Industry · Insurance

Delegation of authority for insurance: one live layer from the boardroom to the binder.

A carrier's authority runs further than any one system can see. The board reserves it, the executives running underwriting and claims hold it, the desks exercise it within a limit every day, and the MGAs, coverholders, and administrators carry it outward, binding and settling in the carrier's name. No one system holds the current answer every examiner, auditor, and governance disclosure asks: who is authorized to underwrite, settle, pay, sign, and bind on behalf of this carrier today, and within what limit? Aptly holds that answer as one live, audit-ready system, internally and across every delegated relationship.

Diagram: insurance carrier authority cascading from board to underwriting and claims and out to a delegated MGA and TPA, one suspended.
Security & compliance
SOC 2 Type II Certified
Multi-Region Hosting
GDPR Compliant
The Gap

Why delegated authority in insurance goes out of date

Delegation of authority (DOA) is the formal structure that defines who can underwrite, settle, pay, sign, and bind on behalf of a carrier, up to what limit, and under what conditions. In insurance, that structure has to hold inside the carrier and outward to every MGA, coverholder, and third-party administrator. The authority is documented carefully, and current nowhere. Carriers document authority as carefully as any regulated industry: board resolutions and reserved-matters schedules, executive delegations, underwriting guidelines that set branch and line limits, claims-handling manuals with authority matrices, and binding authority agreements with every managing general agent, coverholder, and administrator. The problem is not that the authority is undefined. The problem is that it lives across resolutions, manuals, signature cards, and contracts, held by different functions and different companies, updated on different cycles, and impossible to see as one current picture when an examiner, an auditor, or a governance disclosure asks for it. In more than a quarter of organizations (28%), the delegation of authority does not address who is permitted to sign at all.

The authority types get conflated. Underwriting authority, claims settlement authority, claims payment authority, reserving authority, and signing authority are distinct, and people and entities routinely hold one and not the others. When they act on the wrong one, the carrier discovers it during an examination rather than before the risk is bound or the claim is paid.

Outward delegation multiplies the exposure. A managing general agent binds risk, and a third-party administrator settles claims, in the carrier's name, up to limits set in a contract. More premium is being delegated to more third parties than ever, yet the carrier's record of who holds what delegated authority, within what limit, and as of what date is often a spreadsheet and a binder full of agreements.

The picture is reconstructed, not maintained. When a financial examiner, an external auditor, or the corporate governance disclosure asks who was authorized to underwrite, settle, pay, or sign on a given date, internally or at a delegated party, the answer is assembled by hand from manuals, memos, contracts, and email, often long after the fact.

86%

Still on spreadsheets

Only 14% of organizations embed delegation of authority within an IT system. The other 86% keep it as a document, most often on the company intranet, where it goes out of date the moment a role changes.A policy on paper is not the same as a live record of who held that authority on a given date. In insurance, that drift is expensive: a risk bound above an MGA's delegated authority, a claim settled past a delegated limit, or a signature on a treaty or binding authority agreement the signer was not authorized to give, each surfaces in an audit or a regulatory examination rather than before the commitment is made.

Source: EY and the Society for Corporate Governance, "The delegation edge" (2024). Survey of 222 corporate governance professionals, September to October 2024.

The fix is not a tidier binder of resolutions, manuals, and delegated-authority agreements. It is one authority model that holds the board's reserved matters, every delegation beneath them, internally and outward to every delegated party, and the officers and entities authorized to sign and bind, as one live, current record.

The Authority Layer

What policy administration and claims systems both leave out

Between who people are and where the company is bound. Your identity system governs the door: it knows who someone is and what they can log into. Aptly governs the decision once they are through it. Your policy administration, claims, underwriting, finance, and binder systems are where the company gets bound and claims get paid. Neither identity nor those systems knows what a person or a delegated entity is authorized to underwrite, settle, pay, sign, or commit, and up to what limit. That authority lives in board resolutions, executive delegations, underwriting guidelines, claims manuals, and binding authority agreements, outside every system that needs it.

