A Derivative Use Plan Is Not a Permissions List

The section everyone drafts most carefully is the section that matters least. Here is what the document is actually for.

Most derivative use plans open the same way. A list of instruments: interest rate swaps, caps, floors, swaptions, constant maturity swaps, credit default swaps, currency forwards, equity index futures, variance swaps, and the usual closing phrase about combinations and variations thereof.

That list gets drafted with real care. It feels like the part that matters, because it is the part that says what you are allowed to do.

It is the least important section in the document.

The instrument list is largely dictated by your domiciliary statute and the model regulation behind it. It is close to identical across life insurers of similar size and product mix, and any competent outside counsel can produce one in an afternoon. Nothing about it distinguishes a program that works from a program that is one personnel change away from an ugly surprise.

The distinguishing sections are the ones near the back, the ones that tend to get drafted last and reviewed least: management oversight, and internal controls, documentation and reporting standards. Those sections describe an operating process. Everything before them describes an inventory.

A plan built as an inventory is a permission slip. A plan built as a control structure is an operating document. The difference shows up the first time something goes wrong.

Three readers, not one

Part of why plans drift toward inventory is that most are written for a single reader: the examiner who will eventually ask for a copy. That reader is real, but they are not the only one, and writing for them alone produces a document that satisfies a request and guides no behavior.

There are three readers.

The board approves the plan and carries the responsibility. What the board needs is not a catalogue of instruments it will never evaluate. It needs enough to judge whether the risk measurement itself can be trusted, including where it falls short. A plan that tells the board only what management is permitted to do, without telling it how to assess the limits of the machinery producing the numbers, has handed the board accountability without the means to exercise it.

The examiner is reading for whether the controls described are controls that could actually operate. Named departments, named approvals, named frequencies. A plan that says risk will be "appropriately monitored" is describing an intention. A plan that says exposure is reported monthly by a specific function to a specific officer is describing a process.

And the person at the desk on a Tuesday afternoon, holding a trade order at a price that no longer looks reasonable, deciding what to do next. This is the reader almost nobody writes for, and the one whose behavior the document is supposed to govern.

Four things a control structure does

These are the tests I apply. A plan that passes them is doing work. A plan that fails them is a list.

1. It defines separation of duties functionally, not as an org chart

Most plans assert that duties are separated and attach a reporting structure. An org chart is not a control; it is a diagram of who reports to whom, and it survives entirely intact while the control it supposedly represents quietly stops working.

The functional test is different, and it is worth stating in exactly these terms:

The essence of this control is to ensure that persons trading Derivative Instruments do not have the ability to keep their actions from timely management oversight and verification.

That sentence is testable. You can hand it to an auditor and ask: is it true here? Separation of duties is then satisfied not by the shape of the org chart but by a specific condition, that back office, settlement, accounting and reconciliation are performed by a functional area other than the one trading. Two firms can have identical org charts and only one of them can answer that question.

2. It attaches a number to effectiveness

"The hedge will be monitored for effectiveness" is not a control. It is a sentence that will be true no matter what happens, which is what makes it useless.

Effectiveness has to be measured on a stated frequency, by a named function, against a stated method: a retrospective comparison between the change in hedged liabilities and the change in hedge assets, and a matching of current hedge assets against hedged liabilities to confirm the net position sits inside stated risk tolerances.

Stating the method matters more than the specific thresholds you choose, because the method is what makes the result arguable. A number someone can disagree with is a control. An adjective is not.

3. It says what happens when the trade does not get made

Every plan describes the path from identified risk to executed trade. Almost none describe the branch where the trade stops.

That branch is where the real risk lives. A trader holds an approved order. The cost of acquiring the instrument is no longer reasonable given current market conditions. What now? If the plan is silent, the answer is whatever that individual decides, and the decision leaves no record.

A control structure closes the loop: the trader convenes with the CIO and the hedging function, the order is amended, and the amended order goes back for re-approval. Nothing proceeds on one person's judgment, and the deviation is documented rather than absorbed. The same logic governs the plan's hardest line, that derivatives are not to be used for speculation, or in situations where the benefit is unclear. "Unclear" is a stopping condition, and stopping conditions need a defined next step or they will not be used.

