As part of the FCA’s review into the insurance sector, earlier this year it conducted an in-depth analysis of the sector’s financial crime controls. The multi-firm review focused on the design of financial crime frameworks rather than their outcomes.
The review found that financial crime systems and controls across the insurance firms assessed were mostly effective, but identified several areas where firms need to strengthen their approach.
The FCA found that group-level risk assessments and policies were often not sufficiently tailored to individual business units or jurisdictions. This was particularly evident in retail insurance, where risk assessment controls were assessed as weak.
Insurance firms should ensure that financial crime risk assessments consider the specific risks associated with each business unit, product, customer type, distribution channel and jurisdiction, and clearly demonstrate how those risks determine the controls applied.
Firms could utilise technology to support this, using dynamic risk assessments that adapt to different use cases and reduce the need for staff to refer to extensive policy documents, while keeping everything in one central database.
The FCA found that Customer Due Diligence (CDD) controls were weak across most retail firms, largely because firms had not fully documented their approach. The FCA recognises that requirements may differ for non-AML-regulated insurers, but expects firms to clearly document the rationale for any differentiated approach.
Insurance firms should document what information is collected, when screening is performed, when enhanced due diligence is required, how information is refreshed and why different levels of CDD are applied.
It is also vitally important that, when a firm is presented with evidence that a client may be high-risk, the outcome is well documented and easily retrieved. Relying on a broker’s individual knowledge is not acceptable. The old adage, “if it isn’t written down, it didn’t happen”, still applies. Simply being able to show that a search was run isn’t good enough.
Proactive monitoring, including transaction monitoring, was less developed among some retail and wholesale firms, particularly where firms were not AML-regulated or transaction patterns were predictable. The FCA does not necessarily require every insurer to implement the same monitoring model, but expects firms to assess the risks and clearly document their rationale.
Firms should be able to demonstrate why their monitoring approach is proportionate and what alternative controls mitigate the risks where traditional transaction monitoring is not used.
Ongoing monitoring can help firms not only ensure they aren’t working with sanctioned individuals or firms, but can also help identify high-risk customers that might pose either a reputational or financial risk to them.
The FCA’s review found that fraud risk management was a particular area of weakness for wholesale insurers, with limitations in management information and evidence of fraud monitoring arrangements. The review suggested that senior management should have clear MI on fraud volumes, trends, typologies, investigations, financial exposure, emerging risks and control effectiveness.
Although most firms operate a three-lines-of-defence model, many lacked a formal RACI to clarify responsibility across the financial crime framework. The FCA also found that most firms did not maintain an obligations register mapping regulatory requirements to controls and accountable owners.
Some firms lacked structured, risk-based monitoring and testing plans across the second and third lines of defence. The review suggested that firms establish a coordinated assurance programme that tests higher-risk controls more frequently and clearly demonstrates whether controls are both well designed and operating effectively.
Firms generally recognised that outsourcing financial crime activities does not transfer their regulatory responsibility. However, the FCA found limited evidence of enhanced, risk-based oversight of higher-risk third parties.
Insurance firms, when working with third-party providers such as claims management firms or software providers, should conduct their own due diligence on their systems and processes rather than simply relying on their claims.
For example, SmartSearch is certified against the UK Government’s Digital Verification Services Trust Framework, which independently reviews and assesses our ability to deliver our services to the highest standards.
Following the review, the FCA expects all insurers and insurance intermediaries to consider the findings and make improvements where appropriate.
The findings clearly demonstrate that the objective should not simply be to add more controls. It should be to demonstrate that the right controls are being applied to the right risks, by clearly accountable people, with evidence that they work.
This is the core message running through the FCA’s findings.