Who this is for: managing agents, delegated authority managers, compliance officers and coverholders in the Lloyd’s and London markets. It explains where sanctions screening actually has to happen on delegated business, why bordereaux alone do not satisfy the requirement, and what the carrier remains accountable for. It is general information, not legal advice.
Last reviewed 23 August 2026.
Under a binding authority, a carrier delegates underwriting to a coverholder or managing general agent, who binds risks on the carrier’s paper within an agreed scope. The carrier does not see the individual risk at the point it is written. It sees it later, in a bordereau: a periodic schedule of what was written, what premium was collected, or what claims were notified and paid.
Lloyd’s Coverholder Reporting Standards, currently version 5.2 issued under market bulletin Y5261, define three categories of bordereaux data:
Lloyd’s states that core reporting requirements apply to all binding authority agreements and coverholder appointment agreements incepting since July 2017. Bordereaux are submitted and processed through the market’s Delegated Data Manager platform, with defined submission and approval roles.
There is no single market-wide submission deadline. Frequency and timing are set in the individual binding authority agreement rather than by a universal Lloyd’s rule. Monthly reporting in arrears is the common pattern, but the contract governs.
Lloyd’s requires coverholders to “conduct appropriate due diligence and screening against applicable financial sanctions target lists prior to underwriting (ie the HMT Consolidated List… the OFAC list)”.
Prior to underwriting. Not prior to reporting, and not prior to the bordereau being processed.
A bordereau is a record of business already bound. If the first time a name is screened is when it appears in a monthly bordereau, the risk has already been written, the exposure already accepted, and possibly a claim already notified. The screening has happened, but it has happened after the moment the requirement attaches to.
This is not a technicality. Under the UK regime, a firm must report to OFSI as soon as practicable once it knows or has reasonable cause to suspect a person is designated. Discovering a designated insured in a bordereau thirty or sixty days after inception means the firm has been carrying an unreported exposure for that period, and civil liability for the underlying breach is strict for anything occurring on or after 15 June 2022.
OFAC takes the same view of lifecycle timing from the other direction. Its FAQ 65, issued 25 November 2024, expects a risk-based approach that screens issued policies at policy renewal, policy amendment, claim submission and claim payment, and states that the responsibility extends to underwriters, brokers and agents.
This is the point that matters most and it is settled in two places.
Lloyd’s. Coverholders are obliged to have proper and adequate systems and controls to ensure AML and international sanctions compliance. Lloyd’s is equally clear that managing agents have a separate legal responsibility to ensure this, must take steps to ensure each coverholder knows about and adheres to all applicable requirements, and must include specific and measurable questions relating to AML and international sanctions in coverholder audits.
The FCA. Rule SYSC 8.1.6 R provides that a firm outsourcing critical or important operational functions “remains fully responsible for discharging all of its obligations under the regulatory system”, and that “the outsourcing must not result in the delegation by senior personnel of their responsibility”. SYSC 8.1.8 R requires that a firm effectively supervise outsourced functions and retain the necessary expertise and resources to supervise them effectively.
So the carrier cannot answer a regulator by pointing at the coverholder’s contract. It has to be able to show what it did to supervise, and that it kept enough capability in house to do so meaningfully.
| Point in the lifecycle | Who is at the keyboard | Why it is required |
|---|---|---|
| Before the risk is bound | Coverholder or MGA | Lloyd’s requires screening prior to underwriting. This is the one a bordereau cannot cover. |
| On the bordereau, when received | Managing agent or carrier | Independent verification that the coverholder actually screened, and a catch for anything designated since inception. |
| At renewal and at amendment | Coverholder | Named by OFAC FAQ 65. Designations change; a clean subject at inception may not be clean now. |
| At claim notification | Coverholder or claims handler | Named by OFAC FAQ 65. |
| Before any payment | Whoever releases funds | Lloyd’s requires additional screening prior to payment of claims, return premiums and all other sums. OFAC requires premium from a blocked person to be blocked. |
| Continuously against list updates | Carrier | Neither regime treats a point in time check as sufficient across a multi year policy. |
The bordereau is a control. It is not the control. It sits in the second row of that table, and it works as an assurance layer over the coverholder’s own screening rather than as a substitute for it.
