This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.

InsurTech World

| 5 minute read

Insurance claims, delgated authority and governance challenges across Carrier-MGA-TPA-Supply Chain ecosystem

In thye UK, USA and Australia financial regulators place a huge challenge for the insurance ecosystem partners that provide capacity, cover risk under delagated authority, outsource some or all claims to TPAs and manage the supply chains to repair, restore and replace lost and damage. 

The regulatory case is already explicit, not anticipatory

You don't need to forecast this in the UK — the FCA has said it. Its Regulatory Priorities for Insurance 2026 extends oversight to delegated authority models, remuneration arrangements, and the use of AI in underwriting and claims, with a separate review of MGA and coverholder governance reporting findings in early 2027. That review runs from Q2 2026 and centres on claims handling and consumer outcomes under Consumer Duty; capacity providers renewing terms should expect to ask for audited claims-handling MI and evidenced customer outcomes as conditions of capacity rather than good practice.

The sub-delegation point is a thorny problem and has a number attached to it: over 90% of MGAA members outsource claims to a third party, and the FCA has confirmed it is expanding its review of oversight of outsourced claims processes to include different delegated authority models and remuneration arrangements. The failure mode is already documented — in the FCA's 2026 home and travel claims work, the most commonly cited failure was inadequate oversight of outsourced claims handlers: insurers delegated and lost visibility, data did not flow back in a form permitting meaningful oversight, governance meetings produced no actionable MI, and contractual audit rights went unexercised. Deloitte adds the operational detail that many insurers rely on TPA MI that is 30–60 days out of date, which undermines their ability to spot emerging harm or evidence control over their claims processes.

Then add in the increasing adoption of digital agent-authorisation : the Treasury Committee has recommended the FCA publish practical guidance by end-2026 on accountability and the level of assurance expected from senior managers under SMCR for harm caused through AI, and firms are being told to prepare for guidance on audit trails and explainability expected by the end of 2026.

And remember- the capacity provider has the liability which is not transferred to those with delegated authority

  • Australia is actually the sharpest legal statement of my exact point. CPS 230's premise is that you can outsource services but not accountability for operational risk, with obligations flowing downstream to material service providers through contracts — and claims processors are named as an example of an MSP. The last transition arrangements expired on 1 July 2026, so every material service provider contract must now meet the standard whether or not it has come up for renewal, alongside an updated MSP Register template.
  • US: insurers remain accountable for third-party vendor model outputs, and "we don't have access to model internals" is not an accepted examination response, with the bulletin adopted in roughly 25 states by mid-2026. More interesting for you: the NAIC is advancing a proposal for a registry of vendors supplying AI models and datasets to insurers, to give regulators visibility and ensure those third parties maintain appropriate governance. That pulls the tech provider itself into the regulatory frame.
  • EU: worth updating the timeline. High-risk Annex III obligations — documentation, automatic logging, human oversight — have moved from 2 August 2026 to 2 December 2027 following Council approval on 29 June 2026, with product-embedded systems to August 2028. The EU is now the laggard on this clock, not the driver.

How will  claims management platforms tackle the challenges? 

Two key kinds of outcome.

One is a claim-level operational audit trail — every action, touch and approval on the claim record. The other is authority provenance: which instrument granted this authority, to whom, with what limits, signed by which named human, effective from when, superseded when. Your question asks for the second ("who gave the authorisation for the rules the agents followed"). They are different data models and the second is not a byproduct of handling claims.

The solution providers must offer a governed operating layer across intake, triage, assessment, suppliers, finance, communication, reporting and audit, used directly by claims teams (internal and outsourced), MGAs, TPAs, brokers and suppliers, with delegated authority enforced, segregation of duties and every movement logged. 

Various tech providers address the gaps

Aptly is explicitly building the cascade model: governing authority delegated to MGAs, coverholders and TPAs as well as internal authority, and recalling who held what authority, at every delegated party, on any date, with the instrument behind it. Guidewire claims native bordereaux, regulatory controls and audit traceability for delegated authority without custom development. Regure markets Consumer Duty audit trails and automated evidence generation across brokers, MGAs, carriers and TPAs. 

