Key findings from the FCA review
Insurance firms are operating in an environment of increasing complexity. With new products and distribution channels, greater reliance on outsourcing and delegated authority arrangements and evolving fraud and sanctions risks, many firms will find that their exposure to financial crime shifts.
The FCA’s latest multi-firm review of financial crime controls in insurance puts more pressure on firms to map and understand their risk. The regulator found that frameworks across large insurers are generally ‘mostly effective’, but identified areas for improvement, notably in risk assessments, policies and procedures, client due diligence and transaction monitoring. The report’s findings align with the FCA’s wider findings on risk assessments and its further reviews of sanctions compliance.
In response, firms need to develop more robust risk management processes. In doing so, they will restore trust with the regulator and build a clearer picture of their risk exposure as it changes.
Where financial crime risk assessments often fall short
The FCA’s review identified a common issue: financial crime risk assessments exist, but provide too little insight to support risk-based decisions or effectively allocate resources. In practice, this often means a financial crime risk assessment is maintained by compliance, updated annually, held in a spreadsheet and discussed only when a regulator, auditor or board paper requires it. When compliance personnel change and there is no consistent methodology with fully defined inputs and outputs, businesses are left without a shared understanding of risk and clear governance chain.
It also found that relatively few risk assessments were properly tailored to the business. For the insurance sector, this is a particularly important point. Financial crime vulnerabilities can arise across the customer journey and through the distribution chain: onboarding, pricing, policy changes, claims, refunds, introducer arrangements, delegated authority, third-party administrators and outsourced service providers, to name a few. A meaningful risk assessment needs qualitative and quantitative input from underwriting, claims, finance, operations, compliance, financial crime, legal, data, procurement and the first line. Otherwise, it risks missing the points where fraud, sanctions evasion, bribery, money laundering or customer harm could emerge, making it near impossible to identify the controls that help manage these risks.
Why insurance firms need to strengthen risk assessments
Taking a risk-based approach (RBA) is a key tenet of financial crime risk management, enshrined in law and regulation, for example in the UK’s Corporate Criminal Offences regime, the FCA Handbook and the FCA’s overall supervisory approach. It enables firms to focus their finite resources where they are most needed, be that on higher risk customers/policyholders, third parties or transactions. The foundation of an RBA is a robust and regular financial crime risk assessment that provides insight into inherent risks of a firm’s activities, the effectiveness of its controls and the level of risk that remains.
Insurance firms may find they need to maintain multiple risk assessments to cover different financial crime risk areas. Though, the benefit of this approach is that firms can develop a consistent approach with more granular reporting that enables them to compare financial crime risk areas and across their business units in the UK and internationally.
Financial crime risk assessments should not operate in isolation from wider risk management activities. The same business model features that drive growth and efficiency (digital distribution, delegated authority, frictionless onboarding, automation, complex supply chains and data-led pricing) can also create financial crime exposures. As business activities and models evolve, risk assessments need to evolve alongside them.
How insurance firms can strengthen financial crime controls
Good practice involves making the risk assessment sustainable and repeatable over time, so it is more useful. That means bringing the right people into the process, challenging whether risks are described with enough specificity, linking risks to actual controls, assessing the effectiveness of these controls and then assigning clear owners and keeping actions visible until they are addressed. It also means using live indicators and data:
- Gross Written Premium (GWP) data by country.
- Customer risk or third-party ratings.
- Claims trends.
- Complaints.
- Suspicious activity.
- Policy cancellation patterns.
- Payment anomalies.
- Sanctions screening alerts.
- Broker or introducer performance.
- Whistleblowing reports.
- Internal audit findings.
Boards and senior managers will need to focus on gathering evidence to show the FCA that it understands its risk exposure:
- Can the firm explain why it considers certain risks higher or lower?
- Can it show how those risks differ by product, channel, geography, customer type or third-party relationship?
- Can it demonstrate that control weaknesses have been identified, owned and remediated?
- Can it evidence that the assessment has influenced risk appetite or investment decisions, training, monitoring and oversight and assurance activities?
The FCA’s review should be seen less as a narrow financial crime paper and more as a practical reminder that controls need to be embedded where risk arises. For insurance firms, a live, collaborative and business-owned risk assessment remains one of the clearest ways to show that financial crime risk is understood, managed and kept under review.
For more on financial crime risks in insurance, please contact Erin Sims or Peter Hawkins.