Download

Will You Own a Self-Driving Vehicle?

The questions are getting more complex as self-driving vehicles approach reality. It's crucial that we experiment and learn.

The introduction of self-driving vehicles (SDVs) poses many questions. Working for Zurich, I'm often asked about the insurance and liability implications: "What happens if my SDV is involved in an accident, and who pays?" Increasingly, I am facing a line of more technical and legal questioning. For example, "Who homologates the vehicle, approves its circulation, certifies that it complies to safety standards?" Or even, "Am I allowed to operate an SDV to run my morning errands?" I expect these questions to become more complex as we get closer to the reality of our purchasing our first SDVs.

As a strong supporter of public transport, I am keen to understand how the path to autonomy will influence urban buses, trams and the like. Will the trend for car clubs, and sharing in general, extend to SDVs, or will vehicles be mostly owned by individuals and fleet managers? And if SDVs do become a shared mode of transport, how will customers react to boarding a two-seater "autonomous pod," left dirty by that nice gentleman who just stepped out?

No one has a crystal ball that can predict the potential legal, cultural and behavioral impact of SDVs, so it's important that we experiment and learn -- like the researchers at CityMobil2 are doing with a number of demonstrations across Europe. Zurich has just announced it will work with them and, we hope, other similar organizations.

Every big oak was once a small acorn.


Domenico Savarese

Profile picture for user DomenicoSavarese

Domenico Savarese

Domenico Savarese has been the global head of proposition development for personal lines and the global lead of telematics for Zurich Insurance since 2013. Savarese has served as program director for Zurich Insurance, head of finance and deputy head of PMO for Kuoni Travel and engagement manager for McKinsey.

State of Workers' Comp in California

It isn't pretty. California has the highest costs in the U.S., and every time a law is changed the system grows even more complex.

|

At the 2015 California Workers' Compensation & Risk Conference, this panel of industry stakeholders weighed in on the overall condition, including cost drivers and legislation, affecting California's workers' compensation system:

Moderator: Mark Walls, VP communications and strategic analysis at Safety National

David North, CEO at Sedgwick

Kevin Confetti, deputy chief risk officer at University of California

Ann Schnure, VP risk management, claims, at Macy's

Dawn Watkins, AIC, PHR, ARM, director integrated disability management at LA Unified School District

Julius Young, partner at Boxer & Gerson

Richard M. Jacobsmeyer, founding partner at Shaw, Jacobsmeyer, Crain & Claffey

The first question was: How does the California's workers' compensation system compare with other states?

California ranks #1 in costs compared with the rest of the U.S. California simply has more claims that cost more money. That is why California is the most expensive and complicated state. Every time California changes a law, the system gets more complex. What influences workers' comp is far more than just the laws, though. The social norms are different in California. It is a unique culture of employment that affects everything. There are a lot of things that employers and the healthcare community do that are driving these costs.

Why are claims costs so expensive in the Los Angeles basin vs. the rest of California?

Injured employees are transferred away at a larger rate from the primary treating physician of the employer's choice. There is a very different treatment pattern compared with other states, and this medical treatment is driving costs for employers. Litigation rates are higher, which is part of the culture in that area. Very often, LA attorneys try to take medical control and send the injured employees to the doctors that the attorneys prefer. Attorneys and physicians who have had long-lasting relationships are referring almost exclusively to each other. Attorneys are aggressively advertising to injured workers, and workers are responding.

What else is driving workers' compensation costs in California as a whole?

Once an employee gets an attorney referral, it is out of the employer's hands. The employer no longer has the authority to properly take care of the injured worker. California is the only state where, if you do not like what you are paid, you file a lien. This has nothing to do with the quality of care for the injured worker. The root of so many of these issues is the doctor community in the state. Maybe the doctors need to be trained on billing and medical treatment utilization schedule  (MTUS), but it's believed that some may be billing higher than the fee schedule to see if someone will actually pay the higher rate billed. The most important person in workers' comp is the injured worker. We should be spending all the money that employers pay on things like bill review on helping the worker heal. Too much of the costs that employers pay are not going to the injured worker.

What concerns do you have about current legislation and case law affecting the system?

We, mistakenly, have allowed legislation to tell us how to comply. It has become much more about the process rather than helping an injured worker get better. Doctors will say how they think they should treat, but have to send the case through utilization review, which sometimes contradicts the doctor's opinion. This deflates that injured worker's confidence on whether he is getting the best care. It is possible that doctors are not trained on the MTUS and keep trying to push things through the system that shouldn't be. We should focus on how to better train doctors on the system. The system is so complicated. What employers need to do is try to stop the employees from getting into the system. We need to intervene fast. Get the employees good, quality medical care quickly and eliminate the potential for them to get stuck in the system.

How do you improve the quality of benefits to injured workers in California?

The least-likely employee to file a claim is the employee who thinks her employer cares about her. Employees are much less likely to litigate cases if the employer is providing them with good care and communication. That's the gold standard for trying to decrease litigation. It is so important for employers to reflect on how they are treating their injured workers. Are you treating them like a member of your team or just another expense? Often, they are afraid that they are going to lose their job. Let them know what workers' comp is and what they should expect. It is so complicated. Make sure they are well-informed and understand that return to work means they are not going to lose their job because of an injury. Claims examiners in California have a tough job. We need to hire smart people and give them appropriate workloads. They are the glue that holds everything together. California currently has a shortage of qualified adjusters, and it is a large problem. The industry, as a whole, needs to contribute to this issue so we can get quality people interested in this career path.

