Join our Newsletter — 33% off our NHI Course

Why do the amended regulations push firms toward stronger customer due diligence and transaction monitoring?

The amendments expand AML obligations into more sectors, so firms face more opportunities for higher risk customers, products, and transactions to enter the business. That increases the need to spot when enhanced due diligence is required, especially in cases such as cryptoasset activity or higher value trades. Without stronger checks, firms are more exposed to impersonation, fraud, and compliance failure.

Why stronger due diligence becomes necessary after the amendments

The amendments widen the set of firms and activities that must operate with AML discipline, so customer onboarding becomes a higher-risk gate rather than a routine sales step. That matters because the business now has more routes for risky customers, shell structures, higher-risk jurisdictions, cryptoasset exposure, and unusual payment patterns to enter the firm. Stronger due diligence is the control that separates ordinary customers from those that need enhanced scrutiny before the relationship is accepted or continued.

In practice, this means firms cannot rely on a one-time identity check and a static risk rating. The risk picture changes when products, transaction values, ownership chains, or customer behaviour fall outside the expected profile, so due diligence has to be able to surface beneficial ownership gaps, source-of-funds uncertainty, and impersonation indicators early enough for a decision to be made.

That is why a practical customer risk assessment is now central to operations, not just compliance paperwork. The answer is already reflected in the onboarding evidence that firms collect, and the stronger the amended regime becomes, the more the firm must show that it can justify why a customer was accepted, rejected, or escalated for enhanced due diligence.

Why transaction monitoring has to do more work than before

Stronger due diligence helps at entry, but it does not catch everything once the relationship is active. transaction monitoring is needed because laundering, fraud, and impersonation often become visible only when activity is compared with expected customer behaviour over time. When firms expand into new sectors or higher-value activity, the gap between stated purpose and actual transaction patterns becomes easier to exploit and harder to see without continuous monitoring.

The practical change is that monitoring rules must look for behavioural drift, not just obvious threshold breaches. A firm should expect to test for patterns such as rapid movement of funds, unusual counterparties, structuring, repeated use of high-risk payment routes, and activity that does not align with the customer’s stated business model or risk profile. For higher-risk products, that baseline needs to be tighter and reviewed more often.

Monitoring is also the way firms prove that enhanced due diligence was not a paper exercise. If alerts are not reviewed, escalated, and resolved with documented judgement, the firm may still be exposed even if the initial customer file looked complete. That is especially true where the customer profile can change quickly, such as in cryptoasset-related activity or cross-border transactions.

What the amendments change for front-line firms

The main operational shift is that firms need a risk-based process that can scale without becoming purely manual. The strengthened regime pushes teams to align customer acceptance, ongoing review, and alert handling into one control loop, rather than treating them as separate compliance tasks. Where the firm has more complex customer types or more transactional velocity, the threshold for enhanced due diligence should be lower and the evidence standard higher.

For practitioners, the key point is that stronger checks are not only about catching criminals after the fact. They are also about preventing weak onboarding, poor verification, and incomplete monitoring from turning into a systemic control failure. In that sense, the amendments reward firms that can demonstrate consistent triage, clear escalation paths, and defensible decisions across the full customer lifecycle.

Risk and Threat Considerations

Wider AML obligations increase the attack surface for impersonation, fraud, and laundering attempts because more customers, products, and transaction types have to be accepted under time pressure. If the firm’s controls are too light, high-risk activity can enter as a legitimate-looking relationship and then move through the business before suspicion is raised.

Failure mechanism: Weak identity verification, shallow beneficial ownership review, or poorly tuned monitoring allows higher-risk activity to be treated as ordinary business, so red flags appear only after funds have moved or records have aged out.

Impact: The firm can miss suspicious activity, fail to apply enhanced due diligence where required, and face regulatory, financial, and reputational consequences, including exposure to fraud proceeds and compliance breaches.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-2 — Identification and Authentication (Organizational Users) Customer due diligence depends on reliable identity verification and account trust.
AU-6 — Audit Review, Analysis, and Reporting Transaction monitoring relies on reviewing and analysing events for suspicious activity.
AC-6 — Least Privilege Enhanced due diligence limits what higher-risk customers or processes can do.
Recommendation — Strengthen identity proofing and authentication before granting customer access or onboarding approval. Review transaction events and alerts routinely to identify suspicious patterns and escalate them quickly. Limit access and transaction capability until enhanced checks justify broader permissions.
CIS Controls v8 CIS-5 — Account Management Customer onboarding and ongoing review require controlled account lifecycle management.
Recommendation — Track account creation, review, and removal so risky relationships do not persist unchecked.
NIST CSF 2.0 DE.CM-01 — Network Monitoring Continuous transaction monitoring is a detection function that spots abnormal activity.
Recommendation — Continuously monitor activity for deviations from expected customer behaviour and escalate anomalies.

Practitioner Guidance

What to prioritise: Put the highest effort into the points where customer acceptance, product risk, and transaction behaviour meet. If the customer cannot explain source of funds, ownership, or trading purpose clearly, treat that as a decision point for enhanced due diligence rather than a documentation chase.

What to verify: Confirm that monitoring rules are calibrated to the actual products and customer segments the firm now serves, not to the narrower business model that existed before the amendments. The important test is whether the control would still flag unusual activity if the customer were technically valid but behaviourally inconsistent.

Practitioner takeaway: The compliance burden is really a control-design problem, firms that can connect customer risk scoring to ongoing transaction behaviour will catch the cases that static onboarding checks miss.