Showing posts with label risk management. Show all posts
Showing posts with label risk management. Show all posts

Monday, 20 October 2014

PRA's Countdown to Solvency II Implementation Event - When I Need U(SPs)

PRA Implementation countdown
- "Feel like dancing" now?
So along with the entire UK Solvency II sticky-beak brigade, I had the unbridled pleasure of attending the PRA's 'Leo Sayer' on Friday, confidently titled Countdown to Implementation, despite going on to list a range of matters which have probably given both Internal Model and Standard Formula firms plenty of enthusiasm to try and turn the clock backwards rapidly!

Paul Fisher, Julian Adams' replacement as Executive Director of Insurance at the PRA, kicked off with a set of Solvency II vox-pops;

  • Solvency II is the "main game in town"
  • "The end is in sight"
  • The PRA are "not gold-plating the Directive"

A nice bit of reassurance at kick-off time then - unfortunately, the clarity which was to follow from the technical specialists on a range of topics was probably not what everyone wanted to hear, given the tone of some of the audience questioning that followed! In particular (and with everything in full quotation marks below having been said by a PRA rep on the day);

  • That the PRA will "have to prioritise" if everyone in the IMAP queue for 'from 2016' approval drops their applications in at the end of June, and that applicants should be "striving to submit" sooner. Suggests to me that the smaller firms in IMAP may get bumped to squeeze in the big boys.
  • The reinforcement of Mark Carney's message from the other week that they will have no problem refusing permission to use models, though this was couched by Fisher in the more appropriate context of failure to meet any of the TSIMs simply "cannot be allowed".
  • That, although over 90% of the UK industry was down for using Standard Formula, the PRA will be equally aggressive when challenging their preparedness as they will for IM firms.

I didn't hang around for the afternoon sessions as I had a hot date with BA, so pull whatever you can out of the Other Approvals and Regulatory Reporting slideshows. However, I would draw attention to the following from the earlier sessions:

Implementation and Policy overview

  • The Old Lady of Threadneedle Street protested through multiple speakers about how they recognise that bank and insurance internal models are different, and how Insurance Supervision is now "embedded into the Bank" - I would assume to justify the credit crunch-influenced aggression now being taken by the PRA on assessing capital models (visible from Adams's speech around the time of BOE/FSA merger right through to Bailey's speech at Mansion House on Thursday night).
  • An interesting slide 3 about how much more work Solvency II will generate for the PRA from go-live!
  • Referred to FLAOR only once before switching to ORSA, suggesting that this disposable acronym is as much of a pain in the neck for the supervisor as it is for firms!
  • Highlight what "Good" and "Bad" ORSAs have contained to-date. Clearly some firms are box-ticking, leaving an unusable report which is only skin-deep compliant as output. They were particularly scathing on Stress and Scenario Testing efforts, and implored that Reports should not be written for the PRA's benefit (though naturally must cover what the DAs and EIOPA have already set out).
  • A nice piece was discussed around the expected depth of director-level knowledge of their internal models. Andrew Bulley made a useful distinction between "conceptual" and "technical" knowledge, where your dithering 80 year-old INED from the fishing industry might not be expected to understand correlation matrices, but should probably know their significance, and alternatives to them.
  • For model applications to date, far too big ("encyclopedic" in cases), with too much process description, and not enough on assumptions and expert judgements.
  • That it is a firm's responsibility to "ensure compliance" with the Delegated Acts, and given their lessening proximity to the legislators, the PRA flag in advance that they will not be able to give "concrete advice" to firms in future.

Standard Formula

A particularly good ground-setter, given the dearth of work published previously on Standard Formula firms and the PRA's expectations. Calendar included on the slide pack, which will be of massive use to your PM/PMO staff!

  • PRA will review ALL firms ahead of 2016 for SF appropriateness - "priority" firms assessed by Q1 2015, everyone else by end of 2015.
  • While SF SCR is apparently close to current ICG numbers for GENERAL insurers in the UK, it is noticeably larger in LIFE firms 
  • PRA is "not promoting" SF ahead of internal models
  • Vigorously directed all attendees to EIOPA's Underlying Assumptions of SF Paper - expectation that some firms won't read it, and just expect SF plus any add-ons?
  • Very vocal on the "significance of the deviation" between SF SCR and one's own Risk Profile - as we know, the Delegated Acts quantify what 'significant' is in the context of capital add-ons
  • An expectation that ORSAs will be used in the assessment of SF appropriateness - qualitative for sure, possibly quant elements as well?
  • Range of examples of where significant divergences are being found, by Risk Category, and by Life vs General Insurer.
  • A lot of emphasis on Capital Add-ons being used "only as a temporary measure", which will ultimately allow firms to PIM/IM or de-risk. They are however "patient and realistic" on how quickly that change can be done, so it sounds on the face of it like 2016 and 2017 will be targeted for Capital Add-on elimination.
  • In the following session on models, a piece came up on Capital Add-ons, where the PRA confirmed that their process for handling these in future is "still developing", though they expect them to be "a lot, lot rarer" than the existing regime of ICG.

Internal Models

Calendar also provided for IM firms (slide 4), showing how tight their schedule is, and explaining why they threw the earlier curveball about all firms expecting to drop their applications in on 30th June 2015. They also touched on the following:

  • Highlighting weak areas identified to-date such as over-optimistic (new?) business plans being used in capital calculations; ENIDs; omission of certain "Key Risks", and suspiciously low correlations
  • That Use Test is "fundamentally important", and is an opportunity for firms to "put their money where their mouth is". They do not expect to see either end of the use spectrum i.e. no use, or blind use!
  • Too much technical actuarial validation seen. Usefully suggested that validation questions may be better posed as "where might this model be inadequate", rather than "why is it OK".
  • Confirmed that the PRA's SAT has now been replaced by EIOPA's CAT, which won't arrive until the back end of this year - surprisingly, no-one laughed when they said this "might create some work" for existing IMAP programmes!
  • Importantly, they stressed that their powers are to Approve or Reject applications, with no "conditional" powers whatsoever. Attendees were therefore encouraged to delay applications which were thought to be unlikely to succeed, both now and in future.
Though they instinctively feel like they could have been supplied sooner, the clarifications provided in the presentations I witnesses will be hugely welcome by programme directors and PM's alike. I would venture a guess that they will be less welcome by executive committees, who may have hoped for more flexibility on the risk quantification front post-2016.

