"Three Lines of Defense," Part 3
Presenter 3: Bogie Ozdemir
Implementing 3LD Model in Insurance Companies
Need to clearly define the line between the first line and second line. Second line needs to have no gaps and no overlaps, e.g., between actuarial, legal, HR, etc.
Example: credit risk management
First line: business group CEO and delegates, investments, ALM, and Hedging
Second line: business group risk officers, Chief Market Risk Office, back offic
Example: actuarial function
Not clear between 1st and 2nd line. Who is responsible for what between the actuarial function and the risk function? In his company, the Chief Actuary reports to the CRO
In general, there is no fully implemented 3LD that he's aware of.
One interesting thing he mentioned is that his company has a model validation unit, separate from the people who create the models. He also discussed the need for subject-level experts in this control/review process.
Apparently there's a debate as to whether 3LD applies to the finance department or not. Of course, ORSA is a second-line response, and finance plays a key role in ORSA.
Overall, he characterizes 3LD as a capital-optimization problem: capital is allocated by the 2nd line, risk is taken by the first line. The trick is to coordinate the two such that shareholder value is maximized.
End Part 3.
A young actuary's quest to determine causation, conquer risk, and quantify everything
Monday, April 22, 2013
Three Lines of Defense Part 2
"Three Lines of Defense," Part 2
Presenter 2: Dr. Colin Lawrence, Bank of England
Risk, Control, and Culture: the Regulatory Approach
"We've become risk measurers rather than risk managers."
Failure of risk managers was to just measure VaR, without recognizing the context in which it was used. The first question should be "Is the business model sustainable."
"4th line of defense: the regulator." Concern for regulators is the safety and health of the entire financial system, *not* the particular firm.
Focus now is on the biggest risks to failure, whereas it used to be on dozens of different risks. Regulators used to have some tolerance for failure, but now it's zero tolerance.
The Bank of England is doing all these controls, but why aren't other firms doing this? Bank and insurers? Reason is an enormous moral hazard problem: when people are compensated for taking risks. Argument that regulators are needed to enforce risk governance.
Prior to 1960, banks made a stable 7%. When Nixon went off the gold standard, ROR went up to 20%, but with a great deal more volatility (almost 4x). Leverage went crazy. Securities became prevalent. "Re-aging" or "forbearance" might be good as a social value, but you need to build up reserves for the risk of default. Accounting conventions don't require this until there's an actual trigger of default.
Bank of England study on bank data: Found 85% of losses were from structured finance, distributed evenly between trading book and banking book. Bias to record profit in trading book and losses in banking book to avoid disclosing mark-to-market losses. Also note that all banks were essentially in the same investment market: real estate.
This tells us where reforms need to be made structurally. The branch model causes a lot of problems due to perverse incentives for branch managers. None of the governance discussed in the prior presentation were in place. He blames this on a principal agent problem: don't want to disclose, don't want to know.
Lack of IT integration means poor data. Poor data means poor risk management. Good data management needs to be understood and accepted as an essential part of the business - it's a cost of doing business. Book "Why People Cheat" by behavioral economist Dan Ariely talks about how people become institutionalized into not reporting thoroughly and promptly. [KR: I believe he means this book.]
Boards are not in a position to really do their jobs. Most Boardmembers are on multiple Boards; it's not possible that they are able to really understand everything they need to in order to do their jobs. Which firms did well? Mostly those with Boards that are on top of things. Setting limits doesn't actually help; banks just move things around to achieve the ROE in "limit arbitrage." He also notes that controllers are often ignored (and paid very little compared to those taking the risks.)
See slide 13 for a list of what he as a regulator wants each firm to demonstrate to him. Particularly interesting point to me is the emphasis on counter-cyclical resilience. Strikes me as highly applicable to insurance.
Because regulators will no longer tolerate failures, it's important that firms understand the conditions under which they will be resolved. *Not* looking at static values, *not* accounting values. Dynamic analysis of market values under many scenarios. "Ring fencing" means isolating certain business segments or units when things go south. "Contingent capital": regulator decides when it becomes a put option rather than the investor.
Recommends having a diverse jury on the Risk Committee.
Slide 23 shows how they did the bailout in UK. Notes the poor econometrics (he went to UChicago; hurray Maroons!)
