A customer risk assessment converts what the firm knows about a relationship into a rating that determines the depth of due diligence and the intensity of monitoring applied. It should be built from defined factors, scored consistently, capable of principled override, documented end to end and tested independently.
On this page
Purpose and scope
The customer risk assessment is the hinge of a risk-based approach. Everything downstream, the depth of verification, whether enhanced measures apply, how intensively activity is monitored and how often the file is revisited, follows from it. If the rating is arbitrary or undocumented, the proportionality of every other control becomes hard to defend.
Regulatory basis, stated carefully
The Money Laundering Regulations 2017 establish a risk-based framework in which firms assess risk and apply due diligence proportionately. HMRC guidance describes customer due diligence as including identifying and verifying the customer and beneficial owners where applicable, understanding ownership and control, understanding the purpose and intended nature of the relationship, ongoing monitoring, record keeping and updating information on change. The FCA Financial Crime Guide sets out its expectations of the firms it supervises.
The FCA's April 2026 findings on customer due diligence processes and controls described stronger practice as including risk-tailored due diligence, clearly documented enhanced due diligence steps and regular independent testing, and observed weaknesses including insufficient evidence of enhanced measures and weak independent assurance and version control. Those findings describe the firms reviewed; requirements and supervisory expectations vary by sector and supervisor. This page is general information, not legal or compliance advice.
Building the risk factor model
A defensible model uses a bounded set of factors, each with defined values, a stated data source and a documented reason for inclusion that traces back to the business-wide risk assessment.
| Factor | Typical inputs |
|---|---|
| Customer type | Natural person, regulated entity, private company, trust, partnership, charity, complex or layered structure |
| Ownership and control | Number of layers, nominee or bearer arrangements, opacity, jurisdictions in the chain, PEP involvement |
| Geography | Country of incorporation, operation, ownership, funds flow and counterparties, assessed against the firm's own country methodology |
| Product and service | Cash intensity, cross-border capability, ability to transfer value to third parties, transparency of counterparties |
| Delivery channel | Face to face, remote, intermediated, introduced by a third party, digital onboarding |
| Expected activity | Anticipated volumes, values, frequency, counterparties and jurisdictions recorded at onboarding |
| Behavioural and control history | Past alerts, previous escalations, outreach responsiveness, prior quality defects on the relationship |
Scoring and weighting
- Define values before weights. Each factor should have discrete, evidenced values rather than an analyst's impression.
- Weight with a stated rationale. Every weight should have a written reason. Weights chosen to produce a desired distribution of ratings are not defensible.
- Use driver rules where appropriate. Some factors should set a floor on the rating regardless of the aggregate score, for example certain PEP or high-risk jurisdiction exposures.
- Keep bands few and meaningful. Bands should map to genuinely different treatment. If two bands trigger identical measures, they are one band.
- Version the methodology. A rating must be interpretable against the methodology version in force when it was produced.
Agora practitioner interpretation
We would separate the risk model from the measures it triggers. Firms that hard-code measures into scoring logic find they cannot change one without disturbing the other, and cannot explain to a reviewer whether a change altered the assessment of risk or only the response to it.
Overrides and escalation
A model that cannot be overridden will be worked around; a model that can be overridden without a record will be. The practical position is to permit overrides, constrain them and make them visible.
- Require a written rationale referencing evidence on the file.
- Set approval authority by direction and size of the change, with downgrades held to a higher standard.
- Record the pre-override and post-override rating, the approver and the date.
- Report override volumes by reason, team and approver; clustering usually indicates a model defect rather than unusual customers.
- Give overrides a review date so they do not persist unexamined.
Calibration and independent testing
- Test the model against representative and edge cases before release, and retain the results.
- Compare rating distribution against expectation and investigate material drift.
- Back-test ratings against outcomes such as alerts, escalations and internal reports.
- Review the country and product methodologies on a defined cycle and on external change.
- Subject the model to periodic independent testing that is separate from the team that owns it, in line with the assurance expectations described in KYC quality assurance.
Common pitfalls
- Risk factors with no documented link to the business-wide risk assessment.
- Expected activity captured as free text, so it cannot drive monitoring. See purpose and intended nature.
- Scores that cannot be reproduced because the methodology was edited without versioning.
- Overrides used routinely to manage operational capacity.
- Ratings that never move because no trigger exists to revisit them.
- A model no one outside the team can explain, which fails at the first independent review.
Where technology helps
Consistent scoring, factor transparency, override capture and distribution reporting are natural automation targets. The Agora Due Diligence Platform includes a configurable risk assessment module in which the firm controls factors, weights and bands, and every contribution to a rating is visible and can be overridden with a recorded reason.
Primary sources
- The Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017
- HMRC AMLG11300, customer due diligence (updated 16 July 2026)
- FCA, Firms' customer due diligence processes and controls: our findings (8 April 2026)
- FCA Financial Crime Guide, chapter 3
Frequently asked questions
What is a customer risk assessment in CDD?
It is the firm's documented assessment of the money laundering and terrorist financing risk presented by an individual customer relationship, built from defined risk factors such as customer type, ownership structure, geography, product, channel and expected activity. It determines the level of due diligence and monitoring applied.
How does it relate to the business-wide risk assessment?
The business-wide risk assessment identifies the risks inherent in the firm's customers, products, channels and geographies. The customer risk assessment applies that framework to an individual relationship. The two should be consistent: risk factors used at customer level should be traceable to risks identified at firm level.
Should customer risk scoring be automated?
Scoring against an approved methodology automates well because it is rule-describable and benefits from consistency. What should not be fully automated is the decision to accept a rating that does not fit the case, the treatment of discrepancies, and the judgement that enhanced measures have been satisfied.
How often should a customer risk rating be reviewed?
On a risk-sensitive basis and whenever a relevant trigger occurs, such as a change in ownership, jurisdiction, product use or screening status. Most firms also apply a backstop interval by risk band so that no rating stands indefinitely without review.
What documentation does a customer risk assessment need?
The factors considered, the data values used and their source, the weighting or scoring logic and its version, the resulting rating, any override with a recorded rationale and approver, the due diligence measures that rating triggered, and the date and identity of the person who concluded it.
Related resources
CDD and onboarding
Enhanced Due Diligence (EDD): Triggers, Evidence and Controls
CDD and onboarding
Purpose and Intended Nature of the Business Relationship
Governance and assurance
Building a Regulator-Defensible CDD Audit Trail
Remediation and ongoing KYC
KYC Trigger Events: When Should Customer Due Diligence Be Reviewed?
Where the technology fits
Agora is a technology provider: the platform supports the control described above, and your own teams operate it and hold the accountable decisions.
Next step
Testing a risk model against real cases?
See configurable risk assessment, factor transparency and recorded overrides in a working platform.