Download

Don’t Risk a Lot for a Little

As a buyer and seller of insurance, as an agency owner and a business owner,  as a center of influence in your world, BE PREPARED.

The speaker walked to the podium holding a large jar filled with M&Ms. She asked: “Who likes M&Ms?” Hands went up. She then asked, “If I offered each of you $10 for each M&M you could eat, how many would eat some?” More hands went up. Finally, she said, “If I offered you $100 for each M&M you ate, who would get in line for a fistful of these chocolate treats?” All hands were raised, and a line to the podium started to form. Then she said, “But understand – one of these M&Ms is infected with a deadly poison, and, if that M&M touches your lips, you will die. Any takers?” All hands went down, and folks forming the line returned to their seats. She said, “This simple example provides insight into the underlying principles of risk management and insurance:
  • Don’t risk a lot for a little.
  • Don’t risk more than you can afford to lose.
  • Don’t measure your chance of loss as a statistic; measure it in terms of the consequences if it happens to you.
As professionals in the insurance industry, our challenge is not just to sell insurance but also to help our clients manage their risks. Our purpose should be to facilitate our clients maximizing the good in their world, minimizing the bad and, when the bad does occur, mitigating the damage done. Risk management is the process. Insurance is the last step in that process. In 1972, as a G.I., I was blessed to visit the Notre Dame cathedral in Paris. It was a magnificent edifice. Today, it is smoldering ruins. The history remains; the vast majority of the structure does not. I have no idea of the insurance involved. My first question would be: Is it enough? My answer would be: “Probably not.” I’m assuming the liability carriers of the organizations responsible for the loss and the assets of these same organizations will provide the down payment on this disaster. The Catholic Church, billionaires, the French government and the people in the world will probably “re-insure the rest of the loss.” The facility will never be the same. My experience indicates that too many policyholders (risks) measure their losses in terms of losses they have experienced and are comfortable with. They are hard-pressed to venture into the unthinkable. Many residents/business owners in New Orleans were insured for wind and flood but not to the extent that a lady named Katrina delivered to their world. The people in Houston knew rains and floods but “misunderestimated” what 70 inches of rain can do. See also: In a Crisis, Will You Be Ready?   As agents and brokers, we and our clients guess, “How much is enough? We don’t know for sure until it’s too late to change our decision. I insured (circa 1975) a new hospital on the north shore of Lake Ponchartrain. I had been put on notice of a small fire loss that burned a fence and some grass. A dumpster had caught on fire. I was to report to the board soon, so I called the adjuster to be certain that all was well. The adjuster said, “Mike, I was getting ready to call you to advise you that I had reserved policy limits on this case.” (I almost threw up.) He further explained that the “little grass fire” had burned hundreds of acres adjoining the hospital. On the good news side, the landowner was an older man whose timberland had burned before, and this was the first time anyone had come forward to accept responsibility. He walked away from his claim. He appreciated our honesty and we appreciated his generosity. Bart was one of the best clients I ever had. In the mid-1980s, he had been carrying a $1 million umbrella. I suggested he raise the limits to $5 million. He said, “Mike, what could we ever do wrong that would result in that much damage?” I responded, “One of your trucks could run a busload of attorneys off the bridge and into the river.” He responded: “Oh my God, give me the higher limits.” (Two years later, we paid a multimillion-dollar auto loss.) In 1975, Louise (not her real name) was our agency bookkeeper. She had handled the books for decades. She was a blue-haired church lady who never caused trouble or had been a concern. The agency hired a newly minted accounting graduate to help the agency in the future but would let Louise work as long as she wanted out of respect for her decades of loyal service. In the first week, our new CPA discovered that Louise was more slick than innocent or loyal. We ended up discovering a loss of more than $33,000 (no one will ever know how much she stole). Fast forward about 12 years. I was insuring one of the fastest-growing and most profitable ENT practices in town. The practice was tubes in the ears into to gold via the operating room. The doctors realized the need for a more sophisticated accounting system for their practice. They hired a new CPA to be their office leader. He was the son of a prominent business leader. He had literally grown up next door to one of my agency's principals. He was a professional. We raised the employee bond limit to cover the new success of the practice. The carrier asked for additional details on this new employee. We forwarded the request. The information was not forthcoming. We made requests. The new employee used the excuse of “busy.” We believed him; the carrier did not. It sent a notice of cancellation. A few days later, the managing partner called and asked if the practice had a fidelity bond. I joked, “Don’t tell me he went south with the money.” Total silence. He was gone, as was a large sum of money. The good news for us: The prominent father of this “CPA” paid the claim to make other charges go away. It turned out that his son was not a CPA, and other legal issues were about to surface. As an agent/risk manager, I was not nearly as good as I thought. I was lucky. You may not be so lucky. Manage the risks as they are, not as you are or as you hope them to be. Today’s world is not as simple, innocent or honest as the world we left behind. Marcus Welby M.D. and Ozzie and Harriet are dead, and so is the world they lived in. With technology, your accounts can be cleaned out by a techie crook who can’t even spell CPA. Oftentimes, drugs today motivate dishonesty to support a habit. See also: With Innovation, Keep It Simple, Stupid   In the world of tort in Louisiana, there are more attorneys on billboards than there are underwriters trying to protect their carriers from them. Your Daddy’s Oldsmobile is a distant memory. The invincible AIG of my early years has been bankrupt, as have Arthur Andersen and other icons of yesterday. As a buyer and seller of insurance, as an agency owner and a business owner,  as a center of influence in your own world, BE PREPARED. Be prepared for the world as it is now, not as you would like it to be. Remember that technology has made crooks much more effective at mischief than it has made us efficient at self-preservation! How much is enough protection? I don’t know. Do you?

Mike Manes

Profile picture for user mikemanes

Mike Manes

Mike Manes was branded by Jack Burke as a “Cajun Philosopher.” He self-defines as a storyteller – “a guy with some brain tissue and much more scar tissue.” His organizational and life mantra is Carpe Mañana.

Maybe Even Diabetes Can Be Insured

Technology that lets diabetics monitor and manage their disease is showing promise for reducing risky behaviors.

