AI Knowledge Hub

What Is a Coverholder or DCA Audit?

Quick answer

A coverholder or DCA audit is a risk-based examination of whether delegated underwriting or claims activities comply with the relevant contract, policies and controls. It typically combines process review, record and file testing, findings and tracked remedial actions. Lloyd's coordinated audits can reduce duplicated requests where several managing agents oversee the same entity.

What to remember

Key takeaways

  • Audits test how delegated activity operates in practice.
  • The scope should respond to risk rather than repeat a fixed checklist.
  • Findings require evidence, ownership and tracked remediation.
  • Coordination reduces duplication while preserving managing-agent accountability.

Managing agents receive bordereaux, performance measures, attestations and other information from delegated partners. Those sources support routine oversight, but they do not always show how the underlying work was performed.

A coverholder or delegated claims administrator audit examines the processes, controls, records and files behind the reported outcomes.

The aim is to test whether the delegated party is operating within its agreement and managing relevant risks. A useful audit is focused, evidenced and followed through. It is not simply a broad information request.

Audits test the operation behind reported outcomes

A coverholder audit may examine delegated underwriting, policy documentation, premium handling, bordereaux, governance and other activities within the binding authority. A DCA audit focuses on delegated claims services, including claims files, authority, payments, customer treatment and reporting.

Routine monitoring and audit serve related but different purposes. Monitoring can show a change in referral rates, reporting timeliness or claims performance. Audit work investigates whether the processes and controls producing those results are appropriately designed and operating in practice.

An audit also differs from initial due diligence. Due diligence assesses whether a party is suitable for appointment or continued use. Audit testing provides deeper evidence about how selected activities have actually been performed.

Risk determines scope and evidence

Managing agents set the scope according to the authority, products, territories, performance, control changes and previous findings. Lloyd's and the LMA provide a standardised scope, but every section need not be used in every assignment.

Typical work combines interviews, process walkthroughs, policy and procedure review, system evidence and selected underwriting or claims files. Samples should reflect the purpose of the test. A file review chosen only because records are easy to retrieve may miss the higher-risk activity.

The scope should state which contracts, periods and functions are covered. Evidence requests should be proportionate and clear so the coverholder or DCA can prepare without creating unnecessary operational disruption.

Analytics can focus audit attention

Traditional risk assessment uses performance reports, prior audit results, due-diligence information and the judgement of oversight specialists. This remains appropriate.

Data analysis can improve focus by comparing referral patterns, authority exceptions, reporting delays, complaints or claims movements across periods. AI can help classify earlier findings, summarise large evidence sets and identify records with unusual combinations for potential sampling.

These tools do not determine whether a control is effective. Data may be incomplete, and an unusual case may be legitimate. The managing agent defines the scope, the auditor tests the evidence, and appropriately qualified people reach and review the conclusions.

Findings matter only when actions close

At the end of fieldwork, the auditor normally discusses initial findings before issuing a formal report. Findings should identify the requirement or expectation, the evidence observed, the risk and a practical recommendation.

The managing agent reviews the report and decides which actions are required. Each action needs an owner, target date and evidence expectation. A coverholder or DCA response may correct an error, improve a control or explain why another treatment is appropriate.

Where several managing agents participate, a coordinated audit can reduce repeated visits and overlapping requests. Each managing agent still retains responsibility for its own delegated arrangement and any contract-specific concerns.

Closure should be an explicit decision based on sufficient evidence. Recording a response in a workflow does not by itself demonstrate that the underlying weakness has been addressed.

Example

A hypothetical marine cargo coverholder writes business for several Lloyd's managing agents and is selected for a coordinated audit.

The participants agree a risk-based scope covering underwriting authority, policy documents and bordereaux controls. The auditor reviews the process and tests selected files. One finding shows that evidence for a referral decision is not consistently retained.

The coverholder updates its procedure, trains relevant staff and supplies examples from subsequent files. Each managing agent considers the evidence and records its closure decision.

FAQs

  • Is a coverholder audit the same as due diligence?

    No. Due diligence usually assesses suitability before appointment and during periodic review. An audit tests selected processes, controls and files from actual operation. Evidence from each activity can inform the other.

  • Does every audit use the full standard scope?

    Not necessarily. Managing agents select a proportionate scope according to the delegated authority, risk indicators and previous work. They may add bespoke requirements where the standard scope does not address a relevant concern.

  • Who closes an audit finding?

    The responsible managing agent reviews the delegated party's response and supporting evidence and decides whether its required action is satisfactorily closed. Coordinated workflows do not remove that accountability.

What's next?

Talk us through your DA process

Talk us through your DA process

Book a conversation to explore where AI could help improve delegated authority data flow, validation and operational control.

Our latest insurance insights