12.3 Financial Crime, Money Laundering and Fraud
Key Takeaways
- Money laundering has three stages: placement (introducing criminal property into the financial system), layering (obscuring its source through complex transactions), and integration (returning it as apparently legitimate wealth)
- The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR 2017) require customer due diligence, ongoing monitoring, and suspicious activity reports to the National Crime Agency; JMLSG guidance sets industry standards
- Insurance — particularly single-premium life and investment products — is vulnerable to money laundering because criminals can place large sums with insurers and later surrender policies for apparently legitimate proceeds
- The Bribery Act 2010 creates offences of bribing, being bribed, bribing foreign officials, and a strict liability corporate offence of failing to prevent bribery; sanctions are enforced through the Office of Financial Sanctions Implementation (OFSI)
- Insurance fraud divides into application fraud and claims fraud, and is tackled through the Insurance Fraud Bureau, the Insurance Fraud Enforcement Department and the industry-wide Insurance Fraud Register
Money Laundering — The Three Stages
Money laundering is the process by which criminals convert the proceeds of crime ("criminal property") into apparently legitimate funds, goods or services. The Proceeds of Crime Act 2002 (POCA 2002) is the principal criminal statute, defining the principal money-laundering offences. The process is conventionally described in three stages:
| Stage | What happens | Insurance example |
|---|---|---|
| 1. Placement | Criminal property is introduced into the financial system. | Cash paid into a bank account, or used to buy a single-premium life policy. |
| 2. Layering | The source is obscured through complex, often cross-border, transactions. | The policy is switched, partially surrendered, or moved between funds and jurisdictions. |
| 3. Integration | The property re-enters the economy as apparently legitimate wealth. | The policy is surrendered and the proceeds used to buy property or other assets. |
Quick Answer: The three stages of money laundering are placement, layering and integration. Insurance is vulnerable because a single-premium life or investment policy can absorb a large up-front sum (placement), be moved around (layering), and then be surrendered for apparently clean proceeds (integration).
The MLR 2017 and the Regulatory Framework
The principal secondary legislation is the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR 2017), which replaced the 2007 regulations and assimilated the EU's Fourth and Fifth Money Laundering Directives. The MLR 2017 applies to firms in the regulated sector, including insurers and insurance intermediaries when carrying on in-scope business. The regulator for anti-money laundering (AML) purposes depends on the firm: the FCA supervises insurers and most financial firms; HMRC and the Gambling Commission supervise other sectors.
The MLR 2017 imposes a framework of obligations built around risk assessment, customer due diligence (CDD), ongoing monitoring, record-keeping, training, and reporting.
Customer Due Diligence (CDD)
Firms must apply customer due diligence (CDD) when establishing a business relationship, carrying out an occasional transaction above relevant thresholds, or suspecting money laundering. CDD means identifying the customer and verifying that identity using reliable, independent source documents; identifying the beneficial owner (where the customer is not an individual) and taking reasonable measures to verify their identity; and obtaining information on the purpose and intended nature of the relationship. Enhanced due diligence (EDD) is required for higher-risk situations — for example, customers in higher-risk jurisdictions, politically exposed persons (PEPs), and any situation where there is a higher risk of money laundering. Simplified due diligence (SDD) is permitted only in defined lower-risk cases.
Ongoing Monitoring
Firms must conduct ongoing monitoring of the business relationship — scrutinising transactions throughout the relationship to ensure they are consistent with the firm's knowledge of the customer, its business and its risk profile. Where information becomes available that changes the risk picture, the firm must update its CDD.
Suspicious Activity Reports (SARs)
Where a firm knows or suspects that a person is engaged in money laundering, it must make a suspicious activity report (SAR) to the National Crime Agency (NCA). The firm must also obtain consent from the NCA before proceeding with a transaction where the transaction itself is the subject of the suspicion (a "prohibited act" under POCA). Making a SAR in good faith provides a defence against the principal money-laundering offences. Tipping off — telling the customer that a SAR has been made — is itself a criminal offence under POCA, and staff must be trained not to do it.
JMLSG Guidance
The Joint Money Laundering Steering Group (JMLSG) publishes industry guidance that sets out how firms in the financial sector should comply with the MLR 2017. JMLSG guidance is not legislation, but it is widely treated as the industry standard; the FCA expects firms to follow it, and departing from it without good reason is hard to justify. For insurance, the JMLSG guidance addresses single-premium life business, regular-premium policies, and the specific risks around long-term insurance products.
