REG Reviews

REG Reviews – September 2026

2nd September 2026

London's skyscrapers as our main REG Reviews newsletter's image

Welcome to your September Edition of REG Reviews!

Last month, AI ran through everything from the Mills Review to personal lines pricing and a rising wave of generated fraud, delegated authority oversight stopped being treated as housekeeping, private equity narrowed its focus to specialty and MGA platforms, cyber claims grew rarer but far more expensive, and research exposed a two-tier support system in broker wellbeing.

Read these articles and many more as we bring you all the important news and views in the insurance and financial services world…

Industry News​

REGULATORY

The New Reality of Delegated Authority Oversight

Legacy systems are a burden when it comes to delegated authority oversight and governance. According to Insurance Post, despite delegated authority accounting for 50% of what Lloyd’s members write, most MGAs still carry due diligence using outdated processes.

The main problem that’s often being posed is that compliance oversight is seen as housekeeping or a ‘tick box’ exercise rather than an embedded process that’s being addressed comprehensively.

In the end, firms find themselves having to play catchup rather than ensuring their on top of their compliance duties on time.

Richard Spencer, managing partner at New Link Consulting goes on to say that delegation is what enabled the Lloyd’s market to have the level of flexibility and access to specialist expertise in the first place. In fact, Lloyd’s report that delegated underwriting account for 45% of premiums with underwriting authority going hand in hand with customer relationship, product pricing and claim settlement.

However, this level of scale has led oversight to be forgotten.

Spencer also believes that culture is a responsible factor in why the market hasn’t gotten to grips with delegated oversight, mostly because it has always been seen as a separate entity, which led it to lose arguments against obtaining capital.

Delegated data and reporting was regulated by a market-wide programme named Blueprint two for around five years; however, Lloyd’s gave it up, saying that a central programme can’t fix the underlying delegated governance issue.

Some key figures worth noting is that the MGAA’s 2025 Opinion report, 77% of MGAs and 91% of insurance carriers reported that claims process need improvement, which is an increase of 59% compared to two years ago.

The FCA reported that it has already taken action against 40% of some of the home and travel insurers it reviewed.

As regulatory expectations tighten, managing agents and carriers are increasingly expected to demonstrate effective oversight and accountability across delegated authority chains, as responsibility for customer outcomes, claims decisions and coverholder governance ultimately remains with the firm granting the authority.

The next wave of regulatory scrutiny is likely to focus on delegated authority oversight, with firms increasingly expected to demonstrate and evidence effective customer outcomes and governance, rather than simply relying on operational metrics or documented controls

Student Loan Interest Rates to Be Capped at 6%

CYBER

Cyber Claims Are Getting Rarer and Far More Expensive

Chubb’s latest cyber claims report contains two findings that sound contradictory, but aren’t. Claims frequency across the UK and European mid-market has fallen to a record five-year low of only 1.51 claims per 100 policies. However, over the same five years, average claim severity has risen 210%, reaching $318,820 per claim in 2025.

Read together, the picture is straightforward. Basic controls are working. Multi-factor authentication, endpoint detection, backup discipline and patching have stopped a meaningful volume of opportunistic attacks from becoming claims. What does get through is the attack that was designed to get through, and those incidents are considerably more damaging than the ones being prevented.

The report’s most striking example is a single ransomware event from one supplier. Direct losses came to $568m, and losses across the supply chain reached $1.4bn. Manufacturing was halted for five weeks and more than 5,000 organisations were affected. Nobody writes a policy for that. Most of the firms caught up in it had no contractual relationship with the company that was actually attacked, but got caught in the cross fire.

This is where the market’s pricing trajectory becomes genuinely awkward. International cyber rates have fallen 43% since the fourth quarter of 2023, and UK premiums dropped an average of 11% across 2025. Meaning clients have spent three years learning that cyber cover gets cheaper at renewal, and haven’t spent three years watching their limits keep pace with severity, because they had no reason to think about it.

