Wednesday, 27 February 2013

Lloyds - cognition and how human factors affect risk perception

While the Solvency II world will be as grateful for as they are familiar with Lloyds of London's work in the Sol II sphere, they pushed out an intriguing paper for all risk practitioners this week around cognition, the impact of human behaviour, and our interaction with models when identifying and assessing risks.

This is a piece of academic research very much needed at this point in time, where the regulatory obligations around internal model challenge have yet to formally land, let alone be adequately road-tested, while at the same time the UK is continuing with its ICAS+ regime, where entrants will no doubt receive running commentary on their progress in upscaling both assumption/parameter challenge as well as model use.

Anyone involved in the 200-ish pre-applications for internal model use prior to Solvency II go-live in Europe would therefore benefit from a read of this, particularly if you are on the validation-side. I picked out the following;

Fundamentals which impact on modelling choices (data sets, interpolation/extrapolation, correlations, tail dependencies etc)

  • "We are not equally aware of all risks...people make decisions based on a subset of the available evidence"
  • "Expectations are strongly influenced by personal experience and current events"
  • Tendency to "...lose sight of infrequent losses" in the face of more frequent visible events
  • Tendency to procrastinate around risks which are difficult to assess
  • "Some may query the relevance of human factors, given the prevalence of quantitative risk models - the suggestion being.modelling rules out biases"
Risk appetite
  • "Low risk appetite can increase false alarms, and a high risk appetite increases misses"
  • "The greater risk appetite of powerful individuals can stem from a tendency to focus more on rewards and successes, while people who are lacking in power are often more cautious and attentive to threats and potential obstacles" - is it this dichotomy which makes the role of the CRO ultimus inter pares in the boardroom?
Aide-memoire lists for risk practitioners
  • How to counteract risk perceptions - p11
  • Separating risk perceptions from immediate context - p13
  • Awareness of bias linked to power - p16
  • Risks in perspective - p20
  • Behavioural principles which can create added value - p22

Tuesday, 26 February 2013

Clear Path Analysis - Interview with EIOPA's Montalvo

The guys at Clear Path Analysis have come through with another suite of exclusive Solvency II material, following along from their efforts in September 2012 and 2011 (sign up required if you are not already hooked up with them).

This is dominated by asset allocation and Pillar 3 requirements, and I'll cover through those in due course. It was the interview with Sr. Montalvo from EIOPA which immediately caught my eye, so I picked the following bones out of it:

  • Solvency II is "...nothing more and nothing less than a risk-based supervisory framework"
  • Solvency II "aims to be a neutral system" with regard to asset allocation
  • "The new framework creates business opportunities rather than operational risks"
  • "No Pillar prevails, all are equally important" 
  • The capital weightings on asset lines are based on "...sound technical calculations that were taken by the supervisory community (and in particular by the actuarial teams involved)" - is this a tacit acknowledgement of a residual element of black-boxedness?
  • On IFRS convergence "...we had to move forward because in the accounting areas progress was not being sufficiently made". 'Aimerez-vous rencontrer M. Kettle, M. Pot?'
  • On early implementation, "...once we see how it is working, [EIOPA] will have the courage to say which things can be improved"
Perhaps his sweetest quote is worth isolating:

Monday, 25 February 2013

Elderfield speech to Institute of Directors in Ireland - 'the Gene Genie'

With all the subtlety of an American industrialist in Paris, Mr. Elderfield delivered a speech to the Irish IoD this week focused on the Central Bank of Ireland's refresh of its 3-year strategic plan, as well as reinforcing what it expects financial services Boards to be focusing on in the near future.

This of course should sit in the context of what I covered last week on thematic enforcement work in 2013. Aside from his comments around board diversity, namely that the CBoI's 'fit and proper' activity to date is "...broadening the gene pool of corporate life" (eeeewwwww!), emphasis was given  to three particular areas:

Risk Appetite Statements
  • CBoI expects "... [a] high quality risk appetite statement that is well understood and implemented throughout the firm in practice"
  • "...clear articulation of the acceptable level of risk...at different confidence levels, is an important discipline and an essential compliment to a well-articulated business strategy"
  • That, due to disappointments in the past, Risk Appetite statements are "...certainly an area of increasing interest on [the regulator's] part, and where we are debating the best approach for encouraging improvements"

System of Governance and Risk Culture
  • Boards should "...provide broad, challenging scrutiny of your firm's culture regarding regulatory compliance and internal challenge"
  • Ensure that there are "...appropriately resourced and well-qualified risk management and compliance functions"
  • "Think more fundamentally and strategically about the culture in the institution that you oversee"
I would add that a lot of this sits nicely with the FSB's Risk Governance paper which was released last week.

Board composition
  • Expect directors to take a "...hard nosed view on Board composition, with a view to improving performance"
  • Endeavour to attain the "...right gender diversity...and international experience"
With Risk Appetite and Risk Culture both having featured on the IRM's hitlist recently, the practitioners over there will have some assistance to hand from an industry body, however there should be some other useful stuff available in the tag cloud at the bottom of this page on appetite, culture and diversity if you are struggling for inspiration.

Friday, 22 February 2013

Adams speech to the Economist Insurance Summit - lessons from financial crisis

Some particularly useful context setting from Julian Adams last week for anyone in the Internal Model game, with this speech to the Economist Insurance Summit around what lessons could be learned by insurance supervisors from the financial crisis.

While he amusingly interchanges between "financial crisis" and "banking crisis" to emphasise that it wasn't our fault, and drops in the now obligatory reference to the importance of insurers as long-term investors, echoing the Commission's pleas from late last year, the majority of the speech focuses on why models go wrong (not the name of a ropey catwalk reality tv show...)

