Industry Comparison
Select Language
Current language: English (2023)
You are viewing information about the following Industries:
-
Software & IT Services
The Software & Information Technology (IT) Services industry offers products and services globally to retail, business and government customers, and includes entities that develop and sell applications software, infrastructure software and middleware. The industry generally is competitive but with dominant players in some segments. Although relatively immature, the industry is characterised by high-growth entities that place a heavy emphasis on innovation and depend on human and intellectual capital. The industry also includes IT services entities delivering specialised IT functions, such as consulting and outsourced services. New industry business models include cloud computing, software as a service, virtualisation, machine-to-machine communication, big data analysis and machine learning. Additionally, brand value is important for entities in the industry to scale and achieve network effects, whereby wide adoption of a particular software product may result in self-perpetuating growth in sales. -
Insurance
The Insurance industry provides both traditional and non-traditional insurance-related products. Traditional policy lines include property, life, casualty and reinsurance. Non-traditional products include annuities, alternative risk transfers and financial guarantees. Entities in the insurance industry also engage in proprietary investments. Insurance entities generally operate within a single segment in the industry, for example, property and casualty, although some large insurance entities have diversified operations. Similarly, entities may vary based on the level of their geographical segmentation. Whereas large entities may underwrite insurance premiums in many countries, smaller entities generally operate in a single country or jurisdiction. Insurance premiums, underwriting revenue and investment income drive industry growth, while insurance claim payments present the most significant cost and source of uncertainty for profits. Insurance entities provide products and services that enable the transfer, pooling and sharing of risk necessary for a well-functioning economy. Insurance entities, through their products, can also create a form of moral hazard, reducing incentives to improve underlying behaviour and performance, and thus contributing to sustainability-related impacts. Like other financial institutions, insurance entities face risks associated with credit and financial markets. Within the industry, regulators have identified entities that engage in non-traditional or non-insurance activities, including credit default swaps (CDS) protection and debt securities insurance, as being more vulnerable to financial market developments, and therefore more likely to amplify or contribute to systemic risk. As a result, some insurance entities may be designated as Systemically Important Financial Institutions, thus exposing them to increased regulation and oversight.
Relevant Issues for both Industries (9 of 26)
Why are some issues greyed out?
The SASB Standards vary by industry based on the different sustainability-related risks and opportunities within an industry. The issues in grey were not identified during the standard-setting process as the most likely to be useful to investors, so they are not included in the Standard. Over time, as the ISSB continues to receive market feedback, some issues may be added or removed from the Standard. Each company determines which sustainability-related risks and opportunities are relevant to its business. The Standard is designed for the typical company in an industry, but individual companies may choose to report on different sustainability-related risks and opportunities based on their unique business model.-
Environment
- GHG Emissions
- Air Quality
-
Energy Management
The category addresses environmental impacts associated with energy consumption. It addresses the company’s management of energy in manufacturing and/or for provision of products and services derived from utility providers (grid energy) not owned or controlled by the company. More specifically, it includes management of energy efficiency and intensity, energy mix, as well as grid reliance. Upstream (e.g., suppliers) and downstream (e.g., product use) energy use is not included in the scope. - Water & Wastewater Management
- Waste & Hazardous Materials Management
- Ecological Impacts
-
Social Capital
- Human Rights & Community Relations
-
Customer Privacy
The category addresses management of risks related to the use of personally identifiable information (PII) and other customer or user data for secondary purposes including but not limited to marketing through affiliates and non-affiliates. The scope of the category includes social issues that may arise from a company’s approach to collecting data, obtaining consent (e.g., opt-in policies), managing user and customer expectations regarding how their data is used, and managing evolving regulation. It excludes social issues arising from cybersecurity risks, which are covered in a separate category. -
Data Security
The category addresses management of risks related to collection, retention, and use of sensitive, confidential, and/or proprietary customer or user data. It includes social issues that may arise from incidents such as data breaches in which personally identifiable information (PII) and other user or customer data may be exposed. It addresses a company’s strategy, policies, and practices related to IT infrastructure, staff training, record keeping, cooperation with law enforcement, and other mechanisms used to ensure security of customer or user data. - Access & Affordability
- Product Quality & Safety
- Customer Welfare
-
Selling Practices & Product Labeling
The category addresses social issues that may arise from a failure to manage the transparency, accuracy, and comprehensibility of marketing statements, advertising, and labeling of products and services. It includes, but is not limited to, advertising standards and regulations, ethical and responsible marketing practices, misleading or deceptive labeling, as well as discriminatory or predatory selling and lending practices. This may include deceptive or aggressive selling practices in which incentive structures for employees could encourage the sale of products or services that are not in the best interest of customers or clients.
