Charlotte Gerken of PRA Outlines Risk Management Work in Insurance
While speaking at the 24th Annual Financial CEO conference in London, Charlotte Gerken of PRA outlined the ongoing and upcoming policy work on insurance risk management. This includes a consultation paper on the prudent person principle and a supervisory statement on liquidity risk management. She also explained that PRA is thinking about capital treatment and reporting aspects in terms of addressing the cyber risk and is planning to issue a supervisory statement in the area of outsourcing and third-party risk management.
Ms. Gerken outlined the recent guidance issued and the work being in the area of liquidity management, highlighting that much of the response to complex or unmodelable risks is not quantitative but qualitative, which is the domain of the prudent person principle. In the context of Solvency II the prudent person principle sets high level, qualitative standards. Therefore, in response to increasing supervisory concerns, PRA published a consultation paper which sets out proposals for a supervisory statement that clarifies how PRA expects firms to implement the prudent person principle. PRA also published a supervisory statement on liquidity risk management for insurers and updated the existing supervisory statement on illiquid unrated assets to take into account increasing levels of investment in income-producing real estate. All three pieces of guidance concern fundamental risk management principles and how PRA expects firms to put them into practice.
She then discussed technology as the new source of risk and opportunity, highlighting the growing demand for cyber insurance. Solvency II does not mention cyber risk at all, so there is a space for firms—and regulators—to fill. However, the basic framework for dealing with these kinds of business risks is already well-established. PRA is looking at incorporating this relatively new risk into its existing approach. This means thinking about capital treatment and reporting and working with industry to facilitate a move to more explicit coverage, standardization of contracts, and remove barriers to data sharing.
According to Ms. Gerken, the bigger unknowns for PRA are arising from the changes in business models; for instance, the increasing risk of cloud outsourcing. Insurers are increasingly using third-party data storage and processing, development infrastructure, and software delivery. PRA has surveyed insurers in this area and is analyzing the results. PRA is also planning to issue a new supervisory statement on outsourcing in the near future. The supervisory statement is intended to provide a one-stop source of reference on outsourcing and third-party risk management, bringing together the previously issued guidance. PRA is also finalizing policy proposals to require firms to improve their operational resilience, including making it clear how PRA expects them to identify important business services on which they rely.
Some technology developments are creating less tractable risks, for example, machine learning. Hedging models are being built using neural networks rather than financial mathematics. These models are black boxes, producing results that are fundamentally unexplainable. Traditional models to which risk management principles are applied are built on known logic and it is possible to determine the key variables affecting results and sensitivity of the results to changes in those variables. Machine learning poses challenges for a traditional risk management framework based on identifying and analyzing key risks and dependencies. This gives rise to questions regarding how can a firm’s Board satisfy itself of the model’s prudence and appropriateness. Regulators are also struggling to understand what a governance and disclosure framework looks like for a model that cannot be explained.
Related Link: Speech
Keywords: Europe, UK, Insurance, Liquidity Risk, Solvency II, Cyber Risk, Cloud Outsourcing, Fintech, Regtech, PRA
Featured Experts

Adam Koursaris
Asset and liability management expert; capable modeler; risk and capital specialist

Cassandra Hannibal
Life insurance actuary; risk management and economic capital specialist

Jerome Ogrodzki
Insurance asset and liabilities modeling specialist; stochastic modeling expert
Previous Article
US Agencies Publish Semi-Annual Regulatory Agenda in June 2019Related Articles
EBA Clarifies Use of COVID-19-Impacted Data for IRB Credit Risk Models
The European Banking Authority (EBA) published four draft principles to support supervisory efforts in assessing the representativeness of COVID-19-impacted data for banks using the internal ratings based (IRB) credit risk models.
BIS Hub Updates Work Program for 2022, Announces New Projects
The Bank for International Settlements (BIS) Innovation Hub updated its work program, announcing a set of projects across various centers.
US Senate Members Seek Details on SEC Proposed Climate Disclosure Rule
Certain members of the U.S. Senate Committee on Banking, Housing, and Urban Affairs issued a letter to the Securities and Exchange Commission (SEC)
EIOPA Consults on Review of Securitization Framework in Solvency II
The European Insurance and Occupational Pensions Authority (EIOPA) published a consultation paper on the advice on the review of the securitization prudential framework in Solvency II.
UK Authorities Issue Regulatory and Reporting Updates for Banks
The Prudential Regulation Authority (PRA) issued a statement on PRA buffer adjustment while the Bank of England (BoE) published a notice on the statistical reporting requirements for banks.
BaFin Consults on Resolvability Requirements for Resolution Planning
The Federal Financial Supervisory Authority of Germany (BaFin) proposed to amend the “Capital Investment Conduct And Organization Ordinance” and issued a draft circular on the minimum resolvability requirements for resolution planning.
EBA Consults on Certain Standards and Guidelines Under CRR and BRRD
The European Banking Authority (EBA) proposed guidelines, for the resolution authorities, on the publication of the write-down and conversion and bail-in exchange mechanic, with the comment period ending on September 07, 2022.
OJK Publishes Regulatory Updates for Financial Sector Entities
The Financial Services Authority of Indonesia (OJK) is strengthening cooperation with the Australian Prudential Regulation Authority (APRA) and the Japanese Financial Services Agency (JFSA)
EU Publishes Rules on DLT and Data Governance
The European Parliament and the Council published Regulation 2022/868 on European data governance (Data Governance Act).
EBA Publishes Phase 2 of Reporting Framework 3.2
The European Banking Authority (EBA) published phase 2 of its reporting framework 3.2. The technical package supports the implementation of the updated reporting framework by providing standard specifications