← Blog · Compliance
Customer Risk Rating: Building a Defensible AML Scoring Model

A customer risk rating (CRR) is the pivot point of an AML program. It determines who gets simplified due diligence, who gets enhanced checks, and how often files are revisited. Yet many models collapse under examination because the factors are undocumented, the weights are arbitrary, or the output never changes what the institution actually does. A defensible model connects inputs to a rationale, and the rating to a concrete action.
Choosing Factors That Reflect Real Risk
Start with the risk categories most supervisors expect to see, then decompose each into observable inputs:
- Geography: country of residence, nationality, and jurisdictions in the payment corridor, benchmarked against sanctions exposure and Basel AML Index scores.
- Customer type: individual, sole trader, regulated entity, or complex legal structure with layered ownership.
- Product and channel: cash-equivalent products, cross-border rails, or remote-only onboarding versus in-branch.
- Behavioral signals: expected versus actual transaction volume, velocity, and counterparties.
- Screening outcomes: PEP status, adverse media hits, and prior alert history.
Each factor should have a written definition and a source. A rating that cannot be traced to a data point is a rating you cannot defend. Collect only the fields a factor actually consumes; a chat-based intake can gather residence and product intent without pulling documents that never feed the score.
Weighting Without False Precision
Weights imply a claim: that a high-risk geography matters more, or less, than a complex ownership structure. Make that claim explicit and reviewable. Two approaches dominate practice. A weighted-sum model assigns points per factor and sums them into a band (for example, low 0–30, medium 31–60, high 61+). A matrix or override model lets certain triggers, such as a sanctions nexus or an unexplained cash-intensive business, force a rating regardless of the arithmetic.
Most institutions run both: a base score plus a set of hard overrides. Avoid the illusion that a 0.37 weight is more scientific than 0.35. Round to defensible increments, document the reasoning, and record who approved the calibration. When an examiner asks why a factor carries the weight it does, the answer should be a sentence, not a shrug.
From Rating to Action
A rating that does not change behavior is decoration. Map each band to specific consequences:
- Depth of due diligence: standard identity verification for low risk; source-of-funds evidence and senior sign-off for high risk.
- Review cadence: event-driven triggers for lower tiers, shorter fixed intervals for higher tiers.
- Monitoring sensitivity: tighter transaction thresholds and faster alert routing for elevated ratings.
- Approval authority: who can onboard, and who must escalate before onboarding.
Document the linkage in the same policy that defines the factors. This is where CRR earns its keep during an audit: the file shows the rating, the inputs that produced it, and the controls it triggered.
Validation, Drift, and Governance
Models decay. Portfolios shift, typologies evolve, and a weighting that fit last year's book may now flag half your customers as medium risk. Build periodic validation into governance: sample rated files, compare model output against analyst judgment, and check whether high-risk ratings correlate with genuine SAR outcomes. Track the distribution across bands over time; a sudden migration usually signals a data-quality problem or a miscalibrated threshold rather than a real change in customer risk.
Keep an immutable log of model versions, calibration changes, and the approvals behind them. Retention here follows the same discipline as the underlying KYC records: hold what supports the decision for as long as the obligation requires, then delete on schedule. A CRR model is not a one-time build. It is a living control that only stays defensible when its factors, weights, actions, and revisions are all written down and periodically challenged.
General information, not legal advice. Talk to your compliance counsel for guidance on your specific obligations.