AML, Sanctions, and AI in Insurance: AI and Modern Frameworks
- FinScan

- 5 days ago
- 5 min read
How insurers across lines of business and around the world are modernizing financial-crime compliance across risk assessment, sanctions screening, and artificial intelligence.
This is part 3 of a 3-part series.
IV. AI in AML and Sanctions: Promise, Pitfalls, and Pragmatic Steps Forward
The opportunity
Applied with discipline, AI and machine-learning techniques address well-known weaknesses in financial-crime controls. They can reduce false positives by scoring alerts on a wider set of features than a rules engine considers, which lets analysts spend their time on the alerts most likely to matter. They can speed the handling of alerts through better prioritization. And they can surface anomalies and patterns that fixed rules miss. The Financial Action Task Force has acknowledged this potential, describing how these techniques can make compliance faster, less costly, and more effective when adopted responsibly.
The challenges
The same techniques raise questions that insurers have to answer before they rely on them. Explainability is central. A screening or monitoring decision that affects a customer needs a rationale that analysts, auditors, and regulators can follow, and some model types make that harder. Data quality determines whether a model helps or harms, because a model trained on incomplete or biased data will reproduce those flaws at scale. Ethical concerns, including the risk of biased outcomes across customer groups, require active testing rather than assumption. And the regulatory position is still settling, which leaves firms to make decisions against a moving baseline.
The regulatory frame
The picture is becoming clearer in parts. The EU AI Act, which entered into force in August 2024, classifies certain uses as high-risk and attaches specific obligations to them. For insurers, the most directly relevant entry is the Act’s treatment of AI used for risk assessment and pricing in life and health insurance, which it names as high-risk. AI used to detect financial fraud is treated differently. It is carved out of the high-risk category that covers creditworthiness and credit scoring, so financial-crime detection tools generally do not fall into automatic high-risk classification on that basis, though transparency obligations under the Act can still apply, for example where a system interacts with customers. The timeline for high-risk obligations has been in flux. A simplification package known as the Digital Omnibus, provisionally agreed during 2026, would defer the high-risk obligations originally set for August 2026 into late 2027, but until it is formally adopted and published the original dates remain the legal baseline, so insurers are planning against the earlier date while tracking the change.
IN PRACTICE | |
Insurers are planning against the earlier date while tracking the change. | |
BUILD TO | |
![]() | EU AI Act |
![]() | FATF risk-based approach |
![]() | NIST AI RMF |
![]() | NAIC model bulletin |
AT A GLANCE | |
![]() | Life & health pricing AI is named high-risk (Annex III) |
![]() | Fraud-detection AI is generally not auto high-risk |
![]() | Plan to Aug 2026; Digital Omnibus may defer to late 2027 |
Other frameworks fill in the picture. In the United States, the National Association of Insurance Commissioners adopted a model bulletin on the use of AI systems by insurers in late 2023, which many states have since put in place, setting expectations for governance, testing, and third-party oversight. The National Institute of Standards and Technology’s AI Risk Management Framework, a voluntary framework organized around the functions of governing, mapping, measuring, and managing AI risk, gives insurers a structure for that work. And the Financial Action Task Force’s risk-based approach continues to set the expectation that any tool, AI included, is deployed in proportion to assessed risk.
![]() | Recommendations |
1 | Data quality precedes AI adoption. The return on a model depends on the data feeding it, so the work of cleaning, consolidating, and governing customer, policy, and payment data comes before a model is introduced, not after. |
2 | Alignment with established frameworks reduces regulatory risk. Building to the expectations set by the EU AI Act, the Financial Action Task Force, and the NIST AI Risk Management Framework, and to applicable state requirements, keeps a deployment defensible as rules settle. |
3 | Explainable, supervised models with ongoing monitoring form a sound starting point. Beginning with models whose decisions can be explained and that operate under human review, and monitoring them for bias and for drift as conditions change, lets an insurer capture benefit while keeping control. |
V. Building a Modern Insurance Compliance Framework
The three areas above converge. Financial-crime controls work best as one connected system rather than a set of separate tools. A modern framework aligns people, process, and platforms so that a change in any one is reflected in the others.
![]() | ![]() | ![]() |
People | Process | Platforms |
Compliance, claims, underwriting, and data teams share responsibility for financial-crime risk, with clear ownership and escalation paths between them. Cross-functional working is what allows a sanctions hit at the point of claim to be handled correctly rather than missed. | Risk assessment, screening, monitoring, and testing operate on a continuous cycle, with findings from each feeding the next. The annual review remains as a formal checkpoint rather than the only moment the program updates. | The supporting technology screens in real time, covers the jurisdictions an insurer operates in, and adapts as rules and designations change. Configurability matters as much as coverage, because divergent regimes cannot be served well by a single fixed rule set. |
Integrated screening solutions, FinScan among them, are built to support this model by bringing anti-money-laundering, sanctions, and KYC screening into a connected workflow with broad data coverage and configurable logic.
Three supporting elements tend to separate strong implementations from weak ones. Advisory partnerships give an insurer access to expertise as rules change, rather than leaving it to interpret each development alone. Customization of risk scoring lets the system reflect an insurer’s specific products, geographies, and risk appetite rather than a generic default, which is what allows a single program to serve lines whose obligations diverge as much as the two tables in Section I describe. And strong data pipelines ensure that the customer, policy, and payment data reaching the screening engine is complete and current, since screening quality is bounded by data quality.
VI. Conclusion: From Cost Center to Competitive Advantage
Financial-crime compliance is often treated as a cost to be minimized. The insurers making the most progress treat it instead as a contributor to operational resilience, customer trust, and readiness for whatever the next regulatory or geopolitical shift brings. A program that updates continuously absorbs change with less disruption. Controls that counterparties trust protect the banking and reinsurance relationships an insurer depends on. And a framework built to adapt can take on new products and markets without starting its compliance work over.
The insurers that succeed in this environment share a disposition more than a toolset. They treat compliance as a discipline that learns, revising their approach as evidence accumulates. They work across functions, so that risk is managed where it arises rather than in a silo. And they ground innovation in risk, adopting new methods, AI included, where the assessed risk justifies them and the controls can be explained. The move from blind spots to breakthroughs is, in the end, a move from a static program to one that keeps pace with the world it operates in.









