Skip to main content
TCJ

AML Compliance

How to Build a Customer Risk Rating Model for a DNFBP in the UAE

A practical UAE-focused guide to building a customer risk rating model for DNFBPs, covering AML/CFT risk factors, scoring, weighting, EDD triggers, reviews, governance, and documentation.

By Mandeep Masoun·Published ·Updated ·10 min read
How to Build a Customer Risk Rating Model for a DNFBP in the UAE
How to Build a Customer Risk Rating Model for a DNFBP in the UAE

How to Build a Customer Risk Rating Model for a DNFBP in the UAE

Key takeaways

  • A customer risk rating model should translate AML/CFT risk factors into practical CDD, EDD, approval, monitoring and review decisions.
  • UAE DNFBPs should tailor customer risk factors and weightings to their own activities, customers, services and business-wide risk assessment.
  • Mathematical scoring should not be allowed to dilute a material risk that requires escalation or enhanced controls.
  • High-risk customer classifications should lead to documented enhanced due diligence and proportionate ongoing monitoring.
  • Customer ratings and the underlying methodology should be reviewed when risks, customer circumstances or regulatory expectations change.

What is a customer risk rating model?

A customer risk rating model is a documented method for assessing the money laundering, terrorist financing and, where relevant, proliferation financing risks associated with a customer or business relationship. It converts defined risk factors into a risk classification that can guide customer due diligence, enhanced due diligence, approvals, monitoring and reassessment.

Many DNFBPs use classifications such as:

  • Low risk
  • Medium or standard risk
  • High risk

Some businesses use additional categories. That can work, but only if each category results in a meaningful difference in controls or review.

A model with five risk levels but almost identical procedures for each level may create complexity without improving compliance.

A useful risk-rating model does not create more numbers; it creates more consistent decisions. — Consulting Journal editorial observation

Why do UAE DNFBPs need a risk-based customer assessment?

A risk-based assessment allows a DNFBP to apply stronger controls where financial crime exposure is higher rather than treating every customer identically. Current UAE guidance expects DNFBPs to identify and assess relevant risks and apply proportionate mitigation measures, with enhanced measures for higher-risk situations.

This matters across several UAE DNFBP sectors, including real estate businesses, dealers in precious metals and stones, corporate service providers, and independent accountants and auditors.

The UAE's 2024 National Risk Assessment practical guidance also expects supervised DNFBPs to update their internal risk methodologies in response to national and sector-level findings and to reflect relevant customer, geographic, product or service, and delivery-channel risks.

For a Dubai mainland business or UAE free zone company operating within a regulated DNFBP activity, the customer rating should therefore reflect the risks actually created by its customers and services rather than a generic template copied from a bank.

Step 1: Which customer risk factors should a DNFBP assess?

A practical model normally considers customer risk, geographic exposure, products or services, transactions, and delivery channels. The exact factors should be adapted to the DNFBP's activity, business-wide risk assessment, UAE risk information, customer profile, internal controls, and supervisory requirements.

Customer risk

Customer risk considers who the customer is, who ultimately owns or controls the customer, and whether the relationship has characteristics requiring greater scrutiny.

Factors may include:

  • Individual, company, partnership, trust or other legal arrangement
  • Complexity of the ownership structure
  • Ability to identify and verify beneficial owners
  • Customer occupation or business activity
  • Politically exposed person exposure
  • Use of nominees or intermediaries
  • Cash-intensive activities
  • Material adverse information relevant to financial crime risk
  • Unexplained differences between the customer's stated activity and observed behaviour

Complexity alone should not automatically mean high risk.

A UAE holding company with several subsidiaries may have a genuine commercial reason for its structure. The compliance question is whether ownership and control can be understood, supporting documents are credible, and the structure is consistent with the stated business purpose.

Geographic risk

Geographic risk considers the jurisdictions connected with the customer, beneficial owners, business operations, source of funds, transactions and requested services.

DNFBPs may need to assess factors such as:

  • Jurisdictions identified through FATF statements
  • Sanctions-related exposure
  • Countries associated with relevant terrorism financing or proliferation financing concerns
  • Jurisdictions with material AML/CFT weaknesses
  • Cross-border activity inconsistent with the customer's stated profile
  • Countries materially connected with the source of funds or source of wealth

Geographic assessments should be reviewed periodically because country risk information can change.

Nationality should not be used as a shortcut for risk. The assessment should focus on the actual nature of the exposure.

Product, service and transaction risk

The relevant factors depend heavily on the DNFBP's activity.

A corporate service provider may focus on company formation, nominee arrangements, ownership changes and multi-jurisdiction structures. A real estate broker may consider transaction value, third-party involvement, unusual funding arrangements and the commercial rationale for the property transaction.

Other factors can include:

  • Handling or controlling customer assets
  • Formation or administration of legal persons
  • Complex restructuring
  • High-value transactions
  • Unexplained third-party payments
  • Multiple jurisdictions
  • Transactions inconsistent with the customer's known business
  • Services that may increase opacity around ownership or control

Delivery-channel risk

DNFBPs should also consider how the customer relationship is established and managed.

