Download

What Really Sank the Titanic?

You could say it was the lack of ISO 31000 -- or, at least, the ship's builders lack of attention to the potential for cascading risks.

ISO 31000 (Risk Management) and its supporting publications encompass an impressive to-do list of risk management guidelines for organizations. However, if an organization selectively pursues some of the ISO guidelines and ignores others, highly undesirable events -- even tragedies -- can occur. This is what happened with the Titanic.

ISO 31000, section 4.2, suggests we align risk-management efforts to our objectives. White Star Lines, the Titanic's builders, fulfilled this requirement. The objectives were to create a luxury liner at the lowest costs, in the least amount of time, and maybe even break the speed record for an Atlantic crossing. These were admirable goals. The Titanic also followed ISO 31000, Section 5.5.1.b., by "taking or increasing the risk in order to pursue an opportunity." The builders did so because they believed their risks were not extraordinary and could be controlled. This is a common judgment error.

THE PURSUIT OF OPPORTUNITIES, NOT AN ICEBERG, SANK THE TITANIC

The individual risk opportunities that Titanic pursued were not terribly unusual, but collectively they created a perfect storm fueled by three main, linked, cascading risks:

  1. Ship design shortcomings influenced by cost-cutting efforts
  2. Flaws in rivets
  3. Mistakes in the operation and evacuation of the vessel
ISO 31000, Section 5.4.2, warns us that "Risk identification should include examination of the knock-on effects of particular consequences, including cascade and cumulative effects." The World Economic Forum, in its 2014 Annual Global Risk Report, highlights cascading and connected risks many times as a serious threat. The report also stated the need for better efforts to deal with such threats by supplementing traditional risk management tools with new concepts, methods and tools.

What are cascading risks?

Cascades can be beneficial, neutral or destructive. We define cascading risks as a series of interacting risks that emanate from leadership (aces) through the work culture (kings) and work processes (queens) that create bad performances (jacks) and negative feedback loops (jokers) back to leadership. Leaders then either apply learnings in creative ways or ignore the cascade signals, which can lead to disasters. Detailed cascading risk analysis can aid in minimizing such risks.

Cascade #1 That Threatened the Titanic - Inadequate Design

The Titanic’s design was not unsinkable, as was widely publicized at the time. It had many "watertight compartments," but they were open at the top, like an ice cube tray. It had far too few lifeboats, a result of cost-cutting efforts during the design phase. It had a double bottom, but that did not extend up to the waterline, where the iceberg sideswiped the ship. This design flaw was quickly corrected on the Titanic's sister-ship, Britannic, which was still under construction at the time of the Titanic's sinking.

The Titanic's builders claimed that it was constructed considerably in excess of the Lloyds registry safety requirements. Therefore, they never saw the need to seek Lloyd’s registry approval. However, Lloyds disputed that claim publicly after the Titanic sank.

Cascade #2 That Threatened the Titanic - Bad Rivets

The Titanic required 3 million rivets to hold her together. Archives tell us that, at that time, there was a shortage of riveters and the necessary materials to create high-quality wrought iron rivets. White Star's competitors converted to 100% steel rivets, which were much stronger.

The Titanic used steel rivets in the straight section of the hull but not in the front, where the iceberg hit -- wrought iron rivets were easier to rivet by hand than steel rivets in those sections. The recovery of the Titanic's wreck from the sea floor confirmed the low quality and brittleness of the rivets in the impact areas. Higher-quality rivets would have kept Titanic afloat longer and saved more passengers.

Cascade #3 That Sank the Titanic – Operation and Evacuation Errors

The Titanic was cruising near top speed, which was very risky on a moonless night through an area with active iceberg warnings. Just hours before the disaster, the captain canceled a lifeboat drill for no apparent reason. It was suspected that the captain was attempting to break a cross-Atlantic speed record. That recklessness and the collision with an iceberg sealed the Titanic’s fate. Her brittle rivets in the impact area popped off and allowed water to rush into the hull. The Titanic sank in less than three hours. 1,502 people perished after a disorganized evacuation filled the far-too-few lifeboats to just 61% of capacity.

Conclusion

Although ISO 31000 attempts to protect us from ourselves and the outside world, we cannot be selective in what we implement. We need to follow all of the guidelines and even test areas that we believe are safe. We must also heed ISO's challenge to examine cascading and cumulative effects. Effective risk-based thinking must include cascade effect thinking.

Top 10 Emerging Social Risks in 2015

As societies become more related, breakdowns anywhere can cause disruptions worldwide -- these 10 may surface fast.

|

Risk managers make many decisions - building valuation, vendor management, employment issues, budget allocation, to list a few. However, in our rapidly changing society, managing risk is more than simply choosing the best insurance package or retention level. We must monitor our world to watch for emerging societal risks that can abruptly increase our day-to-day challenges.

What is an emerging risk? I'm going to borrow a definition from Donald Donaldson of LA Group in Montgomery, Texas. He defines emerging risk as: "A new loss exposure for which a risk treatment has not been identified, or an existing exposure that is evolving and becomes difficult to quantify." The Organization for Economic Co-operation and Development (OECD) describes "emerging constructs" as "major trends or new and persistent threads of behavior driven by a particular alignment in incentives or a technological innovation." Whether you define societal risks as emerging risks or constructs, many challenges lie ahead for today's risk managers.

Using my education, which includes a master's degree in sociology, and my experience as a risk management professional, I forecast 10 social risks emerging -- in some cases swiftly -- in 2015 and beyond.

1. Europe, Asia and North America face increased risk of "sleeper cell" terrorist attacks. As attacks increase, so will hate crimes against all Muslims. In response to such attacks, formerly moderate Muslims may become increasingly radicalized. Houses of worship will become much more difficult to insure as hate crimes increase.

2. U.S. police forces will face pressure. They will come under increased scrutiny by the public because of societal tensions, social media and a general distrust of authority. The use of body cameras and ramped-up training will increase, in part to satisfy the demands of insurers, which bear the brunt of adverse claims actions.

