Blogs

Six Operational Resilience Scenarios Every Insurer and MGA Should Test

31st July 2026

Six Operational Resilience Scenarios Every Insurer and MGA Should Test

Six severe but plausible operational resilience scenarios for insurers, MGAs and intermediaries, what each one exposes, and the questions to ask when you test them.

Most firms test the scenarios they can imagine. Those tend to be the scenarios they have already mitigated.

The disruptions that actually cause harm are usually quieter, slower and further away. A partner’s governance failure. A manual process that has been quietly load-bearing for three years. A third party your compliance team has never assessed because it sits underneath somebody else’s contract.

Below are six severe but plausible scenarios drawn from what genuinely goes wrong in the insurance market, rather than from a generic business continuity template. For each one: what it looks like, why it is plausible, and the questions worth asking when you work through it.

1. Regulatory reporting failure due to manual compliance processes

What happens: A regulatory submission or internal compliance report is late, or wrong. Not because anybody was negligent, but because the data was collated by hand across spreadsheets, email chains and systems that do not talk to each other.

Why it is plausible: Because manual collation is still extremely common, and because it usually works, processes that depend on individual diligence fail rarely and then all at once.

Questions to ask:

  • How many people could produce this submission correctly without assistance?
  • If the source data were challenged, could you evidence where each figure came from?
  • What is the actual elapsed time between a data error occurring and anybody noticing?

What this usually exposes: Key person dependency, and the absence of an audit trail. Firms often discover that their reporting is accurate but not demonstrable, which is a different problem and harder to fix under pressure

2. Regulatory breach by a delegated authority partner

What happens: An MGA or coverholder operating under your delegated authority commits a regulatory breach. Conduct, pricing, financial crime controls, or a straightforward failure to follow the binder. 

Why it is plausible: Delegated authority is expanding faster than oversight capacity in much of the market. Annual reviews and periodic audits catch some issues. They are not designed to catch issues that emerge in month three of a twelve-month cycle.

Questions to ask:

  • How would you find out? Would the partner tell you, would a report surface it, or would you hear from the regulator?
  • How much time would pass between the breach starting and you finding out?
  • Could you evidence what oversight you had in place at the moment it occurred, rather than what your framework says you do?
  • Do you have equivalent visibility over anyone the partner has sub-delegated to?

What this usually exposes: Oversight is retrospective, and most firms can prove they reviewed a partner. However, fewer can prove they were monitoring one.

3. Inefficiencies and compliance gaps caused by legacy processes

What happens: No single incident. Instead, an accumulation: duplicated work, inconsistent reviews, records held in four places, controls that were designed for a business half the current size.

Why it is plausible: This is the default state of any growing firm that has not deliberately re-engineered its processes. Legacy is not a decision anyone makes; it is what happens while you are busy and don’t improve your systems.

Questions to ask:

  • Which compliance activities exist mainly because they always have?
  • Where does the same information get entered more than once?
  • If you doubled your counterparty count, which process breaks first?
  • How much of your team’s time goes to administration rather than judgement?

What this usually exposes: That capacity, not capability, is the constraint. The team knows what good oversight looks like, but they do not have the time to do it correctly.

4. Cyber incident or financial crime at a key third party

What happens: A third party you depend on suffers a ransomware attack, a data breach, or a financial crime event. Your systems are untouched. but your service to clients stops anyway, and your data may be exposed.

Why it is plausible: Third-party cyber exposure has become one of the more reliable routes into a regulated firm, precisely because the third party’s controls are outside your direct governance. Insurance distribution chains, with their layers of MGAs, coverholders, TPAs and software providers, present a large surface.

Questions to ask:

  • Can you name every third party with access to your data or systems, including those engaged by your partners rather than by you?
  • What are your contractual notification rights, and have you ever tested whether they work?
  • If a TPA were offline for two weeks, could you settle claims another way?
  • Who at your firm would be responsible for the regulatory notification, and would they know within the reporting window?

What this usually exposes: The dependency list is incomplete. Almost every firm can name its top ten. However. the failures come from further down, in the arrangements nobody at your firm signed.

5. Weak compliance culture and inconsistent oversight practices

What happens: Oversight of an MGA in one division looks nothing like oversight of a TPA in another. Standards vary by whoever happens to own the relationship. Escalation is informal and records depend on individual habit.

Why it is plausible: Inconsistency is the natural result of growth without standardisation, particularly after acquisitions or rapid hiring. It rarely shows up in a framework document, because the framework describes what should happen.

Questions to ask:

  • If two people reviewed the same counterparty, would they reach the same conclusion?
  • Would a junior team member escalate a concern about a commercially important partner?
  • Could you produce a consistent oversight record across every counterparty relationship, right now, without a project?
  • Where does your framework describe something nobody actually does?

What this usually exposes: A gap between documented process and lived practice. This is the scenario firms are most reluctant to test honestly, and frequently the most valuable.

6. Operational readiness gaps during expansion

What happens: The business enters a new product line or a new territory. Volumes arrive, and the compliance processes that worked at the previous scale, under the previous regulatory regime, with the previous counterparty count, no longer work now.

Why it is plausible: Commercial timelines and compliance readiness timelines are set by different people, and the commercial one usually wins. Expansion decisions are also rarely revisited once made.

Questions to ask:

  • Which controls were built for a specific regime, and would need rebuilding for another?
  • How long does onboarding a new counterparty take today, and what happens at three times the volume?
  • Who owns the assessment of whether compliance is ready, and can they realistically say no?
  • What did the last expansion cost you in compliance rework?

What this usually exposes: That readiness was assumed rather than assessed, and that the same pattern is likely to repeat.

What to do with what you find

Working through a scenario properly produces three things: a clearer view of your dependencies, an honest rating of your exposure, and a list of gaps, which is also the one most likely to be forgotten.

Two things make the difference between an exercise and an improvement.

Rate impact separately: Breach risk, financial impact and reputational impact diverge more often than people expect. A disruption can be financially minor and reputationally severe, and collapsing them into a single score hides exactly the exposure you most need to see.

Give every gap an owner and a date: Not a team, but a person. Gaps assigned to teams are assigned to nobody.

Repeat it whenever there’s a significant change, which in the insurance market is not a tick-box exercise and happens more often than once a year, since dependencies rarely hold still for long.

Frequently Asked Questions (FAQs)

What makes a scenario “severe but plausible”? It must be serious enough to genuinely stress the business while remaining realistic for your operating model. If the firm comfortably absorbs the scenario, the test has not told you anything.

How many scenarios should we test? There is no prescribed number. Most firms benefit more from testing one scenario honestly than from documenting six superficially. Start with the one you are most reluctant to examine.

Should scenarios always involve third parties? Not always, but in insurance most meaningful disruption arrives through a counterparty, so testing that never crosses an organisational boundary is likely to miss your largest exposures.

Who should be involved in scenario testing? Typically compliance, operations, risk and the relationship owners for any counterparties in scope. Testing done by compliance alone tends to produce a compliance view of an operational problem.

Take the Assesment to Test One of the Above Scenarios Properly

Our interactive Operational Resilience Assessment takes you through any of these six scenarios in 5 to 15 minutes. You map your dependencies, rate breach, financial and reputational exposure, capture lessons learned, and download a report you can take into your next governance or risk meeting.

This article was published by:

Article author:

REG Technologies Logo
REG Technologies

REG Technologies powers the insurance world to accelerate compliant trade. Helping insurance businesses trade faster, smarter, safer.

View LinkedIn profile

020 3946 2880

info@reg.uk.com

See how The REG Network can help you

Talk to one of our experts to start streamlining your processes