How to Stir Dialogue on Cyber Security

An architect explains what cyber security frameworks to "drop" into the emerging Security Enterprise Risk Management Program (SERMP).

|||||

While I continue another implementation of my Security Enterprise Risk Management Program (SERMP), I am also continuing to explore the program's flexibility, to help my colleagues in the information technology security field explain to others in the organization the level of risk they face and the progress being made in managing it. The SERMP tool and process can adapt to multiple frameworks, so I asked my colleague Steve Zalewski, a chief security architect, if he would share his thoughts on alternative frameworks that he might "drop" into the SERMP.

Steve:

The concept of SERMP is well grounded in practical experience, as you outlined in your previous article. It creates a great tool to start the dialogue between the two risk management functions: the established business risk team and the nascent IT cyber security risk function. You have accurately represented ISO 27000 with the 12 security domains outlined as a starting point to bring the teams to the table, providing a meaningful set of definitions to the IT security domains.

As these SERMP teams gain momentum and maturity, there are alternative security frameworks available that can provide additional perspectives for the business discussion. This will improve our outcomes against the ultimate goal of a balanced analysis of total risk based on the key business processes and business continuity plans.

Let me explain what I mean by this. Based on the "technical" security controls of ISO 27000 being populated into the SERMP tool, you have established a productive dialogue based on security capabilities, which is a bottom-up approach.

Grace:

Using a crowdsourcing approach, we have a diverse team that is gathering information and populating the SERMP tool, which is a "bottom-up approach," though I would liken it more to a "hunting gathering" approach, as we are collecting data and documentation related to governance, which is "top down." And, because we are seeking dialogue and information from various groups on the information that is readily available at the time, we are approaching the issue "sideways" too.

This might seem chaotic, but because of the SERMP tool and the disciplined procedure, we are able to make that tradeoff.

The ISO 27000 has been used for both of my implementations thus far, as this framework was chosen by the organization as the standard, but I'm eager to integrate other frameworks into the process.

chart1

Figure 1: Standard Technical Security Controls ISO 27000

Steve:

Compare this with the cyber security framework that was released based on security risk:

chart2

Figure 2: Cyber security Risk Function and Category Unique Identifiers. Source: NIST Framework for Improving Critical Infrastructure Cyber security Version 1.0

As you can see, this aligns to the notional information and decision flows as represented in the diagram below.

chart3

Figure 3: Notional Information and Decision Flows Within an Organization. Source: NIST Framework for Improving Critical Infrastructure Cyber security Version 1.0

Grace:

I can see incorporating the NIST framework by layering in additional categories with the current domains and functions. I would continue to document the strategies for each.

graph

Note: The reporting houses the above information for each domain, plus how the organization is managing the program: Establish, assess, treatment, monitor, review activities and metric tracking for: risk statement, risk impact, key risk indicators (KRIs), risk remediation initiatives, current state (KPI), target state (KRI) and projects.

Steve:

Information security risk frameworks are still maturing as the practice begins to mature. No single security framework is correct, so be flexible based on the maturity of your SERMP implementation, and don't be afraid to experiment with the newer risk-based frameworks as the team gains confidence in the information security arena.

Grace:

Steve can you outline for me how you see the difference between a security risk assessment (SERMP) and an IT security assessment?

Steve:

A security risk assessment methodology is based on the guidelines found in:

  • ISO/IEC 27001:2005, information technology - security techniques - information security management systems - requirements
  • NIST SP 800-30, risk management guide for information technology systems
  • BS 7799-3:2006, guidelines for information security risk assessment

A risk assessment scope is defined based on the most "critical" or "valuable" business information assets identified in regard to the potential impact to the business if the asset's confidentiality, integrity or availability was breached. Through data gathering and analysis, including business continuity plans, critical business processes analysis and critical business impact analysis, the assessment questionnaires, interviews and tests are determined. The observed organizational vulnerabilities to the threats, based on existing security controls, are assessed, and a risk analysis is performed.

The completion of a security risk gap analysis is to determine the organization's compliance with the appropriate regulations, laws and security standards. In addition, a security improvement plan is defined for each risk and "gap" identified, and the implementation of the risk treatment plan is prioritized according to the highest risk scores. The result is to reduce the organization's business risks to an "acceptable" level.

A security assessment methodology is based on the guidelines found in:

  • NIST SP 800-53, security and privacy controls for federal information systems and organizations

The goal of an IT security assessment (also known as a security audit, security review or network assessment), is to ensure that necessary security controls are integrated into the design and implementation of a project.

A properly completed security assessment should provide documentation outlining any security gaps between a project design and approved corporate security policies.

