Insurance

MGA Compliance in 2026: FCA Requirements for UK MGAs

Regulatory Counsel · Published August 2026 · Last reviewed August 2026 · 14 min read

An MGA compliance framework should reflect the business the firm actually operates, because "MGA" is a commercial description rather than a single FCA regulatory category. One MGA may exercise substantial authority over product design, pricing, underwriting and claims, while another performs a much narrower distribution role within parameters established by an insurer. The regulatory risks and controls should therefore follow the firm's permissions, products, contractual authority and customer journey rather than a generic MGA checklist.

That distinction is particularly important in 2026. The FCA has simplified parts of the insurance rulebook while sharpening its emphasis on consumer understanding, claims handling, fair value and oversight of delegated arrangements. The regulator's direction is not towards less accountability, but towards more proportionate rules supported by clearer evidence that firms understand and control the risks that matter.

For senior management, the practical objective is to be able to explain the relationship between the MGA's business model and its regulatory framework. Permissions, product governance, broker distribution, delegated authority, claims, Consumer Duty and compliance monitoring should operate as connected parts of the same system rather than separate compliance workstreams.

Start with permissions and the real operating model

The first step is to map what the MGA actually does. Management should understand the regulated activities undertaken by the legal entity, the permissions relied upon, the insurers providing capacity, the authority delegated under each material arrangement and the customer groups and distribution channels through which business is written.

Contractual authority and regulatory permission are related but different. An insurer may permit an MGA to bind risks, issue documents, apply underwriting criteria or handle claims, but the MGA still needs to ensure that the regulated activities it performs are within the scope of its FCA permissions and that the wider operating structure is legally and regulatorily coherent.

This analysis should be refreshed as the firm grows. MGA models can evolve quickly as new products are added, underwriting discretion expands, broker networks grow or claims responsibility changes. A perimeter assessment that was accurate at launch can become outdated if material business changes do not trigger regulatory review.

Compliance should therefore have a defined role in significant product, authority and distribution changes before they go live. The aim is not to slow commercial development, but to avoid the more expensive problem of discovering later that the firm's permissions, contracts and operating model no longer align.

Product governance should follow the MGA's actual role

PROD 4 is central for many MGAs because the firm may be involved in both product manufacture and distribution. The correct analysis should be performed for each material product, because the same MGA can have a substantial design role in one scheme while acting mainly as distributor in another.

Where the MGA is a manufacturer or co-manufacturer, the product governance framework needs to address product approval, target market, testing, fair value, distribution strategy and continuing review. Where the MGA acts as distributor, it still needs appropriate distribution arrangements and enough manufacturer information to understand the product and customers for whom it was designed.

The underlying decision-making should match the written allocation. If the MGA determines significant coverage, pricing or target-market features while the insurer's documentation assumes that the insurer alone manufactures the product, the governance position may need to be revisited. Product responsibilities should describe commercial reality rather than be chosen because one allocation appears administratively easier.

The December 2025 and June 2026 PROD changes also need to be reflected in current procedures. The lead manufacturer option can simplify qualifying co-manufacturing arrangements, while the newer fair value provisions embed value more explicitly throughout product development. Older product governance templates should be checked against the current framework rather than carried forward automatically.

Broker distribution should produce regulatory evidence

MGAs often rely on independent brokers for customer access, which means a material part of the customer outcome is created outside the MGA itself. The MGA does not supervise an independent broker in the same way a principal supervises an Appointed Representative, but it still needs enough information and control to meet its own product governance and distribution responsibilities.

The starting point is whether the broker is an appropriate channel for the product. The MGA should understand the customers the broker serves, the nature of its distribution model, how product information is communicated and whether remuneration or pricing discretion could affect the value received by customers.

Oversight should then use evidence rather than relationship familiarity. Complaints, target-market exceptions, unusual growth, customer charges, claims patterns and failures to provide required data can all indicate that further review is necessary. Riskier products and channels should attract greater scrutiny than stable lower-risk arrangements.

The important point is that broker information should flow back into product governance. A commercial account-management process that identifies a deteriorating broker relationship but never informs the product or compliance teams is incomplete. Distribution oversight is strongest when commercial, product and regulatory information reinforce each other.

Delegated underwriting and claims authority need operational controls

Delegated authority should be translated into controls that staff and systems can follow. For underwriting, the firm should know the products, customer types, risk parameters, pricing discretion, financial limits and referral requirements within which underwriters can act. Where systems can enforce those boundaries automatically, that can provide stronger control than relying solely on staff memory and retrospective review.

Claims authority requires similar clarity. Settlement limits, repudiation authority, exceptional payments, fraud referrals and cases requiring insurer approval should be understood by the staff making decisions and reflected in the workflow. Where a third-party administrator is used, the MGA should also understand what oversight information it receives and who remains responsible for regulatory decisions.

A common risk is gradual drift between the agreement and actual practice. Commercial teams can develop informal ways of working that become accepted over time even though the formal authority has not changed. Compliance monitoring should therefore compare the contract, systems and actual case handling rather than reviewing the written agreement in isolation.

Material authority breaches also need root-cause analysis. If the same type of exception occurs repeatedly, management should determine whether the issue is training, ambiguous authority, system design or the commercial structure itself. Repeatedly correcting individual cases without addressing the underlying cause provides weak assurance.

