Although the insurance industry is less affected than the banking industry, the credit crisis has revealed room for improvement in its risk management and supervision. Based on this observation, we formulate ten consequences for risk management and insurance regulation. Many of these reflect current discussions in academia and practice, but we also add a number of new ideas that have not yet been the focus of discussion. Among these are specific aspects of agency and portfolio theory, a concept for a controlled run-off for insolvent insurers, new principles in stress testing, improved communication aspects, market discipline, and accountability. Another contribution of this paper is to embed the current practitioners’ discussion in the recent academic literature, for example, with regard to the regulation of financial conglomerates.


In this paper, we address the credit crisis from the perspective of the insurance industry. Our aim is to highlight the impact the crisis had on insurance companies and to derive consequences for risk management and insurance regulation. The prudent and conservative business policies that most insurers engage in have proven the industry to be quite resistant throughout the crisis. However, not all insurance market participants have followed such a prudent strategy (e.g., American International Group (AIG) or Yamato Life). Hence, the crisis has revealed several deficiencies in the fields of risk management and supervision.

Based on these observations, the aim of this paper is to formulate ten consequences for risk management and supervision. Many of these consequences reflect current discussions in academia1 and practice,2 but we also integrate a number of new ideas that have not yet been the focus of discussion regarding the credit crisis. Among these are some basic lessons from agency theory and portfolio theory, the consideration of a controlled run-off for insolvent insurers, new principles in stress testing, and improving communication, as well as aspects of market discipline, and accountability—especially in respect to rating agencies. Another contribution of this paper is to embed practitioners’ discussion in academic literature, for example, with regard to management compensation or the regulation of financial conglomerates.

Although it might be too early to draw conclusions about the credit crisis, a discussion of potential consequences can be helpful in the political decision-making process. This process is on the agenda and it might not be there by the time scholars have collected empirical evidence on its different aspects. Beyond this background, however, we should highlight the consequences for which we have sufficient evidence and where we see a need for future research. Most consequences we discuss are applicable not only to insurance, but also to other sectors of the financial services market. We think that one of the most fundamental lessons from the crisis is that financial services should take place in an integrated marketplace that combines integrated risk management and supervision. The separate regulation of banking, insurance, and other financial services can create options for regulatory arbitrage, which was one of the roots of the crisis.

The remainder of this paper is structured as follows. In the next section, we present a short overview of the emergence of the crisis and its impact on insurance companies. In the subsequent section, consequences for future risk management and supervision of insurance companies are derived. We conclude in the final section with a summary of the policy recommendations.

Impact of the credit crisis on insurance companies

Owing to differences in business models, insurance companies are less affected by the credit crisis than the banking industry is. Insurance companies are generally not at risk of a bank run given that, for example, in non-life insurance, payments are linked to claim events. In addition, insurers are funded in advance. In life insurance, surrendering a contract has disadvantages such as lapse costs, so that the policyholder has a limited incentive to terminate the contract. Furthermore, many insurers, especially those from continental Europe, do not have significant exposure to mortgage-backed securities (MBS) and other forms of securitization and thus have not been directly affected by the credit crunch that was at the root of the current financial crisis.3 Underwriting risk comprises a high proportion of an insurer's overall risk. The liability portfolio is diversified and, in many lines of business, is largely uncorrelated with the asset side (and, hence, to the capital market in general). Again, this is an important difference from the banking industry, where the portfolio of outstanding loans is highly correlated with general economic factors.4

Nevertheless, the insurance industry has suffered substantially in the recent crisis, on both the asset and the liability side. Insurers are among the largest institutional investors on the capital market and thus negative development regarding asset value is almost unavoidable. On the liability side, insurers can be affected through insurance in the credit market, by directors and officers (D&O) as well as errors and omissions insurance, or by a reinsurers’ default. Furthermore, in a situation of economic downturn, insurers will suffer a decline in demand for insurance products.5

Figure 1 shows the Dow Jones 30 index for the years 2005–2009, along with some of the most frequently mentioned events of the financial crisis. The lower part of the figure emphasizes events affecting the insurance industry. Here we divide the financial crises into four phases. The first phase was a time of low interest rates and increasing U.S. housing prices (reaching its maximum in 2005). Warning signs then appeared in Phase 2 (2006 until August 2007), for example, with a flat and then inverse yield curve. The subprime crisis in U.S. housing then started in the summer of 2007.6 One of the first visible events in respect to the financial crisis was the bank run on Northern Rock in September 2007 and the consequent support from the Bank of England (beginning of Phase 3). At that time, many market participants in the banking and insurance industry reported large write-downs due to mortgage defaults or related problems in credit markets. Among these were Merrill Lynch, Citigroup, and Swiss Re (Swiss Re is only one of many insurers to suffer write-downs, but it was the first large write-down in the insurance sector and is thus mentioned). Then the fourth phase of “big hits” and government bailouts began in September 2008 with the federal takeover of Fannie Mae and Freddie Mac, the bankruptcy of Lehman Brothers, and Federal Reserve support of the AIG. Merrill Lynch was sold to the Bank of America and Morgan Stanley as well as Goldman Sachs changed their status from investment banks to traditional bank holding companies. Among the subsequent events were the Royal Bank of Scotland announcing the biggest corporate losses in U.K. history (January 2009) and AIG reporting the biggest corporate losses in U.S. history (March 2009).
Figure 1

Dow Jones 30 index and main events of the financial crisis.

