Remit · decision assurance
Lloyd's · London market · FCA principal firms

Every decision, inside its mandate, on the record.

You delegate authority: to coverholders, to appointed representatives, to third-party administrators, and increasingly to software that decides on its own. You stay accountable for all of it. Remit turns the authority you granted into something that can be checked at the moment a decision is made, and leaves a signed record the party who granted it can verify.

The way in is the Authority Gap assessment. We take one of your mandates, run it against ninety days of your own decisions, and hand back three numbers. One week, fixed scope, nothing installed.

Authority taken from the contract
Permit, refer or refuse
Evidence an auditor can check

Two answers to the same question from an auditor

What most files can say today
“Our policy requires human review before a decline.”
AssertionAnnualCannot be checked
What a decision record says
“The system wanted to decline it. The binder says a named underwriter has to sign that off, so it went to Sarah Okafor. She spent four minutes on it, saw everything the system saw, turned it into a referral instead, and wrote down why. Here is the record, and here is the tool to check we have not touched it.”
ContemporaneousNamedVerifiable without us
01 · The gap

You are accountable for decisions you did not make.

The structure is the same in every delegated relationship. You grant a mandate, somebody else decides inside it, and evidence is produced on a cycle to show that they did. The mandate is usually sound. The evidence is the part that breaks.

01

Which of your delegates let software make a decision that binds you, and in which classes?

Most oversight functions answer this by asking once a year and believing the reply.

02

For a decision that exceeded authority last quarter, who approved the exception, on what basis, and how long did they spend on it?

Referral is what a coverholder audit tests. It is rarely recorded as a field anywhere.

03

If a court or a regulator asked for that file in three years, what would you hand over?

System logs, a spreadsheet, and the recollection of somebody who has since left.

You have sixty coverholders. Three of them have told you they use software somewhere in a decision path. You do not believe that is the real number, and short of asking again there is no way to find out.

None of these are new questions. Coverholder audits and SUP 12 reviews have always asked them, and the answer has always been put together after the fact, by hand, from systems that were never built to give it. What changed is volume and speed. A delegate that decides thousands of times a day cannot be meaningfully sampled, does not remember why, and cannot be interviewed by an auditor.

02 · How it works

Authority, enforced where the decision actually happens.

Three steps. Nothing in them depends on the decision being made by software, which is rather the point.

Step 01

Encode the mandate

Your binding authority, appointment agreement or claims authority schedule becomes a versioned object: scope, limits, conditions, referral triggers, oversight requirements, prohibitions and expiry. Every line traces back to the clause it came from, and the encoding is signed off by a named person and kept as evidence in its own right.

mandate M-2291 · version 4 sha256:7c1e9a04…
# from binding authority B-2291, clause 4.2
# encoding confirmed by J. Whitfield, 6 Jan 2026

scope:       classes [employers_liability, public_liability]
             territories [GB, IM, CI]
limits:      line_size_max 10,000,000 GBP

refer_if:    line_size > 5,000,000  -> senior_underwriter
             territory not in scope  -> principal

oversight:   four_eyes_on [decline]
             capture [reviewer, time_held, seen, reason]

Mandates are encoded by our team alongside yours, and take days rather than minutes. Reading a binder properly is the work, and we would rather do it well than claim it is automatic.

Step 02

Check the decision before it commits

Every decision that touches the mandate is evaluated against the version in force, and gets one of three answers.

Permit

Inside authority. Recorded in full, nothing interrupted, nothing the business notices.

Refer

Outside authority, but the mandate names who may approve the exception. It routes to that person, and their reasoning, the time they held it and what they actually looked at are captured as fields.

Refuse

No route and no approver, or a prohibition was hit. The attempt is recorded with its context, which is evidence that the control fired.

Refer is the one that matters. It is how authority is legitimately exceeded, it is what your audit tests, and it is the part that is almost never written down.

Step 03

Keep the record, and let the other side see it

Every decision leaves a signed record. If you are the principal, your delegated relationships appear in one comparable view: referral rates, oversight coverage, how long reviewers actually spent, which mandate version each delegate is working to, and anything decided outside authority with how it was resolved. You issue and version mandates from the same place, so an amendment reaches enforcement rather than an inbox.

