Risk-based KYC: how to choose the verification level by risk profile

A single verification procedure for all customers means either excessive costs on low-risk users or insufficient control where it is critical. The risk-based approach solves this task differently: the verification level is determined by the risk profile of the specific customer. The principle is enshrined in FATF Recommendation 1 and in the Russian Federal Law 115-FZ — it is precisely this that underlies the practical choice between simplified due diligence (SDD), standard CDD, and the enhanced EDD procedure. Below — what factors make up the risk profile, how the risk matrix and scoring translate it into a KYC level, and at which signals the level needs to be reconsidered.

What factors make up a customer’s risk profile

Image

A risk profile is not a single indicator but a composite assessment made up of several independent groups of factors. It is precisely their combination that determines which verification level is justified for a specific customer. In Recommendation 1, FATF directly states: measures to counter money laundering and terrorist financing must be proportionate to the identified risks rather than applied uniformly to everyone. Russian legislation enshrines this principle in Federal Law 115-FZ and the Bank of Russia’s regulations — Bank of Russia Regulation No. 175-P for credit institutions and Bank of Russia Regulation No. 145-P for non-credit financial organizations.

Regulatory practice and Rosfinmonitoring’s guidelines identify three key groups of risk factors that an organization is obliged to take into account when assessing a customer.

The customer and beneficiaries

The first and most significant group is the characteristics of the customer itself and of the persons in whose interests it acts.

For individuals, what matters is: the status of a politically exposed person (PEP), foreign citizenship or residency in a high-risk jurisdiction, activity in industries traditionally vulnerable to money laundering (cash operations, gambling, trade in luxury goods, weapons, precious metals). None of these circumstances in itself means bad faith, but each raises the final score in the risk scoring.

For legal entities, the defining parameter is the transparency of the ownership structure. Inconsistent or deliberately convoluted ownership chains, reluctance to disclose information about the ultimate beneficiaries (UBO — Ultimate Beneficial Owner), nominee directors, a mass-registration address, zero reporting despite significant turnover — all of this is recorded as risk factors in the internal control rules (ICR). Article 7 of Federal Law 115-FZ obliges organizations to take measures to establish beneficial owners; if the owner is not identified, the customer’s sole executive body is recognized as such.

Separately, the customer’s or associated persons’ inclusion in special lists is checked: the List of terrorists and extremists, the FROMU list, sanctions lists, the list of persons subject to decisions of the Interagency Commission (MVK). A match with any of them entails the automatic assignment of a high risk regardless of the customer’s other characteristics.

Geography and jurisdiction

Country risk is assessed across several dimensions simultaneously: the customer’s country of registration, the country of registration of the beneficial owners, the jurisdiction of the bank through which the customer conducts settlements, and the country of origin of the source of funds.

The regulatory benchmark is the lists of states published by FATF. Jurisdictions from the “black list” (High-Risk Jurisdictions subject to a Call for Action) correspond to the maximum country risk and, as a rule, require the application of enhanced due diligence. Jurisdictions from the “grey list” (Jurisdictions under Increased Monitoring) are taken into account as an aggravating factor but do not require an equally strict response. Rosfinmonitoring additionally maintains its own lists of states and territories, which are applied alongside the international ones.

The registration of a customer in a higher-risk jurisdiction is not a standalone ground for refusing service. It is a factor that increases the scoring value and determines the intensity of the check; the final decision is made on the basis of the combination of all the factors.

The product, channel, and nature of operations

The third group is connected not with who the customer is but with what they do and how.

Product risk is determined by the nature of the requested product or service. Private banking, anonymous operations, complex structured deals with cross-border elements, operations with virtual assets — these are products with a historically high potential for abuse. FATF specifically singles them out as requiring heightened attention.

Channel risk is due to the method of interaction with the customer. Remote onboarding without personal presence is an objectively more vulnerable scenario compared with face-to-face verification. Modern biometric identification and liveness-check solutions substantially reduce this risk: the authenticity of the document and the correspondence of the identity to the person presenting it are checked automatically, and the probability of using someone else’s data or forged documents is minimized. Nevertheless, the very fact of a remote channel remains a standalone element of the assessment.

Reduce channel risk in remote onboarding

Channel risk is not an abstract parameter: remote onboarding without the automatic checking of the document, biometrics, and signs of a live presence leaves a vulnerability that the risk matrix takes into account as a standalone factor. It can be closed by a technical KYC pipeline built directly into the user scenario.

