Risk-Based Approach and Proportional Controls

A risk-based approach is the discipline of deciding where the bank needs more control, where standard control is sufficient, and where unnecessary friction should be removed. It sounds simple. In practice it touches almost every financial-crime decision the bank makes: who it onboards, what evidence it asks for, how often it reviews a customer, which transactions are prioritised, how a monitoring scenario is tuned, whether a product can be launched, how an alert is routed, when a relationship is restricted, and where scarce specialist capacity is used.

The Financial Action Task Force places the risk-based approach at the centre of its AML/CFT framework. Recommendation 1 requires countries and relevant institutions to identify, assess and understand money-laundering and terrorist-financing risks and to apply measures that are proportionate to those risks. FATF strengthened this principle in February 2025 by replacing the older language of measures being “commensurate” with risk with the clearer concept of proportionate measures, and by reinforcing the legitimate use of simplified measures in lower-risk circumstances. The current FATF Recommendations were last updated in June 2026.

The practical implication for a bank is important: maximum control everywhere is not the same as effective control. A process can collect more documents, generate more alerts and refer more payments while still becoming worse at identifying genuinely important risk. Good financial-crime management concentrates attention where it adds risk-reduction value and keeps the reasoning explainable.

This chapter treats the risk-based approach as an operating model rather than a compliance slogan. It connects enterprise risk assessment, customer risk rating, products, channels, geographies, payment behaviour, sanctions, fraud, monitoring, investigations, data, model governance, architecture, testing and customer impact into one joined story.

The simplest mental model

The risk-based approach can be reduced to five questions.

  1. What can go wrong?
  2. How exposed are we before controls?
  3. Which controls should reduce that exposure?
  4. What risk remains after those controls?
  5. What has changed since the last assessment?

Those questions correspond broadly to risk identification, inherent-risk assessment, control design, residual-risk decision and ongoing reassessment.

Risk-based approach operating loop showing identification, inherent-risk assessment, control selection, residual-risk decision and continuous reassessment.

The loop matters because financial-crime risk is not static. A customer changes ownership. A bank launches instant cross-border payments. A country’s risk profile changes. A sanctions regime changes. A fraud typology emerges. A payment service provider introduces a new downstream partner. A previously ordinary account begins receiving unrelated third-party credits. If the risk framework waits for the next scheduled annual review, it is describing yesterday’s bank.

Risk is not suspicion

This distinction should be explicit in policy, requirements, data models and training.

A risk factor indicates that stronger understanding or control may be appropriate. A suspicion is a judgement under the applicable legal and policy framework that observed facts may indicate illicit activity and may trigger investigation or reporting obligations.

A politically exposed person can be high risk and completely legitimate. A cash-intensive business can be high risk and operate honestly. A correspondent bank can present higher inherent risk because the relationship exposes one institution to activity initiated by another institution’s customers. None of those statements is an accusation.

Conversely, a customer originally rated low risk can behave suspiciously. If a salaried retail customer suddenly receives forty unrelated credits and immediately transfers most of the money to new beneficiaries, the low customer-risk rating should not suppress the behavioural concern.

A useful operational principle is:

Risk determines control intensity. Suspicion determines investigative and reporting action.

Confusing the two creates two opposite failures. The first is over-control: high-risk customers are treated as though they are already guilty. The second is under-control: low-risk customers are treated as though suspicious behaviour cannot occur.

Inherent risk, control effectiveness and residual risk

An institution needs a consistent vocabulary for the three layers of risk assessment.

Inherent risk is the exposure created by the business before considering the effectiveness of mitigating controls. A private-banking relationship involving complex ownership and multiple jurisdictions normally presents a different inherent-risk profile from a straightforward domestic savings account. A real-time cross-border payment product creates different timing and traceability challenges from a limited domestic batch product.

Control effectiveness describes whether the measures designed to mitigate the risk actually work. It is not enough to state that a screening engine, monitoring system or KYC procedure exists. The bank must understand whether data reaches the control, whether the logic is correctly configured, whether exceptions are handled, whether evidence is retained and whether known defects undermine the intended mitigation.

Residual risk is the risk remaining after the effect of controls is considered. Residual risk is the risk that management accepts, enhances controls for, restricts, transfers where appropriate, or decides is outside appetite.

This sounds like a simple formula. In real banks, the hard part is evidence. A control can look strong in a policy document and weak in production. A system may screen names but receive truncated party data. A monitoring scenario may exist but exclude transactions from a newly migrated channel. A high-risk customer review may be completed on time but fail to resolve opaque ownership. The assessment must therefore test the real control, not its label.

The risk universe is multi-dimensional

Financial-crime risk rarely comes from one factor. Banks normally look across several dimensions because each dimension explains a different part of exposure.

Customer risk can reflect customer type, occupation, industry, legal form, ownership complexity, public exposure, adverse information, source of wealth, source of funds and previous behaviour.

Product risk asks how a product can store, receive, move, convert or withdraw value. Cash, trade finance, correspondent banking, private banking, instant payments and virtual-asset connectivity create different misuse opportunities.

Channel risk concerns how identity, authority and activity are established. Branch, mobile, web, API, embedded-finance, agent and partner channels can all be safe or unsafe depending on control design.

Geographic risk can include customer residence, nationality where relevant, place of incorporation, business footprint, counterparties, beneficiary-bank country, intermediary routing, sanctions exposure, conflict, corruption, terrorism financing and proliferation concerns.

Behavioural or transaction risk reflects what the customer actually does: value, frequency, velocity, counterparties, payment purpose, cash usage, rapid movement, circularity, funnel patterns, device behaviour, beneficiary creation and deviation from expected activity.

Those dimensions interact. A payment amount cannot be interpreted without the customer. A country cannot be interpreted without the business purpose. A product cannot be interpreted without the channel through which it is accessed. A risk-based programme joins the dimensions instead of creating five disconnected scores.

A score is not the risk

Banks often represent risk through a rating such as low, medium or high, or through a numeric score. The score is useful only if people and systems can explain the drivers beneath it.

Two customers can both receive a risk score of 82 for completely different reasons. One may be a domestic PEP with transparent wealth and simple payment activity. Another may be a privately owned trading company with opaque control, high-risk corridors and extensive cash-equivalent activity. The same final number should not automatically produce identical due diligence.

The bank therefore needs to preserve the components of the assessment: which risk factors were evaluated, where each fact came from, which rules or weightings were used, which version of the model applied, whether an override was used, what evidence supported the result and what downstream control actions followed.

Risk-data model showing customer, product, channel, geography and behaviour drivers, mandatory rules, versioned assessment, control response and historical reconstruction.

This is especially important for model changes. If a regulator, auditor or investigator asks why a customer was rated medium risk eighteen months ago, the bank should not answer using today’s score and today’s model. It should be able to reconstruct the assessment that existed at the relevant time.

Legal requirements cannot be averaged away

Risk scoring and legal obligations are related but not identical.

A risk model might combine twenty factors into one score, but some conditions cannot safely be diluted by averaging. A legal prohibition, mandatory sanctions outcome, required enhanced measure or policy floor may need override logic. A low-risk product score cannot neutralise a prohibited relationship. A strong customer history cannot make a legally restricted transaction permissible.

This is why mature designs separate three concepts:

  • risk scoring, which prioritises and calibrates controls;
  • mandatory rules, which create a floor or override; and
  • case judgement, which resolves facts when automated data is insufficient.

The system should make the difference visible. Otherwise a team may believe that every decision is the output of one universal “AML score,” when the real process includes legal rules, policy rules, models and human judgement.

Enterprise-wide financial-crime risk assessment

The enterprise-wide risk assessment gives senior management a structured view of where the institution is exposed across businesses, legal entities, products, customers, channels and geographies.

A useful assessment begins with the business model. Which customers does the bank serve? Which products move or store value? Which countries are involved? Which legal entities book the relationships? Does the institution provide correspondent banking, trade finance, cash services, private banking, merchant acquiring, payment services or virtual-asset connectivity? Which channels are growing? Which third parties perform important controls? Where is transaction volume concentrated?

The assessment should then connect threats and vulnerabilities to those activities. Fraud, corruption, organised crime, tax crime, terrorist financing, proliferation financing and sanctions evasion do not affect every business in the same way. A retail digital bank may have intense mule-account and impersonation exposure. A trade bank may have greater goods, shipping, document and sanctions-evasion exposure. A correspondent bank may have indirect exposure to customers it does not directly onboard.

The output should influence decisions. If a risk assessment identifies rapid growth in instant payments but no investment follows in real-time fraud controls, beneficiary intelligence or out-of-hours operations, the exercise has not changed the bank. Risk assessment without resource allocation is documentation, not risk management.

Risk appetite makes the assessment actionable

Risk appetite translates broad strategy into boundaries.

Financial-crime risk appetite should distinguish what is prohibited, what is outside appetite, what is high risk but potentially manageable, and what is lower risk. Those categories should not be collapsed.

The bank may prohibit relationships that law does not permit. It may decide not to offer a particular product in a geography where it lacks sufficient controls. It may require senior approval for defined PEP categories, money-service businesses, correspondent relationships or complex legal structures. It may accept certain residual risks temporarily under formal remediation and compensating controls.

A statement such as “zero tolerance for financial crime” can express culture, but it cannot by itself guide product design, customer acceptance or system behaviour. Criminals will attempt to use banks even when controls are strong. The operational question is how the bank identifies, prevents, detects, escalates and learns from that misuse.

A useful appetite framework creates measurable decisions: approval thresholds, prohibited combinations, concentration limits, exceptions, escalation triggers, remediation deadlines and governance ownership.

Customer risk rating starts at onboarding but does not end there

Onboarding creates the first structured view of a customer. The bank collects identity, legal form, ownership and control, business purpose, occupation or industry, expected products, expected transaction behaviour, geography and other information required by law and policy.

The risk rating should affect what happens next. Higher risk may require deeper ownership evidence, source-of-wealth or source-of-funds analysis, senior approval, more frequent review, tighter product restrictions or closer monitoring. Lower risk may justify simplified measures where law permits and lower risk is properly established.

If the score is calculated, displayed and then ignored by every downstream process, it is decoration.

The customer profile should also be usable by monitoring. If a corporate customer states that it imports medical equipment from two suppliers in Germany and normally pays them monthly, that expected activity is valuable only if monitoring and investigators can access it. A PDF in a KYC archive that cannot be queried does not provide the same control value as structured, governed data.

Dynamic risk and event-driven review

Periodic review remains useful, but the calendar should not be the only reason a customer is reassessed.

Material events can include ownership changes, new directors, a new PEP connection, significant adverse information, law-enforcement interest, a new product, entry into a new country, a large change in expected transaction volume, repeated fraud incidents, sanctions exposure or monitoring behaviour inconsistent with the profile.

The design problem is materiality. If every minor data change triggers a full KYC review, operational queues become unusable. If the triggers are too narrow, the bank can continue relying on stale information for years.

A strong event-driven process asks whether the event changes what the bank knows, expects or is required to do. If it does, the risk is reassessed, relevant evidence is refreshed and downstream controls are updated.

Event-driven review flow showing material customer, ownership, business and external events feeding a materiality gate, reassessment, evidence gathering and proportionate action.

The audit trail should retain the event, previous rating, new rating, rationale, effective date, evidence and actions. This helps operations understand why a review occurred and allows audit or supervision to reconstruct the decision later.

Enhanced due diligence should answer a risk question

Enhanced due diligence is often misunderstood as “collect more documents.” That approach creates work without necessarily creating understanding.

EDD should be connected to the reason risk is higher. If ownership is complex, the enhanced work should resolve ownership and control. If the concern is source of wealth, the evidence should help explain how wealth was accumulated. If the relationship involves higher-risk geographies, the bank may need stronger understanding of business purpose, counterparties and transaction routes. If the customer is a PEP, applicable law and policy may require enhanced measures, senior approval and closer ongoing monitoring.

The principle is simple: every additional evidence request should resolve uncertainty or satisfy a defined obligation.

This improves both control quality and customer experience. Asking a legitimate small business for private-banking-level wealth documentation simply because a generic rule labelled it “high risk” can create friction without clarifying the actual exposure.

Simplified measures are part of the RBA

FATF’s 2025 amendments to Recommendation 1 strengthened the emphasis on proportionality and clarified expectations around simplified measures in lower-risk scenarios. In particular, FATF defined proportionate measures as measures or actions that appropriately correspond to the level of identified risk and effectively mitigate those risks, and it introduced an explicit expectation for countries to allow and encourage simplified measures in lower-risk scenarios. Simplified does not mean absent. Core legal requirements remain, and the institution still needs a reasonable basis for establishing that risk is lower under the applicable national framework.

The concept matters because financial-crime controls can create exclusion when they are poorly calibrated. Customers with low income, migrants, rural customers, small businesses, charities or people in fragile contexts may not possess the same documentation as wealthy customers. Applying the most intensive evidence requirement to everyone can push legitimate activity outside regulated finance.

FATF’s June 2025 financial-inclusion guidance stresses that financial inclusion and financial integrity can support each other. Bringing legitimate activity into a regulated environment can improve transparency, while proportionate controls can preserve access without abandoning AML/CFT objectives. The guidance is non-binding and does not override national authorities; institutions still have to map the global standard to the law and supervisory expectations that apply to the relevant legal entity.

For a bank, this means lower-risk design should be intentional. The institution should know which measures are simplified, why the risk basis supports that decision, what legal boundaries apply and what events would cause the treatment to change.

