Skip to main content
Category: Risk Assessment

Segmentation

Simply put

Segmentation generally refers to the practice of dividing a larger whole into smaller groups or units based on shared characteristics. The specific meaning depends heavily on the field in which the term is used, ranging from marketing to computing.

Formal definition

Segmentation is a concept applied across multiple disciplines to partition a larger set into smaller, more homogeneous components. In marketing, it denotes dividing a broader target market into smaller groups based on shared attributes such as geography or demographics. In computing, it takes distinct forms: in operating systems it is a memory-management technique dividing a process into variable-sized units called segments, while in image processing it refers to partitioning a digital image into multiple regions or objects (sets of pixels). The evidence provided does not establish an AML- or financial-crime-specific definition of this term; practitioners should confirm any compliance-context meaning (for example, customer or transaction segmentation for risk purposes) against applicable regulatory guidance, as such usage is not supported by the sources here.

Why it matters

Segmentation is a broadly used term that carries distinct meanings across different disciplines, and the sources supporting this entry establish its usage in marketing, operating-system memory management, and image processing rather than in any anti-money laundering or financial-crime context. For practitioners, this matters because the same word can appear in vendor documentation, technical systems, and business materials with entirely different intended meanings. Treating these usages interchangeably risks confusion, particularly when reviewing tooling or documentation that may draw on marketing or computing terminology rather than a compliance-specific concept.

The evidence here does not support a definition of segmentation as a compliance or financial-crime control. Where the term is used in an AML program context, for example, to describe grouping customers or transactions for risk purposes, that meaning is not established by the sources provided and should be treated as unverified against this entry. Practitioners encountering the term in a compliance setting should confirm the intended meaning against applicable regulatory guidance and internal policy rather than assuming it maps to any of the discipline-specific definitions above.

Because the meaning depends so heavily on the field, careful attribution is essential. A reference to segmentation in an operating-systems document concerns memory management, a reference in a marketing document concerns dividing an audience, and a reference in image processing concerns partitioning pixels. Recognizing which sense is intended avoids misinterpretation when the term crosses from technical or commercial domains into professional practice.

Who it's relevant to

Compliance professionals encountering the term in tooling or documentation
Compliance officers and analysts may see the word segmentation in vendor materials, technical system documentation, or business communications. Because the sources here establish only marketing and computing meanings, practitioners should not assume the term carries a settled AML-specific definition and should confirm the intended meaning against applicable regulatory guidance and internal policy.
Marketing and analytics practitioners
In a marketing context, segmentation refers to dividing a broader target market or audience into smaller groups based on shared attributes such as geography or demographics. This usage is relevant to those conducting market analysis or audience targeting.
Technical and IT professionals
In computing, segmentation refers to distinct technical concepts: a memory-management technique that divides a process into variable-sized segments in operating systems, and the partitioning of a digital image into regions or sets of pixels in image processing. These meanings are relevant to systems and technical practitioners working with the underlying infrastructure or imaging tools.

Inside Segmentation

Customer Segmentation
The practice of grouping customers into categories that share similar characteristics, behaviors, or risk profiles, so that AML controls such as monitoring rules, due diligence intensity, and review cycles can be calibrated to each group rather than applied uniformly. This is an operational and risk-management technique, not a defined legal term, and its specific design is generally left to the obliged entity under a risk-based approach.
Risk-Rating Dimension
The variables used to differentiate segments, which typically include customer type (retail, corporate, correspondent, PEP-linked), product and service usage, delivery channel, geographic exposure, and transactional behavior. The relevant factors vary by institution and by the risk assessment methodology adopted, and no single set of dimensions is prescribed across all jurisdictions.
Peer-Group Benchmarking
The use of segments as reference populations against which an individual customer's activity can be compared, so that deviations from expected behavior within a peer group may be identified for review. This supports transaction monitoring but does not itself establish that any activity is suspicious.
Control Calibration
The application of differentiated measures to each segment, such as enhanced due diligence for higher-risk groups and simplified measures where lower risk is justified. In many jurisdictions the ability to apply simplified measures is conditional on documented low-risk findings and does not exempt an entity from ongoing monitoring obligations.
Model Governance and Documentation
The framework for defining, validating, testing, and periodically reviewing segmentation logic, including the rationale for segment boundaries and thresholds. Supervisors operating under risk-based frameworks generally expect firms to be able to justify their segmentation methodology, though specific documentation expectations differ by regime.

Common questions

Answers to the questions practitioners most commonly ask about Segmentation.

