Showing posts with label FSA. Show all posts
Showing posts with label FSA. Show all posts

Wednesday, 20 November 2013

Fit and Proper Persons in financial services - judge not, lest ye be judged

A quick note on the high-profile leadership-related crises which have reared their heads over the last couple of weeks, and whether the risk management professionals of the world can learn from them.

Two stories related to the flip-side of the kind of driven, charismatic figures that can progress rapidly through their chosen careers while coping with some rather spectacular character flaws. One being the ex-Chair of the UK's Co-operative Bank (already in financial turmoil), caught in a drugs and prostitutes sting this week, which has followed on from the city mayor of Toronto, who has been drawn into a similar web of videotaped misbehaviours.

Sticking with the financial services example, we have a number of issues which should interest the risk pros;

Some elements of the story are dominating the headlines, such as the gender of the prostitutes, the type of drugs used, or the fact that the Co-operative movement, purporting to have a higher calling than the soul-hoovering plcs, should perhaps be impervious to such matters. 

For me, we have a straigthtforward case of significant internal control failings across departments, a failure to hold senior management to account when breaching internal policies, and a very strong working example of a reverse stress test, combining a number of risk factors which in concert deliver a failed business model. On that basis, I would think that the business-as-usual risk teams across the country will be analysing this one until the cows come home.

How much of a bum-paddling the FSA/PRA deserve on this is another matter. Whether light-touch or prescriptive, I think regulators in many countries will wince at the details of the approval of Rev. Flowers' appointment once this one plays out at Treasury Select Committee over the coming weeks (I have no insider information, but let's face it, we'll be watching through our fingers!). 

For context however, in 2009 the FSA (as it was then) made a formal submission to the TSC addressing many of the failings uncovered by the retreating tide post-Lehmans/Bear Stearns/Northern Rock, and what Hector Sants & Co had planned to make up the shortfall. 

The TSC made a number of comments (sandwiched within the FSA's submission) which are worth highlighting today - I have emphasised the parts which should now echo in eternity;

The FSA's assessment of whether senior bankers were fit and proper for their posts appears to have been little more than a tick-box formality, unless the applicant had a criminal record or gave some other evidence of a shady past. That bar was demonstrably set too low. We welcome the acknowledgement from the FSA that a candidate's competence, as well as their probity, will now be thoroughly reviewed before taking up a senior post in a bank. We recognise that there may be some dangers in the FSA assessing competence, not least because the FSA will become exposed to accusations of incompetence itself, if it makes a wrong judgement

We recommend that the FSA assess whether bank executives should possess relevant qualifications. We would like to see banking qualifications become one of the core indicators against which the FSA can assess a candidate's competence. If a candidate has no relevant qualifications, the onus should be on them to prove to the FSA that they have relevant compensatory experience
And from the PRA themselves...
We strongly agree that it is important for bank executives to have the right level of skills and experience. As noted above, we have recently written to all CEOs of relationship-managed firms reminding them that it remains the firm's responsibility to ensure that the candidates they put forward are fit and proper to perform the role in question, and that firms should, therefore, have robust recruitment, referencing and due diligence processes in place
It was only three years ago - at what point do we (grim pun intended) practice what we preach on corporate governance in financial services?

Wednesday, 3 April 2013

UK's "new" Prudential Regulatory Authority - Approach to Insurance Supervision

So a magical thing happened over the weekend: a venerable institution disappeared on Friday, only to come back reborn on Monday...

...that's right, the FSA is no more, being replaced by two more focused entities in the Prudential Regulatory Authority (PRA) and Financial Conduct Authority (FSA). This is part of the UK-specific fallout from the financial crisis, where a perceived lack of focus from the former tripartite system which housed the FSA allowed for both systemic risk (Northern Rock, RBS) and conduct risks (PPI, Interest Rate swaps) to emerge largely unchecked.

Rather excitingly, this means a new website with some natty logos from the Bank of England (which
PRA - emperor's new clothes
or Solvency II aperatif?
has rehoused the PRA side of the FSA), as well as a statement on the new supervisory approach that the PRA will be taking.

For anyone in the ERM/Solvency II/Corporate Governance space, this gives us a chance to pick up on the kind of regulatory interrogation one might expect when writing/upgrading system of governance-related materials in preparation for both full Solvency II implementation in 20??, as well as how they are accommodating EIOPA's interim measures from 2014.

Remembering that the PRA's two statutory objectives are to promote safety and soundness of the firms it regulates, as well as specifically providing appropriate protection to insurance policyholders, I thought it wise to make some notes on how they have catered for Solvency II and deference (when due) to EIOPA, as well as the general content around expectations of governance systems. I found the following worthy of note;


Control function-specific

Section 82 - "[PRA] wants to be satisfies in particular that designated risk management and control functions carry real weight within insurers"

Section 117 - Should have separate risk management and individual control functions in place (dependent on nature scale and complexity etc)

Section 118 - the PRA "expects these functions to be independent of an insurer's revenue generating functions"

Section 120 - expectation of an "operationally independent Actuarial function", which the PRA consider to be "integral to the effective implementation of a firm's risk management framework"

Section 182 - "Actuaries can play an important part in supporting prudential supervision"

Section 119 - an effective Risk function on the other hand merely "ensures that material risk issues receive sufficient attention from the insurer's senior management and Board" - just because I'm paranoid, doesn't mean the Risk profession isn't being made something of a gooseberry here, particularly as the FSA/Actuarial profession love-in started some time ago!

On Risk Appetite

Section 110 - a firm's risk appetite "[is] to be integral to its strategy, and the foundation of its risk management framework"

Remuneration

Section 84 - "remuneration and incentive schemes should reward careful and prudent management" - just like Prudential's and Standard Life's did this week!

Section 194 - Hint at potentially restricting pay in firms if intervention is warranted


Stress/Reverse Stress Testing

Section 109 - the AMSB must have "...an explicit understanding of the circumstances in which their firm might fail"

Section 145 - with regards to Reverse Stress Testing, "...management should consider the reliability of the output of the internal model compared with the results of these tests"

Section 106 - "competent, and where appropriate, independent control functions" should oversee risk management and internal control frameworks


Internal Models

Section 116 - On Internal Models, the AMSB should understand;
  • extent of reliance on models for managing risk;
  • limitations of their structure and complexity;
  • Data used;
  • key underpinning assumptions
Section 140 - "PRA expects internal models to be appropriately prudent"

Section 144 - firms may not choose the lowest capital requirement to determine whether or not to model internally


Regulatory Capital

Section 135 - for capital adequacy, firms "...should not rely on regulatory minima", and also "...should not rely on aggressive interpretations of actuarial or accounting standards"


Proportionality

Sections 212-215 - touches on treatment of "low impact" firms - is this effectively where aggressive approaches to proportionality interpretation should be expected (combined control functions, limited documentation, passive acceptance of Standard Formula etc)?

p43 - table covering the allocation of supervisory staff - 10 staff to 1 firm for the 25 largest insurers, versus approaching 10 firms to 1 supervisor at the small end.