Management can address identified security gaps in three ways:

  • Management can decide to cancel the project
  • Management can allocate the necessary resources to correct the security gaps
  • Management can accept the risk based on an informed risk/reward analysis

In summary, the characteristics are: IT Security Assessment

  • Narrower scope and current state focus
  • Start and end date, with a final report
  • Conducted by IT security experts
  • Is a "point in time" assessment

SERMP

  • Broader scope and continuous improvement focus
  • Continuous review
  • Has a periodic re-evaluation date with a "living document" report
  • Conducted by mixture of personnel with varied backgrounds
  • Focus on reducing business process security risk by analyzing the associated security risks

Grace:

Steve, that was very helpful in distinguishing between these two very important, but distinct assessments. For SERMP, we use the high-level findings of the IT security assessment as one of the sources of content, so the IT security assessment is critical to the SERMP process. The SERMP provides a high-level report of the current risk levels and the maturity of the mitigations in place that will drive improvement in the IT security assessment.

As always it is great to collaborate with you, and I encourage other risk professionals to work closely with their information technology colleagues.

About Steve:

steve

Steve Zalewski has spent 10-plus years in the cybersecurity field and is currently the chief security architect at Levi Strauss, responsible for the company's enterprise security strategy. Before this, Steve was the enterprise security architect at Pacific Gas & Electric, leading the security architecture team responsible for the company's cybersecurity technical strategy and architecture. Other positions have included security manager at Kaiser Permanente and senior engineering/management positions developing storage networking, data protection solutions and operating systems. He has five patents in data protection and multi-processor operating system design and holds CISSP, CISM and CRISC security certifications.


Grace Crickette

Profile picture for user gracecrickette

Grace Crickette

Grace Crickette is a leader in enterprise risk management, risk financing, information technology implementation and security, health benefits and compliance, having operated in a variety of industries, ranging from equipment rental to healthcare, not-for-profit to a Fortune 500 and domestic and foreign operations.

Now Come Autonomous Trucks

While the focus has been on cars, an autonomous truck is now licensed to operate on U.S. roads -- another way to reduce accidents.

|

In 2012, nearly 40,000 people were killed on U.S. roads, and 90% of those fatalities were caused by driver error.

Imagine an advanced autonomous system that could avoid those deadly motor vehicle accidents. Even a system that works only on the highway -- where the technology has already been developed and where trucks spend the majority of their time -- can make a significant difference.

A new report has analyzed the impact of driverless cars on the incidence of fatal traffic accidents and concluded that, by removing human emotions and errors from the equation, we could reduce deaths on the road by 90%. That's almost 300,000 lives saved each decade in the U.S., and a saving of $190 billion each year in healthcare costs associated with accidents. If you expand this to global figures, driverless cars are set to save 10 million lives per decade.

There are now some trucks on the road that begin to fulfill that promise. Daimler Trucks North America's "Inspiration" freightliner semi-truck this year became the first legally operated autonomous commercial vehicle operating on U.S. highways.

For now, the Inspiration is basically a limited take on the autonomous truck. The driverless system engages when the truck is on the highway and ramps up speed. It then maintains a safe distance from other vehicles and stays in its own lane.

If the autonomous truck encounters a circumstance it can't handle (e.g., heavy snow or washed-out lane lines) it will alert the human driver that it's time for him to take over. But what this technology can do is reduce traffic accidents, and that's why I'm pretty excited about the whole thing.

A human driver has limited situational awareness. Autonomous trucks offer an extra set of eyes that continuously monitor a broad range of sensors (e.g., visible and infrared light and acoustic, including ultrasound), both passive and active, with a nearly 360-degree field of view.

Therefore, driverless vehicles can more quickly determine a safe reaction to potential hazards and initiate reactions faster than a human driver. For example, traffic collisions caused by human driver errors such as tailgatingrubbernecking and other forms of distracted or aggressive driving would be eliminated.

Safer and more efficient driving is the motivating force behind this emerging technology. It's not about catching 40 winks on the highway or watching an episode of your favorite show. As cool as that might be to imagine, no one is replacing the human as the ultimate decision-maker.


Daniel Holden

Profile picture for user DanielHolden

Daniel Holden

Dan Holden is the manager of corporate risk and insurance for Daimler Trucks North America (formerly Freightliner), a multinational truck manufacturer with total annual revenue of $15 billion. Holden has been in the insurance field for more than 30 years.

Identity Theft Can Be Double Whammy

Identity theft scammers can not only take your data but, under the guise of helping resolve your problem, trick you into providing more.

||

When it comes to data security and the real-life impact of identity theft, public awareness is at an all-time high. But there is still great confusion and ignorance about what it is, how it happens and what can be done to avoid the pitfalls of life after a data breach or personal compromise.

Most of us still feel flummoxed--and perhaps a bit panicked--when we get a phone call, an email or a letter saying our data or identity has been compromised. Even if it's a situation that can be easily remedied, like a compromised credit card, where the problem is relatively small, it's still frustrating. Even if the only real-life consequences are a day or two's wait for a replacement card and the need to notify a few creditors that your billing information has changed, you feel violated. You wonder if it's going to happen again. And depending on the source of the compromise and what's been taken, it may well happen again. So, you stew and wonder some more.

The unfortunate part is that identity thieves understand this. In the mad dash to understand the full ramifications of what's happened to you, you may expose yourself to further trouble--for instance, by providing your information to a phony identity theft resolution expert, only to be guided through a process of information shedding that brings about further compromise by the very data wolves in sheep's clothing who ran the scam in the first place.

Taking a few simple steps will help you avoid crooked "helpers" like these, as I explain in my book Swiped.

