Insurance

Insurance Compliance Audits in 2026: What Should an MGA or Broker Review Cover?

Regulatory Counsel · Published August 2026 · Last reviewed August 2026 · 12 min read

An insurance compliance audit should establish whether the firm's regulatory framework works in the business that exists today. For an MGA or broker, that means going beyond policies and testing the way products are designed, distributed, sold, serviced and monitored in practice. A firm can have a complete compliance manual and still have weak product governance, poor claims oversight or customer outcome data that is too broad to identify where problems are occurring.

There is no universal FCA rule requiring every insurance intermediary to commission the same annual compliance audit. The scope and frequency of independent assurance should reflect the firm's activities, risks and governance arrangements. A useful audit is therefore not a generic checklist transplanted from another business. It is a risk-based examination of the controls most capable of creating regulatory failure, customer harm or significant remediation exposure.

In 2026, the FCA's Insurance Regulatory Priorities make the direction of travel particularly clear. Consumer understanding, claims handling and service quality remain prominent supervisory themes, while the regulator is also examining delegated and outsourced claims arrangements, product value and distribution. An insurance audit that ignores those areas because last year's audit plan focused elsewhere can miss the issues most likely to attract management and regulatory attention.

Start with the business model, not the audit checklist

The audit should begin by establishing what the firm actually does. For an MGA, that can include product development, underwriting, broker distribution, policy administration, claims and client money arrangements. For a broker, the relevant customer journey may include marketing, demands and needs, advice, product selection, fees, premium finance, policy administration, claims support and complaints. The legal entity, permissions and contractual authority should be mapped against those activities before individual controls are tested.

This matters because the same rule can have very different significance across firms. PROD 4 may be central for an MGA that materially designs products, while a broker acting only as distributor will have a different set of product governance responsibilities. A firm with delegated claims authority should expect claims testing to carry more weight than a broker with no role in claims decisions. Where CASS 5 applies, money handling can warrant detailed operational testing that would be irrelevant to a firm that never receives or holds client money.

The audit scope should also consider what has changed since the last meaningful review. New products, rapid growth, a larger broker network, new Appointed Representatives, changes in delegated authority, higher complaint volumes or new technology can all alter the risk profile. A static audit programme can give false assurance if it continues testing the business the firm used to operate.

The result should be a documented scope that explains why the selected areas matter. That is more defensible than treating every compliance topic as equally important or mechanically rotating through Handbook chapters without reference to actual risk.

Product governance and fair value need evidence behind the conclusion

Where PROD 4 applies, an audit should test the substance of product governance rather than confirm that product approval and fair value templates exist. The reviewer should be able to trace how manufacturer or distributor status was determined, how the target market was defined, what product testing took place and what evidence supports the current fair value conclusion.

For an MGA acting as manufacturer or co-manufacturer, this should include the relationship between product design and actual customer outcomes. Claims, complaints, distribution information, remuneration and other relevant data should be capable of challenging assumptions made when the product was approved. If the product file repeatedly records that outcomes are satisfactory but the supporting data cannot distinguish between products or distribution channels, the governance process may be weaker than the documentation suggests.

Fair value deserves particular attention because it now runs through the relevant stages of product approval. Since 26 June 2026, PROD expressly integrates value considerations into target-market identification, product testing and selection of distribution channels for relevant products. The audit should therefore consider whether value genuinely influenced those decisions or whether the firm completed a retrospective assessment after commercial terms had already been fixed.

The review should also examine remediation. Where product governance previously identified weak value, distribution concerns or poor outcomes, the auditor should establish what changed and whether subsequent evidence shows that the change worked. A finding that remains open through several product reviews is materially different from a concern that was identified, corrected and retested.

Consumer Duty should be tested through the customer journey

For retail business within scope, Consumer Duty testing should focus on the outcomes customers receive rather than the existence of a Duty framework. The audit should use the firm's actual customer journey to assess products and services, price and value, consumer understanding and support in the context of the firm's role.

