Every KYC decision an institution makes — how much documentation to demand, whether to escalate to enhanced due diligence, how often to review a relationship — flows from a single question: how risky is this client? In 2026, regulators no longer accept an intuitive or purely categorical answer. They expect a documented, reproducible customer risk score, applied consistently across the portfolio and demonstrably kept current.
This article is written for Chief Compliance Officers and Heads of KYC who need to build or defend a risk-scoring model that survives supervisory scrutiny. We cover the risk-based approach (RBA) fundamentals, the factors that drive a score, why annual recalculation is no longer enough, how to turn scores into proportionate action, and the model governance standard that separates a defensible programme from a black box.
1. The risk-based approach: why it is mandated, not optional
The risk-based approach is the organising principle of modern AML supervision. Rather than applying identical controls to every client, an institution allocates its due-diligence effort in proportion to the money-laundering and terrorist-financing risk each relationship actually presents. Low-risk relationships receive streamlined treatment; high-risk relationships receive enhanced scrutiny. The score is what makes that allocation objective and auditable.
This is not a best-practice suggestion. The FATF has placed the RBA at the centre of its recommendations for over a decade, and national regimes have translated it into binding law. In Switzerland, the AMLA (LBA/GwG/LRD) and the FINMA AML ordinance (OBA-FINMA/GwV-FINMA/ORD-FINMA) require intermediaries to classify business relationships and transactions by risk and to calibrate their controls accordingly. In the EU, the incoming AMLA authority and the single rulebook push the same logic toward harmonised, supervisable expectations. Our overview of the Swiss AML 2026 changes sets out how the LETA transparency reform, effective 1 October 2026, raises the bar further on beneficial-ownership data quality feeding these scores.
The supervisory consequence is direct: when an examiner reviews a file, they do not merely ask whether you performed due diligence. They ask whether the level of due diligence matched the risk, and whether you can show the reasoning. A programme that cannot produce a coherent score and explain how it drove each decision is exposed regardless of how much work the analysts actually did. This is why risk scoring sits upstream of nearly every other control described across our Wecan Copilot platform.
2. The risk factors that drive a score
A defensible score is built from a defined set of weighted factors, each with documented rationale. The exact weights differ by institution and business model, but the factor families are well established. The table below shows a representative model with indicative weightings.
2.1 The core risk-factor model
| Risk factor | What it captures | Indicative weight | Higher-risk signals |
|---|---|---|---|
| Client type | Natural person, operating company, holding, trust, foundation, PIC | 10–15% | Complex legal vehicles, nominee arrangements |
| Geography | Country of residence, nationality, incorporation, asset location | 15–20% | FATF grey/black lists, high-corruption jurisdictions, sanctions nexus |
| Product / service | Account type, credit, custody, correspondent, payable-through | 10–15% | Payable-through accounts (art. 37 AMLO-FINMA), cash-intensive products |
| Delivery channel | Face-to-face, remote, intermediated via EAM or introducer | 10% | Non-face-to-face onboarding, long intermediary chains |
| PEP status | Domestic/foreign PEP, family member, close associate | 15–20% | Foreign senior political figure, state-owned enterprise link |
| UBO / ownership complexity | Number of layers, cross-border structures, opacity | 10–15% | Multi-jurisdiction layering, undisclosed or circular ownership |
| Transaction profile | Expected volume, frequency, counterparties, corridors | 10–15% | Activity inconsistent with stated profile, high-risk corridors |
| Source of wealth / funds | Origin, plausibility, documentary support | 10% | Unverifiable origin, high-risk economic activity |
2.2 Why weighting and interaction matter
A common failure is treating factors as an additive checklist. In practice, factors interact: a PEP with a simple domestic profile and transparent wealth is not the same risk as a PEP behind a four-layer offshore structure with activity in a sanctioned corridor. A credible model therefore combines a weighted base score with escalation rules — certain combinations force a minimum tier regardless of the arithmetic. Documenting these interaction rules is as important as documenting the weights themselves, because it is where examiners probe hardest.
The quality of the underlying data also caps the quality of the score. Feeding a scoring engine with unverified beneficial-ownership data or stale geographic flags produces a confident number built on sand. This is why data capture at onboarding and structured UBO resolution are prerequisites, not afterthoughts. A useful discipline is to record, alongside each factor, the source and date of the data behind it; a score whose inputs are aging is itself a signal that the relationship warrants a fresh look, independent of any single risk event.
3. Static versus dynamic scoring: why annual recalculation is not enough
Historically, most institutions scored a client at onboarding and recalculated on a fixed cycle — annually for high risk, every two or three years for lower tiers. The problem is structural: risk does not move on your review calendar. A client can acquire a PEP role, appear on a sanctions list, restructure ownership, or shift their transaction pattern the day after their annual review closes. Under a purely periodic model, that elevated risk sits undetected for up to twelve months.
3.1 Event-driven re-scoring
The 2026 standard is event-driven, continuous re-scoring. Instead of waiting for a calendar date, the score recalculates whenever a material input changes: a new adverse-media hit, a sanctions-list update, a change of directors in the commercial register, a threshold-breaching transaction, or an update to the client's declared profile. The review is triggered by the change in risk, not by the passage of time. This is the operating principle of perpetual KYC, which replaces the fixed-cycle review with continuous monitoring and exception-based analyst intervention.
The difference is not cosmetic. A static model measures risk at discrete points and assumes stability in between; a dynamic model treats the score as a live variable. For a supervisor, a live score is also stronger evidence of control — it demonstrates that the institution knows its clients on an ongoing basis, which is the substantive obligation, rather than merely re-attesting to it once a year.