Aptly is the authority layer beneath those systems, governing the authority they execute against. It holds the carrier's delegated authority as a live model: who holds underwriting, claims settlement, payment, reserving, and signing authority, for what line and entity, up to what limit and under what conditions, internally and at every MGA, coverholder, and administrator, with each delegation's source instrument attached and acceptance recorded. Connected to your identity, finance, policy, and claims systems, it keeps that authority current as roles, limits, and relationships change. Keep your core and binder systems for execution; add Aptly as the live authority layer across them.

Identity systems
Who can log in
OktaMicrosoft Entra IDPing Identity
The Authority Layer
Aptly governs who can approve, sign, and commit
Delegations, limits, conditions, and signatories, versioned and evidenced.
Execution systems
Where commitments are made
Guidewire · Duck CreekSapiens · MajescoSAP · Oracle
One authority layer between identity and execution, holding the carrier's delegations and signatories and showing them as one current view.

Identity proves who someone is. Your core and delegated systems execute the work. Aptly is the system of record for what the carrier authorized, internally and outward, kept current.

How It Works

How authority cascades in a carrier, and out to every delegated party

One source of truth, from the board to every delegated party

IssuerApproval

Board of Directors

Holds authority by charter and bylaws. Reserves risk appetite, capital, and major reinsurance, and delegates the rest.

Reserved mattersRisk appetiteCapital & dividendsMajor transactionsBalance-sheet & large-exposure limits
RecipientApproval

Chief Executive Officer

Receives the board's delegation, then sub-delegates by formal instrument to the executives.

Sub-recipientApproval

Chief Underwriting Officer

Underwriting authority, and the guidelines that set branch and line binding limits.

Sub-recipientApproval

Chief Claims Officer

Claims settlement, claims payment, and reserving authority, within limit.

Sub-recipientApproval

Branch Underwriters & Claims Desks

Underwrite, settle, and pay within limit, with referral above it.

Sub-recipientApproval

Delegated MGAs, Coverholders & Administrators

Bind risk or settle claims in the carrier's name, up to the limits set in the binding authority agreement, with referral above.

Sub-recipientSignatory

Authorized Signatories

Named on the carrier's bank mandates and binding authority agreements. The only parties who can bind each entity.

Separate entities and delegated parties, one model

Insurance Holding CompanyOwn board & signatories
Licensed Insurance SubsidiaryOwn board & signatories
Reinsurance / Service EntityOwn board & signatories
1
Authority starts with the board.
Your governing board holds authority by statute, charter, and bylaws. It reserves defined matters, commonly risk appetite, capital and dividends, major transactions, and large-exposure limits, and delegates the rest to the chief executive and executive committee.
2
The chief executive sub-delegates by formal instrument to the officers who run the carrier.
Authority then flows to the chief underwriting officer for underwriting and branch limits, to the chief claims officer for settlement, payment, and reserving, to the branch underwriters and claims managers acting within limit, and outward to the MGAs, coverholders, and administrators that bind and settle in the carrier's name up to each agreement's limits.
3
Only certain officers can actually sign.
Only the authorized signatories named on the carrier's bank mandates and binding authority agreements can bind it on accounts and delegated programs. Accountability stays with the original issuer down every level of sub-delegation and outward to every delegated party, with each acceptance recorded.
4
One model holds the cascade and the entities together.
The carrier is rarely one legal entity. A holding company sits over several licensed subsidiaries plus reinsurance and service entities, each with its own board, signatories, and mandates. Aptly holds reserved matters, every delegation beneath them, the signatories, and per-entity mandates as one model, shown as it stood on any date.

The board's reserved matters, every internal delegation, every delegated MGA and administrator, and the parties authorized to bind, held as one live model that can be shown as it stood on any date.

The Platform

What Aptly governs for insurance carriers

Four capabilities, one system of record. Built for the CFO, general counsel, and chief compliance officer accountable for it.

