Customer Restrictions, De-Risking and Financial Inclusion
A customer can be higher risk without being prohibited, suspicious without being proven criminal, difficult to verify without being dishonest, commercially unattractive without being a financial-crime problem, and legally restricted without the correct response necessarily being account closure. Those distinctions are the foundation of good restriction and exit governance.
The practical question for a bank is not simply whether a customer looks risky. It is what action is lawful, proportionate and operationally effective given the facts the bank actually knows. Possible outcomes can include continued service with no change, enhanced due diligence, tighter transaction limits, removal of a channel or product, enhanced monitoring, temporary controls while evidence is gathered, refusal of a new service, managed relationship exit, or a legally required action such as freezing or rejecting particular activity. Which outcome is appropriate depends on applicable law, the customer's facts, the product, the jurisdiction, the bank's risk appetite and the effectiveness of available controls.
This is where de-risking and financial inclusion meet. A bank that treats every higher-risk category as an automatic exit problem may remove legitimate customers from the regulated system without materially improving financial-crime control. A bank that treats inclusion as a reason to ignore material risk is equally wrong. The professional discipline is to understand the risk, distinguish legal obligations from risk appetite, consider controls that genuinely address the concern, document why the selected outcome is appropriate, and keep the decision reviewable as facts change.
FATF's risk-based approach provides the global starting point. FATF strengthened Recommendation 1 in 2025 and updated its financial-inclusion guidance to place greater emphasis on proportionate risk-based measures and the use of simplified measures in lower-risk situations where permitted. The guidance is not a universal account-access law and does not override domestic legislation. It does, however, reinforce an important principle: AML/CFT controls should respond to assessed risk rather than automatically excluding broad classes of legitimate customers.
Start with the legal question, not the commercial instinct
Before deciding how to restrict a relationship, the bank should identify what kind of problem it is dealing with. Four questions prevent many bad decisions.
First, is there a legal prohibition or mandatory action? A sanctions rule, court order, asset-freeze requirement, licensing condition or other binding measure can dictate what the bank must do. Even here, teams should not assume that "sanctioned" always means "close the account." Some regimes require assets to be frozen and prohibit dealing with them; terminating a relationship or returning funds could itself be impermissible. Legal interpretation therefore sits ahead of generic exit playbooks.
Second, is the issue a customer-due-diligence failure? If required identity, beneficial-ownership, purpose-of-relationship or other evidence cannot be obtained to the standard required by applicable law and policy, the bank may be unable to start or continue the relationship. The exact consequence, timing, reporting implications and communication constraints are jurisdiction-specific. Investigators, relationship managers and operations teams need a common case record so that a request for missing evidence does not become an unexplained restriction in one system and an ordinary service issue in another.
Third, is the activity lawful but outside risk appetite? A bank may decide that it lacks the expertise, systems, correspondent support or monitoring capability to serve a particular risk profile safely. That can be a legitimate risk-management or commercial decision. It should not be described as a statutory requirement unless law actually requires it. The distinction matters for governance, customer communication, complaint handling, management information and future re-entry decisions.
Fourth, can the identified risk be controlled without ending the entire relationship? That is not a rule that a bank must always choose the least restrictive outcome. Some risks cannot be managed acceptably. But asking the question forces decision-makers to connect the proposed consequence to the actual risk instead of treating exit as a substitute for analysis.
The restriction ladder as a decision tool
A useful operating model is a restriction ladder. The bottom of the ladder is normal service. Above it are progressively stronger measures: enhanced information requirements, tighter monitoring, transaction limits, channel restrictions, product restrictions, temporary holds where legally and operationally permitted, refusal of a new capability, and managed exit. A separate legal-action lane handles outcomes such as freezing, blocking, rejecting or reporting where applicable law requires a specific response.
The ladder is valuable because it makes the bank articulate the control hypothesis. If the concern is unverified source of funds for a particular activity, a targeted limit plus evidence request may address the risk better than terminating unrelated services. If the concern is repeated abuse of instant-payment functionality, removal of that channel may be more relevant than closing a deposit account. If ownership cannot be established despite reasonable attempts and continued service would breach CDD requirements, restrictions may not solve the underlying problem and exit may be necessary.
Each rung needs an entry condition, owner, approval level, effective date, review date and release condition. A restriction with no review trigger tends to become permanent through inertia. A restriction with no release condition leaves staff unable to tell a customer what evidence would materially change the decision. A restriction with no technical enforcement path exists only in a case-management note while the payment engine continues to process the activity it was meant to constrain.
The most mature designs also record why alternatives were rejected. That does not mean a bank must produce a legal essay for every decision. It means the evidence trail should be good enough for a later reviewer to reconstruct the logic: what concern existed, what controls were considered, why the selected measure was chosen, who approved it, what the customer was told where disclosure was permitted, and what will cause the decision to be reconsidered.
Relationship exit is a process, not a single status
Relationship exit is often described as a final outcome, but operationally it is a lifecycle. The lifecycle starts with a decision basis and approval, then moves through communication, wind-down, settlement of legitimate obligations, data retention, downstream-system updates and post-exit controls. Depending on jurisdiction and facts, notice periods may be set by contract or law, shortened for defined reasons, or constrained by confidentiality and tipping-off rules. The bank should therefore parameterise notice and communication rules rather than hard-code one universal template.
A defensible exit record distinguishes the reason for exit. Examples include inability to complete required CDD, activity that cannot be reconciled with the stated relationship purpose, risk outside the bank's appetite after escalation, repeated misuse of a product, commercial withdrawal from a service, or a legal requirement. Those grounds should not be merged into a vague label such as "compliance." Vague reason codes weaken analytics, make complaints harder to investigate and encourage staff to attribute commercial decisions to AML/CFT when that is not the real reason.
The wind-down phase also needs control. Pending payments may have different legal and operational treatment from future instructions. Customer funds cannot simply disappear into an operational suspense position because an exit flag was applied. Balances, fees, standing orders, incoming credits, card authorisations, trade instruments, lending obligations and connected entities all need defined handling. Where funds are frozen or otherwise legally restricted, the legal regime determines what can and cannot be moved.
Post-exit controls should focus on legitimate risk questions rather than creating a permanent unofficial blacklist. If the exit involved serious misuse, onboarding teams may need reliable linkage to prior entities, owners, devices or addresses so that a new application can be reviewed with context. At the same time, historic adverse outcomes need appropriate retention periods, access controls and challenge mechanisms under applicable privacy, banking-secrecy and consumer-protection requirements.
What de-risking actually means
The word de-risking is used loosely. For this chapter, it means refusing or terminating relationships broadly because customers belong to a category perceived as higher risk, rather than managing the risk through a sufficiently specific assessment of customers, products and controls. FATF has repeatedly distinguished the risk-based approach from wholesale cutting off of entire classes of customer without serious consideration of their actual risk and available mitigation.
That does not mean every portfolio exit is prohibited. A bank can make legitimate strategic decisions about the markets and products it offers. It may conclude that a business line cannot be operated safely or economically, or that a service no longer fits its strategy. The important discipline is to describe the decision accurately, assess legal and contractual obligations, consider customer impacts, and avoid presenting a commercial portfolio decision as though FATF or a supervisor automatically required every customer in the category to be exited.
Common drivers of de-risking include fear following enforcement action, correspondent-bank pressure, weak customer data, high manual-review cost, uncertainty about a sector's typologies, poor monitoring technology and senior-management concern about reputational exposure. Those pressures are real. The answer is not to pretend they do not exist, but to separate them. A control problem should lead to control remediation. A data problem should lead to better data. A capacity problem should lead to a conscious capacity decision. A commercial problem should be governed as a commercial decision with compliance challenge where financial-crime language is being used to justify it.
This separation is particularly important for money-service businesses, charities, non-profit organisations, correspondent respondents, fintechs, customers from higher-risk jurisdictions and other groups that can be treated as uniformly risky despite wide variation within the category. A licence, country, occupation or sector is a risk factor, not a complete customer conclusion.
