Showing posts with label regulation. Show all posts
Showing posts with label regulation. Show all posts

Wednesday, 12 August 2015

Insurance Banana Skins in 2015 - PwC and CSFI

PwC and the CSFI guys have teamed up for another Insurance Banana Skins publication, a particularly useful doc for the BAU Risk world, and one which I have covered on the blog in years gone by (well, 2011's and 2013's anyway).

In particular, I always found it useful as a means of digging out the kinds of awkward cross-bred expressions which would invariably end up rolling out of 75-year-old INEDs’ mouths at the next Risk Committee meeting, probably due to someone trying to sell insurance cover for it, or a business journal doing a centre spread about it. On this basis, I was delighted to see “Cyber Risk” given prominence this time around, which is the highest new entry, and apparently a “new risk” - here’s the sales forum, and here’s the HBR white paper!

Sarcasm aside, given this pulled in over 800 responses from around the globe, and across the distribution and provision side of the industry, the content is worth poring over and briefing colleagues on if this is your day job. There are also plenty of quotes from the great and good wrapped up inside as well.

I’ve only jumped on a few of the findings below;
  • Regulation remains the top risk for the 3rd survey running, and for the 4th out of the 5 actually held. It did take a ‘world’s end’ scenario for investment returns to knock it off the top in 2009 though, which suggests that those surveyed are happy to bleat about regulatory concerns, regardless of the rest of the exogenous threats to insurance firms.
  • Much of the top ten is focused on investments and returns, whether it be interest ratesinvestment performance or guarantees.
  • Governance and management of insurance companies seen as an area of declining risk – does it therefore warrant the Banking industry-inspired whip that SIMR is about to introduce in the UK?
  • Similarly, Business Practices, incorporating misselling, is falling down the list – not sure a UK-only survey would be so generous!
  • Cyber Risk itself was only #6 on the list for Life Companies, while #1 for Non-Life – wonder why the guys who are selling cover rate it so highly? Of more interest, North America had it as #1 “by some margin” – this suggests the wave will be coming across the Atlantic in the next 12 months (a nice precursor of how that will emerge here)! It is written up nicely however, with cloud storage, and the richness of data held on customers, being elements which make insurers prime targets. It doesn’t dwell on the proliferation of legacy systems in insurers however, which always felt to me a good reason for criminals to ‘have a crack’.
  • Europe considered the interest rate environment, regulation and guarantees to be the top 3 banana skins, which given the aggressive tailoring applied to Solvency II in the drafting stages to negate country-specific difficulties in these areas (MA/VA/Transitionals), is no surprise.
Oh, to have a day job again…

Friday, 24 January 2014

PRA, BaFin and Disclosure - Grüne with envy...

Without being hypercritical, it occured to me that the PRA appear to be keeping materials and opinions "on the downsie" at a time where perhaps the industry would benefit from their overexposure, and I can't work out why.

A few things triggered that thought over the last week;
It is worth expanding on the last point, bearing in mind what a useful piece of text it is for anyone looking to confirm within their own Programme how best to interpret EIOPA's guidelines. BaFin explicitly state;
  • Insurers should "immediately take the necessary steps" to implement the Preparatory Guidelines.
  • That "undertakings are effectively the target audience" for the Preparatory Guidance, which I am delighted to see acknowledged publicly by such a significant participant.
  • It is up to each insurer to determine the order of their implementation activity prior to 2016.
  • That, for the benefit of the industry, BaFin have carved up the Guidance into 15 blocks, and will provide "additional information and tips" periodically over the next two years.
  • That a special activity for Life Insurers will take place, one suspects in order to help identify the capital shortfalls hinted at at the back end of last year for those with high cost of guarantees.
  • That everyone is expected to participate in the QRT exercise, ignoring the thresholds offered by EIOPA to the NCAs.
  • That they will be translating any EIOPA texts released prior to 2016 in English-only into German.
Whilst it may be a case of thinking das gras ist grüner, it would be easy to envy the German contingent when offered this level of disclosure and certainty in dealing with the preparatory phase. What say you, Moorgate?

Tuesday, 10 December 2013

ICAEW on "overarching principles of corporate governance" - how much is too much?

I hadn't got around to this thought-leadership document from the ICAEW on corporate governance, despite their kind tweet asking for my thoughts, due to the welter of Solvency II activity that started from September.

The premise behind their document seems to be that corporate governance codes are perhaps a touch unwieldy these days, and might benefit from some Google-style "Do No Evil" overarching principles which even the sneakiest, mealiest-mouthed Board member would struggle to justify their (mis)conduct in the context of.

In general, the word 'overarching' makes me want to pull my thinning tufts out. I'm not much of a compliance-ferret, but the thought of Board conduct being so misguided by the corporate governance codes in place in developed countries that we need to refine it another notch is one I couldn't entertain. Certainly, given the importance of holding these people to account, and the level of education and experience a great many of them will have attained, I am inclined to think that 'more is more' rather than 'less'.