Increased terrorism may cause police departments to devote more resources to tracking down and isolating suspects. This may, for a time, tip the scales in favor of police forces. However, an increased focus on terror training leaves police with fewer resources to investigate property and day-to-day crime that we now rely on them to handle expeditiously. Losses will increase and further erode the public's confidence in the police. The belief that the police are here to protect only the rich and powerful may spread, adding to the public’s growing distrust of authority.

Homeowners' carriers may find themselves facing unusual risks as more homeowners arm themselves or buy personal protection dogs. Zdenek Blabla, owner of Alpine K-9, imports Czech Border Patrol protection dogs for his clients. "In the past year, I've sold several German shepherd dogs to special forces combat officers who don't want to leave their families without protection during their activation," he says. "They understand probably better than anyone the dangers we face in today’s society."

3. Policing agencies across the nation will face increased recruitment and retention difficulties because of a less robust candidate pool and the need for officers who are better-qualified to interact with diverse communities. For years, U.S. police chiefs complained of their inability to attract highly qualified recruits. According to one textbook on policing tactics, "Poor recruitment and selection procedures result in hiring or promoting personnel who cannot or will not communicate effectively with diverse populations, exercise discretion properly or perform the multitude of functions required of the police." It is clear that today's U.S. police forces face significant and growing challenges.

4. Schools will focus more on instructing schoolchildren how to protect themselves in risky situations. Examples include how to cooperate with the police in a routine traffic stop or other police intervention, what to do in a hostage situation and "duck and cover" exercises for students in newly emerging earthquake zones. This increased focus on situational awareness will drain resources from already depleted public school funding, ultimately reducing the time spent for the actual education of students.

5. Corporations that rely heavily on suppliers both here and abroad will closely analyze their supply chain risk. With political disruptions likely to increase supply line disruptions, risk managers must analyze sole-source and global suppliers and ensure the organization's insurance will respond appropriately to these unique risks. As recently as 2014, one major university referred to supply chain disruption from civil unrest as "not a major concern." Given the recent disturbances in Oakland, CA, New York City and Ferguson, MO, civil unrest is a growing concern for risk managers worldwide in 2015.

6. Employers will realize the need to increase security while also purchasing kidnap and ransom coverage for employees who travel abroad or face domestic terrorism threats. The Charlie Hebdo massacre starkly revealed that Stéphane Charbonnier's bodyguard was completely unprepared for that brutal attack. Business owners will face the need for improved security measures at their homes and businesses, as well as when their family members travel.

7. Communities will experience an increase in social unrest, driven by social media “flash mob” actions or spontaneous reactions after incidents with racial or equality overtones. Other controversial issues, such as environmental measures and other governmental actions, will trigger increased public discord and civil disruption.

8. Continued weather swings will result in property damage and loss of life from natural disasters. With more money allocated to fight the new wave of terrorism both at home and abroad, fewer federal dollars will be available to help weather-ravaged communities. As we saw after Hurricane Katrina, civil unrest follows when authorities cannot provide adequate protection.

9. Poverty, income disparity, unemployment and dissatisfaction among today's youth will increase globally. Expect corporate leaders, including top insurers, to more candidly discuss poverty and income disparity, unemployment and dissatisfaction among today's youth in America, the Middle East and Europe. Graham E. Fuller, author of The Future of Political Islam, discussed this concept in 2003: "The great question for most Middle Eastern societies is who will be able to politically mobilize this youth cohort most successfully: the state, or other political forces, primarily Islamist?" We must not underestimate the ways that unemployment and poverty may lead to the radicalization of youth both here and abroad.

10. Pandemics will threaten local medical resources' ability to provide adequate medical care. Flu epidemics, tuberculosis, measles and other contagious diseases will make medical management much more onerous. An aging population with chronic conditions will place additional stress on available medical resources. According to the World Health Organization, there is an "emerging global epidemic of diabetes."

Are these predictions exaggerated? I don't think so. That advanced degree I mentioned earlier tells me that I have not overstated these predictions; they are credible and approaching quickly. As societies become more complex, yet increasingly related, breakdowns anywhere in the global chain can cause disruptions worldwide.

As risk management professionals, we must do more than simply purchase a coverage portfolio to protect our assets. We must understand and prepare for the societal risks that present unlimited challenges to America’s organizations.

Why Health Insurers Make People Ill

If insurers simplified products and trained staff better, they could eliminate scads of customers tirades while saving tons on reps.

'Tis the season for health insurance open enrollment, which can mean only one thing: My blood pressure is going up.

Health insurers talk a lot about how they're my "wellness partner," helping me "live a healthier life" and "empowering me to make good decisions." But I find all they do is make me ill... sick with annoyance.

That's perhaps best evidenced by the annual health insurance open enrollment process, when insurers put on a master class in exactly how not to treat your customers.

My open enrollment journey began with a letter from my insurer, indicating that my current health plan would no longer be available next year. However, the letter explained, the company had already selected a replacement plan that would best meet my needs.

Of course, the company neglected to tell me what that plan was. Perhaps the company felt that adding an element of mystery and suspense to the process would make it more exciting?

A few weeks later, the company graciously revealed its plan selection in a second notice. It picked a coverage option that was nearly twice as expensive as my current one – with a narrower provider network, to boot. It seemed like a selection that best met the company's needs, instead of mine.

So off to the Internet I went to research my alternatives. That alone was an adventure, given how many insurers' health plan websites appear to have been designed by crazed, blind hermits.

My personal favorite was one major insurer's site, where about half the links to health plan details yielded the dreaded "404 Web Page Unavailable" error. I guess the company really wasn't interested in getting my business (or anyone else's).

After evaluating other offerings, it was time to figure out what my options were with my current insurer. Naturally, the company's online plan descriptions triggered more questions than they answered – which meant I'd have to contact the insurer's 800-line service center (also known as Dante's Ninth Circle of Hell).

