Download

Bizarro World: Where Buying Can Be Fun

Picture a Bizarro world retail destination with a genius bar providing consulting, showing simulations, demonstrating the latest telematics....

In the Bizarro world of insurance, the product that people buy hoping they never use it is replaced with products that people buy via an interactive and engaging learning experience. Last Wednesday, Google opened its first retail store in London: a pop-up store within a British electronics retailer, called Currys PC World. The Google shop lets people play, experiment and learn about all Google has to offer. In a sense, the store is an interactive billboard that places profits at the backseat and lures customers in via a promise to entertain. This concept of "play over purchase" isn’t unique, and can be found in Apple's and Samsung’s business models. In fact, only two years ago, Samsung looked to emulate Apple’s success in the U.S. by launching its own chain of mini-stores in partnership with Best Buy. Surely there is some room for play, not just purchase, in our industry. To get a better idea of how this would work in Bizarro insurance world, picture a retail destination with insurance geniuses standing by, ready and eager to engage customers in the insurance experience all the way from consulting on insurance products to simulating claim-handling and the latest telematics gadgets. These insurance geniuses will welcome consumers and listen to them, to better understand the right combination of products and features to offer. Later, the geniuses will point consumers to different stations, such as "Seriously Real," sponsored by Cyberith, where consumers can enter the virtual world of operating drones for disaster support, or "Hot Quotes," sponsored by Bolt, where consumers can obtain auto insurance quotes faster than Jimmy John’s delivery guy can make a sub. The result will be a house of insurance brands that come together under one roof to clearly communicate the value of insurance for the sake of a branded customer experience. Yes, I'm referring to the two most overused words in this industry – customer experience - which until now were largely defined by an automatic renewal letter sent once a year or perhaps an unused, "downloaded and forgotten" app. We should also draw on the underused word "ecosystem": in this setting, defined as a network of carriers, vendors and insurance startups that collaborate to educate and engage around insurance products via a one-stop shop. To be continued when we revisit the Bizarro world of insurance....

Shefi Ben Hutta

Profile picture for user ShefiBenHutta

Shefi Ben Hutta

Shefi Ben Hutta is the founder of InsuranceEntertainment.com, a refreshing blog offering insurance news and media that Millennials can relate to. Originally from Israel, she entered the U.S. insurance space in 2007 and since then has gained experience in online rating models.

A CMO’s IT Dream Team

CMOs and CIOs must collaborate to build a Dream Team and demonstrate ever-greater value. The key is breaking efforts into six chunks.

Dear CIO and my partner-in-creating-the-future: I came across this great quote from Rita McGrath that makes me laugh but also wince because it’s such a painfully accurate observation, especially as I think about how many of these barriers we could overcome by transforming the way marketing and IT work together: “All of our innovation barriers are self-inflicted.” As the CIO, you lead a function that must demonstrate ever-greater value and impact. The pressure is on to shift away from being a utility provider to an enterprise strategic asset -- an active creator of value and a collaborative contributor -- a function driving, and driven by, innovation. Guess what? Marketing feels a similar set of pressures, and I believe the keys to our success lie in how we work together. Not because there is strength in numbers, so much as because value creation in the new economy will happen at the intersection of three of the hats our functions influence, shape and lead within the organization: customer insight and analytics + user experience + implementation capability. Years ago, I co-led a big initiative alongside one of my all-time favorite CIOs. We were assigned an audacious multi-year, IT-based effort. The CIO gave me a great piece of advice that has stuck with me through many assignments. “Amy,” she said, “you just have to chunk it.” Chunking complex projects down into bite-size and digestible parts has become one of my personal core operating principles, and is relevant to the challenge of reinventing what we do for a digitally powered world. So herewith are six “chunks” I’d like you to embrace as elements of the answer.
  1. Connect the future path of the IT organization to the company’s vision. This sounds obvious. Nonetheless, taking the time to confirm that there is a vision, that it is clear and defensible and that it is understood by all constituencies may expose opportunities to get the IT foundation to be as air-tight as possible.
By the way, this advice applies equally to marketing. With all of the intense pressure to generate marketing return on investment (ROI), step one has to be a connection to business priorities.
  1. Empower IT team members with customer insight. An example of this would be to package and leverage ethnography, including artifacts coming out of in-home/on-site visits and day-in-the-life tag-alongs with customers – and by packaging I mean not the typical, mind-numbing Powerpoint slides, but video and other highly visual, interactive media that bring insights to life and make it easy to draw connections to development decisions.
I’d be happy to conduct workshops with members of the IT team to translate field learning into actions for business performance improvement and potentially disruptive business models.
  1. Insist upon and work actively to foster collaboration between IT and other functions … abolish the “order-taking” role. I’ve never met an IT professional who enjoyed being an order-taker, but it’s hard to redefine a role that for now-irrelevant reasons is often defined as such. Think like a start-up. How to change? Start by establishing processes grounded in business priorities and customer insight that foster collaboration between IT and other functions. Work with marketing to set the example. Demonstrate your role as a source of value.
One process I’ve seen work uses a repeatable approach to tapping into market insight and customer analytics to formulate hypotheses for growth, vetting and prioritizing them, putting the best ones into a test-and-learn cycle with working user prototypes, reading results and moving to next steps: kill, test again or roll out. This model demands design, analytics and technology skills, along with openness, a collaborative mindset and agility. With these conditions in place, it works.
  1. Implement an organization structure that enables digital transformation … and transcends the usual silos and politics. Challenge the norms and at least nudge your approach to accelerate IT’s impact on the digital transformation. There is always an “ideal scenario,” and then there’s the reality of anchoring to the company’s history, culture and business environment. These are all part of the context for a pragmatic organization solution that is both future-focused and rooted.
A good starting point is a fresh approach to a user experience capability. To be done right, this unit taps into a range of skills that would traditionally be distributed in marketing, IT, potentially finance or operations. Don’t overlook the impact on performance of co-location and a unified structure, what skills are really needed and how to close existing gaps. Consider the role of external resources who can jumpstart efforts, whether design agencies, big data analytics partners or maybe mobile app developers. IT should have a seat at the table to form this capability but may not be its organizational home.
  1. Take a clean-sheet approach to what is internal vs. external. Today the questions around what should be internal vs. outsourced, and how those outsourced relationships should be structured, have become more important and more complex. As with internal roles, external providers who know their stuff are more likely to walk the talk on a more multi-functional approach than traditional providers.
For both organization and external capabilities there is no right answer, except to be driven by the business vision and priorities, to be open-minded to new ways to execute and to expect external partners to collaborate, not just take orders.
  1. Enable a real prototyping capability … not just to see if code will run, but to get continuous and actionable customer feedback on the experience, either live in-market, or minimally in a simulation. This capability should enable speed, iteration and low cost.
On this recommendation, I have seen more examples in larger regulated institutions of what won’t work than what will. Live prototyping remains a challenge in regulated sectors, where there is no room for the downside of risks that might hurt a user, but where businesses are foregoing the upside of user-centered design. Disruptors make the choice to frame business models that can advance without the permissions and burdens of a regulated entity. Creating infrastructure that assures compliance and predictability while also enabling agility is by itself an innovation opportunity. Let’s work together on progress toward the Dream Team vision.

