Skip to content Skip to footer

Insurance Brokers: Obligations Under the “ AML-CFT ” and the Orias Registry

In insurance distribution, the broker manages the initial contact, identifies the policyholder, and collects the necessary documents. The insurer holds the policy and bears the risk, as well as, if applicable, files the suspicious activity report. Between the two, anti-money laundering AML-CFT is never the responsibility of a single party.

Each party is responsible for its own compliance obligations before the regulator. The allocation of these obligations must be set forth in an agreement, and its implementation must be verified using a tool. An insurance intermediary that falls within the scope of regulated entities is subject to specific obligations regarding “ AML-CFT,” particularly with respect to identification, due diligence, record-keeping, and, where applicable, reporting of suspicious activity.

Its registration in the single registry does not cover enhanced due diligence, screening against sanctions lists, or identifying the beneficial owner of corporate clients. These obligations are governed by a separate compliance framework tailored to the professional’s activities and risks.

 

The broker is a fully-fledged taxpayer

Article L. 561-2 of the Monetary and Financial Code classifies insurance intermediaries as professionals subject to anti-money laundering and counter-terrorist financing regulations. Insurance intermediaries falling within the scope of Article L. 561-2 of the Monetary and Financial Code are subject to the obligations set forth at AML-CFT under the conditions provided for in the laws and regulations applicable to their activity.

A professional who connects a prospective client with an insurer must verify the policyholder’s identity and identify the beneficial owner of legal entities. The professional must also conduct a screening against sanctions lists and lists of politically exposed persons, and then maintain a time-stamped record of these due diligence procedures.

What Being an Intermediary Entails

Registration in the Orias registry allows for verification that an intermediary is registered to conduct the declared business and that it meets the eligibility requirements for that business applicable to its status. It does not cover risk classification, the enhanced due diligence procedure, or the ongoing monitoring mechanism. The broker must therefore establish a comprehensive compliance framework AML-CFT, tailored to the nature of the contracts it distributes and the profile of its client base.

A risk assessment must identify situations involving high exposure. These include, in particular, life insurance policies with flexible premium payments, beneficiaries designated late, cross-border transactions, and customers based in third countries identified as high-risk by the FATF.

What Is Not Covered by Registration in the Single Registry

The Single Registry of Insurance Intermediaries verifies professional licensing, but not compliance AML-CFT. A properly registered professional may be subject to an administrative enforcement measure or a sanction by the ACPR if they have not implemented the required due diligence procedures.

The Orias verification of a referral agent or representative is the responsibility of the network that connects them with its clients. However, it does not replace the individual screening of subscribers.

 

What the broker must verify, and when

Due diligence is not limited to the underwriting stage. It applies throughout the term of the policy; whenever a transaction alters the scope of the insured risk, the identity of the beneficiary, or the expected cash flows.

What the broker must verify, and when
 

A contract entered into under standard terms may become atypical as a result of a partial redemption that is inconsistent with the known profile. It may also become atypical due to the designation of a beneficiary residing in a jurisdiction subject to sanctions.

When a legal entity subscribes

When a legal entity enters into a contract, the broker must take the following steps:

  • identify the legal representative and verify the registration documents;
  • Identify the beneficial owner based on the criteria set forth in Article R. 561-1 of the Monetary and Financial Code ;
  • screen every individual who directly or indirectly holds more than 25 percent of the capital or voting rights;
  • time-stamp the audits and maintain a record of them for five years from the end of the business relationship.

If the ownership structure does not allow for the identification of a beneficial owner based on this threshold, the legal representative is deemed to be the beneficial owner. The screening process covers sanctions lists, embargo lists, and politically exposed persons.

During the term of the contract

Policy buyouts, policy amendments, changes in beneficiaries, and payments that appear inconsistent with the known profile are among the transactions most frequently reviewed. The intermediary must have a written procedure specifying when to resubmit an existing file for screening, who authorizes the continuation of the relationship, and the procedures for reporting information to the Tracfin correspondent in the event of suspicion.