All I wanted was to speak with someone who could help me. But that was clearly setting the bar too high.

Once I navigated the labyrinth that was the 800-line menu, I was subjected to a series of pre-recorded messages, including one that felt less like a call center greeting and more like an oral history of the Affordable Care Act.

Then there was the 20-minute wait until a representative was available, with the on-hold music periodically interrupted by an ironic recorded assurance that the company "values my time."

The company valued my time so much that it made sure to consume a lot of it. That first call lasted more than two hours and included 10 transfers, because nobody seemed to be the "right person" to help me. You'd think I was asking about some arcane plan feature, but all I had were some straightforward questions comparing networks and benefits across two of the company’s plans.

Each service representative I spoke with began the conversation using the same scripted phrase: "What would you like to accomplish today on this call?"

"I'd like to not get transferred," was the reply I started using about an hour into the odyssey. "That's my goal on this call." The vast majority of the people I spoke with were unable to satisfy even that simple request.

Oftentimes, I found I knew more about these plans than the enrollment representatives themselves. I even resorted to walking one of them, step by step, through the company's own website materials, when the rep insisted the plan I was considering had no out-of-network coverage. (It did, and the rep finally concurred.)

Even after this first marathon call ended, I was compelled to call again... and again and again.

In some cases, it was to follow-up on information that enrollment representatives had promised to send me but never did.

In other cases, it was just to ask the exact same questions of another person, because I had absolutely no confidence in the responses I was getting. I would pose the same question to three representatives and get three different answers. That's how my insurer empowers me to make a good decision?

My experience is not uncommon; health insurers routinely bring up the rear in cross-industry customer satisfaction rankings. It raises the question, though: How much unnecessary expense are these companies incurring as a result of all this incompetence?

If health insurers simplified their products a bit, if they made their information materials a little clearer, if they trained and equipped their staff better - how much consumer confusion would they mitigate? How many incoming calls, e-mails and tirades would they preempt? How much operational savings could they pass on in the form of more affordable coverage?

In a health insurance marketplace that's becoming increasingly consumer-directed, many insurers have taken to the airwaves to highlight how they enrich our lives and improve our well-being.

But you can't advertise your way to a good customer experience. If health insurers are serious about improving my well-being, they can start by creating an open enrollment process that's more satisfying than it is sickening.

This article first appeared at LifeHealthPro.

Did the Work Comp Nurse Make It Worse?

They can cause disasters if not incorporated thoroughly into the team handling a claim -- or they can provide crucial assistance.

|

Case management nurses can unwittingly hinder the control of workers' comp claims. Consider the perfect storm of "assumptions" leading to disaster: An adjuster receives a claim requiring extended treatment, makes the standard screen-clicks to assign a nurse and logs the claim in the diary. The employer assumes the case is being scrutinized and treatment is being managed. The adjuster assumes it is okay to ignore the case for a while. The nurse takes the initial claim information at something approaching face value.

In these situations, many nurses act but don't interact. They assist with referrals and expedite the collection of medical information. Unfortunately, they may not use their clinical acumen on critical issues like compensability, diagnosis, causal relationship, return to work (RTW) and treatment plans. We should note that nurses must balance caseloads and respect their company's requirements for speed. As such, they might feel justified in expediting what appears to be a common assignment.

When it comes to referrals, a well-intentioned nurse can cause disaster. I have experienced all of the following: a claimant alleging breathing issues referred to a "sick building expert"; a claimant with negligible head trauma to a "closed head injury specialist"; a claimant alleging jaw pain to a "TMJ dentist"; and the ever popular referral of a claimant with mysterious pains to a "chronic pain specialist."

These real examples all involved highly questionable claimants. Needless to say, medical expert "hammers" saw perfect "nails" in each claimant and fully validated the conditions and the causal relationship each alleged. By the time of the next adjuster diary, it was all over but for the increase in reserves.

The claimant can steal control of a case and contrive subjective medical issues if a nurse simply collects doctor reports and fails to interact. Countless WC case files exist where medical notes are simply pasted in by the nurse. (As far as I am concerned, this indicates adjuster/employer failure and not necessarily a poor nurse.)

I have witnessed nurse case managers decline to intervene in RTW efforts, and the corporate nurse care management entity can, conveniently, relieve itself of RTW responsibilities without affecting its fixed fee. I would argue that some level of RTW support from a nurse can and should exist on any given case in any jurisdiction.

Quick Tip: You and Your Adjuster Must Engage and Direct Nurse Assignments

A nurse should be vital in selecting providers for specialist evaluation or independent medical exams (IMEs). However, the nurse needs the insight and outlook that can only be gained by communication and planning. Engage the nurse and explain all the case issues and concerns. Compare providers and agree on who might be most appropriate. Agree on the specific background, insight and questions to be given to this provider. An early conference call should be mandatory.

The nurse should be an active member of the claim team, including adjuster, employer, defense counsel, Medicare medical savings account (MSA) vendor and, in certain cases, the special investigative unit (SIU). Nurse contributions should be vital to team decisions and strategy.

Make certain the nurse case management fee-structure allows extended work, as a claim might require. Reconfigure if necessary to ensure nurses can spend adequate time where needed.

A nurse should be asked to evaluate, comment and make suggestions based on all medical info collected. This insight can be used by the team to make tactical and strategic decisions.

A nurse is most useful for assessing the claimant on a personal level. The nurse should be sought for oral comment on impressions and gut feelings based on interaction with the claimant. Written assessments, which are subject to discovery in legal proceedings, need to be subtle and are not as meaningful. Therefore, conference calls on an interim basis are critical for gaining powerful nurse insight.

Nurses should absolutely support RTW efforts, either at most by collecting potential jobs from the employer and sharing these directly with the employee and doctor or at minimum by reminding the doctor that the employer has a RTW program and expects participation. Somewhere along this range of support should fit any jurisdiction.

