News

05.08.26

What you can do with a P&C licence in Central Europe

Modern enterprise office with data flow diagrams

A corporate property and casualty (P&C) insurance licence, granted under Directive 2009/138/EC (Solvency II), authorises an insurance undertaking to underwrite, administer and distribute non-life business in its home Member State and, through passporting, across the entire EU/EEA, subject to Solvency II prudential requirements and national supervisor oversight.

Permitted core activities under a corporate P&C authorisation:

  • Underwriting non-life risks within authorised classes of business
  • Policy administration: issuance, endorsement, renewal and cancellation
  • Claims handling: assessment, settlement and payment
  • Entering proportional and non-proportional reinsurance treaties
  • Investing premium funds within Solvency II prudential limits
  • Distributing through tied agents, brokers and digital channels
  • Providing value-added services (risk analysis, actuarial consulting) that arise directly from insurance operations

A P&C licence is not a one-off permission to trade. EIOPA regards it as an ongoing prudential commitment: capital adequacy, governance and reporting obligations must be met continuously, or the licence is at risk. Immediate next steps: confirm your scheme of operations with your home supervisor (Czech National Bank, Hungarian National Bank, Polish KNF or equivalent), verify passporting notifications for each target territory, and schedule your ORSA cycle.


Table of Contents

What activities does a P&C licence actually permit?

Directive 2009/138/EC draws a clear boundary: an authorised insurer must limit its objects to insurance and operations arising directly from it. Within that boundary, the scope is broad.

Permitted day-to-day operations include:

What falls outside the licence: unrelated commercial activities, banking, asset management for third parties, or any business not connected to the insurance relationship. Supervisors in Central Europe, including the Austrian FMA and Slovak NBS, apply this restriction strictly at authorisation and during on-site reviews.


Which product lines fall under a P&C authorisation?

The Solvency II framework organises non-life insurance into defined classes of business. Your authorisation specifies which classes you hold, and that list determines which products you can write.

Close-up of insurance tech dashboard interface

Product line Typical class(es) Key regulatory consideration (see insurance in property management)
Property (fire, nat-cat) Classes 8–9 Catastrophe risk capital loading; nat-cat model validation
Motor (MTPL and own damage) Classes 3, 10 Mandatory MTPL in all EU/EEA states; data-intensive pricing
Third-party liability Classes 10–13 Long-tail reserving; higher technical provisions
Marine and aviation Classes 4–7 Specialist underwriting; international treaty exposure
Credit and surety Counter-cyclical risk; concentration limits
Financial lines (D&O, PI) Classes 13 Claims-made triggers; extended reporting periods
Specialty (cyber, parametric) Classes 8, 13, 16 May require class variation or new authorisation

“Class of business” is not merely a label. Solvency II ties capital requirements, technical provision methodologies and reporting templates to each class. A product that crosses into a class you do not hold requires a formal authorisation extension before you can write it. Parametric covers, for instance, often sit across classes 8 and 16 and warrant early supervisor dialogue before launch. For a closer look at parametric product design and its regulatory implications, the considerations are more nuanced than most product teams anticipate.


How does EU/EEA passporting work across Member States?

A single Solvency II authorisation is valid across the entire EU/EEA. Two distinct rights flow from it.

Right of establishment means opening a branch in another Member State. Freedom to provide services (FPS) means writing risks in another Member State without a physical presence. Both require formal notification, not a new licence.

Notification checklist for entering a new Member State:

  1. Board decision and updated scheme of operations confirming the target territory and classes
  2. Notification to your home supervisor (Czech National Bank, Hungarian National Bank, Polish KNF or equivalent) with the required documentation
  3. Home supervisor forwards the notification to the host supervisor within one month (branch) or one month (FPS)
  4. Host supervisor may impose local requirements within two months for branches
  5. Confirm local claims-handling contact or representative where the host state requires one
  6. Register with the host state’s insurance intermediary registry if distributing through local brokers
  7. Verify language requirements for policy documents and claims communications

Practical limits to anticipate: host supervisors in Central Europe commonly require locally accessible claims contacts for motor lines, language-compliant policy wording, and evidence that your distribution partners hold valid IDD registrations. None of these require a new licence, but failing to address them before writing the first policy creates conduct risk.


