When EDD uncovers suspicious activity, teams should not treat the finding as a documentation exercise. They should preserve the evidence, complete internal review, decide whether the relationship can continue, and file the required reports to the relevant authority. If the risk is severe, they may need to freeze or decline the account and strengthen ongoing monitoring for related activity.
Why This Matters for Security Teams
enhanced due diligence is only useful if it changes the decision. Once suspicious activity appears, the issue stops being a paperwork exercise and becomes a control, reporting, and containment problem. Teams need to preserve evidence, assess whether the risk can be remediated, and determine whether the relationship can safely continue. That judgment affects fraud exposure, sanctions or AML obligations, downstream access decisions, and whether the organisation can defend its choice later.
For financial crime workflows, the point of EDD is to raise the quality of the decision, not to delay it. If the account, counterparty, or transaction pattern remains unexplained after review, escalation should move quickly to filing the required report and tightening ongoing monitoring. The relevant standard expects customer due diligence, beneficial ownership review, and suspicious activity reporting to work together rather than as separate steps, which is why the decision trail matters as much as the outcome. FATF Recommendations set that baseline.
In practice, many teams only discover gaps in escalation, documentation, and account action after the suspicious pattern has already repeated.
How It Works in Practice
Teams should treat the EDD finding as the start of a structured response. The first task is to preserve the evidence trail, including account history, supporting documents, analyst notes, timestamps, and any transactions or behaviours that triggered the review. The second task is to complete an internal assessment that answers three questions: what happened, how credible the explanation is, and whether the exposure can be contained without continuing the relationship under current terms.
- Preserve all source material before it can be altered or overwritten.
- Correlate the suspicious activity with onboarding data, ownership information, and prior alerts.
- Decide whether mitigation is possible through limits, monitoring, or remediation.
- Escalate for reporting when the activity remains suspicious or cannot be reasonably explained.
- Freeze, restrict, or decline the relationship when the risk cannot be safely managed.
Where the activity may reflect money laundering, fraud, sanctions evasion, or synthetic activity, the threshold for escalation should be low, because the cost of continuing a bad relationship often exceeds the cost of a conservative exit. Filing obligations and internal case closure should be linked, so analysts do not “close” a case before the report and containment steps are complete. The control expectation is similar to incident handling in security operations, preserve, assess, decide, then act, rather than treating review as a detached administrative step. EBA AML/CFT Guidance is useful for EU-oriented teams that need a supervisory lens on that workflow.
These controls tend to break down when ownership data is incomplete, because the team cannot reliably determine who controls the relationship or whether the suspicious behaviour is linked to related accounts.
Common Variations and Edge Cases
Tighter response often increases operational friction, so organisations have to balance customer continuity against the cost of leaving suspicious activity in place. The hard cases are not the obvious ones, but the ones where activity is unusual rather than clearly illegal, or where the relationship has commercial value but the evidence remains incomplete.
In those cases, current guidance suggests using a proportional response: increase monitoring, narrow exposure, and require stronger justification before allowing the relationship to continue. If the suspicion is tied to shell structures, third-party control, or repeated unexplained transactions, a conservative exit is usually safer than an extended remediation cycle. If the activity touches high-risk geographies, rapidly changing beneficial ownership, or repeated threshold avoidance, the case should move faster because those patterns often indicate deliberate evasion rather than a one-off anomaly.
One useful practical distinction is between explainable anomalies and unresolved suspicion. Explainable anomalies can sometimes be contained with enhanced monitoring and documented approval. Unresolved suspicion should trigger reporting and a decision on whether the relationship can continue at all. That distinction matters because it prevents teams from using “more review” as a substitute for an actual decision. FATF Recommendations remain the clearest reference point for that escalation logic.
Risk and Threat Considerations
The main risk is false closure, where a suspicious case is treated as resolved even though the underlying exposure remains active. That creates regulatory risk, repeat-loss risk, and the possibility that the same counterparty or behaviour continues through another channel.
Failure mechanism: Suspicious activity persists when teams fail to preserve evidence, do not connect related accounts or transactions, or rely on incomplete explanations that are not independently verified. In AML terms, the weakness is not only missed detection, but also poor escalation discipline and weak decision accountability.
Impact: The organisation can retain a risky relationship longer than intended, fail to file a required report, and leave related activity unmonitored. In the worst case, that creates compounding exposure across fraud, sanctions, and financial crime controls.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM — Risk Management Strategy | Suspicious activity demands a governed risk decision on continuation, escalation, and containment. |
| RS.CO — Response Coordination | EDD findings require coordinated escalation, documentation, and reporting across teams. | |
| DE.AE — Anomalies and Events | EDD starts from anomalous activity that must be validated and triaged. | |
| Recommendation — Use risk management criteria to decide whether to continue, restrict, or exit the relationship. Coordinate case escalation, reporting, and containment so review does not stall in silos. Triage anomalous behaviour against expected patterns and preserve the evidence trail. | ||
| CIS Controls v8 | 6 — Access Control Management | Suspicious relationships may require freezing, restricting, or revoking account access paths. |
| 8 — Audit Log Management | EDD depends on retaining evidence and traceable analyst decisions for review and reporting. | |
| Recommendation — Revoke or restrict access promptly when suspicious activity cannot be safely contained. Retain logs and case records that support the final disposition and any required filing. | ||
| MITRE ATT&CK | T1078 — Valid Accounts | Suspicious activity often indicates abuse of legitimate accounts or credentials. |
| Recommendation — Hunt for legitimate-account abuse and correlate activity across related records and channels. | ||
Practitioner Guidance
What to prioritise: Preserve the case record first, then decide whether the activity is explainable, containable, or reportable. If those three outcomes are still unclear after internal review, treat the case as unresolved rather than closed.
Decision rule: If the suspicious activity affects ongoing customer, counterparty, or account risk and cannot be convincingly explained, escalate to reporting and consider restriction or exit before extending the investigation window.
What to verify: Verify that the decision path is defensible, that supporting evidence is retained, and that related relationships have been checked for the same pattern. The common mistake is allowing a strong commercial relationship to soften the evidentiary threshold.
Practitioner takeaway: The real control is not the EDD review itself, but the quality of the decision that follows it, especially when the correct outcome is to constrain, report, or stop the relationship.
Related resources from NHI Mgmt Group
- Who is accountable when enhanced due diligence reveals suspicious activity?
- Why does enhanced due diligence need ongoing monitoring after onboarding?
- How should security teams apply enhanced due diligence to high-risk identities?
- What should teams do first after discovering suspicious activity in an MDM platform?