Nurses are great tactical tools against unwieldy claimants. They can relay important details and extraneous issues to a physician that can affect causation determinations and reliability assessment of subjective symptoms. Nurses give doctors an "option B" of facts and background when doctors otherwise would only consider "option A," as relayed by a claimant. Without an "option B," doctors are more likely to give a claimant benefit of the doubt.

Most important: The power of case management nurses is wasted if you do not provide specific insight, direction and expectation for each claim assigned.

5 Ways Insurance Supports the Economy

Insurance helps the economy function by removing the paralyzing fear of adverse incidents -- and that's just the beginning.

Insurance affects everything, and everything affects insurance. It is generally understood that insurance allows those who participate in the economy to produce goods and services without the paralyzing fear that some adverse incident could leave them destitute or unable to function. However, few people are aware of the extraordinary impact the industry has on state, local and national economies. Here are five ways that happens:

Driving Economic Progress

The insurance industry is a major U.S. employer, providing some 2.6 million jobs, according to the Current Population Survey from the U.S. Department of Labor.

Insurers contribute more than $413 billion to the nation's gross domestic product.

In 2013, property/casualty insurers and life insurers incurred federal and foreign taxes of about $20.6 billion. Insurance companies, including life/health and property/casualty companies, paid $17.4 billion in premium taxes to the 50 states in 2013, or about 2% of all state taxes.

Investing in Capital Markets

Insurance companies also help support the economy by investing the funds they collect for providing insurance protection. The industry's financial assets were about $6 trillion in 2013, including $1.2 trillion for the property/casualty sector and $4.7 trillion for the life sector.

In 2013 alone, property/casualty insurers' holdings in municipal bonds totaled $326 billion, according to the Federal Reserve. Life insurers held $1.8 trillion in corporate stocks and $2.2 trillion in corporate and foreign bonds in 2013, according to the Federal Reserve.

Supporting Resiliency and Disaster Recovery

Property/casualty insurers covered $35 billion in catastrophe losses in the U.S. in 2012 and $12.9 billion in 2013, according to the Property Claim Services (PCS) division of Verisk.

Supporting Businesses, Workers, Communities

Property/casualty insurers pay out billions of dollars each year to settle claims.  Many of the payments go to local businesses, such as auto repair companies, enabling them to provide jobs and pay taxes that support the local economy.

Life insurance benefits and claims totaled $586 billion in 2013, including life insurance death benefits, annuity benefits, disability benefits and other payouts. The largest payout, $249 billion, was for surrender benefits and withdrawals from life insurance contracts made to policyholders who terminated their policies early or withdrew cash from their policies.

Empowering Lenders

Specialized insurance products protect lenders and borrowers, shielding businesses such as exporters from customer defaults and facilitating the financing of mortgages and other transactions. These products include credit insurance for short-term receivables.

Credit insurance protects merchants, exporters, manufacturers and other businesses from losses or damages resulting from the nonpayment of debts owed them for goods and services provided in the normal course of business. Credit insurance facilitates financing, enabling insured companies to get better credit terms from banks.

For the full report from which this article is adapted, click here. 

Modernization: CRO Faces New 'Unknowns'

The chief risk officer has special challenges because the very nature of the function is changing.

Internal and external demands have resulted in the clarification and expansion of the role of the chief risk officer and the risk management function. Internally, senior management and the board see the merit of using key risk information. Ensuring the company is managed within its risk appetite enables it to best utilize its resources to take advantage of changing competitive needs and strategic opportunities. Externally, U.S. and global regulators are articulating clear expectations for the role of the CRO and governance of the risk function, as well as the role of the board in risk management and the CRO's and risk function’s relationship with the board. These demands emphasize the need for clear policies and processes with appropriate documentation and governance.

As little as 10 years ago, the risk function was novel at most companies, and there were almost as many models of how to organize and manage the function as there were insurers. This has changed. Leading practice is becoming clearer, and expectations are now more consistent and defined. However, boards and regulators are increasingly inquiring about new "unknowns": data security, cyber terrorism, reputational risk and competitive obsolescence. All of these also fall under the CRO's purview and increase demands on risk resources.

The case for change

The risk function is the newest among the direct stakeholders that insurance modernization directly affects, and there are a number of important implications and outcomes.

  • No existing "pipes" - For the majority of North American risk functions, many risk calculations and resulting reports are very recent creations. Very few have a solid network of pipes that transmit data and input through models and calculations onward to result in verifiable and controlled information. Therefore, compared with many other functions that modernization affects, the risk function does not need to dismantle existing pipes. However, it is critically important that, as insurers plan and develop these new pipes, they do so in cooperation with other stakeholders. If they do not, then the risk function may find itself unnecessarily tearing up what should be a common roadway.
  • From build to oversee - While internal and external changes affect all stakeholders, the risk function is unique in that its very nature also is changing. When the risk function originally came into being, it was the CRO's and his staff's responsibility to create the models and capability needed to support the function. Now, as risk infrastructure takes shape, management, boards and other stakeholders are asking the CRO and risk function to play a key role in governance and control. This brings into question how best to manage and oversee both the risk and overall corporate infrastructure. Can and should these be responsibilities of the risk function, and, if not, who should be responsible for managing this infrastructure?
  • Process and documentation - Much of the newly built infrastructure was constructed quickly and in a "learn by doing" mode. Much of it is parallel to but not coordinated with activity in other areas, especially actuarial. As companies have mapped processes and documented assumptions, models and output, functional overlaps have become clearer. In many cases, clarification and resolution of the overlaps will be necessary to enable rational enterprise level mapping and non-duplicative documentation.
  • Demonstrated engagement – The CRO and risk management staff (with input from actuarial, investment, finance and others) support the foundation on which risk information is built Increasingly, the board and regulators are asking for holistic engagement in agreeing on assumptions and methodologies, not just siloed input from subject-matter experts. The risk function increasingly is being asked: Are the business managers – the first line of defense –in agreement? And, is their collective engagement substantive and verifiable?
  • Governance - As the board's role in risk management and risk taking becomes clearer, many boards and regulators recognize the need to include major risk and strategic initiatives under the oversight umbrella. They look to the CRO to be the conduit of information between them and the insurer. This strongly suggests that the CRO should have insight into modernization initiatives that go beyond just the risk function.