End Part 2.
Presenter 2: Dr. Colin Lawrence, Bank of England
Risk, Control, and Culture: the Regulatory Approach
"We've become risk measurers rather than risk managers."
Failure of risk managers was to just measure VaR, without recognizing the context in which it was used. The first question should be "Is the business model sustainable."
"4th line of defense: the regulator." Concern for regulators is the safety and health of the entire financial system, *not* the particular firm.
Focus now is on the biggest risks to failure, whereas it used to be on dozens of different risks. Regulators used to have some tolerance for failure, but now it's zero tolerance.
The Bank of England is doing all these controls, but why aren't other firms doing this? Bank and insurers? Reason is an enormous moral hazard problem: when people are compensated for taking risks. Argument that regulators are needed to enforce risk governance.
Prior to 1960, banks made a stable 7%. When Nixon went off the gold standard, ROR went up to 20%, but with a great deal more volatility (almost 4x). Leverage went crazy. Securities became prevalent. "Re-aging" or "forbearance" might be good as a social value, but you need to build up reserves for the risk of default. Accounting conventions don't require this until there's an actual trigger of default.
Bank of England study on bank data: Found 85% of losses were from structured finance, distributed evenly between trading book and banking book. Bias to record profit in trading book and losses in banking book to avoid disclosing mark-to-market losses. Also note that all banks were essentially in the same investment market: real estate.
This tells us where reforms need to be made structurally. The branch model causes a lot of problems due to perverse incentives for branch managers. None of the governance discussed in the prior presentation were in place. He blames this on a principal agent problem: don't want to disclose, don't want to know.
Lack of IT integration means poor data. Poor data means poor risk management. Good data management needs to be understood and accepted as an essential part of the business - it's a cost of doing business. Book "Why People Cheat" by behavioral economist Dan Ariely talks about how people become institutionalized into not reporting thoroughly and promptly. [KR: I believe he means this book.]
Boards are not in a position to really do their jobs. Most Boardmembers are on multiple Boards; it's not possible that they are able to really understand everything they need to in order to do their jobs. Which firms did well? Mostly those with Boards that are on top of things. Setting limits doesn't actually help; banks just move things around to achieve the ROE in "limit arbitrage." He also notes that controllers are often ignored (and paid very little compared to those taking the risks.)
See slide 13 for a list of what he as a regulator wants each firm to demonstrate to him. Particularly interesting point to me is the emphasis on counter-cyclical resilience. Strikes me as highly applicable to insurance.
Because regulators will no longer tolerate failures, it's important that firms understand the conditions under which they will be resolved. *Not* looking at static values, *not* accounting values. Dynamic analysis of market values under many scenarios. "Ring fencing" means isolating certain business segments or units when things go south. "Contingent capital": regulator decides when it becomes a put option rather than the investor.
Recommends having a diverse jury on the Risk Committee.
Slide 23 shows how they did the bailout in UK. Notes the poor econometrics (he went to UChicago; hurray Maroons!)
End Part 2.
Three Lines of Defense Part 1
Workshop day. Looks like about 75 people in attendance, and we have six presenters.
Webpage for this day’s sessions: http://www.ermsymposium.org/2013/seminars.php
"The Three Lines of Defense," Part 1
Story about attempts to transfer accountability: manager asks internal audit to review the risk governance process he uses, thus making audit responsible. This is typical behavior from the first line of defense. Accountability in the first line is weak. Ultimately it's management's self-assessment. The Board is the check on this, and they need to review *and* challenge management's assumptions.
"6 is less than 3" - really sees 6 lines of defense, but doesn't say this because people think 6 is overwhelming compared to 3. Part of the reason why he sees 6 as being less than 3 is that he believes the third line of defense can downsize significantly. They are given the most resources, but this enables the first and second lines to rely on the third line instead of doing their jobs.
Story: company that kept hiring more internal auditors every time there was a risk event. Company of a few thousand ended up with 160 internal auditors. It didn't make a difference: the risk crises continued. CEO decided to make a change to the risk culture. He reduced audit back to 3 people, added 2 risk managers, and changed compensation to reflect risk accountability for execs. Number of risk events shrunk dramatically as a result, despite fewer resources allocated to risk management.
Risk management's job is *not* to set limits. Risk management creates the system that guides the setting of limits.