-
Human Capital
- Labour Practices
- Employee Health & Safety
-
Employee Engagement, Diversity & Inclusion
The category addresses a company’s ability to ensure that its culture and hiring and promotion practices embrace the building of a diverse and inclusive workforce that reflects the makeup of local talent pools and its customer base. It addresses the issues of discriminatory practices on the bases of race, gender, ethnicity, religion, sexual orientation, and other factors.
-
Business Model and Innovation
-
Product Design & Lifecycle Management
The category addresses incorporation of environmental, social, and governance (ESG) considerations in characteristics of products and services provided or sold by the company. It includes, but is not limited to, managing the lifecycle impacts of products and services, such as those related to packaging, distribution, use-phase resource intensity, and other environmental and social externalities that may occur during their use-phase or at the end of life. The category captures a company’s ability to address customer and societal demand for more sustainable products and services as well as to meet evolving environmental and social regulation. It does not address direct environmental or social impacts of the company’s operations nor does it address health and safety risks to consumers from product use, which are covered in other categories. - Business Model Resilience
- Supply Chain Management
- Materials Sourcing & Efficiency
-
Physical Impacts of Climate Change
The category addresses the company’s ability to manage risks and opportunities associated with direct exposure of its owned or controlled assets and operations to actual or potential physical impacts of climate change. It captures environmental and social issues that may arise from operational disruptions due to physical impacts of climate change. It further captures socio-economic issues resulting from companies failing to incorporate climate change consideration in products and services sold, such as insurance policies and mortgages. The category relates to the company’s ability to adapt to increased frequency and severity of extreme weather, shifting climate, sea level risk, and other expected physical impacts of climate change. Management may involve enhancing resiliency of physical assets and/or surrounding infrastructure as well as incorporation of climate change-related considerations into key business activities (e.g., mortgage and insurance underwriting, planning and development of real estate projects).
-
-
Leadership and Governance
- Business Ethics
-
Competitive Behaviour
The category covers social issues associated with existence of monopolies, which may include, but are not limited to, excessive prices, poor quality of service, and inefficiencies. It addresses a company’s management of legal and social expectation around monopolistic and anti-competitive practices, including issues related to bargaining power, collusion, price fixing or manipulation, and protection of patents and intellectual property (IP). - Management of the Legal & Regulatory Environment
- Critical Incident Risk Management
-
Systemic Risk Management
The category addresses the company’s contributions to or management of systemic risks resulting from large-scale weakening or collapse of systems upon which the economy and society depend. This includes financial systems, natural resource systems, and technological systems. It addresses the mechanisms a company has in place to reduce its contributions to systemic risks and to improve safeguards that may mitigate the impacts of systemic failure. For financial institutions, the category also captures the company’s ability to absorb shocks arising from financial and economic stress and meet stricter regulatory requirements related to the complexity and interconnectedness of companies in the industry.
Disclosure Topics
What is the relationship between General Issue Category and Disclosure Topics?
The General Issue Category is an industry-agnostic version of the Disclosure Topics that appear in each SASB Standard. Disclosure topics represent the industry-specific impacts of General Issue Categories. The industry-specific Disclosure Topics ensure each SASB Standard is tailored to the industry, while the General Issue Categories enable comparability across industries. For example, Health & Nutrition is a disclosure topic in the Non-Alcoholic Beverages industry, representing an industry-specific measure of the general issue of Customer Welfare. The issue of Customer Welfare, however, manifests as the Counterfeit Drugs disclosure topic in the Biotechnology & Pharmaceuticals industry.-
Access Standard
-
Energy Management
The category addresses environmental impacts associated with energy consumption. It addresses the company’s management of energy in manufacturing and/or for provision of products and services derived from utility providers (grid energy) not owned or controlled by the company. More specifically, it includes management of energy efficiency and intensity, energy mix, as well as grid reliance. Upstream (e.g., suppliers) and downstream (e.g., product use) energy use is not included in the scope.-
Environmental Footprint of Hardware Infrastructure
With the growth of cloud-based service offerings, entities in this industry own, operate or rent increasingly more data centres and other hardware. Thus, managing the energy and water use associated with IT hardware infrastructure is relevant to value creation. Data centres must be powered continuously, and disruptions to the energy supply can have a material effect on operations, depending on the magnitude and timing of the disruption. Entities face a trade-off between energy and water consumption because of data centre cooling needs. Cooling data centres with water instead of chillers improves energy efficiency, but this method may create dependence on significant local water resources. Data centre specification decisions are important for managing costs, obtaining a reliable supply of energy and water, and reducing reputational risks, particularly with the increasing global regulatory focus on climate change and the opportunities arising from energy efficiency and renewable energy innovations.
