Large insurers are increasingly moving beyond treating ESG and cyber as qualitative risk categories and are embedding them into their ORSA and (where applicable) Solvency II internal model frameworks. However, practice is still evolving, and few firms have fully integrated these risks into Pillar 1 capital calculations. Most integration today happens through ORSA, stress testing, scenario analysis, risk appetite, and management actions.
Here's what leading firms are doing.
1. Climate and ESG risk integration
Climate risk is the most mature ESG component in capital modeling.
Physical risk
Insurers are incorporating:
- Increased catastrophe frequency and severity
- Secondary perils (wildfire, flood, hail)
- Property concentration changes
- Reinsurance affordability
Model enhancements include:
- Adjusting catastrophe model assumptions
- Longer-term trend parameters
- Regional hazard overlays
- Correlation changes across perils
Within ORSA:
- Multi-year balance sheet projections
- Climate stress scenarios (1-in-200, severe warming pathways)
- Capital depletion under consecutive catastrophe years
Transition risk
Life and general insurers are modeling:
- Credit spread widening
- Equity market repricing
- Carbon-intensive sector defaults
- Real estate repricing
- Green technology disruption
These typically feed into:
- Market risk modules
- Credit risk capital
- Investment portfolio stress testing
Rather than creating a separate "transition capital charge," firms usually shock existing asset risk factors.
Liability impacts
Emerging work includes:
- Higher mortality from heat events
- Morbidity changes
- Litigation exposures
- Directors & Officers liability
- Professional indemnity claims
- Casualty reserve deterioration
These remain largely scenario-based rather than embedded in standard capital formulas.
2. Broader ESG integration
Social and governance risks are generally incorporated indirectly.
Examples include:
- Conduct risk
- Operational failures
- Third-party oversight
- Supply chain disruption
- Human capital risk
Most firms reflect these through:
- Operational risk scenarios
- Emerging risk registers
- Reverse stress testing
- Qualitative ORSA assessments
Few internal models have explicit ESG capital factors.
3. Cyber risk integration
Cyber is advancing rapidly because of increasing regulatory attention and loss experience.
Most insurers distinguish between:
- Operational cyber risk
- Insurance underwriting cyber accumulation
- Investment cyber exposure
- Third-party/vendor cyber risk
Each is modeled differently.
Operational cyber
Typically modeled using scenario analysis.
Example scenarios include:
- Ransomware shutting claims systems
- Cloud provider outage
- Data breach
- Payment system disruption
- Simultaneous regulatory fines and business interruption
Outputs include:
- Operational losses
- Liquidity impacts
- Recovery costs
- Reputational impacts
Many firms use expert judgment combined with external cyber loss databases because internal history is limited.
Cyber underwriting accumulation
This is becoming a major internal model enhancement.
Rather than treating policies independently, firms model:
- Common software vulnerabilities
- Cloud concentration
- Systemic attacks
- Supply chain attacks
- Geographic accumulation
- Industry accumulation
Examples include:
- Global cloud outage
- Major software exploit
- Critical infrastructure attack
These scenarios estimate simultaneous losses across many policyholders.
Capital modeling techniques
Leading firms are using:
Scenario libraries
- National infrastructure attack
- Cloud failure
- AI-enabled cyber attack
- Payment network outage
Frequency-severity models
Often:
- Poisson frequency
- Heavy-tailed severity
- Extreme value theory for tail losses
Dependency modeling
Instead of assuming independence, firms model correlations between:
- Operational risk
- Market risk
- Liquidity risk
- Reputational risk
Copulas and network-based approaches are increasingly explored for these dependencies.
4. ORSA enhancements
The biggest changes are occurring in ORSA rather than regulatory capital.
Leading insurers now include:
| Area | Typical enhancement |
|---|
| Climate | Multi-decade scenarios |
| Cyber | Severe operational scenarios |
| ESG | Emerging risk assessments |
| Capital | Dynamic capital projections |
| Liquidity | Stressed funding analysis |
| Business model | Strategic resilience assessment |
| Management actions | Dynamic response modeling |
Rather than asking whether today's capital is sufficient, firms increasingly assess whether capital remains adequate under evolving structural risks over a 3–5 year horizon (or longer for climate-related scenarios).
5. Internal model developments
Where insurers have approved internal models, common enhancements include:
- New climate-related risk factors
- Updated dependency structures
- More sophisticated operational risk distributions
- Dynamic balance sheet modeling
- Second-order effects (e.g., market stress following a catastrophe)
- Feedback loops between underwriting and investment performance
However, regulators generally expect robust evidence before approving new quantitative risk factors, so many ESG and cyber risks remain in Pillar 2 assessments rather than Pillar 1 capital.
6. Regulatory expectations
European supervisors increasingly expect insurers to:
- Demonstrate how material ESG risks are identified, assessed, and managed in the ORSA.
- Incorporate climate-related risks into scenario analysis and business planning where material.
- Consider cyber resilience as part of operational risk management and stress testing.
- Explain governance, data limitations, expert judgment, and model validation for emerging risks.
A common supervisory focus is not whether firms can precisely quantify every emerging risk, but whether their assumptions are transparent, proportionate, and supported by a credible governance and validation framework.
What distinguishes leading practice
Across large European insurers, several patterns stand out:
- ESG and cyber risks are increasingly integrated into existing market, credit, underwriting, and operational risk models instead of being modeled as standalone capital charges.
- Dynamic balance sheet projections are used to assess how management actions, reinsurance, asset allocation, and business mix evolve under stress.
- Scenario analysis is supplemented with reverse stress testing to identify combinations of ESG and cyber events that could threaten solvency or business viability.
- Quantitative outputs are linked to decision-making—for example, influencing risk appetite, underwriting limits, reinsurance strategy, investment allocation, and capital planning—rather than being produced solely for regulatory reporting.
- Strong model risk management is applied, with explicit documentation of expert judgment, uncertainty, and validation approaches, reflecting the relative scarcity of historical data for emerging risks.
For insurers undertaking ORSA and Solvency II enhancement programs today, the emphasis is typically on making ESG and cyber risks decision-useful through scenario-based capital planning and governance, while selectively extending quantitative internal models where there is sufficient data and methodological confidence.