The three most often reported events of the crisis for the insurance industry are the government bailout of the AIG, the write-downs at Swiss Re (due to reinsurance in credit portfolios), and the insolvency of Yamato Life Insurance (due to severe risk management failures in asset management). All three events have different characteristics and illustrate that insurers’ balance sheets were affected by different aspects of the crisis. These cases thus show that an adverse scenario can include a combination of negative developments on both the asset side and the liability side. But the different nature of these three events also reveals that they had only a limited systematic impact at the global industry level. Only some insurers were directly affected from investments in structured credit products, but most felt an indirect impact from the losses in many investments during the recent capital market plunge. That these effects on asset management can produce a threatening economic situation is illustrated by the Japanese life insurer Yamato Life Insurance. This company experienced losses in the subprime area, and losses due to a high investment in stocks. From the underwriting side, however, no specific problems have been reported.

One advantage of the continental European insurance industry in this context is that traditionally its asset allocation is conservative and it invests a relatively low portion of assets in stocks. Therefore, these insurers were not too adversely affected by the 2008 stock market plunge. It appears that insurers had learned a valuable lesson from their bad experience with the stock market plunge at the beginning of this century. However, a main difference between the current capital market plunge and other stock market plunges, especially in 2002, is that in the current crisis there are adverse reactions in bond markets and a massive increase in credit risk for products and institutions that had previously been considered safe. An example is the default of Lehman Brothers, in which a number of insurers were deeply involved (e.g., the German health insurer Landeskrankenhilfe, with an asset volume of around €4 billion, had invested €200 million at Lehman Brothers).7 Some insurers (e.g., the U.S.-based Aflac) were also engaged in hybrid capital and other subordinate debt issued by banks, resulting in large write-downs.8

The liability side of the insurance industry has also been affected by the crises, but less severely, with effects largely dependent on the insurer's line of business. If insurers are engaged in credit markets they could suffer a negative impact due to the increase in credit risk, which is what happened at Swiss Re with a depreciation of US$ 1.1 billion in November 2007. The loss resulted from two credit-default swaps (CDS) designed to provide protection for a client against a fall in the value of an MBS portfolio.9 Insurance companies such as AIG, MBIA, and Ambac first suffered ratings downgrades when mortgage defaults increased their potential exposure to CDS losses. AIG had CDSs insuring US$ 440 billion of MBS.10 Thus, following the subprime crisis, AIG had depreciations of US$ 11 billion on its credit portfolio in the fourth quarter of 2008 and a quarterly loss of US$ 5.3 billion, finally resulting in the government bailout.11 In addition to these impacts on the insurance and reinsurance sector, there are also worries with D&O insurance. Many U.S. insurers have already begun to set up reserves for potential claims following the crisis.12 Another aspect that is especially relevant for life insurers is that the uncertainty surrounding the macroeconomic environment and interest rates poses difficulties for providing investment guarantees and hence may lead to the necessity of redesigning life insurance products.13

Ten consequences for risk management and supervision

While insurance regulation has already been the subject of reform in Europe (Solvency II, Swiss Solvency Test (SST)) the ongoing financial market crisis has focused even more attention on risk management and regulation in financial services, both in academia and practice. Issues related to supervision and corporate governance have often been deemed causes of the crisis. These issues include pro-cyclicality and similar behaviour due to regulatory rules, regulatory arbitrage, inappropriate accounting rules based on historical acquisition costs, lack of transparency, and inadequate management decisions, probably driven by wrong incentives. While we might or might not be out of the crisis, there is a consensus in literature that the interaction of several deficiencies caused the crisis,14 making it impractical to single out individual culprits. We therefore believe that numerous consequences should be drawn from this crisis.

(1) We need to strengthen risk management and supervision

Identifying, measuring, and valuing risk is at the core of the insurer business model and should not be delegated to a third party. Although there is evidence that rating agencies are relatively successful in identifying financial distress compared to regulators,15 the financial crisis has made clear that relying heavily on ratings can be misleading and dangerous (see consequence 10 for more details on rating agencies). Insurers and regulators should thus be cautious to substitute their own due diligence by a rating, as rating agencies’ methodologies are not really transparent.16 In contrast to Solvency I, ratings are essential in the SST and under Solvency II, for example, for deriving the credit risk of the insurer's bond portfolio and for determining the default risk of reinsurance exposure, and regulators need to review these rules.17

In light of the challenging market environment, strong enterprise risk management is a crucial element in maintaining financial strength and ensuring a safe insurance industry. Risk management must be proactive, independent, and have sufficient power and authority. Independence is important because of possible conflicts of interest, including those between the underwriting sector, the sales department, and risk managers. It will also employ agency theory to hold risk managers accountable for the behaviour of insurers on behalf of potential crisis victims. Risk management must play a leading role in each insurance company, which could be accomplished by transferring the concept of “responsible actuary” (“verantwortlicher Aktuar”; implemented in Germany, Austria, and Switzerland) or “appointed actuary” (in the United Kingdom, Belgium, and the Netherlands)18 to that of an “appointed risk manager”. By law, the responsible actuary has a predefined function, responsibility, independence, and reporting requirements with regard to the board. The “appointed risk manager” could also be a contact person for the regulator in order to ensure that regulatory rules are embedded within an integrated risk management scheme.

Note that in some countries the function of risk management is one of the duties of the “appointed actuary”. In such a case, we either need to separate the tasks of the “appointed actuary” from those of the “appointed risk manager” or combine both jobs into one position enjoying greater power and authority. We believe that splitting this large and important task into two positions will work best: the “appointed actuary” being responsible for adequate premium and reserves calculation among others, and the “appointed risk manager” being responsible for an integrated risk management process at the company level, and implementing the results in an integrated risk management process.19 Clearly defined responsibilities, along with close collaboration between these two functions, are two important prerequisites.