Amy Radin

Profile picture for user AmyRadin

Amy Radin

Amy Radin is a strategic advisor, keynote speaker, and Columbia University lecturer focused on why transformation succeeds or stalls in large, complex organizations. 

Drawing on senior leadership roles at Citi, American Express, and AXA, including one of the world’s first corporate chief innovation officer roles, she helps leaders build the capabilities required to absorb, scale, and sustain change.

Learn more at amyradin.com.

 

Is It Time for Un-Change Management?

While change management is important for innovation, so is "un-change management," which focuses on eliminating waste.

Pull back on the reins for a moment and come to a complete stop. What do you see behind you? Probably a wake of both straight and winding roads… some intact, some obliterated, most somewhere in between. You probably see customers satisfied and dissatisfied at a number of different levels. Same with employees. Now look ahead of you. What do you see? A yet-to-be-unfolded strategic plan? A vision? Goals? Innovation? "Change management" is used to make the transition to doing things a new or different way. It’s a tool used to implement change required for forward movement, innovation, strategies, etc. "Un-change management" refers to the need for organizations to let go of the unwavering focus on innovation and advancement and share some of the time and energy removing that which is not valued by the external customer or not required by law. In a word, we’ll refer to it simply as "waste." Waste unattended grows, at best, in parallel with your company’s growth. If you are pleased with your growth goals, ask yourself if you’re pleased with your simplicity goals. The ratio of waste to value should be reduced when you grow. Unbridled growth often leads to an increase in the waste-to-value ratio, and that isn’t realized until years later, mostly because all eyes are on growth. Companies then scramble, point fingers, place blame and cut costs without really understanding were the problem could have and should have been addressed in the first place. Continuous improvement is more about elimination of waste than it is about doing anything new. It requires serious focus on work and asking why things are done. The goal is to arrive as close as possible to creating perfect flow in your business systems -- where orders are placed, where product or service is made or conducted and where they are provided to the customer for consumption. Clean out the garage (and keep it clean) For companies that have never emphasized waste, large gains are made in a relatively short period after they introduce their system of elimination. After that, removal efforts continue to whittle away at midsized waste and so on until, finally, the mindset converts to innovation. I think we’d all agree that an innovative company with little waste is a valuable thing indeed. The way companies manage waste has a profound impact on the way the company culture emerges. (See www.ThreeBellCurves.com and download the free whitepaper.) Employees want to work on things that matter, not waste. Customers want to pay for things of value. Keeping the price low requires the elimination of as much waste as possible. Is your company ready to share some of its change management with "un"-change management? If you are, you will create more room for value without escalating costs.

10 Building Blocks for Risk Leaders (Part 5)

Risk leaders must develop a personal vision -- even though that may mean challenging authority -- and must find ways to give back.

