On 23 June 2026, the Financial Conduct Authority (FCA) published the findings of its Insurance Financial Crime Controls – Multi-Firm Review.
The review examined the design of financial crime systems and controls across a selection of large insurance firms, covering retail, wholesale and life insurance businesses. The FCA found that firms’ controls were mostly effective, but identified areas where improvements are needed, particularly in risk assessment, client due diligence and transaction monitoring.
The FCA expects firms to maintain adequate and proportionate policies and procedures to counter the risk that they may be used to further financial crime. Firms should remain alert to evolving risks and invest appropriately in financial crime systems, controls and resources.
Importantly, the review focused on the design of firms’ financial crime frameworks and controls. The FCA assessed firms against the Money Laundering Regulations 2017, its Financial Crime Guide, SYSC, JMLSG guidance and FATF guidance. The FCA’s observations were based on documentation provided by firms and follow-up meetings.
Life insurance firms generally demonstrated stronger controls than retail and wholesale insurance firms, although the FCA noted that this may reflect differences in the regulatory status, products and inherent risks across the sectors.
WHAT DID THE FCA FIND?
The FCA considered 10 key groups of financial crime controls:
- Governance and oversight
- Risk assessment
- Regulatory reporting and issue management
- People and knowledge
- Third-party risk
- Client due diligence
- Sanctions
- AML transaction monitoring
- Fraud
- Anti-bribery and corruption
The FCA identified cross-sector themes across six of these control groups.
HEADLINE SECTOR FINDINGS.
Sector | Areas of relative strength | Areas for improvement |
Retail insurance | Sanctions, fraud risk management, and anti-bribery and corruption | Risk assessment and policies and procedures |
Wholesale insurance | People and knowledge, anti-bribery and corruption, and sanctions | Fraud risk management |
Life insurance | Risk assessment, people and knowledge, third-party risk, client due diligence and sanctions | Transaction monitoring |
The FCA assessed the overall effectiveness of financial crime systems and controls in large retail and wholesale firms as moderate, while life insurance firms represented the strongest portfolio, with design effectiveness assessed as moderate to good.
KEY CROSS-SECTOR FINDINGS IN INSURANCE FINANCIAL CRIME CONTROLS.
AML TRANSACTION MONITORING
Transaction monitoring was less developed among non-AML-regulated insurance firms and where transaction patterns were relatively predictable.
Across the wholesale and retail portfolios, most firms did not undertake formal transaction monitoring and, consequently, this area was not subject to detailed assessment. The FCA recognised that this reflected firms’ regulatory status and the nature of their transaction patterns.
However, the absence of formal transaction monitoring does not remove the need for firms to consider their financial crime risks. The FCA expects firms to consider the risks and benefits of their approach and document the rationale for their chosen controls.
Firms should also remember that their wider obligations in relation to suspicious activity reporting, sanctions compliance and financial crime risk management continue to apply. Where controls are reduced or simplified, the approach should be risk-based, proportionate and properly evidenced.
CONTROLS MONITORING AND TESTING
The FCA found that monitoring and testing activity was generally consistent across the second and third lines of defence, but some firms provided limited evidence of structured, risk-based monitoring and testing plans.
Firms should ensure that their second- and third-line activities are supported by appropriate risk-based plans and that there is effective coordination between them. This should help prevent both duplication and gaps in assurance coverage.
Where a firm does not have dedicated financial crime assurance expertise, it should be able to demonstrate that it has considered its financial crime risks and assessed whether specialist or outsourced assurance activity is appropriate.
POLICIES AND PROCEDURES
Many firms had comprehensive group-level financial crime policies and procedures. However, these were not always sufficiently tailored to individual business units or jurisdictions.
The FCA expects firms to consider how overarching group frameworks are translated into practical requirements for individual businesses and jurisdictions.
Policies can remain group-level documents, but firms should ensure that supporting procedures clearly explain how requirements are applied in practice. This is particularly important where differences in business model, jurisdiction, regulatory status or financial crime risk exist.
ROLES AND RESPONSIBILITIES
Most firms operated a three-lines-of-defence model, but many did not have a formal RACI (Responsible, Accountable, Consulted, Informed) matrix covering their financial crime framework.
The FCA does not require firms to maintain a RACI matrix. However, it identifies this as good practice because it can help establish clear accountability and transparency across financial crime activities.
This may be particularly useful where responsibilities are distributed across several compliance functions, business units or third-party administrators.
OBLIGATIONS MANAGEMENT
Most firms did not maintain an obligations register mapping legal and regulatory requirements to internal controls and accountable owners.
An effective obligations management framework can help firms demonstrate how regulatory requirements translate into specific controls, processes and responsibilities across different products, jurisdictions and regulated or non-regulated activities.
While an obligations register is not itself a prescribed regulatory requirement, the FCA identifies the mapping of obligations, controls and accountable owners as good practice.
