De-risking is when a financial institution exits or refuses whole categories of customers to avoid AML risk rather than managing that risk case by case. It looks like prudent caution, but regulators warn it can cut legitimate people and businesses out of the financial system and push activity into less visible channels.
What is de-risking?
The risk-based approach that underpins modern AML expects a bank to assess and manage each customer's risk, applying more scrutiny where it is warranted. De-risking is the blunt alternative: instead of managing the risk of a category, the institution simply declines or offboards the whole category. Rather than doing enhanced due diligence on a money service business or a customer in a high-risk region, it stops serving that type of customer entirely.
The motive is usually a cost-benefit calculation. Certain segments, correspondent respondents in some regions, money service businesses, some non-profits, crypto firms, cash-intensive businesses, carry higher compliance cost and regulatory scrutiny relative to the revenue they generate. Faced with the threat of penalties for getting it wrong, an institution decides the safest move is to avoid the segment altogether.
For an AML team, de-risking is a double-edged term. It can be a legitimate risk-appetite decision, but done wholesale and without genuine case-by-case assessment, it is widely criticized by regulators as financial exclusion that can drive activity into channels with less oversight, which harms the wider goals of the AML regime.
De-risking versus risk-based management
The difference is whether risk is managed or simply avoided:
What changes | Wholesale de-risking | Risk-based management |
Unit of decision | Entire category | Individual customer |
Assessment done | Category treated as too risky | Risk assessed and priced |
Legitimate customers | Excluded with the rest | Retained with controls |
Effect on visibility | Pushes flows elsewhere | Keeps flows monitored |
Regulator view | Criticized as exclusion | Expected practice |
Who is affected?
Who | How they are affected |
The institution | Lowers its compliance cost and exposure, but forgoes revenue and draws regulator scrutiny for exclusion. |
The excluded customers | Whole segments, MSBs, some non-profits, crypto firms, lose access even when individually legitimate. |
Regulators | Warn that blanket exits undermine financial inclusion and reduce visibility into risky flows. |
The wider system | Sees activity migrate to less-regulated channels where it is harder to monitor. |
What it looks like in practice
A bank reviews its portfolio and finds that money service businesses generate a disproportionate share of alerts, examiner questions, and compliance workload relative to the fees they bring in. Rather than build the enhanced monitoring those accounts would need, leadership decides to close all money service business accounts within ninety days.
Among the accounts closed are several well-run remittance providers serving migrant communities. With mainstream banking cut off, some of that remittance activity shifts to informal value transfer channels that no regulator can see. The bank has reduced its own risk on paper, but the money did not stop moving; it simply moved somewhere with less oversight.
Why it matters to operators
De-risking is where risk appetite meets public policy. From inside one institution, exiting a troublesome segment is a rational way to cap exposure. Seen across the system, wholesale exits can strip legitimate businesses and communities of banking access and push flows into informal channels, which is the opposite of what AML controls are meant to achieve. Regulators have repeatedly signaled that they expect genuine case-by-case assessment, not blanket withdrawal.
The operator's job is to distinguish a defensible risk-appetite decision from lazy category avoidance. That means documenting the actual risk assessment behind an exit, considering whether enhanced controls could retain good customers, and recognizing that offboarding an entire segment is itself a decision regulators may question. Done thoughtfully, it is risk management; done reflexively, it is exclusion that regulators increasingly push back on.
What to watch in the data
- Blanket exits. Whole customer categories closed on the same rationale without individual risk assessment on file.
- Alert-to-revenue framing. Offboarding decisions driven mainly by compliance cost versus fee income rather than actual risk.
- Flow migration. Signs that offboarded activity has moved to informal or less-regulated channels rather than stopping.
- Documentation gaps. Exits with no recorded assessment of whether enhanced controls could have retained legitimate customers.
- Concentration in vulnerable segments. Exclusions falling heavily on remittance providers, non-profits, or specific communities.
Quick questions
Is de-risking against the rules?
Not inherently. An institution can decide a segment is outside its risk appetite. But regulators criticize wholesale de-risking that skips genuine case-by-case assessment, because it excludes legitimate customers and pushes activity into less visible channels.
How is it different from the risk-based approach?
The risk-based approach manages risk at the level of the individual customer, applying more or less scrutiny as warranted. De-risking avoids the assessment entirely by exiting a whole category, which is the opposite of tailoring controls to actual risk.
Which segments get de-risked most?
Commonly money service businesses, correspondent respondents in higher-risk regions, some non-profits, crypto firms, and cash-intensive businesses, because they carry higher compliance cost and scrutiny relative to their revenue.
Why do regulators worry about it?
Because blanket exits can deny legitimate people and businesses access to banking and drive their transactions into informal channels that no one monitors. That reduces overall visibility, which undermines the very purpose of AML controls.
Can de-risking ever be the right call?
Yes, when it reflects a documented, genuine assessment that a segment truly exceeds the institution's risk appetite and cannot be managed with reasonable controls. The problem is reflexive, undocumented category avoidance, not a considered risk-appetite decision.
De-riskingと併せて知っておきたい用語

2026年 不正・AMLレポート
予測は不要です。このレポートは、不正・AMLチームが実際に直面していることと、その対応方法を分解して解説します。
