top of page

AML, Sanctions, and AI in Insurance: The Balancing Act

  • Writer: FinScan
    FinScan
  • Jul 28
  • 5 min read
AML, Sanctions, and AI for Insurance

How insurers across lines of business and around the world are modernizing financial-crime compliance across risk assessment, sanctions screening, and artificial intelligence. This is part 1 of a 3-part series.





Executive Summary

Regulatory expectations on financial crime are rising across every major jurisdiction, and the insurance industry sits squarely within scope.


The European Union’s Anti-Money Laundering Authority began operations in July 2025 and took over the anti-money-laundering and counter-terrorist-financing mandates of the European Banking Authority in January 2026, with a single rulebook that applies starting July 2027.


Meanwhile, sanctions regimes in the United States, the European Union, and the United Kingdom continue to broaden, and they increasingly diverge in their detail even where their objectives align.


And finally, Artificial intelligence has moved from pilot projects into supervised production use for screening and monitoring, while new rules such as the EU AI Act set conditions on how those systems must be built and governed.


For insurers, these pressures arrive with a sector-specific complication. In the United States, Bank Secrecy Act and anti-money-laundering program obligations apply on a product basis. An insurer is covered when it issues permanent life insurance, annuities, or other products with cash value or investment features, and falls outside the program requirement when it does not.


Sanctions obligations work differently. Every US-domiciled insurer is a US person and must comply with the Office of Foreign Assets Control regardless of the products it sells, and OFAC enforces on a strict-liability basis. The result is a compliance picture that is uneven by product line and unforgiving on sanctions.


This series sets out how leading insurers are responding across three areas:

  • risk assessments

  • global sanctions screening

  • AI adoption

Part I. The Compliance Balancing Act

Insurers face a tightening set of expectations from regulators, counterparties, and the public. The pressures fall into three broad categories.


Regulatory intensity

The European Union has consolidated its anti-money-laundering rules into a single framework and created a dedicated supervisor. The Anti-Money Laundering Authority, based in Frankfurt, became operational on 1 July 2025 and assumed the anti-money-laundering and counter-terrorist-financing functions previously held by the European Banking Authority on 1 January 2026. The substantive rules in the Anti-Money Laundering Regulation and the Sixth Anti-Money Laundering Directive apply from 10 July 2027, and the Authority is scheduled to begin direct supervision of selected high-risk institutions in 2028. In the meantime, it is publishing the technical standards and guidelines that will define day-to-day expectations, which makes the period through 2027 a window for preparation rather than a pause.


At the international level, the Financial Action Task Force continues to anchor its standards in a risk-based approach, under which firms are expected to assess their own money-laundering and terrorist-financing risks and apply controls proportionate to them.


In the United States, the Bank Secrecy Act framework reaches insurers selectively. FinCEN’s rules apply to insurance companies that issue covered products, defined as permanent life insurance policies other than group policies, annuity contracts other than group contracts, and any other insurance product with cash value or investment features. An insurer that issues only property, casualty, health, or term products without those features generally falls outside the anti-money-laundering program requirement. This product-based scope is a meaningful difference from the entity-based obligations that apply to banks.


Sanctions exposure is broader. As US persons, all US-domiciled insurers must comply with OFAC’s sanctions programs whether or not they issue covered products, and OFAC has long applied a strict-liability standard, meaning a violation can occur without intent or knowledge. An insurer can therefore sit outside the anti-money-laundering program rules while remaining fully exposed on sanctions, a distinction that shapes where screening effort belongs.


The EU Timeline at a Glance

2025

2026

2027

Then

Jul 1

Jan 1

Jul 10

2028

AMLA becomes operational

Assumes AML / CTF mandate from the EBA

Single rulebook AMLR + 6AMLD) applies

Direct supervision of high-risk entities begins


Reputational stakes

Enforcement actions and public findings carry costs well beyond any penalty figure, because counterparties read them closely. Banks providing correspondent and operating accounts, and reinsurers assessing cedents, factor financial-crime control quality into their decisions, and weak controls can contribute to the loss or repricing of those relationships. The Financial Action Task Force has cautioned against over-de-risking, the practice of withdrawing from customers or regions wholesale rather than managing risk, which signals how seriously the dynamic is taken at the standard-setting level.


Cross-border complexity

Insurers that underwrite, pay claims, or hold reinsurance across borders must reconcile sanctions and anti-money-laundering rules that no longer move in lockstep. A counterparty or transaction permitted under one regime may be restricted under another, and the gap has widened as the United States, the European Union, and the United Kingdom have each expanded their programs at different speeds.


The Cost of Inertia

Static compliance processes were designed for a slower regulatory cycle. When rule changes, designations, and guidance arrive continuously, an annual assessment and a fixed screening configuration leave gaps between updates. Those gaps are where enforcement risk, counterparty risk, and operational disruption accumulate. The sections that follow address the three areas where insurers are closing them.


Obligations also differ by line of business

Jurisdiction is only one slice of difference. The other is the line of business, and the two compound. Anti-money-laundering program requirements concentrate on life and investment-type insurance, where products carry cash value or an investment element. The mechanism varies by region, since the United States scopes the requirement by product while the European Union and the United Kingdom scope it by obliged entity, but the pattern holds. Property, casualty, health, marine, and most specialty lines sit largely outside the anti-money-laundering program requirement while remaining fully exposed to sanctions, which apply to every line in every jurisdiction. Where the risk concentrates, and therefore where screening effort belongs, shifts with the line.

Line of business

AML program obligation

Basis

Life and annuities

In scope

Cash-value and investment-type products carry money-laundering risk through funding, surrender, loans, and beneficiary changes

P&C / general

Largely outside

Non-life products lack the cash-value or investment features that trigger the program requirement

Health

Largely outside

Treated as non-life; outside program scope in the United States and the European Union

Reinsurance

Largely outside

Not a customer-facing covered or investment product; exposure is counterparty-driven

Marine

Largely outside

Non-life; program duties limited, sanctions exposure high

Specialty (travel, cyber, trade credit)

Varies

In scope where a product is life-linked or investment-type; otherwise outside

Table 1. Anti-money-laundering program obligation by line. Sanctions obligations apply to every line regardless of this column.


The exposure that remains, and the screening workflow that addresses it, also varies by line.

Line of business

Where exposure concentrates

Screening focus

Life and annuities

Laundering through policy funding, surrender, and loans; beneficiary and ownership changes

Onboarding, ongoing monitoring, policy and beneficiary changes; entity resolution

P&C / general

Sanctions at claim and payout; third parties, vendors, and beneficiaries

High-volume, low-data screening of names and payments across claims

Health

Fraud and sanctions across members, providers, and administrators

Multiple screening points; integration with claims and billing

Reinsurance

Counterparty and sanctions risk several layers deep in cedant, broker, and ownership chains

Look-through screening across multi-layered counterparties

Marine

Sanctions tied to vessels, ownership, routes, and cargo

Matching across aliases and free-text; vessel and ownership

Specialty (travel, cyber, trade credit)

Cross-border, real-time exposure; cyber to sanctioned parties via ransomware payments

Real-time and batch screening tuned to niche models

Table 2. Where exposure concentrates and what screening addresses, by line.

Sanctions apply to every line, in every jurisdiction

regardless of the AML program. Where AML exposure is low, sanctions exposure often is highest.



bottom of page