Proportionality is not a ladder with one automatic answer

It is tempting to describe proportionality as a simple ladder: standard due diligence at low risk, EDD at high risk, and exit at the top. The idea is useful for teaching, but real decisions need more nuance.

Proportional control ladder showing standard due diligence, enhanced measures, stronger approval and monitoring, and restrictions or exit where risk is not manageable.

Different controls respond to different risks. A high-risk customer may need deeper due diligence but no payment restriction. A high-risk product may need stronger transaction monitoring but not more frequent identity verification. A sanctions issue may require a legal outcome regardless of the customer’s overall AML risk. A fraud concern may require an immediate payment intervention even though the customer risk rating is low.

The purpose of proportionality is therefore not to assign one bigger control package to every higher-risk customer. It is to match the control to the risk driver.

Prioritisation: where limited capacity goes first

Every bank has finite investigator time, engineering capacity, compliance expertise and management attention. The risk-based approach requires deliberate prioritisation.

Prioritisation can affect alert queues, customer reviews, sanctions investigations, model remediation, quality assurance, audit sampling, technology investment and regulatory-change work. A case linked to a known fraud network and rapid onward transfers may need faster review than a repetitive low-value monitoring alert with weak indicators. A sanctions release decision may require specialist review before a payment cut-off. A data defect excluding a payment channel from screening may outrank a cosmetic workflow issue.

This does not mean lower-priority work is ignored. It means service levels, queue ordering and resource assignment reflect risk and legal urgency rather than first-in-first-out convenience.

The priority logic should be governed. If operations cannot explain why one alert jumped the queue, the prioritisation model may be creating hidden risk.

Priority should be set by governed criteria that can combine legal or scheme timing, customer harm, signal strength, value at risk, active loss, sanctions or law-enforcement nexus, data confidence and specialist capacity. The weighting is not universal: it should follow the applicable law, product, payment rail and bank policy.

Effectiveness is the outcome test

A programme can be extremely busy and still ineffective.

It can generate millions of alerts, complete thousands of KYC refreshes and produce large management packs while important risk remains unidentified. This is why Wolfsberg’s updated June 2026 Risk-Based Approach guidance emphasises three linked ideas: proportionality, prioritisation and effectiveness.

Effectiveness asks whether the control environment produces useful risk outcomes. Questions include:

  • Are important threats being detected?
  • Are higher-priority cases identified quickly enough?
  • Are investigators receiving the context they need?
  • Are suspicious reports useful and well supported?
  • Are data defects understood and remediated?
  • Do control changes respond to new typologies?
  • Are low-value activities consuming disproportionate resources?
  • Is customer friction justified by the risk controlled?

A false-positive rate is therefore not good or bad by itself. Reducing false positives is valuable if true risk coverage remains strong. Reducing alerts by simply increasing thresholds can make the metric look better while making the control worse.

Risk-based transaction monitoring

Transaction monitoring illustrates why context matters.

Suppose the bank uses a scenario for rapid movement of incoming funds. A universal rule may generate enormous volumes for legitimate payment businesses that naturally receive and send funds quickly. The same behaviour in a newly opened student account may be far more unusual.

Segmentation can therefore consider customer type, product, historical behaviour, risk rating, geography and expected activity. Thresholds can differ where there is a defensible risk basis. Network analytics can add relationships between accounts, counterparties, devices and beneficiaries. Alert priority can incorporate known fraud intelligence or law-enforcement links.

But risk-based tuning must not become “alert reduction.” Every scenario should map to a risk or typology. Changes should be documented, tested and approved. The bank should examine what risk is gained or lost by changing thresholds, segmentation or suppression logic.

Monitoring is strongest when it combines static customer understanding with dynamic behaviour. Neither is sufficient alone.

Screening and monitoring are different controls

Risk-based design should preserve the difference between screening and monitoring.

Screening often compares parties, payments or other data against sanctions, PEP, adverse-media or internal watchlist data. Monitoring usually looks for behaviour over time. The control timing, data and legal consequences differ.

A customer can be low AML risk and still produce a sanctions match that requires urgent legal review. A customer can be high AML risk and have no sanctions concern. A low-value payment can carry a terrorist-financing or sanctions risk that has little relationship to the amount.

Integrated financial-crime architecture should reuse relevant data without pretending that one universal score can replace specialist controls.

Sanctions and the risk-based approach

Sanctions compliance deserves special treatment because legal prohibitions and asset-freeze obligations can be mandatory.

Risk-based thinking remains useful in designing list coverage, screening architecture, ownership analysis, alert prioritisation, false-positive reduction and specialist capacity. But it cannot override a legal restriction simply because the customer’s overall AML risk is low.

This distinction is particularly important in global banks. Applicable sanctions depend on legal entity, jurisdiction, transaction nexus and the specific regime. A group-level risk model cannot safely replace that legal analysis.

The system design should therefore distinguish a risk-based priority signal from a legally binding decision rule.

Terrorist-financing risk can be low value

Money laundering often begins with criminal proceeds. Terrorist financing can involve funds from lawful sources. That changes the risk logic.

A low-value transaction is not automatically low terrorist-financing risk. Networks, counterparties, destinations, external intelligence, behavioural changes and purpose may matter more than amount.

Risk-based CFT controls should therefore avoid assuming that the largest transactions are always the most important. They should also reflect applicable humanitarian exemptions and avoid creating unjustified barriers to legitimate nonprofit and humanitarian activity.

Proliferation-financing risk requires a joined view

Proliferation-financing risk can intersect with sanctions, trade, shipping, dual-use goods, corporate ownership, intermediaries and unusual payment routes.

A bank may not know the physical end use of every item financed, but it can combine customer due diligence, trade documents, vessel and port information, counterparties, ownership, geography and payment data to identify where enhanced review is justified.

The risk-based principle is not to turn every industrial payment into a specialist case. It is to identify which combinations of product, customer, goods, geography and counterparties justify stronger attention.

Geographic risk is not one country field

Country risk is often oversimplified into a single red-amber-green list. Real transactions contain multiple geographic attributes.

A customer may be incorporated in one country, operate in another, have owners in a third, initiate a payment from a fourth, pay a beneficiary in a fifth and route through an intermediary bank in a sixth. Device location or shipping route can add more geography.

A bank should define which geographic attribute matters for which control. Customer-risk assessment may care about residence, incorporation and business activity. Sanctions screening may care about nexus to restricted countries and parties. Payment monitoring may care about corridors and routing. Trade controls may care about origin, destination, port and trans-shipment.

One generic “country risk” field can hide those distinctions.

FATF increased monitoring is not the same as a blanket high-risk outcome

FATF’s list of jurisdictions under increased monitoring is an important input, but it should be interpreted accurately.

As of 19 June 2026, FATF’s public statement identifies jurisdictions that are working with FATF to address strategic deficiencies. FATF does not say that every customer or transaction connected to those jurisdictions is suspicious. The statement is not a universal instruction to terminate relationships. FATF says the increased-monitoring process does not call for blanket enhanced due diligence on those jurisdictions and does not envisage de-risking entire classes of customers; the information should instead be taken into account in risk analysis.

The bank should understand the specific deficiencies, its own exposure, applicable local regulation and its risk appetite. A customer with a legitimate connection to a monitored jurisdiction may need a different risk treatment from a customer with no credible business reason for a complex route through that jurisdiction.

By contrast, FATF’s 19 June 2026 statement on high-risk jurisdictions subject to a call for action calls for stronger measures. The exact action differs by jurisdiction: the statement calls for countermeasures in relation to the DPRK and Iran, while it calls for enhanced due diligence measures proportionate to risk for Myanmar. Banks should therefore use the current FATF publication and applicable local requirements rather than a generic country label.

This is a good example of why the RBA needs precise source data and version control.

Correspondent banking

Correspondent banking exposes one bank to activity initiated by another financial institution and, indirectly, its underlying customers.

The correspondent normally does not perform ordinary retail CDD on every customer of the respondent. Instead it assesses the respondent relationship: ownership, regulatory status, business model, customer base, countries, products, AML/CFT framework, sanctions controls, transaction profile, nested relationships and payable-through arrangements where relevant.

Higher risk may lead to enhanced due diligence, tighter product access, additional payment transparency, stronger monitoring, senior approval or more frequent review.

The important principle is not to confuse indirect exposure with direct customer ownership. The control should reflect the actual relationship and the correspondent’s legal obligations.

Non-bank payment service providers and fintech partners

Banks increasingly serve payment institutions, fintechs, marketplaces and embedded-finance partners. These relationships can expand inclusion and innovation while changing the bank’s risk surface.

The risk assessment should understand the partner’s licence, business model, customer types, geographies, payment flows, downstream agents or partners, safeguarding arrangements, KYC model, sanctions controls, fraud controls, transaction-monitoring capability and incident history.

Contractual responsibilities matter. If the partner collects identity information and the bank books the account, who verifies the evidence? Who screens the customer? Who handles a sanctions alert? Who is permitted to release a held payment? How quickly must information be provided to the bank? What audit rights exist?

A risk rating that ignores these operating responsibilities is incomplete.

Product risk must be assessed before launch

New-product approval is one of the most practical places to apply the RBA.

Before launch, the bank should understand how the product can be misused and whether existing controls remain suitable. Questions include whether the product stores value, supports third-party funding, allows cash withdrawal, enables cross-border movement, uses instant settlement, introduces virtual assets, exposes the bank to underlying customers of another institution, or relies on a new partner or API.

The assessment should translate into implementation requirements: which data fields screening needs, which monitoring scenarios apply, whether fraud controls operate pre-transaction, how cases are created, what customer messages are allowed, which teams cover out-of-hours activity and what evidence is retained.

Launching first and retrofitting monitoring later is not a risk-based approach.

Instant payments change the control clock

Instant payments are a useful example because the underlying risks may be familiar while the available decision time changes dramatically.

A batch payment may give operations time to repair data, investigate an alert or contact a customer. A real-time payment may settle in seconds and become difficult to recover. The control architecture therefore needs to decide which checks must happen before release, which signals can be evaluated automatically, which events require step-up authentication or rejection, and which monitoring can occur only after settlement.

Fraud, sanctions and AML do not operate on identical clocks. Fraud may need sub-second scoring. Sanctions screening may need a pre-release decision depending on the flow and regime. AML transaction monitoring may identify broader patterns after several transactions. The RBA helps allocate real-time intervention to the risks that genuinely need it.

Change delivery should trigger a financial-crime impact assessment

A system migration can change risk even when the business product appears unchanged.

A payment hub replacement may transform message formats, party fields, channel identifiers, data lineage, timing and exception handling. A cloud migration may change logging and data-retention architecture. An ISO 20022 migration can provide richer party and purpose data but only if downstream controls actually receive and interpret it.

A structured change assessment should look across the main risk dimensions.

Financial-crime change-impact view showing customer, product, geography, channel and behaviour/data dimensions that should be assessed when products, rails or systems change.

For a business analyst or architect, useful questions include:

  • Will screening receive all relevant original and normalised party data?
  • Are customer-risk attributes available at the decision point?
  • Are new transaction types included in monitoring?
  • Are historical transactions migrated with enough lineage for investigations?
  • Are repair changes rescreened where required?
  • Does a faster payment rail reduce manual intervention time?
  • Can investigators trace a case back to the original instruction?
  • Are control decisions, model versions and overrides retained?

The RBA is therefore part of architecture, not only compliance policy.

Data quality is a risk-control dependency

Risk models can only assess what the bank can represent accurately.

A customer may be assigned the wrong geography because a country code was defaulted. A beneficial owner may be missing because ownership is stored in an image. A monitoring scenario may misclassify a payment because product codes changed during migration. A sanctions filter may lose an ultimate-party field during transformation.

Data quality issues should therefore be assessed by their control impact, not simply by record counts. A defect affecting one percent of transactions can be severe if that one percent is an unscreened cross-border channel.

Useful controls include data lineage, reconciliations between source and control systems, completeness checks, controlled code mappings, schema validation, exception reporting and alerting when expected feeds stop.

The risk assessment should explicitly consider known data limitations when judging control effectiveness.

Model risk inside financial-crime risk management

Customer risk models, transaction-monitoring models, fraud scores and machine-learning systems create their own model risk.

A model relies on assumptions, data, segmentation, thresholds and calibration. Those choices can become stale. A factor that once predicted higher risk may stop being useful. A new channel can behave differently from the population on which a model was built. A machine-learning model can become difficult for investigators to challenge if its drivers are not understandable.

Governance should cover model inventory, ownership, documentation, validation, approval, change control, performance monitoring and limitations. The bank should know which outcomes are automated, where human review is required and what happens when the model is unavailable.

An explainable model is not necessarily a simple model, but its decisions need to be governable.

Overrides need stronger governance, not weaker governance

Sometimes a model result is wrong or incomplete because the model cannot represent an important fact. An override can therefore be legitimate.

Examples include a newly identified ownership risk, a mandatory policy floor, reliable external intelligence or a temporary known data issue. The problem arises when overrides are unstructured.

Every override should record who made it, the reason, evidence, effective period and approval. Repeated overrides can reveal a model weakness. A business line that routinely downgrades high-risk customers for commercial convenience is not using the RBA; it is bypassing it.

Override reporting should therefore be part of management information and quality assurance.

Alert-to-case prioritisation

Risk-based thinking continues after detection.

A monitoring alert should not automatically become a full investigation. Triage can combine the alert reason with customer risk, transaction context, linked alerts, known counterparties, fraud intelligence, sanctions links, previous cases and network information.

