AML Risk Scoring Models | Build & Integrate Client Risk Ratings | WebFootprint
Compliance Integrations AML Risk Scoring → Dynamic Client Ratings

AML Risk Scoring Models: Build and Integrate Effective Risk Scores

Static high/medium/low labels set at onboarding go stale while behaviour and geography risk move. Examiners expect dynamic, explainable AML risk scores that combine transaction behaviour, client profile, and geography into a rating you can defend.

We build and integrate the scoring models that route EDD automatically and survive FIC inspection.

A glass CRM panel and a teal Risk Score CRA seal connected by risk score reports on a ribbon of light, illustrating ongoing AML client risk scoring
R50m
maximum FIC Act financial penalty for a legal person under section 45C
90–95%
of traditional AML monitoring alerts are false positives (PwC-cited industry range)
R410–R830
typical labour cost to review one mid-size institution alert
556
FIC inspections in 2024/25, with 330 institutions told to remediate
The Problem

Sound Familiar?

These are the exact issues MLROs and Heads of Risk bring to us:

  • Client risk ratings set at onboarding stay frozen for years while behaviour and geography risk shift
  • High-risk labels are over-applied, so EDD capacity is wasted proving legitimate clients are clean
  • True high-risk clients sit in medium because nobody wants to own another overloaded review queue
  • Board risk packs and FIC sampling requests cannot explain why a rating was assigned or refreshed
  • Transaction monitoring intensity does not follow the client risk rating, so alerts and EDD work at cross purposes

South Africa exited the FATF grey list in October 2025, but the next mutual evaluation will test whether risk-based client assessment actually works in practice. FICA already requires a documented risk-based approach at client level. Static onboarding labels are no longer enough when supervisors sample your book.

How It Works

What the Risk Scoring Model Actually Does

Behaviour, profile, and geography feed one score → band updates → EDD and monitoring follow. No stale spreadsheet labels.

1

Signals Arrive

Transaction behaviour, client profile fields, and geography exposure update from CRM, core, and monitoring feeds

2

Score Recalculated

Your RMCP weightings produce an explainable score and low/medium/high band with factor breakdown

3

EDD & Monitoring Route

Rising or high bands open EDD queues and raise monitoring intensity; falling bands release capacity

4

Audit Trail Ready

Score packs write back to systems and board reports so FIC sampling questions have answers on file

What We Build

Everything You Need for Defensible Client Risk Rating

Behaviour + Profile + Geography Model

Transaction patterns, client profile factors, and jurisdiction exposure combine into one explainable AML risk score, not a static onboarding label.

Dynamic Score Refresh

Scores re-run on schedule by risk band and on trigger events: unusual activity, product change, adverse media, or geography shift.

EDD & Monitoring Routing

High and rising scores open EDD queues and raise monitoring intensity automatically. Declining scores release capacity back to the team.

Score Explainability Packs

Every rating stores factor contributions, weightings, band outcome, and override rationale so examiners see the logic, not a colour cell.

Board & MLRO Reporting

Portfolio risk distributions, migration between bands, and EDD throughput feed board packs and MLRO reporting without spreadsheet archaeology.

CRM & Core Write-Back

Risk band, score, and evidence links write back to CRM, core banking, or case systems so sales, ops, and compliance see the same rating.

Systems We've Connected to Risk Scoring Models

HubSpotSalesforceMicrosoft DynamicsCore bankingWealth platformsLoan originationCustom case systems
Client Story

From a Six-Month EDD Backlog to Eight Weeks Clear

How a mid-size South African FSP cut false-high EDD reviews by 61% with a dynamic AML risk scoring model.

