The onboarding assessment is a snapshot

A static assessment uses information available at a defined moment, usually onboarding or a periodic review. It may consider legal form, business activity, ownership, expected turnover, products, delivery channel, and geographic exposure. Static does not mean useless: a consistent baseline is essential for deciding what due diligence and monitoring are appropriate at the start of a relationship.

The limitation is time. A customer’s ownership can change. A new product can alter how the account is used. Transaction behaviour can depart from the stated profile. Screening information can change. If a score remains fixed while the evidence changes, it becomes a description of the past rather than a useful view of current risk.

SAMA’s AML/CTF guidance, for example, says customer risk profiles should be reviewed and updated regularly based on risk, and its monitoring section connects ongoing monitoring results with review of customer information and categorisation. Institutions should apply the exact requirements of their own jurisdiction; the broader operational lesson is that monitoring and customer assessment should inform each other.

What dynamic scoring adds

Dynamic scoring recalculates or reassesses risk when relevant information arrives. That may happen on a schedule, after an event, or both. The important design question is not whether a dashboard moves in real time. It is whether material evidence reaches the assessment soon enough to support the institution’s controls.

Event-driven updates might follow a change in beneficial ownership, a new country connection, a material shift in transaction volume, a new potential screening match, repeated device anomalies, or an analyst-confirmed data correction. Scheduled updates remain useful because not every change generates a clean event and some sources are refreshed periodically.

Each trigger should be linked to a policy. A sudden volume increase may raise a behavioural component and open a review task; it should not silently reclassify every growing business as high risk. A changed phone number may be routine, while a cluster of access and payment changes may justify closer attention. Context determines significance.

An illustrative before-and-after

Consider an illustrative wholesale food distributor. At onboarding, the business expects monthly domestic payments to a small group of suppliers. Ownership is straightforward, due-diligence information is complete, and the initial customer assessment falls in the institution’s medium band because of product and transaction characteristics. This example is synthetic and does not describe a Merid customer.

Four months later, financing proceeds arrive. Within 36 hours, most of the funds move in split payments to six newly observed counterparties. Two receive several transfers just below an internal review threshold, and one returns part of the money through another entity. The activity differs from the stated supplier pattern.

A dynamic assessment might increase the behavioural component and create an alert explaining the drivers: new counterparties, rapid onward movement, split payments, and a partial circular flow. It should also show counter-evidence: the customer recently provided purchase orders for an expansion, some recipients are verified equipment vendors, and the returned amount is documented as a cancelled order.

The resulting score change is not a verdict. It identifies what needs review. An analyst might request invoices, contracts, proof of delivery, explanations for the intermediary entity, and an updated forecast. The customer’s risk band may stay elevated, return after evidence is verified, or prompt escalation under policy.

Preserve history, not just the latest number

A current score without history is difficult to defend. Teams need to know the previous value or band, the factors that changed, the evidence timestamp, the applicable policy or model version, and whether an analyst reviewed the change. Historical versions also help distinguish a gradual trend from a one-off spike.

Versioning does not need to mean storing every intermediate calculation forever. Retention should follow legal, regulatory, privacy, and operational requirements. At minimum, preserve enough to reconstruct material decisions and understand which data and policy produced them. SAMA’s record-keeping guidance is a jurisdiction-specific example of requirements for retrievable and auditable records; firms should map retention to the rules that apply to them.

An override belongs in that history. Preserve the original output, the reviewer’s decision, the evidence considered, and the reason. Repeated overrides of the same factor can reveal a model or data problem that needs correction.

Practical limitations

Dynamic does not automatically mean accurate. Late transaction feeds create stale assessments. Duplicated events can exaggerate changes. Sparse history makes behavioural baselines unstable. New customers cannot be compared with their own past, so peer groups may be used—but poorly designed peer groups can create bias or noise.

Teams should define freshness expectations, fallback behaviour, and visible data-quality warnings. They should test how quickly legitimate growth or seasonal activity produces alerts and whether analysts can distinguish that from unexplained deviation. They should also monitor score distributions over time; a sudden shift may reflect a data pipeline or policy change rather than a real change in customer risk.

The strongest design combines a documented onboarding baseline, risk-appropriate periodic review, explicit event triggers, and reviewable history. Dynamic scoring then becomes a controlled way to keep the assessment aligned with evidence—not a stream of unexplained fluctuations.

Primary sources

These sources support the regulatory and standards-related statements in this article. They do not endorse Merid or certify any product.

  1. Risk-Based Approach Guidance for the Banking SectorFinancial Action Task Force (FATF), October 2014
  2. Section 1: ML/TF Risk AssessmentSaudi Central Bank (SAMA) Rulebook
  3. Section 6: Record KeepingSaudi Central Bank (SAMA) Rulebook
  4. Section 7: Monitoring of Transactions and ActivitiesSaudi Central Bank (SAMA) Rulebook