Showing posts with label risk function. Show all posts
Showing posts with label risk function. Show all posts

Thursday, 19 September 2013

Financial Reporting Council - documenting 'principal risks' in Strategic Reports

I had recently spotted that the UK's Financial Reporting Council had issued draft guidance on the compilation of the Strategic Report for listed entities. This segment of a company's Annual Report and Accounts (currently called the 'Business Review') has been a rather ubiquitous and clunky affair regardless of industry, delivering little information to prospective and existing shareholders about how the company's risk profile, appetite, preferences etc. are catered for when executing its strategy.

Strategic reporting for UK companies 
- elimination of flannel?
Insurers have been prominent in efforts to improve this, though driven more by the need to pacify the FSA/PRA than by Parliament - see "risk appetite" break out from its box in  Aviva's AR&A between 2007 and 2012 for example - but the fact that a substantial piece of statutory reporting generally in the hands of executive management can potentially stray from the lexicon and structure of their increasingly professionalised Control Functions (and for banks and insurers, potentially their Internal Models), is clearly one that warrants some focus.

The Strategic Report will be compulsory content for Annual Reports and Accounts from October (Companies Act 2006 414C). The FRC's (non-mandatory) guidance regarding the incorporation of risk-related material into this section is to address the requirement on p2 that the Strategic Report;
...should include a description of the principal risks and uncertainties facing the company
The FRC's specific definition of Principal Risk is found on p35 of the draft guidance as;
A risk or combination of risks that can seriously affect the performance, future prospects or reputation of the entity. These should include those risks that affect the viability of an entity.
The draft guidance (p23) aims to tack on a few definitional aspects of how "risks and uncertainties" are reported in the context of strategy, most pointedly;
  • [The risks] should be limited to those considered by the entity’s management to be the most important to the future development, performance or position of the entity. They will generally be matters that the directors regularly monitor and discuss because of their likelihood, the magnitude of their potential effect on the entity, or a combination of the two
  • Principal risks or uncertainties with potential effects of such a magnitude that they may threaten the entity’s viability (ie its solvency and/or liquidity) should be explained fully and given due prominence
  • Directors should consider the full range of business risks including commercial, operational and financial risks
  • The descriptions...should be 
    sufficiently specific that a shareholder can understand why they are important to the 
    entity. This might include a description of the likelihood of the risk, an indication of when 
    the risk might be most relevant to the entity and its possible effects. Significant changes...
    such as a change in likelihood or possible effect, or the inclusion of new 
    risks, should be highlighted and explained. An explanation of how the principal risks and 
    uncertainties are managed or mitigated should also be included.

  • Where the risk or uncertainty is more generic, the description should make 
    clear how it might affect the entity specifically.
Prudential provide a good example here (from p72) of how this is currently done by an insurer - the fact that it is buried in 75 pages of 'Business Review' underlines why the streamlining of this work has become of statutory interest!

Interestingly, the FRC note that definition for "principal risks" has been developed/derived from previous FRC work, supplemented by work from the Sharman Inquiry - all of that therefore feels well divorced from anything produced by the IRM/Actuarial Profession/EIOPA around risk categorisation, and leads to the same bridging work I have been involved in previously; namely, reconciling how one manages and monitors risk within the business against what one reports externally. Might we have expected to see some kind of compulsory categorisation of "principal risks" in here that favours the financial services industry who arguably carry the largest set? 

Much of the other compulsory material in the Strategic Report (with exemptions) touches on other topical or sensitive matters such as;

  • Inclusion of key performance indicators in the report ("...where possible, they should be accepted and widely used")
  • Information on environmental matters, staff and social/community/human rights issues
  • Information on gender splits at Board, Senior Management and All-company level
I may throw some feedback in to the FRC on this paper- comments welcome until late November. Externally, the main change for insurers will be trimming down some of the fluff and flannel already produced in the space. Internally, aligning the concept of "principal risks" with existing ERM programme/Internal Model lexicon may be a bigger job for anyone operating on a shoestring.

Wednesday, 7 August 2013

Deloitte's 8th Global Risk Management Survey - cause for concern?

A survey from Deloitte has recently hit the news stands, namely the 8th edition of their Global Risk Management Survey - I thought I'd postpone my August holidays to pick through the bones of it (?).