Be Prepared

If you don't subscribe to an identity theft resolution service or lack a plan of action before you suffer a personal compromise (other than the theft of a payment card, which can be solved with a couple of phone calls), you will need to spend more time and more money than you are probably prepared to spend. Then, after you have worked your way through the maze of law enforcement, credit bureau, creditor and record-keeping requirements necessary to put yourself back together again, you will almost assuredly spend additional time--more than you thought possible--rearranging the way you make your information available both online and in your everyday transactions.

For this to really work, you need to be willing to make a few adjustments in the way you approach your identity and your data hygiene.

The Best Defense Is a Good Offense

What the great majority of current and future identity theft victims fail to understand is that they really must be their own first line of defense. Because identity thieves can't realistically be completely stopped, you can instead focus on making yourself a harder target, and on being readier when the attack comes.

A simple practice like shredding your personal documents can help, but it's not a solution. Identity thieves can be anyone from a dental hygienist pilfering patient files to small-time crooks breaking into mailboxes or stealing unshredded garbage or tax-related documents during filing season. The more you know what the bad guys want and need, the better you can practice proactive data hygiene.

The fact of the matter is that when it comes to international crime syndicates that breach the databases of multibillion-dollar international corporations and sell the liberated information, deploying a paper shredder is like bringing a knife to a gunfight.

The above is an adapted excerpt from Swiped: How to Protect Yourself in a World Full of Scammers, Phishers and Identity Thieves, which hits bookstores everywhere Black Friday.


Adam Levin

Profile picture for user AdamLevin

Adam Levin

Adam K. Levin is a consumer advocate and a nationally recognized expert on security, privacy, identity theft, fraud, and personal finance. A former director of the New Jersey Division of Consumer Affairs, Levin is chairman and founder of IDT911 (Identity Theft 911) and chairman and co-founder of Credit.com .

What Is the Business of Workers' Comp?

Most workers' comp executives think they're in the insurance business, but they are not. History shows the perils of that misunderstanding.

At the risk of alienating most people within the workers' comp world, here's how things look from my desk:

Most workers' comp executives - C-suite residents included - do not understand the business they are in. They think they are in the insurance business - and they are not. They are in the medical and disability management business, with medical listed first in order of priority.

That statement is bound to lead more than a few readers to conclude I'm the one who doesn't know what I'm doing. For those willing to hear me out, press on - for the rest, see you in bankruptcy court.

Twenty-five years ago, the health insurance business was dominated by indemnity insurers and Blues plans; big insurers like Aetna, Travelers, Great West Life, Met Life and Connecticut General and smaller ones including Liberty Life, Home Life, Jefferson Pilot, Time and UnionMutual. Where are those indemnity insurers today?

With the exception of Aetna, none is in the business; the only reason Aetna survived is it took over USHealthcare, or, more accurately, USHealthcare took over Aetna. The Blues that became HMO-driven flourished, as did the then-tiny HMOs - Kaiser, UnitedHealthcare, Coventry. Why were these provider-centric models successful while the insurers were not? Simple: The health plans understood they were in the business of providing affordable medical care to members, while insurers thought they were in the business of protecting insureds from the financial consequences of ill health.

The parallels between the old indemnity insurers and most of today's workers' comp insurers are frightening. Senior management misunderstands their core deliverable; they think it is providing financial protection from industrial accidents, when in reality it is preventing losses and delivering quality medical care designed to return injured workers to maximum function.

That lack of understanding is no surprise, as most of the senior folks in top positions grew up in an industry where medical was a small piece of the claims dollar. Medical costs were considered a line item on a claim file or number on a loss run, and not "manageable" - not driven by process, outcomes, quality.

Think I'm wrong?

Then why is the industry focused almost entirely on buying medical care through huge discount-based networks populated by every doc capable of fogging a mirror (and some who can't)? Even with those huge networks, why is network penetration barely above 60% nationally? Why has adoption of outcome-based networks been a dismal failure? Why do so few workers' comp payers employ expert medical directors, and, among those who do, why don't those payers give those medical directors real authority? Why do non-medical people approve drugs, hospitalizations, surgeries, often overriding medical experts who know more and better?

Because senior management does not understand that success in their business is based on delivering high-quality medical care to injured workers.

At some point, some smart investor is going to figure this out, buy a book of business and a great third-party administrator (TPA) for several hundred million dollars, install management who understand this business is medically driven and proceed to make a very healthy profit. Alas, the current execs who don't get it will be retired long before their companies crater, leaving their mess behind for someone else to clean up.


Joseph Paduda

Profile picture for user JosephPaduda

Joseph Paduda

Joseph Paduda, the principal of Health Strategy Associates, is a nationally recognized expert in medical management in group health and workers' compensation, with deep experience in pharmacy services. Paduda also leads CompPharma, a consortium of pharmacy benefit managers active in workers' compensation.

Why Mental Health Matters in Work Comp

Mental health conditions are increasingly being recognized as risk factors for prolonged work absences, and even for no return to work.

|

At the 2015 Paradigm Innovation Symposium, Renée-Louise Franche, PhD, RPsych, clinical psychologist and consultant in work disability prevention and occupational health, presented a session discussing why mental health issues are so important in workers' compensation.

Mental health issues in injured workers can no longer be ignored. These conditions are increasingly being recognized as potential risk factors for prolonged work absences, and even for no return to work within the context of workers' compensation.

