Featured Product

    PRA Publishes Results of Survey on Cyber Insurance Underwriting Risk

    January 30, 2019

    PRA published a letter that presents the key themes that emerged from its survey on cyber insurance underwriting risk. This letter from Anna Sweeney, Director of Insurance Supervision, is addressed to the Chief Executives of specialist general insurance firms.

    In July 2017, PRA had published the supervisory statement SS4/17 on cyber insurance underwriting risk. SS4/17 set out the PRA expectations for insurers on the prudent management of cyber underwriting risk in the areas of actively managing non-affirmative cyber risk; setting clearly defined cyber strategies and risk appetites that are agreed by the board; building and continuously developing insurer cyber expertise. In May 2018, and after discussing with industry associations and Lloyd’s, PRA conducted a follow-up survey involving firms of varying size. This letter provides feedback on the key themes that emerged from firms’ responses and describes areas inn which the PRA thinks that firms can do more to ensure the prudent management of cyber risk exposures.

    The survey results suggest that although some work has been done, more ground needs to be covered by firms especially in relation to non-affirmative cyber risk management, risk appetite, and strategy. Having reviewed the responses of firms, PRA also believes that the expectations set out in SS4/17 are relevant and valid. SS4/17 set out the PRA expectations that firms should:

    • Robustly assess and effectively manage their insurance products with specific consideration to non-affirmative cyber risk exposure
    • Monitor their aggregate cyber underwriting exposure and conduct underwriting risk stress tests that explicitly consider the potential for loss aggregation (in case of firms writing affirmative cyber products)
    • Consider cyber underwriting risk stress tests with consideration given to loss aggregation at extreme return periods (up to 1 in 200 years)

    In the letter, PRA states that the responsibility is on firms to progress their work and fully align with the expectations set out in SS4/17. In relation to the expectation that firms reduce the unintended exposure to non-affirmative cyber risk, insurers should develop an action plan by the first half of 2019, with clear milestones and dates by which action will be taken. Supervisors may ask to review this plan and subsequent progress toward it. Over the rest of the year, PRA plans to undertake the following steps:

    • Provide further, targeted feedback to surveyed firms by arranging meetings with individual surveyed firms by the end of the first quarter of 2019
    • Coordinate with Lloyd’s to agree any follow-up actions in relation to Lloyd’s managing agents
    • Carry out sample deep-dive reviews to other firms (not necessarily those in the initial sample) in second half of 2019 to assess how these firms are meeting the expectations set out in SS4/17

     

    Related Links

    Keywords: Europe, UK, Insurance, Cyber Risk, Underwriting Risk, SS4/17, PRA

    Related Articles
    News

    FSB Sets Out Effective Practices for Cyber Incident Recovery

    FSB finalized the toolkit of effective practices to assist financial institutions in their cyber incident response and recovery activities.

    October 19, 2020 WebPage Regulatory News
    News

    HKMA Urges Early Action for Adherence to IBOR Fallbacks Protocol

    HKMA urged authorized institutions to take early action to adhere to the IBOR Fallbacks Protocol, which ISDA is expected to publish soon.

    October 16, 2020 WebPage Regulatory News
    News

    FSB Sets Out Roadmap for Transition to Alternative Reference Rates

    FSB published a global transition roadmap for London Inter-bank Offered Rate (LIBOR).

    October 16, 2020 WebPage Regulatory News
    News

    HM Treasury Publishes Response to Proposal on BRRD2 Transposition

    HM Treasury published a document that summarizes the responses received from a consultation on the approach of UK to transposition of the revised Bank Resolution and Recovery Directive (BRRD2).

    October 15, 2020 WebPage Regulatory News
    News

    HM Treasury Publishes Response to Proposal on CRD5 Transposition

    HM Treasury published the government response to the feedback received on the consultation for updating the prudential regime of UK before the end of the Brexit transition period.

    October 15, 2020 WebPage Regulatory News
    News

    BoE Publishes Reporting Schedule for Statistical Returns

    In a recent statistical notice, BoE announced publication of the reporting schedule for statistical returns for 2021.

    October 15, 2020 WebPage Regulatory News
    News

    EC Welcomes Declaration by Member States on EU Cloud Federation

    EC welcomed the joint declaration by 25 EU member states on building the next generation of cloud in Europe.

    October 15, 2020 WebPage Regulatory News
    News

    MAS Amends Notice on Issuance of Covered Bonds by Banks in Singapore

    MAS published amendments to Notice 648 on the issuance of covered bonds by banks incorporated in Singapore.

    October 15, 2020 WebPage Regulatory News
    News

    FDIC Selects Technology Companies for Rapid Prototyping Competition

    FDIC has selected 14 technology companies—including Accenture Federal Services, LLC, Fed Reporter, Inc, and S&P Global Market Intelligence, LLC—for inclusion in the next phase of the rapid prototyping competition.

    October 15, 2020 WebPage Regulatory News
    News

    GLEIF Defines New Validation Agent Role for Financial Institutions

    GLEIF announced that financial institutions worldwide can realize a variety of cost, efficiency, and customer experience benefits by assuming a new “validation agent” role within the Global Legal Entity Identifier (LEI) System.

    October 15, 2020 WebPage Regulatory News
    RESULTS 1 - 10 OF 5979