De-risking is not compliance. It is risk avoidance dressed as governance.
The Hidden Liability in De-Risking
Regulators have spent a decade documenting what happens when institutions close accounts instead of assessing them. The record doesn't call that compliance — it calls it avoidance, and it comes with a cost.
A Term Regulators Coined to Describe a Mistake
"De-risking" sounds like something a compliance program does on purpose. It isn't a control — it's the term regulators use for a pattern they kept seeing and didn't like. The Financial Action Task Force (FATF) defines it as "the phenomenon of financial institutions terminating or restricting business relationships with clients or categories of clients to avoid, rather than manage, risk in line with the FATF's risk-based approach." The risk-based approach asks an institution to assess each customer. De-risking skips the assessment and closes the account instead.
The FATF has said plainly this is not what its standards call for. Its guidance on correspondent banking states that de-risking "is not in line with the FATF Recommendations, and is a serious concern to the international community." The Recommendations call for terminating a relationship case by case, only where risk cannot be mitigated — not clearing out an entire category of customer because reviewing them individually costs more.
What Governance Actually Requires
Governance means an institution can show its work: who was assessed, on what basis, and why a decision followed. Wholesale account closures by category — every money-service business, every customer from a particular country, every nonprofit with an overseas program — replace that judgment with a shortcut. The FATF has said this kind of blanket approach ignores customers' "level of risk or risk mitigation measures... within a particular sector," which is precisely the analysis a risk-based program is supposed to perform. The drivers behind it rarely have much to do with a customer's actual risk profile: FATF's own review points to "profitability, prudential requirements, anxiety after the global financial crisis, heightened regulatory expectations, or reputational risk" as the recurring causes — business decisions, not risk assessments.
The Liability Hiding in Plain Sight
The uncomfortable part for compliance leaders is that de-risking doesn't make the underlying risk disappear — it relocates it, usually somewhere with less visibility. The FATF has warned that closing accounts "has the potential to force entities and persons into less regulated or unregulated channels," which cuts against the transparency that regulated, traceable banking channels exist to provide.
The pattern shows up clearly in the data. World Bank survey work has repeatedly identified money transfer operators as the segment hit hardest: over 69 percent of banking authorities surveyed said "money transfer operators and other remittance companies are most impacted" by de-risking, ahead of small and medium domestic banks and exporters. IMF discussion of the issue has traced downstream effects too — a reduction in correspondent banking relationships in the Bahamas affecting remittances into Haiti, where remittances make up roughly 23 percent of GDP. When an account closes, the money doesn't stop moving; it moves through a channel with fewer controls and less reporting, working against what a risk-based AML program exists to achieve.
Closing the account doesn't necessarily buy an institution the safety it's chasing, either. FinCEN and the federal banking regulators jointly reminded institutions in 2022 that they are "expected to apply a risk-based approach to Customer Due Diligence that includes the development of risk profiles, specific to each customer," not a categorical exclusion. That statement followed complaints from cash-intensive businesses and independent ATM operators cut off simply for belonging to a disfavored category. A September 2026 joint statement from FinCEN and the federal banking agencies addressed a related transparency question, clarifying that banks may discuss the reasons behind fraud-related account actions with customers, while noting this "does not say that a bank must keep an account open simply because the customer asks for an explanation." What regulators are asking for is documentation: a stated reason for the closure, tied to that customer, rather than a blanket policy applied without review. The FFIEC BSA/AML Examination Manual sets the same expectation, calling for "an appropriate level of ongoing due diligence that is commensurate with the customer's risk profile" — doing more where risk is elevated, rather than exiting the relationship outright.
The distinction that matters: a documented decision to exit a specific, high-risk relationship after due diligence reflects the risk-based approach working as intended. A standing policy of closing every account in a broad category, without individual review, is the exact pattern FATF, FinCEN, and the World Bank have spent the past decade warning against.
The Reputational Side of the Ledger
The reputational cost is documented as well. Reputational risk is both a driver of de-risking and, increasingly, a consequence of doing it badly: U.S. lawmakers have written directly to major banks about categorical account closures, and the U.S. Treasury has stated that de-risking "undermines several key U.S. government policy objectives by driving financial activity out of the regulated financial system, hampering remittances, [and] preventing low- and middle-income segments of the population... from efficiently accessing the financial system." That's a regulator describing a bank's own risk-avoidance behavior as a policy problem — not the cover institutions are hoping a closure will buy them.
The Practical Distinction
| What It Looks Like | Where It Sits |
|---|---|
| Individual due diligence leads to exiting one high-risk relationship, documented and defensible | Compliance — the risk-based approach working as intended |
| Enhanced monitoring or additional information requests for a higher-risk customer segment | Compliance — proportionate, case-by-case risk management |
| Closing every account in a category (MSBs, nonprofits, certain countries) without individual review | De-risking — avoidance mislabeled as governance |
| Treating account closure as a substitute for building the capability to understand a customer | De-risking — and a liability regulators have named explicitly |
Understanding a customer is harder than closing their account. It requires a documented risk assessment and a defensible rationale, applied consistently. But that work is the actual job a risk-based AML program is meant to do — and it's the only version of this decision that regulators, examiners, and the record so far have been willing to call compliance.
Want your team to be able to tell the difference — and defend it in an exam?
Track 1: AI Foundations in Financial Crime Compliance covers the risk-based approach, documentation standards, and how technology fits into individualized customer risk assessment.
Explore Track 1 →
Registered at District Court Munich HRB 302338
VAT ID DE454846466 | nanoacademy@ai-thea.com