Insight on where the FSA thought firms were going awry in the Solvency II modelling preparations was delivered to the industry in the middle of last year, but I found this speech helpful in the context of proportionality i.e. what elements of economic capital modelling are worth spending extra time on theorising, documenting, debating and minuting for IMAP candidates. I saw the following comments as highlights;

Reasons for internal models in the banking industry being exposed;

  • "...rested on assumptions which turned out not to hold when bad times came"
  • "...review period" selected when parameterising
  • "...insufficient rigour and independence from the front end of the business" when parameterising
  • "...management attention too often focused on those parameters considered too conservative at the expense of those that were insufficiently prudent"
  • "...destabilising feedback loops" where underestimation of risk (due to data selection) plus use of the model leads to a vicious cycle of unacknowledged over-accumulation of risk
  • "...flawed technical assumptions" in tail-end probability estimation where data is drawn from "normal" times
Lessons for Solvency II
  • "Data [should be] sufficiently robust"
  • Assumptions should be "appropriately conservative"
  • "[Supervisors] can be helped...by the much greater use of imaginative tests of resilience to deeply stressed scenarios"
  • "...paucity of relevant historical data for the calibration of tail dependencies between risks"
  • That "...the limitations [of capturing tail dependencies] are recognised, and conservatism built in to the calibrations"
  • That "...correlations in the tail are likely to be assymetric in nature" for insurers
  • That "...the adoption of quantitative techniques...will not change the nature of the risk itself"
  • That supervisors "...must not blindly accept the outputs of these models"
Appreciating some of this is hardly new news, any increased documentation and rigour in the areas highlighted will no doubt be well received down at the Wharf.

Wednesday, 20 February 2013

Protiviti - top risks for 2013

Nice piece of 'top risks' benchmarking for practitioners was pushed out this week by Protiviti - heavily US-centric, cross-industry (around 25% financial services, but all respondents are C-suite types), and the 'risks' are provided as a selection of 20 pre-written items, but the work has still got some mileage, even if I am far from convinved by the early statement that "...the first question an organisation seeks to answer in risk management is 'what are our most critical risks'" with no reference to their strategic objectives!

Let's take that as an editorial oversight, and pick through the highlights;
  • Unsurprisingly, economic conditions and regulatory change/scrutiny are top of the financial services hitlist of 'top risks' (and indeed other industries)
  • CROs and Chief Audit Executives were less likely to rate a risk "less significant" than their first-line counterparts - nest feathering or legitimate conservatism?
  • Financial services considerably more likely to deploy additional resource to enhance risk management capabilities in the next year
There is also a "suggested questions for Boards" list at the back, which covers (albeit in a rather flannel-y fashion) the kind of items which emerged in the FSB's risk governance recommendations from earlier in the week, such as;
  • Is the Board sufficiently involved in/informed of the risk assessment process regarding the implementation of strategy (mergers & acquisitions, new lines etc)?
  • Is the MI around the Risk Profile sufficient?
  • Is there an existing emerging risk management process?
  • Is the risk profile consistent with risk appetite?
A decent piece to run through your NEDs at the very worst, and potentially of some use for your emerging risk/reverse stress testing activities for 2013.

Omnibus II - back to October 2013

Following on from the barely noticeable number of previous posts on Omnibus II Plenary vote delays (here, here, here, here, here and here), we can now stick lucky number 7 in the pot, after the procedure file was updated today to show a postponement to October 2013 - whilst the delay was inevitable after EIOPA made it clear that the Long Term Guarantees Assessment report would only reach the co-legislators by July, the actual date helps with short-term planning for all stakeholders concerned.

I guess the big questions that emerge from a delay to October are:

  • Whether it is enough time, factoring in the summer holidays, to consume the LTG report, acknowledge its outcomes regardless of which territory benefits most from the conclusions, and vote positively
  • Whether it is actually too much time to pull apart the report's outcomes, and between the trilogue parties, industry lobbyists and any national political pressures than can be marshalled in the interim, October just becomes the next promises graveyard.
  • The increasing proximity of this date to the campaigning for the 2014 EU parliamentary elections, which must surely impact on how the voting will go if the LTG report gives a duff outcome to those countries still writing swathes of guaranteed business
  • The entry into the mix of Karel van Hulle's replacement (haven't seen a name yet)

Not certain if 2016 is exactly riding on Omnibus II approval by October, but one feels it would certainly help restore some credibility.






















Monday, 18 February 2013

Munich Re on Solvency II Control Functions - an actuary for all seasons...

Munich Re have continued their infrequent-yet-valuable Solvency Knowledge Series with a piece on Key functions within the system of governance of insurers under Solvency II.

Of course to the grizzled old set of risk practitioners who have done the rounds for the last few years, the fundamentals of the directive's requirements on the four control functions are as basic as the ingredients list for a frozen lasagne. It naturally draws attention to the likelihood that there will be "some overlap" between the activities of Risk, Actuarial, Compliance and Internal Audit, as well as touching on outsourcing as "...an attractive way of meeting the wide range of requirements" for those

However I detected more than a whiff of controversy around the content of this particular publication (which I hasten to add is a smart read nevertheless), were one to take it at face value. In particular;
  • Their use of the three lines of defence model in the publication - while perceived to be good practice for segregating operations from risk advisory from risk assurance, it is certainly not cited in any existing materials at Level 1, 2 or 3, and the structure may be disproportionate at the small end of the insurer spectrum. On top of that is the Actuarial function's acknowledged dwelling over a grey area between the first and second lines, in particular if they haven't catered separately for the reporting lines of reserving, pricing and capital management actuaries (p8).
  • The comment that "The risk management function will no doubt have to include people with a professional scientific and mathematical background, ideally backed up by appropriate qualifications (eg actuaries)". Whilst, internal model or not, the Actuarial function will clearly have to provide "considerable support" to the Risk function, I don't see any reason at the small-to-medium level for the Risk function to include actuaries unless through choice, using the lever of proportionality.
  • That the Risk function "...shares responsibility for the risk strategy" - I think the implication is that it shares responsibility with the Board, but the statement doesn't help identify a) who authors and authorizes it and b) who gets fired for its poor deployment! I am more inclined to think the Risk function owns the risk management system and is responsible for monitoring and reporting on the implementation of the risk strategy which sits within it. The FSA define their requirements on this page in any case.
  • That the Risk function "...identify potential risks and recommend appropriate countermeasures to the Board" - as far as emerging risk/top-down risk assessment goes, I certainly expect the function to facilitate the emerging risk/scenario analysis/reverse stress test activities in this regard, but it is most certainly not a solo job.
  • That "The compliance function...will have to include staff with a legal background" - appreciating what the wording of Article 46 implies in particular, this is more a proportionality/outsourcing issue for me than anything. Having said that, I'm sure any existing compliance professionals out their who didn't take the Bar might feel slighted by this! 
  • That "all four functions have a direct reporting line to the Board" - not certain that this is so in the vast majority of cases. Certainly via Board committees the Risk and Internal Audit functions will be well catered for (and the FSB recommended even better than that for the Risk function last week), but I suspect an executive reporting line is as good as it gets for the other two functions in most firms.
Certainly plenty to engage the grey matt with regardless of your country of origin, even around control function crossover areas (which I presented on at the end of last year), so dig in.