-
-
Customer Privacy
The category addresses management of risks related to the use of personally identifiable information (PII) and other customer or user data for secondary purposes including but not limited to marketing through affiliates and non-affiliates. The scope of the category includes social issues that may arise from a company’s approach to collecting data, obtaining consent (e.g., opt-in policies), managing user and customer expectations regarding how their data is used, and managing evolving regulation. It excludes social issues arising from cybersecurity risks, which are covered in a separate category.-
Data Privacy & Freedom of Expression
As Software & IT Services entities increasingly deliver products and services over the Internet and through mobile devices, they must carefully manage two separate and often conflicting priorities. First, entities use customer data to innovate and provide customers with new products and services to generate revenues. Second, entities have access to a wide range of customer data, such as personal, demographic, content and behavioural data creating associated privacy concerns. This dynamic may result in increased regulatory scrutiny in many countries. The delivery of cloud-based software and IT services also raises concerns about potential access to user data by governments that may use it to limit the citizens’ freedoms. Effective management in this area may reduce regulatory and reputational risks that may result in decreased revenues, reduced market share and increased regulatory actions involving potential fines and other legal costs.
-
-
Data Security
The category addresses management of risks related to collection, retention, and use of sensitive, confidential, and/or proprietary customer or user data. It includes social issues that may arise from incidents such as data breaches in which personally identifiable information (PII) and other user or customer data may be exposed. It addresses a company’s strategy, policies, and practices related to IT infrastructure, staff training, record keeping, cooperation with law enforcement, and other mechanisms used to ensure security of customer or user data.-
Data Security
Software & IT Services entities are targets of growing data security threats from cyberattacks, which puts their own data and their customers’ data at risk. Inadequate prevention, detection and remediation of data security threats may influence customer acquisition and retention and result in decreased market share and reduced demand for the entity’s products. In addition to reputational damage and increased customer turnover, data breaches also may result in increased expenses, commonly associated with remediation efforts such as identity protection offerings and employee training on data protection. Meanwhile, new and emerging data security standards and regulations may affect operating expenses through increased compliance costs. Additionally, entities in this industry may be well-positioned to capture revenue opportunities by providing secure software and services to meet the demand for ensuring data is kept secure.
-
-
Selling Practices & Product Labeling
The category addresses social issues that may arise from a failure to manage the transparency, accuracy, and comprehensibility of marketing statements, advertising, and labeling of products and services. It includes, but is not limited to, advertising standards and regulations, ethical and responsible marketing practices, misleading or deceptive labeling, as well as discriminatory or predatory selling and lending practices. This may include deceptive or aggressive selling practices in which incentive structures for employees could encourage the sale of products or services that are not in the best interest of customers or clients.None -
Employee Engagement, Diversity & Inclusion
The category addresses a company’s ability to ensure that its culture and hiring and promotion practices embrace the building of a diverse and inclusive workforce that reflects the makeup of local talent pools and its customer base. It addresses the issues of discriminatory practices on the bases of race, gender, ethnicity, religion, sexual orientation, and other factors.-
Recruiting & Managing a Global, Diverse & Skilled Workforce
Employees are important contributors to value creation in the Software & IT Services industry. Entities commonly find recruiting qualified employees to fill these positions difficult. A shortage in technically skilled employees can create intense competition to acquire highly skilled employees globally, contributing to high employee turnover rates. Some entities contribute to relevant education and training programmes to expand the availability of domestic, skilled employees. Entities offer significant monetary and non-monetary benefits to improve employee engagement and therefore retention and productivity. Initiatives to improve employee engagement and work-life balance may influence the recruitment and retention of a diverse workforce. Since the industry is characterised by relatively low representation from women and minority groups, efforts to recruit and develop globally diverse talent pools may address the talent shortage and improve the value of entity offerings. Greater workforce diversity is important for innovation and helps entities understand the needs of a diverse and global customer base.
