Customer risk rating is how a firm scores the money laundering risk of a single customer. The rating, usually low, medium, or high, decides how much due diligence to apply and how closely to monitor the relationship. It puts the risk-based approach into practice at the customer level.

Key takeaways

  • Customer risk rating scores the laundering risk of one customer.
  • The rating drives how deep the checks and how close the monitoring should be.
  • Common factors are identity, occupation, PEP status, geography, product, and behavior.
  • Ratings are usually low, medium, or high, each with its own treatment.
  • Ratings should be dynamic, updated as behavior and circumstances change.
  • It applies the risk-based approach to individual relationships.

2012

Year the FATF made the risk-based approach central

Source: FATF

$800B to $2T

Laundered worldwide each year that ratings help catch

Source: UNODC

$3B

Paid by TD Bank in 2024 after control gaps

Source: US Department of Justice

What is customer risk rating?

Customer risk rating is the score a firm gives a single customer to show how much money laundering risk they carry. It is worked out at onboarding and kept up to date through the relationship.

The score is not a judgment of character. It is a measure of exposure, based on factors such as who the customer is, what they do, and where they operate.

The rating then sets the level of scrutiny. Read more: it applies the firm-wide AML risk assessment to one relationship.

Why firms rate customer risk

Firms rate customer risk to spend effort where it is needed. Treating every customer the same wastes attention on low-risk relationships and under-watches dangerous ones.

The rating is the engine of the risk-based approach. It decides how much customer due diligence to apply, whether enhanced due diligence is needed, and how often to review the relationship.

It also creates a record. If a regulator asks why a customer was treated a certain way, the rating and its reasoning are the answer.

The alternative is worse for everyone. Without a rating, a firm either over-checks harmless customers, which frustrates them and wastes staff time, or under-checks risky ones, which is how laundering slips through.

Turn customer details into a risk rating

Enter a few details about a customer and get an indicative money laundering risk level to guide your due diligence.

Try the Customer Risk Calculator →

Customer risk factors

A rating combines several factors, not one. Each can push the score up or down, and they are weighed together.

  • Identity and ownership. How clearly the customer and any beneficial owner can be identified.
  • Occupation and business. Whether the customer works in a higher-risk sector, such as a cash-intensive business.
  • PEP status. Whether the customer is a politically exposed person or a close associate.
  • Geography. Whether the customer or their funds touch a high-risk country.
  • Products used. Whether the products favor anonymity or fast movement of funds.
  • Expected behavior. The size, frequency, and type of activity the customer is likely to run.
Worth knowing. A single high-risk factor should not automatically make a customer high risk, and a pile of low-risk factors should not bury one serious red flag. Rating well means weighing factors together, which is why a purely mechanical score, with no room for judgment, tends to produce both false alarms and blind spots.

How customer risk rating works

Rating a customer follows a clear sequence. It turns information into a score and a treatment.

  1. Collect information. Gather identity, ownership, occupation, and expected activity.
  2. Screen the customer. Check against sanctions, PEP, and adverse media data.
  3. Score the factors. Rate each factor, then combine them into an overall level.
  4. Apply the treatment. Set the due diligence and monitoring the level requires.
  5. Record the reasoning. Document how the rating was reached.

Use the tool: screen a customer as part of this step with Combined AML Screening.

What each rating level means

The rating level decides how the firm treats the customer. The three common bands map to three levels of effort.

Rating Due diligence Monitoring
Low Simplified checks Lighter, periodic review
Medium Full customer due diligence Standard ongoing monitoring
High Enhanced due diligence and sign-off Closer, more frequent monitoring

High risk means more scrutiny, not automatic refusal. Declining whole groups of customers to avoid effort is de-risking, which regulators discourage, because it pushes activity into channels no one is watching.

Examples of customer risk levels

A few short examples show how the factors combine into a rating. None is a hard rule, because context always changes the picture.

  • Low risk. A salaried local customer using everyday products, based in a low-risk country, whose identity is clear and whose activity is small and predictable.
  • Medium risk. A small business with moderate cash takings and customers in several countries, where ownership is clear but the activity is varied.
  • High risk. A customer who is, or is closely linked to, a politically exposed person, where the source of wealth needs checking.
  • High risk. A cash-intensive business based in, or trading heavily with, a high-risk country, where funds are harder to trace.

The rating is a starting point, not a verdict on the customer. A high rating means closer checks and monitoring, while a low rating still calls for ongoing awareness in case behavior changes.

Applied consistently, these levels make a firm’s decisions explainable. If one customer faces deeper checks than another, the rating and its factors show exactly why.

Screen a customer as you rate them

Run one search across sanctions, PEP, and adverse media data to feed real signals into the rating.

Try Combined AML Screening →

Dynamic risk rating

A rating is not fixed at onboarding. Customers change, and their risk changes with them, so the score should move too.