For an insurance broker, this may mean following a customer from acquisition through demands and needs, product selection, fees, premium finance and after-sales support. For an MGA, the review may place more emphasis on target market, product value, broker distribution, communications and claims. The purpose is to test the parts of the outcome that the firm controls or materially influences.

The FCA's 2026 consumer understanding work raises the standard here. Communication design, testing, monitoring and governance should operate as a coherent process. An audit should therefore look beyond whether required documents contain the right statements and consider whether customers are likely to understand important exclusions, limits, excesses and other features at the point when the information can influence their decision.

Outcome monitoring should also be challenged. A dashboard can contain a large number of metrics and still provide weak assurance if management cannot identify which products, brokers or customer groups receive poorer outcomes. The reviewer should assess whether thresholds are meaningful, whether data is segmented where necessary and whether management action follows when the evidence deteriorates.

Claims and delegated authority should be tested operationally

Claims can be one of the highest-risk areas in an insurance audit because they reveal whether customers receive the benefit the product was designed to provide. Where an insurer or MGA handles claims, the review should assess decision quality, timeliness, customer communication, support, vulnerability, complaints and the operation of delegated limits rather than focusing only on service-level statistics.

ICOBS 8.1 contains the core claims handling requirements for insurers, including handling claims promptly and fairly, providing reasonable guidance and progress information, not unreasonably rejecting claims and settling promptly once terms are agreed. ICOBS 8.3 contains relevant provisions for insurance intermediaries and insurers handling claims on another insurer's policy. The audit scope should therefore reflect the firm's actual role instead of applying the insurer rule mechanically to every intermediary.

The FCA's home and travel claims review is particularly useful evidence of current supervisory expectations. It identified the importance of robust management information, customer-centred claims handling, effective governance and appropriate oversight of outsourced activity. The 2026 Insurance Regulatory Priorities extend that focus through further work on delegated and outsourced claims arrangements and remuneration.

Where a third-party administrator or another delegate performs claims activity, the audit should examine what the regulated firm receives and how it challenges the provider. A contract containing audit rights does not itself demonstrate oversight. The reviewer should establish whether data is sufficiently detailed, whether outliers trigger investigation and whether the firm can identify poor customer outcomes before complaints become the main source of evidence.

Broker, distributor and AR oversight require different tests

An insurance audit should distinguish between oversight of independent brokers and oversight of Appointed Representatives. The regulatory relationships are not interchangeable. An MGA may need information and controls over independent broker distribution to meet PROD and Consumer Duty responsibilities, but an FCA principal assumes a materially different level of responsibility for regulated activities carried on by its AR within the scope of the appointment.

For broker distribution, the audit can test whether target-market information reaches distributors, whether the MGA understands relevant remuneration and customer pricing, whether required outcome information is received and whether broker risk ratings influence monitoring. Repeated data gaps or persistent exceptions should be visible in the governance record rather than accepted indefinitely.

For principal firms, SUP 12 creates a more extensive framework. The audit should consider appointment due diligence, scope, ongoing monitoring, the principal's own resources, annual reviews for relevant ARs, the governing-body self-assessment and event-driven escalation. Complaint and Consumer Duty data should be capable of identifying material differences at AR level where relevant.

The quality of escalation is important in both cases. A monitoring framework that repeatedly identifies a high-risk distributor or AR but never changes the level of oversight is unlikely to be genuinely risk based. The auditor should examine not only the risk methodology but the decisions it produces.

Client money, financial resources and regulatory reporting should reconcile to reality

Where CASS 5 applies, an audit should test how money actually moves. The legal and contractual position should correspond with bank accounts, ledgers, reconciliations and the firm's treatment of insurer agency or risk transfer. A policy that correctly describes the rules provides limited assurance if the finance system applies a different arrangement.

For insurance intermediaries, regulatory reporting can also expose weaknesses that are not obvious from policies. RMAR data should be capable of being traced to reliable sources, and material figures should reconcile where appropriate with financial accounts, client money records, staffing information or other underlying systems. The exact returns and sections depend on the firm's activities, so the audit should use the firm's current RegData schedule and the applicable SUP 16 requirements rather than a generic return list.

