The ability to identify and manage geographical risk has become a cornerstone of effective Anti-Money Laundering (AML) and financial crime compliance.
Regulators, including the FATF, the European Commission, and national authorities, expect financial institutions to adopt a risk-based approach that takes into account not only customer and product risk, but also the jurisdictions in which business is conducted.
Many compliance professionals grapple with the nuances of geographical risk – what it means, how it differs from “geographical locations risk,” and how it should be scored in a practical, defensible way.
By breaking down this topic, my key aim in this blog article is to provide compliance professionals with both strategic insights and practical guidance to strengthen their institution’s approach to geographical risk and align with global best practices.
Let’s start from the very beginning.
What is Geographical Risk and Why It Matters?
Geographical risk is one of the core factors that help compliance teams to assess when identifying and managing financial crime risk. It matters because where money comes from and goes to can be just as important as the geography of the person who is moving the funds, therefore the company needs to be able to assign a risk rating to any country in the world.
If you check the AML law requirements almost anywhere in the world, you will find the requirements which require for the Financial Institutions and Designated Non-Financial Businesses and Professions (DNFBP) to address financial crime risk from the following angles:
- Customer Risk
- Geographical Risk
- Products & Services Risk
- Delivery Channels risk
Like many other elements that are used today, these risk factors were introduced by the Financial Action Task Force (FATF) Recommendations. In 2003, FATF had extended its requirements requiring considering risk factors during the Customer Due Diligence (CDD) and enhanced due diligence (EDD) measures. However, the risk-based approach was still limited at that time and applied in certain contexts. The key improvements occurred in the 2012 revision of the 40 Recommendations where Recommendation 1: “Assessing Risks and Applying a Risk-Based Approach” was formally clarified risk factors related to the areas of customer risk, country/geographic risk, product/services risk which was also transposed to the EU’s 4th AML Directive which was adopted in 2015.
Difference Between the Geographical Risk and Geographical Locations Risk
When reading the texts from the FATF / EU AML Directives / related guidance, you can find terms “geographical risk”, “country risk”, “jurisdiction risk” etc. are used. The terms “geographical risk” and “geographical location risk” often appear in AML/CTF contexts, and while they sound similar, there is a subtle difference in how regulators and compliance frameworks use them:
- Geographical Risk – addresses the broad concept and refers to the general risk exposure arising from a country or region. It reflects the macro-level characteristics of that geography (e.g., countries included in the FATF high-risk or non-compliant jurisdictions or countries under sanctions or embargoes). For example, doing business with a bank based in a sanctioned country poses geographical risk because of the country’s overall risk profile.
- Geographical Location Risk – addresses more granular concept and refers to the risk based on the specific location of a customer, transaction, branch, or business activity, not just the overall country. It can consider sub-national variations or cross-border contexts, like a customer located in a free-trade zone with a limited oversight or a branch in a border region known for human or goods smuggling routes. Another example could be a customer incorporated in a low-risk EU country but operating in a high-risk conflict zone increases its geographical location risk.
This cheat-sheet below can help you to determine the key differences between these values:
| Element | Geographical Risk (macro) | Geographical Location Risk |
|---|---|---|
| Focus | Relates to countries / regions (third countries, jurisdictions), their AML/CFT effectiveness, corruption, sanctions etc | Relates to specific locations where customers reside, are domiciled, where transactions are initiated / executed; includes sub-national issues, cross-border links. Implicitly covered under “jurisdictions where customers are based”, “places of business”, “relevant personal links” etc. |
| Regulatory wording | “Countries or geographic areas” (FATF Recommendation 10); Regulatory wording “Countries or geographic areas” (FATF Recommendation 10); “Geographical risk factors” (EU AMLD) list country-level risks. | Relates “jurisdictions in which the customer … beneficial owner is based”, “jurisdictions that are the customer’s … main places of business”, “jurisdictions to which the customer … has relevant personal links.” |
| Granularity | Country or large area. Helps to decide if jurisdiction is higher risk or not. | City, region, or place of residence/business, cross-border operations, remittances from/to specific countries etc. Also links with customer location or transaction origin. |
| Purpose in Risk assessment | To determine if an entire jurisdiction poses higher risk (thus requiring enhanced due diligence, etc.). | To understand how that jurisdiction risk materialises for a specific customer or transaction, and whether the customer’s location / operations implicate those higher risk jurisdictions or exposures. |
Sources That Influence Geographical Risk Scoring
Compliance teams usually build the geographical risk tool internally (the tool might be named differently in every organization) by connecting various external sources (e.g., FATF, Transparency International, EU/OFAC sanctions lists) to specific risk, however it is important to make sure that it is built in a way which also allows to take into account intelligence from within the company (e.g., Sanctions or Fraud risk team). This tool also plays an important role in the Customer Risk Assessment area where the geographical locations need to be taken into account when the Customer’s AML risk rating is determined.
