Customer Risk
Customer risk refers to the possibility that a particular customer, or a group of customers, could be involved in money laundering, terrorist financing, or other financial crime. It reflects the idea that different customers pose different levels of risk, so activity that is unremarkable for one customer may be concerning for another. Assessing this risk helps obliged entities decide how closely to scrutinize a relationship.
Customer risk is one of the principal risk categories in a risk-based AML/CFT framework, typically assessed alongside factors such as geographic or jurisdiction risk, product and service risk, and delivery-channel risk. As a compliance concept, it denotes the money laundering and terrorist financing risk posed by a specific customer or category of customers, evaluated through consideration of financial, operational, regulatory, and behavioral characteristics of the customer relationship. Because risk is inherently relative, the same activity may be assessed as high risk for one customer and acceptable for another, depending on the expected profile of the relationship; consequently, the assessment informs customer risk rating and the calibration of due diligence measures (for example, standard, simplified, or enhanced due diligence) rather than serving as a legal determination of wrongdoing. Customer risk assessment supports the detection, mitigation, and management of financial crime risk but does not eliminate it, and the specific factors, weightings, and rating methodologies applied should be confirmed against the requirements of the applicable regulatory regime and the entity's own risk-based approach.
Why it matters
Customer risk sits at the heart of the risk-based approach that underpins modern AML/CFT programs. Because different customers pose different levels of money laundering and terrorist financing risk, obliged entities cannot treat every relationship identically without either wasting resources on low-risk customers or under-scrutinizing higher-risk ones. Assessing customer risk allows an entity to allocate its due diligence effort proportionately, applying more intensive scrutiny where the risk profile warrants it and lighter measures where it does not. This proportionality is central to how supervisors expect firms to operate under a risk-based framework, though the specific factors and methodologies an entity must apply should be confirmed against the applicable regulatory regime.
Who it's relevant to
Inside Customer Risk
Common questions
Answers to the questions practitioners most commonly ask about Customer Risk.