Some alerts can close after a documented explanation. Others should become cases. Multiple alerts may belong to one case. A case may involve several customers and accounts.

Priority can also change during investigation. A low-priority case may become urgent if a new sanctions connection appears or law enforcement asks about the customer. The workflow should support escalation without losing the original chronology.

The RBA is therefore visible in case-management design: priority, SLA, ownership, evidence requirements, QA intensity and escalation path.

Suspicious activity reporting is not a scoring outcome

A customer risk score or monitoring score should not automatically equal suspicion.

Suspicious reporting is a legal judgement under the applicable jurisdiction. The investigator considers facts, context, explanations, linked activity and the relevant threshold. The exact reporting terms, timelines and confidentiality rules differ by country.

A risk score can help prioritise the case or identify which evidence to gather, but the reporting decision needs its own accountable process.

This distinction should be visible in requirements. Fields such as customer risk rating, alert score, case outcome and reporting decision should not be collapsed into one “AML status.”

De-risking versus risk management

A bank may legitimately exit a relationship when it cannot understand the customer, cannot mitigate the risk, faces legal prohibition, or determines that residual risk is outside appetite. That is different from blanket de-risking.

Blanket de-risking occurs when whole categories of customers, sectors or countries are excluded without sufficient individual or segment-level analysis. This can move activity away from regulated finance, reduce transparency and harm legitimate customers.

The stronger approach is evidence-based segmentation. The bank should distinguish customers it cannot serve from customers that can be served with proportionate controls.

Exit decisions should also consider operational sequencing. Account restrictions, payment handling, customer communication, suspicious-report confidentiality, regulatory obligations and record retention may all matter. “Offboard customer” is not a complete requirement.

Customer experience is part of control quality

Financial-crime teams sometimes treat customer friction as separate from risk management. It is not.

Poorly targeted controls can cause repeated document requests, unexplained payment delays, inconsistent decisions and exclusion. Excessive friction can also create operational work that distracts investigators from genuine risk.

The customer should not be told protected information such as the existence of a suspicious activity report, but the bank can still design clear status communication. A payment under review can be described accurately without revealing confidential rationale. A KYC request can explain what information is required and provide a workable path to supply it.

The risk-based objective is not “make it easy.” It is “apply justified friction where it materially reduces risk.”

Governance across the three lines

The first line owns the risks created by customer relationships, products, channels and day-to-day operations. Business and product teams should understand which features create financial-crime exposure and should operate the controls assigned to them.

Second-line financial-crime or compliance functions set frameworks, provide specialist interpretation, challenge first-line decisions and monitor whether the programme remains effective.

Internal audit independently assesses whether governance, risk assessment and controls are designed and operating adequately.

A common failure occurs when the first line treats the customer risk rating as “compliance’s number.” That weakens ownership. The business should understand why the customer or product is risky, while compliance should challenge whether the assessment and treatment are defensible.

Senior management needs a view of the highest exposures, material control weaknesses, unresolved exceptions and important trends.

Management information should describe risk, not only activity

Useful management information goes beyond counts of completed reviews or closed alerts.

It can include high-risk customer concentration by business and geography, overdue EDD, risk-rating changes, alert volumes by scenario and segment, alert-to-case and case-to-report conversion, false-positive concentration, priority case ageing, sanctions-match resolution, data-quality defects, model limitations, overrides, risk acceptances, customer exits, remediation progress and QA findings.

The numbers need interpretation. A rising case-to-report conversion rate could reflect better targeting, but it could also reflect overly aggressive escalation. Falling alert volumes could indicate successful tuning, or a data feed could have failed. Metrics are signals for investigation, not performance truths.

Targets should be designed carefully because people adapt to them. Rewarding analysts only for closure speed can reduce investigation quality. Rewarding teams only for lower alert volumes can encourage under-detection.

Control effectiveness needs evidence

A control should be assessed through design and operation.

Design effectiveness asks whether the control, if performed as intended, is capable of mitigating the relevant risk. A sanctions control that screens only the account holder but not relevant payment parties may be poorly designed for the intended payment risk.

Operating effectiveness asks whether the control actually performed as designed during the period. A well-designed screening control can fail operationally because a feed stopped, data was truncated or analysts released alerts without sufficient evidence.

Evidence can include configuration, test results, exception logs, QA outcomes, incident history, data reconciliations, model-validation findings and sample case reviews.

Residual-risk decisions should reflect known control weaknesses rather than assuming perfect operation.

Formal exceptions and risk acceptance

Sometimes a control weakness cannot be fixed immediately. A bank may need a formal exception or risk-acceptance process.

The record should identify the control gap, affected population, inherent risk, residual risk, compensating controls, accountable owner, approval, expiry date and remediation plan.

Time-bounded acceptance is different from forgetting the weakness. Repeated extensions should trigger challenge. Material financial-crime exceptions should be visible to appropriate senior management and compliance oversight.

Technology teams also need the exception in a form they can act on. “Risk accepted” should not disappear into a governance document while engineering believes the issue remains a production blocker.

Practical example: two identical payments, different context

Consider two USD 100,000 payments to the same overseas supplier.

Customer A is an established manufacturer that has paid the supplier for five years. The invoice, product type, volume and geography align with expected activity. The customer has transparent ownership and no relevant adverse information.

Customer B is a newly incorporated consulting company with no history of international trade. Its payment purpose does not match the stated business. Ownership involves several entities in different jurisdictions, and the beneficiary relationship is unexplained.

The amount and beneficiary are identical. The risk context is not.

A risk-based control may allow Customer A through ordinary checks while referring Customer B for additional review. The bank is not declaring Customer B criminal. It is recognising that more uncertainty exists and stronger evidence is needed.

Practical example: high-risk customer, normal transaction

A PEP customer with substantial, well-documented wealth may be classified high risk and subject to enhanced monitoring. A routine monthly payment to a long-standing utility provider can still be normal.

If every transaction by a high-risk customer becomes an alert, investigators will be overwhelmed and genuine anomalies may receive less attention. The monitoring framework should use the enhanced customer profile to distinguish expected behaviour from meaningful deviation.

This is why good KYC and monitoring are connected. Better customer understanding can reduce noise while improving detection.

Practical example: low-risk customer, abnormal network behaviour

A retail customer has received salary into the same account for four years. The customer is low risk. Over a weekend, the account receives fifteen payments from unrelated individuals and transfers most of the funds to two new beneficiaries within minutes.

The low risk rating should not prevent escalation. Behaviour has changed.

The bank might examine payer relationships, fraud complaints, device changes, beneficiary links, cash withdrawal, virtual-asset exposure and whether other customers send to the same beneficiaries. A static customer score is only one input to the case.

Practical example: a country enters increased monitoring

A country appears on the latest FATF list of jurisdictions under increased monitoring.

A weak implementation immediately sets every customer connected to that country to high risk, orders full EDD and blocks onboarding until manual approval.

A stronger implementation starts by reading the current FATF statement and the applicable regulator’s expectations. The bank identifies the strategic deficiencies relevant to its own exposure, evaluates customers, products and corridors, updates country-risk inputs and determines whether additional measures are justified.

The difference is not “soft versus strict.” It is unreasoned automation versus documented risk analysis.

Practical example: launching instant cross-border payments

A bank launches a service allowing eligible retail customers to send cross-border payments twenty-four hours a day.

The change introduces faster settlement, new corridors, new beneficiary behaviour and out-of-hours activity. Fraud teams need real-time signals. Sanctions controls need appropriate pre-release screening. AML monitoring needs the new transaction type and richer data. Operations needs a model for exceptions outside office hours. Customer messaging must distinguish fraud intervention from ordinary processing delay without exposing protected information.

The financial-crime risk assessment should therefore produce concrete requirements before launch, not a generic “AML sign-off.”

Mini case study: the fast-growing marketplace

A bank has provided a domestic operating account to a technology marketplace for two years. At onboarding, the marketplace was considered medium risk. It sold household goods, received card-settlement credits from known acquirers and paid a relatively stable group of domestic suppliers.

The marketplace expands quickly. It adds third-party sellers from several countries, introduces wallet balances, offers same-day payouts, and begins using an API to create thousands of beneficiary payments. Transaction value triples within six months. The original KYC record still describes a domestic e-commerce retailer.

The first signal appears in operations. Payment volumes exceed expected limits and a manual team repeatedly increases temporary thresholds. Fraud monitoring detects more new-beneficiary activity. Transaction monitoring generates rapid-movement alerts but closes many as expected marketplace behaviour. A sanctions-screening team notices that seller names sometimes arrive truncated from the marketplace API. No single control sees the full change.

A risk-based review should begin with the business model, not the existing score. The bank now has indirect exposure to third-party sellers, faster payouts, cross-border geography and customer data captured partly by the marketplace. The product and channel have changed even though the legal customer is the same company.

The bank should reassess inherent risk across customer, product, channel, geography and behaviour. It should identify which controls still work, where data is incomplete, and who is responsible for seller due diligence and sanctions screening under the contractual and legal model.

The review may conclude that the relationship remains acceptable but requires stronger controls: structured seller identifiers in the API, clearer data obligations, sanctions-screening remediation, revised transaction-monitoring segmentation, enhanced review of the marketplace’s control framework, tighter governance for payout-limit changes and event-driven review if new countries or products are added.

The residual risk should then be approved at the appropriate level and recorded with the evidence supporting it.

The lesson is that risk did not increase because a score changed. The score needed to change because the business changed.

Business analyst view: turn policy into decision logic

A BA working on financial-crime change should not accept a requirement such as “apply enhanced checks to high-risk customers.” It is too vague to build or test.

The requirement should identify:

  • what event creates or changes the risk assessment;
  • which data fields and authoritative sources are used;
  • how risk factors are combined;
  • which mandatory floors or overrides apply;
  • what rating categories exist;
  • what actions each category triggers;
  • which users may override the result;
  • what evidence is required for an override;
  • when the assessment expires or is refreshed;
  • which downstream systems consume the result;
  • what audit data must be retained.

The same approach applies to monitoring. A BA should document the typology, customer population, transaction population, thresholds, lookback period, segmentation, exclusions, prioritisation, case-routing outcome and tuning governance.

“Risk based” must become observable system behaviour.

Architecture view: preserve risk lineage

Risk data should be reusable and time-aware.

A customer risk rating may feed KYC review scheduling, transaction monitoring, case prioritisation and product approval. Country risk may feed customer scoring, payment controls and trade review. Product risk may determine monitoring scenarios. Event-driven review triggers can originate from customer master data, adverse-media services, PEP screening, sanctions changes, transaction monitoring and product systems.

If every application stores its own ungoverned copy, the bank can produce contradictory outcomes. One system may think the customer is medium risk while another still has last year’s low rating.

Architecture should therefore define authoritative sources, versioning, effective dates, lineage and distribution. Consumers need both the current value and, where required, the historical value used at the time a decision was made.

The case platform should capture the risk context used during investigation rather than silently replacing it with the latest rating.

Testing view: prove that risk changes behaviour

Testing a risk model is not complete when the arithmetic produces the expected score. Testers should prove that the score has the intended operational consequences.

Useful scenarios include:

  • two customers with the same transaction but different risk profiles;
  • a low-risk customer whose behaviour changes materially;
  • a high-risk customer carrying out expected activity;
  • a beneficial-owner change that triggers reassessment;
  • a new PEP status event;
  • a country-risk update;
  • an EDD requirement triggered by a specific risk driver;
  • a prohibited condition that cannot be averaged away;
  • a manual override with insufficient evidence;
  • an expired override;
  • a data-feed failure affecting a risk factor;
  • migration of historic risk ratings and effective dates;
  • a product launch in which the new transaction type must enter monitoring;
  • a sanctions rule that remains mandatory regardless of AML score.

Negative tests matter. The system should prove that low-risk status does not suppress legally mandatory controls and that high-risk status does not automatically create suspicion.

Operational view: queues are part of the RBA

A risk-based design can fail in operations if every alert ends up in the same queue with the same service level.

Queue design should consider urgency, legal timing, customer impact and specialist skill. A sanctions match holding a time-sensitive payment may need a different workflow from a post-transaction AML alert. A fraud case involving ongoing customer loss may need immediate intervention. A periodic KYC review can have a longer planning horizon.

Prioritisation should be transparent enough for supervisors and managers to understand why work is sequenced the way it is.

Capacity planning also matters. If a new risk model moves twenty percent of the portfolio into EDD and no staffing or automation changes, the design may be mathematically correct and operationally impossible.

Common failure modes

One-size-fits-all controls. Equal friction is not equal risk management.

Risk scores with no downstream action. A rating that changes nothing is decorative.

High risk treated as guilt. Risk classification must not become an accusation.

Low risk treated as immunity. Behavioural anomalies must still be detected.

Legal rules mixed into ordinary scoring. Mandatory outcomes need clear override or floor logic.

EDD as document collection. Extra evidence should answer a defined risk question.

Static KYC. Important events should change risk before the periodic review date.

Country labels used mechanically. The bank should understand the source, date, specific deficiency and applicable legal expectation.

Alert reduction treated as success. Fewer alerts are useful only if risk coverage remains effective.

Poor data lineage. A score cannot be defended when the bank cannot reconstruct its inputs and model version.

Uncontrolled overrides. Exceptions without reason, expiry and approval undermine the model.

Product launch before controls. Retrofitting financial-crime coverage creates avoidable exposure.

Metrics used as targets. Teams can optimise the number while weakening the outcome.

Customer impact ignored. Disproportionate friction can create exclusion and operational waste without reducing risk.