How Solvency II converts your licence into an ongoing regime

Meeting Solvency II’s three pillars is what keeps the licence operational. Think of authorisation as the starting gate; the pillars are the track.

Infographic showing Solvency II compliance pillars and steps

Pillar I covers quantitative requirements: the Solvency Capital Requirement (SCR), Minimum Capital Requirement (MCR), eligible own funds and technical provisions calculated on a market-consistent basis. Commission Delegated Regulation (EU) 2015/35, as amended by Regulation 2026/269, sets the detailed valuation and own-funds rules. Insurers using the standard formula must apply prescribed stress factors per class; those seeking internal model approval face a separate supervisory assessment process.

Pillar II is where governance lives. It requires a documented risk management system, four key functions (risk management, compliance, internal audit, actuarial), a board-approved risk appetite statement, and the Own Risk and Solvency Assessment (ORSA). ORSA is a continuous governance process, not a document produced once a year. Supervisors expect it to feed directly into capital planning and product approval decisions.

Pillar III governs reporting and disclosure. Quarterly and annual supervisory reports (QRTs), the Regular Supervisory Report (RSR) and the Solvency and Financial Condition Report (SFCR) are all mandatory. EIOPA issues guidance on consistent supervisory practices, which national supervisors adopt on a comply-or-explain basis.

Pro Tip: Link your ORSA cycle to your product launch calendar. Any material new product or class extension should trigger an ORSA update before the product goes live, not after the supervisor asks for one.


Governance, outsourcing and IT resilience obligations

Holding a licence means maintaining a documented governance architecture at all times. Supervisors in Central Europe expect to see:

  • A current scheme of operations covering all authorised classes and territories
  • A board-approved risk appetite statement reviewed at least annually
  • An internal control framework with documented three-lines-of-defence structure
  • Fit-and-proper assessments for all key function holders and board members
  • A documented outsourcing register distinguishing critical from non-critical services

Outsourcing does not transfer regulatory responsibility. Contracts for critical outsourced functions must include audit rights, data access provisions and performance standards. Supervisors expect an outsourcing oversight matrix and evidence of regular service reviews. Modern insurance platforms that support audit trails and API-based integration make this oversight considerably easier to evidence.

On IT resilience: your home supervisor will expect a business continuity plan with defined recovery time objectives, an incident response procedure, and evidence of regular testing. DORA (the Digital Operational Resilience Act) adds a further layer of ICT risk management requirements for financial entities, including insurers, from January 2025.

Pro Tip: Map your outsourcing register to your scheme of operations. If a critical service provider fails and you cannot administer policies or settle claims, that is a licence-condition issue, not just an operational one.


How do you add classes of business or launch new products?

Adding a class or making a material product change requires a formal application to your home supervisor. The process typically runs as follows:

  1. Internal product approval: business case, actuarial sign-off, capital impact assessment
  2. Update the scheme of operations to reflect the new class, product scope and distribution arrangements
  3. Prepare a revised business plan showing projected premium, loss ratios and solvency impact
  4. Submit the formal application to the home supervisor with the updated scheme, business plan, reinsurance arrangements and governance changes
  5. Supervisor review period: timelines vary by jurisdiction but typically run 30–90 days
  6. Receive amended authorisation; update passporting notifications for affected territories

A new product counts as a new class when it covers risks not included in your current authorisation, even if it resembles an existing product in commercial terms. Cyber insurance, for example, often requires explicit class 13 or class 16 authorisation depending on the risk profile. Supervisors may impose additional capital requirements or governance conditions when the new class carries long-tail exposure or concentration risk. Accelerating go-to-market without completing this process first is one of the more common and costly compliance errors Central European insurers make.