The 2025 FATF inclusion lens
FATF's June 2025 Guidance on Financial Inclusion and AML/CFT updated earlier guidance following changes to Recommendation 1 and related interpretive notes. It emphasises proportionate implementation of the risk-based approach and explains how simplified measures can support access in lower-risk situations where the standards and domestic law permit them. The guidance also makes clear that financial inclusion and financial integrity are not opposites: bringing legitimate activity into regulated channels can improve transparency and monitoring.
For a bank, that does not create an automatic duty to onboard every applicant. It changes the quality of the question. Teams should avoid assuming that limited documentation, low income, refugee status, rural residence, digital exclusion or another inclusion characteristic automatically means higher ML/TF risk. The bank should identify what it needs to know, what alternative reliable evidence is available, whether the situation is actually lower, standard or higher risk, and what controls are proportionate to that assessment.
Jurisdiction-specific access rights can go further than the FATF framework. In the European Union, the Payment Accounts Directive creates a right of access to a payment account with basic features for eligible consumers, subject to national implementation and specified conditions. Article 16 also requires refusal where opening the basic account would infringe applicable AML/CFT provisions. This is a useful example of why "financial inclusion" cannot be implemented through a global policy slogan: legal rights, refusal grounds, notice rules and complaint routes depend on the jurisdiction and product.
The EBA's 2023 Guidelines on effective management of ML/TF risks when providing access to financial services are another EU-specific example. They seek to address unwarranted de-risking and require institutions within scope to consider individual risk and proportionate mitigation rather than automatically refusing or terminating customers merely because they belong to a higher-risk category. These requirements should be taught as European regulatory expectations, not as global law.
In the United Kingdom, the FCA's work on payment-account access and closures has similarly focused attention on governance, customer treatment, communication and whether firms can evidence their decisions. UK expectations arise from the UK regulatory and legal framework and should not be copied into another jurisdiction without mapping the local rules first.
Designing an inclusion-aware control without weakening AML/CFT
The strongest inclusion measures are usually concrete product and process choices rather than broad statements about fairness. Examples include accepting reliable alternative identity evidence where local rules permit it, offering a basic or limited-purpose account with functions aligned to the assessed risk, applying lower transaction limits during an evidence-building period, using enhanced monitoring for a defined risk instead of refusing all service, and providing assisted channels for customers who cannot complete a standard digital journey.
The control must still make sense. A low-limit account is not useful if the limit prevents ordinary wages or essential payments. Enhanced monitoring is not a substitute for mandatory identity verification. Alternative evidence should be evaluated for reliability, independence and fraud risk rather than accepted merely because it is alternative. A limited product must not quietly expand through linked features that recreate the exposure the limitation was designed to control.
Product managers, compliance teams and architects should therefore design inclusion and control together. The product catalogue needs flags showing which capabilities are available at each verification and risk state. The rules engine needs to know which limits apply to which transaction types. Case management needs release conditions. Customer channels need clear messages that are accurate without disclosing confidential investigative information. Reporting needs to distinguish legal restriction, risk-based restriction, customer-requested limitation and ordinary commercial product eligibility.
Appeals, complaints and second-look review
Not every jurisdiction gives customers a specific legal right to appeal every financial-crime restriction. But banks generally need complaint and review mechanisms that reflect applicable consumer, conduct, equality, contractual and ombudsman frameworks. Internal second-look review is also a valuable control even where no formal external appeal right exists, because financial-crime decisions are made under uncertainty and new evidence can change the picture.
A good review process separates reconsideration from simple re-performance of the original decision. The reviewer should see the original evidence, understand the decision rule, examine new information and have clear authority to uphold, vary or reverse the measure within the bank's governance model. Sensitive cases may require specialist legal, sanctions, fraud, safeguarding or financial-crime input.
Release and overturn rates should be interpreted carefully. There is no universal "healthy" percentage. A zero overturn rate could reflect excellent first-line decisions or a review process that never genuinely challenges them. A high rate could indicate an effective correction mechanism or poor original quality. The useful analysis is by decision type, reason, business line, reviewer, customer segment and root cause, with samples examining whether similar facts receive similar treatment.
Communication is equally important. Customers need to know what they can do next where disclosure is lawful and appropriate. The bank should avoid invented specificity about suspicious activity when it cannot disclose it, but equally avoid meaningless messages such as "policy decision" when a clearer lawful explanation is possible. Templates should be jurisdiction- and outcome-specific rather than one generic AML letter used for every restriction.
Vulnerability changes how the bank should execute the decision
A technically correct restriction can still produce severe harm if the bank ignores vulnerability. Age-related cognitive decline, disability, financial distress, coercive control, trafficking, scam victimisation, displacement, language barriers and digital exclusion can affect both the customer's ability to understand the process and the meaning of the activity that triggered concern.
For example, an elderly customer making unusual transfers may be a fraud victim rather than a willing participant. A trafficking victim's account may show mule-like movement under coercion. A recent refugee may have weak conventional documentation but strong alternative evidence. A customer with cognitive impairment may need an authorised representative or adapted communication, while the representative may itself need scrutiny if abuse is suspected.
The bank should therefore separate the risk to the institution from the risk to the customer. Safeguarding controls can include safe-contact procedures, restriction of a compromised channel, credential reset, trusted-person arrangements where lawful, specialist review and referral through appropriate local safeguarding or law-enforcement pathways. The exact duties and information-sharing permissions differ by jurisdiction, so global procedures should define the decision pattern while local annexes define the legal gateways.
Data architecture: restriction decisions must be computable and explainable
Restrictions often fail because the policy is more precise than the data model. A decision such as "permit domestic salary receipts and bill payments, block new international beneficiaries, limit cash deposits pending evidence review, review in 30 days" cannot be implemented by a single restricted = true flag.
A useful restriction object contains at least the customer or account scope, reason category, legal-versus-policy basis, affected products and channels, transaction types, thresholds, geography where relevant, start time, expiry or review date, decision owner, approver, linked case, customer-communication status and release conditions. Systems should preserve versions so investigators can reconstruct what restriction applied at the time of a historical payment.
Enforcement points need to be mapped. A mobile channel may enforce beneficiary creation while a payment hub enforces transaction amount, a card platform controls merchant-category usage, and branch systems handle cash. If one system does not receive the restriction quickly enough, the bank can create an inconsistent customer experience and a control gap at the same time.
Business analysts should therefore write requirements as end-to-end outcomes. "Restrict international payments" is incomplete. Which payment types? Which currencies? What about incoming international credits? Standing orders? Card transactions abroad? Trade finance? Internal transfers to a linked FX wallet? What status should the customer see? What does operations see? What happens if the restriction service is unavailable? How is the decision reversed? The answers belong in acceptance criteria, not in post-incident interpretation.
Monitoring whether restrictions actually manage the risk
Restrictions are controls and should be tested as controls. If a cash-deposit cap is imposed, analytics should show whether cash exposure reduced or shifted to another account or channel. If instant payments are removed, monitoring should look for displacement into cards, scheduled transfers or related accounts. If a customer is exited for an ownership problem, new applications using related owners, directors, addresses or devices may require contextual review.
Portfolio analytics should distinguish volumes from quality. Useful measures can include restriction count by reason, age of temporary restrictions, proportion reviewed on time, customer complaints, upheld complaints, restriction release reasons, exit reasons, re-entry detections, alternative-product take-up, and concentrations by segment or geography. Metrics involving demographic characteristics require lawful collection and use under relevant privacy and equality frameworks.
The board does not need every operational field, but senior governance should be able to see whether the institution is moving toward uncontrolled risk or indiscriminate exclusion. A sudden rise in exits with no corresponding change in risk profile should prompt investigation. So should a restriction population that never ages out, a business line with materially different outcomes from peers, or repeated complaints showing that technically correct decisions are being communicated badly.
