Discover the most common weaknesses in customer risk scoring frameworks and learn how to build a dynamic, risk-based model that withstands regulatory scrutiny.
Financial institutions spend considerable time designing customer risk scoring frameworks. These frameworks influence customer due diligence (CDD/EDD), transaction monitoring, periodic reviews and ongoing monitoring. They also determine how compliance resources are allocated across the customer base.
Despite their importance, customer risk scoring remains one of the most common weaknesses identified during independent AML audits. The problem is rarely the absence of a risk scoring framework. Most organizations have one. The issue is that the framework no longer reflects the institution’s actual money laundering and terrorist financing (ML/TF) risks.
An outdated customer risk score creates a domino effect. Customers may receive the wrong level of due diligence. Transaction monitoring thresholds may no longer be appropriate. High-risk customers may not receive timely reviews. Eventually, weaknesses in customer risk assessment begin affecting the entire AML compliance program.
Global regulators continue to emphasize this point. The Financial Action Task Force (FATF) expects financial institutions to identify, assess and understand ML/TF risks so that controls remain proportionate to the level of risk. Similar expectations appear throughout guidance issued by FinCEN, the European Banking Authority (EBA), the UK‘s Financial Conduct Authority (FCA) and the FFIEC BSA/AML Examination Manual.
This article explains why customer risk scoring frameworks fail during AML audits and provides practical guidance for building a framework that supports effective risk-based compliance.
Customer risk scoring is the foundation of a risk-based AML program
Many organizations still treat customer risk scoring as an onboarding exercise. Once KYC is completed, the customer receives a Low, Medium or High risk rating that remains unchanged until the next scheduled review.
An effective AML program does not work this way. Customer risk scoring should evolve throughout the customer relationship. New products, higher transaction volumes, changes in beneficial ownership, adverse media or geographic expansion should all influence the customer’s overall risk profile.
When designed correctly, customer risk scoring strengthens every major AML control.
- Customer Due Diligence (CDD and EDD) – Determines the level of verification and documentation required.
- Transaction monitoring – Supports appropriate monitoring scenarios and alert thresholds.
- Sanctions and adverse media screening – Helps determine review frequency and escalation priorities.
- Periodic KYC reviews – Supports risk-based review cycles rather than fixed timelines.
- Governance and approval workflows – Determines escalation requirements for higher-risk relationships.
When customer risk scoring becomes inaccurate, every downstream control becomes less effective.
Why customer risk scoring frameworks fail
Most failures develop gradually rather than overnight. Business models evolve, new products are introduced and regulatory expectations increase. Unfortunately, the customer risk methodology often remains unchanged.
Static risk scores
The most common weakness identified during AML audits is static customer risk ratings. A customer may initially present relatively low risk. Over time, transaction values increase significantly. New jurisdictions appear. Additional products are used. Despite these changes, the customer continues to carry the same risk rating assigned during onboarding.
The FCA has observed that some firms maintained risk assessment processes that were not sufficiently dynamic, resulting in outdated customer risk profiles that influenced wider compliance decisions. Customer risk scoring should reflect today’s risk rather than the customer’s circumstances several years earlier.
Poor customer information
Another common issue begins during onboarding. Many organizations collect only enough information to satisfy minimum identification requirements. Important information such as expected account activity, source of funds, occupation, business purpose, ownership structure or anticipated transaction behavior may be incomplete.
Without meaningful customer information, meaningful customer risk assessment becomes impossible.
Inherent risk pillars should not operate in isolation
Most customer risk scoring methodologies begin with four core inherent risk pillars:
- Customer risk
- Geographic risk
- Product and service risk
- Delivery Channel Risk
These remain essential components of every framework. However, problems arise when organizations rely exclusively on these factors while ignoring customer behavior.
For example, two customers may both operate in the same country and use identical products. One customer performs routine domestic transactions. The other begins receiving unusually large international transfers involving higher-risk jurisdictions. (Read the update on FATF grey list).
If behavioral information does not influence the risk score, both customers may continue receiving identical risk ratings despite presenting very different ML/TF risks.
The FFIEC BSA/AML Examination Manual makes this expectation clear.
No single indicator should determine whether a customer presents lower or higher risk. Institutions should consider multiple risk factors before assigning an overall customer risk rating. Effective customer risk scoring therefore combines inherent risk with ongoing behavioral indicators.
