AML & Financial Crime

Customer risk-rating methodologies

Design choices in customer risk-rating: attributes, weightings, override governance and calibration.

By Jonas Osman AbdelfourPublished November 20, 2025

Summary Customer risk-rating (CRR) determines the intensity of due diligence, the frequency of review, and the sensitivity of monitoring. Its design shapes the whole KYC operating model.

Attributes Attribute selection should be driven by the EWRA. Common categories include customer type, geography, product usage, expected activity, source-of-wealth complexity, and adverse-information findings.

Weighting and aggregation Weightings should be justified against typologies and outcomes, not set by convention. Simple additive models are defensible if calibrated; more complex approaches require validation against outcomes.

Override governance Overrides are unavoidable and must be governed. Every override should be recorded, reasoned, time-bound and periodically reviewed at aggregate for pattern.

Periodic review Ratings should refresh on defined triggers: event-driven changes, expected periodic review, and portfolio-wide recalibration.

Calibration Backtesting against SAR outcomes, investigation findings and monitoring alerts closes the loop between rating and detection.

Limitations CRR is a prioritisation tool. It does not by itself detect financial crime; it directs finite resources.

Related expertise See [AML and Financial Crime](/expertise/aml).

Frequently asked questions

What should risk leaders know about attributes?

Attribute selection should be driven by the EWRA. Common categories include customer type, geography, product usage, expected activity, source-of-wealth complexity, and adverse-information findings.

What should risk leaders know about weighting and aggregation?

Weightings should be justified against typologies and outcomes, not set by convention. Simple additive models are defensible if calibrated; more complex approaches require validation against outcomes.

What should risk leaders know about override governance?

Overrides are unavoidable and must be governed. Every override should be recorded, reasoned, time-bound and periodically reviewed at aggregate for pattern.

What should risk leaders know about periodic review?

Ratings should refresh on defined triggers: event-driven changes, expected periodic review, and portfolio-wide recalibration.

What should risk leaders know about calibration?

Backtesting against SAR outcomes, investigation findings and monitoring alerts closes the loop between rating and detection.