Wecan
Back to blog
Insights8 min read· October 3, 2026

Client Offboarding: The Lifecycle Phase Nobody Designs

Onboarding gets the budget, the project team and the software. Offboarding gets an email thread. Why the exit phase is where regulatory and legal risk concentrates — and what a designed process looks like.

by Wecan

Every client lifecycle diagram drawn in financial services has the same shape: onboarding, risk assessment, monitoring, periodic review, and then a box at the end labelled offboarding. The first four boxes have owners, budgets, software and metrics. The last one, in most institutions, has an email thread.

This is odd, because the exit phase is where several of the sharpest risks in the relationship converge: the decision to terminate may itself be a regulatory act, it may need to be taken without telling the client why, it generates documents that must outlive the relationship by years, and it is the point at which a commercial relationship most often turns adversarial.

This article sets out why offboarding goes undesigned, what a designed process actually contains, and the specific traps that catch institutions treating it as an administrative formality.

1. Why offboarding gets neglected

It produces no revenue. Onboarding opens a relationship; offboarding closes one. Investment follows the first. This is the honest reason, and it explains most of the gap.

It is rare per relationship manager and frequent in aggregate. Any individual banker closes few relationships a year, so nobody experiences offboarding as a volume problem. Across an institution the numbers are substantial — but they never surface as one person's queue, which is exactly how a process escapes design.

It is unpleasant. Exits are often triggered by something uncomfortable: a client who stopped responding to a remediation request, a screening hit nobody can clear, a risk rating that moved the wrong way. Processes attached to unpleasant conversations get deferred, and deferral is itself the main failure mode.

It looks like an account-closing task. Which it partly is. But the operational closure — moving assets, settling positions, terminating mandates — is the visible half. The compliance half, which determines what happens if a prosecutor asks about this client in five years, is invisible and therefore unowned.

2. The three kinds of exit, which are not the same thing

Treating all terminations as one process is the root error, because the three types have different drivers, different constraints and different risks.

Client-initiated. The client leaves. The institution's job is operational closure plus an orderly record: why they left, what was transferred and to whom, and what the file looked like at closure. Low risk, provided the record is complete.

Commercially-initiated. The institution exits a relationship that no longer fits — size, service model, strategy. The risk here is contractual and reputational rather than regulatory: notice periods, fair treatment, and the practical question of whether the client can actually move the assets somewhere.

Compliance-initiated. The institution exits because of AML, sanctions, risk or conduct concerns. This is a different exercise, and the difference matters: the reasoning may be confidential, the timing may be constrained by reporting obligations, and what is said to the client may be legally limited. Treating this as a commercial exit with a different reason code is where institutions create real problems for themselves.

The first discipline of an offboarding process is therefore to classify the exit before executing it, because the classification determines everything downstream.

3. Where the regulatory risk actually sits

Exit does not end your obligations. Record-keeping duties survive the relationship, typically for ten years in Switzerland. Reporting obligations that arose before closure are not extinguished by closure. An institution that closes a relationship and purges the file has not reduced its exposure — it has removed its own ability to answer questions about it.

The decision to exit can itself be a reportable event. Where termination is driven by suspicion, the decision and any reporting obligation are linked, and the sequence matters. Exiting first and considering the reporting question afterwards is the wrong order, and in some circumstances the exit itself is what a reviewer will scrutinise.

Telling the client why may not be permitted. Where a suspicion has been reported, communicating the reason — or communicating in a way that allows it to be inferred — may constitute tipping off. The practical implication is that a compliance-initiated exit cannot use the standard commercial termination letter, and the person drafting it needs to know which category the exit falls into. This is precisely the kind of thing that goes wrong when offboarding has no designed process: a well-intentioned relationship manager explains too much.

Where the money goes is part of the risk. Closing an account you consider high-risk by remitting the balance to an institution with weaker controls does not make the risk disappear; it relocates it, and the transfer leaves a record of your institution having effected it. Destination due diligence is part of exit due diligence.