Friday, 15 February 2013

Chartered Institute of Internal Auditors - recommendations for UK financial services

The Chartered Institute of Internal Auditors recently created a sub-committee to provide professional guidance "...designed to be a benchmark for effective internal audit in financial services in the UK", and they have just reported back with this feast of fun, which is a vital read for anyone working in control functions within financial services. The opinions they have used to create this guidance have been purloined not only from the profession itself, but also from other professions, regulatory bodies and executive/non-executive directors

They note in summary that there is "strong support for an unrestricted scope for internal audit", while drawing attention to disparity of opinion around matters such as: IA directly challenging strategy; IA reporting to Risk Committees (rather than audit committees) in certain instances; compulsory attendance of Chief Internal Auditors at Executive Committees; and the direction of managerial reporting lines.

The proposed guidance reads very much like the Corporate Governance Code, and is relatively light. It is broken into the following sections, where I have noted anything I found new or controversial alongside (my focus being predominantly scope creep into the Risk function's activity):

  1. Role and Mandate of IA - increased focus on risk assessment and risk coverage adequacy
  2. Scope and Priorities of IA - unrestricted scope ultimately advised; expected to "independently determine" key risks, and assess "the setting of, and adherence to, risk appetite"; assess the "risk and control culture"; allows for potential involvement of IA on "real time basis" in key corporate events (mergers, disposals, new lines of business etc)
  3. Reporting results - factors in reporting obligations to both Risk and Audit Committees where appropriate, and builds in an expectation of an annual independent assessment of governance (which covers off one of the FSB's recommendations covered yesterday!)
  4. Interaction with Risk, Compliance and Finance functions - nothing new
  5. Independence and Authority - Chief Internal Auditor expected to be executive committee-equivalent, have the right to attend Excom, access to all MI, and report directly to either the Chairman of the Board, Audit Committee or at a push, Risk Committee. A secondary line to an executive director should only go to CEO
  6. Resources - all resourcing decisions effectively divorced from the business, to reside with the Chief Internal Auditor and the Audit Committee
  7. Quality assessment - external assessment of the function recommended periodically.
  8. Relationships with regulators - nothing new
  9. Wider considerations - expectation that the "tone at the top" of a firm should be what fosters acceptance of IA
Any controversy? Perhaps around the seniority of the Chief Internal Auditor, and their assessment of the setting of and adherence to Risk Appetite. I think my main concern as a risk practitioner would be the potential for differences of opinion around what constitutes "adequate" risk management, given the Internal Audit predeliction for COSO on all things risk-related, against the IRM or ISO31000. 

Let battle commence?

Financial Stability Board - Thematic review and recommendation on risk governance

The Financial Stability Board (FSB) have been sticky-beaking around systematically important financial institutions (SIFIs) with a relative unchecked remit ever since the financial crisis first reared its head. This week they have emerged with a very significant document for Risk practitioners across the globe, with a thematic review of Risk Governance (press release also available here). The participants were 36 banking and broker/dealer institutions of interest, as well as major supervisory bodies and NGOs.

On the basis that there isn't a single accepted global standard on the matter, the thematic review compares prevailing practices against an amalgamation of content from exising standards from the IAIS, OECD and other bodies. Of major interest to risk practitioners is the document's focus on areas which the IRM have covered recently, namely risk appetite/tolerance/limts/capacity and risk culture.

Bearing in mind the great and good from the prudential regulatory world are active participants in the FSB, the likelihood of their findings emerging in the regulatory principles of tomorrow are pretty high. Of course this research has been based on Non-Insurance SIFIs, and so insurers large and small who have been endeavouring to meet Solvency II Pillar II requirements will find themselves in a decent spot already.

On that basis, I noted the following;

General recommendations to supervisory bodies (p4)
  1. Formal requirements on the independence and skillsets of Boards
  2. Hold Boards directly accountable for risk governance, and whether or not their existing suite of risk MI is sufficient
  3. Formally elevate the stature, authority and independence of the CRO role
  4. Require an independent assessment of the effectiveness of the risk governance framework to be performed on an annual basis (a list of what Internal Audit would generally review in this context follows on page 24)
  5. Engage "more frequently" with Boards and management to assess risk culture
Sound practices list p30-34 - highlighted below are elements which may be new to the UK in particular, were they to be introduced
  • Boards - annual reviews of member qualifications, skills and time commitments; meet quarterly with regulators; "effectively inculcate" an appropriate risk culture
  • Risk Committee - annual approval of risk management policies
  • Risk Management function - CRO to have direct reporting lines to Board/Risk Committee as well as CEO; public disclosure of CRO firing/hiring; be "actively involved" in strategic decision making processes; meet quarterly with supervisors; stress testing "on demand" at the behest of the business
Risk culture and risk governance supervisory assessment
  • Notes that supervisors need to strengthen their ability to assess a firm's risk governance "...and more specifically its risk culture"
  • "More work is needed" on regulatory assessment of risk appetite frameworks
  • "Risk culture plays a critical role in ensuring effective risk governance practices through changing environments"
  • FSB have a working group exploring the potential for formal risk culture assessments, who are  reporting in September 2013
Risk management functions and CROs
  • Acknowledges that there have been "[raised] supervisory expectations for the risk management function" since the financial crisis
  • Highlights that "most firms note that the CRO has a direct reporting line to the CEO", though "access to the Board" apparently remains more of an expression than a vivid reality
  • "Good progress" has been made on enhancing the stature, authority, and independence of the CRO position
  • Rather non-descript comment that "the Chief Risk Officer and the risk management function are responsible for the firm's risk management across the entire organisation" - responsible for what element, not conduct surely?
Risk appetite/tolerance/limts/capacity
  • Acknowledge a "lack of common terminology for risk appetite, risk profile and risk capacity...within firms, across firms and across national authorities"
  • Definitions of appetite and capacity used by FSB largely line up with IRM's definitions (though the IRM use 'tolerance' rather than 'capacity')
  • "Key features of a Risk Appetite Framework" are listed on p22 - however even those firms considered best in breed commented that there are ongoing "operationalising" problems with RAF rollout
  • Suggest that breaches of 'risk limits' should lead to reductions in exposures (piii) - not sure why the alternative of increasing appetite is not acknowledged



Wednesday, 13 February 2013

EIOPA on Solvency II implementation - "no doubt about it"

Now that most Solvency II stakeholder's hands have been temporarily filled with the LTG spreadsheets and assorted accoutrement, Seniors Bernadino and Montalvo have hit the trade press with more aggression than an Irish prop forward in order to clarify their position on the drivers behind their opinion on interim measures at the end of 2012, as well as the ultimately likelihood of Solvency II implementation.