The geographical risk scoring tool usually considers the following publicly available resources, but it is important to note that risk scoring can be created for any financial crime risk (e.g., Drug Trafficking, Human Trafficking etc.):
| Risk Area | Explanation | Resource |
|---|---|---|
| Money Laundering | Jurisdictions with weak AML/CFT controls | FATF’s High-Risk Jurisdictions subject to a Call for Action ("blacklist") and the Jurisdictions under Increased Monitoring (i.e. "grey list") EU’s High-risk third countries for Money Laundering and Terrorism Financing Basel AML Index |
| Terrorist Financing | Countries linked to terrorist organizations or financing | Vision of Humanity’s Global Terrorism Index |
| Sanctions | Jurisdictions subject to international or national sanctions | EU Sanctions Map / Consolidated List of Financial Sanctions / OFAC Sanctions Lists (U.S.) UN Security Council Sanctions Lists |
| Corruption | Countries with systemic corruption, state capture, or political instability | Transparency International – Corruption Perceptions Index (CPI) |
| Tax Evasion | Offshore tax havens, jurisdictions with banking secrecy | Local list of countries considered high risk for tax evasion EU’s list of non-cooperative jurisdictions for tax purposes The Financial Secrecy Index by Tax Justice Network |
Disclaimer: it is important to note that every regulator might have different expectations what factors the geographical risk scoring needs to include and how the final geographical risk scoring methodology should work (which we will also address in the next section).
Challenges in Geographical Risk Scoring
Building a geographical risk scoring tool and methodology sounds straightforward, but in practice, compliance professionals run into a lot of challenges, for example:
Data-related Challenges:
- Limited access to quality data on smaller or developing countries.
- Some data is outdated (e.g., some resources are updated annually or bi-annually).
- Some indices (e.g., Basel AML Index) combine multiple indicators already, so there is a risk of double counting the same elements.
- Data integration failures can lead to inconsistent application of risk scores.
- Conflicting information between sources (e.g., FATF grey list vs Basel AML Index).

Global map of money laundering risks in 2024 based on Basel AML Index. Maximum risk is 10 (red colour). Some of the countries that are not in the FATF’s grey or blacklist (e.g., China or Chad) have higher risk ratings than some of the countries that were included more than a year ago (e.g., Nigeria). Source: Basel Institute of Governance
Methodology-related Challenges:
- Deciding how many risks are scored (e.g., do we stop with the 5 risk areas as mentioned above or do we score all 22 predicate offences that are mentioned in the EU’s 6th AML Directive?)
- Is the methodology aligned with the company’s Risk Appetite?
- Deciding how weights and scores are assigned (e.g., do all risks or sources have the same weights?)
- Over or Under weighting one factor can skew results (e.g., Sanctions risk is rated as High risk but the final risk level is Medium, which might not be in line with the regulator’s expectations).
- Lack of regulatory guidance on exact weights (when there is no guidance, the weights can be assigned subjectively but they might not be within the regulator’s expectations).
- Does the methodology clearly explain in what cases the risk ratings can be overridden?
- When the risk score should be increased based on internal intelligence (e.g., SAR trends, transaction patterns)?
- Is it easy to understand how the final scores are derived?
- Methodologies can be too complex/hard to explain or audit, or vice-versa – overly simple and not risk-sensitive enough.
- Too many countries are rated as High risk, thus creating conflicts with businesses expansion strategies.