Delegation of Authority
Available
Define the carrier's decision types with limits and conditions, then issue delegations with full lineage, from the board's reserved matters through the CEO's instrument to every branch underwriter and claims manager, and outward to every MGA, coverholder, and TPA. Each recipient's acceptance is recorded. When a role changes or a department realigns, Aptly detects the delegations affected, notifies the positions that hold them, and issues or revokes authority automatically rather than letting it carry over silently.
Learn more →
Signatory Management
Available
Maintain authorized signatory lists as a live output of the delegations that produce them, scoped by entity, instrument type, and signing threshold, with the board resolution, power of attorney, or binding authority agreement behind each authority attached. Who can sign and bind for each licensed entity and each delegated party always matches what was authorized.
Learn more →
Authority Hub
Available
Sync delegated authority across your identity directory and your finance and human-capital systems, and route approvals, settlements, and referrals by the governed record so a request always reaches the desk or the officer that actually holds the authority for it.
Learn more →
Intelligence
In Preview
Ask who can underwrite, settle, pay, sign, or bind for a given line, entity, limit, or delegated party in plain language, and get a grounded answer with the delegation behind it.
Learn more →
See one authority model run across your whole carrier.
Schedule a Discovery Call
Frameworks

Which regulations require proof of underwriting and claims authority

The obligations that make current authority non-negotiable. These obligations do not all sit in one office, and they do not pause between audits. Each one assumes the carrier can show who was authorized to act, internally and at every delegated party, and on what date. The effect is that an examination becomes a lookup rather than a reconstruction: the authority that stood on the bind date is retrievable in its exact form, with the actor and the prior value on every change. Aptly maps your authority model to what each one requires:

NAIC MGA Act #225

Govern and recall the authority you delegate to MGAs and TPAs.

The acts of an MGA are the acts of the insurer, binding reinsurance authority must rest with an unaffiliated officer, and the insurer must review the MGA's underwriting and claims operations at least semiannually. Aptly holds each delegated authority as a live, recallable record with the agreement behind it. NAIC Managing General Agents Act (Model #225), Sections 4 to 6. Adopted in varying form by states. Subject to change.
Sarbanes-Oxley Act of 2002, §404; SEC ICFR definition (Exchange Act Rules 13a-15 / 15d-15); PCAOB AS 2201.
NAIC CGAD #305/#306

Describe how authority is delegated across the company.

The confidential annual disclosure, due to the lead regulator by June 1, requires the carrier to describe how oversight and management responsibilities are delegated between the board, its committees, and senior management. Aptly holds that delegation as a live model rather than a once-a-year narrative.
NAIC Corporate Governance Annual Disclosure Model Act (#305) and Model Regulation (#306). Annual filing due June 1.
NAIC Model Audit Rule #205

Evidence internal control over financial reporting.

Insurers at or above $500 million in direct and assumed written premiums file Management's Report of Internal Control over Financial Reporting. Authority and escalation evidence is part of the control environment an examiner tests, and Aptly holds who held it on any date.
NAIC Annual Financial Reporting Model Regulation (#205). ICFR report at $500M+ direct and assumed premium. Subject to change.
SOX 404

Evidence that authority backed every commitment.

For publicly traded carriers and SEC-registrant holding companies, Section 404 requires management to assess internal control over financial reporting, which the SEC defines to include that commitments are made only with proper authorization. Aptly holds who held that authority, with the delegation behind it.
Sarbanes-Oxley Act of 2002, Section 404; SEC Rule 13a-15. Public filers and SEC registrants only.
Delegated-authority oversight

Prove oversight and recall of every delegated relationship.

Rating-agency and regulator expectations, including AM Best's Performance Assessment for delegated underwriting authority enterprises and, in the UK market, the rule that a carrier stays fully accountable for what it delegates, look for demonstrable governance and recall of delegated authority. Aptly is that record.
AM Best Delegated Underwriting Authority Enterprise (DUAE) Performance Assessment; FCA SYSC outsourcing and delegated-authority expectations.
Frameworks last verified June 2026. Obligations vary by carrier, premium volume, public status, jurisdiction, line of business, and delegated structure. This is not legal advice.
Get the Insurance Authority Readiness Brief →

You hold one authority model for the carrier and its delegated relationships. Each obligation reads it in its own terms, so an examination, a governance disclosure, or an MGA audit becomes a lookup, not a fresh reconstruction.