From Sr. Bernadino to the Actuary magazine

  • On the shortcomings of Solvency I - "...if you have more risk, you should have more capital"
  • "I think it will take until then [2016] to get started" on Solvency II
  • "We [EIOPA] believe 2014 and 2015 can be used as an opportunity to enter into the system in a better way"
  • "Solvency II will be implemented, and there should be no doubt about it"
  • "EIOPA will do the necessary work to make the implementation of Solvency II happen on January 2016"
  • Emphasises that we are "not building from Solvency I", in the face of "Solvency 1.5" questions
  • Notes that EIOPA's opinion on interim measures is borne from concerns that the delay may lead to "different national solutions [emerging] to the detriment of a good functioning market"
  • "Differences between supervisory cultures" is part of the IMAP inconsistency problem - no implication that either the UK is doing too much or mainland Europe not enough
  • Makes the point that stakeholders "...must avoid the temptation of re-opening more issues" - hard to think of any contentious issues which aren't already wide open for debate, but clearly some concern that the current smorgasbord could be supplemented.
  • For those at the smaller end of the market, he gies a specific example of where an Actuarial function could be staffed by someone other than a "pure actuary"
All this in the week where a succession of industry figures in London lined up to flog Solvency II's hobbling carcass, whether it be the IMAP element (Hiscox), or the very premise of one-size-fits-all regulation (Pru). Not a good week to be trying to kill a horse in the UK gents...




Thursday, 7 February 2013

Towers Watson on US ORSA, Economic Capital and modelling trends

Towers have released a few decent bits of material of use to risk practitioners over the last couple of weeks which are worthy of comment. One on Economic Capital for Life Insurers is effectively a sales aid for their RiskAgility modelling software, but actually captures the drivers behind the UK's efforts to improve their ICA models to meet Solvency II requirements.

In particular the references to how firms ought to be making their model output 'useful' where they currently fall short (capital by business/risk/product, daily runs without running ALM models and ability to produce "what if" analysis) should be featuring highly on the agendas of both embedded use practitioners and AMSBs during 2013. Of course the sad part for any users of the software comes with the statement that RiskAgility is built "...specifically to deliver monte carlo simulation of 1 year VaR economic capital" - love to hear how the lack of multi-year is being dealt with in firm's ORSAs!

A second publication on ORSA preparedness in North America is also worth a read, even if only for us EU-based practitioners to have an opportunity to live vicariously through a country which will actually get it implemented! It is a relatively small quantum of respondents (mostly CFOs), and around half think they will be exempt on size grounds, but the perceptions which emerge are still valid, and one should be prepared to encounter this either side of the Atlantic;

  • 21% see it as a compliance exercise, while 60% think it will improve ERM and capital/strategic planning
  • Only 22% see their prevailing ERM frameworks tightly liked to strategic and capital planning
  • Only 40% are ready to implement an ORSA in the next 6-12 months
  • Concerns remain around resource requirements for educating "key personnel" and directors/C-suite - 45% and 66% respectively felt they have work to do in this area without necessarily having enough staff to do so.
  • 13% of respondents didn't see their risk management departments contributing to the ORSA process (I'll get my coat then...)
  • 3 year projection of capital requirements is the most common planning period envisaged
The same North American slant is then given to a financial modelling survey, which gives us another chance to peek over the fence. They found the following;
  • Reasonable amount of dissatisfaction around run-times
  • Around half planning to change their model governance processes in the near future
Looks like the NAIC/EIOPA covergence work should be a walk in the park then, at least on these topic...

Tuesday, 5 February 2013

Central Bank of Ireland - Prudential regulatory agenda for 2013

A pretty meaty speech was delivered last week by the CBoI's head of life insurance supervision, covering the prudential regulatory agenda in Ireland for 2013 and beyond. In essence it is a rather sobering take on the flipside of the Celtic Tiger's death and its impact on what was an effervescent, if still fledgling, cross-border insurance industry, noting that new business volumes recorded in Ireland have declined for the 5th year in a row, and currently aggregate out at a break-even APE/PVNBP margin.

I found there was actually a lot to take from this on the ORSA front, and would recommend any readers on the Emerald Isle pick the bones out of it, in particular that the regulator "expects to see";

  • Strategies reflecting "current market realities" - highlighting excessive commission to brokers, swollen lapse/surrender rates and reduced margins from over-competition.
  • Tight management of costs
  • Increased efforts put in place to retain existing in-force business
  • "Credible business plans"
  • Viable alternatives to grow business through distribution or product range changes (online facilities highlighted specifically)
While much of this may read as common sense, one can reasonably assume that the CBoI is not seeing enough evidence of this in the Financial Condition Reports and strategic plans that currently cross their desks, and are expecting a much meatier ORSA-type approach to managing strategic risks over the business planning period in the immediate future.


Monday, 4 February 2013

FSA and ICA+ - making the best of a bad hand...

The FSA released the letter we've all been waiting for at the end of last week regarding their plans for  allowing UK firms to use their intended Solvency II-ready internal models to calculate their compulsory Individual Capital Assessments between now and the go-live date of Solvency II (don't laugh, it's still possible that it might go live ;-) )

I suspect a mix of suitability, financial necessity and pragmatism has led the regulator to pursue a relatively relaxed take on ICA+ , for example;
  • It is "not a condition for IMAP review or approval"
  • It "does not require Solvency II tests and standards [for internal model approval] to be met"
  • Firms will confirm the scope of material which needs to be reviewed for ICA+ assessment, rather than the FSA themselves
  • They also confirm that it is "not [their] intention" to bring in Solvency II reporting requirements "...any sooner than required by EIOPA"
That said, while the FSA try to thin out the field by noting that ICA+ is "most appropriate" for firms who are both in IMAP and due for a business-as-usual ICA review in the next two years, it would make sense for anyone in IMAP to pursue ICA+, more than anything because of the interminable delays in Europe might put a firm outside of ICA+ at a competitive disadvantage on the capital front.

