Articles

How do you calculate a customer AML risk score?

A weighted customer risk model, worked customer by customer, and the arithmetic reason every model needs overrides.

A customer AML risk score is the weighted sum of scores for each risk factor: who the customer is, where it and its money are connected to, what products it uses and how it was onboarded. On an illustrative 1 to 5 scale with weights of 30, 30, 25 and 15 per cent, a domestic company owned from a high-risk third country scores 2.90, medium, below a high band starting at 3.0. No single factor can make a customer high risk in this model unless its weight reaches 50 per cent, which is why every weighted model needs overrides.

Worked in full in The EU AML Handbook by Julian R. Sterling, with every figure reproduced in a free workbook.See the book on Amazon →

The model and the assumptions

The model below is a typical starting design, not a prescribed one: the AMLR requires a risk-based approach and enhanced measures in defined cases, but it leaves the scoring method to the firm, which must justify it from its business-wide risk assessment. All weights, thresholds and customers are illustrative.

Illustrative customer risk model.
FactorWhat it capturesWeight
CustomerLegal form, ownership, occupation or sector, PEP status30%
GeographyResidence, incorporation, owners, counterparties30%
ProductProducts and services used, cash intensity, anonymity25%
ChannelFace to face, remote, introduced by a third party15%
Total100%

Each factor is scored from 1, lowest, to 5, highest. The weighted total is banded: below 2.0 is low, from 2.0 to below 3.0 medium, and 3.0 or above high.

The calculation step by step

Risk score = 30% x customer + 30% x geography + 25% x product + 15% x channel

Customer C: 30% x 2 + 30% x 5 + 25% x 2 + 15% x 2 = 0.60 + 1.50 + 0.50 + 0.30 = 2.90, medium

In Excel, with weights in B2:E2 and a customer's scores in B5:E5: =SUMPRODUCT($B$2:$E$2,B5:E5), and the band =IF(F5>=3,"High",IF(F5>=2,"Medium","Low"))

Four customers through the model.
CustomerCustomerGeographyProductChannelScoreBand
A, salaried resident, current account, opened online0.300.300.250.301.15Low
B, import company, trade finance, online0.900.901.000.453.25High
C, local company, owner in a high-risk third country0.601.500.500.302.90Medium
D, PEP, private banking, met in person1.500.300.750.152.70Medium

The cells are weighted contributions, not raw scores. Customer B, with moderate risk everywhere and nothing extreme, comes out high. Customers C and D, each carrying one risk of the kind for which the AMLR requires enhanced due diligence, come out medium. The model ranks diffuse risk above concentrated risk, which is not the ordering the regulation asks for.

Why a weighted average dilutes the worst factor

Put one factor at 5 and every other factor at the minimum of 1. The score is 1 plus the factor's weight times 4. To reach the high band at 3.0, that weight must be at least 50 per cent.

Score when a single factor is at maximum and the rest at minimum.
Factor at 5WeightScoreBand
Customer30%2.20Medium
Geography30%2.20Medium
Product25%2.00Medium
Channel15%1.60Low
Customer and geography both at 560%3.40High

For customer C to reach the high band on its own merits, its other three factors would need to average 2.14, a customer that is already somewhat risky. A model built this way cannot, by construction, rate a single-risk customer high. That is not a calibration problem to be fixed by nudging weights; it is a property of averaging.

Test any customer risk model with one factor at maximum and the others at minimum. If the result is not high, the model depends entirely on its overrides, and the overrides need to be documented, tested and reported as carefully as the weights.

Two ways to fix it

Most firms use both: overrides for the legally mandated cases and a floor so that a factor the firm itself considers severe cannot be averaged away.

The common mistake

The frequent error is validating a model by checking that the portfolio distribution looks reasonable, for instance a few per cent high risk, without testing single-factor cases. A distribution can look right while the model systematically misses concentrated risks, because those customers are rare. The second error is letting overrides live outside the model, in a manual process, so that the reported high-risk population and the scoring output disagree and nobody can explain the difference to a supervisor.

Takeaway

Weight, add and band: 2.90 for a domestic company owned from a high-risk third country. Then test the extremes, because a weighted model with no factor above 50 per cent cannot rate a single risk high without an override or a floor. The rating drives review frequency, and the effort that follows is sized in how many KYC periodic reviews a year the AMLR implies. The book's working documents and the back-book model are in the free workbook for this book.

Questions readers ask

What weights should a customer risk scoring model use?

There is no regulatory set of weights; the firm must justify its own from its business-wide risk assessment. Whatever they are, test them: with the illustrative 30, 30, 25 and 15 per cent, the highest score a single maximum factor can produce is 2.20, below a high threshold of 3.0, so overrides must catch single-factor high risks.

Why does a PEP not score as high risk in a weighted model?

Because a weighted average dilutes one extreme factor with several ordinary ones. An illustrative PEP with a customer score of 5 but low geography and channel scores comes out at 2.70, medium. Under the AMLR, PEP relationships require enhanced due diligence whatever the model says, so firms normally override the rating to high to keep the rating and the measures applied consistent.

What is a risk score floor in AML scoring?

A rule that the final score cannot be lower than a set distance below the customer's worst factor. With a floor of the highest factor minus 2, any customer with a factor at 5 scores at least 3.00, which lifts the illustrative customer at 2.90 and the PEP at 2.70 into the high band without changing anyone else.

Read the whole case

This article is one calculation from The EU AML Handbook. The book takes the same case from first principles to the decision, chapter by chapter, and every figure it prints is a live formula in the free companion workbooks.

Get the book on Amazon →Free companion files

Also on Amazon UK · Amazon Germany · Amazon France · Amazon Canada

Also on this site

Reading guide: regulation, compliance and banking → · All 453 articles →

If this book helped, or didn’t, a few lines on Amazon are worth more than they look: they are what the next reader goes on. Write a review. The workbook stays free either way.