
Canada's national risk assessment work has flagged dozens of sectors and products, from banks to MSBs to real estate, as carrying elevated inherent money laundering risk. But knowing risk exists at the sector level means nothing if a reporting entity can't translate it into an accurate, defensible assessment of the clients and business relationships it actually has.
FINTRAC's enforcement record makes the stakes concrete. In 2024, FINTRAC published a $9,185,000 AMP against a Canadian bank partly because a number of clients were never placed into its high-risk program, and many of them went without required special measures as a result.
This guide breaks down what a customer risk assessment actually is and how it works stage by stage, including how ratings support evidence-based decisions under regulatory scrutiny.
Key Takeaways
- Customer risk assessment evaluates ML/TF risk for clients and business relationships, individually or in documented logical groups, separate from the entity-wide risk assessment
- Four stages structure the work in practice: data collection, documented risk categorization, due diligence calibration, and ongoing monitoring
- Assessment is continuous — not a one-time onboarding form
- Documented, defensible rationale matters more than the rating itself under FINTRAC scrutiny
- The documented risk level sets both due diligence depth and monitoring intensity
What Is a Customer Risk Assessment in AML?
A customer risk assessment is the process of evaluating the money laundering and terrorist financing (ML/TF) risk posed by an individual client, based on the know-your-customer (KYC) information collected and the risk factors that information reveals. It's the mechanism that turns raw onboarding data into a rating a reporting entity can actually act on.
Without a documented, risk-based rating, an entity has no defensible basis for choosing between simplified and enhanced due diligence. The practical result often looks like this:
- Compliance teams over-scrutinize low-risk clients, burning hours that could go toward genuine red flags
- High-risk relationships slip through with standard-level monitoring, exactly the kind of gap reflected in a published 2024 Canadian bank AMP
This is not the same exercise as an entity-wide risk assessment. FINTRAC draws a clear line between the two.
A business-based assessment looks at the reporting entity's risk across its products, services, delivery channels, and geographic footprint. A relationship-based assessment applies those findings to a specific client. The two can run side by side, but FINTRAC's risk assessment guidance treats them as distinct obligations.
Automation hasn't changed this basic structure. Sanctions screening, PEP checks, and adverse media tools can flag data points in seconds.
What they can't do is justify why a given combination of factors produced a "medium" rather than "high" rating. That judgment call, and its documented rationale, still needs a human signature behind it.
Not every reporting entity must assign an individual numeric score to every client. FINTRAC does not prescribe one scoring method; logical grouping by risk band can be appropriate where it is documented and defensible.
One practical / illustrative four-band model many entities use (not a mandatory FINTRAC scale):
- Lower risk - standard measures applied proportionately; simplified intensity must not drop prescribed duties
- Medium risk - standard due diligence applies
- High risk - enhanced due diligence and senior sign-off apply where required
- Prohibited/declined - the relationship isn't established, or is terminated (a business decision framework, not a FINTRAC-prescribed tier)
FINTRAC doesn't mandate this exact structure or a specific scoring formula. Generic "simplified due diligence" is not a universal Canadian rule that removes prescribed identification or record-keeping. The methodology just needs to scale sensibly: an MSB with a narrow product set will look different from a bank or a real estate brokerage, but both need rating logic they can explain on demand.
How Does a Customer Risk Assessment Work?
The process moves through four connected stages, each one feeding the next: data collection, risk scoring, due diligence calibration, and ongoing monitoring. Skip a stage, or leave it undocumented, and the whole chain becomes difficult to defend.
Risk Identification and Data Collection
The assessment starts at onboarding, when the entity gathers KYC information: identity documents, the nature of the client's business, source of funds, and beneficial ownership details for entities and trusts.
Sanctions, PEP, and adverse media checks are usually automated here. Most compliance platforms run these screens instantly. But the screen itself isn't the assessment. What matters is the documented judgment applied afterward: does this client's occupation, transaction pattern, or ownership structure actually elevate their risk, and why?
That written rationale is what separates a defensible file from a database entry.
Risk Scoring and Categorization
Here's the core mechanism: risk factors already identified in the entity's enterprise-wide assessment (customer type, geography, delivery channel, product or service) get applied to the individual client and weighted into a single rating.
Operationally, this usually looks like:
- Check each factor against the client's profile as present or absent
- Weight the factors according to the entity's documented methodology
- Combine the weighted factors into one overall risk category
The weighting logic is where many files fall apart under review. If two similar clients land in different risk tiers with no documented reason why, an examiner will ask the obvious question: what was the basis for this decision? Consistency and transparency in the weighting, not the sophistication of the scoring model, determine whether a rating is evidence-based and explainable.
Enhanced Due Diligence and Control
The assessed risk level isn't the finish line. It's what the level of control has to be proportionate to:
- Lower risk - proportionate standard measures (still meeting prescribed duties)
- Medium risk - standard due diligence
- High risk - enhanced due diligence, including source of funds and source of wealth verification, plus senior management sign-off where required
Higher ratings also drive monitoring intensity: more frequent file reviews, tighter transaction thresholds, and closer scrutiny of activity that deviates from what's expected for that client.
This calibration step produces some of FINTRAC's most consistent enforcement patterns. In 2024 FINTRAC published a $315,282 AMP against an MSB, citing failure to apply its client-type risk process in practice and monitoring records with no documented investigation or mitigation. An assessed risk level without matching controls is functionally the same as no assessment at all.
Ongoing Monitoring and Recalibration
The output of this whole process is a documented, defensible risk rating, one that dictates how often a file gets reviewed and how sensitively transactions get monitored.
