Organisations should prioritise identity verification, beneficial ownership checks, enhanced due diligence for higher-risk customers, and ongoing monitoring. In practice, the first step is establishing a consistent baseline for all customers, then layering controls for PEPs, cross-border relationships, and virtual asset activity. That sequencing reduces gaps and makes policy enforcement easier to audit.
Why This Matters for Security Teams
For Kenyan AML programmes, customer due diligence is not just a compliance checkbox. It is the control set that determines whether an organisation can understand who the customer is, who ultimately owns or controls the relationship, and whether activity is consistent with the stated purpose. That matters for banks, fintechs, payment firms, and virtual asset businesses because gaps at onboarding often become detection and reporting failures later. The baseline expectations align with the risk-based approach described in the FATF Recommendations — AML and KYC Framework.
The practical mistake is to treat due diligence as a single form or an identity check only. In reality, Kenya-aligned AML control design needs a sequence: identify the customer, validate beneficial ownership where relevant, screen for higher-risk indicators, and keep the profile current through monitoring and review. That sequence matters because each layer answers a different question. Identity verification confirms the person or entity exists. Ownership checks reveal who benefits. enhanced due diligence helps when risk is elevated. Ongoing monitoring catches changes that onboarding cannot predict. In practice, many security and compliance teams encounter failures only after suspicious activity has already moved through an otherwise approved account, rather than through intentional risk-based design.
How It Works in Practice
Prioritisation should follow a risk-based build order, not an exhaustive control rollout. Start with a defensible minimum baseline for every customer, then add stronger controls where the risk profile justifies the cost and friction. That approach is consistent with current AML guidance from FATF and with how supervisory expectations are usually interpreted in practice.
A workable sequence is:
- Verify identity using reliable, independent evidence before account activation.
- Identify and, where required, verify beneficial owners, controllers, and signatories for legal entities.
- Screen customers against sanctions, PEP, and adverse media data sources before acceptance and on an ongoing basis.
- Apply enhanced due diligence to higher-risk categories such as PEPs, complex ownership structures, non-resident relationships, and virtual asset activity.
- Set transaction monitoring and periodic review thresholds that reflect customer risk rather than a one-size-fits-all cadence.
In Kenyan AML contexts, the strongest control is often the one that creates a complete and auditable customer risk profile, because that profile drives both onboarding decisions and later monitoring rules. For identity proofing, the control question is whether the organisation can trust the source evidence and the decision trail. For entities, the key issue is whether beneficial ownership can be traced through layers of control, not just named directors. For higher-risk customers, enhanced due diligence should document source of funds, source of wealth, purpose of relationship, and expected activity. These practices align closely with the control expectations reflected in FATF Recommendations — AML and KYC Framework and the risk-based design principles in regional AML implementation guidance.
Operationally, the control stack should be tied to case management, escalation, and record retention so investigators can show why a customer was accepted, restricted, reviewed, or exited. These controls tend to break down when customer files are fragmented across business units because risk decisions lose consistency and evidence cannot be reconstructed quickly.
Common Variations and Edge Cases
Tighter due diligence often increases onboarding friction and operational cost, requiring organisations to balance customer experience against regulatory defensibility. That tradeoff is especially visible when legal entities, cross-border customers, and digitally sourced identities all sit in the same portfolio.
There is no universal standard for this yet on how much automation is enough for Kenyan AML screening, so best practice is evolving. Some organisations use automated identity proofing with manual review only for exceptions, while others retain broader human oversight for high-risk segments. The right answer depends on product risk, customer mix, and the quality of available evidence. For example, a low-risk retail account may only need standard verification and sanctions screening, but a corporate customer with layered ownership, foreign directors, or nominee arrangements will usually need deeper beneficial ownership analysis and more frequent refresh.
Edge cases also matter for cross-border relationships, politically exposed persons, and virtual asset exposure. Those relationships can trigger more intensive source-of-funds checks, tighter thresholds for monitoring, and earlier escalation to compliance review. When personal data governance is part of the question, organisations should also account for privacy and retention obligations so due diligence files are accessible to investigators without becoming over-collected. The key is to make the baseline consistent and the exceptions explicit, rather than allowing local teams to improvise. Where customer risk scoring is poorly integrated with case workflow, due diligence becomes a static onboarding exercise instead of an ongoing AML control.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63 and NIST CSF 2.0 set the technical controls, while PCI DSS v4.0, DORA and NIS2 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Identity proofing underpins customer verification and onboarding assurance. | |
| NIST CSF 2.0 | PR.AC-1 | Due diligence depends on controlled access to identity and account data. |
| PCI DSS v4.0 | 12.3.1 | Risk-based processes help govern third-party and sensitive data handling in regulated environments. |
| DORA | Art. 9 | Operational resilience supports reliable due diligence workflows and evidence retention. |
| NIS2 | Article 21 | Security governance supports consistent control implementation across onboarding and monitoring. |
Use identity proofing, verification, and lifecycle controls to establish who the customer is before accepting risk.
Related resources from NHI Mgmt Group
- Should organisations prioritise secrets rotation or policy controls first for agents?
- How should organisations decide when a customer needs enhanced due diligence?
- What do organisations get wrong about customer due diligence?
- Should organisations prioritise encryption or secrets lifecycle controls first?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org