Summary
Customer risk-rating (CRR) determines the intensity of due diligence, the frequency of review, and the sensitivity of monitoring. Its design shapes the whole KYC operating model.
Attributes
Attribute selection should be driven by the EWRA. Common categories include customer type, geography, product usage, expected activity, source-of-wealth complexity, and adverse-information findings.
Weighting and aggregation
Weightings should be justified against typologies and outcomes, not set by convention. Simple additive models are defensible if calibrated; more complex approaches require validation against outcomes.
Override governance
Overrides are unavoidable and must be governed. Every override should be recorded, reasoned, time-bound and periodically reviewed at aggregate for pattern.
Periodic review
Ratings should refresh on defined triggers: event-driven changes, expected periodic review, and portfolio-wide recalibration.
Calibration
Backtesting against SAR outcomes, investigation findings and monitoring alerts closes the loop between rating and detection.
Limitations
CRR is a prioritisation tool. It does not by itself detect financial crime; it directs finite resources.
Related expertise
Frequently asked questions
What should risk leaders know about attributes?
Attribute selection should be driven by the EWRA. Common categories include customer type, geography, product usage, expected activity, source-of-wealth complexity, and adverse-information findings.
What should risk leaders know about weighting and aggregation?
Weightings should be justified against typologies and outcomes, not set by convention. Simple additive models are defensible if calibrated; more complex approaches require validation against outcomes.
What should risk leaders know about override governance?
Overrides are unavoidable and must be governed. Every override should be recorded, reasoned, time-bound and periodically reviewed at aggregate for pattern.
What should risk leaders know about periodic review?
Ratings should refresh on defined triggers: event-driven changes, expected periodic review, and portfolio-wide recalibration.
What should risk leaders know about calibration?
Backtesting against SAR outcomes, investigation findings and monitoring alerts closes the loop between rating and detection.