Risk clustering: When everyone becomes “Medium Risk”
One of the clearest indicators of a weak customer risk scoring framework is risk clustering. Some organizations unintentionally classify most customers as Medium Risk. While this may appear balanced, it usually indicates that the methodology lacks sufficient differentiation.
Risk clustering creates several operational challenges.
- High-risk customers may not receive Enhanced Due Diligence.
- Low-risk customers may receive unnecessary reviews.
- Compliance teams spend time investigating customers who present relatively limited ML/TF exposure while genuinely higher-risk relationships receive insufficient attention.
A mature customer risk framework should produce meaningful differentiation based on actual customer characteristics and behavior rather than forcing customers into a narrow range of scores.
Regulatory lessons from recent enforcement actions
Enforcement actions demonstrate that customer risk scoring failures rarely exist in isolation.
In October 2024, FinCEN issued a consent order against TD Bank identifying significant deficiencies within the bank’s customer risk rating system. According to the consent order, longstanding weaknesses affected the bank’s ability to monitor higher-risk customers effectively. Regulators found that the bank failed to adequately consider large cash deposits when assessing customer risk, resulting in customer profiles that no longer reflected actual money laundering risk.
Similarly, FinCEN’s joint 2026 enforcement action against Canaccord Genuity LLC demonstrated the risks of treating customer risk as a static onboarding exercise. The firm failed to reassess customer risk despite significant changes in customer activity and financial profile. Regulators also identified weaknesses in transaction surveillance governance, including automated trade surveillance exception reports that remained unreviewed for extended periods. Together, these deficiencies reduced the firm’s ability to identify and respond effectively to higher-risk activity.
Both cases reinforce the same lesson – Customer risk assessment should continuously support transaction monitoring rather than operate as a separate compliance process.
A practical example
Consider a fintech customer who opens an account as a domestic software consultant with expected monthly transactions of USD 8,000. Based on the available information, the customer receives a Medium Risk rating.
Eighteen months later, monthly transaction volumes exceed USD 300,000. Payments begin arriving from several jurisdictions presenting elevated ML/TF risk. The customer also starts transferring funds to multiple virtual asset service providers.
If the customer risk score remains unchanged, the institution may continue applying standard due diligence, routine transaction monitoring thresholds and a three-year review cycle.
A mature AML program would respond differently. The institution would reassess customer risk, perform Enhanced Due Diligence, review source of funds information, recalibrate transaction monitoring scenarios and shorten the periodic review cycle.
The customer’s behavior changed. The customer risk score should change as well.
Building a stronger customer risk scoring framework
Organizations do not always need to replace their existing framework. In many cases, targeted improvements produce significant benefits.
A practical approach includes:
- Reviewing whether current risk factors remain aligned with the enterprise-wide ML/TF risk assessment.
- Improving customer data quality during onboarding and ongoing due diligence.
- Introducing event-driven customer risk reviews alongside periodic reviews.
- Regularly validating scoring methodologies using independent reviewers.
- Reviewing risk factor weightings as products, services, delivery channels and financial crime typologies evolve.
- Strengthening governance around model changes, overrides and periodic validation.
Customer risk scoring should remain a living framework that evolves alongside the institution’s business model and risk exposure.
Final thoughts
Customer risk scoring is often viewed as a technical calculation. In reality, it is one of the most important governance tools within an AML compliance program. A well-designed framework enables institutions to apply proportionate controls, allocate compliance resources effectively and demonstrate a genuine risk-based approach during regulatory examinations and independent AML audits.
Conversely, an outdated or poorly governed framework weakens customer due diligence, transaction monitoring and ongoing monitoring while increasing regulatory risk.
At Compliance7, we regularly support financial institutions, fintechs, virtual asset service providers (VASPs), Designated non-financial businesses and professions (DNFBPs) and other regulated businesses in reviewing customer risk scoring methodologies, validating AML frameworks and strengthening risk-based compliance programs. Independent reviews frequently identify practical improvements that enhance both compliance effectiveness and operational efficiency.
If your organization has not reviewed its customer risk scoring framework recently, now is an appropriate time to assess whether it continues to reflect your current risk profile and regulatory obligations.
Disclaimer: This article is provided for informational purposes only and should not be considered legal or regulatory advice. Organizations should assess their own regulatory obligations, business model and risk profile before implementing changes to their AML compliance program.