Where general insurance value measures reporting under SUP 16.27 applies, the reviewer should understand the data chain behind the submission and its relationship with product governance. The FCA has continued to publish value measures data and has identified reporting inconsistencies in areas such as home insurance claims acceptance. That makes data quality a regulatory issue as well as an administrative one.

The same principle applies to complaints reporting and other applicable returns. A regulatory return can be filed on time and still be unreliable. The audit should consider whether definitions are understood, material manual adjustments are controlled and unexplained changes are challenged before submission.

Sampling should be designed to find risk, not produce a comfortable pass rate

Audit sampling should follow the purpose of the review. A purely random sample may be useful in some circumstances, but it can also miss the cases most capable of revealing a control weakness. Higher-risk products, complaints, claims declines, vulnerable customers, underwriting exceptions, new brokers or unusual fee arrangements may justify deliberate inclusion.

The sample methodology should be documented so that management understands what the testing can and cannot prove. Ten clean files do not establish that an entire process is effective if the sample excluded the cases where the risk is most likely to occur. Equally, a risk-targeted sample should not be presented as though it represents the statistical performance of the whole population.

Evidence should also be drawn from more than customer files. Policies, system permissions, MI, contracts, regulatory returns, board papers, complaints, product files and interviews can each reveal a different part of the control environment. The strongest audits triangulate these sources rather than treating one document as conclusive.

The reviewer should distinguish between design and operating effectiveness. A control can be well designed but poorly executed, or consistently performed while addressing the wrong risk. The audit conclusion should make that distinction clear where it affects remediation.

Findings should lead to prioritised remediation and retesting

A useful audit report tells management what matters most. Findings should therefore be prioritised according to regulatory significance, potential customer harm, affected population, recurrence and the weakness of the existing control. A long report containing dozens of observations with the same rating can obscure the issues that require immediate senior attention.

Root cause should be identified before remediation is finalised. A missing record may indicate an isolated documentation failure, but it may also reveal that the system never requires the information to be captured. Repeated broker data gaps may reflect poor escalation rather than poor broker behaviour. The corrective action should address the reason the weakness exists.

Material customer impact also needs consideration. Where the audit identifies a systemic product, claims or distribution problem, management should assess whether customers beyond the sample could be affected and whether wider remediation is required. That analysis should not be postponed simply because the original audit was described as a controls review.

Closure should then require evidence. Updating a policy can close a documentation point, but it does not establish that behaviour changed. Where the underlying control is material, follow-up testing should show that the remediation has become operational and is producing the intended result.

How Regulatory Counsel can support

Regulatory Counsel supports MGAs, insurance brokers and principal firms with independent compliance audits, thematic reviews and remediation. Reviews can cover the complete insurance compliance framework or focus on areas such as PROD 4, Consumer Duty, claims, delegated authority, broker or AR oversight, client money and regulatory reporting.

Our approach is risk based and evidence led. The objective is to identify the regulatory issues that matter, explain their practical impact and leave management with a prioritised remediation plan rather than a generic checklist.

Speak to Regulatory Counsel to discuss an insurance compliance audit.

Frequently Asked Questions

There is no universal FCA rule requiring every insurance intermediary to commission the same annual compliance audit. The firm's assurance framework should reflect its activities, risk, governance and applicable regulatory requirements. Specific audit obligations can apply in particular contexts, so firms should distinguish those from a broader compliance review.

The scope depends on the firm, but can include PROD 4, Consumer Duty, ICOBS, claims, delegated authority, broker or AR oversight, CASS 5, complaints, regulatory reporting, governance and remediation.

Where file-level evidence is relevant, sampling can be important. The sample should reflect the regulatory risk being tested and may include higher-risk or exception cases as well as routine files.

Compliance monitoring is the firm's continuing risk-based assurance process. An audit is typically a more defined review of a particular period, framework or theme and can provide additional independent challenge. The two should complement rather than duplicate each other.

Yes. A thematic review can focus on a specific area such as fair value, claims, Consumer Duty, delegated authority, client money or Appointed Representative oversight.

Need Expert Advice?

Free initial consultation. No obligation.

Speak to an Expert