The data was gleaned from an online survey they sent out to CRO/equivalents back in Sept-Dec 2012, so is a bit dusty, and there were 86 respondents, so a half-decent sample. It isn't dominated by a particular sector or continent (p7), but there are more conglomerate/bank-heavy respondents than pure insurers.

There is an infographic for those of a short attention span with a few headline numbers, but having sifted through the larger doc, I found the following elements worthy of note;

Boards, Committees and Risk Management
  • 80% of Boards are reviewing and approving Risk Management Policies/ERM Frameworks and Risk Appetite Statements. Bearing in mind the types of organisation in the sample, that is disappointingly low.
  • 25% don't review individual risk policies
  • 23% don't review strategy against risk profile
  • Almost half don't invite CRO to EXCOM meetings
  • Almost two-thirds delegate risk oversight to satellite committees (and two-thirds of those delegate to a Risk Committee)
  • Only half have their Risk Committee chaired by an INED.
  • Use of specific management risk committees for individual risk types tends to cluster around the 40-60% bracket (for example, 60% have an ERM committee, while 44% have an Op Risk Committee). Heavily weighted by organisation size i.e. larger ones tend to have them! 
  • Emerging risk reporting not supplied to 30% of Boards
  • Model validation results not supplied to 70% of Boards!
  • 66% (of insurance respondents) have their Boards responsible for reviewing economic capital results
CRO and Risk Management Function
  • 97% of large respondents have a CRO, 81% of smaller firms 
  • 88% using "3 Lines of Defence" (almost all of the larger respondents do)
  • 62% have an "ERM Programme"
  • 58% increasing risk management budgets (still!)
  • In the list of tasks currently performed by CROs, the fact that only 63% are involved in the approval of new business lines/products is pretty telling, and not in a good way.
Other control functions

  • Almost half of respondents said that Internal Audit and the ERM Framework do not use common risk categories and language.
  • 33% do not have a independent model validation 'function' (remember, the banks are in these stats as well!) - most of those who have made provision park it in the Risk Management function.

Risk management techniques

  • 90% using some form of stress testing in the business, with most saying the outputs are used in business planning, strategy setting and identifying risk tolerance. More than half however don't use the outputs in the allocation of capital to lines of business.
  • 74% have some type of Stress Testing policy
  • Over 20% either do not have a Risk Appetite Statement, or only have a quantitative one
  • Almost 70% still use regulatory capital as one of their quantitative measures in their Risk Appetite Statements
  • Risk limits tending to be set at enterprise level, as opposed to business or desk/subsidiary level - stats are a little murky due to the emphasis towards banking sector.
  • Model risk and Liquidity risk seem to be the risk types least factored in to companies ERM programmes
Management of Key Risks
  • Full list on p24, with the percentage shown representing the number of respondents who thought their management of each risk was "extremely" or "very" effective - stand outs were that perceptions of the effectiveness of the management of Operational, Model, Outsourcing and Data risks appear to be much lower than one would hope, with Lapse risk management ranked unusually high.
  • Op Risk KRIs and Loss data only collected in 60% of respondents
  • Just over half are modelling Op Risk in some way - varying degrees of complexity experienced
  • Most are using stress testing and/or reserving to assess Insurance risk - over 40% not currently using EC, and over 50% not using VaR.

Risk and Reward

  • Almost 60% of remuneration schemes have no clawback provisions
  • Almost 70% of schemes do not align incentive payouts with the term exposure of the underlying risks

Solvency II-specific
  • 92% (of relevant responders) will focus resource on ORSA in next 12 months
  • 77% will focus resource on Data Quality in next 12 months
  • 69% will focus resource on Documentation and Reporting in next 12 months
  • Less than 25% rate their processes and systems for Data Governance extremely/very effective.
  • Declining trend of insurers who will be modelling economic capital (p19)
  • Only 80% actually calculate Economic Capital
  • Some very grim stats on p21 covering which risk types are modelled for EC purposes (underwriting risks seemingly very low on the list)
There are a number of areas touched on here which fall short of pending (or indeed actual) national/international regulations and codes, never mind "best practice". Perhaps we can account for the innate conservatism of CROs in their responses, and assume things aren't quite as bad as they have self-assessed here?

