ML-Enhanced AML Customer Risk Rating Model

35%

False Positive Reduction

150+

Risk Factors Assessed

3

Auditable Risk Tiers
Creating a customer risk rating model for AML compliance

Customer Risk Rating Model for AML Compliance

Click here to download

Customer Overview

The client is a regulated financial institution operating across retail, SME, corporate, and private banking segments, with exposure to domestic and cross-border transaction corridors. Operating under AML/CFT obligations governed by FATF, RBI, OCC, and FinCEN, the institution maintained a rules-based Customer Risk Rating framework to classify customers and drive due diligence decisions. Growing regulatory scrutiny, rising investigation costs, and mounting false positives from an insufficiently risk-sensitive model created pressure to modernize the CRR program without introducing governance risk.

Project Overview

The client partnered with TenUp to redesign and implement a Customer Risk Rating model capable of producing defensible Low, Medium, and High risk classifications across its full customer base. The existing rules-only framework treated customers with similar profiles identically regardless of behavioral differences, and could not satisfy regulators' expectations for dynamic, proportionate risk assessment. TenUp was engaged to deliver a hybrid model combining policy-driven scoring with a controlled machine learning layer, fully aligned to FATF, RBI, OCC, and FinCEN supervisory requirements.

Challenges

Modernizing the CRR model required balancing regulatory explainability, ML governance constraints, and risk precision, without relaxing existing AML controls or increasing operational burden.

  • Rules-based scoring applied uniform weights regardless of customer behavior, leaving customers with identical profiles but different transaction patterns at the same risk level.
  • High false positive rates drove disproportionate EDD escalations, overloading investigation teams with low-value reviews without a corresponding improvement in risk coverage.
  • Static, backward-looking assessments could not detect behavioral anomalies early, limiting the effectiveness of ongoing monitoring and STR workflows.
  • Regulatory and audit resistance to ML created a hard constraint; any model incorporating ML required full explainability, traceability, and governance approval before deployment.
  • Scoring logic lacked the granularity to assess customer type, product exposure, geography, onboarding channel, and transaction behavior as independent, auditable risk dimensions.
  • Poor investigator prioritization meant high-risk customers were not consistently surfaced first, weakening the defensibility of EDD and case escalation decisions.
  • Any model redesign had to remain fully aligned to FATF's Risk-Based Approach, RBI proportionality requirements, and OCC and FinCEN model governance expectations without relaxing existing controls.

Solution

TenUp designed and implemented a hybrid AML Customer Risk Rating model combining policy-driven scoring with a controlled ML layer to deliver explainable, regulator-defensible risk classifications across the full customer base.

  • Built a rules-based scoring framework assessing customer type, products and services, geography, onboarding channel, transaction behavior, and regulatory history as independent, auditable risk dimensions with policy-defined weights approved by Compliance, Risk, and Governance.
  • Mapped country-level exposure against FATF grey and black lists and RBI high-risk country designations to keep geography-based scoring aligned with current supervisory expectations.
  • Deployed a supervised ML model as a bounded behavioral overlay to detect whether a customer was transacting riskier than peers with a similar inherent risk profile, without modifying policy weights or overriding rules-based scores.
  • Applied strict caps, adjustment thresholds, and governance controls to the ML layer, keeping all behavioral adjustments within compliance-approved limits and subject to model validation and periodic review.
  • Mapped final scores to Low, Medium, and High classifications, each tied to defined due diligence outcomes: simplified monitoring, targeted review, or mandatory EDD with senior approval.
  • Maintained score-level traceability for every customer, with documented risk logic and regulatory rationale per contributing factor to support audit response and regulatory examination.
  • Delivered the model via API for integration with existing AML monitoring and case management platforms without requiring infrastructure changes.

Benefits

The customer risk rating model TenUp built for reliable AML compliance across multiple financial institutions offered the following benefits:

  • Reduced false positives and unnecessary EDD escalations, enabling investigators to focus on genuinely high-risk customers.
  • Earlier detection of behavioral outliers across customers with similar profiles, strengthening EDD prioritization and case decisions.
  • Score-level explainability and audit traceability ensured defensibility across RBI, FATF, OCC, and FinCEN examinations.
  • Bounded ML adjustments and policy-defined controls introduced behavioral intelligence without compliance or governance exposure.