Consumer Duty should be visible in product and claims data

For retail business within scope, Consumer Duty should be integrated into the MGA's existing insurance governance rather than operate as a separate annual exercise. The products and services outcome connects naturally with PROD target-market work, while price and value should align with the firm's fair value assessment and understanding of distribution economics.

Consumer understanding is particularly important because customers may not appreciate significant exclusions or limitations until they need to make a claim. Claims disputes, complaints, customer enquiries and communication testing can therefore provide evidence about whether product information is working in practice.

Consumer support becomes most visible when a customer needs assistance. Claims, cancellation, policy changes and vulnerability can all test whether the firm's processes allow customers to obtain appropriate support without unreasonable barriers. Where these functions are delegated, management still needs information sufficient to understand relevant outcomes.

The governing body's Consumer Duty assessment should draw on this operational evidence. A polished annual report is not strong assurance if the firm cannot identify which products, brokers or customer groups produce weaker outcomes and what management changed as a result.

Claims should inform more than the claims team

Claims are one of the most valuable sources of regulatory information available to an MGA because they reveal how the product performs when customers need the promised benefit. The FCA's 2026 Insurance Regulatory Priorities make this especially relevant, with ongoing supervisory work around claims handling and an expanded review of outsourced and delegated authority claims models.

Management should therefore look beyond headline service measures. Depending on the product, relevant evidence can include claims handling times, acceptance and decline patterns, reasons for decline, complaints, vulnerable customer outcomes and cases that exceed or test delegated authority.

The key is interpretation rather than data volume. A high decline rate may be legitimate for one type of product but concerning for another. Repeated disputes concerning the same exclusion may indicate a communication or product design problem even where the claims decisions themselves are technically correct.

Claims information should feed product review and Consumer Duty monitoring where relevant. If product governance and claims functions operate independently, the MGA can miss evidence that the assumptions made when the product was designed are no longer supported by actual customer experience.

Compliance monitoring should follow the risks that matter

The monitoring programme should be built from the firm's regulatory risk assessment rather than copied from the previous year. An MGA with material product-manufacturing responsibility and delegated claims authority needs a different programme from a smaller intermediary with limited authority and no direct retail customer contact.

Depending on the model, monitoring can include PROD 4, Consumer Duty, ICOBS, broker distribution, underwriting authority, claims, complaints, client money, financial crime and regulatory reporting. The important question is not whether every subject appears every year, but whether the plan gives appropriate attention to the risks capable of causing significant regulatory failure or customer harm.

Sampling should be similarly purposeful. Higher-risk products, unusual underwriting exceptions, complaints, vulnerable customer cases or a fast-growing broker may provide more useful evidence than a random selection dominated by routine files. The method should allow compliance to find problems rather than maximise the number of files recorded as reviewed.

Findings need clear ownership and evidence-based closure. A policy update or training session may be part of remediation, but neither proves that an operational weakness has been resolved. Material findings should be retested where necessary so management can distinguish completed actions from effective remediation.

Governance should tell management what needs attention

Senior management should receive information that allows it to understand the MGA's regulatory position rather than simply the volume of compliance activity undertaken. The governing body should know which products or broker channels present the greatest risk, what claims and complaints are showing, which material findings remain open and whether regulatory change requires action.

This also means presenting uncertainty. Where data is incomplete or the firm cannot yet demonstrate a positive outcome, the issue should be visible rather than converted automatically into a green status. Good governance is strengthened by evidence of management challenge, not by a dashboard in which every indicator remains satisfactory.

Insurer relationships should form part of that framework. Material delegated authority issues, customer harm or product governance concerns may require escalation under the contractual arrangements as well as internal governance. The MGA should know who communicates with each capacity provider and how significant issues are documented.

An FCA-ready MGA is therefore not one that claims never to have problems. It is one that understands its business, identifies problems early, assesses their regulatory and customer impact and can demonstrate that management acts on the evidence.

How Regulatory Counsel can support

Regulatory Counsel supports MGAs with ongoing FCA compliance, PROD 4, Consumer Duty, broker oversight, delegated authority, claims governance, compliance monitoring and regulatory remediation. We can review the complete MGA framework or undertake a focused review of a particular product, distribution channel or regulatory risk.

Speak to Regulatory Counsel to discuss MGA compliance support.

Frequently Asked Questions

No. MGA is a commercial description, and the regulatory position depends on the activities undertaken and the permissions held by the relevant entity. The framework should therefore follow the actual operating model.

It can apply to an MGA as manufacturer, distributor or both, depending on the firm's role in relation to the particular product. That role should be determined from the substance of the arrangement.

The precise level depends on the MGA's role, product and distribution model. Product governance and Consumer Duty responsibilities can require the MGA to obtain and assess information about relevant distribution and customer outcomes.

Yes, depending on the firm's permissions and contractual arrangements. The authority should be clearly defined and supported by operational controls and appropriate oversight.

Yes. Support can cover defined regulatory projects, independent monitoring or additional retained senior compliance capacity alongside the firm's existing compliance arrangements.

Need Expert Advice?

Free initial consultation. No obligation.

Speak to an Expert