January 30, 2019

PRA published a letter that presents the key themes that emerged from its survey on cyber insurance underwriting risk. This letter from Anna Sweeney, Director of Insurance Supervision, is addressed to the Chief Executives of specialist general insurance firms.

In July 2017, PRA had published the supervisory statement SS4/17 on cyber insurance underwriting risk. SS4/17 set out the PRA expectations for insurers on the prudent management of cyber underwriting risk in the areas of actively managing non-affirmative cyber risk; setting clearly defined cyber strategies and risk appetites that are agreed by the board; building and continuously developing insurer cyber expertise. In May 2018, and after discussing with industry associations and Lloyd’s, PRA conducted a follow-up survey involving firms of varying size. This letter provides feedback on the key themes that emerged from firms’ responses and describes areas inn which the PRA thinks that firms can do more to ensure the prudent management of cyber risk exposures.

The survey results suggest that although some work has been done, more ground needs to be covered by firms especially in relation to non-affirmative cyber risk management, risk appetite, and strategy. Having reviewed the responses of firms, PRA also believes that the expectations set out in SS4/17 are relevant and valid. SS4/17 set out the PRA expectations that firms should:

  • Robustly assess and effectively manage their insurance products with specific consideration to non-affirmative cyber risk exposure
  • Monitor their aggregate cyber underwriting exposure and conduct underwriting risk stress tests that explicitly consider the potential for loss aggregation (in case of firms writing affirmative cyber products)
  • Consider cyber underwriting risk stress tests with consideration given to loss aggregation at extreme return periods (up to 1 in 200 years)

In the letter, PRA states that the responsibility is on firms to progress their work and fully align with the expectations set out in SS4/17. In relation to the expectation that firms reduce the unintended exposure to non-affirmative cyber risk, insurers should develop an action plan by the first half of 2019, with clear milestones and dates by which action will be taken. Supervisors may ask to review this plan and subsequent progress toward it. Over the rest of the year, PRA plans to undertake the following steps:

  • Provide further, targeted feedback to surveyed firms by arranging meetings with individual surveyed firms by the end of the first quarter of 2019
  • Coordinate with Lloyd’s to agree any follow-up actions in relation to Lloyd’s managing agents
  • Carry out sample deep-dive reviews to other firms (not necessarily those in the initial sample) in second half of 2019 to assess how these firms are meeting the expectations set out in SS4/17

 

Related Links

Keywords: Europe, UK, Insurance, Cyber Risk, Underwriting Risk, SS4/17, PRA

Related Articles
News

APRA Releases Minor Changes to Reporting Standards on SA-CCR for Banks

APRA released minor changes to the three reporting standards for the standardized approach for measuring counterparty credit risk exposures (SA-CCR).

May 22, 2019 WebPage Regulatory News
News

APRA Proposes to Amend Guidance on Residential Mortgage Lending

APRA is consulting on revisions to the prudential practice guide APG 223 on residential mortgage lending in Australia.

May 21, 2019 WebPage Regulatory News
News

ESAs Amend Technical Standards on Mapping of ECAIs Under CRR

ESAs published a second amendment to the implementing technical standards on the mapping of credit assessments of External Credit Assessment Institutions (ECAIs) for credit risk under the Capital Requirements Regulation (CRR).

May 20, 2019 WebPage Regulatory News
News

OCC Consults on Information Collection for Home Mortgage Disclosures

OCC is soliciting comment on the revision of the information collection titled “Regulation C—Home Mortgage Disclosure.” OCC also notes that it has sent the collection to OMB for review.

May 20, 2019 WebPage Regulatory News
News

EIOPA Updates Q&A on Regulations in May 2019

EIOPA published additional questions and answers (Q&A) on guidelines, directives, and regulations applicable to insurers in Europe.

May 17, 2019 WebPage Regulatory News
News

FSB Publishes Update on Meeting of RCG for Americas

FSB published a summary of the meeting of its Regional Consultative Group (RCG) in Americas.

May 17, 2019 WebPage Regulatory News
News

ESRB Paper on Impact of Business Model Similarities on Risk Capture

ESRB published a working paper on whether information contagion and business model similarities explain bank credit risk commonalities.

May 17, 2019 WebPage Regulatory News
News

CBM Notifies ESRB and ECB on Imposing Borrower-Based Measures in Malta

CBM notified ESRB and ECB regarding its decision to impose borrower-based measures on lenders in Malta.

May 17, 2019 WebPage Regulatory News
News

IASB Issues Work Plan and Meeting Updates for May 2019

IASB published an updated work plan, along with the update of its meeting in May 2019.

May 17, 2019 WebPage Regulatory News
News

FCA Publishes Its Business Plan for the Coming Year

FCA published its Business Plan, which sets out the main areas of focus and priorities for 2019/20.

May 17, 2019 WebPage Regulatory News
RESULTS 1 - 10 OF 3103