Friday, 19 September 2014

FRC on Risk Management and Internal Control disclosure - insurers way ahead?

Muddy Waters
- public disclosure on Risk
The UK's Financial Reporting Council have released guidance on Risk Management, Internal Control and related reporting, just in time to help muddy the waters for UK insurers, who have no doubt finally got their risk, actuarial and compliance functions writing non-conflicting words with Solvency II preparation in mind!

Anyone who has written, peer-reviewed or socially read these sections of public reports (i.e. me, and any other geeks), will know they are normally;
  • Boiler-plate, and completely transferrable between industries, regardless of their disparate risk profiles
  • Aligned to the Strategy sections with a few anchor words, but otherwise divorced
  • Frequently unaligned with the ERM frameworks used internally - i.e. "this is what the City wants to read", not material on our actual risk profile!
Given that this is only guidance, and is further only directly relevant to LSE listed entities, readers may be inclined to take the content with a fistful of salt. There are a number of noteworthy aspects to this publication however which maybe show where the mindset of supervisory-types has got to in the eight or so years since the financial crisis commenced.

 I took the following general points from it;
  • Very little for listed insurers to be concerned about, if they have prepared adequately for ORSA and supervisory reporting (SFCR, RSR) - indeed, their reporting teams will be delighted with the amount of content crossover! Check out the (still not finalised) Delegated Acts of Solvency II in order to see why listed Insurers won't need to stretch to meet these.
  • Frequent references to "culture", as opposed to "risk culture". Checking the FSB's take on Risk Culture from April of this year, one can appreciate the FRC's desire to gemmy culture into these guidelines, if perhaps not the execution - one fears the "culture" words are likely to become a little weasely.
  • Multiple crossovers into ORSA language, in particular re-emphasising the importance of the alignment of risk management with business strategy.
  • Good work in section 4, bringing in the "IMMMR" concept from Solvency II, as well as assessment of current and emerging risks, and assessing exogenous and endogenous risks when doing so.
  • Recommend that risk assessments are performed at inherent and residual level, and that control effectiveness is also considered when arriving at one's final assessment
On the technical front, the following elements caught my eye
  • "Emerging principal risks" used as an expression - not sure if that stands up to scrutiny i.e. if something is emerging, can it be a "principal" anything? How would you measure it to gauge "principality"?
  • Reference to "high profile failures in risk management" in recent years, which feels a little finger-pointy - we could deconstruct every corporate failure to one of risk management failure
  • "Risk Appetite" put into inverted commas within the guidance, but not in the appendices - can't quite work out the aversion to definition given the FSB's work to date at the very least, but certainly EIOPA have similarly dodged it (p59), and looking at Appendix 1 of the Irish regulator's thought paper on Risk Appetite, one can see why!
  • "It is the role of management to implement and take day-to-day responsibility for board policies on risk management and internal control" - really? responsibility for their implementation, sure, but policy content?


Thursday, 20 March 2014

The PRA and Insurer Business Model Analysis - emerging risks into capital add-ons?

A rather revealing "topical article" was pushed out by our pals at the PRA this week, mouthwateringly titled "The role of business model analysis in the supervision of insurers".

I obviously threw my Woman's Weekly professional reading materials to one side in order to see how much juice there was in this particular fruit, and it is certainly worth a glance for anyone in the risk management game, if only for the idiot's guide to Life and General insurer business models it provides!

Ironically, in the Life Insurer case (where they have chosen 'non-standard annuities' as a paradigm-changing product offering), they weren't able to forecast yesterday's scuppering of the UK annuities market in its entirety in their business model analysis!

It actually reads as quite a good case study in how we should be conducting emerging risk assessment against one's prevailing strategy, walking through specific changes in the operating environments of Life and General Insurers driven by both exogenous and endogenous factors.

With the price comparison website example, it is a good example of how a strategic risk filters down into second order risks which require reconsideration. The annuity example shows how the impact of competitors can impact both existing new business streams and the risk profile of one's existing book.

There is evidently an enormous emphasis being paid in the regulator's BMA activity to those grim business school concepts no doubt already permeating your emerging risk assessment processes such as SWOT and PESTLE analysis, as well as what (in future) will be supplied under Solvency II, most notably Profit and Loss Attributions and ORSA supervisory reports. I'm sure we will see over the next couple of years how the PRA's demand for these very sensitive in-house outputs materialises into supervisory action!

What perhaps Risk and Capital Management functions should be particularly cautious of is the leitmotif of the PRA "responding pre-emptively" where they feel that profits are not aligned with the risks insurance firms are taking. The following quote is of particular concern, as I can't see how this and the ORSA supervisory report aren't sharing the same womb (my emphasis)!;
"...the results of a BMA exercise help to inform the PRA's expectations of a firm's financial and non-financial resources. For example, the PRA might raise capital requirements, or require a firm to improve its governance process, to address weaknesses identified by BMA"
Bearing in mind we are months away from the first glut of ORSA material being delivered to Moorgate's finest, is the industry about to fertilise an expensive new world of capital add-ons via supplementary business model disclosure?

I appreciate that it has been emphasised by the PRA (p8) that ORSAs, and their supervisory reports, simply cannot be used to set regulatory capital, but in the context of what is being stated by the BMA team here, would they really be ignored?

Thursday, 28 November 2013

Accenture Insurance Sector research - Global Risk Management survey

Flood Risk?
A nice generic risk management benchmarking piece from the guys and girls at Accenture came out this week, and after I spent last week at the Leicester rugby game, I was happy to see another 15 "tigers", albeit this time scattered throughout the survey paper itself, presumably as a subtle metaphor for "death by tiger" risk...

It is made up of 98 C-suite respondents (nicely spread across disciplines), is Insurance sector-specific, and Global in coverage (one-third Europe, half N.America), so should be useful to any reader for trend-spotting and Board briefing.

