"Three Lines of Defense," Part 5
Presenter 5: Sean Lyons, Principal at R.I.S.C.
Lessons to Be Learned from Corporate Defense Management Failures
This presentation is broader in scope than the others. Rather than the simple 3LD model focused on banks and insurers, he uses an approach he calls "corporate defense." He spent a great deal of time going over this theory, most of which is easy to follow either from the presentation (which can be found here: http://www.ermsymposium.org/2013/seminars.php) or from his video (on YouTube.) The key aspect is that there are many, many dimensions of risk management, and they must go top-to-bottom over the entire firm *and* horizontally across business functions. He also encourages viewing stakeholders in an incredibly broad way (to the point that the definition almost becomes meaningless); he includes shareholders, employees, management, regulators, customers, suppliers, and society at large.
He spent some time recapping the well known problems with AIG, JPM/Chase, and BP. He characterizes the problem at AIG as "only Hank Greenberg knew the big picture" when it came to the risks of the firm. As a result, AIG had lots of small failures that had big consequences. [KR: By the way, I highly recommend The AIG Story, especially for you hard-core capitalists out there.]
I question his analysis of BP. His assumption is that, since the report following Deepwater Horizon contained suggestions, it meant BP had total deficiencies or failures in those areas. However I can't imagine someone be sent in to analyze what went wrong with Deepwater coming back with "nothing, everything was fine." Obviously *something* went wrong, but there are such things as freak accidents. As far as I can tell, there were no obvious failures that lead up to the disaster, just a highly unfortunate series of events.
Honestly I failed to see the point of much of this presentation. There was no real explanation as to what could have actually prevented these disasters. How do you engage in corporate defense when you don't know what you're defending against? This is a recurring question for ERM, in my opinion. Are we supposed to just sit down with everyone in the firm and try to list all the risks? That is literally the approach we currently take, but it seems doomed to failure: the risk that kills you will end up being the one you didn't see coming. What about the alternative idea of trying to build an organization that is flexible and responsive, so that when risks emerge, it's essentially able to either dodge them or lessen the effects?
End Part 5.
A young actuary's quest to determine causation, conquer risk, and quantify everything
Monday, April 22, 2013
Three Lines of Defense Part 4
"Three Lines of Defense," Part 4
Presenter 4: Stephan Schenk, EVP and Head of Operational Risk Management at TD Bank
Implementing the 3LD Model in Banks
Interesting note: he doesn't agree that smaller firms can't do as much risk governance. He points out that smaller firms have smaller, simpler operations, and consequently their risks will be manageable by a small risk function.
He also contradicts the 3LD model to some extent. In a steady state, he agrees that the 1st line of defense should be the largest, then the 2nd, then the 3rd, and that all business functions should roll up into the risk management function. However if a firm is in crisis or after a major change like a merger, the opposite holds. The reason is that when the business is in turmoil, you need to put people who know that business in charge of solving the problem. The risk people are not the preferred resource in that case. So the risk governance function needs to be flexible enough to adapt to the needs of the business, that is, a crisis response process is required.
He notes that the second line of defense has an inherent weakness is that it will never be able to duplicate the expertise in the first line.
He advocates "inverting" the 3LD in this way, then, for new firms/recently merged firms.
Regarding operational risk, he views this as a major weak point. Predictive power in this area has been very low. Until something better is developed, his advice is to be ready for anything. One promising avenue is to conduct "near miss" analyses as opposed to just actual crises. He also notes that the key risk indicators we're all so fond of are more (really only) valuable in combination, rather than individually.
His final word of advice is to approach regulators as if they are customers. The aim is to build long-term relationships and earn their trust.
End Part 4.
Presenter 4: Stephan Schenk, EVP and Head of Operational Risk Management at TD Bank
Implementing the 3LD Model in Banks
Interesting note: he doesn't agree that smaller firms can't do as much risk governance. He points out that smaller firms have smaller, simpler operations, and consequently their risks will be manageable by a small risk function.
