Use case

Account Exit and De-risking

Deciding to end a relationship is one of three available answers, and the least reversible. What the alternatives are, and why the obligations do not stop when the account closes.

Last updated

Group of colleagues in a boardroom meeting around a long table

The decision

Exit is one of three answers, not the default one.

  1. OutcomeUnacceptable risk identifiedA confirmed match, a failed enhanced review, or a pattern the firm is not prepared to hold. The trigger is the same whichever answer follows.
  2. OutcomeRetain with enhanced controlsKeep the relationship under tighter monitoring, lower thresholds and shorter review intervals. Available more often than it is used.
  3. OutcomeRestrictLimit products, geographies or transaction types rather than the whole relationship. Proportionate where the risk is specific rather than general.
  4. Least reversibleExitEnd the relationship, with notice, records and reporting obligations that outlive the account itself.
1 least reversible3 outcome
These outcomes are mutually exclusive, which is why they sit side by side rather than in a row. Exit is the least reversible and the one most likely to be chosen for the wrong reason, because it is the easiest to justify internally.

When a review concludes that a relationship carries risk the firm is not prepared to hold, there are three available answers. Only one of them is irreversible, and it is the one most easily justified in an internal meeting.

That asymmetry is why exit gets chosen more often than the assessment supports. It is defensible, it is quick, and it removes the problem from the firm's own book without requiring anyone to hold a position.

Why the outcomes sit side by side

They are mutually exclusive. Exactly one is taken, which is why the diagram opens out rather than running left to right. A row would imply a sequence, and the wrong reading here is that restriction is a step on the way to exit.

Retaining with enhanced controls is available more often than it is used. Restriction, limiting products or geographies rather than the whole relationship, is proportionate where the risk is specific.

Category de-risking is the failure mode

Withdrawing from an entire category rather than assessing customers individually has attracted sustained regulatory criticism, because it pushes legitimate customers out of the regulated system, which is the opposite of the policy objective.

The defensible position is customer-specific, recorded, even where the answer happens to be the same for several customers in the same segment. What is being defended is the basis, not the outcome.

Closing the account does not close the file

This is the part most workflows omit. A decision to exit does not discharge a reporting obligation. Tipping-off restrictions still apply while the closure is being carried out, which constrains what the customer can be told about why.

Retention obligations then run for years past the final balance, and the file has to remain retrievable for the whole period. A closure process that archives records into somewhere they cannot be produced from is not a completed exit.

An exit done badly is a different problem

Notice periods, contractual terms and the customer's ability to move their funds all sit inside the exit path. Rushing them for compliance reasons produces conduct issues that are harder to defend than the risk that prompted the decision.

For what reopens the file in the first place, see trigger-event review. For the review that precedes this decision, see enhanced due diligence. For the standing model around it, see perpetual KYC.

What we do.

A decision with three answers

Enhanced controls, restriction and exit are all available. Recording which were considered is what distinguishes a risk decision from a reflex.

Proportionality on the record

Wholesale de-risking of a category rather than an assessment of a customer attracts its own criticism. The defence is a documented, customer-specific basis.

Orderly exit

Notice periods, contractual terms and the customer's ability to move funds all sit inside the exit path, and getting them wrong creates a different problem from the one being solved.

Reporting that survives the relationship

A decision to exit does not discharge a reporting obligation, and tipping-off restrictions still apply while the account is being closed.

Records after closure

Retention obligations run for years past the final balance. The file has to remain retrievable long after the customer has gone.

Highlights.

  • Three outcomes considered, with the choice and its basis recorded
  • Customer-specific assessment rather than category-level de-risking
  • Reporting and tipping-off restrictions that continue through closure
  • Retention and retrievability long after the account has closed

Questions

Common questions about account exit and de-risking.

Is exit the correct response to a confirmed match?
Sometimes, but it is one of three answers rather than the automatic one. Enhanced controls and restriction are both available, and both are proportionate where the risk is specific rather than general. What matters is that the alternatives were considered and the reason for the choice is recorded.
What is wrong with de-risking a whole category?
It substitutes a category judgement for a customer assessment, and it has attracted sustained criticism from regulators for pushing legitimate customers out of the regulated system entirely. The defensible position is a customer-specific basis, documented, even where the outcome happens to be the same for several customers.
Do obligations end when the account closes?
No, and this is the most commonly missed part. Reporting obligations are not discharged by exiting, tipping-off restrictions still apply during closure, and record retention runs for years afterwards. The relationship ends; the file does not.
What does an orderly exit actually involve?
Notice consistent with the contract, a route for the customer to move funds, and a closure sequence that does not itself create a reportable event handled badly. Exits rushed for compliance reasons create conduct problems that are harder to defend than the risk that prompted them.
How does this differ from trigger-event review?
Trigger-event review is what reopens the file. This is what happens when reopening it produces an answer the firm is not prepared to live with.

Talk to the MemberCheck team.

Get in touch and we'll walk you through how MemberCheck can help.