From the document itself, I've pulled out the following;

Risk Governance
  • 98% have their "risk management owner" reporting to the CEO
  • 96% have a senior executive (regardless of title) as "risk management owner"
  • 80% have their "risk management owner" report regularly to the Board
  • 55% had a titled CRO
  • A number of those stats (whilst improved since their last survey) are a poor reflection on the Global insurance industry, but perhaps reflect where corporate culture is outside of the EU/US axis
  • Of the governance bodies, I was surprised to see only 60% of Life companies have an operational risk committee
Solvency II/Non EU equivalent legislation-specific
  • Over 80% of Life and P&C respondents seem happy that they are preparing well for their regulatory initiatives (Solvency II or local equivalent).
  • Other than Internal Model development, the main outstanding issues for Life insurers to be prepared for Solvency II/equivalent is IT architecture and Data Management/Integration. For P&C, documenting risk processes and developing a meaningful Use Test are also worrying at least half of respondents.
  • Issues such as training and education, risk culture and risk governance documentation are relatively low on the priority list.
  • Conversely, when asked on a 1-5 scale about specific areas of risk governance, respondents were more positive about their Data preparations than their risk governance - go figure!
  • Use Test preparation remains a laggard throughout.

Generic

  • Top external pressure was Legal risk, and by a good distance. Regulatory risks relatively low on the list, perhaps reflecting Europe's low weighting in the quantum surveyed.
  • Risk Management seemingly well integrated with strategic deployment, but not with product development or reward.
  • Poor statistics around embedding risk management into core functions.
  • Two thirds of Life respondents noting that a lack of "early warning capabilities" impedes emerging risk management.
  • Over half of Life companies said investment benefits ("above and beyond" continued compliance with regulations) would come from better reporting and better integration of Risk and Finance.
There is some of the softer stuff on aspirational elements of risk management thinking at the back, but if you just want to check against your peers, you can save that for a rainy day.


Monday, 30 September 2013

System of Governance - EIOPA's FINAL preparatory guidance for national supervisors

Based on feedback received since their initial consultation paper was released, EIOPA make the following generic clarifications/statements in the preamble of their guidance doc for System of Governance preparations;

  • That proportionality will not be defined or presented as examples in the guideline text (p5-6)
  • That NCAs are "expected to...review and evaluate the quality of the information provided to them" - bad news for the PRA, who were clinically uninterested in reviewing Solvency II reporting attempts according to one blogger (p6)
  • The emergence of a new ORSA acronym, "FLAOR", which looks more like something an amused teenager would write on Facebook (p6)
  • The expectation that 2015 will see submissions of (2014) ORSAs to NCAs (p7)
  • While there is no generic take on what enforcement action should take place in this interim period, firms are expected to (a) Discuss any negative findings from their ORSA/Governance systems with their supervisor, and (b) To produce SCRs using information of appropriate quality. Enforcement action in the absence of this WILL NOT consist of capital add-ons, apparently (p7)
  • That the submission date calendar for all of the information expected will be reviewed at the end of this year, so that EIOPA can take Omnibus II progress into account (p8)
  • That the explanatory text in each set of guidance is NOT part of "Comply or Explain" (p9)
  • That the reasons behind a negative "Comply or Explain" decision from any country will be kept secret as standard (p10, and disgraceful, frankly).
They then go on to focus on some of the larger bones of contention within the 52 guidelines provided. The following generic points stand out for me as a practitioner;
  1. There is almost no discernible movement in EIOPA's position, even after a volumous lobbying effort;
  2. That explanations for the inclusion of contentious content are generally forthcoming, though on a number of occasions, flimsy;
  3. That planning for 2014 full-year mothballing of Solvency II programmes is not an option, particularly for ICAS+ candidates - some may get away with a few months of inertia, depending on the quality of their paperwork (strategies, policies, process guides/maps, terms of reference, charters etc).
The following supporting arguments for EIOPA's final view were, in my mind at least, poorly formulated, regardless of whether the end result is still agreeable;

3.48 (Guideline 6)
- Refused to add more definition around what constitutes a "significant decision", which is poor form.

3.58 (All of Chapter III)
- That the expectations of Risk Management in insurers  "...comprise risk management standards which are considered to be matter-of-course and wide spread activities" - extraordinarily loose, considering the lack of a majority-accepted global, or indeed pan-European standard on the subject (IRM/ISO/COSO/FERMA/FSB's efforts notwithstanding)

3.65 (Guideline 19)
- That, while it is "not an easy task", Operational Risks should be quantifiable, and therefore subject to tolerance limits - I don't think it would have hurt to suggest (or even compel the use of) a method if it is that difficult.

3.68 (Guideline 25)
- That firms should maintain Investment Risk-related KRIs outside of what might be provided by normal parties (for example, ratings agencies), which would help "...increase overall risk management" - not entirely convinced that a generic "increase" is any kind of worthy ambition. 

3.74 (Guideline 31)
- That a capital management policy and capital management plan is both necessary (though for not entirely convincing reasons when tying back to the Directive)

3.78 (Chapter VI [Internal Control])
- That there is already plenty of clarification on what the Compliance function is charged with. I would agree in principle, but have heard evidence to the contrary in practice.

3.81 (Chapter VII [Internal Audit])
- That they neither wish to mandate or discourage rotation of Internal Audit staff or whistleblowing direct to NCAs - in which case, why mention it!

3.110
- A bizarre comment in response to a suggestion that a public statement should be released by the AMSB annually regarding the discharge of responsibilities around the system of governance that the Directive "...only deals with internal governance, not corporate governance" - think I know what they are fishing at, but terribly worded.

3.144
- Justify their decision not to define risk appetite and risk tolerance in the context of these guidelines

They have however provided some more defendable clarifications, for example;

3.51 (Guideline 11)
- Clarified that the gold-plated "Fit and Proper" requirements apply to AMSB/Control Function staff only, as well as specify what is expected from Outsourcers.

3.57 (Chapter III [Risk Management])
- That in the context of separating the duties of the Risk and Actuarial functions, the Directive is abundantly clear and that undertakings "...cannot deviate from [the Directive's] distribution of tasks"

3.62 (All "Policy"-related guidelines)
- That efforts should be targeted towards drafting the required documents during the preparatory phase. I would imagine this would be "re-working" in the UK, where such activity is most probably long done.

3.67 (Guideline 19)
- That there is no compulsion for firms to operate an electronic database to store operational risk events

3.85 (Chapter VIII [Actuarial])
- That, regardless of the absence of a valuation framework for TPs, the processes behind their co-ordination and calculation justify early activity, rather than "wait and see" on Pillar 1.

3.124
- Regarding Op Risk, activity will have to include "...identifying all operational risks that have crystallised and their near misses" (my emphasis)

Relatively easy in summary then - if it was a gap/issue in your system of governance in March, it probably still is, so go and fix it!