The World Health Organization has published a five-year strategic plan focused on 10 major threats to global health in 2019, among which there are noncommunicable diseases, such as diabetes, cancer and heart disease - collectively responsible for over 70% of all deaths worldwide. Through the plan, the WHO wants to try to ensure that 1 billion more people will benefit from access to universal health coverage, 1 billion more people are protected from health emergencies and 1 billion more people enjoy better health and well-being. It’s a very optimistic goal, and different types of solutions are required; all means available should be employed. Where do insurers come in? They are part of the healthcare system and could do more to contribute to global health. Though it may seem perhaps altruistic to associate insurers with such a noble scope, the reality is that they, insurers, would also benefit. Forward-looking companies have understood this opportunity, so there are examples of insurers that have started to use the “Insurer as Partner” approach, which implies an active role in prevention rather than just being reactive and paying claims when an undesirable event occurs. This new potential role of the insurer has been made possible, in great part, by what we now call “connected insurance,” which encompasses IoT (Internet of Things), wearables and other monitoring devices. The re-shaping of the insurance industry has already begun, and it will continue based on new technologies. Connected health insurance can become profitable for insurers as it allows measurement of the risk for a specific client and thus allows the presentation of an improved, better-priced value proposition that may also improve general health. The insurance company can’t possibly make it on its own and will have to seek partners from both the technological innovation sphere and medical providers, keeping in mind that its role in the health system is changing from “payer” to “pivot.” Discovery’s Vitality Program To better grasp the actual benefits for clients and not just for insurers that adopt such an innovative approach, let's look at the South African insurance player Discovery, which can be considered the benchmark when it comes to engaging members and improving their quality of life. Its Vitality program has created a system that not only raises the loyalty of customers but improves their lifestyle and overall health. Discovery’s Vitality uses an "early warning" mechanism that can anticipate serious health problems and more expensive claims. It does so by using connected devices like the smartwatch. According to Discovery, Vitality Gold status members with heart disease have 41% lower risk claims than members with no Vitality membership. Vitality Gold members living with diabetes have 50% lower risk claims. See also: Security of Medical Devices Needs Care   Another claim coming from a presentation by Discovery Vitality at DIA Amsterdam 2018 deserves our attention: There is an 18% reduction of hospital and chronic claim costs for the batch of Vitality members who use the Vitality Active Rewards (VAR) alongside the Apple Watch, compared with the group of insured who do not use an Apple Watch. VAR is a smartphone application based on fitness points, which is designed to encourage Vitality members to increase their activity by setting weekly personalized physical activity goals - and then rewarding users for achieving them. (Discovery specifies that its data is based on a cross-sectional view of the relative claims experience, and it is premature to show the improvement over time given the lower frequency of health claim events.) Discovery says that Apple Watch owners enrolled in the program are 35% more active than prior to getting the watch. Since the VAR system was launched, there has been a 24% increase in physical-activity days and a 9% increase in meeting higher exercise targets. The data is telling, and the implications for ensuring healthy lives and promoting wellbeing are significant. Seen from this point of view, the transition to a “prevention-centered” approach is a pragmatic decision for insurers because, in time, the portfolio tends to change its structure, passing from a majority of “sick” clients to a majority of relatively “in good health” clients. ICS Maugeri’s Mosaic case study Let’s look now at a more specific issue within the spectrum of uninsurable diseases, that is diabetes. Diabetes is a chronic disease that occurs either when the pancreas does not produce enough insulin or when the body cannot effectively use the insulin it produces. In 2014, 8,5% of adults aged 18 years and older had diabetes. In 2016, diabetes was the direct cause of 1,6 million deaths, and in 2012 high blood glucose was the cause of another 2,2 million deaths. It is estimated that the number of diabetic patients worldwide will be 629 million by 2045. Diabetic patients have a high risk to develop severe complications generated by the evolution of the pathology, such as peripheral neuropathy, retinopathy, nephropathy and cardiovascular diseases. It is well-known that insurers either do not cover diabetic patients or, if they do, require a high premium. This is due to the difficulty to measure the probability of the occurrence of risks associated with these clients. Therefore, the insurance sector is leaving uncovered a market that is becoming more and more relevant. ICS Maugeri, a major group of hospitals specializing in rehabilitation medicine, has developed, in partnership with the University of Pavia, an instrument called Mosaic aimed at improving the clinical management of patients affected by diabetes mellitus type 2 (T2DM) that can calculate the risk of developing complications in different time scenarios. Mosaic uses AI and machine learning that is based on algorithms able to learn patterns and decision rules from data. Based on the results expressed in one of their published research papers, the team has been able “to predict the onset of complications (retinopathy, neuropathy, nephropathy) at different time scenarios: at three, five and seven years from the first visit. The final models are thus able to provide up to 84% accuracy in predicting the probability for a diabetic to develop the three main complications and are easy to apply in clinical practice. In insurers’ terms, this shows that risk associated with diabetes can be estimated; furthermore, given that clinical evidences show that a proper management of the diabetic patient (intensive pharmacological treatment etc.) can lead to a significant reduction in the possibility of developing complications, the risk itself can be managed and reduced. The question is: How can insurers make sure that diabetic patients follow the required therapeutic path? It’s a difficult job. Diabetic patients are required to follow a rigorous clinical, diagnostic and therapeutic path to manage and control their pathology and try to limit or slow the consequences of this chronic disease. This path involves periodic medical checks and diagnostic tests as well as continuous and intensive drug therapies, requiring significant effort for patients and their caregivers. Most of the time, the scheduling of such periodic checks must be autonomously managed by the patient, resulting in a progressive reduction of adherence to the required clinical paths. Within the Mosaic project, the patient is monitored with the help of wearables and telemedicine; this allows the team to (i) personalize and update pharmacological treatments, (ii) identify and update the diagnostic path to be performed to monitor and reduce the risk of complications and (iii) identify on-time criticalities that may require timely investigations. Therefore, this approach allows a significant risk control and, potentially, risk reduction, allowing the insurer to update the premium yearly. See also: An Easy Way Forward on Health Costs   How do Discovery Vitality and Mosaic fit in together? Discovery Vitality uses gamification, reward systems and tracking devices to steer clients toward a healthier life style. Imagine if Vitality would be integrated with Mosaic’s technology for diabetes patients. This would mean that suddenly diabetics would become insurable, and the client base would increase. Vitality has already proven that a reward-based system can help improve behavior, so probably it would also work as an additional incentive for diabetics in keeping them effectively engaged with their prescribed treatment. Taking for granted that diabetics will follow a program step by step and change their behavior toward a desired goal is not something anyone should do. Even if the real stake for diabetics is their own life expectancy, which should be motivation enough, the reward element could be a good and fun extra incentive for reaching health goals. As estimated costs with lifestyle-related conditions (including diabetes) will be 47 trillion by 2030, insurers, the healthcare systems, clinical providers and patients could all benefit in some way from such a program. We would like to see this implemented in the short term at a larger scale than the test made by Mosaic, and it would also be interesting to look at how this approach could be extended to other chronic diseases. Article based on the chapter written by Andrea Silvello and Alessandro Procaccini, “Connected Insurance Reshaping the Health Insurance Industry,” Smart Healthcare, Intechopen, 2019, DOI: 10.5772/intechopen.85123.

