AML risk scoring is how fintechs assign a risk level to each customer to determine how much due diligence is required. This guide explains how risk scoring works, what factors drive it, and how to build a model that holds up to regulatory scrutiny.
What Is AML Risk Scoring? How Fintechs Rate Customer Risk
Not all customers carry the same risk. A salaried employee using a payment app to split dinner bills looks very different from a politically connected foreign national running a cash-intensive business in a high-risk jurisdiction.
AML risk scoring is how fintechs systematically assess and categorize those differences — assigning each customer a risk level that determines how much due diligence is required, how closely their activity is monitored, and how frequently their profile is reviewed.
What Is AML Risk Scoring?
AML risk scoring (also called customer risk rating) is a formal process of evaluating a customer's inherent risk of being involved in money laundering, terrorist financing, or other financial crime — and assigning them a risk tier (typically Low, Medium, or High).
The risk score drives how your AML compliance program treats that customer. Low-risk customers receive standard due diligence. High-risk customers require Enhanced Due Diligence and closer ongoing monitoring.
Why Is Risk Scoring Required?
Risk-based approaches to AML are not just best practice — they're a regulatory expectation. The FFIEC BSA/AML Examination Manual, FinCEN's CDD rule, and FATF guidance all require financial institutions to assess and understand the risk of each customer relationship.
Treating every customer identically — applying the same level of scrutiny to a retired schoolteacher and a foreign currency exchange dealer — is not only inefficient, it's a compliance failure. Regulators expect you to concentrate your resources where the risk is highest.
What Factors Drive AML Risk Scores?
A customer risk score is built from multiple risk factors, typically organized into categories:
Customer Type / Profile Risk
- Is the customer an individual, a business, or a trust?
- What is the customer's occupation or industry?
- Is the customer a Politically Exposed Person (PEP)?
- Is the customer a money services business (MSB) itself?
- Is the customer new, or do they have an established relationship history?
Geographic Risk
- What country is the customer a citizen or resident of?
- Does the customer operate in or send funds to high-risk jurisdictions (FATF grey list, sanctioned countries)?
- Are transactions routed through high-risk correspondent banking corridors?
Product / Channel Risk
- What products is the customer using?
- Are they using cash-intensive products, international wires, or cryptocurrency?
- Was the account opened remotely without in-person verification?
Transaction Risk
- What is the expected transaction volume and frequency?
- Does the customer's stated purpose of account match their transaction patterns?
- Are transactions of a complex or unusual nature?
How Risk Scores Are Calculated
Risk scoring models typically assign point values or weights to each risk factor, then aggregate them into a total score that falls into a risk tier. For example:
What Happens After Risk Scoring?
The risk tier assigned at onboarding determines:
- Low risk: Standard CDD, normal transaction monitoring thresholds, periodic review (typically annually)
- Medium risk: Standard CDD with enhanced monitoring, more frequent review
- High risk: Enhanced Due Diligence (EDD), intensive monitoring, senior management sign-off in some cases
Ongoing Risk Reassessment
Risk scoring is not a one-time event at onboarding. Customer risk should be reassessed:
- Periodically (at least annually for higher-risk customers)
- When there's a material change in the customer's profile or transactions
- When a transaction monitoring alert is generated that changes the risk picture
- When the customer submits a SAR-related activity
Frequently Asked Questions
Is there a standard risk scoring model I can use?
There is no single mandated model. The FFIEC BSA/AML Examination Manual and FinCEN's CDD guidance describe what factors to consider, but each institution builds its own model. The model should be documented, tested, and calibrated to your specific customer base and product set.
Can I use a third-party vendor for risk scoring?
Yes. Many fintechs use vendors like Alloy, Sardine, or Unit21 that include risk scoring as part of their KYC/AML platform. You remain responsible for validating that the model meets your regulatory requirements.
How do I handle a customer whose risk level changes?
Update the customer's risk rating, document the reason for the change, and adjust the level of due diligence and monitoring accordingly. If the customer moves from low to high risk, initiate an EDD review.
This article is for educational purposes only and does not constitute legal or compliance advice. Regulations vary by jurisdiction and change frequently. Consult a qualified compliance professional or legal counsel for guidance specific to your business.