Skip to content
Compliance

The Delegated Authority Compliance Checklist for 2026

The governance, audit trail, and operational controls UK MGAs and TPAs must maintain in 2026 to keep binder standing — conduct risk, delegated claims, and evidence expectations.

July 27, 202610 min read

The compliance bar for delegated authority operations in 2026 is meaningfully higher than it was two years ago. Consumer Duty is now well past the initial implementation window and firmly into enforcement, Lloyd's coverholder oversight has tightened as part of the broader Blueprint Two programme, and FCA supervisory expectations of MGAs and TPAs have moved from principle-based to specifically evidence-based.

This checklist consolidates what a UK MGA or TPA actually needs to have in place to maintain binder standing through 2026. It's written for compliance directors and operations leads who need a working reference — not another explanatory piece on why compliance matters. Each item is either a control that must be operational or an evidence pattern that must be produced on demand.

1. Binder governance and authority

  • Current binder terms accessible to underwriters at the point of binding — not filed on a shared drive
  • Authority limits (sum insured, aggregate, class, territory) enforced at binding as a system control, not checked retrospectively
  • Excluded perils and territories enforced in the same way
  • Any breach of authority — even minor, even auto-correctable — logged and escalated per your escalation protocol
  • Renewal of binder terms tracked with automated alerting before expiration
  • Documented conflict-of-interest policy for underwriters, with attestation records

2. Underwriting evidence

  • Every quote and bind carries a documented underwriting rationale — not just “approved”
  • Referrals to the carrier for out-of-appetite risks logged with the specific reason, referral timestamp, and carrier response
  • Guideline exceptions documented with the specific guideline, the rationale for exception, and the approver
  • Rating calculations preserved with the input values so any premium can be reconstructed
  • Version control on rating tables — you can point to the exact rating table version applied at binding for a specific policy

3. Bordereau and reporting

  • Bordereau submission cadence per binder documented and monitored
  • Bordereau generation from a structured source of truth (policy admin system) with schema enforcement per counterparty
  • Pre-submission validation against the counterparty's schema — catches errors before submission, not after rejection
  • Rejection responses captured and fed back into the validation loop
  • Reconciliation between bordereau totals and internal accounting reconciled monthly with any variance documented

See the specific validation loop that prevents Lloyd's rejections.

4. Delegated claims authority

  • Claims decisions within authority documented with rationale, not just decision
  • Coverage determinations tied to the specific policy clause with citation, not just “covered” or “declined”
  • Referrals above authority logged with the specific reason, the referral timestamp, and the carrier response
  • Reserving documented with the basis and any subsequent adjustments
  • SLA adherence tracked and reported — acknowledgment windows, investigation timelines, decision timelines
  • Complaints handled per the FCA process with root-cause analysis and remediation logged

5. Consumer Duty operational evidence

  • Product governance evidence: target market fit reviewed regularly per product, with the review documented
  • Price and value evidence: outcome monitoring across products, with any concerning patterns flagged and remediated
  • Consumer understanding evidence: comms tested for clarity (reading age, financial literacy proxies), with results logged
  • Consumer support evidence: response times, resolution rates, vulnerability handling documented
  • Board-level Consumer Duty reporting produced regularly with the specific evidence packages behind each outcome

See what Consumer Duty specifically requires of brokers and coverholders.

6. Sanctions and financial crime

  • Sanctions screening at binding, renewal, and any material change — automated, not manual
  • Screening against OFSI, OFAC, EU, UN, and any binder-specified additional lists
  • List version and screening timestamp captured per check
  • Positive hits escalated per your documented procedure with resolution logged
  • PEP screening where applicable
  • Suspicious activity reporting process documented with clear escalation to MLRO

7. Data protection (UK GDPR)

  • Data subject access requests fulfilled within 30 days — measured and reported
  • Right to erasure requests handled with documented assessment of retention exceptions
  • Data breach detection and reporting workflow documented, with 72-hour notification capability
  • Records of processing activities (ROPA) current and reviewed at least annually
  • Third-party processor register current with contract terms confirmed

8. Audit trail and evidence integrity

  • Every material action across the policy and claims lifecycle logged with actor, timestamp, and specific action
  • Audit trail protected against modification — cryptographic integrity (Merkle-tree structured) increasingly the expected baseline
  • Server-side timestamps (not client-side) on all logged events
  • Log retention aligned to regulatory requirements (typically 6 years UK, longer for specific lines)
  • Legal hold controls to prevent deletion of documents subject to litigation or investigation

See what an immutable audit trail specifically means and what managing agent auditors look for.

9. Operational resilience

  • Business continuity plan documented, tested (tabletop exercises), and reviewed at least annually
  • Recovery point and time objectives documented and tested
  • Cyber incident response plan with defined escalation to relevant stakeholders
  • Important business services identified and impact tolerances documented per FCA operational resilience rules
  • Third-party dependencies mapped with continuity assessments

10. Governance and controls

  • Compliance function with defined reporting line and adequate resource
  • Risk register current with owners, mitigations, and review cadence
  • Compliance monitoring plan executed with findings reported to senior management
  • Senior Managers & Certification Regime responsibilities mapped where applicable
  • Training programme delivered with attestation records
  • Regular MI package to the board covering compliance, risk, and operational metrics

11. Vendor and outsourcing

  • Outsourcing register current with documented risk assessments per material outsourcing
  • Contract terms confirmed to include right-to-audit, data protection, and continuity obligations
  • Ongoing monitoring of material vendors with defined KPIs and review cadence
  • Exit strategies documented for critical vendors

12. Regulatory reporting

  • Regulatory returns (RMAR, other applicable) filed on time and reconciled to source data
  • Complaints returns filed accurately with underlying complaint records supporting the figures
  • Financial reporting reconciled to bordereaux, ledger, and regulatory returns
  • Ad-hoc regulatory information requests handled with documented response and evidence trail

Applying the checklist

The most useful application isn't to work through it linearly. It's to use it as an audit against your current controls. For each item, one of three things is true:

  • Green: the control is operational, the evidence is being produced, and you can demonstrate it on demand
  • Amber: the control exists but the evidence is manual, retrospective, or fragile — you'd get through an audit but with effort
  • Red: the control isn't operational or the evidence can't be produced — this is a finding waiting to happen

Red items are your remediation priorities. Amber items are your operational-uplift roadmap. Green items are what you already have — and the ratio of green to amber to red is a pretty accurate snapshot of your compliance posture.

Where automation genuinely changes the picture

Around half of the items on this checklist are dramatically easier to maintain when the underlying systems are structured to produce evidence as a by-product of the workflow — bordereau generation, sanctions screening, audit trail, DSAR handling, referral logging, MI reporting. Manual maintenance of these controls at scale is possible but expensive and error-prone, and most amber items in a compliance audit are amber because someone is doing the control manually.

See the compliance teams solution page for the operational baseline, the UK compliance overview, and audit trails platform overview.

Bottom line

Compliance for delegated authority in 2026 has become an evidence discipline more than a rule discipline. The checklist above is the shape of what supervisors and managing agents want to see operating — not just declared. The MGAs and TPAs that operate their systems around continuous evidence production keep binder standing without stress. The ones that produce evidence reactively when asked live in cycles of remediation and audit findings that eventually catch up.

James ThorntonInsurance Operations Lead, UK & Ireland
James leads Regure’s UK and Ireland insurance practice, covering FCA Consumer Duty, Lloyd’s coverholder operations, bordereaux reporting, and the broker / MGA technology landscape across the London market.

Ready to modernize your claims operations?

Book a 20-minute demo and see how Regure automates the manual work holding back your team.

Book a Demo