Why mental health matters in work disability prevention?

  • One-year prevalence of mental disorders in North America ranges from 12% to 26%. For depression, this is 4% to 7%.
  • Worldwide, mental health conditions are the leading cause of disability in high-income countries, accounting for one-third of new disability claims in Western countries.
  • Mental health-related disability is more frequent in young adults.
  • Workers with mental health conditions have earlier retirements than those without.
  • Studies show that mental health issues have a significant impact on claim duration.
  • Another study showed that, within the first 12 months post-injury, more than 50% of workers experienced clinically relative depressive symptoms at some point during their claim. This is highest during the first month following the accident.
  • There is a significant spillover effect to the families of injured workers. Family members of injured workers are three times more likely to be hospitalized three months after the injury than three months before the injury. It is speculated that the distraction of the injured family member leads to unsafe behaviors.

What works in return-to-work interventions?

  • It is important to focus on ability and function rather than disability. The symptoms and diagnosis need to be deemphasized.
  • Worker expectations of recovery are the single most-determining factor in the ability to return to work. Attitude and state of mind are important.
  • Suitable and safe modified work and return-to-work coordination must be available.
  • A workplace culture of respect and support helps to promote return to work.
  • Claims-related stress/perceived injustices have a very negative impact on return to work.
  • Purely clinical approaches lead to purely clinical outcomes. There needs to be an integrated approach between the physician and the workplace.
  • There must be considerate early contact with the injured worker and continued contact to maintain job attachment.
  • There should be a return-to-work coordinator to facilitate labor/employer cooperation and ensure the healthcare provider understands the return-to-work goals.

What needs to improve for workers with mental health issues?

  • Access to care is a concern. A quarter of Americans have inadequate access to mental health services.
  • Healthcare for mental health conditions is NOT work-focused. There are limited tools and published standards around return to work.
  • Workers feel stigmatized and disrespected, and that there is suspicion about the legitimacy of their condition.

Best practices for return-to-work for workers with mental health conditions:

  • Facilitation of access to clinical treatment for those who need it. Too often, this treatment is delayed. Delays in treatment will, ultimately, delay recovery.
  • Work-focused clinical interventions.
  • Facilitation of navigation of the systems involved.
  • Improved processes, leading to improved sense of fairness.
  • Early identification and screening to identify workers who are high risk for psychosocial complications, and assigning those claims to specialized adjusters.
  • A case manager who plays an important role in humanizing communications, decreasing adversary feelings, clarifying the claim process, decreasing delays and developing more accurate expectations in the worker.
  • Judicious use of independent medical exams. Injured workers view these as a very adversarial experience, which usually leads to litigation.

Best bets for future investments:

  • Perceived justice. Perceived injustice leads to longer disability, higher pain complaints, more depression and increased narcotic use. It is important to fully explain the workers' compensation system to injured workers, including the benefits that they will receive and the role of the injured worker in his recovery. People need to be treated with respect and receive information that is clear, accurate and timely.
  • Development of soft skills in the front line claims team. This includes communication skills, conflict-resolution skills and training related to identifying potential mental health issues.
  • Early screening for psychosocial issues so that appropriate intervention strategies can be implemented.

A Word With Shefi: Applebaum at ISG

Stephen Applebaum underscores the need to "leapfrog current incremental innovation around connected vehicle and data technology."

This is part of a series of interviews by Shefi Ben Hutta with insurance practitioners who bring an interesting perspective to their work and to the industry as a whole. Here, she speaks with Stephen Applebaum, managing partner, Insurance Solutions Group, and senior adviser at StoneRidge Advisors, who describes the implications of the "torrents of data that will flow from connected cars, homes, buildings and people."

To see more of the "A Word With Shefi" series, visit her thought leader profile. To subscribe to her free newsletter, Insurance Entertainment, click here.

Describe what you do in 50 words or less:

I provide consulting and advisory services to participants across the North American auto and property insurance ecosystem, which leverage my experience, industry contacts and understanding of innovation and emerging technologies to drive meaningful, measurable improvement in revenue, market share, process, profitability and user and customer experience.

What led you to your career in insurance?

Serendipity, actually. An early management consulting engagement with a technology-based startup providing insurance claims solutions to P&C carriers led to a full-time operational and management role and ultimately a very exciting and rewarding 30-year career spanning several different companies that continues today.

What emerging technology will change how insurance is sold?

Prescriptive analytics applied to the torrents of data that will flow from connected cars, homes, buildings and people - enabled by mobile devices and embedded sensors - will transform virtually every aspect of how insurance products are developed, priced, packaged and sold, and how risk is managed in general.

A carrier you highly value for its innovative culture?

Among the many top-tier carriers that have invested in and developed innovative cultures, USAA stands out because of its highly focused and fierce dedication to pursuing constant improvement and technological innovation in the pursuit of providing superior service excellence to its "members" in insurance as well as the full range of its financial services.

You recently published an article on "Disruption in the Automotive Ecosystem." What tip do you have for companies looking beyond their core value to offer innovative solutions in the auto ecosystem?

