Showing posts with label internal control. Show all posts
Showing posts with label internal control. Show all posts

Wednesday, 20 November 2013

Fit and Proper Persons in financial services - judge not, lest ye be judged

A quick note on the high-profile leadership-related crises which have reared their heads over the last couple of weeks, and whether the risk management professionals of the world can learn from them.

Two stories related to the flip-side of the kind of driven, charismatic figures that can progress rapidly through their chosen careers while coping with some rather spectacular character flaws. One being the ex-Chair of the UK's Co-operative Bank (already in financial turmoil), caught in a drugs and prostitutes sting this week, which has followed on from the city mayor of Toronto, who has been drawn into a similar web of videotaped misbehaviours.

Sticking with the financial services example, we have a number of issues which should interest the risk pros;

Some elements of the story are dominating the headlines, such as the gender of the prostitutes, the type of drugs used, or the fact that the Co-operative movement, purporting to have a higher calling than the soul-hoovering plcs, should perhaps be impervious to such matters. 

For me, we have a straigthtforward case of significant internal control failings across departments, a failure to hold senior management to account when breaching internal policies, and a very strong working example of a reverse stress test, combining a number of risk factors which in concert deliver a failed business model. On that basis, I would think that the business-as-usual risk teams across the country will be analysing this one until the cows come home.

How much of a bum-paddling the FSA/PRA deserve on this is another matter. Whether light-touch or prescriptive, I think regulators in many countries will wince at the details of the approval of Rev. Flowers' appointment once this one plays out at Treasury Select Committee over the coming weeks (I have no insider information, but let's face it, we'll be watching through our fingers!). 

For context however, in 2009 the FSA (as it was then) made a formal submission to the TSC addressing many of the failings uncovered by the retreating tide post-Lehmans/Bear Stearns/Northern Rock, and what Hector Sants & Co had planned to make up the shortfall. 

The TSC made a number of comments (sandwiched within the FSA's submission) which are worth highlighting today - I have emphasised the parts which should now echo in eternity;

The FSA's assessment of whether senior bankers were fit and proper for their posts appears to have been little more than a tick-box formality, unless the applicant had a criminal record or gave some other evidence of a shady past. That bar was demonstrably set too low. We welcome the acknowledgement from the FSA that a candidate's competence, as well as their probity, will now be thoroughly reviewed before taking up a senior post in a bank. We recognise that there may be some dangers in the FSA assessing competence, not least because the FSA will become exposed to accusations of incompetence itself, if it makes a wrong judgement

We recommend that the FSA assess whether bank executives should possess relevant qualifications. We would like to see banking qualifications become one of the core indicators against which the FSA can assess a candidate's competence. If a candidate has no relevant qualifications, the onus should be on them to prove to the FSA that they have relevant compensatory experience
And from the PRA themselves...
We strongly agree that it is important for bank executives to have the right level of skills and experience. As noted above, we have recently written to all CEOs of relationship-managed firms reminding them that it remains the firm's responsibility to ensure that the candidates they put forward are fit and proper to perform the role in question, and that firms should, therefore, have robust recruitment, referencing and due diligence processes in place
It was only three years ago - at what point do we (grim pun intended) practice what we preach on corporate governance in financial services?

Friday, 17 May 2013

Internal Model Validation - the "desire for certainty"

Some useful snippets on the links here for anyone in the model validation space, whether if be the practical applications of Monte-Carlo simulation outside of the insurance industry, actuarial perspectives on model risks themselves such as parameter uncertainty and goodness of fit testing where "the problem is more often too many candidate distributions" as opposed to restrictions in choice.

This fantastic blog post from one of Willis's finest is about as blunt a critique of actuarial modelling activity and its potential for subsequent misuse as I have read, and I would strongly recommend it on to non-expert risk practitioners who may one day find themselves in the model validation/use test firing line. A few of the pearls of wisdom offered (focused on reinsurance industry, but relevant to all) include;
  • How the human "want to believe" and "desire for certainty" can lead to models making rather than guiding decisions
  • Reliance of models on "large numbers of heroic assumptions"
  • "Data is always limited and flawed"
  • That "models take combinations of assumptions and torture them to come to conclusions"
  • The revisiting of assumptions only when the answers don't fit expectations ("euphemistically called 'calibration'", hilarious!)
  • That using models for setting regulatory capital, rather than just informing decision making, has led to "extremely onerous" IMAP activity i.e. the limitations noted above are so well established that the regulators cannot ignore them at a granular level.

