NewsSEALSQ takes a majority stake in Wecan Group — a CHF 5M investment to accelerate our AI Compliance Co-Pilot.
Wecan
Back to blog
Insights10 min read· July 24, 2026

Customer Risk Scoring and the Risk-Based Approach: A 2026 Playbook

How to build a defensible customer risk-scoring model in 2026: risk factors, dynamic re-scoring, tier-based controls, and the model governance regulators now expect.

by Wecan

Every KYC decision an institution makes — how much documentation to demand, whether to escalate to enhanced due diligence, how often to review a relationship — flows from a single question: how risky is this client? In 2026, regulators no longer accept an intuitive or purely categorical answer. They expect a documented, reproducible customer risk score, applied consistently across the portfolio and demonstrably kept current.

This article is written for Chief Compliance Officers and Heads of KYC who need to build or defend a risk-scoring model that survives supervisory scrutiny. We cover the risk-based approach (RBA) fundamentals, the factors that drive a score, why annual recalculation is no longer enough, how to turn scores into proportionate action, and the model governance standard that separates a defensible programme from a black box.

1. The risk-based approach: why it is mandated, not optional

The risk-based approach is the organising principle of modern AML supervision. Rather than applying identical controls to every client, an institution allocates its due-diligence effort in proportion to the money-laundering and terrorist-financing risk each relationship actually presents. Low-risk relationships receive streamlined treatment; high-risk relationships receive enhanced scrutiny. The score is what makes that allocation objective and auditable.

This is not a best-practice suggestion. The FATF has placed the RBA at the centre of its recommendations for over a decade, and national regimes have translated it into binding law. In Switzerland, the AMLA (LBA/GwG/LRD) and the FINMA AML ordinance (OBA-FINMA/GwV-FINMA/ORD-FINMA) require intermediaries to classify business relationships and transactions by risk and to calibrate their controls accordingly. In the EU, the incoming AMLA authority and the single rulebook push the same logic toward harmonised, supervisable expectations. Our overview of the Swiss AML 2026 changes sets out how the LETA transparency reform, effective 1 October 2026, raises the bar further on beneficial-ownership data quality feeding these scores.

The supervisory consequence is direct: when an examiner reviews a file, they do not merely ask whether you performed due diligence. They ask whether the level of due diligence matched the risk, and whether you can show the reasoning. A programme that cannot produce a coherent score and explain how it drove each decision is exposed regardless of how much work the analysts actually did. This is why risk scoring sits upstream of nearly every other control described across our Wecan Comply platform.

2. The risk factors that drive a score

A defensible score is built from a defined set of weighted factors, each with documented rationale. The exact weights differ by institution and business model, but the factor families are well established. The table below shows a representative model with indicative weightings.

2.1 The core risk-factor model

Risk factor What it captures Indicative weight Higher-risk signals
Client type Natural person, operating company, holding, trust, foundation, PIC 10–15% Complex legal vehicles, nominee arrangements
Geography Country of residence, nationality, incorporation, asset location 15–20% FATF grey/black lists, high-corruption jurisdictions, sanctions nexus
Product / service Account type, credit, custody, correspondent, payable-through 10–15% Payable-through accounts (art. 37 AMLO-FINMA), cash-intensive products
Delivery channel Face-to-face, remote, intermediated via EAM or introducer 10% Non-face-to-face onboarding, long intermediary chains
PEP status Domestic/foreign PEP, family member, close associate 15–20% Foreign senior political figure, state-owned enterprise link
UBO / ownership complexity Number of layers, cross-border structures, opacity 10–15% Multi-jurisdiction layering, undisclosed or circular ownership
Transaction profile Expected volume, frequency, counterparties, corridors 10–15% Activity inconsistent with stated profile, high-risk corridors
Source of wealth / funds Origin, plausibility, documentary support 10% Unverifiable origin, high-risk economic activity

2.2 Why weighting and interaction matter

A common failure is treating factors as an additive checklist. In practice, factors interact: a PEP with a simple domestic profile and transparent wealth is not the same risk as a PEP behind a four-layer offshore structure with activity in a sanctioned corridor. A credible model therefore combines a weighted base score with escalation rules — certain combinations force a minimum tier regardless of the arithmetic. Documenting these interaction rules is as important as documenting the weights themselves, because it is where examiners probe hardest.

The quality of the underlying data also caps the quality of the score. Feeding a scoring engine with unverified beneficial-ownership data or stale geographic flags produces a confident number built on sand. This is why data capture at onboarding and structured UBO resolution are prerequisites, not afterthoughts. A useful discipline is to record, alongside each factor, the source and date of the data behind it; a score whose inputs are aging is itself a signal that the relationship warrants a fresh look, independent of any single risk event.

3. Static versus dynamic scoring: why annual recalculation is not enough

Historically, most institutions scored a client at onboarding and recalculated on a fixed cycle — annually for high risk, every two or three years for lower tiers. The problem is structural: risk does not move on your review calendar. A client can acquire a PEP role, appear on a sanctions list, restructure ownership, or shift their transaction pattern the day after their annual review closes. Under a purely periodic model, that elevated risk sits undetected for up to twelve months.

3.1 Event-driven re-scoring

The 2026 standard is event-driven, continuous re-scoring. Instead of waiting for a calendar date, the score recalculates whenever a material input changes: a new adverse-media hit, a sanctions-list update, a change of directors in the commercial register, a threshold-breaching transaction, or an update to the client's declared profile. The review is triggered by the change in risk, not by the passage of time. This is the operating principle of perpetual KYC, which replaces the fixed-cycle review with continuous monitoring and exception-based analyst intervention.

