Claims handling has become a central supervisory priority on both sides of the Channel. Sedgwick's 2026 Claims Administration Intelligence Report maps a wave of UK and EU rules converging on how insurers, self-insured corporates and their third-party administrators manage outsourcing, AI and operational resilience - and frames the shift as already visible in regulators' own published enforcement records rather than as a future risk.
Sedgwick is itself a major TPA operating in this market, which gives it a commercial interest in the narrative that TPA governance matters. That context is worth holding alongside the report's findings. It does not undermine the substance, however - the regulatory data the piece draws on is independently sourced and confirms the same picture.
The FCA's July 2025 review of home and travel claims handling examined 15 home and eight travel insurers. It found poor oversight of outsourced claims handlers was the most common failing across the sample - and notably, only 32% of storm damage claims in the FCA's 2024 sample resulted in payment. That review fed directly into a wider enforcement push: the FCA confirmed in December 2025 it would extend scrutiny of home and travel insurers' claims handling and outsourced oversight, and more than ten insurers were subsequently asked to review their processes in Q1 2026, following a Which? super-complaint on the same market.
On the German banking side, BaFin imposed two of its largest-ever governance-related fines in 2025: a €23 million penalty against Deutsche Bank in February and a €45 million record fine against JPMorgan SE in November, both tied to systemic process failures rather than isolated incidents. In both cases BaFin proceeded despite active remediation efforts, judging that accountability for past failings could not be offset by planned improvements.
EIOPA's published sanctions data shows that in 2024, national supervisors imposed IDD sanctions across 24 EEA member states, with product oversight and governance breaches driving the highest total fine values. DLA Piper's January 2026 GDPR Fines and Data Breach Survey independently confirmed approximately €1.2 billion in European data protection fines in 2025, alongside 443 personal data breach notifications per day - a 22% year-on-year increase and the first time that figure has exceeded 400 since GDPR took effect.
The report makes a specific argument about self-insured corporates that is worth pulling out. Neither the FCA's nor EIOPA's rulebooks bite directly on a self-insured business - but the TPAs, captives, claims platforms and AI vendors those corporates rely on are squarely in scope. The regulatory obligations land on the corporate by contract and by association, across four pressure points the report identifies.
DORA's Article 30 terms and Critical ICT Third-Party Provider rules in Europe, mirrored in the UK by operational resilience requirements and the Cyber Security and Resilience Bill. AI Act deployer obligations, including Fundamental Rights Impact Assessments and human oversight requirements, which attach to whoever actually runs the model in a claims decision - often the corporation's own risk team rather than the TPA. Consumer Duty's fair-value and complaints scrutiny, which extends to employee benefits, group risk and customer-facing self-insured books the moment a TPA touches them. And operational-incident reporting frameworks that expect the principal, not the outsourcer, to own the dependency map and the incident clock.
Darren Betts, head of risk and regulation at Sedgwick International, said regulation is now a decisive factor in the TPA market, and that competitors without internal risk, compliance, regulatory and legal capability will struggle to keep pace. He said the strategic shift is clear: outsourced claims administration is moving from a cost-and-capacity model to a governance-and-control model, with regulators in both the UK and EU expecting principals to evidence oversight of outcomes, technology, model use and resilience, even where delivery sits with TPAs, captives, cloud providers or AI vendors.
Betts said outsourcing no longer shifts regulatory pressure away from the corporate - it spreads it across procurement, risk, internal audit, compliance and claims leadership. Organisations with one dependency map, one evidence base and one decision framework across claims, ICT, AI and cross-border conduct will be better placed to absorb regulatory change without slowing service or increasing remediation cost.
Tobias Walter, chief executive of Sedgwick Germany, said the strongest models over the next 12 to 24 months will treat claims oversight as a strategic capability rather than a delegated back-office function.
For risk managers and captive owners, the practical implication is that internal audit, procurement and risk functions are inheriting compliance work that used to sit implicitly with insurer partners - whether or not those teams have been resourced for it. The FCA, BaFin and EIOPA have already documented the failures that arise when that handover does not happen. Sedgwick's report is describing enforcement already underway, not predicting what might come.