Download

How to Find Mobility Solutions (Part 2)

Until insurers (and agents and brokers) can operate entirely using apps on smart devices, they can't claim to have mobility solutions.

Before continuing from the "How to Find Mobility Solutions (Part 1)" post, I want to repeat my bias: I think that until insurers, and insurance agencies/brokers, can operate entirely using apps on smart device they can't really call themselves "mobile-next." Potential insurance mobility solutions Focus on enabling producers to use a smart device that has the requisite apps to:
  • Manage their day (and week and month) -- seeing list of sales opportunities, setting up appointments, finding meeting locations and going to meetings, using the native calendar/GPS/mapping capabilities of the smart device
  • Get notices about traffic conditions and suggested alternative routes to take if the producer is driving to a meeting
  • Get alerts about severe weather
  • Pull information about the customer from an agency management system or a carrier's customer relationship management (CRM) system before the meeting
  • Note comments about the progress of each sale after each meeting, whether by using the keyboard, stylus (if applicable) or voice entry
  • See charts showing progress-to-date or progress-to-goals
  • Pull all relevant forms into a "potential sale area" on the device -- forms related to the sale of a specific line of insurance and required by the insurance company or regulators
  • View the status of each sale in process and see the steps the carrier still needs to complete, with time estimates of each step
  • Get a quote for any insurance products the producer is allowed to sell
  • Walk a prospect through a policy application form either on the producer's device or by sending it to the prospect's smart device
  • Coordinate a 3-way video session with a subject-matter expert, the prospective client and the producer to answer questions the prospect or producer might have about the insurance product
  • Start a video session with a customer-service representative (CSR) or other colleague in the agency or in the carrier to ask questions or collaborate on an issue - from campaign management to new products to new requirements triggered by new regulations
  • Complete the policy application form, including getting the prospect's e-signature if that can be done at the moment. If completion isn't possible at the time of the meeting with the prospect, then enable the producer to store the policy application and filled-in data on the producer's smart device and also upload the information to the relevant agency or carrier systems
  • Get alerts about any of the producer's customers filing a claim, including the "when, where and why" of the claim
  • See how much time until the next meeting takes place (this is specifically for a smart watch) and get an alert (sound or haptic touch on the wrist) when the producer is close to or at a meeting location.
I realize this is only a starter list of mobile applications for a producer. What would you add?

Barry Rabkin

Profile picture for user BarryRabkin

Barry Rabkin

Barry Rabkin is a technology-focused insurance industry analyst. His research focuses on areas where current and emerging technology affects insurance commerce, markets, customers and channels. He has been involved with the insurance industry for more than 35 years.

It’s Time for a Data Breach Warning Label

Warning labels are required on food and credit card contracts. It's time to make companies list data breaches and how they were handled.

|
The breach at Home Depot is only the most recent in a torrent of high-profile data compromises. Data and identity-related crimes are at record levels. Consumers are in uncharted territory, which raises a question: Is it time to do for data breaches and cybersecurity what the nutritional label did for food? I believe we need a Breach Disclosure Box, and that it can be a powerful consumer information and education tool. Once just a normal part of doing business, data breaches today can sap a company’s bottom line -- and that's the best-case scenario. At their worst, data breaches represent an extinction-level event. The real-world effects for consumers can be catastrophic. Because there is a patchwork of state and federal laws related to data security—some good, some bad, all indecipherable—and none that work together, it’s impossible to know just how safe your personally identifiable information is, and has been, at the places where you shop and with the companies and professional organizations where you do business. Data security, identity-related consumer issues and privacy are all areas screaming for big-picture solutions. This is a situation in search of a paradigm shift—one that produces tools that enable consumers to make informed choices. There is a precedent that could serve as a template. It was passed in 1988, though not implemented until 2000. You may recognize its name—it’s called the Schumer Box. This is the law that put the fine print of credit terms and conditions in your face—bigger, bolder and easier to understand. You see it all the time featured in those countless pleas for your credit business that land in your email and your mailbox. The Schumer Box is simple. It requires that financial services companies provide certain information to the consumer when making a pitch for their business—information like long-term rates, the annual percentage rate for purchases and the cost of financing—and that the information be displayed in a standardized fashion. The Schumer Box is to credit cards what the nutritional label is to food. A Concise Disclosure for Breaches The Breach Disclosure Box that I am proposing would need to be simple, too. While I believe it is important to create a system that informs consumers about breaches, bear in mind that all breaches are not alike. There are breaches where the only piece of compromised information was a credit card number, which can be easily replaced and for which the consumer had zero liability. Then there are breaches involving Social Security numbers, detailed banking data or personal health information. These are very different situations. But they all share one thing in common: Something about you is “out there” and can be used by a criminal to commit either a crime against you or in your name. The “solution” — regardless of a breach’s severity — is the same. I place “solution” in scare quotes because it’s a misnomer to talk about solutions and identity-related crime in the same breath. There is no solution to the pandemic, only containment strategies and best practices. The Breach Disclosure Box would be a crucial part of data-related best practices at the consumer level where it’s all about the 3 M's: Minimizing your exposure, monitoring your public records and financial accounts and managing any damage that occurs from data compromises. Best practices can mean the difference between having a bad day and being financially ruined (or worse), and knowledge of a company’s data security track record can help consumers be better-informed about the risks they’re taking – and ultimately to decide if the risk is worth it. The Breach Disclosure Box would also be a catalyst for companies to step up their game on data security as well as design and implement a breach preparedness plan that promotes an urgent, transparent and empathetic response to any compromise of consumer and employee data. While the following list of Breach Box disclosures could be longer or shorter, the basic idea of a Breach Disclosure Box is essential to consumer safety in this ever-changing and crafty world of data-related crime and data breaches. The box should list:
  • How many times has this company been breached within the past five years?
  • If there has been a breach, what kind(s) of information was exposed?
  • Does this company encrypt all consumer and employee data?
  • Does this company have a breach notification policy?
  • What did the company offer affected consumers?
  • What type(s) of information are customers obligated, or not obligated, to provide?
  • Best practices for avoiding victimization (The 3 M’s)
The contents of the Breach Disclosure Box would ultimately have to be framed by lawmakers and interested parties intent on limiting the amount of ink spilled (or bytes used) to comply with whatever the legislation looks like when it leaves committee; but this bipartisan issue goes way beyond blue state-red state politics. When it comes to data-related crime, we’re all in the same state—a state of emergency.