Solvency II-specific references
  • In the PRA's view "[Solvency II technical detail should] leave scope for supervisors of individual insurers to make informed judgements around risks posed"
  • Confirms that elements of the Directive such as Prudent Person Principle, ORSA, Control Function requirements and Pillar 1 are all aligned with the new Threshold Conditions
  • Model approval will be dependent on "adequate" risk identification, measurement, management, monitoring and reporting throughout the modelling process
  • Will impose capital add-ons when necessary "to ensure insurers meet the required standards"

Friday, 29 March 2013

EIOPA Preparatory Guidance - ORSA (or 'forward looking assessment of risks')

Forward-looking assessment of the undertakings own risks (based on ORSA principles) (plus explanatory text)

The ORSA preparatory guidelines* are not a massive burden for anyone busy rolling eggs down hills at the moment, coming in at 34 pages containing 25 guidelines, as well as 29 pages of explanatory text. In this instance, it is probably disappointing to any underprepared supervisors and insurers in that they may have preferred more!

More pointedly, the materials add little to what was already in existence from EIOPA in July 2012, and certainly will required little in the way of adaption in the UK's instance, who are already in a similar headspace and have been advising accordingly.

Of course the world and her husband have piped up with their opinion on what ORSA should cover and how it should be administered and documented (this post has a decent sweep at capturing most of them), so opinion on this matter is something we are not short on.

For me the headline points are:
  • ORSAs (well, 'overall solvency needs assessments', but let's be serious!) expected from 2014
  • Internal Models should be used by anyone in pre-application
  • Likely that most standard formula firms will have to qualitatively assess deviations between SF and their own Risk Profile at this time
  • Expectation of an internal ORSA report and a ORSA supervisory report
  • Records of the assessment expected to be documented and kept which must be "appropriate" - no prescription of what that means
  • ORSAs to be performed at least annually
The following points are either new, or worthy of reiteration for anyone whose preparations on this front are less than certain - for ease of reference I have used 'ORSA' where EIOPA use 'forward looking assessment of risk', and as with the other preparatory guidance papers I have looked at, I will assume there will be blanket application as written, with no dissent from industry or NCAs:

Guideline 3
  • Overall Solvency Needs assessments will be expected from 2014 (i.e compliance with Article 45.1)
  • Minimum of 80% of the market must also assess whether they would comply with the Articles 45 (b) and (c) from 2014 - regardless of any Pillar 1 uncertainty.
  • Internal Models expected to be used in ORSAs if a company is in model approval pre-application
  • IF the standard formula is 'provided' by 2014, expectation that SF firms will assess deviation between the SF assumptions and their own Risk Profile - this excludes anyone outside of the magic 80% catchment figure mentioned above.
Guideline 6 - Documentation generated by ORSAs must include:
  • An ORSA Policy
  • An ORSA Record
  • An Internal ORSA Report
  • AN ORSA Supervisory Report
Guideline 7 - The ORSA Policy must include
  • Description of component ORSA processes and procedures
  • Consideration of the linkages between Risk Profile, Risk Tolerances and Overall Solvency Needs (OSN)
As well as information on
  • frequency on stress tests, scenario analyses and reverse stress tests; 
  • data quality standards; and 
  • the frequency of the assessment, justified in relation to Risk Profile, volatility of OSN relative to capital position, timing (from calendar perspective I guess) and circumstances for ad-hoc assessments
Guideline 8 - ORSA Record
  • Firms expected to "appropriately evidence" the assessment - no prescription as to what that means (logs, working papers, meeting minutes, e-mails)
Guideline 9 - Internal ORSA Report
  • AMSB must communicate results to "all relevant staff" post-approval, which includes the ORSA results and conclusions
Guideline 10 - ORSA Supervisory Report
  • 2 weeks after concluding ORSA, ORSA supervisory report must be submitted, which must include;
  • Quantitative and qualitative results, and conclusions drawn
  • Methods and main assumptions
  • Comparison between Own Funds, SCR and OSN
Guideline 11
  • Must quantitatively estimate the impact of different valuation bases (if used) when assessing OSN
Guideline 12
  • OSN must be quantified, supplemented by a qualitative description of all material risks
  • Expectation that these items are all stress/scenario tested
Guideline 17ORSA output to be used at least for;
  • Capital Management
  • Business Planning
  • Product Development
Guideline 18
  • ORSA to be performed at least annually

* So let's end with something fundamental, EIOPA - it is NOT useful to replace 'ORSA', as an acronym or indeed in full, with the expression "Forward-looking assessment of risk (based on ORSA principles)" 5 years down the road - I'm sure there is a rationale, just as sure as I am not going to like it (even the GCAE agree with me, going with 'ORSA-like')!

Thursday, 28 March 2013

EIOPA Preparatory Guidelines - System of Governance

Consultation on System of Governance preparatory guidance (plus explanatory text)

For a topic which has felt like a given for a number of years (certainly in UK and Ireland where we already ask a lot in this area), the System of Governance preparatory guidance is still 40 pages, comprising of 57 guidelines, accompanied by 60 pages of explanatory text.

A couple of things immediately grabbed at me when going through the guidance (again anticipating a conservative approach of the supervisors rolling over and applying all content as is)
  • That the Risk Management Policy (regardless of how one structures the component elements) is expected to contain procedure-level information about the management of each major risk category - this sounds hopelessly disproportionate, and almost impossible for supervisors to reasonably get through;
  • That it is "expected" that large or complex firms separate their four key control functions, and that others at the small/medium end may ultimately find it easier to do so than consider the range of controls/maintenance of independence required to have combined functions;
  • That an expectation that insurers' systems of governance require regular independent review, with the AMSB only retaining the ability to choose the performer;
  • That insurers will be expected to formally identify/analyse/report on Operational Risk Events
  • That EIOPA bottled out of defining Risk Appetite and Risk Tolerance, leaving national supervisors and insurers to fight it out amongst themselves.
Ultimately, the document reads like a checklist which practitioners or full-timers can run through against the suite of documentation no doubt already in existence which, if based on CEIOPS/EIOPA final advice and/or the Commission's Draft Level 2 measures, won't be miles away as it stands. On that premise, I've only listed elements which jump out for me.


GENERAL GOVERNANCE REQUIREMENTS

Guideline 3
  • Evidence should be collected of the AMSB "proactively" seeking information from committees/key functions
Guideline 5
  • No more detail than an expectation that the AMSB "appropriately implements" their key functions - in the explanatory text, it goes on to say that larger companies will be "expected" to fully separate Risk/Actuarial/Compliance/IA, with a series of measures expected to preserve functional independence if smaller companies choose to combine some.
Guideline 7
  • Expectation that both AMSB decisions, and how information generated from the Risk Management System (RMS) influences them, is "appropriately documented" - compulsion for Board Decision Logs?
Guideline 8
  • Regular System of Governance reviews appear to be expected, which are documented and reported back to the AMSB - the AMSB retains the right to choose who performs it 
Guideline 9 - All policies must include:
  • Goal of policy
  • Tasks to be performed and by whom (person or role, unlike for validation, where person/s was specified)
  • Associated processes and reporting procedures
  • Obligations of affected operational teams to inform control functions of "relevant facts" at all times
Guideline 10
  • Contingency plans are expected for areas which are "especially vulnerable" - this pushes outside of what one would consider a conventional contingency plan for operational emergencies.