Thursday, 28 March 2013

EIOPA Preparatory Guidelines - System of Governance

Consultation on System of Governance preparatory guidance (plus explanatory text)

For a topic which has felt like a given for a number of years (certainly in UK and Ireland where we already ask a lot in this area), the System of Governance preparatory guidance is still 40 pages, comprising of 57 guidelines, accompanied by 60 pages of explanatory text.

A couple of things immediately grabbed at me when going through the guidance (again anticipating a conservative approach of the supervisors rolling over and applying all content as is)
  • That the Risk Management Policy (regardless of how one structures the component elements) is expected to contain procedure-level information about the management of each major risk category - this sounds hopelessly disproportionate, and almost impossible for supervisors to reasonably get through;
  • That it is "expected" that large or complex firms separate their four key control functions, and that others at the small/medium end may ultimately find it easier to do so than consider the range of controls/maintenance of independence required to have combined functions;
  • That an expectation that insurers' systems of governance require regular independent review, with the AMSB only retaining the ability to choose the performer;
  • That insurers will be expected to formally identify/analyse/report on Operational Risk Events
  • That EIOPA bottled out of defining Risk Appetite and Risk Tolerance, leaving national supervisors and insurers to fight it out amongst themselves.
Ultimately, the document reads like a checklist which practitioners or full-timers can run through against the suite of documentation no doubt already in existence which, if based on CEIOPS/EIOPA final advice and/or the Commission's Draft Level 2 measures, won't be miles away as it stands. On that premise, I've only listed elements which jump out for me.


GENERAL GOVERNANCE REQUIREMENTS

Guideline 3
  • Evidence should be collected of the AMSB "proactively" seeking information from committees/key functions
Guideline 5
  • No more detail than an expectation that the AMSB "appropriately implements" their key functions - in the explanatory text, it goes on to say that larger companies will be "expected" to fully separate Risk/Actuarial/Compliance/IA, with a series of measures expected to preserve functional independence if smaller companies choose to combine some.
Guideline 7
  • Expectation that both AMSB decisions, and how information generated from the Risk Management System (RMS) influences them, is "appropriately documented" - compulsion for Board Decision Logs?
Guideline 8
  • Regular System of Governance reviews appear to be expected, which are documented and reported back to the AMSB - the AMSB retains the right to choose who performs it 
Guideline 9 - All policies must include:
  • Goal of policy
  • Tasks to be performed and by whom (person or role, unlike for validation, where person/s was specified)
  • Associated processes and reporting procedures
  • Obligations of affected operational teams to inform control functions of "relevant facts" at all times
Guideline 10
  • Contingency plans are expected for areas which are "especially vulnerable" - this pushes outside of what one would consider a conventional contingency plan for operational emergencies.

FIT AND PROPER

Guideline 11
  • Must have a Fit and Proper persons policy
  • It must be equally applicable to both hired staff and outsourced functions

RISK MANAGEMENT

Guideline 15 - AMSB is "ultimately responsible" for:
  • RMS effectiveness
  • Setting Risk Appetite and Risk Tolerance Limits
  • Approving Risk Management strategies and policies
Guideline 16 - Risk Management Policy must cover at least
  • Risk categories used and measurement methods
  • How each category/grouping of risks is managed
  • Risk tolerance limits for all categories in line with Risk Appetite
  • Linkage of both SCR and ORSA to risk tolerance limits
  • Frequency and content of regular stress tests, and circumstances for additional testing
In addition, the associated guidelines touch on the risk categories within one's Risk Management Policy. There is an expectation for pretty much every category that procedure-level information is included in the policy documents themselves, as well as hard limits, which is unlikely to be the case as it stands.