In a modernized company, a synergy of efficient processes with clearly defined stakeholder expectations exists among risk, actuarial, finance and technology (RAFT). The modernized risk function will share a common foundation of data, methods and assumptions and tools and technology with the other RAFT functions. (Naturally, the risk function will have certain unique processes that build on this foundation.) Finally, enterprise compatible business management, HR, reporting and governance all channel the process to its apex: intelligent decision making.

  • Data - The organization, with significant risk input, clearly defines its data strategy via integrated information from commonly recognized sources. The goal of this strategy is information that users can extract and manipulate with minimal manual intervention at a sufficient level of detail to allow for on-demand analysis.
  • Methods and analysis - Modern risk organizations emphasize robust methods and analysis, particularly the utilization of different approaches to arrive at insight from more than one perspective. Key to proper utilization of multiple methods is confidence that different outcomes are not the result of inconsistent inputs but rather truly reflect new insight.
  • Tools and technology - Up-to-date tools and technology help the risk function gather, analyze and share information faster, more accurately and more transparently than ad hoc end-user computing analysis. With modern tools and technology, risk personnel can devote the majority of their time to understanding and managing risk rather than programming and running risk models.
  • Stress testing - Stress testing has become a key weapon in the risk management arsenal. Test results convey risk information to senior management, the board and regulators. Resulting impacts on capital under stress scenarios become key to capital planning and calibrating economic capital (EC) models. Moreover, these tests are fully integrated in financial planning and the finance function's agenda.
  • EC/Capital modeling - Economic capital calculations continue to be an important tool for decisions at all levels, from strategic to micro-level asset trading and product design. A modernized organization fully integrates these models with key actuarial activities, and the process and results help the company more effectively plan for and manage risk. Results are available quickly, and efficiency of the process allows for extensive "what if" testing.
  • Validation - A comprehensive model risk management structure is in place. The company routinely validates new models and model changes. Assumption consistency is transparent across risk, actuarial and finance. The company verifies data integrity and uses a model inventory to weed out duplication and overlap. Savings more than pay for model risk management (MRM) costs.
  • Human capital - Risk functions employ more inquisitive and analytical analysts. The emphasis is on managing risk, not running models. A significant portion of the group devotes its time to understanding emerging trends and investigating potential new threats to the organization. Clear organizational design facilitates working in a collaborative manner with other control functions and business managers.
  • Governance - Risk plays a key role in governance and risk appetite is well established. Decision making throughout the organization incorporates risk in a transparent manner. This is in large part because of confidence in risk output because data and input is consistent with finance and actuarial analytics, models are validated and senior management and the board understand key assumptions and limitations.

The benefits

Realizing ERM's promise requires more than just complex economic capital and value at risk (VAR) models. It requires confidence in these models and an understanding of their key assumptions and limitations. This confidence and understanding need to be pervasive - from risk, finance and actuarial personnel themselves, through line of business leadership, up to senior management and the board.

With a modernized platform in place, CROs and risk functions can turn their attention to managing risk, not calculating and reconciling numbers, as well as providing management and board with the best tools for intelligent decision making, confidence in capital deployment and competitive strategies consistent with risk appetite and capacity.

Critical success factors

Plan ahead and in concert with other stakeholders. The risk function is in the unique position of not having to dismantle infrastructure, but it definitely does need to build on it. The function's relative youth and lack of legacy encumbrances mean it is in an ideal position to be a leader in modernization initiatives.

Moreover, the risk function has both an opportunity and an obligation to raise concerns about the risks involved in modernizing in an uncoordinated way or the risk to the insurer's competitiveness from not modernizing at all.

Call to action - Next steps

Look for quick wins, like faster processing, more transparency, deeper insight, but stay true to the long-term plan. Some of these quick wins can be cost savings opportunities. For example, an inventory of documented models can reduce the number of models (and associated maintenance cost) by weeding out redundancies. In addition, the company can streamline internal reports when all areas use the same foundational data and calculations. Moreover, the company may be able to rationalize multi-jurisdictional, external and regulatory reporting.


Henry Essert

Profile picture for user HenryEssert

Henry Essert

Henry Essert serves as managing director at PWC in New York. He spent the bulk of his career working for Marsh & McLennan. He served as the managing director from 1988-2000 and as president and CEO, MMC Enterprise Risk Consulting, from 2000-2003. Essert also has experience working with Ernst & Young, as well as MetLife.

Checklist to Prepare for Business Interruption

Seven actions will not only help with your next loss but can have an immediate benefit to your risk management.

|

Business interruption (BI) losses are among the most confusing types of claims in the insurance industry. As claim specialists, we are often asked for a "checklist" filled with action items for when a loss occurs. A "checklist" isn't practical because there are too many variables and "if/then" scenarios to map out. When you have a significant property damage and business interruption claim, only experience can guide the way to a fair recovery.

However, there are actions that can be taken ahead of a loss to ensure you are prepared. The following seven items represent such a "checklist." It will not only help with your next loss but can have an immediate benefit to your risk management program.

1. Prepare accurate ratable business interruption values

The annual ritual of preparing the business interruption worksheet is often treated as an administrative nuisance.  It should be looked at as an opportunity to accurately account for the insurable risk for which you pay your premium and to accumulate annual values for future trending.

The worksheet provided by the insurance company is woefully inadequate to explain the nuances of most businesses. Go beyond the worksheet and explain your business more completely to underwriters. For an effective BI values methodology, solicit help from the specialists, such as an experienced forensic accountant. The results will be appreciated by underwriters and should translate into more appropriate coverage and possibly a more favorable rate. Once a system is in place, accuracy, consistency and efficiency should be improved.

