Per customer, at onboarding and review

Customer Risk Assessment Checklist

How to rate a customer so the rating can explain itself later: assess the four factors separately, combine them deliberately, and record the reasoning while you still have it.

Last updated

Neoclassical facade with a sculpted pediment above a tall stone colonnade

Rate the factors separately, then combine them on purpose

The point of a risk rating is not the number. It is the ability to say, months later, why this customer received more or less scrutiny than another. That is only possible if the factors were assessed separately and combined by a rule someone chose.

1. Before you rate anything

  • Identity established and verified — a rating on an unverified identity rates nobody
  • Beneficial ownership established for entities, to the individuals
  • Screening run and any matches resolved, so the rating knows what it is rating
  • Purpose of the relationship recorded in the customer's own terms

2. Customer factor

  • Individual or entity, and if an entity, how transparent the structure is
  • PEP status, including close associates and family where relevant
  • Any adverse media, categorised by seriousness and recency rather than counted
  • Source of funds understood well enough to state in a sentence
  • For entities: how many layers between the customer and a named human

3. Product factor

  • Does the product move value, store it, or neither
  • Can it be used to move value across a border
  • Is there a cash component, or a cash-equivalent one
  • How quickly can a customer exit with funds
  • Has this product been used against you before

4. Channel factor

  • Face-to-face, remote, or introduced by a third party
  • If introduced, what the introducer verified and whether you have seen it
  • Whether the customer was ever physically present
  • For remote onboarding, what liveness or document authenticity check was applied

5. Jurisdiction factor

  • Country of residence, country of nationality, and country of operation — separately
  • Recognised indicators applied consistently, and the source named
  • Any jurisdiction in the ownership chain, not just the customer's own
  • Where funds originate, if different from where the customer is

6. Combine, and record

  • Apply the stated combination rule — not an unexamined average
  • Record the four factor ratings, not only the outcome
  • Record the one sentence that explains the outcome
  • If overridden, record who, why, and in which direction
  • Set the review date from the rating, and set the trigger list

7. What the file should show afterwards

A reviewer picking this file up cold should be able to answer, without asking anyone:

  • What did we know about this customer, and when
  • Which factor drove the rating
  • Who decided, and what they decided against
  • When we will look again, and what would make us look sooner

If any of those needs a conversation with the analyst who did the work, the file is incomplete regardless of whether the rating was right.

Questions

Common questions about customer risk assessment checklist.

Should a single high-risk factor make the whole customer high risk?
Not automatically, but the decision has to be deliberate and written down. If one high factor can be outweighed, state what outweighs it and why. The failure mode to avoid is an averaging model nobody chose: four factors quietly averaged so that a customer in a high-risk jurisdiction lands at medium because the other three are low.
Can a rating be overridden by a person?
Yes, and a model that cannot be overridden is worse, because the override happens informally instead. What matters is that overrides are recorded with a reason, are visible in reporting, and go up rather than down more often than not. A pattern of downward overrides is itself a finding.
How often should a rating be reviewed?
On a cycle set by the rating itself — higher risk, shorter cycle — and on a trigger list independent of the cycle. Triggers usually include a change of beneficial owner, a new jurisdiction, a screening hit, unusual activity, and any adverse media match.