Rethinking Insurance in a Compliance World: Key Takeaways

The insurance industry is facing a more complex financial crime and compliance environment. Sanctions risk is no longer limited to checking whether a policyholder's name appears on a sanctions list, while evolving regulations, artificial intelligence and increasingly sophisticated ownership structures are changing how insurers need to approach AML and sanctions compliance.

During a recent Dow Jones webinar, Vera Akiotu, Becki LaPorte and Greg Walsh explored how insurers can strengthen their compliance frameworks, improve the quality of risk intelligence and balance efficiency with effective risk detection.

Here are the key takeaways.
1. Sanctions risk extends beyond the policyholder
A central theme of the webinar was that insurers need to look beyond the individual or entity named on an insurance policy.
Risk can arise through:
Beneficial owners
Policy beneficiaries
Claimants
Corporate entities
Third-party recipients of claim payments
Family members or business associates connected to sanctioned individuals
Sanctions evasion adds another layer of complexity. Individuals who anticipate being sanctioned may attempt to move assets or ownership interests through spouses, relatives, associates or corporate structures.
For insurers, this means sanctions screening cannot be treated as a simple name-matching exercise. Understanding who ultimately owns, controls or benefits from an entity is increasingly important.
2. Ownership intelligence is becoming essential
Traditional screening identifies a sanctioned individual when their name appears directly in a customer record. It is less effective when that individual is hidden behind layers of corporate ownership.
The speakers emphasized the importance of understanding beneficial ownership and the broader network of relationships surrounding a customer.

This is particularly relevant when there are discrepancies between corporate records and an insurer's understanding of who ultimately owns or controls an entity.
The key shift is from asking "Who is this customer?" to also asking "Who owns, controls or benefits from this customer?"
3. AML compliance is moving toward greater consistency and prescription
The discussion around the EU's AML Regulation (AMLR) and the sixth Anti-Money Laundering Directive (AMLD6) highlighted a broader regulatory shift.
According to Greg Walsh, the direction of travel is toward a more rules-based and technically specific approach, with greater focus on:
Beneficial ownership
Ongoing monitoring
Consistent controls across jurisdictions
Consistent risk assessments
Stronger documentation
Integration of AML and sanctions teams into the wider business
Even organizations outside Europe should pay attention. As Becki LaPorte noted, regulatory developments in major markets can become global best practices, influencing supervisory expectations elsewhere.
4. KYC should be treated as an ongoing process
A one-time KYC check at onboarding is increasingly insufficient.
Customer circumstances can change after a policy has been issued. Ownership, addresses, locations, relationships and other risk factors can evolve over time.

For insurers, effective compliance therefore requires continuous monitoring, rather than relying solely on information collected when a relationship begins.
This is particularly important when sanctions or ownership risks can emerge after a policy has already been written.
5. AI can improve efficiency but human judgment remains critical
The panel was broadly positive about the potential of AI to improve compliance operations.
Potential applications discussed included:
Name matching
Alert prioritization
Adverse media summarization
Ownership mapping
Continuous monitoring
Identifying patterns associated with fraud
Gathering and organizing publicly available information
AI can significantly reduce the time investigators spend collecting information, allowing compliance professionals to focus more of their attention on analysis and decision-making.
But the panel stressed that AI should support rather than replace human judgment.
Compliance teams need to understand how an AI-driven conclusion was reached and validate its outputs. A regulator is unlikely to regard "the AI said so" as an adequate explanation for a compliance decision.
The human-in-the-loop model therefore remains important, particularly for higher-risk decisions and investigations.
6. False positives are both a productivity and risk issue
Reducing false positives is about more than making compliance teams more efficient.
Excessive alerts can create backlogs and alert fatigue, potentially making it harder for investigators to identify genuine risks.
At the same time, overly aggressive attempts to reduce alert volumes can create false negatives.
As the discussion illustrated, changing screening parameters can dramatically alter the number of alerts generated. A reduction in alerts is therefore not necessarily evidence of a better control.
The objective should instead be to develop controls that produce fewer irrelevant alerts without materially reducing the detection of genuine risk.
This requires careful calibration based on the compliance system, risk appetite and customer population.
7. Claims screening should follow the money
An important practical point emerged around claims.
When insurance money is leaving the organization, insurers need to understand where it is going and who is receiving it.
That means the relevant parties for screening may extend beyond the policyholder to include claimants, beneficiaries, service providers and other recipients of funds.

The fundamental question is whether the recipient has been appropriately identified and validated, and whether paying that party could create sanctions or AML risk.
8. Adverse media should be treated as a risk signal, not a verdict
Adverse media can provide valuable intelligence, but a negative article should not automatically become a compliance conclusion.
The panel emphasized the importance of evaluating:
The credibility of the source
The nature of the allegation
Whether the information has been corroborated
Whether there is a court case, regulatory action or public filing
How recent the conduct was
Whether the issue is relevant to the insurer's specific risk exposure
Whether the information changes the customer's overall risk assessment
The panel also pointed out that context matters.
For example, different types of misconduct may have very different relevance depending on the insurance product and the organization's risk appetite.
A strong adverse media process therefore uses media as a trigger for assessment, rather than treating every negative reference as proof of wrongdoing.
9. Breaking down compliance silos is critical
One of the strongest organizational themes from the discussion was the need for greater collaboration across financial crime functions.
Sanctions, AML, fraud, investigations, compliance and other teams may operate separately, particularly within large global insurers. But financial crime risks frequently overlap.
Sanctions evasion, for example, may have implications for AML investigations, fraud controls and broader customer risk assessments.
A compliance program should therefore operate as an integrated framework rather than a collection of isolated functions.
Regulators are increasingly looking at how effectively the organization manages risk as a whole.
10. Data, systems and people remain the foundation
When asked what insurers should prioritize over the next 12 months, Greg Walsh highlighted three fundamentals:
Data. Systems. People.
High-quality data is essential for generating meaningful screening and monitoring results. Systems need to be appropriately configured so that alerts are manageable and focused on meaningful risk. And people need the training, awareness and organizational connections required to interpret those results effectively.

Becki LaPorte reinforced the importance of breaking down organizational silos and making it clear who is responsible for managing particular risks across different jurisdictions and business lines.
Technology can improve compliance capabilities, but it cannot compensate for poor data, poorly designed controls or disconnected teams.
The bigger picture
The discussion points to a broader evolution in insurance compliance: from static screening toward dynamic risk intelligence.
Insurers increasingly need to understand the customer in front of them AND the ownership structures, relationships, transactions and events surrounding that customer over time.
The most effective approach combines:
Better ownership and relationship intelligence
Continuous monitoring
Well-calibrated screening controls
Appropriate use of AI
Human oversight and judgment
Contextual assessment of adverse media
Strong claims controls
Cross-functional collaboration
High-quality data and documentation
Ultimately, the goal is to generate better intelligence at the right time, apply it to the right parties, and enable decisions that are efficient for the business and defensible to regulators.


