You Can Delegate the Authority, Not the Accountability

UK General Insurance · Governance, Risk & Delegated Authority

A carrier or managing agent can outsource an activity, but not the responsibility for its outcomes. As the regulator moves from describing that principle to actively testing it, the gap between oversight on paper and oversight in practice is becoming the exposure.

One of our earlier papers examined delays in reporting delegated business. Coverholders often write risks weeks before the accountable managing agent sees them. That lag is real, but it is only a symptom. The underlying root cause is that oversight of third parties in delegated arrangements no longer works as intended. It has lapsed into a documentary exercise: a binder signed, an audit filed, an attestation received. This operating model does not evidence customer outcomes. Delegated business now accounts for close to 40% of all business written at Lloyd's1. Much of that chain of activity, including underwriting, pricing, claims handling and complaints, is delegated to third parties. However, although activity may move to a third party, accountability for customer outcomes does not move with it.

Both the Senior Managers and Certification Regime (SMCR) and the Consumer Duty place responsibility for customer outcomes on the regulated firm and its named senior managers. This principle holds however far down the chain the work is delegated. Consider three typical delegated authorities. A carrier delegates underwriting to a Managing General Agent (MGA) or coverholder. An MGA delegates claims to a third-party administrator (TPA), known at Lloyd's as a Delegated Claims Administrator (DCA). A Principal (an authorised firm) appoints a network of Appointed Representatives (ARs), who carry on regulated activities under the Principal's permission rather than their own. In each case the regulated firm hands out the task but keeps the liability. For years that was a matter of principle. In 2026 it became a matter of supervisory priority.

Figure 1 · The Accountability That Does Not Travel

Activity flows down the chain. Accountability stays at the top.

Non-delegable accountability Delegated → Delegated onward →
Carrier / Managing Agent
Owns the outcome
Held to account by the regulator. Owns customer outcomes. Cannot delegate it.
MGA / Coverholder
Binds the risk
Assesses, prices and binds risks within authority. May delegate claims onward.
TPA / DCA
Handles the claim
Handles claims — the customer's real experience.
Each step delegates the work and a share of the economics. The MGA, coverholder and administrator are each regulated for their own conduct. But none of them takes on the carrier's overarching responsibility for whether the customer received a fair outcome, which cannot be delegated.
Source: New Link Consulting analysis

What changed in February

On 24 February 2026 the Financial Conduct Authority (FCA) published its first in a new series of reports, Regulatory Priorities: Insurance. The series replaces more than forty separate portfolio letters with one statement of priorities for each sector3. The message for delegated authority is clear. From Q2 2026 the FCA will expand its review of how delegating firms oversee outsourced and delegated arrangements. That review covers the delegated models in use and the remuneration incentives within them. Findings are due in early 20273. This is no longer an abstract principle. It is a dated supervisory exercise.

The initial trigger was handling of claims in consumer lines. In September 2025 Which? made a super-complaint to the FCA concerning claims outcomes for home and travel cover. The regulator's response draws its force from the Consumer Duty, which applies to retail customers4. Commercial and specialty delegated business sit largely outside the Duty. However, they do not sit outside the principle. Supervisory Statement PRA SS2/21 (outsourcing and third-party risk management), the SMCR and Lloyd's oversight apply across the book, whatever the line. They reach delegated underwriting as much as delegated claims. Wherever a task is delegated, the accountable firm must show that outcomes match what it would deliver itself.

For claims this lands hardest on Managing General Agents. More than 90% of members of the Managing General Agents' Association (MGAA) outsource at least part of their claims function5. For underwriting, the weight falls on the managing agents and carriers that delegate authority. At Lloyd's, every coverholder binds risk on a managing agent's syndicate, and that managing agent stays accountable for it. For many managing agents, MGAs and coverholders, Figure 1 is not hypothetical. It is the reality the regulator intends to test.

Why the regulator is focused here

Three structural features explain the attention. First, the chain is long. The more organisational links a policy passes through, the more places a fair value or fair outcome obligation can fail. Second, in Supervisory Statement SS2/21 (updated November 2024), the Prudential Regulation Authority (PRA) addresses all third-party dependencies that can affect an insurer's or managing agent's objectives. It requires adequate governance and controls for all dependencies, proportionate to their materiality and risk6. Third, operational resilience joins the above two features. The operational resilience regime has applied since 2022. From the start, carriers and managing agents had to identify their important business services and set impact tolerances. The 31 March 2025 deadline required them to remain within those tolerances, even where a coverholder, MGA or TPA delivers the service on their behalf7. So a coverholder, MGA or TPA delivering an important business service for an in-scope carrier or managing agent is reached as the third party for that carrier or managing agent.