Then there this piece from Deloitte US on model validation, or more specifically, research into the quality of existing actuarial modelling controls, is an eye-opener for anyone working in the validation space. With RMORSA and associated capital modelling firmly on the agenda Stateside, it is interesting to watch how aggressively they approach validation, bearing in mind this work was commissioned by the Society of Actuaries, whose members may ultimately be charged with applying some of these recommendations!

This research in particular assesses current state versus best practice controls over the assumptions, inputs and outputs of actuarial models, and though the sample of respondents to the survey is relatively small (representing "30 unique companies"), the absence of suitable supporting documentation around model governance so evident in the UK's IMAP process appears to be a depressingly constant theme. This report at least includes recommendations as to how the US actuarial profession may bridge some of the gaps Deloitte identify.

In the NAIC's ORSA Manual, they ask that "ORSA Summary Report should provide a general description of the insurer’s process for model validation, including factors considered and model calibration" (p7), which I guess is what one expects to see in the EU (i.e. validation being a sub-process of the ORSA, which can be summarised in the ORSA reports). That said, the breadth of validation work performed over there will surely be driven by S&P expectations communicated in ERM Level III reviews, rather than profession-sponsored consultancy recommendations!


Finally (and slightly off track), an odd piece from Towers Watson on validating ORSAs, pitched to a room full of Internal Auditors. Would be unfair to say there aren't some salient points throughout, but given that there is "no clear requirement" to validate ORSAs (there was something on the matter in the original CEIOPS ORSA pre-consultation, but it was dropped in the public consultation and the final advice), then you would think it could be covered in less than 30+ slides!

As it happens, the TW slide pack for internal model validation appears to have been raided and had the acronym 'ORSA' jemmied into the text for much of the second half of it.

Thursday, 28 March 2013

EIOPA Preparatory Guidelines - System of Governance

Consultation on System of Governance preparatory guidance (plus explanatory text)

For a topic which has felt like a given for a number of years (certainly in UK and Ireland where we already ask a lot in this area), the System of Governance preparatory guidance is still 40 pages, comprising of 57 guidelines, accompanied by 60 pages of explanatory text.

A couple of things immediately grabbed at me when going through the guidance (again anticipating a conservative approach of the supervisors rolling over and applying all content as is)
  • That the Risk Management Policy (regardless of how one structures the component elements) is expected to contain procedure-level information about the management of each major risk category - this sounds hopelessly disproportionate, and almost impossible for supervisors to reasonably get through;
  • That it is "expected" that large or complex firms separate their four key control functions, and that others at the small/medium end may ultimately find it easier to do so than consider the range of controls/maintenance of independence required to have combined functions;
  • That an expectation that insurers' systems of governance require regular independent review, with the AMSB only retaining the ability to choose the performer;
  • That insurers will be expected to formally identify/analyse/report on Operational Risk Events
  • That EIOPA bottled out of defining Risk Appetite and Risk Tolerance, leaving national supervisors and insurers to fight it out amongst themselves.
Ultimately, the document reads like a checklist which practitioners or full-timers can run through against the suite of documentation no doubt already in existence which, if based on CEIOPS/EIOPA final advice and/or the Commission's Draft Level 2 measures, won't be miles away as it stands. On that premise, I've only listed elements which jump out for me.


GENERAL GOVERNANCE REQUIREMENTS

Guideline 3
  • Evidence should be collected of the AMSB "proactively" seeking information from committees/key functions
Guideline 5
  • No more detail than an expectation that the AMSB "appropriately implements" their key functions - in the explanatory text, it goes on to say that larger companies will be "expected" to fully separate Risk/Actuarial/Compliance/IA, with a series of measures expected to preserve functional independence if smaller companies choose to combine some.
Guideline 7
  • Expectation that both AMSB decisions, and how information generated from the Risk Management System (RMS) influences them, is "appropriately documented" - compulsion for Board Decision Logs?
Guideline 8
  • Regular System of Governance reviews appear to be expected, which are documented and reported back to the AMSB - the AMSB retains the right to choose who performs it 
Guideline 9 - All policies must include:
  • Goal of policy
  • Tasks to be performed and by whom (person or role, unlike for validation, where person/s was specified)
  • Associated processes and reporting procedures
  • Obligations of affected operational teams to inform control functions of "relevant facts" at all times
Guideline 10
  • Contingency plans are expected for areas which are "especially vulnerable" - this pushes outside of what one would consider a conventional contingency plan for operational emergencies.