And Lloyd's is the precedent that cuts both ways. It already runs a mandated version of what I describe: DDM as a central bordereaux platform standardising collection and validation of DA risk, premium and claims data, integrated with DCOM so contract data flows without rekeying, plus Delegated Audit Manager for managing audit of coverholders and claims TPAs. That proves cross-market DA evidence infrastructure is viable and fundable — but it's a reporting infrastructure, not authorisation provenance, and in the subscription market the corporation may pre-empt a vendor. The unserved space is the company market and non-Lloyd's MGA/TPA chains.

Three things to test

  1. Who pays. The obligation sits on the capacity provider; the data sits at the TPA; the MGA is in the middle with the thinnest margin. Classic split incentive. The business case and  commercial lever is the capacity-renewal condition — evidence becomes a term of trade, so the MGA buys it to keep capacity. That's protecting the future, not just compliance appetite.
  2. TPA leverage. Crawford, Sedgwick and Davies multi-home across dozens of principals and run their own platforms at scale. They will not re-platform per carrier. The winning shape is more likely a standardised evidence/attestation feed a TPA emits to many principals that delivers sthe audited evidence all three parties operate on. 
  3. "Immutable." What examiners actually test is whether you can reconstruct the state of authority and the decision inputs as at a given date, tamper-evidently. Append-only logs with cryptographic hashing and an effective-dated authority model gets you there.

I have been reviewing claimstech platforms and believe that there is one that can deliver the outcomes provided. Can enable the project that proves the capability to meet and exceed the FCA guidelines that a capacity provider delegating authority to an MGA(s) which manages claims directly and mostly via a TPA must achieve. That actually allows for claims innovation without having to abandon existing claims systems and core systems. 

I urge insurers to have the strategic conversations that set the parameters for such projects  i.e.the measurable success criteria, and start in a bite-sized way to prove the  business, commercial and technology use case to have the confidence to expand across other lines of business acrosss the insurance spectrum. Whilst I do describe this as strategic there is also a tactical urgency!

El Nino is growing in strength and impact every month and is expected to peak in February 2027. Imagine private and business customers impacted by devestating flash floods in Valencia this winter. Low-lying areas in the UK inundated by widespread floods from the Norfolk Broads to Lincolnshire to the Somerset Levels. Californian mountain flash floods and Texan local drainage infrastructure overwhelmed. The opposite in Australia where droughts and high temperatures again threaten bush fires.

Will the Carrier-MGA- TPA ecosystem be resourced with the proven evidence chain to support torrents of surging claims and will they have the robust governance and audit chain to prove MGAs acted within the limits of delagated authority, TPAs managed claims with the necessary visibility and audits to prove duty of care? Repair  shops, restoration companies , contractors all meeting SLAs and evidencing judgements made, actions taken and who authorised them.

The timing is tight but you do have time to solve tactical and strategic challenges. I'd love to hear from you and discuss pratical action plans. You'll find me on LinkedIn.  

Sources

El Nino, FNOL Surges and insurers' capacity to cope

Claim Multi-Agent and Automated Intelligence Platforms Promise Automation Benefits — But Read the Fine Print on Autonomy

Beyond Digital FNOL- innovation across claims

The FCA also plans to increase its oversight of outsourced and delegated arrangements, particularly claims handling. This means ensuring there is clarity around roles, oversight arrangements and reporting structures between insurers, MGAs and any third-party service providers. As the delegated model becomes more widely used, expectations around transparency and governance are naturally increasing. Claims is effectively where the purchased product  is tested in practice  and is therefore central to the FCA’s assessment on delivery of good customer outcomes. For MGAs operating under delegated authority arrangements, this places greater emphasis on robust, well governed claims handling frameworks, whether this is handled in-house or outsourced to TPAs (third party agents) or law firms. This drives clear accountability, consistent reserving and decision-making, and high-quality management information to evidence fair and timely outcomes. In this context, claims data becomes a key asset, supp...

Tags

claims, delegatedauthority, da, fca