Start with the decision the score supports
An AML risk score is a structured assessment of exposure to money-laundering and related financial-crime risk. It combines information the institution considers relevant—such as customer type, ownership, geography, expected activity, products used, counterparties, and observed transactions—into an output that helps determine the appropriate level of review and monitoring.
The score is useful only when it is tied to a clear operational decision. A customer score may influence due-diligence depth or review frequency. A transaction score may help prioritise an alert. A case score may help a team order its investigation queue. Those are different decisions, so they should not be collapsed into one unexplained number.
This reflects the risk-based approach described by FATF: institutions should identify, assess, and understand their money-laundering and terrorist-financing risks, then apply measures proportionate to those risks. A scoring model can support that process, but it does not replace the institution’s risk assessment, policies, or analyst judgment.
Customer risk and transaction risk answer different questions
Customer risk asks what financial-crime exposure is associated with a relationship, given what is known about the customer and how the account is expected to be used. Relevant factors might include legal form, beneficial ownership, business activity, delivery channel, countries connected to the relationship, products requested, and the reliability or completeness of due-diligence information.
Transaction risk asks whether a payment or pattern merits attention in its current context. A transfer may be unusual because of its amount, timing, velocity, destination, counterparty links, or inconsistency with expected activity. The same transfer can carry different significance for two customers with different businesses and histories.
Neither score should be confused with credit risk. Credit scoring estimates the risk relevant to lending or repayment. AML scoring assesses financial-crime exposure. It is also distinct from sanctions-match confidence: a screening system may estimate how closely a name resembles a listed party, while an AML assessment considers the potential match alongside broader customer and transaction context.
Factors, evidence, and missing information
A defensible model starts with factors that are relevant to the institution’s products, customers, channels, and markets. Each factor needs a definition, an authoritative data source, and a reason it affects the assessment. “High-risk geography,” for example, needs a maintained policy basis; it should not be a vague label embedded in code.
Missing information is itself important, but it must be handled carefully. An absent industry code might indicate an incomplete onboarding record rather than suspicious behaviour. A model should distinguish “known negative,” “not applicable,” and “unknown.” Treating all three as zero conceals uncertainty; treating every unknown as maximum risk can flood teams with low-value alerts.
Analysts need to see which inputs were present, which were missing, and when each item was last updated. That context helps them decide whether to request documents, correct a data-quality issue, or investigate activity. It also prevents a polished score from creating false confidence in thin evidence.
- Customer context: business model, ownership, expected activity, products, and relevant geography.
- Observed behaviour: amounts, frequency, counterparties, velocity, and changes from prior activity.
- External or screening context: potential sanctions or PEP matches from configured sources, subject to review.
- Data quality: completeness, freshness, provenance, and conflicts between sources.
Risk bands make policy visible
Many programmes translate a numerical or categorical assessment into bands such as low, medium, and high. A band should correspond to documented actions—for example, standard review, additional evidence, enhanced monitoring, or escalation. The boundaries are policy choices, not universal truths.
A score of 72 is not automatically a 72 percent probability of money laundering. That interpretation would require a defined outcome, representative data, and validation showing that the score is calibrated as a probability. Most operational AML scores are ranking or policy tools. They should be described that way.
Bands also need an exception path. An analyst may identify reliable context that a model did not receive, or may find that a source record is wrong. Overrides should require a reason and preserve both the original output and the reviewed decision. The goal is not to force every case into the model’s first answer; it is to make the decision process consistent and reviewable.
Analyst review remains consequential
A higher score is a prompt to examine evidence, not a finding of wrongdoing. The analyst should review the events and drivers behind the change, compare activity with the customer’s expected profile, identify legitimate explanations, and request appropriate evidence. A possible sanctions or PEP match likewise remains a potential match until it is resolved through the institution’s process.
A practical operating record includes the model or policy version, input timestamp, reason codes, linked evidence, missing fields, analyst notes, and outcome. It should also show what happened after review: no action, information request, monitoring change, escalation, or another policy-defined step.
For fintech teams, the best starting point is modest: define the decisions, separate customer and transaction assessments, expose the drivers, and test whether analysts can use the result consistently. Sophistication comes from better evidence and feedback—not from adding decimal places to an unexplained score.
Primary sources
These sources support the regulatory and standards-related statements in this article. They do not endorse Merid or certify any product.
- Risk-Based Approach Guidance for the Banking SectorFinancial Action Task Force (FATF), October 2014
- Section 1: ML/TF Risk AssessmentSaudi Central Bank (SAMA) Rulebook
- Section 7: Monitoring of Transactions and ActivitiesSaudi Central Bank (SAMA) Rulebook