The onus therefore appears to be on the industry to quantify and explain the differences between the inputs, processes and outputs of their ICA models and Solvency II models, as well as demonstrate how their ORSA processes address the existing requirements of INSPRU, specifically targeting INSPRU 7. There is also a sneaky request for a self-assessment of progress towards achieving compliance with the Solvency II tests and standards for internal model approval.

From a practitioner's perspective, I had a particularly large chortle at the requirement for all materials being used in the ICA+ assessment to have been approved by the firm's Board - I'm sure they are looking forward to another two years of swollen board packs...

There is more information to follow from the FSA in Q2 of this year, presumably on the basis that the  LTG assessment activity they are on the hook for will have concluded, and more focus can be shifted to this pioneering work. Congratulations to them for not overegging this particular pudding, on paper at least.

Monday, 28 January 2013

EIOPA's Long Term Guarantees assessment - long time coming

So EIOPA have finally released the specifications for the Long Term Guarantees assessment (press release here), the second most eagerly awaited release this year behind Kate and Will's baby. Relatively straightforward timetable of events expected by EIOPA it would appear;

  • End of March - completed templates submitted to national regulator
  • April and May - national regulator and EIOPA will analyse and synthesise results
  • Second half of June - technical results to be provided by EIOPA to the trilogue parties
  • Mid-July - report provided by the Commission to the co-legislators
I am stressing the second half due to the current procedure file for the Omnibus II Parliamentary Plenary session pointing at a 10th June date, which is of course too early to consider that report in making a decision on Omnibus II. That leaves one more Plenary window in July before the summer recess, so we can probably bank on a postponement to September at the very least, particularly as the report is bound to contain more contentious bones than a frozen beefburger...

A few things of note in the suite of materials published by EIOPA today, of which the presentation slides are perhaps most useful;
  • Objectives of the assessment include "possible competition distortions" and "impact on long-term investment", which have surely topped the list of differences between trilogue parties and indeed individual countries to date.
  • Predominantly based on YE 2011 balance sheet, but will test pre and post financial crisis positions as well (2004 and 2009)
  • Can optionally use internal models for capital and risk margin calculation, provided the entity is in a national IMAP.
  • At least 50% of Life non-linked TPs and 20% of Non-Life TPs in each country must be covered (hence the industry has been quite vocal about doing this at financial year-end!)
  • 13 scenarios included in the assessment, of which one does not include any of the proposed measures - not sure if that reduced quantum addresses the concerns of the FSA's Insurance Standing Group back in September, when the number sat at 18.
The main meat in today's releases are of course for the digestion of your friendly local actuaries and accountants - best of luck!

Tuesday, 22 January 2013

EIOPA, Parliament, IRSG and LTGs - momentum sustained?

I guess I should start with a Blein Vie Noa to one and all - after a relaxing few weeks in France I am now back on the beautiful Isle of Man sizing up opportunities for 2013 and beyond.

I didn't expect I would be missing much over the festive period and, other than the FSA sacking-off their proposed January IMAP industry briefing in favour of a (yet to be delivered) letter, things did go quiet. Freshfields kindly filled some airtime by pulling together another of their "where are we now" summaries that remain excellent (and free) materials that I would recommend punting on to your non-executive directors.

Luckily the noisemakers got back in the game as soon as school restarted, focused largely on the content of EIOPA's Insurance and Reinsurance Stakeholder Group's minutes. This meeting was held in October, so in terms of new news, it is right up there with "Earth is not flat". That said, we don't all have access to the inside track before publication of such materials, so it was interesting to pick through the doc for steers. I noted the following;
  • Continuing problems with terms of reference for the LTG assessment (indeed the LTG sub-group note on p7 that there isn't even a EU-consistent definition for LTG!) - still looking like it will impact on the designated Plenary session for Omnibus II due to a combination of last minute delivery of the technical specifications to the industry itself as well as the output report to the Parliament, who themselves were reported today as being less than impressed with the final TORs. The potential number of scenarios in the assessment also clearly remains a sore point.
  • Acknowledgement that "Autumn 2013" is now "best case scenario" for Omnibus II adoption, though, according to van Hulle at the last EIOPC meeting, the Commission and Parliament remain almost diametrically opposed on what should materialise at Level 1 and Level 2 (full minutes from EIOPC here)
  • Confirms the ex-ante approach is favoured by Parliament and Commission (significance covered by Gideon here), and that Parliament have no wish to commit to an implementation timescale.
  • The Council members are being "heavily lobbied", fostering implementation uncertainty.
  • Attending stakeholders supported a definitive 2016 date.
  • The IRSG's Governance sub-group flag up consistency issues around Fit and Proper regs as well as the "AMSB" term that I'm sure we have all had practical issues with over the last 2 years!
  • Proportionality remains a "main concern" for mutuals, as well as smaller insurers - despite having a designated sub-group, any substantive guidance on applying the proportionality principle looks a distant prospect at best.
  • Astonishingly, minutes from May 2012 could not be approved due to EIOPA's "workload" - small instance of an institutional tardiness problem?
Whether or not the industry is losing it's appetite for the Solvency II banquet, when you check out EIOPA's workplans for the next couple of years, at least one body will be filling its face!

Another interesting piece came out in the last week, when InsuranceERM pushed out the findings of a Solvency II roundtable (no sub required), bringing in a few UK-based CROs and the like, ostensibly to chew over the loss of momentum in the project. A few noteworthy bits jumped out;
  • Solvency II balance sheet appears to be off the agenda for ICA+, for both regulator and industry
  • Perception that, with the transition of regulatory "ownership" to the Bank of England, there is a decreased likelihood that the industry will be able to use Solvency II as a capital release mechanism
  • A suggestion that the FSA was more minded towards EIOPA's opinions than the industry's during IMAP 1.0, something which has seemingly reversed with the advent of ICA+
One certainly hopes that the UK industry and regulator can make a decent fist of this indeterminate transition period without having to break the bank...