Portfolio oversight trailing 31 days 2 outside threshold
Portfolio oversight across delegated relationships, example data
Delegate Decisions Referred Oversight Median held Mandate Status
Northgate Underwriting 14,208 6.2% 100% 3m 41s v4 current In authority
Harbour Speciality 9,730 4.8% 98% 2m 55s v4 current In authority
Calder Risk Partners 6,411 0.4% 31% 0m 09s v4 current Review dwell
Trent Marine MGA 3,096 7.1% 96% 4m 02s v3, 41d behind Mandate stale
Every cell drills to the individual signed records behind it Example data

The two flagged rows are the reason anyone looks at this. Calder refers almost nothing and signs it off in nine seconds, which is not a clean book, it is a control being waved through. Trent is still working to a mandate you replaced six weeks ago. Neither shows up in an annual sampled audit. Both show up here in the first week.

03 · The evidence

What you would actually hand over.

Exams and disputes turn up years later, long after the system has been switched off and the people have moved on. A log line does not survive that. This is what one record holds. Every field on it is there because somebody eventually asks for it.

Decision record dr_01JQ8F3K2NX7RA5T Refer
Decision
bind · employers' liability · GBP 10,000,000 limit
haulage · Republic of Ireland
14 Mar 2026, 09:42 UTC
Decider
automated triage service uw-triage 3.2
model pinned sha256:9f2c41d8… · instructions sha256:41ab07e2…
deployment DEP-118 approved 9 Jan 2026, J. Whitfield
Mandate
M-2291 v4 · sha256:7c1e9a04…
determinative clause refer_if.territory_not_in_scope (binder B-2291, clause 4.2)
Verdict
REFER · to the principal
Inputs
4 references, content addressed
submission sha256:be07… · loss run sha256:11c9… · sanctions sha256:8a4f… · rating sha256:d302…
the payload stays in your tenant, only the hash is in the record
Oversight
Sarah Okafor · SMF-mapped underwriter
held 4m 12s · viewed 4 of 4 inputs
outcome changed bind → refer to underwriter
reason recorded: “IE outside binder territory. Not writing on this paper.”
Chain
previous sha256:2d90b6c1…
externally anchored 14 Mar 2026, 10:00 UTC
ed25519 signature · retention 7 years ✓ verifies offline

An example record. The fields are fixed. The values are whatever your decision turned out to be.

Tamper-evident
Hash chained and signed as it is written, with periodic external anchoring. An evidence product with an editable log is worth nothing in a dispute.
Verifiable without us
The format is published and the checker runs offline, so your auditor confirms integrity without taking our word for it or touching our servers.
Replayable
The mandate version, the inputs by hash and the evaluation path are all recorded, so the verdict reproduces exactly, years later.
Exportable
Open schema, full export on demand. Your evidence has to outlive your choice of supplier, including us.
Retention aware
Configurable retention, legal hold and jurisdiction pinning. Insurance limitation periods run well past six years.
And what we do not claim

We do not claim to reproduce a model's output years later. Nobody can do that honestly. We claim the verdict, the authority in force at the time and the chain of accountability reproduce exactly. The output is recorded, not re-derived.

04 · Scope

What Remit does, and what it leaves alone.

Remit does
  • Hold the authority you granted, as a versioned object traced to the contract.
  • Check decisions against it on every path a decision can take.
  • Record what was decided, by whom, under which clause, with what oversight.
  • Give both sides of the delegation the same view of it, continuously.
Remit does not
  • Test models for bias, accuracy or drift.
  • Defend against prompt injection or data exfiltration.
  • Write your policies or complete your questionnaires.
  • Ingest, clean or reconcile your bordereaux.

Those are real needs with capable suppliers already in place. We would rather work alongside them than pretend.

It is not really a question about AI

If a person exceeded their authority last year and the file does not show who approved it or on what basis, that is the same gap, and it is usually already a finding. The mandate does not care whether the decider is a person or a service. Firms that put the control in place for their people find that it is already there when something automated arrives.

