EIOPA published reports summarizing the work of the big data working group, the cyber insurance market group, and the insurer cybersecurity working group under the EU-U.S. Insurance Dialogue Project. The reports summarize the topics under discussion, work done in 2019, and the next steps for discussion and action. The EU-U.S. Insurance Project started in early 2012, when EC, EIOPA, NAIC, and FIO agreed to participate in a deeper dialog project to contribute to an increased mutual understanding and enhanced cooperation between the EU and U.S. to promote business opportunity and effective supervision in EU and U.S. The high-level common objectives of the EU-U.S. Insurance Dialogue are to promote the free flow of information between EU and U.S. supervisors, establish a robust regime for group supervision, achieve a consistent approach within each jurisdiction, and ensure the consistent application of prudential requirements.
The Big Data Working Group has been focusing on the increased use of large data sets (Big Data) by insurers and the use of data analytics in the insurance sector. After discussion, the Working Group has outlined the following areas for potential discussion in 2020/2021:
- The further development of artificial intelligence principles in the U.S. and EU including ethical aspects
- Regulatory review of predictive models, including but not limited to assessing transparency and explainability issues arising from the use of machine learning algorithms.
- Industry use of Big Data for fraud detection and claims settlement
- Continue monitoring developments on third-party vendors and consumer disclosure issues
The Cyber Insurance Working Group, in 2019, as a follow-up to the work done in 2018, continued discussions with a focus on the assessment of non-affirmative cyber risk and the potential for catastrophic losses; the challenges and opportunities of insuring and reinsuring cyber risk; and the availability of cyber insurance data. One of the main challenges to further development of the cyber insurance markets in the U.S. and EU relates to the limited data to appropriately assess and quantify cyber risk exposure. Against this background, themes for further elaboration may include the following:
- Discussing approaches to collect data and develop techniques supporting more sophisticated assessment of cyber risks. including potential accumulation risks (for example, scenario-based stress testing)
- Sharing U.S. and EU approaches relative to cyber incident reporting and cyber incident response best practices, including discussion of whether global initiatives could facilitate further understanding and underwriting of cyber risks
- Discussing the current role and use of risk
The Insurer Cybersecurity Working Group’s 2019 Target Outcome or deliverables included further discussions to continue to share examples and approaches to insurer cybersecurity and post-incident coordination Another outcome involved further discussions in moving forward with creating an outline or template for scenarios for an insurance supervisor-only exercise on how to coordinate a cross-border response in the event of an international cybersecurity incident. Insurance sector cybersecurity is a continuing challenge and a matter for ongoing supervisory focus in both the U.S. and EU. The Insurer Cybersecurity Working Group, therefore, recommends continuing its ongoing work in the following areas:
- Continue to share information on insurer cybersecurity and operational resilience including, for example, discussing insurance industry approaches to managing cybersecurity risk; supervisory approaches to reviewing insurers’ cybersecurity measures; the challenges of tracking cyber risks in the EU and the U.S.; preventing and managing a cross-border cyber event from both a supervisory and industry perspective; and the cybersecurity implications of insurers’ increased outsourcing to the cloud
- Complete development of an initial cybersecurity exercise template for EU and U.S. supervisors on how to coordinate a cross-border response in the event of an international cybersecurity incident
- Expand current draft scenario(s) in the template, including scenario timelines with a progression of events mimicking those likely during a real cybersecurity incident and include a list of supervisory contacts
- Develop a timeline for conducting an exercise using the template created by the working group
Keywords: Europe, Americas, EU, US, Insurance, Big Data, Artificial Intelligence, Machine Learning, Cyber Risk, Cyber Insurance, EIOPA
Previous ArticleEIOPA Finalizes Methodological Principles for Insurer Stress Testing
ECB published Guideline 2021/975, which amends Guideline ECB/2014/31, on the additional temporary measures relating to Eurosystem refinancing operations and eligibility of collateral.
EIOPA published a report, from the Consultative Expert Group on Digital Ethics, that sets out artificial intelligence governance principles for an ethical and trustworthy artificial intelligence in the insurance sector in EU.
HKMA published the seventh and final issue of the Regtech Watch series, which outlines the three-year roadmap of HKMA to integrate supervisory technology, or suptech, into its processes.
EC launched a targeted consultation to improve transparency and efficiency in the secondary markets for nonperforming loans (NPLs).
BIS, Danmarks Nationalbank, Central Bank of Iceland, Norges Bank, and Sveriges Riksbank launched an Innovation Hub in Stockholm, making this the fifth BIS Innovation Hub Center to be opened in the past two years.
FDITECH, the technology lab of FDIC, announced a tech sprint that is designed to explore new technologies and techniques that would help expand the capabilities of community banks to meet the needs of unbanked individuals and households.
EC released the EU Taxonomy Compass, which visually represents the contents of the EU Taxonomy starting with the EU Taxonomy Climate Delegated Act.
FDIC is seeking comments on a rule to amend the interagency guidelines for real estate lending policies—also known as the Real Estate Lending Standards.
EIOPA published its annual report, which sets out the work done in 2020 and indicates the planned work areas for the coming months.
The ESRB paper that presents an analytical framework that assesses and quantifies the potential impact of a bank failure on the real economy through the lending function.