2021-10-03
Added · Updated
The Central Bank issues guidance requiring insurance companies to implement International Financial Reporting Standard 17 by establishing board-approved policies for contract definition, aggregation, and measurement. The document mandates specific operational changes, including the use of discount rates reflecting time value of money, the calculation of contractual service margins, and the segregation of non-financial risk adjustments. It further requires insurance entities to manage IT system operations, ensure data security through third-party agreements, and submit annual audit summaries to the regulator.
1 | P a g e Guidance to implement the requirements of the International Financial reporting Standard (17) 2021
2 | P a g e Subject Contents Page Introduction ..................................................................................................... (03) Chapter 1: Implementation of IFRS 17............................................................ (05) Chapter 3: Manage IT system operations ...................................................... (12) Chapter 2: Rules for sharing and storing information with a third party ........ (14) Chapter 4: Central Bank Approval ................................................................. (21)
3 | P a g e Introduction In May 2017, the International Accounting Standards Board (IASB) issued a new standard on insurance contracts, which was to be introduced as of 1/1/2021 and which would replace the currently applied International Financial Reporting Standard (4). The application of the standard requirements was subsequently postponed until 1/1/2023 in June 2020. The International Financial Reporting Standard (IFRS 17) represents a comprehensive change in accounting for insurance contracts, which will enhance the transparency of the actual financial performance of insurance companies, and aims to make corporate financial statements more realistic in measuring results and recognizing revenues and liabilities and be more comparable across insurance companies. The standard covers accounting aspects of a wide range of contracts issued by insurance companies, and the effect of this standard varies depending on the type of contracts held by each company. The greatest impact will be on long-term insurance contracts. However, the change will be fundamental to all insurance companies. Implementing the requirements contained in the new standard will result in changes in the operations of insurance companies, which will require insurance companies to change the accounting processing methods they use, their financial reporting mechanism and the need for them to modify and develop systems and restructure their operations. New principles apply to accounting for insurance contracts (including recognizing expected losses), which requires insurance companies to prepare policies, procedures and decisions that ensure that the company can best apply the standard’s requirements. IFRS 17 relies on taking into account the time value of money when measuring liabilities to reflect the current value of future cash flows, using a discount rate that reflects the risks to the company, and is reviewed and updated frequently. This guide has been prepared to assist insurance companies in implementing the requirements of IFRS 17, taking into account the complexity and proprietary nature of the operations of insurance companies, as well as increasing transparency and ensuring that appropriate and objective financial data is displayed. This guide describes the requirements for the general implementation of IFRS 17, the requirements of information security systems, details of the accounting policy which will describe the application of IFRS 17 by the company, and requirements for
4 | P a g e central bank approval. This reflects the interest of the central bank to ensure that insurance companies observe the minimum requirements stated in the standard and appropriate information is provided to the central bank.