Andrea Silvello

Profile picture for user AndreaSilvello

Andrea Silvello

Andrea Silvello has more than 10 years of experience at internal consulting firms, such as BCG and Bain. Since 2016, Silvello has been the co-founder and CEO of Neosurance, an insurance startup. It is a virtual insurance agent that sells micro policies.

Overcoming Concerns

Millennials value insurance but require tailored products, tools and processes that connect with how they live and consume today.

According to a recent article by Policy Genius, “The cost of college has skyrocketed over the last decade, resulting in $1.4 trillion of outstanding student loan debt. The burden of educational debt weighs greatest on millennials --- those born between 1981 and 1996. Not surprisingly, college debt is influencing their behavior and spending habits. Research shows millennials are holding back on buying homes and making other big-ticket purchases because they are afraid of taking on more debt. Millennial families are also postponing other financial outlays, such as life insurance, because of debt concerns, according to a recent survey by SE2. Marriage and kids continue to be the life-changing events that trigger purchases of life insurance. As millennials buck the trend, insurers have to be versatile to adapt to their consumer tastes and lifestyles to capture this vastly untapped market segment. Start with technology Speed and convenience are increasingly critical to a good brand experience. Those raised as digital natives do not want to wait for several weeks for underwriting to size up an applicant’s risk. To be sure, a number of insurers have leveraged technology to accelerate the cycle time, but there is still far more we have to do. According to a recent report from Celent, cycle times for modest face amount carriers has dropped from 33 to 26 days, which is a solid improvement but still almost four weeks. See also: The Great Millennial Shift   Insurers rely on a mountain of public information --- from motor-vehicle records to credit information to property records --- to properly assess risk and price premiums. One late monthly payment on college debt can cause a credit score to drop, which could drive up premiums. What if price-sensitive millennials could offset the negative of a low credit score by sharing data from their Fitbit exercise app? New York’s top financial regulator is taking a step in this direction by allowing life insurers to use data from social media and other nontraditional sources when setting premium rates. Through leveraging data available through electronic medical records and health claims data, more and more carriers are able to provide a fluidless underwriting experience without an APS (Attending Physician's Statement). In the digital era, many of these digital natives are tracking everything from the food they eat to the number of steps they take every day. Our research shows that millennials might be more willing to buy insurance if their real-time health data could reduce premiums. Create an authentic experience Millennials are increasingly more discriminating about the firms they choose to do business with, showing a preference for companies that are authentic, ethical and committed to social good. This partiality stems in part from the 2008 financial crisis when a shortage of jobs affected the employment opportunities for older millennials. Younger millennials witnessed the pain of parents losing their jobs or their homes, or both. The scary economic news sowed a pessimism about the future and increased their desire for transparency. See also: Why Financial Wellness Is Elusive   Big companies have had to scramble to adjust to shifting attitudes. Mass marketing through TV advertising is proving less effective. Companies that target millennials with creative experiential campaigns are finding greater success. The engagement can be online, too, through gamification, loyalty programs and reporting on daily activities and life events. Some of the more innovative insurance carriers have seem immense success partnering with financial technology startup such as Life.io and Vitality to create customer engagement programs that has led to reduction in lapse rates and opened up new cross-sell and up-sell opportunities. Despite their financial concerns, we found that millennials value insurance and the peace of mind it provides. It falls upon the insurance industry to meet this generation where they are by creating tailored products, tools and processes that connect with how they live and consume today.

Ashish Jha

Profile picture for user AshishJha

Ashish Jha

Ashish Jha has over 15 years of experience positioning global organizations in the financial services and insurance industry. As vice president and chief marketing officer of SE2, Jha drives the company’s marketing and communications activities.

Turning Data Into Action

The key lies in using information obtained from reputable sources to fill in some of the gaps in the data you are already gathering.

|
Over the past decade, insurers have focused heavily on improving the customer’s journey. This task can be particularly challenging because a customer’s engagement with them could be as little as one annual wellness visit with no other claims for that year. In an effort to create engagement and build loyalty while working toward better health status, insurers have gamified biometric device interactions, launched semi-automated communications platforms and established group wellness challenges for employer groups and individual coverage plans. But here’s the challenge: If the data gathered from these engagements that is fed back to insurers is not clean, readable and available in the format and time in which it is needed, then a carrier is unable to optimize its application. If this challenge can be solved, high-quality data that does meet those parameters can be used for CRM modeling tools, experience and loyalty measuring systems, enhanced communications applications, cross-sell offers and lifetime customer value formulas. So how does one begin to solve this challenge? The key lies in using information obtained from reputable sources to fill in some of the gaps in the data you are already gathering. See also: How Agencies Can Use Data Far Better   Here are some of the benefits of using third-party data to inform your analytics:
  1. You can enhance the bland data you already have. You could fill volumes with the amount of information you have about your customers’ basic demographics such as age, geography and household income. But what about their risk for certain health conditions and their history of disease? Including these details can support better communications, closer engagement and efficient transaction processing with care providers and administrative systems managers.
  2. You can improve both the quantity and quality of your data. Quality of data can make or break processing and downstream analytics. When you use a third party to obtain your data, you may experience a more reliable return on investment in your marketing and communications spend. You can also make more informed decisions when you are pricing the risk of catastrophic losses. High-quality data can mean the difference between automated workflow decision making or manual and costly processes. It does not have to be a lot of data — but it does have to be clean, understandable, reliable and available when needed.
  3. You can diversify ways of turning data into actionable insights. Information might be engineered or derived from big datasets that are curated in a way that a payer can ingest, making it useful for activities including workflow automation, risk management assessments, price modeling exercises, population health management or sales and marketing activities.
Of course, it’s important to be able to efficiently manage data from multiple sources. To do that, you need to create a master data management plan. Often, a centralized location for several datasets makes sense, although a connected, decentralized arrangement can work, as well. Establish a standard data dictionary within your company to ensure that your staff understands external data in the right way and can more precisely define even internal data. In other words, break down data silos and functional barriers that may be preventing a standard dictionary that all can leverage. How can you determine whether you are getting the most out of your use of data? A three-step approach may be helpful:
  1. Evaluate the data you have and verify whether it is clean, reliable and accessible in the manner you need it.
  2. Identify the areas in which external data could complement your own and structure a data management approach for all of your data — both internal and external.
  3. Establish a cross-functional executive team that can prioritize where you need the data most, and start on one initiative now. If you are not doing something, your competitors most probably are.
See also: Role of Unstructured Data in AI   Well-organized data can help you engage your current customers, attract new customers and ultimately improve your company’s bottom line. But too much data, that is not optimized for your business needs, may not help the organization meet its goals. When you focus on high-quality and reliable data, you can see some tangible results when you adapt its use into platforms all along the lifecycle of your business.

Denise Olivares

Profile picture for user DeniseOlivares

Denise Olivares

Denise Olivares is an accomplished product and marketing executive with global experience and proven results working for healthcare, insurance and data organizations including CIGNA and LexisNexis. She is currently consulting with Windy Hill Group.