Monday, 12 August 2013

PwC and CSFI's 2013 Insurance Banana Skins survey - "Conduct Risk" firmly a la mode

Following on from the 2011 version, PwC and the Centre for the Study of Financial Innovation have pumped out another version of their Insurance Banana Skins survey, identifying how well the insurance industry feels it is prepared to handle a list of pre-identified risks. The average response on a scale of 1 to 5 was 2.97, which rather unrevealingly suggests the industry is averagely prepared to manage its collective risk profile.

EU Legislative process - not for vegans
This survey was conducted during March/April 2013, and elicited 662 responses from 54 countries, with two-thirds of respondents coming the insurance industry (the rest consultants/brokers etc). Almost half were European, so no surprises that the risks emerging from the regulatory environment were top of the pops for the second survey in a row. Solvency II gets a particularly flavoursome mention, with reference to its struggles to get through the "Brussels Sausage Machine"...

Bearing in mind the exquisite pressures being applied by the EU machinery to quantify risk, this publication is a welcome return to horizon scanning, qualitative assessment and emerging risk, all of which is handy for the ORSA posse, who according to recent surveys, should be all over this during 2013.

Some very interesting snippets emerge from the report, in particular;

  • "Conduct Risk" - if ORSA was the new boy in 2012, then its 2013 counterpart is surely Conduct Risk, which I suspect didn't warrant a category of its own in many risk managers thinking until the return of twin peaks regulation in the UK. Conduct Risk has shot up the charts in its significance for insurers, now sitting 4th (from 18th last year)! Specifically, the suggestion that insurers are now "...looking beyond conduct risk as simply a compliance exercise" makes you wonder what some firms through were acceptable products in the last 10 years!
  • "Guaranteed Products" - was not listed last time around, now jumps to number 6
  • Actuarial Assumptions (which can easily mask the emergence of a number of the risks listed) unchanged at 12th
  • Capital availability down from 2nd last time to 16th this year - interim period been spent squirrelling capital away, or happy that the onerous elements of Solvency II are (thanks to Germany) in the distant future?
  • Reputational risk still in mid-table, at 14th
And sectoral/country specific;

  • Surprisingly, the Life sector doesn't have actuarial assumptions in its top ten concerns
  • Equally surprisingly, the non-life sector doesn't have regulation in its top ten concerns - clearly happy with their proposed Solvency II lot!
  • That reputation doesn't feature in reinsurer's top ten - with customers likely to be eager yet more discerning  under Solvency II, one would think this is an area for enhancement in order to stand out from the similarly-rated crowd
  • The quality of risk management appears to have spiked as a concern largely due to the emergence of emerging market firms into the space playing catch-up (on paper at least), as well as concerns that some firms are playing at risk management without making necessary adaptations to the prevailing risk culture.

Wednesday, 7 August 2013

Deloitte's 8th Global Risk Management Survey - cause for concern?

A survey from Deloitte has recently hit the news stands, namely the 8th edition of their Global Risk Management Survey - I thought I'd postpone my August holidays to pick through the bones of it (?).

The data was gleaned from an online survey they sent out to CRO/equivalents back in Sept-Dec 2012, so is a bit dusty, and there were 86 respondents, so a half-decent sample. It isn't dominated by a particular sector or continent (p7), but there are more conglomerate/bank-heavy respondents than pure insurers.

There is an infographic for those of a short attention span with a few headline numbers, but having sifted through the larger doc, I found the following elements worthy of note;

Boards, Committees and Risk Management
  • 80% of Boards are reviewing and approving Risk Management Policies/ERM Frameworks and Risk Appetite Statements. Bearing in mind the types of organisation in the sample, that is disappointingly low.
  • 25% don't review individual risk policies
  • 23% don't review strategy against risk profile
  • Almost half don't invite CRO to EXCOM meetings
  • Almost two-thirds delegate risk oversight to satellite committees (and two-thirds of those delegate to a Risk Committee)
  • Only half have their Risk Committee chaired by an INED.
  • Use of specific management risk committees for individual risk types tends to cluster around the 40-60% bracket (for example, 60% have an ERM committee, while 44% have an Op Risk Committee). Heavily weighted by organisation size i.e. larger ones tend to have them! 
  • Emerging risk reporting not supplied to 30% of Boards
  • Model validation results not supplied to 70% of Boards!
  • 66% (of insurance respondents) have their Boards responsible for reviewing economic capital results
CRO and Risk Management Function
  • 97% of large respondents have a CRO, 81% of smaller firms 
  • 88% using "3 Lines of Defence" (almost all of the larger respondents do)
  • 62% have an "ERM Programme"
  • 58% increasing risk management budgets (still!)
  • In the list of tasks currently performed by CROs, the fact that only 63% are involved in the approval of new business lines/products is pretty telling, and not in a good way.
Other control functions

  • Almost half of respondents said that Internal Audit and the ERM Framework do not use common risk categories and language.
  • 33% do not have a independent model validation 'function' (remember, the banks are in these stats as well!) - most of those who have made provision park it in the Risk Management function.

Risk management techniques

  • 90% using some form of stress testing in the business, with most saying the outputs are used in business planning, strategy setting and identifying risk tolerance. More than half however don't use the outputs in the allocation of capital to lines of business.
  • 74% have some type of Stress Testing policy
  • Over 20% either do not have a Risk Appetite Statement, or only have a quantitative one
  • Almost 70% still use regulatory capital as one of their quantitative measures in their Risk Appetite Statements
  • Risk limits tending to be set at enterprise level, as opposed to business or desk/subsidiary level - stats are a little murky due to the emphasis towards banking sector.
  • Model risk and Liquidity risk seem to be the risk types least factored in to companies ERM programmes
Management of Key Risks
  • Full list on p24, with the percentage shown representing the number of respondents who thought their management of each risk was "extremely" or "very" effective - stand outs were that perceptions of the effectiveness of the management of Operational, Model, Outsourcing and Data risks appear to be much lower than one would hope, with Lapse risk management ranked unusually high.
  • Op Risk KRIs and Loss data only collected in 60% of respondents
  • Just over half are modelling Op Risk in some way - varying degrees of complexity experienced
  • Most are using stress testing and/or reserving to assess Insurance risk - over 40% not currently using EC, and over 50% not using VaR.