Practitioner checklist

A mature risk-based programme should allow a practitioner to answer the following without relying on tribal knowledge.

What are the bank’s highest inherent financial-crime risks? Which controls mitigate them? Which known weaknesses reduce control effectiveness? What residual risk remains? Who approved it? Which customers or products receive enhanced measures and why? Which populations qualify for simplified treatment and on what basis? What events change a customer risk rating? How are legal overrides separated from scoring? Which geographic attributes drive which controls? How are monitoring scenarios linked to typologies? How are high-priority alerts identified? Can the bank reconstruct a historic score? How are exceptions governed? How does customer impact enter design decisions? How are new products and systems assessed before launch?

If those questions have clear, evidenced answers, the RBA is likely embedded in the operating model rather than sitting only in policy.

Takeaway

The risk-based approach is the mechanism that turns financial-crime knowledge into prioritised action.

It begins by identifying and understanding risk. It distinguishes inherent exposure from the effectiveness of controls. It uses residual risk to make accountable decisions. It connects customer, product, channel, geography and behaviour rather than relying on one label. It applies stronger measures where justified, simplified measures where law permits and lower risk is established, and mandatory legal rules regardless of a convenient score.

Most importantly, it is dynamic. New information, new products, new geographies, new behaviour and new threats should change the control environment.

A mature bank does not ask whether every customer received the same check. It asks whether each material risk received the right evidence, control, ownership, timing and escalation — and whether the outcome can be explained later.

References and further reading

The sources below are public, authoritative materials used to validate this chapter. FATF Standards set an international framework, but binding obligations are implemented through national and regional law. Older FATF sector guidance remains useful for the banking operating model but should be read together with the current Standards and the 2025–2026 updates.

Deep dive: turning the risk-based approach into an operating model

The risk-based approach becomes real only when a bank can show how identified risk changes an actual decision. It is easy to say “we apply stronger controls to higher risk.” The difficult questions are: Which risks? Measured how? Stronger in what way? Who approves the decision? What evidence shows the control is working? When does the risk change? What happens when the bank cannot reduce it to an acceptable level?

A mature programme can answer those questions without hiding behind a score.

Imagine two corporate customers. Both are privately owned trading companies with annual turnover of EUR 20 million. Customer A imports household goods from long-established suppliers in two countries, has transparent ownership and has banked with the institution for eight years. Customer B was incorporated six months ago, has three layers of offshore ownership, trades dual-use electronic components, uses several intermediaries and expects payments through higher-risk jurisdictions.

A one-size-fits-all process might collect the same documents from both customers and review both every two years. A genuine risk-based process asks what could go wrong in each relationship and designs the control intensity accordingly. Customer A may fit standard due diligence and normal monitoring. Customer B may require deeper beneficial-ownership work, clearer end-use and counterparty information, enhanced source-of-funds evidence, specialist sanctions or proliferation review, senior approval, more frequent review and monitoring calibrated to the specific trading pattern.

The important point is not that Customer B is suspicious. The bank may decide the relationship is legitimate and manageable. The point is that the risk is higher and the control response should be proportionate to it.

FATF Recommendation 1: the logic behind the entire programme

FATF Recommendation 1 requires countries to identify, assess and understand their money-laundering and terrorist-financing risks and to take action, including designating authorities or mechanisms to coordinate risk assessment and applying resources to mitigate the risks effectively. The risk-based approach also applies to financial institutions and designated non-financial businesses and professions.

The practical logic is simple: if risk differs, control intensity should differ. Resources should be focused where they can reduce the most meaningful risk. That does not remove mandatory legal requirements. It changes how institutions prioritise and tailor additional measures around them.

FATF has strengthened the emphasis on proportionality and financial inclusion. The 2025 revisions to Recommendation 1 reinforced the idea that lower-risk situations can justify simplified measures where the law permits and that risk-based implementation should avoid unnecessary exclusion. The FATF Recommendations were amended again in June 2026, so practitioners should always verify the current text rather than rely on old training notes.

The Wolfsberg Group’s 2026 Guidance on the Risk-Based Approach describes the private-sector objective through proportionality, prioritisation and effectiveness. Those three words are useful because they turn a regulatory principle into management questions.

Proportionality: Is the control burden reasonably related to the level and nature of risk?

Prioritisation: Are scarce people, technology and management attention focused on the risks that matter most?

Effectiveness: Are the controls producing useful risk outcomes rather than merely activity and volume?

Risk-based does not mean discretionary in the casual sense

One misunderstanding is that the RBA gives analysts freedom to do whatever seems reasonable. That is not what it means. Risk-based programmes need more disciplined governance, not less.

A bank should define the risk factors it considers, how they are combined, what control consequences follow, which decisions require approval, which rules are mandatory and how exceptions are recorded. Analysts can apply judgement within that framework, but the judgement should be explainable and reviewable.

If two analysts reach different outcomes on similar customers, the difference should come from relevant facts or documented judgement, not personal preference. Quality assurance and calibration are therefore essential parts of a risk-based programme.

Enterprise-wide risk assessment: the top of the hierarchy

The enterprise-wide financial crime risk assessment, often called an EWRA, asks where the bank is inherently exposed across its business. It usually considers customers, products, services, geographies, channels, legal entities and sometimes specific financial-crime threats such as money laundering, terrorist financing, sanctions, proliferation financing and fraud.

The EWRA is not the same as the risk rating of one customer. It is a portfolio-level view.

A useful assessment starts with inherent risk. What types of customers does the bank serve? Which products can move value quickly or across borders? Which businesses handle cash? Which entities offer correspondent banking, private banking or trade finance? Which jurisdictions create higher exposure? Which channels depend on remote onboarding or third parties?

Then the bank maps key controls. How does it know customers? How does it screen parties? How does it monitor activity? What specialist controls exist for high-risk products? What assurance shows those controls operate effectively?

Residual risk is the remaining risk after controls are considered. If residual risk is outside appetite, the bank should have a management decision: strengthen controls, restrict activity, accept the exposure under formal governance where permitted, or exit the activity.

A weak EWRA is a spreadsheet exercise completed once a year. A strong EWRA informs investment, staffing, scenario design, product restrictions, thematic reviews, remediation priorities and board discussion.

Threat, vulnerability and consequence: a clearer way to think about risk

Many risk assessments improve when they separate three ideas.

A threat is the source of potential criminal misuse—for example organised fraud, corruption, terrorist financing or sanctions evasion.

A vulnerability is a feature that makes the institution or product easier to misuse—for example weak beneficial-ownership transparency, instant cross-border access, heavy cash use or limited visibility of underlying customers.

A consequence is the potential impact if the risk materialises—for example legal breach, customer harm, criminal proceeds moving through the bank, enforcement, loss of correspondent access or damage to financial-system integrity.

This structure prevents the bank from treating every “risk factor” as equivalent. A country with elevated corruption risk creates a threat context. A product with anonymous or weakly verified access creates vulnerability. A sanctions breach in a high-value cross-border business can create severe consequences.

The interaction matters more than the individual factor.

Customer risk assessment: the score is only the summary

Customer risk rating models often produce low, medium and high categories or numerical scores. The danger is that teams begin to treat the score as the risk itself.

The score is only a summary of underlying factors. Good investigators and reviewers need to see the drivers: ownership complexity, PEP status, industry, geography, products, expected activity, delivery channel, adverse information, correspondent exposure or other relevant factors.

A customer can move from medium to high risk because one factor changes. If the system stores only the final score, the bank cannot explain why the rating changed or whether the model behaved correctly.

The model should therefore retain factor values, weightings or decision logic, model version, date of calculation and the evidence supporting key inputs. Overrides should be visible, justified and approved according to policy.

Customer risk rating is not transaction risk

A high-risk customer can make a perfectly ordinary transaction. A low-risk customer can make a suspicious one.

This distinction is operationally important. Customer risk should influence monitoring sensitivity and review frequency, but it should not become a blanket conclusion about every payment. Likewise, low-risk status should not suppress meaningful behavioural anomalies.

Imagine a long-standing low-risk retail customer who suddenly receives twenty instant payments from unrelated parties and forwards the funds to virtual-asset services within minutes. The prior customer risk rating should not prevent the bank from investigating the new behaviour.

Conversely, a high-risk private-banking customer may routinely send large cross-border investment payments that are fully consistent with known wealth and documented activity. High value alone should not generate endless low-quality alerts.

Geographic risk: build a reason, not a colour

Many banks use country-risk ratings, but a simple red-amber-green map can hide the reason for the risk.

Geographic risk can arise from FATF public statements, sanctions exposure, corruption, organised crime, terrorism, proliferation, weak beneficial-ownership transparency, conflict, cash intensity, regulatory weakness or other factors. Those drivers have different implications.

A country under FATF increased monitoring has strategic deficiencies and is working with FATF on an action plan. FATF does not say that every customer or payment connected to that country is suspicious. The bank should understand the specific deficiencies and apply its own risk-based framework together with local regulatory requirements.

A comprehensively sanctioned jurisdiction, by contrast, may create a very different legal problem. The same “high-risk country” label cannot safely drive both cases.

Country-risk data should therefore preserve underlying drivers and effective dates. When a country’s status changes, the bank should be able to identify which customers and transactions require reassessment.

Product risk: think like someone trying to misuse the product

Product risk assessment should ask how value can enter, move, change form or leave.

A domestic savings account with no third-party payments and low transaction limits may create relatively limited misuse opportunities. A multi-currency corporate account with cross-border transfers, APIs and cash-management services has a wider exposure. Correspondent banking can introduce underlying customers the bank does not directly onboard. Trade finance introduces goods, documents, shipping and pricing. Private banking can involve complex wealth structures. Instant payments compress decision time.

A useful product-risk workshop walks through misuse scenarios. How could a criminal use this product? How could sanctions restrictions be evaded? Could funds be moved rapidly through multiple beneficiaries? Can third parties fund the account? Can customers transact before full due diligence is complete? Can the bank reconstruct who initiated the activity?

The controls should be designed against those misuse paths.

Channel risk: digital is not automatically dangerous and branch is not automatically safe

Remote onboarding is sometimes labelled high risk by default. That is too simplistic. The real question is the strength of identity, authentication, device, fraud and evidence controls.

A digital process using strong document verification, trusted identity sources, biometrics, liveness, device risk, duplicate-identity checks and human referral can be stronger than a branch process that relies on visual inspection of a photocopy.

At the same time, digital channels create different threats: synthetic identity, account takeover, bot activity, credential stuffing, remote-access scams and fast scaling by criminals. Risk assessment should recognise those actual attack paths rather than the word “digital.”

Third-party and embedded-finance channels create additional questions. Who performs CDD? Who owns the customer relationship? Which party sees transaction context? How are alerts shared? Who is responsible for suspicious reporting? Contract language cannot replace regulatory accountability.

Delivery through intermediaries: risk can move but responsibility may not

Banks often rely on agents, introducers, correspondent banks, fintech partners or third parties for parts of the customer journey. The risk-based approach must account for that dependency.

If a third party collects customer information, the bank should know what standards apply, how evidence can be obtained, how quality is tested and what happens if the partner fails. If a respondent bank sends payments through a correspondent, the correspondent does not usually know the respondent’s underlying customers to the same depth. The product design therefore needs controls appropriate to indirect visibility.

Outsourcing an activity does not automatically outsource regulatory responsibility.

Simplified due diligence: what it is and what it is not

Simplified measures are often misunderstood as “skip KYC.” That is wrong. Simplification can mean reducing the intensity, extent or frequency of measures where lower risk has been properly established and law permits it.

A low-risk customer may need fewer additional documents, less frequent review or simpler verification than a high-risk complex entity. But the bank still needs enough information to identify the customer, understand the relationship and meet mandatory requirements.

The decision to simplify should itself be risk-based and documented. It should not be driven only by customer-experience targets.

Enhanced due diligence: ask the question the risk creates

EDD should resolve specific uncertainty.

If the risk comes from complex ownership, obtain evidence that clarifies ownership and control. If it comes from wealth, understand source of wealth. If it comes from a high-risk corridor, understand the commercial or personal reason for the geography. If it comes from a PEP relationship, understand public role, source of wealth, source of funds and relevant approval. If it comes from a trade product, understand counterparties, goods and routes.

Collecting twenty documents that do not address the risk is not enhanced due diligence. It is enhanced paperwork.

A good EDD case note should be able to say: “The risk was X; we obtained Y; that evidence reduced or did not reduce the uncertainty; therefore the relationship was accepted/restricted/escalated.”

PEPs: high risk is not prohibited

Politically exposed persons illustrate why the RBA requires disciplined thinking. PEP status is a risk factor because public position can create exposure to bribery, corruption or misuse of public funds. It is not proof of criminal activity.

Controls may include senior approval, source-of-wealth and source-of-funds measures, enhanced monitoring and periodic review depending on applicable law and policy. The bank should also consider family members and close associates as required by the relevant framework.

Automatic rejection of every PEP relationship is not a sophisticated risk-based approach. Neither is treating every PEP identically. The nature of the role, jurisdiction, wealth, product and transaction activity matters.

Correspondent banking: applying RBA where the customer is another institution

Correspondent banking is a classic higher-risk area because one bank provides services to another and may indirectly process activity for the respondent’s customers.

The correspondent should understand the respondent’s ownership, management, business, customer base, regulatory environment, AML/CFT controls, products and geographic exposure. The level of due diligence should reflect risk.

