2021-09-27

Added · Updated

Guidelines for Implementing IFRS 17 Insurance Contracts Requirements

The Central Bank mandates insurance companies operating in the sector to implement International Financial Reporting Standard No. 17 (IFRS 17) by establishing Board-approved policies for contract definition, aggregation, measurement, and disclosure. The guidelines require specific operational changes, including the use of the Premium Allocation Approach, General Measurement Model, or Variable Fee Approach, alongside rigorous IT system capabilities for data storage, actuarial calculations, and cybersecurity. Companies must also adhere to strict rules for sharing and storing information with third parties, ensuring data encryption, access control, and compliance with service level agreements. These requirements apply to all insurance companies to ensure optimal implementation and transparency of financial data.

Central Bank of Jordan logo

Jordan

Central Bank of Jordan

Click to view thumbnail

1 | P a g e Guidelines for Implementing Requirements of International Financial Reporting Standard No. (17) 2021

2 | P a g e Contents Page Introduction ................................................................................................................ (03) Chapter One: Implementing Requirements of IFRS 17 ..................................... (04) Chapter Two: IT Systems Operations Management .......................................................... (10) Chapter Three: Rules for Sharing and Storing Information with Third Parties ......................................... (12) Chapter Four: Administrative Operations ..................................................................................)18(

3 | P a g e Introduction The International Accounting Standards Board (IASB) issued a new standard regarding insurance contracts in May 2017, which was scheduled to start applying from 1/1/2021, replacing the currently applied International Financial Reporting Standard (4). In its meeting held on 14/11/2018, the IASB agreed to postpone the application of the standard by an additional year starting from 1/3/2020 and put the matter for public discussion. At that time, a vote was held to postpone the application of the standard requirements until 1/1/2023.

IFRS 17 represents a comprehensive review of accounting related to insurance contracts, which will enhance the transparency of the actual financial performance of insurance companies. It aims to make the financial statements of companies more accurate in measuring results and recognizing revenues and liabilities, and more comparable with other insurance companies.

The standard addresses the accounting aspects of contracts issued by insurance companies, and the impact of this standard varies depending on the type of contracts underwritten by each company. The greatest impact will be on long-term insurance contracts; however, the change will be fundamental for all insurance companies.

The implementation of the requirements in the new standard will lead to changes in insurance companies' operations, requiring them to change accounting treatment methods for insurance contracts, the mechanism for preparing and presenting financial reports, and the need for companies to modify and develop systems and restructure their operational processes. The IASB's procedures included new principles for recognizing expected losses and following a specific methodology for insurance contract accounting, which requires insurance companies to prepare policies, procedures, and decisions that ensure the company's ability to apply the standard requirements optimally.

IFRS 17 considers the time value of money when measuring insurance contract liabilities, showing them at the present value of future cash flows using a discount rate that reflects the risks faced by the company, which should be reviewed and updated periodically.

This guideline was prepared to assist insurance companies in implementing the requirements of IFRS 17, taking into account the complexity and specificity of different insurance companies' operations, as well as increasing the level of transparency and ensuring the presentation of appropriate and objective financial data. This guideline addresses the mechanisms and procedures to be followed by the boards of directors of insurance companies operating in the sector to implement the standard, in addition to clarifying the requirements of IT systems, information security, and the requirements for applying this standard and its direct impact on administrative operations. This is based on the Central Bank's interest in ensuring that insurance companies implement the standard optimally, and therefore insurance companies must observe the minimum requirements mentioned in this guideline.

4 | P a g e Chapter One Implementing Requirements of IFRS 17 First: Definition of a Contract • The company must prepare a policy approved by the Board of Directors enabling it to determine whether a contract falls under the definition of an insurance contract as stated in the standard. • The aforementioned policy must include, at a minimum, the following:

  • Definition of an insurance contract.
  • Identification of contracts issued by the company that conform to the definition of an insurance contract.
  • Identification of contracts issued by the company that do not conform to the definition of an insurance contract.
  • Definition of significant insurance risk.
  • Mechanism for determining the relative significance of insurance contract risks.

Second: Separation of Insurance Contract Components • The company must study the contracts it underwrites and ensure that there are no components in those contracts that do not conform to the standard. If such components exist, the company must ensure the possibility of separating those components and treating them according to the most relevant standard, based on a policy for separating insurance contract components approved by the Board of Directors. • The aforementioned policy must include, at a minimum, the following:

  • Mechanism for separating non-insurance components from the insurance contract.
  • Mechanism for identifying embedded guarantees and how to treat them, if any.
  • The most relevant standard to be applied to treat non-insurance components.
  • Mechanism for determining the relative significance of insurance contract components.

