Every answer and its explanation appears here once you have finished the path. Each one then links to the matching glossary entry, where the concept is set out in full with its worked example.
1. An insurer aggregates the capital charges of its various risks, underwriting, market, credit and operational, and gets a total lower than their arithmetic sum. Where does the gap come from?
From aggregation by correlations, which recognises that risks do not all materialise together
The solvency capital requirement is the amount of own funds a European insurer must hold to absorb exceptional losses and meet its commitments with a probability of 99.5 percent over a one year horizon. The equivalent phrasing helps grasp what the figure means: surviving a shock whose severity would be exceeded only once in two hundred years. It covers all quantifiable risks, and it is the aggregation that produces the effect the question describes. Adding up each risk's charge would assume they all materialise in the same year, which is neither observed nor plausible: a market crash and a record claims year are not the same event. The regime therefore aggregates while accounting for correlations between modules, and the resulting total falls below the sum of the parts. This diversification benefit is not a favour, it is the quantified translation of a fact, and it explains why an insurer spread across several lines and territories carries proportionally less capital than a concentrated one. Its counterpart is that everything rests on the correlations assumed: where these tighten in extreme scenarios, the counted benefit evaporates at the very moment it was meant to serve.
Glossary entry · scr2. The standard formula computes required capital by risk module, then aggregates them with correlation matrices set by regulation. What postulates does that procedure assume, and what becomes of them facing a systemic risk such as cyber?
Moderate, stable correlations and losses estimable from history: both give way when tail dependence approaches one
The standard formula is the method available to insurers without an approved internal model. It breaks risk into modules: market with its equity, interest rate, property, currency and spread sub modules, counterparty default, life, health and non life underwriting, and operational risk. Each module receives a charge, then the whole is aggregated by matrix multiplication using predefined correlations. Two postulates carry the entire structure without being stated up front, and naming them is the substance of the question. The first holds that correlations between risks are moderate and stable over time. The second holds that loss distributions can be estimated from sufficiently long historical data. A risk with a systemic component defeats both at once. Its tail dependence approaches one in extreme scenarios, since a single event reaches thousands of insureds together, contradicting the first postulate exactly when it matters. And its history is too short and too unstable to credibly calibrate a one in two hundred year tail, contradicting the second. Concretely, the standard formula provides no dedicated cyber underwriting module: the risk is diluted into the non life module on generic factors, and its operational side is handled on a flat, capped basis.
Glossary entry · formule-standard-s23. An insurer may replace the standard formula with an internal model calibrated on its own profile, subject to supervisory approval. What justifies making that approval so demanding?
The model often lowers the capital requirement, so an under calibrated model would weaken solvency with nothing to flag it
An internal model replaces the regulation's uniform parameters with the firm's own model, calibrated on its actual exposure, and it may be full or partial, the latter covering only modules judged poorly represented by the standard formula. Its appeal is twofold. It better reflects the economic reality of the risks carried, and it often lowers the capital requirement where the insurer's profile is better than the formula's assumed average. It is precisely that second property which commands the strictness of approval, and the reasoning is worth following through: an under calibrated model produces an artificially low requirement, the insurer looks solvent, and nothing in its returns betrays the error since the reference figure itself comes from the faulty model. The gap would surface only at the loss, which is to say too late. Approval therefore requires demonstrating data quality, methodological robustness, and one thing often forgotten when it is cited: the model's effective use in running the business, known as the use test. A model built solely for the regulatory calculation and ignored in operational decisions is refused on that ground. For emerging risks, an internal model offers valuable flexibility against an ill suited formula, but it shifts onto the insurer the burden of correctly calibrating what nobody yet knows well.
Glossary entry · modele-interne-solvabilite-24. The European prudential regime adds a forward looking exercise to the capital calculation, the responsibility of management and the board rather than the actuaries alone. What does it add that the calculation does not, and what is its own weakness?
It takes in risks no formula anticipates, over a multi year horizon, and its quality depends entirely on how seriously the scenarios are chosen
Where the capital requirement imposes a standardised calculation at a point in time, the own risk and solvency assessment asks each insurer to appraise its own risks and overall solvency need, taking in its strategy and a multi year horizon. It is an exercise in governance as much as in calculation, and the fact that management and the board carry responsibility for it is no procedural detail: it is what stops it being an actuaries' document nobody reads. It rests largely on stress tests and adverse scenarios, including scenarios no regulatory formula anticipates, and that is where emerging risks find their place. An insurer exposed to digital accumulation can test its balance sheet there against a simultaneous outage of several providers, when the standard formula offers no module for doing so. Its strength is therefore to admit uncertainty and judgment where the formula reaches its limits. Its weakness is the exact reverse of that strength, and deserves naming just as plainly: the exercise is subjective, and its worth does not exceed that of the scenarios the firm chose to run. A comfortable scenario yields a comfortable conclusion, with no formal check noticing.
