perhaps leading the way. While the profession is quick enough to highlight the weaknesses and limitations of an Actuarial CRO, does this additional qualification do enough to bridge the gap?
Certainly the GCAE suggest in their work that professional education may need further enhancement especially in relation to risk management. Over in Ireland however, the SAI are taking it one step further in their Strategic Plan for the profession, going as far as looking to partner up with a university to develop a risk programme for anyone “who wants to skill up quickly in the area”. Can’t say I’m sure what the rush is, other than opportunity knocking!
On the Risk front, the IRM were very quick to respond to the FSA’s Dream Function presentation back in April 11 with a vigorous defence of the appropriateness of non-Actuarial heads-of-risk, noting that the two professions were “extremely complimentary while different”, whilst mockingly emphasizing that the very concept of CERA highlighted that “Core [actuarial] qualifications do not give sufficiently broad training”.
That said, while the IRM have focused attention on some big ticket items such as Risk Appetite and Risk Culture  over the last 18 months, is it fair to say that training or certification touching on capital measurement and management, modeling, financial and insurance risks and their strategic application would have been a welcome addition to the qualification roster (notwithstanding what is available elsewhere through GARP’s FRM designation)? I rather embarrassingly had to answer a question from a colleague the other day about “how did you get qualified for Solvency II” – I won’t tell you how I answered!
For IA, there is a brave new world for anyone with the chops to upskill or expand their horizons. While the ever-moving implementation date maybe postpones any programme assurance work that IA could have picked up on the run-in to go-live, there is clearly an expectation at the FSA that they will contribute to activity such as internal model validation and data quality assessments, though I’m not seeing anything in the world of training to aid them in doing this (hence the consultancies are doing so well out of it I suspect!).
Deloitte do present a nice picture of some of the additional skills that IA may fall short on, in particular a natural aversion to covering non-Operational risks, despite their relatively higher contribution to the risk profile of insurers. One other thing I had in mind, knowing the IA profession’s predeliction for COSO was changes in the world of Insurer ERM since the last refreshes of COSO’s ERM work, particularly COSO’s latest take on risk assessment – instinctively feels like there may be some catch-up work to do in the IA field, but may be wrong.
For the compliance guys, is it fair to say that you already have your work cut out swallowing Level 1, 2 and 3 paperwork as well as any handbook changes which will emerge at the end of the PRA/FCA divorce. Interested to know if anyone getting roped into other activities!
The last thing I was going to mention was that, in the absence of rapid upskilling, and the wind-down/mothballing of organisation’s Solvency II Programmes, has anyone worked out whose BAU budgets any outsourcing will come out of for the next couple of years?
Moving on to how people are doing on the functional operation and indeed co-operation front, there is a reasonable amount of intel and ideas out there, which you may have clocked on its way through, but maybe makes a bit more sense in aggregate.
Risk function effectiveness
As far as Risk function effectiveness goes, the IRM straw-polled their Solvency II SIG this year, and identified some worrying trends from a Sol II readiness perspective, in particular;
Only half have their CRO communicating directly with the Board on risk matters – breathes some life into the quote from Axa’s Life CRO that risk management is too important to leave to the risk management department”…
     Nearly half said risk papers are "noted with a short discussion" at Boards
     A number of risks were not covered by the respondees' risk functions – ALM and strategic risk in particular
     Over half felt they had overlap with either Actuarial or Compliance, and a quarter with IA
     As mentioned before, a decent number of risk functions are not directly delivering documentation, testing and validation of the internal model.
     Half said the process of implementing Solvency II affects their ability to become relevant to the Board
The IRM also very recently performed a survey (with a reduced quantum due to the subject) on Internal Model Governance trends, which highlighted that;
     Risk is “responsible” for IM governance (with no exceptions in the survey), but Actuarial are “involved”, but with no further details
     And many respondents feel “real decisions” continue to be made outside of IM Governance framework, in particular around stress testing, back testing, model change and expert judgement – makes one wonder if an Actuarial CRO could counter that governance leakage?
Risk appetite design and application
There was a paper released by our hosts this year which emphasized the differences in design and implementation of Risk Appetite Frameworks between Risk and Actuarial functions, noting that a quant heavy actuarial approach gets more traction and quicker! This doesn’t augur well for the new ORSA world of “everything must be quantified”, as it is the qualitative risks that need the most attention.
Reporting lines
The world of reporting lines remains a pretty hot topic, with KPMG putting out a decent paper which recommended, amongst other things, that the Actuarial function should consider a formal demarcation between risk taking and risk assessing/measuring actuaries, which would negate the trend of shoehorning capital actuaries through the Head of Risk, keeping them all reporting through the AFH. They also added that at least half of the respondees were not yet at their desired end-state regarding the basic new Actuarial function requirements around underwriting and reinsurance adequacy opinion provision.
IM Validation
In the model validation space, as early as the end of last year we saw KPMG reporting that half of the IM production staff were also involved in the validation process, emphasizing the practical difficulties in functional separation whilst in Programme mode – would love to see how those numbers have moved since. 
Having seen the FSA’s feedback in May on what had been observed at that point in time (in particular that independence from model development and being “sufficiently competent” went hand in hand), one can imagine that IA’s role in the activity will be marginalized in future at the ongoing expense of bringing in the Big Guns every year.
Things a Risk function could be doing
And finally, while I have touched repeatedly on activities which a Risk function may find cannibalized by their ravenous Actuarial counterparts, as well as responsibilities bestowed upon it that it may not be equipped to discharge, I have seen a few pieces around activities that the Risk function would probably love to be doing more of, given half a chance.
A recent piece by Accenture got my engine running, around the future of data analytics – I definitely feel that, with the appropriate informational power at their hands, the risk function can provide a massively enhanced IMMMR and advisory services at little additional cost (the main cost of course already being sunk into data  quality and data warehousing projects independent of the function)
One lovely piece, pitched in the context of why Equitable failed, reads like a list of things a CRO should be focused on, such as NED ambivalence and underperformance, or executive hubris, while a Towers Watson presentation on prepping for the future draws out the most practical big ticket activities such as superior understanding of model weaknesses and limitations and tail risk, rather than a more general clutch at the full bag of responsibilities bestowed on the function by Sol II.
A research piece from the CII (sadly no longer free!) compliments that, suggesting that a “balance between modeling and judgement” must be struck by Risk departments in order to breath relevance into a function that the author was outspokenly critical of in his research.