Showing posts with label risk. Show all posts
Showing posts with label risk. Show all posts

Monday, 18 August 2014

ORSA - Institute of Risk Management special interest group

Of course while I spent the last couple of months topping up my tan in, errrrr, the Isle of Man, some of the guys in the UK and further afield have been building up an endeavour-flavoured sweat on some of the more malleable elements of Solvency II preparation.

Raining 'Mann' - Glorious Manx summer
The IRM as ever have kept the ball rolling, in particular hosting an ORSA session last month. While you can pick your way through the guest speaker presentations for ideas and comfort (one company specific, one consultant generic, and one which S&ST/RST fans might like as a sense check), I was much more interested in the attendee survey.

A whopping 34 replies came in, via which the attendees have delivered a reasonable ORSA landscape mock-up, which may help some of you get matters shuffled in your priority lists, given where your peers claim to be.

I noted in particular;
  • ORSA Process overwhelmingly run by the Risk functions (over 90%)
  • Just over half going for annual frequency, the rest (who responded) naturally more frequent - doesn't instinctively feel representative, but not all of the smaller firms would send someone down to this!
  • Around two-thirds have their "Reports" at 50 pages or less - if we assume that by "report" we mean Supervisory as well as Internal, the PRA won't be too chuffed with that given their comments at the December industry seminar.
  • Only a third have submitted draft ORSA Reports to the PRA and received feedback
  • Coverage of emerging risk appears to be an area which not only do respondees think is lacking, but has received critical feedback from the PRA
That half have used external consultants in their ORSA work to-date is certainly no surprise. I'd be worried if that consultancy had more than a year's dust on it though, so think hard before you start submitting your 2014 gear!

Monday, 30 September 2013

System of Governance - EIOPA's FINAL preparatory guidance for national supervisors

Based on feedback received since their initial consultation paper was released, EIOPA make the following generic clarifications/statements in the preamble of their guidance doc for System of Governance preparations;

  • That proportionality will not be defined or presented as examples in the guideline text (p5-6)
  • That NCAs are "expected to...review and evaluate the quality of the information provided to them" - bad news for the PRA, who were clinically uninterested in reviewing Solvency II reporting attempts according to one blogger (p6)
  • The emergence of a new ORSA acronym, "FLAOR", which looks more like something an amused teenager would write on Facebook (p6)
  • The expectation that 2015 will see submissions of (2014) ORSAs to NCAs (p7)
  • While there is no generic take on what enforcement action should take place in this interim period, firms are expected to (a) Discuss any negative findings from their ORSA/Governance systems with their supervisor, and (b) To produce SCRs using information of appropriate quality. Enforcement action in the absence of this WILL NOT consist of capital add-ons, apparently (p7)
  • That the submission date calendar for all of the information expected will be reviewed at the end of this year, so that EIOPA can take Omnibus II progress into account (p8)
  • That the explanatory text in each set of guidance is NOT part of "Comply or Explain" (p9)
  • That the reasons behind a negative "Comply or Explain" decision from any country will be kept secret as standard (p10, and disgraceful, frankly).
They then go on to focus on some of the larger bones of contention within the 52 guidelines provided. The following generic points stand out for me as a practitioner;
  1. There is almost no discernible movement in EIOPA's position, even after a volumous lobbying effort;
  2. That explanations for the inclusion of contentious content are generally forthcoming, though on a number of occasions, flimsy;
  3. That planning for 2014 full-year mothballing of Solvency II programmes is not an option, particularly for ICAS+ candidates - some may get away with a few months of inertia, depending on the quality of their paperwork (strategies, policies, process guides/maps, terms of reference, charters etc).
The following supporting arguments for EIOPA's final view were, in my mind at least, poorly formulated, regardless of whether the end result is still agreeable;

3.48 (Guideline 6)
- Refused to add more definition around what constitutes a "significant decision", which is poor form.

3.58 (All of Chapter III)
- That the expectations of Risk Management in insurers  "...comprise risk management standards which are considered to be matter-of-course and wide spread activities" - extraordinarily loose, considering the lack of a majority-accepted global, or indeed pan-European standard on the subject (IRM/ISO/COSO/FERMA/FSB's efforts notwithstanding)

3.65 (Guideline 19)
- That, while it is "not an easy task", Operational Risks should be quantifiable, and therefore subject to tolerance limits - I don't think it would have hurt to suggest (or even compel the use of) a method if it is that difficult.

3.68 (Guideline 25)
- That firms should maintain Investment Risk-related KRIs outside of what might be provided by normal parties (for example, ratings agencies), which would help "...increase overall risk management" - not entirely convinced that a generic "increase" is any kind of worthy ambition. 

3.74 (Guideline 31)
- That a capital management policy and capital management plan is both necessary (though for not entirely convincing reasons when tying back to the Directive)

3.78 (Chapter VI [Internal Control])
- That there is already plenty of clarification on what the Compliance function is charged with. I would agree in principle, but have heard evidence to the contrary in practice.

3.81 (Chapter VII [Internal Audit])
- That they neither wish to mandate or discourage rotation of Internal Audit staff or whistleblowing direct to NCAs - in which case, why mention it!

3.110
- A bizarre comment in response to a suggestion that a public statement should be released by the AMSB annually regarding the discharge of responsibilities around the system of governance that the Directive "...only deals with internal governance, not corporate governance" - think I know what they are fishing at, but terribly worded.

3.144
- Justify their decision not to define risk appetite and risk tolerance in the context of these guidelines

They have however provided some more defendable clarifications, for example;

3.51 (Guideline 11)
- Clarified that the gold-plated "Fit and Proper" requirements apply to AMSB/Control Function staff only, as well as specify what is expected from Outsourcers.