FIT AND PROPER

Guideline 11
  • Must have a Fit and Proper persons policy
  • It must be equally applicable to both hired staff and outsourced functions

RISK MANAGEMENT

Guideline 15 - AMSB is "ultimately responsible" for:
  • RMS effectiveness
  • Setting Risk Appetite and Risk Tolerance Limits
  • Approving Risk Management strategies and policies
Guideline 16 - Risk Management Policy must cover at least
  • Risk categories used and measurement methods
  • How each category/grouping of risks is managed
  • Risk tolerance limits for all categories in line with Risk Appetite
  • Linkage of both SCR and ORSA to risk tolerance limits
  • Frequency and content of regular stress tests, and circumstances for additional testing
In addition, the associated guidelines touch on the risk categories within one's Risk Management Policy. There is an expectation for pretty much every category that procedure-level information is included in the policy documents themselves, as well as hard limits, which is unlikely to be the case as it stands.

Guideline 18 - Insurance Risk Policy
  • Expected to cover types of acceptable insurance risks, how premiums will cover claims/expenses, as well as how product design accounts for investment restrictions and formal risk mitigation techniques
Guideline 19 - Op Risk Policy
  • Expectation that Operation Risk Events will be formally identified/analysed/reported in insurers, and that a system for collecting and monitoring them should be in place.
  • Operational Risk Scenarios should be developed and used, based on failures of key persons/processes/systems and external events
Guideline 23 - Investment Risk Policy
  • Buzzphrase introduced of managing the level of "security, quality, liquidity, profitability and availability" of one's asset portfolio

OWN FUND REQUIREMENTS AND THE SYSTEM OF GOVERNANCE

Guideline 32
  • Concept of a "medium term capital management plan" introduced which covers; planned capital issuances, maturities and distribution policies - not sure how that works for mutuals, but I can see what they're fishing for

INTERNAL CONTROLS

Guideline 33
  • "All personnel [should be] aware of their role in the Internal Control system
  • The Internal Control system should be "commensurate to the risks arising from the activities and processed to be controlled" - this line should hopefully avoid overkill

INTERNAL AUDIT FUNCTION

Guideline 36
  • The Internal Audit policy should include the procedure for informing supervisors [of whistleblowing-level wrongdoing I guess]

ACTUARIAL FUNCTION

Guideline 44
  • "Material"deviations of Best Estimate Liabilities should be back-tested for by the Actuarial function, reported on, and remedial changes proposed
Guideline 46
  • The Actuarial function is expected to "contribute to" specifying the risk coverage in the internal model, as well as the dependency structure - this feels like areas where, even in larger insurers, the function probably already leads, so will they be asked to take a step back?

EIOPA preparatory guidelines - pre-application for Internal Models

Consultation on Pre-application for internal models guidance  (plus explanatory text)

As staggering as it is frightening, and perhaps indicative of the diversity of approaches currently on parade across the Union, the pre-application for IMs preparatory guidance is 60 pages, comprising of 72 guidelines, accompanied by a whopping 144 pages of explanatory text. This accompanies the existing 82 pages of L3 guidance on the matter released by then-CEIOPS in 2010! A sub-group of EIOPA's IRSG has been assigned to deal with the nitty gritty of this element of the preparatory guidelines.

On first read, this feels massively influenced by the UK's activities to date, and indeed anyone working in that space will recognise FSA pawprints all over the granular details contained within. This is fair I suppose - the InsuranceERM models map has the UK down for around 1/3rd of models currently in 'pre-application' across the continent.

Therefore bearing in mind the UK approach is already pretty well established, I have highlighted below areas which either diverge from what is currently being exercised on the ground, or which clarify (at least for me!) areas which were previously ripe for controversy or disproportionate/inconsistent application. Where it is common sense or continuez tout doit, I have ignored it.

Most importantly, I am reading it as a fait accompli - bearing in mind the short window of time between consultation end and period commencement, EIOPA's recent past on consultation responses (i.e. 'thanks but no thanks') and the UK's evident participation in the bulking of these guidelines, I don't see much room for lobbying swathes of this away, nor for the PRA to "explain" rather than "comply"!


GENERAL GUIDELINES
Guideline 3
  • As well as nature, scale and complexity, "design, scope and qualitative aspects" of the IM should be considered when allowing for proportionality 
Guideline 4
  • Any model changes pre-application look like they will be pored over by NCAs, including the associated change approval process 

MODEL CHANGES
Guideline 5 - Model Change Policy
  • Policy should, as well as SCR-related changes, include changes to: system of governance (around model change); compliance with Use Test requirements; appropriateness of technical specifications and changes in Risk Profile
Guideline 6
  • Approach to classifying "major" changes is expected to be objective
  • Must also take into account specificities of the company (so benchmarking percentage changes against your neighbours may not be that useful) 
Guideline 7
  • Aggregated change triggers must be considered, not just isolated changes
  • Offsetting positives and negatives won't be acceptable to avoid a "major change" trigger!
Guideline 8
  • Major/minor changes must be determined at Group and entity level

USE TEST
Guideline 9
  • "No complete and detailed list of specific [model] uses" will be supplied by NCAs.
Guideline 11
  • Granularity of the Risk Management System will need to match the IM in terms of categorisation
  • The "structure of decision making fora" will be assessed in ensuring the IM fits to the business - extraordinary!
  • Records expected to be available to show how IM outputs are designed
Guideline 12
  • Assessment of training, seminars, workshops, meetings and direct interviews "should be considered" in pre-application
Guideline 13
  • Will need to "ensure [IM] will be used" during pre-application, as opposed to "use it"
  • Expectation that, if other tools are used in decision making, IM is improved having assessed inconsistencies against said tools
Guideline 14
  • Evidence of prospective support and retrospective verification of decision making would be advisable for candidates
Guideline 15
  • Must document where model is not aligned to the decision ultimately made

ASSUMPTION SETTING/EXPERT JUDGEMENT
Guideline 19

  • "Materiality" in the context of assumptions will need to be both qualitatively and quantitatively assessed - should generate some healthy Risk/Actuarial function debate!
Guideline 20
  • A validated and documented process for assumption setting and expert judgement will be required
  • Sign-off on assumptions will need "sufficient seniority", up to and including AMSB
Guideline 21
  • A formal and documented feedback should be maintained between assumption setters and users
Guideline 22
  • On the transparency of assumption setting, point 1.64 here effectively asks for an Assumptions Register, as well as dictating what it expects to see in it.
Guideline 23
  • Process mapping of some kind expected for the validation of assumption setting
  • Independent assumption review is also expected - doesn't dictate whether this should be internal/external, but it will keep someone in clover no doubt.

