Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM How should compliance teams implement risk-based customer due…
Identity Beyond IAM

How should compliance teams implement risk-based customer due diligence under South Africa’s AML rules?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 24, 2026 Domain: Identity Beyond IAM

Compliance teams should start with customer risk assessment, then scale verification depth to the profile of the individual, company, or transaction. That means combining identity verification, beneficial ownership checks, ongoing monitoring, and suspicious activity reporting into one controlled workflow. The practical goal is to document why a customer is low, medium, or high risk, and apply enhanced due diligence where exposure is higher.

Why This Matters for Security Teams

Risk-based customer due diligence is the control that keeps AML programmes from becoming either too shallow to stop abuse or too heavy to operate consistently. South Africa’s AML expectations are built around customer risk, not one-size-fits-all checks, so compliance teams need a defensible way to explain why some customers receive simplified due diligence while others trigger enhanced scrutiny. That decision should be tied to documented risk factors, evidence, and review cadence, not intuition. The broader control logic aligns with the FATF Recommendations - AML and KYC Framework, which emphasise proportionality and ongoing monitoring.

The operational challenge is that risk scoring often gets fragmented across onboarding, sanctions screening, beneficial ownership analysis, and transaction monitoring. When those steps are handled in separate tools or by separate teams, the organisation can no longer show a clear line from customer profile to due diligence depth. That creates audit exposure and weakens suspicious activity detection. In practice, many compliance teams discover inconsistencies only after a high-risk customer has already passed through a low-risk workflow that was never reviewed for escalation.

How It Works in Practice

A workable implementation starts with a documented customer risk taxonomy. That taxonomy should consider customer type, geography, product exposure, delivery channel, ownership complexity, source of funds or wealth, and expected transaction behaviour. The objective is not to create a perfect score, but to create a repeatable and explainable method for deciding what evidence is sufficient at onboarding and what must be refreshed later.

Compliance teams usually implement the process as a tiered workflow:

  • Low-risk customers receive standard identity verification and periodic monitoring.
  • Medium-risk customers trigger extra checks on ownership, purpose, and expected activity.
  • High-risk customers require enhanced due diligence, senior approval, and tighter review intervals.

Controls should also be linked to recordkeeping and escalation. If a customer’s profile changes, the risk rating should be reassessed and the workflow should move automatically to the next due diligence tier. This is where identity assurance becomes important: identity verification, beneficial ownership evidence, and source-of-funds checks need to be consistent enough to stand up to audit and investigation. A security-control perspective helps here, and the control mapping in NIST SP 800-53 Rev 5 Security and Privacy Controls is useful for structuring access, logging, and monitoring expectations around the workflow.

At an organisational level, the due diligence model should be supported by governance, evidence retention, and exception handling. That means defining who can override a rating, when enhanced due diligence is mandatory, and how alerts from transaction monitoring feed back into customer risk. Teams that already run a formal information security management system can often reuse policy discipline from ISO/IEC 27001:2022 Information Security Management and ISO/IEC 27002:2022 Information Security Controls to strengthen approval trails and review cycles. These controls tend to break down when onboarding is optimised for speed without a reliable link between customer classification, beneficial ownership validation, and downstream monitoring rules.

Common Variations and Edge Cases

Tighter due diligence often increases onboarding friction and investigation workload, requiring organisations to balance customer experience against regulatory defensibility. That tradeoff becomes sharper where customers have complex ownership structures, operate across multiple jurisdictions, or use intermediaries that obscure the true relationship to the account.

Current guidance suggests that the biggest edge cases are not high-volume retail customers, but entities with layered ownership, politically exposed persons, cross-border payment activity, or unusual transaction patterns. Best practice is evolving around how much automation is acceptable in these cases, especially where screening tools generate false positives and staff are tempted to accept incomplete evidence just to keep throughput moving. There is no universal standard for this yet, so the operating model should clearly define when human review is required.

South African compliance teams should also be careful not to treat customer due diligence as a one-time onboarding step. Risk-based AML works only when monitoring, periodic review, and suspicious activity escalation remain connected to the original risk rationale. That is the practical difference between a compliant process and a checklist. Where digital onboarding, remote verification, or outsourced verification providers are involved, the organisation should ensure the evidence chain remains intact and the accountable party is always clear.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-63 and NIST SP 800-53 Rev 5 set the technical controls, while PCI DSS v4.0 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01Risk-based due diligence needs a formal risk management process and accountability.
NIST SP 800-63Identity proofing supports customer verification and confidence in onboarding decisions.
PCI DSS v4.012.3.1Strong policy and risk procedures help operationalise controlled onboarding workflows.
NIST SP 800-53 Rev 5AU-2Logging and evidence retention are essential for showing why a customer was assigned risk.

Tie identity proofing strength to customer risk and evidence requirements for each onboarding path.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org