EIOPA published the strategies for cyber underwriting and supervisory technology (suptech), in response to the evolving insurance landscape. Also published was the Supervisory Convergence Plan for 2020, which sets out priorities and activities for the coming year. The convergence plan builds on the work of the previous year while incorporating new priorities to reflect new trends and emerging risks. The three new priorities that have been identified for supervisory convergence for 2020 are the development of suptech solutions, promotion of assessment and mitigation tools to address potential systemic cyber and extreme risks; and identification and monitoring of supervisory risks in the authorization of cross-border institutions for occupational retirement provision (IORPs) to develop appropriate supervisory responses.
EIOPA is of the view that appropriate cyber insurance coverage, underwriting practices, and sound supervision can make a valuable contribution for people, businesses, and economies to manage cyber risk. Thus, EIOPA will undertake specific actions as part of its own supervisory and regulatory priorities as well as in its capacity as a facilitator and catalyst to provide advice on cyber insurance. These actions include periodic assessment and supervision of cyber underwriting and risk management; further investigation into the issue of non-affirmative cyber exposures and accumulation of risk; inclusion of scenarios related to cyber risk events and incidents in the stress testing framework; and working with partners to explore and promote the development of a harmonized cyber incident reporting taxonomy.
The suptech strategy of EIOPA aims to facilitate the establishment of a mid- and long-term coordinated plan for development of suptech-based supervisory tools and processes, in line with the strategic objective and annual supervisory convergence plans. The strategy covers both prudential and conduct of business supervision, policy, and interaction with entities, for insurance and occupational pensions sectors. In 2020, the InsurTech Task Force of EIOPA is also expected to work on the regtech field—that is, the application of new technologies for regulatory and compliance requirements by the undertakings. Intrapreneurship programs have been promoted to identify and develop specific tools by the national competent authorities. Supervisors
were invited to present ideas to improve the efficiency and/or effectiveness of their work. Some projects have been chosen and are under development. In the area of improving supervisory processes and the use of data, both quantitative and qualitative, some of the following examples may be identified:
- Text analysis tool to compare the Solvency and Financial Condition Reports (SFCRs) published with the Quantitative Reporting Templates, including sentiment analysis in both to assess differences
- Structure prospects and yearly reports by using machine learning mechanism from unstructured documents
- Text mining or analysis of narrative data with natural language processing to support the use of qualitative information like Own Risk and Solvency Assessment and SFCR, but also from data on authorizations and other publicly available sources
- Smart search engine to access relevant information during on-site supervision activities
- Monitor social media data to capture consumer sentiment and identify informal complaints, based on a third-party and APIs, then build programs to do the analytics
- Search tool among regulatory, methodology, and doctrine texts relevant to the business of the national competent authorities, developing a relevant content navigation and visualization system that will rely on Text Mining algorithms
- Exploit, through artificial intelligence, the thousands of judicial decisions rendered each year against banking and insurance professionals to guide the supervisory actions of national competent authorities
- The use of machine learning techniques to improve data quality and data analytics through supervised and unsupervised learning. Clustering, outlier detection, identification of patterns, and trends are some examples
- A new financial supervision tool based on predictive analytics that can make sense of a growing set of available data
- Press Release on Cyber Underwriting and Suptech Strategies
- Cyber Underwriting Strategy (PDF)
- Suptech Strategy (PDF)
- Press Release on Supervisory Convergence Plan
- Supervisory Convergence Plan (PDF)
Keywords: Europe, EU, Insurance, Cyber Underwriting, Suptech, Cyber Risk, SREP, Regtech, Fintech, Solvency II, EC, EIOPA
Previous ArticleECB Presents Benchmarking Analysis of Recovery Plans of Banks
The European Commission (EC) published the Delegated Regulation 2022/786 with regard to the liquidity coverage requirements for credit institutions under the Capital Requirements Regulation (CRR).
The European Banking Authority (EBA) published the final draft regulatory technical standards specifying the criteria to identify shadow banking entities for the purposes of reporting large exposures.
The European Insurance and Occupational Pensions Authority (EIOPA) published a report assessing insurers' exposure to physical climate change risks
The European Commission (EC) published the results of a public consultation, held in October 2021, on the review of the Web Accessibility Directive.
The Network for Greening the Financial System (NGFS) published two reports to aid central banks and regulators in their oversight of the financial sector and in their central bank operations
The Monetary Authority of Singapore (MAS) and the SC-STS are jointly consulting, until June 10, 2022, on setting adjustment spreads for the conversion of legacy SOR contracts to SORA reference rate.
The Office of the Superintendent of Financial Institutions (OSFI) published the strategic plan for 2022-2025 and the departmental plan for 2022-23.
The European Banking Authority (EBA) is consulting, until August 31, 2022, on the draft implementing technical standards specifying requirements for the information that sellers of non-performing loans (NPLs) shall provide to prospective buyers.
The European Council and the Parliament reached an agreement on the revised Directive on security of network and information systems (NIS2 Directive).
The European Banking Authority (EBA) published the final draft regulatory technical standards specifying information that crowdfunding service providers shall provide to investors on the calculation of credit scores and prices of crowdfunding offers.