Skip to main content

New supervisory and AML rules for insurance groups

In 2027 the revised Solvency II Directive, the new recovery and resolution directive and the EU Anti-Money Laundering Regulation all start to apply. COBACK reads publications from EIOPA, BaFin and the EU Official Journal, checks them against your entities and lines of business and turns a relevant change into tasks.

Atrium of a large office building with stone seating steps, planting and timber cladding, people passing far off in the daylight

Topics and rules

What is changing, who in the company works with it and which legal acts are behind it.

  • Solvency II

    Amending Directive (EU) 2025/2 applies from 30 January 2027. It brings relief for small and non-complex undertakings, requirements on handling sustainability risks and new macroprudential tools. In October 2025 the Commission adopted the matching amendment to Delegated Regulation (EU) 2015/35, which among other things lowers the risk margin. In Germany the VSAAG is to transpose the directive into the Insurance Supervision Act, and the federal government presented the bill in spring 2026. The actuarial function, risk management, investments and supervisory reporting are affected.

    Examples

    • Directive 2009/138/EC (Solvency II)
    • Directive (EU) 2025/2
    • Delegated Regulation (EU) 2015/35
    • German Insurance Supervision Act (VAG)
  • Recovery and resolution

    Directive (EU) 2025/1 (IRRD) creates the first EU framework for the recovery and resolution of insurers. It introduces pre-emptive recovery plans, gives resolution authorities powers for a crisis and must be transposed by 29 January 2027. The German VSAAG bill provides for a separate Insurance Recovery and Resolution Act (VSAG) for this. Risk management, finance and the management board are affected.

    Examples

    • Directive (EU) 2025/1 (IRRD)
    • German bill implementing Directives (EU) 2025/1 and (EU) 2025/2 (VSAAG)
  • Governance and IT

    BaFin's revised MaGo Circular 09/2025 (VA) has applied since 14 October 2025 and also addresses automated business processes and sustainability risks. DORA has applied to insurers since 17 January 2025, and BaFin repealed the VAIT at the end of 16 January 2025. The key functions, IT, information security and outsourcing management are affected.

    Examples

    • MaGo for Solvency II undertakings, BaFin Circular 09/2025 (VA)
    • Regulation (EU) 2022/2554 (DORA)
  • Distribution and products

    The Insurance Distribution Directive requires product approval processes, advice based on the customer's demands and needs and, for insurance-based investment products, questions about sustainability preferences. These products also need a key information document under the PRIIPs Regulation. The retail investment strategy, agreed politically by the Council and Parliament in December 2025, is set to amend the IDD and the PRIIPs Regulation again. Product development, sales and distribution compliance are affected.

    Examples

    • Directive (EU) 2016/97 (IDD)
    • Regulation (EU) No 1286/2014 (PRIIPs Regulation)
    • Delegated Regulation (EU) 2021/1257
    • German Insurance Contract Act (VVG)
  • Anti-money laundering

    Insurers that offer life insurance, accident insurance with premium refund or capitalisation products, or that grant loans, are obliged entities under the German Money Laundering Act. With some exceptions, the same applies to insurance intermediaries who sell these products. From 10 July 2027 the EU Anti-Money Laundering Regulation applies with uniform due diligence rules across the EU. Money laundering reporting officers, application and claims handling and sales are affected.

    Examples

    • German Money Laundering Act (GwG), section 2(1) nos. 7 and 8
    • Regulation (EU) 2024/1624 (AMLR)
  • AI in pricing and underwriting

    Under the AI Act, AI systems intended for risk assessment and pricing in relation to natural persons in life and health insurance are high-risk. Amending Regulation (EU) 2026/1744 moves their obligations to 2 December 2027. The transparency duties, such as telling customers that they are interacting with an AI system, have applied since 2 August 2026. Underwriting, the actuarial function, customer service, IT and data protection are affected.

    Examples

    • AI Act (EU) 2024/1689, Annex III point 5(c)
    • Regulation (EU) 2026/1744

The path of a change

Example: new AI Act deadlines

  1. 01Law database

    The EU Official Journal publishes Regulation (EU) 2026/1744. It moves the obligations for high-risk AI under Annex III of the AI Act to 2 December 2027.

  2. 02Relevance

    COBACK checks it against the twin: according to the documentation in SharePoint, your life insurance company uses a model in underwriting. The score is 82 out of 100, with reasoning that cites Annex III point 5(c).

  3. 03Open questions

    Whether the model affects the premium of individual customers is not in the twin, so COBACK asks instead of guessing. The head of compliance reviews the answer and marks the change as relevant.

  4. 04Task

    Tasks follow: by 27 October 2026, the actuarial function moves the high-risk AI project plan to the new deadline. Customer service checks the AI notice in the customer chat within 2 weeks and IT completes the AI inventory within 6 weeks.

Working with COBACK

  • Sources for insurers

    COBACK reads new publications from EIOPA, BaFin and the GDV every day, along with the EU Official Journal and the German Federal Law Gazette.

  • Reasoning that names the entity

    Every publication gets a score from 0 to 100. The reasoning names the entities and business concerned and the sources it relied on.

  • Questions instead of assumptions

    Where a fact is missing, such as whether a product is unit-linked, COBACK asks. A person decides whether a change is relevant.

  • Tasks for the key functions

    A relevant change becomes tasks with steps, owners and deadlines for the actuarial function, risk management, compliance or sales.

Frequently asked questions

We are a group with several insurers. Can COBACK reflect that?

Yes. The digital twin knows your entities and locations, also with data from public registers such as GLEIF. The reasoning behind a score names the individual entity a change affects.

Does COBACK replace the legal review by our compliance function?

No. COBACK does not give legal advice and does not decide for you. It shows what is new, how likely it is to affect you and why. Your compliance function makes the decision.

How does our company data get into COBACK?

Through connected systems such as SharePoint, Confluence or Google Drive, public registers, your website and a questionnaire. Nobody has to upload files by hand.

Will COBACK e-mail us when something changes?

No. COBACK does not send e-mails or push notifications. New scores, open questions and tasks are in COBACK itself.