-
-
Product Design & Lifecycle Management
The category addresses incorporation of environmental, social, and governance (ESG) considerations in characteristics of products and services provided or sold by the company. It includes, but is not limited to, managing the lifecycle impacts of products and services, such as those related to packaging, distribution, use-phase resource intensity, and other environmental and social externalities that may occur during their use-phase or at the end of life. The category captures a company’s ability to address customer and societal demand for more sustainable products and services as well as to meet evolving environmental and social regulation. It does not address direct environmental or social impacts of the company’s operations nor does it address health and safety risks to consumers from product use, which are covered in other categories.None -
Physical Impacts of Climate Change
The category addresses the company’s ability to manage risks and opportunities associated with direct exposure of its owned or controlled assets and operations to actual or potential physical impacts of climate change. It captures environmental and social issues that may arise from operational disruptions due to physical impacts of climate change. It further captures socio-economic issues resulting from companies failing to incorporate climate change consideration in products and services sold, such as insurance policies and mortgages. The category relates to the company’s ability to adapt to increased frequency and severity of extreme weather, shifting climate, sea level risk, and other expected physical impacts of climate change. Management may involve enhancing resiliency of physical assets and/or surrounding infrastructure as well as incorporation of climate change-related considerations into key business activities (e.g., mortgage and insurance underwriting, planning and development of real estate projects).None -
Competitive Behaviour
The category covers social issues associated with existence of monopolies, which may include, but are not limited to, excessive prices, poor quality of service, and inefficiencies. It addresses a company’s management of legal and social expectation around monopolistic and anti-competitive practices, including issues related to bargaining power, collusion, price fixing or manipulation, and protection of patents and intellectual property (IP).-
Intellectual Property Protection & Competitive Behaviour
Entities in the Software & IT Services industry spend a significant proportion of their revenues on IP protection, including acquiring patents and copyrights. Although IP protection is inherent to some entity business models and is an important driver of innovation, entities’ IP practices sometimes may be a contentious societal issue. Entities sometimes acquire patents and other IP protection to restrict competition and innovation, particularly if they are dominant market players. Because of software complexity, its abstract nature and increasing IP rights protection related to software, entities in the industry must navigate overlapping patent claims to operate. As a result, entities in the industry may find themselves constantly in litigation or subject to regulatory scrutiny either because of allegations of patent violations if they engage in unethical business practices, or are perceived as doing so, or because they engage in IP infringement litigation. Adverse legal or regulatory rulings related to antitrust and IP may expose entities in the industry to costly and lengthy litigations and potential monetary losses as a result. Such rulings also may affect an entity’s market share and pricing power if its patents or dominant position in important markets are challenged legally, with potentially significant effects on revenue. Therefore, entities that balance the protection of their IP and its use to spur innovation while ensuring their IP management and other business practices do not unfairly restrict competition, may reduce regulatory scrutiny and legal actions while protecting their market value.
-
-
Systemic Risk Management
The category addresses the company’s contributions to or management of systemic risks resulting from large-scale weakening or collapse of systems upon which the economy and society depend. This includes financial systems, natural resource systems, and technological systems. It addresses the mechanisms a company has in place to reduce its contributions to systemic risks and to improve safeguards that may mitigate the impacts of systemic failure. For financial institutions, the category also captures the company’s ability to absorb shocks arising from financial and economic stress and meet stricter regulatory requirements related to the complexity and interconnectedness of companies in the industry.-
Managing Systemic Risks from Technology Disruptions
With trends towards increased cloud computing and Software as a Service (SaaS), software and IT service providers must ensure they have robust infrastructure and policies in place to minimise disruptions to their services. Disruptions such as programming errors or server downtime may generate systemic risks, because computing and data storage functions move from individual entity servers in various industries to data centres of cloud-computing service providers. The risks are increased particularly if the affected customers are in sensitive sectors, such as financial institutions or utilities, which are considered critical national infrastructure. Entities’ investments in improving the reliability and quality of their IT infrastructure and services may attract and retain customers, thereby creating revenue and opportunities in new markets.
