Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should financial institutions balance de-risking with a…
Governance, Ownership & Risk

How should financial institutions balance de-risking with a risk-based AML programme?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Governance, Ownership & Risk

Financial institutions should use de-risking as a targeted control, not a blanket refusal strategy. The better approach is to segment clients and activities by risk, apply enhanced due diligence where needed, and reserve termination for relationships that remain unmanageable. That keeps exposure lower while preserving access for legitimate customers and aligns decisions with a documented risk-based framework.

How de-risking should fit inside a risk-based AML programme

De-risking is best treated as one response within a wider anti-money laundering framework, not as a substitute for risk assessment. A sound programme starts by classifying customers, products, geographies and channels, then applies controls proportionate to the risk profile. That lets institutions reduce exposure without turning risk management into indiscriminate exclusion.

The practical distinction is that a risk-based AML programme asks what level of monitoring, due diligence, and escalation is warranted, while de-risking asks whether the relationship can be supported at all. Those are not the same decision. If firms collapse the two, they can end up rejecting entire customer segments that could have been managed with stronger controls.

International AML expectations are built around this risk-based logic, including customer due diligence, beneficial ownership checks, and ongoing monitoring. FATF’s Recommendations, AML and KYC Framework set the baseline for matching controls to risk rather than defaulting to blanket refusals, while FinCEN guidance reinforces that institutions need risk-based programme design and suspicious activity reporting, not simple account avoidance.

Where targeted de-risking is justified

Targeted de-risking is appropriate when the institution cannot obtain enough information to understand the customer, cannot monitor activity effectively, or cannot bring the exposure back within acceptable appetite through enhanced due diligence. In those cases, termination can be the right outcome, especially when the relationship presents persistent opacity, sanctions exposure, fraud indicators, or repeated control failures.

The key is to make the decision relationship by relationship, not by broad label. High-risk customers are not automatically unmanageable, and low-risk customers should not be rejected because they belong to a broad category that has attracted negative attention elsewhere. A defensible programme uses escalation thresholds, enhanced review, and documented exceptions before it closes the door.

That approach is aligned with supervisory expectations in major jurisdictions. The EBA AML/CFT Guidance and FATF both support proportionate controls, while the risk decision should be anchored in evidence from onboarding, transaction monitoring, and beneficial ownership analysis rather than in reputation alone.

How to keep the programme defensible and inclusive

A defensible balance comes from separating policy, operations, and exceptions. Policy should define the risk appetite and the factors that trigger enhanced due diligence or exit. Operations should use consistent segmentation, monitoring rules, and case management. Exceptions should be rare, approved, and reviewable, so the institution can show that decisions were made on evidence, not convenience.

Institutions also need to watch for hidden operational drift. When teams use de-risking to compensate for weak onboarding, poor monitoring, or overstretched investigators, the control becomes a blunt instrument that shifts the problem rather than solving it. The healthier pattern is to strengthen the AML process, then reserve de-risking for the residual cases that remain outside appetite after controls are applied.

For institutions operating across multiple jurisdictions, consistency matters as much as strictness. The same customer type may look different under different legal and supervisory expectations, so the risk model needs enough structure to support local variation without becoming arbitrary. That is where documented criteria and audit trails become as important as the final exit decision.

Risk and Threat Considerations

Overusing de-risking creates two forms of exposure: it can push legitimate activity out of regulated channels, and it can leave firms blind to where real financial crime risk is concentrating. A blunt exit policy also raises fairness and financial inclusion concerns, which can become supervisory and reputational issues when the institution cannot explain why a relationship was not manageable.

Failure mechanism: The institution substitutes categorical refusal for a risk-based control stack, so it loses segmentation, monitoring, and escalation discipline. That can produce either unnecessary exclusion or under-controlled residual risk, depending on how the policy is applied.

Impact: The firm may violate supervisory expectations, miss suspicious activity that should have been escalated, or create a documented pattern of inconsistent customer treatment that is difficult to defend in review.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyBalances de-risking against AML risk appetite and documented risk-based decisions.
ID.RA-01 — Asset Vulnerabilities and Risk IdentificationSupports customer, product and channel risk segmentation before de-risking decisions.
Recommendation — Define a risk appetite that distinguishes manageable AML risk from relationships that must be exited. Identify and segment AML risk drivers before deciding whether controls or exit are appropriate.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeSupports proportional limitation of access and activity in risk-managed relationships.
Recommendation — Apply the minimum access and activity permissions consistent with the customer relationship.
ISO/IEC 27001:2022A.5.12 — Classification of informationRisk-based AML depends on classifying customer and transaction risk consistently.
Recommendation — Classify customers, products and channels so AML controls scale with documented risk.
CIS Controls v8CIS-5 — Account ManagementRelevant to governed approval, review and termination decisions for customer relationships.
Recommendation — Use formal account lifecycle governance to review, restrict or terminate unmanaged relationships.

Practitioner Guidance

What to prioritise: Build a decision tree that distinguishes manageable high risk from unmanageable risk. If enhanced due diligence, tighter monitoring, or product restrictions can reasonably contain the exposure, use those measures before considering termination.

What to verify: Every exit decision should be traceable to a documented risk factor, a failed mitigation attempt, or an inability to obtain required information. If the record only says the customer was “too risky,” the decision is not yet defensible.

Practitioner takeaway: The most effective AML programmes do not choose between de-risking and risk-based management, they use de-risking as the final step after proportionate controls have been tried and documented.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org