How to classify higher-risk customers under the new EU AML framework
Under the new EU anti-money-laundering framework, a risk rating must be explained, evidenced and defended — and higher risk should trigger escalation and enhanced due diligence, not automatic refusal.
Under the new EU anti-money-laundering framework, customer risk classification is becoming more than an internal label in a file. For corporate service providers, lawyers, accountants, tax advisers and other professional gatekeepers, the key question is not only whether a client is "low", "medium" or "high" risk — it is whether the rating can be explained, evidenced and defended.
A higher-risk customer is not automatically a prohibited customer. But higher risk should trigger a more careful process: escalation, enhanced due diligence, senior approval where required, stronger monitoring and clearer file notes.
Risk assessment should usually consider several layers. Customer risk covers ownership, control, business activity, reputation, politically exposed persons, sanctions exposure and adverse information. Geographic risk covers countries of incorporation, residence, operation, banking, suppliers, customers and source of funds. Product and structure risk covers nominee arrangements, trust or similar structures, and asset holding.
EU-facing banks and gatekeepers will increasingly ask clients not just for documents but for a defensible risk narrative. Well-prepared files with clear commercial purpose move faster through onboarding.