Risk and Reward

  • Almost 60% of remuneration schemes have no clawback provisions
  • Almost 70% of schemes do not align incentive payouts with the term exposure of the underlying risks

Solvency II-specific
  • 92% (of relevant responders) will focus resource on ORSA in next 12 months
  • 77% will focus resource on Data Quality in next 12 months
  • 69% will focus resource on Documentation and Reporting in next 12 months
  • Less than 25% rate their processes and systems for Data Governance extremely/very effective.
  • Declining trend of insurers who will be modelling economic capital (p19)
  • Only 80% actually calculate Economic Capital
  • Some very grim stats on p21 covering which risk types are modelled for EC purposes (underwriting risks seemingly very low on the list)
There are a number of areas touched on here which fall short of pending (or indeed actual) national/international regulations and codes, never mind "best practice". Perhaps we can account for the innate conservatism of CROs in their responses, and assume things aren't quite as bad as they have self-assessed here?

Tuesday, 9 July 2013

Actuarial profession and the Risk Function - from 'land grab' to 'colonisation'?

Back in the early days of this Blog I used to post frequently on the Solvency II-sponsored creep towards Risk functions in insurers being 'Chiefed' by members of the actuarial profession as a matter of course rather than choice (here, here and here for a start). It was even a thread in a presentation I delivered to ILAG in late 2012 around areas of control function crossover, in particular that the actuarial profession was acknowledging that there were professional deficiencies in their ability to address the basics of an actuarial function under Solvency II, yet preferred the ambition of conquering a newer (less arduous?) space ahead of remedying them.

Whilst a quant is no doubt a decent fit for such a task, it was an evident snub to the nascent Risk Management 'profession', who took umbridge at the implication of such compulsion from the UK regulator in April 2011, though with seemingly little impact. However, limits to the amount of time and money bodies such as the IRM and FERMA can throw at developing a one-size-fits-all Risk Management qualification package that can appeal to quants and non-quants alike, plus some furious inter-squabbling in the ISO 31000 world, are certainly not lending any credence to "Risk Management" as a profession in its own right as we stand.

Risk and Actuarial professions - 'Poles' apart?
Over in Ireland, the opportunity for the Actuarial profession to secure an additional control function has been pursued so rabidly that the SAI incoming and outgoing presidents were recently able to congratulate themselves on having busted into "the new frontier" of Risk, and are now moving on into "colonisation mode" (p2)! In the UK, the Institute and Faculty of Actuaries already seem to consider that area of influence secured judging by the new president's remarks recently, indicating a desire to influence more mainstream debates than those around risk management systems and corporate governance.

The UK and Ireland don't appear to be the only ones afflicted by the perception of compulsory quants in Risk functions. Munich Re's excellent Knowledge Series delivers a Germanic take that there is "no doubt" that professional mathematicians will be needed for tomorrow's Risk functions.

When considering the history of the Actuarial profession (beautifully summarised here), there should be no reason why Risk Management cannot achieve a similar position given time, regardless of the disparity in existing approaches from representative bodies. A modular qualification which can prepare a 'risk professional' for their favoured activity (insurance buying/continuity management/financial risk/op risk/ERM) is surely an ambition which those bodies can harbour in concert? My concern would naturally be that I probably don't have another 50-100 years to wait for the that convergence to happen and enhance my own career prospects!

Or maybe I do - does anyone know an expert in longevity?

Thursday, 23 May 2013

Risk Appetite white paper from Oliver Wyman - hold the onions...

A white paper on Risk Appetite from Oliver Wyman caught my eye recently whilst fishing for supporting materials for my own take on the matter. I have covered on this blog a range of opinion
Risk Appetite - need to 'ketchup' with
latest benchmarks?
pieces on Risk Appetite from the professional institutes to the consultancies to the regulators perspectives, and so far they never seem to be on the same page at the same time.

From the Solvency II perspective, we know that (as it stands) Risk Appetite only exists in written word in Level 3 System of Governance and ORSA guidance, namely;
  • That the AMSB is "ultimately responsible" for setting it (Sys Gov G15)
  • That EIOPA did not wish to distinguish between "risk appetite" and "risk tolerance", rather let national regulators and the industry scrap out any divergence in term usage themselves (Sys Gov p30-38!)
  • On that basis, "Risk Appetite" doesn't even feature in the L3 ORSA Guidance, though "risk tolerance limits" do (ORSA G7 and G11), perhaps indicating what terminology EIOPA prefer.
From the national regulatory perspective, the PRA have ingrained its importance as the "foundation of [an insurer's] risk management framework" in its new approach paper (section 110), whilst the Central Bank of Ireland have not only built Risk Appetite into the supervisory structure, but even had time remonstrate with the industry for its lack of progress around Risk Appetite statements!

The ratings agencies expectations on Risk Appetite also come into play, with S&P expecting its "clear communication" and "linking to risk limits" as part of its ERM assessment programme (p5, and more extensively, p9). They do however have the courage to define their terms with respect to appetite, tolerance and preference in the appendix. 

Appreciating therefore the Oliver Wyman paper is catering outside of the financial services sector, it still contains a host of rather inane platitudes such as;

Risk Appetite Framework
"...bringing discipline to major strategy decisions" - as opposed to the Chief Exec and Chair? 
"...essential for firms considering an ambitious growth strategy" - as opposed to all firms?
"...developing a robust risk appetite framework does not take an inordinate amount of time and effort" - might want to tell that to the rest of the invoice-generating consultancy world!
Risk Appetite Statement
"...more than just a set of benchmarks" - at what point has a RAS ever been that?
"...setting the 'tone at the top' about the relationship between risk and return" - "tone" as opposed to "rules"? 
It also contains a number of apocryphal tales and irritants, such as
  • Senior management "often" fail to take risk appetite into account - probably true even in the financial services world pre-2007 (indeed it was a major feature of the Lehman's autopsy!), but one would think less so now.
  • "Few" companies able to unlock benefits of a risk appetite framework - that feels a bit light, though I don't doubt some firms may struggle depending on their corporate structure and industry.
  • Frequently interchanging between "Framework" and "Statement" throughout, in the same way as many ORSA-related materials do so for "Process" and "Report".
It ultimately recommends that a Risk Appetite Framework should contain the following characteristics;
  1. Qualitative and Quantitative Risk Appetite Statement
  2. Ensure the statement content is "useful" for all internal stakeholders (Board, Senior Management, Financial analysis teams and business unit leaders"
  3. Connect the statement to the planning, review and decision making processes and forums

There are also a number of positive elements within the document, which I would certainly advocate, such as;
  • Size Limit - they recommend no more than 4 pages for a Risk Appetite Statement, and one could probably get away with less
  • Concepts of Ability (what one can technically afford) and Willingness (to tolerate uncertainty)...
  • ...applied as appropriate to a set of qualitative and quantitative themes which are pretty much ready off the shelf (p3)
  • Ensuring the metrics used for monitoring are company-specific - very easy to replicate what one has seen in previous firms, but these will inevitably not make the cut in decision making processes, thus defeating the point.
I'll be doing more on this topic in the near future, but for now this material may at least be of use to you for benchmarking purposes.