He also contradicts the 3LD model to some extent. In a steady state, he agrees that the 1st line of defense should be the largest, then the 2nd, then the 3rd, and that all business functions should roll up into the risk management function. However if a firm is in crisis or after a major change like a merger, the opposite holds. The reason is that when the business is in turmoil, you need to put people who know that business in charge of solving the problem. The risk people are not the preferred resource in that case. So the risk governance function needs to be flexible enough to adapt to the needs of the business, that is, a crisis response process is required.
He notes that the second line of defense has an inherent weakness is that it will never be able to duplicate the expertise in the first line.
He advocates "inverting" the 3LD in this way, then, for new firms/recently merged firms.
Regarding operational risk, he views this as a major weak point. Predictive power in this area has been very low. Until something better is developed, his advice is to be ready for anything. One promising avenue is to conduct "near miss" analyses as opposed to just actual crises. He also notes that the key risk indicators we're all so fond of are more (really only) valuable in combination, rather than individually.
His final word of advice is to approach regulators as if they are customers. The aim is to build long-term relationships and earn their trust.
End Part 4.
Three Lines of Defense Part 3
"Three Lines of Defense," Part 3
Presenter 3: Bogie Ozdemir
Implementing 3LD Model in Insurance Companies
Need to clearly define the line between the first line and second line. Second line needs to have no gaps and no overlaps, e.g., between actuarial, legal, HR, etc.
Example: credit risk management
First line: business group CEO and delegates, investments, ALM, and Hedging
Second line: business group risk officers, Chief Market Risk Office, back offic
Example: actuarial function
Not clear between 1st and 2nd line. Who is responsible for what between the actuarial function and the risk function? In his company, the Chief Actuary reports to the CRO
In general, there is no fully implemented 3LD that he's aware of.
One interesting thing he mentioned is that his company has a model validation unit, separate from the people who create the models. He also discussed the need for subject-level experts in this control/review process.
Apparently there's a debate as to whether 3LD applies to the finance department or not. Of course, ORSA is a second-line response, and finance plays a key role in ORSA.
Overall, he characterizes 3LD as a capital-optimization problem: capital is allocated by the 2nd line, risk is taken by the first line. The trick is to coordinate the two such that shareholder value is maximized.
End Part 3.
Presenter 3: Bogie Ozdemir
Implementing 3LD Model in Insurance Companies
Need to clearly define the line between the first line and second line. Second line needs to have no gaps and no overlaps, e.g., between actuarial, legal, HR, etc.
Example: credit risk management
First line: business group CEO and delegates, investments, ALM, and Hedging
Second line: business group risk officers, Chief Market Risk Office, back offic
Example: actuarial function
Not clear between 1st and 2nd line. Who is responsible for what between the actuarial function and the risk function? In his company, the Chief Actuary reports to the CRO
In general, there is no fully implemented 3LD that he's aware of.
One interesting thing he mentioned is that his company has a model validation unit, separate from the people who create the models. He also discussed the need for subject-level experts in this control/review process.
Apparently there's a debate as to whether 3LD applies to the finance department or not. Of course, ORSA is a second-line response, and finance plays a key role in ORSA.
Overall, he characterizes 3LD as a capital-optimization problem: capital is allocated by the 2nd line, risk is taken by the first line. The trick is to coordinate the two such that shareholder value is maximized.
End Part 3.
Three Lines of Defense Part 2
"Three Lines of Defense," Part 2
Presenter 2: Dr. Colin Lawrence, Bank of England
Risk, Control, and Culture: the Regulatory Approach
"We've become risk measurers rather than risk managers."
Failure of risk managers was to just measure VaR, without recognizing the context in which it was used. The first question should be "Is the business model sustainable."
"4th line of defense: the regulator." Concern for regulators is the safety and health of the entire financial system, *not* the particular firm.
Focus now is on the biggest risks to failure, whereas it used to be on dozens of different risks. Regulators used to have some tolerance for failure, but now it's zero tolerance.
The Bank of England is doing all these controls, but why aren't other firms doing this? Bank and insurers? Reason is an enormous moral hazard problem: when people are compensated for taking risks. Argument that regulators are needed to enforce risk governance.