3.57 (Chapter III [Risk Management])
- That in the context of separating the duties of the Risk and Actuarial functions, the Directive is abundantly clear and that undertakings "...cannot deviate from [the Directive's] distribution of tasks"

3.62 (All "Policy"-related guidelines)
- That efforts should be targeted towards drafting the required documents during the preparatory phase. I would imagine this would be "re-working" in the UK, where such activity is most probably long done.

3.67 (Guideline 19)
- That there is no compulsion for firms to operate an electronic database to store operational risk events

3.85 (Chapter VIII [Actuarial])
- That, regardless of the absence of a valuation framework for TPs, the processes behind their co-ordination and calculation justify early activity, rather than "wait and see" on Pillar 1.

3.124
- Regarding Op Risk, activity will have to include "...identifying all operational risks that have crystallised and their near misses" (my emphasis)

Relatively easy in summary then - if it was a gap/issue in your system of governance in March, it probably still is, so go and fix it!

Friday, 17 May 2013

Munich Re on Strategic Risk - ORSA food for thought

A thought-provoker from Munich Re for anyone in the business of Emerging Risk/'Top Down' risk review activity with this release called "Strategic Risk to Risk Strategy", which leans on the findings of the World Economic Forum's 2012 Risk Report to observe how the risks highlighted may compromise existing insurer strategies, as well as materialise into the thoughts of underwriters once sufficient data exists.

With coverage of "strategic risk" featuring in everyone's ORSA thoughts, as well as obligations around scenario analysis and reverse stress testing, there are some benchmarks in here that are worthy of consideration for practitioners. In particular;

Strategic Risk definition
Risk of making wrong business decisions, implementing decisions poorly, or being unable to adapt to changes in the operating environment


Subcategories of Strategic Risk
  • Ineffective M&A
  • Incorrect interpretation of external activity in a given market
  • Decision making based on poor pricing/profitability assumptions
  • Legal misinterpretation
Specific points
  • In their opinion an insurer's risk strategy "goes beyond covering the risk capital requirement for a portfolio for the forthcoming financial year on the basis of valid models" to actually questioning and enhancing a company's business. I think most practitioners would agree that any documented risk strategy would look further forward than one-year! 
  • That shortcomings around the evaluation of Strategic Risk "...are not so much of a question of the [informational] resources available", which are plentiful, nor are they especially time-pressured.
  • They also include a definition of Reverse Stress Testing as scenarios which "endanger a company's business model as a whole" - interesting purely in the absence of an EU-driven definition to-date, as it tallies along with UK equivalent definitions.
An edited list of Strategic Risk scenarios is included (p3) which you may want to line up against your own activity in this field, and follow on by exploring which of these are within and outside of an insurer's sphere of influence. You might also benefit from the diagram on p6 on the main stakeholders in an insurance company which may influence your selection of strategic risk scenarios depending on your structure and business model. 


Wednesday, 3 April 2013

UK's "new" Prudential Regulatory Authority - Approach to Insurance Supervision

So a magical thing happened over the weekend: a venerable institution disappeared on Friday, only to come back reborn on Monday...

...that's right, the FSA is no more, being replaced by two more focused entities in the Prudential Regulatory Authority (PRA) and Financial Conduct Authority (FSA). This is part of the UK-specific fallout from the financial crisis, where a perceived lack of focus from the former tripartite system which housed the FSA allowed for both systemic risk (Northern Rock, RBS) and conduct risks (PPI, Interest Rate swaps) to emerge largely unchecked.

Rather excitingly, this means a new website with some natty logos from the Bank of England (which
PRA - emperor's new clothes
or Solvency II aperatif?
has rehoused the PRA side of the FSA), as well as a statement on the new supervisory approach that the PRA will be taking.

For anyone in the ERM/Solvency II/Corporate Governance space, this gives us a chance to pick up on the kind of regulatory interrogation one might expect when writing/upgrading system of governance-related materials in preparation for both full Solvency II implementation in 20??, as well as how they are accommodating EIOPA's interim measures from 2014.

Remembering that the PRA's two statutory objectives are to promote safety and soundness of the firms it regulates, as well as specifically providing appropriate protection to insurance policyholders, I thought it wise to make some notes on how they have catered for Solvency II and deference (when due) to EIOPA, as well as the general content around expectations of governance systems. I found the following worthy of note;


Control function-specific

Section 82 - "[PRA] wants to be satisfies in particular that designated risk management and control functions carry real weight within insurers"

Section 117 - Should have separate risk management and individual control functions in place (dependent on nature scale and complexity etc)

Section 118 - the PRA "expects these functions to be independent of an insurer's revenue generating functions"

Section 120 - expectation of an "operationally independent Actuarial function", which the PRA consider to be "integral to the effective implementation of a firm's risk management framework"

Section 182 - "Actuaries can play an important part in supporting prudential supervision"

Section 119 - an effective Risk function on the other hand merely "ensures that material risk issues receive sufficient attention from the insurer's senior management and Board" - just because I'm paranoid, doesn't mean the Risk profession isn't being made something of a gooseberry here, particularly as the FSA/Actuarial profession love-in started some time ago!

On Risk Appetite

Section 110 - a firm's risk appetite "[is] to be integral to its strategy, and the foundation of its risk management framework"

Remuneration

Section 84 - "remuneration and incentive schemes should reward careful and prudent management" - just like Prudential's and Standard Life's did this week!