Friday, 29 March 2013

EIOPA Preparatory Guidance - ORSA (or 'forward looking assessment of risks')

Forward-looking assessment of the undertakings own risks (based on ORSA principles) (plus explanatory text)

The ORSA preparatory guidelines* are not a massive burden for anyone busy rolling eggs down hills at the moment, coming in at 34 pages containing 25 guidelines, as well as 29 pages of explanatory text. In this instance, it is probably disappointing to any underprepared supervisors and insurers in that they may have preferred more!

More pointedly, the materials add little to what was already in existence from EIOPA in July 2012, and certainly will required little in the way of adaption in the UK's instance, who are already in a similar headspace and have been advising accordingly.

Of course the world and her husband have piped up with their opinion on what ORSA should cover and how it should be administered and documented (this post has a decent sweep at capturing most of them), so opinion on this matter is something we are not short on.

For me the headline points are:
  • ORSAs (well, 'overall solvency needs assessments', but let's be serious!) expected from 2014
  • Internal Models should be used by anyone in pre-application
  • Likely that most standard formula firms will have to qualitatively assess deviations between SF and their own Risk Profile at this time
  • Expectation of an internal ORSA report and a ORSA supervisory report
  • Records of the assessment expected to be documented and kept which must be "appropriate" - no prescription of what that means
  • ORSAs to be performed at least annually
The following points are either new, or worthy of reiteration for anyone whose preparations on this front are less than certain - for ease of reference I have used 'ORSA' where EIOPA use 'forward looking assessment of risk', and as with the other preparatory guidance papers I have looked at, I will assume there will be blanket application as written, with no dissent from industry or NCAs:

Guideline 3
  • Overall Solvency Needs assessments will be expected from 2014 (i.e compliance with Article 45.1)
  • Minimum of 80% of the market must also assess whether they would comply with the Articles 45 (b) and (c) from 2014 - regardless of any Pillar 1 uncertainty.
  • Internal Models expected to be used in ORSAs if a company is in model approval pre-application
  • IF the standard formula is 'provided' by 2014, expectation that SF firms will assess deviation between the SF assumptions and their own Risk Profile - this excludes anyone outside of the magic 80% catchment figure mentioned above.
Guideline 6 - Documentation generated by ORSAs must include:
  • An ORSA Policy
  • An ORSA Record
  • An Internal ORSA Report
  • AN ORSA Supervisory Report
Guideline 7 - The ORSA Policy must include
  • Description of component ORSA processes and procedures
  • Consideration of the linkages between Risk Profile, Risk Tolerances and Overall Solvency Needs (OSN)
As well as information on
  • frequency on stress tests, scenario analyses and reverse stress tests; 
  • data quality standards; and 
  • the frequency of the assessment, justified in relation to Risk Profile, volatility of OSN relative to capital position, timing (from calendar perspective I guess) and circumstances for ad-hoc assessments
Guideline 8 - ORSA Record
  • Firms expected to "appropriately evidence" the assessment - no prescription as to what that means (logs, working papers, meeting minutes, e-mails)
Guideline 9 - Internal ORSA Report
  • AMSB must communicate results to "all relevant staff" post-approval, which includes the ORSA results and conclusions
Guideline 10 - ORSA Supervisory Report
  • 2 weeks after concluding ORSA, ORSA supervisory report must be submitted, which must include;
  • Quantitative and qualitative results, and conclusions drawn
  • Methods and main assumptions
  • Comparison between Own Funds, SCR and OSN
Guideline 11
  • Must quantitatively estimate the impact of different valuation bases (if used) when assessing OSN
Guideline 12
  • OSN must be quantified, supplemented by a qualitative description of all material risks
  • Expectation that these items are all stress/scenario tested
Guideline 17ORSA output to be used at least for;
  • Capital Management
  • Business Planning
  • Product Development
Guideline 18
  • ORSA to be performed at least annually

* So let's end with something fundamental, EIOPA - it is NOT useful to replace 'ORSA', as an acronym or indeed in full, with the expression "Forward-looking assessment of risk (based on ORSA principles)" 5 years down the road - I'm sure there is a rationale, just as sure as I am not going to like it (even the GCAE agree with me, going with 'ORSA-like')!

Tuesday, 5 February 2013

Central Bank of Ireland - Prudential regulatory agenda for 2013

A pretty meaty speech was delivered last week by the CBoI's head of life insurance supervision, covering the prudential regulatory agenda in Ireland for 2013 and beyond. In essence it is a rather sobering take on the flipside of the Celtic Tiger's death and its impact on what was an effervescent, if still fledgling, cross-border insurance industry, noting that new business volumes recorded in Ireland have declined for the 5th year in a row, and currently aggregate out at a break-even APE/PVNBP margin.

I found there was actually a lot to take from this on the ORSA front, and would recommend any readers on the Emerald Isle pick the bones out of it, in particular that the regulator "expects to see";

  • Strategies reflecting "current market realities" - highlighting excessive commission to brokers, swollen lapse/surrender rates and reduced margins from over-competition.
  • Tight management of costs
  • Increased efforts put in place to retain existing in-force business
  • "Credible business plans"
  • Viable alternatives to grow business through distribution or product range changes (online facilities highlighted specifically)
While much of this may read as common sense, one can reasonably assume that the CBoI is not seeing enough evidence of this in the Financial Condition Reports and strategic plans that currently cross their desks, and are expecting a much meatier ORSA-type approach to managing strategic risks over the business planning period in the immediate future.


Thursday, 22 November 2012

KPMG's Solvency II Readiness Survey for CEE - the flaw in EIOPA's plan?

So KPMG released this little gem in the same time period as Solvency II preparedness became something of a moot point!