Legacy portfolios can be a source of vulnerability when they contain outdated data, missing documents, or insufficiently documented due diligence.

 

Allocation of due diligence responsibilities with the risk-bearer

The distribution agreement sets forth the allocation of screening responsibilities, the frequency of screening, the procedures for retaining records, and the process for transmitting information. In practice, the distributor is in contact with the client and performs the initial identification, while the risk-bearer monitors the life of the contract and, if necessary, initiates the suspicious activity report.

This allocation depends on the applicable regulatory framework, whether it involves third-party referral, a mandate with or without delegation of management, or a presentation. It also varies depending on the degree of autonomy granted to the intermediary. The ACPR has published guidance on the AML-CFT issues applicable to insurance brokers, particularly regarding the allocation of due diligence responsibilities among the various distribution channels.

What the agreement must specify

In particular, the agreement should specify the following:

  • the party responsible for the initial screening and collection of supporting documents;
  • the person responsible for updating customer data and monitoring unusual transactions;
  • the person responsible for triggering the suspicious activity report and the escalation process in the event of a positive match;
  • the frequency of customer data updates and the time it takes to transmit documents between the distributor and the risk-bearer.

An unspoken agreement on these points leads each party to assume that the other has carried out the necessary checks. This creates a gray area that hinders the traceability and management of the system.

The Risk of the Gray Area

When the division of responsibilities remains implicit, each party may assume that the other has carried out the necessary checks. Shared vigilance does not mean diluted vigilance. Each party remains responsible to the regulator for its own due diligence, and the absence of a written agreement does not constitute a mitigating factor in the event of a breach.

ACPR inspections regularly focus on the consistency between the provisions of the agreement and the due diligence procedures actually documented in client files. Adjust the level of vigilance to the relationship therefore requires that this allocation be in writing, dated, and accessible to staff who interact with customers.

 

The Orias Verification as Part of the Compliance Process

The single registry of intermediaries makes it possible to verify that a professional is duly authorized to practice. This verification applies to brokers in their dealings with their referral agents and agents, as well as to risk carriers with regard to their distribution networks.

When automated as part of the screening process rather than handled separately, the Orias verification becomes part of the file’s record rather than a one-time check. It is then integrated into a consistent and traceable compliance process.

Verify the authorization of your contributors

A broker who works with business introducers or agents must verify their registration with the Orias registry before entrusting them with a client file. An expired, suspended, or revoked registration constitutes an anomaly that must be detected and addressed to prevent a professional from continuing to engage in an activity for which they no longer have the required authorization.

Manual verification on the Orias website is still possible for a limited number of contacts. However, once the number of active representatives exceeds a few dozen, this ad hoc verification becomes impractical.

Automate rather than punctuate

Incorporating the Orias verification into the screening process allows security clearance to be treated as just one piece of compliance data among others. It is then updated with each transaction, rather than being checked once a year.

AP Scan integrates Orias screening and validation into its engine, so that each file retains a time-stamped record of the credentials of the professional who processed it. Automation does not replace the network’s responsibility. It provides the network with the means to track its checks and respond as soon as an anomaly arises.

 

What the audit examines in a broker

The ACPR verifies that there is a risk classification system appropriate to the nature of the contracts distributed, that customer data in legacy portfolios is up to date, and that there is a time-stamped record of the screenings performed. It also reviews the written rationale for rejected correspondence and the process for reporting suspicious activity.

What the audit examines in a broker
 

Portfolios established several years ago are the most common source of vulnerability. The ACPR verifies that the financial professional has a remediation procedure in place, has identified incomplete files, and has scheduled their update.

The points typically reviewed

During an inspection, the ACPR reviews the following items, among others:

  • risk mapping and written vigilance procedures;
  • training for staff who interact with customers and the role of the Tracfin liaison officer ;
  • the quality of the internal control system;
  • Coverage, through screening tools, of international sanctions lists, politically exposed persons, and high-risk third countries as defined by the FATF.

The screening tool must ensure adequate coverage of the sanctions and asset freeze measures applicable to the professional’s business activities. Depending on the professional’s geographic exposure and activities, the system may also incorporate other relevant sources. Coverage of relevant sources is therefore an essential criterion for evaluating the system.

