AML, Sanctions, and AI in Insurance: Dynamic Risk Assessments and Sanctions in a Fragmented World
- FinScan

- Aug 5
- 4 min read
Updated: Aug 10
How insurers across lines of business and around the world are modernizing financial-crime compliance across risk assessment, sanctions screening, and artificial intelligence.
This is part 2 of a 3-part series. Read part 1
II. Dynamic Risk Assessments: Moving Beyond Periodic Reviews
What's broken
Many insurance compliance programs still rely on a risk assessment refreshed once a year. An annual cycle assumes the risk picture holds steady between reviews, and it rarely does. New products, distribution partners, geographies, and sanctions designations can change an insurer’s exposure within weeks, so a document finalized in the first quarter can be out of date by the third. When a group operates across several jurisdictions the problem compounds, because local teams often assess risk on different schedules and with different methods, leaving the organization without a consistent view.
What's working
Insurers that have strengthened this area share a few common moves. They treat risk assessment as a continuous process, refreshing key inputs as conditions change rather than waiting for the annual cycle. They bring sanctions risk and money-laundering risk into a single view rather than running them as separate exercises, since the same customer, intermediary, or payment can carry both. And they connect their key risk indicators and key performance indicators to that assessment, so that movements in alert volumes, clearance times, and screening hit rates feed back into how risk is scored.
![]() | Recommendations |
1 | Continuous risk assessment replaces the fixed annual cycle. The assessment becomes a living model, updated as products, partners, geographies, and designations change, with the annual review serving as a formal checkpoint rather than the only point of refresh. |
2 | Data quality and governance come first. A risk assessment is only as reliable as the data beneath it. Clear ownership of customer, policy, and payment data, with defined standards for completeness and accuracy, is the foundation on which screening and monitoring depend. |
3 | Feedback loops connect audits and risk owners. Findings from independent testing and internal audit return to the people who own each risk, so that control weaknesses identified in one cycle are reflected in the next assessment rather than tracked separately. |
III. Sanctions in a Fragmented World
What's new
The sanctions response to recent geopolitical events has produced one of the most active periods of designation and rule-making in decades. The United States, the European Union, and the United Kingdom remain broadly aligned in objective, yet the detail of their programs increasingly diverges. The European Union adopted its twentieth package of measures concerning Russia in April 2026, extending listings and adding new categories of restriction. The three regimes have at times set different parameters for comparable measures, including different treatment of energy-related thresholds, which means a single transaction can be assessed differently depending on which regime applies. Supervisors have signaled that screening quality is under scrutiny. In May 2026 the United Kingdom’s Financial Conduct Authority published findings on how firms manage sanctions compliance, identifying weaknesses that included incomplete screening and slow handling of alerts.
WHERE IT BITES | |
![]() | Claims & payouts, not just onboarding |
![]() | Ownership & control: look through structures |
![]() | Secondary sanctions & USD clearing |
![]() | Third-party & reinsurance settlements |
Operational risk
For insurers, sanctions risk runs through the full contract lifecycle. A party can be clear at underwriting and later become the subject of a designation, so exposure surfaces at the point of a claim or a payout rather than at issuance. Third-party payments, premium financing, and reinsurance settlements add further points where a restricted party can enter the chain. Two features of sanctions practice make this harder than a simple name check. The first is ownership and control. A party that is not itself listed can still be restricted if it is owned or controlled by a listed person, which requires insurers to look through corporate structures rather than screen only the named counterparty. The second is secondary-sanctions and dollar-clearing exposure. Because many cross-border payments clear through US financial institutions, an insurer with no US presence can still face consequences for dealings that touch US-restricted parties.
![]() | Recommendations |
Because this exposure runs the full contract lifecycle and turns on ownership, dollar-clearing, and third-party links that a simple name check misses, insurers are converging on a few practical moves. | |
1 | Centralized sanctions intelligence and workflows give the group a single source for designations, guidance, and decisions, so that local teams work from the same current information rather than maintaining separate interpretations. |
2 | Configurable screening logic handles regional rules. Screening that can be tuned to the requirements of each applicable regime, rather than applying one fixed rule set everywhere, allows an insurer to meet divergent obligations without either over-blocking or missing restricted parties. |
3 | Compliance embedded in claims, reinsurance, and third-party payments extends screening beyond onboarding to the points where restricted parties most often appear. Re-screening at claim and at payout, and screening the parties to reinsurance and third-party settlements, closes the gaps that a one-time check at issuance leaves open. |
Because many cross-border payments clear through US financial institutions, an insurer with no US presence can still face consequences for dealings that touch US-restricted parties.