Worth a conversation if
  • You oversee twenty or more delegated relationships and answer for all of them.
  • You are a coverholder facing the AI section of the next audit.
  • You are an FCA principal firm running annual reviews across appointed representatives.
  • You are accountable for decisions a third party's system makes on your paper.
Not yet, if
  • You have three binders, no automated decision path, and a consultant who knows your book well. You are fine. We will say so rather than sell you something.
05 · How to start

Start with three numbers about your own book.

No software, no integration, no procurement cycle to open.

Free · one week · fixed scope

The Authority Gap assessment

We encode one mandate: a binder, an appointment agreement or a claims authority schedule. We run it against ninety days of your own decisions, taken from bordereaux or a system export. You get a short report with three numbers.

  • Decisions that fell outside authority. How many, which clause, what value.
  • Decisions with no evidence of the human review the mandate required.
  • Decisions that cannot be attributed to any identifiable decider at all.
Useful whether or not you go further. If it finds nothing, that is the answer, and we will tell you.
£12k · 90 days · credited in full

Then a pilot

One mandate family live, one link to the other side of the delegation, and an audit-format export on day 90. The fee is credited in full against a first-year subscription.

  • Success criteria written down on day one, with an explicit exit.
  • If you cannot bring the other side to the link, we stand in as their proxy for the pilot.
  • Fixed price, fixed scope, the same model NodeNova uses for its engineering work.
If the pilot does not hit what we wrote down on day one, you walk away and you keep the records.
After the pilot
  • £18k a year for a delegate: one mandate family, up to three decision types, hosted, standard export.
  • £30k to £45k for a delegate running several binders, with every decision path covered and reconciliation on.
  • £75k base for a principal, plus a per-relationship fee for each delegate you oversee, capped.
  • £2k to £6k per mandate we encode with you. The first one is free inside a pilot.

Never priced per seat, and the audit export is never a separate line item. It is the thing you came for.

Remit is built by NodeNova, an engineering practice that delivers production systems for insurers, retailers and the UK public sector, self-hosted or air-gapped where the data requires it. Trading as NOVA AI SW LIMITED, company number 16962401. ISO 27001:2022 aligned, Cyber Essentials ready.

06 · Questions

What people ask us first.

01

What stops someone just going round it?

Nothing, if you only check the paths you know about. So we also work backwards: we take what actually committed, from bordereaux, the ledger and the policy records, and match it against the decision records. Anything that happened without one gets flagged. Without that step the whole thing can be bypassed and nobody would know, which would make the assurance worth very little.
02

Where does the decision data live?

Hosted in the UK or EU by default, region pinned. In your own cloud account where procurement asks for it. Self-hosted / on-prem for the largest accounts and the public sector. The record is exportable and verifiable in all three, otherwise the choice would be decoration.
03

Does this replace our policy administration or claims system?

No. The decision still commits where it commits today. Remit reads the decision, returns a verdict before it commits, and keeps the record. The paths we care most about are the ones outside your systems entirely: a spreadsheet, an email approval, a third party's platform.
04

We are not using AI in decisions yet.

Then start with the human referral controls, which are very likely undocumented and may already be a finding. The mandate works the same either way, and the control is in place before anything automated arrives, rather than being retrofitted under time pressure.
05

What happens if we stop using Remit, or you stop trading?

Open, documented schema. Full export on demand. An offline checker that validates your records without touching our servers. You keep your evidence and can prove it indefinitely. Evidence that only works while you keep paying for it is not really evidence.
06

This costs more than a consultant.

A consultant writes you a document once. Put the cost next to one audit finding you have to remediate, one binder placed on notice, or the hours your own team already spends pulling oversight evidence together by hand. If the assessment says the gap is small, that is a real answer and you should spend the money elsewhere.
07

What do you need from us for the assessment?

One mandate document, and a decision export or bordereaux covering ninety days. No system access, nothing installed. One call to scope it, one call to walk through what we found. Under NDA if you prefer.
07 · Engage

Find out what last quarter would have produced.

Thirty minutes to walk through one of your binders or appointment agreements as an executable mandate, and to scope an Authority Gap assessment against your own decisions.