EIOPA published reports summarizing the work of the big data working group, the cyber insurance market group, and the insurer cybersecurity working group under the EU-U.S. Insurance Dialogue Project. The reports summarize the topics under discussion, work done in 2019, and the next steps for discussion and action. The EU-U.S. Insurance Project started in early 2012, when EC, EIOPA, NAIC, and FIO agreed to participate in a deeper dialog project to contribute to an increased mutual understanding and enhanced cooperation between the EU and U.S. to promote business opportunity and effective supervision in EU and U.S. The high-level common objectives of the EU-U.S. Insurance Dialogue are to promote the free flow of information between EU and U.S. supervisors, establish a robust regime for group supervision, achieve a consistent approach within each jurisdiction, and ensure the consistent application of prudential requirements.
The Big Data Working Group has been focusing on the increased use of large data sets (Big Data) by insurers and the use of data analytics in the insurance sector. After discussion, the Working Group has outlined the following areas for potential discussion in 2020/2021:
- The further development of artificial intelligence principles in the U.S. and EU including ethical aspects
- Regulatory review of predictive models, including but not limited to assessing transparency and explainability issues arising from the use of machine learning algorithms.
- Industry use of Big Data for fraud detection and claims settlement
- Continue monitoring developments on third-party vendors and consumer disclosure issues
The Cyber Insurance Working Group, in 2019, as a follow-up to the work done in 2018, continued discussions with a focus on the assessment of non-affirmative cyber risk and the potential for catastrophic losses; the challenges and opportunities of insuring and reinsuring cyber risk; and the availability of cyber insurance data. One of the main challenges to further development of the cyber insurance markets in the U.S. and EU relates to the limited data to appropriately assess and quantify cyber risk exposure. Against this background, themes for further elaboration may include the following:
- Discussing approaches to collect data and develop techniques supporting more sophisticated assessment of cyber risks. including potential accumulation risks (for example, scenario-based stress testing)
- Sharing U.S. and EU approaches relative to cyber incident reporting and cyber incident response best practices, including discussion of whether global initiatives could facilitate further understanding and underwriting of cyber risks
- Discussing the current role and use of risk
The Insurer Cybersecurity Working Group’s 2019 Target Outcome or deliverables included further discussions to continue to share examples and approaches to insurer cybersecurity and post-incident coordination Another outcome involved further discussions in moving forward with creating an outline or template for scenarios for an insurance supervisor-only exercise on how to coordinate a cross-border response in the event of an international cybersecurity incident. Insurance sector cybersecurity is a continuing challenge and a matter for ongoing supervisory focus in both the U.S. and EU. The Insurer Cybersecurity Working Group, therefore, recommends continuing its ongoing work in the following areas:
- Continue to share information on insurer cybersecurity and operational resilience including, for example, discussing insurance industry approaches to managing cybersecurity risk; supervisory approaches to reviewing insurers’ cybersecurity measures; the challenges of tracking cyber risks in the EU and the U.S.; preventing and managing a cross-border cyber event from both a supervisory and industry perspective; and the cybersecurity implications of insurers’ increased outsourcing to the cloud
- Complete development of an initial cybersecurity exercise template for EU and U.S. supervisors on how to coordinate a cross-border response in the event of an international cybersecurity incident
- Expand current draft scenario(s) in the template, including scenario timelines with a progression of events mimicking those likely during a real cybersecurity incident and include a list of supervisory contacts
- Develop a timeline for conducting an exercise using the template created by the working group
Keywords: Europe, Americas, EU, US, Insurance, Big Data, Artificial Intelligence, Machine Learning, Cyber Risk, Cyber Insurance, EIOPA
Previous ArticleEIOPA Finalizes Methodological Principles for Insurer Stress Testing
EBA published an erratum for the technical package on phase 2 of the reporting framework 3.0.
MAS amended Notice 643A that addresses requirements for banks to prepare statements of exposures and credit facilities to related concerns or parties.
ECB has published, in the Official Journal of the European Union, the Guideline 2021/565 on the euro short-term rate (€STR) and this guideline amends the previous ECB Guideline 2019/1265.
EBA launched a consultation on the draft regulatory technical standards on the list of countries with an advanced economy for calculating the equity risk under the alternative standardized approach (FRTB-SA).
PRA is proposing, via CP7/21, the approach to implementing new requirements related to the specification of the nature, severity, and duration of an economic downturn in the internal ratings-based (IRB) approach to credit risk.
The UK government launched the Recovery Loan Scheme (RLS) as part of its continued COVID-19 support for UK businesses, as announced by HM Treasury on March 03, 2021.
FSB published a letter, from its Chair Randal K. Quarles, to the G20 Finance Ministers and Central Bank Governors, ahead of their virtual meeting on April 07, 2021.
OSFI issued a letter to the deposit-taking institutions issuing covered bonds and announced the unwinding of the temporary increase to the covered bond limit for deposit-taking institutions, effective immediately.
To support recovery from the COVID-19 crisis, EU has published two regulations to amend the securitization framework, as set out in the Securitization Regulation (2017/2402) and the Capital Requirements Regulation or CRR (575/2013).
HM Treasury announced that G7 Finance Ministers and Central Bank Governors met ahead of COP 26, the 2021 UN Climate Change Conference, and agreed on green agenda.