The hidden complexity behind UK’s latest solvency reporting amendments

The latest Solvency UK reporting changes show that regulatory reform does not end when the rules are finalised. The real test is whether insurers can translate continuous technical change into accurate data, controlled implementation and clear evidence of compliance, says Rohini Gupta, CEO of FinregE.

The latest policy statement (PS 18/26) from the Prudential Regulation Authority (PRA) is not another wholesale redesign of Solvency UK. It is something more revealing: a post-implementation test of whether insurers can translate technical regulatory change into reliable data, controlled processes and defensible reporting.

PS18/26 shows what comes next in any major regulatory reform: implementation friction becomes visible, ambiguities emerge in templates and instructions, data definitions do not always align, and apparently small corrections create real work across actuarial, finance, regulatory reporting, technology and compliance teams.

The PRA has now finalised a package of post-implementation reporting and disclosure amendments, together with a targeted Own Funds permissions change. The policy applies broadly to UK Solvency II firms, Lloyd’s (the specialist insurance and reinsurance market) and its members and managing agents, insurance and reinsurance groups, UK holding companies and, for relevant provisions, third-country branches.

The strategic message is clear: regulatory simplification does not eliminate change management. It raises the standard for how quickly firms can identify, interpret, implement and evidence change.

What changed: The template-level breakdown

The final policy is detailed, but its most important elements can be grouped into six implementation themes.

Reporting templates and instructions are being corrected and clarified

The PRA is amending a substantial set of reporting and disclosure templates and instructions to resolve errors, inconsistencies and interpretative questions identified after the 2024 reforms. Although many of the individual adjustments are described as minor, the PRA acknowledges that their cumulative effect can require meaningful analysis, system development and testing.

For non-life reporting, changes affect areas including income and expenditure, lines of business, accepted reinsurance, non-life annuities and related validations. The PRA has also changed some draft proposals after industry feedback—for example, it will add total income and expenditure to an existing template rather than create a separate new variant.

MALIR is moving from Excel to XBRL

The Matching Adjustment Asset and Liability Information Return (MALIR) will move into the Bank of England insurance taxonomy and be submitted in XBRL. As part of this transition, the PRA is also removing duplicate reporting, simplifying some requirements and reducing the frequency of certain cashflow reporting.

This is not just a change in file format. XBRL embeds the regulatory definitions, validations and data relationships within the reporting process. Thus firms need to test not only that data can be produced, but that its lineage, sign conventions, classifications and reconciliations are correct under the new taxonomy.

NACE 2.1 presents a cross-border data challenge

The change to NACE 2.1 classifications affects the reporting of assets and collateral, including the relevant MALIR templates. Firms may choose to adopt NACE 2.1 from 31 December 2026 reporting reference date, ahead of mandatory implementation from 1 January 2027.

For insurers operating across the UK and EU, temporary divergence in implementation timing can create dual-data requirements. This is not merely a taxonomy issue: it can affect data sourcing, vendor feeds, mapping rules, system configuration, controls and reconciliation.

Third-country branches will report projected FSCS liabilities

Third-country branches will be required to report projected Financial Services Compensation Scheme liabilities. Following feedback on proportionality, the PRA reduced the requirement from three plan years to one, cutting the proposed data points from eighteen to six.

The regulatory purpose remains significant. The PRA wants earlier visibility of changes in FSCS-protected liabilities and their implications for outwards reinsurance arrangements and policyholder protection. Branches should therefore treat the requirement as part of forward-looking prudential supervision, not as an isolated reporting field.

A permission requirement for certain Own Funds instruments is being removed

The PRA will remove the requirement for firms to obtain a specific permission to classify equity-accounted subordinated liabilities into Own Funds tiers where those instruments fall within the recognised lists. The standard pre-issuance notification process will continue to apply, while genuinely novel or non-standard items remain subject to the permission regime.

The change reduces avoidable administrative burden, but it also requires firms to update internal capital classification procedures, reporting logic, controls and documentation so that the revised treatment is applied consistently.

The implementation date is fixed and close

The amendments will apply to reporting reference dates on or after 31 December 2026. The PRA will publish the revised reporting taxonomy shortly after the policy statement. Firms have the second half of 2026 to compress in interpretation, impact assessment, build, testing, governance approval and deployment.

The real issue is not the number of changed cells

Much commentary on regulatory reporting updates naturally focuses on which templates, rows, columns and instructions have changed. That information is essential,but it is not sufficient. The more important question is whether a firm has an operating model capable of absorbing continuous regulatory refinement without losing control of data quality.

PS18/26 sets out five risks that can be under-estimated when changes are seen as technical or small.

  • Interpretation risk: a change in the instructions can affect the sourcing, calculation or classification of data even if the template seems to have changed little.
  • Cumulative change risk: multiple systems, teams and controls are affected by dozens of small changes, creating dependencies that are not visible when each item is considered on its own.
  • Data lineage risk: XBRL and updated validations amplify the need for traceability of every reported figure back to its source, transformation logic and accountable owner.
  • Cross-regime risk: Firms reporting in both the UK and EU may need to apply parallel classification and reporting treatments, increasing the risk of inconsistent data.
  • Evidence risk: Companies may get the right result but find it difficult to prove who assessed the change, what was changed, how it was tested and who approved it.

A strategic implementation agenda for insurers

Insurers should avoid treating PS18/26 as a narrow reporting-project update. A stronger, five pillar response connects regulatory interpretation to data, systems, controls and governance.