Third: Aggregation Level • The company must prepare a policy approved by the Board of Directors to aggregate insurance contracts within separate portfolios, which are classified and treated independently, divided into three levels as follows:

  1. Similar risks managed together.
  2. Underwriting year.
  3. Profitability.

• Level One (Similar Risks) Insurance companies must aggregate insurance contract portfolios based on the similarity of risks of those contracts, and at a minimum as follows:

  • Mandatory motor insurance portfolio.
  • Comprehensive motor insurance portfolio.
  • Bus fleet insurance portfolio.
  • Engineering insurance portfolio.
  • Insurance portfolios for tenders extending more than one year.
  • Other insurance contract portfolios based on the company's estimates and experience.

• Level Two (Underwriting Year) The company must classify insurance contract portfolios according to the classifications mentioned in Level One into groups based on the underwriting year (e.g., all contracts issued during 2020 are treated in a group independent of contracts issued in 2021, and so on).

• Level Three (Profitability) The company must classify the contract groups mentioned in Level Two into the classifications listed below, based on the expected net cash flows from the contract and the accounting methodology followed in treating contract groups, as will be indicated later in this guideline:

  • Contracts where there is no probability of becoming onerous at initial recognition.
  • Onerous contracts.
  • Other contracts - if any.

Fourth: Recognition of Contracts and Modifications • The company must recognize a group of insurance contracts from the following dates, whichever is earlier:

  • Start of the coverage period.
  • Due date of the first installment.
  • When the group of contracts becomes onerous.

• Regarding modifications that may occur to contracts, the company must prepare a policy approved by the Board of Directors, which must include at a minimum the following:

  • Contract modifications considered "significant" and the mechanism for treating those modifications.
  • Cases where recognition of the contract is cancelled and the mechanism used to treat it.

5 | P a g e Fifth: Future Cash Flows • Cash flows are defined as all amounts expected to be collected and paid resulting from insurance contracts. Their estimation at the recognition of an insurance contract must be based on an actuarial policy approved by the Board of Directors, including the company's assumptions and experience in managing the group of insurance contracts. Future cash flows must include, at a minimum, the following:

  1. Future Cash Inflows:
  • Underwritten premiums, considering the payment mechanism specified in the insurance contract.
  • Revenues related to the insurance contract, such as insurance contract issuance fees.
  • Revenues resulting from expected recoveries and salvage.
  1. Future Cash Outflows:
  • Best estimate of incurred claim costs and incurred but not reported (IBNR) claims.
  • Claims expected to be incurred, including payments resulting from non-separable non-insurance components.
  • Administrative expenses and employee costs related to insurance contracts.
  • Allocation of cash flows for acquisition costs.
  • Costs incurred in providing non-financial services (vehicle maintenance, home reconstruction).
  • Claim processing costs (loss adjusters, legal expenses).
  1. Future Cash Flows to be Excluded When Calculating Insurance Contract Profitability:
  • Cash flows arising from held reinsurance contracts, such as premiums received and interest paid on held balances.
  • Investment returns.
  • Cash flows that may arise from future insurance contracts.
  • Cash flows arising from components separated from the insurance contract.
  • Cash flows not related to the insurance contract portfolio.

• The company must consider the following aspects when setting assumptions related to estimating future cash flows for groups of insurance contracts:

  • Inherent risks.
  • Aggregation level.
  • Probability of natural disasters.
  • Probability of contract termination before the insurance coverage expiration date, and other expected practices of the contract holder.
  • Factors that will affect estimates and information sources for these factors.

Sixth: Acquisition Costs • The company must prepare a policy approved by the Board of Directors and evaluated by the company's appointed actuary, enabling it to allocate acquisition costs according to the group of insurance contracts and their treatment method. It must include, at a minimum, the following:

  • Mechanism for estimating acquisition costs when preparing budget estimates.
  • Mechanism for amortizing acquisition costs.

• The insurance company must defer the recognition of acquisition costs. Deferred acquisition costs must be proven in the statement of financial position and amortized according to the mechanism approved in the aforementioned policy.

