Risk Management and Internal Controls ASSAL 20 November 2014 Annick Teubner Chair, IAIS Governance Working Group.

Slides:



Advertisements
Similar presentations
Organizational Governance
Advertisements

ICP 20 Public Disclosure Yoshihiro Kawai IAIS-ASSAL Conference 22 April 2014.
IMFO Audit & Risk Indaba June 2012
SEMINAR NAIC/ASSAL/SVS REGULATION & SUPERVISION OF MARKET CONDUCT © 2014 National Association of Insurance Commissioners Overview and Purpose of Market.
Core principles in the ASX CGC document. Which one do you think is the most important and least important? Presented by Casey Chan Ethics Governance &
Development of internal control: methodology and responsibility
1 The critical challenge facing banks and regulators under Basel II: improving risk management through implementation of Pillar 2 Simon Topping Hong Kong.
The Development of Enterprise Risk Management and Supervision for Insurance Companies in Taiwan Dr. Huang, Tien-Mu Director General, Insurance Bureau Financial.
Introduction to Enterprise Risk Management (ERM)
Investments Institute of Insurance and Risk Management (IIRM) Hyderabad, India 15 November 2005 Arup Chatterjee – Advisor International Association of.
Executive Insight through Enhanced Enterprise Risk Management Leverage Value From Your Risk Management Investment.
Role of actuarial function supporting the FLAOR leading to the ORSA Ian Morris June 2014.
Corporate Governance of the Insurance companies
NAIC Review of ERM & Internal Controls David Altmaier Florida Office of Insurance Regulation.
UCSD Office of the Controller1 SAS112 Implementation UCSD Status Update.
Internal Control and Internal Audit
CORPORATE RISK MANAGEMENT & INSURANCE BY R P BLAH D.G.M. INCHARGE THE ORIENTAL INSURANCE COMPANY LIMITED REGIONAL OFFICE BHUBANESWAR.
“The Impact of Sarbanes Oxley, An Evolving Best Practice” Ellen C. Wolf Senior Vice President & Chief Financial Officer American Water National Association.
Corporate Governance in a Group Context
PAINTING THE FULL PICTURE
1 Solvency II Part 3: Other pillars Vesa Ronkainen Insurance Supervisory Authority, Finland
Corporate Governance in Financial Institutions OCDE/IAIS/ASSAL Conference on Insurance Regulation & Supervision in Latin America Punta Cana, Dominican.
Session No. 3 ICAO Safety Management Standards ICAO SMS Framework
Financial Services Board INSURANCE LAWS AMENDMENT BILL Jonathan Dixon Deputy Executive Officer: Insurance Financial Services Board Page 1.
Towards a systematic approach to credit union governance Paul A Jones PhD Research Unit for Financial Inclusion Financing the Future: Achieving Sustainable.
The role of internal audit in enterprise-wide risk management (ERM)
OECD Guidelines on Insurer Governance
AUDIT COMMITTEE PRACTICES THE SOUTH AFRICAN EXPERIENCE Presenter: Beerson Baboojee | National Treasury | 4 December 2014.
Annual Conference The Internal Auditor – value added to both the Audit Committee and Management 7 November 2012.
Corporate Governance: Basel II and Beyond Corporate Governance Program for Bank Directors of Indian Banks Mumbai December 14, 2005.
Consolidated Supervision: Managing the Risks in a Diversified Financial Services Industry Barbara Baldwin June 2001.
Building a Corporate Risk Culture Shane Troyer, CPA, CIA, CFE, CISSP Principal Operational Advisory Joost Houwen, CISA,
“ Heightened Expectations” for Corporate Governance AIBA 2 nd Annual Compliance Seminar June 14, 2012 Lester Miller, Senior International Advisor International.
 The quality and frequency of risk information for governing bodies varies significantly from firm to firm.  Where risk information is provided, performance.
IAEA International Atomic Energy Agency Reviewing Management System and the Interface with Nuclear Security (IRRS Modules 4 and 12) BASIC IRRS TRAINING.