"We exited them" is not a complete answer. When a regulator or correspondent asks about a historic client, the answer that works is the documented one: when the concern arose, what was assessed, what was decided, by whom, on what basis, and what was reported. An institution that can produce that has handled the matter. One that can only produce a closure date has not.

4. What a designed offboarding process contains

Six components. None of them is technically difficult; the difficulty is that nobody owns them.

A classification step. Client-initiated, commercial, or compliance-driven — decided and recorded before anything else happens, because it governs the communication, the approvals and the retention.

An approval path matched to the classification. A commercial exit needs a business decision. A compliance-driven exit needs compliance sign-off, and in sensitive cases escalation. The two should not share a workflow.

A communication template per classification, reviewed by legal. The point is to remove drafting discretion at exactly the moment when discretion is dangerous.

A final-state record. A snapshot of the client file at closure: risk rating, beneficial ownership as last known, open alerts and their disposition, documents held. This is what makes a file answerable years later, and it costs nothing if the record is structured — and a great deal if it has to be reassembled from four systems.

A retention and access policy. The file must remain retrievable for the full retention period, with access controlled. Note the tension with data protection: a closed client has deletion rights that are constrained by your retention obligations, and the ability to explain which data is retained under which legal basis is itself a compliance capability.

A re-entry rule. Exited clients come back — directly, or as a beneficial owner inside another structure. If the exit reasoning is not attached to the person and the entity in a way that surfaces on re-screening, you will onboard tomorrow the client you exited last year. This is the single most commonly missed component, and it is only solvable where beneficial ownership is held as structured data rather than as documents in a closed folder.

5. The traps

The slow exit. The decision is taken in March and executed in September, because nobody owns the follow-through. The institution carries the risk it decided to remove, for six months, with a documented decision showing it knew. This is worse than not having decided.

The silent exit. The account is closed operationally but the client record is never updated, so screening keeps alerting on a client who is no longer there, and periodic review keeps scheduling them. Noise accumulates, analysts learn to dismiss alerts on closed relationships, and the habit of dismissal spreads.

The over-explained exit. A relationship manager, wanting to preserve goodwill, explains more than they should in a compliance-driven termination. This is a training problem, and the fix is a template rather than more training.

The purge. Someone closes the relationship and, in good faith, deletes the data under a data-minimisation policy, ahead of the retention period. Data protection and AML retention pull in opposite directions here, and the resolution has to be decided in policy, not by whoever handles the closure.

The orphaned structure. The operating company is exited; the holding company, the trust or the related entity is not, because they sit in different portfolios. The risk that justified the exit is still in the book.

6. Offboarding as evidence of lifecycle maturity

Offboarding is diagnostic. An institution that can execute a clean, documented, correctly classified exit has, by implication, a single client record, a current risk rating, structured beneficial ownership and a working audit trail — because you cannot produce a clean final-state record without them.

Conversely, an institution that struggles with exits is usually not struggling with exits. It is discovering, at the least convenient moment, that its client data was never unified. The exit is just where that becomes visible, in the same way that remediation is where fragmentation becomes expensive.

This is why offboarding belongs in the client lifecycle rather than beside it. The same record that was opened at onboarding, scored, monitored and periodically reviewed is the record that closes — with its history intact, its reasoning attached, and its retention clock running.

Wecan's CLM platform treats closure as a state of the client record rather than its deletion. The exit classification, approvals, final-state snapshot and retention status live on the same record as everything that preceded them, and the re-entry rule works because the beneficial ownership graph does not disappear when an account does.

Most institutions will never be asked about most of the clients they exit. The ones they are asked about are, by definition, the difficult ones — which is precisely the population an undesigned process handles worst.


This article is provided for information purposes and does not constitute legal or regulatory advice.

See Wecan in action. In 30 minutes.

A live walkthrough on real KYC scenarios — no slides, no commitment. Just see if it fits your context.