EIOPA Publishes Supervisory Convergence Plan and Suptech Strategy
EIOPA published the strategies for cyber underwriting and supervisory technology (suptech), in response to the evolving insurance landscape. Also published was the Supervisory Convergence Plan for 2020, which sets out priorities and activities for the coming year. The convergence plan builds on the work of the previous year while incorporating new priorities to reflect new trends and emerging risks. The three new priorities that have been identified for supervisory convergence for 2020 are the development of suptech solutions, promotion of assessment and mitigation tools to address potential systemic cyber and extreme risks; and identification and monitoring of supervisory risks in the authorization of cross-border institutions for occupational retirement provision (IORPs) to develop appropriate supervisory responses.
EIOPA is of the view that appropriate cyber insurance coverage, underwriting practices, and sound supervision can make a valuable contribution for people, businesses, and economies to manage cyber risk. Thus, EIOPA will undertake specific actions as part of its own supervisory and regulatory priorities as well as in its capacity as a facilitator and catalyst to provide advice on cyber insurance. These actions include periodic assessment and supervision of cyber underwriting and risk management; further investigation into the issue of non-affirmative cyber exposures and accumulation of risk; inclusion of scenarios related to cyber risk events and incidents in the stress testing framework; and working with partners to explore and promote the development of a harmonized cyber incident reporting taxonomy.
The suptech strategy of EIOPA aims to facilitate the establishment of a mid- and long-term coordinated plan for development of suptech-based supervisory tools and processes, in line with the strategic objective and annual supervisory convergence plans. The strategy covers both prudential and conduct of business supervision, policy, and interaction with entities, for insurance and occupational pensions sectors. In 2020, the InsurTech Task Force of EIOPA is also expected to work on the regtech field—that is, the application of new technologies for regulatory and compliance requirements by the undertakings. Intrapreneurship programs have been promoted to identify and develop specific tools by the national competent authorities. Supervisors
were invited to present ideas to improve the efficiency and/or effectiveness of their work. Some projects have been chosen and are under development. In the area of improving supervisory processes and the use of data, both quantitative and qualitative, some of the following examples may be identified:
- Text analysis tool to compare the Solvency and Financial Condition Reports (SFCRs) published with the Quantitative Reporting Templates, including sentiment analysis in both to assess differences
- Structure prospects and yearly reports by using machine learning mechanism from unstructured documents
- Text mining or analysis of narrative data with natural language processing to support the use of qualitative information like Own Risk and Solvency Assessment and SFCR, but also from data on authorizations and other publicly available sources
- Smart search engine to access relevant information during on-site supervision activities
- Monitor social media data to capture consumer sentiment and identify informal complaints, based on a third-party and APIs, then build programs to do the analytics
- Search tool among regulatory, methodology, and doctrine texts relevant to the business of the national competent authorities, developing a relevant content navigation and visualization system that will rely on Text Mining algorithms
- Exploit, through artificial intelligence, the thousands of judicial decisions rendered each year against banking and insurance professionals to guide the supervisory actions of national competent authorities
- The use of machine learning techniques to improve data quality and data analytics through supervised and unsupervised learning. Clustering, outlier detection, identification of patterns, and trends are some examples
- A new financial supervision tool based on predictive analytics that can make sense of a growing set of available data
Related Links
- Press Release on Cyber Underwriting and Suptech Strategies
- Cyber Underwriting Strategy (PDF)
- Suptech Strategy (PDF)
- Press Release on Supervisory Convergence Plan
- Supervisory Convergence Plan (PDF)
Keywords: Europe, EU, Insurance, Cyber Underwriting, Suptech, Cyber Risk, SREP, Regtech, Fintech, Solvency II, EC, EIOPA
Featured Experts

Cassandra Hannibal
Life insurance actuary; risk management and economic capital specialist

Paul McCarney
Insurance product strategist; insurance domain expert; extensive experience developing risk assessment frameworks for insurers

Brian Robinson
Actuary; risk management specialist; corporate and capital modelling expert
Previous Article
ECB Presents Benchmarking Analysis of Recovery Plans of BanksRelated Articles
EBA Launches Stress Tests for Banks, Issues Other Updates
The European Banking Authority (EBA) launched the 2023 European Union (EU)-wide stress test, published annual reports on minimum requirement for own funds and eligible liabilities (MREL) and high earners with data as of December 2021.
EBA Proposes Standards for IRRBB Reporting Under Basel Framework
The European Banking Authority (EBA) proposed implementing technical standards on the interest rate risk in the banking book (IRRBB) reporting requirements, with the comment period ending on May 02, 2023.
FED Issues Further Details on Pilot Climate Scenario Analysis Exercise
The U.S. Federal Reserve Board (FED) set out details of the pilot climate scenario analysis exercise to be conducted among the six largest U.S. bank holding companies.
US Agencies Issue Several Regulatory and Reporting Updates
The Board of Governors of the Federal Reserve System (FED) adopted the final rule on Adjustable Interest Rate (LIBOR) Act.
ECB Issues Multiple Reports and Regulatory Updates for Banks
The European Central Bank (ECB) published an updated list of supervised entities, a report on the supervision of less significant institutions (LSIs), a statement on macro-prudential policy.
HKMA Keeps List of D-SIBs Unchanged, Makes Other Announcements
The Hong Kong Monetary Authority (HKMA) published a circular on the prudential treatment of crypto-asset exposures, an update on the status of transition to new interest rate benchmarks.
EU Issues FAQs on Taxonomy Regulation, Rules Under CRD, FICOD and SFDR
The European Commission (EC) adopted the standards addressing supervisory reporting of risk concentrations and intra-group transactions, benchmarking of internal approaches, and authorization of credit institutions.
CBIRC Revises Measures on Corporate Governance Supervision
The China Banking and Insurance Regulatory Commission (CBIRC) issued rules to manage the risk of off-balance sheet business of commercial banks and rules on corporate governance of financial institutions.
HKMA Publications Address Sustainability Issues in Financial Sector
The Hong Kong Monetary Authority (HKMA) made announcements to address sustainability issues in the financial sector.
EBA Updates Address Basel and NPL Requirements for Banks
The European Banking Authority (EBA) published regulatory standards on identification of a group of connected clients (GCC) as well as updated the lists of identified financial conglomerates.