Is customer segmentation the same as customer risk rating?
No. Segmentation groups customers by shared characteristics, behaviors, or expected activity so that monitoring and controls can be calibrated to each group, whereas customer risk rating assigns a risk level (such as low, medium, or high) to an individual customer. Segmentation may feed into or inform risk rating, and the two are often used together, but they are distinct exercises: a customer's segment describes what kind of activity is expected of them, while their risk rating expresses the assessed level of money laundering or terrorist financing risk they present. Treating the two as interchangeable can lead to controls that are misaligned with either dimension.
Does placing a customer in a low-risk segment mean less monitoring is always acceptable?
Not automatically. Segmentation supports a risk-based approach, and lower-risk segments may generally justify proportionate, less intensive monitoring, but this is a calibration tool rather than a basis for switching monitoring off. The appropriate intensity depends on the applicable regime, the obliged entity's own risk assessment, and the customer's actual behavior, which may diverge from the segment's expected profile and warrant re-evaluation. Segment membership is a starting assumption to be tested against real activity, not a permanent exemption, and exact expectations should be confirmed against the applicable regulation and supervisory guidance.
What data is typically used to build customer segments?
Segmentation typically draws on a combination of customer attributes and behavioral data. Common inputs include customer type (individual versus legal entity), products and services used, expected transaction volumes and values, geographic exposure, occupation or business activity, and observed transaction patterns over time. The specific data used should be documented and justified against the entity's risk assessment, and firms generally validate that the inputs are accurate and current, since segmentation quality depends heavily on data quality.
How does segmentation interact with transaction monitoring thresholds and rules?
Segmentation commonly allows monitoring rules and thresholds to be tuned to the expected behavior of each group, so that alerts are more relevant to what is normal for that segment. For example, a threshold appropriate for a retail individual may be inappropriate for a corporate customer with high expected volumes. This can help manage alert volumes and reduce noise, though it does not guarantee that suspicious activity will be detected. Firms generally test and calibrate segment-specific rules and monitor for customers whose behavior no longer fits their assigned segment.
How often should segmentation models be reviewed?
Segmentation is generally reviewed periodically and when triggered by relevant changes, rather than treated as a fixed one-time exercise. Triggers may include changes in the customer base, new products or services, changes in the entity's risk assessment, and observed drift between segment expectations and actual behavior. The appropriate cadence depends on the entity's size, complexity, and risk profile, and firms typically document the review approach so that it can be evidenced to supervisors.
How can a firm demonstrate that its segmentation approach is defensible to a regulator?
Firms generally maintain documentation showing the rationale for how segments are defined, the data inputs used, how segments connect to monitoring calibration and risk assessment, and the governance around review and validation. Being able to explain why a customer sits in a given segment, how that affects the controls applied, and how the model is tested and updated helps demonstrate a considered, risk-based approach. What specific evidence is expected can vary by regime and supervisor and should be confirmed against applicable guidance.

Common misconceptions

Segmentation is a regulatory requirement with a fixed, universally defined methodology.
Segmentation is an operational and risk-management technique that supports a risk-based approach rather than a term defined identically across regimes. While FATF standards and instruments such as the EU AML framework, the US Bank Secrecy Act and FinCEN rules, and the UK Money Laundering Regulations generally expect risk-sensitive controls, they typically do not prescribe a single segmentation model, leaving design choices to the obliged entity subject to supervisory expectations.
Assigning a customer to a lower-risk segment means simplified due diligence can replace ongoing monitoring.
Placement in a lower-risk segment may support simplified measures where permitted and where low risk is documented, but it generally does not remove the obligation to conduct ongoing monitoring or to reassess risk as circumstances change. Simplified measures are typically conditional and should be confirmed against the applicable regulation.
When a customer's activity deviates from its segment peer group, this confirms wrongdoing.
A deviation from expected peer-group behavior is a detection signal that may warrant review, not proof of money laundering, terrorist financing, or any other offense. Segmentation is a measure to help detect and manage risk; it does not establish criminal conduct, and any escalation should follow the firm's investigation and reporting processes.

Best practices

Document the rationale for each segment, including the dimensions used and the boundaries or thresholds applied, so the methodology can be justified to supervisors under a risk-based approach.
Align segmentation dimensions with the institution's enterprise-wide risk assessment, covering customer type, product and channel, geography, and transactional behavior rather than relying on a single variable.
Calibrate controls to each segment, applying enhanced measures to higher-risk groups while ensuring that any simplified measures for lower-risk groups meet the documented conditions permitted under the applicable regime and do not suspend ongoing monitoring.
Validate and periodically review segmentation logic and thresholds, testing whether segments still reflect actual customer behavior and updating them as risks, products, or regulations change.
Treat peer-group deviations as review triggers, not conclusions, and route escalations through established investigation and internal reporting processes before any decision on suspicious activity filing.
Confirm specific thresholds, simplified-measure conditions, and documentation expectations against the applicable regulation and supervisory guidance in each jurisdiction where the institution operates, since these diverge across regimes.