Skip to main content
Category: Risk Assessment

Customer Risk

Also known as: Customer Risk Category, Client Risk
Simply put

Customer risk refers to the possibility that a particular customer, or a group of customers, could be involved in money laundering, terrorist financing, or other financial crime. It reflects the idea that different customers pose different levels of risk, so activity that is unremarkable for one customer may be concerning for another. Assessing this risk helps obliged entities decide how closely to scrutinize a relationship.

Formal definition

Customer risk is one of the principal risk categories in a risk-based AML/CFT framework, typically assessed alongside factors such as geographic or jurisdiction risk, product and service risk, and delivery-channel risk. As a compliance concept, it denotes the money laundering and terrorist financing risk posed by a specific customer or category of customers, evaluated through consideration of financial, operational, regulatory, and behavioral characteristics of the customer relationship. Because risk is inherently relative, the same activity may be assessed as high risk for one customer and acceptable for another, depending on the expected profile of the relationship; consequently, the assessment informs customer risk rating and the calibration of due diligence measures (for example, standard, simplified, or enhanced due diligence) rather than serving as a legal determination of wrongdoing. Customer risk assessment supports the detection, mitigation, and management of financial crime risk but does not eliminate it, and the specific factors, weightings, and rating methodologies applied should be confirmed against the requirements of the applicable regulatory regime and the entity's own risk-based approach.

Why it matters

Customer risk sits at the heart of the risk-based approach that underpins modern AML/CFT programs. Because different customers pose different levels of money laundering and terrorist financing risk, obliged entities cannot treat every relationship identically without either wasting resources on low-risk customers or under-scrutinizing higher-risk ones. Assessing customer risk allows an entity to allocate its due diligence effort proportionately, applying more intensive scrutiny where the risk profile warrants it and lighter measures where it does not. This proportionality is central to how supervisors expect firms to operate under a risk-based framework, though the specific factors and methodologies an entity must apply should be confirmed against the applicable regulatory regime.

Who it's relevant to

Compliance Officers and MLROs
Those responsible for an AML/CFT program rely on customer risk assessment to design and justify a proportionate, risk-based approach to due diligence and monitoring. They set the factors, weightings, and rating methodologies used to classify customers and must be able to demonstrate to supervisors that these choices align with the applicable regulatory regime and the entity's own documented risk-based approach.
Onboarding and Customer Due Diligence Teams
Staff performing onboarding use customer risk ratings to determine the level of due diligence required, distinguishing between customers who may warrant standard, simplified, or enhanced measures. Because activity acceptable for one customer may be concerning for another, these teams apply the risk rating to establish the expected profile of a relationship at the outset.
Financial Intelligence and Transaction Monitoring Analysts
Analysts use customer risk categories as context when reviewing activity, since the same transaction may be assessed differently depending on the customer's expected profile. A customer's risk rating helps frame what is unremarkable versus unusual for that relationship, though it is not proof of wrongdoing on its own.
Risk and Audit Functions
Risk management and internal audit teams review whether customer risk assessment methodologies are sound, consistently applied, and calibrated to the entity's overall risk-based framework. They evaluate customer risk alongside geographic, product, and delivery-channel risk to confirm the program supports the detection, mitigation, and management of financial crime risk.

Inside Customer Risk

Customer Risk Rating
An overall assessment, typically expressed on a scale (for example, low, medium, or high), that reflects the money laundering and terrorist financing risk a customer may pose to an obliged entity. The rating generally informs the level of due diligence applied and the frequency of ongoing monitoring and review.
Customer Type and Legal Structure
Consideration of whether the customer is a natural person, a legal entity, a trust, or another arrangement, and how complex or opaque the ownership and control structure is. Layered structures or entities that obscure beneficial ownership may generally elevate risk.
Politically Exposed Person (PEP) Status
Whether the customer, or a related party such as a family member or close associate, holds or has held a prominent public function. PEP status is a risk factor that in many jurisdictions triggers enhanced due diligence, but it is distinct from sanctions status and does not itself imply wrongdoing.
Geographic Risk
Exposure associated with the jurisdictions connected to the customer, including country of residence, nationality, incorporation, and the location of business activity. Jurisdictions identified as higher risk by bodies such as FATF, or subject to sanctions regimes, generally increase customer risk.
Products, Services, and Delivery Channels
The nature of the products or services the customer uses and how the relationship is conducted (for example, face-to-face versus non-face-to-face onboarding). Certain products, cash intensity, or remote channels may present higher inherent risk.
Behavioral and Transactional Profile
The expected nature, volume, and purpose of the customer's activity, established at onboarding and monitored on an ongoing basis. Deviations from the expected profile may prompt review but are not, in themselves, proof of illicit activity.
Relationship to CDD/EDD
Customer risk is the primary driver of the risk-based application of customer due diligence. A higher risk rating generally requires enhanced due diligence (EDD), while lower risk may permit simplified measures where the applicable regime allows.

