Skip to content
Compliance

Managing Agent Oversight of Coverholder Systems: What They Actually Look For in an Audit

The auditor's checklist behind a coverholder systems review — audit trails, data integrity, sanctions checks, and evidence preservation that keeps your binding authority intact.

June 29, 202610 min read

A managing agent's oversight of its coverholders is not a formality. It is the mechanism by which the Lloyd's market controls risk written under delegated authority, and it is the mechanism by which a managing agent evidences to Lloyd's that it is discharging its own supervisory duty. When a systems review comes around, the auditors are not there to catch you out. They are there to build evidence they can show Lloyd's.

Coverholders who understand that shift the conversation. Instead of scrambling to produce evidence during the audit, they operate systems that continuously produce it. The audit becomes a demonstration, not a discovery. This piece is the practical checklist of what a systems reviewer is looking for, in the order they typically ask.

1. Audit trail — completeness and integrity

The first thing any competent auditor asks for is a full audit trail on a sample of policies and claims. Not summary logs. Not “here's what we did.” The actual, timestamped record of every action taken on the policy from quote to close.

What they're checking:

  • Completeness. Every material action is logged. Quote generation, underwriting decision, binding, endorsement, claim receipt, claim payment. If any action is missing, the audit trail is not complete.
  • Actor identification. Every logged event names the specific user (not “system” or “admin”) who took the action.
  • Timestamps that survive. Not local clock-based. Server timestamps that cannot be altered from the client.
  • Integrity. Can the log be modified after the fact? If yes, the log is evidence of nothing. Auditors increasingly ask about cryptographic integrity — Merkle-tree structured logs where any modification is detectable — because that's the standard emerging for regulatory-grade audit trails.

See what an immutable audit trail actually is for the technical baseline, and the audit trails platform page for how the mechanism works in practice.

2. Data integrity — one version of the truth

Auditors will ask for a reconciliation between what your system says about a specific policy and what appears in the bordereau you submitted to the managing agent. They will pick five to ten policies and compare across three data points: the policy record, the bordereau submission, and any endorsements.

The failure mode they're looking for is data drift. If your PAS says the effective date is 1 April but the bordereau says 1 May, or the premium in your system is £12,400 but the bordereau shows £12,000, that's a serious finding — because it means either the bordereau was wrong (breach of reporting terms) or the system was wrong (breach of controls).

The controls they're verifying:

  • Single source of truth per data domain (policy = PAS; claims = claims system)
  • Bordereaux generated from that source of truth, not re-keyed
  • Endorsements captured on the policy record and reflected in the next bordereau
  • Version history preserved so changes can be reconstructed

3. Sanctions and financial crime checks

Sanctions screening at binding is a hard control. Auditors will ask to see evidence that every risk written under your binding authority was screened against the relevant sanctions lists at binding, that the screening was performed at the correct point in the workflow (not retrospectively), and that any positive hits were escalated and documented.

The specific evidence they want:

  • Timestamp of the sanctions check relative to the binding decision
  • The specific lists screened against (OFSI, OFAC, EU Consolidated List, UN Security Council)
  • The version of each list at the time of screening (lists change; you need to prove you checked against the current version)
  • Documentation of any positive matches and the escalation/resolution path

The failure that gets flagged: sanctions screening as a separate manual step after binding, not integrated into the binding workflow. If your team can bind a risk without the sanctions check having run, the control is theatrical.

4. Evidence preservation and retention

Under Lloyd's binder terms and FCA SYSC, documents relating to bound policies must be retained for defined periods (typically 6 years post-expiration for UK business, longer for certain lines). Auditors will ask you to produce documents from expired policies, at random.

What they're checking:

  • Can you actually retrieve the documents? (Auditors are seeing more “we know we have them but they're in a legacy system we don't use anymore” answers, which is a fail.)
  • Is the metadata intact? Timestamps, actor, version.
  • Are documents on legal hold flagged and excluded from any automated deletion?
  • Is the retention policy documented and applied consistently?

5. Underwriting authority controls

Your binder specifies limits: maximum sum insured per risk, aggregate limits per class, excluded perils, excluded territories. Auditors will look at bound risks against your authority to check every risk was within scope.

The system control they want to see: authority limits enforced at the point of binding, not checked retrospectively. If an underwriter can bind a $10M risk under a $5M binder without the system flagging it, the control has failed. Post-hoc detection of authority breaches, while important, doesn't satisfy the auditor because the risk has already been written.

6. Claims handling — timeliness and evidence

On the claims side auditors check SLA adherence and decision evidence. Acknowledgment within the required window (typically 5 working days for UK personal lines, longer for commercial). Reserving performed and updated as information develops. Coverage decisions documented with rationale.

The failure mode: claims files where the paper trail is complete but the decision rationale is missing. “Claim declined” without the specific policy exclusion cited, or “claim paid” without the coverage confirmation documented.

See how claims automation with structured decision capture addresses this.

7. Conduct and Consumer Duty evidence

For coverholders writing UK retail business, Consumer Duty adds a layer: evidence of good customer outcomes across the four PRIN 2A areas (products & services, price & value, understanding, support). Auditors will ask for MI showing outcome tracking, not just complaint volumes.

See what Consumer Duty actually requires of brokers and coverholders, and the UK compliance overview for the specific evidence expectations.

8. Systems change management

Auditors now routinely ask about how changes to your systems are controlled. If your PAS is upgraded, or your bordereau template is modified, is there a documented change record? Who approved it? What testing was performed? This is standard IT governance applied to insurance operations.

What “audit-ready on day one” actually means

The phrase is used loosely. Operationally, it means the following are true without any special preparation:

  • A specific policy or claim can be selected at random and its complete audit trail produced within minutes
  • The audit trail contains actor, timestamp, and action for every material event
  • Data on the audit trail matches data on the bordereau matches data in the PAS — no reconciliation gap
  • Sanctions, authority, and retention controls are enforced at the workflow level, not applied by post-hoc review
  • Documents from expired policies are retrievable with intact metadata

If those five statements are true, the audit is a straightforward demonstration. If any is not true, the audit becomes a scramble.

The compliance teams solution page covers the operational baseline; the bordereaux rejection piece covers the specific upstream data controls that also serve audit-readiness.

Bottom line

Managing agent audits are not tests. They are evidence exercises. Coverholders who build their operations around continuous evidence generation — audit trail, data integrity, control enforcement — turn the audit into a routine review. Coverholders who build their operations around getting work done and then reconstructing evidence when asked live in cycles of audit stress. The systems difference is smaller than most people think; the operational difference is enormous.

James ThorntonInsurance Operations Lead, UK & Ireland
James leads Regure’s UK and Ireland insurance practice, covering FCA Consumer Duty, Lloyd’s coverholder operations, bordereaux reporting, and the broker / MGA technology landscape across the London market.

Ready to modernize your claims operations?

Book a 20-minute demo and see how Regure automates the manual work holding back your team.

Book a Demo