Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM What should teams do after enhanced due diligence…
Identity Beyond IAM

What should teams do after enhanced due diligence uncovers suspicious activity?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 16, 2026 Domain: Identity Beyond IAM

When EDD uncovers suspicious activity, teams should not treat the finding as a documentation exercise. They should preserve the evidence, complete internal review, decide whether the relationship can continue, and file the required reports to the relevant authority. If the risk is severe, they may need to freeze or decline the account and strengthen ongoing monitoring for related activity.

Why This Matters for Security Teams

enhanced due diligence is only useful if it changes the decision. Once suspicious activity appears, the issue stops being a paperwork exercise and becomes a control, reporting, and containment problem. Teams need to preserve evidence, assess whether the risk can be remediated, and determine whether the relationship can safely continue. That judgment affects fraud exposure, sanctions or AML obligations, downstream access decisions, and whether the organisation can defend its choice later.

For financial crime workflows, the point of EDD is to raise the quality of the decision, not to delay it. If the account, counterparty, or transaction pattern remains unexplained after review, escalation should move quickly to filing the required report and tightening ongoing monitoring. The relevant standard expects customer due diligence, beneficial ownership review, and suspicious activity reporting to work together rather than as separate steps, which is why the decision trail matters as much as the outcome. FATF Recommendations set that baseline.

In practice, many teams only discover gaps in escalation, documentation, and account action after the suspicious pattern has already repeated.

How It Works in Practice

Teams should treat the EDD finding as the start of a structured response. The first task is to preserve the evidence trail, including account history, supporting documents, analyst notes, timestamps, and any transactions or behaviours that triggered the review. The second task is to complete an internal assessment that answers three questions: what happened, how credible the explanation is, and whether the exposure can be contained without continuing the relationship under current terms.

  • Preserve all source material before it can be altered or overwritten.
  • Correlate the suspicious activity with onboarding data, ownership information, and prior alerts.
  • Decide whether mitigation is possible through limits, monitoring, or remediation.
  • Escalate for reporting when the activity remains suspicious or cannot be reasonably explained.
  • Freeze, restrict, or decline the relationship when the risk cannot be safely managed.

Where the activity may reflect money laundering, fraud, sanctions evasion, or synthetic activity, the threshold for escalation should be low, because the cost of continuing a bad relationship often exceeds the cost of a conservative exit. Filing obligations and internal case closure should be linked, so analysts do not “close” a case before the report and containment steps are complete. The control expectation is similar to incident handling in security operations, preserve, assess, decide, then act, rather than treating review as a detached administrative step. EBA AML/CFT Guidance is useful for EU-oriented teams that need a supervisory lens on that workflow.

These controls tend to break down when ownership data is incomplete, because the team cannot reliably determine who controls the relationship or whether the suspicious behaviour is linked to related accounts.

Common Variations and Edge Cases

Tighter response often increases operational friction, so organisations have to balance customer continuity against the cost of leaving suspicious activity in place. The hard cases are not the obvious ones, but the ones where activity is unusual rather than clearly illegal, or where the relationship has commercial value but the evidence remains incomplete.

In those cases, current guidance suggests using a proportional response: increase monitoring, narrow exposure, and require stronger justification before allowing the relationship to continue. If the suspicion is tied to shell structures, third-party control, or repeated unexplained transactions, a conservative exit is usually safer than an extended remediation cycle. If the activity touches high-risk geographies, rapidly changing beneficial ownership, or repeated threshold avoidance, the case should move faster because those patterns often indicate deliberate evasion rather than a one-off anomaly.

One useful practical distinction is between explainable anomalies and unresolved suspicion. Explainable anomalies can sometimes be contained with enhanced monitoring and documented approval. Unresolved suspicion should trigger reporting and a decision on whether the relationship can continue at all. That distinction matters because it prevents teams from using “more review” as a substitute for an actual decision. FATF Recommendations remain the clearest reference point for that escalation logic.

Risk and Threat Considerations

The main risk is false closure, where a suspicious case is treated as resolved even though the underlying exposure remains active. That creates regulatory risk, repeat-loss risk, and the possibility that the same counterparty or behaviour continues through another channel.

Failure mechanism: Suspicious activity persists when teams fail to preserve evidence, do not connect related accounts or transactions, or rely on incomplete explanations that are not independently verified. In AML terms, the weakness is not only missed detection, but also poor escalation discipline and weak decision accountability.

Impact: The organisation can retain a risky relationship longer than intended, fail to file a required report, and leave related activity unmonitored. In the worst case, that creates compounding exposure across fraud, sanctions, and financial crime controls.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM — Risk Management StrategySuspicious activity demands a governed risk decision on continuation, escalation, and containment.
RS.CO — Response CoordinationEDD findings require coordinated escalation, documentation, and reporting across teams.
DE.AE — Anomalies and EventsEDD starts from anomalous activity that must be validated and triaged.
Recommendation — Use risk management criteria to decide whether to continue, restrict, or exit the relationship. Coordinate case escalation, reporting, and containment so review does not stall in silos. Triage anomalous behaviour against expected patterns and preserve the evidence trail.
CIS Controls v86 — Access Control ManagementSuspicious relationships may require freezing, restricting, or revoking account access paths.
8 — Audit Log ManagementEDD depends on retaining evidence and traceable analyst decisions for review and reporting.
Recommendation — Revoke or restrict access promptly when suspicious activity cannot be safely contained. Retain logs and case records that support the final disposition and any required filing.
MITRE ATT&CKT1078 — Valid AccountsSuspicious activity often indicates abuse of legitimate accounts or credentials.
Recommendation — Hunt for legitimate-account abuse and correlate activity across related records and channels.

Practitioner Guidance

What to prioritise: Preserve the case record first, then decide whether the activity is explainable, containable, or reportable. If those three outcomes are still unclear after internal review, treat the case as unresolved rather than closed.

Decision rule: If the suspicious activity affects ongoing customer, counterparty, or account risk and cannot be convincingly explained, escalate to reporting and consider restriction or exit before extending the investigation window.

What to verify: Verify that the decision path is defensible, that supporting evidence is retained, and that related relationships have been checked for the same pattern. The common mistake is allowing a strong commercial relationship to soften the evidentiary threshold.

Practitioner takeaway: The real control is not the EDD review itself, but the quality of the decision that follows it, especially when the correct outcome is to constrain, report, or stop the relationship.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 16, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org