A respondent serving only domestic retail customers is different from one providing nested access to payment institutions across multiple high-risk corridors. Both are banks, but the exposure is not the same.

The correspondent must also monitor the relationship over time. Unexpected payment corridors, rapid volume growth, opaque nested activity or repeated transparency issues can change the risk after onboarding.

Trade finance: RBA across customers, goods and routes

Trade finance creates a multi-dimensional risk because the bank may need to understand customer, counterparty, goods, route, vessel, documents and payment.

A lower-risk established importer buying ordinary consumer goods from known suppliers is different from a newly formed trader purchasing dual-use equipment through multiple intermediaries. Controls may include deeper sanctions and proliferation review, goods screening, document review, enhanced customer understanding and specialist escalation.

The bank should be clear about what it can and cannot verify. Trade documents are evidence supplied by parties; they are not proof that goods physically moved exactly as described.

Instant payments: RBA under severe time pressure

Instant payments create a control-design challenge because settlement may occur in seconds and may be difficult to reverse. The RBA therefore has to work before and during the transaction, not only through post-event monitoring.

Banks can use customer risk, device data, beneficiary history, behavioural signals, sanctions screening and velocity to decide whether a transaction can proceed straight through or requires intervention. But excessive friction destroys the instant-payment proposition and can create customer harm.

The solution is not “screen less.” It is to use the best available data and focus intervention on higher-risk combinations.

Post-transaction AML monitoring remains important because not every laundering pattern can be identified within the payment’s execution window.

Risk appetite: translating strategy into decisions

A financial-crime risk appetite should be practical enough to guide acceptance, restriction and escalation.

Statements such as “zero tolerance for financial crime” communicate intent but do not tell a relationship manager whether the bank will serve a money-service business, a charity operating in a conflict area or a high-net-worth PEP.

A useful appetite framework can define prohibited relationships, restricted sectors, approval requirements, geographic limitations, product constraints, customer-risk thresholds and material exposure limits. It should also explain how exceptions are governed.

Risk appetite should be aligned with capability. A bank should not enter a high-risk business it cannot monitor effectively merely because revenue is attractive.

De-risking: when risk management becomes exclusion

De-risking often refers to broad withdrawal from categories of customers or markets rather than case-by-case risk management. FATF has repeatedly emphasised that the RBA is not intended to promote wholesale de-risking.

There are legitimate reasons to exit relationships: legal prohibitions, inability to complete due diligence, unacceptable residual risk, repeated lack of transparency or business-model decisions. But exiting every money-service business, charity or customer from a particular country can push activity outside regulated finance and reduce visibility.

A mature bank should be able to explain why a category is prohibited or why a particular relationship is unmanageable. The decision should be grounded in risk and capability, not fear of complexity alone.

Financial inclusion and proportionality

Financial inclusion is not separate from financial-crime policy. Excessive identification requirements, documentation burdens or blanket exclusions can prevent legitimate customers from using regulated financial services.

A risk-based framework allows the institution to apply appropriate simplified measures in genuinely lower-risk situations where law permits. This can support access while maintaining effective control.

The challenge is to avoid two extremes: weak controls in the name of inclusion and unnecessary exclusion in the name of compliance. Proportionality is the discipline between them.

Transaction monitoring: risk segmentation without tuning away the risk

RBA is especially visible in transaction monitoring. A single threshold applied to every customer often generates poor results because expected activity differs by segment.

A payment processor may legitimately receive thousands of credits and send consolidated payments. A retail salary account should not. A private-banking customer may make high-value international transfers. A student account may not.

Segmentation can therefore improve detection by comparing customers with relevant peers and expected behaviour. But segmentation should not create blind spots. Every segment needs coverage for meaningful risks, and high-risk customers should not be placed into a group where their behaviour becomes invisible because everyone is high volume.

Scenario tuning should document the risk hypothesis, data used, threshold rationale, test results and residual limitations.

Risk-sensitive alert prioritisation

Not every alert needs the same operational priority. A mature programme can prioritise based on customer risk, typology, sanctions or law-enforcement connection, value, network significance, vulnerability, product and time sensitivity.

Prioritisation should not mean ignoring lower-priority alerts indefinitely. It means allocating capacity in a way that protects the highest risks first while maintaining controlled backlog limits.

Service levels should reflect the risk and legal context. A sanctions payment hold may need immediate attention. A post-transaction monitoring alert may tolerate a different investigation window. A high-risk customer review approaching expiry may need escalation before restrictions apply.

RBA in sanctions: where risk-based and mandatory controls meet

Sanctions creates an important boundary. Some sanctions obligations are legal prohibitions and are not optional based on a customer’s risk score. A designated person does not become permissible because the customer is low risk.

The risk-based element appears in how the institution identifies exposure, allocates screening resources, performs ownership analysis, reviews higher-risk products, manages list data, tests systems and controls proliferation or evasion risk. Mandatory restrictions remain mandatory.

This is why “risk-based sanctions” should never be interpreted as “screen only high-risk customers.”

RBA in terrorist financing

Terrorist-financing risk can be difficult to assess because relevant transactions may be low value and sources of funds may be lawful. FATF guidance highlights these challenges.

Risk assessment may therefore rely more heavily on geographic exposure, networks, intelligence, sectors, charities, remittance corridors and behavioural patterns. A purely amount-driven model can miss the risk.

The bank should understand how its products could be used to raise, store or move funds connected to terrorism and how sanctions, monitoring and intelligence controls interact.

RBA in proliferation financing

FATF requires countries and relevant private-sector entities to assess risks of breaches, non-implementation or evasion of targeted financial sanctions related to proliferation financing and to apply mitigating measures commensurate with those risks.

For a bank, this can mean deeper attention to trade finance, dual-use goods, shipping, front companies, procurement networks, unusual intermediaries and countries linked to proliferation concerns.

The risk assessment should reflect the bank’s products. A purely domestic retail bank has a different proliferation-financing exposure from a global trade-finance bank.

Dynamic risk: the customer profile must be able to change

A risk-based programme fails if the customer’s risk rating can change only during a scheduled review.

Event-driven triggers can include ownership changes, new directors, PEP status, sanctions or adverse-media developments, new products, unusual transaction activity, major volume changes, new countries, law-enforcement information or significant fraud events.

The system should define which events recalculate risk automatically, which create a review task and which require immediate restriction or escalation.

Event-driven design is particularly important in fast-growing digital businesses, where a customer’s behaviour can change dramatically between periodic reviews.

Model risk in customer risk scoring

Customer risk-rating models are models and should be governed accordingly. Teams should understand data inputs, assumptions, weightings, thresholds, overrides, validation and performance.

If a model assigns high weight to nationality but ignores actual transaction geography, it may create poor risk differentiation. If beneficial-ownership data is frequently missing, the model may systematically understate risk. If a model has not been recalibrated after the bank enters a new business, it may no longer reflect exposure.

Validation should ask whether the model separates risk meaningfully, whether inputs are reliable and whether control consequences are proportionate.

Human judgement and overrides

No model captures every fact. Human overrides can therefore be legitimate. But an override should be a controlled decision, not a workaround.

The user should record why the score or control consequence is being overridden, what evidence supports the decision, who approved it and whether the override has an expiry date. Override patterns should be monitored. If one business unit overrides 40% of high-risk scores, the problem may be the model or the business behaviour.

Overrides are valuable management information.

Risk acceptance and exceptions

Sometimes a control cannot be implemented immediately. A new payment platform may launch with an interim manual review while an automated control is being built. A customer may need a temporary exception while documents are updated. These situations require formal risk acceptance.

A good risk acceptance defines the gap, risk, compensating control, owner, approval, expiry date and remediation plan. Permanent “temporary” exceptions are a warning sign.

Financial-crime risk should not disappear into generic project waivers without specialist ownership.

New product approval: RBA before launch

Every new product should undergo financial-crime risk assessment before launch. The review should understand customer types, jurisdictions, value flows, funding methods, payout methods, intermediaries, transaction speed, limits, reversibility, data captured and operational exceptions.

The assessment should identify which existing controls can be reused and which new controls are needed. If the product introduces new exposure—such as virtual assets, cross-border reach or third-party distribution—the bank should not assume existing scenarios are sufficient.

Testing should include misuse scenarios, not just happy-path customer journeys.

Change risk: when technology alters the control without changing policy

A technology migration can materially change financial-crime risk even if the policy is unchanged.

Moving from MT messages to ISO 20022 can change data richness. Moving payments to an instant rail changes decision time. Replacing a customer master can change identifiers. Outsourcing screening can change list-management and audit evidence. Migrating case systems can lose historical links.

The RBA should therefore be part of change impact assessment. Teams should ask which risk factors, controls and evidence are affected and whether residual risk changes during transition.

Parallel-run and reconciliation controls can be especially important when old and new systems coexist.

Control effectiveness: design effectiveness versus operating effectiveness

A control can be well designed and badly operated. A policy can require sanctions screening of all relevant payment parties, but a mapping defect can omit the ultimate creditor. The design is conceptually sound; operation is not.

Conversely, a control can operate exactly as designed but still be ineffective if the design itself is poor. A transaction-monitoring rule may process every transaction correctly but look only at amounts and therefore miss the behaviour it was intended to detect.

Testing should therefore separate design effectiveness from operating effectiveness. Both feed the residual-risk assessment.

Effectiveness metrics: move beyond volume

Alert counts, SAR/STR counts and review completion rates are easy to measure but do not prove effectiveness.

A stronger set of questions includes whether material risks are covered, whether higher-risk cases are identified in time, whether investigations use relevant information, whether reports are useful, whether false positives consume disproportionate capacity, whether known weaknesses are remediated and whether customer friction is justified.

Wolfsberg’s focus on effectiveness is valuable because it challenges “more activity equals better compliance.” Sometimes a control produces more volume because it is poorly targeted.

Management information and the danger of target-driven compliance

Metrics can create unintended behaviour. If analysts are told to close twenty alerts per day, quality may fall. If teams are rewarded for reducing false positives, thresholds may be raised too far. If a business is penalised for high-risk customers, it may manipulate risk classifications.

Management information should therefore support judgement rather than become a simplistic production target.

Trend analysis is useful. Why did high-risk customer numbers increase? Why did one scenario’s alert-to-case conversion fall? Why are sanctions-resolution times increasing? Why did one jurisdiction generate more EDD backlog? The explanation matters more than the raw number.

Risk-based quality assurance

QA itself can be risk-based. A bank does not need to review every case at the same intensity. Higher-risk decisions, analyst overrides, suspicious-report closures, sanctions releases and complex EDD cases may receive deeper sampling.

Random sampling still matters because it can reveal systematic weaknesses in apparently low-risk cases. A purely risk-targeted QA programme can miss broad process errors.

The sampling methodology should therefore combine targeted and representative coverage.

Internal audit and independent challenge

Internal audit provides independent assurance over the framework, but it does not own the risk. First-line business and operations own day-to-day risk. Compliance sets or oversees the framework and provides challenge. Audit independently assesses whether governance and controls are adequate and effective.

A risk-based audit plan should focus more attention on higher-risk businesses and known control weaknesses while still maintaining sufficient enterprise coverage.

Regulatory supervision is increasingly risk-based too

Supervisors also use risk-based approaches. FATF guidance on risk-based supervision explains that supervisory intensity should reflect the risks and characteristics of institutions and sectors.

For banks, this means supervisory attention can concentrate on material exposures rather than treating every institution identically. A bank with large correspondent and trade-finance businesses should expect deeper questions about those areas than a small institution without them.

The institution should be able to explain its own risk assessment in the same language: risk, controls, effectiveness and residual exposure.

A detailed worked case: remittance business customer

A regulated money-service business applies for an account. It serves migrant communities and sends remittances to several countries, including some with elevated financial-crime risk.

A blanket de-risking approach would reject the customer because “MSB plus high-risk corridors equals high risk.” A risk-based approach goes deeper.

The bank should understand licensing, ownership, management, agent network, customer base, products, transaction volumes, source and destination countries, AML/CFT controls, sanctions screening, transaction monitoring, cash handling and regulatory history. It should assess whether the respondent can provide sufficient transparency and whether the bank’s own controls can manage the exposure.

If controls are credible, the bank may accept the relationship with enhanced monitoring and periodic review. If ownership is opaque, regulatory status is uncertain or the MSB cannot explain its agent network, the risk may be unmanageable.

The result comes from evidence, not category alone.

A detailed worked case: charity in a conflict area

A humanitarian charity operates in a region where sanctioned groups and terrorist organisations are active. Its mission is legitimate and socially valuable. The bank faces sanctions, CFT and operational risk while also needing to avoid unjustified financial exclusion.

The RBA should examine governance, funding sources, local partners, beneficiary controls, payment channels, countries, cash use and monitoring. Specialist sanctions review may be needed where designated groups control territory or financial infrastructure.

The bank may impose transaction limits, require additional information for certain payments or apply enhanced review to higher-risk corridors. A blanket exit may not be necessary if risks can be managed.

This is exactly the kind of situation where proportionality matters.

A detailed worked case: instant-payment product launch

A bank launches real-time payments to retail customers. The product allows 24/7 transfers with final settlement in seconds. Existing fraud models were designed for slower payments, and sanctions screening relies on a batch-updated customer-risk feed.

The new product changes risk even though the customers and accounts are the same. Criminals can move scam proceeds faster. Manual sanctions review has less time. Velocity increases. Overnight controls may be too slow.

A risk-based change assessment should identify those differences before launch. Fraud decisioning may need real-time beneficiary and device signals. Sanctions list and customer data may need more frequent updates. Transaction limits or step-up controls may be risk-sensitive. Post-transaction AML monitoring may need rapid mule-network scenarios.

