Skip to article sections

Kari Haleis a Partner and Head of Deloitte & Touche Global Financial Services Industry Governance and Regulation practice.

In a previous article I discussed how authorized businesses should respond to ensure that their responsibility for establishing and maintaining appropriate"compliance" with High Level Standards (HLS) can be achieved, and so maintain a high standing with their regulator, the FSA.

I outlined how a proper regard for "5 Cs" of risk management (culture,compliance, control, communication and comprehension) can enable a sound approach to governance and assist you in demonstrating that your organization can safely and successfully meet its regulatory obligations.

The FSA's primary tool for examining a company's HLS standards compliance is the so called "Arrow visit", designed as part of the overarching Arrow framework which drives the FSA to respond in a risk prioritized way to its statutory imperatives of maintaining market confidence, promoting public awareness,protecting consumers and reducing financial crime.

In general, I have found that companies' preparation for Arrow visits can be somewhat patchy, and frequently one finds documentation to be incomplete,inconsistent or out of date, and the degree of understanding of management to be variable.

The search for substance

It goes without saying that the FSA should be, and indeed are, concentrating on looking for matters of substance rather than presentational weaknesses. But,and it is a big but, if your firm is not in the best position to demonstrate clearly and professionally how it meets its requirements and how it is managed,it is inevitable that the regulator's judgements will be colored, and it is less likely that you will gain full credit for the many things that are no doubt done properly and well.

Invariably, given the "holistic" nature of the FSA's risk model, the responsibility for preparing for these visits will involve people from across the entire organization. The wealth of evidence that must be presented is unlikely to be housed within a single functional area or indeed to reside within the responsibilities of a single person – business strategy sits with the board and the CEO, assurance with internal audit, management information with finance and risk, training and competence with the human resources department,and so on.

Such diffusion can lead to difficulties in quickly and efficiently gathering up to date, consistent information when you need it, and if your management team are in addition not well briefed it may prove extremely challenging for you to avoid the FSA finding discrepancies or gaps that will need expensive remediation through your risk mitigation plan.

At Deloitte, we encourage our clients to be thoroughly prepared for the Arrow visit process. For example, not only should all the key documentation be collated and organized well in advance of the visit, but the day-to-day maintenance of this information should ideally be enforced as a matter of best practice during "business as usual" periods to provide a general reference for HLS compliance.

Why do this? The simple answer is that it is always possible that an unexpected issue may crystallize, and you really do not want to be on the receiving end of an enforcement visit looking for root causes without the basics of sound prudential management in place. Such circumstances can be career threatening.

Gathering the documentation

In thinking about what sort of material to gather and maintain, we would recommend you consider the following ten points as a sensible starting point.

  • 1.

    Documents to demonstrate how approved persons:

    • discharge their responsibilities as an approved person properly;

    • are allocated clear accountability for specific aspects of the business,including up to date, clear and detailed structure charts;

    • exert significant influence appropriately over the business areas for which they are responsible; and

    • identify, control and manage risks within defined tolerances and how this is evidenced, for example by management information that they receive.

  • 2.

    Job descriptions that accurately reflect their current responsibilities.

  • 3.

    The procedures used for changes in approved persons, and details of how succession planning is managed in the organization.

  • 4.

    How evaluations are conducted and evidenced, how this process is reviewed and when it was last reviewed, and how this links to your training and competence arrangements.

  • 5.

    How you identify and monitor the control of outsourcing risks (including intra-group).

  • 6.

    Business continuity and disaster recovery plans, including details of when last tested.

  • 7.

    Details regarding internal audit, its operational independence, resources,remit and outputs.

  • 8.

    Key operational management information including, inter alia,financial performance, risk reporting and compliance reporting.

  • 9.

    Minutes of key committees and terms of reference for each such committee.

  • 10.

    Descriptions of the planning and strategy setting processes, and the resulting documents.

Assembling this information in a digestible form and single location will undoubtedly facilitate an efficient review by the FSA, and our experience is that by gathering it and reviewing the materials that are available, you will immediately benefit from a clear insight into any major gaps or inconsistencies,in good time to put these to right ahead of the regulator's own review.

Thinking through the strategy

So what about the visit itself and the sort of questions that are most likely to be asked?

Set out below, categorized in terms of the nine risk groups of FSA's own risk model, are examples of typical questions that your management team and non-executive directors might be expected to answer:

Strategy

  • How is the risk appetite articulated and how is this reflected in the strategy of the organization?

  • What data is prepared to support the planning process?

  • What stress testing and scenario analysis is performed on the plan?

  • How are targets set?

Market, credit, operational and legal risk

  • How do you gain an understanding of key areas of risk within the organization?

  • What is the risk framework for managing those risks?

  • How do you ensure that those risks are captured and effectively managed?

  • What is the process for aggregating risks and is there a common risk language to facilitate this?

Financial soundness

  • How do you manage your capital position?

  • What is the process for liquidity management?

Nature of customers, products and services

  • What is sold and to whom?

  • What processes are in place to ensure that the products/services sold are appropriate to the individual customers?

Treatment of customers

  • Where does responsibility lie for ensuring fair treatment?

  • What processes are in place to deal with customer complaints?

Organization

  • What is the relationship between the legal structure and the operational structure of the organization?

  • What is the ownership structure of the organization?

Board, management and staff

  • What are your reporting lines (upward and downward)?

  • What are the key committees and other governance mechanisms?

  • How is challenge provided to key decisions and what is the nature of this challenge?

  • How is delegation of authority documented?

  • What processes are in place to ensure that resource of the appropriate skills and experience is recruited and retained?

  • Do you have succession plans in place?

Internal systems and controls

  • What key management information is used in running the business?

  • What is the profile of internal audit within the business?

  • How do you ensure that the organization is complying with relevant rules and regulations?

  • How do you get comfort that money-laundering regulations are being complied with?

Business and compliance culture

  • How would you characterize the culture of the organization?

  • What is the process for embedding the culture and desired behavior?

  • How is the tone set from the top?

In general, the right and only basis on which to prepare for communicating with the FSA is to accommodate the visit and, to the best of one's ability answer their questions openly within a constructive dialog. The interview is likely to be relaxed rather than confrontational if your attitude is right, and in particular we believe that you should be prepared to view the process as an opportunity to present your business's strong points in a positive light.

Aim for understanding

Achieving this end does require a degree of preparation from interviewees. They should understand the FSA's objectives, hot topics and the Arrow process so as to have context for their responses. They should be aware of the likely areas of inquiry and prepared to provide the appropriate information and explanations. And they should be aware of the "big issues" in the business in order to ensure a relatively consistent message comes over to the FSA that shows the management team are communicating effectively and have a common agenda.

With the right documentation in place, and the preparation of the interviewees properly completed, an Arrow visit should hold no fears for you. To the contrary it can become an opportunity for presenting your organization in its best light and so enhance your reputation and relationship with the FSA.

Data & Figures

Contents

Supplements

References

Languages

or Create an Account

Close subscription notice
Close access options