That gap becomes a broker problem before an underwriting problem.
A £1m limit bought in 2021 against a very different loss distribution is not a £1m limit today in any meaningful sense. Only around 61% of medium-sized UK businesses hold any cyber cover at all, and standalone uptake is considerably lower, so a large part of the conversation is still about whether cover exists rather than whether it is adequate.

The renewal question has changed shape. It is no longer whether the client has cyber cover, or even whether the price is competitive. It’s whether the limit would survive the kind of loss the market is now actually producing, and whether the client has ever been shown the math.

REG UPDATES

Coming Soon: Our New Whitepaper on RegTech in Insurance

Compliance in insurance has stopped being a back office concern. Across the distribution chain, insurers, MGAs and brokers are now expected to evidence oversight of counterparties they do not control, in an environment where new regulatory updates appear nearly every seven minutes.

Most firms recognise the problem. Far fewer have the systems to prove they have solved it. Our own 2024 research found that just 25% of general insurance professionals currently use RegTech, with a further 22% aware of its benefits without yet using it.

That gap is why we have written RegTech in Insurance: Navigating Compliance, Risk and Regulatory Change, which goes live on 28th September.

The whitepaper sets out where the RegTech market has actually got to, and what it means in practice for firms managing delegated authority, TOBAs, counterparty due diligence and audit readiness. It explains why KYC and KYB across a distribution chain behave nothing like retail onboarding, why manual processes introduce the very risk they are meant to manage, and what the FCA’s growing scrutiny of delegated authority models means for oversight expectations.

It also delves deeper into why MGAs are leaders in the market when it comes to adopting technology and what differentiates them from the rest.

Throughout, the whitepaper draws on firms already doing the work. Compliance and distribution leaders at CNA Hardy, Arc Legal, Lorega and Generis Underwriting describe what changed for them after adopting RegTech. It closes with a measured look at AI in compliance, covering where predictive risk scoring and dynamic alerting genuinely help, and where model bias, explainability and unsettled regulation introduce new problems.

The thinking behind it is straightforward. RegTech is discussed constantly and understood unevenly. This is an attempt to set out what it does, what it does not do, and what good oversight looks like across the insurance value chain.

The whitepaper will be published on the 28th September. Join the waitlist and we will send a copy straight to your inbox on the day it goes live

Join the Waitlist

FINANCE

Fewer Deals, Bigger Bets, and a Clear Preference for MGAs

UK insurance distribution M&A has slowed markedly, but reading that as a cooling market would be a mistake.

Just 47 deals were announced across UK distribution in the first seven months of the year, 22% down on the same point in 2025 and the lowest count since 2017. July was simultaneously the highest value month of the year. Fewer buyers are transacting, and the ones who are have moved decisively upmarket.

The clearest example came with Cinven and La Caisse agreeing to jointly acquire specialty MGA platform Optio, a business spanning multiple specialty lines, a large panel of third party capacity providers and offices across 15 countries. Wihlst financial terms were not disclosed, what the deal signals is harder to miss: two very large institutional investors, one of them a pension fund manager, concluded that the most attractive distribution asset available to them was an MGA platform rather than a retail broker.

That preference shows up in the aggregate data too. Private equity was involved in around 45% of all UK distribution deals, and in over half of specialty and MGA transactions. Specialty and MGA deals made up 27% of total deal flow, a disproportionate share of a shrinking pool. Capital isn’t leaving the sector, it’s simply becoming more selective about where in the value chain it wants to sit.

The logic is not difficult to follow. Underwriting authority, proprietary data and product control command a multiple that commission income does not. An MGA that owns its pricing, its distribution relationships and its claims experience looks a great deal more defensible to an investor, than one that primarily owns access.

There is also a timing factor worth noting. Speculation about capital gains tax changes at the autumn Budget is widely expected to pull some transactions forward, so the deal count may look rather different by the end of the year.

For brokers weighing their own options, the read-across is uncomfortable but useful. The market is paying for control, not scale. Firms with genuine underwriting capability, clean data and evidenced governance are being competed for. Firms whose value rests on relationships alone are finding fewer bidders, and less generous ones.