Before

Static Onboarding Labels

  • Risk bands set once at KYC and rarely refreshed unless a complaint forced a review
  • About 18% of the book sat in high risk, many because geography or product alone forced the band
  • EDD queue ran six months behind; analysts spent weeks proving legitimate clients were clean
  • Board packs showed colour counts with no factor breakdown when supervisors asked why
  • Monitoring thresholds ignored the rating, so alerts and EDD fought for the same capacity
6 months EDD backlog at peak
After

Dynamic AML Risk Scores

  • Behaviour, profile, and geography re-score on schedule and on trigger events
  • High-risk band fell to about 7% with stronger true-positive concentration
  • False-high EDD reviews dropped 61%; backlog cleared in eight weeks
  • Every sample file now opens with factor scores, weightings, and override history
  • Monitoring intensity and EDD routing follow the same live band
8 weeks to clear the backlog
61% fewer false-high EDD reviews
11 pts drop in high-risk band share
R1.4m+ analyst time recovered (year 1)
4 months to full ROI on the build
The Difference

Before vs After AML Risk Model Design

Before
After
Client risk rating
Static onboarding label
Dynamic behaviour + profile + geography score
Refresh cadence
Years, or never
Risk-tiered schedule + event triggers
EDD capacity
Wasted on false highs
Focused on true elevated risk
Examiner question "why this band?"
Colour cell, no trail
Factor pack on every file
Monitoring intensity
Disconnected from rating
Follows live risk band
Board risk packs
Manual spreadsheet counts
Automated band migration reports
Getting Started

How It Works

From first conversation to live scoring in 6–12 weeks, depending on data feeds and product complexity.

01

Tell Us Your Book

How you rate clients today, where scores go stale, and which systems hold behaviour, profile, and geography data.

02

Free Scoping Call

30-minute call to map scoring factors, band thresholds, EDD routing, refresh cadence, and write-back targets.

03

Build & Calibrate

We encode your model, back-test against historical clients and STR outcomes, and tune false-high rates with your MLRO.

04

Go Live & Monitor

Switch off static labels. Monitoring keeps scores, routing, and board packs reliable as the book grows.

Questions

Frequently Asked Questions

How is this different from a KYC onboarding risk rating?

Onboarding ratings classify a client when the relationship starts. This build is ongoing AML client risk scoring: it keeps combining transaction behaviour, client profile, and geography after day one, and it drives EDD intensity, monitoring thresholds, and board risk packs throughout the lifecycle.

How often should AML risk ratings be refreshed?

FICA expects a risk-based approach, not a single calendar for every client. Industry practice typically reviews high-risk clients at least annually (often more frequently for PEPs), medium-risk every 12–36 months, and low-risk on longer cycles, with immediate out-of-cycle refresh when behaviour or profile changes. We encode your RMCP cadence and the trigger events your examiners expect to see.

Will this replace our RMCP or FICA obligations?

No. You remain the accountable institution. Section 42 still requires an RMCP that sets out how you identify, assess, and rate ML/TF/PF risk. We build the scoring model and integrations that apply the methodology your board approved, with an audit trail that survives FIC inspection.

Can we keep MLRO overrides on borderline scores?

Yes. Clear low and high bands can run straight through. Borderline scores, PEPs, and policy exceptions pause for MLRO or compliance review with the factor breakdown already attached, so the decision is recorded rather than reinvented under pressure.

How do you reduce false-high ratings that waste EDD capacity?

We calibrate weightings against your historical book and known outcomes, separate onboarding labels from ongoing behaviour signals, and measure how many clients migrate out of the high band once transaction evidence is included. The goal is fewer false highs without missing true risk.

How much does an AML risk scoring model integration cost?

Focused scoring models with CRM or case write-back typically start from around R45,000. Fuller builds with behaviour feeds, multi-product matrices, EDD routing, and board reporting usually fall in the R70,000–R140,000 range. Firms clearing a meaningful false-high EDD backlog often recover the build within 3–6 months from analyst time alone.

Ready to modernise client risk rating?

Stop Defending Stale High/Medium/Low Labels

If your AML risk scores still reflect day-one KYC rather than how clients actually behave, you are carrying examination risk and burning EDD capacity at the same time.

Tell us how you rate clients today, which systems hold behaviour and profile data, and where the false-high backlog hurts most. We will show you how a model that combines transaction behaviour, client profile, and geography would work for your book.

Chat with us