The lesson is that risk belongs to the product behaviour, not just the customer population.

A detailed worked case: customer risk changes after ownership event

A medium-risk corporate customer has transparent domestic ownership and a stable business. It is acquired by a holding company in another jurisdiction. The holding company is owned through a trust, and one new controller is a PEP.

If the bank waits for the next periodic review, the old risk rating can remain in force for months or years. An event-driven RBA should trigger ownership refresh, PEP assessment, source-of-wealth review where relevant and risk recalculation.

The customer may remain acceptable. The important point is that the control reacts to new facts.

A detailed worked case: monitoring threshold that creates false comfort

A bank uses a single rule: generate an alert when more than EUR 100,000 is transferred internationally in 24 hours. The rule produces many alerts for corporate treasury customers and almost none for retail accounts.

Investigators find that most corporate alerts are expected business activity, while several mule cases involve EUR 20,000 to EUR 40,000 in rapid transfers that never reach the threshold.

The problem is not merely false positives. The scenario’s risk hypothesis is weak. The bank should redesign using customer segment, expected activity, velocity, counterparty pattern and network indicators rather than simply increasing the threshold.

RBA means improving risk sensitivity, not just reducing volume.

BA and architecture requirements for a true RBA

A system implementing risk-based controls should preserve the facts that drive risk and the consequences of the rating.

The customer-risk engine should expose factor values, calculated score, risk band, model version, date and override information. Downstream systems should know which risk attributes they are authorised to use and how fresh they are.

Monitoring systems should support segmentation without duplicating customer logic inconsistently. Case systems should display relevant risk drivers, not only the final score. Product systems should know when risk affects limits or approval. Reporting should show concentrations and control gaps.

Changes to risk methodology should be versioned so that historical decisions can be reconstructed.

Testing an RBA implementation

Testing should include more than verifying that “high risk” appears on screen.

Test boundary conditions around score thresholds. Test missing data. Test contradictory factors. Test event-driven recalculation. Test that high-risk status triggers the intended EDD workflow. Test that simplified measures cannot be applied where prohibited. Test that overrides require the right approval. Test that old model versions remain reconstructable. Test that downstream monitoring receives updated risk values.

Also test the customer journey. Does a high-risk referral create an unexplained dead end? Can operations tell the customer what information is needed without exposing internal suspicion? Does the system distinguish “high risk but acceptable” from “prohibited”?

Those are control requirements, not cosmetic UX details.

What management should be able to explain to a supervisor

A senior manager should be able to explain where the bank’s highest financial-crime risks are, how the bank knows that, what controls mitigate them, what evidence shows those controls work, what residual risks remain and what weaknesses are being remediated.

If the answer is “our risk model says high/medium/low,” the programme is not mature enough.

The board does not need to know every threshold. It does need to understand material exposure and whether the institution is operating within appetite.

What a 50-minute reader should retain

The risk-based approach is not simply a customer score and not an excuse to reduce controls. It is the discipline of matching controls, resources and scrutiny to identified risk while preserving mandatory legal requirements.

It operates at several levels: national risk, enterprise risk, business and product risk, customer risk, transaction and behavioural risk, control effectiveness and residual risk. Each level should inform the next.

Proportionality prevents both under-control and unnecessary friction. Prioritisation focuses scarce resources on material risk. Effectiveness asks whether the programme actually detects, prevents, manages and reports financial crime rather than merely producing alerts and documents.

A strong RBA is dynamic, evidence-based and explainable. It changes when the customer, product, geography, channel, threat or control changes.

Deep practitioner expansion: turning the risk-based approach into an operating model

The risk-based approach becomes meaningful only when it changes decisions. A bank can publish a sophisticated risk methodology, assign customer scores, maintain heat maps and still operate a largely rules-based, one-size-fits-all control environment. The real test is whether risk understanding changes the intensity, timing, ownership and evidence of controls.

The Financial Action Task Force places the risk-based approach at the centre of AML/CFT frameworks. Wolfsberg’s updated June 2026 guidance reinforces proportionality, prioritisation and effectiveness. Those words sound high level, but each has a very practical banking meaning.

Proportionality means the level of control should correspond to the risk being managed. Prioritisation means scarce investigative, operational and technology capacity should be directed toward the risks that matter most. Effectiveness means the programme should be judged by whether it identifies, manages and reports meaningful risk rather than by how many forms, alerts or policies it produces.

A mature RBA therefore links enterprise risk assessment, customer risk rating, product risk, geographic risk, delivery-channel risk, transaction behaviour, control performance and management action. If those elements are disconnected, the organisation may have several “risk-based” processes that do not actually influence each other.

Enterprise-wide financial crime risk assessment

The enterprise-wide financial crime risk assessment is the starting point for understanding where the institution is exposed.

A useful assessment considers the bank’s customers, products, services, countries, legal entities, distribution channels, transaction volumes, correspondent relationships, trade activity, digital channels, third parties and emerging threats. It then evaluates the controls used to mitigate those risks and the residual exposure that remains.

The process should not become a once-a-year spreadsheet exercise. The assessment should influence priorities. If the bank identifies rapid growth in instant payments, increased exposure to non-bank payment service providers or higher-risk trade corridors, investment and control design should respond.

Inherent risk

Inherent risk describes exposure before considering the effectiveness of controls. It asks what could go wrong because of the nature of the business.

A domestic salary account typically presents a different inherent risk from a private-banking relationship involving complex legal structures and cross-border assets. A correspondent banking service presents different exposure from a simple savings product. An instant-payment product creates different timing risk from a batch payment processed only during business hours.

The inherent-risk assessment should be specific enough to be useful. Labels such as “payments: high” are too broad. Domestic retail transfers, cross-border correspondent payments, merchant acquiring, cash services and instant payments can have very different risk profiles.

Control effectiveness

Control effectiveness asks whether the mitigating measures actually work.

A sanctions-screening control should not be rated effective simply because a screening engine exists. The assessment should consider data completeness, list-update governance, matching configuration, alert handling, release authority, quality assurance and whether material defects are known.

Likewise, a transaction-monitoring control is not effective merely because alerts are generated. The bank should consider scenario coverage, data quality, prioritisation, investigation quality, tuning, model validation and case ageing.

Control assessments therefore need evidence. Policy existence, system configuration, testing results, operational MI, audit findings, quality-assurance results and incidents can all contribute.

Residual risk

Residual risk is the exposure remaining after controls are considered. It is not automatically low just because many controls exist.

A business line can have many controls and still retain high residual risk if those controls are weak, fragmented or unable to address the underlying threat. Conversely, a higher-inherent-risk activity can sometimes be managed to an acceptable level through strong controls.

This is where risk appetite becomes important. Residual risk must be compared with what the bank is willing and legally able to accept.

Risk appetite is a decision framework, not a slogan

“Zero tolerance for financial crime” sounds strong but is not an operational risk appetite. No bank can guarantee that no criminal will ever attempt to use its products.

A useful risk appetite framework defines boundaries. It may prohibit certain activities entirely, require senior approval for defined exposures, impose product restrictions, set concentration limits, establish mandatory escalation thresholds or specify when residual risk is unacceptable.

Examples can include restrictions on relationships with shell banks, limits on certain high-risk geographies, approval requirements for particular PEP categories, conditions for serving money service businesses, requirements for higher-risk correspondent relationships or prohibited customer types under local law.

The key is that appetite should translate into decisions that systems and people can apply.

Customer risk rating: what the score is actually for

A customer risk score is useful only if it changes what happens next.

Banks commonly combine customer type, geography, product use, ownership, occupation or industry, delivery channel, PEP status, adverse information and other factors into a customer risk rating. The exact model varies by institution and jurisdiction.

The score should drive control intensity. Higher-risk customers may receive enhanced due diligence, more frequent review, stronger approval, closer monitoring or additional source-of-funds analysis. Lower-risk customers may be eligible for simplified measures where law permits.

If a score is calculated and stored but does not change due diligence, monitoring or review frequency, it is largely decorative.

Score versus reason

A number alone is not enough. An investigator should understand why the customer is rated high risk.

Two customers can both have a score of 85 for very different reasons. One may be a PEP with complex wealth. Another may be a cash-intensive business in a higher-risk jurisdiction. Their enhanced due diligence should not be identical because the underlying risks differ.

For that reason, risk drivers should be retained alongside the final rating.

Dynamic risk and event-driven review

Customer risk is not static.

Ownership can change. A director can become politically exposed. A new country can enter the customer’s business model. Transaction volume can increase. An adverse-media event can emerge. A customer can add new products. A country’s FATF status can change. Sanctions measures can be introduced or lifted.

An effective programme therefore uses both periodic review and event-driven review.

Event triggers can include material ownership changes, new PEP status, significant changes in transaction behaviour, law-enforcement requests, new adverse media, sanctions exposure, repeated fraud events or a major change in products used.

The challenge is avoiding excessive noise. If every minor change creates a full KYC refresh, operations will be overwhelmed. Event logic should distinguish material from immaterial changes.

Product risk assessment

Every product should be assessed for how it can be misused.

Important questions include:

  • Can the product hold value?
  • Can value be moved cross-border?
  • Can it be funded by third parties?
  • Can funds be withdrawn in cash?
  • Does it support instant or irrevocable movement?
  • Can the customer transact anonymously or through intermediaries?
  • Does the product expose the bank to underlying customers of another institution?
  • Does it involve goods, securities or virtual assets?
  • Can it be accessed through APIs or third-party channels?

A product may be low risk in one configuration and higher risk in another. A domestic current account with limited functionality is not the same as a multi-currency account with instant international payments and API access.

New product approval

Financial-crime risk should be part of new product approval before launch.

The bank should assess how onboarding, screening, transaction monitoring, fraud controls, sanctions controls, case management, reporting and data retention will work. Controls should be tested before customers begin using the product.

A frequent failure pattern is to launch a digital product and retrofit monitoring later. In fast payment environments, that gap can become material very quickly.

Geographic risk

Geographic risk should combine multiple sources rather than rely on one country list.

Relevant inputs can include FATF public statements, national risk assessments, sanctions exposure, corruption indicators, conflict, terrorism financing risk, proliferation concerns, predicate crime threats, supervisory quality and the bank’s own experience.

FATF’s June 2026 statement on jurisdictions under increased monitoring is particularly important because FATF explicitly states that increased monitoring does not automatically call for enhanced due diligence and does not support blanket de-risking. Institutions should consider the information in their risk analysis and apply a risk-based response.

This is a practical warning against mechanical country rules.

Country is not one field

A banking transaction can have many geographic attributes: customer residence, nationality, place of incorporation, business operations, beneficiary location, beneficiary bank country, intermediary bank country, IP location, shipping route and source-of-funds geography.

A good risk model defines which geography matters for which control.

Channel risk

Digital onboarding, branch onboarding, agent channels, embedded-finance partners and APIs create different control challenges.

Remote onboarding may increase impersonation and synthetic-identity risk, but strong digital identity controls can mitigate it. Branch onboarding can provide face-to-face interaction but may still be weak if evidence is poorly verified.

Channel risk therefore concerns the reliability of identity, authority and data — not whether the customer is physically present.

API and partner channels also raise accountability questions. If a fintech partner captures customer information and the bank books the account, who is responsible for due diligence? Which party performs sanctions screening? How is evidence transferred? How are exceptions escalated? These responsibilities must be explicit.

Behavioural risk

Transaction behaviour is where static risk assessments meet reality.

A low-risk customer can become concerning through unexpected behaviour. A high-risk customer can conduct entirely expected activity.

Behavioural risk can include changes in value, frequency, velocity, geography, counterparties, cash use, channel, time of day, beneficiary creation, device pattern or transaction purpose.

The strongest monitoring compares observed behaviour with both the customer’s own history and relevant peer groups.

Peer groups

Peer groups can reduce false positives by recognising that different customers naturally behave differently.

A grocery retailer and a software consultancy should not have identical transaction expectations. A remittance business will naturally have many third-party payments. A corporate treasury centre may move high values across group entities.

Peer grouping must be governed carefully because poor segmentation can hide risk. The peer group should be economically meaningful and periodically reviewed.

Enhanced due diligence should resolve uncertainty

EDD should not become a list of extra documents collected because a customer is high risk.

The enhanced measures should address the specific risk drivers.

If ownership is complex, EDD should establish ownership and control. If source of wealth is unclear, evidence should explain how wealth was accumulated. If transaction geographies are high risk, the bank may need deeper understanding of business partners and purpose. If a customer is a PEP, senior approval, source-of-wealth analysis and enhanced monitoring may be relevant.

Every requested document should answer a question.

Simplified measures and financial inclusion

Where law permits and lower risk is properly established, simplified measures can reduce unnecessary friction.

Simplified does not mean no customer due diligence. The bank must still meet core legal obligations. The difference is that the intensity or frequency of certain checks may be reduced in line with risk.

This matters for financial inclusion. Excessive documentation can exclude low-income customers, migrants, small businesses or humanitarian organisations without materially improving control effectiveness.

FATF’s recent changes and Wolfsberg’s RBA guidance reinforce that risk-based implementation should avoid unnecessary barriers to legitimate financial activity.

De-risking versus risk management

Blanket de-risking occurs when institutions avoid entire customer classes, sectors or countries rather than assess risk individually.

Sometimes exit is justified. A bank may lack the controls to manage a particular exposure or law may prohibit the activity. But broad exclusion can push legitimate activity into less transparent channels and can undermine financial inclusion.