Risk taking structure: Board (oversight, approval) -> Executive Management Committee (ultimate responsibility, select risk appetite) -> Business Functional Head -> Business Leadership Groups (setting limits) -> Individual Risk Takers
Story: dominant CEO of insurer ignored Board and others and elected not to hedge. Lost 90% of market cap when stock market declined. They had an "Audit and Risk Committee," where risk was an add-on and not really understood. Everything that went to the Board went through CEO as well.
My question for him: CEOs change. Do you really have to revamp your risk governance every time your CEO changes? Answer: Yes, to the extent that is required with the particular CEO, *but* the principles of risk management for the firm should not change with the CEO. Principles remain constant, but the system needs to change to accommodate the personalities involved. [KR: this is interesting to me, the potential psychological angle to qualitative ERM.]
"Doers and checkers" - how his friend (actuary and CRO of reinsurer) describes the 6 line process.
Note that not all checkers would be full-time. Large banks have full-time staff doing model validation, but most likely for policy review, you wouldn't hire someone just for that. The key is for the checker to be competent and independent.
Business case for effective risk governance: it's about improving the odds when taking risks. Reduce surprises, optimize risk/return, improve shareholder value.
He believes it's a bad idea to have the CEO also be the Chairman of the Board or President.
My question for him: What's a small firm to do? How do you find competent, independent checkers? Answer: Smaller firms are limited in what they can do. Priority should be putting accountability with the risk taker. Remember that the principles would still remain the same.
My question for him: What if risk appetite is high to the point that perhaps you *want* the CEO to run wild? Answer: There is a limit to the risk your capital can absorb, regardless of your risk appetite. Risk appetite is deciding how close to that limit you're willing to go. Even if you are willing to go all the way to the limit, risk governance will still be needed to monitor and control *that* limit.
End Part 1
Webpage for this day’s sessions: http://www.ermsymposium.org/2013/seminars.php
Mostly
insurers in attendance, 15% consultants, and a smattering of banks.
Most insurers in attendance say they are implementing this idea to some
extent.
Intro (Alexander Shipilov):
“Three lines” was originally just a metaphor, but regulators adopted
it, so it stuck. There is a group on LinkedIn, “3 Lines of Corporate Defense,” where
you can go to continue the discussion and ask more questions. He recommends joining the group if you have an interest.
Presenter 1: Leon Bloom, Sr. Partner at Deloitte
Risk Governance: evolving beyond the traditional “three lines of defense” model
He sees the
financial crisis as caused by failure of risk governance. Regulators,
investors, and analysts are now focused in this area, making this a hot
topic. Firms that have adopted this approach have been more resilient.
Risk governance is the system for controlling the management of risk. It
involves roles, authority, responsibility, and information. Currently
seen as a gap area for the industry. The 3 line model is sound in theory but hasn’t been
sound in application; consequently it needs to evolve.
6 key issues for global financial institutions: capital,
liquidity, economy (US debt at all-time high, Euro insolvency, etc; very bad timing for all these problems),
operations (reducing costs), M&A, risk governance
“There will be winners and there will be losers...the winners with be those with the best handle on risk management.”
He has concerns about regulation becoming very prescriptive, getting the way of actual effectiveness.
Four
priority areas for regulation: inherent riskiness of the business
model, tail risk, pricing, risk governance (audit function =! risk
governance)
Story: Northern
Rock- successful institution, ROC was good, etc., but didn’t recognize that it was
heavily dependent on two sources for funding: mortgage-backed securities
and issuing short-term commercial paper. Liquidity dried up overnight. 9
weeks before they collapsed, their ORSA-equivalent had two paragraphs
on liquidity (and regulator signed off). Entire business model was
dependent on liquidity; plenty of capital, but that didn't matter.
Pricing hasn’t been sensitive to risk historically (and regulators blind to it).
Lack
of clarity around ownership of risk by the first line of defense -
failure of risk governance. Those who take the risks should be
accountable, rather than use the second and third lines as a management
control. [KR: this was the main emphasis of his presentation.]
“...as we continue to move through the financial crisis” - emphatic about this: it’s not over.
“Risk
people” should *never* own risk; ownership of risk should fall as close to the origin
of the risk as possible. The person taking the risk should own it.