Distribution, reinsurance and capital management choices

Distribution channel selection has direct supervisory implications. Tied agents require registration and training oversight under IDD; independent brokers need their own IDD authorisation; digital platforms used for distribution are subject to outsourcing oversight rules. Supervisors assess market conduct across all channels, so your oversight framework must extend to every point of sale.

Reinsurance is a capital management tool as much as a risk transfer mechanism. Proportional treaties reduce net premium and loss exposure proportionally, which lowers the SCR for underwriting risk. Non-proportional (excess-of-loss) treaties cap severity exposure and are particularly relevant for property cat and liability lines. The quality of reinsurance documentation, including credit risk assessment of reinsurers, forms part of Pillar II governance. Sound capital management ties reinsurance strategy directly to reserve adequacy and own-funds planning.


How national supervisors interact with licence holders

Supervisory engagement is not limited to annual reporting. Expect:

  • Routine quarterly and annual QRT submissions reviewed against peer benchmarks
  • Thematic reviews on specific topics (e.g., claims handling, cyber risk, ORSA quality)
  • On-site inspections covering governance, controls and data quality
  • College of supervisors coordination for cross-border groups operating in multiple Member States

Enforcement escalates in stages. Early intervention typically involves a supervisory letter requesting remediation. If capital falls below the SCR, the insurer must submit a recovery plan within two months. A breach of the MCR triggers more immediate action, potentially including restrictions on new business. Persistent governance failures can result in capital add-ons, requirements to replace key function holders, or, in the most serious cases, licence withdrawal. EIOPA’s guidance on supervisory convergence means that the bar is broadly consistent across Central European jurisdictions, even if procedural timelines differ.


90-day operational checklist for P&C licence holders

Immediate (days 1–30):

  1. Confirm authorised classes and territories with your home supervisor
  2. Verify passporting notifications are current for all active markets
  3. Review scheme of operations for accuracy against live products and distribution arrangements
  4. Confirm ORSA schedule and assign ownership

Days 31–60:

  1. Audit outsourcing register; confirm critical service contracts include required provisions
  2. Validate claims-handling contacts and local representatives in each passported territory
  3. Confirm AML/CTF controls are documented and staff training is current
  4. Check QRT submission calendar against home supervisor deadlines

Days 61–90:

  1. Complete a capital adequacy review against current SCR and MCR
  2. Confirm IT resilience testing schedule and DORA compliance gap assessment
  3. Brief the board on supervisory interaction calendar and any open remediation items
  4. Validate that policy administration and claims systems produce data in the formats required for Pillar III reporting

Systems priorities: policy administration, claims workflow, actuarial reserving, finance sub-ledger and compliance monitoring must all be operational and integrated before you write the first policy in a new territory.


How IBSuite supports P&C operations and Solvency II compliance

Ibapplications builds IBSuite, a cloud-native, API-first core insurance platform covering the full P&C value chain. The table below maps key platform capabilities to specific regulatory and operational requirements.

IBSuite capability Regulatory / operational need
Configurable product engine Supports scheme of operations changes and new class launches without custom code
Policy administration module Manages full lifecycle across multiple territories and classes
Claims workflow and settlement Supports cross-border claims handling and local contact requirements
Automated QRT and regulatory reporting Pillar III: reduces manual effort and reporting error risk
Financial sub-ledger and reserving Pillar I: supports technical provisions calculation and own-funds tracking
API-first integration layer Outsourcing oversight: enables audit trails and third-party service monitoring
Evergreen cloud updates Keeps the platform current with regulatory technical standard changes

When evaluating any core platform for regulatory compliance, check for: native support for Solvency II reporting templates, configurable product architecture that does not require code changes for class extensions, documented data lineage for audit purposes, and a clear contractual position on data residency (relevant for GDPR and national data-protection requirements in Central Europe). Compliance-oriented platform design is not a feature list; it is an architecture decision that affects every supervisory interaction you will have.


Key takeaways

A corporate P&C licence in Central Europe authorises underwriting, administration, claims, reinsurance and cross-border distribution across the EU/EEA, but only within authorised classes and subject to continuous Solvency II compliance.