The ICAEW paper comes up with 5 overaching principles of corporate governance, centred around;
  1. Leadership
  2. Capability
  3. Accountability
  4. Sustainability 
  5. Integrity
The following parts jumped out at me;
  • That overarching principles should be "aspirational and credible" - feels counter-intuitive.
  • That overarching principles should "think beyond the letter of laws and regulations" - why should they? Laws and regulations, regardless of how badly drafted, capture the kind of corporate recklessness that we would all gladly see consigned to history. Punishment seems to be a bigger issue (i.e. why aren't white collar criminals thrown to the dogs, or captains of industry who are hoist by their own petard immediately banned for life?)
  • The thought of companies explaining links (or gaps) between overarching principles and their actual actions is almost too grubby to contemplate, giving leaders an undeserved shade of grey to support bad governance ("...well, in principle...")
  • That overarching principles should be "...easy for boards and stakeholders to understand". Why should a Board job be easy? Why do people of such talent, education, breeding (?), etc. need to have the words "Don't be an idiot" written for them in crayon? Briefing onesself on the requirements of a national corporate governance code is only beyond a Board member who cannot be ar bothered.
  • That the current UK code, at 18 principles and 28 supporting principles is "...too detailed for most people to remember". That would include me! However, it's only a click away, and is certainly not justification for further refinement.
I definitely sympathise with anyone who has to keep on top of corporate governance code development, particularly in the EU, where pan-European angles bubble up with regularity (here and here for example). That said, just do your job and comply with them!

Given that certain organisational bodies cannot be held to similar standards, yet may be equally significant in the case of UK/Planet Earth plc (Government departments, Private Equity firms, Mutuals/Friendly Societies), I would certainly find it hard to transplant such a layer onto existing requirements for listed entities. If anything, these overrarching principles could be targeted towards the general public in order to help laymen and women understand what areas our current codes are focused on, and why.

I certainly don't see the overarching principles as aiding leaders of business in any other respect that providing another layer of excuse confetti when they need to explain away the next slew of avaricious corporate conduct. I wonder who it's going to be next?

Wednesday, 20 November 2013

Financial Stability Board - Principles for an Effective Risk Appetite

Christmas has come early everyone - the Financial Stability Board have released their Principles for an Effective Risk Appetite Framework today, and I'm greedily ripping in to it before JC's birthday like a spoilt, yet handsome child...

FSB's RAF Principles published
send the car back lads...
There has been a reasonable amount of traffic on Risk Appetite this year (here, here and here for a start), after the FSB but announced their consultation earlier in the year, I've been on tenterhooks. This was following of the back of a thematic review on Risk Governance as a whole by the FSB, which they published back in February.

So where do they take this deep dive into Risk Appetite? Other than awkwardly shoehorning in the soup de jour of "SIFIs", they stick to the hard areas which will get every risk practitioners' attention (namely, Risk Appetite Framework, Risk Appetite Statements, Risk Limits and Roles and Responsibilities), though "for clarity and simplicity", they jettison the use of Risk Tolerance. Definitions are supplied on p2-3, which you may find useful as anchor references.

They somehow make room for anodyne flannel in this very short document, for example;

Risk Appetite Frameworks
  • Should "facilitate embedding risk appetite into the financial institution’s risk culture
  • Development and establishment is an "...iterative and evolutionary process that requires ongoing dialogue throughout the financial institution to attain buy-in across the organisation" (groan)
Risk Appetite Statements
  • "Risk appetite may not necessarily be expressed in a single document; however, the way it is expressed and the manner in which multiple documents form a “coherent whole” need to be carefully reviewed to ensure that the board obtains a holistic, but compact and easy to absorb, view of the financial institution’s risk appetite"
Risk Limits
  • "Having risk limits that are measurable can prevent a financial institution from unknowingly exceeding its risk capacity as market conditions change and be an effective defence against excessive risk-taking" - tell that to Lehmans!
However, the salient points for me were as follows;

Risk Appetite Frameworks

  • RAF "...sets the financial institution’s risk profile" - not convinced on that one, but may be semantic issue
  • "explicitly defines the boundaries within which management is expected to operate when pursuing the institution’s business strategy"
  • Should "be adaptable to changing business and market conditions" to allow for limit increases where appropriate


Risk Appetite Statements

  • "[should] address the institution’s material risks under both normal and stressed market and macroeconomic conditions"
  • "...should establish quantitative measures of loss or negative outcomes that can be aggregated and disaggregated"
  • "...include key background information and assumptions"
  • "...include quantitative measures that can be translated into risk limits"
  • "...be forward looking and, where applicable, subject to scenario and stress testing"

Risk Limits

  • "[should] be set at a level to constrain risk-taking within risk appetite"
  • "...should not be strictly based on comparison to peers or default to regulatory limits"
  • "[should] not be overly complicated, ambiguous, or subjective"

Roles and Responsibilities

The Board

  • ...must establish the institution-wide RAF and approve the risk appetite statement, which is developed in collaboration with the chief executive officer (CEO), chief risk officer (CRO) and chief financial officer (CFO)
  • FSB specifically comment that Boards who "receive" or "note" Risk Appetite Statements have a lower understanding of risk appetite (so don't sponsor it!)
  • " [should] regularly review and monitor the actual risk profile and risk limits against the agreed levels (e.g. by business line, legal entity, product, risk category), "including qualitative measures of conduct risk"
  • " [should] ensure risk management is supported by adequate and robust IT and MIS to 
  • enable identification, measurement, assessment and reporting of risk in a timely 
  • and accurate manner."
CEO should
  • "...be accountable, together with the CRO, CFO, and business lines for the integrity of the RAF"
  • "...ensure that the institution-wide risk appetite statement is implemented by senior management"
  • "...provide leadership in communicating risk appetite to internal and external stakeholders" 
  • "...establish a policy for notifying the board and the supervisor of serious breaches of risk limits and unexpected material risk exposures"

While there are specific sections for the obligations of CRO, CFO, Internal Audit and Business Unit Management, they don't necessarily expand much further than what I consider to be normal functional expectations, so I haven't elaborated on them.