Section 194 - Hint at potentially restricting pay in firms if intervention is warranted


Stress/Reverse Stress Testing

Section 109 - the AMSB must have "...an explicit understanding of the circumstances in which their firm might fail"

Section 145 - with regards to Reverse Stress Testing, "...management should consider the reliability of the output of the internal model compared with the results of these tests"

Section 106 - "competent, and where appropriate, independent control functions" should oversee risk management and internal control frameworks


Internal Models

Section 116 - On Internal Models, the AMSB should understand;
  • extent of reliance on models for managing risk;
  • limitations of their structure and complexity;
  • Data used;
  • key underpinning assumptions
Section 140 - "PRA expects internal models to be appropriately prudent"

Section 144 - firms may not choose the lowest capital requirement to determine whether or not to model internally


Regulatory Capital

Section 135 - for capital adequacy, firms "...should not rely on regulatory minima", and also "...should not rely on aggressive interpretations of actuarial or accounting standards"


Proportionality

Sections 212-215 - touches on treatment of "low impact" firms - is this effectively where aggressive approaches to proportionality interpretation should be expected (combined control functions, limited documentation, passive acceptance of Standard Formula etc)?

p43 - table covering the allocation of supervisory staff - 10 staff to 1 firm for the 25 largest insurers, versus approaching 10 firms to 1 supervisor at the small end.

Solvency II-specific references
  • In the PRA's view "[Solvency II technical detail should] leave scope for supervisors of individual insurers to make informed judgements around risks posed"
  • Confirms that elements of the Directive such as Prudent Person Principle, ORSA, Control Function requirements and Pillar 1 are all aligned with the new Threshold Conditions
  • Model approval will be dependent on "adequate" risk identification, measurement, management, monitoring and reporting throughout the modelling process
  • Will impose capital add-ons when necessary "to ensure insurers meet the required standards"

Monday, 18 February 2013

Munich Re on Solvency II Control Functions - an actuary for all seasons...

Munich Re have continued their infrequent-yet-valuable Solvency Knowledge Series with a piece on Key functions within the system of governance of insurers under Solvency II.

Of course to the grizzled old set of risk practitioners who have done the rounds for the last few years, the fundamentals of the directive's requirements on the four control functions are as basic as the ingredients list for a frozen lasagne. It naturally draws attention to the likelihood that there will be "some overlap" between the activities of Risk, Actuarial, Compliance and Internal Audit, as well as touching on outsourcing as "...an attractive way of meeting the wide range of requirements" for those

However I detected more than a whiff of controversy around the content of this particular publication (which I hasten to add is a smart read nevertheless), were one to take it at face value. In particular;
  • Their use of the three lines of defence model in the publication - while perceived to be good practice for segregating operations from risk advisory from risk assurance, it is certainly not cited in any existing materials at Level 1, 2 or 3, and the structure may be disproportionate at the small end of the insurer spectrum. On top of that is the Actuarial function's acknowledged dwelling over a grey area between the first and second lines, in particular if they haven't catered separately for the reporting lines of reserving, pricing and capital management actuaries (p8).
  • The comment that "The risk management function will no doubt have to include people with a professional scientific and mathematical background, ideally backed up by appropriate qualifications (eg actuaries)". Whilst, internal model or not, the Actuarial function will clearly have to provide "considerable support" to the Risk function, I don't see any reason at the small-to-medium level for the Risk function to include actuaries unless through choice, using the lever of proportionality.
  • That the Risk function "...shares responsibility for the risk strategy" - I think the implication is that it shares responsibility with the Board, but the statement doesn't help identify a) who authors and authorizes it and b) who gets fired for its poor deployment! I am more inclined to think the Risk function owns the risk management system and is responsible for monitoring and reporting on the implementation of the risk strategy which sits within it. The FSA define their requirements on this page in any case.
  • That the Risk function "...identify potential risks and recommend appropriate countermeasures to the Board" - as far as emerging risk/top-down risk assessment goes, I certainly expect the function to facilitate the emerging risk/scenario analysis/reverse stress test activities in this regard, but it is most certainly not a solo job.
  • That "The compliance function...will have to include staff with a legal background" - appreciating what the wording of Article 46 implies in particular, this is more a proportionality/outsourcing issue for me than anything. Having said that, I'm sure any existing compliance professionals out their who didn't take the Bar might feel slighted by this! 
  • That "all four functions have a direct reporting line to the Board" - not certain that this is so in the vast majority of cases. Certainly via Board committees the Risk and Internal Audit functions will be well catered for (and the FSB recommended even better than that for the Risk function last week), but I suspect an executive reporting line is as good as it gets for the other two functions in most firms.
Certainly plenty to engage the grey matt with regardless of your country of origin, even around control function crossover areas (which I presented on at the end of last year), so dig in.

Monday, 10 December 2012

Governance Matters at ILAG - Co-operation between control functions under Solvency II

Been a bit quiet on the Blog front - not because my country and I are licking our wounds after being opened up by HMRC like a Manx kipper, but because I had been asked to chip in with my two cents at an event hosted by the Investments and Life Assurance Group in London. It was an exceptionally well run event, with some interesting takes on the participation of Risk, Actuarial and Internal Audit functions in meeting not only the Directive requirements, but also the expectations of wider stakeholders and indeed policyholders.

My particular focus was on Control Function interaction, the inevitable areas of crossover and emerging skill gaps, and I also touched on some benchmarking papers as well.

My transcript is below and, conveniently enough, reads like a Blog Post. If you would like the slides with the script/hyperlinks embedded, either register with ILAG or drop me a line at allan@governance-matters.co.uk and I will send them on for the bargain price of...free!