FIT AND PROPER

Guideline 11
  • Must have a Fit and Proper persons policy
  • It must be equally applicable to both hired staff and outsourced functions

RISK MANAGEMENT

Guideline 15 - AMSB is "ultimately responsible" for:
  • RMS effectiveness
  • Setting Risk Appetite and Risk Tolerance Limits
  • Approving Risk Management strategies and policies
Guideline 16 - Risk Management Policy must cover at least
  • Risk categories used and measurement methods
  • How each category/grouping of risks is managed
  • Risk tolerance limits for all categories in line with Risk Appetite
  • Linkage of both SCR and ORSA to risk tolerance limits
  • Frequency and content of regular stress tests, and circumstances for additional testing
In addition, the associated guidelines touch on the risk categories within one's Risk Management Policy. There is an expectation for pretty much every category that procedure-level information is included in the policy documents themselves, as well as hard limits, which is unlikely to be the case as it stands.

Guideline 18 - Insurance Risk Policy
  • Expected to cover types of acceptable insurance risks, how premiums will cover claims/expenses, as well as how product design accounts for investment restrictions and formal risk mitigation techniques
Guideline 19 - Op Risk Policy
  • Expectation that Operation Risk Events will be formally identified/analysed/reported in insurers, and that a system for collecting and monitoring them should be in place.
  • Operational Risk Scenarios should be developed and used, based on failures of key persons/processes/systems and external events
Guideline 23 - Investment Risk Policy
  • Buzzphrase introduced of managing the level of "security, quality, liquidity, profitability and availability" of one's asset portfolio

OWN FUND REQUIREMENTS AND THE SYSTEM OF GOVERNANCE

Guideline 32
  • Concept of a "medium term capital management plan" introduced which covers; planned capital issuances, maturities and distribution policies - not sure how that works for mutuals, but I can see what they're fishing for

INTERNAL CONTROLS

Guideline 33
  • "All personnel [should be] aware of their role in the Internal Control system
  • The Internal Control system should be "commensurate to the risks arising from the activities and processed to be controlled" - this line should hopefully avoid overkill

INTERNAL AUDIT FUNCTION

Guideline 36
  • The Internal Audit policy should include the procedure for informing supervisors [of whistleblowing-level wrongdoing I guess]

ACTUARIAL FUNCTION

Guideline 44
  • "Material"deviations of Best Estimate Liabilities should be back-tested for by the Actuarial function, reported on, and remedial changes proposed
Guideline 46
  • The Actuarial function is expected to "contribute to" specifying the risk coverage in the internal model, as well as the dependency structure - this feels like areas where, even in larger insurers, the function probably already leads, so will they be asked to take a step back?

Tuesday, 20 September 2011

IRM principles on Risk Appetite and lessons from UBS

Pretty interesting finish to last week, with UBS getting spanked for a cool $2.3bn through the now-typical route of a back office know-it-all getting promoted to the trading desk and circumventing the plethora of internal controls designed to stop the very activity they and they alone know how to take to the n-th degree.

I thought of this when looking through the IRM's risk appetite and tolerance paper released at the end of last week (separate post to follow incidentally, only so many hours in the day!), specifically whether there was anything being promoted/supported by the institute which may have averted this rather grim result for the boys from Berne.

6 IRM principles to start with;
  1. Risk appetite can be complex - don't try to dumb it down if it isn't justifiable
  2. Risk appetite needs to be measurable
  3. Risk appetite is not a single fixed concept
  4. Risk appetite should be developed in the context of an organisation's risk management capability
  5. Risk appetite must take into account views at strategic, tactical and operational level
  6. Risk appetite must be integrated with the control culture of the company
Sadly for the profession, the risk governance set up at UBS is paper-perfect in this regard, so I dare say the CRO may feel obliged to hand in his cards. This despite the fact that, as with the Leeson and Kerviel cases beforehand, if you personally know the gaps (and the reward is great enough) the rogue trader is nigh on unstoppable by the second line of defence in these kinds of organisations. However, it looks more of a "should have done better" case for the second line, and should categorically be used as a counter argument to the dismissive tones of management when discussing risk limits and qualitative tolerances.

Some great quotes below from their website (highlights are for my benefit);


High Level – Risk Management and Internal Control
The [risk controls]framework is dynamic and continuously adapted as our businesses and the market environment evolve. It includes clearly defined processes to deal with new business initiatives as well as large and complex transactions.

Risk assessment and management oversight performed by the BOD considers evolving best practice and is intended to confirm to statutory requirements
 
Risk Appetite
Our risk appetite framework establishes risk appetite objectives in respect of earnings and capital levels that we seek to maintain, even after experiencing severe losses over a defined time horizon.
Our risk appetite is approved by the BoD. Risk appetite is based on our risk capacity, which is in turn based on our capital and forecasted earnings resources. Our overall risk appetite is set as an upper limit covering the aggregate risk exposure for each risk appetite objective, taking into account inherent limitations in the precision of risk exposure measures that focus on extreme market and economic events. Comparison of the firm's risk exposure with our risk capacity under prevailing operating conditions as well as prospective business plans serves as an input to the risk limit framework. This comparison is also a key tool to support management decisions on potential adjustments to the risk profile of our firm.
 