In parallel, the conduct regulator's posture has hardened from guidance to evidence. The Consumer Duty, in force since July 2023, made good outcomes a board-level obligation across the distribution chain. The Product Intervention and Product Governance sourcebook (PROD) requires manufacturers and distributors to evidence fair value. This applies where an MGA helps design a product, which makes it a joint manufacturer with the carrier. It also applies where the MGA distributes that product under delegated authority2. The 2026 priorities confirm the FCA will now inspect how that duty is discharged in delegated models. It will look in particular at whether remuneration rewards volume in ways that work against fair claims outcomes3.

The question is no longer whether a firm oversees its delegates. It is whether the firm can prove the oversight produced fair outcomes, on a date the regulator has now set.

The market is not waiting for the regulator

This is not only a regulatory priority. The market's own institutions are moving the same way. In 2025 the Lloyd's Chief Underwriting Officer warned of a "laser focus" on coverholder oversight — that is, outcomes from delegated underwriting. The warning came with restrictions on delegation where coverholders were deemed poorly managed1. The Corporation's 2025 Market Oversight Plan named delegated claims data, its timeliness, accuracy and use, as a focus8. Each managing agent now has a dedicated oversight relationship. It tests that expectation rather than merely announcing it.

In 2020 the Lloyd's Market Association (LMA) launched its Delegated Authority Reimagined (DARE) initiative to rebuild delegated business around customers and data. Having delivered that vision, the LMA Delegated Authority Committee is now in Phase 2 implementation, in step with the Future at Lloyd's programme9. That committee also leads the market's response to the byelaws, standards, codes and risk-based oversight framework against which managing agents are measured9.

The clearest signal is the audit scope itself. The LMA's common Coverholder and DCA audit scope is the market's shared yardstick for meeting FCA and PRA expectations. The coverholder side tests delegated underwriting: whether business is bound within the authority, priced and selected as agreed. The DCA side tests delegated claims. Both have now been widened. Financial oversight now reaches the risks that build up when cover is delegated through several layers. Where a coverholder delegates onward, premiums and exposures pass down a chain which the carrier must track. The information technology and information security scope now reflects cyber and artificial intelligence (AI) risk.

A fuller review of the scope is due in 202610. In parallel, the LMA's Delegated Authority Claims Group is developing delegated claims standards and a new DCA agreement with market standard service levels11. On the underwriting side, the binding authority agreement is the equivalent instrument, setting how a coverholder may price and bind. Expectations are tightening in exactly the areas where delegated oversight is hardest: underwriting, claims, cyber, AI and layered delegation.

What we see going wrong

In our work, we have seen similar failures recur. They appear wherever oversight of third parties is treated as a periodic compliance exercise rather than a continuous operating model. These are the kind of failures the 2026 review is likely to surface.

Oversight as an annual event. The binder is reviewed once a year, an audit is commissioned, the file is closed. Between reviews the managing agent relies on the delegate's own attestations. It has no independent MI to interrogate and analyse. Outcomes drift in the eleven months nobody is looking.

Activity is measured, outcomes are not. The oversight pack reports volumes, turnaround times and loss ratios. It does not show whether declined claims were fairly declined, whether pricing stayed within the agreed basis, or whether the product still reached its target market. Nor does it show whether vulnerable customers were identified or complaints resolved. For retail business these are the outcomes the Consumer Duty asks about2. For commercial business the same evidence is simply good oversight.

Onward delegation not visible to the coverholder or MGA. The coverholder or MGA delegates claims but does not control where they go next. Larger or complex claims are often referred up to the capacity provider, the carrier or syndicate that backs the policy. Others are handled by a TPA/DCA it never contracted with, perhaps a subcontractor of its own TPA. SMCR accountability still rests with the named senior manager within the coverholder or MGA. Yet that manager often cannot say who is handling the customer's claim.

Remuneration that pulls against the outcome. Profit share, volume override and contingent commission arrangements are set without testing their effect. They can create an incentive to bind more business, or to settle claims for less. These are precisely the structures the FCA has said it will examine3.

Agreements that are legal documents, not operating documents. The binder sets out data, conduct and audit rights in clauses nobody operationalises. When the FCA or the Oversight Manager asks for evidence the standard was met, the managing agent or MGA has the contract but not the proof.

Consider a common pattern. A coverholder holds a binder that allows claims to be passed onward. The managing agent has never mapped that arrangement. It surfaces only when a vulnerable customer complaint escalates, by which point three parties have touched the claim and none owns the outcome.

What good looks like, in the order that works

The managing agents and MGAs ahead of this are typically not running a transformation programme. One way or another, they conduct four stages in sequence, and the discipline is in the order, as shown in Figure 2 below and explained further below the graphic. The first three stages are not material investments and collectively they reduce the risk in the fourth stage.

