Two customers start the same onboarding flow. One is a salaried employee with a stable local income and intentions to use your services for transfers to friends and relatives. The other plans to use the service for gambling and crypto transfers, with much higher expected turnover. Their IDs may both be genuine, but the AML compliance questions they raise are different.
That’s the basic idea behind a risk-based approach: the wider customer context can call for a different level of review.
From there, the path can split. One customer may continue through the standard KYC flow, while another is asked for more information, sent for enhanced due diligence or manual review, or declined altogether.
Key takeaways:
-
Risk-based KYC applies different levels of scrutiny based on customer risk.
-
Customer risk scores typically combine multiple signals, such as jurisdiction, customer profile, product exposure, delivery channel, and expected activity.
-
Customer risk assessment methodology determines how relevant risk factors are evaluated and weighted to produce a customer risk score.
-
Risk appetite defines which levels and types of risk the company is willing to accept, which require additional controls or escalation, and which fall outside its acceptance criteria.
-
Identity verification provides part of the evidence, alongside compliance screening and other customer data.
What is a risk-based approach in KYC and AML?
A risk-based approach (RBA) adjusts the level of scrutiny to the level of risk associated with a customer. Instead of applying the same controls to every case, companies can use customer risk scores to distinguish between lower-risk relationships and those that require stronger controls.
Typically, customers can have one of these risk levels:
-
Low risk
-
Medium risk
-
High risk
Separately, certain relationships may be classified as prohibited or outside the company’s risk appetite because they trigger predefined exclusion criteria or legal restrictions. These conditions can operate as hard stops regardless of the customer’s numerical risk score.
The assigned risk score then becomes an input into the KYC process: it affects how much information is collected, whether additional checks are triggered, and whether a case needs escalation.
The logic follows the framework developed by the Financial Action Task Force (FATF), the international body that sets global standards for combating money laundering and terrorist financing. FATF treats the risk-based approach as a core principle of AML/CFT compliance: organizations are expected to assess relevant risks and apply measures proportionate to them.
Subscribe to receive a bi-weekly blog digest from Regula
Which factors influence customer risk?
Customer risk assessments commonly consider four broad categories of potential risk signals: customer, product or service, delivery channel, and geography.
| Risk category | What it covers |
|---|---|
| Customer risk | Customer type, PEP status, source of wealth (SOW) or funds (SOF), nature of business (NOB), ownership structure, adverse information |
| Product or service risk | Anonymous products, confidential services, complex financial instruments, high-speed or high-volume transfers, any innovative or newly introduced products |
| Delivery channel risk | How the customer accesses the service, including non-face-to-face (remote) or intermediary-based onboarding |
| Geographic risk | FATF gray- or black-listed jurisdictions, countries with high corruption or weak AML regimes, sanctioned countries, conflict zones, jurisdictions with high terrorism risk, etc. |
The exact signals depend on the customer type and business model.
For an individual, the assessment may draw on several sources. Identity data provides attributes such as citizenship, country, and age. Onboarding questions can cover employment, expected turnover, purpose of the relationship, and source of wealth. Other signals may come from PEP status, IP location, or links to blocked accounts.
For a company, it may also include the country of incorporation, legal entity type, nature of business, company age, ownership complexity, UBO information, expected turnover, and online presence.
These factors have a compound effect: a single signal may have little impact on the final customer risk score, whereas several moderate-risk indicators can materially affect the overall assessment.
What is the risk appetite, and how does it shape customer risk scoring?
Risk appetite describes the level and types of risk a company is ready to tolerate. In practice, it serves as a boundary for customer acceptance.
Risk appetite is typically formalized so that compliance teams and automated systems can apply the same logic consistently. Turkish Akbank, for example, publishes a compliance risk appetite statement that classifies its risk appetite across different stages of the customer value chain:
Akbank’s Risk Appetite Statement is reviewed periodically by the Board of Directors, and the bank requires its strategic and business plans to remain consistent with it. Source: Akbank
What exactly a company considers a risk factor depends on its market, industry, and product. For example, a gambling company may translate its risk appetite into operational rules and controls covering:
-
Top-ups: should cash top-ups be permitted or not?
-
Wagering requirements: what is the deposit/bonus amount that must be wagered before a withdrawal can be made?
-
Card limit: how many different bank cards does it take before the account is blocked?
-
Failed deposits: how many failed attempts from different cards are allowed before the account is blocked?
