An MGA compliance monitoring programme should tell management whether the regulatory controls that matter are actually working. It should not be a calendar of policies scheduled for annual review, and it should not measure success mainly by the number of files checked. For an MGA, the most significant risks often sit at the point where product design, delegated authority, broker distribution and customer outcomes interact, so monitoring needs to follow the operating model rather than a generic FCA checklist.
This article is deliberately sector specific. Regulatory Counsel already has a broader guide to building an FCA compliance monitoring programme, covering risk assessment, testing methods, reporting and governance across regulated firms. The question here is different: which areas should an MGA prioritise, what evidence should it test, and how should the 2026 insurance supervisory agenda influence the plan?
For many insurance intermediaries, SYSC 3 requires effective systems and controls for compliance with applicable requirements and regular assessment of their adequacy. The precise Handbook application depends on the firm's classification, so an MGA should map its own regulatory position rather than assume that every detailed compliance-function rule applies identically. The monitoring programme should then provide proportionate assurance across the risks that are material to that business.
Build the monitoring universe from the MGA's actual regulatory model
The starting point should be a regulatory risk assessment that reflects what the MGA currently does. Management should understand which products the firm manufactures or distributes, the nature of its delegated underwriting and claims authority, how business reaches customers, whether Consumer Duty applies, how money is handled and which third parties are critical to the customer journey.
This determines the monitoring universe. An MGA with significant manufacturer responsibilities may place PROD 4, target market, fair value and distribution near the top of the plan, while a firm exercising material claims authority may need deeper claims testing. An MGA with client money exposure needs an appropriate CASS workstream, whereas a firm that never receives or holds relevant money should not copy a client money review into the plan simply because another MGA has one.
The risk assessment should also distinguish inherent risk from control strength. A high-risk activity may have strong controls and still warrant meaningful assurance because the consequence of failure is significant. Conversely, an area that appears operationally routine can deserve attention where the firm has identified repeated findings or weak data.
A useful monitoring universe is therefore recognisably connected to the business. Senior management should be able to look at the plan and understand why the highest-risk products, distribution channels and delegated activities receive the greatest attention.
Overlay the FCA's 2026 insurance priorities without copying them blindly
The FCA's 2026 Insurance Regulatory Priorities should be a formal input into the monitoring plan. The report tells boards and chief executives to review the priorities and act where relevant, and it places particular emphasis on consumer understanding, claims handling, service quality and the oversight of outsourced and delegated claims arrangements.
That does not mean every MGA should paste the FCA's priorities into its monitoring calendar. The firm should assess which themes intersect with its own products and activities. An MGA operating delegated home or travel claims, for example, has a more direct reason to test claims oversight in depth than a wholesale MGA with no retail claims role.
Fair value also remains important. The FCA's 2026 report tells firms to continue their fair value assessments, while current PROD rules require value to be considered throughout product approval and distribution. Where an MGA manufactures retail insurance products or exercises significant pricing and distribution influence, the monitoring programme should test the evidence behind those conclusions rather than merely confirm that an assessment exists.
Supervisory priorities should therefore sharpen the firm's existing risk assessment. They are most useful when they cause management to ask whether an area already considered medium risk deserves deeper review because the FCA is seeing market-wide problems in the same activity.
Design tests to challenge the control, not confirm the document exists
Every monitoring review should begin with a clear question. If the firm is testing delegated underwriting authority, the objective may be to determine whether cases outside defined parameters are referred correctly. If it is testing fair value, the objective may be to determine whether management has enough claims, remuneration and distribution information to support the conclusion reached.
The methodology should then be chosen to answer that question. File sampling, data analysis, walkthroughs, interviews, system testing and document review can each be appropriate, but no single technique is sufficient for every risk. A review that checks policy wording without observing the underlying workflow may miss the control failure that matters most.
Independence should also be considered proportionately. First-line quality assurance can provide useful evidence, particularly in smaller firms, but compliance should understand whether it is relying on a control owner to assess their own process. Where the regulatory risk is material, additional second-line challenge or an independent thematic review may be appropriate.
Sampling should be purposeful rather than purely random. Complaint cases, pricing exceptions, high-risk brokers, vulnerable customers, authority breaches and rapidly growing products may provide more insight than a sample dominated by routine files. Random sampling can still be useful, but the monitoring plan should be designed to find weaknesses rather than maximise the number of clean files.
