Enhanced due diligence is needed when the customer, product, channel, or geography raises higher AML or fraud risk. Common triggers include unusual transaction patterns, opaque ownership, politically exposed persons, and higher-risk jurisdictions. Organisations should treat enhanced due diligence as a control overlay, not a substitute for standard identification, and document why the higher-risk path was chosen.
Why This Matters for Security Teams
Standard onboarding is designed for known, lower-risk customers with clear identity signals. enhanced due diligence applies when those signals are incomplete, inconsistent, or inherently higher risk, because the real problem is not just who is being onboarded, but how much confidence the organisation can place in the evidence. That distinction matters for AML, fraud prevention, sanctions exposure, and downstream monitoring.
Current guidance from the FATF Recommendations — AML and KYC Framework treats risk-based escalation as a core control expectation, not an exception. In practice, the most common mistake is applying the same checklist to every applicant and assuming a completed form equals acceptable assurance. NHIMG research shows the same pattern in identity governance more broadly: only 5.7% of organisations have full visibility into their service accounts, which is a warning sign about how often identity evidence is partial or poorly governed; see Ultimate Guide to NHIs — Standards. In practice, many security teams encounter escalation criteria only after a suspicious profile has already been approved, rather than through intentional risk screening.
How It Works in Practice
Enhanced due diligence is not a separate identity process so much as a higher-assurance decision path. Teams typically begin with standard verification, then add deeper checks when the customer, product, delivery channel, or geography crosses predefined risk thresholds. Those checks may include beneficial ownership review, source-of-funds validation, adverse media screening, sanctions and PEP screening, document re-verification, and manual approval by a trained analyst.
The key operational question is whether the evidence supports the stated identity and use case. If a remote applicant presents mismatched documentation, routes through a high-risk jurisdiction, requests unusual account privileges, or shows an ownership structure that cannot be traced to natural persons, the onboarding flow should move from automated approval to analyst review. That review should be documented, because risk-based escalation must be explainable to auditors and investigators. NHIMG guidance on identity governance and lifecycle control in Ultimate Guide to NHIs — Standards reinforces the same operational principle: high-risk identities need stronger proof, tighter control, and clearer evidence of who or what is being granted access.
- Use standard verification for low-risk, well-evidenced cases.
- Escalate when ownership, geography, product, or behavior increases exposure.
- Require manual approval when automated signals cannot explain the risk.
- Keep a record of the trigger, reviewer, and rationale for the decision.
For program design, many teams align onboarding checks with FATF Recommendations — AML and KYC Framework and then tune thresholds by product segment, transaction type, and jurisdiction. These controls tend to break down when onboarding is fully automated for high-risk corridors because the model accepts incomplete evidence faster than investigators can challenge it.
Common Variations and Edge Cases
Tighter screening often increases friction, manual review time, and abandonment, so organisations must balance faster conversion against stronger assurance. That tradeoff becomes sharper in remote onboarding, where the available evidence may be digital, cross-border, or inconsistent across documents and data sources.
There is no universal standard for every risk trigger, so current guidance suggests using documented criteria rather than ad hoc judgment. A politically exposed person is not automatically rejected, but the case usually needs stronger source-of-wealth checks and enhanced monitoring. Likewise, a customer in a higher-risk jurisdiction may still be onboarded if the organisation can validate beneficial ownership, purpose, and transaction expectations. The same logic appears in incident response: NHIMG notes that secrets and identity weaknesses often remain exploitable after discovery, which is why preventive controls matter; see the Schneider Electric credentials breach for a practical reminder of how identity failures can cascade.
Edge cases also include intermediated onboarding, where a reseller or affiliate performs part of the verification, and cases where the applicant’s profile is legitimate but the intended activity is unusual. In those situations, enhanced due diligence should focus on whether the risk is explainable, supportable, and monitorable, not just whether the paperwork is complete.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Remote onboarding decisions hinge on strong identity proof and risk-based access. |
| NIST CSF 2.0 | PR.AA-01 | Identity proofing and authorization must match the risk of the onboarding case. |
| NIST AI RMF | MAP | Risk mapping is needed to justify when standard verification must escalate. |
| NIST Zero Trust (SP 800-207) | DA.DP | Zero Trust requires stronger verification when trust cannot be assumed remotely. |
| NIST SP 800-63 | IAL2 | Higher-risk onboarding often requires stronger identity proofing assurance. |
Require stronger identity evidence and escalation when onboarding risk exceeds standard assurance.
Related resources from NHI Mgmt Group
- When do Colombian AML controls need enhanced verification for remote onboarding?
- Who is accountable when remote identity verification and due diligence controls fail in a regulated market?
- Why do remote business relationships in South Africa require stronger verification and due diligence controls?
- Which controls matter most when comparing remote identity verification with due diligence in Austria?