Seventh: Discount Rate • The company must prepare a policy approved by the Board of Directors and evaluated by the company's appointed actuary to determine the discount rate. It must include, at a minimum, the following:

  • Determination of the mechanism followed in calculating the discount rate.
  • Mechanism for reviewing assumptions used in calculating the discount rate.
  • The discount rate must be consistent with the yield curve, reflecting the time value of money, characteristics of cash flows, and liquidity characteristics of insurance contracts.
  • The discount rate must be compatible with the currency in which contract liabilities are recorded.
  • Determination of the yield curve used to discount cash flows if using one of the methods dependent on the yield curve.
  • Mechanism for treating financing expense/income.

• The discount rate is applied to cash flows when calculating the following items:

  • Liabilities for incurred claims (claims expected to be settled within more than 12 months).
  • Liabilities for remaining coverage (General Method / Variable Fee Approach).

Eighth: Non-Financial Risk Adjustments • The company must prepare a policy approved by the Board of Directors to calculate non-financial risk adjustments for each group of insurance contracts as part of the risk management policy, evaluated by the company's appointed actuary. This policy must include, at a minimum, the following:

  • Definition of non-financial risks, such as risks of increases in claim values and expenses, excluding risks associated with inflation indices, which are considered financial risks.
  • Determination of the method to be followed in monitoring the value of non-financial risk adjustments.
  • Confidence level used to calculate the value of non-financial risk adjustments.

• The company must explicitly include the value of non-financial risk adjustments when calculating the following items:

  • Liabilities related to incurred claims.
  • Liabilities for remaining coverage (General Method / Variable Fee Approach).

Ninth: Contract Measurement Approaches • The standard has provided insurance companies with three approaches for measuring and treating insurance contracts and held reinsurance contracts accounting-wise, as follows:

  1. Premium Allocation Approach Applied to groups of insurance contracts listed below:
  • Those where the insurance coverage period does not exceed one year.
  • Those where the value of "Liabilities for Remaining Coverage" does not differ significantly from its value when applying the requirements of the General Method.

Considering the necessity of using a discount rate to calculate the present value of cash flows if the approach is applied to a group of contracts with a coverage period exceeding one year, according to the aforementioned exception.

  1. General Measurement Model (GMM) Applied to all insurance contracts. It requires measuring liabilities of groups of insurance contracts by discounting future "inflow and outflow" cash flows, then subtracting non-financial risk adjustments to arrive at the contractual service margin (unearned profit) for the group of insurance contracts.

  2. Variable Fee Approach (VFA) This is the approach through which some requirements of the General Method are modified to treat investment contracts that include a participation feature.

• The company must prepare a policy for measuring and treating insurance contracts and held reinsurance contracts, approved by the Board of Directors and evaluated by the company's appointed actuary. It must include, at a minimum, the following:

  • Insurance contracts to be treated according to the Premium Allocation Approach and/or General Method and/or Variable Fee Approach.
  • Mechanism for testing the applicability of the Premium Allocation Approach according to the level of materiality in cases where the coverage period is more than one year.
  • Mechanism for determining the level of materiality used in testing the application of the Premium Allocation Approach.

6 | P a g e Tenth: Disclosures In addition to what is mentioned in paragraphs 93 to 132 of the standard, the company must disclose, at a minimum, the following aspects in its financial statements:

• Reconciliations between opening and closing balances for the "Liabilities for Remaining Coverage" item, showing the present value of future cash flows, risk adjustments, contractual service margin, and financing expense/income for each portfolio separately. Additionally, the loss component must be clarified if there are onerous contracts within the groups of insurance contracts.

• Reconciliations between opening and closing balances for the "Liabilities for Incurred Claims" item, showing the present value of future cash flows, risk adjustments, and financing expense for each portfolio.

• Discount rates used in calculating the present value of future cash flows, the method used, and factors relied upon in calculating those rates, along with justifications for their adoption.

• Regarding the impact of transition to applying the standard, for contracts measured under the Modified Retrospective Approach or Fair Value Approach upon transition to IFRS 17, disclosure must be made of the contractual service margin reconciliation and insurance revenue amounts separately for contracts under each approach, in addition to justifications for using those approaches.

• Contracts issued by the company that do not meet the standard's requirements.

• Management estimates regarding assumptions used in the following aspects:

  • Estimation of cash flows.
  • Aggregation level.
  • Testing the application of the Premium Allocation Approach to contracts with a coverage period exceeding one year.
  • Non-financial risk adjustments.
  • Mechanism for treating acquisition costs.
  • Separation of insurance contracts.
  • Method for treating financing expense/income.
  • Accounting methods used for each portfolio separately.
  • Any changes in assumptions used for the items mentioned above.

