Skip to content
eQomply
  • Platform

    Platform

    • Governance
    • Risk Management
    • Compliance Management
    • Integrations
    0 +

    Evidences Tracked

    0 +

    Regulatory Workflows

  • GRC Solutions

    By Role

    • For Compliance Leaders
    • For Chief Risk Officers
    • For Data Protection Officers
    • For CISOs
    • For Internal Audit Teams

    by industry

    • Banks & NBFCs
    • Insurance
    • Capital Markets
    • Pharma & Healthcare
    • More..

    by regulations

    • RBI Compliance
    • SEBI Compliance
    • IRDAI Compliance
    • DPDP Act
    • More..

    Featured Resource

    • Compliance Documentation Best Practices
    • IRDAI AML Compliance for Insurers Explained
  • Resources
  • Company
eQomply
Request Demo
IRDAI Compliance

IRDAI AML Compliance for Insurers Explained

July 20, 2026 Pritesh Baviskar No comments yet

Insurance companies in India operate under a dual AML framework that demands attention to both the Prevention of Money Laundering Act (PMLA) 2002 and IRDAI’s specific guidelines on anti-money laundering. IRDAI AML compliance for insurance is not a peripheral regulatory concern. It sits at the core of how insurers onboard customers, process claims, manage surrenders, and report to the Financial Intelligence Unit (FIU-IND). Yet the insurance sector continues to see enforcement actions and inspection findings that suggest structural gaps in how companies implement these requirements.

This post breaks down the AML framework applicable to insurance companies, the specific obligations around customer due diligence, transaction monitoring, reporting, and record-keeping, and identifies where most insurers fall short during regulatory inspections.

The AML Framework for Insurance: IRDAI Guidelines and PMLA

The foundational legislation is the PMLA 2002, which designates insurance companies as “reporting entities” under Section 2(1)(wa). This means life insurance companies, general insurance companies, and health insurance companies are all obligated to maintain records, verify customer identity, and report specified transactions to FIU-IND.

Layered on top of PMLA is IRDAI’s Master Circular on Anti-Money Laundering and Counter Financing of Terrorism (AML/CFT), which was most recently updated to align with FATF recommendations and the evolving domestic regulatory landscape. The circular provides sector-specific guidance that goes beyond what PMLA alone prescribes, particularly around risk categorization of products, customers, and distribution channels.

Key Regulatory Instruments

Instrument Applicable To Key Obligations
PMLA 2002 (as amended) All insurance companies CDD, record-keeping, STR/CTR filing
PML Rules 2005 (as amended 2023) All reporting entities KYC procedures, beneficial ownership identification
IRDAI AML/CFT Master Circular Life, general, health insurers Risk-based approach, product risk assessment, agent training
FIU-IND Guidelines All reporting entities Filing formats, timelines, quality of reports
IRDAI Corporate Governance Guidelines All insurers Board-level AML oversight, Principal Officer appointment

The interplay between these instruments creates a compliance architecture where the insurer must satisfy both the letter of PMLA and the spirit of IRDAI’s risk-based expectations. Consider a life insurance company that writes single-premium policies with high surrender values. Under PMLA, the basic KYC obligations apply. Under IRDAI’s guidelines, this product category itself demands enhanced scrutiny because of its inherent vulnerability to layering of illicit funds.

Customer Due Diligence for Policyholders

CDD in the insurance context extends beyond the point of sale. It covers the proposer, the life assured (where different), the beneficial owner, the nominee, and in some cases, the assignee. The PML Rules mandate identification and verification of customers using officially valid documents, but IRDAI’s framework adds layers of expectation around ongoing monitoring and risk-based categorization.

Risk Categorization of Customers

IRDAI expects insurers to classify customers into low, medium, and high-risk categories based on defined parameters. These include the customer’s occupation, source of funds, geographic location, political exposure, and the nature of the insurance product being purchased. A salaried individual buying a term plan through an employer group scheme presents a different risk profile compared to a walk-in customer purchasing a single-premium endowment policy with cash payment.

The risk categorization must be documented, periodically reviewed, and reflected in the level of due diligence applied. Enhanced Due Diligence (EDD) triggers include customers from high-risk jurisdictions, politically exposed persons (PEPs), and cases where the source of funds is not readily verifiable.

Beneficial Ownership Identification

For policies taken by companies, trusts, or other legal entities, the insurer must identify the ultimate beneficial owner, defined as the natural person who ultimately owns or controls the policyholder entity. The 2023 amendments to PML Rules tightened the threshold for identifying beneficial owners to 10% for unlisted companies (from the earlier 25%), which has significant implications for group insurance and corporate-purchased policies.

Where insurance is purchased through agents or intermediaries, the insurer cannot delegate its CDD obligations. The IRDAI Master Circular explicitly states that while intermediaries may assist in collecting documents, the responsibility for verification and risk assessment remains with the insurer.

Suspicious Transaction Identification in Insurance

Identifying suspicious transactions in insurance requires understanding the specific typologies relevant to the sector. Unlike banking, where transaction patterns are high-frequency and easily monitored, insurance transactions are episodic: premium payments, policy changes, surrenders, claims, and assignments occur at irregular intervals. This makes rule-based automated monitoring more challenging to calibrate.

Insurance-Specific Red Flags

IRDAI’s guidelines and FATF’s sectoral guidance identify several indicators that should trigger enhanced scrutiny. Early surrender of policies at a loss, particularly within the first few years when surrender values are low, may indicate that the customer is using the policy purely as a vehicle for moving funds through a legitimate financial institution. Similarly, repeated free-look cancellations followed by new policy purchases with different payment modes suggest potential structuring.

Other red flags include disproportionate premium amounts relative to the customer’s declared income, reluctance to provide source of funds information, requests for refunds to third-party accounts, overpayment of premiums followed by refund requests, and frequent changes in beneficiary or nominee designations without clear rationale.

Consider a scenario where a customer purchases multiple ULIPs across different branches of the same insurer, pays premiums in cash just below the CTR threshold of Rs. 10 lakhs, and then surrenders them within two years. Each transaction individually may not trigger alerts, but the pattern across the customer’s portfolio indicates potential money laundering through structuring and layering.

Building an Effective Transaction Monitoring Framework

IRDAI expects insurers to have systems that can aggregate transactions across products and channels for a single customer identity. This is where many insurers struggle. Legacy policy administration systems were not designed with AML monitoring in mind, and customer data often exists in silos across life, health, and general insurance subsidiaries within the same group.

An effective monitoring framework connects policy issuance data, premium payment patterns, policy servicing requests, claims data, and surrender/withdrawal activity into a consolidated customer view. This consolidated view then needs to be assessed against defined rules and scenarios. Platforms like eQomply help insurers structure this compliance monitoring by providing unified risk registers and compliance workflows that connect regulatory requirements to operational controls, ensuring that AML obligations are tracked with the same rigor as other IRDAI compliance mandates.

Reporting Obligations: STR and CTR Filing

Insurance companies must file three types of reports with FIU-IND: Suspicious Transaction Reports (STRs), Cash Transaction Reports (CTRs), and Counterfeit Currency Reports (CCRs, where applicable). The filing obligations are non-negotiable and carry strict timelines.

Cash Transaction Reports

CTRs must be filed for all cash transactions exceeding Rs. 10 lakhs (or equivalent in foreign currency) within a month. The report must be filed with FIU-IND by the 15th of the succeeding month. For insurance, this commonly arises from cash premium payments, particularly for single-premium policies or high-value renewal payments made in cash.

Insurers must also report all series of integrally connected cash transactions within a month that individually fall below Rs. 10 lakhs but aggregate to Rs. 10 lakhs or more. This “structuring detection” obligation requires the insurer to maintain systems that can identify such patterns, which is operationally challenging when premium collections happen through multiple channels including agents, bancassurance partners, and branch offices.

Suspicious Transaction Reports

STRs must be filed within seven working days of the Principal Officer arriving at a conclusion that a transaction is suspicious. There is no monetary threshold for STRs. A transaction of any value can be reported if it gives rise to reasonable grounds of suspicion regarding money laundering or terrorist financing.

The quality of STRs matters significantly. FIU-IND has repeatedly communicated that “defensive filing” (reporting transactions simply to avoid regulatory action without genuine suspicion) dilutes the effectiveness of the STR regime. Each STR must contain a clear narrative explaining the basis of suspicion, the customer’s profile, the transaction details, and why the transaction appears inconsistent with the customer’s known profile.

Filing Quality and Timeliness

Report Type Threshold Filing Deadline Common Deficiency
CTR Rs. 10 lakhs (cash) 15th of succeeding month Failure to capture aggregated transactions
STR No threshold 7 working days from conclusion Delayed escalation from branches to Principal Officer
CCR All instances 15th of succeeding month Non-reporting from branch offices
NTR (Non-Profit Org) As specified 15th of succeeding month Incomplete beneficial ownership details

Record-Keeping Requirements Under PMLA

Section 12 of PMLA mandates that reporting entities maintain records of all transactions for a period of five years from the date of the transaction. For identity records, the retention period is five years after the business relationship has ended, which in insurance terms means five years after the policy matures, lapses, is surrendered, or the claim is settled.

IRDAI’s AML guidelines elaborate on what “records” means in the insurance context. This includes the application form and all KYC documents, records of premium payments (mode, amount, source), policy servicing records (endorsements, assignments, nominations), correspondence related to claims, surrender documentation, and any internal suspicious activity reports or escalations, even if they did not ultimately result in an STR filing to FIU-IND.

Digital Record Maintenance

With the shift toward digital onboarding and e-KYC, insurers must ensure that electronic records carry the same evidentiary value as physical documents. The Information Technology Act 2000 provisions on electronic records apply here. Records must be maintained in a manner that allows reproduction in hard copy, ensures integrity and authenticity, and permits retrieval within reasonable timelines when requested by regulators or law enforcement.

This is where many insurers face practical challenges. Policies sold through digital channels ten years ago may have been stored in systems that have since been decommissioned or migrated. Ensuring continuity of records across system migrations, while maintaining an audit trail of any changes, requires deliberate design of the records management architecture. Using a compliance management platform that maintains evidence trails and document versions, such as eQomply, helps insurers demonstrate to IRDAI that their record-keeping obligations are being met systematically rather than through ad hoc processes.

Common Gaps Found During IRDAI Inspections

IRDAI’s inspection reports and enforcement orders reveal recurring themes in AML compliance deficiencies across the insurance sector. Understanding these patterns helps compliance teams prioritize their remediation efforts.

Inadequate Board-Level Oversight

IRDAI expects the Board of Directors to approve the AML/CFT policy, review its implementation at least annually, and ensure that the Principal Officer has adequate resources and authority. Inspection findings frequently note that Board discussions on AML are perfunctory, limited to noting compliance reports without substantive engagement on risk trends, new typologies, or adequacy of the monitoring framework.

Weak Customer Risk Profiling

Many insurers have a risk categorization framework on paper but fail to operationalize it. Inspectors find that the majority of customers are categorized as “low risk” without genuine assessment, that risk categories are never updated during the policy lifecycle, and that enhanced due diligence for high-risk customers is indistinguishable from standard CDD in practice.

Distribution Channel Gaps

Insurance is sold through agents, brokers, corporate agents, bancassurance, and direct channels. AML training and awareness often does not reach the distribution network effectively. Agents, who are the first point of contact with customers and best positioned to identify red flags, frequently lack the training to recognize suspicious indicators or the escalation pathways to report them.

Delayed STR Filing

The seven-day clock for STR filing starts from when the Principal Officer reaches a conclusion on suspicion. Inspections reveal that the internal escalation process, from branch or underwriting team to the AML team to the Principal Officer, often takes weeks or months. This gap between detection and reporting is a consistent finding that results in regulatory censure.

Absence of Independent Testing

IRDAI expects an independent audit or testing of the AML/CFT framework at least annually. Many insurers either do not conduct this testing or conduct it as part of a general internal audit without the specialized expertise needed to assess AML controls. The testing should cover the effectiveness of transaction monitoring rules, the adequacy of CDD processes, the quality of STR filings, and the completeness of record-keeping.