Common questions

Answers to the questions practitioners most commonly ask about Customer Risk.

Does a high customer risk rating mean the customer is involved in money laundering or other financial crime?
No. A customer risk rating is a compliance measure used to allocate monitoring and due diligence resources, not a determination of criminal conduct. A high rating indicates that the customer's profile presents characteristics that may warrant enhanced scrutiny under a risk-based approach; it does not establish that any wrongdoing has occurred. Treating a rating as evidence of criminality confuses a risk-management tool with a legal finding.
Is customer risk the same as the overall money laundering risk faced by an institution?
No. Customer risk is only one component of the broader risk assessment. In many frameworks, institutions also assess product and service risk, delivery-channel risk, and geographic or jurisdictional risk, among others. Customer risk focuses specifically on the characteristics of the customer relationship, and it should be considered alongside these other risk categories rather than treated as a proxy for the institution's total exposure.
What customer characteristics typically feed into a customer risk rating?
Institutions generally consider factors such as the customer type and legal structure, the nature and purpose of the relationship, beneficial ownership complexity, whether the customer or connected parties are politically exposed persons, the customer's occupation or business activity, and geographic connections. The specific factors and their weightings depend on the institution's own risk-based methodology and applicable regulatory expectations, so exact criteria should be confirmed against the relevant regime and internal policy.
How does the customer risk rating connect to the level of due diligence applied?
Under a risk-based approach, the rating generally drives the intensity of customer due diligence. Lower-risk relationships may be eligible for simplified measures where permitted, standard-risk relationships receive standard CDD, and higher-risk relationships typically trigger enhanced due diligence, which may include additional information gathering, source-of-funds or source-of-wealth inquiries, and closer ongoing monitoring. The precise scope of each tier depends on the applicable regime and the institution's policies.
When should a customer's risk rating be reviewed or updated?
Customer risk is generally treated as dynamic rather than static. Institutions typically reassess ratings on a periodic basis tied to the risk tier, and also on a trigger basis when relevant events occur, such as material changes in ownership, activity inconsistent with the expected profile, adverse media, or a change in the customer's circumstances. The specific review cadence and triggers should be set out in internal policy and aligned with regulatory expectations.
How should institutions handle overrides where analyst judgment differs from the automated risk score?
Many institutions permit adjustments to a model-generated rating, but these are typically governed by documented procedures requiring a stated rationale, appropriate approval, and an audit trail. Overrides that raise or lower risk should be defensible and subject to review, so that the rating remains consistent with the institution's methodology and can withstand regulatory scrutiny. The governance requirements for overrides should be defined in policy.

Common misconceptions

A high customer risk rating means the customer is involved in money laundering or other financial crime.
A customer risk rating is an operational, compliance-oriented measure of potential exposure, not a determination of criminal conduct. It informs the intensity of due diligence and monitoring, and a high rating does not establish wrongdoing.
PEP status and sanctions status are effectively the same customer risk factor.
They are distinct. PEP screening identifies individuals in prominent public functions who may warrant enhanced scrutiny, whereas sanctions screening identifies parties subject to legal restrictions. A PEP is not necessarily sanctioned, and being a PEP is a risk indicator rather than a prohibition.
A customer's risk rating is set once at onboarding and remains fixed.
Customer risk is generally treated as dynamic. Ratings are typically reassessed on an ongoing basis and upon trigger events, such as changes in ownership, behavior, or geographic exposure, in line with a risk-based approach.

Best practices

Base customer risk ratings on a documented, multi-factor methodology that considers customer type and structure, geographic exposure, PEP status, products and channels, and expected behavior, rather than any single indicator.
Align the level of due diligence to the assessed risk, applying enhanced due diligence to higher-risk customers and simplified measures only where the applicable regime permits, and record the rationale for each rating.
Screen PEP status and sanctions exposure separately, treating each as a distinct risk consideration and avoiding conflation of the two.
Treat risk ratings as dynamic by reassessing them through ongoing monitoring and defined trigger events, updating the rating when the customer's profile or circumstances change.
Document the basis for risk decisions clearly, and ensure that a high rating drives proportionate controls and monitoring rather than being interpreted as evidence of criminal conduct.
Confirm jurisdiction-specific requirements, thresholds, and PEP or geographic risk designations against the applicable regulations, as these vary across regimes such as the EU AML framework, the US Bank Secrecy Act and FinCEN rules, and the UK Money Laundering Regulations.