Monday, 17 December 2012

ABI update on Board Effectiveness - updates on Diversity and more

The ABI pushed out their Board Effectiveness update recently, which remains thematic rather than broad-brush, so I hoped to take something significant out of it, particularly around Board Diversity, which they have touched on before in a rather clunky manner, reflecting the uncertainty around the topic (specifically the gender element) last year when it was brought to the fore politically by Lord Davies report amongst other works

Diversity - apparently impossible
without symmetry...
 Staggeringly, the terms "Board Diversity" and "Gender Diversity" continue to be interweaved, which flies in the face of recommendations around "diversity of perspective" (p8, then reinforced by Chairs on p18), which of course needn't be constrained by gender any more than class, race, age or all-round Manx rugged handsomeness...maybe not the last one then :-(

That said, the statistics have clearly improved over the year on overall female Board representation, despite some recent high profile FTSE 100 CEO resignations leaving things at the Executive end somewhat less positive. Some benchmarks included on what "good" looks like in the context of disclosures and gender diversity policies, with M&S (what we're doing) and Vedanta (why we can't do it) representing opposite ends of the inclusivity spectrum while remaining concise. Good stuff on examples of gender diversity policies and affirmative action from p31-33 as well.

The ABI have also picked out the trend of using existing relationships with remuneration consultants/auditors to spin-off independent Board evaluation work to, and have recommended that it cease, and be replaced by something more independent (hmmmm, wafer thin market and lack of independence - sound familiar to anyone in IMAP?)

Monday, 10 December 2012

Long Term Guarantees and Pillar 2 - back to the future?

Just like the popular floor filler from Chris Rea*, it looks like the individual countries would like to "Go their own way" when it comes to capital calculations for long term business, so reports Reuters.

Clearly the elephant in this particular room of different products in different countries is "why wait 10 years to table this", on the basis that retirement products in Europe haven't changed seismically in the genesis period of Solvency II? A cynic might say that the conflicting market/product representatives each thought they would emerge victorious after the lobbying rounds (hence didn't ask for carve-outs at outset), only to find an economic crisis and the threat of an EU-wide 'lost decade' was the backdrop to negotiations.

To see a political move from the French Finance minister to attempt to outflank EIOPA's LTG assessment is pretty poor form, but is at least in keeping with DG Faull's letter to Sr. Bernadino, which did everything but tell him the desired answer to the LTG question, and I suppose the weight of public opinion if nothing else would suggest that discouraging long term investment right now (even if the initial maths say that the capital price is right) is politically naive and a shade obtuse economically.

This parting of the ways may certainly be the case for the balance sheet question, but oddly seems to also be rearing around early adoption of Pillar 2, where the Dutch are looking pretty keen while at the same time the Irish have stated that they will wait for the crowd.
*PS Shame on anyone who, with their Solvency II hats on, thought I might be talking about the "Road to Hell"!

Governance Matters at ILAG - Co-operation between control functions under Solvency II

Been a bit quiet on the Blog front - not because my country and I are licking our wounds after being opened up by HMRC like a Manx kipper, but because I had been asked to chip in with my two cents at an event hosted by the Investments and Life Assurance Group in London. It was an exceptionally well run event, with some interesting takes on the participation of Risk, Actuarial and Internal Audit functions in meeting not only the Directive requirements, but also the expectations of wider stakeholders and indeed policyholders.

My particular focus was on Control Function interaction, the inevitable areas of crossover and emerging skill gaps, and I also touched on some benchmarking papers as well.

My transcript is below and, conveniently enough, reads like a Blog Post. If you would like the slides with the script/hyperlinks embedded, either register with ILAG or drop me a line at allan@governance-matters.co.uk and I will send them on for the bargain price of...free!

________________________________________________________________________________


So back in my former life of BAU busy-ness, my interests in Control Function optimisation were generally led by budget (or lack of it), in particular;
     Professional standards – were there enough bodies, and were they sufficiently skilled or motivated, to perform the fundamentals required (bearing in mind corporate governance code reforms both in the UK (2010 changes BTW, not 2012’s!) and Ireland meant that some system of governance work had to jump the Solvency II queue regardless)
     Proportionality – would the lack of definition around the proportionality principle (Lloyds take a stab on p2) lead to companies being woefully underprepared once the national regulators inevitably bared their teeth post-2009. The impact of misinterpreting Article 41.2 genuinely put the fear in me!
     Multiple roles per person/outsourcing – Whilst some common sense calls were made at the smaller end by merging Risk and Compliance functions, the more operationally substantial calls around merging risk and actuarial functions, outsourcing internal audit/compliance advisory services and recently the march towards outsourcing independent model validation and data quality assessments all posed questions.
Of course, having now worked with one of the biggest, my natural curiosities are not piqued by the unavailability of resource and budget, more by the complexity of wading through the reams of opinion and material that large budgets generate! In particular, I have been monitoring;
     The ability to get bang for buck out of programme spend, with most Tier 1 firms having comfortable broken 3 figures despite, from a Pillar 2 perspective at least, having something akin to “textbook” governance systems at outset
     Whether the “Consultant writes/BAU implements” will be proven to be a successful method of preparing for Solvency II, or whether the plethora of Pillar 2 material outputs will, once unsupported by its transient authors, die a little death
     Control functions in Groups, and perceptions of which countries’ governance is considered superior/inferior in the world of supervisory colleges
But you lucky guys in the UK already have a decent amount of written word around what your control functions are up to, with GENPRU, INSPRU, SYSC, SUP and the Corporate Governance Code all building cases for functional remits and appropriate governance structures
     So we know our friendly actuarial function will be knocking out the sums which end up in our pricing and reserving worlds, produce the EV and capital calcs that (hopefully) keep the wolf from the door, thus quantifying any risks which lend themselves to being quantified, and all the while self-policing the suite of models, methodologies and assumptions that aid them in doing so…
     We know our compliance function will be focused on monitoring and assessing the effectiveness of an entity to comply with prevailing laws and regulations, at a micro and macro level…
     We know our beloved IA function will be assessing the effectiveness of risk management, internal controls and governance processes…
However, the one rather raggedy looking function out of the existing set up is my one, the humble Risk function! While SYSC21 has beefed up the significance of Risk in the prevailing regs, the other SYSC tasks attributed make it feel a bit powder puff functionally by comparison.
In fact, both Risk and Compliance don’t especially feel enormously catered for in the prevailing set up as opposed to Actuarial and IA – not sure whether this is due to the consistency of their development as professions dwelling in the more certain lines either side of the second or not, but it’s certainly my feel as an outsider looking in…
…but thanks to Sol II (or at least the veiled threat of its implementation before I retire), we are now looking at control functions in reasonably neat packages complete with instructions!
One of the biggest problems that I’m sure all present have easily surmounted over the last couple of years is the ambiguities in the language of the Directive and Implementing Measures.
As a man who is married to a wonderful French woman, I am used to following instructions, but of course we are frequently confronted with flowery language such as “covers”, “advises”, “provides an opinion”, “liaises”, which is a consultant’s dream come true, but doesn’t help BAU demarcate and co-operate with any great certainty.
That said, the long and short of it ends with;
Risk
Risk come out with a pretty wide-ranging remit which mostly sits in the FSA’s Dream Function world of advisory, co-ordination, challenge and monitoring, though its ability to monitor “the general risk profile” is clearly reliant on the Actuarial function. Not assuming all present are part of IMAP, but the big ownership piece comes of course with the Risk function taking on responsibility for compliance with the internal model requirements on its design, implementation, testing, validation, documentation and weakness and limitation reporting. Clearly a massive undertaking and, certainly at the small/medium end, not one that can be naturally chalked off with an existing compliment of staff.
Actuarial
Actuarial function requirements include requiring knowledge of actuarial and financial maths but leaving an “other standards” clause in to help out the less well-policed countries! They do also however get some wriggle room on responsibility where it would otherwise be assumed (at least by me!), and so ”co-ordinate” TP calcs, “express opinions” on reinsurance arrangements and the underwriting policy, or “contribute to” implementation of the risk management system.
Compliance
Compliance are not burdened with a laundry list of tasks as such, however to advise the AMSB on compliance with Solvency II is a pretty unenviable one (particularly now!). Perhaps the biggest challenge looking at the remit impartially is the depth and breadth of coverage that the function will need to provide, not just on Level 1, 2 and 3 and SOLPRU, but also be able to challenge the adequacy of the vastly expanded internal policy suite
Internal Audit
IA get the unimaginable luxury of having a relatively unchanged remit, particularly in this neck of the woods where risk-based internal auditing and planning is de rigeur.
Outsourcing
The aggression in the wording around the Outsourcing requirements suggests that the days of outsourcing control functions being a “write a cheque, then dusting-of-the-hands” job are at an end!

