Risk Assessment
Score each customer from verified data (identity confidence, screening results, jurisdiction, product and channel) and let the tier decide which checks apply. Same inputs, same rating, every time.
What feeds a rating
Factors and weightings are yours to define. Each rating stores the inputs it used.| Factor | Source | Signals |
|---|---|---|
| Identity confidence | KYC result | high · medium · low |
| Screening result | PEP · sanctions · media | clear · hit |
| Jurisdiction | Address & nationality | standard · high-risk |
| Product & channel | Onboarding context | configurable weighting |
| Behaviour | Monitoring alerts | re-rate on trigger |
Why risk ratings need a system
A risk-based program is only defensible if the ratings themselves are consistent.The approach is mandatory
AUSTRAC requires a risk-based program. That presumes a working method for rating customers.
Consistency
Two analysts, same customer, same rating. Scored factors remove the judgement lottery.
Ratings that move
A new screening hit or address change re-rates the customer then, not at the annual review.
Documented rationale
Each rating stores its inputs, so "why is this customer low risk?" has an answer on file.
Where the checks run
Pick by how your team works; the checks and results are the same.Which factors can feed a rating?
add
Five categories, each drawn from data you have already verified, not entered by hand:
- Identity confidence — from the KYC result, graded high, medium or low
- Screening result — PEP, sanctions and adverse media, clear or hit
- Jurisdiction — from address and nationality, standard or high-risk
- Product and channel — the onboarding context, with configurable weighting
- Behaviour — monitoring alerts, which re-rate on trigger
Which factors you use and how heavily each one weighs are yours to define. The model is not fixed, because the risks a remittance business carries are not the risks a conveyancer carries.
Why do risk ratings need a system at all?
add
Because a risk-based program is only defensible if the ratings themselves are consistent.
AUSTRAC requires a risk-based approach, which presumes a working method for rating customers. If the same customer would be rated medium by one analyst and high by another depending on who picked up the file, the program has a rating step but not a rating method, and that difference becomes very visible under review.
Scored factors remove the judgement lottery. Two analysts, the same customer, the same rating. That consistency is what makes the tiering downstream mean anything at all.
Can an analyst override a rating?
add
Yes, with a recorded reason. Overrides are a necessary part of any scored model, because no set of factors anticipates every situation.
The override sits alongside the scored rating instead of replacing it, so a later review can see both the model's assessment and the human decision, together with the reasoning given at the time.
That structure also makes override patterns visible. If one tier is being overridden downward routinely, that is information about the model, not about the customers, and it is worth acting on.
How often are customers re-rated?
add
Ratings are revisited whenever new information arrives about a customer, and the main source of new information is your monitors.
Monitors re-screen the customers in a program on the schedule you set, from daily through to quarterly, and raise an event when something is found. Reviewing that event is the point at which the customer's risk level is confirmed or changed, with the reason recorded alongside it.
Scheduled reviews can be layered on top for high tiers, where periodic re-examination is warranted whether or not anything has visibly moved.
The lever here is cadence. A customer screened daily is re-rated within a day of a new match appearing; one screened quarterly may not be. Matching the schedule to the risk tier is how you keep that exposure inside your own appetite instead of leaving it to chance.
How do tiers connect to check depth?
add
Each tier maps to a defined check set: standard customer due diligence for low, added screening for medium, full enhanced due diligence for high.
The rating decides and the checks follow automatically, which is the part that makes the model operational instead of descriptive. A rating that does not change what happens to the customer is a label, not a control.
Because the mapping is configured, not fixed, you can adjust what each tier requires as your risk assessment evolves, and the change applies consistently from that point forward.
What is stored with each rating?
add
The inputs the rating used, and the rationale.
That means "why is this customer low risk?" has an answer on file, and the answer identifies the specific factor values that produced the score, not a general description of the methodology.
It also means a historical rating can be understood in its own context. If a customer's rating is questioned two years later, you can see what was known at the time it was assigned, which is a different question from what is known now, and the only fair basis on which an earlier decision can be assessed.
Can we feed our own events into a re-rate?
add
Yes. Ratings can be pulled into your own systems, and events that should trigger a re-rate can be pushed in from them.
That matters because some of the most useful risk signals are ones only you hold: a disputed transaction, a failed payment, a complaint, an internal escalation. A rating built solely on external data misses them.
Caspar also feeds the factors directly, contributing court records, address history and associations as inputs to the model instead of as separate research a reviewer has to reconcile by hand.
Other solutions
AML/CTF compliance
Screening, ongoing customer due diligence and audit trails aligned to AUSTRAC requirements.
Read morearrow_forward securityFraud prevention
Detect stolen and synthetic identities before an account is opened.
Read morearrow_forward person_searchInvestigation tools
Search tools for locating people and assembling background information on them.
Read morearrow_forwardRequest a demo of our solutions
Complete the form and our team will be in touch shortly to walk you through how it works.
SOME OF OUR TRUSTED CLIENTS
Request a Demo
"*" indicates required fields
