Skip to main content
Category: Customer Due Diligence

High-Risk Customer

Also known as: High-Risk Client, Higher-Risk Customer
Simply put

A high-risk customer is an individual or organization that a financial institution considers more likely to be involved in money laundering or other financial crime, based on factors such as who they are, where they operate, or how they use their accounts. Because they present a greater level of risk, businesses typically apply extra checks and closer monitoring to these customers. Being classified as high-risk does not mean the customer has done anything wrong; it means the institution has determined that additional scrutiny is warranted.

Formal definition

Within a risk-based AML/CFT framework, a high-risk (or higher-risk) customer is one whose risk profile, assessed across factors such as customer type, geography, products or services used, and transaction behavior, is rated as posing an elevated risk of money laundering or other financial crime relative to an institution's standard customer base. Such a classification is a compliance and risk-management determination made by an obliged entity, not a legal finding of wrongdoing. In many jurisdictions, customers assessed as higher-risk are subject to enhanced due diligence (EDD), which typically involves collecting additional information about the customer and applying heightened ongoing monitoring, as distinct from standard customer due diligence (CDD). The specific factors, thresholds, and required measures are set by the applicable regime and each institution's own risk assessment, and exact requirements should be confirmed against the relevant regulation; the FFIEC BSA/AML Examination Manual, for example, describes EDD as the collection of additional information about customers that pose heightened risk.

Why it matters

The classification of a customer as high-risk sits at the heart of the risk-based approach to AML/CFT. Rather than applying the same level of scrutiny to every customer, obliged entities are generally expected to allocate their resources according to the level of risk a customer presents, directing closer attention to those whose profile, geography, products, or behavior suggests an elevated likelihood of involvement in money laundering or other financial crime. Getting this determination right allows an institution to detect, deter, and mitigate risk more effectively; getting it wrong, by under-classifying customers who warrant additional scrutiny, can leave gaps that criminal actors may exploit.

It is important to stress that a high-risk classification is a compliance and risk-management determination, not a legal finding of wrongdoing. Labeling a customer as high-risk does not establish that the customer has committed any offense; it means the institution has concluded that additional scrutiny is warranted based on its risk assessment. This distinction matters operationally and reputationally, because the classification triggers heightened measures rather than adverse conclusions about the customer's conduct.

For examiners and regulators, the way an institution identifies and manages high-risk customers is a visible indicator of the maturity of its overall AML program. The FFIEC BSA/AML Examination Manual, for example, frames enhanced due diligence as the collection of additional information about customers who pose heightened risk. How consistently an institution identifies such customers, documents the basis for the rating, and applies proportionate controls speaks directly to whether its risk-based framework functions in practice or exists only on paper.

Who it's relevant to

Compliance officers and MLROs
Those responsible for an institution's AML/CFT program must define the factors used to classify customers as high-risk, ensure enhanced due diligence is applied proportionately, and document the basis for each determination. They also oversee that heightened ongoing monitoring is in place for customers rated as higher-risk, in line with the applicable regime and the institution's risk assessment.
CDD and onboarding teams
Front-line and onboarding staff assess customer type, geography, and intended use of products or services to help determine risk ratings. Where a customer is assessed as higher-risk, these teams typically collect the additional information that enhanced due diligence requires, distinguishing this from the standard CDD applied to the general customer base.
Financial crime and transaction monitoring analysts
Analysts apply the heightened ongoing monitoring associated with high-risk customers, reviewing transaction behavior for activity inconsistent with the customer's expected profile. Their role is to detect and escalate potential concerns, bearing in mind that a high-risk classification alone does not establish wrongdoing.
Examiners and regulators
Supervisory bodies assess whether obliged entities identify and manage high-risk customers consistently and proportionately. Resources such as the FFIEC BSA/AML Examination Manual describe enhanced due diligence as collecting additional information about customers who pose heightened risk, providing a reference point for evaluating an institution's risk-based framework.
Risk and audit functions
Risk-management and internal audit teams review whether the criteria for high-risk classification are applied consistently, whether the resulting controls are proportionate to the assessed risk, and whether documentation supports each determination, helping to confirm the risk-based approach operates as intended in practice.

Inside High-Risk Customer

Risk-Rating Outcome
A 'high-risk customer' is generally a classification assigned through an obliged entity's customer risk-assessment methodology, not a fixed legal category. The designation reflects the entity's assessment that a customer presents a heightened risk of being involved in money laundering or terrorist financing, and typically triggers enhanced due diligence (EDD) rather than establishing any wrongdoing.
Customer Risk Factors
Factors relating to the customer that may elevate risk, such as the customer being a politically exposed person (PEP) or associated with one, having complex or opaque ownership structures, or where beneficial ownership is difficult to verify. Frameworks such as the FATF Recommendations and the EU AML Directives identify categories of potentially higher-risk customers, though specific factors and weightings vary by jurisdiction and by each entity's methodology.
Geographic Risk Factors
Risk associated with the jurisdictions connected to a customer, including countries subject to sanctions, those identified by the FATF as having strategic deficiencies (for example, jurisdictions under increased monitoring or subject to a call for action), or countries assessed as higher-risk for corruption or terrorist financing. These are indicators to be weighed, not automatic determinations.
Product, Service, and Channel Risk
Elements relating to how the customer interacts with the entity, such as products that facilitate anonymity, non-face-to-face onboarding, or services associated with higher illicit-finance exposure. In many frameworks these factors combine with customer and geographic factors to produce an overall rating.
Enhanced Due Diligence (EDD) Trigger
In many jurisdictions, classifying a customer as high-risk generally requires the application of EDD measures, which go beyond standard customer due diligence (CDD). EDD typically involves obtaining additional information on the customer and source of funds or wealth, enhanced ongoing monitoring, and senior management approval, though the specific measures depend on the applicable regime.
Ongoing Monitoring and Review
A high-risk designation generally entails more frequent review of the customer relationship and closer transaction monitoring. The classification is dynamic and may change as new information emerges or as the customer's circumstances evolve.