“Risk management’s” job is *not* to manage risk; its job is to create
systems, policies, and support to guide the risk owner. Accountability
needs to be accompanied by authority.
Emerging
risk governance requirements: governance, closer alignment of risk and
business considerations, holistic risk governance approach.
Challenges: he lists a number, but the most interesting to me was the point that the objectives and target end-state for ERM are unclear.
Aside on Dodd-Frank:
it was passed in a hurry, with too many complex, confusing requirements. He doesn’t
think it’s going to help, and he expects it will be thrown out and replaced eventually.
Guiding
principles - see slide 8. Risk has been taken based on CEO personality (ability to intimidate the Board);
establishing principles can help keep that from happening.
Story: 12
months ago in UK a trader was sentenced to 12 year prison for losing 2b
lbs. He knew all the risk governance policies, but his boss told him to ignore it. This is the
operating culture versus the risk governance.
“The operating culture is
what goes on when no one’s looking.” - this is the other major take-away from this presentation.
Evolution
of the ‘lines of defense model’: “Roles, responsibilities,
accountabilities, authority, design, and information” (see graphic, slide 11)
Maturity
levels (of a firm's risk governance): unaware, fragmented, integrated, comprehensive, optimized.
Small organizations do too little, large can do too much (bureaucratic.)
"6 is less than 3" - really sees 6 lines of defense, but doesn't say this because people think 6 is overwhelming compared to 3. Part of the reason why he sees 6 as being less than 3 is that he believes the third line of defense can downsize significantly. They are given the most resources, but this enables the first and second lines to rely on the third line instead of doing their jobs.
Story: company that kept hiring more internal auditors every time there was a risk event. Company of a few thousand ended up with 160 internal auditors. It didn't make a difference: the risk crises continued. CEO decided to make a change to the risk culture. He reduced audit back to 3 people, added 2 risk managers, and changed compensation to reflect risk accountability for execs. Number of risk events shrunk dramatically as a result, despite fewer resources allocated to risk management.
Risk management's job is *not* to set limits. Risk management creates the system that guides the setting of limits.
Risk taking structure: Board (oversight, approval) -> Executive Management Committee (ultimate responsibility, select risk appetite) -> Business Functional Head -> Business Leadership Groups (setting limits) -> Individual Risk Takers
Story: dominant CEO of insurer ignored Board and others and elected not to hedge. Lost 90% of market cap when stock market declined. They had an "Audit and Risk Committee," where risk was an add-on and not really understood. Everything that went to the Board went through CEO as well.
My question for him: CEOs change. Do you really have to revamp your risk governance every time your CEO changes? Answer: Yes, to the extent that is required with the particular CEO, *but* the principles of risk management for the firm should not change with the CEO. Principles remain constant, but the system needs to change to accommodate the personalities involved. [KR: this is interesting to me, the potential psychological angle to qualitative ERM.]
"Doers and checkers" - how his friend (actuary and CRO of reinsurer) describes the 6 line process.
Note that not all checkers would be full-time. Large banks have full-time staff doing model validation, but most likely for policy review, you wouldn't hire someone just for that. The key is for the checker to be competent and independent.
Business case for effective risk governance: it's about improving the odds when taking risks. Reduce surprises, optimize risk/return, improve shareholder value.
He believes it's a bad idea to have the CEO also be the Chairman of the Board or President.
My question for him: What's a small firm to do? How do you find competent, independent checkers? Answer: Smaller firms are limited in what they can do. Priority should be putting accountability with the risk taker. Remember that the principles would still remain the same.
My question for him: What if risk appetite is high to the point that perhaps you *want* the CEO to run wild? Answer: There is a limit to the risk your capital can absorb, regardless of your risk appetite. Risk appetite is deciding how close to that limit you're willing to go. Even if you are willing to go all the way to the limit, risk governance will still be needed to monitor and control *that* limit.
End Part 1
Saturday, April 20, 2013
2013 ERM Symposium
This year, for the first time, I will be attending the ERM Symposium in Chicago. Not only will this be a great opportunity to learn more about ERM, it will also be a chance to network, enjoy some time in one of my favorite cities, and get some efficient "hotel study time" in (I admit, I'm extra excited that the conference is being held at Swissotel, a hotel at which I've long wanted to stay.)