That output doesn't sit still. It feeds directly into transaction monitoring thresholds and suspicious transaction report (STR) triage: a high-risk client's activity gets measured against a tighter baseline than a low-risk client's would.
Recalibration matters just as much as the initial score. When new information surfaces — such as a shift in transaction behaviour, a new business line, adverse media, or an address change — the rating needs revisiting. Entities that recalibrate consistently catch high-risk relationships that would otherwise stay hidden under an outdated low-risk label. They also avoid the opposite problem: unnecessarily de-risking legitimate clients who got flagged once and never reassessed.

Key Components a Customer Risk Assessment Should Include
A defensible risk assessment is a documented case built from several categories of evidence:
- Customer and entity factors - client type, occupation or nature of business, ownership and control structure
- Geographic factors - jurisdictions tied to residence, incorporation, or transaction activity, checked against FATF and FINTRAC high-risk country lists
- Product, service, and channel factors - cash-intensive activity, non-face-to-face onboarding, correspondent banking relationships
- Screening results - PEP status, sanctions exposure, and adverse media findings
- Behavioural and transactional signals - patterns surfaced through ongoing monitoring, not just what was known at onboarding
- Documented rationale - an explicit link between each customer-level factor and the findings of the entity's enterprise-wide risk assessment
FATF currently flags jurisdictions like North Korea, Iran, and Myanmar for a call to action, requiring enhanced due diligence or specific countermeasures.
A separate, longer list covers countries under increased monitoring, including Angola, Haiti, Syria, and Venezuela. FATF does not require blanket enhanced due diligence or wholesale de-risking of every client tied to those jurisdictions. Geography needs nuance, not a blunt exclusion list.
That last bullet, the documented rationale, is essential. A high-risk determination on paper without recorded reasoning is difficult to defend when the basis for the rating is examined.
Where and When Customer Risk Assessment Applies
Customer risk assessment starts at onboarding, but it doesn't end there. It continues for the life of the client relationship through ongoing due diligence, making it a continuous obligation rather than a form filled out on day one.
This obligation applies across every PCMLTFA-regulated sector, from banks and MSBs to securities dealers, mortgage lenders, casinos, real estate businesses, and life insurers. What changes between sectors is depth and formality, not whether the obligation exists:
- A large bank needs granular scoring models and multiple review tiers
- A smaller MSB can run a simpler methodology, as long as it's documented and consistently applied
Review frequency has to match the assessed level of risk, which for higher-risk relationships commonly means periodic review, with event-driven recalibration on top. The assessed level should also be revisited when:
- Transaction behaviour shifts materially from what's expected
- New information surfaces through ongoing monitoring
- Regulatory guidance or FATF jurisdiction lists change
Event-driven reassessment only works if the underlying methodology is sound. Entities that haven't stress-tested theirs recently often don't know whether it would operate effectively under an examiner's questions until they're already being asked.
That's usually where an independent effectiveness review proves its value: it tests whether the risk-rating logic, not just the paperwork behind it, operates as designed. AlphaDelta conducts Independent AML Effectiveness Reviews for Canadian reporting entities to answer that question with evidence - without claiming to catch every issue before FINTRAC does.
Conclusion
A customer risk assessment is a continuous, evidence-based discipline, not a static form completed once and filed away. It's built from documented reasoning that connects enterprise-level risk factors to individual client decisions, and that reasoning has to survive being questioned months or years later.
Reporting entities that understand why each stage exists - data collection, scoring, due diligence calibration, ongoing monitoring - build programs that can be explained with evidence under FINTRAC scrutiny. Entities that treat it as a checklist tend to surface the gap during an examination, when it is far costlier to fix.
If your organization is preparing for a FINTRAC examination, or isn't certain its risk assessment methodology would operate effectively under challenge, senior practitioner guidance can test that reasoning now - before a regulator does.
Frequently Asked Questions
How do you conduct a client AML risk assessment?
Gather KYC data on identity, business nature, and source of funds. Apply risk factors from your enterprise-wide assessment—customer type, geography, channel, and product—to that client. Document how those factors combine into an assessed risk level, then match due diligence and monitoring to it. FINTRAC does not prescribe a single scoring or rating method.
What should a client AML risk assessment include?
It should cover customer and entity factors, geographic exposure, product and delivery channel risk, and screening results for PEP, sanctions, and adverse media. Every factor needs a documented rationale linking it back to the entity's broader risk assessment.
What is a client risk assessment in AML?
It's the evaluation of the money laundering and terrorist financing risk a client or business relationship poses, based on their KYC profile and relevant risk factors, assessed individually or in documented logical groups. It's distinct from an entity-wide risk assessment, which looks at risk across the whole business.
How often should a customer risk rating be reviewed?
Review frequency has to match the assessed level of risk, so higher-risk relationships are commonly reviewed periodically, with event-driven recalibration when material facts change — a shift in transaction behaviour, new adverse media, or updated regulatory guidance. An assessment untouched for over a year despite new information is a common examination finding.
What is the difference between a customer risk assessment and an enterprise-wide AML risk assessment?
The enterprise-wide assessment identifies risk across the entire business: products, channels, geography, and client base. The customer risk assessment applies those same findings to clients and business relationships to produce a specific, documented and actionable risk level.
What happens if a reporting entity's customer risk assessment is found deficient during a FINTRAC examination?
Outcomes range from mandated remediation and follow-up examinations to administrative monetary penalties. Those penalties have reached into the millions of dollars for undocumented or inconsistently applied methodology. Documented rationale usually separates a manageable finding from a significant one.


