Customer risk profile — the decision you cannot delegate
The customer risk profile is not a score — it is a decision, and Regulation (EU) 2024/1624 treats it as one. Article 18(3) puts the decision on the risk profile attributed to the customer on the short list of tasks that may not be outsourced under any circumstances. Everything downstream — the depth of due diligence, the monitoring benchmark, the refresh cycle, whether enhanced measures engage — runs off it.
1. What the profile is for
Three separate provisions consume it, which is why a profile that exists only as a colour in a CRM is not doing its job:
- Due diligence depth. Article 20(2) is the route into firm-identified higher risk, and Article 34(1) makes enhanced due diligence follow from it.
- The monitoring benchmark. Article 26(1) requires monitoring to establish that transactions are consistent with the entity’s knowledge of the customer, their business activity and risk profile. The profile is literally the yardstick.
- The refresh cycle. Article 26(2) makes the period between updates of customer information depend on the risk posed by the relationship.
2. What feeds it
| Input | Anchor |
|---|---|
| The business-wide risk assessment, which frames what “higher risk” means for this firm | Article 10 |
| Risk variables in Annex I and risk factors in Annexes II and III | Article 10(1)(a) |
| The purpose and intended nature of the relationship | Article 25 |
| The nature of the customer’s business | Article 20(1)(e) |
| Higher-risk factors, AMLA guidelines and other indicators including FIU notifications | Article 34(3) |
3. Why the decision cannot be outsourced
A provider may gather documents, run checks, apply the firm’s matrix and present a recommendation. What Article 18(3) reserves to the obliged entity is the decision on the risk profile attributed to the customer — and, separately, the decision to enter into the business relationship.
The practical test is not who performs the analysis but who takes the decision and can evidence taking it. An arrangement in which a provider’s output is auto-accepted with no recorded decision inside the entity has outsourced the decision in substance, whatever the contract says. The workable pattern is the opposite: the provider’s assessment arrives as an input, and the entity’s own rules — which can be systematic and automated — produce the profile and record it as the entity’s own.
Article 18(3) also reserves the approval of the criteria for detecting suspicious or unusual transactions, so the same logic reaches the monitoring thresholds the profile drives.
FAQ
Is the risk profile the same as a risk score?
A score is one way of expressing it. The Regulation treats the profile as a decision with consequences for due diligence, monitoring and refresh — so what matters is the recorded decision and its basis, not the number.
Can an automated model set the profile?
Yes, provided the decision is the entity’s own, taken on the entity’s rules and recorded in its systems. What is prohibited is the decision being taken by an outsourced provider.
How often should the profile be reviewed?
The refresh period depends on the risk posed by the relationship under Article 26(2), and any event that changes the inputs — a new product, a new jurisdiction, a PEP match — should be capable of re-opening it.
Related: Ongoing monitoring · AMLR outsourcing · Enhanced due diligence


