Customer Risk Rating
A Customer Risk Rating is the process financial institutions use to judge how much money laundering or other financial crime risk a particular customer may pose, and to sort customers into risk categories accordingly. Because the same activity can be normal for one customer but concerning for another, the rating is tailored to each customer's individual circumstances. It is a tool to help institutions focus their attention and controls, not a determination that any customer has done anything wrong.
A Customer Risk Rating (also commonly referred to as customer risk scoring) is a methodical assessment conducted by financial institutions to categorize customers according to their perceived financial crime risk, typically as part of a risk-based AML compliance program. The process generally involves evaluating various risk indicators associated with a customer and, in many implementations, assigning a numerical or categorical score used to allocate the appropriate level of due diligence and ongoing monitoring. As reflected in supervisory guidance such as the FFIEC BSA/AML Examination Manual, any customer account may potentially be used for illicit purposes, so risk ratings are calibrated to the specific customer rather than applied uniformly, since activity considered high-risk for one customer may be acceptable for another. A customer risk rating is a risk-management measure intended to help identify, manage, and mitigate risk; it does not eliminate financial crime risk and does not, in itself, establish wrongdoing. Specific methodologies, factors, and rating scales vary by institution and applicable regulatory regime.
Why it matters
Customer Risk Rating sits at the heart of a risk-based AML program because it determines how an institution allocates its finite compliance resources across a large and varied customer base. As supervisory guidance such as the FFIEC BSA/AML Examination Manual notes, any customer account may potentially be used for illicit purposes, including money laundering. Rather than treating every customer identically, institutions use the rating to focus heightened attention on relationships that present greater perceived risk while applying proportionate measures to those that present less. This calibration is what allows customer due diligence and ongoing monitoring to be applied in a manner commensurate with risk.
The importance of tailoring the rating to each customer's individual circumstances cannot be overstated. Activity that appears concerning for one customer may be entirely ordinary for another, so a rating that reflects a customer's specific profile helps reduce both missed risk and unnecessary friction for lower-risk relationships. Where ratings are poorly calibrated, an institution may under-monitor genuinely higher-risk customers or over-allocate resources to relationships that do not warrant it, weakening the overall effectiveness of the program.
It is essential to understand what a customer risk rating is not. A high rating is a risk-management signal used to determine the appropriate level of due diligence and monitoring; it is not a determination that a customer has done anything wrong, and it does not, in itself, establish wrongdoing. Equally, a rating is a measure intended to help identify, manage, and mitigate financial crime risk, but it does not eliminate that risk. Specific methodologies, factors, and rating scales vary by institution and applicable regulatory regime, and exact requirements should be confirmed against the rules that apply to a given entity.
Who it's relevant to
Inside CRR
Common questions
Answers to the questions practitioners most commonly ask about CRR.