KYC and AML/CFT in insurance: insurers' obligations
6
Min
•
04.08.2026
In short
- Insurance undertakings, especially in life insurance and capitalisation, are AML/CFT-regulated entities within the meaning of the French monetary and financial code. In France, they are supervised by the ACPR.
- The obligations cover KYC (identifying and verifying the customer when the relationship begins), knowledge of the business relationship, identification of beneficial owners, risk-based due diligence, enhanced due diligence for politically exposed persons (PEP) and higher-risk situations, record keeping and suspicious transaction reporting to TRACFIN.
- Life insurance is a major point of vigilance: it can be used as a money laundering vehicle through premium payments and surrenders.
- AML6 (the European AML package of 2024, applicable on 10 July 2027) harmonises and strengthens these obligations, with the new AMLA authority.
- The operational challenge: staying compliant without breaking the smoothness of underwriting, which drives the automation of controls.
Are insurers subject to AML/CFT?
Yes. Insurance undertakings are among the entities subject to the framework for combating money laundering and terrorist financing (AML/CFT), as defined by the French monetary and financial code. In France, their supervisor is the French prudential supervisor ACPR (Autorite de controle prudentiel et de resolution), which monitors the quality of their framework and can sanction breaches.
This regulated status primarily targets life insurance and capitalisation activities, which present the highest risk, but it also concerns, depending on the case, intermediaries such as brokers and agents. In practice, an insurer or a broker cannot simply sell a contract: it must know its customer, understand the source of funds and detect suspicious transactions.
Being a regulated entity means putting in place a complete framework: internal procedures, risk classification, staff training, internal control and the ability to respond to requests from TRACFIN and the ACPR.
KYC and AML/CFT obligations in insurance
The obligations rest on a simple logic: know who you are dealing with, understand the relationship and monitor it over time. Here are the essential building blocks.
Customer identification and verification (KYC)
When the business relationship begins, the insurer must identify the customer and verify their identity using reliable and independent documents or data. This applies to natural persons as well as legal entities.
Beyond identity, the regulated entity must gather elements of knowledge of the business relationship: nature of the transaction, purpose and source of funds, and the policyholder's situation. This information makes it possible to assess the consistency of payments and to detect any anomalies. For a deeper look at the method, see our complete KYC guide.
Beneficial owners
When the customer is a legal entity, the insurer must identify the beneficial owner or owners, that is, the natural persons who actually control the entity or benefit from it. This step is essential to prevent legal structures from being used to conceal the real identity of those giving the instructions.
In insurance, vigilance also applies to the beneficiary of the contract: knowing who will receive the capital is an integral part of customer knowledge.
Risk-based due diligence and PEP
The framework rests on a risk-based approach. The intensity of controls must be proportionate to the level of risk of each relationship: lighter due diligence for low-risk situations, enhanced due diligence for sensitive ones.
Enhanced due diligence is required in particular for politically exposed persons (PEP), their close associates and related persons, as well as for complex transactions, those of an unusually high amount or with no apparent economic justification. It calls for additional checks on the source of wealth and funds and approval at an appropriate level.
Suspicious transaction reporting
When a regulated entity knows, suspects or has good reason to suspect that funds derive from an offence or contribute to terrorist financing, it must file a suspicious transaction report with TRACFIN, the French financial intelligence unit. This report is confidential and the customer must not be informed of it.
All the elements (identity documents, supporting evidence, risk analyses, reports) must also be kept for the period set by the regulations, in order to guarantee an audit trail usable in the event of an inspection.
Life insurance, a point of vigilance
Life insurance concentrates a significant share of the sector's AML/CFT risk. Its flexibility is its commercial strength, but also its vulnerability: a contract can receive free premium payments, then be subject to partial or full surrenders, which makes it possible to move funds around and blur their origin.
Several signals call for particular attention: payments unrelated to the policyholder's profile, rapid surrenders after subscription, frequent changes of beneficiary, or unexplained payments from third parties. This is why vigilance does not stop at signing: it is exercised throughout the life of the contract, at every significant transaction.
What AML6 changes
The AML package adopted in 2024 (often called AML6) marks a turning point. It harmonises AML/CFT rules across the European Union and strengthens the obligations of regulated entities, including insurers. Its application is scheduled for 10 July 2027.
Two developments shape this new framework:
- The creation of the AMLA, the European anti-money laundering authority, tasked with supervising and coordinating the application of the rules across the Union.
- A body of rules that is more directly applicable and more uniform across member states, reducing differences in interpretation and raising the bar on customer knowledge, beneficial owners and the traceability of controls.
For insurers, the challenge is to anticipate: the frameworks put in place today must already be designed for this strengthened standard. We detail these changes in our article dedicated to the AML6 regulation.
How to stay compliant without breaking underwriting
The real challenge is not only regulatory, it is operational. Multiplying requests for supporting documents and lengthening timelines makes policyholders drop out. Conversely, easing controls exposes you to breaches and sanctions. The answer lies in the automation of a control process that is both rigorous and fast.
In practice, an effective framework makes it possible to:
- Verify the identity of the policyholder and identify the beneficial owners in an automated way, without manual re-entry.
- Apply a risk score that adjusts due diligence to the profile and triggers enhanced controls only when necessary.
- Detect PEP signals and higher-risk situations, and document every decision to build a complete audit trail.
- Return a decision in 2 to 5 seconds, so that compliance fits into the underwriting journey instead of slowing it down.
That is precisely the purpose of our fraud score and identity verification (KYC) use case, which combines control and smoothness in the service of insurers.
In conclusion
Insurers, and particularly players in life insurance, are fully subject to AML/CFT: KYC, beneficial owners, risk-based due diligence, PEP handling and suspicious transaction reporting to TRACFIN are all part of their obligations, under the supervision of the ACPR. With AML6 and the arrival of the AMLA, the level of requirements will rise even further by 2027. The key to holding this course without degrading the underwriting experience: an automated, documented and auditable framework, capable of arbitrating risk in a few seconds.
Sources: French monetary and financial code (AML/CFT framework), ACPR (supervision of insurance undertakings), TRACFIN (suspicious transaction reporting), European Union AML package (AML6, AMLA).
Compliant, frictionless insurance underwriting
Meelo verifies the policyholder's identity and beneficial owners, and flags risky situations, without breaking the underwriting journey. A decision in 2 to 5 seconds, documented and auditable.



.jpg)