Delegated authority allows insurance firms to place underwriting, claims and administrative functions with businesses that may have specialist expertise, distribution reach or operational capability. The commercial logic can be strong, but delegation also creates regulatory distance between the firm responsible for an outcome and the people making day-to-day decisions.
That is why effective delegated authority governance requires more than a binder, TOBA or service agreement. Management needs to know precisely what has been delegated, whether the delegate remains capable of performing it, what information demonstrates that the arrangement is working and what happens when authority or customer outcomes move outside expectations.
This is particularly relevant in 2026. The FCA's Insurance Regulatory Priorities include an expanded review of oversight of outsourced claims processes and delegated authority models, with findings expected in early 2027. Firms should therefore assume that the regulator will be interested not simply in whether oversight arrangements exist, but in whether they are sufficiently strong to identify poor outcomes and control failures in practice.
Define the delegated authority precisely
"Delegated authority" can describe materially different arrangements. An insurer may delegate underwriting within defined parameters, policy issuance, administration, claims handling or combinations of these activities, while an MGA may itself delegate elements of servicing or claims to another provider.
The first governance requirement is therefore a clear responsibility map. For underwriting, management should know which products, territories, customer groups and risks the delegate can bind, what pricing discretion exists and when referral to the insurer is required. For claims, the arrangement may need to distinguish investigation, settlement authority, repudiation, fraud escalation and exceptional payments.
The map should identify what remains with the delegating firm as clearly as what has moved to the delegate. Ambiguity can create situations in which each firm assumes the other owns a product governance, claims or customer communication responsibility.
The regulatory perimeter should then be checked against that allocation. Contractual authority from an insurer does not by itself determine whether the intermediary has the FCA permissions necessary for every activity it performs, while regulated status does not make a loosely drafted authority sufficiently clear.
Due diligence should reflect the significance of the authority
The delegating firm should assess whether the proposed delegate is capable of performing the activity appropriately before material authority is granted. The depth of that assessment should reflect the nature of the function, customer population and potential for harm.
An MGA receiving broad underwriting and claims authority for a complex retail product deserves a different assessment from a provider performing a narrow administrative service. Relevant considerations can include regulatory status, ownership, management, financial position, product expertise, systems, compliance capability, claims experience and the quality of management information the firm can produce.
The delegating firm should also assess its own capability to oversee the relationship. Selecting a technically strong MGA does not create an effective control environment if the insurer has insufficient knowledge or resource to challenge underwriting, product governance or claims outcomes.
This is a recurring practical issue in delegated models. The more expertise that moves outside the insurer, the greater the risk that internal teams become dependent on the delegate's own assessment of its performance. Oversight should therefore preserve enough internal understanding to challenge rather than merely receive reports.
Contracts and systems need to describe the same arrangement
A delegated authority agreement should define the permitted activity, but the operating systems need to enforce or identify those limits in practice. If an MGA may bind business only within specified underwriting parameters, technology and workflow should support the appropriate referral process rather than relying solely on retrospective detection.
Claims authority requires the same discipline. Settlement limits, repudiation rights and exceptional decisions should be clear to claims handlers and reflected in system permissions or review controls where appropriate. The fact that the contract contains a limit is weak protection if the day-to-day process allows it to be exceeded routinely.
The greatest risk is often gradual drift. Commercial relationships develop, informal exceptions become normal and new products or responsibilities are introduced without a corresponding update to the authority. Over time the contract, systems and real working practices can begin to describe different arrangements.
Periodic review should therefore compare all three. Where authority has genuinely changed, the documents and compliance framework should be updated. Where operational practice has drifted beyond agreed authority, management should understand why and correct the underlying control.
Delegated underwriting and PROD 4 are closely connected
An MGA can acquire manufacturer responsibilities through the substance of its role in product design. Where it determines essential features such as coverage, pricing, target market or other material elements, the manufacturer analysis under PROD should reflect that reality rather than assume the insurer is solely responsible because it provides capacity.
Where both insurer and MGA manufacture the product, the responsibilities should be addressed through the applicable PROD arrangements. Product approval, target market, fair value, distribution strategy and product review then need information and cooperation across the firms involved.
Delegated underwriting information can also become valuable product governance evidence. Referral patterns, pricing exceptions, changing risk profiles and shifts in the customer population can reveal that the product is operating differently from the assumptions used when it was approved.
This means underwriting oversight should not focus only on whether the MGA stayed inside financial limits. A technically compliant underwriting decision can still contain information relevant to target market, value or product design. The governance framework should enable that evidence to reach the people responsible for the product.