-
-
-
Access Standard
-
Energy Management
The category addresses environmental impacts associated with energy consumption. It addresses the company’s management of energy in manufacturing and/or for provision of products and services derived from utility providers (grid energy) not owned or controlled by the company. More specifically, it includes management of energy efficiency and intensity, energy mix, as well as grid reliance. Upstream (e.g., suppliers) and downstream (e.g., product use) energy use is not included in the scope.None -
Customer Privacy
The category addresses management of risks related to the use of personally identifiable information (PII) and other customer or user data for secondary purposes including but not limited to marketing through affiliates and non-affiliates. The scope of the category includes social issues that may arise from a company’s approach to collecting data, obtaining consent (e.g., opt-in policies), managing user and customer expectations regarding how their data is used, and managing evolving regulation. It excludes social issues arising from cybersecurity risks, which are covered in a separate category.None -
Data Security
The category addresses management of risks related to collection, retention, and use of sensitive, confidential, and/or proprietary customer or user data. It includes social issues that may arise from incidents such as data breaches in which personally identifiable information (PII) and other user or customer data may be exposed. It addresses a company’s strategy, policies, and practices related to IT infrastructure, staff training, record keeping, cooperation with law enforcement, and other mechanisms used to ensure security of customer or user data.None -
Selling Practices & Product Labeling
The category addresses social issues that may arise from a failure to manage the transparency, accuracy, and comprehensibility of marketing statements, advertising, and labeling of products and services. It includes, but is not limited to, advertising standards and regulations, ethical and responsible marketing practices, misleading or deceptive labeling, as well as discriminatory or predatory selling and lending practices. This may include deceptive or aggressive selling practices in which incentive structures for employees could encourage the sale of products or services that are not in the best interest of customers or clients.-
Transparent Information & Fair Advice for Customers
Insurance products play an important societal role in alleviating unexpected economic shocks, allowing individual policyholders to reduce the financial consequences of events such as illnesses, accidents and deaths. However, unclear insurance policies, ambiguous product terms and potentially misleading sales tactics may erode brand reputation, spur legal disputes, and reduce the number of services and products an entity can offer. Regulators may deem some policies overly complex and unsuitable for customers. Moreover, entities compete based on financial strength, price, brand reputation, services offered and customer relationships. Dissatisfied customers may reduce or avoid insurance coverage, potentially leading to negative financial outcomes such as personal bankruptcies. While financial regulators continue to emphasise consumer protection and accountability, entities that maintain transparent policy terms and sell products to customers best suited to them may better maintain their brand reputation, avoid regulatory scrutiny and protect shareholder value. Failure to inform customers about products in a clear and transparent manner may result in increased consumer complaints, customer churn, or regulatory fines and settlements.
-
-
Employee Engagement, Diversity & Inclusion
The category addresses a company’s ability to ensure that its culture and hiring and promotion practices embrace the building of a diverse and inclusive workforce that reflects the makeup of local talent pools and its customer base. It addresses the issues of discriminatory practices on the bases of race, gender, ethnicity, religion, sexual orientation, and other factors.None -
Product Design & Lifecycle Management
The category addresses incorporation of environmental, social, and governance (ESG) considerations in characteristics of products and services provided or sold by the company. It includes, but is not limited to, managing the lifecycle impacts of products and services, such as those related to packaging, distribution, use-phase resource intensity, and other environmental and social externalities that may occur during their use-phase or at the end of life. The category captures a company’s ability to address customer and societal demand for more sustainable products and services as well as to meet evolving environmental and social regulation. It does not address direct environmental or social impacts of the company’s operations nor does it address health and safety risks to consumers from product use, which are covered in other categories.-
Incorporation of Environmental, Social and Governance Factors in Investment Management
Insurance entities must invest capital to preserve accumulated premium revenues equivalent to expected policy claim pay-outs and maintain long-term asset-liability parity. Because environmental, social and governance (ESG) factors increasingly have a material impact on the performance of corporations and other assets, insurance entities increasingly must incorporate these factors into their investment management. Failure to address these issues may diminish risk-adjusted portfolio returns and limit an entity’s ability to issue claim payments. Entities, therefore, should enhance disclosure on how they incorporate ESG factors, including climate change and natural resource constraints, into the investment of policy premiums and how they affect the portfolio risk. -
Policies Designed to Incentivise Responsible Behaviour
Advances in technology and the development of new policy products have allowed insurance entities to limit claim payments while encouraging responsible behaviour. The industry is subsequently in a unique position to generate positive social and environmental externalities. Insurance entities can incentivise healthy lifestyles and safe behaviour as well as develop sustainability-related projects and technologies, such as those focused on renewable energy, energy efficiency and carbon capture. As the renewable energy industry continues to grow, insurance entities may seek related growth opportunities by underwriting insurance in this area. Additionally, policy clauses may encourage customers to incorporate environmental, social and governance (ESG) factors to mitigate overall underwriting portfolio risk, which may reduce insurance pay-outs over the long term. Therefore, disclosure on products related to energy efficiency and low carbon technology, as well as discussion of how entities incentivise health, safety or environmentally responsible actions or behaviours, may assist investors in assessing how insurance entities incentivise responsible behaviour. -
Financed Emissions
Entities participating in insurance activities face risks and opportunities related to the greenhouse gas emissions associated with those activities. Counterparties, borrowers or investees with higher emissions might be more susceptible to risks associated with technological changes, shifts in supply and demand and policy change which in turn can impact the prospects of a financial institution that is providing financial services to these entities. These risks and opportunities can arise in the form of credit risk, market risk, reputational risk and other financial and operational risks. For example, credit risk might arise in relation to financing clients affected by increasingly stringent carbon taxes, fuel efficiency regulations or other policies; credit risk might also arise through related technological shifts. Reputational risk might arise from financing fossil-fuel projects. Entities participating in insurance activities are increasingly monitoring and managing such risks by measuring their financed emissions. This measurement serves as an indicator of an entity’s exposure to climate-related risks and opportunities and how it might need to adapt its financial activities over time.