Prior to 1960, banks made a stable 7%. When Nixon went off the gold standard, ROR went up to 20%, but with a great deal more volatility (almost 4x). Leverage went crazy. Securities became prevalent. "Re-aging" or "forbearance" might be good as a social value, but you need to build up reserves for the risk of default. Accounting conventions don't require this until there's an actual trigger of default.
Bank of England study on bank data: Found 85% of losses were from structured finance, distributed evenly between trading book and banking book. Bias to record profit in trading book and losses in banking book to avoid disclosing mark-to-market losses. Also note that all banks were essentially in the same investment market: real estate.
This tells us where reforms need to be made structurally. The branch model causes a lot of problems due to perverse incentives for branch managers. None of the governance discussed in the prior presentation were in place. He blames this on a principal agent problem: don't want to disclose, don't want to know.
Lack of IT integration means poor data. Poor data means poor risk management. Good data management needs to be understood and accepted as an essential part of the business - it's a cost of doing business. Book "Why People Cheat" by behavioral economist Dan Ariely talks about how people become institutionalized into not reporting thoroughly and promptly. [KR: I believe he means this book.]
Boards are not in a position to really do their jobs. Most Boardmembers are on multiple Boards; it's not possible that they are able to really understand everything they need to in order to do their jobs. Which firms did well? Mostly those with Boards that are on top of things. Setting limits doesn't actually help; banks just move things around to achieve the ROE in "limit arbitrage." He also notes that controllers are often ignored (and paid very little compared to those taking the risks.)
See slide 13 for a list of what he as a regulator wants each firm to demonstrate to him. Particularly interesting point to me is the emphasis on counter-cyclical resilience. Strikes me as highly applicable to insurance.
Because regulators will no longer tolerate failures, it's important that firms understand the conditions under which they will be resolved. *Not* looking at static values, *not* accounting values. Dynamic analysis of market values under many scenarios. "Ring fencing" means isolating certain business segments or units when things go south. "Contingent capital": regulator decides when it becomes a put option rather than the investor.
Recommends having a diverse jury on the Risk Committee.
Slide 23 shows how they did the bailout in UK. Notes the poor econometrics (he went to UChicago; hurray Maroons!)
End Part 2.
Presenter 2: Dr. Colin Lawrence, Bank of England
Risk, Control, and Culture: the Regulatory Approach
"We've become risk measurers rather than risk managers."
Failure of risk managers was to just measure VaR, without recognizing the context in which it was used. The first question should be "Is the business model sustainable."
"4th line of defense: the regulator." Concern for regulators is the safety and health of the entire financial system, *not* the particular firm.
Focus now is on the biggest risks to failure, whereas it used to be on dozens of different risks. Regulators used to have some tolerance for failure, but now it's zero tolerance.
The Bank of England is doing all these controls, but why aren't other firms doing this? Bank and insurers? Reason is an enormous moral hazard problem: when people are compensated for taking risks. Argument that regulators are needed to enforce risk governance.
Prior to 1960, banks made a stable 7%. When Nixon went off the gold standard, ROR went up to 20%, but with a great deal more volatility (almost 4x). Leverage went crazy. Securities became prevalent. "Re-aging" or "forbearance" might be good as a social value, but you need to build up reserves for the risk of default. Accounting conventions don't require this until there's an actual trigger of default.
Bank of England study on bank data: Found 85% of losses were from structured finance, distributed evenly between trading book and banking book. Bias to record profit in trading book and losses in banking book to avoid disclosing mark-to-market losses. Also note that all banks were essentially in the same investment market: real estate.
This tells us where reforms need to be made structurally. The branch model causes a lot of problems due to perverse incentives for branch managers. None of the governance discussed in the prior presentation were in place. He blames this on a principal agent problem: don't want to disclose, don't want to know.
Lack of IT integration means poor data. Poor data means poor risk management. Good data management needs to be understood and accepted as an essential part of the business - it's a cost of doing business. Book "Why People Cheat" by behavioral economist Dan Ariely talks about how people become institutionalized into not reporting thoroughly and promptly. [KR: I believe he means this book.]
