// MGAs and program administrators

Your capacity renewal is a data problem.

Capacity providers are shortening contract durations, raising attachment points and expanding data requirements on delegated business. The reporting you build this year is the reporting your 2027 capacity depends on. This is the segment where the deadline is monthly.

Dearborn Labs is an AI-native software development firm built specifically for insurance. You hire us; you don't buy software from us.

Get a read on one workflow →Or start with Discovery →

// The situation

The gap in the filings is the problem, stated as a number.

US MGA premium reached $128B in 2025, up 17.8% against roughly 5% for P&C overall — a fifth consecutive year of double-digit growth, across roughly 800 reporting MGAs. Only $102.6B of it appears in statutory filings; Conning derives the reported figure from NAIC Annual Statement Note 19 and estimates the remainder.

Conning MGA Study 2026 · AM Best 2026.

That $25B difference is not an accounting curiosity. It means a material share of delegated-authority premium is not visible in any structured regulatory filing, so the only authoritative record of your book is the one you keep. Making that record correct, reproducible and reportable in N formats is the whole job on this page.

// The stack you actually run

The spreadsheet is not laziness. It is rational.

A program administrator writing a manuscript program has a rating model no policy administration vendor supports out of the box, a capacity provider that changes the rate structure at each treaty renewal, and a book the vendor configuration projects are not sized for. So the build reads from the spreadsheet rather than requiring its replacement first.

The named failure mode in this segment is a startup MGA overbuying platform capacity before it has generated any operating data. Where the spreadsheet is still the right answer, the work is to automate around it: keep the rating model where the underwriter can edit it, and put the intake, the reconciliation and the reporting on rails.

And the reporting is plural by construction. Underwriting authority is granted in more than 75% of MGA contracts reviewed, and non-exclusive contracts are now the majority of MGA-produced premium. AM Best · 2026. You answer to a capacity panel rather than to one carrier, which means N reporting formats rather than one.

And the panel has turned. AM Best reports capacity providers now demanding long-term underwriting quality over growth, with enhanced due diligence before renewal, while reinsurers impose shorter durations and expanded data requirements on delegated business.

// The build

Four builds, in the order the book can carry them.

01

N bordereaux from one book of record

A coverholder managing 20 binding authority relationships produces 20 materially different bordereau layouts for the same period, and premium, claims, technical account and risk bordereaux run 30 to 60-plus fields each. All of them generate from one canonical record, with per-carrier field mapping held as configuration rather than as a person's memory.

Surface: your book of record plus a mapping layer you edit. Lloyd's Coverholder Reporting Standards v5.2 gives you a specification if you are coverholder-backed; there is no US-domestic equivalent.

02

Reported-versus-booked reconciliation

The gap between what you reported to the carrier and what the carrier booked. Today nobody owns it, it surfaces at audit, and it damages the relationship that renews your capacity. This is the highest-value, least-glamorous problem in the segment: unavoidable, currently manual, and measurable in dollars.

Surface: your premium and claims ledgers against each carrier's returned statement.

03

Submission triage against the binding authority contract

Class, limit, geography and premium-size boundaries live in a PDF contract. They become an executable check that runs at intake, so an out-of-authority risk is flagged before an underwriter spends an hour on it, with a citation to the governing clause. It also catches the same risk arriving from three wholesalers under slightly different insured names, which corrupts your hit ratio.

Surface: the intake mailbox and the contract itself, held as machine-readable rules.

04

The delegated-authority audit file

Model 225 requires quarterly financial accounts in a format that lets the carrier complete its annual statement, annual CPA reports, and at least semi-annual audits. The evidence assembles continuously instead of in a scramble, and that file is also the one that answers the reinsurer's expanded data request.

Surface: the same canonical record, with the audit trail retained by transaction.

What we measure

Days from period close to last bordereau delivered — Lloyd’s deadlines run 15 to 20 business days, US program deadlines vary by contract. Lloyd’s CRS v5.2 · current at September 2026. Reconciliation variance between reported and booked premium, as a dollar figure and a trend. Rejected or re-requested bordereaux per quarter. Hours of manual keying per reporting cycle, baselined by observation rather than by estimate.

// We ran one of these

Reading a bordereau against booked premium is the first build on this page rather than the dashboard, because the reconciliation is where the discrepancy lives.

The operating record →

// What's hard about this

Two constraints worth knowing before you fund anything.

Column-name drift is a governance problem, not a parsing problem.

“GWP” against “Gross Written Premium,” DD/MM/YYYY colliding with MM/DD/YYYY, currency stated somewhere else or not at all. All of it normalizes. What cannot be normalized away is a carrier changing its template next quarter without telling you, and there is no US-domestic reporting standard to appeal to. So the durable fix is a mapping layer you own and can edit — new column, one configuration change — rather than a model that has memorized this quarter’s file.

Portfolio decisioning needs a book with enough history to decide on.

Decisioning is a real capability, and it runs on operating data the book has to have produced first. Two years of thin, inconsistently keyed history cannot support appetite steering, and a model built on it will express the keying rather than the risk. The sequence that works is intake automation first, the research layer second, and decisioning when the book supports it — which is also the order in which each stage produces the data the next one needs.

// What ships with it

The audit file and the AI file are the same discipline.

Delegated authority does not delegate accountability, and roughly half the states have adopted the NAIC AI Model Bulletin. Connecticut requires an annual AI compliance certification attested by a named officer, and Iowa formally defines bias and outcomes testing.

NAIC and state bulletins · current at September 2026.

So a triage model that screens submissions leaves with a model inventory entry and risk tier, data lineage naming the provenance of every inbound file, pre-deployment testing results, drift thresholds with remediation triggers, and a human-override specification naming who can bind outside the check. That is the same evidence your capacity provider’s due diligence asks for, assembled once.

What the governance file contains →

Start with the reporting your capacity renewal reads.

Four weeks, fixed scope, one named senior engineer inside your reporting cycle. We instrument the close, read your binding authority contracts against what actually gets bound, and return a buildable spec.