Where Were the Risk Managers for King's Landing?

Couldn't dragon-resistant building codes have been imposed? Are there enough adjusters in all of Westeros to handle all the claims?

sixthings

As Daenerys Targaryen unleashed her dragon on the defenseless King's Landing in the penultimate episode of "Game of Thrones" on Sunday, millions of viewers wondered: Why didn't the writers prepare us more for her turn to the dark side? How did the city's artillery go from hitting everything a week earlier to hitting nothing this week? And, if there was budget for such extensive special effects showing the destruction of the city, then why couldn't Jon Snow have hugged his CGI-generated direwolf goodbye the week before? (Maybe that was just my question.)

Those of us in the insurance industry had even tougher questions: Why didn't the risk managers prepare the city better for an attack? Couldn't dragon-resistant building codes have been imposed? Are there enough adjusters in all of Westeros to handle all the claims?

Right?

Let's imagine two scenarios, one traditional and one cutting-edge, that consider how King's Landing might recover. (If either gets picked up as one of the inevitable prequels or sequels to GoT, I hereby lay claim to a share of the royalties. I can see it now: "A Song of Fire and Fire Insurance.")

We all know the traditional scenario, which we see after hurricanes and wildfires. An army of adjusters descends on the city. They start handing out partial checks and plowing through debris and the details of the policies. An insurer or two is undercapitalized—Lannister Re surely didn't survive this attack, despite its slogan: "Lannister always pays its debts." Loads of people are underinsured, and that's even before the massive competition begins for the materials and skilled workers needed to rebuild. The lawyers get involved, and people learn that being covered for fire doesn't mean they're covered for ALL fire—dragon fire is a special case, after all—or for the damage caused when fire makes someone else's building collapse on them or their homes. Pretty soon, billboards go up advertising for personal injury lawyers: "If You Suffered Emotional Distress in the Dragon Attack, Call Qyburn & Qyburn at 123-456-7890."

The city eventually recovers, but it takes forever; there is a ton of wasted effort and money; and many customers feel ill-used.

Now let's imagine a more, well, magical scenario. George R.R. Martin hasn't finished the books yet, so I'll claim literary license. 

In this scenario, King's Landing insurers saw themselves as in the services business, not in the payment-for-damages business. They helped businesses and citizens prepare for the dragon attack, whose possibility had been building for years. So, many buildings had been hardened and survived reasonably intact. (The episode just didn't show those.) Insurers drew on the new possibilities from insurtechs, especially Bran Stark Analytics (the predecessor of Stark Industries and Tony Stark, aka Iron Man). Based on its Three-Eyed Raven platform, Stark Analytics used AI (aerial intelligence) to warn clients right before the attack and get them to safe areas. (Again, the episode somehow missed these people.) After the attack, the insurtech dispatched flocks of crows (controlled via warging) to survey the damage, quickly started paying claims and helped clients soon get back on their feet. 

There was still plenty of dislocation—dragon attacks will do that—but the focus on prevention and the use of cutting-edge technology meant that the city quickly recovered and thrived under the long reign of....

Cheers,

Paul Carroll

Editor-in-Chief

P.S. Spare a thought for the 3,500-plus girls who over the course of the show have been named some version of Daenerys or Khaleesi. Named after a symbol of female strength, the girls and their parents are now finding that Daenerys has become an unhinged mass murderer.


Paul Carroll

Profile picture for user PaulCarroll

Paul Carroll

Paul Carroll is the editor-in-chief of Insurance Thought Leadership.

He is also co-author of A Brief History of a Perfect Future: Inventing the Future We Can Proudly Leave Our Kids by 2050 and Billion Dollar Lessons: What You Can Learn From the Most Inexcusable Business Failures of the Last 25 Years and the author of a best-seller on IBM, published in 1993.

Carroll spent 17 years at the Wall Street Journal as an editor and reporter; he was nominated twice for the Pulitzer Prize. He later was a finalist for a National Magazine Award.

How to Avoid Snarl of N. Korea Sanctions

As sanctions enforcement widens, insurtech can help firms spot bad actors and avoid transacting with suspect vessels.

||||||
The timing was excellent – or unfortunate – depending on your perspective. Just a week before South Korean President, Moon Jae-in, jets to Washington to talk DPRK denuclearization, it was reported that a South Korean oil tanker had been detained. The P PIONEER – the first local vessel seized by South Korean authorities — is among four detained by Seoul. All are suspected of violating United Nations sanctions on fuel shipments to North Korea. Just last month, the UN Security Council (which uses Windward technology) published its latest report on North Korea. It laid out in graphic detail Pyongyang’s evolving tactics in evading sanctions, and the maritime compliance risk faced by anyone connected – however unwittingly – to vessels engaged in this kind of activity. THE P PIONEER According to reports, the P PIONEER was detained last October on suspicion of shipping oil to North Korea via clandestine ship-to-ship transfers and is “an indicator of the increasing pressure the U.S. is exerting on foreign governments and businesses to crack down on North Korean sanctions evasion,” according to Tahlia Townsend and Joseph Grasso, who head the International Trade Compliance and Insurance Practice Group at U.S. law firm Wiggin and Dana. A Windward analysis of the vessel’s behavior in the 12 months leading up to its detention reveals a pattern of dark activities in several parts of the East China Sea. In total, we detected 13 separate occasions when this happened – the kind of deceptive shipping practices routinely employed by North Korea, as highlighted by an updated advisory published last month by the U.S. Treasury’s Office of Foreign Assets Control. During our analysis, another notable pattern of behavior emerged: In the 12 months before it was detained, the P PIONEER only visited ports in South Korea. In other words, every voyage the vessel undertook began and ended in South Korea. Map showing polygons (areas) linked to possible clandestine oil transhipments to North Korea. Source: OFAC, UN. See also: Can Insurers Stop Financial Crimes? Yes   Searching in the dark Detecting such behavior just by searching for “dark activity” won’t get you very far. Indeed, if you use this behavior as a proxy for illicit activity in the East China Sea, you’ll end up with a short list of 20,000 vessels during the past 12 months (the East China Sea is notorious for poor AIS coverage, meaning many vessels that “go dark” don’t do so deliberately). Of these, 1,200 were tankers – a number way too big to differentiate between innocent vessels just passing through and those potentially engaged in illicit oil trading with North Korea. If identifying dark activity was all we could do, compliance officers, charged with ensuring vessels they deal with are complying with sanctions, would probably jump overboard. Map showing clusters of Dark Activities by vessels in the East China Sea over the past year Where we can narrow things down for maritime compliance risk is by looking at how frequently vessels went dark – where it was an integral part of a vessel’s modus operandus. As the chart below shows, most tankers had no more than one dark activity in the area; only 3.5% of them did it more than five times. We can look more closely at repeat offenders, to find those that might be evading sanctions (our algorithms can detect which turn-off-transmissions are due to lack of reception and which due to skulduggery). Distribution of vessel dark activity, highlighting two additional vessels that were mentioned in the recent OFAC advisory regarding DPRK as possibly being involved in illegal transports of petroleum products. Behavioral Analysis Another way to whittle down the list of potential miscreants is to look at trade patterns. As discussed above, most vessels passing through this area were heading to ports in the region. The P PIONEER’s voyages always started and finished in South Korea (with a dark activity in between), a pattern we see in just 81 other vessels over the past 12 months. If we narrow our time window to the past 60 days, we find only 17 vessels were engaged in this pattern of behavior – a much more manageable data set. Within those 17, we find one, very interesting, vessel, called the P CHANCE. Like the P PIONEER, it’s a tanker; it’s flagged in South Korea; it had 21 dark activities in the region in the past year – including one last month. Oh, and it belongs to the same registered owner (see below). Looking at the P CHANCE’s economic utilization profile, one can spot the same risk indicators but from a different perspective. With more than 15 dark activities in the East China Sea in 2018, the vessel spent only 31 days in port (compared with 80 days for similar tankers). See also: Europe’s New Data Breach Requirements   To be sure, this analysis isn’t a smoking gun – it just means that out of the thousands of vessels transiting the East China Sea every month, this vessel stands out, indicating that further investigation may be warranted. Maritime Compliance Risk The deceptive shipping practices discussed in this article were once only relevant to intelligence agencies and NGOs that monitored and enforced sanctions. But as we’ve seen in the recent OFAC advisory, and the UN Panel of Experts report, sanctions enforcement is no longer something only bad actors need worry about; counterparty due diligence (CDD) teams in every industry that interacts with shipping now need to up its game considerably. Indeed, when list managers or compliance officers consume data feeds and black lists, the recent OFAC advisory might now require them to prepare and consume a global daily review of dynamic sanctions evasions tactics, to mitigate compliance risk. With the right technology, they can do so – while keeping their businesses running as usual.