The difference is not cosmetic. A static model measures risk at discrete points and assumes stability in between; a dynamic model treats the score as a live variable. For a supervisor, a live score is also stronger evidence of control — it demonstrates that the institution knows its clients on an ongoing basis, which is the substantive obligation, rather than merely re-attesting to it once a year.

4. Turning the score into action: controls and review cadence by tier

A score is only useful if it deterministically drives what happens next. The mapping from tier to controls and review frequency should be written into policy, applied automatically, and identical for every client in a tier — this is where consistency is won or lost.

4.1 Risk tier to control and cadence

Risk tier Onboarding treatment Ongoing controls Review cadence
Low Standard CDD, automated verification, straight-through where clean Baseline monitoring, event-driven flags Every 3 years (or on trigger)
Medium Standard CDD plus targeted checks, brief analyst review Enhanced monitoring thresholds, periodic sampling Every 2 years (or on trigger)
High EDD: source-of-wealth evidence, senior sign-off Continuous monitoring, tighter transaction thresholds Annual (or on trigger)
Unacceptable / prohibited Onboarding declined or exited N/A — relationship not entered or terminated N/A

4.2 EDD triggers and escalation

Enhanced due diligence should be triggered by clear, documented conditions rather than analyst discretion alone: a high-risk tier, PEP status, a high-risk jurisdiction nexus, payable-through account arrangements, or a scoring escalation rule firing. When any trigger is met, the file follows a defined EDD path — additional source-of-wealth evidence, senior management approval, and tighter ongoing thresholds — and the reasons are recorded against the score. This turns escalation from a judgement call into a repeatable, auditable process, and it ensures that two analysts facing the same facts produce the same outcome. The downstream review workload this generates is handled through the periodic reviews and client lifecycle workflows.

5. Model governance and explainability: the 2026 demonstrable-effectiveness standard

The single biggest shift in supervisory expectation is that having a scoring model is no longer enough; you must be able to demonstrate that it works and explain how it reaches its conclusions. This is the demonstrable-effectiveness standard, and it has direct consequences for how a model is built.

5.1 Documented methodology and traceable inputs

Every score must be reconstructable. That means a written methodology setting out the factors, weights, interaction and escalation rules, and their rationale; version control so you can show which methodology applied to a given decision; and full traceability from the final score back to the specific data inputs that produced it. When an examiner asks "why is this client rated medium rather than high?", the answer must be a factual trace, not an analyst's recollection.

5.2 Avoiding bias and the black-box problem

Opaque scoring — whether from an undocumented spreadsheet or an unexplainable machine-learning model — is now a liability. If you cannot explain a score, you cannot defend it, correct it, or prove it is free of inappropriate bias. The governance standard therefore favours transparent, rule-based models whose logic is fully inspectable, with any statistical components constrained to explainable, auditable behaviour. Periodic model validation — testing the score against actual outcomes, tuning weights, and documenting the changes — closes the loop and is itself an examinable control. These governance requirements are why platform-level controls, described under Wecan Comply security, matter as much as the scoring logic.

6. Where automation delivers measurable gains

Manual scoring fails in a specific and predictable way: it drifts. Two analysts weigh the same factors differently, the same analyst weighs them differently on a busy afternoon, and no one re-scores the portfolio the moment new data arrives. Automation attacks exactly these weaknesses.

6.1 Consistency, currency, and throughput

Automated scoring applies one methodology identically to every file, eliminating inter-analyst drift. It re-scores instantly when any monitored input changes, so the portfolio is always current rather than current-as-of-last-review. And it removes the manual recalculation burden that makes continuous scoring impossible by hand. The table below quantifies the typical impact, using ranges consistent with our broader KYC/AML ROI analysis.

Metric Manual scoring Automated scoring Gain
Time per periodic review 2–4 hours 20–45 minutes −70%
Clients per analyst per month 15–25 80–120 ~4–5x
Portfolio re-scoring latency Up to 12 months Real-time on new data Near-instant
Scoring consistency across analysts Variable Uniform methodology Drift eliminated
Manual periodic-review workload removed 70–90% Major reduction

The freed capacity does not disappear; it redeploys onto the small share of genuinely high-risk files where human judgement adds the most value. That is the practical meaning of the risk-based approach — spending analyst time where risk actually concentrates.

7. How Wecan Comply operationalizes risk scoring

Wecan Comply treats the customer risk score as a living, governed object rather than a one-time calculation. The factor model, weights, and escalation rules are configured to your institution's methodology and applied identically across the entire portfolio, removing manual drift. Scores recalculate automatically as monitored inputs change — sanctions and PEP updates, ownership changes, adverse media, transaction signals — so every relationship carries a current rating rather than a stale one.

Because every score is traceable back to its inputs and the methodology version that produced it, the model is explainable by construction: each rating can be reconstructed and defended in front of a supervisor. Tier-based controls, EDD triggers, and review cadences flow automatically from the score, and the resulting review work is orchestrated through structured periodic review and lifecycle workflows. The result is a risk-based approach that is consistent, current, and demonstrably effective — the standard 2026 supervision now expects.

See Wecan in action. In 30 minutes.

A live walkthrough on real KYC scenarios — no slides, no commitment. Just see if it fits your context.