Relevant factors may include:

  • Face-to-face or remote onboarding
  • Use of intermediaries
  • Reliance on third parties
  • Digital identity verification
  • Customer location
  • Difficulty obtaining or validating original supporting documents

Remote onboarding should not automatically mean high risk. A well-controlled digital onboarding process may mitigate some of the underlying exposure.

Step 2: How should AML customer risk be scored?

The scoring method should be simple enough for compliance staff to understand and consistent enough to produce comparable results. A three-point system can work well: 1 for lower risk, 2 for moderate risk and 3 for higher risk, provided the methodology clearly explains what each score means.

The DNFBP should document the criteria behind every score.

For example, "complex ownership = 3" is too vague. A better methodology would explain which characteristics create the higher score, such as unexplained ownership layers, difficulty identifying the ultimate beneficial owner, nominee arrangements without a clear purpose, or jurisdictions that increase the assessed risk.

The supporting evidence matters as much as the numerical result.

Step 3: Should all customer risk factors have the same weight?

Not necessarily. Weighting allows the DNFBP to give greater importance to risks that are more relevant to its particular business model. The weighting should be based on documented risk reasoning rather than selected simply because the percentages produce convenient customer classifications.

An illustrative professional-services model might assign:

  • Customer risk: 30%
  • Geographic risk: 25%
  • Service and transaction risk: 30%
  • Delivery-channel risk: 15%

These percentages are examples, not regulatory requirements.

A UAE corporate service provider may reasonably place greater emphasis on ownership structure and the services being requested. A DNFBP regularly dealing with international customers may decide geographic exposure deserves greater weighting.

The important point is that the methodology can be explained and defended.

Step 4: How should low, medium and high-risk thresholds be set?

Thresholds should convert the overall score into an understandable risk classification and should be tested before being adopted. A model should separate genuinely lower-risk relationships from customers requiring additional attention and from relationships where enhanced measures are necessary.

For a model producing an overall result between 1 and 3, an illustrative approach could be:

  • 1.00 to 1.49: Low risk
  • 1.50 to 2.24: Medium risk
  • 2.25 to 3.00: High risk

Again, these thresholds are examples rather than UAE-prescribed limits.

Test the model against actual customers before relying on it.

If nearly every customer becomes medium risk, the methodology may not be distinguishing risk effectively. If customers with clearly elevated characteristics rarely reach high risk, the weights, scoring criteria or thresholds may require adjustment.

Step 5: When should overrides and EDD triggers apply?

Overrides are useful where one material risk could otherwise be diluted by several low scores. They should be predefined, documented and subject to appropriate approval rather than applied informally whenever an analyst disagrees with the mathematical result.

Potential escalation triggers can include:

  • Significant concerns about beneficial ownership
  • High-risk jurisdiction exposure
  • Material inconsistencies in source of funds or source of wealth
  • Serious adverse information relevant to financial crime risk
  • Specific PEP circumstances requiring enhanced measures
  • Material unexplained third-party involvement
  • A combination of risk factors that makes the relationship high risk overall

Current Ministry guidance states that EDD should be applied to customers or business relationships assessed as presenting high ML/TF/PF risk and identifies measures such as stronger verification, deeper understanding of the business relationship, source-of-funds or source-of-wealth checks where relevant, increased monitoring and higher management approval.

The treatment of PEPs should also follow the applicable UAE requirements and the particular PEP category and risk circumstances. The model should not replace the legal analysis required for a specific relationship.

Step 6: What should happen after the customer receives a risk rating?

The rating should directly influence the DNFBP's compliance response. If low, medium and high-risk customers all receive the same checks, approvals and monitoring, the model is not operating as a meaningful risk-based control.

In practice:

  • Low-risk customers should still receive all mandatory CDD, with additional measures adjusted only where legally permitted.
  • Medium-risk relationships normally require standard CDD and monitoring appropriate to the customer and service.
  • High-risk relationships require EDD and stronger scrutiny, approvals and monitoring appropriate to the identified risks.

A low internal score should never override a mandatory legal requirement.

Step 7: How often should a customer risk rating be reviewed?

Customer risk should be reviewed periodically and when material information changes. A customer that was appropriately classified at onboarding may present a different level of risk after changes in ownership, business activity, geography, services, transaction behaviour or other relevant information.

Event-driven reassessment may be appropriate following:

  • A change in beneficial ownership
  • A significant change in business activity
  • New PEP exposure
  • Material adverse information
  • Entry into new jurisdictions
  • Unusual transaction activity
  • New products or services
  • Doubts about previously obtained CDD information

The DNFBP should also periodically assess whether the risk-rating model itself is still effective.

The UAE's NRA guidance specifically calls for DNFBPs to update customer risk assessment models, including relevant risk factors and weightings, when changes to the broader risk assessment require it.

What does a practical DNFBP risk assessment look like?

Example 1:

A Dubai real estate brokerage onboards a UAE trading company purchasing commercial premises for its own operations. The ownership structure is straightforward, the UBO is identified and verified, funds originate from an established UAE bank account, and the transaction broadly matches the customer's documented business profile.