NeuroVision builds the full verification chain: AI-OCR recognizes and validates the document, including the MRZ and security features — 10,000+ document types from 200+ countries are supported; the Enface algorithm compares the selfie with the photo in the document with an accuracy of 99.74%; the liveness module confirms the presence of a live person with an accuracy of 99.9% and blocks substitution — a photograph, a video recording, a mask, or a deepfake. Additionally, 40+ anti-fraud algorithms and checks against sanctions lists and PEP registries are connected.

Integration via a REST API or SDK takes from 24 hours, the full KYC cycle (document + face + liveness + AML) — from 35–50 rubles per check. The platform is available in a SaaS version and deployed on the customer’s infrastructure.

Request a demo and a cost calculation

Operational risk is assessed by the nature, volume, and structure of transactions. A mismatch between the declared activity profile and the actual operations, an atypical frequency or amount of transfers, the splitting of transactions below threshold values, cash operations without an economically justified reason — all of these are signs that the monitoring system records as anomalies and includes in the risk assessment. This is precisely why the risk profile is not static: it is formed at onboarding but is adjusted throughout the entire lifecycle of the customer relationship as data on actual behavior accumulates.

How to choose the KYC level by risk profile

Image

The collected risk factors do not in themselves answer the question of which check to assign to a specific customer. Between the risk profile and the KYC level lies a risk matrix with a scoring model: a tool that translates qualitative assessments into a formalized decision.

The KYC risk matrix and customer scoring

A KYC risk matrix is a formalized assessment system in which each risk factor is assigned a numeric weight, and their combination forms the customer’s final risk score. The weight reflects two parameters: the probability that the factor indicates illegitimate activity, and the potential damage to the organization and the financial system if this risk materializes. The product of these two values forms the weighted contribution of each factor to the final assessment.

A typical matrix operates with three groups of factors: — the customer and beneficiaries (PEP status, citizenship, transparency of the ownership structure, presence on sanctions lists, reputational signals); — geography (the country of registration and operations, inclusion in the FATF lists — blacklist and grey list, the level of corruption according to the Transparency International CPI); — the product, channel, and transactional logic (the degree of anonymity of the product, remoteness, the non-standard nature of operations, volumes).

Each variable is assigned a score on a scale (for example, 1-5 or 1-10), the scores are multiplied by the weights and summed. The resulting sum is compared with the threshold values enshrined in the ICR: a result below the lower threshold corresponds to low risk, above the upper one — high, the range between the thresholds — medium.

The organization determines the thresholds on its own, based on its risk appetite and industry benchmarks, but they must be documented and justified and must not contradict regulatory requirements.

Scoring at onboarding is only the starting point. FATF Recommendation 10 and Russian legislation (Article 7, subclause 3.1 of Federal Law 115-FZ) oblige organizations to keep the assessment current: the risk score is reconsidered when significant customer data changes, as well as in the scheduled periods established by the ICR. The frequency of review is differentiated: low-risk customers (SDD) are reassessed when their data changes significantly, medium-risk ones (CDD) — as a rule, once every two to three years, high-risk ones (EDD) — at least once a year, and if necessary in a continuous monitoring mode.

The automation of scoring reduces subjectivity and speeds up decision-making: when a KYC platform is integrated with sanctions databases, PEP registries, and internal rules, the assessment is formed in real time, and borderline cases are passed for manual verification.

Automate AML screening and the handling of compliance cases

A customer’s match with sanctions registries or PEP databases is an unconditional ground for high risk, which nullifies the scoring value of the other factors. So that such a match is not missed either at onboarding or during service, screening must cover current sources and work continuously.

The NeuroVision AML module connects 1,700+ databases — international sanctions registries (OFAC SDN, the UN, the EU, HMT), PEP lists, Rosfinmonitoring lists, adverse media — and updates them daily. When a customer’s status changes, the system automatically notifies the responsible employee without waiting for the scheduled reassessment. Case management records every action with a timestamp, forms an audit log, and prepares reporting for the regulator. The stated effect of automation is a reduction in the manual load on screening and case management of up to 80%.

Integration of the AML loop takes 1–2 days; it is available in SaaS mode and deployed on the customer’s infrastructure.

Submit a request to connect the AML module

When simplified customer due diligence is permissible

Simplified Due Diligence (SDD) is applied to customers whose risk score, based on the results of scoring, corresponds to the low zone and provided that a number of additional conditions are met. According to the FATF recommendations and Federal Law 115-FZ, SDD is not a waiver of verification but a reduction of its scope: the organization collects a smaller set of documents, updates the file less frequently, and applies simplified operation monitoring.

