Blog Login
AML

What Is AML Risk Scoring? How Fintechs Rate Customer Risk

A

Anzar Dewani

2 days ago

AML risk scoring is how fintechs assign a risk level to each customer to determine how much due diligence is required. This guide explains how risk scoring works, what factors drive it, and how to build a model that holds up to regulatory scrutiny.

What Is AML Risk Scoring? How Fintechs Rate Customer Risk

Not all customers carry the same risk. A salaried employee using a payment app to split dinner bills looks very different from a politically connected foreign national running a cash-intensive business in a high-risk jurisdiction.

AML risk scoring is how fintechs systematically assess and categorize those differences — assigning each customer a risk level that determines how much due diligence is required, how closely their activity is monitored, and how frequently their profile is reviewed.

What Is AML Risk Scoring?

AML risk scoring (also called customer risk rating) is a formal process of evaluating a customer's inherent risk of being involved in money laundering, terrorist financing, or other financial crime — and assigning them a risk tier (typically Low, Medium, or High).

The risk score drives how your AML compliance program treats that customer. Low-risk customers receive standard due diligence. High-risk customers require Enhanced Due Diligence and closer ongoing monitoring.

Why Is Risk Scoring Required?

Risk-based approaches to AML are not just best practice — they're a regulatory expectation. The FFIEC BSA/AML Examination Manual, FinCEN's CDD rule, and FATF guidance all require financial institutions to assess and understand the risk of each customer relationship.

Treating every customer identically — applying the same level of scrutiny to a retired schoolteacher and a foreign currency exchange dealer — is not only inefficient, it's a compliance failure. Regulators expect you to concentrate your resources where the risk is highest.

What Factors Drive AML Risk Scores?

A customer risk score is built from multiple risk factors, typically organized into categories:

Customer Type / Profile Risk

Geographic Risk

  • What country is the customer a citizen or resident of?
  • Does the customer operate in or send funds to high-risk jurisdictions (FATF grey list, sanctioned countries)?
  • Are transactions routed through high-risk correspondent banking corridors?

Product / Channel Risk

  • What products is the customer using?
  • Are they using cash-intensive products, international wires, or cryptocurrency?
  • Was the account opened remotely without in-person verification?

Transaction Risk

  • What is the expected transaction volume and frequency?
  • Does the customer's stated purpose of account match their transaction patterns?
  • Are transactions of a complex or unusual nature?

How Risk Scores Are Calculated

Risk scoring models typically assign point values or weights to each risk factor, then aggregate them into a total score that falls into a risk tier. For example:

Risk Factor

Low Risk

Medium Risk

High Risk

Customer Type

Individual, salaried

Self-employed, SMB

PEP, MSB, cash-intensive business

Geography

Domestic, low-risk country

Mixed jurisdictions

Sanctioned or FATF grey-listed country

Product

Basic deposit, P2P payment

International wire, crypto

High-volume international, cash-equivalent

Transaction Volume

Low, consistent with stated purpose

Moderate, some variation

High, inconsistent with profile

What Happens After Risk Scoring?

The risk tier assigned at onboarding determines:

  • Low risk: Standard CDD, normal transaction monitoring thresholds, periodic review (typically annually)
  • Medium risk: Standard CDD with enhanced monitoring, more frequent review
  • High riskEnhanced Due Diligence (EDD), intensive monitoring, senior management sign-off in some cases

Ongoing Risk Reassessment

Risk scoring is not a one-time event at onboarding. Customer risk should be reassessed:

  • Periodically (at least annually for higher-risk customers)
  • When there's a material change in the customer's profile or transactions
  • When a transaction monitoring alert is generated that changes the risk picture
  • When the customer submits a SAR-related activity

Frequently Asked Questions

Is there a standard risk scoring model I can use?

There is no single mandated model. The FFIEC BSA/AML Examination Manual and FinCEN's CDD guidance describe what factors to consider, but each institution builds its own model. The model should be documented, tested, and calibrated to your specific customer base and product set.

Can I use a third-party vendor for risk scoring?

Yes. Many fintechs use vendors like Alloy, Sardine, or Unit21 that include risk scoring as part of their KYC/AML platform. You remain responsible for validating that the model meets your regulatory requirements.

How do I handle a customer whose risk level changes?

Update the customer's risk rating, document the reason for the change, and adjust the level of due diligence and monitoring accordingly. If the customer moves from low to high risk, initiate an EDD review.

 

This article is for educational purposes only and does not constitute legal or compliance advice. Regulations vary by jurisdiction and change frequently. Consult a qualified compliance professional or legal counsel for guidance specific to your business.

 

Talk to the ComplyOne team to get started.

Share this article:

Related Articles