5 | P a g e Chapter I Implementation of IFRS 17 First: Definition of contract In order for a company to meet the requirements of the standard, a company must prepare a board-approved policy that enables it to determine whether or not the contract complies with the definition of an insurance contract contained in the standard. The policy referred to above shall include the minimum:
6 | P a g e Third: The level of aggregation In order to meet the requirements of the standard, the company must prepare a board-approved policy to collect insurance contracts in separate portfolios that are separately written and processed, divided into three levels, respectively:
7 | P a g e Fourth: Recognition of the insurance contract • In order for the company to meet the requirements of the standard, the company must recognize a group of insurance contracts as at the following dates, whichever is earlier:
8 | P a g e
9 | P a g e
10 | P a g e Ninth: Contract Measurement Approaches • The standard provides insurance companies with three approaches to measuring and treating insurance contracts and reinsurance contracts that are held for accounting, which are as follows:
11 | P a g e Tenth: Disclosures The company shall disclose in its financial statements, in addition to what is stated in paragraphs (93) to (132) of the standard, at a minimum, the following aspects:
12 | P a g e Chapter II. Manage IT system operations First, manage the IT systems project for implementing IFRS 17 In order for the company to manage the project more efficiently and effectively, the company must develop a board-approved business plan that is tailored to the nature of the company's business and the complexity of the requirements of IFRS 17, including the distribution of supervision and control functions and responsibilities over the stages of project implementation, the necessary reporting process, and risk assessment throughout the project period. In preparing the above-mentioned business plan, the company should consider the following aspects:
13 | P a g e
14 | P a g e Chapter III. Rules for sharing and storing information with a third party The following aspects of sharing and storing information with a third party should be extended to prospective IT systems for IFRS 17. First: The minimum rules to be observed when sharing and storing information with a third party: Contractual and legal aspects A company should use a risk based assessment methodology to determine which data is permitted to be stored or processed outside the company according to the nature, classification, and degree of data risk, subject to compliance with the relevant legislation in force. 1 The IT systems service provider must be known and reputable, and have no improper practices with those who work with or have worked with them. 2 A Service Level Agreement and Non-Disclosure Agreement with the IT service provider should be made, with agreements to define the standards by which operations are carried out by the IT service provider. The agreements should include penal and criminal provisions for any action or conduct that violates the privacy and security of information. 3 Information should be kept confidential so that it complies with the provisions of confidentiality of information under the Insurance Organization Act No. 12 of 2021 and the relevant legislation. 4 The company should ensure that its IT service provider has adequate controls to enable the company to meet its contractual and legal obligations, such as maintaining data privacy and reporting compliance with security and control controls. 5 Incident response procedures must be established to ensure that all incidents to which data may be exposed are dealt with effectively in a timely manner. 6 The company must assess the efficiency and effectiveness of the cloud computing service and its compatibility with information security requirements. 7
15 | P a g e The company can either use the cloud computing service directly from the IT service provider or through an intermediary that the IT service provider uses. In the case of an intermediary, the company must consider the application of all applicable security and regulatory requirements as if the service was provided directly by the IT service provider. 8 The company should confirm the information privacy requirements when the contract with the IT service provider or intermediary ends, whether it is terminated or transferred to another service provider. All data, including backups, must be deleted by the IT service provider or intermediary after delivery to the company. 9 Manage data access Logical access and identity verification mechanisms must be used to access data stored by the IT service provider, which prohibits the granting of broad access permissions that result in unauthorized device/user access to data. 1 The company must create a secure and encrypted trunk to the IT service provider through a Virtual Private Network (VPN), especially when the connection is Site-to-Site. 2 Some sensitive protocols, such as SSH and RDP, should not be used over the internet without adequate and appropriate controls to prevent unauthorized use of data access methods. 3 Data protection The company should make sure that the data stored by the IT service provider is kept separate from data of other clients of the IT service provider through necessary isolation mechanisms, such as Multi-Tenant Environment. 1 The company must encrypt data during network traffic and when it is stored on servers, storage, and backups, taking into account the use of secure and acceptable encryption algorithms and protocols. 2 The company must set appropriate controls on encryption keys, and if its IT service provider is granted access to encryption keys, the responsibility for the data remains with the company. 3
