What regulatory expectations apply to AI use in DA?
AI use in delegated authority does not sit outside existing regulatory expectations. Lloyd's and PRA/FCA requirements around accountability, outsourcing oversight, auditability and data governance all continue to apply. The managing agent or insurer remains fully accountable for outcomes, whether a human or an AI tool performed the underlying processing, and must be able to evidence appropriate oversight of how AI is used.
Key takeaways
- Regulators have not created a separate rulebook for AI in delegated authority; existing oversight principles apply.
- Accountability for DA decisions and outcomes always remains with the insurer or managing agent, never the AI tool or its vendor.
- Auditability and explainability are the practical tests: teams must be able to show how AI-assisted outputs were reviewed and approved.
- Existing third-party and outsourcing oversight frameworks should be extended, not replaced, to cover AI vendors and tools.
Managing agents, insurers and MGAs are increasingly introducing AI tools into bordereaux processing, validation and reporting.
This naturally raises a question for delegated authority oversight teams: does existing regulation still apply, or does AI require a different compliance approach altogether?
The answer is straightforward. AI does not create a new regulatory category. It operates within the same delegated authority oversight framework that already governs coverholders, MGAs and outsourced processing arrangements.
What changes is not the regulatory principle, but the practical questions oversight teams need to be ready to answer.
The regulatory backdrop for delegated authority oversight
Delegated authority arrangements have always required robust oversight.
Lloyd's Minimum Standards set expectations around coverholder and MGA governance, including due diligence, ongoing monitoring, bordereaux review and audit.
PRA and FCA requirements add expectations around outsourcing, operational resilience and the general principle that firms remain responsible for functions they delegate to third parties, regardless of who physically performs the work.
Together, these frameworks establish a consistent baseline: the insurer or managing agent is accountable for the quality and integrity of delegated processes, whatever tools or parties are involved in delivering them.
Any AI tool introduced into a DA workflow sits inside this existing baseline. It does not need a separate regulatory justification, but it does need to fit comfortably within it.
How oversight has traditionally been evidenced
Before AI tools were part of the picture, managing agents and insurers demonstrated DA oversight through familiar mechanisms.
These typically include:
- Coverholder and MGA audits.
- Bordereaux review and sign-off processes.
- Exception logs and escalation records.
- Documented delegated authority agreements setting out reporting obligations.
- Periodic reviews of underwriting performance and data quality.
Auditors and regulators look for evidence that these processes are followed consistently, that exceptions are identified and resolved, and that accountable individuals have reviewed and approved outcomes.
This evidence trail is what demonstrates effective oversight, independent of the specific tools used to produce it.
What changes, and what does not, when AI is introduced
Introducing AI into bordereaux validation or processing does not remove any of the obligations described above. It does raise some additional practical questions.
Oversight teams should be able to explain, in reasonably plain terms, how an AI tool arrived at a particular output. This does not require a technical breakdown of the underlying model, but it does require a clear account of what the tool does, what inputs it uses and how confident or uncertain outputs are handled.
Documentation should show how AI-assisted outputs are reviewed by qualified individuals before they are relied upon, and how exceptions or low-confidence results are escalated.
Vendor oversight also matters. Existing third-party and outsourcing risk frameworks should be extended to assess AI vendors, covering areas such as data handling, resilience and how the vendor's tool is maintained and updated.
Accountability for the accuracy and appropriateness of outcomes remains with the managing agent or insurer throughout. An AI tool can support interpretation and reduce manual effort, but it cannot hold responsibility for the decisions that follow.
Practical governance questions to be ready to answer
Regulators, auditors and internal compliance functions are likely to ask similar questions about AI-assisted DA processes as they would about any other significant change to operational processing.
Typical questions include:
- Who reviews and approves AI-assisted outputs before they are used?
- How are exceptions or low-confidence results identified and escalated?
- What due diligence was performed on the AI vendor, and how is that vendor monitored on an ongoing basis?
- How is AI tool performance reviewed over time, and what happens if performance declines?
- Can the organisation explain, in plain terms, what the AI tool does and does not do?
Being able to answer these questions with clear documentation is the practical test of appropriate governance, whether or not AI is involved.
Example
A Lloyd's managing agent introduces an AI tool to help validate incoming bordereaux from several coverholders before they are loaded into its systems. During a routine Lloyd's oversight review, the agent is asked to demonstrate how it ensures the AI tool's outputs are accurate and how exceptions are handled.
The managing agent shows documented review procedures, records of exceptions flagged by the AI tool and how underwriters resolved them, and evidence that the AI vendor was assessed through its existing third-party risk framework.
The reviewer confirms this meets expectations, since accountability and audit trail remain clearly with the managing agent.
FAQs
-
Does Lloyd's have specific rules for using AI in delegated authority?
There is no separate AI-specific rulebook. Existing oversight, outsourcing and minimum standards requirements apply to AI-assisted processes in the same way they apply to any other tool or process used within delegated authority.
-
Who is accountable if an AI tool makes an error in bordereaux processing?
Accountability remains with the managing agent or insurer, not the AI vendor. This is why human review and sign-off processes remain essential wherever AI is used to support DA data processing.
-
What documentation should we keep to show appropriate oversight of AI use?
Useful documentation includes records of how AI outputs are reviewed, exception handling logs, vendor due diligence records, and evidence of periodic review of AI tool performance over time.
Your BDX Insights
Answer six quick questions about your bordereaux data and tooling, and we'll give you instant, tailored insights into how you can use AI to help your BDX processing — plus a perspective we think is worth your time as you answer each question.