Now the legislative ambiguities just mentioned leave ample room for control function bun-fighting due to the inevitable crossovers of skillsets for certain tasks and, perhaps most pointedly, who takes precedence in such instances.
ORSA
Probably the biggest area of convergence and potential toe-stepping-on is of course the ORSA space (covered here on the blog) which in the crossover context it is more about who performs which sub-processes, under whose authority, and who “holds the pen” when collating the record of the ORSA performance.
More by process of elimination than by legislative direction, ORSA oversight seems to sit at the door of Risk, a concession even made by the SAI over in Dublin whilst simultaneously illustrating how little they are required in the ORSA Process! Is this therefore real or nominal oversight, or even worse, a PMO-type record collection role.
One other crossover area comes from the removal of the requirement (after pre-consultation) of an independent assessment of the ORSA Process – whilst losing the compulsion should be welcomed on principle, is there a danger that the IA function, through risk-based planning, may under or over-Audit the ORSA space? Just a thought...
Risk IMMMR/Advisory/Challenge
The world of risk identification/measurement/management/monitoring/reporting also becomes one with potential for friction, through the merger of the worlds of the Risk function’s qualitative risk register-type approach and the actuarial function’s established risk quantification methods, into what ultimately comprises the “general risk profile” as per the Directive text – one of the Big 4 suggested that the P&L Attribution is, for actuaries, “the real risk profile” for example, and perhaps some of you concur!
Regardless, the twin horrors of agreeing with Actuarial quantification methodologies for hard-to-quantify risks, while fostering a dependence on them for measurement, monitoring and reporting facilities around financial and insurance risks suggests more of a one-sided dependence rather than “close co-operation” between the functions.
Compliance risk
This works similarly for the world of compliance risk identification/assessment, nominally in the remit of the Compliance function - are they being dragged somewhere nearer the first line if they are producing this work for the Risk function? Just feels a bit blurry…
Emerging Risk
For emerging risks, my main concern is the robustness of the top-down/emerging risk identification process filtering its way into some quantified element within the ORSA and/or internal model – Risk is chalked down for identifying and assessing emerging risks, but their ultimate measurement isn’t catered for.
For internal Modellers
And into the internal model space, the “close co-operation” between the Risk and Actuarial functions, at firms big and small, has the potential to cause all manner of difficulties, in pure process efficiency terms as well as the cost implications of IMAP failure,. One CRO referred to this as having to “solve the risk management team/actuarial team conflict” in a recent presentation on model governance! Clearly though there is quite a gap to bridge between how this governance worked under ICA and the demands of Solvency II.
Establishing an “independent” team for regular validation, regardless of headcount seems to be something of a holy grail, with a growing trend towards “bringing someone in”, if only for the comfort of benchmarking against one’s neighbours. This also helps a company stay in line with Mr Cardoni from the FSA’s call that “individuals performing the validation must possess the necessary skills, knowledge, expertise and experience”, but does little for self-sufficiency, as well as leaving the Risk function with the job of relationship manager during validation exercises.
The approaches available for the Risk function to discharge its other responsibilities around the internal model requirements, in particular around model design and implementation, of course crossover into terra firma for the actuarial function – would be interesting to know how any modelers in the room have approached this, as a cursory sign-off from Risk on a suite of model development and implementation paperwork doesn’t feel in keeping with the spirit of the regs, though an IRM survey from March suggested at least 11 IMAP applicants were doing something along these lines!
So even if Sol II doesn’t directly ask for enhanced skill sets, we in all functions can all see the iceberg coming if we don’t fix up and look sharp. As ever, the most fascinating movements are in the actuarial space as they meander over towards the risk in what is lined up to be the biggest land grab since Enclosure!
There is certainly plenty of encouragement, in a profession which one of its own was happy to recently decry is “trained to deal principally in numbers and statistics”, to branch out into Risk, with the CERA qualification – “the most comprehensive and rigorous demonstration of ERM expertise available” – perhaps leading the way. While the profession is quick enough to highlight the weaknesses and limitations of an Actuarial CRO, does this additional qualification do enough to bridge the gap?
Certainly the GCAE suggest in their work that professional education may need further enhancement especially in relation to risk management. Over in Ireland however, the SAI are taking it one step further in their Strategic Plan for the profession, going as far as looking to partner up with a university to develop a risk programme for anyone “who wants to skill up quickly in the area”. Can’t say I’m sure what the rush is, other than opportunity knocking!
On the Risk front, the IRM were very quick to respond to the FSA’s Dream Function presentation back in April 11 with a vigorous defence of the appropriateness of non-Actuarial heads-of-risk, noting that the two professions were “extremely complimentary while different”, whilst mockingly emphasizing that the very concept of CERA highlighted that “Core [actuarial] qualifications do not give sufficiently broad training”.
That said, while the IRM have focused attention on some big ticket items such as Risk Appetite and Risk Culture  over the last 18 months, is it fair to say that training or certification touching on capital measurement and management, modeling, financial and insurance risks and their strategic application would have been a welcome addition to the qualification roster (notwithstanding what is available elsewhere through GARP’s FRM designation)? I rather embarrassingly had to answer a question from a colleague the other day about “how did you get qualified for Solvency II” – I won’t tell you how I answered!