UK Net Migration Falls as Visa Rules Tighten

ESG

Broker Stress Is Falling, but Support Depends on Who You Work For

Ecclesiastical’s seventh annual study of broker wellbeing carries a headline that reads well, but with a detail underneath it that does not.
Stress is down: 67% of brokers reported work-related stress in the past twelve months and 44% reported anxiety, both improvements on 2025. Then comes the access figure. 89% of brokers at national firms have a confidential helpline available to them. But among provincial brokers, the figure is only 33%.

That’s not a small difference in benefits options. It is two different working experiences sharing one job title. A broker at a national facing a difficult period has a route to confidential support that does not involve telling a colleague. Two thirds of provincial brokers do not have that same option, which in a twelve-person office often means the only available route runs through someone they sit next to.

The drivers of stress are recognisable to anyone in the industry, and notably they are structural rather than personal. Workload leads at 69%, followed by regulation and compliance at 57%, customer demands at 53%, staff shortages at 45% and insurer relationships at 41%. Only one of those is something an individual can meaningfully fix alone, and it is the one they have least control over.

The research also found women reporting higher stress intensity than men, and the study’s chartered psychologist offered a caution worth taking seriously: an improvement in reported stress may reflect a reduced willingness to say so rather than a genuine reduction. Wellbeing data measures what people are prepared to disclose, and disclosure depends on whether disclosing feels safe.

There is a regulatory dimension here too, and it arrives shortly. The FCA’s non-financial misconduct rules take effect on 1 September, bringing serious bullying and harassment formally within the Conduct Rules. Third party harassment liability follows in October under the Employment Rights Act 2025. Both assume a firm can detect problems in its own culture, which requires people to feel able to raise them.

For provincial brokers in particular, this is a genuinely actionable finding. A confidential helpline is not an expensive benefit, and the gap between 89% and 33% is not a gap in resources so much as a gap in whether anyone has got round to it. Given what lands on 1 September, getting round to it has become rather more pressing.

REGULATORY

The Insurance Industry's Claims Data Contradiction

The CEOs of three price comparison sites told the government that consumers need standardised and transparent claims data from insurers if they are to compare policies on anything more meaningful than price alone, as reported on Insurance Post.

Compare the Market CEO Mark Bailie, alongside the CEOs of Confused.com and MoneySuperMarket, has renewed calls for insurers to provide standardised claims data, arguing that comparison sites can’t help consumers assess value beyond price without greater transparency on claims performance.

Amazon attempted to bring greater transparency to insurance purchasing through its insurance store, promising features such as customer reviews, ratings and claims acceptance data. However, the platform failed to gain significant traction and was ultimately shut down before claims data was ever introduced.

Insurers and comparison sites remain divided over the push for standardised claims data, with aggregator CEOs arguing that inconsistent definitions make it difficult for consumers to compare insurers beyond price.

Despite years of discussions, only four in ten insurers have agreed to proposed industry definitions, highlighting ongoing challenges in achieving greater transparency and consistency across the market.

Fairer Finance co‑founder James Daley has challenged the reliability of the FCA’s claims data, arguing that inconsistent definitions of what constitutes a claim make comparisons difficult.

He also noted that claims acceptance rates alone provide an incomplete picture, as they do not reflect customer satisfaction or cases where potential claims are rejected before being formally recorded.

Standardised claims data could help shift competition away from price alone and towards claims performance, improving transparency and consumer trust. With insurance continuing to face trust challenges, supporters argue that greater disclosure could lead to better outcomes and enable customers to make more informed decisions.

Insurance Post’s Deputy Editor Scott McGee argues that the industry’s reluctance to embrace standardised claims data sits uneasily alongside its criticism of price‑driven comparison sites. In his view, greater transparency around claims performance could help improve consumer trust and shift competition towards service and value, yet significant resistance remains.

The MGA Pricing Challenge

Pricing flexibility, enhanced data capabilities and digital distribution are emerging as key differentiators for MGAs seeking to stay ahead of the competition, according to Vicki Summerhayes of Insurance Age.

She emphasises that pricing agility has become a critical differentiator for MGAs, particularly in a competitive and fast-moving market where speed of response can directly impact growth and profitability.

