AML Best Practices for Life Insurance Companies
AML Best Practices for Life Insurance Companies. – Helping Life insurers guard against the wrong customers.
Although life insurance products are not high on a money launderer’s shopping list, life insurers do promote flexible investment-type products which might be viable as a medium to launder illicit funds. Albeit a remote one, the threat cannot, therefore, be ignored.
Establishing robust Anti Money Laundering & Combatting the Financing of Terrorism (AML & CFT) procedures and controls requires time, effort and investment in resources. With regulations continuously changing, the whole process may seem to be embarking on a never-ending journey.
It is not my intention to cover all the details of the implementation of AML & CFT procedures, but simply to give an overview of the main best practices that may be adopted.
1. Setting the Risk Appetite – Customer Acceptance Policy
One of the first steps an insurer must make is to create a Customer Acceptance Policy which should, briefly, provide a description of the characteristics of customers that are likely to pose a higher-than-average risk and which therefore fall outside the customer acceptance policy of the company.
2. Understanding Potential Risks
To mitigate the risks of doing business with potentially devious characters insurers need to understand threats, which might emanate from the main risk areas i.e. its Customer, Geographical, Transactional, Method of Payments, Product and Distribution Channel.
This process requires a good dose of common sense and creativity on our part as we need to put ourselves in a money launderer’s shoes to identify potential vulnerabilities.
The process by which money laundering vulnerabilities are identified includes:
Analysing money laundering typologies facing the life insurance industry
An insurer should adopt a proactive approach to identify current and new AML/CFT typologies by analysing its own internal reports, submitted Suspicious Transaction Reports (STR) and typology reports published by international or local authorities.
Business Risk Assessment
A Money Laundering Business risk assessment enables an insurer to identify and measure actual risk exposures emanating from the main business risk areas.
This exercise can turn into a complicated one, but in very simple terms, the objective is to enable the insurer to implement adequate risk mitigation measures and controls to those risk areas where the actual exposures are deemed to be too close to or outside its risk appetite.
This assessment needs to be reviewed at least annually to ensure that there are no material changes. It is good practice to review the process more frequently when new internal or external threats and vulnerabilities are identified, or to monitor the success or lack thereof of any risk mitigation measures applied.
Customer Risk Assessment & Grading
In order to ensure that Customer Due Diligence measures will reflect each customer’s risk profile insurers need to carry out a customer risk assessment covering, at least, the following steps:
1. Know who is Your Customer and Your Customer’s Customer by ensuring that the Customer(s) (including the beneficiaries, Ultimate Beneficial Owners) have been satisfactorily identified.
2. Know Your Customer’s source of funds and source of wealth by establishing the nature of the activity (e.g. occupation) which generated the payment.
-
Identify potential high-risk features:
Geographical risks e.g., whether a customer’s nationality, residency or business activity is linked to a high-risk country.
Occupational Risks e.g. whether the customer’s occupation/business is a high-risk one e.g. PEP.
Customer’s behaviour e.g. if there is lack of cooperation in submitting KYC, source of funds/wealth information.
Transaction risks e.g. transactions which do not seem to fit into the customer’s profile.
Presence on an international Sanctions lists prohibits the insurer from offering any product to the targeted individual/entity.
Presence on internal Watch lists. Maintaining an IT data base of High-Risk customers ensures an automated referral process to the MLRO. Such a list should include individuals or entities linked to:
-
A Suspicious Transaction Report;
-
Internal Reports submitted to the MLRO;
-
Requests for information from the FIAU, Police and
-
Attachment/Freezing Orders.
3. Know your Distribution Channel