For IA, there is a brave new world for anyone with the chops to upskill or expand their horizons. While the ever-moving implementation date maybe postpones any programme assurance work that IA could have picked up on the run-in to go-live, there is clearly an expectation at the FSA that they will contribute to activity such as internal model validation and data quality assessments, though I’m not seeing anything in the world of training to aid them in doing this (hence the consultancies are doing so well out of it I suspect!).
Deloitte do present a nice picture of some of the additional skills that IA may fall short on, in particular a natural aversion to covering non-Operational risks, despite their relatively higher contribution to the risk profile of insurers. One other thing I had in mind, knowing the IA profession’s predeliction for COSO was changes in the world of Insurer ERM since the last refreshes of COSO’s ERM work, particularly COSO’s latest take on risk assessment – instinctively feels like there may be some catch-up work to do in the IA field, but may be wrong.
For the compliance guys, is it fair to say that you already have your work cut out swallowing Level 1, 2 and 3 paperwork as well as any handbook changes which will emerge at the end of the PRA/FCA divorce. Interested to know if anyone getting roped into other activities!
The last thing I was going to mention was that, in the absence of rapid upskilling, and the wind-down/mothballing of organisation’s Solvency II Programmes, has anyone worked out whose BAU budgets any outsourcing will come out of for the next couple of years?
Moving on to how people are doing on the functional operation and indeed co-operation front, there is a reasonable amount of intel and ideas out there, which you may have clocked on its way through, but maybe makes a bit more sense in aggregate.
Risk function effectiveness
As far as Risk function effectiveness goes, the IRM straw-polled their Solvency II SIG this year, and identified some worrying trends from a Sol II readiness perspective, in particular;
Only half have their CRO communicating directly with the Board on risk matters – breathes some life into the quote from Axa’s Life CRO that risk management is too important to leave to the risk management department”…
     Nearly half said risk papers are "noted with a short discussion" at Boards
     A number of risks were not covered by the respondees' risk functions – ALM and strategic risk in particular
     Over half felt they had overlap with either Actuarial or Compliance, and a quarter with IA
     As mentioned before, a decent number of risk functions are not directly delivering documentation, testing and validation of the internal model.
     Half said the process of implementing Solvency II affects their ability to become relevant to the Board
The IRM also very recently performed a survey (with a reduced quantum due to the subject) on Internal Model Governance trends, which highlighted that;
     Risk is “responsible” for IM governance (with no exceptions in the survey), but Actuarial are “involved”, but with no further details
     And many respondents feel “real decisions” continue to be made outside of IM Governance framework, in particular around stress testing, back testing, model change and expert judgement – makes one wonder if an Actuarial CRO could counter that governance leakage?
Risk appetite design and application
There was a paper released by our hosts this year which emphasized the differences in design and implementation of Risk Appetite Frameworks between Risk and Actuarial functions, noting that a quant heavy actuarial approach gets more traction and quicker! This doesn’t augur well for the new ORSA world of “everything must be quantified”, as it is the qualitative risks that need the most attention.
Reporting lines
The world of reporting lines remains a pretty hot topic, with KPMG putting out a decent paper which recommended, amongst other things, that the Actuarial function should consider a formal demarcation between risk taking and risk assessing/measuring actuaries, which would negate the trend of shoehorning capital actuaries through the Head of Risk, keeping them all reporting through the AFH. They also added that at least half of the respondees were not yet at their desired end-state regarding the basic new Actuarial function requirements around underwriting and reinsurance adequacy opinion provision.
IM Validation
In the model validation space, as early as the end of last year we saw KPMG reporting that half of the IM production staff were also involved in the validation process, emphasizing the practical difficulties in functional separation whilst in Programme mode – would love to see how those numbers have moved since. 
Having seen the FSA’s feedback in May on what had been observed at that point in time (in particular that independence from model development and being “sufficiently competent” went hand in hand), one can imagine that IA’s role in the activity will be marginalized in future at the ongoing expense of bringing in the Big Guns every year.
Things a Risk function could be doing
And finally, while I have touched repeatedly on activities which a Risk function may find cannibalized by their ravenous Actuarial counterparts, as well as responsibilities bestowed upon it that it may not be equipped to discharge, I have seen a few pieces around activities that the Risk function would probably love to be doing more of, given half a chance.
A recent piece by Accenture got my engine running, around the future of data analytics – I definitely feel that, with the appropriate informational power at their hands, the risk function can provide a massively enhanced IMMMR and advisory services at little additional cost (the main cost of course already being sunk into data  quality and data warehousing projects independent of the function)
One lovely piece, pitched in the context of why Equitable failed, reads like a list of things a CRO should be focused on, such as NED ambivalence and underperformance, or executive hubris, while a Towers Watson presentation on prepping for the future draws out the most practical big ticket activities such as superior understanding of model weaknesses and limitations and tail risk, rather than a more general clutch at the full bag of responsibilities bestowed on the function by Sol II.
A research piece from the CII (sadly no longer free!) compliments that, suggesting that a “balance between modeling and judgement” must be struck by Risk departments in order to breath relevance into a function that the author was outspokenly critical of in his research.