Correspondent-bank pressure
De-risking can be transmitted through correspondent banking. A respondent may be told to improve controls, provide additional information, reduce exposure to a particular nested relationship or face termination. The respondent then has a choice: remediate the specific weakness, diversify correspondents, redesign the product, change the underlying customer relationship, or exit activity it can no longer support safely or commercially.
The mistake is to copy the correspondent's pressure mechanically into blanket downstream customer exits. The respondent should identify what the correspondent is actually concerned about. If it is payment transparency, improve data. If it is nested respondent visibility, establish the required respondent due diligence and payment controls. If the correspondent is making a commercial strategic withdrawal regardless of control quality, the respondent should treat that as a dependency and resilience problem as well as a financial-crime issue.
Correspondent requirements also need contractual traceability. A rule that originates from a correspondent contract should not be represented internally as a legal prohibition unless it is one. That distinction helps legal teams, operations, product owners and customer-facing staff apply the right consequence and helps the bank revisit the restriction if the correspondent arrangement changes.
Cross-border groups: one customer, several legal environments
A global bank can serve the same corporate group through multiple legal entities. Restrictions applied in one entity may not automatically apply in another because the law, product, contractual relationship, risk appetite and data-sharing permissions differ. Group policy can set minimum governance standards, but local entities still need to map domestic legal requirements and determine what customer information can be shared across borders.
The data model should therefore retain legal-entity context. A group-wide case identifier can link the risk story, while each entity records its own legal basis, product impact and decision. This avoids two opposite failures: treating every local decision as isolated and missing the group risk, or propagating a restriction globally without checking whether the same legal and factual basis exists everywhere.
Notification and reporting duties should be mapped explicitly rather than assumed. Some regulated circumstances create mandatory notifications or reporting; others impose confidentiality or tipping-off constraints. The requirement depends on the jurisdiction, product and event. Requirements documents should point to the applicable local rule or policy owner instead of encoding a global statement such as "all exits must be reported to the regulator."
A realistic mini case: a remittance business under pressure
Consider a licensed remittance company that has banked with the institution for six years. Transaction volumes rise sharply after the company adds new agent locations. Monitoring identifies higher cash funding, new corridors and several payments involving counterparties outside the customer's historic profile. None of those facts alone proves laundering, but together they justify reassessment.
The bank's first task is evidence. Relationship teams obtain the updated agent network, licensing information, corridor rationale, source-of-funds model and customer-screening controls. Financial-crime specialists compare the new activity with the stated business model and test a sample of agent transactions. Payment data shows that most growth is coherent, but two agents have unusually high cash concentration and weak underlying originator information.
A blanket exit of the entire remittance company would remove the two problematic exposures but also terminate legitimate activity across the rest of the network. Instead, the bank considers whether the identified risk can be isolated. It suspends the two agents from the banked flow pending remediation, applies enhanced monitoring to the expanded corridors, requires improved originator data, and schedules a 60-day review. The relationship remains open subject to those controls.
At review, one agent supplies sufficient evidence and is restored with tighter monitoring. The other cannot explain repeated incomplete originator information and is removed permanently from the permitted network. The bank records why company-wide exit was not necessary, why the targeted controls were sufficient, and what would trigger escalation if the pattern recurs. Had the evidence shown systemic management involvement or inability to identify the underlying customers, a broader restriction or exit could have been justified.
This example is deliberately not presented as a mandatory regulatory sequence. It illustrates the reasoning pattern: define the concern, gather evidence, distinguish localised from systemic risk, identify applicable legal requirements, choose controls that genuinely address the risk, and preserve escalation if the controls fail.
BA, architecture and testing considerations
For a business analyst, restriction design should produce requirements that operations and technology can execute without interpretation gaps. Each restriction type needs a state model, trigger, scope, owner, effective time, expiry or review rule, customer-facing status, audit trail and reversal process. Legal holds, fraud blocks, sanctions freezes and AML risk restrictions should not share one generic status because their permitted actions and communications can differ materially.
For architects, the key question is where the decision is enforced. The customer master may store the reason, but real-time payment, card, trade and channel systems need the executable rule. Event-driven propagation should have acknowledgements and reconciliation so a failed update is visible. Systems should prevent one channel from silently remaining open because it uses a stale customer cache.
For testers, positive and negative scenarios both matter. Positive tests confirm that the intended restricted activity is blocked or limited. Negative tests confirm that allowed activity still works, because over-blocking is a customer-harm and operational-risk problem. Boundary tests should cover effective times, expiry, daylight-saving or timezone effects where relevant, overlapping restrictions, related accounts, failure of the restriction service, manual overrides and release after review.
For operations, queue design should separate temporary restrictions needing evidence from permanent or legally driven outcomes. Ageing controls matter because a temporary restriction that no one reviews becomes an undeclared permanent restriction. Service levels should be risk- and customer-impact aware rather than one universal target.
For governance, quality assurance should sample both decisions to restrict and decisions not to restrict. Looking only at adverse outcomes creates confirmation bias. The institution also needs to know whether staff are over-restricting customers because it is operationally easier than performing deeper analysis.
Practical takeaways
Customer restriction is not a synonym for exit. Higher risk is not the same as prohibited activity. Financial inclusion is not permission to relax mandatory controls. De-risking is not solved by forcing every institution to bank every customer. The central discipline is a documented risk-based decision that identifies the applicable legal framework, connects the concern to an effective control, considers customer impact, and remains reviewable when the evidence changes.
FATF's 2025 changes make proportionality and financial inclusion more explicit within the global risk-based framework, but domestic law still determines the legal rights, refusal grounds, reporting duties and customer-remediation requirements that apply in a particular market. EBA rules apply within their European scope; EU basic-account rights arise from EU law and national implementation; FCA expectations apply within the UK framework. A global bank should therefore use one consistent decision architecture with jurisdiction-specific legal rules, not one universal legal conclusion.
The strongest restriction regime is neither the one that exits the most customers nor the one that preserves every relationship. It is the one that can explain, with evidence, why each material outcome was lawful, proportionate to the assessed risk, operationally effective and subject to appropriate governance.
References and further reading
- Financial Action Task Force (FATF), Guidance on Financial Inclusion and Anti-Money Laundering and Terrorist Financing Measures, June 2025: https://www.fatf-gafi.org/en/publications/Financialinclusionandnpoissues/guidance-financial-inclusion-aml-tf-measures.html
- Financial Action Task Force (FATF), The FATF Recommendations: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
- Financial Action Task Force (FATF), FATF clarifies risk-based approach: case-by-case, not wholesale de-risking: https://www.fatf-gafi.org/en/publications/Fatfgeneral/Rba-and-de-risking.html
- European Banking Authority (EBA), Guidelines on policies and controls for the effective management of ML/TF risks when providing access to financial services: https://eba.europa.eu/legacy/regulation-and-policy/regulatory-activities/anti-money-laundering-and-countering-financing-6
- European Banking Authority (EBA), EBA issues Guidelines to challenge unwarranted de-risking and safeguard access to financial services to vulnerable customers, 31 March 2023: https://www.eba.europa.eu/publications-and-media/press-releases/eba-issues-guidelines-challenge-unwarranted-de-risking-and
- European Union, Directive 2014/92/EU on payment accounts, including Article 16 on access to payment accounts with basic features: https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX%3A32014L0092
- Financial Conduct Authority (FCA), UK payment accounts access and closures: update, 4 September 2024: https://www.fca.org.uk/publications/corporate-documents/uk-payment-accounts-access-and-closures-update
- Basel Committee on Banking Supervision, Sound management of risks related to money laundering and financing of terrorism: https://www.bis.org/bcbs/publ/d505.htm
Operational deep dive: vulnerability, coercion and age-related risk
The base chapter established restriction proportionality. This deep dive covers the populations where standard restriction mechanics fail without adaptation: vulnerability markers demanding care procedures, coercion and trafficking contexts requiring victim-centred responses, and age-related decline challenging capacity assumptions that restriction decisions depend upon.