2.    Analyze exposure scenarios and calculate MFL and PML

Once the ratable BI values are calculated, policyholders should explore realistic loss scenarios. The BI value is an annual number that does not factor in real-life responses that would generally mitigate a claim. To get to the actual exposure to risk, companies should determine the maximum foreseeable loss (MFL) and probable maximum loss (PML) measurements. The MFL measures a "worst case scenario" in which all of the loss-control protections fail. The PML is the more realistic loss scenario, in which mitigation systems work and contingency plans are executed properly. In both cases, the property damage and business interruption effects would be calculated as if they had occurred.

Loss scenarios should be postulated in detail, e.g. by location and by occurrence, considering all factors. These numbers should not be measured by simply applying a daily "BI rate" to an engineered loss period. It is more realistic to prepare as if presenting a claim, exploring all "what if" possibilities. Insurers may offer some assistance in this process, but remember, their version will be from their perspective. As with any claim, you should always prepare your own scenarios and your own calculations according to your understanding of your operations. An independent forensic accountant will have prepared claims just like your scenarios and would be able to accurately value the losses.

3.   Analyze contingent risks

Concurrent with the MFL and PML analysis, you should work to understand contingent risks to your business. Knowing what your suppliers' and customers' exposures are is important. Policyholders should involve leaders in operations, procurement and sales to help identify contingent exposures. If you have a sole supplier, your contingent exposure may be greater than anticipated and should be examined.

It is important to understand how your current policy language would respond to the contingent loss scenarios you've identified. For example, if suppliers in your policy are referred to as direct supplier," make sure you understand how this would be interpreted in a claim. If "direct" means only those suppliers with whom you have a direct contract, and an indirect supplier, i.e. a second-tier supplier, has a loss that affects you, would you be covered? These scenarios should be discussed with your broker and underwriter to ensure your policy will respond as expected.

Once the values and scenarios are updated, you will be better able to make informed decisions about your insurance coverage, limits and terms.

4.    Business interruption vs. extra expense

Another common discovery from performing an exposure analysis is which type of time element coverage is the best risk transfer solution. Considering each location, if the risk is a lost of sales, BI would cover the lost earnings. If sales are not the risk or they can be sustained at an extra expense, extra expense coverage would be more appropriate. If sales are at risk but can be mitigated to the degree contingency measures are enacted at an additional expense, it's a combination loss exposure.

It's of value to risk managers to know what the exposure truly is because, if an exposure can be covered by extra expense coverage, it may eliminate or reduce the need for BI insurance. For example, if you are a distributor with multiple warehouses whose inventory is insured at selling price, what's at risk? If you have alternative space or can quickly secure temporary space, the likelihood of experiencing a sales loss that exceeds the sales value of your lost inventory is remote. How much BI coverage should you buy vs. extra expense? Exploring your loss scenarios and subsequent contingency plans would allow you to better quantify your risks and select the option best suited to your needs. Extra expense is a more "tangible" risk than BI, making it easier for underwriters to rate, and it generally will cost less.

5.   Gross earnings, gross profit and business income

The names are different, but the intent is the same - to protect earnings lost because of damage or loss of use of insured property. The history of each of these forms would take a separate paper to detail, but, in a nutshell, gross earnings is a form commonly used in the U.S. with a basis in manufacturing risks, while gross profit is used throughout the world and has its basis in mercantile operations. Business income is the term used for the current ISO forms. Today, all forms have been modified to accommodate almost any business -- however, there are some situations where one form may be preferable. The terminology and the mechanics of calculating business interruption loss varies among the forms, but the answer should be the same, regardless.

The exception to this has to do with the period of indemnity -- the gross profit form is usually limited to a specific time, while gross earnings will continue until repairs are (or should be) completed with "due diligence and dispatch"; there is the ability to add an extended period to recover sales. It is important to make sure the form you have would cover your potential loss period. For example, if you have a manufacturing company with specialized production equipment that have long lead times to replace -- longer than the period that a gross profit form would cover -- you should probably have a gross earnings form. If you do not see a scenario that would exceed the gross profit period and you cannot accurately predict an extended period required to add to gross earnings, the gross profit might be a better option. If there isn't any scenario that would create a loss that exceeds the gross profit period of indemnity and you are comfortable that you can cover that time to recover sales, than either form would work. There are new options that allow you to pick which form you would like to use up until the closure of a claim -- these forms eliminate the need to determine which form is right for your business. Just make sure you have a form that will cover your worst-case scenario.

6.   Professional fees coverage

Most policies now include professional fees coverage. Insurers recognize the need for dedicated claim preparation experts and are willing to pay for it as part of the claim. Often, this coverage is subject to limits that can be negotiated. If you are not familiar with this coverage or do not have it, you should discuss with underwriters. For the most part, this coverage can be included at some level just by asking. The benefits of having specialized claim preparation experts available as a resource for a claim can make the difference between a successful claim and a headache.

7.  Organize your claim team

In addition to forensic accountants, a claim may include forensic engineers, attorneys and others. It is a good idea to know those you want to use before needing their services. Meet with the various providers beforehand and select those that fit best for your organization. Typically, paperwork associated with hiring someone can be completed before needing their assistance (i.e. non-disclosure, purchasing, W-9, etc.) so that if something happens they can begin work immediately. Additionally, there may be an opportunity for the provider to help with reporting issues on business interruption values.

While no business wants to suffer a loss of earnings, the more prepared you are the better the results will be. The steps shown above may take years to fully develop and should be evaluated annually to account for changes to your business.

If these recommendations are incorporated into your insurance program, there's no need for a claim checklist. Your risk management team will be prepared for any worst-case situations with the best-case solutions.

