

In the hushed glow of dawn, Heimdall stands eternal guard before Valhalla, eyes that pierce distant worlds, ears that catch the faintest whisper; admitting only the pure, barring all with ill intent.
In India's financial sector, two such sentinels stand watch: one guarding the purity of economic flows, the other the sanctity of personal data. Together, they form the bedrock of trust on which the insurance industry rests.
Insurance; a business of utmost good faith, is, by its nature, vulnerable to those who would exploit it to launder dirty money. AML compliance (compliance with Anti-Money Laundering laws) and data privacy regulation are therefore not mere obligations but sacred duties. For insurers, the challenge lies in harmonizing the seven laws that govern them - both in letter and spirit - to protect the nation and its customers alike.
India's governance framework on anti-money laundering, counter financing of terrorism (CFT), and personal data protection evolved from implied protections under FEMA and Article 21 of the Constitution, to a robust statutory architecture — the Prevention of Money Laundering Act, 2002 ('PMLA'), Prevention of Money Laundering (Maintenance of Records) Rules, 2005 ('PMLR'), the Information Technology Act, 2000 ('IT Act'), the IT (Reasonable Security Practices and Sensitive Personal Data) Rules, 2011 ('SPDI Rules'), the Digital Personal Data Protection Act, 2023 ('DPDP Act'), its Rules ('DPDP Rules'), and IRDAI's Master Guidelines on AML/CFT, 2022 ('Master Guidelines').
The PMLA casts a statutory duty on all financial institutions, including insurers, to verify customers, monitor transactions, and report suspicious activity. IRDAI's Master Guidelines operationalise these obligations for the insurance sector specifically.
The AML framework empowers insurers to gatekeep against money laundering — through KYC/e-KYC verification, anomaly detection, refusal of suspicious business, and prompt reporting of red flag indicators to the Financial Intelligence Unit-India (FIU-IND).
Where AML asks "who are you, and where did this money come from?", data protection asks "what are we doing with what you've shared?" The DPDP Act frames this as both a right and a duty. Insurers, as data fiduciaries, routinely collect identity proofs, health records, financial statements, and even biometrics - beginning at the very first proposal form.
In short, data protection in insurance is about dignity. It says: if a person hands you their medical history, their identification, their financial details in exchange for protection, you owe them not just a promise of payout, but a promise that their information will not be mishandled or exposed.
To a common man, AML and DPDP may appear as yin and yang — one demanding disclosure, the other confidentiality. Yet it is their synergy that protects the insurance industry. This is best understood by walking through the lifecycle of an insurance policy. Each stage — solicitation, underwriting, issuance, and operation — carries its own obligations of vigilance and restraint.
The first threshold
The story begins when an insurer, directly or through a licensed intermediary, approaches a prospective customer. What appears a commercial overture carries significant legal weight.
As a Data Fiduciary under the DPDP Act, the insurer must first provide clear notice — specifying what personal data will be collected, for what purposes (KYC, underwriting, servicing), and how it will be handled. Only upon free, explicit, and informed consent may the insurer proceed to process data for AML purposes. That consent must be affirmative and specific — a ticked box, a digital confirmation, a signed declaration not an assumption buried in fine print.
Where the proposed insured is a minor or an unborn child, common in child plans, the law adds an additional layer of protection. The proposal must be made by the legal guardian, and verifiable parental consent is mandatory before processing the child's data, as required under Section 9(1) of the DPDP Act. The child stands under a double aegis: shielded from financial misuse and from premature exposure of personal data.
Following consent, insurers must perform Customer Identification and Due Diligence under IRDAI's Master Guidelines, read with the PMLA and PMLR collecting and verifying KYC documents before the commencement of any account relationship.
Examining the soul of the risk
Once the proposal and KYC documents are received, the insurer shifts from gathering information to verifying its authenticity. Under the Master Guidelines read with Rule 9 of the PMLR, if any document or information appears inconsistent or suspicious during due diligence, the insurer must pause and file a Suspicious Transaction Report. No policy may be issued until client due diligence is satisfactorily completed.
Risk classification follows at minimum, into low-risk and high-risk categories. High-risk customers attract Enhanced Due Diligence (EDD): deeper scrutiny of the source of funds, purpose of the policy, income proofs, and senior-level review. Low-risk customers attract Simplified Due Diligence (SDD).
Throughout, the DPDP Act confines the use of personal data strictly to purposes aligned with the consent obtained risk assessment, AML compliance, and underwriting. Any use beyond this, including marketing, requires separate legal grounds and fresh consent. The PMLA reinforces this: KYC and AML information is to be used only as the law permits, not treated as a commercial asset.
Writing the covenant and guarding the archive
Upon acceptance of risk, the insurer issues the policy. Compliance then shifts into record-keeping and data protection.
Under Section 12 of the PMLA and its Rules, insurers must maintain records of all transactions and customer identity information in a manner that allows each transaction to be fully reconstructed. This encompasses proposal forms, KYC documents, premium payment records, correspondence, and internal notes — retained for a minimum of five years from the date of the transaction or the end of the business relationship, whichever is later.
In parallel, the DPDP Act requires insurers to treat this archive as a sanctum - secured through technical measures such as encryption, and organizational controls such as access restrictions, audit logs, and periodic reviews.
Even after issuance, a policy does not fall silent, it continues to breathe, evolve, and demand vigilance. The obligations of AML and data protection do not lapse with the policy term. They persist, ensuring that the flow of money remains unsullied and personal data remains protected.
Confidentiality survives the life of the policy. Records may be summoned by regulators, auditors, or FIU-IND when the law demands, but remain shielded from all others. Every intermediary, whether agent, broker, or surveyor, stands bound not merely by compliance manuals but by the legal and ethical duty to honour the trust placed in them under the PMLA, the Master Guidelines, and the DPDP Act.
In this convergence of transparency and restraint, insurers do not merely sell policies, they guard financial integrity. They do not merely store data; they protect what people have entrusted to them. The insurance industry, at its best, is not just a commercial enterprise but a custodian of trust: a sentinel at the intersection of money and privacy.
About the author: Priti Rohira is an Executive Partner at ElpeeCo.
Disclaimer: The opinions expressed in this article are those of the author(s). The opinions presented do not necessarily reflect the views of Bar & Bench.
If you would like your Deals, Columns, Press Releases to be published on Bar & Bench, please fill in the form available here.