Showing posts with label internal controls. Show all posts
Showing posts with label internal controls. Show all posts

Tuesday, 17 December 2013

Governance flaws in UK financial institutions - complacency or one-offs?

Some very interesting bits released over the weekend which should prick the ears of the UK's banking and insurance entities like a corporate governance-driven piercing gun, hot off the back of last month's Co-operative Group scandal.

Governance structures
- unchallenged by Risk for too long?
Over at RSA, one of the UK's most venerable General Insurance, a house of horrors-style drama appears to be emerging. Starting with what looked like a serious, yet relatively modest, localised valuation issue over in Ireland has developed in short order into the straw which has broken the camel's back with regards to the tenure of the Chief Executive of the entire group - all off the back of a routine audit, according to one source, and perhaps not coincidentally breaking formally as a story one day after the announcement of enormous premium hikes in the country.

Astonishingly, one of the three men suspended at the Irish unit is also one of the biggest hitters in their national industry, being the current president of the Irish Insurance Federation. He was quoted in August thus (my emphasis);
I’m very optimistic about the future. The Irish Insurance Industry is robust, well capitalised, making a significant contribution to the economy and most importantly, delivering for customers.
While it is fair to say that the knives were already out for the Group CEO, who has presided over general bad news over the last year or so (this year's profit warnings one and two for example), to actually see a FTSE 100 insurer crippled to the point of fire sales to plug capital holes by such a matter is pretty remarkable, even if the geographical source of the pain is less surprising after Quinn went down actuary-less a couple of years back.

What's more, the interim CEO (who is pulling off the much-maligned Chairman/CEO double act for now, though was Non-Exec) has sanctioned a root and branch review of governance arrangements in the firm across all markets (cited here from an analyst call), quite an undertaking in itself bearing in mind its geographical spread.

It made me revisit the published feedback to EIOPA's preparatory guidance, where I had remembered that the feedback received from RSA was pretty caustic with regards to the appropriateness of EIOPA's guidance where it seemingly went above and beyond the Directive and Implementing Measures.

Pointedly in the context of this particular failure of their internal controls, they fed back extensively on the Fit and Proper requirements (p237), most of which centred around 'less is more', and emphasised the administrative burden such activity already causes. This is supplemented on p339 with a piece against the rotation of internal audit teams, both of which look discomforting in hindsight!


Thursday, 1 December 2011

Should the CRO carry the can?

Normally after a high profile operational risk materialises, the end cost normally determines how high up the food chain the sackings go,but they generally would stay in the first line of defence.

This one therefore stood out for me as a bit of a outlier. I'm all for individual and collective responsibility, and would personally have fallen on my sword if I was within a square mile of this abomination regardless of my job spec. However, is it correct to dismiss the CRO because of an internal control failing (albeit a whopper!)?