As MGAs grow, boards, capacity providers and regulators increasingly expect independent assurance over governance, risk management and internal controls. Informal oversight by compliance or operations eventually reaches its limit. This article sets out a practical, proportionate framework for establishing internal audit in an MGA — one that delivers genuine assurance without creating unnecessary bureaucracy.
When should an MGA establish an internal audit function?
There is no regulatory requirement for every MGA to maintain a dedicated internal audit function. However, as the business grows, boards, capacity providers and other stakeholders increasingly expect independent assurance over governance, risk management and the control environment. Common triggers for establishing — or formalising — an internal audit function include:
- Sustained growth in premium volume or operational complexity.
- Multiple binders, capacity providers or delegated authority arrangements.
- Increased regulatory obligations or supervisory engagement.
- New products, distribution channels or jurisdictions.
- Material outsourcing or third-party dependencies.
- Significant technology change or AI deployments.
- Requests from investors, boards or capacity providers for independent assurance.
The objective is not to create another layer of process, but to provide independent insight into whether key risks are being identified and managed effectively.
Understanding the Three Lines Model
Internal audit forms part of the third line of defence, providing independent assurance over the effectiveness of governance, risk management and controls. It should remain independent from the first line (business operations) and the second line (risk, compliance and other oversight functions). Maintaining this separation is essential if internal audit is to provide objective challenge and credible assurance to the board and audit committee.
Choosing the right operating model
Few growing MGAs need — or can sustain — a full in-house internal audit function. The operating model should be proportionate to the size, complexity and risk profile of the business, and to the expectations of capacity providers. Three models work well in practice:
- Fully outsourced to a specialist firm, with a named partner accountable to the audit committee. Efficient at smaller scale; weaker on institutional knowledge.
- Co-sourced — a fractional Head of Internal Audit supported by an external firm for fieldwork. Often a strong fit for mid-sized MGAs balancing cost, independence and expertise.
- In-house with co-source overflow — appropriate where scale, complexity or capacity provider expectations justify a permanent function with specialist support on demand.
Whichever model is adopted, internal audit should report functionally to the audit committee (or the board where no audit committee exists) and administratively to the CEO. Any alternative reporting structure may create perceived or actual independence concerns and should be carefully considered and clearly justified.
Building the audit universe
The audit universe sets out everything the function could potentially audit. For an MGA, it is typically constructed from four lenses:
- Regulatory and conduct: SM&CR, Consumer Duty, CASS 5, complaints handling, financial crime, sanctions, data protection and operational resilience.
- Delegated authority and capacity provider obligations: binder terms, minimum standards, bordereaux quality, underwriting and claims authority.
- Core processes: underwriting, pricing, claims, finance, IT, HR, third-party risk management and distribution.
- Strategic and emerging risks: new product launches, system migrations, M&A activity, AI governance and model risk, and business continuity.
A documented risk assessment methodology
Each entry in the audit universe should be assessed against a documented and consistently applied risk methodology. Relevant factors typically include regulatory impact, financial exposure, customer outcomes, operational criticality, change activity, outsourcing dependency, technology risk and known management concerns. The output is a ranked view of risk that informs the annual audit plan, refreshed at least annually and revisited where the business or risk profile changes materially.
A risk-based annual audit plan
The number of audits should be proportionate to the size, complexity, risk profile and regulatory obligations of the MGA. Shorter, deeper audits with meaningful recommendations generally deliver more value than broad, shallow coverage. Each plan entry should set out:
- A clear scope statement — what is in and what is explicitly out.
- The risk rationale, linked back to the audit universe.
- Estimated effort and timing.
- A named senior stakeholder.
The plan should be approved by the audit committee, with their challenge an integral part of the process rather than a formality.
The capacity provider perspective
Capacity providers increasingly expect MGAs to demonstrate effective governance and control environments over delegated authority arrangements. A well-designed internal audit function can provide independent assurance not only to the board but also to capacity providers seeking confidence that binders, underwriting authority, claims handling and bordereaux processes are being managed appropriately. This is increasingly a factor in capacity negotiations and renewals.
A repeatable audit methodology
Every audit should follow the same lifecycle. Documenting it once and applying it consistently is what distinguishes a function that scales from one that reinvents itself each quarter.
- Planning: objectives, scope, risks, controls, tests, sample approach and a kick-off with the auditee.
- Fieldwork: walkthroughs, control design assessment, operating-effectiveness testing and evidence capture in a structured working paper file.
- Findings: each finding articulated through condition, criteria, cause, consequence and recommendation, and agreed with the auditee before reporting.
- Reporting: a concise report with an overall opinion and findings rated by significance, supported by management actions with owners and target dates.
- Tracking and validation: findings logged centrally and reported to the audit committee until independently validated and closed.
Core controls testing
Beyond the risk-based plan, certain control areas typically warrant coverage each year in an MGA environment:
- Bordereaux accuracy and timeliness.
- Underwriting and claims authority compliance.
- CASS 5 — calculation, reconciliation and breach reporting.
- Complaints handling against DISP and Consumer Duty expectations.
- Financial crime — sanctions, PEP screening and source-of-funds.
- SM&CR fitness, propriety and certification.
- Third-party risk management and operational resilience.
- IT general controls and AI/model governance where relevant.
Managing audit findings
The value of internal audit is realised through remediation, not reporting. Every finding should have:
- A named accountable owner.
- An agreed action plan.
- A realistic target completion date.
- Evidence of implementation.
- Independent validation before closure.
A single, well-maintained findings tracker — reviewed regularly by management and the audit committee — is one of the clearest indicators of a healthy control environment.
The role of the audit committee
The audit committee should approve the annual audit plan, review audit findings, monitor remediation progress and assess the effectiveness and independence of the internal audit function. Quarterly papers should cover plan progress, reports finalised in the quarter, the open findings tracker with ageing, and an honest view of any scope or resource pressures. A committee that only sees positive reporting is not being well served.
Common challenges
- Limited resources and competing priorities.
- Lack of specialist insurance and audit expertise.
- Maintaining independence in a smaller organisation.
- Balancing audit volume with the capacity to remediate findings.
In summary
Internal audit should not be viewed as a regulatory obligation or a capacity provider tick-box. When designed proportionately, it provides boards, management and capacity providers with confidence that key risks are understood, controls are operating effectively and the business can scale in a controlled and sustainable manner. For many MGAs, the challenge is not whether to introduce internal audit, but how to do so in a way that adds genuine value without creating unnecessary bureaucracy.
JanthanaK provides fractional Head of Internal Audit support, outsourced fieldwork and internal audit advisory for MGAs through the MGA Internal Audit service. Book a 30-minute scoping call to discuss what a proportionate internal audit function could look like for your organisation.
About the author
Janthana Kaenprakhamroy is an insurance executive with experience spanning internal audit, governance, risk management, operational resilience and business transformation. She advises insurers, MGAs and brokers on building proportionate assurance and governance frameworks that support sustainable growth.