Understanding the Fine
After De Nederlandsche Bank fined ABN AMRO EUR 8.5 million for failing in due diligence on high-risk customers, compliance officers everywhere are asking similar questions. They feel relief that it wasn't their institution, but then realize they might have similar gaps in their processes.
These questions aren't hypothetical. They're what compliance managers ask when reviewing their high-risk portfolios, wondering if their due diligence would withstand regulatory scrutiny.
What Are "Structural Shortcomings"?
When regulators mention "structural" issues, they're pointing to systemic problems in your control framework. This means your processes, governance, or risk assessment methods are flawed.
In high-risk customer due diligence, structural shortcomings often mean:
- Your procedures don't align with the risk profile of the customer segment.
- You're not conducting reviews as often as your risk methodology requires.
- Your verification standards for wealth and funds aren't consistently applied.
- Your triggers for unusual activity aren't suited to the risk tier.
A regulatory finding of "structural" issues should prompt a review of your entire control design, not just individual files.
Identifying Gaps in Your High-Risk Customer Base
Begin with a stratified sample audit. Don't just pull random files. Segment your high-risk population by subcategory (PEPs, correspondent banking, cash-intensive businesses, high-value accounts) and sample from each.
For each file, check:
- Date of last enhanced due diligence.
- Current and verified source of wealth documentation.
- Transaction monitoring thresholds that match the business model.
- Adverse media screening within the past year.
- Complete and verified beneficial ownership information.
Look for patterns. If a large percentage of files lack current verification, that's a structural issue. If it's a few files, you might have execution problems, but your framework could be sound.
The FATF Recommendations require due diligence measures to match risk. If you can't show this in your documentation, there's a gap.
Is a Long Checklist Enough?
A long checklist doesn't mean it's effective. I've seen 60-item checklists where most questions were yes/no, lacking depth.
What matters is whether your checklist helps you gather and analyze information that reveals red flags. For high-risk customers, your process should answer:
- Can you verify the origin of the customer's wealth?
- Does the transaction pattern match the business purpose?
- Why does this customer maintain a banking relationship in your jurisdiction?
- For PEPs, what controls prevent misuse of their position?
If your checklist doesn't require documentation of these answers with evidence, it's just for show.
How Often Should You Refresh High-Risk Customer Files?
The Wolfsberg Principles don't set a universal timeframe, as risk varies. Here's a practical approach:
For active high-risk accounts with regular transactions, conduct full reviews at least annually. For PEPs in high-risk areas or cash-intensive businesses, consider semi-annual reviews.
For dormant accounts, periodic reviews are still needed, but you can extend the interval to 18-24 months if monitoring hasn't flagged issues.
Document your rationale. If questioned, show that you've assessed risk factors and adjusted your review frequency accordingly.
Addressing Gaps in High-Risk Files
Have a remediation protocol. When you find an incomplete or outdated file, don't just update it.
First, assess if the gap poses a money laundering or sanctions risk. If you can't verify funds and the account has significant activity, consider filing a Suspicious Activity Report.
Next, request updated documentation from the customer, setting a deadline of 30 to 45 days. If they don't comply, have an escalation path that includes account restrictions or termination.
Finally, determine why the gap existed. Was it a process failure, system issue, or staff turnover? This helps decide if you need to fix one file or redesign a control.
Convincing the Business to Act
Frame it as loss prevention. The EUR 8.5 million fine is just the start. The cost of responding to enforcement, investigation, remediation, consultant fees, management time, often exceeds the fine.
Build a business case including:
- Cost of your current EDD process per file.
- Estimated cost to fix gaps across your high-risk population.
- Regulatory fine risk based on your jurisdiction and portfolio size.
- Reputational risk if publicly named in an enforcement action.
If your high-risk base generates significant revenue, position enhanced due diligence as relationship protection. Continuous oversight reduces the chance of suddenly exiting a profitable relationship.
Next Steps
Consult your primary regulator's examination manual for what they expect in high-risk customer files. In the US, that's the FFIEC Bank Secrecy Act/Anti-Money Laundering Examination Manual. In the EU, check your national authority's guidance on AML Directives.
The FATF Recommendations, especially Recommendation 10 on customer due diligence, set the international standard. The Wolfsberg Principles offer detailed guidance for high-risk scenarios.
If you find systemic gaps, hire a specialized AML consultant for a control assessment before your regulator does. Voluntary remediation is always cheaper than mandated action.