Proof

A binding authority suspended in one place, everywhere at once.

A multi-line carrier delegates binding authority for a coastal property program to a managing general agent, up to a set limit by line and territory, and delegates claims handling on that program to a third-party administrator, up to a per-claim settlement limit. In Aptly, each is a Recipient holding a delegated authority with lineage back to the Chief Underwriting Officer and Chief Claims Officer who granted it. When a dispute arises over the program, the carrier suspends the agent's binding authority during the pendency of the dispute, exactly as the binding authority agreement and the model law allow, in one action.

“Who can still bind risk on this program the moment the MGA's binding authority is suspended?”
Only one desk can sign
Only authority the carrier has not recalled. The suspension takes effect at a point in time across the record.
Authority traced to its source
That binding authority is delegated from the board through the chief underwriting officer to the MGA, recorded at each step (ref BA-2026-00471).
Executed against the signatory list
Every new binding and settlement now routes against the current authority, within limit, with referral above it.

The suspension cascades everywhere at once. The authorized-signatory and binding records update, the administrator's claims-settlement authority above the referral threshold routes back to the carrier's Chief Claims Officer, and any branch underwriter relying on the program sees the change. When the carrier is examined, and when it files its corporate governance disclosure and its Model Audit Rule report, Aptly recalls exactly who held what authority, internally and at every delegated party, on any date, with the instrument behind it. Reference BA-2026-00471.

Illustrative scenario on Aptly's Covered Insurance dataset.
FAQ

Insurance delegation of authority: common questions

Does Aptly govern the authority we delegate to MGAs, coverholders, and TPAs, as well as our internal authority?
Yes, both. Internally it models the cascade from the board through executives to branch underwriters and claims desks. Outward, each MGA, coverholder, or TPA is a Recipient holding delegated authority to bind risk or settle and pay claims up to the limit in its binding authority agreement, with lineage back to the officer who granted it and the ability to suspend, recall, or reassign it at any point in time.
Those systems run policies and claims and ingest delegated-business data. None is the system of record for who is authorized to underwrite, settle, pay, sign, or bind, internally or at a delegated party, up to what limit, with the delegation behind it kept current and recallable on any date. Most carriers keep their existing platforms and add Aptly as the live authority layer the routing, signing, and binding rely on.
Aptly models them as distinct authorities, because they are. Underwriting authority binds risk, claims settlement agrees a resolution, claims payment releases funds, reserving sets the carrier's stated liabilities, and signing authority binds the company. A person or entity can hold one and not the others. Aptly makes each explicit on the matrix and routes each action to the authority that governs it, with escalation and referral above the limit.
Yes. Signatory lists are managed in the same system as the delegations that produce them, scoped by entity, instrument type, and signing threshold, with the source resolution, power of attorney, or binding authority agreement attached. When an officer moves or a delegation changes, Aptly flags the signature authorities that may no longer be valid, so they can be reviewed and reassigned before someone binds the carrier on lapsed authority. On delegated business the binding authority agreement is the source document, attached to the authority it grants, so a coverholder's limit and the carrier's record of it cannot diverge.
No. Any carrier that delegates authority, internally to branch underwriters and claims desks or outward to MGAs and TPAs, and that answers to an examination, a governance disclosure, or a Model Audit Rule report, needs a current, recallable record of who holds what authority. Aptly scales from a single licensed entity to a holding company with many carriers and delegated relationships.
Pairs With

Built to work with the rest of your authority program.

Use case

Contract Approval & Signature Authority
Prove who can approve and who can sign every treaty, binding authority agreement, and commitment the carrier executes.

View use case →

Use case

Regulatory Readiness & Compliance
Produce audit-ready evidence of who was authorized to underwrite, settle, pay, and sign on every matter, on the date it happened.

View use case →

Use case

Multi-Entity Governance
Carry one authority model across the holding company and every licensed subsidiary and service entity.

View use case →

See your carrier's authority as one live system.

Bring your delegation structure for one line, one claims operation, one licensed subsidiary, or one MGA or TPA relationship, and the authority each one holds. We will show you the single, current, audit-ready view Aptly produces, using your authority data.