Vulnerability markers and care procedures
Vulnerability identification needs systematic markers embedded in customer data and interaction observation rather than dependence on individual staff sensitivity that varies unpredictably across the estate. Data markers include age thresholds with cognitive-decline awareness, disability registrations with consent-based recording, financial-distress indicators from arrears and erratic balances, and life-event signals — bereavement, divorce, displacement — that temporarily impair financial capability. Interaction markers emerge from communication patterns: confusion about previously understood products, repeated identical queries, susceptibility signals in scam-vulnerability screening, and third-party voices directing customer responses during calls that coercion monitoring flags specifically.
Care procedures activate on marker detection with adapted processes rather than standard treatment plus sympathy. Decision timeframes extend with review scheduling accommodating comprehension needs and support-person arrangement. Communication shifts to plain-language explanations with comprehension verification, avoiding legalistic restriction letters that vulnerable customers cannot parse or contest. Specialist reviewers with vulnerability training assume complex cases from generalist queues, bringing expertise in capacity assessment, safeguarding referral and trauma-informed inquiry that standard reviewer training never covers. Each adaptation needs defined entry and exit criteria preventing permanent special-handling status that infantilises capable customers while ensuring genuine vulnerability receives sustained accommodation.
Coercion, trafficking and victim-centred restriction
Coerced customers — trafficking victims directed to move funds, elder-abuse victims instructed by carers, intimate-partner financial-abuse targets, debt-bondage labourers operating accounts for controllers — present risk indicators identical to willing criminal participants while moral and legal status differs fundamentally. Distinguishing evidence includes transaction-direction analysis revealing external control through timing correlation with controller contact, benefit-flow tracing showing value bypassing the nominal accountholder entirely, communication monitoring with consent-framework compliance detecting instruction patterns, and direct sensitive inquiry conducted by trained staff in safe conditions where victim disclosure becomes possible. No single indicator proves coercion; assembled patterns support safeguarding responses that criminal-justice framing would foreclose prematurely.
Restriction responses for confirmed or probable victims prioritise protection continuity over relationship termination: account controls blocking controller access while preserving victim banking, transaction limits preventing exploitation-scale movements without removing legitimate access, and safe-contact protocols ensuring bank communication reaches victims rather than controllers monitoring their channels. Safeguarding referrals to law enforcement, social services and specialist charities proceed with victim-consent frameworks varying by jurisdiction and urgency, with information-sharing gateways documented for each referral pathway. Staff need explicit permission to spend time on victim cases that standard productivity metrics penalise, since safeguarding work resists throughput measurement while preventing the revictimisation that blunt restriction inflicts when victims lose banking access along with controller contact.
Child exploitation and county-lines account handling
Child criminal exploitation through county-lines drug distribution and similar models uses young people's accounts for transit and collection at scales that transaction monitoring detects as mule networks while age markers demand safeguarding-first responses that adult-fraud procedures would mishandle punitively. Identification combines age data with exploitation indicators: transaction direction by older controllers evidenced through device and communication analysis, balance patterns inconsistent with legitimate youth finances, school-term timing anomalies suggesting coercion scheduling around education, and missing-person or social-service flag correlation where information-sharing gateways permit. Classification as potential child victim triggers statutory safeguarding duties in many jurisdictions with referral obligations and timescales that restriction processes must satisfy regardless of fraud-investigation sequencing preferences.
Account handling balances exploitation prevention with the child's welfare and future financial inclusion: transaction controls blocking criminal transit while preserving legitimate access that complete closure would remove punitively, trusted-adult involvement with careful assessment distinguishing protective family from complicit controllers, and law-enforcement coordination through child-exploitation protocols rather than standard fraud-reporting channels that lack safeguarding integration. Staff need specialist training recognising that exploited children may present as uncooperative, hostile or loyal to exploiters, requiring trauma-informed engagement that standard interview techniques damage further. Records carry safeguarding-grade protection with multi-agency sharing governed by child-protection frameworks that override standard confidentiality in defined circumstances the bank's procedures must navigate precisely.
Disability-inclusive restriction design
Disability affects restriction journeys through communication barriers, comprehension differences, authentication challenges and support-network dependencies that standard processes penalise systematically without inclusive design. Sensory-impairment accommodations provide alternative communication formats with equivalent legal validity — braille, audio, easy-read versions of restriction notices that standard letters render inaccessible — while authentication alternatives serve customers unable to complete biometric or device-based verification through assisted pathways with safeguarding controls. Cognitive-disability adaptations extend decision timeframes, simplify language with comprehension verification, and involve support persons with consent frameworks preventing helper abuse that assistance relationships enable.
Process testing with disabled users reveals exclusion points that able-bodied design teams never encounter: CAPTCHA-style challenges blocking screen-reader users, video-verification excluding customers with facial differences or movement conditions, timeout-driven sessions punishing slow but legitimate interaction, and branch-closure programmes removing the assisted alternative digital journeys assumed as backup. Each finding needs remediation with disabled-user validation rather than design-team assumption about accessibility adequacy. Regulatory equality duties in many jurisdictions make inclusive restriction design a legal obligation independent of fairness preference, with supervisory findings on exclusionary processes carrying consequences beyond complaint volumes into enforcement territory that restriction governance must treat with corresponding seriousness.
Substance-misuse and gambling-related vulnerability
Substance misuse and problem gambling impair financial decision-making in patterns restriction regimes must recognise as vulnerability rather than misconduct, since standard fraud-response restriction punishes symptoms of conditions requiring safeguarding. Indicator frameworks combine transaction-pattern evidence — erratic timing inconsistent with employment routines, round-amount transfers to gambling operators with loss-chasing escalation signatures, cash advances preceding disconnection periods — with interaction evidence where customer contact reveals confusion, distress or third-party direction. Classification as vulnerability rather than complicity changes the entire response trajectory from restriction-and-exit toward limit-setting with consent, cooling-off mechanisms, gambling-block features and support-service referrals that preserve banking relationships while constraining harm.
Product-design responses embed harm-reduction directly into restriction tooling: voluntary gambling blocks with meaningful cooling-off periods preventing impulsive reversal, spending-limit frameworks customers set during lucid periods with strong authentication required for modification, and merchant-category controls enabling self-exclusion from high-risk transaction types without full relationship restriction. Operator collaboration with gambling firms through data-sharing gateways enables cross-institution harm detection where single-bank visibility captures only fragments of multi-operator behaviour. Staff training distinguishes moral judgement from safeguarding duty explicitly, since disapproval of addiction-driven behaviour leaks into restriction decisions that punish vulnerability while claiming risk management that evidence-based harm reduction would serve more honestly and more effectively.
Trafficking-victim account handling at scale
Human-trafficking operations use victim accounts for transit, collection and layering at volumes that transaction monitoring detects as criminal networks while victim identification lags structurally behind. Victim-indicator frameworks combine transaction direction analysis revealing external control, benefit-flow tracing showing value bypassing nominal holders, communication-pattern evidence with lawful acquisition, and demographic-vulnerability markers that together support safeguarding classification without requiring victim self-disclosure that coercion prevents. Classification confidence grades distinguish confirmed victims with disclosure or law-enforcement corroboration from probable victims with strong indicator assemblies warranting safeguarding responses, and possible victims needing enhanced monitoring with sensitive inquiry rather than immediate restrictive action that premature classification would impose unjustly.
