Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM What are the signs that a customer relationship…
Identity Beyond IAM

What are the signs that a customer relationship needs enhanced due diligence?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 16, 2026 Domain: Identity Beyond IAM

A relationship needs EDD when the customer sits in a higher risk jurisdiction, operates in a vulnerable industry, shows unusual cash movement, or has complex ownership and licensing issues. Politically exposed persons, unexplained transaction spikes, and adverse media are also warning signs. When several indicators cluster together, teams should treat the case as elevated risk and investigate more deeply.

Why This Matters for Security Teams

enhanced due diligence is the point where routine customer onboarding stops being enough and the organisation has to test the relationship against wider financial crime, fraud, sanctions, and reputational exposure. The trigger is rarely one signal by itself. More often, teams see a jurisdictional concern, opaque ownership, adverse media, or transaction behaviour that does not fit the stated profile, then discover that the real issue is the combination. That is why KYC and AML processes need escalation paths, not just checklists. The EBA AML/CFT Guidance remains a useful reference point for how institutions are expected to deepen scrutiny when risk rises. In practice, many teams first encounter the need for EDD only after transactions, counterparties, or ownership structures have already created more exposure than the initial file suggests.

How It Works in Practice

EDD is a risk-based escalation, not a separate customer class. Teams usually start by comparing the customer’s stated business model, location, and expected activity against the evidence collected so far, then looking for contradictions that require more scrutiny. The most important step is not to ask, “Is this customer unusual?”, but “What part of the relationship is not yet explained well enough to trust the profile?” That is what turns a normal file review into a deeper investigation.

  • Jurisdictional risk: higher-risk geographies, weak controls, or cross-border complexity can make source-of-funds and source-of-wealth checks more important.
  • Ownership and control: layered entities, nominees, trusts, or licensing ambiguity often require a clearer beneficial ownership picture.
  • Activity mismatch: cash intensity, spikes in volume, circular flows, or payments that do not match the expected business model can indicate elevated risk.
  • Counterparty and media risk: PEP status, sanctions proximity, adverse media, or linked third parties may justify deeper review even when the customer itself appears ordinary.
The operational test is whether the team can defend the relationship to an internal reviewer or regulator without relying on assumptions. Where that defence depends on incomplete or contradictory information, EDD should require additional documentation, senior approval, or enhanced monitoring. The FATF Recommendations are the clearest global baseline for that escalation logic. These controls tend to break down when ownership chains are complex but the business insists the relationship is “low risk” because the customer is already known to sales.

Common Variations and Edge Cases

Tighter due diligence often increases friction, so organisations have to balance investigative depth against onboarding speed and customer experience. The practical question is not whether every unusual factor should trigger the same response, but whether the unusual factor is explainable, isolated, or part of a broader risk pattern.

Some cases are genuinely high risk from the outset, such as politically exposed persons, opaque offshore structures, or activity that is hard to reconcile with the customer’s stated purpose. Others become material only when indicators cluster, for example a moderate-risk jurisdiction plus complex ownership plus unexplained transaction spikes. Best practice is evolving toward that cumulative view rather than a single-signal approach.

Edge cases also matter. A customer may be legitimate but still require EDD because the sector is cash-heavy, the licensing regime is fragmented, or the entity has multiple layers of third-party control. The right response is proportionate: collect more evidence, verify more deeply, and monitor more closely, rather than assuming the issue is either benign or malicious on first sight.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM — Risk Management StrategyEDD is a risk-based escalation decision requiring governance over customer risk.
GV.OV — OversightEDD depends on oversight of elevated-risk relationships and approvals.
ID.RA — Risk AssessmentEDD is triggered by assessing jurisdiction, ownership, media, and activity risk.
Recommendation — Align customer escalation rules to a documented risk management strategy. Require oversight for customers that exceed standard risk thresholds. Assess customer risk factors before relying on standard due diligence.
CIS Controls v812 — Network Infrastructure ManagementCustomer due diligence relies on monitoring and control of exposure paths.
Recommendation — Strengthen monitoring and approval paths for higher-risk customer activity.
NIST SP 800-635.1.2 — Identity Proofing RequirementsEDD often requires stronger proofing when identity evidence is incomplete or inconsistent.
Recommendation — Increase proofing rigor when customer evidence does not match the declared profile.

Practitioner Guidance

What to prioritise: Treat explanation quality as the main decision point. If the customer’s ownership, source of funds, expected activity, or counterparty profile cannot be reconciled quickly, that is usually a stronger EDD signal than any single headline risk factor on its own.

What to verify: Confirm that the case file supports the stated risk rating with evidence, not narrative. The practical standard is whether another reviewer could understand why the relationship was accepted, escalated, or rejected without having to guess.

Decision rule: If two or more moderate concerns cluster, escalate to EDD even when none of them alone looks decisive. If one high-risk factor is present, such as a PEP link or an opaque ownership chain, require deeper verification before allowing the relationship to proceed on standard terms.

Practitioner takeaway: The strongest EDD trigger is usually not one dramatic red flag, but the point at which the customer profile stops being internally consistent enough to trust at ordinary due diligence depth.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 16, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org