The European Union's Anti-Money Laundering Authority began operations in July 2025, and the single rulebook takes effect in July 2027. For insurers, this timeline highlights a critical issue: your anti-money-laundering obligations focus on life and annuity products, while your sanctions obligations cover every line you underwrite, including property, casualty, health, marine, and specialty. This gap is where your exposure lies.
Regulatory Shifts Impacting Compliance
Three major regulatory changes have made insurance compliance more complex:
Regulatory consolidation in the EU. The Anti-Money Laundering Authority took over the European Banking Authority's AML and counter-terrorist financing mandate in January 2026. Direct supervision of high-risk entities starts in 2028, and the Authority is now publishing technical standards to define compliance under the new regime.
Divergence across sanctions regimes. The United States, the European Union, and the United Kingdom are expanding their sanctions programs at different rates and with varying details. A counterparty or transaction allowed under one regime might be restricted under another, and this gap is widening.
Strict liability on sanctions. The Office of Foreign Assets Control enforces sanctions on a strict-liability basis for all US-domiciled insurers, regardless of the products they sell. Violations can occur without intent or knowledge, meaning every line of business carries sanctions exposure, even if it falls outside the Bank Secrecy Act program requirement.
Key Findings
Mismatch between AML and sanctions obligations. In the United States, anti-money-laundering obligations apply on a product basis. You're covered when issuing permanent life insurance, annuities, or products with cash value or investment features. You're not covered when issuing property, casualty, health, or term products without those features. However, sanctions compliance is mandatory for every US-domiciled insurer, regardless of product mix.
High sanctions exposure in low AML risk lines. Marine insurance, largely outside the AML/CFT Framework requirement, carries significant sanctions exposure related to vessels, ownership, routes, and cargo. Cyber insurance, also outside the program, exposes you to sanctioned parties through ransomware payments. Reinsurance isn't a customer-facing covered product, but your exposure runs deep through cedants, brokers, and ownership chains. Focus your screening efforts where sanctions exposure is highest, not where the AML/CFT Framework applies.
Static screening configurations create risks. Designations, rule changes, and guidance are continuous. An annual risk assessment and fixed screening configuration mean you're operating on outdated parameters between updates. These gaps increase enforcement risk, counterparty risk, and operational disruption.
Counterparties monitor enforcement actions. Banks and reinsurers consider your financial-crime control quality in their decisions. Weak controls can lead to the loss or repricing of these relationships. The Financial Action Task Force has warned against over-de-risking, but your compliance posture still affects your access to counterparties.
Implications for Your Team
If you're a sanctions analyst at a multi-line insurer, you're screening across lines with varying data quality, transaction volumes, and exposure profiles. A life insurance onboarding process provides structured customer data. A marine claim offers free-text vessel descriptions and aliases. A cyber claim might give you a payment destination with minimal context. Your screening workflow must adapt to the data you receive.
If you're managing sanctions compliance at a US insurer issuing only property and casualty products, you're outside the Bank Secrecy Act anti-money-laundering program requirement but still fully exposed to OFAC. Your sanctions screening program must be resourced and supervised independently of any AML/CFT Framework obligation, as the regulatory basis differs.
If you're preparing for the EU's single rulebook, you have until July 2027 before substantive rules apply. This is your window to align your controls with the technical standards and guidelines being published now, before direct supervision begins in 2028.
Action Steps
Map your sanctions exposure by line of business. Create a table showing where sanctions exposure concentrates across your book: life and annuities, property and casualty, health, reinsurance, marine, and specialty lines. Identify screening points (onboarding, claims, payouts, beneficiary changes, third-party vendors) and the data quality at each point. This map will guide resource allocation and data capture improvements.
Separate your sanctions program from your AML/CFT Framework. If you're a US insurer issuing only non-covered products, document that your sanctions program operates independently of the Bank Secrecy Act framework. Assign clear ownership, define escalation paths, and resource the program based on your sanctions exposure, not your AML/CFT Framework scope. OFAC enforces on a strict-liability basis, so the absence of an AML/CFT Framework obligation doesn't reduce your sanctions compliance requirement.
Tune your screening configuration by line. A single screening threshold across all lines can lead to too many false positives or misses. Set thresholds and matching rules by line based on data quality and exposure profile. Marine insurance may require looser matching on vessel names and ownership aliases. Life insurance may require tighter matching on structured customer data. Reinsurance may require look-through screening across multiple counterparty layers.
Review your EU timeline if you operate in the bloc. The Anti-Money Laundering Authority's technical standards and guidelines are being published now. Assign someone to track them, assess the gap between your current controls and the new requirements, and build a remediation plan with milestones through mid-2027. If you're a high-risk entity that may fall under direct supervision in 2028, prioritize governance documentation and control testing.
Test your counterparty screening depth. Reinsurance and correspondent relationships expose you to sanctions risk through cedants, brokers, and ownership chains. Define how many layers deep you screen, what data sources you use, and when you refresh. If you rely on counterparties to screen their own chains, document what assurance you receive and how often you validate it.



