Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Who is accountable for EDD decisions in a…
Governance, Ownership & Risk

Who is accountable for EDD decisions in a regulated organisation?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 10, 2026 Domain: Governance, Ownership & Risk

Accountability should sit with the functions that own the risk decision, not only with the analysts collecting documents. Compliance, financial crime, and business owners all need defined roles for escalation, approval, and ongoing review. If responsibility is unclear, high-risk relationships can slip through because no one owns the final judgment or the review cadence.

Who owns EDD decisions in a regulated organisation?

EDD is not a document-collection task with no owner. In a regulated organisation, accountability sits with the business and control functions that can accept, escalate, or decline the relationship, while analysts support the review. The key test is simple: the team making the final risk judgment must be named, empowered, and able to evidence why the decision was taken.

Why accountability has to follow the risk decision

EDD exists to answer a risk question, not just a process question. If the people gathering information are treated as the owners, you get a common failure mode, strong paperwork with weak judgment. The accountable function must own the threshold for escalation, the rationale for approval, and the conditions that trigger enhanced monitoring or exit decisions.

That usually means compliance, financial crime, and the business line share the work, but not the same role. Analysts can prepare the case, subject matter experts can challenge it, and the business owner must remain accountable for the relationship outcome when the risk is accepted. Where the decision is spread too thinly, accountability gaps create a false sense of control and slow down action when risk changes.

Well-run organisations also separate operational support from decision authority. Review teams can validate information quality, but they should not become the final decision maker by default. For broader control design, see ISO/IEC 27002:2022 Information Security Controls for the general principle that security responsibilities should be assigned and operationalised, not implied.

What good governance looks like across escalation, approval, and review

Clear EDD accountability should define who can recommend, who can approve, who can reject, and who must re-review when facts change. The governance model should also say what evidence is required before a higher-risk relationship is accepted, and who owns the follow-up if the customer profile, adverse media, ownership structure, or transaction behaviour changes later.

This matters most when the organisation has multiple decision points. If one team approves onboarding, another team sets monitoring rules, and a third team handles exceptions, the organisation needs a single accountable owner for the full lifecycle. Without that, review cadence slips, exceptions accumulate, and nobody is clearly responsible when an initial decision becomes stale.

That governance pattern aligns with control frameworks that emphasise assigned accountability, access to evidence, and ongoing review. In a security context, NIST SP 800-53 Rev 5 Security and Privacy Controls is useful because it reinforces the need for defined roles, reviewable control operation, and decision support that can be audited after the fact. For regulated organisations, the practical lesson is that EDD should be governable like any other control decision, not left as a loose workflow.

Why weak ownership creates real regulatory and conduct risk

EDD failures are rarely caused by missing forms alone. They usually come from unclear accountability, so high-risk relationships are approved without a defensible owner, or remain open even when the risk has materially changed. That creates exposure in onboarding, periodic review, and exception handling, especially where adverse information or ownership complexity requires a deliberate decision rather than a routine refresh.

Once ownership is unclear, the organisation can also lose evidence quality. Teams may be able to show that checks were performed, but not who exercised judgment, what alternatives were considered, or why an exception was tolerated. For financial crime programmes, that is a serious control weakness because regulators care about the quality of decision-making as well as the existence of the process.

Good practice in this area is also consistent with a broader governance approach: NIST Cybersecurity Framework 2.0 places governance and roles at the centre of control effectiveness. The same principle applies here, decision rights must be explicit enough that escalation, oversight, and remediation are not optional.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
ISO/IEC 27001:2022A.5.3 — Information security roles and responsibilitiesEDD needs named decision ownership and escalation authority.
A.5.1 — Policies for information securityEDD decisions need a policy-backed governance model and accountable roles.
Recommendation — Assign clear EDD decision rights, escalation paths, and review ownership. Set policy-defined accountability for approval, escalation, and review.
NIST SP 800-53 Rev 5CA-7 — Continuous MonitoringEDD requires ongoing review when customer risk changes over time.
PL-2 — System Security and Privacy PlansEDD governance needs documented roles, responsibilities, and control operation.
Recommendation — Define recurring review triggers and re-assessment criteria for high-risk relationships. Document who approves, who challenges, and who owns exception handling.
NIST CSF 2.0GV.RR-01 — Roles, Responsibilities, and AuthoritiesEDD ownership depends on explicit decision authority and accountability.
Recommendation — Assign and communicate EDD roles, authorities, and escalation responsibilities.

Practitioner Guidance

What to verify: Confirm that every EDD case has a named decision owner, a named approver for exceptions, and a separate reviewer if the process requires independent challenge. If those roles are merged by default, the control is usually weaker than it appears.

Decision rule: If the relationship can create regulatory, sanctions, fraud, or conduct exposure, do not treat EDD as complete until the final risk owner is identified in the record and the review cadence is defined. If no one can evidence the judgment, the decision is not really owned.

What good looks like: The file shows who escalated, who approved, what was accepted, what follow-up was required, and when the case must be revisited. The organisation can explain the decision without relying on tribal knowledge.

Practitioner takeaway: EDD accountability should sit with the function that can defend the risk decision end to end, because document review without decision ownership is where control failure usually starts.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org