The Luxembourg Insurance Commission has standardized the information that insurance professionals must provide when seeking prior authorization for an automated process that accepts customers assessed as presenting low money laundering and terrorist financing risk. Applications must cover five areas: the process design, risk assessment, customer onboarding, ongoing due diligence, and governance and internal controls. The application must explain customer and product eligibility, projected volumes, participating service providers, and any expert or artificial intelligence systems used. Firms must document decision rules, system autonomy, identity checks, customer risk scoring, screening for higher risk factors, exclusions that trigger manual intervention, ongoing monitoring and audit trails. Authorized processes must undergo regular compliance reviews, second level controls and internal audit coverage. Authorization applies only to the approved process, and firms must notify the commission of material changes, including changes to eligibility criteria or the use of new technologies. Firms must also ensure compliance with applicable new rules, including European Union anti-money laundering and counterterrorist financing requirements and related technical standards from July 10, 2027.
Source: 2026-09-29Luxembourg Commissariat aux Assurances
Luxembourg Insurance Commission sets authorization expectations for automated acceptance of customers with low money laundering and terrorist financing risk
The Luxembourg Insurance Commission has standardized prior authorization applications for automated acceptance processes covering customers with low money laundering and terrorist financing risk. Firms must document process design, risk controls, automated decision rules, manual escalation, ongoing monitoring and internal oversight. Material changes must be notified, and processes must comply with relevant European Union requirements from July 10, 2027.