Alternative Strategies for Provider Networks

Although dealing with provider networks is wildly complex, there are concrete steps that employers can take to cut their medical costs.

In this second article regarding sustainability of provider networks and managing health plan costs, we will focus on carve-out programs, integration of provider delivery models and direct contracting. As referenced in the first article, the Affordable Care Act (ACA) has hurt re-pricing through preferred provider networks (PPNs). Claim amounts being billed by specialty and institutional providers has escalated to such a level that preferred provider organizations (PPOs) have lost much of their appeal. As a result, the introduction of commercial accountable care organizations (ACOs), direct employer/provider contracting, narrow network arrangements and cost-to-charge methodologies have gained significant market share. While the self-funded industry has begun applying many of these alternatives, a high percentage of employers are unwilling to fully embrace some of these changes. Instead, we are seeing intermediate steps through the application of network carve-outs, integration of existing PPOs with specialty care vendors and limited direct contracting. What outcomes do these intermediate steps offer an employer? To start with, a better control of healthcare consumption and lower overall claim costs. Let’s explore the basics of network carve-out programs. The simplest carve-out is an organ transplant product that removes claims from the underlying medical excess coverage and places them with a separate policy. In most cases, the transplant policy includes a centers of excellence network where the procedure must be completed for 100% of the claim to be eligible for reimbursement. When a non-participating facility provides the service, reimbursement may be limited to a lower percentage of the bill and will in many cases have caps. These products may include individual deductibles, waiting periods and lifetime maximums. Less common carve-out solutions are non-risk bearing and target specific treatment types, such as renal dialysis or surgical events. A renal or surgical carve-out is accomplished through a change in plan document provisions that move the service to a non-network benefit. This can be a challenge when dealing with national PPOs, which typically include these service providers in their networks. When considering any form of carve-out program, the client should take care to avoid any reference to a specific disease state and mind the gaps that could potentially exist between the plan document, underlying medical stop loss policy and carve-out policy or provision. The industry is buzzing with the term “transparency,” yet most people are unable to determine the actual cost of service provided to patients. Solutions include the integration of existing PPO networks and specialty care providers through direct contracting and domestic tourism. Additionally, a number of surgical centers are now publishing fee schedules and treatment outcomes online. This disclosure is enticing patients to acquire services in these facilities. The result is a creation of carve-out referral agreements for self-funded employers with fees significantly lower than the most aggressive PPO contract. If the initial reports are accurate, then, in addition to significant savings, patients are experiencing shorter recovery times and fewer complications than through traditional networks. We are also seeing an integration of specialty care providers with traditional networks as a cost-effective tool. In our experience, clients have integrated direct contracts with oncologists, orthopedists, surgical centers, dialysis centers and pain management clinics to more effectively manage care and cost. This approach may be challenged by traditional PPO networks, but the outcome is worth the effort. In a number of cases, we have found it effective to integrate PPOs for institutional services only and contract directly with medical groups based on a capitated model. In other situations, we have contracted with a PPO network for professional services tied to the Medicare Regionally Based Relative Value Schedule (RBRVS) and re-priced the institutional claims on a cost-to-charge or referenced-based pricing scenario. We will discuss reference-based pricing more in a coming article. For PPOs to remain relevant, they must adapt to these emerging innovative solutions. For some, innovation will start with direct contracting on behalf of our client health plans. The process of direct contracting can be relatively painless when working with an independent practice association (IPA) or multispecialty medical group. The purpose of these groups is to establish and oversee patient protocols, referrals and outcomes management on behalf of their member providers with health plans and health maintenance organizations (HMOs). Medical groups typically contract with payers through discounted fee for service, Medicare RBRVS or capitation (pre-payment). While direct contracting can take many forms, our discussion will focus on provider engagement through capitation arrangements. Since ACA's implementation, providers have become more receptive to assumption of risk through direct capitation agreements with employer groups. In its purest form, capitation is essentially a monthly retainer paid to the provider for services to be rendered to the covered member. The provider is then responsible to deliver care with a goal to making a profit from the monthly pre-payment. For this to be effective, the provider must have a patient population whose utilization and medical histories support this methodology. Some may ask how capitation is possible without an HMO license. In some states, such as California, laws allowing the creation of HMOs do not require licensing for pre-payment arrangements when risk-sharing between various medical groups and institutions does not exist. Therefore, if a medical group contracts without sharing in a profit or risk pool with other not-related practices, capitation may be allowed. This approach has been implemented and successfully tested through the Department of Managed Healthcare in California. With this in mind, I would caution employers from running out to look for a willing medical group. The challenge is to find the right medical group that can meet all of the client’s healthcare needs. Will the capitated approach work with institutional providers? The simple answer is yes, though in our experience the process is difficult because many facilities struggle to clearly identify cost of care, and hospitals do not control direction of care.  In settings where capitated institutional models are not practical, we have utilized hospital-only PPO carve-out and referenced-based reimbursement solutions with varying degrees of success. Providers are rushing to establish community risk assumption models, resulting in the elimination of traditional insurance contracts. We will address the provider direct model more in the following article. While we have focused on direct contracting through capitation, I want to briefly introduce another successful approach that integrates current PPO contracting methods with HMO-type protocol management and measurements. The measurements may include average length of stay, bed days per thousand, re-admission and encounter frequency, delivery setting, prescription dispensing and adherence to published standards of care. Practice management providers may participate in profit sharing even in a self-funded plan. This model is not commonly available through third-party administrators (TPAs) because most systems are not equipped to support the protocol and outcomes management required for risk-sharing models. The TPAs with the greatest potential for administering these programs are those that are owned by hospital or provider organizations and that manage risk on behalf of HMO contracts. That being said, we have identified several TPAs that offer these services to self-funded employer plans. The topic of provider contracting will be debated for years to come, and the number of opinions are as great as the options they represent. The challenge for us today is to move the needle of cost management and improved outcomes forward.

