Ongoing Customer Due Diligence

We strengthen your ongoing customer due diligence and risk classification processes

When risk classification changes: ongoing customer due diligence as part of everyday AML work

View as Markdown
6 mins read • Legal Writer • 3 June 2026

For many obliged entities, customer due diligence linked to risk classification is still primarily associated with onboarding. However, anti-money laundering legislation is based on a risk-based approach throughout the entire customer relationship. For AML officers and operational staff, this means that risk classification must be treated as an ongoing process, not an initial step that is “ticked off” and then left untouched.

Why ongoing customer due diligence and risk classification are connected

Anti-money laundering legislation requires obliged entities to understand the customer’s risk profile and monitor it over time. The initial risk classification at onboarding provides only a first view of the customer. When the customer’s business, ownership structure or behaviour changes, the original assessment can quickly become outdated.

Ongoing customer due diligence is therefore about:

  • continuously monitoring the customer’s transactions and behaviour,
  • identifying changes that affect money laundering, terrorist financing and sanctions risk,
  • updating the risk classification when the risk profile changes, and
  • adapting the scope of customer due diligence measures to the new risk level.

When should the risk classification be reassessed?

A common practical issue is that the business lacks clear thresholds for when risk classification should be reassessed. The result is that customers remain in a low or normal risk category, even though their actual risk profile has changed materially.

Typical situations in which the risk classification should be reassessed include:

  • New owners or beneficial owners – particularly where they have links to high-risk countries or politically exposed positions (PEPs).
  • Increased geographical exposure – for example, where the customer’s business begins to cover new countries, sectors or customer categories with higher risk.
  • New products or services – where the customer’s business model changes, for example from straightforward consultancy services to complex arrangements with multiple transaction flows.
  • Unusual behaviour – transactions, volumes or payment patterns that do not match what you expected based on the customer’s profile.
  • Adverse media – for example, reporting on financial crime, sanctions lists or other circumstances that affect the customer’s risk classification.
  • Internal warning signals – recurring deficiencies in documentation, reluctance to provide information or repeated attempts to circumvent your procedures.

From observation to updated risk classification: a practical workflow

For ongoing customer due diligence and risk classification to work in day-to-day operations, there must be a clear workflow for what happens when something does not feel right. A practical approach is to link each deviation to a structured process:

  • Observation – an employee notes unusual behaviour, new information or external media reporting.
  • Initial assessment – the person who identified the deviation makes a brief note and escalates the matter in accordance with the established escalation route.
  • AML review – the AML officer or designated function analyses whether the new information affects the risk profile.
  • Updated risk classification – the risk category is adjusted where necessary, including a documented rationale.
  • Adjusted measures – a decision is made on enhanced customer due diligence, stricter monitoring, amendment of terms or possible termination of the customer relationship.

The key point is that there is a clear connection between observation, analysis, risk classification and measures, and that all steps are documented in a way that can be followed up and explained during supervisory review.

What does a higher risk category mean in practice?

Increasing a customer’s risk category is not merely a note in a system. It must have concrete consequences for how you manage the customer. The precise measures that are proportionate will depend on the nature of the business, but typical consequences may include:

  • extended identification of beneficial owners and verification of ownership structures,
  • a deeper understanding of the customer’s business model and revenue flows,
  • more frequent transaction monitoring and manual review,
  • requirements for supplementary documentation and explanations for transactions,
  • internal reporting to the AML function or management where recurring concerns arise, and
  • assessment of whether suspected money laundering should be reported to the Financial Intelligence Unit.

Similarly, a lower risk category, following a well-reasoned and documented reassessment, may mean that certain enhanced measures are no longer necessary. This must also be a deliberate and traceable assessment.

Common pitfalls in ongoing customer due diligence and risk classification

Where ongoing customer due diligence risks becoming a paper exercise, recurring patterns are often present. Typical pitfalls include:

  • Onboarding-led thinking – all effort is placed on the initial customer due diligence, while limited resources are allocated to follow-up.
  • Lack of thresholds – no clearly defined events that automatically trigger a reassessment of the risk category.
  • Unclear responsibility – employees are unsure who should act when something appears unusual.
  • Systems that do not support the business – the risk category is recorded at the outset but cannot easily be updated or linked to follow-up measures.
  • Dependence on individuals – knowledge of customers and risks exists in employees’ “heads” rather than in documented assessments.

For AML officers, the task is often to translate the regulatory framework into clear procedures, simple decision-making tools and system support that makes it easy to do the right thing, even under time pressure.

How to strengthen ongoing customer due diligence and risk classification

Effective work with ongoing customer due diligence and risk classification requires both structure and culture. Concrete steps may include:

  • Define clear events that must always lead to reassessment of the risk category, such as a new beneficial owner, new countries or adverse media coverage.
  • Ensure that aml transaction monitoring captures deviations linked to the customer’s expected behaviour.
  • Introduce a simple internal reporting route for “something seems wrong” and train employees in how and when to use it.
  • Make it easy to document and track risk classification decisions, preferably directly in your existing systems.
  • Review a sample of existing customers annually to verify that the risk category remains reasonable.

When ongoing customer due diligence and risk classification work well, they become more than a way to comply with anti-money laundering legislation. They also become a management tool for selecting the right customers and protecting the business’s reputation. At Morling Consulting, experienced AML lawyers support companies and organisations operating and serving clients across Europe with designing and implementing risk-based procedures, training employees and quality-assuring customer due diligence work over time.

Speak to an AML lawyer

Do you need to reassess customer risk classifications under AML rules? Contact us and we will assess them

"*" indicates required fields