Companies often draw on regulatory guidance, international standards, and external risk indicators when defining their risk appetite:
-
FATF gray and black lists of jurisdictions subject to enhanced monitoring or a call for action
-
The Basel AML Index — a basis for assessing geographical risk
-
Corruption Perceptions Index (CPI) by Transparency International
Local laws, regulatory guidance, sanctions regimes, and national risk lists can be just as important. In the US, for example, OFAC maintains broad Cuba-related sanctions. A US person or company may be prohibited from dealing with certain Cuban parties even if the same relationship wouldn’t be treated the same way under another country’s rules.
Where regulation doesn’t prescribe a hard stop, companies still have room to interpret risk through their own appetite. For example, the same customer from a jurisdiction with weak AML controls and a high risk of corruption may receive different treatment at two fintechs. One may request additional information or route the case for manual review. Another may decide that the jurisdiction falls outside its risk appetite.
How does customer risk scoring work in practice?
Consider a company incorporated in the British Virgin Islands in 2025. Its business is art dealing and trading, with an expected monthly turnover of $100,000–$120,000.
Here is how that profile could be assessed under a risk-based model:
- Jurisdiction: As of June 2026, the BVI is on the FATF gray list (a significant geographic risk factor)
- Nature of business: Art dealing and trading (carries higher risk because artwork prices are often subjective and difficult to benchmark, which makes it easier to disguise the true value of a transaction or move illicit funds through apparently legitimate sales)
- Expected turnover: $100,000–$120,000 per month may trigger an additional document request
- Company age: A recently established company with a short operating history adds another risk signal
- Ownership / UBOs: A simple, transparent ownership structure may reduce concern; a complex or opaque one may increase it
Customer risk scoring separates two things: how much a parameter matters overall (weight) and how risky the customer’s specific value for that parameter is (score). For example:

The final score would be calculated as a weighted sum:
(90 × 0.6) + (85 × 0.2) + (55 × 0.1) + (80 × 0.1) = 84.5
If the company defines 0–33 as Low Risk, 34–66 as Medium Risk, and 67–100 as High Risk, this customer would fall into the High Risk category.
The numbers here are illustrative. The weights, thresholds, and treatment of specific signals depend on the company’s risk appetite and scoring methodology.
What can identity verification contribute to risk assessment?
Before a customer can be assigned a risk level, the company needs enough information to assess them. Identity verification supplies part of the evidence that the scoring model can use alongside broader compliance data.
Depending on the workflow, it can provide or validate signals such as:
-
Document type and сountry of issue
-
Nationality
-
Date of birth
-
NFC chip data and document authenticity
-
Consistency of identity data across document fields and sources
-
Biometric face match
-
Liveness
-
Other device or session-level signals available in the verification flow
Identity verification contributes an important layer of evidence to customer risk assessment, but the full picture usually draws on additional sources. Expected turnover, occupation, source of funds, nature of business, PEP or sanctions status, adverse media, and transaction behavior may come from onboarding questionnaires, screening systems, third-party databases, internal records, or ongoing monitoring.
How do you build your risk appetite into the verification workflow?
Once a risk level has been assigned, it can be used to shape the verification workflow: whether the customer gets automatically onboarded, needs additional checks, or requires another action later in the lifecycle.
A workable setup may include:
-
A baseline onboarding flow for all customers
-
Step-up checks when specific thresholds or combinations of signals trigger extra verification steps
-
Case management with manual review paths for cases that cannot be resolved automatically
-
Access and reauthentication checks when users log in, access sensitive features, or perform high-risk transactions
-
Persistent profiles and lifecycle checks triggered by events such as document expiry, account changes, or a new risk signal, plus periodic reviews scheduled according to the customer’s risk level (for example, a High Risk customer may be reviewed at least annually, while a Low Risk customer every three years or more)
-
Different workflows for different customer segments, products, or jurisdictions
Point solutions can work while the process is simple. But once risk scoring starts affecting onboarding, step-ups, manual review, and later lifecycle checks, they become hard to manage. At that point, orchestration matters as much as the checks themselves.
Regula supports that broader setup: identity checks at onboarding and later in the customer lifecycle can be managed in one environment, with ready-made KYC scenarios for different industries or fully customized workflows, triggers, step-ups, case management, and review paths.
If you are designing or revising a risk-based KYC flow, it can help to start with patterns that have already been tested in your industry. Regula works with 300+ banks, including UBS, and has also implemented identity verification in gambling environments, including Grand Casino Luzern and INSPIRE Entertainment Resort, where identity data feeds directly into compliance and AML processes.
Got a risk model or KYC flow you are trying to put into practice? Talk to us about the architecture behind it.