The conditions under which SDD is lawful:

  • the customer is an individual who is not a PEP and has no connections with high-risk jurisdictions from the current FATF list;
  • the product or operation has a low level of ML/TF risk: limited functionality, clear amount limits, or an obviously clear economic sense;
  • there are no alarming signals during the initial check — matches on sanctions and terrorist lists, adverse media, an anomalous structure.

The legislation sets strict limits on the applicability of SDD. Since May 30, 2025, under Federal Law 115-FZ (Federal Law No. 122-FZ of 28.12.2024), credit institutions are prohibited from conducting simplified identification of individuals for transfers over 100,000 rubles without opening a bank account — such operations require the standard procedure. Thus, transaction threshold values can raise the required verification level regardless of the customer’s risk profile.

SDD is not applicable if at least one of the risk factors belongs to the unconditionally high category: the customer is from a country on the FATF blacklist (Iran, North Korea), is subject to sanctions, or is a politically exposed person. In these cases, the scoring value does not matter — the verification level is raised regardless of the other parameters.

When standard CDD is needed

Customer Due Diligence (CDD) is the basic verification level, applied to most customers: those whose risk profile falls into the medium zone, as well as those for whom the regulator provides neither explicit grounds for simplification nor mandatory enhancement.

Standard CDD includes:

  • customer identification: confirmation of identity by an identity document, verification of the data through government or trusted sources;
  • establishing beneficial owners: for legal entities — disclosure of the ownership chain down to the ultimate UBO with a share of direct or indirect control of 25% or more, for individuals — a check of whether the customer is acting in the interests of a third party;
  • understanding the business relationship: the purpose and expected nature of the interaction, the source of funds in general terms, the profile of the expected operations;
  • checking against lists: sanctions registries, PEP databases, Rosfinmonitoring lists, adverse media databases.

The key requirement of standard CDD is documentation: each verification step and the decision made on its basis are recorded in the customer’s file. This is mandatory both for internal audit purposes and for a possible check by the regulator. According to Rosfinmonitoring’s updated requirements (Order No. 14 of 23.04.2025, in force from 11.07.2025), the composition of the mandatory information has been expanded compared with the previous regulation — in particular, regarding work with beneficial owners and the customer’s representatives.

The frequency of updating the file under standard CDD is determined by the organization’s ICR but, as a rule, is once every two to three years. The update is initiated ahead of schedule when significant data changes or alarming signals appear during monitoring.

When enhanced customer due diligence EDD is needed

Enhanced Due Diligence (EDD) is a mandatory regime for high-risk customers. Its difference from standard CDD lies not only in the volume of data collected but also in the depth of its verification and the density of the subsequent monitoring.

The unconditional grounds for EDD, enshrined in international standards (FATF Recommendations 12 and 19) and Russian legislation (Article 7.3 of Federal Law 115-FZ): — PEP status — a politically exposed person or a close relative of such a person. For a PEP, it is mandatory to establish the source of origin of funds and wealth (Source of Funds / Source of Wealth), as well as to obtain management approval to establish the business relationship; — a high-risk jurisdiction — the customer is registered, conducts activity, or carries out operations through countries on the FATF blacklist or grey list, or countries with a high level of corruption according to recognized international indices; — a non-transparent beneficial ownership structure — complex multi-level ownership chains, nominee shareholders, trusts, or other instruments that complicate the identification of the ultimate UBO; — the non-standard nature of operations — volumes or patterns that do not correspond to the customer’s declared activity profile.

With EDD, the organization is obliged to obtain an expanded set of information: detailed information about the sources of funds and property, confirmation of the legitimacy of the business (for legal entities — financial statements, contracts with counterparties), an in-depth analysis of business reputation using open sources and specialized adverse media databases. The decision to establish a business relationship with a high-risk customer requires approval at the level of a senior compliance officer or another authorized official.

EDD is not a one-time measure at onboarding but a regime of constant control: the frequency of updating the file is higher, operation monitoring is stricter, and any deviations from the expected profile require immediate analysis. Tools for the automatic scoring of transactions and checking against updated lists in real time make it possible to promptly identify changes in a customer’s behavior without waiting for the scheduled review of the file.

When to change the verification level

Image

The KYC level is not fixed forever. The risk profile changes throughout the entire service period — along with the customer’s operations, jurisdictions, positions, corporate structures, and external circumstances. The risk-based approach implies not only the correct choice of level at the start but also its timely review — both upward and downward.

