Perspectivas
Perspective 009Practice

The hidden risks sitting quietly in your customer base.

It is easy to spend more time looking for the next financial-crime risk than asking whether yesterday's customers still represent today's risk. Age is not the risk. Staleness is.

El texto completo de este análisis se publica en inglés. La estructura, las cifras y las referencias son las mismas en ambas versiones del sitio.

Por Everett MorganWinter 202610 min read
Amsterdam Zuidas financial district at dusk reflected in a calm canal
Executive brief

Reading time · 10 minutes  ·  Primary audience · Boards, MLROs, Heads of Client Lifecycle Management, Chief Risk Officers

Why this matters

The risk I worry about is not only at the front door. A material part of it may already be sitting inside the book: customers accepted under an earlier standard, whose circumstances have moved and whose files have not. Onboarding tells you what the firm understood about the customer when the relationship began. Ongoing monitoring tests whether that understanding is still true. Ongoing due diligence is where some of the least visible risk can accumulate.

Key findings
  1. 01Beneficial ownership changes. Source of funds evolves. Activity moves. Where those changes are not picked up, the file stops describing the customer the firm actually has.
  2. 02Enhanced due diligence performed once at onboarding and never revisited is a snapshot, not an ongoing control.
  3. 03Trigger-based review is only as good as the trigger framework underneath it. Triggers need to reflect the firm's actual risks, produce meaningful escalation and be tested and recalibrated when the evidence says they are not working.
  4. 04A mature customer book needs a proportionate ongoing-monitoring framework that combines risk-based review, meaningful triggers and current customer and activity information.
  5. 05Patterns in legacy populations can expose wider themes: inconsistent application of methodology, unexplained differences in judgement, and weaknesses in ongoing governance.
  6. 06Firms that already understand their existing exposure will be better placed as Article 26 of Regulation (EU) 2024/1624 applies and AMLA's work on ongoing monitoring develops.
Questions Boards should ask
  1. 01For our highest-risk customer cohorts, when were the files last genuinely reviewed against the current CDD standard, rather than simply refreshed on the system?
  2. 02Of the customers whose activity has materially changed since their last substantive review, what proportion have had their risk assessment and EDD status reconsidered?
  3. 03Which parts of the existing book do we trust, which parts have we actually tested, and which parts still worry us?

The problem: the book you have is not the book you assessed

Most firms spend their time looking for new financial crime risks. Fewer stop to ask whether yesterday's customers still represent today's risks. That question matters even more as the EU framework puts renewed attention on ongoing monitoring, keeping customer information current and understanding activity across the life of the relationship.

Beneficial owners change. Business models pivot. Jurisdictions shift risk profile. New typologies emerge. Any established customer book accumulates that history: customers onboarded years ago, files built under older methodologies, relationships inherited through a portfolio purchase, dormant accounts nobody has had a reason to look at.

Age is not the risk. Staleness is. A customer onboarded ten years ago may be perfectly well understood today if the relationship has been monitored and refreshed properly. A customer onboarded two years ago may already be stale if the business, ownership or activity has changed and nobody noticed.

So the question is not how old the file is. It is whether the firm's current understanding of the customer is still reliable. The control problem starts when firms treat onboarding as permanent and ongoing monitoring as administration.

This is where many organisations become uncomfortable. Looking backwards rarely feels urgent, until it becomes unavoidable.

Low activity does not automatically remove a relationship from the firm's financial-crime risk universe. If the relationship remains open, its treatment should still be explainable within the firm's risk-based framework. That is not the same as treating every dormant account as high risk. It rarely is.

The evidence: ongoing due diligence is where the findings recur

The consequences of weak ongoing monitoring are visible repeatedly in European enforcement and supervisory work. Two cases are worth reading for what they say about existing customer populations rather than about onboarding.

Where the hidden risks actually sit

In practical work, hidden exposure tends to cluster in a small number of recognisable places. These are not rules, and none of them automatically requires the same response. The response stays risk-based. But reading an existing book against these categories is usually more informative than a general review of file quality.

Good practice and poor practice in ongoing due diligence

Business impact: the size of the exposure

In mature books, I have repeatedly seen the population requiring substantive review increase once the scope and data are properly tested. That does not necessarily mean the first line was optimistic. Often the firm was being asked to estimate something it had never measured properly. The impact then combines the cost of the review work itself, any supervisory response, any restrictions on new customer acceptance while the book is cleared, and the disruption to relationships with customers who have been on the books for years and are suddenly being re-documented.