Important things in life are not easily reduced to 10 steps. Nevertheless, this series provides a list of 10 building blocks to achieving long-term success in risk management from someone who has spent more than 25 years striving to carve out the most satisfying career possible, while never losing sight of the attributes attached to the bigger picture. Part 1 is here, Part 2 here, Part 3 here and Part 4 here. This is the fifth and final part.
9. Advance the Profession by Finding or Creating Personal Vision The concept of innovation is directly and explicitly tied to risk and risk management. Put simply, there is no innovation without risk. Part of this paradigm is taking personal risk to move the discipline forward to places others may not have imagined. In the realm of risk management, settling for the status quo is to be avoided at all costs . Nothing stays the same for long, and a core competency of a true risk leader is having the gumption to push back on owners, which sometimes means questioning authority. Just as the overall business environment is ever-evolving, the myriad internal and external drivers that can affect the risk profile of organizations must be carefully monitored. It is in this monitoring where the willingness to challenge conventional thinking and the status quo can lead to change, and risk-taking behaviors can be shifted to be more in line with risk appetite and tolerances. A vision for more innovative processes, tools and techniques can be developed, as well as an enhanced view into the murk of risk itself. Importantly, this demonstration of risk leadership will lead to the evolution of risk leaders’ personal vision for more effective risk management for their organizations.
If we haven’t learned anything else since that fateful day on Sept. 11, 2001, we’ve learned that new risks emerge with increasing regularity and seem to have increasing relevance to enterprise success. Furthermore, these new and emerging risks often fall into the strategic category, so they are often not easily measured or mitigated. All this speaks to the need for continuous improvement and innovation in how risk management is practiced and how it affects the design and execution of the organization’s risk framework and model. While personal vision for risk management is necessary -- for personal satisfaction and the long-term success of the firm -- no two frameworks or models are exactly alike, just as no two firm risk profiles are identical. By crafting risk strategy, framework and model around the continuously evolving needs of the firm, risk leaders’ vision for risk management will take shape. As it is successfully implemented, this vision will also drive the risk profession forward, through benchmarking, networking and professional external collaborations, allowing all risk practitioners to improve, as well. This is the perfect segue to the last element of a personal risk leader success profile. 10. Give Back Giving back to the next generation and to communities and nonprofit organizations (some of which can’t afford the cost of risk expertise, e.g., churches and civic organizations) is essential to developing a well-rounded leader and person. But giving back goes well beyond even service to the community and to nonprofits. In the larger context, giving back includes various strategies to help others. Examples include employing interns on a regular basis and taking the time to coach and mentor them well. Too often, intern programs are mismanaged or even abused as sources of raw labor out of which no real development or education occurs. This destroys the attraction to enter the risk profession. Because these programs—done well—can be the source of exceptional talent, it behooves all risk leaders to take advantage of intern sourcing when feasible and include it as a key component of long-term resource planning.
Giving back is also accomplished by bringing the risk leaders’ considerable knowledge to various forums, such as at conferences and industry meetings, through presentations and participation in efforts to discover new solutions to problems. While the primary goal should be to help others, it almost always includes mutual benefit. Many of my colleagues say they actually get more out of this effort than they put in. That has certainly been true for me. Another example of giving back is the Spencer Educational Foundation’s Risk Manager in Residence Program. This program provides funding for risk experts to bring that expertise into higher educational institutions through a series of lectures and teaching done with the collaboration of selected professors whose goal is to bring diverse experiential learning to students pursuing risk and insurance degrees. This program has been instrumental in highlighting for students the opportunities available in the risk discipline. There are many opportunities to serve other organizations through volunteer board and advisory positions, where risk experience and expertise is made available to help these organizations, particularly with risk governance. A residual benefit of this activity is broadening the network of contacts and relationships outside the industry, where a clear demand for risk expertise is almost always needed, but infrequently recognized or acted upon. Last, but certainly not least, is the ever-present opportunity to mentor and coach others to help them achieve their career goals. This is a fundamental responsibility of every manager of people. But it really gains traction with others when those outside the immediate work circle ask for mentoring or coaching, as they recognize and value the deep and broad expertise they can learn via a mentoring program. Usually accompanying that is a keen understanding of the political, social and cultural aspects of work life that those with less experience often find challenging to navigate. One benefit of this activity is a deep and lasting gratitude that is too infrequent in day-to-day business interactions. The related personal satisfaction is often immeasurable and certainly lasting. Personal brands are enhanced, and those being mentored can close the loop on what a true risk leader profile looks like.
Conclusion There you have it—my list of 10 building blocks for long-term success in risk management. All functions need great leaders to achieve high performance, and risk leaders have more than their share of hurdles to overcome in the process. And yet, those who stick their necks out and take the personal risk associated with doing extraordinary things often succeed in doing so. I urge you to think big about the possibilities of a career in risk and consider these 10 important things that can help define the correct path to take. After all, no risk, no reward.

Christopher Mandel

Profile picture for user ChristopherMandel

Christopher Mandel

Christopher E. Mandel is senior vice president of strategic solutions for Sedgwick and director of the Sedgwick Institute. He pioneered the development of integrated risk management at USAA.

Things Not Mentioned in ProPublica

The ProPublica series makes valid points about problems in workers' comp but misses some context and omits many, many positive stories.

By now, most of you have read the series of articles published by ProPublica on “The Demolition of the Workers’ Comp.” These well-written articles touched on some very important issues faced by our industry. For example, caps to the wage-replacement benefits provided under workers’ compensation can devastate employees earning higher wages. In addition, there is wide variation in the total-loss-of-use benefits provided under the various state systems. Legislators around the nation and people in the workers’ compensation industry would do well to carefully consider some of the issues raised by ProPublica. As someone who has been in the workers’ compensation industry for more than 25 years, I also found there were several shortcomings in the ProPublica stories. For example, ProPublica failed to touch on what is often the biggest reason behind an injured workers’ poor recovery, and that is the secondary-gain motivation of unscrupulous medical providers and attorneys. I remember years ago, when I first started handling claims, Texas had the worst workers’ compensation system in the nation. Plaintiff attorneys would refer injured workers to physicians who had been sued so many times that they had lost privileges at every hospital in the state. But that didn’t discourage these physicians, who had set up operating rooms in their offices and continued ruining the lives of so many injured workers. Many of the injured workers who were treated by these physicians were left in ruin both physically and financially. But this harm to injured workers was not being done by insurance companies or employers or the state systems. This harm to injured workers was being done by the attorneys those injured workers trusted and the doctors who worked with those attorneys. These attorneys and doctors were not motivated by what was best for the injured worker. They simply wanted a payday. Today, Texas has one of the best workers’ compensation systems in the nation. What changed? The legislators and regulators realized that they had to stop those who put their self-interests ahead of injured workers. Legislators instituted treatment guidelines, mandatory second opinions, attorney fee caps and approved physician panels. Over time, those doctors who put their financial interests ahead of the health of injured workers were removed from the system. Texas is a remarkable success story that illustrates how the workers’ compensation system can be improved to provide better outcomes for both injured workers and employers. ProPublica also noted that insurance premium rates are at a 25-year low. While this may be true, it is an extremely misleading statistic. Over time, there have been significant advances in loss prevention and safety. Workplaces are safer than they were 25 years ago. Lower "rates" reflect both safer workplaces and more competition among carriers. However, lower “rates” do NOT mean employers are paying lower premiums than they were 25 years ago. I would challenge you to find any employer that is paying lower premiums than 25 years ago. For most employers, premiums have increased steadily over time, and they continue to increase. Rate is but a single element in the calculation of premiums, so looking at rate alone as a performance measurement does not provide an accurate reflection of the true picture. Also, based on National Council on Compensation Insurance (NCCI) data, claims costs have risen pretty steadily over the last 20 years, as well. So, premiums and claim costs are significantly higher than 25 years ago. Those data elements are a better reflection on the actual state of the workers’ compensation industry than rate. Many choose to use the ProPublica articles as an indictment on the entire workers’ compensation system. While I agree the system is far from perfect, the system functions quite well most of the time. The vast majority of injured workers receive medical treatment and return to work in their pre-injury job without any conflict or complications. Those workers do not retain attorneys, suffer financial hardship or have significant lasting physical effects from their work injury. For these workers, the system does exactly what it is intended to do. There will always be examples of injured workers for whom the workers’ compensation system produced an undesired result. It is impossible to design a perfect system. However, for every example that can be provided where the system didn’t work, I can provide you examples where it worked very well. In the workers’ compensation industry, we are in the business of helping people recover from injury and resume their place as a productive member of our society. For the most part, this is something the industry does very well. My company deals with catastrophic injuries and other high-dollar claims. Our caseloads are literally the “worst of the worst” in the workers’ compensation industry. We see horrible, life-changing, devastating injuries every day. Yet, in spite of this, I can provide countless examples of how the efforts of our staff, the employers we insure and the claims adjusters and service providers we work with went above and beyond what was required under the workers’ compensation statutes. For example:
  • A paraplegic worker lived with his family in a dilapidated mobile home that was insufficient for his wheelchair. We were obligated to provide him with comparable housing, which would have been a new mobile home. Instead, we purchased a house that was large enough for him and his family, complete with all the necessary modifications needed to make the home handicap-accessible.
  • A paraplegic worker used to enjoy hunting with his family. We purchased an all-terrain wheelchair in addition to his regular wheelchair so he could continue to enjoy this activity with his family.
  • We recently purchased experimental motorized leg braces for a paraplegic worker. Because of these braces, he is able to walk again.
  • I have seen numerous injured workers whom we have assisted in recovering from an addiction to opioid pain medications. When these injured workers are free of this addiction, their quality of life and their relationship with their families is significantly improved. We have had both injured workers and their family members thank us for helping them overcome this addiction.
I’m sure every workers’ compensation carrier or third-party administrator has similar examples they could share. My point is, for everything wrong that people can identify about the workers’ compensation system, there are also a lot of good things about it. There are also many good people in this industry who work very hard to assist injured workers in their recovery. At the end of the day, claims adjusting is about helping people. Perhaps we, as an industry, need to do a better job sharing the positive stories of what we do every day to make the lives of injured workers better.

