Skip to content
Risk-Based Differentiation
Jason DaviesSep 21, 2026, 3:15:56 PM10 min read

Risk-Based Differentiation: Navigating Underwriting Discipline Under the Lloyd's 2026–2030 Strategy

Under Lloyd’s 2026-2030 Strategy, underwriting performance, capital advantage and a more efficient marketplace are at the centre of the market’s next phase, creating a clear shift in emphasis.

Risk management is no longer only about protecting an organisation from downside exposure. It is now becoming a more active part of how managing agents demonstrate discipline, evidence control, and create confidence in their ability to operate under a more risk-based oversight model.

Lloyd's strategy points towards more targeted, proportionate oversight. Firms that can demonstrate strong governance, mature risk models, reliable data, and disciplined underwriting are likely better placed than those still relying on manual controls, inconsistent data, or late-stage risk review.

Central market oversight remains important for risk management, but firms need to show their own frameworks can identify, monitor, and manage risk effectively across underwriting, aggregation, operational resilience, third parties, and technology dependencies.

As pricing momentum slows across some speciality classes, discipline becomes even more important. A softer rating environment can test underwriting boundaries quickly, but risk teams still need the data, governance, and escalation routes to understand where exposures are building, where business is moving outside plan, and where operational or supplier dependencies could affect resilience.

Under the 2026-2030 strategy, the strongest risk functions will provide organisations with clear visibility, stronger challenge, and earlier warning when underwriting discipline or operational control begins to weaken.

Principles-Based Oversight places more weight on evidence

Principles-Based Oversight gives managing agents more responsibility for demonstrating how they meet Lloyd’s expectations. The model is designed to be targeted and proportionate, meaning that firms need to provide better evidence that their governance, risk management and control frameworks are operating effectively.

Having a framework in place is key, but those responsible for risk management need to show how it is applied in practice, how decisions are made, how risks are escalated, and how management information supports effective oversight.

As Lloyd’s looks to reduce unnecessary friction for firms that can demonstrate strong control, a managing agent with clean data, mature risk governance and low volatility should be easier to oversee than one where information is incomplete, controls are unclear or exposures are difficult to explain.

However, the challenge is that evidence often depends on the quality of underlying processes. If underwriting decisions, risk appetite exceptions, aggregation positions or third-party dependencies are tracked inconsistently, the risk function may struggle to give senior leaders and oversight teams the confidence they need.

Principles-Based Oversight therefore puts greater pressure on internal discipline. Managing agents need clear ownership, reliable data capture, documented decisions and governance structures that can stand up to scrutiny. Organisations that do this well may be better placed to benefit from a more proportionate oversight relationship, while those with weaker evidence may face greater challenge.

Underwriting discipline needs live risk visibility

Underwriting discipline is one of the clearest risk priorities under the Lloyd’s 2026-2030 Strategy. As pricing momentum slows across some specialty classes, managing agents need to understand whether underwriting decisions remain aligned to appetite, business plan and aggregate exposure limits.

As such, risk teams need to be closer to the point of decision. If risk information is only reviewed after placement, or if exceptions are only visible once reporting has been consolidated, the organisation may not be able to intervene early enough. In a more differentiated oversight environment, that delay can create both commercial and governance pressure.

Strong underwriting discipline depends on clear boundaries. Underwriters need to understand where authority sits, which risks require escalation and when a proposed placement falls outside agreed appetite or business plan assumptions. Risk teams also need consistent information that lets them identify patterns across portfolios, classes, coverholders, and distribution channels.

When risk capture is inconsistent, this becomes more difficult; if key data is missing at inception, or if aggregate exposures are only fully understood through later manual reporting, managing agents may be relying on incomplete information when decisions are being made, weakening the firm’s ability to manage accumulation risk, monitor underwriting drift and evidence effective governance.

Technology can support this, but only if the underlying controls are clear. Real-time alerts, workflow controls and automated escalation points can help flag risks that fall outside agreed parameters. Used properly, they give risk and underwriting teams earlier visibility of potential issues, rather than relying on retrospective review.

The priority for Chief Risk Officers and Risk Directors is to now make underwriting discipline visible and testable. Firms should be able to clearly show how underwriting boundaries are defined, how exceptions are approved, how risk information is captured and how aggregate exposures are monitored as business is written.

Data quality is becoming a risk control

Data quality is central to risk-based differentiation. Managing agents cannot demonstrate underwriting discipline, aggregation control or operational resilience if the underlying data is incomplete, inconsistent or captured too late in the process.

Where business is written through coverholders, MGAs, or delegated authority arrangements, this becomes particularly important; if exposure data is not captured digitally at inception, risk teams may only see the full position later through bordereaux, mid-term reporting, or manual reconciliation. By that point, the opportunity to challenge the risk before it enters the portfolio may already have passed.

Decision-grade risk capture needs to become part of the control environment, with clear standards for broker submissions, defined mandatory data fields, improved validation, and risk information that underwriting, actuarial, finance, and risk teams can use without repeated rework.

Aggregation risk is a clear example: multi-class cyber exposure, supply chain concentration, climate-related risk and geographic accumulation can build across portfolios if data is not captured consistently. While a managing agent may understand individual risks, they may still struggle to see how those risks connect across classes, clients, territories or distribution channels.

CROs and Risk Directors should now treat data quality as more than a reporting issue, and view it as part of how the firm controls the business it writes. Stronger data supports better underwriting decisions, clearer aggregation monitoring, more reliable scenario testing and stronger evidence under Principles-Based Oversight.

As Lloyd’s moves towards a more targeted and proportionate oversight model, firms will need to show that their risk data can support the decisions being made. Poor data quality makes that harder, as it creates uncertainty, slows challenge and weakens confidence in the firm’s ability to manage risk within appetite.