Omer Eilat

Profile picture for user OmerEilat

Omer Eilat

Omer Eilat is a decorated former naval captain and commander. A certified yachtsman, he is director of business development at maritime risk analytics company, Windward.

ROI Study on Customer Experience

A Watermark study vividly illustrates the financial benefit of a great customer experience – for insurers, in particular.

|||||
What’s a great, differentiated customer experience (CX) really worth to a company? It’s a question that seems to vex lots of business executives, many of whom publicly tout their commitment to the customer but are actually unsure about the ROI of customer experience — leaving them reluctant to invest in customer experience improvements. As a result, companies continue to subject their customers to complicated sales processes, cluttered websites, dizzying 800-line menus, long wait times, incompetent service, unintelligible correspondence and products that are just plain difficult to use. To help business leaders understand the overarching influence of a great customer experience (as well as a poor one), my firm sought to elevate the dialogue. That meant getting executives to focus, at least for a moment, not on the cost/benefit of specific customer experience initiatives but, rather, on the macro impact of an effective customer experience strategy. We accomplished this by studying the cumulative total stock returns for two model portfolios – composed of the Top 10 (“Leaders”) and Bottom 10 (“Laggards”) publicly traded companies in customer experience. As the graphic in the next section vividly illustrates, the results of our study were quite compelling. The Results Eleven years of customer experience rankings were available for our analysis. The graph below shows the cumulative total return across that period for the Leaders and Laggards.
  • Customer Experience Leaders outperformed the broader market, generating a total return that was 45 points higher than the S&P 500 Index.
  • Customer Experience Laggards trailed far behind, posting a total return that was 76 points lower than that of the broader market.
  • Customer Experience Leaders generated a total cumulative return that was nearly three times greater than that of the Customer Experience Laggards.
Commentary This analysis reflects over a decade of performance results, spanning an entire economic cycle, from the pre-recession market peak in 2007 to the post-recession recovery that continues today. While there are obviously many factors that influence a company’s stock price, the results of this study indicate that, over the long term, a great customer experience helps build business value, while a poor customer experience erodes it.  That’s an important takeaway, for public and private entities alike. What creates that enhanced value? Revenue growth. When most people think about the economic benefit from a great customer experience, this is where their heads go.  That’s entirely appropriate, because revenue growth is indeed one clear advantage of customer experience excellence. Why? Happy, loyal customers have better retention, they’re less price-sensitive and they’re more willing to entertain offers for other products and services – all helping to raise revenue. Plus, because they love you so much, they spread positive word-of-mouth and refer new customers to you – lifting revenue even higher. Expense control. This is the part of customer experience economic equation that most businesses fail to appreciate. (It’s also why using revenue growth, alone, to demonstrate customer experience ROI is misguided.) When you have happy, loyal customers, it helps to better control – if not reduce – your expenses. For example, due to all the customer referrals you’re getting, you can spend less on business acquisition – which reduces expenses. In addition, happy customers tend to complain less, putting reduced stress on your operating infrastructure (e.g., lower call volumes), thereby also helping to keep expenses in check. Of course, these economic dynamics cut both ways. Customer Experience Laggards struggle to raise revenue (e.g., poor retention, high price-sensitivity, limited cross-purchasing, negative word-of-mouth), and they’re burdened with higher expenses (e.g., to acquire new customers, and to deal with the existing unhappy ones). This weighs on their long-term profitability and makes them less valuable in the eyes of the market. To learn more about the study’s methodology, and what Customer Experience Leading firms do to achieve their outperformance, view Watermark’s complete Cross-Industry Customer Experience ROI Study. The Insurance Industry Perspective The insurance industry often views itself as being different than other sectors, given, for example, its highly regulated nature and the fact that its products are something of a “grudge purchase” for consumers. Well, we’ve crunched the Customer Experience ROI numbers for the Auto and Home insurance industries – and it turns out the customer experience story is even more compelling in those sectors: Insurance Customer Experience Leaders outperformed the Laggards by over a three-to-one ratio. It’s a striking result that suggests, at least in this regard, the insurance industry isn’t different from most other sectors, and the compelling economics of a customer experience excellence still apply. To learn more about Watermark’s insurance industry analysis, including the implications for insurance providers seeking to improve their own customer experience, view the complete Insurance Customer Experience ROI Study.

Jon Picoult

Profile picture for user JonPicoult

Jon Picoult

Jon Picoult is the founder of Watermark Consulting, a customer experience advisory firm specializing in the financial services industry. Picoult has worked with thousands of executives, helping some of the world's foremost brands capitalize on the power of loyalty -- both in the marketplace and in the workplace.

