Regulatory primer

IDD

Directive (EU) 2016/97 — Insurance Distribution Directive · European Union · In force since 23 February 2018

The Insurance Distribution Directive governs how insurance + reinsurance products are sold + distributed across the EU. For insurtech, IDD Art. 25 product oversight + governance (POG) is the most directly engaged provision — distributors + manufacturers must operate a documented process covering each product's lifecycle.

Updated 15 May 2026·Reading time ~ 7 min·Regulator-first explainer

What it is

IDD replaced the 2002 Insurance Mediation Directive (IMD). The shift broadened scope from intermediaries to all distributors (including direct-sales insurer channels), introduced detailed conduct-of-business rules, and added the product-oversight + governance regime that's increasingly the focus of supervisor attention.

Supervised by national competent authorities (e.g. ACPR in France, BaFin in Germany, FCA in UK pre-Brexit, DNB in Netherlands). EIOPA coordinates at EU level + publishes supervisory expectations + supervisory convergence reports.

IDD2 — a revision proposal — is under consideration. EIOPA's 2023 report on differentiated insurance pricing flagged AI-related concerns that may inform the revision.

Who's in scope

  • Insurance + reinsurance distributors: insurance intermediaries, ancillary insurance intermediaries (under thresholds), reinsurance intermediaries, insurance undertakings + reinsurance undertakings directly distributing.
  • Cross-border distributors via freedom-of-establishment / freedom-of-services.
  • Excluded: certain ancillary insurance for limited risks (where premium ≤€200 + complementary to goods/services), insurance products linked to specific service contracts.

Key obligations

Art. 25 — product oversight + governance (POG)

Manufacturers + distributors must operate a documented product-oversight + governance process. Identification of target market, assessment of relevant risks, consistency between product features + target-market needs, periodic review.

Art. 17-18 — general principles + conflicts of interest

Distributors act honestly, fairly + professionally in the customer's best interests. Identification + management of conflicts of interest including remuneration arrangements.

Art. 20 — demands + needs

Distributors specify the customer's demands + needs based on the customer-supplied information. Advised sales require a personalised recommendation explaining why a particular product best meets demands + needs.

Art. 29 — information requirements + insurance-based investment products

Enhanced disclosure for IBIPs including costs + charges, periodic statements, suitability + appropriateness assessments where advice is given.

Timeline + applicability

  • 23 Feb 2016IDD adopted.
  • 23 Feb 2018IDD became applicable (postponed by 6 months due to industry readiness).
  • OngoingEIOPA supervisory expectations + national-supervisor enforcement priorities continue to develop, especially on POG + differentiated pricing.

What's still being worked out

Areas where the regulation's interpretation is genuinely unsettled. Vendor pages skip this; we don't. Your counsel is the right venue for definitive guidance on your deployment.

  • How POG applies to AI-driven product configuration + pricing — EIOPA's differentiated-pricing concerns + supervisory practice are evolving.
  • Distribution-AI scope — chatbot-driven advice or recommendation engines blur the Art. 20 demands-and-needs + Art. 30 suitability/appropriateness boundaries.
  • Interaction with AI Act §5(c) — life + health insurance risk + pricing AI is high-risk under AI Act, layering Chapter II obligations on top of IDD POG.
  • Cross-border distribution + concurrent national-supervisor jurisdiction.

Sectors most affected

Primary sources

Where Promethean fits

Promethean's L12 chain feeds IDD Art. 25 POG annual reviews + supervisor inquiries. The chain captures per-decision evidence on the AI driving product configuration, distribution decisions, pricing recommendations: spec hash (which configuration was active), reviewer verdicts (where always-human gates fire on high-value or contested decisions), fallback rate (system reliability metric). For multi-MGA + multi-carrier platforms, R4 tenantId enables per-carrier audit bundle filtering, which addresses both IDD-driven evidence requests + the carrier's parallel ORSA + DORA obligations.

What Promethean does NOT solve

  • POG process design + target-market analysis — that's product + actuarial responsibility.
  • Conflicts-of-interest management + remuneration governance — operator's compliance function.
  • Demands-and-needs assessment process — operator's distribution workflow.
  • Suitability + appropriateness assessments for IBIPs — operator's investment-services compliance.

FAQ

Is my MGA in IDD scope?

Yes — Managing General Agents acting as insurance intermediaries are in scope. MGAs design + distribute insurance products on behalf of insurers; both the manufacturing (when applicable) + distribution roles engage IDD. Art. 25 POG applies in particular to MGAs that materially shape product features.

How does IDD interact with EU AI Act for life/health insurance?

AI Act Annex III §5(c) classifies AI for life + health insurance risk assessment + pricing as high-risk. Concurrent application with IDD Art. 25 POG. Practical effect: AI-driven life/health products engage Chapter II AI Act obligations (Art. 9 risk management, Art. 12 record-keeping, Art. 14 human oversight) AND IDD POG annual reviews simultaneously.

What's EIOPA's view on differentiated pricing?

EIOPA's 2023 Supervisory Statement on differentiated pricing flagged practices that could result in unfair customer outcomes (price walking, post-renewal premium uplift on inertia, AI-driven personalisation that disproportionately affects vulnerable consumers). Pricing AI is being scrutinised under both IDD POG (Art. 25) + Solvency II governance obligations. The substrate's per-decision evidence is increasingly demanded in EIOPA-coordinated inspections.

What does Art. 25 POG actually require us to document?

A documented process covering: identification + assessment of target market for each product, assessment of all relevant risks to the target market, consistency between the product + the target market's needs/objectives, distribution strategy consistent with target market, periodic review of products in light of events that could materially affect risk. The process must be proportionate to product complexity + customer harm potential. For AI-influenced products, demonstrating that the AI's behaviour stays within the target-market scope is a recurring supervisor question.