Guide for insurance distributors

IDD Article 20: what you need to be able to show

Article 20 of the Insurance Distribution Directive, Directive (EU) 2016/97, is about the sale itself: what the customer needs, and whether what you proposed fits. It never uses the word “record”. But every duty in it is one you may be asked to demonstrate long after the conversation is over, and the only way to demonstrate it is with evidence you kept at the time.

The text

What Article 20 asks of a distributor

Before an insurance contract is concluded, the distributor must:

Article 23 then governs how that information reaches the customer: on paper, or on another durable medium or a website where the conditions for that are met. In Belgium the directive is transposed by the Act of 4 April 2014 on insurance, and the FSMA supervises its conduct rules.

Evidence

Each duty, and what would show you met it

A duty you cannot evidence afterwards is, in an inspection or a complaint, a duty you cannot show you met. This is the practical reading: for each part of Article 20, the question someone will eventually ask, and what answers it. The last column says honestly which parts a system like RiskRouter can evidence and which stay entirely with you.

DutyThe question you will be askedWho holds the evidence
Demands and needs What did the customer tell you, and what did you conclude they needed? You. RiskRouter records no customer information at all, by design.
Consistency of what was proposed Exactly what was proposed: which product, which options, at what price, when? RiskRouter records this: the vertical, the on or off state of every component, the premium, the rating-matrix version and the time, in an entry nobody can edit afterwards.
Objective information Was the price you showed the price the rules produced, and which rules were they? Partly. The server computes every price and ignores any a browser sends, and each entry carries the version of the rate table that priced it. The wording you showed stays in your own system.
Personalised recommendation Where you advised, what did you recommend and why? You.
IPID (non-life) Which version of the product information document did the customer receive? You, and your product manufacturer.
Durable medium (Article 23) How and when did the information reach the customer? You.

How long to keep this evidence is not something this page states. Check the period that applies to you with your supervisor or your professional federation.

The weak point

Evidence that could have been edited proves less

Most distributors do keep records: a CRM note, a spreadsheet, a PDF in a shared drive. The difficulty is that every one of those can be changed after the fact by anyone with access, and usually leaves no trace when it is. A record that could have been corrected is a record whose accuracy rests on your word, which is exactly what it was meant to replace.

That is the gap an append-only, hash-chained ledger closes: changing any entry breaks every entry after it, and anyone holding an earlier checkpoint can see that it happened. The difference is set out in database log vs tamper-evident ledger, and you can watch a chain refuse an edit on the verify page.

Scope

What this page is not

This is a plain-language reading of the directive, written to explain why RiskRouter records what it records. It is not legal advice and not an authoritative interpretation; your own counsel, your supervisor and your federation are. Using RiskRouter transfers none of your obligations to us. The regulatory position sets out what stays with you in full.

Get a sandbox key The audit-trail checklist