(2) We need to take care of model risk and non-linearities

One of the greatest pitfalls of risk models and solvency approaches is model risk. For instance, there is always the possibility that the underlying risk distributions have been wrongly specified. This can occur when there is not a sufficient number of historical observations available (a smaller data set, ceteris paribus, increases the probability of a misspecification). Moreover, the underlying distribution might not be stable over time and, hence, probability distributions observable in the past provide very little information about the future. In addition to misspecifications as to the “true” probability distributions, the chosen stochastic model itself might be inappropriate.

To guard against too much faith being placed in a specific risk model/solvency approach and its assumptions, we believe that it is important to vary the implicit model parameters in a specified range, similar to what is done in stress testing. By doing this, risk managers and regulators can obtain a much better understanding of the sensitivity of specific results of the solvency model and provide additional information regarding an insurer's main sources of risk. A first step in this direction—one that has less to do with model risk, and more to do with the economic environment—has been taken in the scenario testing concept given of the SST.

The results of risk models and the quality of decisions based thereon depend on an appropriate modelling of the stochastic behaviour of assets and liabilities. In this context, mapping non-linear dependencies is a point of concern.20 Many risk models such as the Basel II, Solvency II, and SST standard model still focus on linear correlation even though the literature suggests that solely considering linear correlation is inappropriate when modelling dependence structures between heavy-tailed and skewed risks, which are frequent in the insurance context.21 These risks are especially relevant in the case of extreme events such as the 11 September, 2001 terrorist attacks that resulted in large losses for insurance companies both from their underwriting business and the related capital market plunge.22 The financial crisis is another situation in which some insurers sustained losses from their investments (e.g., in MBS, as well as from insuring credit products such as collateralised debt obligations), which emphasizes the relevance of non-linear dependencies in the crisis. We thus believe that non-linear dependencies should not be neglected, especially in stress testing. Existing stress tests were not “stressful” enough to capture downside risks that were realized throughout the crisis, that is, the tests often were based on mild or even wrong assumptions.23

Regarding risk measures, different concepts used in risk management and regulation might be critically reviewed in the light of the crisis. For example, the expected shortfall concept used in the SST allows—in contrast to the value-at-risk approach used in Solvency II—to capture the extent of a shortfall. The advantage of value at risk is its easier implementation, as it does not require data to estimate the tail of a distribution, which at the same time constitutes its most serious drawback.24 Since the value at risk does not provide information about the severity of a default, it may be rather adequate from the shareholders’ perspective in the case of limited liability where losses are restricted to their initial contribution. However, the cost of insolvency is significant for policy-holders and will thus be of central concern for regulators.25

Another question in the modelling context is what risks should be considered. The most dangerous risks are the unforeseen risks. Typically, market, credit, and underwriting risk are modelled, but the credit crisis has shown that we do not have sufficiently good models to handle liquidity risk.26 Thus, we need to develop new models for liquidity risk management and we need to take into consideration new risk sources that have not yet been the focus of discussion. In addition, we need to remember that one of the main assumptions of many pricing and risk management models is a liquid market. If a liquid market does not exist (anymore), the use of such models is highly questionable. Another point that should be kept in mind is that mathematical models are typically not constructed to anticipate risk sources that are not, in some manner, foreshadowed in historical data. New risk sources can thus not be easily quantified by mathematical models. Regarding the risk management process, mathematical models can be helpful for analysing a loss exposure, but other techniques from the field of risk identification (such as questionnaires, inspections, check lists, among others27) are needed to identify the loss exposure. In this context, it is important to strengthen the risk perception of all stakeholders and to define a clear and simple process for communication of potential risks within the insurance company.

(3) We need easy to use and understandable risk management

The interaction between risk models, the risk management process, and managerial decisions can be improved. The best risk models are useless if the results are not understood by the people who make decisions. A serious problem in this context is the communication gap between risk managers and decision-makers on the executive board. Stulz describes how communication failures have played a key role in the crisis.28 Union de Banques Suisses (UBS), for example, published a report for its shareholders in which it discusses the causes of its subprime-related write-downs. In that report, they note that “… a number of attempts were made to present subprime or housing related exposures”. The reports did not, however, communicate an effective message for a number of reasons, in particular because the reports were overly complex, presented outdated data or were not made available to the right audience.

Risk managers and actuaries develop and implement risk models and it is likely that most of them are aware of the underlying assumptions and limitations of the model when interpreting its results. However, the executive board may not have the same degree of competence in this particular area or the time to develop it. Thus, they require easy to use and understandable statistics. However, due to the inherent problems of models as discussed above, regardless of how well presented, their results should not be the sole basis for management decisions. Model results are best employed as supporting, either for or against, different strategies. How the statistic output of a risk model is communicated to top management is crucial. Here, we believe that the communication skills of risk managers and actuaries can be improved, for example, by using more intuitive forms of communication, such as graphs and diagrams, instead of long lists of numbers and complicated tables and equations. However, management also needs to be a little more flexible in its decision-making process, looking at things more in terms of confidence intervals. Effective communication of results and effective use of results can be hugely important to a firm's success.29 Communication is another area that might benefit from the concept of an “appointed risk manager” with independence, a clear function, and reporting requirements to the executive board (see consequence 2). In this respect, the financial crisis makes a strong argument for improving the education of model users and decision-makers.