METHODOLOGICAL CONSISTENCY
Guideline 26
  • Methodological consistency to be validated

P&L ATTRIBUTION
Guideline 37
  • Point 1.105 seems to confirm P&L attribution by risk driver is required
Guideline 39
  • P&L attribution must be used at least annually in the decision making process
Guideline 40
  • P&L attribution to be used in the validation process (specifically, old ones to be compared against  experience

VALIDATION
Guideline 41 - Validation Policy to contain at least
  • Process, methods and tools, and their purposes
  • Frequency of validation for each part of the IM, and triggers for ad-hoc validation
  • Persons (not roles) responsible for each task
  • Procedure to be followed where reliability of IM is questioned, and ensuing decision making process
Guideline 42
  • Shies away from touching Internal Model scope when talking of validation scope - great move!
Guideline 43
  • Evidence of sensitivity testing expected when determining materiality
Guideline 44
  • Must document known limitations of validation process, as well as circumstances where the process falls over
  • May even be asked to quantify the degree of uncertainty!
Guideline 45
  • A documented escalation path would be advised
Guideline 46
  • Risk Management function will be pressured, as the function with overall responsibility, to ensure all tasks are completed (if not directly performing them) - new skill set?
Guideline 47
  • Evidence of how the RM function ensures that the validation process remains independent of IM design and ops should be collected/enhanced
Guideline 49
  • A process will be expected to ensure the choice of validation tools used considers; complexity, nature, independence and knowledge of participants - feel this could be tricky for the smaller IMAP guys without leading to additional spend on consultants
Guideline 50
  • Must be able to document the appropriateness of the validation tools used accounting for; materiality of IM part, granularity of the data being tested, purpose of the task and the expected outcome

DOCUMENTATION
Guideline 53
  • Expectation of a "...clear referencing system [for IM documentation] which should be used in a documentation inventory"
Guideline 55
  • An overall summary of IM shortcomings, "consolidated into a single document" will be expected
  • This needs to cover at least; Risks not modelled, limitations in modelling, sources of uncertainty in results, data deficiencies, external models/data, IT limitations and governance limitations.
Guideline 56
  • Potential suggestion that there should be more than one level of IM documentation to suit other audiences/uses - IM for Dummies anyone?
Guideline 57
  • End-to-end User Manual expected which an Independent Knowledgeable Third Party could operate
Guideline 58
  • Stress that a single document containing all model outputs (as Use Test evidence) is not required - acceptable as single docs

EXTERNAL MODELS AND DATA
Guideline 60
  • Expectation that external data sets will be sense-checked against "other relevant sources"
Guideline 61
  • Understanding of external models must extend to technical and operational aspects, as well as assumptions
Guideline 64
  • "Material" assumptions of external models must be validated
  • In point 1.163, any potential for cherry-picking features/options of external models is constrained



Wednesday, 27 March 2013

EIOPA consultation on "Solvency II Preparation Guidelines" - Wham!

In between Mickey Mouse cartoons today, my young lad said "EIOPA just don't publish enough consultations about Solvency II, I hope we see some more soon" - well wait no further son, this year's motherload has just arrived!

EIOPA Guidelines - supervisors have
been 'hanging on like a yo-yo'
What was mooted back in December as EIOPA's interim measures, intended to make sure that impatient  individual national supervisors didn't 'plan on going solo' have been released today for public consumption and comments, covering the 4 areas "fundamental to ensure effective preparation for Solvency II".

The consultation is open until June 19th, but the guidelines once finalised will apply from Jan 1st 2014.

EIOPA will apply them proportionally to the national supervisors, who in turn are asked to "...regard the burden on small and medium sized undertakings" when incorporating these guidelines into national regulatory landscape. May be the first acknowledgement of disproportionately burdening SMEs I have seen from EIOPA!

Those 4 areas are:
  1. System of Governance (L2 final advice here)
  2. Forward-looking assessment of Risk/ORSA (issues paper here)
  3. Submission of information to national authorities (L2 advice here)
  4. Pre-application for internal models (L3 guidance here)
I'll pick these off as separate posts and link them back to this page, so sers toi in the meantime and happy reading!

InsuranceERM round table on Solvency II and Capital Management

Nice freebie from the InsuranceERM guys, covering a CRO/ERM Head roundtable touching on economic capital, internal models and Solvency II - the first of this double header is here. With representation from from all sides and sizes of the insurance industry spectrum, the views tabled should be useful for most practitioners in this space, even if some of it is not exactly new news.

They are relatively benign on controversial areas such as industry cost, and even positive when talking of Solvency II having provided an incentive to improve both risk and model governance in the here-and-now, regardless of the necessity from a pure compliance perspective.

Between the two, the following noteworthy views were tabled;

On Solvency II

  • "...has to be considered now if, not necessarily when"
  • "...from a non-life risk and capital perspective, Solvency II just does not work" - citing reserve risk specifically as inherently flawed 
  • The UK's ICA+ regime "...pushes [Solvency II] back towards a more sensible view of capital"
On Internal Models
  • "The main issue with the models is spurious accuracy and detail masking big assumptions, which is possibly a systemic risk"
  • Regulators in some European countries think internal models are "unnecessarily complicated"
  • In response to the suggestion that internal modellers could be "gaming the system" to reduce capital requirements regardless of risk profile, Aviva's ERM head noted that the FSA have identified through their own research that the ICA regime appeared to have done just that back in 2004
  • It is "...inevitable that [the Bank of England wearing their PRA hat] is going to take a far more sceptical view of internal models", particularly where Internal Model SCR is lower than Standard Formula SCR
  • On Use Test, "...potentially 3 or 4 years before the model is truly bedded in"
On Ratings Agencies and their capital requirements to maintain target ratings
  • "...many people, especially in Bermuda, see ratings agencies as de facto regulators"
  • "...may take internal models less seriously in the short term" off the back of Solvency II
  • Ratings agencies capital requirements are "the worst common denominator" alongside SF SCR and IM SCR
I've personally been relatively well shielded from the extent of the discontent on the non-life side, but judging by the confidence intervals used by high profile insurers as their EC targets (frequently observed at 99.9-something/A or AA rating space), it's no surprise that ratings agency requirements are in many cases paramount - that business could potentially be dragging three or four capital measures to their respective Boards for the next 3 years (agency capital, IM SCR, ICA and SF SCR) is a grim prospect.

Perhaps of more immediate concern is the view that the FSA/PRA have the potential to be more cantankerous around internal models once they move into their new office - something to look forward to in 2013?

Thursday, 14 March 2013

FSA and cost of Solvency II in the UK - two tunnels or half a tunnel?

Andrew Bailey, incoming head of the PRA in the UK, was widely quoted yesterday as saying that the spiralling costs of Solvency II could ultimately cost "twice as much" as London's new £15bn choo-choo tunnel Crossrail. This was at a parliamentary select committee, which for non-UK readers is where second tier politicians jump on the latest bandwagons, so that fact that Solvency II is getting some air-time is telling in itself.

Not entirely certain what expenses are included in this £30bn mega-bill, but the number is surely as inconceivable as a 2014 start date unless we add FSA costs, industry costs and slap on some arbitrary figure for "additional capital the industry will probably need to hold" - which is of course what was contained in the Cost Benefit Analysis commissioned by the FSA published back in 2011. With much of that based on QIS5 standard formula results (but at least in the same ball park as £30bn), I guess we can swallow £30bn, albeit with a pint, rather than a pinch, of salt.

"But wait a second" keen readers of the FT cry, "this time last month a prominent CEO said the cost was supposed to be HALF that of Crossrail,". Has someone in the fact sheet-preparing department at the Wharf got their wires more crossed that a breakdancing electrician, and sold their boss a dud here? Has one of the journos at the Telegraph or FT misquoted someone? Either way, there's probably a salient lesson in there somewhere around looking before you leap, it just remains to be seen who's left with the proverbial, errr, mucky shoes.

Incidentally, the full text from a separate questionnaire which the UK Parliament's Treasury Select Committee asked Mr Bailey to respond to is available here - this is separate to the interrogation transcript where the "twice as much" quote was obtained from, but contains some insight into where prudential regulation is going as of next month when the PRA take the reigns, including some good news on the regulatory levy front;

"For the next year, we intend to levy just £0.1mn [for Solvency II]. The difference [from last year's £15m] reflects cut backs that we have applied to Solvency 2 preparation costs. Although it is hard to be sure of the final cost of Solvency 2 preparations given the uncertainty on timing and substance, I expect the overall cost to be considerably lower than previously estimated. This will be a saving for insurers."