A rating should be reviewed on a schedule tied to its level, and re-checked whenever something shifts. A change in behavior, a new monitoring alert, a move into a new country, or a change in ownership can all warrant a re-rating.

Common mistakes

Ratings go wrong in a few familiar ways. Avoiding them keeps the score meaningful.

  • A static score. A rating set once and never revisited stops reflecting the customer.
  • Mechanical scoring. A model with no room for judgment misses context.
  • No reasoning. A level with no written logic cannot be defended.
  • Ignoring behavior. Onboarding data alone misses how a customer actually acts.
  • Ratings that only fall. A score that is only ever lowered, never raised, is a warning sign in itself.

Get an indicative AML risk rating for your firm

See where your money laundering risk is concentrated across customers, products, channels, and geographies.

Try the AML Risk Assessment →

Frequently asked questions

What is customer risk rating?

Customer risk rating is the score a firm gives a single customer to show how much money laundering risk they carry. It is set at onboarding and updated through the relationship. The rating, usually low, medium, or high, decides how much due diligence to apply and how closely to monitor the customer.

Why do firms rate customer risk?

Firms rate customer risk to focus effort where it is needed, rather than treating every customer the same. The rating drives how much customer due diligence to apply, whether enhanced due diligence is needed, and how often to review the relationship. It also records why a customer was treated a certain way.

What factors affect a customer’s risk rating?

The main factors are identity and ownership, occupation and business type, politically exposed person status, geography, the products used, and expected behavior. Each can raise or lower the score, and they are weighed together. A single high-risk factor should not automatically make a customer high risk on its own.

What are the levels of customer risk rating?

The common levels are low, medium, and high. Low risk gets simplified checks and lighter monitoring. Medium risk gets full customer due diligence and standard monitoring. High risk gets enhanced due diligence, senior sign-off, and closer monitoring. High risk means more scrutiny, not an automatic refusal to onboard the customer.

How is a customer risk rating calculated?

A firm collects identity, ownership, occupation, and expected activity, then screens the customer against sanctions, PEP, and adverse media data. It scores each risk factor and combines them into an overall level. That level sets the due diligence and monitoring, and the reasoning behind the rating is recorded.

What is a dynamic customer risk rating?

A dynamic risk rating is one that changes as the customer changes, rather than staying fixed at onboarding. It is reviewed on a schedule tied to its level and re-checked when something shifts, such as a change in behavior, a monitoring alert, a move into a new country, or a change in ownership.

What is the difference between customer risk rating and an AML risk assessment?

A customer risk rating scores a single customer, while an AML risk assessment looks at the whole firm. The firm-wide assessment sets the framework, deciding which customer types, products, and countries are risky. The customer rating applies that framework to one relationship, so the two work together.

What does a high-risk customer rating mean?

A high-risk rating means the customer carries more money laundering risk, so the firm applies enhanced due diligence, senior sign-off, and closer monitoring. It does not mean the customer must be refused. With the right controls, a high-risk customer can still be onboarded, and the rating explains why the extra scrutiny applies.

How often should a customer risk rating be reviewed?

A rating should be reviewed on a schedule tied to its level, with high-risk customers reviewed more often. It should also be re-checked whenever something changes, such as unusual activity, a monitoring alert, a new country link, or a change in ownership. A rating set once and never revisited becomes inaccurate.

Can a customer risk rating change over time?

Yes. Ratings should be dynamic, because customers and their circumstances change. A customer rated low at onboarding may become higher risk if their behavior shifts, they move into a new market, or their ownership changes. Reviewing and updating ratings keeps them useful and defensible.

What is the role of screening in customer risk rating?

Screening checks a customer against sanctions, politically exposed person, and adverse media data as part of the rating. A match, or a link to a higher-risk category, raises the score and can trigger enhanced due diligence. Screening is repeated over time, because lists and a customer’s status can change.

How does customer risk rating relate to due diligence?

The customer risk rating decides how much due diligence to apply. A low rating supports simplified checks, a medium rating calls for full customer due diligence, and a high rating requires enhanced due diligence. The rating and the due diligence are linked, so the level of checks always matches the assessed risk.

Read more: our ultimate guides, whitepapers and templates

Related guides and resources to help you act on what you just read.

Last reviewed July 12, 2026 · 10 min read · Written for compliance and risk professionals · By the WhoWiki editorial team

Key takeaway: customer risk rating scores one customer’s laundering risk, and that score decides how deep the checks and how close the monitoring should be.

Learn & stay current

A compliance reference that keeps up with the regulators

Plain-English explainers, country rules, and data you can cite, updated as the landscape moves.

Comparing tools before you commit?

See how WhoWiki lines up against the platforms you already know, and which free tools fit which job.

See how current your screening could be

Book a walkthrough with our team, or start with the tools today. No account needed to run your first check.