System of Governance Articles 41 to 49 of Directive 2009/138/EC 11 th May 2010 Eamonn Henry.
Monitoring Internal Control Systems Johann Rieser Senior Auditor, Ministry of Finance, Vienna.
Internal Control in a Financial Statement Audit
Enterprise Risk Management Expectations Outpacing Capabilities and The Audit Committee’s Role July 30, 2013 Presented by: Suzette E. Ramsden (B.Sc., CISA,
How does the ECA assess Member States’ internal control systems? Workshop on Audit/Evaluation of Public Internal Financial Control Systems (PIFC) Ankara,
City of Tshwane GDS August Reputation promise/mission The Auditor-General of South Africa has a constitutional mandate and, as the Supreme.
International Auditing and Assurance Standards Board Communication with Those Charged with Governance ISA Implementation Support Module Prepared by IAASB.
Impact of the Financial Crisis and Lessons Learnt Impact of the Financial Crisis and Lessons Learnt Rob Curtis Regional Information Session, Cape Town.
Corporate Governance Yoshi Kawai Secretary General, IAIS IAIS-ASSAL Regional Seminar Buenos Aires, Argentina, November 2011 PUBLIC.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
APRA: Supervision Approach CPA Insurance Industry Symposium 20 th November, Keith Chapman General Manager Diversified Institutions Division.
1 Internal Audit. 2 Definition Is an independent activity established by management to examine and evaluate the organization’s risk management processes.
Divisional Chief Executives Supported by Divisional Risk Committees Executive Committee Group Chief Executive Group Functions Group Finance Director Group.
Internal Controls Christina Urias Managing Director – International Regulatory Affairs NAIC.
Audit Outcomes – PFMA 2007/08 Auditor-General 18 November 2008.
ICP 8 – Risk Management and Internal Controls Ekrem Sarper Vice Chair, Implementation Committee San Jose, Costa Rica.
Internal/External Audit and Internal Controls February 23, 2000 David Dudley Federal Reserve Bank of NY.
Kathy Corbiere Service Delivery and Performance Commission
December 29, 2010 Satyan Jambunathan Prudential requirements A Life industry perspective.
CAS Spring Meeting June 2007 Introduction to ERM …The Measurements, Quadrants, Tools, and Solutions Prof. Mark C. Vonnahme Fox Family Clinical Professor.
Approval of Financial Statements Shareholders Boards Audit Committee Bert Vos Russian Corporate Governance Roundtable Meeting November 2004.
The Use of Actuaries as Part of a Supervisory Model Michael Hafeman – Consultant World Bank May 2004.
Chapter 5 Evaluating the Integrity and Effectiveness of the Client’s Control Systems.
Linkage of Risk, Capital and Financial Management CAS Annual Meeting Aaron Halpert, ACAS, MAAA Leslie R. Marlo, FCAS, MAAA November 12, 2007 INSURANCE.
PROTECTING THE INTERESTS OF CONSUMERS OF FINANCIAL SERVICES Role of Supervisory Authorities Keynote Address to the FinCoNet Open Meeting 22 April 2016.
Key Financial Issues in the Audit Committees and Responsibilities of Governing Bodies Nigel Paul Director of Corporate Services, University of Edinburgh.
1 Vereniging van Compliance Officers The Compliance Function in Banks Amsterdam, 10 June 2004 Marc Pickeur CBFA CBFA.
Page 1 Own Solvency and Risk Assessment Jarl Kure Malta 9 April 2010.
AUDIT STAFF TRAINING WORKSHOP 13 TH – 14 TH NOVEMBER 2014, HILTON HOTEL NAIROBI AUDIT PLANNING 1.
Panel 6 IAIS Framework for Prudential Regulation
ENTERPRISE RISK MANAGEMENT IN THE CASE OF THE FINANCIAL SERVICE SECTOR
IIASA Governance Review
Regional Seminar on Reinsurance and Other Forms of Risk Transfer
An overview of Internal Controls Structure & Mechanism
Operational Risk Management
Presentation transcript:

Risk Management and Internal Controls ASSAL 20 November 2014 Annick Teubner Chair, IAIS Governance Working Group

Agenda Introduction Risk Management and Controls Why Risk governance and controls matter… Revision ICPs’: topics 2014 Implementation Risk Governance and controls in a group Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls 2

Risk management: quantitative and qualitative aspects Risk strategy Risk appetite Risk tolerance (ICP 16) Supervisory review (ICP 9) Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls 3 Risk culture Risk governance (ICPs 5, 7, 8)

Sound Risk Management and Controls need.. Clearly defined, documented risk strategy (Board approval); Clearly defined and embedded risk appetite; Proper allocation of responsibilities; Processes for identifying, assessing, monitoring, managing & reporting risks; Clear direction and leadership; Sound risk culture promoted; Strong and independent control functions -> Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls 4

Control Functions Add to the governance checks and balances and are a source of support for the Board in the fulfilment of its risk, compliance and control oversight duties. Control functions include: Risk Management, Compliance, Actuarial function, and Internal Audit. In order to function properly, Control Functions need:  Authority and status  Independence  Resources Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls 5

Why risk governance and controls matter? Many financial losses occurred due to lack of proper risk governance, risk management and internal controls. Examples of weaknesses: Lack of adequate management oversight and accountability, Failure to develop a strong control culture Inadequate recognition and assessment of risks Absence or failure of key control structures and activities Inadequate communication of information between different levels of management, especially the upward communication of problems Inadequate or ineffective audit programs and monitoring activities Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls 6

Trends 2014 Risk Governance Importance of a sound risk culture and risk appetite to drive risk management; Oversight of the implementation of the risk appetite and the risk appetite statement; Requirements for boards to establish an independent risk committee. Control Functions Not all 4 Control Functions always present No sufficient distinction between functions Lack of actuarial capacity or access to actuarial services Lack of controls on outsourcing of material functions Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls 7

Trends 2014 Supervisory review Assessments of risk management and internal controls not always regular, robust and comprehensive; Lack of pro-active assessments; only when problems are identified; Not always all control functions required; Not always assessment of resources, independence and authority of control functions; Lack of legislative powers with regard to control functions; Need to assess effectiveness of board oversight of risk. Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls 8

Effective risk management and controls To ensure effectiveness, need for more focus on: Supervisors: pro-active approach and regular, robust and comprehensive assessments. People > structures (risk culture) Importance of having independent control functions with sufficient authority and resources Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls 9

Risk Governance and Controls within a group Issues Paper: Approaches to group corporate governance; impact on control functions Risk Governance and Controls should be applied group-wide: at entity level and at group level; Inherent complexity of group requires a balance of powers and of interests at each level of the group; The governance framework of a group can vary: more centralised and more decentralised models. Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls 10

Centralised model Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls 11 Parent Subs INFORMATION

Decentralised model Coop Insurer Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls 12

Challenges in a centralised group Difficult for Control Functions at group level to monitor group- wide implementation; Control functions at entity level lacking authority or ability to take responsibility for group issues; Difficult to ensure: risk tolerance levels of the group take into account the risk tolerance capacity of entities; the group risk and compliance culture effective the example for all levels effective implementation of group governance requirements by all entities. Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls 13

Challenges in a decentralised group Ensure independence of Control Functions at entity level; Difficult for Control Functions at the group level to ascertain the extent to which the common approach of the group is being followed Difficult to ensure: risks are treated consistently across the group; group-wide risks are properly identified, aggregated and mitigated; A group-wide consistent risk culture in all entities. Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls 14

Risk management and compliance: some practices to address challenges Authority and responsibilities of key players group- wide; Group-wide direction and coordination; Consideration of both entity and group perspective Communication and information Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls 15

Control Functions: some practices to address challenges Authority and responsibilities of key players group- wide; Group-wide direction and coordination; Consideration of both entity and group perspective Communication and information Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls 16

Risk Governance and Controls within a group In any model good governance is achievable; Any model has its the challenges or risks; Case-by-case analysis needed; Balance between group-wide interests and interests of entity. Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls 17

Thank you for listening and contributing. Any questions? Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls 18

Annex ICP 8 and Standards Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls 19

ICP 8 Risk Management and Internal Controls Principle Statement: The supervisor requires an insurer to have, as part of its overall corporate governance framework, effective systems of risk management and internal controls, including effective functions for risk management, compliance, actuarial matters and internal audit. Proportionality applies 20 Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls

Systems for risk management and internal controls, including Control functions Standard 8.1 The supervisor requires the insurer to establish, and operate within, effective systems of risk management and internal controls. Standard 8.2 The supervisor requires the insurer to have effective control functions with the necessary authority, independence, and resources. Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls 21

Control Functions The supervisor requires the insurer to have an effective: risk management function capable of assisting the insurer to identify, assess, monitor, manage and report on its key risks in a timely way. (8.3) compliance function capable of assisting the insurer to meet its legal and regulatory obligations and promote and sustain a corporate culture of compliance and integrity. (8.4) actuarial function capable of evaluating and providing advice to the insurer regarding, at a minimum, technical provisions, premium and pricing activities, and compliance with related statutory and regulatory requirements. (8.5) internal audit function capable of providing the Board with independent assurance in respect of the insurer’s governance, including its risk management and internal controls. (8.6) Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls 22

Outsourcing Standard 8.7 The supervisor requires the insurer to retain at least the same degree of oversight of, and accountability for, any outsourced material activity or function (such as a control function) as applies to non-outsourced activities or functions. Annick Teubner - Assal Nov 2014 – Risk management and Internal Controls 23