A customer risk rating model is the method you use to score each customer's money laundering and terrorist financing risk, so you can decide how much scrutiny they need
It combines factors like the customer's country, occupation, product usage, ownership structure and political exposure into a rating, usually low, medium or high, which then drives whether they get standard customer due diligence (CDD) or enhanced due diligence (EDD).
Most institutions have one. Far fewer can explain how it works.
The common pattern goes like this. Someone builds a scoring sheet during an implementation project. Weightings get set once, often by whoever was configuring the platform that week. The model runs at onboarding. Then it sits there, quietly rating people, for years.
This guide covers how to build one deliberately, and more importantly how to keep it accurate after go-live.
For the underlying factors that feed a rating, see our guide to customer risk rating factors. This article deals with what you do with them.
What Is a Customer Risk Rating Model?
A customer risk rating model, sometimes shortened to CRR, is the logic that converts customer attributes into a risk score and a risk band. Some institutions call it a customer risk rating methodology. Professional services firms tend to say client risk rating. Others render it as a customer risk rating matrix, a grid showing which combination of factors lands a customer in which band. Same thing, different packaging.
It exists because the Financial Action Task Force (FATF) Recommendation 1 requires a risk-based approach. You are expected to identify your risks and apply resources proportionate to them, which means you cannot treat every customer identically. Somebody has to decide who gets the light-touch process and who gets source of funds questions and senior management sign-off.
A working model has four parts:
- 1. Risk factors. The attributes you assess, such as country, occupation, product, delivery channel and ownership.
-
- 2. Weightings. How much each factor moves the score.
-
- 3. Bands. The thresholds that turn a score into low, medium or high risk.
-
- 4. Triggers. The events that force a re-rating.
Most institutions get the first one right and improvise the other three. The improvised parts are where examinations go badly.
Why Most Customer Risk Ratings Are Out of Date Within a Year
Here is the problem nobody puts in the project plan.
A customer risk rating is a snapshot. You take it when the relationship opens, based on what the customer told you and what your checks returned that day. Then the world moves.
The customer takes a government appointment and becomes a politically exposed person (PEP). Their trading company starts dealing with a new jurisdiction. Their transaction pattern shifts from small local payments to large cross-border ones. They acquire a business partner who appears in adverse media. Their beneficial ownership changes.
None of these things generate a phone call to your compliance team. If your model only runs at onboarding, the rating on file describes someone who no longer exists, and the level of due diligence you are applying is calibrated to a person who has changed.
That is the case for a model that updates itself, and it is also what the regulator now expects. The CBN's Baseline Standards for Automated AML Solutions, issued in March 2026, require dynamic, risk-based monitoring with customer profiles adjusted in real time rather than static rules applied once.
How to Build a Customer Risk Rating Model in Five Steps
The five steps below take you from a blank page to a model you can defend. Each one ends with a concrete output, because the difference between a model and an opinion is the paperwork behind it.
Step 1: Choose Your Risk Factors and Document the Rationale
Start with the categories every risk-based approach uses: customer risk, geographic or jurisdiction risk, product risk, and delivery channel risk.
Under each, list the specific attributes you will actually assess. Customer risk might cover occupation, PEP status, beneficial ownership complexity, whether they are a cash-intensive business, and adverse media. Geographic risk covers country of residence, country of operation, and the jurisdictions their counterparties sit in. Product risk covers which of your products they use and what those products enable. Delivery channel risk covers whether they were onboarded face to face, remotely, or through an intermediary.
The discipline is to write down why each factor is on the list. An examiner will ask, and "it came with the platform" is a bad answer.
Equally, be willing to remove factors that do not discriminate. If a factor gives the same value to 98% of your customers, it is not telling you anything. It is adding noise to your score and cost to your onboarding.
The Result: A documented factor list with a stated rationale for each.
Step 2: Set the Risk Factor Weightings and Get Them Approved
The weightings are the model. Everything else is data collection.
Two institutions can use identical factors and produce completely different ratings, purely because one weights jurisdiction heavily and the other weights product usage heavily. That difference is not technical. It is a statement about what your organisation believes is risky, which makes it a risk appetite decision.
So it needs a name attached to it. The MLRO or head of compliance should approve the weightings, with senior management endorsement, and the approval should be dated and recorded.
Three practical points.
1. Avoid weightings that let one factor silently dominate. If country risk can single-handedly push any customer into high risk regardless of everything else, you have not built a model, you have built a country blacklist with extra steps.
2. Decide how missing data behaves. If you do not know a customer's occupation, does that score as neutral or as elevated risk? Both are defensible. Only one of them is defensible if you never wrote it down.
3. Handle the automatic overrides separately. Some things should force a rating regardless of score: a confirmed sanctions match, a foreign PEP, a jurisdiction subject to countermeasures. Treat those as rules sitting above the model, not as very large weightings inside it.