Figure 2 · From Document to Operating Model

Map first, evidence last

01
Map the chain
Every delegate and onward delegate, and where SMCR accountability sits.
02
Test the agreements
Each binder and terms of business agreement (TOBA) against the outcomes it must now deliver.
03
Build outcome MI
A few indicators, monitored continuously, not an annual audit.
04
Evidence it
A pack ready for the board and the regulator that demonstrates, not asserts.
Done before the next review Proof for board and FCA
Steps one to three can be completed before the next review without a system build. Step four is where the firm proves to its board and to the FCA that the chain delivers what it promised.
Source: New Link Consulting analysis

First, they map the chain in full. That means every coverholder, MGA, TPA and AR, what each is delegated, who they rely on in turn, and which senior manager carries SMCR accountability. Most discover the map is incomplete. The gaps cluster around claims that have been delegated onward.

Second, they read each agreement against the outcomes it must now deliver, not the risks it was drafted to allocate. Where the binder is silent on conduct data, fair value evidence, complaints visibility or audit access, they tighten it at the next renewal.

Third, they build a small set of outcome indicators. These include fair value flags, pricing and loss ratio drift, patterns in declined claims and complaints, and how vulnerable customers are identified. They monitor these as live management information (MI), not an annual audit. The point is to know within weeks, not at year end, when a delegate's outcomes drift.

Fourth, and only fourth, they assemble the evidence into a pack the board can sign and the regulator can read. By then the firm is demonstrating equivalent outcomes from data it already holds. That is exactly what the 2026 review is likely to ask for.

The deadlines are not abstract

The operational resilience deadline has already passed. Full compliance was required by 31 March 20257. The FCA's delegated authority and remuneration review begins in Q2 2026, with findings expected in early 20273. The window in which firms can get ahead of it is now. Close behind, the PRA's final policy on operational incident and third-party reporting (PS7/26) takes effect on 18 March 2027. It sharpens how material third-party arrangements must be identified and reported12. Firms with European business face a parallel regime. Under the Digital Operational Resilience Act (DORA), the European Supervisory Authorities designated the first critical information and communications technology third-party providers on 18 November 2025. This brings direct European oversight of key providers into effect13. And HM Treasury's consultation on reform of the appointed representatives regime signals tighter expectations on principals' oversight of their ARs14. The common thread across all four is the same one running through this paper: evidence of oversight, on a defined timetable. Failing that test has consequences. The FCA can require remediation under supervision, restrict a firm's delegated authority, or commission a skilled person review under section 166. The accountability is personal to the named senior manager.

Senior Management Self-Assessment

Six questions for the next executive meeting

For the Head of Delegated Authority, the relevant Senior Management Function (SMF) holder and the board. None requires a project to answer. All should be answerable from what your firm already holds.

The map. Can your firm produce a complete list of every party it delegates to, and every party they delegate to in turn? Is the accountable senior manager named against each?

The outcomes question. For underwriting and claims handled under delegation, what evidence shows that pricing held and declined claims were fairly declined, matching what your firm would deliver itself?

The remuneration test. Has your firm tested whether any profit share, override or contingent commission creates an incentive that works against a fair outcome?

The evidence test. If the FCA asked tomorrow for proof that each binder's conduct and fair value standards were met last quarter, what data could answer?

The drift. If a delegate's outcomes deteriorated, how long before the operating model, rather than an individual, would surface it, and to whom?

The resilience link. Where a delegated service supports an important business service, can your firm evidence it stays within its impact tolerance when that third party is disrupted?

To summarise our core theme: you can delegate the authority, not the accountability. That gap was tolerated because, until recently, evidencing oversight across a long chain was slow and costly. So firms relied on the contract and the annual audit and hoped. That no longer holds, and the regulator has set a date to test it. Firms that act in 2026 will enter the review with the evidence already assembled. Those that do not will assemble it under supervision.

A Diagnostic Worth Running

If you delegate underwriting, as a managing agent or carrier, the focus is your coverholders or MGAs: testing whether they price, bind and stay within authority. If you delegate claims, as an MGA or coverholder, the focus is your administrators: whether declined claims, complaints and vulnerable customers are handled as you would yourself.

Oversight diagnostic

Full mapping of the delegation chain, including onward delegation
SMCR accountability traced to named senior managers
Binder & TOBA test against conduct and fair value duties
Remuneration structure conflict review
Gap assessment mapped to the FCA 2026 focus areas, the LMA common audit scope and Lloyd's oversight framework

Oversight operating model

Continuous outcome MI: fair value, declines, complaints
Vulnerable customer identification across the chain
Exception flagging, escalation and referral triggers
Operational resilience linkage for delegated services
Oversight evidence pack ready for the board and the regulator

If this resonates and it would help to have a partner who has done it before, we would be glad to have that conversation. Please contact Richard Spencer at new-business@new-linkconsulting.com.

