Join our Newsletter — 33% off our NHI Course

How should compliance teams handle users who appear legitimate but still show elevated money laundering risk?

Treat them as candidates for enhanced due diligence, not as routine approvals. Recheck identity, screen against sanctions and PEP lists, and examine source of funds, transaction patterns, and business legitimacy. Keep monitoring after onboarding because risk can change over time. If suspicious activity persists, escalate the case and restrict access until the review is complete.

Why Legitimate-Looking Users Still Need Enhanced Due Diligence

When a user looks authentic on the surface but still carries elevated money laundering risk, the right response is to separate identity plausibility from risk acceptability. Compliance teams should treat the case as unresolved, because legitimacy signals do not erase source-of-funds concerns, behavioural anomalies, or adverse intelligence. FATF’s customer due diligence model exists for exactly this reason: AML decisions depend on corroborated risk, not appearance alone, and should be anchored in customer due diligence and ongoing monitoring.

The practical implication is that onboarding should stay conditional until the team has enough evidence to explain the risk profile. That usually means revalidating identity evidence, checking beneficial ownership where relevant, and testing whether the activity makes sense for the stated profile. The decision is not “approve or reject” on a first glance, but “can the team justify acceptance under the documented risk appetite?”

A useful operating rule is to treat “legitimate but high-risk” as a monitoring state, not a comfort state. If the customer’s activity is difficult to reconcile with the declared business model, the file should remain open for enhanced review even if no single data point is dispositive. That keeps compliance from confusing clean paperwork with clean behaviour.

What Evidence Should Change the Risk View?

The most important evidence is not a generic score, it is the relationship between identity, funding source, transaction behaviour, and business purpose. Source of funds and source of wealth matter because they show whether the money flow is explainable. Transaction patterns matter because structuring, rapid movement, unusual counterparties, or routing through higher-risk jurisdictions can point to laundering risk even when the user has passed basic identity checks.

Business legitimacy is also a key test. A real company can still be a weak laundering vehicle if its stated activity does not match its payment volumes, counterparties, geography, or timing. Compliance teams should look for consistency across documents, onboarding statements, and actual activity, then ask whether the pattern would still make sense if the account were reviewed by a skeptical investigator.

For this kind of review, the useful question is not whether the customer exists, but whether the activity is coherent. That is why FATF customer due diligence expectations are built around risk-based assessment, not one-time identity verification.

How to Keep the Case Under Control After Onboarding

High-risk customers require continued monitoring because laundering risk can emerge after the initial review. An account that looked plausible at intake can become suspicious once transaction volumes rise, counterparties change, or cross-border patterns develop. The monitoring process should therefore test whether current behaviour still fits the original narrative, rather than assuming that prior approval remains valid.

Escalation should be triggered by persistence, not just by a single odd event. If anomalies repeat, if explanations change, or if the customer cannot substantiate source of funds, the file should move beyond routine review. In practice, that means enhanced due diligence, tighter case ownership, and restrictions on activity when the team cannot justify continued acceptance.

Internal review discipline matters here because risk teams are often pressured to normalize a case once basic checks pass. That is the wrong threshold. Once the file has indicators of elevated laundering risk, the team should keep the case in active review until the evidence supports either controlled acceptance or formal escalation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-2 — Account Management Covers controlled approval and review of user access for risk cases.
IA-2 — Identification and Authentication (Organizational Users) Supports revalidating identity evidence before trusting a customer relationship.
AU-6 — Audit Review, Analysis, and Reporting Supports ongoing monitoring and escalation of suspicious transaction patterns.
Recommendation — Restrict and review account status until the customer risk case is resolved. Reconfirm identity evidence before allowing higher-risk onboarding to proceed. Review and escalate suspicious activity patterns through audit and monitoring workflows.
NIST CSF 2.0 PR.AA-05 — Identity Management, Authentication, and Access Control Covers identity verification and access decisions for risky users.
Recommendation — Verify identity and apply stronger access decisions for elevated-risk cases.

Practitioner Guidance

What to prioritise: Put explanation quality ahead of checklist completion. A fully populated onboarding record is not enough if the source of funds, business model, or counterparties do not make commercial sense.

Decision rule: If identity is plausible but the economic story is weak, treat the customer as an enhanced due diligence case and keep restrictions in place until the risk is explained, not merely documented.

What to verify: Reconcile KYC data, source of funds evidence, transaction behaviour, and any sanctions or PEP screening results against the stated purpose of the account. Any mismatch should be treated as a live control issue, not an administrative defect.

Practitioner takeaway: The key judgment is whether the relationship can be defended under scrutiny over time; in AML, a legitimate-looking user is still high risk until behaviour and funding are consistent enough to justify acceptance.