Rule
Rule - Risk Management for Insurers (March 2015)
Status not confirmedView on CIMA's website Source document
Summary
This is a binding CIMA Rule, issued under section 34 of the Monetary Authority Law, setting out minimum risk management requirements for insurers licensed under the Insurance Law. It applies to all insurers regulated by CIMA and should be read alongside related CIMA guidance on internal controls, asset management and investment strategy, corporate governance, and reinsurance arrangements.
The Rule requires every insurer to establish, implement and maintain a documented risk management framework capable of identifying, measuring, assessing, reporting, monitoring and controlling all material risks, including credit, underwriting/reinsurance, investment, market/liquidity, strategic, concentration, compliance, financial crime, and operational risks (including outsourcing and business continuity).
- Proportionality: The framework must be proportionate to the insurer's size, complexity and risk profile.
- Board-approved strategy: It must include a Board-approved risk management strategy.
- Risk tolerances: It must include defined risk tolerances and appetite.
- Escalation process: It must include an escalation and feedback process.
- Independent review: It must be subject to independent review, e.g. internal or external audit, actuarial or compliance functions.
Governance expectations
- Board oversight: The Board must approve, oversee and periodically review the framework and set business objectives consistent with the risk appetite.
- Group-wide application: Insurance groups must apply governance and risk management on both a legal-entity and group-wide basis.
- Staff training: Staff must be trained on risk policies regularly.
- Outsourcing oversight: Outsourced functions (internal or external) must be overseen, and outsourcing providers approved by the Board or senior management.
- Capital linkage: Risk management must be linked to capital management.
Captive insurers that rely on a parent's risk management function are not expected to duplicate it, but must document an appropriately scaled risk management function. Breaches are addressed through CIMA's Enforcement Manual and powers under the Insurance Law and MAL.
Key obligations
- Establish, implement, and maintain a documented risk management framework capable of identifying, measuring, assessing, reporting, monitoring and controlling all material risks in a timely manner, proportionate to the insurer's size, complexity and risk exposures.
- Include in the framework a written, Board-approved risk management strategy addressing all material risks, adequate risk management policies and procedures, and clearly identified managerial responsibilities and controls.
- Address measurement, monitoring and control of specified risk categories including credit, underwriting/reinsurance, investment, market/liquidity, strategic, concentration, compliance, money laundering/terrorist financing/fraud, and operational risk.
- Document the approach and key assumptions used in measuring risks, including risks covered.
- Define, via the Board, an appropriate risk tolerance/appetite and limits for material risk sources, considering relationships between risk sources.
- Board must adopt a written process for setting, approving and overseeing business objectives and risk strategies, consistent with fair treatment of customers and long-term financial soundness.
- Ensure business objectives and risk strategies align with approved risk appetite and tolerance levels.
- Regularly review the market environment and take appropriate action to manage adverse impacts on the business.
- Conduct quantitative and qualitative analyses (stress tests and scenario analysis) as appropriate to size and complexity.
- Implement and communicate an escalation process for reporting risk issues within and outside normal reporting cycles.
- Include a feedback loop enabling the Board and senior management to act on changes in risk profile and monitor effects of their decisions.
- Board must approve the risk management framework, provide oversight of its implementation, and periodically review it.
- For insurers in a group structure, ensure appropriate governance, internal controls and risk management at both legal entity and group-wide levels, and ensure timely dissemination of material information.
- Ensure risk policies and procedures are communicated to senior management and key personnel, and that relevant staff receive regular training.
- Subject the risk management framework to effective, comprehensive review by an independent function (e.g. internal audit, external audit, insurance manager, actuarial, compliance), with such functions having access and reporting lines to the Board.
- Maintain oversight and clear accountability for outsourced functions (internal or external) as if performed internally, subject to normal internal control standards and periodic review.
- Ensure outsourcing providers are approved by the Board or senior management.
- Describe in the risk management policy how risk management links to capital management (regulatory and economic capital).
- For captive insurers relying on a parent's risk management function, the Board should consider and document a risk management function appropriate to the nature, scale and complexity of the business.
Applies to
insurers regulated by the Authority under the Insurance Law, insurance groups, captive insurers