How to Boost Loyalty in Auto Insurance

Many think the key to customer retention is customer satisfaction. That's wrong. Lots of satisfied customers still switch carriers.

In any industry, customer loyalty is a precious commodity. That’s no less true in the world of auto insurance. As Bain puts it: "Loyalty improves a carrier's economics and leads to sustained, above-market growth."

But what does it take to make customers stay with an auto insurer for the long term?

Customer retention isn't just customer satisfaction.

When customers choose to stick around because of the benefits an insurer provides, their actions are driven by positive experience. You could say, then, that the key to customer retention is customer satisfaction.

You'd be mistaken. A new survey released by Accenture Global found that while 86% of insureds who filed a claim were satisfied with how it was handled, 41% of those customers are still likely to switch insurers in the next 12 months.

In fact, the data shows that the very act of filing a claim makes a customer more likely to switch insurers, even when they're completely satisfied with how it went.

It’s not to say customer satisfaction in the claims process doesn't matter - speed and transparency being the two most important factors, according to 94% of Accenture survey respondents. Having access to digital channels also ranks high in satisfaction requirements.

However, if having a claim tends to trigger the insurance shopping process, the most important question may be how to prevent the claim altogether.

Use UBI as a tool to prevent claims and build the relationship.

By harnessing usage-based insurance data, insurers can define strategies to help customers manage risks and even reduce the number of claims they file. As a result, insurers not only lower claims costs, but may gain an advantage in customer loyalty, Bain says.

However, usage-based insurance isn't just about data collection. It offers insurers the opportunity to go far beyond information gathering, and to nurture the relationship. UBI provides a chance to communicate with customers every time they drive, in a constructive manner. UBI is the ultimate digital connection - not hinging on potentially negative touch points like claims or billing, but rather facilitating quality, helpful coaching.

And here's the great thing: The relationship-nurturing capabilities start immediately. Insurers can provide helpful driving tips as soon as UBI policyholders install the app and take their first trips. Insurers don't have to wait for data, actuaries and new rating tables. They have an instantaneous ability to provide coaching and thereby start a new kind of insurance relationship.

They say that when you teach a man to fish, you feed him for a lifetime. What happens when you teach a man, or a woman or their teenagers to drive more safely and avoid the pain of accidents? They appreciate it and remember it. And, greater loyalty, retention and referrals just might ensue.

Click here to learn how usage-based insurance works for insurers.

Will 2015 Top 2014 in Security Exposures?

It might. The pace of data theft and identity loss certainly hasn't slowed since last year. But a series of precautions can reduce your risk.

It's hard to imagine how 2014 could be surpassed as the worst year for massive identity theft and data loss exposures.

The news developments of 2014 were relentless and mind-numbing. Heartbleed and Shellshock rose to the fore as two of the nastiest Internet-wide vulnerabilities ever to come to light. Heartbleed exposes the OpenSSL protocols widely used by website shopping carts. And Shellshock enables a hacker to take control of the module used to type text-based commands on Linux, Unix and Mac servers.

"These are problems in the very fabric of what the Internet is built on," says David Holmes, security evangelist at F5 Networks.

Click here to receive fresh analysis of breaking developments from top cybersecurity and privacy experts.

Meanwhile, Target, Nieman Marcus, Dairy Queen, Home Depot, JP Morgan and SonyPictures led a parade of organizations disclosing major data breaches. Indeed, the tally of data breaches made public in the U.S. hit a record 783 in 2014, nearly 30% higher than in 2013, according to the the Identity Theft Resource Center.

"The ubiquitous nature of data breaches has left some consumers and businesses in a state of fatigue and denial about the serious nature of this issue," says Eva Velasquez, chief executive offer of the ITRC.

The scary part

Now here's the scary part: The pace hasn't slowed in the first few weeks of 2015.

Consider that the financial services sector has spent billions over the past decade on the best defensive technologies and systems money can buy. Yet a low-level Morgan Stanley financial adviser was able to exfiltrate account records, including passwords, for six million of the Wall Street giant’s clients.

Meanwhile, forensic analysts at Dell SecureWorks recently uncovered a novel strain of malware circulating deep inside a corporate network. It's being referred to as a "skeleton key." With a skeleton key an intruder can fool the authentication protocols on widely used Microsoft Active Directory systems by typing arbitrary passwords. This enables the attacker to do such things as gain unfettered access to webmail and virtual private networks (VPNs).

"It's much easier to be an attacker than a defender," observes Jeff Williams, director of security strategy for Dell SecureWorks' Counter Threats Unit. "As a defender, you must protect all paths of access, whereas the attacker only needs to find one foothold from which to mount an intrusion."

If nothing else, the headlines of 2014 should grab the attention of company owners, directors and senior executives. No one wants to make it to the ITRC's list of U.S. breaches for 2015.

SMBs exposed

But small and medium-sized businesses (SMBs) should pay heed as well, says William Klusovsky, a security specialist at NTT Com Security. SMBs should grasp that they are part of a wider supply chain and that modern day cybercriminals are intensively hunting for all weak links, he says.

Small business owners should "understand your businesses processes, be aware of your risk profiles and be able to explain that to your partners," Klusovsky advises. "And then within reason implement the protections you can afford."

A good place to start, for companies of any size, is to step into an attacker's shoes, Dell SecureWorks' Williams says. "Identify paths of entry and put mitigations in place, whether that be two-factor authentication, removing unneeded services, implementing, monitoring or training staff," Williams says.

Security consultants can be valuable guides, and third-party managed services can do the day-to-day heavy lifting. But the due diligence must come from the business owner.

The business owner should plan to "remain engaged and active in the conversations with that security service provider," Williams says.

Over time, all business owners need to develop some level of skill about security policies and procedures and look to infuse that knowledge into the company's infrastructure.