Claims oversight should assess quality as well as speed
Claims are a particularly important delegated function because this is often where the customer experiences the real value of the insurance product. Traditional service measures such as turnaround time can be useful, but they do not establish whether decisions are fair, explanations are clear or customers receive appropriate support.
Depending on the product, management may need to understand claim acceptance and decline patterns, reasons for decline, settlement experience, complaints, vulnerable customer outcomes, long-running cases and instances where delegated authority is exceeded or tested.
The evidence should be capable of identifying differences between providers, products or channels. A materially different decline rate associated with one claims administrator may have a legitimate explanation, but it should be understood. Oversight is weak when unusual results are visible in the data but never generate challenge.
Claims can also reveal weaknesses elsewhere. Repeated disputes concerning the same exclusion may indicate poor consumer understanding or product design, while significant friction in the claims process can affect the practical value customers receive. Claims information should therefore feed Consumer Duty and product governance where relevant.
Management information should tell the firm when to intervene
Effective delegated authority oversight does not require the largest possible reporting pack. It requires information that can identify when the arrangement is no longer operating as expected.
For underwriting, this may include authority exceptions, referral patterns, pricing deviations, product mix and rapid changes in volume. For claims, the useful measures may concern service, outcomes, complaints and authority. The right indicators depend on the activity rather than a standard template.
The firm should also define what happens when those measures deteriorate. A material increase in complaints or authority breaches should be capable of changing the level of review before the next scheduled annual audit. Oversight that remains identical regardless of the evidence is not genuinely risk based.
Direct testing remains important because aggregate data can conceal poor individual outcomes. File reviews, thematic testing and audits can provide assurance that is not available through MI alone. Contractual audit rights should therefore be connected to an actual methodology for deciding when deeper review is required.
Remuneration and conflicts belong inside the oversight framework
Delegated authority arrangements are commercial relationships, and the way firms are paid can influence behaviour. MGA commission, profit commission, claims remuneration and other performance-related payments should therefore be understood as part of the regulatory risk assessment rather than treated exclusively as finance matters.
For relevant products, remuneration also interacts directly with fair value. Distribution costs can increase the final customer price, while some incentive structures may affect underwriting or claims behaviour. The presence of remuneration is not itself problematic, but the firm should understand whether the incentive could create outcomes inconsistent with the regulatory framework.
Claims remuneration deserves particular care where payment arrangements could encourage cost reduction in a way that conflicts with fair treatment of customers. Similarly, an underwriting incentive linked solely to volume or profitability may warrant consideration alongside product and conduct controls.
The objective is not to eliminate commercial incentives. It is to ensure that management understands them, monitors their effect and can demonstrate why they remain compatible with appropriate customer outcomes.
Breaches and remediation should address the cause
Not every delegated authority breach requires the same response. A minor administrative exception may require correction and monitoring, while repeated underwriting outside authority, systemic claims failures or material customer harm may justify restrictions, deeper investigation or reconsideration of the relationship.
The escalation process should therefore reflect seriousness, recurrence and potential impact. Management should avoid treating every breach as an isolated incident if the pattern indicates that the underlying control is failing.
Root cause is essential. If the system itself allows staff to operate beyond delegated limits, another training session is unlikely to provide a lasting solution. If the parties have different interpretations of responsibility, rewriting one internal procedure may leave the fundamental governance gap untouched.
Material remediation should identify what failed, why it failed, whether customers were affected and what evidence will demonstrate that the corrective action has worked. The delegating firm should retain sufficient oversight to challenge closure rather than rely exclusively on the delegate confirming that its own actions are complete.
How Regulatory Counsel can support
Regulatory Counsel supports insurers, MGAs and insurance intermediaries with delegated authority governance, underwriting and claims oversight, PROD 4, management information, remuneration, Consumer Duty and regulatory remediation. We can review an individual arrangement or the firm's wider delegated authority framework.
Speak to Regulatory Counsel to discuss delegated authority compliance support.
Frequently Asked Questions
No. Delegation does not remove regulatory obligations that continue to apply to the insurer. The respective responsibilities should be mapped against the activities actually performed.
Potentially. Manufacturer status under PROD depends on the MGA's actual decision-making role in designing and developing the product rather than simply the existence of a delegated authority agreement.
The appropriate framework depends on the product and authority, but can include claims decisions, declines, complaints, vulnerability, service, delegated limits, management information and remediation. Oversight should consider customer outcomes as well as operational performance.
There is no single review frequency appropriate for every arrangement. Oversight should reflect the risk of the activity and respond to material changes or adverse indicators rather than rely only on a fixed annual timetable.
Yes. We can assess regulatory responsibilities, authority limits, product governance, customer outcomes, remuneration, management information, audit rights and remediation.