Can MGA Technology Improve Underwriting — or Merely Accelerate Bad Decisions?

Something significant is happening in Canadian insurance right now. Three separate regulatory tracks are landing on MGA technology at once in 2026, and the timing is pointed. The OSFI AI Bulletin, CAMGA's provincial white paper, and OSFI Guideline E-23 are each asking the same underlying question: is faster underwriting actually better underwriting? Based on what regulators are putting in writing, the answer is not necessarily.

Three Tracks, One Crossroads

Start with OSFI's AI Bulletin from July 13, 2026. It maps AI risk guidance onto three existing guidelines covering technology, operational resilience, and third-party risk management. McCarthy Tétrault puts it plainly: financial institutions "do not need to reinvent the wheel" on AI risk. It gets layered onto existing governance, with AI-specific detail on top. The companion Frontier AI Guidance, though, doesn't leave much room for interpretation. Institutions must "set limits on what automated systems can do independently" and "maintain human involvement for higher-impact decisions."¹

Then there's OSFI Guideline E-23, effective May 1, 2027. It extends model risk management to all federally regulated insurers and explicitly pulls AI and machine-learning models into scope. Deloitte Canada points out that E-23 covers "underwriting, pricing, financial planning, marketing, claims analytics," which is essentially everything an MGA's technology stack does on a given day. It also ties back to B-10 directly: "organizations remain accountable for outsourced activities and must manage associated risks."² The moment E-23 kicks in, AI in underwriting stops being a productivity win. It becomes a paper trail.

CAMGA's provincial white paper, authored by Patrick Ballantyne, former CEO of the Registered Insurance Brokers of Ontario and former Chair of CISRO, puts the MGA's role in plain terms: "Managing General Agents act as delegated extensions of an insurer's underwriting, distribution and administration functions." The paper's 14 formal recommendations make something clear: delegation doesn't move accountability. It focuses it.³

The Gap No Automation Closes

Here's the part that tends to get overlooked. OSFI Guideline B-10 is unambiguous: "the FRFI retains accountability for business activities, functions and services outsourced to a third party."⁴ Any carrier flowing delegated authority through an MGA's automated system is still on the hook. No asterisk.

Kirsten Thompson of Dentons LLP has watched this play out in practice: "Very few insurers are developing their own AI. They're usually using a vendor, third party, and then training it on their data sets. So, in my experience, there's not a lot of scrutiny of third-party AI vendors." Her due diligence checklist cuts right to it: "What is your training centre? Where did the data come from? What are your fallbacks? What's the explainability? What are your outcomes? Where is the transparency?"⁵

OSFI adds the systemic dimension: "reliance on AI vendors concentrates both AI-specific and broader third-party risk." That problem compounds when vendors themselves are using AI to deliver their services. An MGA relying on a third-party rating platform with embedded AI is sitting inside that layered exposure, whether it knows it or not.

What Should Never Be Automated Without an Underwriter Looking Over Its Shoulder

Five categories stand out where human oversight simply isn't optional, drawing from OSFI and CAMGA's combined frameworks.

  • Binding decisions outside pre-approved authority limits. CAMGA Recommendation 5 requires that automated systems stay within contracted insurer authority at all times. Any system capable of binding outside that boundary leaves the Designated Individual with no credible defence.
  • Final accept/decline on higher-impact risks. OSFI's Frontier AI Guidance is specific: institutions must be "maintaining human involvement for higher-impact decisions."
  • Using AI output as a final answer. OSFI is clear that institutions should "treat AI outputs as inputs to decision-making rather than definitive outcomes."
  • Decisions an MGA can't reconstruct on audit. B-10 and E-23 together require model inventories, validation status, and audit rights. If a decision can't be explained, it won't hold up under regulatory review.
  • Silent vendor model updates. OSFI requires vendors to disclose AI use and institutions to log model changes. An MGA whose rating logic gets quietly updated without its knowledge is in breach by proxy.

The competitive edge won't go to the MGA that automates the most. It'll go to the one that knows what should never be automated without an underwriter looking over its shoulder.

5 Key Takeaways

  1. Regulatory accountability doesn't transfer with delegation. Carriers are still responsible for everything automated under their delegated authority, including what the MGA's technology vendors are doing.
  2. The compliance clock is running. OSFI E-23, effective May 1, 2027, requires documented model inventories and independent validation for every AI-assisted underwriting or pricing decision, and that obligation will follow MGAs contractually.
  3. Canada's largest insurance market has no mandatory MGA licensing. Ontario — Canada's largest insurance market — has no statute requiring MGAs to be licensed at all. Many choose to license voluntarily through the Registered Insurance Brokers of Ontario, whose financial requirements CAMGA calls the most robust among intermediary regulators in the country. But choosing is the operative word: nothing in Ontario law compels it, which is precisely why CAMGA's own white paper recommends requiring Ontario brokers to deal only with RIBO-licensed MGA partners..
  4. Vendor dependency is a concentration risk. IBM data cited in Canadian Underwriter's reporting shows 65% of Canadian businesses acquire AI tools from vendors rather than building in-house, meaning most MGA automation is third-party by default.
  5. Speed and decision quality aren't the same thing. Automation reliably makes processing faster. It only sometimes produces better risk selection, pricing adequacy, and decisions that hold up under scrutiny.

 

Footnote:

¹ Morgan, Charles S., and Francis Langlois. "Managing the AI Risks in the Financial Sector: OSFI's Bulletin on Generative and Agentic Artificial Intelligence." McCarthy Tétrault TechLex, 7 Aug. 2026, https://www.mccarthy.ca/en/insights/blogs/techlex/managing-the-ai-risks-in-the-financial-sector-osfi-s-bulletin-on-generative-and-agentic-artificial-intelligence.

² Meissner-Roloff, Karl, Nanette Zhu, and Nicolas Gémin. "Guideline E-23 Is Here." Deloitte Canada, 15 Dec. 2025, https://www.deloitte.com/ca/en/Industries/financial-services/perspectives/osfi-expanded-guidelines.html.

³ Ballantyne, Patrick. "White Paper on Recommended Provincial Regulatory Standards for Property and Casualty Managing General Agents." CAMGA, 20 May 2026, https://camga.ca/wp-content/uploads/2026/05/ENGLISH-CAMGA-White-Paper-for-Members-May-20-2026.pdf.

⁴ Office of the Superintendent of Financial Institutions. "Third-Party Risk Management Guideline B-10." OSFI, 30 Apr. 2023, https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/third-party-risk-management-guideline.

⁵ Thompson, Kirsten. Quoted in "Experimenting with AI? Beware of Your Third-Party Risk." Canadian Underwriter, 16 Jan. 2025, https://www.canadianunderwriter.ca/insurance/experimenting-with-ai-beware-of-your-third-party-risk-1004254976/.

Total
0
Shares
Previous Article

When Everything Trades Together, Diversification Gets Harder

Next Article

Nearly Half of Canadian Advisors Have No Succession Plan: Which half are you in?

Related Posts