Account-treatment protocols for probable and confirmed victims prioritise exploitation prevention with access preservation: transaction limits blocking exploitation-scale movements while permitting subsistence activity, controller-access removal through credential resets and device re-registration conducted safely, and safe-contact establishment ensuring bank communication reaches victims rather than monitored channels controllers surveil. Coordination with law enforcement follows victim-consent frameworks varying by jurisdiction and urgency, with non-governmental organisation referrals providing support infrastructure banks cannot deliver directly. Staff handling victim cases need trauma-informed training with supervision structures addressing secondary-trauma effects that sustained exposure produces, since safeguarding quality depends on workforce capacity the bank must actively sustain rather than assume.
Mental-capacity law interface for restriction decisions
Mental-capacity legislation in many jurisdictions establishes decision-making frameworks that restriction processes must integrate rather than operate parallel to, with principles presuming capacity, supporting decision-making before substituting judgement, and acting in best interests where capacity is lacking. Restriction teams need working knowledge of applicable capacity law sufficient to recognise when formal assessment is required, engaging specialist assessors for borderline determinations that front-line staff must not make alone regardless of operational pressure. Supported-decision-making measures — trusted-person involvement with consent safeguards, communication adaptations, extended timeframes — precede substituted decisions wherever the customer can participate meaningfully with assistance that restriction processes must offer proactively.
Attorney and deputy oversight under capacity frameworks adds verification layers where restriction decisions affect represented customers: authority validation confirming appointment scope covers the relevant decisions, conduct monitoring detecting attorney self-dealing through transaction-direction analysis, and independent customer contact attempted safely before adverse action where coercion indicators suggest the representative rather than the customer drives activity. Court-of-protection or equivalent interactions require legal-team involvement with defined escalation paths, since restriction decisions touching court-supervised arrangements face judicial scrutiny that standard governance never encounters. Records preserve capacity evidence with health-data protection standards while remaining available to future reviewers, balancing sensitivity against the continuity that repeated capacity re-assessment from scratch would waste destructively.
Age-related decline and capacity assessment
Ageing customer bases make cognitive decline a portfolio-scale restriction consideration rather than an edge case, as diminishing capacity affects comprehension of products, vulnerability to exploitation and reliability of instructions that restriction decisions must interpret carefully. Capacity assessment distinguishes normal ageing with preserved decision-making from decline impairing financial capability, using interaction evidence — comprehension failures on previously managed products, contradictory instructions within short periods, susceptibility to evident scams — rather than age thresholds alone that discriminate unlawfully while missing early-onset cases in younger customers. Assessment needs specialist input where available with occupational-therapy or medical perspectives informing borderline determinations that front-line staff should not make alone.
Powers of attorney and deputyship arrangements require verification depth matching their abuse potential: registration validation with issuing-authority confirmation, scope analysis distinguishing general authority from transaction-specific mandates, activation-condition verification where springing powers depend on capacity events requiring evidence, and attorney-conduct monitoring detecting self-dealing patterns where attorneys redirect customer funds with transaction-direction analysis. Restriction decisions involving attorneys must assess whether the attorney serves customer interests or exploits authority, with independent customer contact attempted safely before adverse action where coercion indicators exist. Records preserve capacity evidence with sensitivity-appropriate access controls, since capacity information is health-adjacent personal data demanding stronger protection than standard customer records while remaining available to future reviewers facing related decisions.
Advanced practice: portfolio analytics, re-risking and correspondent pressure
The base chapter explains customer-level decisions. This supplement moves up one level and asks whether the restriction regime is behaving sensibly across a portfolio. The objective is not to force every segment to have the same outcome. It is to identify where results reflect assessed risk and where they may instead reflect weak data, operational convenience, inconsistent judgement or a commercial decision labelled as financial-crime control.
Portfolio analytics need both risk and customer-impact measures
Restriction volumes alone tell very little. A rising exit count can mean the bank has identified previously uncontrolled exposure, changed risk appetite, lost a correspondent route, improved detection, introduced a stricter legal rule, or simply become more willing to close difficult customers. Management information therefore needs the reason behind the movement.
Useful measures include restrictions and exits by reason, product, geography and business line; age of temporary restrictions; review completion; complaint and upheld-complaint outcomes; release reasons; repeated restrictions on the same customer; re-entry attempts; operational exceptions; and alternative-product uptake where the bank offers limited or basic products. Trend analysis should link changes to known events such as policy revisions, sanctions developments, new monitoring scenarios, data remediation or business strategy changes.
Overturn rates require interpretation rather than targets copied from another institution. A high rate might indicate poor first-line quality or an effective independent review process. A low rate might indicate strong original decisions or a review function that rarely challenges them. Case sampling is therefore more informative than declaring an arbitrary "healthy" percentage.
Where demographic or vulnerability characteristics are analysed, the bank must first establish a lawful basis for collecting and using that data. Equality, privacy and employment-style sensitive-data rules vary by jurisdiction. A global dashboard should not assume that every legal entity can collect the same attributes simply because group governance wants comparable inclusion metrics.
Distinguish financial-crime risk from commercial viability
Some relationships are expensive to serve because they require enhanced review, specialist staff, additional correspondent due diligence or manual processing. Those costs are relevant to business strategy, but they should not be disguised as a legal AML requirement.
Risk-based pricing also needs careful governance. In some products and jurisdictions the institution may be able to price additional service complexity; in others, law, conduct expectations, contractual terms or financial-inclusion policy may constrain fees. Pricing is not itself an AML/CFT control and cannot replace required due diligence, monitoring or reporting. The bank should therefore separate three decisions: is the relationship legally permissible, can the risk be controlled, and is the resulting service commercially viable?
That separation improves customer communication and future review. If a segment is exited because the operating model is uneconomic, the bank can revisit the decision when technology or scale changes. If a segment is exited because the risk cannot be managed within appetite, re-entry requires a control change. If law prohibits the activity, commercial economics are irrelevant until the legal position changes.
Re-risking means rebuilding capability, not simply reopening a door
A bank that previously withdrew from a segment can later revisit the decision. The starting point should be an exit audit: what risk drove the withdrawal, what evidence supported it, which weaknesses belonged to customers and which belonged to the bank, and what would need to change before service could resume?
Re-entry capability can include specialist onboarding, better ownership data, segment-specific monitoring, enhanced payment transparency, agent-network visibility, additional correspondent arrangements and clearer restriction tooling. Pilot portfolios are useful where the institution wants bounded evidence before scaling. The pilot should define success and stop criteria in advance rather than allowing commercial momentum to redefine them later.
Governance should separate advocacy from approval. The business can present the opportunity and economics. Compliance challenges the risk analysis. Operations confirms capacity. Technology confirms enforceability. Legal maps jurisdiction-specific constraints. Internal audit or independent validation can provide assurance where the bank's governance model calls for it. No one function needs to own every decision, but accountability must be explicit.
Correspondent pressure should be decomposed
A correspondent can create real downstream pressure by requiring more transparency, rejecting certain payment patterns or withdrawing service. The respondent bank should identify whether the pressure comes from law, the correspondent's contract, its risk appetite or a strategic market exit. Those sources can lead to different responses.
If the issue is missing originator or beneficiary information, the respondent should improve payment transparency and data quality. If nested relationships are not understood, it may need stronger respondent due diligence and flow visibility. If the correspondent has made a commercial decision to leave a market regardless of the respondent's control quality, the problem becomes one of dependency and resilience as well as financial-crime risk.
The respondent should avoid automatically passing the pressure to every underlying customer. Instead, it should identify which customer or product changes are genuinely necessary for the correspondent route and which exposures can be supported through alternative controls or payment routes. Any downstream restrictions should retain their own evidence and governance rather than citing "correspondent requirement" without explaining the actual condition.
Board reporting should explain trade-offs, not only activity
Board-level reporting works best when it connects risk outcomes to customer consequences. A balanced pack can show restriction and exit trends, material legal or policy drivers, complaint themes, temporary-restriction ageing, alternative-product usage, major correspondent dependencies and the results of quality assurance. Significant changes should include short case examples that demonstrate how policy works in practice.