Common questions

Answers to the questions practitioners most commonly ask about High-Risk Customer.

Does classifying a customer as high-risk mean they are engaged in money laundering or other financial crime?
No. A high-risk classification is a risk-management determination, not a finding of wrongdoing. It indicates that the customer's characteristics, products, geography, or behavior present a greater potential exposure to money laundering, terrorist financing, or other illicit-finance risk, and therefore typically warrant enhanced due diligence (EDD) and closer monitoring. It does not establish that any crime has occurred, and it should not be treated as evidence of criminality. Only a proper investigation and, where applicable, a determination by the relevant authorities can address questions of actual wrongdoing.
Is 'high-risk customer' a single, universally defined category that regulators apply the same way everywhere?
No. There is no single global definition that applies identically across jurisdictions. The FATF Recommendations set risk-based standards but are not binding law, and different regimes, such as the EU AML Directives and AML Regulation, the US Bank Secrecy Act and FinCEN rules, and the UK Money Laundering Regulations, describe higher-risk situations and factors in their own terms. In practice, each obliged entity generally translates these into its own risk-assessment methodology, so what triggers a high-risk classification, and the resulting measures, can vary by jurisdiction and by institution. Exact criteria should be confirmed against the applicable regulation and internal policy.
What enhanced measures typically apply once a customer is classified as high-risk?
In many jurisdictions, a high-risk classification generally triggers enhanced due diligence (EDD), which may include obtaining additional identifying and beneficial ownership information, establishing source of funds and source of wealth, obtaining senior management approval to establish or continue the relationship, and applying more frequent or intensive ongoing monitoring. The specific measures depend on the applicable regime and the institution's risk-based policies, so exact requirements should be confirmed against the relevant regulation.
How often should a high-risk customer relationship be reviewed?
High-risk relationships are generally subject to more frequent periodic review than standard or lower-risk relationships, and reviews may also be triggered by events such as material changes in behavior, ownership, or activity. Regulations often do not prescribe a single fixed interval; instead they typically require review frequency to be proportionate to the assessed risk. The precise cadence is usually set by the institution's risk-based policies and should be documented and confirmed against applicable guidance.
Can a high-risk classification be reduced or removed over time?
Yes. Risk ratings are generally dynamic and can be adjusted as new information becomes available or as circumstances change. Where the factors that drove the elevated rating no longer apply, and enhanced review supports a lower assessment, an institution may reclassify the customer in line with its methodology. Such changes should typically be supported by documented rationale and, where relevant, appropriate internal approval.
Should a high-risk classification, on its own, lead to filing a suspicious activity report?
No. A high-risk classification and a suspicious activity report (SAR), or suspicious transaction report (STR) in some jurisdictions, are distinct. A risk rating reflects the level of due diligence and monitoring applied to a relationship, while a suspicion-based report arises when specific activity meets the applicable reporting standard. Being high-risk may mean activity is scrutinized more closely, but the decision to file rests on whether the relevant suspicion threshold is met, not on the risk rating itself.

Common misconceptions

A 'high-risk customer' is a legally defined category identical across all jurisdictions.
The classification is primarily a risk-based, operational designation produced by an obliged entity's own methodology. While instruments such as the FATF Recommendations (which are standards, not binding law), the EU AML Directives, and national rules identify categories associated with higher risk, exact definitions, factors, and required responses diverge across regimes and should be confirmed against the applicable regulation.
Labelling a customer high-risk means the customer is involved in money laundering or a crime.
A high-risk rating is a compliance measure to manage and mitigate potential exposure; it does not establish, imply, or prove any wrongdoing. It generally signals only that additional scrutiny and controls, such as EDD and enhanced monitoring, are warranted.
Being a politically exposed person (PEP) automatically makes a customer high-risk to the same degree everywhere.
PEP status is a distinct concept that is a common trigger for enhanced scrutiny, but PEP screening is not the same as an overall high-risk determination. Treatment of PEPs, including distinctions between foreign, domestic, and international-organisation PEPs, varies by jurisdiction, and a PEP relationship is one factor weighed alongside others rather than a universal, fixed rating.

Best practices

Document a clear, methodology-driven basis for each high-risk classification, recording which customer, geographic, and product/service/channel factors contributed to the rating so decisions are auditable and defensible.
Apply enhanced due diligence proportionate to the assessed risk, including additional verification, understanding of source of funds and source of wealth where appropriate, and senior management sign-off in line with the applicable regime's requirements.
Treat the classification as dynamic by scheduling more frequent periodic reviews and refreshing customer information as circumstances or risk indicators change.
Keep the terminology precise: distinguish PEP screening, sanctions screening, and overall risk rating, and confirm specific thresholds, PEP definitions, and higher-risk-jurisdiction lists against the regulations and lists applicable to your jurisdiction.
Frame controls as measures to detect, deter, and mitigate risk rather than as guarantees, and ensure staff understand that a high-risk label is not evidence of criminality.
Calibrate enhanced monitoring so that alerts and reviews for high-risk customers are actioned and escalated consistently, avoiding both under-monitoring and defensive over-classification that dilutes resources.