Test PROD 4 through the evidence chain
For an MGA with manufacturer or distributor responsibilities, product governance should be tested through the full evidence chain. The review should not stop at confirming that a product approval document, target market and fair value assessment exist, because the more important question is whether the underlying data supports the conclusion and whether the process is capable of identifying poor outcomes.
A manufacturer review can test whether the target market is sufficiently granular, whether significant product changes trigger approval, whether fair value considers the full distribution chain and whether the scheduled review interval is supported by the current risk-based framework. The reviewer should then trace claims, complaints, distributor information and other MI into the product decision to see whether governance is actually using live customer evidence.
Distributor testing should examine whether the MGA obtains enough manufacturer information to understand the product and value assessment and whether its own remuneration, services and distribution strategy remain consistent with fair value. If the firm adds premium finance, customer fees or additional products, those features should be reflected in the review where relevant.
The strongest test asks whether the process has consequences. A product governance framework that identifies an adverse trend but does not change the product, channel or remuneration may require deeper investigation even where the paperwork is complete.
Test broker oversight for outliers and information quality
Broker oversight monitoring should reflect the distinction between independent brokers and ARs. For independent brokers, the MGA should test whether its product governance and contractual information rights are working, rather than imposing the full SUP 12 framework that belongs to Appointed Representative relationships.
The review can examine onboarding, product and target-market information, risk segmentation, remuneration data, complaint trends, customer pricing and the broker's compliance with information requirements. It should also test whether the risk rating changes the intensity of oversight and whether adverse evidence produces escalation.
Data quality is a major part of the control. If the MGA needs broker information for fair value or product review, compliance should test whether the data received is complete, timely and sufficiently reliable to support the conclusion. Repeated gaps should not disappear inside a monitoring report as an administrative observation if they prevent the firm from evidencing a regulatory requirement.
Where complaints or claims identify outliers, the monitoring programme should be able to investigate further. This can include targeted file review, direct broker engagement or deeper analysis of a particular distribution channel. The purpose is to understand why the outcome differs and whether the issue sits with the broker, the product or both.
Test delegated underwriting and claims against real authority
Delegated underwriting monitoring should compare contractual limits with actual decisions. The reviewer should understand the products, risk parameters, pricing discretion, authority limits and referral rules and then test whether staff and systems operate within them. A clean binder agreement is not strong assurance if operational systems allow underwriters to exceed authority without an effective referral control.
Claims testing should follow the authority and customer risk. Relevant areas can include settlement limits, repudiation, referrals, service standards, vulnerable customers, complaints and the quality of oversight where claims are outsourced to a third-party administrator. The FCA's 2026 focus on outsourced and delegated claims arrangements makes this a natural priority for firms with material exposure.
The monitoring should also look for recurring causes. Several small authority breaches caused by the same workflow weakness can be more significant than one larger isolated exception, because they indicate that the control design itself may be ineffective.
Claims and underwriting evidence should feed back into product governance where appropriate. A recurring claims decline reason or a change in risk selection can reveal that product assumptions, target-market boundaries or customer communications need review, which is why monitoring should avoid treating these functions as regulatory silos.
Test Consumer Duty and ICOBS through the customer journey
Where Consumer Duty applies, the monitoring programme should focus on actual outcomes rather than the existence of a Duty policy or annual board report. Product and services, price and value, consumer understanding and consumer support should be connected to the data the MGA already holds across distribution, claims and complaints.
Consumer understanding is particularly relevant in 2026. Monitoring can test whether significant exclusions and limitations are communicated in a way customers can understand, whether customer testing or other evidence is used where appropriate and whether recurring complaints or claims disputes are changing the firm's communication approach.
ICOBS remains relevant alongside the Duty. The monitoring programme should identify the detailed rules that apply to the MGA's activities and test them within the real customer journey. This avoids both a narrow checklist approach that ignores outcomes and a high-level Consumer Duty review that overlooks specific conduct requirements.
The governing-body Duty assessment should be traceable to the underlying evidence. Compliance should be able to identify where outcomes are weaker, whether the data is sufficiently segmented to reveal differences, and whether the board's conclusion is supported by the product and customer evidence beneath it.
Test CASS operationally where client money rules apply
Where the MGA receives or holds money in a way that brings CASS 5 into scope, monitoring should use operational evidence rather than treating client money as a policy review. The firm should understand which money is held under client money trust arrangements, which money is held as agent of an insurer and how those different treatments are reflected in systems, accounts and reconciliations.