A mature bank distinguishes between prohibited, outside risk appetite, high risk but manageable, and lower risk. Those are not the same category.

Correspondent banking and the RBA

Correspondent banking demonstrates why the RBA must look beyond the direct customer.

The correspondent bank has a relationship with another financial institution, not usually with all of the respondent’s underlying customers. The correspondent therefore assesses the respondent’s business, AML/CFT framework, ownership, products, geographies, customer base and regulatory environment.

Nested relationships can increase risk because other institutions may access the correspondent indirectly. Payable-through accounts can create additional exposure. The control response can include enhanced due diligence, restrictions, transaction monitoring, payment transparency and periodic review.

The objective is not to know every underlying customer as though they were direct customers. It is to understand and manage the risk of the respondent relationship.

Non-bank payment service providers

Banks increasingly provide services to payment institutions, fintechs and other non-bank payment service providers. These relationships can create valuable competition and inclusion but also introduce indirect customer and transaction risk.

Risk assessment should consider the PSP’s licence, business model, customer types, geographies, products, transaction flows, safeguarding model, AML controls, sanctions controls, fraud controls and downstream partners.

Wolfsberg’s 2026 guidance on providing banking services to non-bank PSPs is useful here because it emphasises proportionate due diligence rather than automatic exclusion of the sector.

Instant payments and risk prioritisation

Instant payments compress the time available for preventive controls.

A transaction can settle before a manual analyst could reasonably review it. The RBA therefore affects where real-time controls are applied, which transactions receive step-up checks, how beneficiary risk is assessed and how post-transaction monitoring is prioritised.

A bank cannot manually review every instant payment. The risk-based response may combine customer-risk attributes, beneficiary history, device intelligence, fraud signals, sanctions screening and behavioural analytics.

The principle is prioritisation under time pressure.

Transaction monitoring segmentation

Monitoring design should reflect different risks across customer segments and products.

One universal threshold for rapid movement of funds can create poor outcomes. A money-service business will naturally receive and distribute funds rapidly; the same pattern in a newly opened student account may be more unusual.

Segmentation can consider customer type, risk rating, product, geography, expected activity and historical behaviour.

The purpose is not to reduce alerts for convenience. It is to make detection more relevant.

Alert prioritisation

Not all alerts require the same urgency.

Prioritisation can consider customer risk, transaction value, sanctions or law-enforcement links, known fraud intelligence, network connectivity, typology severity, vulnerability, time sensitivity and legal deadlines.

A high-priority alert should receive quicker review and appropriate specialist ownership.

Service levels should reflect risk, not merely queue order.

Risk-based quality assurance

Quality assurance can also be risk-based.

High-risk customer reviews, sanctions releases, suspicious-report decisions and high-value correspondent cases may receive more intensive QA than routine low-risk cases.

Sampling can combine random selection with targeted thematic review. A purely random approach may miss the areas with greatest potential harm.

Model risk and the RBA

Risk models can create their own risk.

Customer-risk models, transaction-monitoring models, fraud scores and machine-learning systems depend on data quality, assumptions and calibration.

Governance should include documentation, validation, change control, performance monitoring and review of unintended bias.

A model should not become unchallengeable because it is mathematically complex. Investigators and compliance officers need to understand enough about the drivers to use the result responsibly.

The danger of risk-score averaging

A common model weakness is that high-risk factors can be diluted by many low-risk factors.

For example, a sanctioned-country exposure should not necessarily be averaged away by ordinary product or channel scores if the legal framework requires stronger treatment. Some factors need override or floor logic.

The model should distinguish risk scoring from legal prohibitions.

RBA and sanctions

Sanctions compliance is not simply a risk-based version of AML. Legal prohibitions can be mandatory.

Risk-based thinking still matters in how banks design screening coverage, prioritise false-positive reduction, conduct ownership analysis and allocate specialist resources. But a high-confidence legal restriction cannot be ignored because the overall customer score is low.

This distinction is critical in integrated financial-crime platforms.

RBA and terrorist financing

CFT requires special care because transaction values can be small and sources of funds can be legitimate.

Risk assessment may therefore rely more heavily on networks, geography, counterparties, external intelligence and behaviour than on transaction size.

The bank should also account for humanitarian exemptions and legitimate nonprofit activity. Overly broad restrictions can create unintended consequences.

RBA and proliferation financing

Proliferation-financing risk often intersects with trade, sanctions and geography.

Risk-sensitive controls can focus attention on relevant industries, goods, end users, routes, shipping patterns and ownership structures.

Again, the bank should avoid turning every industrial trade transaction into a specialist review. The purpose of the RBA is to identify where enhanced scrutiny is justified.

Management information

Management information should show whether risk is being managed, not only whether work is being completed.

Useful views include:

  • high-risk customer concentration by business and geography;
  • overdue EDD and periodic reviews;
  • significant risk-rating changes;
  • alert volumes and conversion by segment;
  • sanctions-match ageing;
  • transaction-monitoring scenario performance;
  • high-priority case ageing;
  • material data-quality defects;
  • control exceptions;
  • customer exits and restrictions;
  • known model limitations;
  • remediation progress;
  • quality-assurance results.

Trend is often more useful than one month’s number.

Metrics can create bad behaviour

Targets should be designed carefully.

If analysts are rewarded for closing more cases, they may close too quickly. If teams are rewarded for reducing alerts, they may tune away risk. If suspicious-report conversion becomes a target, investigators may over-escalate.

Metrics should inform judgement, not replace it.

Scenario: same payment, different customer risk

Two customers each send USD 100,000 to the same overseas supplier.

Customer A is an established manufacturer that has used the supplier for five years. Volumes, invoices and geographies fit the expected profile.

Customer B is a newly incorporated consulting company with no previous international activity. The beneficiary is unrelated to the stated business and the ownership chain is opaque.

A one-size-fits-all control sees the same amount and beneficiary. A risk-based control sees very different context.

The bank may allow Customer A to proceed through normal controls while Customer B receives enhanced review.

The difference should be explainable and evidence-based.

Scenario: high-risk customer, normal behaviour

A PEP customer with complex wealth may be rated high risk and subject to enhanced monitoring. A routine monthly payment to a long-standing utility provider can still be normal.

High customer risk does not mean every transaction should generate a case.

The monitoring framework should use the enhanced customer profile to distinguish expected from unexpected activity.

Scenario: low-risk customer, sudden anomaly

A low-risk retail customer who has received salary for years suddenly receives multiple unrelated credits and sends them immediately to new beneficiaries.

The low risk rating should not suppress the behavioural anomaly.

This is why dynamic transaction behaviour must complement static customer risk.

Scenario: new instant-payment product

A bank introduces 24/7 instant cross-border payments.

The product team focuses on speed and customer experience. The financial-crime risk assessment identifies several changes: reduced intervention time, new beneficiary patterns, out-of-hours operations, richer payment data, new scheme rules and increased scam exposure.

The RBA should influence design before launch. The bank may enhance beneficiary risk, real-time fraud controls, sanctions screening, operational staffing, customer warnings and post-transaction monitoring.

A simple copy of the batch-payment control framework may not be sufficient.

Scenario: FATF increased monitoring

A country is added to the FATF list of jurisdictions under increased monitoring.

A weak response automatically classifies every customer and transaction connected to that country as high risk and requires full EDD.

A stronger response reviews the FATF statement, identifies the specific strategic deficiencies, assesses the bank’s exposure and updates relevant risk models proportionately.

FATF explicitly states that increased monitoring does not itself call for automatic EDD and should not result in indiscriminate de-risking.

Change management

Financial-crime risk changes when systems, products and rules change.

A major transformation should include an AML/CFT change-impact assessment.

Questions include:

  • Does the new platform preserve all screening fields?
  • Are customer-risk attributes available in real time?
  • Do monitoring scenarios receive the same or better data?
  • Are historical transactions migrated?
  • Can investigators reconstruct pre- and post-migration activity?
  • Are alert and case identifiers preserved?
  • Does the new payment rail shorten decision time?
  • Are new products or geographies introduced?
  • Does the operating model have enough capacity?

A control that worked in the old architecture may fail after transformation even when the business process looks similar.

Risk acceptance and exceptions

Sometimes a control gap cannot be fixed immediately.

The bank may use a formal risk-acceptance or exception process. The decision should identify the weakness, affected population, risk severity, compensating controls, owner, expiry date and remediation plan.

Exceptions should not become permanent through repeated extensions without challenge.

Financial-crime risk acceptance should receive appropriate senior and compliance oversight because the consequences can be significant.

First line and second line under the RBA

The first line owns the risk created by products and customer activity. Compliance provides policy, independent challenge and oversight.

A common failure is for first-line teams to treat the risk rating as “compliance’s number.” That weakens ownership.

Business and product teams should understand which features create financial-crime risk and why certain controls are required.

Second-line compliance should challenge whether the controls remain proportionate and effective.

Internal audit

Internal audit should assess whether the RBA is genuinely embedded.

Questions include whether enterprise risk assessments influence priorities, whether customer risk ratings change control intensity, whether models are governed, whether high-risk populations receive stronger review, whether low-risk populations are treated proportionately and whether risk decisions are supported by evidence.

An institution can have a technically sophisticated RBA and still fail this test if operations behave identically for every customer.

Business analysis requirements for risk-based controls

A BA should make risk logic explicit.

For a customer-risk model, document the risk factors, data sources, weighting or decision logic, overrides, refresh triggers, output categories and downstream actions.

For monitoring, document segmentation, threshold logic, scenario objective, data dependencies, alert prioritisation and tuning governance.

For EDD, document which risk drivers trigger which evidence requirements.

For product controls, document how product risk changes screening, monitoring, limits and case routing.

For country risk, document which geographic attributes are used and which authoritative sources drive updates.

Architecture principles

Risk data should be reusable across controls.

A customer risk rating should be available to monitoring, case management and review scheduling. Country risk should not be separately maintained in five inconsistent systems. Product risk should be linked to the actual product instance. Event-driven review triggers should be generated from controlled source events.

The architecture should also preserve version history. Investigators and auditors may need to know what the customer’s risk rating was at the time of a transaction, not only the current rating.

Testing a risk-based design

Testing should prove not only that a score is calculated but that the score changes behaviour.

Test cases should include:

  • two customers with identical transactions but different risk profiles;
  • a customer whose risk increases after an ownership change;
  • a low-risk customer with an unusual behavioural pattern;
  • a high-risk customer conducting expected activity;
  • a country-risk update;
  • an expired EDD review;
  • a model override;
  • a prohibited factor that must not be diluted by scoring;
  • a control exception and its expiry;
  • migration of historical risk ratings.

Effectiveness reviews

An RBA should be challenged periodically.

Are high-risk customers actually producing more useful intelligence, or is the model simply conservative? Are low-risk customers generating unexpected cases? Are some risk factors no longer predictive? Are certain segments overburdened with EDD? Are country rules causing unnecessary customer exits? Do alert-priority rules correspond to material outcomes?

The purpose is continuous improvement.

Financial inclusion and customer fairness

Financial-crime programmes can unintentionally create exclusion.

Small charities, remittance customers, migrants and customers with limited formal documentation may face disproportionate friction if controls are not designed carefully.

Risk-based does not mean lenient. It means controls should be tied to evidence of risk.

If a legitimate low-income customer cannot open an account because the bank requires documentation designed for private banking, the control may be disproportionate.

The RBA should support both integrity and access.

Practitioner review questions

A reader should be able to explain the difference between inherent and residual risk, why high risk is not the same as suspicion, why a customer risk score needs risk drivers, why FATF increased monitoring should not automatically trigger blanket EDD, why dynamic behaviour can override a low static risk rating, why sanctions legal prohibitions are different from ordinary risk scoring, how instant payments change control timing and why product change should trigger financial-crime reassessment.

If those questions are clear, the reader understands the RBA as an operating model rather than a policy concept.

Practitioner masterclass: making proportionality work in a real bank

The hardest part of a risk-based approach is not assigning a risk rating. It is translating that rating, together with the underlying risk drivers, into a control response that is strong enough to manage the exposure without becoming mechanical, indiscriminate or disconnected from the customer’s real activity. FATF’s 2025 revisions to Recommendation 1 sharpened this point by placing clearer emphasis on proportionate measures and on the legitimate use of simplified measures where lower risk has been properly established. That does not weaken AML/CFT controls. It asks institutions to make them more deliberate.

A mature bank therefore avoids two extremes. At one extreme, every customer receives the most intensive treatment regardless of risk, which creates operational congestion and can exclude legitimate customers without improving detection. At the other extreme, a numeric risk score is treated as permission to reduce scrutiny even when a mandatory legal requirement, sanctions restriction or specific suspicious indicator requires action. Proportionality sits between those extremes. It means understanding what creates the exposure and selecting controls that address that exposure directly.

Risk drivers should be visible after the score is calculated

A risk rating should never become a black box. If a customer is classified as high risk, the bank should be able to explain whether the result arose from ownership complexity, PEP exposure, industry, geography, product use, expected transaction profile, delivery channel, adverse information or some combination of these factors. That explanation matters because different drivers need different responses.

A customer with a complex ownership chain may require deeper beneficial-ownership analysis. A customer whose main exposure is a higher-risk payment corridor may require stronger understanding of counterparties and transaction purpose. A customer whose risk arises from PEP status may require the enhanced measures and approvals applicable under the relevant jurisdiction. Applying the same generic document request to all three customers can create a large file without answering the actual risk question.