Considering real-world complexity and communication, we also believe that it is important to keep simple “manual” management rules in mind. Limits on asset allocation are a very simple and intuitive way of ensuring diversification of risk. Another simple instrument that prevents excess risk taking is risk sharing, for example, via retention. A very problematic development during the financial crisis was the excessive securitization and retrocession of risks. Risks were transferred from one party to another without any amount of risk retained, leading to poor underwriting and risk classification. Generally, retention is a very effective way to delimit moral hazard and the adverse selection problems that are inherent to such transactions. In this context, it is important to require a retention scheme for retrocession.

(4) Take heed of the lessons from agency theory—the right incentives are needed

According to Jensen and Meckling's theory of the firm,30 ownership structure, management incentives, and monitoring of management are important determinants of risk taking.31 For example, management ownership in the company might increase or decrease risk taking; theoretically, it is not clear which effect dominates. On the one hand, when managers’ stakes increase, their interests become more aligned with those of shareholders, and equityholders have an incentive to increase the value of their equity call options by increasing risk.32 On the other hand, however, Smith and Stulz argue that most managers will not hold a well-diversified portfolio and thus may become more risk averse as managerial ownership increases.33

Compensation based on options have often been identified as a problem during the crisis; it can create an incentive to raise risk taking to an unacceptable level.34 Agency theory suggests that since the value of option-based compensation is positively connected with the underlying stock variance, granting option-based compensation to CEOs will motivate them to take on higher levels of risk.35 We agree with the CRO Forum that the principle of performance-related compensation is the right one, but it must be correctly applied.36 Performance-related compensation can encourage excessive risk taking. In this context, a consequence is that compensation based on options should not be short term by nature, but instead oriented to the long-term success of the company.

(5) Take heed of the lessons from portfolio theory—risk, return, and diversification

Two of the best-known and accepted lessons from portfolio theory are (1) that there is a positive relationship between risk and return and (2) that one should not put all one's eggs in one basket. While most insurance companies follow a prudent business policy, we believe that some market participants have not taken these two lessons to heart in recent years.

There is a natural relationship between risk and return in capital markets, and no market participant can expect an unusually high level of return without a corresponding high level of risk. If there arises an opportunity to achieve “higher than usual” gains, all market participants will quickly reallocate their funds in the direction of that investment opportunity. The massive and sudden increase in market price then eliminates the opportunity. In other words, at least in theory, there is no free lunch in capital markets.37 This basic rule should be true for other markets as well, for example securitization.

Portfolio theory also illustrates the advantages of investing in different assets, regions, and markets. One problem revealed as the crisis developed was that many instruments considered to be very safe actually were not. Adequate diversification across different instruments, regions, and markets should be a part of every prudent investment strategy. As mentioned, AIG had CDSs insuring US$ 440 billion of MBS—a situation that reflects no sufficient diversification. One problem in the recent crisis was the sensitivity of different asset classes to extreme events in other asset classes. Unexpectedly, high correlations were triggered as disaster in one asset class spilled over into others (see also consequence two on non-linear dependencies). Some small banks largely avoided MBS and other securitizations and many practiced very conservative lending policies, but found themselves in trouble when homeowners (their borrowers) lost income, and economic activity froze up even though these banks had money to lend. It might thus be arguable whether diversification could have provided sufficient protection against the recent crisis. In an extreme scenario, all economic activities may be subject to spillover and hence only global political actions may be successful in such circumstances. However, we see two different points in this discussion: (1) the problem of spillover effects that might limit diversification also if a portfolio is diversified; and (2) the lack of portfolio diversification that might have troubled companies such as AIG in the absence of spillover effects.

(6) Principles instead of rules—Solvency II and SST are steps in the right direction

Solvency II and the SST focus on an enterprise risk management approach in order to obtain equity capital standards.38 In our opinion, the steps toward more principle-based regulation taken here are a move in the right direction for reducing the effects of the financial crises. The idea behind principle-based regulation is that the regulator provides only a set of principles to follow, but does not prescribe exactly how to implement the principles. Table 1 summarises the main pros and cons of principles- and rules-based regulation.
Table 1

Rules-based versus principles-based regulation


Standard rules-based regulation

Principles-based regulation


Regulator provides a detailed set of rules to follow and a model to implement

Regulator provides only a set of principles to follow and no information on how to implement


Solvency I

Swiss Solvency Test

Systemic risk

Pro-cyclicality and similar behaviour problematic

Pro-cyclicality and similar behaviour less problematic

Reflection of risk

One-size-fits-all model cannot capture the full spectrum of individual risk profiles

Individual model to capture true, individual risk profile of the insurer


Low flexibility for handling individual situations

Higher flexibility for handling individual situations


Little room for innovation

Might trigger innovation, for example, internal risk models (insurers need to develop to some degree their own risk models based on the principles)

Integration in risk management

No integration, regulatory requirements and insurers RM are mostly separate systems

Integration of regulatory requirements into the risk management process

Model arbitrage

More effective

Less effective

Predictive power






Implementation costs



Data requirement






Practical application






Model risk






Systemic risk



A major drawback of standard rules-based models is that they do not have the flexibility to handle individual situations and thus might not be very effective in assessing the wide range of insurance risk profiles. Generally speaking, a principle-based approach is more flexible and better able to capture an individual risk profile, for example, by using insurer-specific model parameters instead of ones predetermined by the regulator. A principle-based approach may also trigger innovation, such as when insurers need to develop their own risk models. Furthermore, the principle-based approach provides the insurer with the opportunity to integrate regulatory requirements into its risk management process. Business and regulatory objectives are then more closely aligned and should lead to more efficient regulation. Another advantage of using principles instead of strict rules is that doing so has the potential to reduce the danger of similar behaviour and, in turn, systemic risk within the market.