Guideline 18 - Insurance Risk Policy
  • Expected to cover types of acceptable insurance risks, how premiums will cover claims/expenses, as well as how product design accounts for investment restrictions and formal risk mitigation techniques
Guideline 19 - Op Risk Policy
  • Expectation that Operation Risk Events will be formally identified/analysed/reported in insurers, and that a system for collecting and monitoring them should be in place.
  • Operational Risk Scenarios should be developed and used, based on failures of key persons/processes/systems and external events
Guideline 23 - Investment Risk Policy
  • Buzzphrase introduced of managing the level of "security, quality, liquidity, profitability and availability" of one's asset portfolio

OWN FUND REQUIREMENTS AND THE SYSTEM OF GOVERNANCE

Guideline 32
  • Concept of a "medium term capital management plan" introduced which covers; planned capital issuances, maturities and distribution policies - not sure how that works for mutuals, but I can see what they're fishing for

INTERNAL CONTROLS

Guideline 33
  • "All personnel [should be] aware of their role in the Internal Control system
  • The Internal Control system should be "commensurate to the risks arising from the activities and processed to be controlled" - this line should hopefully avoid overkill

INTERNAL AUDIT FUNCTION

Guideline 36
  • The Internal Audit policy should include the procedure for informing supervisors [of whistleblowing-level wrongdoing I guess]

ACTUARIAL FUNCTION

Guideline 44
  • "Material"deviations of Best Estimate Liabilities should be back-tested for by the Actuarial function, reported on, and remedial changes proposed
Guideline 46
  • The Actuarial function is expected to "contribute to" specifying the risk coverage in the internal model, as well as the dependency structure - this feels like areas where, even in larger insurers, the function probably already leads, so will they be asked to take a step back?

Tuesday, 11 September 2012

Did we learn from Equitable Life? Professor says "No"...

A cracking thought paper was released this week by Professor Roberts from Kings College regarding the lessons one could reasonably have learned from British mutual Equitable Life's demise in early 2000s, and more importantly, did UK plc actually learn them! (simple timeline of recent events here for our non GB readers, but anyone whose website starts with a banner exclaiming "recreating value for policyholders" has clearly had a lean few years!)

This document works nicely as an aide-memoire for anyone working in a financial services risk function as to what one should be wary of in the day-job. Professor Roberts ties in some of the most recent work in this space (leaning heavily on the Cass Business School/AIRMIC Roads to Ruin research and its conclusions in particular), and comes to the inevitable conclusion that lessons are well publicised, but never learned.

My main concern as a risk specialist is that certain recurring themes in the failure of financial services firms appear to remain outside of the Risk function's control or indeed influence, notably;
  • Hubris of Senior/Chief executives - Almost every example of failure in insurance and banking referenced in Prof. Roberts paper includes a flukey, unchallenged CEO who got bolder as circumstance rather than skill kept their businesses growing. I had flagged a couple of articles in a post last year touching on what makes an executive tick, and since then I have seen psychopathy and leadership (as opposed to cherubic faces!) examined further in a popular mainstream book. The legitimate concern here of course is that CROs are seemingly no nearer to being guaranteed seats at the top table, let alone a veto to keep the most dominant executives in check, regardless of their loud voices, when necessary.
  • Poor quality governance from Non-Executive Director level - Risk functions simply must have the NEDs performing at their optimum in order to provide acceptable services to their employers. While the "old school tie" approach to recruiting NEDs may take a generation to phase out entirely (to be replaced by an army of Fembots, so Viviane Reding would have us think), Risk functions are left with tottering old fee-sweepers as their key route to early intervention. The more visceral approaches to documenting risk appetite/tolerance/preference now being supported by corporate governance codes and vocational/professional bodies may make it easier to raise concerns with NEDs in future (probably as it will be colour coded and in Excel...), but until they are actually prepared to risk their comfortable semi-retirement with some probing questions in the C-suite itself, should Risk functions ever think they can overcome such a void?
  • Failure of regulation - Should Risk functions be banking on the (inevitable?) failure of the nascent regulatory environment, and reserve for subsequent claims/compensation if one or a number of products are "too" successful, thus providing the necessary quantum of dissatisfied customers for the regulator to act? I would have laughed this suggestion out of the room until a year ago, since when the FSA have made retrospective calls on interest rate swaps, PPI, and TLPs, all of which would have been presented as "compliant" products in the Boardroom.
For the Solvency II fans, it also notes on page 11-12 that Equitable Life featured in the research which grew up to be Solvency II! Maybe we did learn something after all - if we smash up the affordability of long-term guaranteed products, we can all go unit-linked and never have to worry about another Equitable...