-
-
Physical Impacts of Climate Change
The category addresses the company’s ability to manage risks and opportunities associated with direct exposure of its owned or controlled assets and operations to actual or potential physical impacts of climate change. It captures environmental and social issues that may arise from operational disruptions due to physical impacts of climate change. It further captures socio-economic issues resulting from companies failing to incorporate climate change consideration in products and services sold, such as insurance policies and mortgages. The category relates to the company’s ability to adapt to increased frequency and severity of extreme weather, shifting climate, sea level risk, and other expected physical impacts of climate change. Management may involve enhancing resiliency of physical assets and/or surrounding infrastructure as well as incorporation of climate change-related considerations into key business activities (e.g., mortgage and insurance underwriting, planning and development of real estate projects).-
Physical Risk Exposure
Catastrophic losses associated with extreme weather events will continue to have a material, adverse effect on the Insurance industry. The extent of this effect may evolve as climate change increases the frequency and severity of both modelled and non-modelled natural catastrophes, including hurricanes, floods and droughts. Failure to appropriately understand environmental risks, and price them into the underwritten insurance products, may result in higher-than-expected claims on policies. Therefore, insurance entities that incorporate climate change considerations into their underwriting process for individual contracts, as well as the management of entity-level risks and capital adequacy, may be better positioned to create value over the long-term. Enhanced disclosure of an entity’s approach to incorporating these factors, in addition to quantitative data such as the probable maximum loss and total losses attributable to insurance pay-outs, may provide investors with the information necessary to assess current and future performance on this issue.
-
-
Competitive Behaviour
The category covers social issues associated with existence of monopolies, which may include, but are not limited to, excessive prices, poor quality of service, and inefficiencies. It addresses a company’s management of legal and social expectation around monopolistic and anti-competitive practices, including issues related to bargaining power, collusion, price fixing or manipulation, and protection of patents and intellectual property (IP).None -
Systemic Risk Management
The category addresses the company’s contributions to or management of systemic risks resulting from large-scale weakening or collapse of systems upon which the economy and society depend. This includes financial systems, natural resource systems, and technological systems. It addresses the mechanisms a company has in place to reduce its contributions to systemic risks and to improve safeguards that may mitigate the impacts of systemic failure. For financial institutions, the category also captures the company’s ability to absorb shocks arising from financial and economic stress and meet stricter regulatory requirements related to the complexity and interconnectedness of companies in the industry.-
Systemic Risk Management
Entities in the Insurance industry have the potential to pose, amplify or transmit a threat to the financial system. The size, interconnectedness and complexity of entities highlight the industry’s exposure to systemic risk. Regulators have identified entities that engage in non-traditional or non-insurance-related activities as being more vulnerable to financial market developments and subsequently more likely to contribute to systemic risk. As a result, entities may be designated as Systemically Important Financial Institutions. Central banking systems in various jurisdictions may subject such entities to stricter prudential regulatory standards and oversight. Such entities may face stricter limits on their risk-based capital, leverage, liquidity and credit exposure. In addition, regulators may require entities to maintain a plan for rapid and orderly dissolution in the event of financial distress. Regulatory compliance can be costly, and failure to meet qualitative and quantitative regulatory performance thresholds could lead to substantial penalties. To demonstrate how these risks are being managed, entities should disclose important aspects of their systemic risk management and their ability to meet stricter regulatory requirements.
-
-
General Issue Category
Remove
Software & IT Services
Access Standard
Remove
Insurance
Access Standard
Energy Management
-
Environmental Footprint of Hardware Infrastructure
With the growth of cloud-based service offerings, entities in this industry own, operate or rent increasingly more data centres and other hardware. Thus, managing the energy and water use associated with IT hardware infrastructure is relevant to value creation. Data centres must be powered continuously, and disruptions to the energy supply can have a material effect on operations, depending on the magnitude and timing of the disruption. Entities face a trade-off between energy and water consumption because of data centre cooling needs. Cooling data centres with water instead of chillers improves energy efficiency, but this method may create dependence on significant local water resources. Data centre specification decisions are important for managing costs, obtaining a reliable supply of energy and water, and reducing reputational risks, particularly with the increasing global regulatory focus on climate change and the opportunities arising from energy efficiency and renewable energy innovations.