However, a principles-based approach is not without its downside. Relying on principles could increase the complexity and costs of regulation, both for the insurer and for the regulator, the latter needing sufficient resources to appraise all the individual models instead of one standard model.39 In addition, the degree of freedom inherent in principles-based regulation might be abused by some market participants to lower their capital requirements so that the regulatory requirements are less strict (problem of “loosening up”). Given a choice between internal risk models and a standard model, insurers may use internal risk models only if it results in lower capital requirements. And in case of using internal models, insurers again have incentives to use their freedom to lower the capital requirements since there might be different ways to model the main risk drivers (e.g., regarding distributional assumptions). Principles-based regulation might thus offer opportunities for model arbitrage, while rules might be clearer and enable market participants to compare the results more easily.

In general, the debated over rules-based versus principles-based regulation reflects the debate over standard models versus internal models. In principle, rules-based standard models are simple to implement and easy to use, whereas internal models—which are subject to specific principles by the regulator—are much more complex. For example, the SST provides a standard model, which is especially useful to small insurers without the resources to develop an internal risk model, but encourages all insurers to develop their own internal models as these are expected to better reflect the true risk profile. Consequently, there is a standard model only for life insurance, health, and property-casualty and none for reinsurers, as these are expected to have sufficient know-how and resources to develop such internal risk models. In general, we anticipate that models with great predictive power will be more complex.40

We believe that allowing insurers to use internal risk models is a move in the right direction, for three reasons. First, as mentioned, the use of different approaches may prevent “systemic risk” within the capital markets. More precisely, the risk of identical reactions given an unusual market event (e.g., stock crash) is reduced.41 Thus, it might make sense to have multiple solvency models, allowing market competition to determine which ones work best. Recently, the CRO Forum analysed the pro-cyclical nature of Solvency II and proposed a solution to address the problem:42 in times of distressed markets for certain assets, the solvency capital requirement (SCR) is temporarily complemented by a reduced capital requirement, documented under Pillar two and subject to disclosure under Pillar three of Solvency II. The lower capital requirement shall only be applied if case management intends to hold these assets over the duration of the liabilities it covers (i.e., typically longer than the one year planning horizon of Solvency II). We believe this to be an appropriate way to counteract market downturns.

Second, another problem with standard rules-based models—and one that can be handled much more easily with internal risk models—is up-to-dateness. Daníelsson, for example, claims that Basel II is state-of-the-art for 1998.43 In the insurance industry, this problem is even more severe. The length of the Solvency II process in the European Union (EU) is a good example of how difficult it is to introduce an innovative regulatory system. Political decision-making takes time, and usually needs a triggering event to actually occur. In the EU, this trigger was the formation of the common financial services market in 1994, but even so the new framework is not expected to be introduced until at least 2012.

Third, it can be argued that the attempt to avoid rules by creative new products that lie outside rules-based regulation was one of the root causes of the crisis. AIG's CDSs were not adequately recognized in insurance regulation since CDSs were not regulated and were not even categorized as a traditional insurance product, so that AIG did not have to provide risk capital for potential losses from this area.44 It might thus be that a principle-based approach that calls for consideration of all relevant risks makes gaming the system more difficult.

(7) A concept for a controlled run-off in the insurance industry is needed

In addition to the entry of new market participants, another aspect of a free market economy is the failure of unsuccessful companies. SCRs can only reduce the probability of insolvency; they cannot prevent it. If insolvency occurs, policy-holders bear the consequences—in principle, the discrepancy between liabilities and assets—since equityholders enjoy limited liability. However, if stakeholders are aware of their burden in the event of insolvency—in other words, there is no information asymmetry—fair pricing of equityholder claims should take place in a competitive market.45

In the case of distress of financial institutions, recent defaults have been (partly) covered by the governments. Such action, which basically means that the taxpayers have to pay any discrepancy between liabilities and assets, eliminates an important element of a free market economy. In a competitive market, such action will create wrong incentives for policy-holders, equityholders, and the management of an insurance company. To allow a controlled run-off for insurance companies, an insurance guaranty fund is an option. In contrast to the way it is done in some countries, risk-adequate premiums—for instance, based on the default put option value—are required for the funds in order to avoid cross-subsidization.46 Guaranty funds can create a put-option-like subsidy to equityholders, which also might create incentives for risk taking.47 A risk-adequate pricing of the premium in a competitive market is thus an important prerequisite for a guaranty fund. Calculations based on empirical data are necessary here in order to derive a minimum level of an insurance guaranty fund under different market scenarios and assumptions regarding the interrelations between the insurers in place.

Since the creation of such a guaranty fund will, ceteris paribus, lead to an increase in policyholder premiums, it is necessary that all major insurance markets be subject to similar rules, including the banking industry, since insurance companies and the banking industry sell many similar products. However, both the creation of a guaranty fund and advanced solvency rules lead to a high degree of regulation and, consequently, high transaction costs, so the costs and benefits of regulation should be weighed carefully before it is implemented.

(8) Financial conglomerates need to be supervised at the group level

Given the increasingly frequent consolidation activity in the insurance market, the advantages and risks of corporate diversification have become a focus of regulatory authorities. As stated in the literature, conglomeration leads to a diversification of risks—the so-called diversification benefit—but, at the same time, to a decrease in shareholder value—the conglomerate discount.48 To obtain accurate information about the safety level of a financial conglomerate, analyses must be conducted at both the single legal entity level and the enterprise level. In particular, capital and risk transfer instruments used between different legal entities within the financial conglomerate need to be taken into consideration.