I suggest that auto insurance carriers focus on leapfrogging current incremental innovation around connected vehicle and data technologies and begin designing and developing the auto insurance products and services of the future. These will likely be very different than anything offered today and will be enabled by enormous amounts of data flowing from not just connected cars but the broader Internet of Things. They may include personalized, utilization-based micro auto insurance coverages, ride-and-car sharing insurance solutions for owners, drivers and passengers, risk management services from behavioral driving modification assistance to location-based and contextual alerts for commercial favorites as well as navigational, traffic, roadside assistance and weather conditions.

You've had more than 25 years of consulting experience in the P&C space. What piece of advice have you found to always be relevant regardless of the subject matter?

I regularly ask myself, "What am I doing, and why am I doing it, and is this the best possible use of my time and talents?" It sounds so simplistic, but if you do it honestly you will find it very valuable.

You are a frequent chairman in industry conferences. In fact, you are the chairman of a coming event on IoT in Miami in December. Who should be attending and why?

Anyone who plans to work, invest and succeed anywhere in the insurance ecosystem over the next decade and beyond should attend. This includes insurance C-level executives, heads of innovation, strategy, claims and innovation, underwriting, business development, product development, strategy, design and innovation, heads of IT, technology and digital, IoT technology companies and startups and regulators.

When you are not consulting on insurance or hosting insurance events, you are most likely...?

Reading, watching and listening to anything and everything that relates to my work - which is, in fact, also my hobby.


Shefi Ben Hutta

Profile picture for user ShefiBenHutta

Shefi Ben Hutta

Shefi Ben Hutta is the founder of InsuranceEntertainment.com, a refreshing blog offering insurance news and media that Millennials can relate to. Originally from Israel, she entered the U.S. insurance space in 2007 and since then has gained experience in online rating models.

How to Remove Fear in Risk Management

Fear creates a culture that inhibits decisions on risk. Firms must move to SRM, or "sustainable" risk management.

Someone is looking over your shoulder, and you know who it is. If you're the CEO, it's your board and shareholders. On the factory floor or in the cubicles, it's the foreman or the supervisor. But just as often these days, the sources of anxiety and caution confronting risk managers may not be corporate employees at all. Rapidly shifting technology that is often difficult to understand and measure, unfamiliar demographics, expanding globalization, and ever more stringent regulatory compliance requirements are now part of an anxiety- producing stew that organizations' risk managers must understand and deal with. All these forces threaten a corporation's revenue, margins, profitability, and overall competitiveness more quickly and unpredictably than ever.

Consequently, if you are an internal auditor - the person responsible for assessing and helping improve the risk management process - your chair these days may feel more like a hot seat. Which of the decisions daily barraging a modern corporation should be the higher priorities? And how, in a business world of frequent disruption, will you, your superiors, and those who report to you weigh and mitigate the waves of serious risks facing the company nonstop? What are the most important metrics to use for any given risk issue? Can the company rely solely on its in-house staff to analyze and resolve unforeseen and often unforeseeable problems?

Just as important, how will the enterprise as a whole handle these issues and make necessary decisions? How does company culture get in the way of using risk management effectively, to reach the decisions that will help the company grow and become more competitive, and how can sustainable risk management (SRM) assist?

Company managers often are not encouraged to exercise independent judgment, even when they are the acknowledged experts. Without transparency and effective multilevel communications in their company, managers are likely to be wary of crossing unseen boundaries, suspect that hidden agendas are controlling important decisions, or feel isolated and unsure of the enterprise objectives that should help guide their decisions. Moreover, anxiety about making important decisions is common in organizations that don't give their decision-makers the tools and data required to make intelligent risk analyses. Without confidence that they understand the risks associated with a decision, and in a culture where the consequences of a bad outcome are punitive, managers understandably are likely to be cautious.

Behind employees' hesitation to make and express independent judgments or to make decisions can be a corporate culture of mistrust, caution, and covering one's backside. In other words, a culture of fear - fear of losing face, losing a contract, losing revenue, losing political advantage, losing a job.

A culture of isolation and timidity defeats collaboration, creativity, transparency, and the ability of a corporation to objectively analyze the broad range of risks it faces each day. It can render the internal audit function far less effective and useful than it should be and can be. In this environment, the internal audit function may mistakenly be seen solely as a means of uncovering errors, assigning blame, and enforcing penalties. Managers may be understandably reluctant to provide anything other than the most general and diluted information about their operations and decisions.

One need not wade through the scientific research about the impact fear has on decision- making to understand how destructive it can be. The brain has separate centers for processing fearful and rewarding experiences. As Dr. Gregory Berns, director of the Center for Neuropolicy at Emory University, has explained, "The most concrete thing neuroscience tells us is that when the fear system of the brain is active, exploratory activity and risk-taking are turned off." Good decisions in this state are unlikely. "Fear prompts retreat. It is the antipode to progress," said Berns. "Just when we need new ideas most, everyone is seized up in fear, trying to prevent losing what we have left."

In this way, fear can nullify or dilute a company's risk management processes. An effective SRM program, however, encourages and supports an environment that minimizes fear, reduces uncertainty, and increases transparency and confidence in decision-making throughout the enterprise.

Barriers to Solutions

It may seem that established tenets of good corporate governance already include rooting out the fear, indifference, lack of collaboration, and siloed decision-making that stand in the way of optimizing risk management. After all, most companies talk an excellent game when it comes to collaboration and open and honest risk analysis. Too few, however, have developed the internal mettle to tolerate it.