To stay ahead, many MGAs are modernising their operating models and adopting more dynamic pricing capabilities, enabling them to react quickly to changing market conditions, improve conversion rates and avoid margin pressure.

Karen Hogg, COO at Stella Insurance, said investments in pricing, data and AI are helping MGAs become more agile, enabling faster and more frequent rate changes.

Meanwhile, Jordan Barnard, Head of Strategy at Paragon, argued that firms without modern pricing capabilities risk falling behind as the market increasingly demands real-time responsiveness and pricing agility.

Data is becoming a key source of competitive advantage for MGAs, with firms increasingly using enriched datasets, real-time analytics and AI to improve pricing accuracy, speed up decision-making and enhance conversion rates. 

Hogg and Barnard highlighted the value of combining external data with internal claims insights, while Gary Humphreys, Chief Commercial Officer at Saturn Group, emphasised the role of continuous feedback loops in refining pricing strategies. They also noted that AI is helping firms process growing volumes of data more efficiently and extract deeper insights from their pricing models.

Digital trading and automation are becoming key differentiators for MGAs, as brokers increasingly expect fast, seamless service. Barnard also reported that greater use of full-cycle digital trading can reduce manual processes, improve efficiency and allow underwriters to focus on complex risks and product development rather than routine administration.

He also highlights the importance of using referral data to streamline workflows and remove unnecessary friction from the underwriting process.

Looking at the future, long-term success for MGAs will depend not just on specialist expertise, but on the ability to make smarter, faster decisions powered by technology and data.

UK Insurers Are Solvent — But the Buffer Is Getting More Interesting

The UK insurance market remains comfortably solvent. But beneath the reassuring headline numbers, a more nuanced picture is emerging: the industry is becoming increasingly polarised, with some insurers operating with significantly less capital headroom than others.

That is the key takeaway from new analysis of insurers’ Solvency and Financial Condition Reports (SFCRs), which found that the aggregate solvency coverage ratio fell to 190% in 2025/26, compared with 195% in each of the previous two years.

On the face of it, there is little cause for alarm. A 190% aggregate ratio means eligible own funds across the insurers analysed were almost twice the amount required under Solvency UK. No insurer in the three-year dataset fell below the 100% regulatory threshold. But aggregate figures can hide what is happening underneath.

The more revealing statistic is that 22% of insurers now have an SCR coverage ratio below 150%, up from 14% the previous year. At the same time, 13% sit above 300%. The result is a market that appears increasingly divided between insurers with substantial capital buffers and those operating closer to the regulatory floor.

That matters because solvency is not simply about whether a firm passes a regulatory test today. Capital headroom provides protection against adverse claims experience, investment volatility, changing economic conditions and unexpected shocks. The 100% threshold is therefore better viewed as a floor than a comfort zone.

The Prudential Regulation Authority’s own data reinforces the overall resilience of the sector, but also shows differences between life and non-life insurers. At the end of 2025, the median SCR coverage ratio was 201% for life insurers and 222.6% for non-life insurers. Tier 1 capital represented 92.8% and 88.6% of total capital respectively.

In other words, the UK’s insurance sector continues to be supported by a substantial quantity of high-quality capital. The question is what happens if the operating environment becomes less forgiving.

Insurers are already navigating a complex combination of pressures: changing claims patterns, economic uncertainty, investment considerations, evolving regulation and continued pressure to improve returns. At the same time, consolidation is changing the shape of the market.

Recent activity from major insurers illustrates the point. Aviva’s acquisition of Direct Line has significantly increased its scale, while its first-half 2026 results showed operating profit rising 24% to £1.33bn. Yet even Aviva’s shareholder cover ratio declined from 180% at the end of 2025 to 176% at the end of June.

Capital strength, therefore, cannot be considered in isolation from the decisions insurers are making about growth, acquisitions, underwriting and their wider risk exposure. And that is where the latest solvency figures become particularly relevant to counterparty risk.

An insurer’s resilience is not determined solely by its own balance sheet. Modern insurance businesses operate within increasingly complex ecosystems of MGAs, brokers, TPAs, reinsurers, suppliers and other third parties. As those networks expand, so does the importance of understanding the financial and operational resilience of the organisations sitting within them. A strong insurer working with poorly capitalised or financially distressed counterparties can still face disruption.

