Skip to content
EBA · EU-wide

Customer risk profile — the decision you cannot delegate

Fintech Passport
August 20, 2026 · 3-min read
Customer risk profile — the decision you cannot delegate

The customer risk profile is not a score — it is a decision, and Regulation (EU) 2024/1624 treats it as one. Article 18(3) puts the decision on the risk profile attributed to the customer on the short list of tasks that may not be outsourced under any circumstances. Everything downstream — the depth of due diligence, the monitoring benchmark, the refresh cycle, whether enhanced measures engage — runs off it.

1. What the profile is for

Three separate provisions consume it, which is why a profile that exists only as a colour in a CRM is not doing its job:

  • Due diligence depth. Article 20(2) is the route into firm-identified higher risk, and Article 34(1) makes enhanced due diligence follow from it.
  • The monitoring benchmark. Article 26(1) requires monitoring to establish that transactions are consistent with the entity’s knowledge of the customer, their business activity and risk profile. The profile is literally the yardstick.
  • The refresh cycle. Article 26(2) makes the period between updates of customer information depend on the risk posed by the relationship.

2. What feeds it

InputAnchor
The business-wide risk assessment, which frames what “higher risk” means for this firmArticle 10
Risk variables in Annex I and risk factors in Annexes II and IIIArticle 10(1)(a)
The purpose and intended nature of the relationshipArticle 25
The nature of the customer’s businessArticle 20(1)(e)
Higher-risk factors, AMLA guidelines and other indicators including FIU notificationsArticle 34(3)

3. Why the decision cannot be outsourced

A provider may gather documents, run checks, apply the firm’s matrix and present a recommendation. What Article 18(3) reserves to the obliged entity is the decision on the risk profile attributed to the customer — and, separately, the decision to enter into the business relationship.

The practical test is not who performs the analysis but who takes the decision and can evidence taking it. An arrangement in which a provider’s output is auto-accepted with no recorded decision inside the entity has outsourced the decision in substance, whatever the contract says. The workable pattern is the opposite: the provider’s assessment arrives as an input, and the entity’s own rules — which can be systematic and automated — produce the profile and record it as the entity’s own.

Article 18(3) also reserves the approval of the criteria for detecting suspicious or unusual transactions, so the same logic reaches the monitoring thresholds the profile drives.

FAQ

Is the risk profile the same as a risk score?

A score is one way of expressing it. The Regulation treats the profile as a decision with consequences for due diligence, monitoring and refresh — so what matters is the recorded decision and its basis, not the number.

Can an automated model set the profile?

Yes, provided the decision is the entity’s own, taken on the entity’s rules and recorded in its systems. What is prohibited is the decision being taken by an outsourced provider.

How often should the profile be reviewed?

The refresh period depends on the risk posed by the relationship under Article 26(2), and any event that changes the inputs — a new product, a new jurisdiction, a PEP match — should be capable of re-opening it.


Related: Ongoing monitoring · AMLR outsourcing · Enhanced due diligence

Related reads.