A Way to Attack Healthcare Fraud

Unless we work to stop fraudulent claims, through the use of sound counsel, our healthcare system will continue to suffer.

If insurers want to mitigate risk, rather than risk their time and money with litigation, if they want to guard against fraudulent claims, if they want to protect good doctors against wrongful claims, then they should invest in sound legal counsel. Insurers should highlight the value of retaining healthcare lawyers with the intelligence to know—and the strength to do—what is necessary to defeat false allegations of fraud or abuse. A doctor’s career can hang in the balance when defending against a professional liability claim. Without sound counsel, our best doctors may not be able to practice medicine. Unless we work to stop fraudulent claims, or make it more difficult for fraudsters to enlist the government to pursue these claims, our healthcare system will continue to suffer. Stopping this injustice starts with healthcare lawyers in search of justice—namely, healthcare lawyers whose expertise doctors need. See also: Proof of Value for Medical Management   According to Fenton Law Group, which specializes in defending healthcare providers against allegations of fraud and abuse, the charges themselves have their own nuances and degrees of sensitivity. Take the firm’s representation of Dr. Alwin Lewis (Lewis v. Medical Board) before the Supreme Court of California, regarding a purported violation of a patient’s privacy rights. Because HIPAA prevents people from delving into personal medical records, an insurer cannot muster much of a defense without access to and knowledge of the very things that would exonerate a doctor from a wrongful claim. Bear in mind, too, that insurance companies often hire panel counsel to defend against claims of fraud. Which is not to say that all insurance companies put savings ahead of saving doctors from fraudulent claims. Given these circumstances, doctors need effective counsel. Insurers should, in turn, at least listen to what healthcare lawyers have to say about what constitutes a smart legal strategy. Perhaps elevating the role of defense counsel will benefit insurers, reducing the number of fraudulent claims by increasing the difficulty of bringing claims against doctors who have done nothing wrong. Perhaps hiring the right healthcare lawyers is the right thing do. Perhaps, indeed; but until then—until the honest unite against the dishonest—we need defense lawyers who can expose fraudulent claims and dismantle claims of fraud against innocent doctors. We cannot afford to do otherwise. Not if we want to preserve our healthcare system and protect our preferred providers of healthcare. We cannot afford to have insurers settle all fraudulent claims, either, because we will pay the price for these payouts in higher premiums and deductibles. See also: 4 Reasons to Join Agency Networks   The price will come at the expense of choice, leaving us with one of two choices: less affordable care or no care at all. We must avoid that false choice. We must have lawyers who champion our rights. We must have lawyers who defend the rights of doctors and healthcare providers. We must have lawyers who expand our rights. To have lawyers at the forefront of this cause is a good thing, an altogether just and necessary thing.

The Globalization of Risk Management

A firm operating only in the U.S. may still have customers, suppliers and traveling employees in another country.

Globalization is affecting just about every business these days. Even if a company operates only in the U.S., its customers, suppliers and traveling employees may very well be in another country. That means the laws, regulations and cultural differences in those areas are likely affecting the organization. This increased globalization of businesses means risk managers must have more of a global focus. Managing risk on a multinational basis was one of our "Issues to Watch" for 2019, as many risk managers are looking for ideas and resources. To help us better understand the issue, we had four distinguished experts join us for our most recent Out Front Ideas with Kimberly and Mark webinar:
  • Maggie Biggs, VP of insurance and risk management for VF Corporation
  • Kevin Hoskinson, client executive of global risk management for Marsh
  • Mary Roth, CEO of the Risk & Insurance Management Society
  • David Stills, VP of global risk management for Walmart
Why It Matters Companies with no physical presence outside the U.S. are nevertheless affected by international regulations around issues such as data privacy. For example, the General Data Protection Regulation (GDPR), a law that regulates how companies protect the personal data of citizens in the European Union, caries stiff penalties for noncompliance. Businesses must be aware of the tenets of the law and adhere to them. Issues such as the expansion of the GDPR prompted RIMS to address the idea of globalization several years ago. With members in more than 60 countries, the organization was hearing that the risk management culture present in the U.S. was just not the same in other areas of the world. RIMS identified the Asia Pacific region as the area where it could truly make an impact by bringing in its resources. After surveying its members, the organization set up advisory groups that include people in risk management in the affected markets and is building programs there. Program Structure Setting up a risk management program in another part of the world depends on several factors, such as the country and its laws and regulations and the organization. While centralized and decentralized are the two basic models, many companies instead have a hybrid. A totally centralized model means all decisions are made at the corporate office. These decisions could include factors like the risks to retain in addition to which brokers and other partners to use. The other extreme is all decisions made within each country. Going completely one way or the other may be a mistake. Instead, our panelists said the process should be fluid and allow for changes in leadership. See also: Why Risk Management Is a Leadership Issue   A centralized decision-making model may be more balanced and less expensive. On the other hand, local regulations can complicate things. Communication barriers can also present problems, as one panelist explained. A simple question from a team member in Asia would not reach her desk for 12 hours; then it would go to the broker team and others. It could take a week before there was an answer. Program enhancements to address such hurdles that our panelists have tried include consolidating broker relationships into a single hub and ensuring the broker has local input to help place insurance with capable companies that meet the business’ needs. An important consideration in a program’s structure is premium allocations. Regulators and taxing authorities are finding that premium taxes can be a new revenue source. Regulatory officials are looking at what a company has in terms of exposures and requiring the business to justify that the premium is commensurate with the risk. For example, one panelist noted a situation with a client who sustained a large property loss in France but had not allocated any premiums specifically to that country. While the insurer was happy to pay the claim, it was difficult to determine whether shifting the money paid in the U.S. to a local French subsidiary constituted income or a gift, both of which were taxable. The issue can be complicated and expensive. Businesses should at least have an idea of how they might handle such a situation. Culture Addressing cultural differences is one of the most important things a risk manager can do, our panelists said. It’s critical to understand these differences and learn how to work within various cultures. For example, employees in some Asian countries may feel embarrassed or even ashamed to admit, let alone report, their injuries. Implementing safety strategies and incident reporting processes would need to be done in a way that respects that cultural difference. The typical challenges encountered by any business are that much more complicated because of language barriers, time differences, regulatory disparities and cultural variances. The key to overcoming these hurdles is solid communication and strong relationships with the company’s international partners. It is important to dispel the idea that the world revolves around the U.S. and how we do things here. That perception creates obstacles for businesses trying to work effectively in other countries. The theme of “Think globally, act locally” was endorsed by several of our panelists. It means adapting to local nuances and practices. Risk tolerance levels, for example, may be different in another country. Instead of dictating how things should work, it is better to get local input. There are also different applications of law in other countries. Negligence or leases, for example, may not have the same elements as in the U.S. It behooves a company to discover the local laws and how they are applied. Something as simple as communicating with international partners can be complex. Instead of email, for example, WhatsApp or WeChat may be the more popular mode of messaging. Risk Management Differences Companies need to be aware of risk management differences in countries outside of the U.S. Our speakers outlined several examples:
  • Court system differences. There may or may not be a jury system. The class action mechanism may not be available in certain countries, creating a difficult environment for mass claims. The speed of the legal system may be incredibly slow, compared with the U.S.
  • Adequacy of damages. Other countries have different perspectives on what is considered adequate. Some jurisdictions lean toward inflated awards that make no sense to us. Or, a company might not need the level of general liability coverage, for example, that it would need in the U.S.
  • Deductible levels. In some countries, there is a strong preference to have first-dollar insurance. While that may not seem cost-effective, teams in some countries are responsible for their own profits and losses and can be severely affected by a large hit. In some cases, international policies for general liability will have zero-dollar deductibles, while other lines – such as property/casualty and directors and officers liability – have large deductibles globally.
Risk managers are used to reviewing contracts to ensure their company is protected from risks associated with a business arrangement. However, internationally there is a tendency to deal with those risks on a business basis rather than through insurance. Because of this, there may not be adequate insurance in place to cover risks. As an example, consider a manufacturer and supplier in China that does not buy the product liability coverage limits typically seen in U.S. contracts, but the part it makes is entering the U.S. market. There are situations where there was a large loss on a product in the U.S., and it basically shut down the Chinese company because the insurance coverage was inadequate. Additional Considerations Political risk and supply chain are two issues that can have a significant impact on global risk management programs. U.S./China relations of late have generated the risk of tariffs on Chinese-made products imported into the U.S. Likewise, there can be a backlash on U.S. brands sold elsewhere. A regulatory change could spark political unrest that causes damage or looting to a business. There is also the risk of local governments confiscating properly. See also: How to Improve ‘Model Risk Management’   A political uprising or natural disaster could devastate a company. The panel advised businesses to consider, for example, whether remote operations are warranted, or whether backup stock of products is necessary. Supply chain challenges related to theft can be a major concern for multinational companies, especially products traveling through Mexico and South America. There’s also potential risk to the security of the people moving the products. Monitoring the political climate of other countries, and lobbying where possible, is invaluable. Some companies do an annual deep dive evaluation of the risks in specific countries. While it may not be possible to manage all the risks, understanding what is happening can go a long way to protecting property and people. Available Resources Organizations looking for help to better understand and address global risk management issues can turn to RIMS for help. Since the organization embarked on its globalization efforts several years ago, it has developed a plethora of resources for risk managers. Under the Community section of the RIMS web page, you will find all their global resources. The link is HERE. To listen to the full Out Front Ideas webinar on Globalization of Risk Management, please click HERE.

