On 30 September 2026, the Australian Transaction Reports and Analysis Center (AUSTRAC) cautioned financial institutions against indiscriminately closing or restricting accounts for entire groups of customers deemed “high risk”. This act is referred to as de-risking.
The regulator is urging companies to conduct individual assessments, apply proportionate controls, and adopt a Risk-Based Approach (RBA) to Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF). The message is clear: greater risk does not necessarily mean restricting customers.
AUSTRAC Draws a Line on Blanket De-Risking
AUSTRAC’s message is especially pertinent to sectors often affected by debanking, such as remittance providers, Virtual Asset Service Providers (VASPs), fintech companies, not-for-profit organizations, and businesses that rely heavily on cash.
Debanking, also known as de-risking, happens when financial institutions refuse or limit their services because it regards a customer or a group of customers as “too risky”. A higher-risk rating does not automatically justify suspending or terminating user access or a business relationship.
Instead, the regulator expects more proportionate controls. In particular, businesses should evaluate other risk signals. These include the customer’s jurisdiction, the nature of the transaction, and delivery channels before reaching a decision.
Why Indiscriminate Debanking Can Increase Financial Crime Risk
At first glance, removing high-risk customers might seem to lower AML risk exposure. However, widespread debanking can have the reverse effect. For example, excluding legitimate businesses can increase activity towards less regulated services and channels. Additionally, it can make customers less transparent about the nature of their activities if they believe they might lose access to banking services.
We discourage indiscriminate or widespread account closures across entire sectors.
As such, having full visibility over transactions and suspicious activity will be harder to detect and monitor. Furthermore, debanking can worsen financial inclusion. A registered business may be denied access without justification of a money-laundering threat. This can occur simply because it operates in a high-risk sector.
Most importantly, sector-wide exclusion can weaken a risk-based AML framework. Effective AML compliance requires knowing when to apply step-up verification and enhanced due diligence, and when a customer’s risk is genuinely too high to manage.
Regulators Are Converging Around the Risk-Based Approach
AUSTRAC’s warning is not unique. In fact, leading regulators have repeatedly advocated the risk-based approach, bringing the focus away from blanket de-risking. Across EMEA, APAC, and AMER, supervisors are echoing the same message: higher risk should trigger investigation, not automatic exclusion.
Businesses must ensure customers have access to the financial services they need to fully participate in society and are not denied this access.
The European Banking Authority (EBA) notes that rejecting groups of users without considering individual risk profiles is a telling indication of ineffective AML and CTF risk management. It also emphasizes the negative implications of unsubstantiated de-risking for vulnerable customers and organizations.
Enforcing overly stringent CDD processes prevents many legitimate businesses and individuals from opening or maintaining accounts.
Hong Kong mirrors a similar approach. The Hong Kong Monetary Authority (HKMA) stresses the importance of risk differentiation. It notes that effective Customer Due Diligence (CDD) measures must ensure customers and businesses are treated fairly, with transparent and reasonable documentation of compliance decisions.
De-risking threatens financial integrity and the risk-based approach by creating opacity and eliminating the ability to manage ML/TF risks.
In South Africa, the Financial Intelligence Center (FIC) states that wholesale de-risking to avoid risk goes against the RBA. A proper risk assessment does not require complete risk avoidance. It enables addressing ML and TF risks instead.
The FATF Standards do not envisage de-risking, or cutting-off entire classes of customers.
FATF, the body that sets global standards for fighting ML, TF, and financial crime, has repeatedly warned about de-risking. The regulator emphasizes the need to identify, assess, and understand financial crime risk before making decisions. It also states that jurisdictions under increased monitoring should not invite indiscriminate Enhanced Due Diligence (EDD).
Implement Effective Risk-Based Approach
While it is crucial to avoid wholesale de-risking, it is equally important to identify, prevent, and mitigate ML and TF risk effectively. As such, the answer is not weaker compliance. Rather, the approach demands precise compliance. It distinguishes entities and users needing scrutiny from risks that cannot be managed entirely.
For an effective, risk-based approach, businesses must identify risk accurately. They should apply proportionate controls and explain why each decision was made.
- Ongoing risk assessment: Customer risk can evolve over time. Ongoing monitoring enables businesses to detect changes in a customer’s risk rating in real time. This includes listings across sanctions, adverse media, and Politically Exposed Persons (PEPs) data sources. Continuous monitoring supports AML compliance by providing instant risk alerts, speeding case investigation and regulatory reporting when required.
- Build strong risk intelligence: To build a clearer picture of a customer or business’s risk profile, gather robust due diligence and risk intelligence from the outset. Companies should perform Know Your Customer (KYC) checks, including identity verification, liveness detection, and document checks to establish who a customer is. Additionally, fraud intelligence tools, including device and email verification, can surface hidden risk indicators and strengthen compliance decision-making.
- Enhanced due diligence workflows: Businesses must map higher-risk relationships to proportionate EDD checks, rather than flat-out rejection. Depending on the risk identified, this can include deeper beneficial ownership checks and source-of-funds verification. KYC smart forms can give businesses a comprehensive view of a business or customer by capturing intended purpose, expected activity, and supporting documents.


Find out more AML news in ComplyCube’s Trust Edition newsletter. We explore the latest in developments across identity verification and AML globally.