For insurers operating delegated authority models in particular, this becomes even more important. Growth through MGAs and other distribution partners can create significant commercial opportunities, but it also means insurers need confidence that the businesses representing them have appropriate controls, governance and financial resilience in place.

The latest solvency data is therefore a useful reminder that risk does not stop at the balance sheet.

The UK’s insurers remain well capitalised, and there is no suggestion that the sector is facing an immediate solvency crisis. In fact, the quality of capital supporting the market remains reassuringly strong, with 84% of available own funds in the latest analysis coming from unrestricted Tier 1 capital. But the direction of travel deserves attention.

A falling aggregate SCR ratio, a growing proportion of insurers below 150% and increasing divergence between firms all point towards a market where understanding individual risk is becoming more important than relying on sector-wide averages.

For insurers, the lesson is simple: resilience needs to be understood across the entire network, not just within the four walls of the balance sheet.

As insurance ecosystems become more interconnected, continuous visibility of counterparties will become an increasingly important part of maintaining that resilience.

ESG

ESG in Insurance Isn't a Statement. It's a Strategy.

Most of the times, companies have an internal ESG agenda, but does it translate into meaningful action given the rising pressure and need to demonstrate tangible ESG results?

That’s what Insurance Times covers: the knowledgeable gap between the ESG commitments and strategies insurance firms promised five years ago and the ability to prove these actions are resulting in measurable outcomes.

The increasing ESG scrutiny and pressure from governance bodies has played a significant role in these changes, especially since the FCA’s anti-greenwashing rules introduced a couple of years ago and ensuring firms’ ESG efforts are explained clearly and fairly with supporting data and honest statements.

The ABI also recognises the benefits that resilient reporting frameworks have played in strengthening insurer’s governance and showing their sustainability efforts like switching to lower-carbon methods.

According to the global insurance industry collaboration ClimateWise’s programme director, Felicity Alvey, important ESG impact now more than ever relies on data and evidence rather than mere aspirations, saying that: “Anyone can say they care about climate change. The challenge is being able to say we really care about climate change and nature. We care because of the threat it poses to our business and the risks it brings, but also because of the opportunities.”

She also added that: “One of the things those making the most impact really stand out for is that they’re able to articulate not only what they’re doing, but the outcome of those actions and why that matters.”

As a member of ClimateWise, Aviva stresses that meaningful ESG impact starts with governance, with Chief Sustainability Officer, Claudine Blamey, debating that plausible ESG strategies demand detailed transition blueprints and transparent accountability.

For example, Aviva’s ESG success can be explained by its involvement of senior management and board members at every step of the way, while also integrating ESG reporting in its annual report as a key component for complete transparency.

Gayle Bennouir, risk management director at Verlingue, speaks on the importance of integrating ESG into everyday business decisions across all departments and ensuring all employees are involved at all times.

She said, “One small change. We can all make one small change”, helping establish ESG as a culture rather than a mere tick-box compliance exercise.

Finally, while insurers broadly agree on the importance of ESG, the sector’s biggest test may be proving that collaboration can move beyond strategy and discussion to create measurable improvements for both businesses and customers.

REGULATORY

How The Mills Review Is Reshaping the Future of Broking

Robin Knowles, Compliance Consultant at UKGI, argues that while The Mills Review does not introduce new AI rules or regulatory requirements, focusing on what it lacks overlooks its broader significance and the direction of travel it signals for AI governance.

The Mills Review reinforces the FCA’s view that existing regulations already provide the framework for AI governance, placing the focus on how firms oversee and evidence their use of AI rather than introducing new rules or requirements.

The Future of Broking Is Redefinition, Not Replacement.

Knowles argues that AI is more likely to reshape the broker’s role than replace it. As AI becomes more involved in customer interactions, brokers who can interpret AI-generated insights, challenge inaccuracies and provide tailored advice will become increasingly valuable, while firms that rely on AI without applying human judgement risk losing relevance.

