Risk Classification (AML Portal)
Structuring Your KYC/AML Risk Matrix & Tiered Questionnaires
This guide explains how to leverage your Risk Matrix to adjust the depth of your Know Your Customer (KYC) and Anti-Money Laundering (AML) inquiries, link specific questions to tangible risk controls, and maintain an effective risk-based approach.
Understanding the Risk-Based Approach
An effective AML framework doesn't treat every customer the same. Instead, it dynamically scales scrutiny according to the customer's risk profile.
Your customer risk profile is typically calculated using four core risk drivers:
- Customer Risk: Who are they?
- Geographic Risk: Where are they based and operating?
- Product/Service Risk: What services are they buying?
- Delivery Channel Risk: How are they interacting with you?
Tailoring Questionnaires by Risk Tier
Your risk assessment matrix categorizes clients into distinct risk tiers (e.g., Low, Medium, High). Each tier determines the depth of questioning, document requirements, and verification intensity.
- HIGH RISK
- Enhanced Due Diligence
- UBO Deep Dive
- Media
- Screening
- MEDIUM RISK
- Standard Due Diligence
- Proof of Source of Funds
- Business Activity Verification
- LOW RISK
- Simplified Due Diligence
- Standard ID
- Basic Occupation / Entity Checks
Low Risk (Simplified Due Diligence)
- Objective: Establish and verify identity with minimal friction.
- Scope: Standard identity verification (Government ID / Corporate Registry extract), address verification, and basic occupation or business activities.
- Review Cadence: Periodic review every 1-2 years.
Medium Risk (Standard Due Diligence)
- Objective: Gain a clear understanding of the customer's financial baseline and expected platform usage.
- Scope: Standard ID checks plus detailed inquiries into the Source of Funds, expected transaction volumes, and operational business activities.
- Review Cadence: Annual or bi-annual review.
High Risk (Enhanced Due Diligence)
- Objective: Uncover ultimate ownership, hidden political exposure, and potential illicit ties before establishing a business relationship.
- Scope: Full EDD package including Source of Wealth verification, face-to-face or video interviews, deep Ultimate Beneficial Owner (UBO) unlayering, adverse media screening, and direct verification of bank details.
- Review Cadence: Continuous monitoring with mandatory annual or semi-annual reviews and required Senior Management Sign-off.
Mapping Questions to Risk Controls & Red Flags
Every question asked during onboarding or re-assessment must serve a specific purpose. If a question reveals a risk indicator, it should immediately trigger a corresponding internal control or mitigation action.
Risk Category | KYC / AML Inquiries | Identified Red Flag | Control & Mitigation Action |
Political Exposure | "Are you, any immediate family member, or any UBO a Politically Exposed Person (PEP)?" | Close associate or PEP status confirmed. | Trigger EDD, escalate to Chief Compliance Officer (CCO) for sign-off, reduce transaction limits. |
Ownership Structure | "What is the country of incorporation, and who are the UBOs (>25% or >10% depending on jurisdiction)?" | Complex offshore ownership or shell company structure. | Request full ownership chart, verify all UBO IDs, run targeted adverse media screening. |
Expected Activity | "What is your expected monthly transaction volume, average transaction size, and primary corridors?" | Projected activity exceeds standard retail/SME baselines. | Set custom automated alert thresholds in transaction monitoring tool. |
Source of Funds | "What is the origin of the funds deposited/transacted with us?" | Vague answers (e.g., "savings" or "consulting" without proof). | Freeze withdrawals/deposits pending bank statements, tax returns, or audited accounts. |
Virtual Assets | "Do you plan to interact with or transact using cryptocurrencies or virtual assets?" | Unregulated Virtual Asset Service Provider (VASP) exposure. | Apply wallet screening tools (Chainalysis/Elliptic) and enforce strict VASP counterparty checks. |
Geographic Risk | "Will you operate in or transfer funds to/from non-FATF compliant jurisdictions?" | High-risk/sanctioned jurisdiction exposure. | Block transactions to non-permitted regions or require manual compliance review per transfer. |
Best Practice
- Align questions to specific risks: Every question must map to a customer, geographic, product, or delivery channel risk driver.
- Avoid dead-end inquiries: Ensure every answer has a defined next step (Clear, Flag, or Escalate).
- Proportionate friction: Match the questionnaire length to the customer's risk tier to optimize onboarding conversion.
- Verifiable inputs: Never ask a high-risk question without requiring supporting documentation (e.g., audited statements, tax filings).
- Continuous alignment: Regularly review your risk matrix against updated local regulatory requirements (e.g., EU Anti-Money Laundering Directives, FATF guidance).
.png)