Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should financial firms identify high-risk customers during…
Governance, Ownership & Risk

How should financial firms identify high-risk customers during onboarding and ongoing monitoring?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Governance, Ownership & Risk

Financial firms should use a risk based customer due diligence process that combines identity verification, beneficial ownership review, sanctions and PEP screening, adverse media checks, and transaction monitoring. The goal is to match the depth of review to the customer’s profile and activity. If risk indicators change after onboarding, enhanced due diligence should be triggered and the relationship monitored more closely.

What “high-risk” means in financial onboarding

High-risk customers are not identified by a single red flag. Firms typically assess a combination of customer type, geography, ownership structure, business activity, source of funds, delivery channel, and expected transaction behaviour. The core test is whether the relationship creates elevated money-laundering, sanctions, fraud, or reputational exposure that justifies deeper due diligence and tighter monitoring.

A practical screening model starts with risk scoring, but it should not end there. Firms need clear triggers for enhanced due diligence when the customer profile is complex, opaque, unusually urgent, or inconsistent with stated purpose. That is especially important when beneficial ownership is difficult to verify or when the customer’s activity profile is not easy to explain from the onboarding information alone.

For firms that need a common control baseline, AML due diligence principles and customer risk classification guidance from FATF Recommendations, AML and KYC Framework and EBA AML/CFT Guidance provide the clearest external reference points for customer due diligence, beneficial ownership, and ongoing monitoring expectations.

How onboarding controls should combine identity, ownership, and screening

Good onboarding is layered. Identity verification establishes who the customer is, beneficial ownership review establishes who ultimately controls or benefits from the relationship, and sanctions, PEP, and adverse media screening establish whether the person or entity sits inside a known risk zone. Each control answers a different question, so firms should not treat one as a substitute for the others.

The main failure mode is over-reliance on a clean ID check or on a single database match. A low-risk appearance at onboarding can still hide higher-risk control relationships, shell structures, or politically exposed connections. The onboarding process should therefore compare declared purpose, ownership, jurisdiction, and expected activity against what the customer can actually evidence, then escalate any material mismatch.

For firms that want their onboarding checks tied to broader security and access governance, identity verification and review discipline align well with NIST SP 800-53 Rev. 5 Security and Privacy Controls for authentication and auditability, and NIST SP 800-63 Digital Identity Guidelines for assurance and proofing decisions. For financial firms that operate in cloud or platform-heavy environments, NIST Cybersecurity Framework 2.0 also provides a useful control-language bridge between identity, monitoring, and response.

What ongoing monitoring must detect after onboarding

Onboarding risk is only the starting point. Ongoing monitoring should look for changes in transaction patterns, account behaviour, beneficial ownership, geography, counterparties, and adverse information that make the original risk score stale. A customer that was acceptable at onboarding may become high risk later because activity volume, payment rails, destination countries, or ownership structure changes materially.

Transaction monitoring is strongest when it is scenario-based and customer-specific, not just threshold-driven. Firms should tune monitoring to the expected profile captured at onboarding, then investigate deviations such as round-dollar movement, rapid in-and-out flows, unusual counterparties, structuring patterns, or activity inconsistent with declared business purpose. When a monitoring alert confirms a real change in risk, the response should be enhanced due diligence, not a routine case closure.

For firms handling regulated payments or exposed services, controls in PCI DSS v4.0 illustrate the broader principle that access and account handling must follow business need, while FinCEN remains a useful source for AML obligations and suspicious activity expectations in the United States.

Risk and Threat Considerations

High-risk customer identification fails most often when firms treat onboarding as a one-time event or rely on isolated checks that do not reinforce one another. That creates exposure to synthetic identities, hidden control relationships, sanctions evasion, money mule activity, and delayed detection when customer behaviour changes after the account is opened.

Failure mechanism: Weak ownership transparency, poor screening coverage, stale customer risk ratings, or monitoring rules that are too generic can allow higher-risk customers to pass as ordinary relationships until suspicious activity is already established.

Impact: The firm can miss suspicious activity, file reports too late, accept prohibited relationships, or inherit regulatory, financial crime, and reputational exposure that becomes harder to unwind once the relationship is active.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-8 — Identification and Authentication (Non-Organizational Users)Customer onboarding needs identity proofing and verification for external customers.
AU-6 — Audit Review, Analysis, and ReportingOngoing monitoring depends on reviewing account and transaction activity for suspicious change.
Recommendation — Apply IA-8 to verify external customer identities before granting account access. Use AU-6 to review alerts and escalate anomalous customer activity.
NIST CSF 2.0ID.RA-01 — Risk AssessmentCustomer risk scoring and EDD decisions are direct risk-assessment activities.
Recommendation — Perform ID.RA-01 risk assessments to classify customers and update risk ratings when conditions change.
CIS Controls v8CIS-5 — Account ManagementOnboarding and monitoring rely on account lifecycle governance and access review discipline.
Recommendation — Apply CIS-5 to govern customer account lifecycle, review exceptions, and revoke risky access paths.
ISO/IEC 27001:2022A.5.34 — Privacy and protection of PIIKYC and beneficial ownership checks process sensitive personal and business identity data.
Recommendation — Use A.5.34 to protect identity and onboarding data used in customer due diligence.

Practitioner Guidance

What to prioritise: Make the customer risk rating a living decision, not an onboarding label. The best programs connect onboarding data, sanctions and PEP results, beneficial ownership evidence, and monitoring scenarios so that a change in one source can reopen the risk assessment.

What to verify: Confirm that every high-risk decision is explainable from documented evidence, not analyst instinct. If the firm cannot show why a customer was rated high risk, what changed, and why enhanced due diligence was or was not triggered, the control is too weak for audit or regulator review.

Practitioner takeaway: The practical test is whether your firm can detect a risk increase after onboarding quickly enough to change treatment before the relationship becomes materially exposed.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org