Customer Privacy
-
Data Privacy & Freedom of Expression
As Software & IT Services entities increasingly deliver products and services over the Internet and through mobile devices, they must carefully manage two separate and often conflicting priorities. First, entities use customer data to innovate and provide customers with new products and services to generate revenues. Second, entities have access to a wide range of customer data, such as personal, demographic, content and behavioural data creating associated privacy concerns. This dynamic may result in increased regulatory scrutiny in many countries. The delivery of cloud-based software and IT services also raises concerns about potential access to user data by governments that may use it to limit the citizens’ freedoms. Effective management in this area may reduce regulatory and reputational risks that may result in decreased revenues, reduced market share and increased regulatory actions involving potential fines and other legal costs.
Data Security
-
Data Security
Software & IT Services entities are targets of growing data security threats from cyberattacks, which puts their own data and their customers’ data at risk. Inadequate prevention, detection and remediation of data security threats may influence customer acquisition and retention and result in decreased market share and reduced demand for the entity’s products. In addition to reputational damage and increased customer turnover, data breaches also may result in increased expenses, commonly associated with remediation efforts such as identity protection offerings and employee training on data protection. Meanwhile, new and emerging data security standards and regulations may affect operating expenses through increased compliance costs. Additionally, entities in this industry may be well-positioned to capture revenue opportunities by providing secure software and services to meet the demand for ensuring data is kept secure.
Selling Practices & Product Labeling
-
Transparent Information & Fair Advice for Customers
Insurance products play an important societal role in alleviating unexpected economic shocks, allowing individual policyholders to reduce the financial consequences of events such as illnesses, accidents and deaths. However, unclear insurance policies, ambiguous product terms and potentially misleading sales tactics may erode brand reputation, spur legal disputes, and reduce the number of services and products an entity can offer. Regulators may deem some policies overly complex and unsuitable for customers. Moreover, entities compete based on financial strength, price, brand reputation, services offered and customer relationships. Dissatisfied customers may reduce or avoid insurance coverage, potentially leading to negative financial outcomes such as personal bankruptcies. While financial regulators continue to emphasise consumer protection and accountability, entities that maintain transparent policy terms and sell products to customers best suited to them may better maintain their brand reputation, avoid regulatory scrutiny and protect shareholder value. Failure to inform customers about products in a clear and transparent manner may result in increased consumer complaints, customer churn, or regulatory fines and settlements.
Employee Engagement, Diversity & Inclusion
-
Recruiting & Managing a Global, Diverse & Skilled Workforce
Employees are important contributors to value creation in the Software & IT Services industry. Entities commonly find recruiting qualified employees to fill these positions difficult. A shortage in technically skilled employees can create intense competition to acquire highly skilled employees globally, contributing to high employee turnover rates. Some entities contribute to relevant education and training programmes to expand the availability of domestic, skilled employees. Entities offer significant monetary and non-monetary benefits to improve employee engagement and therefore retention and productivity. Initiatives to improve employee engagement and work-life balance may influence the recruitment and retention of a diverse workforce. Since the industry is characterised by relatively low representation from women and minority groups, efforts to recruit and develop globally diverse talent pools may address the talent shortage and improve the value of entity offerings. Greater workforce diversity is important for innovation and helps entities understand the needs of a diverse and global customer base.
Product Design & Lifecycle Management
-
Incorporation of Environmental, Social and Governance Factors in Investment Management
Insurance entities must invest capital to preserve accumulated premium revenues equivalent to expected policy claim pay-outs and maintain long-term asset-liability parity. Because environmental, social and governance (ESG) factors increasingly have a material impact on the performance of corporations and other assets, insurance entities increasingly must incorporate these factors into their investment management. Failure to address these issues may diminish risk-adjusted portfolio returns and limit an entity’s ability to issue claim payments. Entities, therefore, should enhance disclosure on how they incorporate ESG factors, including climate change and natural resource constraints, into the investment of policy premiums and how they affect the portfolio risk. -
Policies Designed to Incentivise Responsible Behaviour
Advances in technology and the development of new policy products have allowed insurance entities to limit claim payments while encouraging responsible behaviour. The industry is subsequently in a unique position to generate positive social and environmental externalities. Insurance entities can incentivise healthy lifestyles and safe behaviour as well as develop sustainability-related projects and technologies, such as those focused on renewable energy, energy efficiency and carbon capture. As the renewable energy industry continues to grow, insurance entities may seek related growth opportunities by underwriting insurance in this area. Additionally, policy clauses may encourage customers to incorporate environmental, social and governance (ESG) factors to mitigate overall underwriting portfolio risk, which may reduce insurance pay-outs over the long term. Therefore, disclosure on products related to energy efficiency and low carbon technology, as well as discussion of how entities incentivise health, safety or environmentally responsible actions or behaviours, may assist investors in assessing how insurance entities incentivise responsible behaviour. -
Financed Emissions
Entities participating in insurance activities face risks and opportunities related to the greenhouse gas emissions associated with those activities. Counterparties, borrowers or investees with higher emissions might be more susceptible to risks associated with technological changes, shifts in supply and demand and policy change which in turn can impact the prospects of a financial institution that is providing financial services to these entities. These risks and opportunities can arise in the form of credit risk, market risk, reputational risk and other financial and operational risks. For example, credit risk might arise in relation to financing clients affected by increasingly stringent carbon taxes, fuel efficiency regulations or other policies; credit risk might also arise through related technological shifts. Reputational risk might arise from financing fossil-fuel projects. Entities participating in insurance activities are increasingly monitoring and managing such risks by measuring their financed emissions. This measurement serves as an indicator of an entity’s exposure to climate-related risks and opportunities and how it might need to adapt its financial activities over time.