Drawing in responses from 84 people, with around three-quarters EU-based and 70% under £100m in GWP, the questions were posed in Q2 2012, so with Omnibus II missing the last plenary before summer holidays, the writing was already on the wall - despite that, KPMG reckon most respondees would have been working to a 2014 go-live date. It expands on their 2010 work in this area, where 44% or respondents hadn't got started on their Solvency II projects, so progress on that front would be considered a good start!

I gleaned the following from it;
  • 31% not expecting to be "Solvency II compliant" before 2014 - one problem that's gone away then!
  • Almost half do not have a risk management function in line with the Directive, with smaller companies the main culprits
  • Only 19% (down from 40% in 2010) will be using IM or PIM for SCR calculation. Attributed to the realities of building them as well as Groups rethinking their IMAP strategies over the last few years.
  • 62% of companies not even planning an ORSA dry run until 2013 at the earliest, with 14% not planning for one at all as it stands.
  • Only 14% electing to use more than 3 years as their "business planning period" for ORSA - two thirds settling for 3 years - supports the anecdotal trend of 3-5 years as par for the course
  • 20% reported that their internal models allow for multiple year calculations to project for the ORSA - not sure if that is stochastic or deterministic though, didn't think any of the kernel technologies out there could do multi-year projections
  • Half of companies have 50% or less of the data required to populate their QRTs
  • Extraordinary perceptions on staffing requirements for both project and BAU, which even KPMG are drawn into calling "excessively pessimistic and indeed unrealistic" - it may be led in some respects by subsidiaries using shared Group services, but is still shocking in its naivety.
  • Three quarters would like "more interpretation" from their regulator on Level 1 and 2 texts - not sure what there is to "interpret", so maybe its the Pillar 2 and 3 elements that they are struggling with (the other stats here would certainly lend weight to that).
  • More than half of model applicants strugglinbg with Validation, highlights assumption setting and expert judgement as problem areas (no surprises there)
  • 70% looking to define "new roles and responsibilities" around Data Governance - as referenced in my earlier post, not convinced that will end happily. Over a quarter don't plan to compile their data dictionaries until mid-2013.
  • Only a third looking to do full SCR calculations quarterly, and over 50% look like they will struggle to generate the SCR calculation faster than 8 weeks.
  • 20% have a dedicated Solvency II team - explaining a lot of the shortfalls in preparedness relative to Western Europe, but given the delays and uncertainty, a financially astute move.
What should worry EIOPA is the results around control function preparedness, or lack of it. If Sr Bernadino thinks that the low hanging fruit of Pillar 2 is ripe for picking before 2016, a quick review of those stats would suggest that a decent number of the 27 countries are in no such state.

Tuesday, 30 October 2012

Aon Benfield's CRO guide to Solvency II - in case you're not ready yet...

For all those CROs who are about to get left holding the Solvency II baby three years early by their over-enthusiastic executive colleagues, Aon Benfield pulled together a CRO guide to Solvency II which aims to take the journey "from complexity to best practice". 10 out of 10 for ambition...

It leans heavily towards General Insurers/Reinsurers (indeed it reads like a reinsurance sales brochure in many parts!), but nevertheless contains a suite of very useful content for anyone in the Risk space, as well as attempting to shatter a few myths. I took the following from it;
  • Steady early bits on capital planning and common questions a CRO should be posing in that space
  • On page 5, an excellent table comparing standard formula against internal modelling by risk driver, in particular emphasising why internal modelling may be more appropriate, rather than how much capital it could shave off. Being able to explain to the national regulator why one has neglected to apply the enhancements that internal modelling introduces to the accuracy of one's quantitative risk profile would be a smart thing for CROs to practice!
  • The undo some of that noble work by suggesting part of any IM feasibility study should include estimating the capital benefits!
  • Nice examples at the top of p6 of what mixes of business lend themselves to benefitting from an IM approach
  • Highlighting that domicile of firm continues to dictate feasibility of IMs for smaller firms (i.e some countries can't staff it!).
  • Recommend reviewing SF SCR factoring in the draft L2 asap. As was clear from the E&Y research I covered yesterday, many firms across the EU consider themselves to be advanced in the Pillar 1 space while disregarding draft L2. They highlight the Swiss experience as one where they struggled to authorise models for "Day 1" approval, and the Aon crowd propose some meaningful contingencies on p8
  • Useful analysis of capital drivers and optimisation strategies (p9-10)
  • Section on expert judgement validation (p15), touching on the Level 3 expectations, and in particular how a (non-Actuarial) CRO may struggle to adequately challenge certain judgement calls, such as selected data series or correlation matrices, without specialist advice. Very hard for smaller firms to obtain that, as most of their actuarial function will have probably contributed to the judgement!
  • Note that one of the key challenges for documenting the IM is getting the best-placed people (who are normally swimming in BAU) to pick up a pen and write!
  • Neat section on ORSA (p27-29), emphasising that SF firms with complex risk profiles may find they struggle to justify that approach when concluding the assessment. They go on to suggest that early experiences of ORSA Report/process documentation submissions have left CROs feeling that the regulatory approach is (Level 3?) tickbox as to content expectations.
  • Key challenges for CRO in briefing and educating senior colleagues for Solvency II-readiness are all fair, in particular the gap that could emerge if a CRO is not also an executive member.
  • The section on Risk Appetite is particularly useful for smaller non-IMAP firms, who may struggle to quantify their target measures - whether using Standard Deviations/volatility measures as suggested is a touch too simple depends on the business I guess.
  • The Pillar 3 section hits on the same issues I (and the FSA!)have picked up on earlier, such as end-user computing, inability to transition to BAU, data ownership issues etc.
I did take exception to a couple of bits in here, where the industry or indeed common sense appears to suggest otherwise;
  • The "fallacy" outlined on p5 that an IM enables a firm to hold less capital than an SF equivalent. The research I pointed to yesterday (p20) suggests across the EU that modellers are already "making it rain" with their capital savings
  • That the IM alternative for Op Risk is based on ORIC and individual loss event info. I'd certainly seen Milliman suggest that this approach is as flimsy as the SF approach, recommending options such as Bayesian networks to generate IM inputs.
  • Concerns that evidencing senior management model "use" could create a "value-destroying documentation burden". Is that what we call "minutes" these days!
  • Comments around the documentation delivery for the Internal Model Application Process becoming detached from the underlying processes referenced in those docs influencing BAU value-adding activity are perfectly valid, but no real solution is proposed.
  • The operation of the Model Change Policy features heavily (p19-21), as anyone in that space would expect. Again. little offered in the way of solutions, but I certainly would have expected more discussion on the "scope" of the model, which in my experience is a solid, liquid or gas depending on which control function you speak to, and I'm sure the FSA would agree!
PS All the best to you guys on the US East Coast, let's hope the worst has passed...