Why Insurance Is Vulnerable
Insurance — and especially single-premium life and investment-linked products — is attractive to money launderers because a large up-front premium can be placed with an insurer, the policy can be held for a relatively short period, and the surrender value can then be drawn down as an apparently legitimate payment from a regulated insurer. The risks are lower in general insurance (where premiums are smaller and the policy does not return value to the policyholder beyond an indemnity), which is why much of the AML focus in insurance is on life and investment business. Insurers and intermediaries must therefore apply CDD on single-premium business, monitor for red flags (for example, a customer who is unusually keen to pay in cash, or who wants to surrender a policy very shortly after taking it out), and report suspicious activity to the NCA.
Sanctions and the Bribery Act 2010
Financial sanctions are restrictions imposed by the UK government (often through the Office of Financial Sanctions Implementation (OFSI) in HM Treasury) on individuals, entities and countries. Insurers and brokers must screen customers and beneficiaries against the UK sanctions list and must not provide cover, pay claims, or handle funds for a designated person without an OFSI licence. Breach of financial sanctions is a criminal offence and can attract significant penalties, including asset freezing.
The Bribery Act 2010 creates four offences:
- Bribing another person (active bribery).
- Being bribed (receiving a bribe).
- Bribing a foreign public official to obtain or retain business or an advantage.
- Failing to prevent bribery — a strict liability corporate offence: a commercial organisation is liable if a person associated with it bribes another person to obtain or retain business for the organisation, unless the organisation can show it had adequate procedures in place to prevent bribery.
For insurers and brokers, the failing-to-prevent offence is the most demanding: firms must design and maintain adequate procedures — proportionate risk assessments, top-level commitment, due diligence on associated persons, clear policies, training, and monitoring — and be able to demonstrate them.
Insurance Fraud and the IFB
Insurance fraud is a major financial-crime issue for the industry. It falls broadly into two types:
- Application fraud — dishonest information given at proposal stage (for example, failing to disclose previous claims, or understating a young driver's use of a car) to obtain cheaper cover.
- Claims fraud — dishonest claims, including staged or invented accidents, exaggerated personal injury claims, and "crash for cash" motor schemes.
The Insurance Fraud Bureau (IFB) is a not-for-profit organisation set up by the UK insurance industry to detect and disrupt insurance fraud, particularly organised fraud rings. Insurers share data with the IFB, which uses analytics to spot patterns across multiple insurers that no single insurer would see. The Insurance Fraud Enforcement Department (IFED) is a specialist police unit, funded by the insurance industry, that investigates and prosecutes insurance fraud. The Insurance Fraud Register (IFR) is an industry-wide database of confirmed fraudsters. ICOBS and the Public Interest Disclosure Act underpin the regulatory and whistleblowing framework around fraud.
Key Takeaways
- Money laundering has three stages — placement, layering and integration — and insurance (especially single-premium life and investment products) is vulnerable because large sums can be placed, moved, and surrendered for apparently legitimate proceeds.
- The MLR 2017 require customer due diligence (CDD), ongoing monitoring, record-keeping, training, and suspicious activity reports (SARs) to the National Crime Agency (NCA); JMLSG guidance sets the industry standard, and tipping off is a criminal offence under POCA.
- The Bribery Act 2010 creates offences of bribing, being bribed, bribing a foreign public official, and a strict liability corporate offence of failing to prevent bribery (defended by showing adequate procedures); financial sanctions are enforced by OFSI.
- Insurance fraud includes application fraud and claims fraud; the Insurance Fraud Bureau (IFB), the Insurance Fraud Enforcement Department (IFED), and the Insurance Fraud Register (IFR) support detection and enforcement.
- Suspicious activity reports (SARs) go to the National Crime Agency, and a firm must obtain NCA consent before proceeding with a transaction that is itself the subject of the suspicion.
A customer takes out a single-premium life insurance policy paying a large cash premium, asks to switch the underlying funds three times in the first six months, and then requests that the policy be surrendered and the proceeds transferred to an offshore account. Which of the following best describes the money-laundering risk and the firm's response?
Under the Bribery Act 2010, a commercial organisation can be guilty of the offence of failing to prevent bribery by a person associated with it. Which of the following is the recognised statutory defence?