Remediation is governance information

A remediation programme is easy to misread as an administrative exercise to refresh documents. A good one should do more than that. It should tell management what the historic population says about today's control environment.

That does not mean judging every historic decision as though today's standard existed at the time. There are two different questions: was the original decision defensible when it was made, and is the relationship still sufficiently understood and controlled today?

Both questions are worth asking, and they do not always have the same answer. Sometimes historic decisions hold up well. Sometimes they do not.

What the patterns show matters more than any single file. Inconsistent application of methodology, unexplained differences in judgement, risk assessments that moved without explanation, gaps in ongoing governance. Those are not merely file-quality issues. They can point to wider operational and governance weaknesses that the Board should understand.

The review should be designed against both the population and the risk. Higher-risk and older cohorts may deserve greater weight, but the sample should also be capable of showing whether the issue extends beyond the obvious high-risk segment. If you only look where you already expect to find problems, you learn very little about the rest of the book.

A note for smaller firms

A proportionate, risk-based review of older customer populations can give management a clearer view of whether the older book still sits comfortably within the firm's current risk framework. The objective is not to revisit every decision ever made. It is to establish where the greatest exposures sit today, and whether the firm can explain them.

Why this matters now

The new EU framework does not make the legacy book a separate category of risk. Ongoing monitoring is about maintaining a current understanding of the relationship over time. Under Regulation (EU) 2024/1624 that includes keeping customer information current, monitoring activity during the relationship, and reassessing where relevant risk factors or circumstances change. AMLA's current work on ongoing monitoring of business relationships is developing the technical detail. That detail is not binding yet, and it would be wrong to treat it as though it were, but the direction is clear enough to act on.

That makes the question straightforward: how much of the existing book can the firm still explain with confidence?

Practical solutions

The Claritas approach

I prefer to start with the data before opening files. Compare what the firm understood about the customer with what the relationship looks like now, across the population where the data allows it or through a deliberate stratified analysis where it does not. That tells you where the file work should go.

From there, the programme can be risk-tiered, the QA approach built around the real failure modes, and the Board reporting reduced to what governance actually needs to understand. Where QA is finding material defects, the programme may be producing volume without producing reliable remediation, and that is worth knowing early rather than at the end.

In closing

The age of a customer file is not the issue. The issue is whether the firm's understanding of that customer is still current. A mature book needs more than periodic refresh. It needs a risk-based way of noticing when the customer, ownership, activity or exposure has moved far enough that the original CDD judgement needs to be made again.

If you cannot explain which parts of the existing book you trust, which parts you have tested and which parts still worry you, that population is already a governance question.

What success looks like
  • 01The Board understands the quality position across the firm's highest-risk and materially exposed customer cohorts, including the limits of the evidence supporting that view.
  • 02Ongoing review involves substantive reconsideration of whether the customer still matches the firm's understanding, not confirmation of previously recorded information.
  • 03Governance MI shows whether material triggers are actually changing customer risk assessments, CDD or control outcomes, rather than reporting trigger volume alone.
  • 04Material divergence between expected and actual customer activity is identified, assessed, escalated where necessary and resolved.
  • 05Escalation, restriction and exit pathways for material unresolved CDD issues are defined, owned and visible in governance where appropriate.
References
  • Regulation (EU) 2024/1624 (AMLR), provisions on customer due diligence and ongoing monitoring of the business relationship, applying from 10 July 2027.
  • AMLA, published material and consultation work on ongoing monitoring of business relationships (developing technical detail, not yet binding).
  • European Banking Authority, ML/TF Risk Factors Guidelines (EBA/GL/2021/02, as revised), where still relevant.
  • Danske Bank, Report on the Non-Resident Portfolio at Danske Bank's Estonian branch (Bruun & Hjejle, 2018).
  • De Nederlandsche Bank / Openbaar Ministerie, Settlement with ING Bank N.V., September 2018.
  • SEPBLAC, published supervisory material on ongoing due diligence and monitoring of business relationships.
Sobre el autor
Everett Morgan
Founder & Principal Adviser, Claritas Risk Advisory

Everett has more than twenty years' experience in financial crime, AML governance, regulatory compliance and operational risk gained within Deutsche Bank, Morgan Stanley and BNP Paribas. He established Claritas Risk Advisory to provide smaller regulated financial institutions with experienced independent judgement, practical insight and proportionate recommendations.

¿Necesita una opinión independiente?

Preparing for regulatory change starts with understanding where your organisation stands today.

If you would like to discuss your financial crime framework or explore how Claritas Risk Advisory can help, I would be pleased to arrange a confidential conversation.

Empecemos con una conversación