Legacy portfolios: a vulnerability

A file opened in 2018 in accordance with the standards in effect at that time may no longer meet current requirements. It may contain an expired identification document, a beneficial owner who has not been identified, or a screening that is either missing or not time-stamped. The professional must identify these files, assess the level of residual risk, and schedule corrective actions according to a documented timeline.

For a large portfolio, remediation may require a phased rollout. In such cases, it must be based on a documented plan that includes priorities and a timeline that takes into account the risk level of the cases involved.

 

Enhancing vigilance without slowing down production

Screening, Orias verification, monitoring of atypical transactions, and document retention are repetitive tasks that lend themselves to automation. A well-equipped system does not reduce a professional’s responsibility. It gives them the means to track their due diligence and focus their time on high-stakes cases.

AP Scan enables the integration of AML-CFT screening, Orias validation, and beneficial owner searches into a single interface. Positive matches are displayed along with their relevance score and the reason for the alert, which reduces analysis time while leaving the final decision to the compliance analyst.

A brokerage network equipped can process tens of thousands of verifications per year with a small compliance team. This processing capacity makes it possible to handle high volumes without compromising the traceability of the checks.

What Can Be Usefully Automated

Several operations can be effectively automated:

  • screening against sanctions lists, embargo lists, and lists of politically exposed persons;
  • verification of the registration of contributors and agents in the ORIAS registry;
  • detection of atypical transactions based on configurable rules;
  • the creation of the vigilance file, with a timestamp for each step.

Automation does not eliminate the need to train staff or designate a Tracfin liaison officer. It helps ensure that the system is traceable and auditable—two aspects that may be examined during an ACPR audit. An explainable engine also makes it easier to document and justify the handling of alerts.

The fraud challenges specific to the insurance industry underscore the value of explainable automation. A Glass Box engine makes it possible to justify each alert to the regulator.

 

Frequently Asked Questions

Is an insurance broker subject to the obligations set forth in the “ AML-CFT  ”?

Yes. Insurance brokers and intermediaries are fully regulated professionals. Acting as an intermediary does not mean delegating compliance responsibilities to the risk bearer.

The broker must identify the policyholder, determine the beneficial owner of legal entities, and screen them against sanctions lists and lists of politically exposed persons. The broker must also maintain a record of these due diligence efforts.

Who verifies what between the broker and the insurer?

The division of responsibilities depends on the distribution agreement, and that is precisely where the risk lies. When it remains implicit, each party may assume that the other has carried out the necessary checks. The agreement should specify who performs the screening, how often, who retains the documents, and how the information is transmitted.

In practice, the distributor interacts with the customer and performs the initial identification. The risk-bearing entity monitors the contract’s status and, if necessary, files a suspicious activity report.

Which aspects of the contract require special attention?

Policy buyouts, policy amendments, changes in beneficiaries, and payments that appear inconsistent with the policyholder’s known profile are among the transactions most frequently reviewed. Vigilance does not end at the time of purchase.

A contract entered into under ordinary terms may become atypical due to its outcome or the person designated as the beneficiary. Any significant change in the contract must therefore be evaluated in light of its known profile.

What is the purpose of the Orias verification in a " AML-CFT " system?

The single registry of intermediaries makes it possible to verify that a professional is duly authorized to practice. This verification applies to brokers in their dealings with their referral agents and agents, as well as to risk carriers with regard to their distribution networks.

When automated as part of the screening process rather than handled separately, the Orias verification becomes part of the case file rather than a one-time check. It thus contributes to the overall traceability of the system.

What does an audit of an insurance broker involve?

An audit typically examines whether the risk classification is appropriate for the nature of the distributed contracts and whether customer data in legacy portfolios is up to date. It also verifies the time-stamped record of the screenings performed, the written rationale for rejected correspondence, and the process for escalating suspicious activity.

Portfolios established several years ago represent the most common point of vulnerability. They must be addressed through a documented remediation plan, with priorities set based on risk level.