Since I've been so lax in posting, I am going to compensate by live-blogging all of the sessions I'm attending. Stay tuned!
Since I've been so lax in posting, I am going to compensate by live-blogging all of the sessions I'm attending. Stay tuned!
Friday, April 5, 2013
Future Fellows
Since I have little time for blogging these days (a good thing- work is very busy and very rewarding), I'd like to draw your attention to my most recent article in Future Fellows. If you don't already read this publication regularly, I highly recommend it, even for non-exam takers. It's really the main source of information on the admissions process. We even publish articles and commentary directly from the Exam Committee itself, which are often very illuminating.
Check it out:
http://www.casact.org/newsletter/index.cfm?fa=ff
My article, a short humor piece which is very appropriate for exam season, can be found here:
http://www.casact.org/newsletter/index.cfm?fa=viewart&id=6523
As always, let me know if any candidates out there would like to see articles on any particular topics in the future.
Good luck this sitting!
Katrina
Check it out:
http://www.casact.org/newsletter/index.cfm?fa=ff
My article, a short humor piece which is very appropriate for exam season, can be found here:
http://www.casact.org/newsletter/index.cfm?fa=viewart&id=6523
As always, let me know if any candidates out there would like to see articles on any particular topics in the future.
Good luck this sitting!
Katrina
Thursday, December 20, 2012
2012 in Review
Let's see how I did with those resolutions:
Obtain
Fellowship - Instead of making FCAS in one clean sweep, I decided to "grow as a person" by failing Exam 9 (I have lots to say about that but another time for that) and skipping Exam 8. No regrets, however, as I got myself a new job to go with my new credentials. I'll take promotion to consultant over passing an exam (almost) any day.
Read Articles - I've been better about this than I honestly thought I would. Maybe it's the pressure of being a consultant, but at this point keeping up on industry news has fallen nicely into my routine.
Wake up! - Starting my new job was a great excuse to get serious about my early to bed/early to rise resolution. Although my team is still mostly late-risers, I've been finding it relatively painless to arrive decently early.
Blog - Ha. See for yourself. Between exams, job hunt, and various personal trials, blogging just couldn't be a priority. I will strive for more balance in 2013, but something tells me that once a month blogging is an overly ambitious goal for an exam-taking consultant.
Research - Possibly my one real regret was not doing enough independent research this year. I have several ideas I'm excited about. Now to put aside the time to work on them.
Study Earlier - Less relevant since I skipped 8 this sitting, but I have already started on Exam 9 (before Halloween, in fact.) Bloom's (on which I have much to say) seems to demand a radically different approach to studying; developing a new method takes time, so I've made sure I have plenty of that.
Getting Things Done - Check. David Allen remains a life-saver for me.
Email - I am now the queen of email organization. Now to become the queen of email reading and responding.
Project Notes - Definitely a carry-over goal for 2013. New company, new projects, new practice, new everything. It's a lot to take in, and I've hardly had the time to breathe. That's unlikely to change in the next few months, but perhaps I can catch my breath some time in March. Oh wait, I'll be studying then. Eh, who needs O2?
VB - I ended up trading this goal for learning SQL. Some progress made, more to go, though I'm not sure I'll continue, since I'm unlikely to ever work at an insurer. Any thoughts, readers?
Candidate Liaison Committee - Mission accomplished. I very nearly panicked and aborted my trip to our annual in-person meeting at ISO's headquarters in New Jersey this month, but in the end I bucked up. I'm glad I did. The new members of the committee are enthusiastic and insightful, not to mention connected to me in surprising ways. We're fond of remarking on the smallness of the actuarial/insurance community, but it's still quite amazing to me how closely connected we all are.
All in all, I'm declaring 2012 a success. I started out the year feeling held back but ultimately came out on top with my ACAS, my new position at a new company, and a great deal of optimism for what's to come in 2013.
Finish strong, 2012.
P.S. I'm writing this in the middle of exam results. Congrats to those I already know passed, condolences to those that didn't (I now know all too well how that feels), and for those still waiting to hear, I hope your pain ends tomorrow. Mazel tov.
Thursday, July 5, 2012
Radio Silence
I haven't had anything to say lately, but that will probably change once exam results are released. Stay tuned!
Subscribe to:
Posts (Atom)