John Youngs

Profile picture for user JohnYoungs

John Youngs

John Youngs is the chairman and CEO of OneSource StopLoss Insurance Services. He entered the insurance industry in 1983, working as a broker, and moved to the insurer side in 1989, with a focus on large group self-funded, group life and long-term disability and development of community health plans, the precursor of affordable care organizations.

Chasing the Right Numbers on Claims

Metrics are great, but only if they're the right numbers, based on the right goals, and aren't distorted by the time they reach the daily staff.

Managing a claims operation is challenging. There are so many moving parts, dynamics and procedures. Information comes gushing in like a fire hose, making it difficult for many companies to effectively assemble and organize it. It's crucial to help claims divisions focus on the right numbers instead of chasing numbers that have no value. Most claims leaders know that there are a few factors that affect the majority of claim outcomes. However, many times organizations will mistakenly target metrics “for metrics' sake,” at the expense of common sense. Traditionally, a claims supervisor or branch manager will receive metric targets from senior leadership. Unfortunately, the intent of these goals is skewed dramatically by the time they reach front-line personnel. For example, let’s take a company that wants to improve customer service by inspecting vehicle damage the same business day. While this is a noble idea and has the potential to increase customer satisfaction, branch level managers are often forced to abandon rational thinking to meet a specific “inspection metric” or quota. Managers will chase the numbers to obtain an inspection, often having staff appraisers take photos of damaged vehicles over fences or taking shortcuts in an attempt to meet requirements. This often leads to compromised accuracy and raises the question -- “Does it really make sense?” It does to the manager who needs to meet goals and protect her job but does it truly increase customer satisfaction? Not necessarily. Having a goal at the top doesn’t mean that the numbers will retain their true meaning by the time they get to the daily staff. It’s crucial to focus on figures that actually create better claim outcomes and customer experiences. Here’s another example of how differing goals within a claims organization can skew overall results when managers are forced to manage to the wrong numbers: Let’s say your insured damages another vehicle and that claimant decides to go through his own carrier for repairs. Now the carrier sends in a subrogation demand that includes excessive rental, overlapping operations, duplicate invoices and mathematical errors. Would it be a good idea to just pay what is being asked without reviewing for accuracy? Well, for some insurers that don’t have the staffing or the expertise in the subrogation department, quite often an excessive demand like this might just be rubber-stamped. The subrogation department may be overseen by an individual who has been compartmentalized away from day-to-day claims. If this manager’s goals and metrics don’t include accuracy, he may just pay this overinflated demand. Chasing the wrong numbers can give the misperception that the manager is achieving goals, but the best possible outcome wasn’t achieved. So what’s the answer? The key is matching numbers to desirable outcomes that make sense. Eliminate any metrics that provide little value and only serve to create busywork. With the wealth of data that companies are able to gather and analyze, the focus should be on information that has a direct impact on customer retention and quality service. One must carefully focus on the right numbers to add value and help push the organization forward to achieving that ideal balance of client satisfaction and operational efficiency.

10 Questions on Capital Standards

International capital standards (ICS) are advancing, to protect insurers in the next financial crisis, but raise numerous ticklish issues.

PwC U.S. risk and capital management leader Henry Essert and PwC global insurance regulatory director Ed Barron recently sat down to discuss the proposed International Capital Standards (ICS) for insurers. They addressed at length what the ICS is and what it could mean to insurers. Here are their thoughts on the standard, as well as some background information on capital management and related issues in the insurance industry.

1. Why have an ICS?

The ICS is about creating a consistent capital measure across globally active insurers and is being promoted as a solution for group-wide supervisors to better manage capital allocation around an international business. Insurers generally have developed their own capital standards, and what they have developed applies globally across groups. However, regulators need a capital measure to oversee insurers, and most of the regulatory measures are at the legal-entity level. During the last financial crisis, problems arose when parts of a troubled financial institution fell through a regulatory crack. Even before that, many insurance regulators were concerned that they did not have a good picture of companies as a whole because capital is measured differently in different jurisdictions. This makes it hard for a supervisory college to identify where there may be shortfalls in capital.

2. Who wants it?

Primarily regulators and, by extension, policymakers and politicians/elected representatives. At the end of the 2008 crisis, many of them were concerned about avoiding or better handling any subsequent crises. This prompted politicians (via the Financial Stability Board) to direct regulators to improve the regulatory system for all of financial services, particularly as it relates to capital standards. And, while the banking industry has received the most attention, the insurance industry is part of a wider move for change in financial services; in fact, the FSB is now firmly focusing on the sector. However, many elected officials in the U.S. are now concerned about adopting a "foreign" calculation that differs from what regulators in their jurisdiction have used. To run their business and generate a good return on capital, multinational and other groups need to have some way to measure how much capital they need in total on a consistent basis. They have devised their own ways of doing this calculation using a combination of current regulatory calculations and their own capital models (which are sometimes called economic capital models). They tend to do these calculations on their own without outside prompting and have concerns that the ICS calculation could conflict with what they are already doing. There has been extensive regulatory change in recent years, and the ICS is yet another initiative that insurers have to address – and in a very aggressive timeframe.

3. Does it reflect current practices or does it break from them?

Practices differ by country, so there is no single current practice standard to compare with, and the ICS is intended to be a truly global group measure. The current ICS proposal is not the same as any practice in any jurisdiction currently, but most people would say it is closer to European Solvency II approach than to the current U.S. practice. Accordingly, ICS (as it currently stands) would be a considerable change to the U.S. market. This is why the Federal Insurance Office (FIO) is leading a workstream on setting up a GAAP+ concept that will be more closely aligned to U.S. practice.

4. Who’s going to enforce compliance?

The International Association of Insurance Supervisors (IAIS) does not have any executive powers; its role is strictly to develop regulatory guidelines and best practices for national supervisors to adopt, either in whole or part. Application of the ICS is up to individual supervisors, and the question remains if they will act in many major jurisdictions. In theory, the ICS will apply (via ComFrame) to only internationally active insurance groups (IAIGs), of which there are roughly 50 worldwide. However, many observers expect that when the ICS becomes an industry standard, other companies also will use it to calculate and report their capital adequacy. Several jurisdictions do not have an IAIG. Therefore, we assume they would not be pressured into introducing an ICS concept. However, because most jurisdictions readily adopt many IAIS principles, we would not be surprised to see some of the principles within ComFrame and the ICS “trickle down” to smaller markets, especially where there is not necessarily global activity but a high concentration of regional activity (e.g., Asia). The reason countries tend to adopt IAIS guidelines is because, when the IMF/World Bank conducts its Financial Sector Assessment Program (FSAP) reviews, it uses IAIS principles as the benchmark for assessing the insurance sector. Therefore, it is in many people's interest to adopt IAIS standards to achieve strong FSAP results (which feed into sovereign rating, etc.).

5. Who at insurers will be most affected?

If the calculation is similar to others already in use, then primarily risk, actuarial, financial and compliance will be affected. If, on the other hand, the calculation is very different, then just about all functional areas could be affected because of a knock-on effect on product portfolio, pricing, investment strategy and so on. In either case, boards will need to demonstrate they understand the numbers and what they mean, particularly as they relate to strategic decisions. Taking a look at the bigger picture, the ICS is only part of a larger regulatory package for IAIGs called Comframe. Other aspects of Comframe, like governance, risk management policies and Own Risk and Solvency Assessment (ORSA) also will have an effect on many areas, regardless of where the ICS ends up.

6. How much investment/effort would implementation and compliance require?

This depends on the nature of both the calculation that is adopted and its enforcement. It is almost certain that the calculation will be complex. But, if the calculation is similar to what groups are already using, either because it is similar to the main regulatory calculation groups use or is similar to their own internal, economic capital calculation, then the investment/effort will be less significant. More importantly, if it winds up being similar to current calculations, then the new ICS would not have a major impact on how the company's business profitability is measured. However, if the calculation is different, implementation/compliance and business impact will be significant. Investment and effort may not necessarily be limited to basic compliance. Insurers can look to their experience with Solvency II, which entailed more than just change to capital standards, and required significant investment in new technology, as well as potential changes to organizational structures.

7. Will product offerings change? Are there certain products that may disappear?

If calculations are different than those now in use, then, yes, there would likely be impacts on premiums for some products, and some may even become nonviable. Many life companies are concerned that if certain types of calculations (notably, market-consistent calculations) are used, then long-term savings products may be too costly to remain viable. At the least, if certain products do not disappear, then their design may need to change (which would change the balance of insurers’ product portfolios).

8. What’s been the reaction of ratings agencies and analysts?

Ratings agencies typically have their own capital calculation formula and, for the most part, at the group level. It is not clear if they will replace their own with ICS but could do so if they think the latter is a comparable or better formula. Equity analysts typically are concerned with the ability to pay dividends or buy back stock, which happens at the parent company level. Accordingly, they typically do their analysis at the group level. They have not been a vocal part of this discussion but probably would find an ICS helpful. In fact, most stakeholders are likely to support the concept of a global capital standard for the insurance industry, but there almost certainly will be differences of opinion about what one should look like as details are hashed out about how the standard will actually work.

9. With all this in mind, is a true ICS likely?

It’s too early to say for certain one way or the other, but even the regulators who question the necessity of an ICS seem reconciled to the notion that one should be developed. The debate now is what the one true ICS should look like, and how the calculation should be done is the main area of disagreement between and among geographies. For other aspects of the Comframe regulatory package, like governance, risk management policies and ORSA, there is significantly less disagreement.

10. What should insurers be doing now?

Building the ICS calculation formula and finalizing the rest of Comframe probably will take several years. The following are likely to be key steps in the journey:
  • In the early stages, companies will want to understand how the different, proposed ICS options may affect them, to determine which option they favor.
  • As regulators further develop the different options' details, they will want to study how different factors in the proposed formulas will affect companies. They will ask insurers to conduct studies of these different factors for their business (i.e., field testing).
  • Once the nature of the ICS becomes clear, companies will need to implement the formula (and eventually, the rest of Comframe).
  • All stakeholders should remain aware of ICS developments to assess where there is consensus and disagreement. If there continues to be significant divergence in how required capital is calculated across regimes, and if ICS adds complexity rather than reducing it, then most insurers will need to factor these developments into how they are modernizing or plan to modernize their risk, actuarial, financial and technology platforms to operate effectively and efficiently in the new environment.
  • Insurers may need to redesign and reprice their products, as well as potentially rethink their business strategies. It is possible that they will need to divest certain businesses and add others.

What are current capitalization requirements?

Current capital requirements in the U.S. are set at a legal-entity level. There are no global requirements for a company that operates in more than one country, and calculation formulas for capital requirements typically vary in each jurisdiction. Solvency II gets close to mandating a group standard. However, it uses the concept of “equivalence” to deal with differing capital regimes between the EU and the rest of the world, rather than enforcing Solvency II capital standards on a third country. In other words, if a country outside of the EU is deemed equivalent, then the group headquartered in the EU can use the capital standard of the operation outside the EU within its group calculation on the grounds that EU regulators are comfortable with the system in that third country.

Are those requirements adequate if there’s another market shock like 2008 or a series of catastrophic events?

During the 2008 shock, some significant companies did not have enough capital, and governments intervened. In many cases, the formulas that set the capital requirements that proved insufficient are still in use. However, that doesn’t necessarily mean current requirements would be inadequate for future shocks. There’d need to be a model to test if current requirements are adequate for a defined market shock like 2008, but we would need to define exactly what "a series of catastrophic events" means before modeling its impact.

What results in undercapitalization?

The more risky the business, the theory is that insurers will need to hold more regulatory capital against the risk. To be undercapitalized is normally a reflection of poor reserving or liquidity management. More specifically, companies hold assets to defease their liabilities, which are calculated based on a more or less average level of claims. Additional assets are set aside (not available to pay shareholder or policyholder dividends) to pay for claims should they be higher than the average. This amount of additional assets is the regulatory required capital. If these assets set aside prove insufficient during a crisis, then undercapitalization results.

What is an adequate level of capital reserves (and, if the level varies by sector, what is the appropriate level for each)?

Figuring out the answer to this question is what the whole ICS global and country level debate is all about.

Which sector (reinsurance, P&C, life) has the biggest challenges remaining adequately capitalized?

There is no perception that this is a bigger issue for one sector compared with another. Problems have occurred in all sectors. Some future crisis events will affect all sectors, like credit risk events; others are more harmful for PC (wind storms) or life (pandemics).

Do different sectors have different standards? In other words, does life have a lower standard than P&C?

No, the same formula is used across the sectors. The formula will cover risks that are common across sectors with the same calculation. Different types of risk are covered by having different factors assigned to different exposures. Some of these will apply only to business/exposures written by life companies or PC companies.

Which are better capitalized, groups or subsidiaries (or does it vary)?

Each subsidiary typically has an amount of actual and required capital it holds on its own balance sheet. The group actual and required capital is the sum of these. Many companies hold actual capital in the subsidiaries just sufficient to cover the regulatory requirement in that subsidiary. They would hold any significant excess at the parent company. So for these types of companies, that would mean the group is better capitalized than the subsidiaries. But that is not always the case. A group parent company typically can send capital to subsidiaries, subject to meeting its own capital requirements if it is an insurance company. However, the normal capital flow is from subsidiaries to the parent, but the flow is constrained by the subsidiaries' own capital requirements. (Laws differ from country to country about how readily a company can move capital from one entity to another when it has a group capital position.)

Are there certain insurance lines that are difficult to adequately capitalize?

There are certain coverages for which the level of required capital is too high to make premiums affordable. Where this occurs, some form of government intervention typically occurs (e.g., flood insurance in certain areas). This is unlikely to change with or without an ICS. However, when the objective is policyholder protection, capital is not the only tool. Better risk management is also key, with tools such as the ORSA and governance protocols being paramount. If it is hard to quantify a certain risk type, then strong risk management principles should augment the degree of policyholder protection.

Henry Essert

Profile picture for user HenryEssert

Henry Essert

Henry Essert serves as managing director at PWC in New York. He spent the bulk of his career working for Marsh & McLennan. He served as the managing director from 1988-2000 and as president and CEO, MMC Enterprise Risk Consulting, from 2000-2003. Essert also has experience working with Ernst & Young, as well as MetLife.

Verified Burglar Alarms Reduce Losses

Burglar alarms that send video to a central station for review by an operator lead to fast action by police, more arrests and less crime.

At a recent International Security Conference (ISC) law enforcement seminar, Chief Chris Vinson of the Texas Police Chiefs Association explained why verified burglar alarms work better: “We will give [them] the priority response [they] deserve. We will arrive on the scene in time to make an arrest. And making those arrests [is] what it is all about because when you increase arrests, you reduce the crime rate. When you reduce the crime rate, you are reducing property loss. When you reduce that property loss, it reduces the insurance rate for those property owners. When those insurance rates drop down [and] the crime rates drop down, then the property values go up, which makes our constituents happy.” The burglar alarms matter so much because, with a video-verified burglar alarm, an operator at a central station can review on video what is happening at the site before calling 911 center. The operator serves as a virtual eyewitness to a crime in progress. And, when police are sure a crime is being committed, they respond faster and make more arrests. (To see an excerpt from the seminar, click here:  https://www.youtube.com/watch?v=nX3IzynaUUY) A recent meeting between several of the major alarm companies and Verisk discussed how best to collect and quantify the advantages of professionally monitored video-verified alarm solutions for the insurance industry. Insurers are looking for technology and data to help them contain costs, and law enforcement and alarm response times are a crucial component. In April 2015, the largest police chiefs association in the country passed a resolution endorsing verified alarms and priority response. The Texas Police Chiefs definition of a verified alarm requires Central Station monitoring with operators specifically trained to review videos and communicate the pertinent information to law enforcement. Home surveillance systems might work as a nanny-cam but lack the protocols and processes for alarm response provided by the central station. (Here is a link to the Texas Police Chiefs resolution on verified alarms:  http://www.ppvar.org/_asset/wfdzry/TPCA-Priority-Response-Resolution-2015.pdf) Without technology and new policies, property losses will only get worse as the number of officers declines. At the recent ISC conference, officials from Akron, Ohio, and Chula Vista, CA, said their police departments had already shrunk because of budget cuts, forcing them to reconsider response to alarms -- responding to false alarms represents between 8% and 15% of total calls for service at the 911 center. Akron adopted a “verified response policy” in 2014, and over the past year burglaries went down 5%, with increasing arrests. Retired Capt. Gary Ficacci said Chula Vista was policing 260,000 people with 212 police officers, one of the leanest staff/population ratios in the county. The economic downturn caused the city to lose about 40 officers and provided the impetus to change the alarm ordinance to promote a form of verified response. Chula Vista figures it spends more  than $100,000 in officers and staff for every arrest made in response to a burglar alarm, but video verified alarms could cut that number significantly. How much better can verified burglar alarms actually be? Radius Security in Vancouver, Canada, just completed a short study of its verified alarms compared with the traditional, unverified alarms. For Radius, its verified alarms were 1,000 times more effective. The arrest rate for unverified alarms is between 0.08% and 0.02%, while arrest rates for verified alarms are often in double-digit percentages. Why? Because law enforcement treat a verified alarm like a crime in progress instead of something highly likely to be a false alarm. Texas Chief Vinson says, “The calls that truly merit a higher priority response, those get pushed to the top. Those get the response they need to actually make arrests, and that is what we are all going for here, because if you take that guy off the street that is committing the offenses and you’ve solved that crime you have probably solved a handful of crimes that occurred before that he has already committed that he confesses to. And then you prevent all the crimes that he is not going to commit while he is sitting in jail. So, it is a big deal to make arrests on one of these calls, because it makes a difference in the actual crime rate that affects that city.” (For video on Radius Data, click here:  https://www.youtube.com/watch?v=AlXMGu-lT7g)

When Everybody Does the Right Thing

Following a burglary at a church, a reward leads to the recovery of a huge cache of stolen goods, providing a feel-good story about insurance.

It sometimes seems that all we hear about are the complaints, when something goes wrong for a policyholder dealing with an insurance company, especially when a claim is involved. So we thought we’d bring you a story where everybody did the right thing – even beyond right, because the client couldn’t have expected to be treated as well as it was. It happens that we know this story because our founder, Dave Dias, was involved. But we’d happily share other stories on an occasional basis if you email them to me at jared@insurancethoughtleadership.com. This story begins in the first week of September 2014, when the Folsom, CA, campus of Bayside Church was burglarized. Bayside, a “mega-church” based in Granite Bay, CA, has campuses throughout the Sacramento area and has been holding services at a middle school in Folsom. During the week, someone broke into a steel container at the school and stole much of the audio-visual equipment that Bayside stored there. Dave Hanson, the CFO of Bayside, says the equipment was valued at $75,000 to $100,000. The case quickly went cold. The thieves had known what they were doing – for instance, they broke only into the container with the valuable equipment, not into containers with, say, materials for the children’s ministry – and didn’t leave clues behind. There were no witnesses and no security video. This is where the insurers swept in. Hanson says, “Dave [Dias, a former police officer who is the InterWest broker on the Bayside account] was thoroughly frustrated that someone would steal from a church, and Folsom PD had zero leads. So, in an attempt to help the police department, he said, ‘Let’s put up a reward.’” InterWest, a Sacramento-based broker, and Philadelphia Insurance, the carrier, offered a $10,000 reward for information leading to the return of the equipment. Within days, someone came forward with information, and police raided a house in nearby Carmichael. They not only found all the Bayside equipment but also recovered two stolen vehicles, an enclosed trailer, a watercraft, small amounts of drugs and numerous weapons, including three handguns, two rifles, an assault rifle and more than 3,000 rounds of ammunition. The owner of the house, a convicted felon, was arrested and is awaiting trial. “He had guns, ammunition, money, lots of acetylene torches, power tools; it was obvious he had stolen stuff from construction sites,” Hanson says. Recovering the equipment obviously saved Philadelphia Insurance from having to pay a large claim. But it also saved Bayside from having to pay the deductible and from the hassle of having to locate and rent equipment each week, until its claim was paid. “The partnership aspect of client, broker and carrier is the most important aspect here,” Hanson says. He notes that the Folsom police department, which had never worked a rewards case, got a high-profile win and says the main winner was the community. It no longer has to worry about a big-time, professional thief. Isn’t this sort of story better than what you usually hear when you tell someone you’re involved in the insurance industry?

The Real Root of Innovation? Insurance

Entrepreneurs and technical geniuses are hailed for their innovations, but what allows them to take risks in the first place? Insurance.

