De-risking means reducing or ending exposure to customers or activities perceived as high risk, while enhanced due diligence means keeping the relationship and applying deeper checks. EDD is a control within a risk-based programme. De-risking is a more restrictive decision, used when the institution cannot manage the risk adequately through monitoring, verification, or other safeguards.
How de-risking and enhanced due diligence differ in practice
The practical difference is that enhanced due diligence keeps the relationship and adds scrutiny, while de-risking narrows or exits exposure when the risk cannot be managed acceptably. In financial crime programmes, that choice is usually driven by customer profile, transaction behaviour, product use, and whether the institution can obtain evidence strong enough to support ongoing monitoring.
EDD is therefore a control response within a risk-based process, not a rejection decision. It is designed to improve understanding and confidence so the institution can continue the relationship with proportionate safeguards. De-risking is the more restrictive outcome, and it becomes relevant when the residual risk, uncertainty, or control cost is too high for the institution to sustain.
The distinction matters because the same high-risk signal can lead to different outcomes depending on the institution’s ability to verify source of funds, beneficial ownership, transaction patterns, sanctions exposure, and expected activity. One organisation may continue with tighter controls; another may determine that the only defensible option is to exit the exposure.
Why institutions use EDD instead of immediate de-risking
EDD exists to avoid overreacting to risk indicators that are real but still manageable. A customer can be high risk without being unserviceable, and many cases call for deeper review rather than immediate termination. That usually means collecting more documentation, checking the relationship’s purpose, and confirming that the observed activity matches the customer’s stated profile.
In practice, EDD is most useful when the institution has a plausible way to reduce uncertainty through better evidence. That may include tighter approval steps, more frequent review, stronger transaction monitoring, or restricted products and channels. If the organisation can still set a monitorable boundary, EDD preserves the relationship while lowering blind spots.
De-risking becomes more likely when the institution cannot reach that boundary with confidence. Common reasons include persistent opacity, unreliable customer information, repeated adverse findings, or an activity pattern that is incompatible with the firm’s risk appetite. In those cases, the question is no longer “what extra checks should we do?” but “can we responsibly continue at all?”
What practitioners should look for when deciding between them
The decision is less about labels and more about whether the institution can still explain and control the exposure. Practitioners should separate cases where the risk is high from cases where the risk is ungovernable. EDD is appropriate when the issue is information deficit; de-risking is appropriate when the issue is control infeasibility or unacceptable residual exposure.
That also means the decision must be consistent with the institution’s documented risk appetite and customer acceptance criteria. If a team de-risks purely because a case is operationally inconvenient, it is usually avoiding analysis rather than managing risk. If a team keeps a relationship open without evidence that monitoring and verification are actually effective, it is probably under-controlling the exposure.
For teams working across onboarding, periodic review, and exit decisions, the useful question is whether the chosen response changes the risk state in a measurable way. If more evidence, tighter limits, or increased review cadence can plausibly bring the exposure into tolerance, EDD is the more proportionate path. If not, de-risking may be the only defensible outcome.
Risk and Threat Considerations
Both approaches carry risk if they are applied mechanically. Overuse of de-risking can push legitimate customers out of the regulated perimeter and reduce visibility, while weak EDD can leave the institution carrying unresolved exposure for too long.
Failure mechanism: The control fails when high-risk relationships are either exited without a defensible basis or retained without enough evidence, monitoring, or verification to justify the residual exposure.
Impact: The institution can end up with blind spots, inconsistent treatment, regulatory challenge, or unmanaged financial crime exposure, especially where monitoring depends on customer disclosure that is incomplete or unreliable.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | De-risking and EDD are risk-treatment choices within risk appetite. |
| PR.AA-05 — Identity Management, Authentication and Access Control | EDD relies on stronger verification and access-related assurance over customer activity. | |
| ID.RA-01 — Asset Vulnerabilities Identified and Recorded | The decision depends on identifying what makes the relationship or activity riskier. | |
| Recommendation — Define when to continue, intensify, or exit customer relationships based on documented risk appetite. Apply stronger verification and access checks before continuing higher-risk relationships. Record the specific risk drivers that make a relationship unsuitable for standard controls. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Continuation decisions depend on whether access and control boundaries can be enforced. |
| A.5.34 — Privacy and protection of PII | EDD often needs deeper checks on customer information and sensitive data handling. | |
| Recommendation — Enforce access boundaries that match the organisation's assessed risk tolerance. Protect customer information used to support enhanced review and ongoing monitoring. | ||
Practitioner Guidance
What to verify: Before choosing EDD, confirm that the additional checks you plan to apply can materially improve confidence in the relationship, not just increase paperwork. If the evidence you can obtain will not change the risk decision, EDD is probably only delaying an exit decision.
Decision rule: If the exposure can be bounded through stronger verification, tighter monitoring, or product restrictions, treat it as an EDD case. If the residual risk remains outside appetite after those measures are considered, escalate to de-risking rather than inventing another review cycle.
Practitioner takeaway: The right test is not whether a customer is “high risk”, but whether the institution can still explain, monitor, and defend the relationship with proportionate controls.
Related resources from NHI Mgmt Group
- What is the difference between customer due diligence and enhanced due diligence?
- What is the difference between standard KYC and enhanced due diligence for customer verification?
- What is the difference between attack surface management and NHI governance?
- What is the difference between reviewing human access and reviewing NHIs?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org