Customer Risk Profile
Pronunciation: KUS-tuh-mer RISK PROH-fyle
Definition
A Customer Risk Profile is a documented view of a customer’s financial-crime and related risk based on identity, ownership, business activity, geography, products, channels, expected behavior, transaction history, and adverse information. It is an individualized application of risk factors, while an enterprise-wide or AML risk assessment evaluates exposure at program or organizational level. The profile should record factor sources, weighting, overrides, review date, confidence, expected activity, due-diligence level, monitoring treatment, changes over time, and rationale for acceptance, restriction, or exit.
Overview
A Customer Risk Profile is a documented view of a customer’s financial-crime and related risk based on identity, ownership, business activity, geography, products, channels, expected behavior, transaction history, and adverse information. The control exists to identify, assess, and control financial-crime exposure while supporting proportionate customer due diligence, transaction decisions, investigation, and regulatory reporting. It is an individualized application of risk factors, while an enterprise-wide or AML risk assessment evaluates exposure at program or organizational level. It should be interpreted alongside AML Risk Assessment because the concepts can affect the same decision without representing the same control, event, or risk.
The workflow combines customer and beneficial-owner information, expected activity, transaction data, counterparties, geography, delivery channel, typologies, and external intelligence. Automated indicators should create explainable alerts or risk changes, while trained analysts review context, request evidence, document uncertainty, and escalate according to authority. In this context, the profile should record factor sources, weighting, overrides, review date, confidence, expected activity, due-diligence level, monitoring treatment, changes over time, and rationale for acceptance, restriction, or exit.
It should connect the term to Business Verification where that relationship changes access, transaction treatment, investigation, communication, or recovery.
Records should preserve source data, rule and model versions, timestamps, thresholds, attribution confidence, customer explanations, analyst notes, approvals, restrictions, and links to cases or reports. Data quality, false positives, missed scenarios, and changes in products or threats need periodic testing.
Useful measures include review coverage, alert volume, true-positive yield, investigation time, overdue cases, risk-rating changes, reporting outcomes, data-quality exceptions, and effectiveness findings from independent testing.
The relationship with Suspicious Activity Monitoring should be documented where it affects residual risk or control ownership.
Key Takeaway
The profile should record factor sources, weighting, overrides, review date, confidence, expected activity, due-diligence level, monitoring treatment, changes over time, and rationale for acceptance, restriction, or exit.
Sources
- Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPs — FATF (2026-08-03)
- Virtual Assets Red Flag Indicators of Money Laundering and Terrorist Financing — FATF (2026-08-03)
- Sanctions Compliance Guidance for the Virtual Currency Industry — U.S. Treasury OFAC (2026-08-03)