7 | P a g e Chapter Two IT Systems Operations Management First: Management of the IT Systems Project for Implementing Standard Requirements • To enable the company to manage the project more efficiently and effectively, the company must prepare a work plan approved by the Board of Directors, consistent with the nature of the company's business and the complexity of the standard's requirements. This plan must include the distribution of tasks and responsibilities for approval and control over project implementation stages, the preparation of necessary reports, and risk assessment throughout the project period.

• When preparing the aforementioned work plan, the company must, at a minimum, consider the following aspects:

  1. Adequacy and efficiency of available resources (expertise, liquidity, human resources, etc.), including IT system provider resources to execute the project effectively.
  2. Coordination between different company departments related to implementing the standard's requirements.
  3. Study of the aspects that must be present in the IT system related to the standard's requirements, consistent with the nature of the company's business.
  4. Adequacy of control and security controls used in the IT system to mitigate cybersecurity risks or data breaches.
  5. Determination of administrative reports needed by the company to evaluate its performance, in addition to determining the frequency of extracting those reports.
  6. Ability to retrieve data existing with IT system providers in a timely manner.
  7. Keeping backup copies in a secure and accessible location when needed, and a mechanism for inspecting them.
  8. Appropriate disaster recovery procedures and testing them periodically.

Second: IT Systems • When the Board of Directors approves an IT system provider, the company must ensure the system's ability to process the following aspects, at a minimum:

  • Storing and archiving data at the contract level.
  • Aggregating contracts according to required levels - mentioned in Chapter Four - to separate non-insurance components from the insurance contract.
  • Ability to apply all requirements of the accounting measurement method used and suitable for the nature of the company's business.
  • Automatically estimating future cash flows to evaluate insurance contract liabilities, with actuarial assumptions for cash flow estimates fixed in the system.
  • Calculating the present value of future cash flows according to the discount rate policy approved by the Board of Directors.
  • Calculating the value of non-financial risk adjustments and contractual service margin according to actuarial assumptions.
  • Managing held reinsurance contract operations separately.
  • Preparing financial reports and related disclosures, in addition to administrative reports.
  • Treating changes in actuarial assumptions used in the subsequent measurement stage of groups of insurance contracts.
  • A list of account names and numbers included in the ledger according to standard requirements.
  • A list of technical accounting entries for each approved method for measuring insurance contract liabilities (and reinsurance contract assets, in addition to all accounting entries related to insurance contract revenues and expenses according to the aforementioned standard requirements).

• Considering what is stated in prevailing relevant legislation, the company's Board of Directors must take into account the following aspects regarding IT systems audit operations:

  • Ensuring that internal audit staff are sufficiently familiar with best practices for IT systems auditing and the requirements necessary to implement the standard's requirements.
  • Providing the Central Bank with an IT systems audit report prepared by the internal audit department, including all related documents and verifying the adequacy of adopted internal control systems. The report must show the scope and methodology of the audit, summary of results, and corrective actions annually.

8 | P a g e Chapter Three Rules for Sharing and Storing Information with Third Parties First: Minimum Rules to be Complied With When Sharing and Storing Information with a Third Party: Contractual and Legal Aspects The company must use a risk-based assessment method to determine data stored or processed outside the company, according to the nature, classification, and degree of data risks, while complying with prevailing relevant legislation.

  1. The IT system service provider and/or third party must be well-known and reputable, and must not have improper practices with entities it works or has worked with.
  2. Concluding Service Level Agreements (SLA) and Non-Disclosure Agreements (NDA) with the IT system service provider and/or third party. The agreements must define the standards by which operations are executed by the IT system service provider and/or third party, and must include penalty clauses and fines for any action or omission violating information privacy and security.
  3. Maintaining information confidentiality, including compliance with the provisions of information confidentiality according to Insurance Business Regulation Law No. (12) of 2021 and related legislation.
  4. Ensuring that the IT system service provider and/or third party adopts sufficient control measures to enable it to fulfill its contractual and legal obligations, such as maintaining data confidentiality and preparing compliance reports for security and control controls.
  5. Establishing incident response procedures to ensure effective and timely handling of all incidents that data may be exposed to.
  6. The company may use cloud computing services directly from the service provider or through an intermediary. In case of dealing with an intermediary, the company must apply all requirements and control and security measures applied to the service provider.
  7. The company must evaluate the efficiency and effectiveness of cloud computing services and their compatibility with information security requirements.
  8. Ensuring information privacy requirements upon contract expiration or cancellation with the service provider or intermediary, or transfer to another service provider. All data, including backup data, must be deleted after delivery to the company.