However, when one reads that, in his own words, the new head of Prudential regulation in the UK is "...by comparison new to insurance, but [he takes] it very seriously", you truly hope if the £30bn faux pas is attributable to him, that it can be put right - with all the Solvency II scaremongering and doom-mongering, we could probably use a little realism-mongering...






Wednesday, 13 March 2013

AKG - Solvency II perspectives from the financial advisory industry

In the absence of materials pointed towards the sector, AKG have released a Solvency II guide for financial advisers (sign-up required, but worth it), which provides a refreshing angle change from the usual bureaucrats vs lobbyists vs politicians chatter flooding the trade presses.

Solvency II and RDR -
"mess with me, you mess
with my whole family"
While Solvency II was clearly De Vito to RDR's Schwarzenegger over the last year and a half for the financial advisory industry (indeed all bar one of those surveyed by AKG's pollsters had been concentrating "exclusively" on RDR), there was at least some familiarity with the impact on product availability from the current impasse - Protection and Annuity rates, With Profits availability and Guarantee costs are all on the industry's radar.

While there was a couple of faux pas in the document (the official timeline is certainly not "established and managed by EIOPA", and as the world and her husband will tell you, the ORSA is not an annual report!), the document helps understand the concerns and needs of the distribution world at this uncertain time. I picked out the following;

  • That CROs will be more concerned about risks posed by external distributors and advisors in future
  • That advisers will likewise need assurance on product supplier risks, and that provider and product ratings from external sources "...will be crucial components in gaining this reassurance"
  • That the alignment of capital and risk "...will undoubtedly drive capital light products in future"
  • That the mainstream press hasn't yet "gone big" on Solvency II, but that advisers may get caught out when they do
  • That the advisory industry wants "...a guide [to Solvency II] to explain in an easy-to-understand, jargon-free manner" - over to you FCA!
  • There are concerns around the quantum and familiarity of products/providers once Solvency II goes live and we see new market entrants/consolidation
They conclude that "advisers should not panic about Solvency II and its implications". That has a whiff of Chamberlain about it to say the least, but the "panic" would be about convincing punters to pay more for guarantees or share the risks in insurance products in the near future, as opposed to the solvency adequacy of the providers themselves.

Friday, 22 February 2013

Adams speech to the Economist Insurance Summit - lessons from financial crisis

Some particularly useful context setting from Julian Adams last week for anyone in the Internal Model game, with this speech to the Economist Insurance Summit around what lessons could be learned by insurance supervisors from the financial crisis.

While he amusingly interchanges between "financial crisis" and "banking crisis" to emphasise that it wasn't our fault, and drops in the now obligatory reference to the importance of insurers as long-term investors, echoing the Commission's pleas from late last year, the majority of the speech focuses on why models go wrong (not the name of a ropey catwalk reality tv show...)

Insight on where the FSA thought firms were going awry in the Solvency II modelling preparations was delivered to the industry in the middle of last year, but I found this speech helpful in the context of proportionality i.e. what elements of economic capital modelling are worth spending extra time on theorising, documenting, debating and minuting for IMAP candidates. I saw the following comments as highlights;

Reasons for internal models in the banking industry being exposed;

  • "...rested on assumptions which turned out not to hold when bad times came"
  • "...review period" selected when parameterising
  • "...insufficient rigour and independence from the front end of the business" when parameterising
  • "...management attention too often focused on those parameters considered too conservative at the expense of those that were insufficiently prudent"
  • "...destabilising feedback loops" where underestimation of risk (due to data selection) plus use of the model leads to a vicious cycle of unacknowledged over-accumulation of risk
  • "...flawed technical assumptions" in tail-end probability estimation where data is drawn from "normal" times
Lessons for Solvency II
  • "Data [should be] sufficiently robust"
  • Assumptions should be "appropriately conservative"
  • "[Supervisors] can be helped...by the much greater use of imaginative tests of resilience to deeply stressed scenarios"
  • "...paucity of relevant historical data for the calibration of tail dependencies between risks"
  • That "...the limitations [of capturing tail dependencies] are recognised, and conservatism built in to the calibrations"
  • That "...correlations in the tail are likely to be assymetric in nature" for insurers
  • That "...the adoption of quantitative techniques...will not change the nature of the risk itself"
  • That supervisors "...must not blindly accept the outputs of these models"
Appreciating some of this is hardly new news, any increased documentation and rigour in the areas highlighted will no doubt be well received down at the Wharf.

Friday, 15 February 2013

Financial Stability Board - Thematic review and recommendation on risk governance

The Financial Stability Board (FSB) have been sticky-beaking around systematically important financial institutions (SIFIs) with a relative unchecked remit ever since the financial crisis first reared its head. This week they have emerged with a very significant document for Risk practitioners across the globe, with a thematic review of Risk Governance (press release also available here). The participants were 36 banking and broker/dealer institutions of interest, as well as major supervisory bodies and NGOs.

On the basis that there isn't a single accepted global standard on the matter, the thematic review compares prevailing practices against an amalgamation of content from exising standards from the IAIS, OECD and other bodies. Of major interest to risk practitioners is the document's focus on areas which the IRM have covered recently, namely risk appetite/tolerance/limts/capacity and risk culture.

Bearing in mind the great and good from the prudential regulatory world are active participants in the FSB, the likelihood of their findings emerging in the regulatory principles of tomorrow are pretty high. Of course this research has been based on Non-Insurance SIFIs, and so insurers large and small who have been endeavouring to meet Solvency II Pillar II requirements will find themselves in a decent spot already.

On that basis, I noted the following;

General recommendations to supervisory bodies (p4)
  1. Formal requirements on the independence and skillsets of Boards
  2. Hold Boards directly accountable for risk governance, and whether or not their existing suite of risk MI is sufficient
  3. Formally elevate the stature, authority and independence of the CRO role
  4. Require an independent assessment of the effectiveness of the risk governance framework to be performed on an annual basis (a list of what Internal Audit would generally review in this context follows on page 24)
  5. Engage "more frequently" with Boards and management to assess risk culture
Sound practices list p30-34 - highlighted below are elements which may be new to the UK in particular, were they to be introduced
  • Boards - annual reviews of member qualifications, skills and time commitments; meet quarterly with regulators; "effectively inculcate" an appropriate risk culture
  • Risk Committee - annual approval of risk management policies
  • Risk Management function - CRO to have direct reporting lines to Board/Risk Committee as well as CEO; public disclosure of CRO firing/hiring; be "actively involved" in strategic decision making processes; meet quarterly with supervisors; stress testing "on demand" at the behest of the business
Risk culture and risk governance supervisory assessment
  • Notes that supervisors need to strengthen their ability to assess a firm's risk governance "...and more specifically its risk culture"
  • "More work is needed" on regulatory assessment of risk appetite frameworks
  • "Risk culture plays a critical role in ensuring effective risk governance practices through changing environments"
  • FSB have a working group exploring the potential for formal risk culture assessments, who are  reporting in September 2013
Risk management functions and CROs
  • Acknowledges that there have been "[raised] supervisory expectations for the risk management function" since the financial crisis
  • Highlights that "most firms note that the CRO has a direct reporting line to the CEO", though "access to the Board" apparently remains more of an expression than a vivid reality
  • "Good progress" has been made on enhancing the stature, authority, and independence of the CRO position
  • Rather non-descript comment that "the Chief Risk Officer and the risk management function are responsible for the firm's risk management across the entire organisation" - responsible for what element, not conduct surely?
Risk appetite/tolerance/limts/capacity
  • Acknowledge a "lack of common terminology for risk appetite, risk profile and risk capacity...within firms, across firms and across national authorities"
  • Definitions of appetite and capacity used by FSB largely line up with IRM's definitions (though the IRM use 'tolerance' rather than 'capacity')
  • "Key features of a Risk Appetite Framework" are listed on p22 - however even those firms considered best in breed commented that there are ongoing "operationalising" problems with RAF rollout
  • Suggest that breaches of 'risk limits' should lead to reductions in exposures (piii) - not sure why the alternative of increasing appetite is not acknowledged



Monday, 4 February 2013

FSA and ICA+ - making the best of a bad hand...

The FSA released the letter we've all been waiting for at the end of last week regarding their plans for  allowing UK firms to use their intended Solvency II-ready internal models to calculate their compulsory Individual Capital Assessments between now and the go-live date of Solvency II (don't laugh, it's still possible that it might go live ;-) )

I suspect a mix of suitability, financial necessity and pragmatism has led the regulator to pursue a relatively relaxed take on ICA+ , for example;
  • It is "not a condition for IMAP review or approval"
  • It "does not require Solvency II tests and standards [for internal model approval] to be met"
  • Firms will confirm the scope of material which needs to be reviewed for ICA+ assessment, rather than the FSA themselves
  • They also confirm that it is "not [their] intention" to bring in Solvency II reporting requirements "...any sooner than required by EIOPA"
That said, while the FSA try to thin out the field by noting that ICA+ is "most appropriate" for firms who are both in IMAP and due for a business-as-usual ICA review in the next two years, it would make sense for anyone in IMAP to pursue ICA+, more than anything because of the interminable delays in Europe might put a firm outside of ICA+ at a competitive disadvantage on the capital front.

The onus therefore appears to be on the industry to quantify and explain the differences between the inputs, processes and outputs of their ICA models and Solvency II models, as well as demonstrate how their ORSA processes address the existing requirements of INSPRU, specifically targeting INSPRU 7. There is also a sneaky request for a self-assessment of progress towards achieving compliance with the Solvency II tests and standards for internal model approval.

From a practitioner's perspective, I had a particularly large chortle at the requirement for all materials being used in the ICA+ assessment to have been approved by the firm's Board - I'm sure they are looking forward to another two years of swollen board packs...

There is more information to follow from the FSA in Q2 of this year, presumably on the basis that the  LTG assessment activity they are on the hook for will have concluded, and more focus can be shifted to this pioneering work. Congratulations to them for not overegging this particular pudding, on paper at least.

Tuesday, 22 January 2013

EIOPA, Parliament, IRSG and LTGs - momentum sustained?

I guess I should start with a Blein Vie Noa to one and all - after a relaxing few weeks in France I am now back on the beautiful Isle of Man sizing up opportunities for 2013 and beyond.

I didn't expect I would be missing much over the festive period and, other than the FSA sacking-off their proposed January IMAP industry briefing in favour of a (yet to be delivered) letter, things did go quiet. Freshfields kindly filled some airtime by pulling together another of their "where are we now" summaries that remain excellent (and free) materials that I would recommend punting on to your non-executive directors.

Luckily the noisemakers got back in the game as soon as school restarted, focused largely on the content of EIOPA's Insurance and Reinsurance Stakeholder Group's minutes. This meeting was held in October, so in terms of new news, it is right up there with "Earth is not flat". That said, we don't all have access to the inside track before publication of such materials, so it was interesting to pick through the doc for steers. I noted the following;
  • Continuing problems with terms of reference for the LTG assessment (indeed the LTG sub-group note on p7 that there isn't even a EU-consistent definition for LTG!) - still looking like it will impact on the designated Plenary session for Omnibus II due to a combination of last minute delivery of the technical specifications to the industry itself as well as the output report to the Parliament, who themselves were reported today as being less than impressed with the final TORs. The potential number of scenarios in the assessment also clearly remains a sore point.
  • Acknowledgement that "Autumn 2013" is now "best case scenario" for Omnibus II adoption, though, according to van Hulle at the last EIOPC meeting, the Commission and Parliament remain almost diametrically opposed on what should materialise at Level 1 and Level 2 (full minutes from EIOPC here)
  • Confirms the ex-ante approach is favoured by Parliament and Commission (significance covered by Gideon here), and that Parliament have no wish to commit to an implementation timescale.
  • The Council members are being "heavily lobbied", fostering implementation uncertainty.
  • Attending stakeholders supported a definitive 2016 date.
  • The IRSG's Governance sub-group flag up consistency issues around Fit and Proper regs as well as the "AMSB" term that I'm sure we have all had practical issues with over the last 2 years!
  • Proportionality remains a "main concern" for mutuals, as well as smaller insurers - despite having a designated sub-group, any substantive guidance on applying the proportionality principle looks a distant prospect at best.
  • Astonishingly, minutes from May 2012 could not be approved due to EIOPA's "workload" - small instance of an institutional tardiness problem?
Whether or not the industry is losing it's appetite for the Solvency II banquet, when you check out EIOPA's workplans for the next couple of years, at least one body will be filling its face!

Another interesting piece came out in the last week, when InsuranceERM pushed out the findings of a Solvency II roundtable (no sub required), bringing in a few UK-based CROs and the like, ostensibly to chew over the loss of momentum in the project. A few noteworthy bits jumped out;
  • Solvency II balance sheet appears to be off the agenda for ICA+, for both regulator and industry
  • Perception that, with the transition of regulatory "ownership" to the Bank of England, there is a decreased likelihood that the industry will be able to use Solvency II as a capital release mechanism
  • A suggestion that the FSA was more minded towards EIOPA's opinions than the industry's during IMAP 1.0, something which has seemingly reversed with the advent of ICA+
One certainly hopes that the UK industry and regulator can make a decent fist of this indeterminate transition period without having to break the bank...

Tuesday, 6 November 2012

Solvency II compliance ahead of "Go-Live" date - over to you, regulators

Judging by the rather resigned tones around the achievability of Solvency II "go-live" by 2014 (CBoI recently joining the FSA) and 2015 (here and here), there appears to be a growing swell of support for implementing some of the less wobbly bits sooner rather than later.

While it's unlikely that there will be more spurious adoptions than a Madonna safari trip, it is interesting to see what we can point at to-date;

UK - ICA+ regime, which lends itself, subject to the quality of the ICA-to-SCR reconciliation, to implementation from as early as year-end 2013, though one suspects 2014 is a safer bet.

Germany - Cheeky bit of Pillar II, judging by Bafin's (indirectly quoted) comments on Reuters today, although what "some risk controls" actually means is another thing!

Ireland - via the sterling work on PRISM, fitness and probity and corporate governance, it's hard to argue where they are not already Pillar II Solvency II-equivalent (at least in word, if not in deed!)

France - reference to compulsory submissions to the ACP in XBRL by Q1 2014 at the bottom of this doc, apparently confirmed at a recent soiree.

So we could very well have 3 Pillar coverage by 2014, just randomly spread out over multiple countries...

Any more for any more?

Monday, 5 November 2012

Institute of Risk Management on Risk Culture - ABCs, Double S's and mercenaries

So I figured it might be worth seeing how the other half were living by reading something that didn't start with "Solvency II" and end with "indefinite delay"!

The IRM are endeavouring to produce white papers on some of the less tangible elements of a risk practitioner's day job, which one would hope contribute to more consistency in practitioner approaches and ultimately more credence in the concept of risk professionalism (indeed, their work around defending pure risk professionalism as a career, as opposed to loading risk functions with cross-over actuaries, was very much required in early 2011).

Having scrutinised their work on Risk Appetite in 2011 (lined up against some of the competing influencing bodies here), I figured it was only fair to take a punt at their new release on Risk Culture. It's fair to say that for politicians, regulators and fingers-caught-in-the-till employees, 'culture' or 'risk culture' appears to be a handy soundbite when explaining why they didn't fulfil their obligations to their stakeholders. The IRM are joined by Protiviti in producing this guidance, Protiviti themselves having delivered a survey based on UK insurers on this very topic in the summer, which was not shy about highlighting how little some organisations think of their Risk functions.

I've always felt that the 'culture' comfort blanket was one weasel word too many i.e. "there was a culture of greed" = "they were greedy ********", or "there was a culture of fear" = "scared of the gaffer", so I approached this doc with a pretty open mind, but tempered with a Manxman's natural scepticism. I found the following (sequentially);

What does a good risk culture look like?
  • Appears to have used examples of what a "bad" risk culture has recently led to, then flipped that on its head! Would have thought a clean slate approach is better for white papers, rather than reacting to zeitgeist incidents
  • Fair list of 10 criteria for anyone in the risk culture assessment space, though will always be a nightmare to codify/quantify.
  • The appearance of the dreaded "tone from the top" suggestion, which makes an appearance in the FRC's (p4), the FSA's and EIOPA's world (p10) - bearing in mind that the "top" is normally the problem when it comes to organisational catastrophe (Lehman, Northern Rock) as opposed to fat tail op risk loss events UBS/Credit Agricole/JP Morgan), I would be more inclined to call it "tone at the top".
What does risk culture mean?
  • I like the IRM's take on culture being "the repeated behaviour" of a group - very convincing definition in comparison to say the FSA in SYSC (p12), though the rest of the ABC approach is a tad woolly.
  • "Virtuous" versus "vicious" cycle sits nicely alongside this image of repetition, but nothing as such around how best to break a vicious one, either as a NED or a Head of Risk - perhaps that has been saved for the more extensive and expensive practitioner's guide!
Why is risk culture important?
  • Don't agree that risk culture affects the capability to take strategic decisions, rather it enhances or impairs the quality of those decisions. Immediately makes me think of ORSA, and how "playing" at it or "doing" it doesn't prevent strategic decisions from being made.
  • Also don't agree that "at worst" an inappropriate risk culture could lead to "serious reputational and financial damage" - I'm sure stockholders at Bear Stearns may say it can be a bit graver than that!
  • Nice emphasis on how risk culture can both stifle necessary risk-seeking behaviour at one extreme (smartly citing Eastman Kodak as a "too slow" corporate failure), as well as the more obvious "prison rules" which emerge from uncontrolled risk taking.
What can the board do?
  • Should they really ask themselves "what is the current risk culture"? If so, is that at a chinwag-type round table, or via some kind of evaluation survey issued by Risk function? Instinctively sounds like the kind of thing that would be squeezed into a Q1/Q3 board meeting at the point of a gun, which is as cynical as it is sad!
Understanding risk culture in an organisation
  • The meatier (i.e. costs money!) practitioner guide apparently contains some diagnostic tools to effectively indicate and track culture within an organisation. The flash we are given here reminds me of the psychometric testing for "what makes a great Risk Manager" that I looked at last year, but feels ultimately very high-end.
  • The "Double S" model is an intriguing addition to the mix, specifically the comment that low scores on either rating "create a barrier to the effective management of risk". Would love to see more of the research cited, as I've found that the odd mercenary firm can work wonders...
Changing a risk culture
  • Can a risk culture effectively be changed top-down without a change in personnel? Can't imagine an existing CEO being prepared to antagonise his board/exec team by declaring them culturally bankrupt unless he had carte blanche to do so, which is normally the case with regime change. I'm more inclined to think a decent CEO, partnered with Risk, could do it by stealth, rather than with a pricey change management programme which would inevitably rock a few boats.
  • "Risk culture is not a precise science" - does that make it an art?
10 questions a Board should ask itself
  • I would probably make it 11 questions, and frame the first one "Do we genuinely care about how culture impacts on our decision making, or only insofar as laws and regulations insist upon it?". If a Risk practitioner gets the answer to that directly from the Board/Exec, the other questions can be catered for with proportional vigour.
Thought provoking in the right ways, I guess it does what a good white-paper should - thanks to all concerned at the Institute.

Tuesday, 30 October 2012

Aon Benfield's CRO guide to Solvency II - in case you're not ready yet...

For all those CROs who are about to get left holding the Solvency II baby three years early by their over-enthusiastic executive colleagues, Aon Benfield pulled together a CRO guide to Solvency II which aims to take the journey "from complexity to best practice". 10 out of 10 for ambition...

It leans heavily towards General Insurers/Reinsurers (indeed it reads like a reinsurance sales brochure in many parts!), but nevertheless contains a suite of very useful content for anyone in the Risk space, as well as attempting to shatter a few myths. I took the following from it;
  • Steady early bits on capital planning and common questions a CRO should be posing in that space
  • On page 5, an excellent table comparing standard formula against internal modelling by risk driver, in particular emphasising why internal modelling may be more appropriate, rather than how much capital it could shave off. Being able to explain to the national regulator why one has neglected to apply the enhancements that internal modelling introduces to the accuracy of one's quantitative risk profile would be a smart thing for CROs to practice!
  • The undo some of that noble work by suggesting part of any IM feasibility study should include estimating the capital benefits!
  • Nice examples at the top of p6 of what mixes of business lend themselves to benefitting from an IM approach
  • Highlighting that domicile of firm continues to dictate feasibility of IMs for smaller firms (i.e some countries can't staff it!).
  • Recommend reviewing SF SCR factoring in the draft L2 asap. As was clear from the E&Y research I covered yesterday, many firms across the EU consider themselves to be advanced in the Pillar 1 space while disregarding draft L2. They highlight the Swiss experience as one where they struggled to authorise models for "Day 1" approval, and the Aon crowd propose some meaningful contingencies on p8
  • Useful analysis of capital drivers and optimisation strategies (p9-10)
  • Section on expert judgement validation (p15), touching on the Level 3 expectations, and in particular how a (non-Actuarial) CRO may struggle to adequately challenge certain judgement calls, such as selected data series or correlation matrices, without specialist advice. Very hard for smaller firms to obtain that, as most of their actuarial function will have probably contributed to the judgement!
  • Note that one of the key challenges for documenting the IM is getting the best-placed people (who are normally swimming in BAU) to pick up a pen and write!
  • Neat section on ORSA (p27-29), emphasising that SF firms with complex risk profiles may find they struggle to justify that approach when concluding the assessment. They go on to suggest that early experiences of ORSA Report/process documentation submissions have left CROs feeling that the regulatory approach is (Level 3?) tickbox as to content expectations.
  • Key challenges for CRO in briefing and educating senior colleagues for Solvency II-readiness are all fair, in particular the gap that could emerge if a CRO is not also an executive member.
  • The section on Risk Appetite is particularly useful for smaller non-IMAP firms, who may struggle to quantify their target measures - whether using Standard Deviations/volatility measures as suggested is a touch too simple depends on the business I guess.
  • The Pillar 3 section hits on the same issues I (and the FSA!)have picked up on earlier, such as end-user computing, inability to transition to BAU, data ownership issues etc.
I did take exception to a couple of bits in here, where the industry or indeed common sense appears to suggest otherwise;
  • The "fallacy" outlined on p5 that an IM enables a firm to hold less capital than an SF equivalent. The research I pointed to yesterday (p20) suggests across the EU that modellers are already "making it rain" with their capital savings
  • That the IM alternative for Op Risk is based on ORIC and individual loss event info. I'd certainly seen Milliman suggest that this approach is as flimsy as the SF approach, recommending options such as Bayesian networks to generate IM inputs.
  • Concerns that evidencing senior management model "use" could create a "value-destroying documentation burden". Is that what we call "minutes" these days!
  • Comments around the documentation delivery for the Internal Model Application Process becoming detached from the underlying processes referenced in those docs influencing BAU value-adding activity are perfectly valid, but no real solution is proposed.
  • The operation of the Model Change Policy features heavily (p19-21), as anyone in that space would expect. Again. little offered in the way of solutions, but I certainly would have expected more discussion on the "scope" of the model, which in my experience is a solid, liquid or gas depending on which control function you speak to, and I'm sure the FSA would agree!
PS All the best to you guys on the US East Coast, let's hope the worst has passed...

Monday, 22 October 2012

FSA's Adams on Solvency II delay, IMAP and ICA - how long do you want lads?

It would appear that stabs in the dark on the Solvency II implementation date by senior insurance industry officials are like British buses - after the omerta-like silence of September, no fewer than three bigwigs have piped up in the last few days. First Sr. Bernadino decided to do his briefing via a Stateside publication, settling on 2016 as most probable, followed by Sr Montalvo who concurred (along with a great joke about his missus!).

While it didn't take a handsome Archaeology graduate to know that 2014 was ash, what the industry likes more than anything is cold, hard confirmation from their friendly national supervisor...

...which came today! Julian Adams gave a speech this morning ostensibly about the practical side of implementing the PRA's new approach after they get divorced from their FCA counterparts next year. Worth bulleting the big messages on IMAP;
  • Current timetable "completely unrealistic" after Plenary postponement confirmed last week
  • 2015 "...likely to prove very challenging"
  • FSA will agree a revised landing slot with IMAP participants (presumably just those who have yet to submit?), UP TO A MAXIMUM OF END DECEMBER 2015.
  • Will change this to match up with what comes out of Brussels if the two are divergent
  • For ICAS, "we will have to live with the current regime for longer than any of us expected"
  • The previously stated "aspiration" of potentially replacing ICA with internal model SCR will be formalised into a two step process. First, reconcile ICA with IM SCR (the easy bit!), then once the FSA are sufficiently happy, just produce IM SCR.
  • Retain discretion to apply ICG throughout the interim period
  • Benefits of this approach will therefore include much meatier pre-application evidence of use.
Hard to know where to go with this. Great news for anyone who remains on target for their original landing slots, as there is potentially some early-adopter capital benefits if they can abandon ICA. That said, the recent E&Y industry survey (which I will look at separately) suggested the Brits are mostly in a good spot for IMAP, so does extending the window negatively impact on the work already delivered? Certainly opens up a rather pricey Pandora's box around Validation activity which I'm sure many firms would have been delighted to have paid for one-time-only!

All in all, these public declarations will be welcomed by everyone who isn't writing a cheque for next year's IMAP activity...

Tuesday, 9 October 2012

Omnibus II and the inevitable delay - why it's not so clear cut

Fantastic work over on the Solvency II Wire from Gideon on the meat and potatoes inside the eternally-baking Omnibus II pie, illustrating why the trialogue parties haven't just rolled over and declared 2015 as the new 2014.

While it would appear that the lobbying arms at Insurance Europe, AMICE, GCAE etc haven't piped up on industry preference yet, it looks like we have two deeply unpleasant alternatives to look forward to; hard launching a year late (i.e Omnibus II would only get signed off after the recently requested LTG consultation but 2015 would be the definitive "go-live"), or soft launching with 2 years parallel running (i.e. Omnibus II can go through before the LTG consult is finished, but with the sword of Damocles hanging over its contibution to the regulations until 2016).

My guess would be that there is little appetite in the firms for parallel running Solvency I/Solvency II to 2016 based on the administrative burdens this would currently place on the UK in particular through the current ICA process. A 'hard' 2015 and some more effective leadership in Brussels would be welcome relief to Solvency II Programmes from a planning perspective, though the knock-on effect on the model approval process and other scheduled supervisory work is yet to be seen.

Oddly, the EIOP-ians of the world pushed out the 2013 Work Programme this week which of course skips over any of the practicalities around such a delay - so having "already achieved a great deal" in Solvency II prep, they will "finalise the [53] standards and guidelines" currently required of them, set up an "internal model support expert unit", and "finalise the preparation of the [supervisory] Colleges" - and all of this while Rome burns!

It is a perverse situation when a subject as politically divisive as capital requirements for long term guarantees across the union is not as complex as trying to get three well-briefed parties around a table to agree on an implementation date. At a time when the Commission wants an inflation-busting funding rise (which Parliament have 'ole'd through) and EIOPA have grown in headcount and cost by 50% y-o-y, the alarming regularity with which national self-interest and horse-trading has derailed a project of such significance makes me long for the jingoistic certainty of the Corn Laws - I'm guessing that's not a good thing...

Monday, 1 October 2012

FSA on ongoing appropriateness of internal models (which aren't appropriate yet...)

Ploughing on regardless like a John Deere with a lobotomised driver, the FSA continue to work on their plans for ongoing appropriateness of internal models after Solvency II goes live. Having put their initial ideas out for feedback in June, they have this week provided an update on responses received, which hinted at a few things;
  • IMAP Participant apathy - 10 responses (attrition rate is potentially rising these days, but we must still have 60-odd with skin in the IMAP game, so that feels pretty lousy)
  • That inappropriateness would only be to a firm's benefit, hence the supervisory response to its detection "in all but exceptional cases" will be a capital add-on (PS if 'inappropriateness' is a word, I'll mange my chapeau, but I'll stick with it for now).
  • That the early warning indicators planned will form part of the FSA's BAU Supervisory Review Process alongside "in particular" model validation results - any danger the early warning indicators may therefore be used informally in the pre-application work? They do go on to stress in the letter that they "do not intend" to use early warning indicators in the initial approval process, but bearing in mind no-one showed up for round 2 of the three-way today, we're all eating at a pretty moveable feast right now!
The link between early warning indicators and validation results is probably the big message in here - could verging on breaching the % tolerance, plus a negative validation report, lead to a capital add-on in 2014/2015/20XX?