Every client lifecycle diagram drawn in financial services has the same shape: onboarding, risk assessment, monitoring, periodic review, and then a box at the end labelled offboarding. The first four boxes have owners, budgets, software and metrics. The last one, in most institutions, has an email thread.
This is odd, because the exit phase is where several of the sharpest risks in the relationship converge: the decision to terminate may itself be a regulatory act, it may need to be taken without telling the client why, it generates documents that must outlive the relationship by years, and it is the point at which a commercial relationship most often turns adversarial.
This article sets out why offboarding goes undesigned, what a designed process actually contains, and the specific traps that catch institutions treating it as an administrative formality.
1. Why offboarding gets neglected
It produces no revenue. Onboarding opens a relationship; offboarding closes one. Investment follows the first. This is the honest reason, and it explains most of the gap.
It is rare per relationship manager and frequent in aggregate. Any individual banker closes few relationships a year, so nobody experiences offboarding as a volume problem. Across an institution the numbers are substantial — but they never surface as one person's queue, which is exactly how a process escapes design.
It is unpleasant. Exits are often triggered by something uncomfortable: a client who stopped responding to a remediation request, a screening hit nobody can clear, a risk rating that moved the wrong way. Processes attached to unpleasant conversations get deferred, and deferral is itself the main failure mode.
It looks like an account-closing task. Which it partly is. But the operational closure — moving assets, settling positions, terminating mandates — is the visible half. The compliance half, which determines what happens if a prosecutor asks about this client in five years, is invisible and therefore unowned.
2. The three kinds of exit, which are not the same thing
Treating all terminations as one process is the root error, because the three types have different drivers, different constraints and different risks.
Client-initiated. The client leaves. The institution's job is operational closure plus an orderly record: why they left, what was transferred and to whom, and what the file looked like at closure. Low risk, provided the record is complete.
Commercially-initiated. The institution exits a relationship that no longer fits — size, service model, strategy. The risk here is contractual and reputational rather than regulatory: notice periods, fair treatment, and the practical question of whether the client can actually move the assets somewhere.
Compliance-initiated. The institution exits because of AML, sanctions, risk or conduct concerns. This is a different exercise, and the difference matters: the reasoning may be confidential, the timing may be constrained by reporting obligations, and what is said to the client may be legally limited. Treating this as a commercial exit with a different reason code is where institutions create real problems for themselves.
The first discipline of an offboarding process is therefore to classify the exit before executing it, because the classification determines everything downstream.
3. Where the regulatory risk actually sits
Exit does not end your obligations. Record-keeping duties survive the relationship, typically for ten years in Switzerland. Reporting obligations that arose before closure are not extinguished by closure. An institution that closes a relationship and purges the file has not reduced its exposure — it has removed its own ability to answer questions about it.
The decision to exit can itself be a reportable event. Where termination is driven by suspicion, the decision and any reporting obligation are linked, and the sequence matters. Exiting first and considering the reporting question afterwards is the wrong order, and in some circumstances the exit itself is what a reviewer will scrutinise.
Telling the client why may not be permitted. Where a suspicion has been reported, communicating the reason — or communicating in a way that allows it to be inferred — may constitute tipping off. The practical implication is that a compliance-initiated exit cannot use the standard commercial termination letter, and the person drafting it needs to know which category the exit falls into. This is precisely the kind of thing that goes wrong when offboarding has no designed process: a well-intentioned relationship manager explains too much.
Where the money goes is part of the risk. Closing an account you consider high-risk by remitting the balance to an institution with weaker controls does not make the risk disappear; it relocates it, and the transfer leaves a record of your institution having effected it. Destination due diligence is part of exit due diligence.
"We exited them" is not a complete answer. When a regulator or correspondent asks about a historic client, the answer that works is the documented one: when the concern arose, what was assessed, what was decided, by whom, on what basis, and what was reported. An institution that can produce that has handled the matter. One that can only produce a closure date has not.