Technology

  • Python
  • Pandas
  • Scikit-Learn
  • Django
  • SQL Server

Industry

  • FinTech
AML compliance improvement for a financial institution

Conclusion

TenUp Software Services replaced a static, rules-only framework with a hybrid customer risk rating model combining policy-driven scoring and bounded ML-based behavioral assessment. Each customer is scored across independent, auditable risk dimensions with policy-defined weights and full score-level traceability. Compliance teams retain complete control, no black-box decisioning, no governance exposure. The institution can now produce defensible Low, Medium, and High risk classifications, reduce unnecessary EDD escalations, and demonstrate a regulator-ready Risk-Based Approach under RBI, FATF, OCC, and FinCEN frameworks.

Frequently asked questions

What is a Customer Risk Rating Model in AML compliance?

faq arrow

A Customer Risk Rating (CRR) Model classifies customers as Low, Medium, or High risk for money laundering by evaluating customer profile, geography, products, and transaction behavior. Each classification drives a defined due diligence outcome, from simplified monitoring to mandatory Enhanced Due Diligence (EDD), aligned to FATF, RBI, OCC, and FinCEN requirements.

What is the difference between a rules-based and a hybrid AML risk model?

faq arrow

A rules-based model applies fixed weights uniformly across all customers, generating high false positives by ignoring behavioral differences. A hybrid model layers controlled machine learning on top of rules-based scoring to detect behavioral anomalies, improving risk precision and reducing false positives, without overriding compliance-approved policy weights or sacrificing regulatory explainability.

Why do rules-based AML models generate high false positives?

faq arrow

Rules-based AML models generate high false positives because they apply fixed, uniform thresholds across all customers without behavioral context — treating a low-risk customer with unusual but legitimate activity the same as a genuinely high-risk one, overwhelming investigation teams with low-value escalations.

How do regulators like FATF and RBI evaluate a Customer Risk Rating Model?

faq arrow

Regulators such as FATF and RBI evaluate Customer Risk Rating (CRR) models by assessing whether they follow a risk-based approach, use reliable customer, geographic, product, and behavioral risk factors, and produce explainable, auditable risk scores. They also verify that risk classifications trigger appropriate controls (e.g., Enhanced Due Diligence) and are regularly validated, documented, and updated.

Can machine learning be used in AML compliance without regulatory pushback?

faq arrow

Yes. Regulators allow machine learning in AML compliance when models are explainable, robustly validated, and governed within a formal model‑risk framework with ongoing human oversight, auditability, and documented model controls. In practice, ML is typically used to enhance rules-based monitoring, reducing false positives and detecting complex patterns, without replacing compliance decision-making.

What is Enhanced Due Diligence (EDD) and when is it triggered in a risk rating model?

faq arrow

Enhanced Due Diligence (EDD) is an advanced AML/KYC review applied to high-risk customers. In a risk rating model, EDD is triggered when a customer’s risk score exceeds a predefined threshold, often due to factors like PEP status, high-risk jurisdictions, or complex ownership. It requires source-of-funds verification, enhanced monitoring, and senior compliance approval.

What risk factors should a Customer Risk Rating Model assess?

faq arrow

A Customer Risk Rating (CRR) model should assess key AML risk dimensions: customer profile (individual, corporate, PEP), geographic exposure (high-risk or sanctioned jurisdictions), products and services used, delivery channel (digital or intermediary onboarding), transaction behavior, and adverse media or sanctions history. Each factor should be independently weighted and auditable to produce a defensible risk score.

What should financial institutions look for in a Customer Risk Rating Model solution for AML compliance?

faq arrow

Financial institutions should choose a Customer Risk Rating (CRR) solution that provides policy-driven scoring, configurable risk weights, and full explainability for every risk classification. It should integrate customer, geographic, product, and behavioral risk data, support regulatory frameworks for both local authorities and global standard‑setters like FATF, and include auditable governance, model validation, and clear links to due diligence actions.

Download Case Study
Contact us