Kimberly George

Profile picture for user KimberlyGeorge

Kimberly George

Kimberly George is a senior vice president, senior healthcare adviser at Sedgwick. She will explore and work to improve Sedgwick’s understanding of how healthcare reform affects its business models and product and service offerings.

Integrating Cyber Risk in ERM Framework

The company that integrates a robust cyber risk management approach and its ERM framework has a distinct edge.

Enterprise risk management (ERM) is often viewed as a bureaucratic and unnecessary process, subtly or overtly motivated by regulation, accompanied by internal risk leadership kingdom building and suggesting an unclear value proposition. Occasionally, these perceptions are correct, and ERM fails. Yet, there is hope for a successful ERM approach with the right motivations and when designed and implemented with the real business goals and culture of the organization in mind. This is when ERM becomes an invaluable approach to learning about and managing truly destructive risks. A successful ERM approach also creates a clearer lens for seeing and responding to emerging risks, including potential impacts, and helping to prioritize the more valuable solutions. The resulting ERM processes are, however, often fraught with hurdles, preventing many organizations from achieving a level of risk astuteness and maturity beyond ad-hoc decision making. Few risks affect organizations with the diversity, impact and pervasiveness of cyber. As we are now a truly internet-connected and -dependent world, few organizations escape material exposure to this ever-evolving risk and its wide range of impacts; fewer still seem to have effective plans for cyber risk mitigation or an ability to calculate the value “in play” gained, or not, from their cybersecurity strategies. This is not to say many organizations haven’t addressed or aren’t trying to address cyber risk. Beyond regulatory requirements, no effective governance structure today would allow management to ignore or not actively investigate this growingly complex enterprise-wide risk. Even so, why would cybersecurity become a clarion call for ERM? What role does ERM play in helping to solve the cyber dilemma, and to assess this critical cross enterprise risk? We are glad you asked. Every organization should approach risk management in a way that is effective for itself and its key stakeholders, both internal and external. This sounds good but, as mentioned, is hard to accomplish. ERM often means something much less than a comprehensive, multi-step framework and numerous processes addressing a full gamut of ERM components. ERM should at least mean, however, that those elements that most meaningfully contribute to solving the problem (i.e. understanding and controlling the risk) are employed. Certainly, at a minimum, this means identifying and valuing the significance of the exposure, treating it appropriately and then monitoring its status until it is no longer a significant threat. However, is it necessary to first build a risk culture, create a risk appetite, implement a risk tolerance strategy, appoint risk liaisons across the business, establish ERM committees and invest in sophisticated risk modeling? Likely not, unless your key stakeholders suggest or regulation requires otherwise. ERM processes can easily become overly complicated and burdensome, often working to slow or complicate risk identification and mitigating responses and unnecessarily constraining the business. Further, many ERM processes focus repetitively on risks with a potential for the most obvious and severe impacts (larger inherent risks), sacrificing an ability to otherwise tease out emerging risks and those subtle, often related, frequency risk impacts (lower-level risks), which may be slowly (or rapidly) correlating across the business. ERM frameworks primarily focused on a severity approach, unfortunately, result in a blurry ERM lens and may inadvertently expose the organization to emerging and systemic risk blind-spots. A good example of an emerging risk blind-spot is the various risks found today within a category of risks associated with information security (i.e. cyber risks). See also: Why Risk Management Is a Leadership Issue Cyber risks are a notably different type, when compared with the types of risks historically addressed within an enterprise-wide risk management framework. Why? Cyber risk management is analogous to identifying and responding to risk impacts from multiple, simultaneous “smart tornadoes" (e.g., advanced persistent threats). For example, consider these two facts: 1) cyber risk can be high-frequency and low-severity, or high-frequency and high-severity, at the same time; and 2) cyber risk “impacts” vary widely depending on complexity of known and unknown harm administered, success rate of harm administered and internal acceleration of any such harm (dwell time, lateral movement, then organizational detection and response). These variables create an infinite number of impacts and costs, matrixed across a business. This is an unusual risk behavior, to say the least, and today’s dynamic cyber risk ecosystem creates a delicate challenge for many in the information security profession. When a person proclaims (or attests, or suggests) “don’t worry, we have cyber risk covered” (e.g., managed or otherwise solved for), then she is suggesting an ability to see the future. In other words, she is implying that she generally knows how those smart cyber tornadoes are going to behave outside, inside and throughout the business, every day. Admittedly, for most, it is difficult to acknowledge what we do not know and, especially, the vulnerability we may have in facing a first-of-its kind risk management challenge – with various risks we are unlikely to completely mitigate. However, as more and more businesses engage cloud service providers and increase use cases for Internet of Things (IoT) endpoints, organizational key stakeholders, such as boards of directors, regulators and rating agencies, are becoming increasingly concerned about how organizations are identifying gaps in cybersecurity efforts. There is movement by these stakeholders to test and confirm that risk management processes are in effect and that the enterprise is identifying and responding to risks associated with those smart cyber tornadoes. It is important to understand that even if an organization believes it “has cyber risk covered” by virtue of its current information security (‘InfoSec’) approach, there is still, for many, a critical regulatory requirement to assess the cybersecurity risk itself. Failure to adequately identify, test, monitor, trend and report on enterprise-wide cyber risks creates significant financial, regulatory, reputational and operational exposure for the organization. Static reports that capture log data but are not otherwise normalized or matched to enterprise risk profiles and controls are arguably not offering complete or robust information to the