Boards also need clarity about what the figures cannot prove. A fall in exit volumes does not necessarily mean risk is lower. A rise in enhanced monitoring may reflect better proportionality or insufficient escalation. A low complaint rate may reflect good service or customers who do not know how to challenge a decision. Management interpretation and independent challenge are therefore part of the control.
Internal audit and quality assurance should test outcomes
File review should go beyond checking whether the correct form was completed. Samples can test whether the restriction ground matches the evidence, whether alternatives were considered where relevant, whether similar cases receive consistent treatment, whether temporary restrictions are reviewed on time and whether customer communication matches the legal and policy basis.
Appeal or complaint samples are particularly useful because they show where the original decision or its communication failed. Vulnerable-customer cases deserve targeted sampling because the same restriction can create very different harm depending on the customer's circumstances. Product-level samples can reveal whether a technical limitation is overblocking allowed activity.
Quality assurance should also review decisions not to restrict. A programme that samples only adverse decisions cannot tell whether staff are missing material risks. Proportionality requires evidence in both directions: the bank must detect genuine risk without defaulting to unnecessary exclusion.
Analytics and machine learning need model governance
Analytics can help identify unusual restriction patterns, likely complaint drivers, inconsistent decision-makers and clusters of long-running temporary controls. Machine-learning techniques may support text analysis or pattern detection, but they should not be treated as a shortcut around explainable governance.
If models are used to recommend restriction outcomes, the bank needs appropriate validation, performance monitoring, human decision rights and bias analysis. Historical restriction data can contain past policy choices and past exclusion patterns. Training a model on those outcomes without examining the labels can automate inconsistency at scale.
The safest use cases often begin with decision support rather than autonomous adverse action: flag cases for second review, identify concentrations requiring QA, or detect restriction parameters that are no longer aligned with policy. Any move toward automated restriction should be assessed under the institution's model-risk, conduct, privacy and operational-risk frameworks as applicable.
Regulatory and management reporting is jurisdiction-specific
There is no single global regulatory return for de-risking and financial inclusion. Particular jurisdictions, products or supervisory programmes may require data on account access, closures, complaints, basic accounts or other customer outcomes. The bank should maintain a jurisdictional inventory stating exactly what is required, by whom, at what frequency and under which definition.
Operational systems should preserve enough structured data to satisfy those obligations without forcing analysts to reconstruct reasons manually from free text. Where reporting definitions differ across jurisdictions, the data model can maintain common internal fields with local mappings rather than pretending one group definition is legally authoritative everywhere.
Narrative explanations should be equally disciplined. If a report says exits increased because of "higher risk," governance should be able to show what changed in the risk environment or control framework. If the true driver was withdrawal from a product, that should be stated accurately. Clear provenance is more defensible than trying to make every customer-access decision sound like an AML requirement.
Practice close: delivery checklists, scenarios and acceptance criteria
This supplement converts the chapter into requirements and tests that a delivery team can use. The aim is to prove that a restriction is targeted, technically enforceable, reviewable and consistent with the applicable legal and policy basis.
BA checklist before accepting a restriction design
A restriction requirement should answer five questions. What precise risk or legal condition triggers it? What customer, account, product, channel or transaction does it affect? Which system enforces it? Who can approve, override and release it? When must it be reviewed?
A statement such as "high-risk customers must be restricted" is not testable. A better requirement identifies the decision state and execution point: for example, customers placed in a defined enhanced-control state may retain domestic transfers but cannot add new international beneficiaries until specified evidence is accepted, with the decision reviewed after a defined period. The example is illustrative; the actual control must be justified by the risk and local framework.
Exit requirements should distinguish CDD failure, risk-appetite exit, product withdrawal, confirmed misuse and legally driven outcomes because each can have different approvals, notices, communications and settlement rules. Sanctions or court-ordered restrictions should not be forced into a generic exit workflow where the law may require assets to remain frozen rather than returned.
Temporary restrictions need expiry or review logic. A temporary state with no owner or ageing control becomes permanent through neglect. Requirements should define the review queue, service level, escalation for overdue cases, permitted extensions, evidence required for release and customer communication where permitted.
Acceptance criteria should test outcomes
Good acceptance criteria prove both protection and precision. They confirm that prohibited or restricted activity is stopped, that activity intended to remain available still works, that the restriction reaches every relevant channel, and that the audit trail shows who made the decision and why.
For a transaction limit, test the boundary amount, repeated transactions, multiple channels, linked accounts where relevant, effective time, expiry and manual override. For a channel restriction, confirm that the blocked channel cannot be used while authorised alternatives remain available. For a product restriction, verify that related product features do not recreate the prohibited capability indirectly.
Review-process criteria should use internally defined service levels and quality measures rather than a universal target for overturn rates. The useful evidence is whether decisions are reviewed on time, whether similar fact patterns receive consistent treatment, whether reviewers can genuinely vary or release controls, and whether repeated root causes lead to policy or training improvements.
Scenario 1: evidence weakens but the customer cooperates
A long-standing small-business customer has a material increase in turnover and cannot immediately evidence the source of several large credits. The customer responds promptly, provides partial documentation and explains that a new distribution contract caused the change.
The bank should not treat cooperation as proof of legitimacy, but neither should it treat incomplete evidence as automatic proof of laundering. A testable decision process might request the missing contract and invoices, increase monitoring during the review period, and consider a targeted control only if the unexplained activity creates a risk the current controls cannot manage. If mandatory CDD cannot ultimately be satisfied, the consequence follows applicable law and policy.
The testing point is whether the system and case process can support a bounded evidence-gathering state instead of forcing analysts into a false choice between "fully clear" and "exit now."
Scenario 2: a high-profile customer with uncorroborated allegations
Adverse media alleges corruption involving a customer, but the reporting is single-source and lacks supporting facts. A higher-risk profile may justify enhanced review, but the allegation should not be converted automatically into a confirmed financial-crime finding.
The case should test source quality, relevance, identity match, transaction behaviour, PEP status where applicable and other corroborating evidence. Possible controls depend on what the review finds. The QA question is whether the decision record distinguishes allegation, verified fact and bank judgement clearly enough that a later reviewer can see how much weight each carried.
Scenario 3: repeated transactions designed to avoid a control threshold
A remittance customer repeatedly makes transactions just below a threshold that is relevant to the bank's monitoring or, where applicable, a jurisdiction-specific reporting rule. The pattern is accompanied by evasive explanations and changes in counterparty behaviour.
The bank should analyse the pattern as a whole rather than treating each payment as independently acceptable because it is below one threshold. Monitoring, information requests and escalation should reflect the applicable local framework. Testing should avoid hard-coding one country's reporting threshold into a global scenario library; the scenario should call the jurisdictional rule or parameter used by the legal entity processing the activity.
Scenario 4: possible coercion or exploitation
An elderly customer begins making large transfers from a new device while a third party dominates calls with the bank. A blunt response could freeze ordinary access and leave the customer dependent on the suspected controller.
The test case should activate vulnerability and safeguarding procedures: safe contact, specialist review, assessment of who controls the device and payment instructions, and targeted controls designed to prevent further loss while preserving legitimate access where possible. Local safeguarding and information-sharing law determines any referral obligations or permissions.
Complaint and review analytics
Complaints should be coded by root cause, not just resolved individually. Useful categories include evidence disagreement, unclear communication, delay, failure to apply an agreed adjustment, vulnerability handling, product availability and inconsistent decision-making. Trends can then be compared with restriction type and business line.
The bank should be cautious about treating complaint volume as a direct measure of fairness. Some customers complain frequently; others never complain even when badly affected. A stronger control combines complaint analysis with sampled file review, customer research where appropriate, restriction ageing and evidence from second-look decisions.
Where an ombudsman, court or regulator makes a relevant decision, the institution should assess whether the reasoning affects only the individual case or reveals a broader process defect. External decisions are jurisdiction-specific and should not be converted into a universal global rule without legal analysis.