What Risk Reports Won't Tell You

Monthly risk reports typically look at a single point (usually P80) that hides crucial information about the probability and impact of a risk.

||||||||||
Usually, the first questions the project director asks are,
  1. “What are the top 10 risks by cost P80?”
  2.  “What is the P80 of cost risk?”
  3. “How does the total compare with the cost contingency?”
These seem like fundamental, simple questions for a project director, but they actually display a complete failure to understand the nature of risk or risk over time. In this short paper, I want to summarize just what information monthly risk reports can provide that is useful to the project managers. 1.     Quantitative Risk Analysis Monte Carlo simulation is the core of quantitative risk analysis (QRA) and is used to combine risk distribution assessments for probability and consequence. Risk is historically defined as the product of probability and consequence (De Moivre 1711). But multiplying two distributions together is no casual mathematical exercise. On a mega-project, there can easily be a thousand-plus risks. The sum of all the products of the individual risks is a distribution for the total risk. Risk has two components: i. Probability of occurrence, the subjective belief that it will occur. This is a binary distribution because it has two states -- i.e., it happens or doesn't happen -- and is called a Bernoulli distribution ii. A consequence measured in terms of cost, delay or performance deterioration. This is also a distribution. In project risk, three-point triangular or PERT distributions are commonly used. With the understanding that risk is composed of two probability distributions, one can see that describing risk magnitude in the "project management way," by a single value (the P80 of cost) doesn't make any sense at all. The usual way to show a risk distribution for either an individual risk or for total risk is with a Pareto graph, which combines a probability density function (pdf) and a cumulative density function (cdf). These are also known as a histogram with an S-curve.

Untitled Figure 1. A Pareto Graph

2.    What are the Top 10 Risks?

It is common for the project director to request the top 10 risks in monthly risk reports for both cost risk and schedule (delay) risk. These are usually ranked in descending of P80. What is P80? This means the 80 percentile of the distribution -- 80% of the data points are to the left of the 80th percentile and 20% to the right. The interpretation of this is that one can be 80% sure that the cost or delay will be at that value or less and, conversely, that one can be 20% sure that the cost/delay will be greater. Some companies use the P90, which suggest they are more risk averse. Some use P75, which is the upper quartile, Some use P68.2, which is one standard deviation – the statistical metric for uncertainty. And some companies use the P50, which is the same as tossing a coin. It is not possible to use Pareto graphs to identify the top risks. This is best done using either or all of the following graph types:
  1. Box and whisker graph
  2. Tornado diagram
  3. Density strip
All of these three methods work well in visually presenting the risks in order of magnitude, although the tornado chart is rather a "black box" method that may give different results from the other two graphs.

Untitled Figure 2 Box & Whisker Graph

Untitled Figure 3 Tornado Diagram

Untitled Figure 4 Impact Density Strips

It is important to understand that the P80 value does not tell one which is the biggest risk; the P80 is a single point on the pdf that simply means that one can be 80% sure that it will cost $X or less or that you can be 20% sure that it will cost $X or more! Do you get the message there about uncertainty? To truly explain this important point, I have plotted 10 risks, all with approximately the same P80 = 54.2, in the iso-contour graph below. Each of the risks has a different consequence and different probability. Untitled Figure 5 Iso-Contour Chart of 10 Risks With P80=54.2 Using the box & whisker plot and impact density strip, it should be immediately apparent, even to the untrained eye, that the risks are very different in terms of uncertainty and consequence. The challenge is determine which is biggest.