________________________________________________________________________________


So back in my former life of BAU busy-ness, my interests in Control Function optimisation were generally led by budget (or lack of it), in particular;
     Professional standards – were there enough bodies, and were they sufficiently skilled or motivated, to perform the fundamentals required (bearing in mind corporate governance code reforms both in the UK (2010 changes BTW, not 2012’s!) and Ireland meant that some system of governance work had to jump the Solvency II queue regardless)
     Proportionality – would the lack of definition around the proportionality principle (Lloyds take a stab on p2) lead to companies being woefully underprepared once the national regulators inevitably bared their teeth post-2009. The impact of misinterpreting Article 41.2 genuinely put the fear in me!
     Multiple roles per person/outsourcing – Whilst some common sense calls were made at the smaller end by merging Risk and Compliance functions, the more operationally substantial calls around merging risk and actuarial functions, outsourcing internal audit/compliance advisory services and recently the march towards outsourcing independent model validation and data quality assessments all posed questions.
Of course, having now worked with one of the biggest, my natural curiosities are not piqued by the unavailability of resource and budget, more by the complexity of wading through the reams of opinion and material that large budgets generate! In particular, I have been monitoring;
     The ability to get bang for buck out of programme spend, with most Tier 1 firms having comfortable broken 3 figures despite, from a Pillar 2 perspective at least, having something akin to “textbook” governance systems at outset
     Whether the “Consultant writes/BAU implements” will be proven to be a successful method of preparing for Solvency II, or whether the plethora of Pillar 2 material outputs will, once unsupported by its transient authors, die a little death
     Control functions in Groups, and perceptions of which countries’ governance is considered superior/inferior in the world of supervisory colleges
But you lucky guys in the UK already have a decent amount of written word around what your control functions are up to, with GENPRU, INSPRU, SYSC, SUP and the Corporate Governance Code all building cases for functional remits and appropriate governance structures
     So we know our friendly actuarial function will be knocking out the sums which end up in our pricing and reserving worlds, produce the EV and capital calcs that (hopefully) keep the wolf from the door, thus quantifying any risks which lend themselves to being quantified, and all the while self-policing the suite of models, methodologies and assumptions that aid them in doing so…
     We know our compliance function will be focused on monitoring and assessing the effectiveness of an entity to comply with prevailing laws and regulations, at a micro and macro level…
     We know our beloved IA function will be assessing the effectiveness of risk management, internal controls and governance processes…
However, the one rather raggedy looking function out of the existing set up is my one, the humble Risk function! While SYSC21 has beefed up the significance of Risk in the prevailing regs, the other SYSC tasks attributed make it feel a bit powder puff functionally by comparison.
In fact, both Risk and Compliance don’t especially feel enormously catered for in the prevailing set up as opposed to Actuarial and IA – not sure whether this is due to the consistency of their development as professions dwelling in the more certain lines either side of the second or not, but it’s certainly my feel as an outsider looking in…
…but thanks to Sol II (or at least the veiled threat of its implementation before I retire), we are now looking at control functions in reasonably neat packages complete with instructions!
One of the biggest problems that I’m sure all present have easily surmounted over the last couple of years is the ambiguities in the language of the Directive and Implementing Measures.
As a man who is married to a wonderful French woman, I am used to following instructions, but of course we are frequently confronted with flowery language such as “covers”, “advises”, “provides an opinion”, “liaises”, which is a consultant’s dream come true, but doesn’t help BAU demarcate and co-operate with any great certainty.
That said, the long and short of it ends with;
Risk
Risk come out with a pretty wide-ranging remit which mostly sits in the FSA’s Dream Function world of advisory, co-ordination, challenge and monitoring, though its ability to monitor “the general risk profile” is clearly reliant on the Actuarial function. Not assuming all present are part of IMAP, but the big ownership piece comes of course with the Risk function taking on responsibility for compliance with the internal model requirements on its design, implementation, testing, validation, documentation and weakness and limitation reporting. Clearly a massive undertaking and, certainly at the small/medium end, not one that can be naturally chalked off with an existing compliment of staff.
Actuarial
Actuarial function requirements include requiring knowledge of actuarial and financial maths but leaving an “other standards” clause in to help out the less well-policed countries! They do also however get some wriggle room on responsibility where it would otherwise be assumed (at least by me!), and so ”co-ordinate” TP calcs, “express opinions” on reinsurance arrangements and the underwriting policy, or “contribute to” implementation of the risk management system.
Compliance
Compliance are not burdened with a laundry list of tasks as such, however to advise the AMSB on compliance with Solvency II is a pretty unenviable one (particularly now!). Perhaps the biggest challenge looking at the remit impartially is the depth and breadth of coverage that the function will need to provide, not just on Level 1, 2 and 3 and SOLPRU, but also be able to challenge the adequacy of the vastly expanded internal policy suite
Internal Audit
IA get the unimaginable luxury of having a relatively unchanged remit, particularly in this neck of the woods where risk-based internal auditing and planning is de rigeur.
Outsourcing
The aggression in the wording around the Outsourcing requirements suggests that the days of outsourcing control functions being a “write a cheque, then dusting-of-the-hands” job are at an end!