Saturday, 31 March 2012

IRM Solvency II Special Interest Group - making Risk Function more relevant

The IRM guys always put on a good show with their Special Interest Group activity for Solvency II, and generally has relevance outside of the Insurance industry. Couple of interesting subject matters for the last two, my notes below.

Developing the Risk Function to be Board-relevant (under Solvency II) - international flavour in presenters, so bear that in mind when you look at the slides!
  • Jose Morago presentation - Aviva's EU Risk Director has a nice slide on educating and supporting the Board on risk responsibilities, but on the Risk function's "four distinct personalities", I would disagree that the function "leads the optimisation of the insurer's risk/capitalisation profile" (advises, certainly, but leads?). The personalities seem to be light on review and challenge activity as well, and there is a fair amount of risk jargon, which Boards are never keen on in my experience.
  • Kendra Felisky presentation - While Jose went with Risk function as "Officer, Business Leader, Teacher and Advisor", Kendra has the second line of defence as "Assess, Monitor, Support and Challenge", which I concur with, and goes on to comment that "Our job is to enable to Board to do their job", which I would also subscribe to. She has a rather dated slide showing what the Risk function was compared to what it is/needs to be (you'd need a time machine to remember the 'old' Risk function!), and a good slide on levels of participation in risk management, and MI requirements. The slide on how to talk to the Board recommends 'no jargon' (which cuts across Jose's terminology a bit!), and the section on Key Risk reporting seems to be focused on risk mitigation and elimination, rather than optimisation.
  • Pierre-Andre Camps presentation - Feels like a lot is lost in translation on these slides, so have a leaf through, but don't hang your hat on anything.
Survey findings on  making the Risk function Board relevant (35 participants, so small sample)
  • Only half have their CRO communicating directly with the Board on risk matters- surely explains the necessity of this event!
  • Horrifically, almost half said risk papers are "noted with a short discussion" at Boards - is the problem that all papers are not 'risk papers', hence it can be siloed as a talking point?
  • Half said the process of implementing Solvency II affects their ability to becoime relevant to the Board - that is definitely a bad development all round
  • Three-quarters said there is no action plan or training programme to aid the Risk function in communicating and presenting to Boards.
  • A third of attendees report to a CRO, while a quarter report to a CEO (I find that instinctively high)
  • Not surprised by smattering of risks not covered by the attendees' functions - smaller companies are unlikely to cover financial and non-financial categories, and the categories with least coverage tend to lean towards having expert ownership and established controls (ALM in particular).
  • Over half felt they had overlap with either Actuarial or Compliance
  • A worrying number are not directly delivering testing and validation of the internal model. Understandable on the design/implementation/documentation front, but surely testing and validation?

Thursday, 7 July 2011

Society of Actuaries in Ireland - Land grab for the Solvency II grey areas?

Having already blogged on the brewing discomfort of the Institute of Risk Management regarding the perceived preference of the FSA for Actuaries to run Risk functions under Solvency II (and had to follow up as the story developed), I was very interested to read through the Irish Society of Actuaries strategic plan released today.

There is definitely the beginnings of a land grab here, with a number of statements eagle-eying the juicy cuts of what is currently ascribed to the Risk function as per the extracts below;

We also aim to have our members recognised as being committed to the highest standards
of skill and professionalism and well equipped to take up both actuarial and risk management
roles under Solvency II.”

"enhance the standing and role of actuaries within insurance and reinsurance
companies, and in particular, to enhance the standing of actuaries as risk managers"


"Promote the qualifications and relevant experience of actuaries as risk managers."

"Increase awareness of the CERA (Chartered Enterprise Risk Actuary) qualification."

"Another area that is becoming increasingly important for actuaries is risk management,
including the management of risks beyond financial risks. We have already delivered a
number of CPD events aimed at improving members’ knowledge and understanding of risk
management concepts and skills and this will remain an important area of focus."

And perhaps the most land-grabby target;
"Explore the feasibility of partnering with an appropriate university or similar body to
develop a comprehensive risk management training programme for actuaries who want
to skill up quickly in this area."

It's a good job I'm all about openness and competition, otherwise I might start to get an inferiority complex!