He suggests the real challenge is not technology adoption, but ensuring firms can clearly demonstrate the expertise and value they offer beyond what AI alone can provide.

Upskilling Is a Present-Day Priority, Not a Future Goal.

The review highlights that firms remain accountable for how AI is used, regardless of whether content or decisions are AI-assisted. It places growing emphasis on AI literacy, staff training and governance, with organisations expected to ensure employees can use AI responsibly, challenge its outputs and demonstrate appropriate oversight.

Brokers Will Need More Than Expertise. They’ll Need Evidence.

The review also emphasises that firms must be able to demonstrate how AI‑assisted decisions are made, reviewed and governed, not just the outcomes they produce.

It highlights the importance of maintaining clear oversight, documentation and ongoing monitoring of AI tools, with governance focused on transparency, accountability and continuous testing as models evolve over time.

Ultimately, the FCA’s message is clear: firms must be able to evidence how AI is governed, not just how it is used.

TECHNOLOGY

AI Adoption Is Accelerating. Insurance’s AI Fluency Isn’t

The insurance industry has spent the past few years asking how quickly it can adopt artificial intelligence. Increasingly, the more important question is whether its people are ready for what comes next.

A new warning from the Chartered Insurance Institute (CII) has put the spotlight on what it describes as a critical “AI fluency gap” across insurance and personal finance. Its concern is not simply that employees lack technical skills. Rather, it is that organisations could move faster than their people’s ability to understand, challenge and govern AI effectively.

That distinction matters.

AI is already moving beyond the experimental stage in insurance. Research published earlier this year found that 55% of UK insurers had integrated AI into at least some business functions, with the industry increasingly looking to translate individual use cases into broader operational capabilities.

At the same time, demand for AI expertise is rising. Insurance job listings requiring AI skills reportedly increased by 70% over the past year, across areas including underwriting, claims, broking and data strategy.

The direction of travel is therefore clear: AI is becoming part of the insurance workforce. But becoming familiar with a tool is not the same as being capable of challenging its output.

One of the most interesting points from the CII is its challenge to the idea that simply having a human involved makes an AI process safe.

A “human in the loop” only provides meaningful protection if that person understands what the system is doing, can identify when an output looks wrong and feels empowered to challenge it.

That is particularly important in insurance, where seemingly small decisions can have significant consequences for customers, counterparties and firms. An employee who treats an AI-generated recommendation as inherently credible is not providing meaningful oversight simply because they clicked “approve”.

The CII is consequently calling for training that goes beyond basic AI tool usage, with greater emphasis on critical thinking, professional scepticism and the confidence to question automated outputs.

This also changes the conversation around AI skills. The future insurance professional does not necessarily need to become a data scientist. But they increasingly need to understand enough about AI to recognise its limitations, assess whether an application is appropriate and know when human judgement should take precedence.

The timing of the CII warning is significant because regulators are also making clear that AI does not sit outside existing accountability frameworks.

The FCA has said it does not plan to introduce a separate set of AI regulations, instead relying on existing frameworks such as the Consumer Duty, Senior Managers and Certification Regime and wider governance expectations.

That effectively puts responsibility back on firms.

For insurers, brokers and MGAs, responsible AI therefore cannot simply be a technology or compliance project. It needs to become part of everyday operational governance: who approved the system, what data is being used, what decisions it influences, who monitors performance and what happens when something goes wrong?

This becomes even more important as AI moves towards more autonomous applications. Recent developments in AI agents are already forcing cyber insurers to reconsider how policies account for systems capable of taking actions with limited human intervention.

The risk is no longer just that AI produces an inaccurate answer. It is that an organisation may not fully understand how a system arrived at a decision — or who ultimately remains accountable for it.

There is an irony here. The more AI becomes embedded across insurance, the more valuable professional judgement may become.

The CII has argued that AI is unlikely to remove the need for insurance professionals altogether; instead, the profession will need to evolve around skills that technology cannot easily replicate, including judgement, ethics and trust.

That suggests the industry’s AI race should not be measured purely by how many processes can be automated.

The more meaningful question is whether firms can create an environment where technology makes people better at their jobs without weakening accountability.