Dynamic Nature of Risk:
- FATF grey and black lists are updated multiple times in a year, therefore the tool needs to be updated every time.
- Geographical risks shift over time due to political instability, wars, conflicts, or emerging terrorist groups, therefore the risk can increase risk faster than resources or models are updated.
- Risk is not always country-level and some regions within a country are much higher risk (e.g., border zones, free trade zones).
![]()
Active Global Conflicts Worldwide as of September 2025. Source: Global Conflict Tracker (owned by the Council of Foreign Relations)
Best Practices for Developing Your Own Geographical Risk Tool
A strong geographical risk scoring tool should be regulator-aligned, data-driven, transparent, dynamic, and integrated into the institution’s wider Financial Crime Compliance framework. If you want to develop your own geographical risk scoring, the following list can be used in order to ensure that this tool is built effectively, but also don’t forget to use other available trusted documents in this process (for example, the Wolfsberg Group’s publication of its updated Country Risk Frequently Asked Questions (FAQs) 2024).
-
- Start with Regulatory Alignment – start by analysing the requirements of the country(-ies) where the organization holds licenses and map methodology to local regulator expectations. Every risk factor should have a clear regulatory or business rationale.
- Use Multiple Credible Sources – rely on a blend of external sources (like the ones that are mentioned above) to avoid bias and cross-validate data to reduce over-reliance on a single list.
- Define Clear Scoring Methodology – use a weighted scoring model with transparent logic and document rationale for weights so it’s defensible to regulators. Weight internal data carefully, but don’t ignore it — it reflects the institution’s actual exposure. Include quantitative (numeric) data as well as qualitative (analytical and research-based) inputs.
- Keep It Simple – keep the scoring model simple enough to explain, but granular enough to capture risk differences.
- Automate Updates (if possible) – automate ingestion of regular updates or schedule periodic recalculations (e.g., monthly/quarterly) to ensure scores stay current. Also, don’t forget to maintain version control — keep a record of historical risk scores and methodology changes.
- Incorporate the Scoring Across Different Programs – link geographic scores directly into Customer Risk Ratings and transaction monitoring scenarios. Also, make sure it is consistent with the enterprise-wide risk assessment (EWRA), as well as other business lines and Operations teams.
- Perform Back-Testing & Validation – test scoring outcomes against actual operational volumes. Adjust weights if the model consistently over- or under-rates risk and
- Documentation – don’t forget to keep a methodology document (e.g., policy or procedure) explaining factors, weights, and data sources. This will come handy during the next audit and regulatory reviews.
- Training & Communication – ensure business units understand the implications of geographic risk scores. Train compliance personnel and relationship managers on the risk scores and how they affect daily work for AML operations team.
- Periodically review the methodology for improvements
How Compliance Software Supports Organizations
Regulators expect firms to maintain risk-based approaches and justify why they do or don’t engage with high-risk jurisdictions. Non-compliance with such can lead to hefty fines, loss of licenses, or reputational damage (e.g., banks fined billions for processing payments linked to sanctioned countries), therefore it is important to select a software provider who understands your companies needs and can adapt accordingly.
At AMLYZE, we’ve built our Customer Risk Assessment module with these exact challenges in mind. Our solution enables compliance teams to integrate geographical risk seamlessly alongside other risk factors – customer, product, and channel – into a unified, dynamic scoring model.
-
Fully configurable: tailor risk scoring logic to your institution’s appetite and regulatory obligations, without developer support.
-
Behaviour-aware scoring: move beyond static KYC data with continuous re-assessment as customer behaviour or new data emerges.
-
Automation at scale: streamline onboarding, re-scoring, and case creation, cutting risk assessment time by up to 60%.
-
Unlimited data inputs: enrich scoring with internal intelligence and external lists (FATF, EU, OFAC, Basel AML Index, Transparency International, etc.) to ensure your model reflects real-world exposure.
Trusted by Advanzia Bank and Vinted, AMLYZE empowers compliance teams to focus on genuine threats instead of false alarms – helping you maintain a regulator-aligned, risk-sensitive approach to geographical risk.
Ready to see how AMLYZE can strengthen your risk assessment framework? Request a demo today.





