The International Financial Services Centers Authority (AML, CFT, and KYC) Guidelines, 2022 mandates the regulated entities to assess the level of risk posed by the customer and apply adequate mitigation measures to manage the risk.
While establishing the business relationship or executing a transaction, the regulated entities must assess the level of money laundering and terrorist-financing risk the customer poses to the business and determine its risk profile.
For performing customer risk assessment, there are specific parameters that one must take into consideration. Here is the illustrative list of parameters that must be considered for creating a customer’s risk profile:
Based on the evaluation of these parameters, it is determined whether the customer poses low-risk, medium-risk, or high-risk to the regulated entity.
Customer risk profiling is crucial as it decides the level of due diligence required of every customer individually. One can go for simplified due diligence when the customer poses a low risk. However, enhanced due diligence is required when the customer risk profile suggests high level of ML/FT risk.
Customer risk profiling is the assessment that assigns each customer a money laundering and terrorist financing risk rating, which then determines the depth of due diligence, the periodic review cycle and the monitoring applied to that relationship.
A customer’s risk profile is determined by four main factors; the type of customer and nature of business, the products and services they use, the delivery channel through which the relationship is conducted, and geographic exposure, including their country of residence and where they transact.
Factors such as PEP status, complex ownership structures, and cash intensity within the customer’s business and Non-face-to-face onboarding are standard factors that may increase the risk levels and therefore requires appropriate controls. The weight assigned to each factor is determined by the entity’s own risk assessment methodology and must be documented so that the risk assessment can be independently tested.
A customer’s risk profile should be reviewed according to the periodic updating cycle prescribed by the applicable framework and whenever a trigger event occurs. Under the IFSCA guidelines, the general cycle is annually for high-risk customers, every three years for medium-risk customers and every five years for low-risk customers.
A separate 2,8, and 10-year cycle applies to certain resident Indian customers who already maintain a relationship within the financial group in India, under the January 2026 circular. Where the group and IFSC entity assign different risk categories, the stricter periodicity applies. A material change in the customer’s activity, ownership, jurisdiction or products should trigger reassessment regardless of the scheduled review date.
Important Links
subscribe to newsletter
WhatsApp Group
Schedule a meeting now!