Additionally, non-insurance entities (banks or non-supervised companies) that are a part of the conglomerate need to be investigated by regulators in order to judge whether they substantially influence the overall risk situation of the conglomerate. In this respect we support the Pan European Insurance Forum, which argues that—at a global level—group supervision should be achieved through multinational recognition of foreign supervisory activities.49 This will necessitate a set of general standards for the main insurance markets so as to avoid market distortion within different countries.

(9) Avoid regulatory arbitrage in financial services markets

Globalization and deregulation have led to an integrated financial services market, and consumers have generally benefited from the lower prices and higher quality services made possible by increased competition. However, it is hardly possible to distinguish business activities between different financial services providers and across different countries. The credit crisis has illustrated that financial services are one integrated market, one that is in need of integrated risk management and supervision. Separate regulation of banking, insurance, and other financial services providers invariably creates opportunities for regulatory arbitrage, which was one of the roots of the crisis. This holds not only for different parts of the industry (banking, insurance, pension funds, and other financial services providers), but also across countries. There are prominent examples of the importance of regulatory arbitrage in the crisis: With regard to regulatory arbitrage across countries, many banking subsidiaries have been created in Ireland due to lower regulatory requirements and tax advantages, such as the German Hypo Real Estate subsidiary Depfa bank. In recent years, insurance companies also sold many products from the Irish jurisdiction for many of the same reasons. The problem with the cross-country design is that the regulatory authority and competence is limited when multiple countries are involved. The German regulator BaFin, for example, claimed that it was not authorized to assess the risk of the Irish Depfa bank.50 The AIG case is an example for regulatory arbitrage across banking and insurance companies. AIG sold credit-default swaps for MBS to banks, which was an easy way for the banks to lower their capital requirements since AIG had a “triple A” rating.51 The immense credit risk potential with AIG was not assessed, since the risk of CDSs were not adequately recognised in the insurance regulation frameworks.

To ensure a safe financial services industry in the future, it is necessary that regulation itself becomes “globalized”. We need international cooperation and an international regulatory institution for coordination. However, due to complexity and cross-country differences, we do not think that a centralized global institution can conduct efficient supervision. Rather a non-centralized structure with single responsibilities for local financial institutions and a close coordination between the different regulatory authorities in respect to global financial institutions can be the most efficient way to create a sound future financial architecture. When multiple countries and industries are involved, one lead regulator should be clearly denoted.

The playing field must be globally level for the same types of business, irrespective of the exact business type or specific region where it is conducted. This is an important requirement not only to protect policy-holders, but also to ensure fair competition in a global industry.52

(10) Transparency, market discipline, and accountability are needed

Pillar three of Solvency II deals with market transparency and disclosure requirements aimed at promoting market discipline. We believe that market discipline, that is, the influence of customers, brokers, rating agencies, and investors on firm behaviour could be a big step toward creating a strong and solvent insurance industry. Impediments to market discipline have been an important flaw in the financial crisis, for example, considering complex financial products or non-transparent rating agencies.53 Transparency and disclosure requirements are closely connected to the aspect of monitoring mentioned in consequence five. The monitoring instance is the public (i.e., all market participants) in this case and the expectation is that more monitoring will limit executive discretion and decrease the opportunity for excess risk taking.54 We believe that the credit crisis has revealed the necessity of taking a closer look at transparency in financial services markets.55

Transparency is crucial for complex financial products. Particularly in the case of retrocession, it is essential that the underlying risk and all involved intermediaries be known. The buyer of a product should be aware of the sensitivity of the product price with regard to changes in financial markets, such as changes in interest rates or volatility.56 Also, interdependencies with other types of risk in the investment portfolio should be unambiguous.

Rating agencies are accused of bearing a strong responsibility for the subprime crisis57 and also are in need of much greater transparency. The crisis has shown the flaws of the business model in the rating industry, with conflict of interest in generating revenues from the insurers being rated. The problem is thus not inherently with ratings, but with the rating industry, so that a reform of the business model of the rating industry should be added to the agenda.58 The existing self-regulatory framework for rating agencies based on the 2004 International Organization of Securities Commissions (IOSCO) Code of Conduct is thus not enough and further international level regulatory measures are needed.

Moreover, the insurance industry itself will benefit from more transparency since reputation in general, and customer and shareholder trust specifically are key assets.59 Enhancing market discipline should thus be encouraged and will be rewarded with increased consumer trust. Toward this end, we suggest more disclosure with regard to the valuation of assets and liabilities. In this context, a unified framework for a market-consistent valuation of assets and liabilities, and a transparent disclosure of all underlying assumptions would be beneficial.60 More transparency is also needed in the area of off-balance-sheet obligations, as these are crucial in determining the insurer's risk situation. Additional disclosure requirements will enable market participants to better understand the risk situation of an insurance company. As a consequence, effective risk management will be appreciated by the market and risky behaviour sanctioned. More information also reduces agency conflicts, that is, information asymmetries between insiders (management) and outsiders (analysts, stockholders, policy-holders) and thus uncertainty.

However, more information is not necessarily better information. We will achieve better information only if the additional information is understandable and easy to access. The information must also be presented appropriately, for example, in a standardized format, so that comparisons are possible. Such a standardized comparison could be delivered, for example, on the regulator's web page. Furthermore, because providing information is costly, coordination should be encouraged where appropriate with other relevant disclosures, such as, for example, the international financial reporting standards.61

Accountability is another important aspect not very much discussed so far. One idea, for example, is to introduce accountability for rating agencies. Rating agencies might take more care with their ratings if they faced liability for the consequences incurred by making inaccurate ratings—for instance, if available and relevant information is not taken into account. It might be that the potential liabilities arising from a wrong rating decision are higher than the capital that rating agencies have. However, one solution for such a “low frequency, high severity” situation could be the purchase of insurance coverage. Insurance premiums might have to be quite costly, but the price could be lowered, for example, by retention and other safety measures such as internal risk control. We believe that all these measures that would accompany accountability would create the right incentives and improve the safety of the financial services industry. The same mechanisms might also be considered for D&O insurance or for regulators. A substantially high retention to be paid by the managers themselves might have helped avoid the excess risk-taking observed with some market participants in recent years.