Thursday, 18 October 2012

Society of Actuaries in Ireland on ORSA - a rock in a sea of turmoil

In these days of certainty around the Solvency II implementation timetable (i.e. certainly not 2014!), it’s nice to cling on to the consultant's comfort blanket of ORSA which, thanks to the IAIS and NAIC, isn’t disappearing in a hurry for global insurers. This item flagged on the SAI's newsletter last month, but dating back to April, would benefit anyone working in the ORSA space, being a "practical considerations" guide which is very accessible for non-actuaries, particularly for assessing or challenging options for the required ORSA processes.
 
The document takes care to reference the at-the-time EIOPA guidelines in each chapter (which would have been superseded by June's release of course, but didn't change seismically), and does an excellent job of focusing on required processes as opposed to ORSA Reporting, which these types of papers often do. Worth reading all but noting the following;
Overview
·     Proportionality - remember justification of approach is as important as executing the selected approach itself.
·     Documentation - "...Traditionally, this is not an area of strength for actuaries" - I'll drink to that!
ORSA Contributors
·     "It is likely" that Risk will co-ordinate the process. This logic follows on from the IRM’s survey findings (p2) which saw Risk as predominantly leading early process development, and there is nothing to suggest the other candidate functions are likely to be sufficiently staffed in the BAU world to both actively participate and co-ordinate.
·     Board as "owners” of the ORSA – this is an important point which, for practitioners, is awkwardly inferred by the Directive text, rather than spelled out. Indeed this document later goes on to say the Risk function "will likely be the owner of the overall ORSA process".
This gruesome melange of who owns what in the ORSA space (and indeed what 'ownership' confers), remains a little too common in thought papers like this, so be certain to define these elements in your ORSA Policy.
·     Capital Management function - "ORSA is the process where risk and capital management get together" - get a room you guys!
Policy and Process
·     Generally a very clean and useful section, particularly around "dynamic" and "static" processes and their outputs. Section on ORSA Report content is less useful, being based on the 2008 issues paper, and there are plenty of papers covering that topic (sift through yourself!).
·     Projection process - No suggestion of whether recommendations from balance sheet projection activity should be balled up in the ORSA Report or reported separately as part of conventional committee/Board reporting. I always found this element a nuisance to pin down, as one wouldn’t necessarily want to present material of such significance in a 20-200 page ORSA Report if it meant it didn’t get the appropriate table time at strategy days etc.
Economic Capital 
·     Practical obstacles - all seem to revolve around there being a shortage of actuarial time/resource. Well get off my land and go do some counting then!
EC and Risk Management
·     Document is a little unclear around risk appetite framework/risk management framework/risk management system terminology, which is a little unhelpful
·     Interesting comment regarding non-quantification of risk that "risks cannot be quantified" rather than "risks cannot be quantified easily" – this is an actuarial paper, you guys can quantify anything, surely!
·     Define reverse stress testing as "testing to destruction" - the UK definition is more discrete than this, and certainly more useful for stimulating debate in Board exercises
ORSA Projections
·     More industry consensus on what 'business planning period' constitutes, being 3-5 years. Barely seen anything to suggest firms venturing outside this window for projection purposes.
·     Nice simple explanation of the component parts of the economic balance sheet which should be projected as well as recommendations for projecting risk appetite metrics and the P&L.
·     Suggestion that, unless already stochastically projecting, firms will project deterministically, "unless the company is planning significant changes to its future business mix". Judging by the jostling for position around Long Term Guarantees right now, is that not likely to be quite a few!
·     Acknowledge that the approaches already used for Financial Condition Reporting should be leaned on for smaller or less complex entities.
Scenarios
·     Reverse stress testing has grown into a different beast from that reference earlier in the piece, incorporating "back-solving" (new one on me!), and looks for events that reduce own funds to zero - not sure I've heard RST defined like that before, and certainly not convinced that own funds of zero necessarily constitutes "destruction"
·     Good recommendation for selecting scenarios from emerging risk assessments as well as a firm’s existing quantum – best not to take the path of least resistance in this area of ORSA.

Tuesday, 2 October 2012

Deloitte with more on the US-of-ORSA

Billed as a "regulatory guidepost to the future", Deloitte in the States have published their thoughts on ORSA developments, following on from recent activity in the space, most notably the NAIC's adoption of the RMORSA Act a few weeks back.

Hard to tell whether Deloitte have borrowed much from their European counterparts, who ponied up with the EIOPA-compliant equivalent document last week, but both documents ultimately point at the same end goal, namely getting the ORSA Process and ORSA Report content right.

Confidently declaring the first regulatory filing of an ORSA Report to be precisely, errr, "Sometime in 2015", the stateside plans are anchored more to ERM and, I guess by association, ratings agency implications. The document does help identify a couple elements which, with the Solvency II hat on, are easy to forget;
  • IAIS ICP 16 is bringing ORSA to the table of all signatories at some future juncture (which means I may get a job back home one day!)
  • Existing techniques for monitoring solvency, even in a jurisdiction of this size, are seemingly past their sell-by-date in terms of both content and turnaround time (p2) - holds true for many of the Solvency II-covered countries as well (plenty on that topic in here).
The rest of the document draws out the preparatory work which firms should be undertaking, despite the relative lack of certainty at this point in time, such as increasing real-time data availability and changes in reporting, management and governance structures. It also touches on suggested content, process implementation (more like formalisation from experience), and a checklist of operational considerations, resourcing (or even briefing/coaching) being highest priority in my mind in 2012.

Good document for you statesiders to pass round your friendly non-executive directors anyway, as an early socialising of the concept in this format goes a long way when you have tiny windows to educate them on the topic over the next 3 years - looks like you will be filing ORSA Reports before we are!

Interesting footnote is that AIG have been labelled as a potential SIFI today - ORSA may be 5 years too late to have saved the behemoth it once was, but let's hope it can help its slimmed down current-day version.