One Constellation
Free Interactive Tool

AML Risk Scoring Calculator

Score any customer against a FATF-aligned risk matrix in under a minute. Enter the eight factors that drive customer risk and get an indicative risk rating, the due diligence level you should apply, and the review cycle that goes with it.

FATF Recommendation 10 aligned No sign-up required Nothing is stored

Score a customer

8 factors · updates live
Indicative risk score
0/100
Risk rating
Low
Simplified DD
Due diligence level
36 months
Periodic review cycle
Analyst
Approval authority
What is driving the score

    How to read this. This calculator applies a generic weighted matrix for illustration. It is not a substitute for your own board-approved risk methodology, and it does not screen any name against sanctions, PEP or adverse media data. Your firm's matrix should reflect your national risk assessment, your regulator's expectations and your own product set. Nothing you type here is transmitted or stored.
    Methodology

    How the score is calculated

    The calculator uses a weighted additive model, which is the most common structure for customer risk rating in regulated firms. Each of the eight factors carries a maximum point value reflecting how strongly it correlates with money laundering and terrorist financing risk in FATF's own typologies. The raw total is normalised to a 0–100 scale so scores stay comparable as you change the inputs.

    Two inputs act as override triggers rather than simple additions. A customer connected to a jurisdiction subject to a FATF call for action, or an unresolved sanctions or watchlist match, will floor the rating at High regardless of how benign the other seven factors look. This mirrors the way most institutions build hard stops into an otherwise additive matrix, and it prevents a low-value retail product from diluting a factor that regulators treat as non-negotiable.

    Factor weightings used

    • Customer type (max 25) — legal form and ownership opacity. Nominee arrangements and bearer instruments score highest because they defeat beneficial ownership transparency.
    • Country risk (max 25) — the highest-risk jurisdiction anywhere in the relationship: residence, incorporation, UBO nationality or the origin of funds.
    • Screening outcome (max 25) — sanctions, PEP and adverse media results, weighted by whether the hit was resolved.
    • Product or service (max 20) — correspondent banking, virtual assets and private banking carry the highest inherent exposure.
    • PEP status (max 20) — foreign PEPs attract mandatory enhanced due diligence in most regimes; domestic PEPs and RCAs are risk-based.
    • Expected activity (max 16) — value and velocity relative to the customer's stated profile.
    • Delivery channel (max 14) — non-face-to-face onboarding without biometric liveness is a recognised risk amplifier.
    • Source of wealth (max 14) — verified and documented against self-declared.

    Rating bands and what they mean

    ScoreRatingDue diligenceReview cycleApproval
    0–24LowSimplified due diligence, where your regime permits it36 monthsOnboarding analyst
    25–44MediumStandard customer due diligence24 monthsOnboarding analyst
    45–69HighEnhanced due diligence, documented source of wealth12 monthsCompliance officer
    70–100Very highFull EDD, senior management sign-off, consider whether to accept6 monthsMLRO or senior management
    Why risk rating fails in practice

    A matrix in a spreadsheet is not a risk framework

    Almost every regulated firm has a customer risk matrix. Far fewer can prove that it was applied consistently to every customer, that the rating was refreshed when circumstances changed, or that an analyst who overrode it recorded why.

    🧮

    Scoring drifts between analysts

    When the matrix lives in a document and the score lives in a spreadsheet, two analysts reach two different answers on the same file. Regulators test exactly this during thematic reviews.

    🕓

    Ratings go stale on day two

    A rating calculated at onboarding is a point-in-time judgement. Without event-driven re-scoring, a customer who becomes a PEP or moves funds to a newly grey-listed country keeps a Low rating for years.

    📄

    Overrides are undocumented

    Overrides are legitimate and expected. What supervisors object to is an override with no recorded rationale, no approver and no expiry.

    One Constellation runs your risk matrix as configuration inside the platform rather than as a policy document analysts are expected to remember. Every customer is scored on the same weightings, every factor value is captured against the customer record, and the resulting rating drives what happens next automatically: which due diligence pack is requested, whether the file goes straight through or into a review queue, who is allowed to approve it, and when the next periodic refresh falls due.

    Because scoring is continuous rather than point-in-time, a sanctions list update, a new adverse media hit, a change in the FATF lists or a transaction pattern outside the expected profile re-triggers the calculation and moves the customer into the right queue on its own. Every recalculation is written to an immutable audit trail with the inputs, the output and the person who accepted or overrode it.

    Questions

    About AML risk scoring

    What is an AML risk score?+
    An AML risk score is a numerical rating a regulated firm assigns to each customer to express how much money laundering and terrorist financing risk that relationship carries. The score is produced by applying weightings to risk factors such as customer type, jurisdiction, product, delivery channel and screening results. It determines the depth of due diligence applied, how often the file is reviewed, and who has authority to approve the relationship.
    Which risk factors are mandatory under FATF?+
    FATF Recommendation 10 and its interpretive note require a risk-based approach built on customer risk, country or geographic risk, and product, service, transaction and delivery channel risk. Most regimes then layer on specific requirements: enhanced due diligence for foreign PEPs, for correspondent banking relationships, and for customers connected to jurisdictions FATF has identified as higher risk. Read more on our regulations hub.
    Can a low score justify simplified due diligence?+
    Only where your regime permits it and your own risk assessment supports it. Simplified due diligence is not an exemption from customer due diligence; it allows you to reduce the extent, timing or type of measures applied. It is generally unavailable where there is any suspicion of money laundering, and never available for customers connected to jurisdictions subject to a FATF call for action.
    How often should customer risk ratings be refreshed?+
    Periodic review cycles are typically 12 months for high-risk customers, 24 for medium and 36 for low, though supervisors increasingly expect event-driven review as well as calendar-driven review. Any material change — a new sanctions match, a change in beneficial ownership, a jurisdiction being added to the FATF grey list, or activity inconsistent with the expected profile — should re-trigger the assessment immediately rather than waiting for the next cycle.
    Does this calculator screen names against sanctions lists?+
    No. This tool only models the risk matrix. It has no access to sanctions, PEP or adverse media data, and it does not perform any name matching. Screening is a separate control, and One Constellation delivers it inside the platform using World-Check data. See our AML and CFT solution.
    Can our own weightings be configured in One Constellation?+
    Yes. The platform's risk engine is configuration rather than code. You define your own factors, weightings, band thresholds, hard-stop triggers, approval hierarchies and review cycles, and they apply consistently to every customer from that point forward. Changes to the matrix are versioned so you can evidence which methodology was in force when any given customer was rated.

    Run your matrix automatically, on every customer

    Book a 30-minute demo and see your own risk factors configured live, driving due diligence, approval routing and review scheduling end to end.

    Scroll to Top