Aggregation risk needs to be challenged earlier

Aggregation risk becomes harder to manage if firms lack a clear view of exposure as business is written. Individual underwriting decisions may appear within appetite, but the combined position can look different once risks are viewed across classes, geographies, sectors, coverholders and counterparties.

Under Lloyd's 2026–2030 Strategy, risk teams need to identify those patterns earlier. If aggregation is only understood after data has been consolidated through later reporting, the firm may have already accepted more exposure than intended, creating pressure for underwriting, capital planning, reinsurance strategy and senior risk governance.

As a result, risk capture at inception is now more important. Managing agents need to know whether the data they receive is detailed enough to support aggregation monitoring, whether delegated authority arrangements provide timely visibility, and whether exposures can be reviewed before they create a material concentration.

Scenario testing should also reflect the realities of the next market cycle. Risk teams should test severe-but-plausible scenarios that assume prolonged reliance on legacy technology, delayed market modernisation or supplier delivery failure during the transition period.

Aggregation risk should not be treated as a periodic reporting exercise, but as part of live risk governance, supported by better data, clearer escalation, and scenario testing that reflects how the organisation would respond under pressure. With a stronger approach, risk committees have a clearer view of where exposures are building, how resilient the operating model is and whether underwriting discipline remains aligned to the firm’s appetite as market conditions change.

Scenario testing should reflect operational reality

Managing agents already use scenario testing to understand the potential impact of severe events, portfolio stress and changing market conditions. Under Lloyd's 2026–2030 Strategy, those scenarios also need to reflect the operational environment firms are working in.

A scenario test should not only test what happens if a major loss event occurs, but also test whether the organisation has the data, systems, suppliers, governance and decision-making routes needed to respond effectively. If a firm still relies on legacy technology, manual controls, or delayed supplier delivery during the market transition period, those dependencies need to be understood as part of the risk picture.

As market modernisation continues incrementally, firms may need to run old and new processes side by side longer than expected. Operational resilience needs to be closely connected to underwriting and risk governance, as incremental change can create additional operational risk, especially where data moves between systems, teams rely on manual reconciliation or critical reporting depends on third-party delivery.

The priority should be to ensure scenario testing reflects how the organisation operates by testing its ability to identify issues, escalate decisions, access reliable data, and maintain control under pressure, as well as the financial impact of a stress event.

Risk governance needs to be active, not retrospective

Risk governance will need to become more active as oversight becomes more differentiated.

A risk committee cannot provide effective challenge if it reviews issues only after they have already moved through the business. By that point, the firm may have already accepted exposure, committed capacity, relied on incomplete data or allowed a dependency to become embedded.

Stronger governance depends on earlier visibility. Risk leaders need clear management information showing where underwriting is moving outside appetite, where aggregate exposures are building, where operational dependencies are creating pressure, and where supplier or technology risks could affect delivery. Clear decision rights, defined escalation routes and a shared understanding of when risk needs to intervene are all key here. If underwriting, operations, actuarial, finance, and technology teams each look at different versions of the same issue, senior committees will struggle to reach a consistent view.

Risk governance also needs to be connected to transformation. As firms modernise systems, adopt new tools, improve data capture or change underwriting workflows, risk teams need to understand how those changes affect controls and accountability. A technology change may improve speed, but it can also introduce new risks around data quality, access, third-party dependency or model reliance.

Governance should be practical and timely, enabling firms to show how risk appetite is applied, how exceptions are reviewed, how decisions are evidenced, and how senior leaders are informed before issues become material.

Practical actions for risk leaders

Risk leaders should start by reviewing how well their current framework supports differentiated oversight. Practical actions should include:

  • Review risk data capture at inception. Assess whether key risk information is captured early enough, consistently enough, and in a format that supports underwriting decisions, aggregation monitoring, and senior risk governance.
  • Strengthen standards for broker, coverholder and MGA data. Where exposure data is still being corrected manually or received too late in the process, the risk function may not have the visibility it needs to challenge decisions effectively.
  • Test underwriting boundaries in live workflows. Firms should understand whether appetite, business plan limits and escalation requirements are clear within day-to-day underwriting activity. Where risks move outside agreed parameters, the organisation should be able to identify that quickly and evidence how the decision was reviewed.
  • Refresh scenario testing for the 2026–2030 market cycle. This should include severe-but-plausible events, operational dependencies, technology constraints, supplier issues and the organisation’s ability to maintain control during disruption.
  • Connect risk governance to transformation activity. As firms improve data architecture, introduce automation, modernise systems or change underwriting workflows, risk teams need to be involved early enough to understand the impact on controls, accountability and operational resilience.
  • Make the framework visible and testable. Managing agents should be able to show not only that risk controls exist, but that they operate effectively and support disciplined underwriting decisions as market conditions change.

The practical aim is to build a risk framework that gives senior leaders earlier visibility, stronger challenge and clearer evidence.

How Brighter Consultancy can support

Brighter Consultancy supports London Market firms with risk and transformation programmes that require practical delivery, clear ownership and strong control. We work with clients to review current processes, strengthen governance structures, improve data and reporting, and support change delivery across complex operating environments.

Our work can support risk governance reviews, underwriting control frameworks, aggregation risk processes, scenario testing, operational resilience, data quality improvement and wider transformation delivery. We help firms understand where current ways of working may limit visibility, increase manual effort, or make it harder to evidence effective risk management.

If your organisation is reviewing its risk governance, underwriting controls or transformation priorities under the Lloyd’s 2026–2030 Strategy, speak to our team.

COMMENTS

RELATED ARTICLES