The Result: A weightings table with a named approver and a date.
Step 3: Set Your Risk Rating Scale and Band Thresholds
The bands turn a score into an action. Low risk gets standard CDD. High risk gets EDD, source of wealth and source of funds, and senior management approval before onboarding.
Where you draw those lines determines your workload, and this is where honesty pays off.
Ask what proportion of your customer base each band should contain, and then ask whether your team can actually deliver EDD to everyone the high band will capture. A model that rates 30% of your customers high risk is not a rigorous model. It is a model that will produce shortcuts, because the alternative is an EDD backlog nobody can clear.
The failure mode is predictable and it is worse than setting a looser band. Analysts under pressure start completing EDD as a formality, the file gets a tick, and the control becomes documentation rather than diligence.
Set the bands where the work is genuinely deliverable, write down the reasoning, and revisit it when volumes change.
The Result: band thresholds, expected distribution, and a note on the capacity assumption behind them.
Step 4: Build a Dynamic Customer Risk Rating
This is the step that separates a model from a spreadsheet. A dynamic customer risk rating means the score changes when the inputs change, without waiting for a calendar date.
Three things make it work.
1. Event triggers. Define what forces an immediate re-rating: a PEP or sanctions screening hit, adverse media, a change in beneficial ownership, a new jurisdiction appearing in transaction flows, a product upgrade, or transaction behaviour outside the expected pattern you recorded at onboarding.
2. Continuous screening. Your PEP, sanctions and adverse media screening should run against the whole customer base as lists change, not only at onboarding. A customer clean today can be designated next month.
3. Periodic review as a backstop, not the main mechanism. Annual or risk-based cycle reviews still have a place. They just should not be the only time a rating can move. If a customer became a PEP in February and your model notices in November, the review cycle is doing the work that triggers should have done.
Then measure the thing almost nobody measures: how many customers changed band in the last quarter, and why. If the answer is close to zero, your model is not dynamic regardless of what the vendor called it.
The Result: A trigger list, a re-screening schedule, and a quarterly report of rating changes.
Step 5: Validate the Customer Risk Rating Model
A rating model is a model, which means it needs testing by someone who did not build it.
Validation should answer three questions.
1. Does it discriminate? Compare ratings against outcomes. Of the customers who generated suspicious transaction reports (STRs) in the last year, what were they rated? If your STRs are coming predominantly from customers you rated low risk, the model is not identifying risk, and that is a finding you want to make yourself rather than have an examiner make for you.
2. Is it stable? Track the band distribution over time. A sudden shift usually means a data problem upstream rather than a genuine change in your customer base.
3. Is it explainable? Take any customer and ask the system why they are rated as they are. You should get the factors that drove it, not just a number. This matters twice over in Nigeria: the CBN requires explainable models, and under Section 37 of the Nigeria Data Protection Act a customer affected by an automated decision has the right to human intervention and to contest it.
The Result: A validation report, dated, by someone independent of the model's operation.
Customer Risk Rating Requirements Under Nigerian AML Rules
Nigerian institutions are working from three instruments at once, and they pull in the same direction.
1. The Money Laundering (Prevention and Prohibition) Act 2022 and the CBN AML/CFT/CPF Regulations 2022 require a risk-based approach, with enhanced due diligence, source of wealth and senior management approval for higher-risk relationships including PEPs.
2. The CBN Baseline Standards for Automated AML Solutions, issued 10 March 2026, require risk assessment and profiling as one of seven core system functions, with dynamic risk-based monitoring that adjusts customer profiles in real time. Deposit money banks have 18 months from issuance. Other financial institutions have 24.
3. The Nigeria Data Protection Act 2023 governs what happens when the rating drives an automated decision about a person.
Two things are worth flagging for Nigerian compliance teams specifically.
1. Domestic PEP exposure carries more practical weight here than models borrowed from other markets assume. If your weightings came from a template built for a jurisdiction with different corruption dynamics, they will not reflect where your risk actually sits.
2. Beneficial ownership is harder to establish than the model assumes. A rating that treats ownership complexity as a factor is only as good as your ability to see through the structure, which argues for asking directly at onboarding and screening the owners you find, not just the account holder.
How Youverify Supports Dynamic Customer Risk Rating
The judgement in this guide is yours. Nobody else sets your weightings or decides your risk appetite.
What technology should do is make continuous re-rating possible and the reasoning visible. That means screening customers and beneficial owners against sanctions, PEP and adverse media sources continuously rather than once, feeding those hits back into the rating automatically, surfacing the factors behind any score rather than the score alone, and recording every rating change so you can show an examiner what moved and when.
Youverify's customer risk assessment solution supports configurable risk factors and weightings, continuous re-screening, and a full record of every rating decision, built for institutions operating under CBN supervision.
To see how your current model would hold up under examination, talk to our compliance experts.