Reference

The UK delegated authority compliance calendar, 2026 to 2027

For years, oversight of delegated authority meant an annual audit, a quarterly bordereau and a long wait in between. That settlement is ending. Three London bodies now put the same question to every capacity provider, and each one asks it in its own dialect, through its own paperwork, on its own clock: can you prove what happened on your paper? The FCA asks through supervision. Lloyd's asks through data. The LMA asks through the audit. This page sets out what each expects, when it expects it, and what single body of evidence satisfies all three at once.

Updated August 2026

The FCA turns to delegated arrangements

The FCA published its first Regulatory Priorities report for insurance on 24 February 2026. The new annual series replaces more than forty portfolio letters. One line in its timeline matters most here. In the second quarter of 2026 the regulator began expanding its review of firms' oversight of outsourced claims processes to include different delegated authority models and remuneration arrangements. It aims to report findings in early 2027, so the review is running as you read this. The review grew out of claims handling, after a consumer super complaint pushed home and travel claims up the regulator's agenda, and it now follows that logic all the way down the distribution chain. Hand the binding pen or the claims file to another firm and the duty stays with you. Outsourced underwriting is still underwriting. Outsourced claims are still claims. The same report also opened a separate review of how insurers use AI in underwriting and claims, which began in the first quarter.

What does the regulator want to see? It wants evidence, not policy documents. Which risks were bound, which claims were paid, under whose authority, inside or outside appetite, and who noticed when they fell outside? A quarterly bordereau answers none of that on its own. It reports the what. Supervision now probes the how and the who.

Lloyd's rewires the data

Delegated underwriting carries roughly 45 percent of Lloyd's premium income, so the market's data plumbing is no side issue. That plumbing changed shape. The Delegated Data Manager, the central bordereaux platform, ceased to be a core market service in September 2024, and it survives only as an elective through LIMOSS. Managing agents now run their own bordereaux systems. The pipes fragmented. The standard did not. Lloyd's still mandates that every syndicate collect data consistent with the Coverholder Reporting Standards on any binding authority incepting since July 2017, which means the standard survives the platform, and the submission timeline sits in the binding authority agreement itself. The pipes are yours to choose. The data is not.

The next change is already in motion. On 4 June 2026 the London Market Group's Data Council opened a consultation to extend the Core Data Record to delegated authority business, and the window closed on 19 June. The framework already covers open market and treaty. The LMA calls this piece the last of the jigsaw. The work runs in lockstep with the Computable Binding Authority Agreement; the DA record forms a subset of that fuller model. The Data Council is working through the feedback, with results expected later in 2026. Once adopted, a single standard record will decide which fields count for a delegated risk, every party on the binder will have to supply those fields cleanly, and the gaps that quarterly reporting used to forgive will show up at once. The consultation closed. The standard is coming. Get your data ready before it lands.

Cadence carries its own signal. Monthly bordereaux remain the working norm for high volume books, and a coverholder whose numbers slip tends to get moved onto monthly reporting as enhanced oversight. Treat that move as the early warning it is.

The LMA audit now asks about AI

The LMA updated its coverholder audit scope in October 2025 under bulletin LMA25-029-DG. Its IT and information security section now reaches cyber and artificial intelligence risks by name. The association calls the round a mini update and plans a wider review from 2026, so the direction of travel points one way. The rollout is under way: the revised scope sits with LIMOSS to be copied into the Delegated Audit Manager platform, Lloyd's triggered the Q1 2026 audit programme on the existing scope, with the DAM changes targeted for the Q2 cycle. The sensible preparation does not change with the paperwork. Know where AI touches decisions on your paper. Know who holds authority over it. Know what trail it leaves.

The NAIC reached the same conclusion across the Atlantic. Its Model Bulletin keeps the insurer responsible for AI supplied or run by third parties, and its evaluation tool pilot treats that exposure as a core exam focus. Read the London scope and the American bulletin together and one plain rule emerges from both. Your MGA's AI is your AI. If a model helped bind a risk on your paper and nobody can show how it did so, the finding lands on you and not on the vendor, however the contract reads. Fifteen questions to put to any MGA before renewal sit in our free guide, The Delegated AI Oversight Questions.

The lines beyond London

Cross border books answer to more calendars than one. The EU AI Act's high risk duties now bite on 2 December 2027; the Digital Omnibus that moved them from August 2026 entered into force on 27 July 2026. The date moved. The duty did not. US state adoption of the NAIC bulletin continues to spread. The full list, with dates we keep current, lives on our AI regulation dates page.

What good evidence looks like this quarter

All of the above reduces to one demand: a record that stands up without a scramble. Five things deliver it. An audit trail covers every action, human and machine alike. A source page sits behind every extracted field. Binding authority adherence gets scored on every bound risk, not sampled once a year. Appetite drift shows up the week it starts. And the book reads as it stands today, not as it stood ninety days ago.

Capacity providers run exactly this on Braven. Every decision on the platform lands in a tamper evident trail, retained for seven years, and every field links back to the document that produced it. The examiners' questions arrive eventually. The answers should already exist.