enterprise, for either historical or prospective time periods. And, when we say a risk is managed, it is important to note we are applying a risk management term of art – regulators often have definitions and tests to demonstrate assurance. Managing a risk means identifying, tracking, scoring and valuing, normalizing and trending risk performance, including the net impacts. These steps are performed in accordance with compliance standards and aligned with risk tolerance. Management also includes evaluating how the risk profile (e.g., an enterprise grouping of all defined cyber risks) is changing over time (and we know it is changing) and what key risk impacts the organization is facing from the portfolio of (cyber) risks. This is where the ERM framework and ERM processes can help. The existence of an ERM framework does not provide a carte blanche solution for cyber risk management or mitigation of undesirable cyber risk outcomes. Instead, consider ERM a distinct, enterprise-wide enabler for addressing cyber risk management. In many cases, in-force ERM processes and protocols provide the “plumbing” that InfoSec leaders can immediately access and rely on to deploy quick(er) cyber risk identification, monitor the effects of specific risk mitigation strategies and capture and analyze overall enterprise-wide cybersecurity results. The interplay between ERM and InfoSec serves a critical function for the business. It helps to optimize risk management resources to ensure the InfoSec team is able to focus on the cybersecurity battle at hand. Hacker-driven intrusions and internal actors, along with many other threat vectors and attack surfaces, keep the InfoSec community scrambling for the best depth of defense and tactical offenses required to maintain uptime productivity, lower dwell times, accelerate responses and ensure overall data governance. Meanwhile, together with ERM, InfoSec faces global regulation of personal data actively shifting underfoot, resulting in increasing complexities and wider adoption of cybersecurity regulatory standards. These newly enacted regulatory standards are providing regulators with an ability to dig deep and assess enterprise-wide cybersecurity risk management. For instance, the National Association of Insurance Commissioners recently said: "State insurance regulators have undertaken a number of steps to enhance data security expectations to ensure these entities are adequately protecting this information. As part of these efforts, the NAIC developed Principles for Effective Cybersecurity that set forth the framework through which insurance regulators will evaluate efforts by insurers, producers, and other regulated entities to protect consumer information entrusted…(sic)" Additionally, the New York Department of Financial Services recently said: "Given the seriousness of the issue and the risk to all regulated entities, certain regulatory minimum standards are warranted, while not being overly prescriptive so that cybersecurity programs can match the relevant risks and keep pace with technological advances. Accordingly, this regulation is designed to promote the protection of customer information as well as the information technology systems of regulated entities. This regulation requires each company to assess its specific risk profile and design a program that addresses its risks in a robust fashion. Senior management must take this issue seriously and be responsible for the organization’s cybersecurity program and file an annual certification confirming compliance with these regulations. A regulated entity’s cybersecurity program must ensure the safety and soundness of the institution and protect its customers." It important to note both regulatory agencies are concerned with evaluating enterprise-wide cybersecurity risk – which, in turn, leads us back to the enterprise-wide risk management “plumbing” and risk governance processes and how the ERM-InfoSec interplay can be helpful in achieving organizational risk management objectives. As an example, we can consider how to use the NIST-CSF (National Institutes of Standard and Technology - Cybersecurity Framework) as a starting point for an enterprise-wide cyber risk identification exercise. The NIST framework offers a diagnostic approach for assessing an organization’s technical cyber risk profile (the current state) versus desired risk tolerance and outcomes (the target state). Separately, using a similar approach, ERM can be assessed through commonly adopted risk maturity evaluative frameworks. One such framework is the RIMS Risk Management Maturity model (RIMS-RMM). This model shares several diagnostic themes with the NIST CSF, including evaluations of risk identification, risk culture, risk resiliency and risk governance. (National Association of Insurance Commissioners, 2014) See also: How Insurtech Boosts Cyber Risk   The common themes between several functional topics within the two frameworks create an opportunity to explore the corollaries between the two frameworks. Scores can be mapped and linked, effectively creating an integrated overall score, by applying relativity factors that capture the directional relationships between the two frameworks. For instance, how might low technical cyber risk scores, such as weak DLP oversight, inform and potentially change the ERM score addressing risk (data) governance? When properly integrated, the NIST CSF and RIMS RMM provide a synchronized view on data governance, privacy and enterprise-wide cybersecurity performance. An integrated analysis, such as a combined NIST CSF plus RIMS RMM approach, helps an organization accelerate their ERM and InfoSec risk management performance and increases risk awareness. In turn, increasing risk awareness leads to becoming more risk astute. When an organization is more risk astute, it is maturing in its risk management thinking, as evidenced by positive return on risk investments and system-wide risk mitigation solutions prioritized and finely attuned to best support organizational growth and profitability. Most importantly, they are increasing their cyber resiliency while deploying strategic cyber risk management. The company that successfully integrates a robust cyber risk management approach and its ERM framework is at a distinct competitive advantage. Not only is such an organization effectively managing its resources and expenses; it is linking cyber security to its business goals, enterprise risk profile and strategic vision.

Yvette Connor

Profile picture for user YvetteConnor

Yvette Connor

Yvette Connor serves as Grant Thornton’s strategic risk management leader within risk advisory services. She has over 25 years of domestic and international risk management experience.


Christopher Mandel

Profile picture for user ChristopherMandel

Christopher Mandel

Christopher E. Mandel is senior vice president of strategic solutions for Sedgwick and director of the Sedgwick Institute. He pioneered the development of integrated risk management at USAA.