Skip to main content
Risk-Based EDD Is Making You Less CompliantAML and KYC
4 min readFor AML/KYC Compliance Officers

Risk-Based EDD Is Making You Less Compliant

The Conventional Wisdom

Your Anti-Money Laundering (AML) program likely places customers into low, medium, and high-risk categories. You've documented criteria, assigned risk scores, and apply Enhanced Due Diligence (EDD) to high-risk customers while using lighter procedures for others. This aligns with the Financial Action Task Force (FATF) recommendations and is what auditors expect. It's the standard practice in compliance.

The risk-based approach to EDD is seen as efficient: focus resources where risk is highest and avoid wasting effort on low-risk customers. This should help catch bad actors while maintaining efficiency.

Why We Disagree

The issue isn't the principle of risk-based EDD, but how it's often implemented. Many organizations treat it as a static sorting exercise instead of a continuous assessment. This creates compliance theater, not effective risk management.

Typically, you assess a customer's risk at onboarding. An algorithm assigns a risk score, which dictates their EDD path. Then you move on. The risk level becomes a label, not a dynamic evaluation.

This approach leads to three main vulnerabilities:

First, your risk categories are retrospective. You're assessing customers based on existing attributes and behaviors. A shell company in a high-risk area gets flagged. But what about a legitimate business that starts routing payments through a newly sanctioned region months later? Without ongoing monitoring, your initial assessment misses these shifts.

Second, you've created permission structures. Labeling a customer "low-risk" changes how your team treats them. Analysts spend less time on their transactions, and alerts get lower priority. Essentially, you've instructed your compliance program to overlook a large portion of your customer base after an initial screening.

Third, risk-based EDD encourages threshold thinking. Instead of asking "what risks does this relationship present?" you're asking "does this customer meet high-risk criteria?" These are fundamentally different. The first requires judgment; the second is about checking boxes.

The Evidence

The Bank Secrecy Act doesn't mandate risk-based approaches. It requires programs "reasonably designed" to detect and report suspicious activity. The FFIEC BSA/AML Examination Manual mentions risk-based approaches as one option, not the only one.

EDD involves gathering and verifying more information than standard due diligence. Notice what's missing: there's no mention of limiting EDD to pre-categorized high-risk customers. The requirement is about investigation depth when necessary, not sorting customers into permanent risk categories.

Consider what triggers a Suspicious Activity Report. It's not a customer's initial risk category, but specific transaction patterns, behavioral changes, or unexpected information. These indicators often emerge over time, even from customers who wouldn't score as "high-risk" in a static assessment.

A risk-based approach should focus resources on high-risk areas, but interpreting it as "do minimal work on low-risk customers" misses the point. The approach should guide resource intensity, not investigation quality.

What to Do Instead

Implement trigger-based EDD, not category-based EDD. Define specific circumstances that require enhanced procedures: changes in transaction velocity, new geographic exposure, beneficial ownership changes, adverse media, or industry shifts. These triggers should apply to all customers, regardless of initial risk score.

Separate monitoring intensity from investigation depth. Monitor low-risk customers less frequently but maintain thorough investigations when issues arise. Frequency and thoroughness are different; your risk-based approach should affect the former, not the latter.

Build escalation paths that ignore risk categories. When something suspicious is identified, the investigation protocol shouldn't reference the customer's risk level. Investigate the specific concern, not validate a risk score. This avoids confirmation bias and ensures low-risk labels don't limit investigations.

Document decision points, not risk scores. Instead of "Customer assigned medium risk: 65/100," record "Customer operates in regulated industry with transparent ownership; will monitor for transaction pattern changes and geographic expansion." This creates an audit trail of reasoning rather than a numerical justification for less work.

Treat risk assessment as continuous. A customer's risk profile six months after onboarding is more relevant than at account opening. If you're not re-evaluating risk based on actual behavior and relationship evolution, you're not doing risk-based compliance; you're doing intake-based compliance.

When the Conventional Wisdom IS Right

Risk-based EDD is sensible for resource allocation in specific contexts. If you're a correspondent bank evaluating thousands of relationships, you can't apply the same scrutiny to a community bank in Iowa and a shell bank in a non-cooperative jurisdiction. The risk-based approach prevents overwhelming work.

It's also appropriate for compliance with regulations that require risk categorization, such as certain EU AML Directive provisions. When regulation mandates the framework, you implement it.

The risk-based approach works for determining review frequency, documentation requirements at onboarding, or seniority level for exceptions. These are legitimate efficiency decisions.

Where it fails is when risk categories become barriers to investigation. When "low-risk" means "don't look too hard." When your risk-based approach creates a two-tier compliance program where most customers get procedural compliance and a small subset gets real scrutiny.

Your EDD procedures should be triggered by risk indicators, not limited by risk categories. This distinction matters. One is responsive compliance; the other is just sorting.

You Might Also Like