For insurance leaders, that means investing in AI literacy alongside AI infrastructure. It means training people to challenge outputs rather than simply consume them, building governance into workflows rather than adding it afterwards, and ensuring that AI adoption is driven by a clearly defined business or customer problem rather than fear of being left behind.

The industry has already demonstrated that it can adopt AI.

The next test is whether it can develop the judgement to know when to trust it, when to challenge it and when not to use it at all.

That may ultimately be the real measure of responsible AI adoption in insurance.

CYBER

Cyber Resilience Is Becoming Everyone’s Problem — Not Just IT’s

Cyber risk has moved well beyond the IT department. For insurers, it is increasingly a question of how resilient the whole business — and the wider network around it — really is.

That is the message behind new recommendations from the Association of British Insurers (ABI), which is calling for a more joined-up approach to cyber resilience across UK businesses and the insurance industry. The recommendations include clearer cyber insurance policies, stronger distribution, better data sharing and closer alignment between insurance and wider cyber resilience initiatives.

The timing is hard to ignore. The latest government figures cited by the ABI show that 43% of UK businesses experienced a cyber breach or attack in the previous 12 months. At the same time, cyber threats are becoming more sophisticated, with AI making it easier for attackers to identify vulnerabilities and scale attacks.

For insurers, this creates an interesting challenge. Cyber insurance has traditionally been viewed as the financial backstop when something goes wrong. But the ABI is making the case for something broader: insurance can play a role in helping businesses prevent, prepare for and recover from cyber incidents, rather than simply paying the claim afterwards.

That is already happening to an extent. Cyber policies can include threat monitoring, incident response and recovery services, while the ABI’s own guidance highlights practical measures such as good logging and monitoring, strong encryption and checks on suppliers and third parties.

That third-party point is particularly important. A business can have strong internal cyber controls and still be exposed through a supplier, broker, technology provider or other external partner. As insurance businesses become more connected and reliant on third-party providers, the question is no longer simply “How secure are we?” It is also “How secure are the organisations we rely on?”

This is where cyber resilience starts to overlap with counterparty risk management. For insurers and MGAs, third-party oversight is already a core part of managing distribution networks. Counterparties need to be identified, onboarded, assessed and monitored. Cyber risk is increasingly another part of that picture.

The ABI and PwC report is also calling for better data sharing across the cyber insurance market. That could be significant. One of the challenges with cyber risk is that the threat landscape moves faster than traditional risk models. Better information sharing between insurers, businesses and government could help firms understand emerging threats and improve how risk is assessed and priced. But data sharing only helps if businesses can actually turn that information into action.

This is where continuous monitoring becomes increasingly important. Annual or point-in-time assessments can provide a useful snapshot, but cyber risk does not stay still for 12 months. A supplier’s financial position can change. Its ownership can change. Its technology environment can change. A new vulnerability can emerge overnight.

Recent developments around AI make that challenge even clearer. The emergence of autonomous AI agents is already forcing cyber insurers to reconsider how policies define cyber events, liability and coverage, with insurers adapting products as the technology develops. The lesson is that resilience cannot be treated as a one-off exercise.

For insurers, it means having a clearer view of the businesses sitting within their wider ecosystem and understanding how those risks evolve over time. For brokers and MGAs, it means being able to demonstrate that appropriate controls are in place — not just when a relationship begins, but throughout its lifecycle.

The ABI’s recommendations are ultimately pointing towards a more proactive model of cyber resilience: better information, stronger controls, clearer insurance products and closer collaboration between the different organisations involved. That feels like the right direction.

Because in an increasingly connected insurance market, your cyber resilience is only as strong as the network you depend on. 

REG on the Road: Four Events, One Big Conversation

Insurance is changing fast. MGAs are scaling, distribution networks are becoming more complex and insurers are under growing pressure to demonstrate that they understand — and can evidence — the risks sitting across their counterparty relationships. That makes the next few months an important one for REG Technologies.

Our team will be out across the UK and Europe, meeting the people shaping the future of insurance, from MGA leaders and capacity providers to insurers, brokers and specialists working in emerging areas of the market.