Untitled Figure 6 Density Strip of the 10 Risks

  Untitled

Figure 7 Box & Whisker Plot of the 10 Risks

We can see that risk 5 is actually quite certain, whereas risk 2 is very uncertain, and yet they both have the same P80. Here we need to understand how to deal with a risk and its certainty. It should now be clear that ranking and prioritizing risks on the basis of P80 alone is neither correct nor particularly meaningful, as all evidence of the probability distribution and impact distribution are missing. The three graphical solutions – box plot, density strip and tornado diagram -- make it easier for the managers to prioritize the risks visually by relating directly to both consequence and uncertainty. 3.    What Is the Significance of the Total P80 Cost? Almost the very first number that appears in the monthly risk report will be the P80 total for all cost risks. You might wonder why the P80 instead of the P90 or P50 or the standard deviation (P68.2). To project directors, the P80 is a magic number that can be shared with colleagues, the directors, the client. Why the P80 became the popular percentile is unknown. There is obviously a relationship between risk aversion and risk taking -- the more risk averse, the higher the P value that is preferred. -- Contingency as a percentage of baseline cost The project planning process will involve detailed cost estimates by quantity surveyors and cost engineers. These estimates will become the baseline cost of the project covering materials, labor and inflation. The risk manager will endeavor to get the cost team to do a risk review and build a range of uncertainties around the costs. During the design stage, this will usually be a +/-25% ball park figure, with the range narrowing as design and time progress. The formula used for determining cost based contingency is usually: P80 of cost estimate – base cost = contingency Often, the cost team includes project risks in the calculations, which are based on their personal experiences, which are usually undocumented and which inflate the base cost. You do not want this to happen. The planning team will, at the outset, establish some percentage of the total cost as a contingency. On the most recent mega-project valued at $2.3 billion, the contingency was 7% of the total forecast cost. How this contingency was determined was undocumented but presumably based on some experiential rule of thumb of the planning team. Curiously, this figure was shown on the management reports as a P80, presumably in an endeavor to give credibility to the contingency figure. -- Contingency as a function of risk assessment The risk management process is a journey over the duration of the project. It starts at the design phase, progresses through manufacturing, then on to construction and finally to commissioning. Although these are broadly distinct phases, there will be many overlapping time periods. The time of greatest risk will be during the design phase, when everything is pretty much unknown to all the project team. The uncertainties will be legion, from planning permission to technology, contracts to quality control, civil engineering works to change management. The risk should appear as a series of waves, growing rapidly during the design phase and then decreasing until approaching zero as the problems are solved. After all, you wouldn’t begin a project with huge quantities of unresolved risk. The graph below gives a idea of the risk over time over the course of the project:  

Untitled Figure 8 Risk Over Time

As each phase progresses, the risk will ebb and flow, progressively decreasing as the project concludes successfully. The risk total for the month will have meaning only in the context of the previous month’s risk total, the phase of the project and the forecast for the future risk over the course of the project. Untitled Figure 9 A Box & Whisker Plot of the First 10 Monthly Total Risk Values It can be seen from Figure 9 that the risk is progressively increasing until month 9, after which it appears to start declining. Risk will follow the phases described in Figure 8. Risk can be graphed according to each individual phase or a global overview. It should be apparent that the P80 doesn’t help the project director understand the current or future risk on the project, the nature of the uncertainty or the risk over time. A simple enhancement in Excel combining Figures 8 and 9 is given in Figure 10 so that deviations from forecast are clearly visible and comparable. Untitled

Figure 10 Current Monthly Risk Total Vs. Forecast P50 & P90.

The range of uncertainty in the current situation and the forecast are clearly displayed. Alternative measures of uncertainty can be used -- e.g., mean+/- 1 standard deviation.

In Figure 10, there is a noticeable  discrepancy between the current total risk and the forecast. It is essential to understand and report on the source -- for example, possibilities such as these:
  1. Fewer risks have been identified than expected
  2. The quantification of risks is too optimistic, i.e., lower cost
  3. The handling plans are assessed as more effective
  4. The forecast risk is higher than actually being experienced during design stage
  5. The design phase is running behind schedule
  6. Improved estimation skills are required, so a calibration training course needs to be put in place
It is important for the project director to understand exactly what is being measured in this concept of total risk. Useful reference: How to Manage Project Opportunity and Risk: Why Uncertainty Management Can be a Much Better Approach Than Risk Management, by Stephen Ward and Chris Chapman.

Gavin Lawrence

Profile picture for user GavinLawrence

Gavin Lawrence

Gavin Lawrence has 18 years of experience as a risk manager for international mega-projects in the UK, Africa, Venezuela and Russia. Projects include high-speed rail, subsea pipelines, oil rigs, underground metro systems, offshore windfarms and urban redevelopment projects.

Convenience, Meet Technology -- 4 Steps

We now live in a one-click-to-buy world where customers demand extreme convenience based on deep understanding of their needs.

With technology rapidly changing, customers now expect simple, fast transactions from companies. These expectations have helped create a one-click-to-buy world, further changing not just how, but why and where, we spend our hard-earned money. On-the-Go Shopping Goes State-of-the-Art  A case in point is multinational grocer Tesco, based in the UK, Known in Korean markets as Homeplus, Tesco sought to better understand the dilemma that grocery shopping posed for many time-compressed people there. Why not bring the store to the people? Why not turn wait-time during daily commutes into time for shopping? Why not use readily available technology to give consumers grocery stores in the palms of their hands? “Virtual” grocery stores, complete with mock aisles and fridge displays, were placed in mass transit stations. Commuters scanned the QR codes of the products they wished to buy with their smart phones and scheduled a home delivery at a time convenient for them. Tesco’s online sales skyrocketed. Why did this work? First, Tesco recognized the thing most desired by consumers: convenience. Second, Tesco used the best tools, such as smart phone apps and mobile technology, to give consumers what they wanted. Hearing Customers, Responding With Useful Technology It’s not just about having a slick interface (though that never hurts). Companies that are on top of the online shopping game are providing seamless and smart integration of both in-store and online customer experiences. The use of “virtual” stores by Tesco was a smart move, allowing customers to explore the technology in a setting that was familiar to them, making the acclimation to full online shopping seamless. The “aisles” and “fridges” brought with them the comfort of a brick and mortar store, allowing for the browsing and impulse buying that we often associate with picking up our groceries. However, the use of the smart phone app upped the ante and scratched other consumer itches: the desire for speed and convenience. Four Steps to Take: 
  1. Seek to have a deep understanding of your customers' needs.
  2. Combine that understanding with technology, to build a truly singular and timely customer experience that is both appealing and significant
  3. Integrate mobile and online technologies into the company’s identity and marketing
  4. Bring the best uses of technology to the company and deliver that tech-savvy company to the consumer
Tesco offers us a portrait of what it looks like to utilize technology to stay competitive in an increasingly diverse market. And remember, at this heart of success is a deeper understanding of what the customer wants.