The customer may score relatively low across several categories, subject to the brokerage completing all mandatory CDD, screening and transaction-specific checks.

Example 2:

A UAE corporate service provider is asked to establish several companies for an overseas customer using multiple ownership layers across different jurisdictions. An intermediary leads the onboarding, the commercial rationale is initially unclear, and additional evidence is required to establish beneficial ownership and source of wealth.

Several elevated factors may produce a high-risk classification or trigger escalation. The appropriate response is not simply to add points. The compliance team should resolve the identified concerns, apply required EDD, document the rationale and determine whether the relationship can be accepted under applicable requirements and internal policy.

What common customer risk rating mistakes should DNFBPs avoid?

Several weaknesses regularly reduce the usefulness of a risk model:

  • Copying a bank's methodology without adapting it to the DNFBP's activities
  • Using vague scoring descriptions that analysts interpret differently
  • Treating every factor as equally important without considering actual exposure
  • Allowing several low scores to cancel a critical higher-risk issue
  • Treating red flags and customer risk factors as exactly the same thing
  • Automatically treating complexity as suspicious
  • Failing to document the reason for the final rating
  • Using manual overrides without defined authority and evidence
  • Building the model once and never recalibrating it
  • Failing to connect a high-risk rating to stronger due diligence and monitoring

The model should support professional judgment, not replace it.

What documents should a DNFBP prepare and retain?

A well-governed customer risk assessment process should be capable of being reconstructed later by compliance management, internal audit or a supervisory authority.

Businesses should consider maintaining:

  • Approved customer risk assessment methodology
  • Business-wide risk assessment
  • Defined customer risk factors and scoring criteria
  • Weighting methodology and rationale
  • Risk thresholds
  • Override and escalation rules
  • Customer KYC and CDD records
  • Beneficial ownership information
  • Screening evidence
  • Source-of-funds and source-of-wealth evidence where applicable
  • Risk-rating worksheets or system records
  • Analyst rationale
  • Senior management approvals where required
  • EDD records
  • Monitoring and review records
  • Evidence of changes to customer ratings
  • Model testing and validation records
  • AML/CFT/CPF policies and staff training records

The Ministry's practical NRA guidance also stresses maintaining documented and auditable evidence of risk methodologies, approvals, onboarding documentation, transaction monitoring records, training and compliance reviews.

How can KPM Global Services UAE assist DNFBPs?

KPM Global Services UAE can assist businesses in reviewing whether their customer risk-rating methodology is practical, documented and aligned with their wider compliance framework.

Depending on the DNFBP's activity and regulatory position, support may include:

  • Customer risk assessment methodology design
  • Review of scoring criteria and risk weightings
  • AML/CFT/CPF policy and procedure review
  • CDD and EDD workflow assessment
  • Beneficial ownership documentation processes
  • Risk-rating templates and control documentation
  • Review and escalation procedures
  • Compliance file readiness
  • Staff training and implementation support

The objective should be to create a process that staff can operate consistently and management can explain, rather than adding unnecessary complexity.

What should management take away from the model?

A customer risk rating should lead to a decision that can be explained. Management should be able to understand what created the customer's risk level, what evidence supports the assessment, what additional controls were applied and when the relationship will be reviewed again.

A simple model operated consistently is generally more useful than a complicated model that staff cannot explain.

For UAE DNFBPs, the model should also remain connected to the business-wide risk assessment, relevant national and sector risk information, current regulatory requirements and changes in the customer's circumstances.

This article is for informational purposes and does not constitute legal, tax, accounting, or financial advice.

Questions and answers

Q: What is a customer risk rating in AML?

A: A customer risk rating is a documented assessment of the financial crime risk associated with a customer or business relationship. It helps a DNFBP determine the appropriate level of due diligence, approval, monitoring and review.

Q: What risk factors should a UAE DNFBP include in its customer risk model?

A: Common areas include customer characteristics, beneficial ownership, geography, products or services, transactions and delivery channels. The final factors should reflect the DNFBP's business-wide risk assessment, sector, customer base, services and applicable UAE requirements.

Q: Does the UAE prescribe a specific low, medium and high-risk scoring formula?

A: A single universal numerical formula should not be assumed. DNFBPs should use a documented methodology appropriate to their own risk profile while complying with applicable UAE legal, regulatory and supervisory requirements.

Q: When should enhanced due diligence be applied?

A: EDD should be applied where the customer, business relationship or transaction presents high risk or where applicable requirements specifically call for enhanced measures. The measures should address the particular risks identified rather than operate as a generic checklist.

Q: How often should a DNFBP review customer risk ratings?

A: Reviews should follow the frequency required by applicable rules and internal risk-based procedures. DNFBPs should also reassess customers when material events occur, such as ownership changes, new geographic exposure, unusual activity, new PEP exposure or significant changes in the services requested.

Our services

What we can do for you

The Consulting Journal publishes analysis—and we also deliver commercial work: publishing, brand expansion, promotion, SEO, influencers, UAE setup, VAT, accounting, and consultations. Open a service to enquire.

See all services and send a request