Humanity’s innate urge for creativity coupled, perhaps, with the promise of fame and riches have been important drivers of innovation throughout history. But what has served as the foundation for innovation? What has helped individuals make the leap from coming up with a great idea to executing it? In one way, the answer is insurance. Insurance and risk transfer are key historical inventions that contributed to the rise of innovation around the Industrial Revolution. Legal and financial advancements, such as modern insurance policies, have been just as significant to innovation as technological breakthroughs. They have allowed humanity to view risky situations as opportunities to progress. Before the Industrial Revolution, creative risks were, well, a lot riskier. In the days of hunter-gatherers and early agriculture, individuals or small family groups bore total responsibility for any consequences should a new crop be unsuccessful or sickness spread because an unproven concept failed. (Starvation and death are steep prices to pay.) As time progressed, hierarchical systems ensured the ruling classes quickly claimed and controlled any innovation devised by those low on the totem pole. Historically, oppression has rarely served to spark advancement at all, let alone at a decent pace. When formalized insurance came along, in addition to stocks, bonds, patents and other financial tools, it allowed people to share the risks and rewards of their personal creativity. Because the downside of failure was no longer as excessive, people were empowered to take bigger leaps. Insurance and its associated analytics removed many of the unknowns from taking a chance on a risk. Insurance and risk management are now so ingrained in the innovation process that we take it for granted as just another step on the way to progress. When you hear about modern space travel, for example, you don’t hear about the insurance policies that make it possible for entrepreneurs to launch ambitious new projects. Unfortunately, the only time we make the connection between insurance and innovative efforts is when something goes wrong. Case in point: It was only when an unmanned commercial rocket exploded last fall that many articles rushed to note it was insured for about $200 million. Today, insurance is stepping in to lower innovators’ risks in other creative ways. One example is a firm that created insurance protection from “patent trolls.” While patents are supposed to protect inventors, some people have found ways to exploit the patent system to enrich themselves instead, while also limiting actual innovation. The high litigation price of defending a patent has caused many start-ups to stall out. Patent trolls have forced even established companies like Apple, Google and Samsung to spend massive quantities of capital addressing seemingly gratuitous patent claims. The new solution steps in to help organizations keep creating. Recently, some insurance companies have begun to offer protection for the bitcoin business. The virtual currency has had its fair share of troubles in the last year or so, with cyber attacks and technical snafus costing investors millions upon millions of dollars. With the advent of protections similar to those offered by the long-established Federal Deposit Insurance Corporation, these organizations are making it possible for the bitcoin industry to mature, potentially ushering in a new, all-digital era for commerce. The New York Times Magazine recently dedicated an entire issue to the subject of innovation. It cited prominent M.I.T. economist Daron Acemoglu directly linking the advancement of society to the necessity of insurance and risk management. In other words, the better we manage risk, the more risks we take and the better off we may all be. This article was originally published on IAmagazine.com.

It's Time to Revise ISO 31000

Risk management needs to go from being administrative to being an active tool, and an updated ISO 31000 is the way to get there.

With the recent release of a new British standard BS 65000 on organizational resilience and the announcement by the Committee of Sponsoring Organizations of the Treadway Commission (COSO) of a review of its 2001 enterprise risk management (ERM) framework, I believe that business is moving ahead of ISO 31000 as a necessary response to the evolving business environment and accelerating rate of technical change. Therefore, there is a strong case for a taking a fresh look at ISO 31000. As I’ve stated many times, the pace of business changes and evolution of management systems is accelerating in the 21st century. So, too, has the role of risk management. The ground is continuing to move under our feet. Long a supporter of Martin Davies' causal approach to risk management, I feel the albatross of risk heat maps and 20th century occupational health and safety (OHS) perceptions of risk are causing business to bypass risk management. Has Risk Management Been Lost in Operational Risk? In a recent article by David Vos titled “Ten steps to corporate risk analysis,” he refers to the need for quantitative risk analysis (QRA) and says “only about one quarter of corporate strategic planning departments truly use simulation analysis (the most useful means of evaluating risks), and only a third quantify their risks at all.” This left me dumbfounded, for if risk is the level of uncertainty on objectives, how can any system claim to be managing risk without quantifying it? It leads me to ask, outside banking and insurance, how many people are really “managing” risk as opposed to recording it? Could it be arrogance, where we have elevated ourselves to the “opportunity and decision making” levels of business, causing us to lose sight of our primary role in the business landscape? Is the Legal Department Taking Over Risk? In a recent article, I criticized plan, do, check, act (PDCA) as an outdated, serial approach to continuous improvement, proposing instead realization, optimization and innovations as an interactive real-time approach using mathematical predictive analytics. It seems the usually lagging legal fraternity is advocating a similar approach “that may be used by the legal department for risk management purposes. These innovative uses of available technology can increase the return on investment in the technology and provide an added incentive to move forward with new approaches to risk management.” Is the legal department to become the vanguard for ERM? With legal's relationship to corporate governance, that is not beyond the realm of possibilities! Although I am most likely preaching to the converted, we need to change the purpose of risk management from being administrative to being an active, valuable tool. This mandates, at a minimum, a reasonable level of understanding of statistical and analytic mathematics and the realization that an Excel spreadsheet cannot be proactive. As ISO 31000 is the only tool we have to wage this war, and 2009 was a lifetime ago in terms of business practice (basically, before the end of the Great Financial Crisis), I believe it requires a major overhaul or risk becoming irrelevant. Finally, risking the wrath of the ever-swelling ranks of generalist operational risk consultants out there: However altruistic was the original decision for ISO 31000 not to be certifiable, there is a need to introduce a method of certification to engender value and consistency into the reputation of ISO31000. My Suggestions for a Revised ISO 31000 As a starting point, I would suggest:
  • Strengthen requirements on risk culture and risk appetite
  • Mandate the use of quantitative risk analysis (QRA)
  • Mandate the use of causal analysis and monitoring
  • Take an active approach to risk management
  • Incorporate BS65000 and resilience as part of ISO 31000
  • Introduce certification to protect the ISO 31000 brandaszzz

Fraud: When Mom Is Your Worst Enemy

More than 30% of identity theft cases involve a family member or close friend. The reason is simple: access. Even moms commit fraud.