For us, these events are about more than networking. They are an opportunity to listen to what the market is struggling with, build relationships and show how a more connected approach to counterparty risk can help insurance businesses grow with greater confidence.

European MGA Summit – Paris

First up is The Insurer, by Reuters, European MGA Summit in Paris, where Stephen Line, CEO, Graham Hogan, CRO, Zoë Parsons, Head of Marketing, Sandra Simoes, Head of Product and Anisa Berisha, Account Executive will be representing REG.

Taking place on 29–30 September, the summit brings together senior leaders from across Europe’s MGA and delegated authority market. With the European MGA landscape continuing to mature, the focus is firmly on growth, capacity, performance and the operational foundations needed to build sustainable businesses.

That makes it a particularly important event for REG.

As MGAs expand their portfolios and insurers work with increasingly sophisticated distribution networks, keeping track of counterparties is becoming harder. Brokers, MGAs, TPAs, coverholders and other third parties all form part of the wider ecosystem — and each relationship brings its own onboarding, due diligence, documentation and ongoing monitoring requirements.

The opportunity is to move beyond fragmented processes and give insurers and MGAs a clearer, continuous view of the counterparties they depend on.

Paris is also an important step in REG’s European market ambitions. Getting closer to the people operating in different markets helps us understand where the challenges are the same, where they differ and where technology can genuinely make a difference.

MGAA ROI Presentation 2026

From Paris, we head to Dublin, with Graham Hogan, CRO, attending the MGAA’s Ireland event on 7 October.

REG has a strong connection with the MGA community through its relationship with the MGAA, so events like this are a valuable opportunity to continue those conversations and build relationships within the Irish market.

Ireland’s insurance market has an increasingly important role within the wider European ecosystem, and for MGAs and insurers operating across borders, effective oversight of third parties is becoming an increasingly important part of managing the business.

The conversations in Dublin will therefore be focused on a simple question: how can insurance businesses make counterparty management easier, more efficient and more robust as their networks grow?

InsTech: The golden age of MGAs? Building to win in any market cycle

Steve Callen, Account Executive, will also be attending InsTech’s MGA event, bringing together senior figures from MGAs, insurers, brokers, capacity providers and the wider insurance ecosystem.

The event’s focus on the future of MGAs is particularly relevant to REG. The MGA market has entered what many describe as a period of significant opportunity, but growth brings scrutiny.

Capacity providers increasingly want confidence that their MGA partners have the right controls, governance and visibility in place. Regulators expect firms to understand their distribution chains. And MGAs themselves need efficient infrastructure that allows them to grow without adding layers of manual administration.

That is where counterparty risk management becomes more than a compliance requirement. It becomes part of the infrastructure for growth.

For REG, InsTech is a chance to be part of that wider conversation and demonstrate that managing risk across an insurance network does not have to slow the business down.

Parametric Insurer Conference 2026

Finally, REG will be represented at the Parametric Insurer Conference.

Parametric insurance is one of the more innovative areas of the market, with new products, distribution models and partnerships continuing to emerge. It is a useful reminder that the insurance ecosystem is not standing still — and neither are the risks and relationships within it.

For REG, attending events like this is about looking beyond today’s market and understanding where tomorrow’s insurance models are heading.

Whether it is a traditional MGA, a global insurer or a specialist entering an emerging market, the underlying challenge remains familiar: businesses need to know who they are working with, understand the risks they present and maintain oversight as those relationships evolve.

That is the common thread running through all four events.

The insurance market may be changing, but the need for better visibility, stronger governance and continuous oversight of counterparties is only becoming more important.

We’ll be out there having those conversations over the coming months.

Going to any of these events? We’d love to meet you. Get in touch with the REG team to arrange a chat, or come and find us at the event.

This article was published by:

Article author:

REG Technologies Logo
REG Technologies

REG Technologies powers the insurance world to accelerate compliant trade. Helping insurance businesses trade faster, smarter, safer.

View LinkedIn profile

020 3946 2880

info@reg.uk.com

See how The REG Network can help you

Talk to one of our experts to start streamlining your processes