Glossary entry · orsa5. To estimate the capital a book needs, an insurer simulates a million possible years and reads off the distribution the loss only the worst years exceed. What bounds the reliability of that figure?
The distributions and dependencies fed in, which more draws never correct
Monte Carlo simulation estimates the distribution of an uncertain quantity by generating a very large number of random scenarios and observing how the results fall. Where complexity forbids an analytical calculation, because several sources of uncertainty interact non linearly, one draws thousands or millions of possible futures and reads off the quantiles. The method has become central to internal solvency models, catastrophe models and extreme risk measures, and its power lies in its flexibility: almost any probabilistic problem yields to it. Its limit sits elsewhere than intuition looks for it, and that is the whole point of the question. Raising the number of draws reduces sampling error, the error arising from the randomness of the simulation itself, and that error is generally the smaller of the two. It does nothing to specification error, which comes from the distributions and above all the dependency structures fed in. A million draws from a wrong dependency yields a wrong answer with great apparent precision, and the precision displayed is then misleading rather than reassuring. Where those assumptions are poorly known, as with digital accumulation, the outputs call for particular caution.
Glossary entry · simulation-monte-carlo6. The heavy use of the Gaussian copula in 2000s finance contributed to the misjudgment of risk at the heart of the 2008 crisis. What did that dependency structure understate?
Tail dependence: risks barely correlated in normal times materialise together in extreme scenarios
A copula is a function linking the individual distributions of several variables to their joint distribution, isolating the dependency structure that binds them independently of their own laws. Sklar's theorem guarantees such a decomposition always exists, which explains the tool's flexibility: one can choose each risk's distribution and the way they move together separately. For insurance the stakes are decisive, because dependence, and still more dependence in extreme events, is exactly what sets the scale of an accumulation. A good copula captures the fact that risks independent in ordinary times become strongly correlated in a crisis. The Gaussian copula fails precisely there, and that is the distinction to keep: it can reproduce a correct average correlation while assigning near zero probability to extremes occurring together. The stated parameter looks reasonable, and yet the tail of the joint distribution is empty. Its heavy use for structured products backed by residential credit thus suggested a diversification that did not exist, until the defaults proved simultaneous. The lesson carries to cyber, where dependencies between insureds are many, hidden and non stationary: the choice of dependency structure there is a critical and unresolved question.
Glossary entry · copule7. To price, an actuary separately estimates the influence of sector, size and the presence of multifactor authentication on claim frequency. Why is this family of models still preferred to more powerful learning methods?
For its transparency: each factor's own effect stays readable and defensible before a regulator
The generalized linear model extends linear regression to variables that do not follow a normal distribution, which is exactly the case for insurance quantities: claim frequency is often modelled by a Poisson law, severity by a gamma law. A link function connects the prediction to the explanatory variables, and the model estimates each risk factor's own influence, all else being equal. That last point is what made it the standard of non life pricing: it isolates the effect of industry sector from that of size, and states how far the presence of a security control shifts expected frequency, separately from everything else. The reason it holds its ground against more powerful learning methods is not raw performance, and it would be wrong to claim so. It is readability: a coefficient can be explained, discussed and defended before a regulator, where an opaque model gives a prediction without accounting for it. That quality matters internally too, for understanding one's own book rather than merely bearing it. The limit shows on new risks, where sparse and unstable data weaken the estimates and force statistics to be supplemented by expert judgment.
Glossary entry · modele-lineaire-generalise8. During Hurricane Ian in 2022, the main vendors' catastrophe models understated insured losses by roughly thirty to forty percent, and the error hit insurers, reinsurers and insurance linked funds together. What does that simultaneity reveal?
Model risk turned systemic: the same shared representations make the same errors shared
Model risk is the exposure to losses or wrong decisions caused by the failure of the model representing a phenomenon. It takes three forms worth separating. Specification, when the mathematical structure is unsuited to the phenomenon, a normal tail where extremes are fat, for instance. Calibration, when the model is well specified but fitted on insufficient, unrepresentative or outdated data, which is the central problem climate change poses to catastrophe models. Use, when the model is taken outside its domain of validity or its implicit assumptions escape those relying on it. The question bears on a fourth dimension, not a fourth form but an effect of scale, and the most counterintuitive one. Catastrophe model supply is concentrated among a small number of vendors, and when a whole market uses the same representations and the same calibration scenarios, portfolios share the same estimation errors. An outcome that defies the dominant models therefore does not strike one unlucky insurer, it strikes the entire market at the same moment, and the diversification across counterparties everyone assumed does not operate. Climate non stationarity compounds the effect by progressively outdating every model fitted on history.
Glossary entry · risque-de-modele