Starting with assessing corporate culture and change management practices, internal auditors can play an important role in transforming the boilerplate talk into sustainable programs. They can provide unbiased, to-the-point assessments, independent of internal politics. The problems they find and the solutions they recommend can be critical for a company seeking to develop the capacity for SRM. But whether from too much caution and resignation or just fear of change, many internal auditors say the structure of their jobs discourages them from alerting their companies to critical gaps in risk assessment and mitigation.

A recent global study by The Institute of Internal Auditors (IIA) Research Foundation spotlights some of the problem areas. Not even two-thirds of the surveyed chief audit executives (CAEs) said they consult with division or business heads when they develop audit plans. Only slightly more than half said they consult with audit committees. There may be many reasons for this audit-in-isolation phenomenon, but it commonly occurs in companies that do not value the risk management process and therefore do not prioritize it. The phenomenon occurs in companies where key players are not encouraged to speak up.

Just one-third of audit plans are updated three or more times a year, the study found. This means that CAEs may be overlooking important changes in the business environment. No wonder only 57 percent said that their internal audit departments were "fully aligned or almost fully aligned" with the enterprise strategic plan. This kind of exclusion signals that leadership does not embrace the people responsible for monitoring management of the company's risk and that the audit function is not seen as a critical part of the management process.

Our experience with clients reflects these findings and shows that risk management professionals themselves may be at least partially responsible for the isolation and erosion of their programs. They could assume, for instance, that the value and relevance of SRM are obvious and not consistently sell a program that's underway, neglecting to point out its continuing value, highlight its successes, and develop metrics that are easily understandable.

The program itself may not be as inclusive as it should be. Sometimes risk management processes are not designed to seek out and incorporate the views of front-line employees. Any effective SRM process, however, must reach into the depths of company operations. At the same time, employees at all levels often are not trained well in how to assess and evaluate risk. Employees may be able to calculate some risk in dollar terms without appreciating that they also should be looking at, for example, threats to customer satisfaction, employee safety, and regulatory and contract compliance.

Too often, as well, an unappreciated or ineffective risk management program does not account for the unique characteristics and business objectives of the corporation. Organizations sometimes employ a cookie-cutter approach to developing a risk management framework that's not calibrated to address essential and distinctive company attributes.

Sometimes risk reporting to the board and top executive levels may be so extensive and detailed that no one reads the reports. Or risk reporting may be so superficial that its assessments and proposed solutions carry little weight. When risk management is not seen as a source of continuous improvement for the organization, risk management funding may be erratic or inadequate, its staffing just an afterthought, and its placement in the corporate hierarchy too isolated to be effective.

Working Toward a More Viable Program

An SRM program protects and advances the organization's primary business objectives. To do their job effectively, risk management leaders must be included as members of the executive management team. Their inclusion helps to ensure that consideration of risks is incorporated into every significant strategic decision.

It is also possible that a company and its leadership simply are not prepared for the important cultural shift required to champion SRM. All too typically, executives are experts at shifting blame, pointing fingers, and covering their reputations when something goes wrong or hard decisions must be made.

SRM requires a no-blame environment, a collaborative process in which personnel work together to assess and solve problems without fear that their careers will suffer or they will lose the confidence of their peers. A frank and constructive assessment of an operational failure, for instance, is possible only when, instead of trying to find fault, the evaluation concentrates on solutions to keep the failure from happening again. This collaborative approach is not common enough in modern corporations.

Why SRM Is Worth It

The benefits of developing an open, fearless, and transparent SRM program ripple through every level of the enterprise. The program helps ensure that the company can perform with confidence and agility in the face of unpredictable events and shifting economic conditions. It supports the development of accurate, timely, and relevant metrics that reduce uncertainty in decision-making. It provides an effective process for dealing with emerging technologies, surprising moves by competitors, market uncertainties, natural disasters, and even internal scandals. When the program is working, the board, C-suite executives, and managers at all levels understand the kinds of risks the company must deal with and then use that awareness when making their decisions.

An active and embedded SRM program, visibly supported by leaders, regularly refreshes the managers' awareness and stimulates their insights concerning the shifting market and business conditions that pose the greatest risks to the company's operations. Employees work collaboratively with their supervisors and are asked to help solve missteps rather than being blamed or punished for them.

SRM offers continuing opportunities to save costs and improve productivity. It can reduce operational and material losses and waste and spotlight process improvements. SRM more closely aligns people, assets, processes, and technology with the organization's business strategies. It also reassures the board and other stakeholders that compliance issues are being addressed and that company assets and reputation are being protected. The results - which we see time and again - include increased growth, improved profitability, and higher staff morale.


Marc Dominus

Profile picture for user MarcDominus

Marc Dominus

Marc Dominus is a management consultant and practitioner who excels at enterprise risk management (ERM) implementation, enterprise risk assessment (ERA), executive facilitation, training and management workshop design.

New Insurance Models: The View From Asia

Innovative companies in Asia are, for instance, selling return insurance for items bought on Alibaba or marketing via a WeChat app.

Recently, I chaired the 4th annual Asia Insurance CIO Technology summit in Jakarta, Indonesia. The experience brought me into contact with an entirely different set of insurers and insurance technology players. I was rewarded with a fresh view on the challenges and opportunities of insurance during an era of disruptive innovation, as well as a new perspective on how Asian insurers are creating and launching products, defining new channels and new models to out-innovate the competition.

