EstatePass

FIELD UNDERWRITING · 6 MIN READ

AML, Privacy, and Federal Screening Requirements

Federal financial-crimes law reaches insurance through FinCEN's anti-money-laundering rule for insurance companies, which covers insurers issuing covered products — permanent life insurance (other than group), individual annuities, and other products with cash value or investment features. Covered insurers must run a written AML program with training for employees and producers, because the producer is the customer-facing sensor for laundering red flags. Two reports carry the tested thresholds. A Currency Transaction Report is required for currency transactions over $10,000. A Suspicious Activity Report must be filed when the insurer knows, suspects, or has reason to suspect a transaction of $5,000 or more involves illicit funds, evades reporting, lacks lawful purpose, or facilitates crime — filed within 30 calendar days of initial detection, with up to 30 additional days to identify a suspect. Under the USA PATRIOT Act's Customer Identification Program requirements, firms collect and verify name, date of birth, address, and identification number at account opening, and the Customer Due Diligence rule extends identification to the beneficial owners of legal-entity customers. Every applicant must be screened against OFAC's Specially Designated Nationals list before binding coverage — transactions with listed parties are blocked, full stop. Privacy statutes wrap around the underwriting file. Gramm-Leach-Bliley requires an initial privacy notice no later than establishing the customer relationship, periodic notices thereafter, and — before sharing nonpublic personal information with nonaffiliated third parties outside the exceptions — a reasonable opportunity to opt out, generally 30 days. The NAIC privacy models implement these duties at the state level, and the Insurance Information and Privacy Protection Model adds consumer rights against insurers specifically: access to recorded personal information within 30 business days of a written request, rights to seek correction or deletion, limits on pretext interviews, and disclosure-authorization standards. The Fair Credit Reporting Act governs consumer reports used in underwriting — insurers must use reasonable procedures, provide adverse-action disclosures, and producers must disclose that an investigative report or MIB check may be made. Finally, the FTC's Identity Theft Red Flags Rule requires financial institutions and creditors offering covered accounts — including some cash-value insurance arrangements — to maintain a written identity theft prevention program with four elements: identify relevant red flags, detect them, respond appropriately, and update the program periodically.

Key rules

AML covers cash-value products: permanent life and individual annuities, not group.

Covered insurers need a written AML program with producer training, since products with cash value or investment features are the laundering vehicles of choice.

Why the exam cares: Which-products-are-covered is the standard first-level AML question.

CTR at over $10,000 in currency; SAR at $5,000 with suspicion, filed within 30 days.

The SAR clock runs from initial detection, extendable 30 more days to identify a suspect. Suspicion triggers include illicit funds, structuring to evade reports, and transactions without lawful purpose.

Why the exam cares: The paired dollar thresholds and the 30-day filing window are the most-quoted AML numbers.

OFAC SDN screening happens before binding; matches block the transaction.

Screening applicants, owners, and beneficiaries against the sanctions list is a pre-bind gate; business with listed persons is prohibited regardless of product.

Why the exam cares: Pre-bind timing is the tested nuance — screening after issue is too late.

GLBA: initial privacy notice at the customer relationship, opt-out before third-party sharing.

Consumers get a reasonable window — generally 30 days — to opt out before nonpublic personal information goes to nonaffiliated third parties outside the statutory exceptions.

Why the exam cares: Notice timing and the opt-out (not opt-in) design are the exam's GLBA anchors.

The Red Flags Rule requires a written program: identify, detect, respond, update.

Financial institutions and creditors with covered accounts must maintain board-approved written programs, train staff, and oversee service providers.

Why the exam cares: The four program elements are tested as an ordered list, with fake elements as distractors.

Numbers to memorize

  • $10,000 — currency transaction threshold triggering a CTR
  • $5,000 — suspicious transaction threshold for a SAR
  • 30 calendar days — SAR filing deadline after initial detection (plus up to 30 more to identify a suspect)
  • 30 days — general GLBA opt-out window before sharing with nonaffiliated third parties
  • 30 business days — insurer response deadline for a consumer's written access request under the NAIC privacy model
  • 4 elements — identify, detect, respond, update in an identity theft prevention program

Common traps

  • Applying AML rules to term or group products — remember coverage targets permanent life and individual annuities with cash value or investment features.
  • Swapping the CTR and SAR thresholds — remember CTR is currency over $10,000; SAR is $5,000 or more plus suspicion.
  • Screening OFAC after policy issue — remember the SDN check is a pre-bind requirement and a match blocks the deal.
  • Reading GLBA as opt-in — remember consumers must be given a chance to opt out; sharing proceeds unless they object within the window.

File the dollar figures as a ladder — 5,000 SAR, 10,000 CTR — and attach 30 to almost everything else: SAR filing, GLBA opt-out, and privacy access (in business days).

Test it before the exam does

Our L&H bank drills Field Underwriting with AI-explained answers. 20 questions free, no signup.

Taking the L&H exam in your state?

Studying for the Life & Health insurance exam? Track every lesson free — progress syncs with the app.

Start free