Testing customer journeys
Journey testing should include standard, digitally excluded and vulnerable users because a restriction can be operationally correct while the route to resolve it is unusable. Test whether customers can understand what action they may take, submit permitted evidence, receive acknowledgement, use accessible communication channels and continue allowed services.
Mystery shopping can be useful where local rules and ethics permit it, but it is not a regulatory requirement everywhere. If used, scenarios should be designed independently from the teams being tested, and findings should be linked to measurable remediation rather than treated as anecdotal observations.
Accessibility testing should include screen readers, alternative formats, timeout behaviour, assisted channels and authentication alternatives. A restriction process that requires a digital step some customers cannot complete may unintentionally turn a targeted control into full exclusion.
Training and competency
Restriction staff need more than AML typology knowledge. They need to understand the difference between law, bank risk appetite and commercial strategy; how to write evidence-based reasons; when vulnerability changes the handling; what can be communicated to the customer; and when legal or specialist escalation is required.
Competency is better tested through scenarios than through completion records alone. Reviewers can be given the same fact pattern and their outcomes compared for consistency. Seeded cases can test whether staff identify a legal-action path separately from ordinary restrictions and whether they release controls when the defined evidence arrives.
Training should be refreshed when policy, law, product features or recurring QA findings change. A fixed annual course may still be part of the programme, but it should not be the only mechanism for correcting emerging decision-quality problems.
End-to-end test matrix
A complete test pack should cover normal service, each restriction rung, overlapping restrictions, effective dating, expiry, review, release, manual override, failed propagation to downstream systems, channel outages and customer communication. It should also test the negative case: activity that looks unusual but is legitimate should not be blocked merely because the test environment is designed around adverse outcomes.
For cross-border customers, tests should confirm which legal entity owns the decision and whether another entity should receive the same restriction, a related alert, or no action because local law and facts differ. For correspondent-driven requirements, the test record should identify the actual contractual or risk condition instead of labelling it generically as "regulatory."
The final acceptance question is simple: can the bank reconstruct the decision later and demonstrate that the implemented control matched the intended scope? If not, the restriction design is not complete even if the front-end status appears correct.
Masterclass: rebuilding service after a wholesale MSB exit
This is a composite teaching case, not a description of one real bank or a regulatory precedent. All figures are illustrative. It shows how a bank can revisit an earlier segment-wide exit without assuming that re-entry is required, commercially desirable or acceptable in every jurisdiction.
The original exit
A bank had previously withdrawn from money-service-business customers after serious control concerns elsewhere in its financial-crime programme. The response was broader than the original problem: new MSB onboarding stopped, existing relationships were wound down and no re-entry criteria were defined. Several years later, the bank could explain why it had been worried, but it could not show a customer-level or well-defined cohort analysis demonstrating that every exited MSB presented the same risk.
A later portfolio review separated four questions that the original decision had collapsed together. What were the actual ML/TF risks of the segment? Which weaknesses belonged to the bank's own control environment rather than the customers? What service model could manage those risks now? And would re-entering the segment still fit strategy, correspondent dependencies and risk appetite?
That distinction matters. A bank should not reverse an old exit merely because the decision now looks conservative. Re-risking is defensible only if the institution understands why it exited, can demonstrate that relevant capability has changed, and is willing to stop or narrow the programme if the new controls do not work.
Rebuild capability before contacting customers
The bank begins with a segment risk assessment. It distinguishes licensed remitters, agent-heavy networks, cash-intensive models, nested arrangements and digital-only providers instead of treating "MSB" as one risk state. It maps customer transparency, ownership, licensing, agent governance, corridors, expected transaction patterns and payment data quality. The exercise produces an explicit view of which subsegments the bank is equipped to serve and which remain outside appetite.
Control design then follows the risks. KYC procedures are expanded to capture agent-network information and relevant licensing evidence. Monitoring is calibrated around the actual transaction patterns of the intended customers rather than applying generic high-risk thresholds. Payment-transparency requirements are defined for originator, beneficiary and corridor data. Escalation rules state when an individual agent issue can be contained and when evidence indicates a systemic customer-level problem.
Operations capacity is treated as a control, not an afterthought. A programme that needs specialist review cannot scale safely if every case lands in a general KYC queue with no MSB expertise. Staffing, quality assurance, ageing limits and management information therefore form part of the re-entry gate.
Correspondent dependencies are tested explicitly
If returned MSB flows rely on correspondent banks, correspondent expectations have to be understood before customer volumes return. The bank should distinguish contractual requirements from legal prohibitions and from the correspondent's own risk appetite. Where the correspondent requires additional respondent information or transparency, those requirements are mapped into the product and operating model rather than left as relationship-manager knowledge.
The bank may share its control framework, provide requested due-diligence evidence and agree additional reporting where commercially and legally appropriate. That does not make the correspondent an approver of the bank's AML programme, and it does not turn a correspondent preference into global law. The purpose is dependency management: the proposed customer proposition is not viable if the payment route that supports it can disappear as soon as volumes arrive.
Diversification is also considered. A segment whose entire payment capability depends on one correspondent remains vulnerable even if the financial-crime controls are sound. Treasury, payments, product and compliance therefore examine resilience alongside AML/CFT design.
Use a bounded pilot
Rather than reopen the segment at full scale, the bank starts with a small number of customers whose ownership, licensing, agent model and expected activity are well understood. Pilot criteria are measurable: data completeness, alert quality, review ageing, restriction frequency, unexplained activity, correspondent exceptions, complaints and operational effort. The bank defines pause and exit triggers before commercial momentum makes them politically difficult to use.
The most important pilot evidence is not simply that no major incident occurs. It is whether the control model can distinguish legitimate remittance activity from activity that requires investigation without generating unmanageable false positives or pushing analysts toward blanket restriction. Samples test whether customer files explain the activity, whether payment data is sufficient, whether agent exceptions are visible and whether restrictions are applied consistently.
Where one customer cannot provide required transparency, the pilot does not fail automatically. The issue is handled according to its facts. The bank may restrict an agent, request more evidence, narrow a corridor or end that customer relationship if the risk cannot be managed. The programme fails when those individual outcomes reveal that the underlying control design cannot manage the segment at the intended scale.
Governance separates advocacy from approval
The business team can own the commercial case, but it should not be the only function deciding whether the control framework is adequate. Financial-crime compliance challenges the risk analysis and proposed mitigants. Operations tests whether the procedures are executable. Technology confirms that restrictions and monitoring can be implemented across relevant systems. Legal maps jurisdiction-specific obligations. Independent validation or internal audit can be used where the institution's governance model requires additional assurance.
The bank also documents what has not changed. If a subsegment remains outside appetite, that boundary is explicit. If a corridor depends on evidence the bank cannot currently obtain, the programme does not assume future data will solve it. If the monitoring platform cannot distinguish agent-level behaviour, the bank does not promise agent-level control until the technical capability exists.
This prevents a common re-risking failure: treating an old blanket exit as proof that every restriction was wrong and then overcorrecting into uncontrolled expansion.
Supervisory engagement is jurisdiction and circumstance specific
A bank should not assume that a supervisor must approve re-entry into a customer segment unless applicable law, an enforcement commitment, licence condition or specific supervisory requirement says so. In some circumstances, regulatory engagement may be appropriate or required, particularly where the institution is operating under remediation commitments or the change is material to an existing supervisory concern. In other circumstances, re-entry remains an internal governance decision subject to ordinary supervisory review.
Where engagement occurs, the useful approach is factual. The bank can explain the historic issue, the root cause, what changed in the control framework, the scope of the pilot, the metrics used to judge it and how the bank will respond if controls underperform. Any supervisory feedback is recorded and mapped to actions where relevant, without describing routine dialogue as regulatory endorsement of the commercial strategy.
That distinction protects both accuracy and governance. A regulator's awareness of a programme is not the same as approval. Likewise, the absence of a specific objection does not transfer responsibility for the risk decision away from the bank.