I should state at the outset that Asian insurers aren't doing everything differently than North American and European insurers. It is a global era. In many ways, their competitive issues are similar. We are all having the same conversations. As I considered the similarities, however, it made the small differences stand out. Just as Asia is hours ahead of the Western world throughout the day, I had the strange feeling that I was listening to the ends of conversations that are only beginning in other parts of the world. Because populations, cultures, use of digital technology and the nature of businesses vary, I thought I would share a short list of insights from my eavesdropping in an effort to shed light on how disruption is being embraced elsewhere and how it could ripple through the industry. I'll center my thoughts on models, mandates and marketing.

Models

Everyone is discussing models. Business models. Technology models. Distribution models. Transaction models. There is good reason. It's a model v. model world, and Asia-Pacific insurers know that the model is the center of a business. For the outer layer to be responsive, the business model can't be a slow-moving leviathan. Disruption has the disturbing tendency to render perfectly good models obsolete. Creating a responsive, obsolescent-proof business model is of great interest to Asian insurers, which are responding to radically different consumer expectations and competitive models than in prior decades.

Traditional insurers at the conference (as well as challengers) are aggressively rethinking the insurance business model. Some believe that insurance will be run more in an open ecosystem, becoming more fragmented and niche-focused, building on the micro concept. If an insurer can embed products in other business models/industries, especially those with high-frequency transactions, then they capture the opportunity for both a new distribution channel and a new product. New Distribution Channel + New Product = New Market Opportunity.

These are areas where insurers can see quantum leaps in growth, yet they are also the areas where insurers are most susceptible to start-ups beating them to the punch.

Mandates

Three clear mandates stood out above all others for Asian insurers - the role of CIOs, the necessity of new cyber security solutions and a new, enterprise-wide look at analytics.

For CIOs, the clarion call was for a rapid advancement and widening of scope for their role within the insurance organization. CIOs must become change agents and grow in influence. They must be active in technology review and adoption, more collaborative with CMOs regarding digital platforms and data sharing and more effective at translating business vision into system and process transformation.

Cybersecurity is a never-ending mandate that also seems to never have the perfect solution. It was universally agreed-upon that today's security measures have the frustrating trait of being mostly temporary solutions. Blockchain technology (currently in use by Bitcoin, among others) was discussed as a more permanent solution for many security issues. Blockchain use makes transaction fraud nearly impossible. Verification of transaction authenticity is instant and can be performed by any trusted source, from any trusted location.

On a broader note, however, it was conceded that security is no longer just an IT issue, but it is a board-level, organization-wide imperative because security concerns the full enterprise. Boards must fund and address cybersecurity across three aspects: confidentiality, availability and integrity.

Enterprise-wide analytics was another organizational mandate. Some Asian insurers are moving toward using end-to-end analytics solutions that cross the enterprise in an effort to gain a single client view and execute a targeted pipeline, with unified campaigns and advertising. Analytics will also give them risk- and assessment-based pricing, improved predictability for loss prevention and better management of claims trends, recovery and services.

Marketing

Insurers are rapidly moving from product-driven to customer-driven strategies and from traditional distribution channels (such as agents) to an array of channels based on customer choice. At the same time that Asian insurers are looking at relevant business models, they are diving deeply into how marketing tactics may completely shift from a central hub to a decentralized "micro" model. The industry spark has been a short list of both established insurers and start-ups that are capturing new business through new marketing methods, new partnerships and new market spaces.

ZhongAn, for example, is selling return insurance for anything bought on Alibaba. Huatai Life is promoting unit-linked policies on JD.com and selling A&H insurance via a WeChat app. PICC Life has found a distribution partner in Qunar.com, an online travel information provider. These examples require a completely different, high-volume, interaction-based, data-rich, small-issue marketing plan. That kind of marketing will prove to be of great value to insurers that have added flexible, transaction-capable core insurance systems...that are cloud-based to scale rapidly.

Aggregators are now commonplace in insurance, and Asian insurers are looking at how this channel will affect their business, as well as how to use aggregators as a tool for competitive advantage. GoBear, currently selling in Singapore and Thailand, was given as a prime example of how aggregators represent the future of insurance shopping. GoBear isn't just an aggregator. It is an innovator, revamping the concept of insurance relationships. GoBear Matchmaker, for example, will allow a prospect to pick insurance but also allow the insurer to pick prospects/clients. GoBear Groups will leverage groups/crowd sourcing.

What do these M's add up to?

Insurance business models, mandates and marketing are all ripe for inspection and change. In some ways, Asian insurers are in a better position for these ground-shaking industry changes because so many of them recognize the stakes involved and the cultural shift required to thrive. Asian populations and culture are ready to embrace technology solutions to meet consumer demands. As all insurers globally address their models, mandates and marketing, it will be fascinating and educational to see how quickly the different markets adapt and are emerging as innovative leaders and how these regional innovations will influence other regions as they turn into global solutions.

One thing was clear to me in my time in Jakarta - Asian insurers are optimistic, active and excited about the road ahead.


Denise Garth

Profile picture for user DeniseGarth

Denise Garth

Denise Garth is senior vice president, strategic marketing, responsible for leading marketing, industry relations and innovation in support of Majesco's client-centric strategy.