Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What are the signs that a customer’s risk…
Governance, Ownership & Risk

What are the signs that a customer’s risk profile is changing after onboarding?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Governance, Ownership & Risk

Warning signs include sudden large cash deposits, repeated transfers to another country, activity involving higher risk jurisdictions, and transactions that no longer fit the customer’s expected profile. Adverse media linking the customer to illegal activity is another signal. When these indicators appear, firms should reassess the customer, increase monitoring, and consider enhanced due diligence or restrictions if warranted.

How to recognise a meaningful shift in customer behaviour after onboarding

The clearest signal is not a single unusual transaction, but a pattern that changes the customer’s expected behaviour profile. That includes new value levels, new destinations, new channels, or activity that appears inconsistent with what was verified at onboarding. In AML/KYC practice, the question is whether the relationship still fits the original risk assessment and due diligence basis.

For a useful review, compare recent activity against the customer’s stated business model, source of funds, geographies, counterparties, and frequency. A genuine shift usually shows up as repeated exceptions, not one-off noise. The point is to decide whether the customer’s risk rating, monitoring rules, and due diligence depth still match current reality.

Signals that the original profile no longer fits

Common change indicators include sudden large cash deposits, repeated transfers to another country, activity involving higher-risk jurisdictions, and transactions that no longer fit the customer’s expected profile. Adverse media linking the customer to illegal activity is another strong signal, especially when it aligns with a change in transaction behaviour or counterparties.

Other signals are more subtle: a customer may begin using new payment corridors, increase transaction velocity, add new beneficial owners or counterparties, or move into products that were not part of the original onboarding rationale. The practical issue is whether the new pattern can be explained by a legitimate change in the customer’s circumstances or whether it creates a new risk picture.

When those signs appear, the customer should be reassessed rather than simply watched passively. That usually means confirming whether the original KYC file is stale, whether the expected activity profile needs to be rewritten, and whether the monitoring scenario set is still tuned to the right thresholds and geographies.

What firms should do when the risk profile changes

The response should be proportional to the size of the deviation and the seriousness of the new exposure. A modest change may justify updated monitoring and a refreshed customer review. A sharper shift, especially one involving high-risk jurisdictions, unusual cash activity, or adverse media, may justify enhanced due diligence, source of funds checks, senior review, or temporary restrictions while the facts are validated.

This is where good case handling matters. Firms should document what changed, why it matters, what evidence was reviewed, and what decision was taken. If the customer cannot explain the change coherently, or if the explanation conflicts with payment behaviour, corporate structure, or third-party information, the case should be escalated through the relevant AML governance path.

External guidance on customer due diligence and ongoing monitoring is aligned with this approach, including the FATF Recommendations and the EBA AML/CFT Guidance. For practitioners, the key is to tie the operational response to the evidence of change, not to treat every unusual payment as proof of misconduct.

Risk and Threat Considerations

Changing customer behaviour is risky because it can mark the point where an originally low or medium risk relationship becomes misaligned with the controls applied to it. If firms fail to recognise that shift, they may miss layering, sanctions exposure, mule activity, or criminal use of a legitimate account structure.

Failure mechanism: The monitoring baseline remains anchored to onboarding assumptions while the customer’s actual behaviour, geography, or counterparties change. That creates a detection gap, and suspicious activity can continue long enough to build volume, conceal origin, or move value through higher-risk routes.

Impact: The firm may under-escalate a customer, miss suspicious activity reporting triggers, or continue a relationship under a risk rating that is no longer defensible. In regulated environments, that can create compliance findings, remediation work, and reputational damage, especially if the pattern was persistent and observable.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingRisk profile changes can expose stale customer records and controls.
Recommendation — Reassess and retire outdated customer assumptions when behaviour no longer matches the original profile.
NIST CSF 2.0ID.AM-01 — Identities and assets are inventoriedOngoing customer review depends on an accurate, current customer record.
Recommendation — Keep customer and account records current so changed behaviour is evaluated against the right baseline.
CIS Controls v8CIS-1 — Inventory and Control of Enterprise AssetsCustomer profile change detection relies on maintaining an accurate population and context record.
Recommendation — Maintain complete customer inventory and context records to support ongoing monitoring.
NIST SP 800-53 Rev 5AU-6 — Audit Record Review, Analysis, and ReportingChanged-risk signals depend on reviewing transaction and alert evidence.
Recommendation — Review transaction evidence and alert patterns to identify material changes in customer behaviour.
ISO/IEC 27001:2022A.5.18 — Access rightsProfile changes can require adjusting permissions or relationship access to financial services.
Recommendation — Review and adjust access or relationship permissions when customer risk materially increases.

Practitioner Guidance

What to verify: Compare the new behaviour with the original expected activity profile, source of funds narrative, ownership structure, and jurisdictional footprint. If the change is recurring rather than isolated, treat it as a potential profile reset, not just an alert to suppress.

Decision rule: If the customer’s explanation is plausible but the pattern is still materially different, refresh the profile and increase monitoring. If the explanation is weak, inconsistent, or contradicted by adverse media or high-risk routing, escalate for enhanced due diligence and consider restrictions before the exposure grows.

Practitioner takeaway: The important judgement is whether the customer’s current behaviour still fits the reason the relationship was approved; once that fit breaks, monitoring and due diligence should change with it.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org