The data arrives dirty. Names come in free text, inconsistently formatted, often without dates of birth, addresses, jurisdictions or company numbers. Match quality falls sharply without secondary identifiers, which pushes alert volumes up and precision down.
The volume is lumpy. A book that generates a manageable trickle of alerts day to day produces a spike when a quarterly bordereau lands. Staffing for the peak is expensive and staffing for the average means the peak is cleared late.
One name is not one alert. A single screened name can match many list entries. An alert is a name that hit something. A concern is an individual list entry it matched against, and one alert can carry dozens. Sizing a bordereaux screening operation on alert counts rather than concern counts understates the work by a wide margin.
The audit trail has to survive. OFAC’s recordkeeping requirement moved from five years to ten, effective 21 March 2025, following the extension of the statute of limitations to ten years in April 2024. A cleared bordereau line needs an evidence file that can be reconstructed a decade later.
What addresses these is not more analysts. It is resolving identity properly, ranking by genuine risk so the queue is ordered rather than merely long, disposing of the structurally impossible matches automatically with a recorded reason, and escalating anything uncertain rather than clearing it.
No. Lloyd’s requires screening against applicable financial sanctions target lists prior to underwriting. A bordereau reports business already bound, so screening at that point happens after the requirement attaches. Bordereaux screening is a valid assurance layer over the coverholder’s own screening, not a replacement for it.
Yes. Lloyd’s states that coverholders must have adequate systems and controls and that managing agents have a separate legal responsibility to ensure they do, including specific and measurable sanctions questions in coverholder audits. FCA rule SYSC 8.1.6 R provides that a firm outsourcing critical or important functions remains fully responsible for discharging all of its regulatory obligations, and SYSC 8.1.8 R requires it to retain the expertise and resources to supervise effectively.
There is no single market-wide deadline. Frequency and timing are set in the individual binding authority agreement rather than by a universal Lloyd’s rule. Monthly reporting in arrears is the common pattern. The Lloyd’s Coverholder Reporting Standards, version 5.2 under market bulletin Y5261, define the data content rather than a universal submission deadline.
Risk data covering policy and underwriting information, premium data covering placement and premium, and claims data covering losses and claims. Lloyd’s core reporting requirements apply to all binding authority agreements and coverholder appointment agreements incepting since July 2017.
OFAC FAQ 65, issued 25 November 2024, expects a risk-based approach screening issued policies at exposure points including policy renewal, policy amendment, claim submission and claim payment. It states that the responsibility extends to underwriters, brokers and agents, not only the carrier.
Two reasons. Bordereaux data is typically free text with few secondary identifiers such as date of birth, address or jurisdiction, which reduces match precision and raises volume. And one name can match many list entries: an alert is a name that hit something, while a concern is each individual list entry it matched against. Sizing the work on alert counts rather than concern counts understates it substantially.
Where there is any US nexus, ten years. OFAC extended its recordkeeping requirement at 31 CFR 501.601 from five years to ten with effect from 21 March 2025, following the extension of the statute of limitations for IEEPA and TWEA violations from five years to ten by the 21st Century Peace through Strength Act, signed 24 April 2024.
Global RADAR screens bordereaux data at scale against more than 1,400 sanctions and watchlists, resolves identity where secondary identifiers are thin, and orders the queue by genuine risk rather than returning it unsorted. Structurally impossible matches are disposed of automatically with a recorded reason code, and anything uncertain escalates rather than clearing. Every decision is reproducible and exportable for the full ten year retention period.
Read the full alert clearing methodology and model governance, see how this works for the London and specialty market, or review how clearing is delivered and priced.