See more at Third Certainty

How Google Is Wrong About the Internet

Even very smart people in very serious settings consistently make two mistakes that lead them to just assume a sort of technological utopia.

sixthings

Eric Schmidt, the executive chairman of Google, said this week that the Internet will disappear -- "There will be so many IP addresses, so many devices, sensors, things that you are wearing, things that you are interacting with, that you won’t even sense it," he said. Now, Eric is a very smart fellow; he's worth several billion dollars more than I am (the score is Schmidt, $8.3 billion, me, $0 billion); and he even has a better hairline than I do despite being two years older. He made his comments in Davos at the World Economic Forum, known as the gathering spot for very serious people. So his remarks have been getting quite a bit of attention and consideration. 

But he's wrong.

He's wrong for the same reason that people have been wrong since I started covering technology for the Wall Street Journal going on 30 years ago. That suggests to me that people will keep being wrong for the same reasons for some time to come, including in the world of insurance, where we are all having to try to figure out how the Internet of Things will play out. So let me point out the two issues that mean that even very smart people in very serious settings can't just assume the sort of technological utopia that Schmidt is describing.

They are:

  • Decision rights
  • Transaction costs

Let's look at those issues in the context of an article in the New York Times many years ago that got me mad enough to start thinking about the blind spot in the first place. A very bright reporter, and something of a friend, began by painting an idyllic vision of an automated future: A person hopping out of bed would step on a sensing device that would let the house know he was up. The house would then turn on CNN in the family room, start the coffee and probably do some other things that I no longer remember at this remove.

Nice image, right?

Decision rights

But what if I don't want to watch CNN? What if I'm more interested in watching ESPN that morning? Or my kids were already awake and watching cartoons -- would my stepping on the pad change the channel despite the screams that would surely result? What if I'm heading off to meet someone for breakfast and will have coffee there, not at home that day?

A key question with any sort of automation is: Who owns the decision rights? In the case of CNN and the coffee, do I want the house to have the decision rights, or do I want to retain them?

Transaction costs

How much effort do I have to put into the automation? Is it really worth it to put a sensor under my carpet or even to lay something on top of the carpet? What does that cost? How long does it take me to configure the TV and other systems in the house so that they react appropriately?

Those transaction costs then have to be compared against the benefits, which, in the case of CNN and the coffee, are trivial. It's just not that hard to pick up the remote and click the TV on or to fix the coffee in the morning (which you would have had to do before going to bed in the automated scenario.)

People tend to get so excited about the George Jetson-like possibilities that they ignore decision rights and transaction costs and paint visions that simply won't occur in any reasonable timeframe.

That's how we ended up with:

-- The talk back in the early '90s about "agents" that would pull together what some called "The Daily Me," a personalized newspaper that would gather all the news that it knew you were interested in and mix it in with your schedule and other things to lay out your day for you. The problem was that these personalized papers took a huge amount of effort and were so inaccurate that no one would turn all the decision rights over to an agent. What if you didn't have time to read the news that day? What if you had become interested in some topic that you'd never read about before -- how would your agent know?

(I took the talk of agents somewhat personally because the three pieces I wrote for the Wall Street Journal that easily got the most response from readers in my 17 years there were about: a time I sailed across the Atlantic in a small boat, having never sailed before, in what turned out to be some monster storms; my two-week career as a professional wrestler; and my mother (a piece written with my younger brother). I guarantee you that no one who picked up the Wall Street Journal the day those pieces appeared was looking for anything about sailing, professional wrestling, my mother or me, so no one would have ever seen them in a world of agents.)

This talk of agents is cropping up again, by the way, and is surely part of the reason that Schmidt wants to talk about having the Internet disappear. Google wants to make search so efficient that its engine knows what you want to find even before you think to look. The company has made impressive strides -- if you type in Elm Street while looking for directions on your Android phone, Google Maps usually guesses quickly and correctly which Elm Street you want -- but that's a long way from the world that Google is describing, and the transaction-cost and decision-rights issues will still get in the way.

-- The fuss over the "Internet refrigerator" that still crops up from time to time. The idea is that your refrigerator would sense when, say, you were low on milk and reorder it for you. But that requires an awful lot of engineering, both in the refrigerator and in whatever system of grocery delivery would be used, and only makes sense if you're turning just about all your shopping over to your refrigerator -- if you have to go to store anyway, it's simple to grab some milk.

And there is always the issue of decision rights. What if a family goes on vacation? How long will the refrigerator keep ordering? I have a friend whose 21-year-old son drinks a gallon of whole milk a day. When the son -- who is 6'5", weighs 285 pounds and looks like he could bench press a cow -- is home, they can't buy milk fast enough, but when he's gone at school they don't need any. Do they have to let a few gallons of milk sour before the refrigerator figures out the son is gone?

-- The excitement about home controls: remote-controlled lighting, the Internet thermostat that will sense who's in a room and adjust lighting levels and temperature to personal preferences and so on. Those are just an awful lot of work for not much benefit -- you can always flip a light switch or adjust a rheostat -- and doesn't resolve the issues that come up when one person likes a room cooler than the other.

Technology will make plenty of tasks disappear, but let's not be too hasty. We need to think through the costs, the benefits and the potential for errors and conflicts in automated systems, to make sure we don't fall victim to the seductive tendency to ignore transaction costs and decision rights.

The Internet won't disappear in my lifetime, which I'm assuming will be at least 30 more years. I won't even have sensors that turn on CNN and start my coffee when I get out of bed.


Paul Carroll

Profile picture for user PaulCarroll

Paul Carroll

Paul Carroll is the editor-in-chief of Insurance Thought Leadership.

He is also co-author of A Brief History of a Perfect Future: Inventing the Future We Can Proudly Leave Our Kids by 2050 and Billion Dollar Lessons: What You Can Learn From the Most Inexcusable Business Failures of the Last 25 Years and the author of a best-seller on IBM, published in 1993.

Carroll spent 17 years at the Wall Street Journal as an editor and reporter; he was nominated twice for the Pulitzer Prize. He later was a finalist for a National Magazine Award.