Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM How should financial institutions implement enhanced due diligence…
Identity Beyond IAM

How should financial institutions implement enhanced due diligence for high-risk customers?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 16, 2026 Domain: Identity Beyond IAM

Financial institutions should use enhanced due diligence as a risk-based process, not a one-size-fits-all checklist. Start by collecting and validating core identity data, then add deeper review of source of funds, business purpose, ownership structure, and transaction behaviour. Apply stronger monitoring to higher-risk relationships, keep records, and update risk ratings as new information emerges.

Why This Matters for Security Teams

enhanced due diligence is the control that turns customer onboarding from a binary approve-or-reject exercise into an ongoing risk decision. For financial institutions, the practical challenge is not simply identifying a high-risk customer, but proving that the customer’s profile, purpose, funds, ownership, and behaviour are internally consistent over time. That matters because weak due diligence creates exposure to money laundering, sanctions evasion, fraud, and regulatory findings, especially where layered entities or opaque funding sources make the first pass look benign. Current AML guidance expects institutions to go beyond surface checks when the risk profile justifies it, which is why EBA AML/CFT Guidance is directly relevant to how institutions should scale the depth of review. In practice, many failures happen because the initial risk rating is treated as static, rather than as a decision that should tighten or loosen as new evidence arrives.

Enhanced due diligence also serves a governance function. It creates a defensible record of why a customer was accepted, what extra scrutiny was applied, and what triggered escalation. In a financial crime programme, that audit trail is often as important as the review itself.

How It Works in Practice

Effective enhanced due diligence starts with a baseline customer record and then adds scrutiny only where the risk factors justify it. That means institutions should first confirm core identity information, then collect supporting evidence that explains why the relationship exists and how it will be used. For corporate customers, that usually includes beneficial ownership, control structure, expected activity, source of wealth where relevant, and a clear business rationale. For individuals, the review often focuses on source of funds, occupation or economic purpose, geographic exposure, and whether expected account behaviour matches the declared profile.

Practically, the process works best when it is built as a decision chain rather than a document stack:

  • Establish the customer risk rating before opening the relationship.
  • Define which triggers require escalation, such as adverse media, high-risk jurisdiction exposure, unusual complexity, or unexplained payment patterns.
  • Apply stronger ongoing monitoring so transaction behaviour is compared against the original profile, not just screened in isolation.
  • Record the evidence reviewed, the rationale for the decision, and the review cadence for refreshes.
  • Reassess the rating when ownership, purpose, counterparties, or transaction patterns materially change.

Regulators and supervisory bodies generally expect EDD to be risk-based, proportionate, and repeatable, not a manual ceremony reserved for a few obvious cases. That is why institutions often pair policy with typology-based playbooks and escalation thresholds rather than relying on individual analyst judgement alone. A useful external reference point is FATF Recommendations , AML and KYC Framework, which anchors customer due diligence, beneficial ownership, and ongoing monitoring expectations.

These controls tend to break down when customer due diligence, onboarding ops, and transaction monitoring sit in separate workflows because the evidence does not feed back into the risk rating.

Common Variations and Edge Cases

Tighter due diligence often increases onboarding time and investigator workload, so institutions have to balance speed against the cost of false confidence. The trade-off is most visible in correspondent banking, complex corporate structures, politically exposed persons, cross-border customers, and customers using intermediaries or opaque source-of-funds documentation. In those cases, the standard checklist is rarely enough, and current guidance suggests that institutions should expand review depth in proportion to complexity rather than apply a fixed package to every high-risk file.

Some edge cases require a different emphasis. A newly formed company with a legitimate but fast-scaling business model may need more scrutiny of expected payment flows than of trading history. A long-standing customer can still warrant enhanced review if ownership changes or activity shifts abruptly. High-risk does not always mean suspicious, but it does mean the institution should be able to explain why the relationship is credible and what evidence supports that conclusion.

For global institutions, the most common variation is jurisdictional. Different regulators may expect different refresh cycles, document types, or escalation thresholds, but the underlying discipline is the same: verify the story, test the story against activity, and revisit the decision when facts change. Where FinCEN guidance is part of the operating environment, teams should make sure suspicious activity escalation and recordkeeping are aligned with the EDD workflow rather than treated as separate obligations.

When counterparties, ownership layers, or payment corridors are especially opaque, the review often stops being about customer acceptance and becomes a question of whether the institution can continue the relationship with a credible monitoring model.

Risk and Threat Considerations

High-risk customers create elevated exposure to financial crime, sanctions breaches, fraud, and regulatory scrutiny because the institution is being asked to trust a relationship that is harder to verify and easier to misuse. The risk is not limited to bad actors at onboarding, it also includes later drift, where a once-credible customer gradually becomes inconsistent with the original profile.

Failure mechanism: The main failure pattern is weak source-of-funds validation, poor beneficial ownership transparency, or ineffective ongoing monitoring, which allows illicit activity to blend into ordinary account behaviour. Complexity, intermediaries, and inconsistent documentation make that easier to miss, especially when analysts are overloaded or risk ratings are not refreshed.

Impact: The institution can end up processing suspicious flows, missing red flags, filing late or incomplete reports, and inheriting supervisory findings or remediation costs. In the worst case, the firm becomes a reliable channel for laundering or sanctions evasion rather than a gatekeeper.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM — Risk Management StrategyEDD is a risk-based control decision for customer relationships.
ID.RA — Risk AssessmentEDD depends on assessing customer, ownership, and transaction risk.
PR.AA — Identity Management, Authentication, and Access ControlEDD begins with validating customer identity and authority evidence.
Recommendation — Define escalation thresholds and review cadence for high-risk customers. Assess customer risk factors before applying enhanced review depth. Validate identity and authority evidence before approving the relationship.
CIS Controls v85 — Account ManagementEDD needs review, approval, and lifecycle control over customer profiles.
6 — Access Control ManagementEDD relies on limiting who can approve exceptions and escalate cases.
8 — Audit Log ManagementEDD requires records of review, rationale, and escalation decisions.
Recommendation — Review and retain customer account evidence through the relationship lifecycle. Restrict EDD exceptions to authorised reviewers and approvers. Log due diligence decisions and retain the evidence trail for audit.
NIST SP 800-63IAL — Identity Assurance LevelEDD starts by validating the reliability of customer identity evidence.
AAL — Authentication Assurance LevelHigh-risk customer access channels need stronger assurance where applicable.
FAL — Federation Assurance LevelThird-party or federated onboarding flows require stronger trust validation.
Recommendation — Match identity evidence requirements to the customer risk profile. Apply stronger authentication assurance to sensitive customer access paths. Validate federated identity trust before accepting external assertions.

Practitioner Guidance

What to prioritise: Put the highest effort into the elements that explain the money, the control structure, and the expected behaviour. If those three do not line up, the file should stay open until they do.

What to verify: Verify that the risk rating is actually driving review depth. A common mistake is collecting extra documents without changing monitoring intensity, refresh frequency, or escalation thresholds.

Decision rule: If new information changes ownership, purpose, geography, or transaction pattern, treat it as a risk-rating event, not just a file update.

Practitioner takeaway: Enhanced due diligence works when it changes decisions over time, not when it merely creates a thicker onboarding file.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 16, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org