Document collection system

Two reviewers on the same compliance team open the same new client file. Every document is in, from the owner's passport to a recent bank statement, and the identity checks have passed.

One marks the company medium risk. The other says high, because the owner lives abroad and payments come from another country. Nothing in the firm's policy settles it, so the rating depends on who picked up the file.

At a US bank, examiners may review individual rating decisions like this one to test the process. Someone would then have to explain why this file got its rating.

What an AML Customer Risk Assessment Decides

The rating on a client file decides what happens next: which proof you ask for, who signs off and how closely you watch the account.

A customer risk assessment sets that rating. It usually rates each new client low, medium or high for money laundering risk. The rating rests on who the client is, what they want and where the money moves.

US banks need risk-based procedures to understand the nature and purpose of each customer relationship and develop a customer risk profile (31 CFR 1020.210(a)(2)(v)). The FFIEC exam manual notes it is also called the customer risk rating. Some teams call the whole step a KYC risk assessment, because it uses answers collected during KYC.

A business-wide AML risk assessment is a different document. It covers broad risks across the business, while a customer rating is decided case by case (AUSTRAC, Australia's AML regulator).

From 10 July 2027, EU rules connect the two. How far you check each client depends on an individual risk analysis that uses the business-wide assessment (Regulation (EU) 2024/1624, Article 20). A higher risk calls for enhanced due diligence, while a lower one may allow simplified measures, such as less frequent updates (Article 33).

How to Do a Client Risk Assessment in 5 Steps

Two reviewers reach the same rating when they follow the same written method.

Decide Which Risk Factors You Will Rate

Your business-wide assessment should already name the main factors, so apply them to the individual client. AUSTRAC sorts customer risk rating factors into four groups: the kind of customer, the service they want, how they reach you and the countries involved.

The FFIEC manual adds that actual or expected account activity can be a key factor.

EU rules list higher-risk examples (Regulation (EU) 2024/1624, Annex III). One is a trust or company set up to hold personal assets. Another is a transaction involving precious metals or stones.

Ask for Each Factor on Your Intake Form

If the form never asks the question, nobody can rate the answer. AUSTRAC's sample onboarding form for a property conveyancer asks about:

  • Whether the client is a person, company, trust or association
  • The service they want
  • Name, date of birth, address and occupation, or a company's address and owners
  • Whether they act for someone else, such as under a power of attorney
  • The countries they live in or deal with
  • The reason they want the relationship
  • Whether they, or a relative or close associate, are a politically exposed person (PEP) or under sanctions

In Clustdoc, the onboarding form supports conditional logic. A company can be asked about its owners, while a person never sees those questions.

Rate Each Factor Low, Medium or High

A client who lives abroad can be routine for one firm and unusual for another. Rate each factor against your own business and this client's facts.

US bank examiners expect no set number of risk levels (FFIEC). AUSTRAC gives low, medium and high as examples.

In 2022, five US agencies, including FinCEN, said again that no type of customer carries one fixed level of risk. A foreign address alone does not make a client high risk by default.

Combine the Factors Into One Customer Risk Rating

This is where the two reviewers from the opening split. One weighs all the factors together, and the other lets the country factors decide.

AUSTRAC's general method balances all the factors present, but its conveyancer example lets any high-risk factor make the whole client high risk. The FFIEC manual says no single indicator is necessarily decisive.

"Not necessarily" leaves the choice with you, as long as your rule is written down. Name the few factors that decide the rating on their own, such as ties to a high-risk country or ownership through a company with no real business.

Every other factor only adds weight, and you may weigh some more heavily than others (FFIEC). With our customer scoring, you set the weights and risk thresholds, and the score can use data from forms, stages and steps.

Record the Reason and Who Signed Off

A rating with no reason attached is hard to defend later. Firms covered by Australia's AML/CTF law must keep records of each customer risk assessment, the decision and the rationale (AUSTRAC).

US bank examiners expect procedures that name who may change a client's risk profile. If the process is effective and staff followed it, examiners should not fault the bank for one rating decision (FFIEC). The exceptions are bad faith, other aggravating factors, or a decision that weakens the whole due diligence program.

Each step in our approval workflow can carry a review note next to the approve or reject decision. Role-based permissions set who can change a scoring model and who can approve a high-risk case.

Two Sample Clients, Rated Factor by Factor

The table below links each factor to the form question behind it. Its examples come from AUSTRAC and the EU's risk factor lists.

Factor

What the form asks

Usually lower risk

Usually higher risk

Kind of customer

Person, company or trust? Who owns it?

A local resident, or a listed company that discloses its owners

Owned through an entity with no real business

Service

Which service do you want?

A life insurance policy with a low premium, or a workplace pension

A product or payment that helps someone stay anonymous

Countries

Where do you live and do business?

Lower-risk countries only

A country under sanctions, or one the FATF flags for weak AML controls

How they reach you

In person or online?

In person

Online, with no identity safeguard

Expected activity

What will you use it for, and why?

Fits the job or business on the form

No clear economic or lawful purpose

For a company client, rate the first row only after you verify the company and the people who own or control it.

Client One Comes Out Low

A financial adviser takes on a self-employed graphic designer. She lives and works in the adviser's country and wants a life insurance policy with a low premium. She verifies her passport online with a selfie, and the money comes from her own bank account.

This adviser's method rates that online ID check low, and every other factor is low too. As a low-risk client, she gets the standard checks, and her file is reviewed again when something changes.

Client Two Comes Out High

A lender takes on a small import company owned by a local family. Its main supplier is in a country the FATF has placed under increased monitoring, and the loan will fund payments there.

The family meets the lender in person, wants a standard business loan and expects payments that fit the company's trade. Those four factors rate low or medium.

Averaged, the five factors could land on medium. But the lender's written rule lets a tie to a country on that FATF list decide the rating alone. The file is rated high.

A high-risk customer usually gets enhanced due diligence, meaning more proof before approval. FFIEC examples include the source of funds and wealth, financial statements and details of major suppliers.

Events That Call for a New Rating

A low rating can stop being true once a new owner takes over. For US banks, an event sets off the update, not the calendar (FFIEC). Banks may still choose periodic reviews by risk.

EU rules add time limits from 10 July 2027. Firms must review a file when the client's circumstances change, and update it at least yearly under enhanced checks (Regulation (EU) 2024/1624, Article 26). For other clients, the limit is five years.

Events like these can call for a fresh customer risk assessment:

  • Large, unexplained changes in account activity
  • A new job or a change in business operations
  • A change in who owns the business
  • Red flags from suspicious activity monitoring
  • A law enforcement request
  • A negative news result
  • A long gap since the last review
  • The client refuses to give information or documents (AUSTRAC)

Every scoring decision and data change stays in our audit trail, with who made it and when. If you already have a written rating method, a demo call shows how its factors and thresholds can be set up in Clustdoc.

Frequently Asked Questions

What is a customer risk assessment?

A customer risk assessment rates each client for money laundering risk, and the rating sets how much checking the client gets. Each firm sets its own method.

AUSTRAC says yours must suit the nature, size and complexity of your business. US bank examiners say each bank assesses customer risk factors in its own way.

What are the 5 levels of risk rating?

There is no standard set of five. US bank examiners expect no set number of levels, since it depends on the bank's size and complexity. AUSTRAC's examples use three: low, medium and high.

How often should customer risk assessments be updated?

Whenever something material changes, such as new owners or unexplained activity. US bank rules set no fixed cycle, though your policy may set one by rating.

From 10 July 2027, EU rules require updated customer information at least yearly for clients under enhanced checks. For everyone else, the limit is five years.

What makes a customer high risk?

One serious factor can be enough, or several smaller ones together. AUSTRAC's high-risk examples include an unusually complex control structure, ties to high-risk countries and a foreign politically exposed person. Your written rule decides which factors count on their own.