What Is Customer Risk in AML? Key Factors, Scoring Models, and Best Practices

Mažvydas Miliauskas
Author
Mažvydas Miliauskas, CAMS
Published
November 18, 2025
Customer Risk in AML

In the ever-evolving landscape of financial crime, Anti-Money Laundering (AML) programs stand as the frontline defence for financial institutions worldwide. At the heart of these programs lies the Customer Risk Assessment – a systematic process that identifies, evaluates, and mitigates the risks posed by customers engaging in money laundering, terrorist financing, or other illicit activities.

Every decision, from onboarding a client to setting transaction monitoring thresholds, depends on how well the organization identifies and assesses customer risk. In order to understand the bigger picture let’s double click into this complex topic in more detail.

Why Customer Risk is Important?

 At its core, AML compliance is risk-based and it is not a coincidence that the very first Financial Action Task Force (FATF) Recommendation (out of 40) is dedicated to “Assessing risks and applying a risk-based approach”.

The FATF description of the 1st Recommendation

The FATF description of the 1st Recommendation (Source: FATF)

Regulators expect institutions to allocate resources where the threat is greatest, and that begins with understanding who the customer is, what they do, and how they interact with the financial system. A well-designed customer risk framework considers many factors at once: the customer’s identity, occupation or business activities, source of funds, transaction behaviour (customer risk), geographic connections (geographical risk), the ways how the service is provided (delivery channel risk) and product usage (product risk). Together, these form a profile that helps determine whether the customer poses a low, medium, or high risk of money laundering or terrorist financing.

Without accurate customer risk assessment, an AML program becomes reactive rather than pro-active. Controls such as transaction monitoring and ongoing due diligence rely on the initial risk rating to calibrate their sensitivity and effectiveness. A low-risk customer may require standard monitoring, while a high-risk customer – such as a politically exposed person or someone operating in a high-risk jurisdiction – requires enhanced scrutiny. In an era of digital banking and cross-border transactions, where criminals exploit vulnerabilities like pseudo-anonymous cryptocurrencies or shell companies, assessing customer risk helps prevent the infiltration of illicit funds into legitimate activities. Moreover, effective customer risk assessment fosters trust. Customers value privacy and security, and institutions that ask the right questions demonstrate diligence in risk management can build stronger relationships.

 Ultimately, customer risk assessment is not just an operational process. It is the analytical lens through which an institution interprets all applicable AML obligations. It guides resource allocation, shapes compliance strategy, and anchors the organization’s defence against regulatory breaches and reputational harm. In short, without a clear and dynamic understanding of customer risk and how the risk ratings are assigned, there can be no meaningful AML compliance.

 The Key Factors of the Customer Risk

 Identifying key risk factors is essential for categorizing customers into low, medium, or high-risk categories. These factors vary between business (corporate) and private (individual) customers, reflecting their distinct profiles and potential vulnerabilities. Sometimes regulators provide guidance, but institutions must customize the Customer Risk Scoring model based on their risk appetite and operations. As in any other compliance risk assessments, the risk needs to be reflected using the key dimensions of Customer, Geographical, Product/Service, and Delivery Channel.

Examples of the low and high-risk factors for private customers (list is not exhaustive):

Risk CategoryHigh-Risk FactorsLow-Risk Factors
Customer Risk• Foreign Politically exposed person (PEP)
• Inconsistent or unverifiable source of wealth/funds
• Unusual or complex relationships (for example, third parties managing the account)
• Adverse media or criminal record
• High transaction volumes or frequent large cash deposits
• Clear occupation with verifiable income
• Simple account ownership (individual)
• Transparent and verified source of funds
• No adverse media or sanctions exposure
• Limited and predictable transaction activity
Geographical Risk• Non-resident or foreign national with limited ties to the jurisdiction
• Residence or tax domicile in FATF high-risk or sanctioned countries
• Transactions with or from high-risk jurisdictions
• Links to countries with weak AML frameworks or corruption issues
• Resident in the country of the financial institution
• Residence in low-risk, FATF-compliant jurisdictions
• Transactions limited to domestic or low-risk countries
• No exposure to sanctioned or secrecy jurisdictions
Product / Service Risk• Private banking, offshore investments, or crypto assets
• Complex financial products (derivatives, structured products
• Standard retail banking products (savings, salary account)
• No use of cash-intensive or high-risk investment products
Delivery Channel Risk• Non-face-to-face onboarding
• Introduced by third-party intermediaries
• Reliance on weak digital ID verification
• Face-to-face onboarding at branch
• No third-party involvement
• Strong e-KYC and identity verification processes

Examples of the low and high-risk factors for business customers (list is not exhaustive):

Risk CategoryHigh-Risk FactorsLow-Risk Factors
Customer Risk• Shell or front company with opaque ownership
• Use of Bearer shares
• Operates in high-risk sectors (casinos, real estate, Money Service Business (MSB), arms trade)
• Complex ownership structure (e.g., trust, foundation)
• PEP or sanctioned ownership links
• Negative media on corruption or tax evasion
• Unusually large or inconsistent transactions