Scaling only after the operating model proves itself
If the pilot performs as designed, expansion follows control capacity rather than marketing demand. Growth gates consider reviewer workload, data quality, alert ageing, quality-assurance findings, corridor stability and the number of restrictions that require manual handling. A programme that doubles customer count without expanding specialist capacity can recreate the conditions that caused the original withdrawal.
Adjacent segments are assessed separately. Success with conventional licensed remitters does not automatically justify onboarding crypto-adjacent transmitters, offshore gaming operators or other businesses with different risk characteristics. Each material change requires its own risk analysis and capability check.
Post-implementation review compares expected and actual outcomes. Commercial returns are measured after the additional control cost, not before it. Customer access is measured alongside risk outcomes. Complaints, exits and restrictions are analysed for signs that the bank has recreated de-risking inside the reopened segment through overly broad operational decisions.
The central lesson is simple: reversing a wholesale exit is not about becoming more tolerant of financial crime risk. It is about replacing category-level avoidance with evidence, capability and bounded decision-making. If the bank cannot build those capabilities, remaining outside the segment may still be the responsible choice.
Knowledge check and glossary
Use these questions to test whether the restriction logic is genuinely risk-based rather than merely procedural.
Why should a bank consider targeted controls before broad restriction? Because a targeted control can preserve legitimate activity while addressing the specific risk. That is not a universal legal rule requiring the least restrictive option in every case. If law requires a specific outcome, or the risk cannot be controlled within appetite, broader restriction or exit may be appropriate.
What distinguishes different exit grounds? CDD failure, risk outside appetite, product or market withdrawal, confirmed misuse and legally driven action can require different evidence, approvals, communications and operational handling. Calling all of them "compliance exit" destroys useful distinctions.
Why is wholesale de-risking different from a risk-based portfolio decision? FATF has criticised wholesale cutting off of customer classes without serious consideration of their actual risk and available mitigation. A bank may still make legitimate strategic or risk-appetite decisions about products and markets, but those decisions should be described accurately and governed on their real basis.
Does FATF's financial-inclusion guidance create a global right to a bank account? No. FATF provides global standards and non-binding guidance implemented through national frameworks. Account-access rights, refusal grounds and complaint mechanisms come from applicable domestic or regional law. The EU Payment Accounts Directive is an example of a jurisdiction-specific access framework.
What makes a second-look review useful? It allows new evidence, changed facts or quality findings to alter the original outcome. The reviewer should have a defined mandate and should distinguish re-assessment from simply repeating the first decision. There is no universal target for how many restrictions should be overturned.
How should vulnerability change the handling? It can change communication, safeguarding, contact methods, review timing and the interpretation of suspicious-looking activity. It does not remove the need to control risk. A coerced mule, scam victim or cognitively impaired customer may need controls that block exploitation while preserving safe access.
What proves a restriction works technically? The intended activity is constrained across all relevant channels, activity that should remain available still works, the decision is auditable, downstream systems receive the change, review and expiry logic execute correctly, and release restores the permitted service without leaving stale blocks.
What should management information show? Not only restriction volumes. It should explain reasons, ageing, review outcomes, complaint themes, release causes, product and segment concentrations, re-entry patterns and operational exceptions. Where demographic analysis is used, collection and processing must be lawful for the relevant entity.
How should correspondent pressure be handled? Determine whether the requirement comes from law, contract, the correspondent's risk appetite or commercial strategy. Address the actual concern and avoid automatically passing broad restrictions downstream without customer-specific reasoning.
What makes re-risking credible? A clear explanation of the original exit, updated segment risk assessment, rebuilt capability, bounded testing or pilot where appropriate, independent challenge and predefined conditions for pause, escalation or withdrawal. Re-entry is not automatically required simply because a past exit was broad.
How do cross-border differences affect restrictions? Group standards can provide a common decision framework, but legal obligations, product rights, confidentiality, complaint routes and reporting duties vary. The legal entity applying the restriction needs its own mapped basis.
Glossary for delivery teams
Restriction ladder: a graduated set of possible controls such as enhanced review, limits, channel restrictions, product restrictions and managed exit. Legally prescribed actions such as asset freezing should be handled through the applicable legal path rather than forced into the ladder.
De-risking: in this chapter, broad refusal or termination based mainly on customer category or perceived risk rather than sufficiently specific risk assessment and mitigation. The term should not be used to obscure an ordinary commercial market withdrawal.
Risk-based approach: identifying, assessing and understanding ML/TF risk and applying measures proportionate to that risk within the applicable legal framework. FATF strengthened the emphasis on proportionality in Recommendation 1 in 2025.
Financial inclusion: access to and meaningful use of regulated financial services by people and businesses that may otherwise be unserved or underserved. Inclusion objectives do not override mandatory AML/CFT, sanctions or other legal requirements.
Second look: a bank-initiated re-assessment prompted by new evidence, elapsed time, quality findings or another defined trigger, even where the customer has not made a formal appeal.
Appeal or complaint route: a process through which a customer can challenge or complain about a decision where available under law, policy, contract or ombudsman arrangements. Rights and timeframes are jurisdiction-specific.
Vulnerability marker: information indicating that a customer may need adapted communication, safeguarding or specialist review because capability, coercion, disability, distress or another circumstance affects the normal process.
Wind-down: controlled termination of a relationship, including handling of pending activity, customer balances, connected products, records and communications. It must not override a legal freeze or other rule that restricts movement of assets.
Re-risking: disciplined reconsideration of a segment or customer population previously restricted or exited, based on updated risk understanding and demonstrably improved control capability.
Restriction object: the structured data representing a restriction, including scope, reason, legal or policy basis, affected channels or products, effective dates, owner, approvals, review triggers and release conditions.
References and further reading
Global risk-based approach and financial inclusion
- Financial Action Task Force (FATF), Guidance on Financial Inclusion and Anti-Money Laundering and Terrorist Financing Measures, June 2025: https://www.fatf-gafi.org/en/publications/Financialinclusionandnpoissues/guidance-financial-inclusion-aml-tf-measures.html
- Financial Action Task Force (FATF), The FATF Recommendations: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
- Financial Action Task Force (FATF), FATF clarifies risk-based approach: case-by-case, not wholesale de-risking: https://www.fatf-gafi.org/en/publications/Fatfgeneral/Rba-and-de-risking.html
European access and de-risking framework
- European Banking Authority (EBA), Guidelines on policies and controls for the effective management of ML/TF risks when providing access to financial services: https://eba.europa.eu/legacy/regulation-and-policy/regulatory-activities/anti-money-laundering-and-countering-financing-6
- European Banking Authority (EBA), EBA issues Guidelines to challenge unwarranted de-risking and safeguard access to financial services to vulnerable customers, 31 March 2023: https://www.eba.europa.eu/publications-and-media/press-releases/eba-issues-guidelines-challenge-unwarranted-de-risking-and
- European Union, Directive 2014/92/EU on payment accounts, including Article 16 on access to payment accounts with basic features: https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX%3A32014L0092
UK supervisory and customer-access material
- Financial Conduct Authority (FCA), UK payment accounts access and closures: update, 4 September 2024: https://www.fca.org.uk/publications/corporate-documents/uk-payment-accounts-access-and-closures-update
- Financial Conduct Authority (FCA), Financial Crime Guide: https://handbook.fca.org.uk/handbook/fcg
Bank control framework
- Basel Committee on Banking Supervision, Sound management of risks related to money laundering and financing of terrorism: https://www.bis.org/bcbs/publ/d505.htm
These sources have different legal status and geographic scope. FATF provides global standards and non-binding guidance implemented through national frameworks. EBA material and the Payment Accounts Directive are European. FCA material is UK-specific. The chapter therefore uses them to explain decision architecture and proportionality without presenting any one jurisdiction's account-access, notice, appeal or reporting rules as universal law.