“Our policy requires human review before a decline.”
You delegate authority: to coverholders, to appointed representatives, to third-party administrators, and increasingly to software that decides on its own. You stay accountable for all of it. Remit turns the authority you granted into something that can be checked at the moment a decision is made, and leaves a signed record the party who granted it can verify.
The way in is the Authority Gap assessment. We take one of your mandates, run it against ninety days of your own decisions, and hand back three numbers. One week, fixed scope, nothing installed.
Two answers to the same question from an auditor
“Our policy requires human review before a decline.”
“The system wanted to decline it. The binder says a named underwriter has to sign that off, so it went to Sarah Okafor. She spent four minutes on it, saw everything the system saw, turned it into a referral instead, and wrote down why. Here is the record, and here is the tool to check we have not touched it.”
The structure is the same in every delegated relationship. You grant a mandate, somebody else decides inside it, and evidence is produced on a cycle to show that they did. The mandate is usually sound. The evidence is the part that breaks.
Most oversight functions answer this by asking once a year and believing the reply.
Referral is what a coverholder audit tests. It is rarely recorded as a field anywhere.
System logs, a spreadsheet, and the recollection of somebody who has since left.
You have sixty coverholders. Three of them have told you they use software somewhere in a decision path. You do not believe that is the real number, and short of asking again there is no way to find out.
None of these are new questions. Coverholder audits and SUP 12 reviews have always asked them, and the answer has always been put together after the fact, by hand, from systems that were never built to give it. What changed is volume and speed. A delegate that decides thousands of times a day cannot be meaningfully sampled, does not remember why, and cannot be interviewed by an auditor.
Three steps. Nothing in them depends on the decision being made by software, which is rather the point.
Your binding authority, appointment agreement or claims authority schedule becomes a versioned object: scope, limits, conditions, referral triggers, oversight requirements, prohibitions and expiry. Every line traces back to the clause it came from, and the encoding is signed off by a named person and kept as evidence in its own right.
# from binding authority B-2291, clause 4.2
# encoding confirmed by J. Whitfield, 6 Jan 2026
scope: classes [employers_liability, public_liability]
territories [GB, IM, CI]
limits: line_size_max 10,000,000 GBP
refer_if: line_size > 5,000,000 -> senior_underwriter
territory not in scope -> principal
oversight: four_eyes_on [decline]
capture [reviewer, time_held, seen, reason]
Mandates are encoded by our team alongside yours, and take days rather than minutes. Reading a binder properly is the work, and we would rather do it well than claim it is automatic.
Every decision that touches the mandate is evaluated against the version in force, and gets one of three answers.
Inside authority. Recorded in full, nothing interrupted, nothing the business notices.
Outside authority, but the mandate names who may approve the exception. It routes to that person, and their reasoning, the time they held it and what they actually looked at are captured as fields.
No route and no approver, or a prohibition was hit. The attempt is recorded with its context, which is evidence that the control fired.
Refer is the one that matters. It is how authority is legitimately exceeded, it is what your audit tests, and it is the part that is almost never written down.
Every decision leaves a signed record. If you are the principal, your delegated relationships appear in one comparable view: referral rates, oversight coverage, how long reviewers actually spent, which mandate version each delegate is working to, and anything decided outside authority with how it was resolved. You issue and version mandates from the same place, so an amendment reaches enforcement rather than an inbox.
| Delegate | Decisions | Referred | Oversight | Median held | Mandate | Status |
|---|---|---|---|---|---|---|
| Northgate Underwriting | 14,208 | 6.2% | 100% | 3m 41s | v4 current | In authority |
| Harbour Speciality | 9,730 | 4.8% | 98% | 2m 55s | v4 current | In authority |
| Calder Risk Partners | 6,411 | 0.4% | 31% | 0m 09s | v4 current | Review dwell |
| Trent Marine MGA | 3,096 | 7.1% | 96% | 4m 02s | v3, 41d behind | Mandate stale |
The two flagged rows are the reason anyone looks at this. Calder refers almost nothing and signs it off in nine seconds, which is not a clean book, it is a control being waved through. Trent is still working to a mandate you replaced six weeks ago. Neither shows up in an annual sampled audit. Both show up here in the first week.
The loop closes at D: the principal issues and versions the mandate there, and it takes effect at B. An amendment reaches enforcement instead of an inbox.
Exams and disputes turn up years later, long after the system has been switched off and the people have moved on. A log line does not survive that. This is what one record holds. Every field on it is there because somebody eventually asks for it.
An example record. The fields are fixed. The values are whatever your decision turned out to be.
We do not claim to reproduce a model's output years later. Nobody can do that honestly. We claim the verdict, the authority in force at the time and the chain of accountability reproduce exactly. The output is recorded, not re-derived.
Those are real needs with capable suppliers already in place. We would rather work alongside them than pretend.
If a person exceeded their authority last year and the file does not show who approved it or on what basis, that is the same gap, and it is usually already a finding. The mandate does not care whether the decider is a person or a service. Firms that put the control in place for their people find that it is already there when something automated arrives.
No software, no integration, no procurement cycle to open.
We encode one mandate: a binder, an appointment agreement or a claims authority schedule. We run it against ninety days of your own decisions, taken from bordereaux or a system export. You get a short report with three numbers.
One mandate family live, one link to the other side of the delegation, and an audit-format export on day 90. The fee is credited in full against a first-year subscription.
Never priced per seat, and the audit export is never a separate line item. It is the thing you came for.
Remit is built by NodeNova, an engineering practice that delivers production systems for insurers, retailers and the UK public sector, self-hosted or air-gapped where the data requires it. Trading as NOVA AI SW LIMITED, company number 16962401. ISO 27001:2022 aligned, Cyber Essentials ready.
Thirty minutes to walk through one of your binders or appointment agreements as an executable mandate, and to scope an Authority Gap assessment against your own decisions.