Now the legislative ambiguities just mentioned leave ample room for control function bun-fighting due to the inevitable crossovers of skillsets for certain tasks and, perhaps most pointedly, who takes precedence in such instances.
ORSA
Probably the biggest area of convergence and potential toe-stepping-on is of course the ORSA space (covered here on the blog) which in the crossover context it is more about who performs which sub-processes, under whose authority, and who “holds the pen” when collating the record of the ORSA performance.
More by process of elimination than by legislative direction, ORSA oversight seems to sit at the door of Risk, a concession even made by the SAI over in Dublin whilst simultaneously illustrating how little they are required in the ORSA Process! Is this therefore real or nominal oversight, or even worse, a PMO-type record collection role.
One other crossover area comes from the removal of the requirement (after pre-consultation) of an independent assessment of the ORSA Process – whilst losing the compulsion should be welcomed on principle, is there a danger that the IA function, through risk-based planning, may under or over-Audit the ORSA space? Just a thought...
Risk IMMMR/Advisory/Challenge
The world of risk identification/measurement/management/monitoring/reporting also becomes one with potential for friction, through the merger of the worlds of the Risk function’s qualitative risk register-type approach and the actuarial function’s established risk quantification methods, into what ultimately comprises the “general risk profile” as per the Directive text – one of the Big 4 suggested that the P&L Attribution is, for actuaries, “the real risk profile” for example, and perhaps some of you concur!
Regardless, the twin horrors of agreeing with Actuarial quantification methodologies for hard-to-quantify risks, while fostering a dependence on them for measurement, monitoring and reporting facilities around financial and insurance risks suggests more of a one-sided dependence rather than “close co-operation” between the functions.
Compliance risk
This works similarly for the world of compliance risk identification/assessment, nominally in the remit of the Compliance function - are they being dragged somewhere nearer the first line if they are producing this work for the Risk function? Just feels a bit blurry…
Emerging Risk
For emerging risks, my main concern is the robustness of the top-down/emerging risk identification process filtering its way into some quantified element within the ORSA and/or internal model – Risk is chalked down for identifying and assessing emerging risks, but their ultimate measurement isn’t catered for.
For internal Modellers
And into the internal model space, the “close co-operation” between the Risk and Actuarial functions, at firms big and small, has the potential to cause all manner of difficulties, in pure process efficiency terms as well as the cost implications of IMAP failure,. One CRO referred to this as having to “solve the risk management team/actuarial team conflict” in a recent presentation on model governance! Clearly though there is quite a gap to bridge between how this governance worked under ICA and the demands of Solvency II.
Establishing an “independent” team for regular validation, regardless of headcount seems to be something of a holy grail, with a growing trend towards “bringing someone in”, if only for the comfort of benchmarking against one’s neighbours. This also helps a company stay in line with Mr Cardoni from the FSA’s call that “individuals performing the validation must possess the necessary skills, knowledge, expertise and experience”, but does little for self-sufficiency, as well as leaving the Risk function with the job of relationship manager during validation exercises.
The approaches available for the Risk function to discharge its other responsibilities around the internal model requirements, in particular around model design and implementation, of course crossover into terra firma for the actuarial function – would be interesting to know how any modelers in the room have approached this, as a cursory sign-off from Risk on a suite of model development and implementation paperwork doesn’t feel in keeping with the spirit of the regs, though an IRM survey from March suggested at least 11 IMAP applicants were doing something along these lines!
So even if Sol II doesn’t directly ask for enhanced skill sets, we in all functions can all see the iceberg coming if we don’t fix up and look sharp. As ever, the most fascinating movements are in the actuarial space as they meander over towards the risk in what is lined up to be the biggest land grab since Enclosure!
There is certainly plenty of encouragement, in a profession which one of its own was happy to recently decry is “trained to deal principally in numbers and statistics”, to branch out into Risk, with the CERA qualification – “the most comprehensive and rigorous demonstration of ERM expertise available” – perhaps leading the way. While the profession is quick enough to highlight the weaknesses and limitations of an Actuarial CRO, does this additional qualification do enough to bridge the gap?
Certainly the GCAE suggest in their work that professional education may need further enhancement especially in relation to risk management. Over in Ireland however, the SAI are taking it one step further in their Strategic Plan for the profession, going as far as looking to partner up with a university to develop a risk programme for anyone “who wants to skill up quickly in the area”. Can’t say I’m sure what the rush is, other than opportunity knocking!
On the Risk front, the IRM were very quick to respond to the FSA’s Dream Function presentation back in April 11 with a vigorous defence of the appropriateness of non-Actuarial heads-of-risk, noting that the two professions were “extremely complimentary while different”, whilst mockingly emphasizing that the very concept of CERA highlighted that “Core [actuarial] qualifications do not give sufficiently broad training”.
That said, while the IRM have focused attention on some big ticket items such as Risk Appetite and Risk Culture  over the last 18 months, is it fair to say that training or certification touching on capital measurement and management, modeling, financial and insurance risks and their strategic application would have been a welcome addition to the qualification roster (notwithstanding what is available elsewhere through GARP’s FRM designation)? I rather embarrassingly had to answer a question from a colleague the other day about “how did you get qualified for Solvency II” – I won’t tell you how I answered!
For IA, there is a brave new world for anyone with the chops to upskill or expand their horizons. While the ever-moving implementation date maybe postpones any programme assurance work that IA could have picked up on the run-in to go-live, there is clearly an expectation at the FSA that they will contribute to activity such as internal model validation and data quality assessments, though I’m not seeing anything in the world of training to aid them in doing this (hence the consultancies are doing so well out of it I suspect!).
Deloitte do present a nice picture of some of the additional skills that IA may fall short on, in particular a natural aversion to covering non-Operational risks, despite their relatively higher contribution to the risk profile of insurers. One other thing I had in mind, knowing the IA profession’s predeliction for COSO was changes in the world of Insurer ERM since the last refreshes of COSO’s ERM work, particularly COSO’s latest take on risk assessment – instinctively feels like there may be some catch-up work to do in the IA field, but may be wrong.
For the compliance guys, is it fair to say that you already have your work cut out swallowing Level 1, 2 and 3 paperwork as well as any handbook changes which will emerge at the end of the PRA/FCA divorce. Interested to know if anyone getting roped into other activities!
The last thing I was going to mention was that, in the absence of rapid upskilling, and the wind-down/mothballing of organisation’s Solvency II Programmes, has anyone worked out whose BAU budgets any outsourcing will come out of for the next couple of years?
Moving on to how people are doing on the functional operation and indeed co-operation front, there is a reasonable amount of intel and ideas out there, which you may have clocked on its way through, but maybe makes a bit more sense in aggregate.
Risk function effectiveness
As far as Risk function effectiveness goes, the IRM straw-polled their Solvency II SIG this year, and identified some worrying trends from a Sol II readiness perspective, in particular;
Only half have their CRO communicating directly with the Board on risk matters – breathes some life into the quote from Axa’s Life CRO that risk management is too important to leave to the risk management department”…
     Nearly half said risk papers are "noted with a short discussion" at Boards
     A number of risks were not covered by the respondees' risk functions – ALM and strategic risk in particular
     Over half felt they had overlap with either Actuarial or Compliance, and a quarter with IA
     As mentioned before, a decent number of risk functions are not directly delivering documentation, testing and validation of the internal model.
     Half said the process of implementing Solvency II affects their ability to become relevant to the Board
The IRM also very recently performed a survey (with a reduced quantum due to the subject) on Internal Model Governance trends, which highlighted that;
     Risk is “responsible” for IM governance (with no exceptions in the survey), but Actuarial are “involved”, but with no further details
     And many respondents feel “real decisions” continue to be made outside of IM Governance framework, in particular around stress testing, back testing, model change and expert judgement – makes one wonder if an Actuarial CRO could counter that governance leakage?
Risk appetite design and application
There was a paper released by our hosts this year which emphasized the differences in design and implementation of Risk Appetite Frameworks between Risk and Actuarial functions, noting that a quant heavy actuarial approach gets more traction and quicker! This doesn’t augur well for the new ORSA world of “everything must be quantified”, as it is the qualitative risks that need the most attention.
Reporting lines
The world of reporting lines remains a pretty hot topic, with KPMG putting out a decent paper which recommended, amongst other things, that the Actuarial function should consider a formal demarcation between risk taking and risk assessing/measuring actuaries, which would negate the trend of shoehorning capital actuaries through the Head of Risk, keeping them all reporting through the AFH. They also added that at least half of the respondees were not yet at their desired end-state regarding the basic new Actuarial function requirements around underwriting and reinsurance adequacy opinion provision.
IM Validation
In the model validation space, as early as the end of last year we saw KPMG reporting that half of the IM production staff were also involved in the validation process, emphasizing the practical difficulties in functional separation whilst in Programme mode – would love to see how those numbers have moved since. 
Having seen the FSA’s feedback in May on what had been observed at that point in time (in particular that independence from model development and being “sufficiently competent” went hand in hand), one can imagine that IA’s role in the activity will be marginalized in future at the ongoing expense of bringing in the Big Guns every year.
Things a Risk function could be doing
And finally, while I have touched repeatedly on activities which a Risk function may find cannibalized by their ravenous Actuarial counterparts, as well as responsibilities bestowed upon it that it may not be equipped to discharge, I have seen a few pieces around activities that the Risk function would probably love to be doing more of, given half a chance.
A recent piece by Accenture got my engine running, around the future of data analytics – I definitely feel that, with the appropriate informational power at their hands, the risk function can provide a massively enhanced IMMMR and advisory services at little additional cost (the main cost of course already being sunk into data  quality and data warehousing projects independent of the function)
One lovely piece, pitched in the context of why Equitable failed, reads like a list of things a CRO should be focused on, such as NED ambivalence and underperformance, or executive hubris, while a Towers Watson presentation on prepping for the future draws out the most practical big ticket activities such as superior understanding of model weaknesses and limitations and tail risk, rather than a more general clutch at the full bag of responsibilities bestowed on the function by Sol II.
A research piece from the CII (sadly no longer free!) compliments that, suggesting that a “balance between modeling and judgement” must be struck by Risk departments in order to breath relevance into a function that the author was outspokenly critical of in his research.

