Raymond Cheung
Chartered Actuary · CRO · Board Adviser · Singapore
On 18 August 2026, I facilitated a full-day Professional Certification programme on Enterprise Risk Management and Business Continuity Planning for Indonesian insurance and reinsurance brokers, organised by APARI and Singapore College of Insurance at JW Marriott Jakarta. Here is what we worked through and why it matters for Indonesia's evolving regulatory landscape.
On 18 August 2026, I facilitated the Professional Certification in Enterprise Risk Management and Business Continuity Planning at JW Marriott Hotel Jakarta, organised by APARI (the Association of Indonesian Qualified Insurance and Reinsurance Brokers) and Singapore College of Insurance. The programme ran from 09:00 to 17:00 and brought together active insurance and reinsurance brokers from across Indonesia.
Indonesia's insurance brokerage sector is operating under an increasingly demanding regulatory framework. OJK regulations POJK 44/2020, POJK 4/2021, and POJK 24/2023 have progressively tightened expectations around risk governance, capital adequacy, and operational resilience. The programme was designed to translate those regulatory requirements into practical tools that brokers can implement immediately.
The Modern Risk Landscape for Indonesian Brokers
The opening session grounded participants in what risk actually means in the current operating environment. The conventional risks -- counterparty default, premium collection failure, E&O claims -- remain. But they now sit alongside a new layer of emerging exposures: AI-driven underwriting decisions that brokers cannot audit, cyber incidents that can freeze client operations overnight, and regulatory changes that compress implementation timelines.
For an Indonesian broker operating across multiple lines, this creates a risk identification problem before it creates a risk management problem. If your risk register only reflects the risks your predecessors wrote down five years ago, it is not a risk register -- it is a historical document.
“Compliance with POJK is the floor, not the ceiling. The brokers who treat ERM as a governance tool rather than a reporting obligation will outperform on client retention and regulatory standing.”
ERM Frameworks: ISO 31000 and COSO in an Insurance Context
The programme covered both ISO 31000 and the COSO ERM framework, with particular attention to how each applies in an insurance distribution context. ISO 31000 provides the principles and process architecture for risk management -- the iterative cycle of context-setting, risk identification, analysis, evaluation, treatment, and monitoring. COSO ERM adds the strategic dimension, connecting risk management to value creation and linking it explicitly to organisational objectives.
The key shift both frameworks demand is from siloed risk management -- where compliance, operations, and finance each manage their own risks independently -- to an integrated, enterprise-wide view. For brokers, this means connecting client risk profiles to internal operational risks and understanding how disruptions in one area cascade into others.
Risk Governance: The Board, Three Lines of Defence, and Accountability
Risk governance is where many Indonesian brokers, particularly mid-sized firms, face the largest gap. The Three Lines of Defence model -- operational management as the first line, risk and compliance functions as the second, and internal audit as the third -- requires clarity about who owns each risk and who is accountable when something goes wrong.
In practice, the most common failure mode is not a broken process -- it is ambiguous ownership. Participants worked through how to assign clear risk owners at the operational level, how to structure the second line function proportionately for a brokerage firm (which may not need a dedicated CRO but does need a named risk officer with actual authority), and how the board receives and acts on risk information.
- First line: Business units and client-facing teams own and manage risk day-to-day
- Second line: Risk and compliance functions set standards, monitor, and challenge
- Third line: Internal audit provides independent assurance to the board
- Board: Sets risk appetite, receives MI, and holds management accountable
Practical Risk Identification and the Risk Appetite Statement
The afternoon sessions moved into hands-on exercises. Participants built a risk register for a representative Indonesian brokerage, working through risk identification, likelihood and impact assessment, and prioritisation. The exercise surfaced risks that participants had not previously documented -- including technology dependency on legacy policy administration systems and concentration risk in client portfolios.
The Risk Appetite Statement exercise was particularly valuable. Many firms have a generic statement that says they want to 'minimise risk' or 'maintain financial stability' without specifying what that means in measurable terms. The session guided participants through writing appetite statements that are specific, linked to strategic objectives, and actionable -- so that a front-line broker can use the statement to make a real decision about whether to pursue a particular client or product line.
Business Continuity Planning: From BIA to Crisis Playbook
The BCP module covered the full lifecycle: Business Impact Analysis (BIA) to identify critical functions and their dependencies, Recovery Time Objective (RTO) and Recovery Point Objective (RPO) setting, crisis playbook construction, and testing protocols.
For insurance brokers, the BIA typically surfaces three critical vulnerabilities: loss of access to policy management systems, inability to reach key clients during a crisis, and dependence on insurer capacity that may itself be constrained during a major event. The session addressed each with practical mitigation approaches.
Testing is where most BCP programmes fail. A plan that has never been tested is not a plan -- it is an assumption. The programme covered tabletop exercises, functional drills, and the governance requirement to document test results and close gaps identified.
Why This Matters Now for Indonesia
Indonesia's OJK has progressively embedded risk management requirements into its licensing and supervision framework for insurance intermediaries. Firms that have already implemented credible ERM and BCP frameworks are better positioned for regulatory review, better able to demonstrate resilience to their insurance company partners, and better equipped to retain institutional clients who now routinely ask about counterparty risk management during broker selection.
The programme was SCI-certified, with participants receiving the Certificate of Completion in Enterprise Risk Management and Business Continuity Planning from Singapore College of Insurance -- a qualification that carries professional credibility across the ASEAN region.
Thank you to APARI and Singapore College of Insurance for the invitation, and to all participants who brought their real-world challenges into the room. That is what makes a training programme useful.
Common Questions
What ERM regulations apply to Indonesian insurance brokers under OJK?
Indonesian insurance brokers are subject to OJK regulations including POJK 44/2020 on insurance business, POJK 4/2021 and POJK 24/2023, which progressively expand risk governance, capital, and operational resilience requirements for insurance intermediaries. Compliance requires documented risk management frameworks and business continuity plans.
What is the difference between ISO 31000 and COSO ERM for insurance firms?
ISO 31000 provides a universal risk management process framework covering risk identification, analysis, evaluation, treatment and monitoring. COSO ERM adds a strategic layer, explicitly linking risk management to value creation and organisational objectives. For insurance intermediaries, ISO 31000 is the more commonly referenced standard in the ASEAN regulatory context, but COSO ERM is valuable for firms seeking to embed risk into strategic planning.
Does Raymond Cheung provide ERM training for insurance companies and brokers in Asia?
Yes. Raymond Cheung facilitates professional ERM and BCP certification programmes for insurance companies, reinsurers and brokers across Asia, including the APARI programme for Indonesian brokers delivered in partnership with Singapore College of Insurance. He is available for in-house corporate training and public certification programmes.
Related insights
About the author
Raymond Cheung is a Chartered Actuary, C-suite executive and board adviser with more than 20 years of experience across Asia in risk management, insurance, ESG and corporate governance. He is the CEO of CER Consultancy and an accredited trainer at SMU Academy and the Singapore College of Insurance.