Signals for moving a customer to EDD

Moving a customer to enhanced due diligence is initiated when new data appears that significantly changes the risk assessment. Such data comes from three sources: transaction monitoring, external databases, and changes in the customer’s own profile.

CategoryDescription
Transactional signalsThe most frequent trigger for review. The key signs: a sharp increase in the volume or frequency of operations without an apparent business reason, transactions that do not correspond to the declared occupation, the splitting of payments (structuring), non-standard routes of funds through several jurisdictions, large cash operations without justification of the source of origin.
Information signalsConcern changes in the customer itself or its circle: the acquisition of PEP status or the appearance of a PEP among the beneficiaries, inclusion in sanctions lists or lists of associated persons, negative publications in the media, a change of the ultimate beneficiary (UBO) or corporate structure, as well as data on involvement in litigation over financial crimes.
Geographic and operational changesComplete the picture: a change of the jurisdiction of registration or operational activity toward countries on the FATF lists, the opening of accounts or the conduct of operations through offshore zones, the start of work with counterparties from high-risk countries.

According to FATF Recommendation 10 and the requirements of Federal Law 115-FZ, the detection of any of the listed signs obliges the organization to consider the question of changing the assigned level and applying the appropriate verification measures — without waiting for the next scheduled review date.

Monitoring and reviewing the risk profile

Continuous monitoring is a mandatory element of risk-based KYC rather than an optional add-on. FATF enshrines this in Recommendation 10: organizations are obliged to conduct ongoing control of business relationships, including the analysis of transactions for correspondence with the customer’s declared profile. In Russian legislation, a similar requirement is established by Federal Law 115-FZ.

In practice, monitoring is built along two loops. The event-driven one reacts to specific triggers in real time: the AML/KYT system records an anomaly, automatically forms an alert, and the compliance officer decides on a review. The scheduled one is a regular reassessment of the profile on a schedule, the frequency of which depends on the assigned risk level: for EDD customers — at least once a year, for CDD — as a rule, once every two to three years, for customers under simplified due diligence — when their data changes significantly. Each organization sets the specific timeframes in its internal compliance policy, guided by regulatory expectations and its own risk appetite.

The result of a review is not necessarily an increase in the level. If no new risk factors have been identified over the reporting period, the initial level is confirmed. If the profile has improved — for example, the established period after the closure of PEP status has expired or the customer’s operational geography has changed — the level can be justifiably lowered with the corresponding documentary record.

The technical basis of monitoring is the integration of the KYC platform with the transaction layer and external data sources: sanctions lists, PEP registries, adverse media screening. Automatic rules reduce the load on analysts and speed up the reaction to changes, but the final decision to review the verification level requires a documented judgment by the responsible employee — this is fundamental both for compliance with regulatory requirements and for the subsequent audit: the regulator expects to see not just the fact of a review but the justification of the decision made.

Connect monitoring that documents every decision

During an inspection, the regulator assesses not the fact of a change in the KYC level but the justification of why the decision was made in exactly that way and at exactly that time. This is feasible only with a system that records every alert, every operator action, and every reference to a source — at the moment it arises rather than retrospectively.

The NeuroVision KYT module processes thousands of transactions per second: it builds a connection graph, detects the splitting of payments, non-standard routes, anomalies in frequency and volume. When a deviation is detected, the system forms an alert in real time and automatically opens a case with pre-configured SAR/STR reporting templates. The reduction in false positives reaches up to 90%, which lowers the load on analysts without loss of completeness of control. The AML loop works in parallel: 1,700+ sources with daily updates notify the compliance officer of any change in the customer’s status — a change in PEP status, inclusion in a sanctions list, appearance in adverse media.

Each review is recorded in the audit log with the justification of the decision made — in a format that makes it possible to pass a regulatory inspection substantively rather than formally.

Sign up for a call with an expert
Conclusion
Risk-based KYC is not a one-time choice but a manageable process

The risk profile turns customer verification from a uniform procedure into a managed decision: the risk matrix and scoring link the customer’s characteristics, geography, and operational profile to a specific level — SDD, CDD, or EDD. This choice is not fixed forever: new transactional signals, a change of jurisdiction, or the appearance of PEP status change the score and entail a review of the level — without waiting for the scheduled date and regardless of the initial assessment.

The practical value of the approach lies in three connected elements: the correct level at onboarding, continuous monitoring during service, and a documented review when the profile changes. Where this chain is built, the organization complies with the requirements of Federal Law 115-FZ and the FATF recommendations substantively rather than formally — and verification resources are concentrated precisely where the real risk is focused.