Thursday, 22 November 2012

Accenture study on Risk Analytics - lessons for Insurance Industry

Decent piece of benchmarking from Accenture on the current usage of risk analytics as well as drivers for the future. 450 mostly c-suite level respondees from across industries (40% insurers), but the findings are targeted specifically at the Insurance industry. Interestingly, respondees leaned towards incomplete data sets, rather than a lack of data or technological capability, as the main constraint.

While it touches on a number of areas of interest for Use Test specialists, it also covers Stress and Scenario Testing (13% of Life and 21% of P&C insurers reporting that they "rarely" or "never" use stress testing in decision making), and Reporting (which suggests the main driver for reporting improvements is regulatory rather than voluntary, due to regulators "...[increasing] their focus on the quality and frequency of reporting"). Internal Modelling also gets a mention, with almost 80% of respondents saying they already use, or are planning to use, an internal model for capital adequacy requirements.

Data Governance  of course gets decent treatment here. Only 69% of insurers polled currently have a Data Policy, but 41% have a data quality department, which feels alarmingly high, particularly when drawn against Accenture's comment that "...many firms have insufficient rigor who owns data, who sets it up and who manages it". The FSA concurred with that in their preliminary Data Quality Review findings back in September, and I'm not at all convinced that a DQ department will help in this respect (i.e. BAU absolve themselves of responsibility for their data sets!)

The Accenture crew use the "Leaders" and "Laggards" analogy throughout, so benchmark away and find out which one you are!

Monday, 7 May 2012

KPMG - Solvency II paper, "Beyond compliance towards optimisation"

Another titbit from the Big 4, this time covering the benefits that are available off the back off the legislative delays, specifically around optimising the Finance and Risk functions. If you are one of the Tier 1 companies, this comes across as a bit of a "Where's Wally" paper (or 'Waldo' for my American pals!), as it borrows of their extensive 'experience' on site with clients over the last few years. Despite that extensive experience, this is pretty light at a fistful of pages.