• Well-established, regulated company with transparent structure
• Company with publicly listed shares in a Stock Exchange that meets certain requirements (note: the institution must assess each stock exchange and jurisdiction individually before assigning a lower risk rating to listed entities)
• Operates in low-risk sectors (manufacturing, education, healthcare)
• Clear, verifiable beneficial ownership
• No adverse media or sanctions hits
• Well-established, regulated company with transparent structure
• Company with publicly listed shares in a Stock Exchange that meets certain requirements (note: the institution must assess each stock exchange and jurisdiction individually before assigning a lower risk rating to listed entities)
• Operates in low-risk sectors (manufacturing, education, healthcare)
• Clear, verifiable beneficial ownership
• No adverse media or sanctions hits
Geographical Risk• Incorporated or operating in high-risk or sanctioned jurisdictions
• Frequent cross-border trade with weak AML countries
• Supply chain links to tax havens or secrecy jurisdictions
• Incorporated and operating in FATF-compliant countries
• Domestic operations only
• No trade or exposure to high-risk countries
Product / Service Risk• Trade finance, correspondent banking, or high-value asset transactions
• Heavy use of cash or crypto payments
• Basic business accounts and payment services
• Transactions align with stated business activity
• Low cash usage, transparent payment methods
Delivery Channel Risk• Onboarded via third-party intermediaries or agents
• Non-face-to-face onboarding without site visit
• Limited ongoing monitoring
• Direct onboarding with in-person verification
• Site visits and business validation performed
• Regular ongoing monitoring and review

Institutions often use questionnaires at onboarding to gather data on these factors, ensuring a holistic view. By systematically evaluating these, AML programs can pre-emptively address vulnerabilities, aligning with regulatory expectations for thorough risk identification.

Designing a Risk Scoring Model

Designing a Risk Scoring Model a complex task where the information obtained during onboarding (and ongoingly) is transformed into the relevant risk factors, weights are assigned with defined thresholds, and it incorporates dynamic re-scoring mechanisms. The following factors are important when designing a new model:

Risk Factors: factor selection draws from the key risks outlined earlier. Models typically include certain number of factors (e.g., 10-20), categorized into customer, geographic, product, and channel risks that can be qualitative and quantitative (or mixed). For instance, a private customer’s PEP status might be a binary factor (yes/no), while transaction volume could be scaled (e.g., low < EUR 10,000/month, high > EUR 100,000).

Clear Value Scoring: it is important to use a simple numerical range (e.g., 1–5 or 1–10) for each factor, where higher values indicate higher risk and a weighted sum yields an overall score, say 0-100. Thresholds then can categorize the outcome, for example:

Value Scoring system illustration (Source: Generated via ChatGPT)

Value Scoring system illustration (Source: Generated via ChatGPT)

Weights: weighting assigns relative importance to every factor and risk area. Using expert judgment or statistical methods like regression analysis, weights reflect impact. For example, the Geographic risk might weigh 30% if the institution operates internationally, while Product risk could be 20%. Total weights sum to 100%, ensuring balance. Also, it is important to incorporate situations when certain weights can override the final score.

 Dynamic Scoring: risk scoring models aren’t static; events like address changes, large transactions, or adverse media can trigger prompt reviews and should work in line with the Ongoing Due Diligence (ODD) controls. Integration with transaction monitoring systems allows real-time triggers, such as when cumulative transactions exceed thresholds. Advanced models employ machine learning or AI for adaptive weighting, learning from past alerts. For example, if data shows cryptocurrency usage correlates strongly with laundering in certain demographics, weights auto-adjust.

Challenges in Risk Scoring

Despite their utility, customer risk scoring models face significant challenges that can undermine AML effectiveness, for example:

Data Quality: data quality is a primary hurdle. Inaccurate, incomplete, or outdated information leads to flawed scores. For instance, self-reported data from customers might be falsified, or third-party sources could have errors. In global operations, varying data standards across jurisdictions complicate aggregation. Poor data results in misclassifications, such as overlooking a high-risk customer due to missing PEP flags or vice versa.

Static Models: traditional rule-based systems fail to adapt to emerging threats, like new laundering typologies, involving Non-Fungible Tokens (NFTs) or decentralized finance (DeFi). Without regular updates, models become obsolete, increasing false negatives. In dynamic environments, static approaches struggle with nuanced risks, such as subtle behavioural shifts.

Subjective Overrides:  compliance officers might manually adjust scores based on judgment, but this can lead to inconsistencies or favouritism if the model is not detailed enough. For example, overriding a high-risk score for a valuable client risks regulatory scrutiny. Balancing automation with human insight can be tricky, however risk overrides are applied daily, then maybe the model needs to be reviewed.

Model Complexity: overly intricate models that are hard to explain might be considered not aligned with the relevant transparency requirements. Scalability issues can also arise for institutions with millions of customers, where computational demands strain resources. In addition, these models must comply with varying regulatory standards.

According to the PwC’s Global Compliance Study 2025, 77% of the respondents stated that their company had been negatively impacted to some or a great extent by compliance complexity across several areas that drive growth.