Boards are not in a position to really do their jobs. Most Boardmembers are on multiple Boards; it's not possible that they are able to really understand everything they need to in order to do their jobs. Which firms did well? Mostly those with Boards that are on top of things. Setting limits doesn't actually help; banks just move things around to achieve the ROE in "limit arbitrage." He also notes that controllers are often ignored (and paid very little compared to those taking the risks.)
See slide 13 for a list of what he as a regulator wants each firm to demonstrate to him. Particularly interesting point to me is the emphasis on counter-cyclical resilience. Strikes me as highly applicable to insurance.
Because regulators will no longer tolerate failures, it's important that firms understand the conditions under which they will be resolved. *Not* looking at static values, *not* accounting values. Dynamic analysis of market values under many scenarios. "Ring fencing" means isolating certain business segments or units when things go south. "Contingent capital": regulator decides when it becomes a put option rather than the investor.
Recommends having a diverse jury on the Risk Committee.
Slide 23 shows how they did the bailout in UK. Notes the poor econometrics (he went to UChicago; hurray Maroons!)
End Part 2.
Three Lines of Defense Part 1
Workshop day. Looks like about 75 people in attendance, and we have six presenters.
Webpage for this day’s sessions: http://www.ermsymposium.org/2013/seminars.php
"The Three Lines of Defense," Part 1
Story about attempts to transfer accountability: manager asks internal audit to review the risk governance process he uses, thus making audit responsible. This is typical behavior from the first line of defense. Accountability in the first line is weak. Ultimately it's management's self-assessment. The Board is the check on this, and they need to review *and* challenge management's assumptions.
"6 is less than 3" - really sees 6 lines of defense, but doesn't say this because people think 6 is overwhelming compared to 3. Part of the reason why he sees 6 as being less than 3 is that he believes the third line of defense can downsize significantly. They are given the most resources, but this enables the first and second lines to rely on the third line instead of doing their jobs.
Story: company that kept hiring more internal auditors every time there was a risk event. Company of a few thousand ended up with 160 internal auditors. It didn't make a difference: the risk crises continued. CEO decided to make a change to the risk culture. He reduced audit back to 3 people, added 2 risk managers, and changed compensation to reflect risk accountability for execs. Number of risk events shrunk dramatically as a result, despite fewer resources allocated to risk management.
Risk management's job is *not* to set limits. Risk management creates the system that guides the setting of limits.
Risk taking structure: Board (oversight, approval) -> Executive Management Committee (ultimate responsibility, select risk appetite) -> Business Functional Head -> Business Leadership Groups (setting limits) -> Individual Risk Takers
Story: dominant CEO of insurer ignored Board and others and elected not to hedge. Lost 90% of market cap when stock market declined. They had an "Audit and Risk Committee," where risk was an add-on and not really understood. Everything that went to the Board went through CEO as well.
My question for him: CEOs change. Do you really have to revamp your risk governance every time your CEO changes? Answer: Yes, to the extent that is required with the particular CEO, *but* the principles of risk management for the firm should not change with the CEO. Principles remain constant, but the system needs to change to accommodate the personalities involved. [KR: this is interesting to me, the potential psychological angle to qualitative ERM.]
"Doers and checkers" - how his friend (actuary and CRO of reinsurer) describes the 6 line process.
Note that not all checkers would be full-time. Large banks have full-time staff doing model validation, but most likely for policy review, you wouldn't hire someone just for that. The key is for the checker to be competent and independent.
Business case for effective risk governance: it's about improving the odds when taking risks. Reduce surprises, optimize risk/return, improve shareholder value.
He believes it's a bad idea to have the CEO also be the Chairman of the Board or President.
My question for him: What's a small firm to do? How do you find competent, independent checkers? Answer: Smaller firms are limited in what they can do. Priority should be putting accountability with the risk taker. Remember that the principles would still remain the same.
My question for him: What if risk appetite is high to the point that perhaps you *want* the CEO to run wild? Answer: There is a limit to the risk your capital can absorb, regardless of your risk appetite. Risk appetite is deciding how close to that limit you're willing to go. Even if you are willing to go all the way to the limit, risk governance will still be needed to monitor and control *that* limit.