Consolidating AML Compliance into Operational Workflows

The pattern across these findings points to a structural challenge. IRDAI AML compliance for insurance cannot be managed as a standalone function disconnected from policy administration, underwriting, claims, and distribution management. It requires integration into the operational fabric of the insurer, with clear accountability, automated triggers, and demonstrable evidence of compliance at each stage.

This is precisely where a purpose-built GRC platform adds value. eQomply enables insurers to map IRDAI AML requirements to specific internal controls, assign ownership, track completion, maintain evidence, and generate audit-ready reports, all within a single platform that connects AML compliance to the broader regulatory obligations an insurer manages, including those under the insurance compliance program framework.

Moving from Reactive to Structured AML Compliance

The cost of AML non-compliance for insurers extends beyond financial penalties. IRDAI has the authority to restrict business operations, mandate enhanced supervision, and publicize enforcement actions. Reputational damage in the insurance sector, where trust is the core product, can have lasting business consequences.

Building a structured AML program requires moving beyond document collection at onboarding to genuine risk-based monitoring throughout the policy lifecycle. It requires connecting data across products and channels, training distribution networks, empowering Principal Officers with real-time information, and maintaining records that can withstand regulatory scrutiny years after the transaction occurred.

For compliance teams looking to consolidate their IRDAI AML compliance obligations into a structured, auditable framework, eQomply offers the infrastructure to manage regulatory requirements, track controls, collect evidence, and demonstrate compliance readiness. If that aligns with where your AML program needs to go, schedule a walkthrough to see how it works in practice.

  • AML
  • compliance
  • insurance
  • IRDAI
  • PMLA
Pritesh Baviskar
Pritesh Baviskar

Founder at eQomply. Writes about compliance, regulatory shifts, and what it takes to build GRC functions that actually work.

Post navigation

Previous
Next

Search

Categories

  • Board Reporting (4)
  • CERT-In (4)
  • Compliance Management (8)
  • DPDP Act (9)
  • Evidence Management (5)
  • GRC (7)
  • Guides (5)
  • IRDAI Compliance (4)
  • Perspectives (1)
  • RBI Compliance (8)
  • SEBI Compliance (5)
  • Third Party Risk (4)
  • Uncategorized (4)

Recent posts

  • Compliance Documentation Best Practices
  • IRDAI AML Compliance for Insurers Explained
  • How to Build a Strong Compliance Culture in Organizations

Tags

AML audit audit readiness audit trail banking BFSI board reporting case-studies CERT-In circulars cloud compliance compliance management consent CRO cyber audit cybersecurity data protection documentation DPDP evidence governance GRC incident reporting inspection insurance IRDAI IRM IT governance maturity model metrics outsourcing PMLA policy management privacy RBI regulation regulatory change risk management SEBI third party risk vendor monitoring vendor risk version control VPN

Related posts

Evidence Management

Compliance Documentation Best Practices

July 21, 2026 Pritesh Baviskar No comments yet

Discover compliance documentation best practices, including version control, traceability, retention, and audit-ready record management.

DPDP Act, Third Party Risk, Uncategorized

Vendor Data Processing Agreements Under the DPDP Act

July 15, 2026 Pritesh Baviskar No comments yet

Understand how vendor data processing agreements support DPDP Act compliance, including vendor obligations and breach notifications.

RBI Compliance

RBI Compliance for Payment Companies Explained

July 13, 2026 Pritesh Baviskar No comments yet

Understand RBI compliance requirements for payment companies, including governance, KYC and AML, cybersecurity and regulatory reporting.

Subscribe to Field Notes

    Enterprise GRC for regulated industries

    Platform
    • Overview
    • Policy Management
    • Risk Management
    • Compliance
    Solutions
    • By Role
    • By Industry
    • By Regulation
    Resources
    • Field Notes
    • Guides
    • Regulatory Library
    • Terms of Services
    • Privacy Policy

    © QomplySuite Private Limited Copyright 2026