4. It builds in a check the organization does not control

Internal review tells you whether people followed the process. It cannot tell you whether the process is sound, because the same assumptions are on both sides of the test.

So the plan needs at least one input the organization cannot mark its own homework on: an annual independent assessment of internal controls over derivative transactions, with exceptions reported to the board rather than resolved quietly at management level.

Valuation deserves the same treatment. Internal marks calculated through a vendor system, checked against a second vendor system, and then compared against the counterparty's own valuation, is not redundancy for its own sake. It is three independent answers to the same question, and disagreement among them is information.

The tell: whether it is connected to the liabilities

There is a faster way to judge a derivative use plan than reading it end to end. Look at the asset/liability management section and see whether it names the specific risks the derivatives exist to address.

Four of them recur in a life and annuity book.

Spread deficiency, the shortfall between what the asset portfolio earns and what is credited to corresponding liabilities, which bites hardest in falling rates. Disintermediation, assets liquidated at a loss, or borrowing required, to fund surrenders and loan utilization when rates rise sharply. Cash flow mismatch and liquidity risk, asset cash flows insufficient to fund surrenders and benefit claims, forcing sales at inopportune times. Accounting mismatch, assets and liabilities whose valuations move differently in response to the same rate, spread or market movement, so the economics are hedged and the reported results are not.

A plan that names these has been written by someone who thought about the liabilities. A plan that speaks generally about managing interest rate risk has been written by someone working from a form.

Worth stating plainly alongside them, and rarely stated at all:

There is no single risk measure or ALM methodology sufficient to capture the risk profile for a given asset/liability portfolio.

An admission like that is not weakness in a governance document. It is the sentence that justifies running several methods instead of one, and it gives the board the honest frame it needs to assess everything downstream of it.

Statutory limits are the floor, not the plan

Aggregate limits are the one place where the numbers are handed to you. For a Connecticut-domiciled insurer they currently run:

  • 7.5% of admitted assets, statement value of options, caps, floors and warrants not attached to another instrument, used in hedging
  • 6.5% of admitted assets, potential exposure of collars, swaps, forwards and futures used in hedging
  • 3% of admitted assets, statement value of options, caps and floors written in hedging transactions

Your own limits will differ; the statute that binds you is your domiciliary state's, and these are cited as an illustration rather than a standard. But the point holds regardless of the numbers: a plan that adopts the statutory ceiling as its risk appetite has not expressed a risk appetite. It has copied one. The ceiling tells you where the regulator stops you. It says nothing about where you should stop yourself, and that second number is the one the board is actually being asked to approve.

The same applies to counterparty exposure. The statute constrains aggregate concentration; it does not tell you what a reasonable minimum transfer amount is, whether collateral should be posted from the first dollar of exposure, or how often exposure should be reported and to whom. Those are choices, and choices are what a plan is for.

The test

Hand your derivative use plan to a competent person who was not in the room when it was written.

Can they tell who is permitted to authorize a trade, and who is not? Can they tell what happens when an approved order meets a market that has moved? Can they tell how effectiveness will be measured, how often, and by whom? Can they tell what would have to be true for the program to be judged as failing?

If yes, you have a control structure, and it will still work after the people who wrote it have moved on. If no, you have a permissions list, and it will hold up right until the moment you need it to.

Most plans I have read are closer to the second than their authors believe. The good news is that the fix is not a rewrite of the whole document. It is four sections, and they are the four nobody reads.


Scarborough Road works with insurers and asset managers on derivatives governance, hedging operations, and the investment data infrastructure that demonstrates the governance was followed. If you have a derivatives book and a regulator asking questions, that is the conversation to have.

This article draws on a model derivative use plan the author developed for a life insurance general account. It is general commentary on governance practice, not legal, actuarial or investment advice, and it is not a substitute for review by your own counsel against your domiciliary statute.

Previous
Previous

Git for the Middle Office

Next
Next

Write Down What You Are Not Hedging