Donna Peeples

Profile picture for user DonnaPeeples

Donna Peeples

Donna Peeples is chief customer officer at Pypestream, which enables companies to deliver exceptional customer service using real-time mobile chatbot technology. She was previously chief customer experience officer at AIG.

The Questions to Ask on Telemedicine Risk

Insureds often ask, "Am I covered if...?" That can be a good question but, for complex issues like telemedicine, must lead to dozens more.

A conversation with our insureds often begins with them asking, “Am I covered if…?” As an insurance carrier risk manager, I’m happy that they’re asking (and I’m really happy if it turns out they are asking before starting the business, practice, procedure or service that prompts the question). The question gives us all an opportunity to refocus on applying the risk management process to identify, analyze, treat and then re-evaluate the risk. Increasingly, these types of questions among healthcare providers are related to some kind of telemedicine service or activity, and they are interesting questions. The applications for telemedicine are growing exponentially (as is the variety of providers), much as TV and microwaves caught fire decades ago (figuratively, not literally, although hazards are also a domain of risk management). Why the surge in interest? For starters: healthcare cost containment; an increasing financial incentive; increasing market share; access to specialists and other care providers in rural or other underserved areas; access to healthcare for those who are unable to travel; convenience and time management (both for patients and providers) and continuity of care. Although “risk avoidance’ is a legitimate risk technique, it can be an easy out and may be a natural reaction to an emerging risk area such as telemedicine. It is critically important that today’s healthcare risk managers not be known as “the just say no people.” As a former clinician, I have seen how cutting-edge approaches to medicine have advanced the state of healthcare. And, telehealth is here to stay! Let’s get back to the “Am I covered?” question. The short answer would, I hope, be: “Of course you’re covered. Telemedicine is a good thing for patients.” Right? But, (yes, risk managers like to say “but,” usually after saying, “I don’t want to be negative about this idea, service, procedure, etc.”) a certain road is paved with good intentions, and there are some significant possible risk exposures and obstacles to implementing a safe, compliant and effective telemedicine program. Although risk managers are generally fun people – honest -- we can be perceived as wet blankets at times, because we always look at the world through the “risk vs benefit” lens. So, in reality, insurance carrier risk managers may need to say, “It depends. . . .” and then, “I have some questions.” This is where you can help by confidently putting your best foot forward and saying, “Ask away, I have the answers you need.” A risk manager’s job (yours and mine), first and foremost, is to protect the assets of the organization. And that protection certainly includes helping to appropriately support and defend good clinical care and those who provide it, especially when someone registers a complaint or pursues a professional liability claim. We need to not only look at specific professional liability insurance policy language, but we must also consider all of the risks and exposures associated with telemedicine and determine whether you are adequately treating those risks. Insurance coverage is just one of the risk treatment techniques (risk transfer) used to address risk exposures – even though it can feel like the most important one to those who are kept awake at night worrying about an organization’s risk exposures, liability and finances. In today’s complex healthcare environment, there is a need for an operational (enterprise) risk management approach to decision making to help manage liability exposure across all of the domains of risk. Along with that, the role of the healthcare risk manager is evolving into taking a leadership role in this approach. But developing a culture and discipline of identifying, analyzing and treating risks is more of a journey than a sprint, so try not to get daunted by the process right away. You can be more “tactical” (a rapid response) as the circumstances may require once you establish process. An Example Let’s take an example of one risk exposure for a telemedicine program -- credentialing and privileging -- and illustrate how we can help answer the “Am I covered…” question by using the risk management process (the first three steps anyway; I’ll leave the “monitor/re-evaluate” steps to you). Risk Identification What do we already know about some of the key risk exposures related to telemedicine? We recognize that they generally may include the following, but you’ll need to also identify any other risks unique to your program:
  • Information privacy/data security
  • Potential technology-related issues (e.g., failure, resolution, accuracy, etc.)
  • Data ownership/retention/destruction/e-discovery
  • Credentialing/privileging of providers
  • Patient selection, communication, education
  • Documentation of communication and encounters
  • Consent for use of technology/treatment
  • Health insurance payer coverage/reimbursement
  • Billing
  • Compliance
  • Contracts/agreements
  • Liability insurance coverage
Analyzing the Risk Here’s a series of questions that I’d like to know the answers to as your carrier in evaluating you as a “risk.” You should have done your due diligence already. The sample list is not meant to be exhaustive, but illustrates developing a discipline around a comprehensive analysis:
  • Does your governing body understand its role and responsibilities regarding credentialing and privileging? (Standards of care, scope of practice, negligent credentialing, non-delegable duty, D&O, E&O, etc.) Even when a third-party credentialing verifications organization is used, privileging decisions are still the responsibility of the hospital’s governing body.
  • Are you a hospital telemedicine site? A free-standing telemedicine site? An originating site or distant site? Is there a solid understanding about how telemedicine credentialing and privileging should be done depending on your role?
  • Have you met all applicable state statutory requirements for a telemedicine license? How about applicable state medical/licensure board requirements for all licensed practitioners? Non-licensed? What are the exceptions to requirements?
  • Have you met all accreditation standards and requirements (if applicable)?
