Blog & newsroom ResearchRegulation

The regulator's view of embedded insurance: supervision themes worldwide

Yasmina LegalLegal & compliance11 August 20265 min read

Read what supervisors actually publish — the FCA pausing GAP sales over 6% claims ratios, EIOPA warning banks on credit protection insurance, the IAIS flagging digital sales journeys — and a consistent picture emerges of what embedded distribution must prove.

Very few regulators have published rules with "embedded insurance" in the title. That does not mean they have no view. Supervisors have been examining insurance sold alongside other products — through banks, car dealers, retailers and digital checkouts — for years, and their interventions form a coherent doctrine if you read them together. This piece does that reading: three well-documented supervisory actions and papers, what each reveals, and the composite picture of what regulators will expect from embedded distribution as it scales.

The summary, up front: regulators are not hostile to insurance sold at the point of need. They are hostile to what point-of-sale convenience has historically hidden — products paying out a fraction of premiums, commissions driving what gets offered, and distribution chains where no one clearly answers for the customer. Embedded insurance inherits the scrutiny of every add-on scandal that preceded it, and its licence to operate depends on being demonstrably better.

Exhibit one: the FCA stops a market

In February 2024, the UK's Financial Conduct Authority secured an agreement from firms representing about 80% of the guaranteed asset protection market to pause sales of GAP insurance — a product sold overwhelmingly alongside car purchases. The numbers behind the intervention explain its bluntness: the FCA found only 6% of premiums paid was being returned to customers in claims, while some firms were paying as much as 70% of premium to the intermediaries selling the product. Firms were allowed back into the market only months later, after demonstrating fair value changes.

Two lessons transfer directly to embedded distribution. First, the claims ratio is the tell. A product that returns almost nothing to customers cannot be defended by disclosure quality or purchase convenience; value for money has become a measurable, enforceable standard. Second, distribution economics are now supervisory business. When most of the premium funds the channel rather than the cover, regulators read the commission structure itself as the cause of harm.

Exhibit two: EIOPA warns the banks

Eighteen months earlier, in October 2022, the EU's insurance authority issued a formal warning to insurers and banks over credit protection insurance — cover sold with loans and mortgages, embedded insurance's older sibling. EIOPA's thematic work found high profitability for banks and insurers alongside limited claim payouts to consumers, warned that high commissions create detrimental conflicts of interest, and noted that 83% of banks in its review bundled CPI with their own credit products, limiting customers' ability to choose or switch. The warning demanded compliance with the EU's product oversight and governance rules and explicitly held both manufacturer and distributor responsible.

The transferable doctrine here is accountability across the chain. In EIOPA's framing, "the bank sold it" does not relieve the insurer, and "the insurer designed it" does not relieve the bank. Applied to embedded insurance: platform, infrastructure layer and carrier are jointly visible to a supervisor, and contracts allocating blame internally do not change who answers externally.

Exhibit three: the IAIS names the digital risks

The International Association of Insurance Supervisors — the global standard-setting body whose members supervise most of the world's insurance markets — examined digital distribution in a 2018 issues paper that remains the reference text for how supervisors think about online sales journeys. Its concerns are recognisably about embedded mechanics: pre-contractual information that becomes incomprehensible on small screens, add-on offers timed so purchase is passive rather than chosen, algorithmic journeys that cannot register the hesitation a human adviser would notice, undisclosed ownership and remuneration in comparison and distribution platforms, and granular data-driven risk selection that can quietly exclude customers from affordable cover. The paper also stresses that these risks cross borders and require supervisors to cooperate — including with privacy and competition authorities.

The IAIS matters because it writes the templates national regulators adapt. Themes in its papers have a habit of resurfacing, years later, as local rules.

The composite picture

Set side by side, the three documents converge on four expectations that any embedded insurance operation can be tested against today.

  • Value for money, evidenced. Know your products' claims ratios and be able to defend them. The FCA showed that a bad enough number ends the product.
  • Remuneration that survives daylight. Commission structures are no longer private commercial arrangements; they are conduct-risk indicators supervisors will read.
  • Real choice at the point of sale. Bundling, pre-ticked additions and buried disclosures are exactly the patterns EIOPA and the IAIS single out. An embedded offer must be an offer — visible, priced, declinable.
  • A chain with no accountability gaps. Every party in the distribution stack should be able to state its regulatory responsibility for the sale and produce records proving it met that responsibility.

Our own reading, stated as opinion: this doctrine favours licensed, auditable embedded infrastructure over informal distribution. The historical add-on scandals happened in channels where compliance was an afterthought bolted to a sales operation. An embedded model built on regulatory approval, logged consent, disclosed pricing and clean data trails is not just safer — it is the version of this market supervisors are effectively describing when they list what went wrong elsewhere. In Saudi Arabia, where distribution runs under Insurance Authority approval, that alignment is the design premise rather than a retrofit.

Sources and limitations

This analysis rests on three public documents — an FCA press release and intervention, an EIOPA warning and its underlying thematic review, and an IAIS issues paper — chosen because they are primary, dated and verifiable. Limitations are real: the FCA and EIOPA actions concern specific products in specific markets, and extrapolating them to all embedded insurance involves judgement; the IAIS paper is pre-2020 and descriptive rather than binding; and no Gulf-specific supervisory action on embedded distribution is analysed here, because the instructive public record so far sits in Europe. Figures cited are the regulators' own; the synthesis and its application to embedded models are ours.

Embedded insuranceSupervisionConsumer protection