When a review concludes that a relationship carries risk the firm is not prepared to hold, there are three available answers. Only one of them is irreversible, and it is the one most easily justified in an internal meeting.
That asymmetry is why exit gets chosen more often than the assessment supports. It is defensible, it is quick, and it removes the problem from the firm's own book without requiring anyone to hold a position.
Why the outcomes sit side by side
They are mutually exclusive. Exactly one is taken, which is why the diagram opens out rather than running left to right. A row would imply a sequence, and the wrong reading here is that restriction is a step on the way to exit.
Retaining with enhanced controls is available more often than it is used. Restriction, limiting products or geographies rather than the whole relationship, is proportionate where the risk is specific.
Category de-risking is the failure mode
Withdrawing from an entire category rather than assessing customers individually has attracted sustained regulatory criticism, because it pushes legitimate customers out of the regulated system, which is the opposite of the policy objective.
The defensible position is customer-specific, recorded, even where the answer happens to be the same for several customers in the same segment. What is being defended is the basis, not the outcome.
Closing the account does not close the file
This is the part most workflows omit. A decision to exit does not discharge a reporting obligation. Tipping-off restrictions still apply while the closure is being carried out, which constrains what the customer can be told about why.
Retention obligations then run for years past the final balance, and the file has to remain retrievable for the whole period. A closure process that archives records into somewhere they cannot be produced from is not a completed exit.
An exit done badly is a different problem
Notice periods, contractual terms and the customer's ability to move their funds all sit inside the exit path. Rushing them for compliance reasons produces conduct issues that are harder to defend than the risk that prompted the decision.
For what reopens the file in the first place, see trigger-event review. For the review that precedes this decision, see enhanced due diligence. For the standing model around it, see perpetual KYC.