One of the most important aspects is that there should be a direct connection between those who make decisions (e.g., managers) and those who have to bear the (negative) financial consequences. It was lack of this connection that is responsible for at least part of the current financial crisis.62 Thus, we believe that more consideration of accountability—of regulators, rating agencies, and managers—is an important step that can be taken, even more important than imposing another set of regulations.

Summary of policy recommendations

The point can be made that we might not be out of the crisis yet and that we do not yet understand the details of the crisis well enough to derive precise consequences from it. Some lack of understanding, however, will not prevent policy-makers from proposing new legislations. Therefore, we think that it is important to outline potential consequences that we see from the crisis—even though we have to admit that we have, in some cases, no empirical evidence that clearly supports our line of reasoning. In this context it is important to highlight for which of the consequences derived we believe to have sufficient evidence and where we see need for future research. As a summary of the discussions presented in this paper, Table 2 provides an overview of our policy recommendations, how these recommendations are related to the crisis, whether there is sufficient evidence, and what concrete measures for implementation of our recommendations might be. Fields where we see need for future research are displayed in the last section of Table 2.
Table 2

Summary of policy recommendations

Policy recommendation

Example for importance in the credit crisis

Evidence from the literature

What to do

1. Strengthen risk management and supervision

 • No outsourcing of risk assessment; regulators need to review role of ratings in supervision (e.g., Solvency II)

• Rating and regulatory arbitrage: AIG and use of CDS products, AIG and use of 2a-7 puts (see Nocera, 2009); systemic risk when all market participants rely on the same ratings

• Mathis et al. (2009) show specific problems of current business model in the rating industry; other evidences: Goodhart (2008), Portes (2008), Hellwig (2009), Dowd (2009), and Stolper (2009); earlier discussions surrounding Basel II, e.g., Daníelsson et al. (2001)

• Ratings might be used for decision support, but they cannot substitute own due diligence; see also consequence 10 for ratings

 • Enhance risk management by appointing a “responsible risk manager”

• Flaws in risk management process have led to problems (see Stulz, 2008); risk management might actually have been counterproductive (Dowd, 2009)

• Stulz (2008) describes a taxonomy of risk management failures; Dowd (2009) also describes risk management failures

• Clear definition and documentation of communication channels and responsibilities, these should be reported to regulators (e.g., MaRisk in Germany and the Swiss Quality Assessment are right steps in that direction)

2. Take care of model risk and non-linearities

 • We need more stress testing to adequately assess model risk

• Existing stress tests were not “stressful” enough to capture the realized downside risk in the crisis (see De Larosière, 2009)

• De Larosière (2009) criticizes stress testing as often based on mild or even wrong assumptions

• Use of different models and assumptions in stress testing in order to adequately assess model risk

 • Stress testing should also consider non-linear dependencies

• Low returns on stock and bond markets throughout the credit crisis, correlation might be higher in crisis (see Eling and Toplek, 2009)

• Eling and Toplek (2009) illustrate relevance of non-linear dependencies in stress testing, also motivated by the financial crisis

• Extend stress testing by incorporating non-linear dependency

 • Develop models for handling liquidity risk

• Liquid products such as MBS suddenly became illiquid (e.g., MBS; see Crotty, 2009; Venter, 2009)

• Daníelsson et al. (2001) and Daníelsson (2008) calls for liquidity risk models; Brown et al. (1999) mention relevance of liquidity risk

• Check portability of liquidity risk models, e.g., from banking (e.g., Longstaff, 1995; Zheng, 2006) to insurance; reconsider cash flow matching (Feldblum, 1989)

 • Review of measures used in risk management and regulations (value at risk, expected shortfall)

• Existing risk measures and models have underestimated tail risk (see Yamai and Yoshiba, 2005; Dowd, 2009; Schmitz and Forray, 2009)

• The properties of risk measures and their right use have been extensively discussed in literature (see, e g., Dowd and Blake, 2006)

• Use of expected shortfall in regulation rather than value at risk, use of different risk models to assess model risk

3. Easy to use and understandable risk management

 • Improve communication

• Complex risk management tools and their apparent accuracy is problematic; Stulz (2008) describes how communication failures have played a role in the crisis

• Eling et al. (2008) discuss importance of communication; Stulz (2008) describes failures in risk communication; Löffler (2009) illustrates that deficiencies in communication must have been relevant in the crisis

• Use of confidence intervals with each estimation to illustrate their stochastic nature; clear definition and documentation of communication channels and responsibilities; improve education, e.g., by presentation and communication skills

 • Use simple risk management rules

• Diversification: AIG's CDS portfolio; no retention in securitization (resulting in adverse selection, moral hazard problems, and poor underwriting)

• See Banks and Sundaram (1998) for retention; for empirical evidence of the effects of deductibles, see Wang et al. (2008); key points of risk management in addition to specific modelling aspects are derived in Doherty (1975)

• Limits on asset allocation for diversification; retention in risk sharing to reduce moral hazard and adverse selection

4. Take heed of the lessons from agency theory

 • Bonuses should be oriented on the long-term success of the company

• Wrong incentives from compensation programmes have often been named as a cause of the crisis (see Crotty, 2009)

• A number of articles show how bad incentives can be created by wrong compensation programmes (Coles et al., 2006; and Low, 2009).

