AML Risk Scoring Calculator
Score any customer against a FATF-aligned risk matrix in under a minute. Enter the eight factors that drive customer risk and get an indicative risk rating, the due diligence level you should apply, and the review cycle that goes with it.
Score a customer
8 factors · updates liveHow the score is calculated
The calculator uses a weighted additive model, which is the most common structure for customer risk rating in regulated firms. Each of the eight factors carries a maximum point value reflecting how strongly it correlates with money laundering and terrorist financing risk in FATF's own typologies. The raw total is normalised to a 0–100 scale so scores stay comparable as you change the inputs.
Two inputs act as override triggers rather than simple additions. A customer connected to a jurisdiction subject to a FATF call for action, or an unresolved sanctions or watchlist match, will floor the rating at High regardless of how benign the other seven factors look. This mirrors the way most institutions build hard stops into an otherwise additive matrix, and it prevents a low-value retail product from diluting a factor that regulators treat as non-negotiable.
Factor weightings used
- Customer type (max 25) — legal form and ownership opacity. Nominee arrangements and bearer instruments score highest because they defeat beneficial ownership transparency.
- Country risk (max 25) — the highest-risk jurisdiction anywhere in the relationship: residence, incorporation, UBO nationality or the origin of funds.
- Screening outcome (max 25) — sanctions, PEP and adverse media results, weighted by whether the hit was resolved.
- Product or service (max 20) — correspondent banking, virtual assets and private banking carry the highest inherent exposure.
- PEP status (max 20) — foreign PEPs attract mandatory enhanced due diligence in most regimes; domestic PEPs and RCAs are risk-based.
- Expected activity (max 16) — value and velocity relative to the customer's stated profile.
- Delivery channel (max 14) — non-face-to-face onboarding without biometric liveness is a recognised risk amplifier.
- Source of wealth (max 14) — verified and documented against self-declared.
Rating bands and what they mean
| Score | Rating | Due diligence | Review cycle | Approval |
|---|---|---|---|---|
| 0–24 | Low | Simplified due diligence, where your regime permits it | 36 months | Onboarding analyst |
| 25–44 | Medium | Standard customer due diligence | 24 months | Onboarding analyst |
| 45–69 | High | Enhanced due diligence, documented source of wealth | 12 months | Compliance officer |
| 70–100 | Very high | Full EDD, senior management sign-off, consider whether to accept | 6 months | MLRO or senior management |
A matrix in a spreadsheet is not a risk framework
Almost every regulated firm has a customer risk matrix. Far fewer can prove that it was applied consistently to every customer, that the rating was refreshed when circumstances changed, or that an analyst who overrode it recorded why.
Scoring drifts between analysts
When the matrix lives in a document and the score lives in a spreadsheet, two analysts reach two different answers on the same file. Regulators test exactly this during thematic reviews.
Ratings go stale on day two
A rating calculated at onboarding is a point-in-time judgement. Without event-driven re-scoring, a customer who becomes a PEP or moves funds to a newly grey-listed country keeps a Low rating for years.
Overrides are undocumented
Overrides are legitimate and expected. What supervisors object to is an override with no recorded rationale, no approver and no expiry.
One Constellation runs your risk matrix as configuration inside the platform rather than as a policy document analysts are expected to remember. Every customer is scored on the same weightings, every factor value is captured against the customer record, and the resulting rating drives what happens next automatically: which due diligence pack is requested, whether the file goes straight through or into a review queue, who is allowed to approve it, and when the next periodic refresh falls due.
Because scoring is continuous rather than point-in-time, a sanctions list update, a new adverse media hit, a change in the FATF lists or a transaction pattern outside the expected profile re-triggers the calculation and moves the customer into the right queue on its own. Every recalculation is written to an immutable audit trail with the inputs, the output and the person who accepted or overrode it.
About AML risk scoring
Other free compliance tools
Run your matrix automatically, on every customer
Book a 30-minute demo and see your own risk factors configured live, driving due diligence, approval routing and review scheduling end to end.