Data Access Management Identity verification and logical access mechanisms must be used to access data stored with the IT system service provider and/or third party. Broad access rights leading to the possibility of any unauthorized device/user accessing data are prohibited.

  1. Establishing a secure and encrypted communication channel via VPN (Virtual Private Network) when the connection is Site-to-Site.
  2. Not using sensitive protocols such as (RDP, SSH) via the internet without sufficient control measures and compliance, which leads to their use in non-suggested ways to access data.

Data Protection Ensure that data stored with the IT system service provider and/or third party is kept isolated from other participants' data through necessary isolation mechanisms such as Multi-Tenant Environments.

  1. The company must encrypt data during the data transfer process through the network and when storing it on servers and/or storage units and backups, considering the use of secure and accepted encryption algorithms and protocols.
  2. Establishing appropriate control measures on encryption keys. If the IT system service provider and/or third party is granted access rights to encryption keys, the responsibility for data lies with the company.
  3. Ensuring that the systems/services of the IT system service provider and/or third party are not exposed to any of the OWASP Top Ten threats.
  4. Protecting all systems via Anti-Malware/Anti-Virus and Intrusion Prevention System to prevent any interference or activity causing damage to data.
  5. Using Web Application Firewall to reduce or stop attacks on web applications and existing vulnerabilities.
  6. Ensuring the enhancement of data security and protection controls (System Hardening) for all applications, systems, and devices according to best practices.

9 | P a g e Physical Protection The company and the IT system service provider and/or third party must keep servers and devices related to IT infrastructure in a secure location.

  1. Ensuring protection from external threats.
  2. Ensuring the provision of backups and a business continuity plan to sustain the company's operations.
  3. Ensuring the existence of a disaster recovery plan including all potential disaster scenarios, and testing them periodically.

Protection of Identity and Authentication Elements

  1. Using Two-Factor Authentication for all accounts to enhance protection when using usernames and passwords.
  2. The use of built-in Administrator accounts is prohibited. They must be kept in a secure location and used only for work requiring them and in emergency cases. They should be replaced with accounts having privileges that meet work needs (Least Privileges).
  3. The use of Shared Accounts is prohibited. Usernames and passwords must be created according to the Least Privilege principle, and tasks and privileges must be separated.
  4. Applying best practices in password policies and standards and session management.
  5. Protecting passwords and Application Programming Interface (API) security keys and changing them periodically.

Security Logs and Auditing

  1. Ensuring the activation of security event logs and alerts, ensuring that created records include the account, event, date, time, and other matters. Logs must be reviewed to monitor and detect suspicious movements and identify abnormal activities.
  2. The IT system service provider and/or third party must notify and inform the company in case of any other party requesting access to data.
  3. Timely access to logs necessary for auditing and criminal investigations, and reporting information related to data or company-specific applications.

10 | P a g e Second: Minimum Guideline Rules Recommended to Adopt: Contractual and Legal Aspects

  1. The company or IT system service provider and/or third party must conduct Vulnerability Assessment and Penetration Testing periodically. If the service provider conducts those tests, a report of the results must be provided to the company.
  2. Conducting Scenario-Based Risk Assessment and Planning Activity periodically for the purpose of:
  • Identifying ways that may allow unauthorized access to data.
  • Analyzing the effectiveness of current prevention and detection controls to mitigate the probability of unauthorized data access.
  • Analyzing the probability and impact of Plausible and Significant Attack Vectors according to the control measures used.
  • Analyzing the effectiveness of response controls used to mitigate the impact of Plausible and Significant Attack Vectors.
  • Determining the need for additional preventive or detective controls.
  1. Availability of appropriate qualifications and expertise for the IT system service provider and/or third party and the team responsible for managing the company's data to ensure they perform their tasks efficiently and effectively.

Data Access Management

  1. Establishing appropriate control measures in a restricted manner to manage data access processes (i.e., Restricted Access), activating and using public access rights (Access Global) for the network.
  2. Using Mutual Authentication or Two-Factor Authentication to allow access to stored data.

Data Protection Consider that the encryption process follows the (Safe-Fail) principle, such that...