One should certainly therefore expect a much more aggressive approach from supervisors in future off the back of this - combing through strategy and board papers for evidence of Risk Appetite in application, and making sure that Risk Appetite Statements are not just 'rubber stamped', for example.

I certainly don't see much in this for stakeholders. Nothing particularly new is brought to the table here, and if this is the results of peer review and shared experiences, then clearly there is concurrence on how an RAF should be constructed, what a RAS looks like, and who should do what in regard to continuous monitoring.

The skill will be for risk practitioners to convince their CEOs/NEDs that, this is no longer a sidecar activity in the ERM best practice space, but a nascent global minimum standard which will invariably surface in national regulations in the forthcoming moths and years.

Monday, 9 September 2013

Deloitte on 'regulatory uncertainty in Europe' - embedding a new modus operandi (?)

In a wonderful example of predicting the present, Deloitte have released a white paper (sign-up required) giving their take on regulatory uncertainty in the European insurance industry, and how the volume of new regulations (and their inability to land on time) is driving emerging best practices in the consideration of regulatory risk at Board level.

New Modus Operandi - alloy wheels optional?
Of course, it is always best to wait for such matters to emerge before proselytising, and the current cup of omni-postponed over-elaborate regulations is running over (Sol II, IFRS 4 Phase II, FATCA, etc), naturally causing difficulties for all those responsible for preparing for them, as well as the execs who take the topics into the boardroom every quarter, only to say "it's been delayed again, can I have more money"...

From my perspective, it was particularly interesting to see that proactivity is recommended regardless of nature/scale/complexity, bearing in mind the first time I spoke to a Board of Directors at a tiny insurer regarding Solvency II preparations was in 2009 - only consultants could comfortably suggest that an new executive-level role is established, and Board agenda time is regularly set aside, only to explain the latest delays in multi-jurisdictional regulations (I certainly know what my old CEO would have said to that!)

That aside, they suggest that two major problems need to be overcome; that few insurers have a single view of regulatory risk; and that regulatory insight is poorly represented in the strategic workings of insurers, both of which are easy to agree with purely on circumstantial evidence.

Whilst this frequently reads like a paper written to justify bringing consultants in to compensate for failing in risk and compliance professionals' armoury, Deloitte make the following noteworthy assertions/recommendations in it;

Trends

  • That most insurers prefer to 'wait and see' rather than be 'first mover' when it comes to regulatory preparations - after the Solvency II experience, does that surprise anyone?
  • That "...Deloitte's view is that regulation can be regarded as a 'structural' driver of the insurance industry"
  • That "...Deloitte's considers a regulatory dividend can and should be sought", which is not necessarily my experience of consultancies when on site, who (presumably for legal reasons) prefer to promote a gold-plated complaince approach to regulation-driven projects.
  • Cost of compliance is now materially diluting return on equity in EU insurers
  • That Conduct Risk is likely to become high profile across Europe over a longer period of time than its current flavour of the month feel, thanks to IMD2/PRIPS/MIFID
  • National regulators are increasingly impeding on day-to-day running - examples given (all of which have a whiff of IMAP requirements about them), include documentation improvements and influencing risk appetite/capital allocation work.
Costs and volume

  • Regulation prep cost the European insurance industry €4.2-€4.7bn in 2012 - they go on to expand that to €8.1-€9.2bn over the last 3 years.
  • UK industry will be subject to 29 new pieces of legislation of the next 5 years (surprisingly lower than the French at 35, and the Germans at 32!)
  • That the "cost of doing nothing" while waiting for regulatory clarity may be significant - as significant as consultancy spend preparing for something which never arrives perhaps?
  • That compliance functions are naturally struggling to cope with the current volume of initiatives
Solvency II-specific
  • They extrapolate an estimated €550m cost of Solvency II compliance preparations in 2012 into a €1.5bn-€1.8bn 'top 40 insurers' number, and a €2.4-€2.9bn figure for the whole industry - feels a bit light, bearing in mind 'UK plc' must have done the best part of £1bn on Solvency II alone in 2012.
  • They quote one strategy director as saying that "Solvency II is killing European M&A..." - p10
Their recommendations (from p19) are too woolly in aggregate to help a normal practitioner - they are probably targeted more towards programme directors and managers - but the recommendation  to establish a Regulatory Assessment and Response Executive with a suitable remit is a smart idea, even if from a practical perspective this might need to either be balled in with the responsibilities of an existing executive, or only be a mid/senior management role, in smaller companies. 

These recommendations also include the marvellous suggestion to "embed a new modus operandi" - an expression normally reserved for profilers of serial killers, and perhaps the hardest sell since Isle of Man beach holidays.

PS I apparently missed the memo where the oft-ridiculed speech of Donald Rumsfeld used to support war against Iraq became de rigeur in risk management/insurance white papers. If there is one "known known" in this world, it is that I will never use that expression on the job!

Friday, 2 August 2013

Central Bank of Ireland - Corporate Governance Code refresh

The Irish approach to corporate governance in financial services, at least up until the onset of the financial crisis in 2006/07, resembled something of an all-you-can-grasp buffet for a select number of executive golf club pals and octogenarian ex-politico Non-Executive Directors (NEDs), having their voting arms operated a la Weekend at Bernies.

Ireland pre-2007 - Waking NED?
The new FSA-flavoured approach brought in by Matthew Elderfield in 2009 (elaborated on here) fortified by the findings of a devastating 2011 report summarising the truly horrid governance practices in the Irish banking industry, has led to a change of regulatory tack at the Central Bank of Ireland that represents the biggest volte-face in Europe since the Macarena.

Alongside PRISM, a piece of revolutionary work in the assessment of financial institutions by supervisory bodies, the CBoI also made substantial changes in areas such as Annual Compliance Statements, Fitness and Probity of directors, Risk Appetite Statements.

All of this ran off the back of Mr Elderfield's first major gig in 2010, a full revamp of the Corporate Governance Code, which could hitch a ride off the back of the work of the FSA and CEIOPS (at the time!) and deliver a more substantial suite of obligations to a cabal of directors who, after feasting on carrots for years, desperately needed the stick.

This makes the release of yesterday's consultation on the Corporate Governance code a touch baffling, as the ink is barely dry on 2010's effort - it perhaps reflects that the regulator has reached optimum staffing levels if they can review it so regularly! Having said that, the level of divergence from accepted CG practices in the UK was flagged by Grant Thornton back in 2011 as being substantial, so a point-in-time revamp should not be so unwelcome, regardless of the proximity to the last one, and of course, all of this activity was too late to prevent Quinn Insurance from going down.

They emphasise that this review takes into account developments in the Solvency II space, as well as on-the-ground experience and publications from other parties of interest. Of particular note was their emphasis that, where national regulations are not as stringent as relevant EU or international one (or indeed vice versa?), the most onerous one should be complied with. In a number of instances around corporate governance, this will mean the CBoI outranking Solvency II as the more onerous of the two!

While these are proposals rather than stitched-on changes at this point, the CBoI doesn't have a great track record for backtracking these days. Highlights for me were;

Risk Committees

  • Require a majority of NEDs on Risk Committees, and must be chaired by a NED
Committees in general
  • Require the Risk Committee and Audit Committee chairs to sit on each other's committees
  • Require the Remuneration Committee chair to sit on the Risk Committee
  • In High Impact firms, the Risk Committee and Audit Committee Chair may not be the same person
  • Must be at least 3 members of Risk Committees and Audit Committees
Chief Risk Officers
  • They note that it is "Generally accepted best practice" to have a CRO who, amongst other tasks, is charged with "...facilitating risk appetite setting by the Board". In addition;
  • All "High Impact" firms will be required to appoint a specialist CRO
  • Firms with a lower PRISM rating may have a CRO who is shared with another control function, "...provided that there is no conflict of interest between the two roles". Can't help but feel that this might rule out CRO/Chief Actuary dual roles, but allows for CRO/Head of Compliance and CRO/Head of Internal Audit, which would be to the chagrin of the Society of Actuaries in Ireland!
  • CRO to have direct access to the Chairman of the Board
Board Meeting frequency
  • Seem to acknowledge that the compulsory 11 meetings per year for High Impact firms may be a touch much, so are looking for comments
  • Also acknowledge that compulsory 1 meeting per calendar quarter is a bit constrictive for the smaller firms, so may relieve this to be pragmatic
Chairman and CEO
  • Some of the restrictions around number of roles held at any one time to be relieved for smaller firms, but seemingly only to populate inter-Group roles.
Board Diversity
  • Acknowledges that, while the debate in the EU is gender-centric, that diversity of all types is a worthy target for Boards, but falls short of compelling firms to do anything at national level, choosing to seek comments and wait for the supra-national activity to drive any compulsion. This seems to fit with the thinking of Irish directors published back in 2011 i.e. no "Golden Skirt" quotas.
Random
  • "...appropriate Risk Culture" makes its way in (6.3), perhaps cognisant of the FSB's proposals
  • Built in a piece which allows for video-conferencing rather than physical attendance at meetings (7.5)
  • Board responsibilities updated (13.1)
  • Compulsory Board skills matrix (14.9)

Tuesday, 9 July 2013

EU Commission and Quick Fix 2 - Silence is golden (delicious)...

We are a good week down the line since Solvency II technically became a rolling ball, at least from a 'transcription into national law' perspective, and the party has barely stopped around the EU...

Man from Del Monte
- he says 'Non-Compliant'
Joking aside, the wonderfully obscure lobbying miscreants at ICODA released findings (expanded on here) of a straw poll they had issued to all member states around their preparedness to implement both Solvency II and EIOPA's interim measures. Not even half of those polled responded, and only 6 responded in full, so the sample isn't ideal. That said, there are enough seeds of doubt sown by the responses to grow a Del Monte-style orchard of non-compliance by next year.

As one would have anticipated off the back of the last-ditch attempt to secure a second 'quick fix' Directive, there would appear to be major concerns around NSAs meeting the requirements as at 1st Jan 2014, for example;

  • All respondees are in favour of 'Quick Fix 2'
  • 40% don't feel adequately prepared for ORSA obligations
  • Half are not prepared for internal model pre-application obligations
  • A quarter are not prepared for submission of information obligations

Is 'Quick Fix 2' simply being seen by some of the straggling NSAs as an opportunity to postpone the inevitable rather than to actually prepare for it, thus avoiding the decadent yet ultimately unnecessary project spend of the early adopters? Indeed, is 'Quick Fix 2' even legally possible now that the date for transcription into national law has passed?

I took the opportunity on Monday 1st July to contact representatives of note to ask where the legislation currently stands, specifically around the potential for retrospective 'Quick FIx 2', and received the following cavalcade of replies in the last 7 days;

  • EU Commission - nothing
  • An EU Parliamentarian heavily involved in Solvency II - nothing
  • EIOPA - a holding e-mail thanking me for my question

I hope that world exclusive information helps you all with your preparations!

Late post-script - I didn't bother checking in with the Council, but they have surprisingly made public comment today due to the changeover in presidencies to the Lithuanian delegation. Knowing the guys in Vilnius are big fans of the whole Solvency II shooting match (?), it was interesting to see they only have "...continued negotiations on the Omnibus II insurance dossier" scheduled over the next 6 months, as opposed to something more positive. We'll certainly be seeing Santa before the Parliamentary Plenary vote then, big question is will we also see the 2014 Easter Bunny?

Wednesday, 3 April 2013

UK's "new" Prudential Regulatory Authority - Approach to Insurance Supervision

So a magical thing happened over the weekend: a venerable institution disappeared on Friday, only to come back reborn on Monday...

...that's right, the FSA is no more, being replaced by two more focused entities in the Prudential Regulatory Authority (PRA) and Financial Conduct Authority (FSA). This is part of the UK-specific fallout from the financial crisis, where a perceived lack of focus from the former tripartite system which housed the FSA allowed for both systemic risk (Northern Rock, RBS) and conduct risks (PPI, Interest Rate swaps) to emerge largely unchecked.

Rather excitingly, this means a new website with some natty logos from the Bank of England (which
PRA - emperor's new clothes
or Solvency II aperatif?
has rehoused the PRA side of the FSA), as well as a statement on the new supervisory approach that the PRA will be taking.

For anyone in the ERM/Solvency II/Corporate Governance space, this gives us a chance to pick up on the kind of regulatory interrogation one might expect when writing/upgrading system of governance-related materials in preparation for both full Solvency II implementation in 20??, as well as how they are accommodating EIOPA's interim measures from 2014.

Remembering that the PRA's two statutory objectives are to promote safety and soundness of the firms it regulates, as well as specifically providing appropriate protection to insurance policyholders, I thought it wise to make some notes on how they have catered for Solvency II and deference (when due) to EIOPA, as well as the general content around expectations of governance systems. I found the following worthy of note;


Control function-specific

Section 82 - "[PRA] wants to be satisfies in particular that designated risk management and control functions carry real weight within insurers"

Section 117 - Should have separate risk management and individual control functions in place (dependent on nature scale and complexity etc)

Section 118 - the PRA "expects these functions to be independent of an insurer's revenue generating functions"

Section 120 - expectation of an "operationally independent Actuarial function", which the PRA consider to be "integral to the effective implementation of a firm's risk management framework"

Section 182 - "Actuaries can play an important part in supporting prudential supervision"

Section 119 - an effective Risk function on the other hand merely "ensures that material risk issues receive sufficient attention from the insurer's senior management and Board" - just because I'm paranoid, doesn't mean the Risk profession isn't being made something of a gooseberry here, particularly as the FSA/Actuarial profession love-in started some time ago!

On Risk Appetite

Section 110 - a firm's risk appetite "[is] to be integral to its strategy, and the foundation of its risk management framework"

Remuneration

Section 84 - "remuneration and incentive schemes should reward careful and prudent management" - just like Prudential's and Standard Life's did this week!

Section 194 - Hint at potentially restricting pay in firms if intervention is warranted


Stress/Reverse Stress Testing

Section 109 - the AMSB must have "...an explicit understanding of the circumstances in which their firm might fail"

Section 145 - with regards to Reverse Stress Testing, "...management should consider the reliability of the output of the internal model compared with the results of these tests"

Section 106 - "competent, and where appropriate, independent control functions" should oversee risk management and internal control frameworks


Internal Models

Section 116 - On Internal Models, the AMSB should understand;
  • extent of reliance on models for managing risk;
  • limitations of their structure and complexity;
  • Data used;
  • key underpinning assumptions
Section 140 - "PRA expects internal models to be appropriately prudent"

Section 144 - firms may not choose the lowest capital requirement to determine whether or not to model internally


Regulatory Capital

Section 135 - for capital adequacy, firms "...should not rely on regulatory minima", and also "...should not rely on aggressive interpretations of actuarial or accounting standards"


Proportionality

Sections 212-215 - touches on treatment of "low impact" firms - is this effectively where aggressive approaches to proportionality interpretation should be expected (combined control functions, limited documentation, passive acceptance of Standard Formula etc)?

p43 - table covering the allocation of supervisory staff - 10 staff to 1 firm for the 25 largest insurers, versus approaching 10 firms to 1 supervisor at the small end.

Solvency II-specific references
  • In the PRA's view "[Solvency II technical detail should] leave scope for supervisors of individual insurers to make informed judgements around risks posed"
  • Confirms that elements of the Directive such as Prudent Person Principle, ORSA, Control Function requirements and Pillar 1 are all aligned with the new Threshold Conditions
  • Model approval will be dependent on "adequate" risk identification, measurement, management, monitoring and reporting throughout the modelling process
  • Will impose capital add-ons when necessary "to ensure insurers meet the required standards"

Thursday, 28 March 2013

EIOPA Preparatory Guidelines - System of Governance

Consultation on System of Governance preparatory guidance (plus explanatory text)

For a topic which has felt like a given for a number of years (certainly in UK and Ireland where we already ask a lot in this area), the System of Governance preparatory guidance is still 40 pages, comprising of 57 guidelines, accompanied by 60 pages of explanatory text.

A couple of things immediately grabbed at me when going through the guidance (again anticipating a conservative approach of the supervisors rolling over and applying all content as is)
  • That the Risk Management Policy (regardless of how one structures the component elements) is expected to contain procedure-level information about the management of each major risk category - this sounds hopelessly disproportionate, and almost impossible for supervisors to reasonably get through;
  • That it is "expected" that large or complex firms separate their four key control functions, and that others at the small/medium end may ultimately find it easier to do so than consider the range of controls/maintenance of independence required to have combined functions;
  • That an expectation that insurers' systems of governance require regular independent review, with the AMSB only retaining the ability to choose the performer;
  • That insurers will be expected to formally identify/analyse/report on Operational Risk Events
  • That EIOPA bottled out of defining Risk Appetite and Risk Tolerance, leaving national supervisors and insurers to fight it out amongst themselves.
Ultimately, the document reads like a checklist which practitioners or full-timers can run through against the suite of documentation no doubt already in existence which, if based on CEIOPS/EIOPA final advice and/or the Commission's Draft Level 2 measures, won't be miles away as it stands. On that premise, I've only listed elements which jump out for me.


GENERAL GOVERNANCE REQUIREMENTS

Guideline 3
  • Evidence should be collected of the AMSB "proactively" seeking information from committees/key functions
Guideline 5
  • No more detail than an expectation that the AMSB "appropriately implements" their key functions - in the explanatory text, it goes on to say that larger companies will be "expected" to fully separate Risk/Actuarial/Compliance/IA, with a series of measures expected to preserve functional independence if smaller companies choose to combine some.
Guideline 7
  • Expectation that both AMSB decisions, and how information generated from the Risk Management System (RMS) influences them, is "appropriately documented" - compulsion for Board Decision Logs?
Guideline 8
  • Regular System of Governance reviews appear to be expected, which are documented and reported back to the AMSB - the AMSB retains the right to choose who performs it 
Guideline 9 - All policies must include:
  • Goal of policy
  • Tasks to be performed and by whom (person or role, unlike for validation, where person/s was specified)
  • Associated processes and reporting procedures
  • Obligations of affected operational teams to inform control functions of "relevant facts" at all times
Guideline 10
  • Contingency plans are expected for areas which are "especially vulnerable" - this pushes outside of what one would consider a conventional contingency plan for operational emergencies.

FIT AND PROPER

Guideline 11
  • Must have a Fit and Proper persons policy
  • It must be equally applicable to both hired staff and outsourced functions

RISK MANAGEMENT

Guideline 15 - AMSB is "ultimately responsible" for:
  • RMS effectiveness
  • Setting Risk Appetite and Risk Tolerance Limits
  • Approving Risk Management strategies and policies
Guideline 16 - Risk Management Policy must cover at least
  • Risk categories used and measurement methods
  • How each category/grouping of risks is managed
  • Risk tolerance limits for all categories in line with Risk Appetite
  • Linkage of both SCR and ORSA to risk tolerance limits
  • Frequency and content of regular stress tests, and circumstances for additional testing
In addition, the associated guidelines touch on the risk categories within one's Risk Management Policy. There is an expectation for pretty much every category that procedure-level information is included in the policy documents themselves, as well as hard limits, which is unlikely to be the case as it stands.

Guideline 18 - Insurance Risk Policy
  • Expected to cover types of acceptable insurance risks, how premiums will cover claims/expenses, as well as how product design accounts for investment restrictions and formal risk mitigation techniques
Guideline 19 - Op Risk Policy
  • Expectation that Operation Risk Events will be formally identified/analysed/reported in insurers, and that a system for collecting and monitoring them should be in place.
  • Operational Risk Scenarios should be developed and used, based on failures of key persons/processes/systems and external events
Guideline 23 - Investment Risk Policy
  • Buzzphrase introduced of managing the level of "security, quality, liquidity, profitability and availability" of one's asset portfolio

OWN FUND REQUIREMENTS AND THE SYSTEM OF GOVERNANCE

Guideline 32
  • Concept of a "medium term capital management plan" introduced which covers; planned capital issuances, maturities and distribution policies - not sure how that works for mutuals, but I can see what they're fishing for

INTERNAL CONTROLS

Guideline 33
  • "All personnel [should be] aware of their role in the Internal Control system
  • The Internal Control system should be "commensurate to the risks arising from the activities and processed to be controlled" - this line should hopefully avoid overkill

INTERNAL AUDIT FUNCTION

Guideline 36
  • The Internal Audit policy should include the procedure for informing supervisors [of whistleblowing-level wrongdoing I guess]

ACTUARIAL FUNCTION

Guideline 44
  • "Material"deviations of Best Estimate Liabilities should be back-tested for by the Actuarial function, reported on, and remedial changes proposed
Guideline 46
  • The Actuarial function is expected to "contribute to" specifying the risk coverage in the internal model, as well as the dependency structure - this feels like areas where, even in larger insurers, the function probably already leads, so will they be asked to take a step back?

Thursday, 14 March 2013

FSA and cost of Solvency II in the UK - two tunnels or half a tunnel?

Andrew Bailey, incoming head of the PRA in the UK, was widely quoted yesterday as saying that the spiralling costs of Solvency II could ultimately cost "twice as much" as London's new £15bn choo-choo tunnel Crossrail. This was at a parliamentary select committee, which for non-UK readers is where second tier politicians jump on the latest bandwagons, so that fact that Solvency II is getting some air-time is telling in itself.

Not entirely certain what expenses are included in this £30bn mega-bill, but the number is surely as inconceivable as a 2014 start date unless we add FSA costs, industry costs and slap on some arbitrary figure for "additional capital the industry will probably need to hold" - which is of course what was contained in the Cost Benefit Analysis commissioned by the FSA published back in 2011. With much of that based on QIS5 standard formula results (but at least in the same ball park as £30bn), I guess we can swallow £30bn, albeit with a pint, rather than a pinch, of salt.

"But wait a second" keen readers of the FT cry, "this time last month a prominent CEO said the cost was supposed to be HALF that of Crossrail,". Has someone in the fact sheet-preparing department at the Wharf got their wires more crossed that a breakdancing electrician, and sold their boss a dud here? Has one of the journos at the Telegraph or FT misquoted someone? Either way, there's probably a salient lesson in there somewhere around looking before you leap, it just remains to be seen who's left with the proverbial, errr, mucky shoes.

Incidentally, the full text from a separate questionnaire which the UK Parliament's Treasury Select Committee asked Mr Bailey to respond to is available here - this is separate to the interrogation transcript where the "twice as much" quote was obtained from, but contains some insight into where prudential regulation is going as of next month when the PRA take the reigns, including some good news on the regulatory levy front;

"For the next year, we intend to levy just £0.1mn [for Solvency II]. The difference [from last year's £15m] reflects cut backs that we have applied to Solvency 2 preparation costs. Although it is hard to be sure of the final cost of Solvency 2 preparations given the uncertainty on timing and substance, I expect the overall cost to be considerably lower than previously estimated. This will be a saving for insurers."


However, when one reads that, in his own words, the new head of Prudential regulation in the UK is "...by comparison new to insurance, but [he takes] it very seriously", you truly hope if the £30bn faux pas is attributable to him, that it can be put right - with all the Solvency II scaremongering and doom-mongering, we could probably use a little realism-mongering...






Wednesday, 20 February 2013

Protiviti - top risks for 2013

Nice piece of 'top risks' benchmarking for practitioners was pushed out this week by Protiviti - heavily US-centric, cross-industry (around 25% financial services, but all respondents are C-suite types), and the 'risks' are provided as a selection of 20 pre-written items, but the work has still got some mileage, even if I am far from convinved by the early statement that "...the first question an organisation seeks to answer in risk management is 'what are our most critical risks'" with no reference to their strategic objectives!

Let's take that as an editorial oversight, and pick through the highlights;
  • Unsurprisingly, economic conditions and regulatory change/scrutiny are top of the financial services hitlist of 'top risks' (and indeed other industries)
  • CROs and Chief Audit Executives were less likely to rate a risk "less significant" than their first-line counterparts - nest feathering or legitimate conservatism?
  • Financial services considerably more likely to deploy additional resource to enhance risk management capabilities in the next year
There is also a "suggested questions for Boards" list at the back, which covers (albeit in a rather flannel-y fashion) the kind of items which emerged in the FSB's risk governance recommendations from earlier in the week, such as;
  • Is the Board sufficiently involved in/informed of the risk assessment process regarding the implementation of strategy (mergers & acquisitions, new lines etc)?
  • Is the MI around the Risk Profile sufficient?
  • Is there an existing emerging risk management process?
  • Is the risk profile consistent with risk appetite?
A decent piece to run through your NEDs at the very worst, and potentially of some use for your emerging risk/reverse stress testing activities for 2013.

Tuesday, 11 September 2012

Did we learn from Equitable Life? Professor says "No"...

A cracking thought paper was released this week by Professor Roberts from Kings College regarding the lessons one could reasonably have learned from British mutual Equitable Life's demise in early 2000s, and more importantly, did UK plc actually learn them! (simple timeline of recent events here for our non GB readers, but anyone whose website starts with a banner exclaiming "recreating value for policyholders" has clearly had a lean few years!)

This document works nicely as an aide-memoire for anyone working in a financial services risk function as to what one should be wary of in the day-job. Professor Roberts ties in some of the most recent work in this space (leaning heavily on the Cass Business School/AIRMIC Roads to Ruin research and its conclusions in particular), and comes to the inevitable conclusion that lessons are well publicised, but never learned.

My main concern as a risk specialist is that certain recurring themes in the failure of financial services firms appear to remain outside of the Risk function's control or indeed influence, notably;
  • Hubris of Senior/Chief executives - Almost every example of failure in insurance and banking referenced in Prof. Roberts paper includes a flukey, unchallenged CEO who got bolder as circumstance rather than skill kept their businesses growing. I had flagged a couple of articles in a post last year touching on what makes an executive tick, and since then I have seen psychopathy and leadership (as opposed to cherubic faces!) examined further in a popular mainstream book. The legitimate concern here of course is that CROs are seemingly no nearer to being guaranteed seats at the top table, let alone a veto to keep the most dominant executives in check, regardless of their loud voices, when necessary.
  • Poor quality governance from Non-Executive Director level - Risk functions simply must have the NEDs performing at their optimum in order to provide acceptable services to their employers. While the "old school tie" approach to recruiting NEDs may take a generation to phase out entirely (to be replaced by an army of Fembots, so Viviane Reding would have us think), Risk functions are left with tottering old fee-sweepers as their key route to early intervention. The more visceral approaches to documenting risk appetite/tolerance/preference now being supported by corporate governance codes and vocational/professional bodies may make it easier to raise concerns with NEDs in future (probably as it will be colour coded and in Excel...), but until they are actually prepared to risk their comfortable semi-retirement with some probing questions in the C-suite itself, should Risk functions ever think they can overcome such a void?
  • Failure of regulation - Should Risk functions be banking on the (inevitable?) failure of the nascent regulatory environment, and reserve for subsequent claims/compensation if one or a number of products are "too" successful, thus providing the necessary quantum of dissatisfied customers for the regulator to act? I would have laughed this suggestion out of the room until a year ago, since when the FSA have made retrospective calls on interest rate swaps, PPI, and TLPs, all of which would have been presented as "compliant" products in the Boardroom.
For the Solvency II fans, it also notes on page 11-12 that Equitable Life featured in the research which grew up to be Solvency II! Maybe we did learn something after all - if we smash up the affordability of long-term guaranteed products, we can all go unit-linked and never have to worry about another Equitable...

Friday, 9 March 2012

FSA Speech on the Solvency II Policy Landscape - Omnibus-man's holiday?

Not sure what the delay was on this speech, delivered at the FSA Industry Briefing day on the 27th Feb was (more likely an RSS feed fault rather than regulatory inertia!), from being published. Some useful summarising of the legislative impasse for anyone who needs Board briefing material.

Of more interest was this particular quote regarding Omnibus II's legislative path;

"I would not like to commit as to whether or not I expect that to happen before the summer recess of the Parliament but certainly once we have the voted-upon Parliament text we will have a clearer idea as to how far away the different parties are from reaching a consensus"

I can't be miles away by suggesting that if this isn't through by July, we have a problem! That being the case, does the lack of commitment speak volumes as to the differences between the competing interests in the trialogues?

Tuesday, 28 June 2011

FSA plans for conduct of business under the FCA

Speeches today from Hector Sants and Margeret Cole on the future of regulation for the 24,000+ small financial services firms who will not fall under the auspices of the Prudential Regulatory Authority.

Both provide quality insight as to how the risk/reward argument is playing out at the FSA as they prepare for the 2013 split - particularly liked the parallel of cost of extra regulatory visits against the cost of product failures such as Keydata.

Wednesday, 22 June 2011

ABI Conference - Single European Regulator?

EIOPA's Chief Exec kindly planted the seed of the single EU regulator at the ABI today - bearing in mind how the EU functions are struggling with consensus for Omnibus II right now, this is one matter best pushed to the back of the cabinet!

Wednesday, 25 May 2011

FSA update - Solvency II, Supervision Framework and death of ARROW

The FSA had a busy week, with a major conference in London on the future of the regulator in its new guise as the Prudential Regulatory Authority (PRA) .

Media commenced with an interview in which which Hector Sants discussed the obligations of the regulator to publish findings  such as those from their report into RBS (which has been taken out of the FSA's hands). Speeches given by Hector Sants and Andrew Bailey are available here and here respectively.

It is of course banking focused, but the new risk assessment framework (p9) shows much more agressive intent from the regulator, and it will be interesting to see any transference of experience between Solvency II preparations and changes on the Banking side when the PRA finally comes out to play

As a funny aside, Andrew Bailey confirmed in the speech that the ARROW supervision model was to be scrapped - having seen the number of site visits it generates dwindle as shown in these numbers, I am surprised it has taken so long to confirm it!