THIRD-PARTY OUTSOURCING
Where financial crime activities were outsourced, firms generally recognised that they retained responsibility for the outsourced activities.
The FCA found, however, that the level of oversight was not always sufficiently differentiated according to the risk and materiality of the outsourced activity. Only one firm in the review demonstrated enhanced, risk-based oversight of higher-risk controls.
Firms should therefore consider categorising third-party relationships according to risk and matching their oversight accordingly.
The FCA also expects firms to produce and review risk-focused management information covering third-party performance, emerging risks and escalation. Governance arrangements and escalation routes should be clear, with oversight activity and decisions appropriately documented.
SECTOR-SPECIFIC FINDINGS
RETAIL INSURANCE
The FCA assessed the effectiveness of financial crime systems and controls across large retail firms as moderate overall.
Strengths included sanctions, fraud risk management, and anti-bribery and corruption controls. The FCA noted that this is consistent with the lower inherent AML risks associated with many retail insurance products, where financial crime exposure may be more likely to arise through fraud and sanctions breaches.
The FCA identified a number of areas for improvement:
- Some firms relied heavily on group-level policies and frameworks that were not sufficiently specific to individual firms or business units.
- Roles and responsibilities could be unclear where financial crime responsibilities were distributed across multiple teams.
- Risk assessment controls were assessed as weak, particularly because firms did not provide sufficient evidence specific to individual business units.
- Client due diligence controls were weak across most large firms, primarily because firms had not fully documented their approach.
For non-AML-regulated firms, the extent of client due diligence may legitimately differ. However, firms should be able to clearly demonstrate and document the rationale for any differentiated approach.
WHOLESALE INSURANCE
The FCA assessed the effectiveness of financial crime systems and controls across large wholesale firms as moderate overall.
The strongest areas were people and knowledge, anti-bribery and corruption, and sanctions.
Fraud risk management was comparatively weaker, with limitations identified in management information and the detail available regarding firms’ fraud monitoring arrangements.
Transaction monitoring was also not consistently embedded across wholesale firms. Again, the FCA recognised that this reflected the nature of firms’ business models, risks and transaction flows.
The key consideration for firms is therefore not necessarily whether they have a particular transaction monitoring solution, but whether they have appropriately assessed their risks, determined what controls are necessary and can evidence the rationale for their approach.
LIFE INSURANCE
Life insurance firms represented the strongest portfolio reviewed by the FCA, with design effectiveness assessed as moderate to good, although improvements were identified in transaction monitoring.
Areas of particular strength included:
- Risk assessment
- Client due diligence
- People and knowledge
- Third-party risk
- Sanctions
Some firms also demonstrated strong fraud risk management, including the use of automated fraud surveillance tools and actionable management information.
WHAT THE REVIEW MEANS FOR INSURANCE FINANCIAL CRIME CONTROLS.
Although the FCA’s review focused on a selection of larger firms, it expects other firms to consider the findings in the context of their own business models and make any necessary improvements.
For insurers and insurance intermediaries, the review provides a useful opportunity to challenge whether their financial crime framework is genuinely risk-based, proportionate, clearly owned and appropriately evidenced.
In particular, firms should consider:
- Is our financial crime risk assessment sufficiently tailored to individual business units, products and jurisdictions?
- Can we clearly demonstrate why our client due diligence arrangements are appropriate to our regulatory status and risk profile?
- Have we documented the rationale for our approach to transaction monitoring, including where formal monitoring is not undertaken?
- Are our second- and third-line monitoring and testing plans risk-based and appropriately coordinated?
- Are group policies supported by sufficiently detailed business-unit and jurisdiction-specific procedures?
- Are roles and responsibilities clearly defined across the three lines of defence?
- Can we map key regulatory obligations to controls and accountable owners?
- Is our oversight of outsourced financial crime activity proportionate to the risk and materiality of the services provided?
- Do senior management and relevant committees receive sufficiently meaningful management information to identify emerging financial crime risks and control weaknesses?
The FCA has made clear that it will continue to monitor how firms meet their requirements to prevent and detect financial crime.
For insurance firms, the message is therefore clear: a proportionate financial crime framework does not mean a less rigorous framework. Firms should be able to demonstrate why their controls are appropriate to their specific risks, how responsibilities are allocated, and how the effectiveness of the framework is monitored and assured.
HOW COSEGIC CAN STRENGTHEN YOUR INSURANCE FINANCIAL CRIME CONTROLS
Cosegic can support insurers and insurance intermediaries in reviewing their financial crime frameworks against the FCA’s latest findings.
We can undertake a targeted review of your financial crime policies, risk assessments, client due diligence arrangements, transaction monitoring rationale, governance, testing and third-party oversight, helping you identify gaps and prioritise proportionate enhancements.
Read the FCA’s Insurance Financial Crime Controls – Multi-Firm Review