Weak due diligence leaves institutions blind to who the customer is, what activity is normal, and when behaviour becomes suspicious. That gap makes it harder to identify high-risk clients, apply the right level of scrutiny, and detect unusual transactions early. The result is higher exposure to financial crime, regulatory penalties, and reputational damage.
Why This Matters for Security Teams
Weak customer due diligence does more than miss a compliance checkbox. It prevents institutions from building a trustworthy risk picture, which means higher-risk customers can enter with incomplete screening, beneficial ownership can stay opaque, and transaction monitoring starts from bad assumptions. That is exactly how money laundering, account takeover, mule activity, and synthetic identity fraud gain room to operate. Guidance from the FATF Recommendations makes clear that customer identification, ongoing monitoring, and risk-based controls are foundational, not optional.
For security teams, the practical problem is that weak due diligence compounds downstream. Screening tools can only flag what they can match, and monitoring rules can only detect what they are tuned to see. If the customer profile is thin, stale, or inaccurate, the institution loses the context needed to separate legitimate volatility from suspicious behaviour. That creates both false negatives and noisy alerts, which increases analyst fatigue and lets real risk blend into ordinary operations. NHI Management Group has also shown how visibility gaps create broad exposure in identity systems, with the Ultimate Guide to NHIs — Why NHI Security Matters Now noting that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys.
In practice, many institutions discover due diligence failures only after suspicious activity has already moved through multiple accounts or channels.
How It Works in Practice
Effective due diligence is a lifecycle discipline, not a one-time onboarding check. At entry, the institution should verify identity, assess ownership and control, classify the customer by expected behaviour, and assign a risk tier that determines what evidence is required before approval. During the relationship, the profile must be refreshed when activity changes, new counterparties appear, or adverse information emerges. That is why the FATF model is paired with control disciplines from the NIST Cybersecurity Framework 2.0 and control baselines such as NIST SP 800-53 Rev 5 Security and Privacy Controls, where monitoring, access discipline, and auditability are treated as operational requirements.
Practitioners usually apply due diligence through a combination of customer screening, transaction monitoring, and periodic review:
- Know who the customer is, including beneficial owners and control relationships.
- Define expected activity so deviations can be measured against a baseline.
- Use risk scoring to drive enhanced due diligence for higher-risk customers.
- Reassess records when behaviour, geography, ownership, or products change.
- Escalate cases where source of funds, purpose, or counterparties cannot be explained.
The same logic that governs identity trust applies here: incomplete identity data produces weak access decisions, and weak access decisions create exposure. NHI research is relevant because identity sprawl often teaches the same lesson at machine scale. For example, the Top 10 NHI Issues and the Ultimate Guide to NHIs — Key Challenges and Risks show how poor identity visibility leads to excessive privilege, stale access, and delayed remediation. In customer due diligence, the analogue is stale customer risk data, which leaves monitoring blind to meaningful change. These controls tend to break down when high-volume onboarding, third-party intermediaries, or cross-border structures outpace manual review capacity because the organisation can no longer keep customer risk profiles current.
Common Variations and Edge Cases
Tighter due diligence often increases onboarding friction and operating cost, requiring organisations to balance customer experience against fraud resistance and regulatory defensibility. That tradeoff becomes more pronounced for digital-first banks, payments firms, and marketplaces, where fast approval is commercially important but weak review can be exploited at scale. Best practice is evolving, but there is no universal standard for how much automation should replace manual review in every segment.
Some customers also present legitimate complexity rather than suspicious behaviour. Corporate structures, charities, trusts, politically exposed persons, and cross-border remittance flows can all look unusual even when lawful. In those cases, the quality of due diligence matters more than the speed of decisioning. Evidence should be proportionate to risk, but it must still be enough to explain ownership, purpose, and source of funds. NHI Management Group’s broader identity guidance reinforces the same principle: if the institution cannot explain who or what it is trusting, it cannot defend the trust decision later.
For this reason, due diligence works best when paired with clear escalation thresholds, refresh triggers, and documented exceptions. Without those guardrails, institutions either over-block legitimate customers or under-detect laundering and fraud patterns until losses are material.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 | Due diligence needs clear organisational risk context to set customer risk expectations. |
| NIST SP 800-63 | IAL2 | Identity proofing strength directly affects how much trust the institution can place in a customer. |
| OWASP Non-Human Identity Top 10 | NHI-03 | Poor identity lifecycle control mirrors stale customer records and weak trust decisions. |
| NIST AI RMF | Risk governance supports repeatable decisions for automated screening and escalation. |
Define customer risk objectives and map due diligence triggers to your governance and monitoring workflow.
Related resources from NHI Mgmt Group
- Why does weak CIAM increase fraud and account takeover risk in customer-facing applications?
- Why does weak Segregation of Duties control in ERP systems create fraud and misstatement risk?
- Why do standing accounts and weak account lifecycle controls increase operational risk in identity security portals?
- Why does collecting too much customer information early increase risk in omnichannel identity programs?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 1, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org