End Part 1
Webpage for this day’s sessions: http://www.ermsymposium.org/2013/seminars.php
Mostly
insurers in attendance, 15% consultants, and a smattering of banks.
Most insurers in attendance say they are implementing this idea to some
extent.
Intro (Alexander Shipilov):
“Three lines” was originally just a metaphor, but regulators adopted
it, so it stuck. There is a group on LinkedIn, “3 Lines of Corporate Defense,” where
you can go to continue the discussion and ask more questions. He recommends joining the group if you have an interest.
Presenter 1: Leon Bloom, Sr. Partner at Deloitte
Risk Governance: evolving beyond the traditional “three lines of defense” model
He sees the
financial crisis as caused by failure of risk governance. Regulators,
investors, and analysts are now focused in this area, making this a hot
topic. Firms that have adopted this approach have been more resilient.
Risk governance is the system for controlling the management of risk. It
involves roles, authority, responsibility, and information. Currently
seen as a gap area for the industry. The 3 line model is sound in theory but hasn’t been
sound in application; consequently it needs to evolve.
6 key issues for global financial institutions: capital,
liquidity, economy (US debt at all-time high, Euro insolvency, etc; very bad timing for all these problems),
operations (reducing costs), M&A, risk governance
“There will be winners and there will be losers...the winners with be those with the best handle on risk management.”
He has concerns about regulation becoming very prescriptive, getting the way of actual effectiveness.
Four
priority areas for regulation: inherent riskiness of the business
model, tail risk, pricing, risk governance (audit function =! risk
governance)
Story: Northern
Rock- successful institution, ROC was good, etc., but didn’t recognize that it was
heavily dependent on two sources for funding: mortgage-backed securities
and issuing short-term commercial paper. Liquidity dried up overnight. 9
weeks before they collapsed, their ORSA-equivalent had two paragraphs
on liquidity (and regulator signed off). Entire business model was
dependent on liquidity; plenty of capital, but that didn't matter.
Pricing hasn’t been sensitive to risk historically (and regulators blind to it).
Lack
of clarity around ownership of risk by the first line of defense -
failure of risk governance. Those who take the risks should be
accountable, rather than use the second and third lines as a management
control. [KR: this was the main emphasis of his presentation.]
“...as we continue to move through the financial crisis” - emphatic about this: it’s not over.
“Risk
people” should *never* own risk; ownership of risk should fall as close to the origin
of the risk as possible. The person taking the risk should own it.
“Risk management’s” job is *not* to manage risk; its job is to create
systems, policies, and support to guide the risk owner. Accountability
needs to be accompanied by authority.
Emerging
risk governance requirements: governance, closer alignment of risk and
business considerations, holistic risk governance approach.
Challenges: he lists a number, but the most interesting to me was the point that the objectives and target end-state for ERM are unclear.
Aside on Dodd-Frank:
it was passed in a hurry, with too many complex, confusing requirements. He doesn’t
think it’s going to help, and he expects it will be thrown out and replaced eventually.
Guiding
principles - see slide 8. Risk has been taken based on CEO personality (ability to intimidate the Board);
establishing principles can help keep that from happening.
Story: 12
months ago in UK a trader was sentenced to 12 year prison for losing 2b
lbs. He knew all the risk governance policies, but his boss told him to ignore it. This is the
operating culture versus the risk governance.
“The operating culture is
what goes on when no one’s looking.” - this is the other major take-away from this presentation.
Evolution
of the ‘lines of defense model’: “Roles, responsibilities,
accountabilities, authority, design, and information” (see graphic, slide 11)
Maturity
levels (of a firm's risk governance): unaware, fragmented, integrated, comprehensive, optimized.
Small organizations do too little, large can do too much (bureaucratic.)
"6 is less than 3" - really sees 6 lines of defense, but doesn't say this because people think 6 is overwhelming compared to 3. Part of the reason why he sees 6 as being less than 3 is that he believes the third line of defense can downsize significantly. They are given the most resources, but this enables the first and second lines to rely on the third line instead of doing their jobs.