Testing can include the relevant agency agreements, bank accounts, ledger entries, reconciliations, commission withdrawals and exception handling. Where insurer agency or risk transfer is relied upon, the reviewer should confirm that the written authority and customer disclosure align with the actual money flow.
Mixed arrangements deserve additional attention because the same firm can operate on an insurer-agency basis for some transactions and under client money trust arrangements for others. Compliance should be able to explain how finance systems distinguish them and how errors would be detected.
The monitoring scope should remain tailored to the firm's actual CASS position. A generic client money checklist can create false comfort if it does not follow the particular agency and trust arrangements the MGA uses.
Rate findings by regulatory impact and close them with evidence
The monitoring report should help management distinguish material regulatory weaknesses from administrative improvements. Findings should consider the rule or expectation involved, potential customer harm, systemic impact, recurrence and whether the weakness undermines the firm's ability to evidence another regulatory conclusion.
Root-cause analysis should be proportionate to the issue. A missing document caused by one isolated filing error may require a simple fix, while repeated missing evidence across a product could indicate a system or governance weakness. The action should address the reason the control failed rather than simply correct the files already identified.
Closure requires evidence. A revised policy shows that documentation changed, and training shows that staff received information, but neither proves that the process now works. Material findings may need a follow-up sample, system evidence or outcome data before compliance can conclude that the risk has been resolved.
This discipline is particularly important where the same theme has appeared in previous monitoring cycles. Repeated findings that are continually marked complete without a change in underlying outcomes can indicate that the remediation process itself is weak.
Use the annual plan as a live governance tool
A compliance monitoring programme should be approved through appropriate governance, but it should not become fixed for the remainder of the year. New products, broker growth, complaints, regulatory change or a material claims issue can justify changing the scope or timing of planned work.
A useful board report should explain what has been tested, what was found, where risk is increasing and which actions are overdue. Reporting only the percentage of the monitoring plan completed can create an illusion of control because it says little about whether the firm's highest risks are well managed.
An MGA in 2026 should therefore treat the monitoring plan as a live assurance programme. The highest-quality programmes are not those with the most reviews, but those that direct limited compliance resource towards the controls most capable of causing significant regulatory failure or customer harm and provide clear evidence that weaknesses are being resolved.
Illustrative monitoring priorities for an MGA
| Risk area | What the review should establish | Typical evidence |
|---|---|---|
| PROD 4 and fair value | Product governance conclusions are supported and acted upon | Product files, claims, complaints, remuneration, distributor MI |
| Broker distribution | Target market, pricing and information flows operate as intended | Broker MI, fees, complaints, risk ratings, sample files |
| Underwriting authority | Decisions stay within delegated authority and referrals work | Underwriting files, system controls, referral logs |
| Claims | Decisions, service and support meet the applicable framework | Claims files, decline reasons, complaints, service MI |
| Consumer Duty and ICOBS | Customer journey and outcomes are supported by evidence | Communications, testing, complaints, call or journey reviews |
| CASS 5 where applicable | Money handling matches the legal and contractual framework | Agency agreements, bank records, reconciliations, ledgers |
How Regulatory Counsel can support
Regulatory Counsel supports MGAs with compliance risk assessments, monitoring programme design, thematic reviews, sampling, testing, findings, board reporting and remediation. We can build or review the full programme or provide independent testing of higher-risk areas such as PROD 4, delegated authority, claims, Consumer Duty, broker oversight and CASS.
Speak to Regulatory Counsel to discuss an MGA compliance monitoring programme.
Frequently Asked Questions
No. The programme should reflect the firm's own activities, regulatory classification, products, customers, delegated authority and distribution model. A generic template can be a starting point, but it should not replace a firm-specific risk assessment.
Not necessarily. The programme should be risk based and capable of changing when risk changes, although some high-impact controls may justify frequent assurance even where previous results have been satisfactory.
Yes where customer or transaction-level testing is relevant to the risk under review, but file checking should not become the whole programme. Data analysis, system testing, walkthroughs and governance review can be equally important depending on the control.
It can provide useful evidence, but compliance should understand the independence and scope of that assurance. Material risks may require additional second-line or independent testing rather than relying solely on the control owner to assess their own process.
The evidence should demonstrate that the underlying weakness has been corrected, not merely that an action was completed. For material issues this may require follow-up testing, system evidence or outcome data showing that the control now operates effectively.