  • Are there written policies and procedures in place that outline the credentialing and privileging appointment and reappointment processes, criteria for telemedicine activities, scope of practice protocols, OPPE and FPPE and the data from the originating and distant sites that must be collected and analyzed (and acted on)? How will the originating site be notified of privilege or license revocations or suspensions?
  • Do your hospital or medical staff bylaws and rules and regulations accurately reflect these issues for telemedicine: federal regulatory and state specific licensure requirements (for all providers); current CMS CoPs; health insurer panel requirements for credentialing; the privileged provider’s medical staff category?
  • Does the current structure of your quality-improvement and peer review programs adequately protect shared data between originating and distant sites?
  • Is there a compliance plan that addresses billing practices and regulatory noncompliance?
  • Are there written agreements in place between the distant site hospital or entity and the hospital seeking services?
  • Do you have the appropriate medical staff leadership and medical staff services resources to manage your credentialing and privileging activities?
  • Are there appropriate, required governing body, medical staff leadership and medical staff services training and education on credentialing and privileging for telemedicine?
Analyzing Insurance Coverage By way of this next series of questions, you can begin to bring into focus some possible strategies for treating telemedicine risk exposures by using the risk transfer technique to ensure you have the right coverage for those risks:
  • Will existing health professional liability (HPL) coverage address errors and omissions on the part of distant-site physicians and practitioners?
  • Do you have adequate coverage limits for the telemedicine activities and providers?
  • Are there subcontractors allowed? If so, confirm the subcontractor’s insurance coverage and limits.
  • Are there shared or individual coverage limits? Which should be required to meet your risk financing needs?
  • Are there any jurisdictional limits for coverage under the policy? State-to-state provider licensure?
  • Are there practitioners practicing outside of the U.S.? Do you have any exposure in countries outside of the U.S.? Will (HPL) coverage extend to such services?
  • Is your insurance carrier licensed to write coverage in multiple states? Foreign countries?
  • What types of insurance coverage are in place for negligent credentialing, where claims are based on reliance on credentialing and privileging information submitted by a distant-site hospital or distant-site telemedicine entity?
  • Does the hospital have appropriate coverage for business disruption (the third-party vendor stops offering the service)?
  • Are insurance coverages (at limits set in medical staff bylaws approved by the governing body) in place for credentialing and privileging legal exposures:
    • Does the telemedicine provider have professional liability coverage for this service?
    • Does the telemedicine provider have cyber risk coverage?
    • Does your cyber risk/technology E&O coverage extend to the telemedicine activities?
    • What types of insurance coverages and limits will be required by contract of the distant-site hospital and distant-site telemedicine entities?
    • Will the contract preclude shared coverage among the (ever-changing) list of care providers and the distant-site hospital or distant-site telemedicine entity?
    • Will the insurance coverage include indemnification coverage for cost of defense up to the point of disposition of a regulatory investigation based on the telemedicine services furnished by the distant-site hospital or distant-site telemedicine entity?
  • Review of your insurance coverages should extend to the various layers of an insurance program – excess carriers – and also to specialty programs such as RRGs, insurance trusts and captive insurance plans.
In Summary How can you develop a discipline of comprehensive risk identification, analysis, treatment and evaluation to address risks such as telemedicine credentialing? Here are some key steps in the process to consider:
  • First, create or gather your “Operational/ERM Committee” (or whatever you wish to call it). There should be a core group for this, and then perhaps create ad hoc “tactical taskforces” for each specific issue as necessary. In the case of telemedicine, this may mean consulting with internal and external resources such as legal , insurance carrier, risk managers, medical staff, medical staff services, marketing, finance, regulatory, accreditation, quality, compliance and IT professionals.
  • Gather data and input. As a side note, this is an area where some insurance carriers provide valuable tools and resources for their clients to use; for example, OBPI has a web-based Telemedicine Risk Assessment Tool that will efficiently perform a “risk inventory” to help in your data gathering and risk identification. So be sure to tap into that expertise.
  • Create/document your “risk inventory” (include all of the domains of risk).
  • Perform your risk “gap analysis.” Where are your weaknesses or gaps?
  • Determine your risk evaluation (for each weakness/gap determine the domains affected and the degree of impact to the organization).
  • Decide how you wish to treat each risk exposure (the proposed risk treatment technique and proposed action plan). Develop or revise your written operational plans, policies and procedures and credentialing and privileging services agreements as necessary.
  • Talk to your producer/agent to determine what type of coverage, at what limits of liability, are best for your organization.
  • Put your requirements for coverage in your organization bylaws or medical staff bylaws.
  • Monitor, measure (develop dashboards/scorecards), re-evaluate and re-design as necessary.
In the End To circle back to the initial question, “Am I covered?”, as you can see, the answer may not be a simple, immediate “yes.” “It depends” is what you may be more likely to hear. But despair not. Remember, we’re all risk managers, in this together, trying to protect the assets of the organization by treating risk exposures adequately and effectively. Be prepared to present your ERM analysis and treatment results in response to questions (or, even better, preemptively present them when you ask the question about insurance coverage), and you’ll be on your way to an answer that is hopefully more like, “Of course you’re covered. Your telemedicine program is a good thing,” than, “Houston, we have a problem.” And, you, your carrier and your broker can all breathe a sigh of relief and get a good night’s sleep.

