Customer risk rating and scoring your examiner can follow, factor by factor.
A six-factor risk-scoring model across country, industry, product, delivery channel, customer behaviour and PEP or sanctions exposure, with configurable weights and risk bands, four-eyes approval on every override and periodic reviews scheduled by risk band, so every rating has a reviewable history.
Inside the module.
Six risk factors
Country, industry or business type, product, delivery channel, customer behaviour, and PEP or sanctions exposure, each weighted and banded to match your risk assessment.
Configurable without code
Weights and risk bands are configuration, so compliance can change the model as the business or the national risk assessment changes.
Four-eyes overrides
Any manual override of a rating needs a second authorised reviewer, and the reason is recorded, so the rating you present to an examiner has a controlled history.
Reviews scheduled by risk band
Periodic reviews are scheduled automatically by risk band, and high-risk customers go into an enhanced due diligence workflow, so a high-risk file does not go stale.
Beneficial owners in the picture
Entity resolution and a beneficial-owner graph link legal-entity customers to the people behind them, so exposure flows into the rating.
Explainable scores
Where AI scoring is used, every score shows its top three reasons and a confidence level, and a person accepts, modifies or rejects it.
Risk-based duties, country by country
Every FATF-aligned law asks institutions to understand and rate their customers' risk and to apply more scrutiny where it is higher. How each country frames that duty, in the terms our country pages use:
| Country | The duty | Where it sits |
|---|---|---|
| Kenya | Identify customers and their beneficial owners, rate their risk, and apply enhanced due diligence to higher-risk customers | POCAMLA and the POCAML Regulations, 2023 |
| South Africa | Document, maintain and implement a Risk Management and Compliance Programme, and apply its customer due diligence | Section 42 of the FIC Act |
| UAE | Identify, assess, document and keep updating ML/TF risks, and set the scope of customer due diligence by risk, with regard to the national risk assessment | Article 19 of Federal Decree by Law No. 10 of 2025 |
| Nigeria | Enhanced measures for PEPs and higher-risk relationships, within each regulator's AML/CFT rules | Section 4 of the MLPPA 2022; CBN, SEC and NAICOM regulations |
Summaries of each country page's verified facts; the country pages give the statutory sources. Not legal advice.
Frequently asked questions.
What is customer risk rating in AML?
Scoring each customer's money-laundering and terrorist-financing risk from factors such as geography, industry, product, channel, behaviour and PEP or sanctions exposure, then banding the scores so that higher-risk customers get more scrutiny and more frequent reviews.
Is customer risk scoring the same as a risk assessment?
They are linked. The institution's risk assessment decides which factors matter and how much; customer risk rating applies that judgement to each customer, consistently, and keeps the evidence.
Can compliance change the model without IT?
Yes. Weights and risk bands are configuration, and every change and every override is recorded, with overrides needing four-eyes approval.
How often are customers reviewed?
As often as your policy sets for each risk band: periodic reviews are scheduled automatically by band, and high-risk customers are reviewed through the enhanced due diligence workflow.
Is risk rating in the entry tier?
Yes. The Starter tier covers screening, customer risk rating and case basics, so a smaller institution can start with a defensible rating model and add monitoring later.
See it on your own data.
Bring your own scenarios to a live demo of the AML compliance software, tuned to your sector and the country you report in.