Point Details
Passporting is notification, not a new licence Notify your home supervisor for each new territory; host supervisors may add local conduct requirements.
Classes of business define your product boundary Any product crossing into an unauthorised class requires a formal application and revised scheme of operations.
ORSA is a continuous process Link ORSA updates to product launches and capital planning, not just the annual cycle.
Enforcement escalates in stages SCR breach triggers a two-month recovery plan; MCR breach can restrict new business immediately.
Ibapplications IBSuite Maps platform capabilities to Pillar I–III obligations, supporting reporting, product configuration and claims across territories.

The compliance gap nobody talks about at board level

The standard board conversation about a P&C licence focuses on what you can sell. The more consequential question is whether your operational infrastructure can actually support what the licence permits.

Passporting notifications are filed, but claims-handling contacts in the host territory are not confirmed. The ORSA is produced annually, but nobody links it to the product approval process, so a new cyber product launches before the capital impact is assessed. Outsourcing contracts are signed, but the oversight matrix is never updated when a subcontractor changes.

These are not exotic failures. They are the ones supervisors find most often during thematic reviews, and they are the ones that generate the most uncomfortable board conversations. The licence gives you the permission. The governance architecture is what makes the permission usable.


IBSuite for P&C compliance and operations

For P&C insurers in Central Europe managing Solvency II obligations across multiple territories, the operational burden is real: QRT submissions, ORSA documentation, cross-border claims contacts, outsourcing oversight. Ibapplications built IBSuite specifically for this environment, with policy administration, automated regulatory reporting and a configurable product engine that supports class extensions without rebuilding your core system.

If you are assessing whether your current platform can keep pace with supervisory expectations, a capability briefing with the Ibapplications team is a practical starting point. Request one at ibapplications.com.

Ibapplications is a technology vendor, not a regulator. All authorisation, passporting and compliance decisions must be confirmed with your home supervisor and qualified legal counsel.


Useful sources

Primary documents your legal and compliance teams should hold:

  • Directive 2009/138/EC (Solvency II): the foundational authorisation and prudential framework for all EU/EEA insurers
  • EIOPA Solvency II rulebook and guidance: EIOPA’s consolidated guidance, recommendations and Q&As; national supervisors apply these on a comply-or-explain basis
  • Commission Delegated and Implementing Acts (Solvency II): includes Delegated Regulation 2015/35 (as amended by 2026/269) and Implementing Regulation 2025/216 on technical provisions and own-funds calculation
  • EUR-Lex Solvency II summary: plain-language summary of the Directive’s scope and requirements
  • Your home supervisor: the Czech National Bank, Hungarian National Bank, Polish KNF, Austrian FMA, Slovak NBS or equivalent is the authority of record for your authorisation, passporting notifications and any class extensions

FAQ

What does a corporate P&C licence permit an insurer to do?

It authorises the undertaking to underwrite, administer and distribute non-life insurance within authorised classes of business, handle claims, enter reinsurance treaties and invest premium funds, subject to Solvency II and national supervisor requirements.

Can a P&C insurer write business in other EU/EEA states without a new licence?

Yes. A single Solvency II authorisation covers the entire EU/EEA through passporting. The insurer notifies its home supervisor, which forwards the notification to the host supervisor; no separate licence is required.

What happens if an insurer wants to add a new product line?

If the new product falls within an already-authorised class, no formal application is needed. If it crosses into a new class, the insurer must submit a formal application with a revised scheme of operations, business plan and solvency impact assessment.

What are the consequences of breaching the SCR?

The insurer must submit a recovery plan to its home supervisor within two months. Persistent non-compliance can lead to capital add-ons, restrictions on new business or, in serious cases, licence withdrawal.

How does IBSuite help with Solvency II compliance?

IBSuite’s automated reporting module supports Pillar III QRT submissions, while its configurable product engine and financial sub-ledger assist with Pillar I and II obligations, reducing manual effort and audit risk across multiple territories.