Build a single, controlled inventory of change

Every amendment should be captured at a granular level and linked to the relevant rule, supervisory statement, template, instruction, taxonomy component and implementation date. This creates a common source of truth for compliance, actuarial, finance, reporting and technology teams.

Map each change to the operating model

For every requirement, firms should identify impacted data fields, calculation logic, source systems, reporting processes, policies, procedures, controls, owners and third parties. The objective is to move beyond a document comparison and establish the complete chain from regulatory text to reported outcome.

Prioritise by implementation risk—not regulatory wording

A change described as clarificatory may still require code changes, data remapping or extensive regression testing. Impact ratings should therefore reflect operational complexity, number of dependencies, data availability and control maturity.

Test UK and EU treatments together

Cross-border firms should develop an explicit divergence matrix that encompasses NACE classifications, reporting dates, taxonomy versions, data sources and local interpretations. Parallel reporting logic should be deliberately governed, not allowed to emerge through local workarounds.

Build an audit trail ready for evidence

The implementation record should record the source change, interpretation, impact assessment, actions assigned, testing evidence, exceptions, approvals and final closure. It forms the basis for internal assurance, audit and supervisory engagement – and cuts down on dependency on fragmented spreadsheets and email chains.

90-day implementation plan

Based on the PS18/26 implementation timeframe (the reference date is December 31, 2026), a practical workplan may looks something like the below:

Days 1–30: Impact Assessment and Data Inventory

Activity

Output

Owner

Map all PS18/26 template changes to current reporting engine

Gap analysis document

Head of Reporting

Identify NACE 2.1 dual-regime exposure (UK + EU)

Asset classification inventory

Data Governance

Validate MALIR XBRL readiness (data structure, tagging capability)

Technical readiness assessment

IT / Data Architecture

Review own funds template terminology changes

Validation rule update log

Actuarial / Finance

 

Days 31–60: Workflow Integration & Control Testing

Activity

Output

Owner

Update obligation mappings for IR.05.04 and IR.16.01 changes

Revised control framework

Compliance

Test NACE 2.1 optional adoption (if pursuing early transition)

Classification accuracy report

Data Governance

Build XBRL tagging logic for MALIR templates

Tagging validation results

IT / Reporting

Document audit trail for all template changes

Evidence pack

Internal Audit

 

Days 61–90: UAT, Sign-Off & Submission Prep

Activity

Output

Owner

End-to-end UAT on updated templates

UAT sign-off

Head of Reporting

Committee pack preparation (Board / Risk Committee)

Governance approval

CRO / CFO

Final validation checks against PRA taxonomy

Validation pass confirmation

IT / Reporting

Submission dry-run (if possible)

Error log & remediation

Reporting Team

The wider lesson from PS18/26

Solvency UK was designed to create a more tailored and proportionate prudential regime. PS18/26 does not undermine that objective. Instead, it demonstrates that proportionality depends on high-quality implementation. Regulators can remove templates and simplify rules, but firms still need reliable data, consistent interpretation and controlled execution.

The organisations best placed for the next phase of Solvency UK will not be those that simply update their reporting software fastest. They will be those that can connect regulation, data and accountability across the enterprise and show, at any point, how a new requirement has moved from publication to compliant outcome.

For insurers, PS18/26 should therefore be treated as more than a year-end reporting amendment. It is an opportunity to test whether the regulatory change operating model is ready for an environment in which rules, instructions, taxonomies and supervisory expectations continue to evolve together.

Where FinregE fits: turning policy into proof

This is where generic horizon scanning tools reach their limit. They tell you what changed. They don’t operationalise what to do about it.

FinregE’s End-to-End Regulatory Operating System (FinregE ROS) is built for exactly this workflow:

AI RIG – Obligation Extraction at Scale

The Regulatory Insights Generator (RIG) extracts obligations directly from PS18/26 and related policy materials, classifying them by:

  • Template affected (IR.05.04, IR.16.01, IR.23.01, etc.)
  • Function impacted (Reporting, Actuarial, Finance, Risk)
  • Deadline (31 December 2026 reference date)
  • Jurisdiction (UK Solvency UK, with EU NACE alignment flags)

This isn’t summarisation. It’s structured obligation inventory that feeds directly into impact assessments.

Policy-to-Regulation Traceability

Once obligations are extracted, RIG MAPS links them to your internal:

  • Policies (e.g., Regulatory Reporting Policy, Own Funds Policy)
  • Controls (e.g., IR template validation rules, NACE classification controls)
  • Processes (e.g., quarterly reporting workflow, MALIR submission process)

When the PRA asks why you reported a figure, you can show the complete lineage: source text → obligation → policy → control → evidence.

End-to-End Audit Trail

Every action in FinregE is logged:

  • Who reviewed the PS18/26 impact assessment?
  • When was the IR.05.04 mapping updated?
  • Which control owner signed off the NACE 2.1 classification?
  • What evidence supports the MALIR XBRL tagging logic?

This isn’t optional. The Direct Line £10.6m fine was fundamentally about control failures, not technical errors. FinregE makes controls visible, testable, and defensible.

NACE 2.1 Dual-Regime Management

For firms operating across UK and EU jurisdictions, FinregE maintains parallel classification schemas with automated crosswalks. When the PRA taxonomy updates, your asset inventory is re-tagged without manual intervention – reducing the dual-reporting window from quarters to days.

Turn Solvency UK change into controlled implementation.

See how FinregE can help your teams identify, map, implement and evidence the requirements of PS18/26. Book a demo.

Downloads Alert