I would struggle to distinguish between 'capital minimisation' and 'capital optimisation', which they start off with, but they go on to describe a world of risk and finance "centres of excellence, which utilise the good work currently being done on the data warehousing front by Data teams to populate the various regulatory reporting requirements as well as management information needs, and that all sounds plausible.

The Risk section is naturally a little flannel-y, but suggests the best functions will be able to predict cash flows better, ultimately improving risk, capital and business planning and as a by-product, RAROC comprehension and enhancement.

Not a lot else, but some ideas around communicating future value of today's expenditure at the very least.


Monday, 30 April 2012

Society of Actuaries in Ireland Newsletter, April 2012 - ERM and ORSA features

Always a riveting read, the SAI pushed out their latest newsletter, which generally provides enough consumable detail on actuarial concept to help relative novices like me!

Get stuck in to the sections on contract boundaries, and the reason for professional vs EIOPA divergence on p4, some ERM activity over the last couple of months on p9 (and slides from those both here for ERM and here for ORSA). Some brief analysis of the older presentation from Towers Watson on ORSA is also summarised.

Tuesday, 24 April 2012

PwC paper - Solvency II Pillar II "operational issues of risk management"

Following on from KMPG's efforts, the PwC crew have released their own aide-memoire for Pillar II specialists, which at the very least should be handy for CRO/Head of Risk etc amongst us for board training/briefing ideas as we approach the home straight.

At 60 pages, it's not exactly a comic, and while a great deal of the introductory material is 'Pillar 2 101', it does contain material (either text or schematics) which should be of immediate use, so I would recommend checking out;
  • First line of defence and reasons for risk ownership (p26)
  • Definitions of Risk Appetite/Risk Tolerance/Risk Profile/Risk Limits/Risk Budget (p35) - I haven't cross referenced these against IRM definitions for example, but may be worth doing for consistency. An accompanying schematic is on p36.
  • Internal Model Scope (p40) and Validation (p48) should be extremely topical after Mr Adams's speech on Thursday.
  • Communications and training plan ideas (p53-54)
  • ORSA schematic, and some talk around process industrialisation (p56)
Perhaps the main weakness in the text is that there are no references to the Commission's draft Level 2 text, which is now clearly a document in a lot of people's hands (not least the FSA, who have made it clear that this plus the Directive text is what IMAP is based on). I also wasn't mad keen on the reference to P&L attribution being "the real risk profile" (p48) - there is already enough flab around this term without additional mis-steers.

All in all, well worth dissecting, even if like a Roast Pigeon, you end up throwing away more than you consume!

PS - Far be it from me to suggest a document from one of the Big 4 has a whiff of Google Translate about it, but this was authored almost entirely by PwC France it would appear, perhaps explaining the odd COSO-ERM reference on p17, the rather oblique title, and of course, the whopping 60 pages...

PPS - Wife is French, so allowed the odd cheap gag around bureaucracy!

Monday, 23 April 2012

KPMG Paper - Solvency II still fit for purpose?

A handy survey from one of the Big 4 on some of the biggest challenges remaining on Solvency II. Small sample (20 people), and is GI-flavoured, but that doesn't make the experiences any less relevant to you 'Lifers' out there. The following was noteworthy;
  • A good half of respondents expect their capital models to be a key driver in their business planning process post- Solvency II, with the remainder using it as a "reasonable consideration" - this contrasts with a quarter who use them to a negligible degree if at all pre-Solvency II.
  • Suggestion that, with Solvency II accounting being viewed as a "regulatory exercise" for non-lifers, there is plenty of transitional work to do in order to align the GAAP/IFRS view with the Solvency II accounting view
  • Concerns around reporting lines for different strands of actuarial activity (pricing, reserving and capital) potentially going into one executive, with those assessing risk versus those taking it being the primary issue.
  • Suggestion that the increased requirements around actuarial staffing may drive some work offshore in order to reduce the costs
  • Concerns around calculation of Risk Margin, specifically around what the Finance function will demand versus what the Actuarial function can provide.
  • Comment that, as the internal model is expected to change as a business's risk profile changes, that current best practice ensures this is done at least annually, though monitoring of new business (therefore plan against portfolio) agaist forecast is done more frequently - no lead on size of divergence that might drive a model change however, which was one of Mr Adam's bugbears from the speech last week.
  • The provision of Actuarial opinions regarding the adequacy of reinsurance and underwriting arrangements appears to have split the respondents, with a decent number taking a wait-and-see approach - KMPG are similarly guarded when providing their own view, highlighting concerns with the impact of opinions on decision making and how they are worded.
  • Further areas of collaboration between Risk, Actuarial and Finance functions are expected around Capital Management, Performance Management and ORSA, with devolution of previously shared responsibilities made to first line functions, and the second line becoming a multi-skilled "centre of excellence" - nice schematic to go with this on page 18.



Monday, 9 April 2012

Internal Models - more "Hassel" than they are worth?

Pardon the dodgy David Hasselhoff pun (product of an idle mind!), but it looks like a storm is brewing with out German pals on the internal modelling front - hot on the heels of Hannover Re's threat to abandon ship via a Societas Europaea passport to an easier ride, Gothaer, a German mutual, has now apparently decided to give up altogether.

Whilst the knowledge that people are giving up part-way through is not new (the UK managed to slim down from 100+ expected to 70-odd pre-applications between 2010-11), I was under the impression that Bafin were not dealing with a huge number to start with (this seems to suggest no more than a dozen), so to see two teetering on the brink is newsworthy I guess. 

