The FCA’s recent review of insurers’ financial crime controls highlights important findings for retail, wholesale, and life insurance firms. A selection of the largest firms were asked to submit documents in response to 38 questions across ten groups of financial crime controls.  

Overall, the regulator found that financial crime frameworks are generally in place but not always sufficiently embedded in practice. For insurers, the challenge is no longer designing controls but, instead demonstrating that they work in real-world risk across business units, products and third-party relationships. 

What sits behind the financial crime controls review findings

The regulator identified a familiar theme in its insurance review findings, in line with similar communications it has published of late. Although many firms have financial crime controls in place, they may not always be sufficiently tailored, evidenced or embedded in practice. The key question is therefore shifting from whether firms have frameworks in place to whether those frameworks genuinely reduce financial crime risk. 

As outlined in the findings, the risks facing a retail insurer, a wholesale intermediary and a life insurer may vary significantly, as will the products, customer relationships, distribution models and third-party arrangements that shape those risks. But five important priorities for all insurance firms to consider include: 

1. Grounding risk assessments in business reality

For insurers reviewing their financial crime controls, a risk assessment is only as strong as its connection to how the firm actually operates. When assessments are too high-level or generic, it becomes harder to demonstrate how controls mitigate specific risks. It’s therefore vital to be able to show how financial crime risk assessments reflect a firm’s operating model in practice. This includes considering how products are structured, how claims and payments flow, and where third parties sit within the chain.  

For example, the FCA’s review indicates that weaknesses can arise when risk assessments are insufficiently evidenced or tailored to specific parts of the business, making it harder to link risks to the controls that mitigate them. 

Ultimately, the effectiveness of financial crime controls depends on whether firms can explain why particular risks are relevant to them, plus how those risks vary across the business. It’s important to evidence those conclusions with a clear and defensible rationale.  

2. Making due diligence decisions clear and defensible

Due diligence is a key component of financial crime controls, often requiring judgment at the point of application. Where the underlying approach is not clearly defined, this can lead to variation in how controls are applied across the business. 

In parts of the insurance sector where inherent anti-money laundering (AML) risk may be lower, firms often take a more proportionate approach. The challenge then comes in demonstrating how that approach has been determined, how it is applied in practice and where the boundaries sit. For instance, the FCA’s findings highlight that where firms have not clearly documented their due diligence approach, it becomes harder to evidence why different levels of scrutiny are applied in different scenarios. 

Stronger financial crime controls in this area are typically those with an explicit rationale. That includes how customer risk is assessed, what level of due diligence is expected in different scenarios and what triggers further scrutiny or escalation.

3. Translating policy into operational financial crime controls

In insurance, a large number of departments can be involved in managing financial crime risk, from underwriting and claims, through to distribution and outsourced operations. So, it’s easy to see that without context-specific guidance there is a real risk that controls are applied inconsistently across a business. The FCA notes that while firms often have established policies and procedures in place, these are not always sufficiently supported by detailed guidance in specific areas. In turn, this can create gaps in how controls are applied.  

It’s therefore important for insurers to be able to demonstrate that their policies are supported by practical guidance explaining how controls operate in different scenarios. Alongside this, it’s pivotal to outline what evidence should be retained and at what points issues should be escalated. 

4. Strengthening governance and oversight of financial crime controls

Effective financial crime controls require a governance framework that demonstrates how oversight and accountability are maintained across a business.  

For insurers, this often involves multiple layers of responsibility, particularly when financial crime controls intersect with business units, legal entities or third-party arrangements. In these environments, the clarity of ownership becomes as important as the design of the controls themselves. The FCA particularly highlighted the importance of firms demonstrating how responsibilities are allocated and how oversight is exercised, rather than relying solely on high-level governance structures.  

A robust approach is to map financial crime obligations to specific controls and accountable owners, supported by management information (MI) that provides real visibility into performance.  

5. Treating third-party oversight as part of financial crime controls

Third parties often form an integral part of many insurance operating models. However, reliance on external providers still remains in the scope of a firm’s financial crime controls framework. 

When third parties are involved in activities that influence financial crime risk, the effectiveness of controls depends on how well the relationship is overseen. This includes how responsibilities are defined, what information is shared and how performance is monitored. For instance, the FCA’s review reinforces that firms remain responsible for their financial crime controls even when activities are outsourced, making it essential to evidence how oversight is applied in practice. 

This means recognising that not all third-party relationships present the same level of financial crime risk. Where exposure is higher, firms should be able to demonstrate closer oversight, clearer accountability and a more structured approach to identifying and escalating issues. 

A broader shift in expectations

Taken together, the regulator’s findings point to a consistent challenge across the insurance sector. Financial crime controls are generally established but they are not always tailored sufficiently or evidenced consistently across the business.  

An important next step for insurers is to reflect on how different elements of their financial crime risk framework connect. Risk assessments, due diligence, governance and third-party oversight often exist as individual components. Still, the FCA is increasingly keen to see how they operate as a whole – and whether firms can demonstrate that in practice.  

The immediate priority is not introducing new controls but testing existing ones to provide a true reflection of how firms currently operate. This includes whether decisions are clearly documented, if approaches are applied consistently and whether oversight is strong enough to identify and respond to issues as they emerge.  

Benefit from an independent perspective

TCC works with insurance firms to assess how financial crime controls operate across their full framework. We also support insurers through financial crime interim resourcing, providing external specialists who can embed within teams to strengthen controls, improve consistency and help evidence how frameworks operate.  

Get in touch today to discover how we can help your firm.