Physical Impacts of Climate Change
-
Physical Risk Exposure
Catastrophic losses associated with extreme weather events will continue to have a material, adverse effect on the Insurance industry. The extent of this effect may evolve as climate change increases the frequency and severity of both modelled and non-modelled natural catastrophes, including hurricanes, floods and droughts. Failure to appropriately understand environmental risks, and price them into the underwritten insurance products, may result in higher-than-expected claims on policies. Therefore, insurance entities that incorporate climate change considerations into their underwriting process for individual contracts, as well as the management of entity-level risks and capital adequacy, may be better positioned to create value over the long-term. Enhanced disclosure of an entity’s approach to incorporating these factors, in addition to quantitative data such as the probable maximum loss and total losses attributable to insurance pay-outs, may provide investors with the information necessary to assess current and future performance on this issue.
Competitive Behaviour
-
Intellectual Property Protection & Competitive Behaviour
Entities in the Software & IT Services industry spend a significant proportion of their revenues on IP protection, including acquiring patents and copyrights. Although IP protection is inherent to some entity business models and is an important driver of innovation, entities’ IP practices sometimes may be a contentious societal issue. Entities sometimes acquire patents and other IP protection to restrict competition and innovation, particularly if they are dominant market players. Because of software complexity, its abstract nature and increasing IP rights protection related to software, entities in the industry must navigate overlapping patent claims to operate. As a result, entities in the industry may find themselves constantly in litigation or subject to regulatory scrutiny either because of allegations of patent violations if they engage in unethical business practices, or are perceived as doing so, or because they engage in IP infringement litigation. Adverse legal or regulatory rulings related to antitrust and IP may expose entities in the industry to costly and lengthy litigations and potential monetary losses as a result. Such rulings also may affect an entity’s market share and pricing power if its patents or dominant position in important markets are challenged legally, with potentially significant effects on revenue. Therefore, entities that balance the protection of their IP and its use to spur innovation while ensuring their IP management and other business practices do not unfairly restrict competition, may reduce regulatory scrutiny and legal actions while protecting their market value.
Systemic Risk Management
-
Managing Systemic Risks from Technology Disruptions
With trends towards increased cloud computing and Software as a Service (SaaS), software and IT service providers must ensure they have robust infrastructure and policies in place to minimise disruptions to their services. Disruptions such as programming errors or server downtime may generate systemic risks, because computing and data storage functions move from individual entity servers in various industries to data centres of cloud-computing service providers. The risks are increased particularly if the affected customers are in sensitive sectors, such as financial institutions or utilities, which are considered critical national infrastructure. Entities’ investments in improving the reliability and quality of their IT infrastructure and services may attract and retain customers, thereby creating revenue and opportunities in new markets.
-
Systemic Risk Management
Entities in the Insurance industry have the potential to pose, amplify or transmit a threat to the financial system. The size, interconnectedness and complexity of entities highlight the industry’s exposure to systemic risk. Regulators have identified entities that engage in non-traditional or non-insurance-related activities as being more vulnerable to financial market developments and subsequently more likely to contribute to systemic risk. As a result, entities may be designated as Systemically Important Financial Institutions. Central banking systems in various jurisdictions may subject such entities to stricter prudential regulatory standards and oversight. Such entities may face stricter limits on their risk-based capital, leverage, liquidity and credit exposure. In addition, regulators may require entities to maintain a plan for rapid and orderly dissolution in the event of financial distress. Regulatory compliance can be costly, and failure to meet qualitative and quantitative regulatory performance thresholds could lead to substantial penalties. To demonstrate how these risks are being managed, entities should disclose important aspects of their systemic risk management and their ability to meet stricter regulatory requirements.