Skip to content
CRYSTAL ITIT Solutions
Insurance

Anti-money laundering in Moroccan insurance: intermediaries' obligations and what software brings

August 1, 20268 min read
Anti-money laundering in Moroccan insurance: intermediaries' obligations and what software brings

The fight against money laundering and terrorist financing (AML-CFT) is no longer, in Morocco, a matter for banks alone. The insurance sector is fully subject to the national framework stemming from law 43-05, as amended and supplemented, and ACAPS oversees its application by insurance undertakings and their intermediaries alike. For a broker or a tied agent, this translates into concrete obligations: knowing your customer, exercising due diligence proportionate to the risk, retaining documents, detecting atypical transactions and, where warranted, reporting suspicions to the National Financial Intelligence Authority (ANRF). Kept by hand, these obligations are heavy; built into the management software, they become largely automatic. This article takes stock of the framework applicable to Moroccan intermediaries and of the way a tool such as CRYSTAL ASSUR IA (Crystal Assur, the insurance broker software) helps comply with it without weighing down daily work.

The Moroccan framework: law 43-05, ACAPS and the ANRF

The bedrock of the framework is law 43-05 on the fight against money laundering, amended and supplemented several times to align Morocco with international standards. It defines the offence of money laundering, the list of subject persons — including the insurance sector — and their obligations: customer due diligence, internal monitoring, document retention and suspicious transaction reporting. The National Financial Intelligence Authority (ANRF) receives and processes suspicious transaction reports, while each supervisory authority checks compliance with the framework in its own sector.

For insurance, that supervisory authority is ACAPS. It has specified the sector's obligations by circular — notably the circular on the due diligence and internal monitoring obligations of insurance and reinsurance undertakings and intermediaries (circular AS/02/19, as amended and supplemented) — and publishes practical guides for professionals. The message is clear: the intermediary is not a spectator of the framework, but a front-line actor in it, precisely because they are in direct contact with the client and with premium flows. The reference texts can be consulted on the ACAPS website, which is worth following as the framework evolves regularly.

Knowing your customer: identification and due diligence

The first obligation is customer identification: knowing whom you are contracting with. For a natural person, that means a valid identity document; for a legal entity, the documents establishing its legal form, its address, the identity of its directors and — a point now central to AML-CFT frameworks — of its beneficial owners, that is, the natural persons who ultimately control it. These elements must be gathered before entering into the relationship, kept up to date, and retained.

Due diligence is then proportionate to the risk: this is the risk-based approach, the cornerstone of international standards. Not all clients and transactions present the same profile: a motor policy paid by monthly direct debit does not call for the same level of attention as a subscription with a large single premium paid in cash, a relationship with a non-resident or a politically exposed person. The intermediary must therefore classify its business relationships by risk level and adjust the intensity of its checks accordingly — an exercise unworkable on paper once the portfolio numbers a few thousand clients, and natural once the client file is structured in business software.

  • Systematic identification before entering the relationship: identity, address, supporting documents archived in the file.
  • Identification of the beneficial owner for legal entities.
  • Classification of business relationships by risk level, reviewed periodically.
  • Enhanced due diligence in sensitive situations: large premiums in cash, non-residents, politically exposed persons.
  • Client files updated throughout the relationship, not only at subscription.

Detect, retain, report: the operational obligations

Beyond customer knowledge, the framework requires transaction monitoring. The intermediary must be able to spot atypical transactions: premiums out of proportion to the client's economic profile, early and repeated surrenders of investment policies, split payments designed to stay under thresholds, third-party payers with no apparent link to the policyholder. These signals do not establish an offence — they call for a documented examination, concluding either in a legitimate explanation or in a suspicious transaction report to the ANRF. A report made in good faith protects the reporting party: professional secrecy cannot be held against them.

Added to this is the retention obligation: identification documents and records relating to transactions must be kept for the statutory periods and remain quickly retrievable — an inspection does not tolerate untraceable archives. Finally, internal monitoring presupposes written procedures, a designated officer and regular staff training. So many requirements that, scattered between paper and spreadsheets, become a crushing burden for an organisation of a few people — and that, built into the management system, largely execute themselves.

What management software changes for AML-CFT compliance

Well-designed insurance software turns AML-CFT compliance from a project into a by-product of daily management. Identification becomes a compulsory step in creating the client record, with documents digitised and attached to the file — CRYSTAL ASSUR IA's OCR reading and filing them automatically. Since collections are recorded with their payment method, sensitive situations — cash above a threshold, split payments, a third-party payer — become detectable through alert rules rather than the counter clerk's memory (Premium receipts and collections).

Retention stops being a problem: every document, transaction and exchange is archived, time-stamped and retrievable in seconds, which changes the complexion of an inspection. And the system's overall traceability — who did what, when, on which file — provides the audit trail that internal monitoring requires. This logic joins the firm's overall compliance with its regulator, detailed in our article on ACAPS compliance (ACAPS compliance: what your insurance software must cover), and the personal data protection imposed by law 09-08.

Making compliance an advantage rather than a burden

It is tempting to see AML-CFT as one more administrative constraint. That is an error of perspective: a firm whose client files are complete, whose flows are traceable and whose procedures are maintained is a better-run firm — one that knows its clients better, collects more cleanly and answers inspections without stress. Well-tooled compliance is an outward sign of seriousness, towards the regulator as towards partner insurers, at a time when the latter are tightening their own requirements on their networks.

The point to watch is not to improvise: the framework evolves, the circulars are supplemented, and supervisors' expectations rise. Relying on a local publisher, in touch with the market and its rules, is a lasting asset. CRYSTAL IT, publisher of CRYSTAL ASSUR IA based in Rabat for more than 20 years, evolves its platform at the pace of the Moroccan framework — as its full business range shows (our products). The general framework applicable to intermediaries is detailed in our guide to the Insurance Code (The Moroccan Insurance Code).

Anti-money laundering is not optional for Moroccan insurance intermediaries: law 43-05, the ACAPS circulars and the ANRF's oversight make it a fully-fledged component of the trade. Identification, the risk-based approach, transaction monitoring, retention and suspicious transaction reporting: these obligations are heavy on paper and light in an integrated management system, where they execute in the course of business. CRYSTAL ASSUR IA, the first insurance application in Morocco published by CRYSTAL IT since 2014, structures client files, traces flows and archives documents — the raw material of your compliance. Request a free demonstration, and verify this point like the others: on your own cases.

Have a project or a question? Let's talk with a CRYSTAL IT expert.

Request a demo