Mother’s Day is a special time to celebrate all those kisses and hugs, the rides to the mall, the doctors’ appointments, the countless soccer-basketball-baseball games, a special note tucked into a pocket or care package sent to camp. But remember, sometimes it’s what a person doesn’t do that matters, and some moms are just bad to the bone. More than 30% of identity theft cases involve a family member or close friend. The reason is simple: access. Whether it’s your mother, father, foster families, siblings, close friends or your spouse—access often is the only catalyst needed to turn your credit report into a crime scene. Here are a few examples from the Mommy Dearest files. Betz Noir Axton Betz-Hamilton discovered she was an identity theft victim when she rented her first apartment and was told that a deposit was required to turn on the electricity because she had bad credit. She thought she had no credit at all. Her credit report said otherwise. Her assumption at the time was that whoever stole her parents’ credit a while back had hit hers, as well. Then the truth came out. Betz-Hamilton’s mom, Pamela Betz, died in 2013. Shortly after that, Betz-Hamilton says her father discovered a box that contained credit card statements in Axton’s name, so he called to razz her about her profligate spending. He then discovered he also had some crazy spending, and so did his father, who lived with them. They all allegedly were hit by Mama Betz. Free resource: Stay informed with a free subscription to SPWNR No Cheers for This Mom Some mothers have a hard time giving their kids space to grow and become their own person. Others can be smothering to the point that children can’t do anything on their own, but Wendy Brown took it to another level when she used her daughter's identity and showed up for cheerleader tryouts at Ashwaubenon High School in Wisconsin. With her daughter living in another state with family, Brown, 33, decided it was time to get her high school diploma—and it seems, while she was at it, get another shot at the high school experience. She was caught by truancy officers and sentenced to three years in a psychiatric hospital. G.I. Jane Deferred Cassidy McKenna had just graduated from high school and was excited about enlisting in the armed forces. But when she signed up, they wouldn’t take her. While it’s generally known that bad credit can affect a soldier’s security clearance, the Armed Forces also will turn down prospective recruits with unpaid debts that are overdue or in collection, until the issues are resolved. McKenna said she didn’t know that she had bad credit. She had always lived at home and had no credit cards. The damage was caused by an outstanding electric bill for $1,755 and another $1,123 owed to a cable provider. When she confronted her mother about the bills, she said her mom went AWOL, only turning up at the Kerr County Courthouse, where she was answering McKenna’s theft charges against her. Apple of Her Eye? Mom and alleged fraudster Kristina Anh Giusti, 44, of Garden Grove, CA, first attracted the attention of the Chino Hills Police Department after an investigation into $800 in fraudulent credit card charges at local retailers. Investigators say the evidence they collected points to Giusti's making the charges. According to CBS Los Angeles, police found “altered credit cards issued in the suspect’s name, six laptops, two tablets, an embossing machine and a tip card machine used for forging credit cards. … Detectives also found a card encoder, several boxes of white stock credit cards, a money counter” and $11,000 in cash. Police allege the woman had two accomplices … one of them her daughter. ‘In the Family Way’ Fraud Hairdresser Jennifer Perik, from DuPage County outside of Chicago, is expecting both a baby and a criminal trial in the months to come. If the charges stick, she will join the ranks of identity-thief moms. Perik is accused of making $6,000 in fraudulent charges on a Discover card that belonged to her hair client, a 94-year-old woman. Investigators say that more than half that amount went to a sperm bank with offices in Virginia and Maryland that boasts high-quality donors. At a bond reduction hearing, Assistant State’s Attorney Diane Michalak said that Perik was seven weeks pregnant, but that it was not known if the pregnancy was the result of in vitro fertilization. We’re always talking about identity theft being the third certainty in life, yet the crime almost always takes victims by surprise—all the more if the perp is Mom. It’s always a good idea to take protective measures to reduce your risk, but even then it’s impossible to entirely prevent the crime from happening. You can, however, reduce the damage from fraud by detecting it as quickly as possible. Check your financial statements—ideally online, every day—for any fraudulent charges, and dispute anything you didn’t authorize. Request your credit reports, which you can get for free once a year, to look for new accounts that you don’t recognize. And your credit scores serve as your snapshot of your credit health—by tracking them over time, you can catch any big, unexpected changes that may be a sign of a big, unexpected problem. You can get your credit scores for free from many sources, including Credit.com. This Mother’s Day, celebrate the women who have done so much for us—and thank your lucky stars that your mom isn’t a fraudster. Or is she? … Maybe wait until Monday to investigate. This piece was written by Adam Levin. Levin is chairman and co-founder of Credit.com and Identity Theft 911. His experience as former director of the New Jersey Division of Consumer Affairs gives him unique insight into consumer privacy, legislation and financial advocacy. He is a nationally recognized expert on identity theft and credit.