Sources

  1. Rachel Turk, Chief Underwriting Officer, Lloyd's of London. Q2 2025 market message, reported in Insurance Journal, "Lloyd's Has 'Laser Focus' on Oversight of Coverholders to Proactively Avoid Market Risk," 16 May 2025.
  2. FCA, Consumer Duty (PRIN 2A), in force 31 July 2023; product governance and fair value obligations under PROD 4. Both place outcome accountability on manufacturers and distributors across the distribution chain, alongside the Senior Managers and Certification Regime (SYSC / the SMF framework).
  3. FCA, Regulatory Priorities: Insurance, published 24 February 2026. It states that from Q2 2026 the FCA will expand its review of oversight of outsourced and delegated authority arrangements. This includes remuneration structures, with findings expected in early 2027. Summarised by, among others, TLT LLP, PwC UK and the Managing General Agents' Association, March 2026.
  4. Which? lodged a super-complaint to the FCA on the home and travel insurance markets in September 2025. It cited poor claims handling, inappropriate sales processes and weak enforcement of existing rules. The FCA published its response on 18 December 2025, committing to expand its work, including reviewing how firms oversee third parties that handle claims. See also FCA, "Home and travel claims handling arrangements: good practice and areas for improvement," July 2025, which flagged lack of control over outsourced arrangements, poor management information and poor oversight of cash settlements.
  5. Managing General Agents' Association commentary on the FCA 2026 priorities, reported in Insurance Business UK, March 2026. It notes that over 90% of MGAA members outsource at least part of their claims function to a third party. The figure is industry reported; verify against the primary MGAA source before publication.
  6. PRA, Supervisory Statement SS2/21, "Outsourcing and third-party risk management," updated November 2024 (Bank of England). Sets PRA expectations for governance and controls over all third-party dependencies, proportionate to materiality and risk.
  7. FCA Policy Statement PS21/3 and PRA Supervisory Statement SS1/21, "Operational resilience," with full compliance required by 31 March 2025. Covers identification of important business services, impact tolerances and scenario testing, including for services delivered by third parties.
  8. Lloyd's of London, 2025 Market Oversight Plan; section identifying delegated claims data (timeliness, accuracy and use to drive performance) as an oversight focus.
  9. Lloyd's Market Association, DARE (Delegated Authority Reimagined) initiative and the LMA Delegated Authority Committee (LMADAC). DARE was launched by LMADAC in 2020 with delivery partner 6point6; the end-to-end DA vision was published in 2021 (lmadare.com). The committee is now progressing Phase 2 implementation, in alignment with the Future at Lloyd's programme. LMADAC leads the market's response to byelaws, standards, codes of practice and Lloyd's risk-based oversight framework. Source: lmalloyds.com.
  10. Lloyd's Market Association, Coverholder and DCA Audit Scope and associated guidance (lmalloyds.com). The common audit scope is designed to support managing agents, coverholders, TPAs and DCAs in meeting FCA and PRA expectations. A recent update expanded financial oversight to include cascading risk transfer risk, and expanded the IT and information security scope to reflect cyber and AI risk. A wider review is planned to commence in 2026. Confirm current scope against the LMA source before relying on specifics.
  11. Lloyd's Market Association, Delegated Authority Claims Group / Delegated Authority Claims Management Group (lmalloyds.com). Workstreams include development of delegated claims standards, a new DCA agreement with market standard service level agreements, and enhancement of the LMA9157 Co-Lead Claims Agreement.
  12. PRA Policy Statement PS7/26, "Operational resilience: Operational incident and third-party reporting," Bank of England, published 18 March 2026. Final rules and the updated SS2/21 take effect on 18 March 2027 (companion to FCA PS26/2). bankofengland.co.uk.
  13. European Supervisory Authorities (EBA, EIOPA, ESMA) designated the first critical information and communications technology third-party providers under the Digital Operational Resilience Act (Regulation (EU) 2022/2554). The designation was published on 18 November 2025, covering 19 providers for direct ESA oversight. EIOPA and the ESAs, joint announcement, eiopa.europa.eu.
  14. HM Treasury, consultation paper on reform of the Appointed Representatives regime, published 12 February 2026 (closed 9 April 2026). It builds on HM Treasury's policy statement of 11 August 2025. Proposals include a regulatory gateway requiring FCA permission before an authorised firm may act as a principal, extension of Financial Ombudsman Service jurisdiction to ARs, and alignment of ARs with the SMCR.
Next
Next

Fixing Delegated Authority After Blueprint Two (Insurance Day Article)