Why this matters now
The current compliance agenda is moving away from the question of whether firms possess a customer due diligence policy and toward whether the customer due diligence framework produces defensible outcomes. The International Compliance Association highlighted the FCA’s 2026 review of customer due diligence as one of its principal August compliance issues. For compliance leaders, the important signal is that documentation is not enough: firms need to show that customer risk assessment, onboarding, enhanced due diligence and ongoing monitoring operate as one connected control system.
CDD should be treated as a risk decision, not a checklist
A customer file may contain an identity document, address evidence and a screening result while still failing to explain the actual financial crime risk. Effective due diligence begins with the nature of the relationship: who the customer is, why the product is needed, how the customer expects to use it, what jurisdictions and counterparties are involved, and what source of funds or source of wealth is economically plausible. The risk rating should emerge from that understanding rather than being created by a mechanical score that is never challenged.
The weakness of static risk ratings
Many firms still treat customer risk classification as a one-time onboarding output. That is increasingly difficult to defend. Risk can change because ownership changes, business activity changes, transaction behaviour diverges from the original profile, sanctions exposure increases, adverse media emerges or the customer begins using new products. Compliance functions should define specific event-driven triggers for reassessment rather than waiting for a periodic review date.
Evidence matters as much as policy
A strong control framework can demonstrate why a particular level of due diligence was considered proportionate. Reviewers should be able to trace the risk assessment to evidence, identify which higher-risk factors were considered, understand why any mitigants were accepted and see who approved exceptions. This creates a defensible audit trail for regulators, internal audit and future investigators.
Customer risk methodology
Risk methodologies should be back-tested against actual outcomes. Firms should ask whether customers later associated with suspicious activity were originally classified in a manner consistent with their observed risk. False low-risk outcomes are particularly important. A methodology that produces attractive distributions but systematically misses genuinely risky relationships is not working, regardless of how sophisticated its scoring engine appears.
Governance actions
Compliance leaders should review whether CDD decisions are owned by the business, challenged by the second line and supported by sufficiently skilled investigators. Management information should show more than the number of overdue reviews. It should include risk-rating overrides, enhanced due diligence completion, trigger-event reassessments, quality assurance findings, high-risk approval trends and recurring root causes.
Conclusion
The 2026 CDD agenda is fundamentally about control effectiveness. Firms that can explain why they know the customer, how they assessed the risk, what changed over time and why their controls responded appropriately will be in a stronger position than firms that rely on completed forms. The practical objective is not more documentation. It is better evidence that customer risk is understood and managed.
Related reading
See AML & Financial Crime, Regulatory Compliance and Governance, Risk and Compliance.
About the author
Jonas Adam Mohamed Osman Abdelghafour is a risk and compliance expert advising banks, insurers, payment institutions and asset managers on governance, financial crime, AI oversight and enterprise risk across UK and EU regimes. See qualifications and services, or get in touch to discuss an engagement.
*This article discusses regulatory frameworks in general terms and is not legal advice. Jurisdictional interpretation should be confirmed with qualified counsel.*
Sources
- International Compliance Association — current compliance issues: https://www.int-comp.org/
The International Compliance Association is cited here as an editorial source for current compliance issues. No affiliation with, or endorsement by, the ICA is claimed or implied.
Frequently asked questions
Why this matters now?
The current compliance agenda is moving away from the question of whether firms possess a customer due diligence policy and toward whether the customer due diligence framework produces defensible outcomes. The International Compliance Association highlighted the FCA’s 2026 review of customer due diligence as one of its principal August compliance issues. For compliance leaders, the important signal is that documentation is not enough: firms need to show that customer risk assessment, onboardi...
What should risk leaders know about cDD should be treated as a risk decision, not a checklist?
A customer file may contain an identity document, address evidence and a screening result while still failing to explain the actual financial crime risk. Effective due diligence begins with the nature of the relationship: who the customer is, why the product is needed, how the customer expects to use it, what jurisdictions and counterparties are involved, and what source of funds or source of wealth is economically plausible. The risk rating should emerge from that understanding rather than b...
What should risk leaders know about the weakness of static risk ratings?
Many firms still treat customer risk classification as a one-time onboarding output. That is increasingly difficult to defend. Risk can change because ownership changes, business activity changes, transaction behaviour diverges from the original profile, sanctions exposure increases, adverse media emerges or the customer begins using new products. Compliance functions should define specific event-driven triggers for reassessment rather than waiting for a periodic review date.
What should risk leaders know about evidence matters as much as policy?
A strong control framework can demonstrate why a particular level of due diligence was considered proportionate. Reviewers should be able to trace the risk assessment to evidence, identify which higher-risk factors were considered, understand why any mitigants were accepted and see who approved exceptions. This creates a defensible audit trail for regulators, internal audit and future investigators.
What should risk leaders know about customer risk methodology?
Risk methodologies should be back-tested against actual outcomes. Firms should ask whether customers later associated with suspicious activity were originally classified in a manner consistent with their observed risk. False low-risk outcomes are particularly important. A methodology that produces attractive distributions but systematically misses genuinely risky relationships is not working, regardless of how sophisticated its scoring engine appears.