Story: company that kept hiring more internal auditors every time there was a risk event. Company of a few thousand ended up with 160 internal auditors. It didn't make a difference: the risk crises continued. CEO decided to make a change to the risk culture. He reduced audit back to 3 people, added 2 risk managers, and changed compensation to reflect risk accountability for execs. Number of risk events shrunk dramatically as a result, despite fewer resources allocated to risk management.
Risk management's job is *not* to set limits. Risk management creates the system that guides the setting of limits.
Risk taking structure: Board (oversight, approval) -> Executive Management Committee (ultimate responsibility, select risk appetite) -> Business Functional Head -> Business Leadership Groups (setting limits) -> Individual Risk Takers
Story: dominant CEO of insurer ignored Board and others and elected not to hedge. Lost 90% of market cap when stock market declined. They had an "Audit and Risk Committee," where risk was an add-on and not really understood. Everything that went to the Board went through CEO as well.
My question for him: CEOs change. Do you really have to revamp your risk governance every time your CEO changes? Answer: Yes, to the extent that is required with the particular CEO, *but* the principles of risk management for the firm should not change with the CEO. Principles remain constant, but the system needs to change to accommodate the personalities involved. [KR: this is interesting to me, the potential psychological angle to qualitative ERM.]
"Doers and checkers" - how his friend (actuary and CRO of reinsurer) describes the 6 line process.
Note that not all checkers would be full-time. Large banks have full-time staff doing model validation, but most likely for policy review, you wouldn't hire someone just for that. The key is for the checker to be competent and independent.
Business case for effective risk governance: it's about improving the odds when taking risks. Reduce surprises, optimize risk/return, improve shareholder value.
He believes it's a bad idea to have the CEO also be the Chairman of the Board or President.
My question for him: What's a small firm to do? How do you find competent, independent checkers? Answer: Smaller firms are limited in what they can do. Priority should be putting accountability with the risk taker. Remember that the principles would still remain the same.
My question for him: What if risk appetite is high to the point that perhaps you *want* the CEO to run wild? Answer: There is a limit to the risk your capital can absorb, regardless of your risk appetite. Risk appetite is deciding how close to that limit you're willing to go. Even if you are willing to go all the way to the limit, risk governance will still be needed to monitor and control *that* limit.
End Part 1
Saturday, April 20, 2013
2013 ERM Symposium
This year, for the first time, I will be attending the ERM Symposium in Chicago. Not only will this be a great opportunity to learn more about ERM, it will also be a chance to network, enjoy some time in one of my favorite cities, and get some efficient "hotel study time" in (I admit, I'm extra excited that the conference is being held at Swissotel, a hotel at which I've long wanted to stay.)
Since I've been so lax in posting, I am going to compensate by live-blogging all of the sessions I'm attending. Stay tuned!
Since I've been so lax in posting, I am going to compensate by live-blogging all of the sessions I'm attending. Stay tuned!
Friday, April 5, 2013
Future Fellows
Since I have little time for blogging these days (a good thing- work is very busy and very rewarding), I'd like to draw your attention to my most recent article in Future Fellows. If you don't already read this publication regularly, I highly recommend it, even for non-exam takers. It's really the main source of information on the admissions process. We even publish articles and commentary directly from the Exam Committee itself, which are often very illuminating.
Check it out:
http://www.casact.org/newsletter/index.cfm?fa=ff
My article, a short humor piece which is very appropriate for exam season, can be found here:
http://www.casact.org/newsletter/index.cfm?fa=viewart&id=6523
As always, let me know if any candidates out there would like to see articles on any particular topics in the future.
Good luck this sitting!
Katrina
Check it out:
http://www.casact.org/newsletter/index.cfm?fa=ff
My article, a short humor piece which is very appropriate for exam season, can be found here:
http://www.casact.org/newsletter/index.cfm?fa=viewart&id=6523
As always, let me know if any candidates out there would like to see articles on any particular topics in the future.
Good luck this sitting!
Katrina
Subscribe to:
Posts (Atom)