This is also why data lineage matters. The bank should retain the facts used by the model, the model or rules version, any manual override, the final rating, the reasons for that rating and the controls triggered by it. If an investigator later reviews suspicious activity, or a supervisor asks why a relationship was accepted, the institution should be able to reconstruct the decision using the information that existed at the time rather than today’s profile.

Risk appetite cannot override law

Risk appetite helps management decide which exposures the institution is willing and operationally able to manage, but it does not convert a legal prohibition into an acceptable risk. This distinction should be explicit in policy, architecture and user interfaces.

A useful design separates mandatory legal or regulatory rules from risk-based decisions. Sanctions restrictions, statutory prohibitions and jurisdiction-specific obligations may create hard stops or mandatory actions. Risk appetite then operates around the exposures that remain legally permissible: whether the bank will serve a customer segment, offer a product in a market, permit a particular channel, accept a concentration of higher-risk relationships or require additional approval.

For architects and business analysts, that separation should appear in the decision model. A single composite “AML score” should not silently mix legal prohibitions, policy appetite, behavioural risk and human judgement. The downstream system needs to know whether an outcome is a legal restriction, a policy restriction, an enhanced-control requirement or an investigative referral because each has different ownership, customer communication and audit requirements.

The customer lifecycle is a continuous risk assessment

Onboarding is only the first risk decision. Once the relationship is active, the bank receives new evidence through payments, account behaviour, product changes, ownership updates, device activity, adverse information, screening results, fraud events, law-enforcement contact and customer interactions. A mature risk-based approach uses that evidence to keep the risk view current.

Periodic review remains useful, but event-driven review is often more responsive. The design challenge is materiality. A trivial address formatting change should not create the same workflow as a new beneficial owner, a significant change in business activity or the discovery of a PEP connection. Trigger logic therefore needs thresholds, reason codes and governance. Operations should be able to see why the review was created, what changed, which evidence must be refreshed and which downstream controls may need recalibration.

The same principle applies when the customer adopts a new product. A customer who was originally assessed for a domestic current account may later add cross-border payments, merchant acquiring, trade finance or API-based bulk payments. The institution should assess the incremental exposure created by the new capability instead of assuming the original onboarding decision remains sufficient.

Payment speed changes where proportional controls must sit

The risk-based approach becomes especially practical in instant and high-speed payment environments. A batch process may leave time for manual intervention before release. An instant payment may settle in seconds. The bank therefore cannot design the same control sequence for both and simply demand faster analysts.

A proportionate real-time design places the strongest preventive logic where a decision must be made before value moves. Depending on the payment rail and applicable obligations, this can include sanctions screening, fraud scoring, beneficiary or counterparty intelligence, customer-risk attributes, device signals, transaction velocity and unusual-behaviour indicators. Post-transaction monitoring then examines patterns that cannot reasonably be resolved at transaction speed.

The objective is not to stop every unusual payment. It is to identify which combinations of risk justify friction, step-up authentication, referral, rejection where permitted, or later investigation. A long-standing corporate customer making a payment to a known supplier can present a different risk picture from a newly opened account sending its first high-value cross-border transfer to an unrelated beneficiary, even if the amount is identical.

Third parties and payment-service providers require a layered RBA

Banks increasingly serve fintechs, payment institutions and other non-bank payment service providers. The direct customer may be the PSP, while the economic activity originates from many underlying users. This creates a layered risk problem rather than a reason for automatic exclusion.

The bank should understand the PSP’s regulatory status, products, customer types, geographies, transaction flows, use of agents or downstream partners, safeguarding or settlement arrangements, AML/CFT controls, sanctions controls and fraud controls. It should also understand what information will be visible in the payment data and what responsibilities sit with each party. Wolfsberg’s 2026 guidance on banking non-bank PSPs reinforces the value of proportionate due diligence based on the actual business and flow of funds.

For technology teams, the relationship has to be represented in data. The payment should not lose relevant originator, beneficiary, intermediary or underlying-party information simply because it enters through an API or partner channel. Monitoring should be able to distinguish the direct banking customer from the underlying transaction parties where the business model requires it.

Effectiveness is more important than activity volume

Risk-based programmes can be distorted by the wrong metrics. More alerts do not automatically mean better detection. More customer-document requests do not automatically mean better due diligence. More exits do not automatically mean lower risk. A control should be assessed by the quality of the risk information it produces and the decisions it supports.

Useful management information therefore connects volumes to outcomes. Alert counts are more informative when paired with conversion, ageing, priority and typology coverage. High-risk customer numbers are more useful when management can see the risk drivers, overdue reviews, control exceptions and concentration. Screening statistics are more meaningful when the bank understands true matches, false positives, data-quality defects and release decisions. A large fall in alerts can be positive because tuning removed noise, or dangerous because a data feed disappeared. The metric alone cannot tell management which interpretation is correct.

This is where the Basel Committee’s risk-management perspective is important. AML/CFT risk management should form part of the bank’s wider risk framework because weak financial-crime controls can create legal, operational, reputational and safety-and-soundness consequences. The financial-crime programme should therefore be capable of showing senior management not only how much work was completed, but where residual exposure remains.

Mini case: a cross-border PSP adds instant payouts

Consider a bank that already provides an operating account to a regulated payment service provider. The PSP historically processes domestic transfers in daily batches. It now proposes instant cross-border payouts through an API, with materially higher volumes and several new destination countries.

A weak process might say that the PSP is already an approved customer and therefore no new financial-crime assessment is needed. Another weak response might classify the entire change as “high risk” and demand a generic EDD package without considering the new flow.

A stronger risk-based assessment asks what changed. Payment speed is now near real time, which reduces manual intervention time. Cross-border exposure has expanded, so country and sanctions considerations have changed. API initiation creates different authentication and data-quality dependencies. New destination markets may change beneficiary and correspondent-bank exposure. Volume growth can change monitoring thresholds and operational capacity. The bank should also determine whether existing payment messages contain sufficient underlying-party information for screening and monitoring.

The control response then follows those drivers. The bank may refresh due diligence on the PSP’s new product and geographies, validate the PSP’s own controls, confirm contractual responsibilities, assess sanctions and fraud controls before launch, establish new transaction-monitoring segmentation, test API data completeness, define real-time decision rules, update risk appetite approvals and strengthen post-launch monitoring. None of those actions is justified merely because the customer is “high risk”; each responds to a specific changed exposure.

Testing should reflect the same logic. Test cases should include normal expected traffic, higher-risk corridors, incomplete underlying-party data, sanctions-like names, unusual velocity, repeated new beneficiaries, payment repair, rejected or returned transactions, timeouts and fallback processing. The bank should also test evidence: can an investigator reconstruct which customer profile, risk score, payment data, screening result and decision rules existed when the transaction was processed?

The final approval should record residual risk, control dependencies, accepted limitations and any conditions for launch. After go-live, actual behaviour should be compared with assumptions. If volumes, countries or alert patterns differ materially from the approved model, the risk assessment should be revisited.

What good looks like

A strong risk-based approach is visible in everyday decisions. Staff can explain why a control exists and what risk it addresses. Systems preserve the drivers behind a score. Mandatory legal outcomes cannot be averaged away. Lower-risk treatment is used where justified rather than being viewed as a control failure. Higher-risk relationships receive targeted scrutiny instead of indiscriminate paperwork. Product change automatically prompts consideration of financial-crime exposure. Monitoring uses customer and product context. Investigators can reconstruct decisions. Senior management can see concentrations, control weaknesses and residual risk rather than only workload statistics.

Most importantly, the framework stays dynamic. FATF’s current standards, amended through June 2026, continue to place the risk-based approach at the centre of AML/CFT. The practical requirement for a bank is to keep its assessment connected to changing customers, products, payment rails, jurisdictions and threats, and to demonstrate that its controls remain proportionate to the risks it actually faces.

Further worked cases and independent practice

These portfolio cases develop the choice of proportionate controls, the assessment of residual risk and the distinction between effective risk management and indiscriminate de-risking. Read the chapter and explanations first; allow additional time for the exercises and diagram interpretation. Exercise time is additional to the chapter's reading estimate.

Risk assessment is a decision process, not a score

A customer-risk score can be useful, but the risk-based approach is broader than scoring. It begins with understanding the risk the institution faces before controls, then evaluating how well controls reduce that risk and deciding what residual exposure remains. The bank should be able to explain the reasoning behind the result, not simply show a number produced by a formula.

Inherent risk commonly considers customer type, ownership, products, services, delivery channels, geographies and expected activity. Control effectiveness considers whether identification, due diligence, screening, monitoring, escalation, reporting and governance actually work for that exposure. Residual risk is what remains after those controls are considered. Risk appetite then determines whether that residual risk can be accepted, needs additional mitigation, requires restriction or cannot be supported.

High risk does not automatically mean suspicious, criminal or prohibited. It means the bank needs stronger understanding and controls where appropriate. Conversely, a customer classified as low risk can still generate suspicious activity if behaviour changes.

Portfolio case: two customers in the same higher-risk country

Customer A is a regulated manufacturing company with transparent ownership, audited financials, long-standing counterparties and payments that align with known trade activity. Customer B is a newly established company with opaque ownership, high-value third-party funding, rapid pass-through activity and no credible explanation for its counterparties. Both have exposure to the same country.

A country score alone would treat them similarly. A genuine risk-based approach does not. Geography matters, but so do customer transparency, business purpose, ownership and behaviour. The control response may include different due-diligence depth, approval level, monitoring intensity and review frequency.

This is also why FATF's monitored-jurisdiction statements should not be converted into blanket customer exits. The June 2026 increased-monitoring statement explicitly says FATF does not call for automatic enhanced due diligence or blanket de-risking merely because a jurisdiction is under increased monitoring. Institutions should use the information in their own risk-based framework.

Product case: instant payments

Instant payments increase speed and reduce the time available for intervention. That can increase fraud and mule-account exposure, but it does not mean every instant payment is high risk. The bank can apply proportionate controls at different points: onboarding quality, account-age monitoring, beneficiary risk, device and behavioural signals, transaction limits, fraud warnings, real-time interdiction where appropriate and post-event AML network analysis.

The control design should reflect the risk that must be managed in seconds versus the risk that can be investigated later. A daily batch can support network detection but cannot stop value moving in real time. A real-time model can prevent some losses but may create customer friction, so thresholds and override rules require governance.

Simplified measures are not weak controls

Where law and risk assessment permit, simplified due-diligence measures can be appropriate for lower-risk relationships. Simplification should follow from evidenced lower risk; it should not mean abandoning core identification or ignoring unusual activity. The institution should be able to explain why a measure is simplified, what risk assumption supports that choice and what events would trigger stronger measures.

This matters for financial inclusion. Excessive documentation requirements, rigid thresholds or blanket sector exits can exclude legitimate customers without materially reducing crime. Proportionality means using enough control to manage the risk—not the maximum possible control regardless of context.

De-risking versus risk management

Exiting every customer in a higher-risk sector can move financial activity outside regulated channels and reduce visibility. At the same time, a bank is not required to accept risk it cannot understand or control. The professional question is whether the specific residual risk is manageable within law and appetite.

A defensible exit decision should therefore show the customer or portfolio risk, the controls attempted, the unresolved exposure, the applicable policy or legal constraint and the decision authority. "High-risk industry" alone is weak reasoning.

Practice exercise — work through this before reading on.

Control-design exercise

Choose one risk factor—complex ownership, cash intensity, correspondent banking, crypto exposure, high-risk geography or non-face-to-face onboarding. Design three levels of response: standard, enhanced and unacceptable/unmanageable. For each level, state what additional information is required, what approval is needed, what monitoring changes, what evidence must be retained and what event triggers re-assessment.

Then test the design against false positives. Could a legitimate charity, treasury centre, payment institution or family-owned business be unfairly classified? If so, what contextual information would distinguish it?

Practice exercise — work through this before reading on.

Residual-risk and risk-appetite exercise

Consider a bank that has strong onboarding and sanctions screening but weak transaction-monitoring coverage for a new product. The product's inherent risk may be moderate, but the weak detective control can make residual risk unacceptable until coverage is improved. This demonstrates why risk rating cannot be based only on customer characteristics. Control effectiveness is part of the risk picture.

Now reverse the example. A product has high inherent cross-border exposure but excellent transparency, robust customer due diligence, strong real-time and post-event controls and mature investigations. Residual risk can be materially lower than inherent risk without pretending the underlying exposure disappeared.

Final proportionality test

For each of the following, state whether the correct response is stronger due diligence, different monitoring, a legal prohibition, customer restriction, additional evidence or no special treatment: a PEP with transparent wealth; a low-risk retail customer receiving victim-linked fraud proceeds; a customer in a FATF monitored jurisdiction; a payment involving a legally prohibited party; a charity operating in a conflict region with strong governance; an opaque company using unexplained third-party funding; and a long-standing company expanding into a new country.

The discipline is to ask what risk is present, what evidence is missing, which control addresses that risk and whether the response is proportionate. Risk-based does not mean relaxed. It means targeted, explainable and effective.

References and further reading

These public, authoritative materials were used to validate this lesson. FATF and Basel materials establish international standards and supervisory guidance, while Wolfsberg provides industry guidance. Binding obligations still depend on the law, regulation and policy applicable to the relevant bank legal entity and jurisdiction.

The core design principle is to apply stronger or simplified measures according to identified risk where the applicable framework permits, while keeping mandatory legal prohibitions, reporting thresholds and other non-discretionary obligations outside ordinary risk scoring.