Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk How should organisations build an AML compliance programme…
Governance, Ownership & Risk

How should organisations build an AML compliance programme for Italy when customer relationships are opened remotely?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 27, 2026 Domain: Governance, Ownership & Risk

Organisations should map Italian AML obligations to the full customer lifecycle, starting with identity collection, verification, and due diligence before account opening. For non-face-to-face relationships, controls should be risk-based, documented, and supported by reliable evidence. The programme should also retain records, escalate exceptions, and align operational checks with the specific legal requirements that apply in Italy.

Why This Matters for Security Teams

An AML programme for remotely opened Italian customer relationships has to do more than collect documents. It must prove that identity evidence, verification, and due diligence were performed before the relationship was activated, and that exceptions were handled under documented risk-based rules. That makes the control problem both regulatory and operational: if the process is weak, the firm may onboard the wrong customer, miss beneficial ownership signals, or fail to retain defensible evidence for audit and challenge.

Current guidance from the FATF Recommendations — AML and KYC Framework makes clear that customer due diligence must be risk-based, but remote onboarding increases the burden on the institution to show how that risk was assessed and mitigated. NHI Management Group’s Ultimate Guide to NHIs — Regulatory and Audit Perspectives is relevant here because the same governance problem appears in both domains: controls fail when evidence is scattered, lifecycle ownership is unclear, and revocation or escalation is not operationalized.

For Italy, the practical test is whether the onboarding workflow can withstand review after the fact, not whether the customer passed a single verification checkpoint. In practice, many security and compliance teams encounter weaknesses only after an exception, freeze, or audit request has already exposed gaps in the remote onboarding trail.

How It Works in Practice

A workable programme ties Italian AML obligations to a controlled workflow that starts before account opening and continues through ongoing monitoring. Security and compliance teams should define what evidence is required for each risk tier, how that evidence is validated, and which cases require manual review. The same discipline that underpins NIST Cybersecurity Framework 2.0 also applies here: identify, protect, detect, respond, and recover in a way that can be demonstrated to regulators.

Operationally, remote onboarding usually needs a sequence like this:

  • Capture identity data and supporting documents from a trusted channel.
  • Verify document authenticity and consistency against declared profile data.
  • Perform sanctions, PEP, and adverse media screening before activation.
  • Apply risk scoring that reflects geography, product type, delivery channel, and ownership complexity.
  • Require enhanced due diligence where indicators warrant it, with escalation paths that are logged and time bound.
  • Retain the full evidence set, including exceptions and approvals, for the required retention period.

That workflow should be supported by controls that preserve auditability. The NIST SP 800-53 Rev 5 Security and Privacy Controls offers useful control patterns for access control, audit logging, and integrity protection, while NHI Management Group’s Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs is a useful analogue for designing lifecycle checkpoints, approvals, and revocation-style offboarding discipline. The key is to make onboarding decisions reproducible, not informal.

These controls tend to break down when remote onboarding is treated as a front-end form submission rather than a governed lifecycle with authenticated evidence, human review, and immutable recordkeeping.

Common Variations and Edge Cases

Tighter verification often increases friction and abandonment, so organisations have to balance customer experience against evidentiary strength and regulatory defensibility. That tradeoff is especially visible when customers are cross-border, corporate, or represented by intermediaries.

There is no universal standard for remote AML evidence sufficiency across all Italian customer types, so current guidance suggests a risk-based approach rather than a single fixed checklist. For low-risk retail cases, streamlined checks may be acceptable if the institution can still show reliable identity proofing and screening. For higher-risk customers, such as complex legal entities or politically exposed persons, enhanced due diligence should be triggered early, not after account activation.

Edge cases often arise where the relationship is opened through digital channels but relies on third-party verification, delegated signing authority, or document sources that are hard to authenticate. In those situations, organisations should document why the control is trustworthy, who is accountable for it, and what would cause the case to be rejected or escalated. The ISO/IEC 27001:2022 Information Security Management and ISO/IEC 27002:2022 Information Security Controls are helpful for structuring governance and evidence handling, but they do not replace Italy-specific legal interpretation.

NHI Management Group’s Top 10 NHI Issues reinforces a parallel lesson: governance fails when identity, access, and evidence are managed as isolated tasks instead of one controlled lifecycle. For AML programmes, the same pattern means remote onboarding controls must be consistent, reviewable, and resilient to exception handling.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the technical controls, and NIS2 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1Remote onboarding depends on verified identity and controlled access before activation.
NIST SP 800-63IAL2Identity proofing strength is central to remote customer due diligence.
OWASP Non-Human Identity Top 10NHI-01Lifecycle governance and evidence retention mirror secure identity management discipline.
NIST AI RMFRisk governance and accountability support defensible AML decisioning for remote channels.
NIS2Operational resilience and governance expectations reinforce controlled evidence handling.

Tie onboarding gates to verified identity evidence before any customer relationship is activated.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org