16 | P a g e The company must ensure that system/service assurance at the IT service provider is not exposed to any of the ten OWASP-related threats. 4 The company must ensure that all systems are protected through AntiVirus/Anti-Malware Software, and that an Intrusion Prevention System is installed to prevent any interference or activity that damages data. 5 The company must ensure that a Web Application Firewall is used to minimize vulnerabilities or stop attacks on web applications. 6 The company must ensure that all applications, systems and devices are enhanced by System Harding controls in accordance with best practices. 7 Physical protection The company or IT service providermust keep the servers and IT systems infrastructure equipment in a safe place. 1 The company must ensure physical protection against external threats. 2 The company must ensure backup and business continuity plan are provided to sustain the business. 3 The company must ensure that a disaster recovery plan includes all possible disaster scenarios and is periodically tested. 4 Identity and Authentication Element Protection (Credentials) The company should ensure that the two-factor authentication method is used for all accounts to enhance protection when using username and password. 1 The company should never use accounts with absolute authority (built-in Administrator) as such authorities should only be used for certain actions that require them and only and in an emergency. Where absolute authorities are more generally used they should be replaced with accounts dedicated to work-needed powers (Least Privileges) 2 Shared accounts are prohibited. User names and private passwords must be created according to the Least Privilege principle, and tasks and powers must be separate. 3 The company should ensure that best practices in password policy and standards and session management are applied. 4 The company should ensure that application programming interface passwords and security keys are protected and changed periodically. 5
17 | P a g e Security and audit records The company should ensure that security event logs and alerts are enabled to include for generated accounts (at least) event description, date and time, and that records are reviewed to monitor and detect suspicious movements and identify abnormal activities. 1 The company must ensure that the IT service provider alerts and notifies the company if any third parties request access to the data. 2 The company must ensure timely access to the necessary records for criminal investigation and investigation, and reporting of information relevant to the specific data or applications of the company. 3 Second: The minimum guiding rules to be adopted: Contractual and legal aspects The company or IT service provider should periodically perform a Penetration Testing and Vulnerability Assessment, and the results should be reported to the company. 1 The company should ensure that a scenario-based risk assessment and planning activity is periodically performed to:
18 | P a g e The company should ensure that mutual authentication or binary authentication is used to allow access to stored data. 2 Data protection The company should be aware that encryption is a fail-safe process so that a cryptographic mechanism/tool failure or security control failure does not affect encrypted data, and that unauthorized third parties have access to data that is unreadable and unusable. 1 The company should assess the information security requirements applied to the IT service provider, ensuring that data security standards are complied with, performing the Penetration Testing and Vulnerability Scanning, and continually assessing risk. 2 Identity and Authentication element Protection (Credentials) The company should ensure that a mechanism to continuously audit users' accounts and authority and cancel or disable unused accounts is adopted. 1 The company must ensure that the name of the account is considered for all accounts and assets, and that the name of the account does not indicate the powers granted. 2 Security and audit records The company should ensure that technologies that constantly monitor and check applicable security settings are used periodically. 1 The company should ensure that best practices for Application Programming Interface are used for testing, auditing, and protection of abnormal activities. 2
19 | P a g e Third: The most important criteria to be used in the field of cloud The company must ensure that the following standards are applied Standards Subject Cobit ISO/IEC 20000 SAE 16 or ITIL Dependding on type of workload ISO/IEC 27001 and ISO/IEC 27002 ISO/IEC 27017 & ISO/IEC 27018 ISO/IEC 38500 - it Governance Cloud Security Alliance (CSA) Cloud Controls Matrix National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) Governance, risk management and compliance SSAE 16 ISO/IEC 27000 Operational and commercial operations LDAP, SAML 2.0, OAuth 2.0, WS-Federation, OpenID Connect, SCIM XACML PKCS, X.9, OpenPG Manage roles HTTPS, SFTP, VPN using IPsec or SSL Oasis KMIP US FIPS 140-2 Data and information protection ISO/IEC 27018 Privacy policies ISO/IEC 27033 or FIPS199/200 Standards Network security and protection ISO/IEC 27002 ISO/IEC 27017 & ISO/IEC 27018 Infrastructure security controls ISO/IEC 19086 ISO/IEC 27004:2009, TM Forum TR 178, NIST Special Publication 800-55, CIS Consenssus Security Metrics V1.1.0, and Enisa Procure secure Service level Agreement Security conditions
20 | P a g e CWE List CSA Star Registry PCI DSS FedraMP Program
21 | P a g e Chapter IV Administrative processes First: Planning and Estimated Budgets • The company should define the bases and assumptions for preparing the estimated budgets in proportion to the requirements of the standard to ensure that the administrative reports are compatible with the financial reports. Second: Actuarial Operations • The actuarial operations related to the requirements of the standard consist of the following: