Customer Risk Profiling
Customer risk profiling is the assessment that assigns each customer a risk rating, which then determines how much due diligence they receive and how closely they are monitored. It is the mechanism that makes a risk-based AML program risk-based — and the thing examiners look at first when a program fails.
| Also called | Customer risk rating, customer risk assessment, CRR |
| Purpose | Decide the depth of due diligence and monitoring each customer receives |
| Typical output | A tier — low, medium, high — or a numeric score |
| Common factors | Customer type, geography, products used, delivery channel, transaction patterns, PEP status |
| Regulatory basis | The risk-based approach in FATF Recommendation 1 |
| When assigned | At onboarding, then refreshed on triggers and on a cycle |
| Drives | Simplified, standard, or enhanced due diligence, and monitoring intensity |
| Common weakness | Profiles assigned at onboarding and never revisited |
| Examination focus | Whether the methodology is documented and consistently applied |
How it works
A profile is built from factors the institution has decided are predictive, weighted according to its own risk assessment. The usual families are the customer themselves — individual or entity, occupation, ownership structure, PEP status; the geography they connect to; the products they use, since some carry more laundering risk than others; the channel they arrived through, with remote onboarding generally rated higher than in-person; and their observed behavior once active.
The output drives everything downstream. A low-rated customer may receive simplified due diligence and periodic review; a high-rated one receives enhanced due diligence, senior sign-off, and closer monitoring. That is the entire point of a risk-based approach — finite compliance resource pointed where the risk is.
Two failure patterns recur. The first is static profiling: a rating assigned at onboarding and never revisited, so a customer whose behavior changed two years ago is still monitored as though nothing did. The second is uniform profiling: a methodology that in practice rates almost everyone medium, which produces the appearance of a risk-based program with none of the discrimination that makes one useful.
Examiners look at the methodology rather than the outcome. Is it documented, is it applied consistently, does the distribution of ratings make sense given the customer base, and can the institution explain why a particular customer sits where they do.
Why it matters for identity verification
A risk profile is only as good as the identity it describes, and the dependency is more direct here than almost anywhere else in AML.
Nearly every profiling factor is an attribute of the customer: who they are, where they are, what they do. All of it comes from onboarding. If the identity was never verified, the profile is built from self-reported claims — and a customer with something to hide will report whatever produces a low rating. The institution then applies reduced due diligence and lighter monitoring to exactly the customer who warranted more.
That failure is quiet, which is what makes it dangerous. Nothing alerts. The program appears to be functioning: profiles exist, tiers are assigned, monitoring runs. The distribution looks reasonable. What has actually happened is that the highest-risk customers self-selected into the lowest tier.
Verified identity closes that loop. An authenticated document establishes nationality, date of birth and name as facts rather than claims, and the profile built on them describes a real person. Behavioral and device signals then supply the observed half, and Microblink’s KYC and AML workflow feeds both into the rating rather than leaving it resting on a form.
Risk profiling vs transaction monitoring
| Customer risk profiling | Transaction monitoring | |
|---|---|---|
| What it assesses | The customer | Their activity |
| When | At onboarding, then on review | Continuously |
| Output | A risk tier or score | Alerts on specific activity |
| Drives | How much due diligence and monitoring applies | Investigation and SAR decisions |
| Time horizon | The relationship | The transaction or period |
| Dependency | Verified identity attributes | An accurate expected-activity profile |
The two are sequential rather than parallel. Profiling sets the monitoring thresholds, so a wrong profile produces monitoring calibrated to the wrong expectation — and monitoring cannot detect that its own baseline is wrong.
What it can’t do
It cannot predict individual behavior. A risk rating is an actuarial judgment about a category, not a forecast about a person. Most high-rated customers never launder anything, and some low-rated ones do.
It cannot work on unverified data. Every factor except observed behavior comes from what the customer told you at onboarding. Unverified, the profile describes a claim rather than a customer.
It cannot stay accurate without refresh. Circumstances change — ownership, geography, activity, PEP status. A profile that is never revisited describes a customer who no longer exists, and this is the single most common finding in this area.
It cannot substitute for judgment on individual cases. A low-rated customer doing something obviously wrong still requires action. Programs that treat the rating as a ceiling on scrutiny rather than a floor get into difficulty.
Frequently asked questions
What factors go into a customer risk profile?
Customer type and occupation, geographic exposure, the products and services used, the delivery channel, PEP status, and observed transaction behavior. Weightings come from the institution’s own risk assessment rather than from a standard template.
How often should customer risk profiles be reviewed?
On a risk-based cycle — more frequently for higher-rated customers — and on trigger events such as a change in ownership, a significant shift in activity, or adverse information surfacing. Fixed periodic review with no trigger-based refresh is a frequent examination finding.
What is the difference between customer risk profiling and transaction monitoring?
Profiling assesses the customer and sets how much scrutiny they receive. Monitoring watches their activity against expectation. Profiling comes first and calibrates monitoring, so an inaccurate profile misconfigures everything downstream.
Why do most customers end up rated medium risk?
Usually because the methodology lacks discriminating factors or the weightings are too flat. A distribution clustered in one tier defeats the purpose of a risk-based approach and is something examiners look for directly.
Related reading
- Enhanced due diligence — what a high rating triggers
- Customer due diligence — the obligation profiling calibrates
- AML red flags — what monitoring looks for once thresholds are set
- Compliance officer — who owns the methodology at examination