Operational Risk-specific
Management and risk committees are the governing bodies responsible for oversight and active discussion of risk management activities, including the question of whether or not the cost of mitigating actions is adequately balanced against the acceptable level of operational risk. Management, in all functions, is responsible for establishing an appropriate operational risk management environment, including the establishment and maintenance of robust internal controls and a strong risk culture.
 
Material operational risks and significant internal control deficiencies are identified and reported at least quarterly to stakeholders, including the BoD, GEB, divisional/regional/local management, Group Internal Audit, external auditors and regulators.
 
We have developed a model for the quantification of our operational risk, which meets the regulatory capital standard specified by the Basel II advanced measurement approach (AMA). Our model has two main components. The expected loss component is a statistical measure based on our own historical loss experiences (collected since 2002), and is used primarily to determine the expected loss portion of our capital requirement. The unexpected loss component is based on a set of generic scenarios representing categories of operational risks that are relevant to the firm. The scenarios are reviewed extensively on an annual basis by internal experts, using internal and external event information, information about the prevailing business environment and our own internal control environment. This component is used to determine the unexpected loss portion of our capital requirement.
 
Risk and Reward

Friday, 1 July 2011

Basel Committee - Principles for sound management of Operational Risk refresh

The Basel Committee pushed out their new, improved version of the Operational Risk guidance for the Banking Industry - as I suspect the insurance industry will ferret through this for the good bits, I had a good look through myself.

The 11 principles they settle on are all logical - highlights next to each;

The board of directors should take the lead in establishing a strong risk management culture.

  • Recommends a code of conduct or "ethics policy"
  • Compensation should be aligned to the bank's risk appetite/tolerance statement
  • Training needs reflected by seniority, role and responsibilities of staffBanks should develop, implement and maintain a Framework that is fully integrated into the bank’s overall risk management processes.
    • Outputs of Op risk framework should be incorporated into the strategy development process (if used for capital allocation, this would be inevitable)
    • Framework should define Op Risk and Op Loss in a comprehensive board approved policy
    The board of directors should establish, approve and periodically review the Framework
    • Board should ensure that management avail themselves of best practice as it develops

    • Ticklists for what the board should be considering in context of this principle
    The board of directors should approve and review a risk appetite and tolerance statement for operational risk Senior management should develop for approval by the board of directors a clear, effective and robust governance structure
    • More ticklists for achievement
    • Provides for two-tier risk committee scrutiny based on "nature scale and complexity" (either an ERM committee considering reports from Market Credit and Op, or a flatter approach for smaller banks)

    • Standard list of identification/assessment tools, which are in use in most industries, so serve yourself if you are not familiar
    • Optional piece on "capture and [monitoring of] operational risk conttributions to credit and market risk related lossess in order to obtain a more complete view of operational risk exposure" - I like this piece on "border risks", and it is important from the Solvency II angle for correlation matrices
    • Differentiate KRIs and KPIs in a way I haven't seen previously
    Senior management should ensure that there is an approval process for all new products, activities, processes and systems that fully assesses operational risk. Senior management should implement a process to regularly monitor operational risk profiles and material exposures to losses.
    • "Reports should be manageable in scope and volume"! I suspect this will delight the Op Risk staff as well as the Board's, right up to the point at which something critical is left out on the principle of keeping the reporting 'manageable'.
    • Smal;l ticklist of content that "should" be included in Op Risk reports
    Banks should have a strong control environment that utilises policies, processes and systems; appropriate internal controls; and appropriate risk mitigation and/or transfer strategies.
    • Lots of ticklists on policy and process content that "should" be in place
    • Technology and Outsourcing risk given special treatment as far as internal controls go
    • Board of Directors expected to "determine the maximum loss exposure the bank is willing and has financial capacity to assume, and should perform an annual review of the bank's risk and insurance management programme".

    • Ticklists for continuity management processes and considerations
    Banks should have business resiliency and continuity plans in place A bank’s public disclosures should allow stakeholders to assess its approach to operational risk management.
    • No obligations for public disclosure of Op risk loss events
    • Disclosure focused mostly on detail of the Op Risk framework itself, ostensibly that it should be detailed enough to let the public make an informed judgement on its adequacy.

    • Ticklist for new product/activity/process/system consideration provided - noted as "should be considered"
    Senior management should ensure the identification and assessment of the operational risk inherent in all material products, activities, processes and systems
Strong culture unequivocally linked to "ethical business pactices"