It could be that these guys have seen something in the Commission's draft Level 2 that they don't like, or indeed the outcome of the ECON lobbying didn't quite go there way, but anything which leads to insurers not measuring their overall solvency needs using their own experience analysis and calibrations is surely unwelcome.

Some good quotes on just how onerous Bafin may be are included in this article (subscriber only I'm afraid), the most telling perhaps being "So far we see very few small insurers building an internal model [or partial model],". Very few, minus one, it would appear...

Wednesday, 18 January 2012

IRM Solvency II SIG Presentations from January - Stress Testing

For anyone who is working on firming up their approach to stress testing and its cousins for Solvency II purposes, I would recommend taking a look at the outputs from this month's IRM Solvency II Special Interest Group.

The presentation has some worth, although I guess you needed to be there to get the full gist. The survey however is of much more use for justifying any approaches you currently have in play (who is responsible for what, and indeed what varieties of stress testing are actually used). Small sample as you might expect for a SIG at 28 respondents, but worthy nonetheless.

Tuesday, 6 December 2011

PRISM and Central Bank of Ireland - ORSA come early?

Towards the end of last week, Matthew Elderfield launched the Probability Risk and Impact SysteM (PRISM, summary here and detail here), which aims to usher in a new age of supervisory challenge to the Irish financial sector, well documented as having had an easy time of it before credit started to get crunchy.

One big challenge for the CBoI will be to get everything up and running before June 2012 (hopefully the recruitment drive wasas good for quality as it seemingly was for quantity!), so all the best to them for that. More pointedly, the acknowledgement that the ramping up of staff numbers will start to be felt in the industry levies asap, coupled with future income streams referenced in their planned aggresive enforcement and fining of non-compliant firms must have any of the stragglers still living in 2006 quaking in their boots.

Very interesting to see the take on Risk Appetite, Risk Tolerance, Risk Assessment Criteria etc applied by a regulator to its industry, rather than my normal vantage point of a risk consultant, either advising on or benchmarking the same facets of individual ERM frameworks within an insurance undertaking. I would have thought the way in which these things are described in Mr. Elderfield's speech should be good guidance for corporate governance code adherence over there (let's face it, it doesn't get better than from the horse's mouth!).

One thing that would make me very uncomfortable as an Insurance consultant is the extent of the crossover between ORSA, QRTs, SFCR and RSR and what is being proposed under PRISM. I would not be keen on, for example, defining 'Risk Profile' for my client in line with Solvency II definitions, only to be contradicted by the regulator's PRISM definition of 'Risk Profile', which is overall solvency needs by any other name.

If I get some spare time, I may run a cross-check between ORSA and PRISM obligations, and work out whether the CBoI is trying to tell the insurance industry how to do an ORSA via subliminal messages - for the life of me, I can't quite work out what this does for the industry that an ORSA run with "appropriate" frequency doesn't.

Friday, 25 November 2011

CERA and the challenge to the Risk Profession

Very reassuring article in the Actuary magazine regarding one aspect of the inevitable land grab between risk and actuarial professionals (which I have blogged on several times), this one covering the thoughts of a few CERA students as to whether this qualification was likely to enhance their career prospects.

Judging by the responses of those students likely to be CERA-qualified in the near future, I suspect that the Risk profession will still be gainfully employed for some years to come - particularly liked the reponse about selling the qualification in one sentence "It counts as verifiable CPD!"

PS The score on CRO hires moved to 4-0 to the Actuaries this month with Aviva UK's new guy - however, the hunter has become the hunted, with the new top man at the Institute and Faculty of Actuaries being a chartered accountant!

Tuesday, 22 November 2011

Economist Intelligence Unit - Getting new perspective on strategic risk

This out last week from the Economist Intelligence Unit, always a great spot for benchmarking, and at a verty opportune time for anyone working on ORSA or enhancing the visibility of strategic risk in general. Sample size is almost 500, around a month old, and all respondents have responsibility for risk management in their respective firms. The research is also supplemented by interviews with a few big cheeses.

Again, it;s a quality publication, so doesn't need much sifting through, but the salient points for me include;
  • Lot of agreement that Risk should challenge management's view of the future (two-thirds)
  • Almost three-quarters agree that flexibility is more important that ability to plan for the long-term (indeed a third of respondents don't even plan for events a decade or more into the future)
  • "By extending their risk models further into the future, companies must be aware that the data being used to populate them are increasingly unreliable" - interesting in the context of ORSA (i.e where does one stop projecting)
  • Main barriers to considering longer term risks are executive management's focus on immediate risks (41% of respondents), and the nature of the business making such work redundant (36%)
  • Almost 60% have their Risk functions actually participating in the formulation of strategy
  • The risk planning horizon doesn't appear to be aligned with the strategic planning horizon (risk planning being much shorter) - obviously changes with ORSA for insurers, but not sure what the resolution is for other organisations.
  • 60% have one of the most important objectives of the risk management function being the identification of new and emerging risks - may actually be the cause of some of the mismatch mentioned above. Despite that, only 40% feel they are doing a better than average job of anticipating and measuring such risks
  • Main areas for enhancing risk management practices have been to make risk management more forward looking (50%), and allocating more board and senior management time to long-term risk analysis.
  • 40% have their CEOs as being responsible for exploring long-term impact of risk on strategy - very high, considering that boards/committees were alternative responses
  • 44% think a bigger commitment to ERM will help align risk and business strategy, while 33% thought that the Risk function presenting themselves more as business enablers would do the same thing.
  • Only a third of Risk functions report to the board quarterly - seems very low
  • 30% have no plans to use horizon scanning - beyond mad!
  • Only around half of respondents have or plan to have a CRO