5 crucial AML signs you can learn from your existing underwriting data
Like many accountable industries, insurance houses are spending big on their anti-fincrime tools. But heavy resourcing is only half of the story; it is AML effectiveness that counts, particularly at the underwriting stage where risk should first be caught. Even though South African life insurers and investment companies are actively preventing financial crime, some R131.6 million is still lost to criminals. Why is that?
Typically, insurers’ defense systems against AML and fraud teams can be split across varying systems and workflows and report to different managerial staff. Where AML and transaction monitoring sit with compliance, fraud sits with underwriting and claims teams. This separation then grows depending on the maturity of a firm’s digital systems and volumes of data. We see a similar scenario play out at financial institutions.
However, when data maturity is achieved and AML processes are integrated, red flags can be found immediately. In this article, we will look at how to consistently spot concrete evidence of wrongdoing at insurers and why it’s often living in existing underwriting files and payment pattern histories.

Insurance’s unique risk environment
Both insurers and banks are accountable institutions under Schedule 1 of the Financial Intelligence Centre Act (FICA), although insurance creates an entirely different risk proposition.
As part of complex intermediary and third-party webs, as well as domestic or cross-level financial groups (as outlined by FATF), insurance’s sector-specific instruments welcome criminal typologies that banks’ user-set transaction monitoring alerts may miss: single-premium life policies; excessive lump-sum claims; products designed for high-net-worth individuals; and switched beneficiaries.
This validates insurance’s need for bespoke risk-based approaches that can discover unique threats hiding within the underwriting process.
Five underwriting red flags
When underwriting already evaluates client risk to verify any insurable interest, it shares DNA with AML: necessary due diligence to investigate every potential customer’s legal identity, policy intent, sources of funds, and relationships.
The difficulty following this initial underwriting stage is to maintain compliance oversight for changing risk profiles – where any suspicious customer activity gets identified through the continuous screening and monitoring of underwriting files and transactions, including:

1. Beneficiary changes at significant claim events
At pivotal moments in an insurance policy’s lifecycle, such as its maturity date, criminals may attempt to substitute beneficiary details. Newly added or amended beneficiaries often have no clear or legitimate connection to the policy, making them suitable candidates for enhanced due diligence.
2. Uncharacteristic premium payments
In instances where a client exhibits unusual behaviours – including hefty premium overpayments or unexpected third-party funding – a mismatched customer profile may be indicative of staggered laundering activity. Sudden lump-sum insurance payouts are commonly exploited to turn illicit funds into ‘clean’ income.
3. Easily-accepted surrenders
While legitimate customers may surrender policies for valid reasons, repeated early surrenders or a willingness to absorb significant penalties without clear justification can be a warning sign.
4. Inconsistent claim patterns against underwritten risk
Insurance underwriters should be able to monitor recurring claim patterns according to risk: the rates with which they historically receive, process, and pay out claims to policyholders. Common signals of ‘staged’ fraud involve claims being filed shortly after the policy’s inception, manipulating costs to match maximum policy limits for huge payouts, or rare round-number claim totals – all indicative of high-risk fraudsters using the insurer for their own gain.
5. Anomalies within intermediaries
Insurance agents can provide services to facilitate criminality knowingly or unwittingly. Indicators of suspicious behaviour include a single broker driving quick, high-value fund flows, premiums being paid through unknown or risky jurisdictions, and spikes in premium payments without any logical personal justification. Such alerts indicate the necessity for thorough Know Your Customer (KYC) checks during the underwriting process – the first integral stage of an end-to-end AML process.
Closing the integration gap
Firms with great digital maturity are leading the way, in that their richly detailed and centralised filings can be used to drive AML and fraud intelligence and tools. Such aforementioned risk signals can then be detected at the underwriting stage, rather than in retrospect. If underwriting data is not currently being read for these unique AML risk alerts, the likelihood is that insurance firms are falling behind in their compliance requirements.
So, there’s also a cultural divide that still must be bridged. Knowing how to spot and escalate risky AML and fraud typologies need to be understood by insurers’ compliance, underwriting, legal, and executive teams, using the same language and under the same framework, with particular focus granted to the Insurance Act’s prudential standards. This compliance-first mindset should promote greater information sharing too, between insurance groups and the nation’s private and public sectors.
Crafting a leading AML compliance culture and process is no mean feat – but it can be simplified by partnering with regulatory technology providers. Integrating with a single automated solution can align once-siloed governance, expertise, entity resolution, and transactional data for practical AML that works in real-time. That way, the insurance world that relies on trust and integrity can continue as such whenever onboarding new customers, safe from the growing manipulative threat of opportunistic criminals – who will find insurance companies a far tougher ‘way in’ to clean their dirty cash.