• Long-term orientation in compensation such as option excercise after five years or bonus banks

 • Reduce asymmetric information between top and line management

• With special respect to the case of German state owned commercial banks, the board of directors was, in many cases, not familiar with the risks and the leverage exposure by the written contracts

• For example, Inderst and Laux (2005) develop and evaluate capital allocation techniques with respect to their ability to mitigate problems stemming from information asymmetries between the board or the owners of the firm and the line management

• Capital allocation methods, risk-adjusted performance measures, and compensations schemes based on them should be analysed in how they apply the right incentives

5. Take heed of the lessons from portfolio theory

 • Risk and return

• AIG viewed CDS as return without risk

• See Markowitz (1952) or Campbell (1996) for a consideration of risk and return

• Strengthen awareness of the relation between risk and return

 • Diversification

• AIG had CDSs insuring US$ 440 billion of MBS

• See Lintner (1965) or Solnik (1995) for measures of diversification; for diversification in the context of non-linear dependencies see, e.g., Embrechts et al. (2002), Eling and Toplek (2009)

• General standard for a minimum asset diversification for insurance companies in respect to their underwriting portfolio are necessary in global insurance markets

6. Principles instead of rules

 • Implement principles-based regulation

• Attempt to avoid rules by creative new products that lie outside rules-based regulation (e.g., AIG credit default swaps were not adequately recognized in insurance regulation)

• Various articles discuss pros and cons of principle versus rules in case of the supervision of insurance companies (e.g., Eling et al. (2007) and Eling et al., (2008))

• Principles-based approach that considers all relevant risks might make gaming the system more difficult, but critical review is needed here, since implementation problems might emerge (e.g., problem of “loosening up”)

 • Similar rules to regulate insurers should be avoided since they force companies to behave identically in crisis (systemic risk)

• Pro-cyclicality of rules-based regulation in times of crisis

• See Gordy and Howells (2006) and Dowd (2009) for pro-cyclicality in Basel II

7. A concept for a controlled run-off in the insurance industry is needed

 • Implement guaranty funds with risk-adequate premiums to reduce the default risk for the policyholder in case of insolvency

• Dowd (2009) discusses problems regarding deposit insurance beyond the background of the financial crisis, and presents cases from the financial industry

• Guaranty funds and deposit insurance can create a put-option-like subsidy to equityholders, which also might create incentives for risk-taking (see Cummins, 1988; Lee et al., 1997)

• Research needed in respect to the fair pricing within guaranty funds when strong asymmetric information between the market players is present (Cummins, 1988)

8. Financial conglomerates need to be supervised at the group level

 • Supervision of global financial institutions must be conducted at both the single legal entity level and the enterprise level

• The true safety level of AIG with 4,000 legal entities and complex capital and risk transfer instruments between the different legal entities could not have been captured by the many regulatory authorities in the different countries involved

• See Liebenberg and Sommer (2008) with regard to supervision of conglomerates

• Derive solvency standards for global institutions taking capital and risk transfer instruments into account

• Capital and risk transfer instruments used between different legal entities must be taken into account in order to judge the safety level of a financial conglomerate correctly (see, e.g., Gatzert and Schmeiser, 2008)

• A single leading regulator for conglomerates is needed

9. Avoid regulatory arbitrage in financial services markets

 • Similar principles-based standards are needed for the financial services industry as well, as in the global financial market

• Regulatory arbitrage across countries and across different parts of the financial services markets; e.g., German Hypo Real Estate subsidiary Depfa bank in Ireland; AIG and its CDS business

• Hellwig (2009) describes flaws in financial system architecture also regarding regulatory arbitrage

• Non-centralized structures with single responsibilities for local institutions with a close coordination between the different regulatory authorities with respect to global institutions

10. Transparency, market discipline, and accountability are needed

 • Enhance transparency

• Unclear products, unclear rating process, unclear business practices in the industry regarding derivatives and other products

• Holmström (1979): More information is never detrimental and, under mild assumptions, strictly beneficial; Epermanis and Harrington (2006) with empirical evidence for market discipline

• Use of market consistent valuation techniques with disclosure of all underlying assumptions; regulator might develop a standardized database with information on all companies

 • Reform of rating agencies

• See consequence one and Hellwig (2009) for role of ratings

• Mathis et al. (2009) show flaws of business model in the rating industry; other evidence: Goodhart (2008), Portes (2008), among others (see consequence one)

• Reform of rating agencies, e.g., the platform-pays model described in Mathis et al. (2009)

 • Enhance accountability

• See Dowd (2009) for aspect of accountability

• Concepts to enhance accountability for rating agencies, regulators, and managers setting the right incentives needed

Considering Table 2, many of the problems and solutions are not unknown, but acquire special relevance in the light of the crisis. Significant need for future research can be identified, however, considering modelling of liquidity risk in the insurance industry. Another important aspect is to evaluate the impact of transparency and market discipline in insurance markets, especially outside the United States. In general, there is need for empirical work on the effects of the crisis in risk management and regulation whenever data become available. Furthermore, careful monitoring of the policy measures that are undertaken right now must be carried out in order to learn for a future crisis. Among these problems is also a critical review of principles-based regulation that is now implemented in some countries, since it might lead to problems such as abuse of freedom by some market participants. In addition, concepts are needed for a controlled run-off of insurance companies whenever a default occurs.