According to the PwC’s Global Compliance Study 2025, 77% of the respondents stated that their company had been negatively impacted to some or a great extent by compliance complexity across several areas that drive growth. Source: PwC

Lack of Resources: addressing these risk and timely changes require ongoing validation, but resource constraints in smaller firms hinder this. Ultimately, these challenges highlight the need for resilient, adaptable systems to maintain AML integrity.

Best Practices in Customer Risk Assessment

 In order to overcome challenges and optimize customer risk assessment process, institutions should consider the following:

Automation and Workflow Integration: Automation is foundational. Leveraging AI and machine learning streamlines scoring, reducing manual errors and enabling real-time assessments. Tools like robotic process automation (RPA) handle updates and data ingestion, while predictive analytics forecast risk evolutions. In general, automate where possible and make sure integration with KYC and transaction monitoring systems where the risk scores should seamlessly feed into onboarding, monitoring, and review workflows.

Audit Trails: every score change must be logged with a timestamp, input data, and user/system source for regulatory traceability. Also, don’t forget that it needs to be reflected in the relevant policies before these changes occur.

Data Integration and Quality Management: data integration consolidates sources for a 360-degree view. Therefore, it is important that it has consistent formats for identifiers, countries, products, and risk ratings across all systems that combines customer data from onboarding systems, transaction monitoring, screening, and external data providers into one unified model input. And don’t forget to regularly monitor for missing, outdated, or inconsistent data.

External Sources: make sure to integrate reliable third-party data such as FATF, Transparency International, Basel AML Index in the Geographical risk area and any other outcomes that are required by the local legislation.

Regular Validation and Calibration: conduct annual validation to test the logic, data integrity, and consistency of results. Also, during the back-testing process compare historical customer outcomes (e.g., alerts, STRs, confirmed suspicious activity) against model-assigned risk scores to evaluate accuracy. At least once a year adjust thresholds and weights based on typology updates, regulatory changes, or portfolio evolution.

Automated Alerts: create automated alerts that detect model drifts. For example, if too many customers start clustering in the same risk category, it could be a signal that the model is not working as intended.

Training: training staff on risk factors and the upcoming changes in the Customer Risk Assessment process helps to foster a proper compliance culture and make sure all teams are aligned. Also, there external trainings online and industry forums where insights and best practices are shared with a larger audience that can be used to enhance the existing model within your organization.

Online training in Udemy platform which explains how the organizations can use AI for automation and other tasks, like risk scoring

Online training in Udemy platform which explains how the organizations can use AI for automation and other tasks, like risk scoring. Source: Udemy

Documentation is Key: a sound AML risk scoring model should be transparent, data-driven, and defensible. The documentation should define:

 Objectives are clearly defined which explain how the elements from the core risk dimensions (Customer, Geography, Product/Service, and Delivery Channel) are integrated.

  • Established measurable indicators (each dimension should include quantifiable and verifiable data point).
  • Track all updates to the model — changes in weighting, data sources, or thresholds must be versioned and approved.
  • Review and adjust weights periodically based on emerging typologies, audit findings, or regulatory changes.
  • Ensure the model aligns with FATF guidelines, local AML regulations, and internal risk appetite frameworks.

Conclusions

Customer risk assessment remains indispensable in AML compliance, serving as the backbone of any risk-based framework. As financial crime typologies continue to evolve – from the misuse of legal entities and cross-border schemes to emerging technologies like crypto and DeFi–institutions must continuously adapt their methodologies, data sources, and scoring logic. A well-designed model does more than categorize customers; it ensures that monitoring thresholds are calibrated, due diligence is proportionate, and resources are deployed where they matter most.

However, the effectiveness of a customer risk framework depends on its ability to remain accurate, dynamic, and transparent. Ongoing data validation, automated recalibration, integration with KYC and transaction monitoring systems, and clear documentation are essential to maintaining regulatory trust and operational efficiency. Organizations that invest in modern, adaptable risk assessment capabilities not only reduce exposure to financial crime but also strengthen customer relationships by demonstrating diligence and accountability.

If your organization is looking to optimize or simplify the customer risk assessment process – whether through configurable scoring, behaviour-aware models, or seamless integration with screening and monitoring systems – consider exploring AMLYZE’s Customer Risk Assessment solution. It is designed to help institutions enhance accuracy, reduce manual overhead, and keep pace with the fast-changing regulatory landscape.

Mažvydas Miliauskas,
AML Risk & Assessments Lead at TransferGo

👉 Ready to see how AMLYZE can strengthen your customer-specific AML risk assessment? Request a demo today.

👉 To understand how geography influences overall customer exposure, you can also read our companion article:
Geographical Risk in AML: What Compliance Teams Need to Know

👉 For a deeper look at how specific industries elevate financial crime threats, explore:
Industry-Related AML Risks: A Guide for Compliance Teams

About the author

Mažvydas Miliauskas
Author
Mažvydas Miliauskas, CAMS
Mažvydas is AMLYZE contributing author. CAMS certified high achiever who is passionate about financial crime compliance, ML/TF typologies and enterprise risk management.

Related