Patricia Hughes

Profile picture for user PatriciaHughes

Patricia Hughes

Patty Hughes is responsible for OBPI’s risk management resources and services for healthcare policyholders. Recognizing that the role of the healthcare risk manager is changing, Hughes continuously strives to develop and position offerings in a unique way that support the evolution of this role across all healthcare settings and that help to demonstrate the value of an effective risk program in an organization.

The Gristle in Dodd-Frank

An unintended consequence of Dodd-Frank means that some insurers are unfairly being held to capitalization standards designed for banks.

I love using the phrase “unintended consequences” when talking about our issues on Capitol Hill. It’s so commonly understood among veteran staffers that legislative actions produce market reactions, some that are unexpected and unintended. Whoops!
Sometimes these unintended consequences are significant, like when Congress passed the behemoth rewrite of financial regulations in the Dodd-Frank Act. A big unintended consequence of that law gave the Federal Reserve the authority to regulate non-bank “systemically important financial institutions” (SIFI), as designated by the Financial Stability Oversight Council (FSOC), with the same capital standards that they impose on banks. Insurance companies at risk of being regulated by the Federal Reserve, like MetLife, Prudential and AIG, are facing the big threat of being held to an additional layer of capital standards that are bank-centric and threaten their regulatory compliance models and ultimate product safety. The thing is, the business of insurance is very different from banking, and regulatory capital standards designed to protect consumers should reflect those differences. Property-casualty and life insurance products are underwritten with sophisticated data and predictable global risk-sharing schemes that inherently withstand most market fluctuations. And to protect consumers, different capital standards are imposed on insurance companies for the different models and products they produce. Traditional banks, however, have different economic threats, requiring different standards. There cannot be a run on insurers with claims the way there can be on banks. The last economic crisis demonstrated that varying insurance capital standards protected the insurance industry throughout the global debacle. Even AIG’s insurance operations were well protected (it was AIG’s non-insurance financial products division that led to the company’s near-demise). Allowing the Fed to regulate insurers with the same standards as banks not only threatens corporate compliance models but also ultimately makes it more expensive for insurers to share risk, increases the cost for the same level of coverage and spikes prices for consumers. Even the congressional authors of the too-big-to-fail language recognize the issue and are pushing to correct it. Sen. Susan Collins, R-Maine, who originally wrote the Dodd-Frank provision to allow the FSOC to designate insurance companies as SIFIs, recognizes that any capital standards imposed by the Fed should be duly tailored for insurance companies. She said in congressional testimony: “I want to emphasize my belief that the Federal Reserve is able to take into account—and should take into account—the differences between insurance and other financial activities…. While it is essential that insurers subject to Federal Reserve Board oversight be adequately capitalized on a consolidated basis, it would be improper, and not in keeping with Congress’s intent, for federal regulators to supplant prudential state-based insurance regulation with a bank-centric capital regime for insurance activities.” Fed Chair Janet Yellen, who is responsible for implementing the law, agrees. So there’s now legislation in the grinder designed to fix the problem by giving the Fed flexibility to tailor capital standards to the unique characteristics of the insurance industry. The bill passed the Senate without opposition but at the time of this writing is stalled in the House and risks being caught in the partisan battle between the House and Senate’s varying legislative vehicles. It’s rightly frustrating to stakeholders and lawmakers that the fix is held up, but it’s not surprising that another serious unintended consequence is facing our industry. I’ve used the term when discussing the Foreign Account Tax Compliance Act (FATCA), flood reform, and the Affordable Care Act (ACA). I hope we can see the legislative fix to this latest unintended consequence signed into law soon. This article first appeared in Leader’s Edge magazine.

Joel Kopperud

Profile picture for user JoelKopperud

Joel Kopperud

Joel Kopperud is the Council of Insurance Agents & Brokers’ vice president of government affairs. He focuses on legislative and regulatory activity affecting employer-provided benefits, property/casualty insurance regulation and federal natural catastrophe policies. He is a regular contributor to Leader’s Edge magazine.

Core Transformation – Start Your Engines!

Insurers recognize the need for core transformation but need three technical capabilities to be able to keep up with changes in the market.

Ready, GO, set! That might not describe every core modernization project, but it certainly can seem that way in today’s fast-moving environment. Now that the insurance industry recognizes modernization as an indispensable tool for remaining competitive, it is worthwhile to take a step back and look at the technical capabilities that insurers really need from modern core systems to fulfill the potential of core transformation. First, it helps to define what exactly a modern system is today. This is trickier than it sounds because the definition of “modern” has changed in recent years – and will continue to change. Core systems that were considered modern in 2010 are already showing their age, as recent systems have far outpaced their capabilities. Strategy Meets Action (SMA) defines a modern system as an application that includes robust configuration capabilities usable by both IT and business users, uses standardized application programming interfaces (APIs) to facilitate integration of new systems and technologies and leverages service-oriented architecture (SOA) principles to enable scalability. Each of these capabilities is crucial to being able to use core modernization as a launch pad for core transformation. In our recent study on trends in policy administration, an amazing 94% of P&C insurers reported that product configuration capabilities are a required feature in a new policy administration system. This is a requirement across the industry for all core systems. Configuration capabilities are so important because they are critical to accelerating speed to market and speed to service. An insurer’s ability to react to market changes and take advantage of new opportunities is limited by the amount of time it takes internally to roll out new products and services or modify existing ones. Robust configuration tools not only make configuration easier but also spread it throughout a wider portion of the company, reducing the bottlenecks that often occur when all changes must be coded by a programmer. In a market where products and services are more personalized, configuration within policy, billing and claims becomes an essential tool. Core systems today are required to dynamically integrate with various internal and external systems and new and real-time data, as well as big data. SMA’s research reveals that, as the sophistication of the solutions on the market has grown, insurers are often using third-party solutions for ancillary systems like business intelligence, agent portals, new business and document management. The number of data sources continues to grow significantly each year, including maturing and emerging technologies like telematics and the Internet of Things (IoT) that generate large quantities of data ripe for analysis. Data from these and other new technologies have myriad uses, including to rate a risk, personalize a service or present a new product offering. Specific solutions depend on integration with the core, and reducing the time and effort demanded by integration promotes the consideration of, for example, a business intelligence (BI) solution capable of vastly more in-depth analysis than the integrated BI component of a PAS, or an external data source that provides information that an insurer otherwise could not use. Easing the friction of integration benefits insurers well into the future, because easier integration today also translates to less arduous integration with systems and applications not yet imagined. The most modern solution on the market is only as good as the book of business it can manage. With transaction volume and speed increasing, insurers must have scalable systems capable of meeting new and increasing demands, which requires leveraging SOA principles. Not only do insurers gain the ability to use a modern system’s capabilities with an increasing number of transactions, they also can extend the life of the system by enabling it to expand. When demand spikes after a catastrophic event or when a new market opportunity is identified, the system is well prepared to manage it. Cloud capabilities are presenting real alternatives to provide the scalability needed to successfully handle peak workloads, both anticipated and unexpected. These three critical components of a modern system are not just what insurers need today – they prepare insurers to adapt to the future. Modern core systems with these capabilities can evolve along with the insurer. Insurers need to be able to shift their technology environment as needed to meet the future’s unknown opportunities and challenges, and that requires the ability to create products, integrate the latest systems and technologies and scale in concert with an insurer’s book of business. When the need arises for integration of artificial intelligence, for example, or processing millions more transactions per hour than ever before, the capacity is already ready and waiting. Once insurers know they can depend on their core systems to support them through market changes, they can focus their attention on optimizing their current processes and innovating to become a Next-Gen Insurer. The order is important – ready, set, go. No matter how fast you want to move, you need to plan and then execute! Don’t let technology drive you – embrace the change and adopt technology with your future vision in sight.

Karen Furtado

Profile picture for user KarenFurtado

Karen Furtado

Karen Furtado, a partner at SMA, is a recognized industry expert in the core systems space. Given her exceptional knowledge of policy administration, rating, billing and claims, insurers seek her unparalleled knowledge in mapping solutions to business requirements and IT needs.