CySEC AML · Chapter 5 · Topic 5 of 6

How are ML/TF risks rated and weighted?

Taking a holistic view, the usual three risk levels and the due diligence each one triggers, the cases the law always treats as high risk, and the rules for weighting risk factors.

By the ExamPass CY editorial teamLast reviewed 6 min read

Short answer

After identifying the risk factors, a firm weighs them together in a holistic view and places each business relationship or occasional transaction in a risk category, usually low, medium (normal) and high. Low risk may allow simplified due diligence, which is never an exemption from CDD. Normal risk means standard CDD. High risk calls for enhanced due diligence in addition to CDD and closer monitoring. PEPs, and relationships or transactions involving high-risk third countries, always require enhanced measures. No single factor may unduly dominate, and profit plays no part.

Risk levels and what they trigger

Low riskSimplified due diligence may be applied once the lower risk is established and there is no suspicion: the amount, timing or type of CDD measures adjusted, never removed
Medium or normal riskStandard CDD, with its extent set on a risk-sensitive basis
High riskEnhanced due diligence on top of CDD, plus more rigorous monitoring
Enhanced due diligence always required by lawPEPs and their family members and close associates; business relationships or transactions involving high-risk third countries; cross-border correspondent relationships involving payments
Weighting rulesNo single factor unduly dominates; profit plays no part; a high-risk rating must remain possible
ProofThe firm must be able to show its supervisor that its measures are proportionate to the risk

Source: Law 188(I)/2007, Articles 61, 63 and 64, as amended up to 2026; CySEC AML Directive, paragraphs 7 and 14; EBA ML/TF Risk Factors Guidelines (EBA/GL/2021/02).

What does taking a holistic view of risk mean?

Risk factors are not scored one by one and then forgotten. The firm looks at all the factors it has identified for a business relationship or occasional transaction and decides, taken together, what level of risk they add up to. A wealthy customer from a low-risk country buying a simple product through a regulated bank presents a different picture from the same customer using nominee companies and asking for secrecy.

As part of that judgement a firm may give some factors more weight than others, depending on the product, the customer and the relationship. The weighting is a matter of informed judgement, not a fixed formula.

Terms used in this note

Simplified due diligence (SDD)
Reduced CDD for situations assessed as low risk, adjusting the amount, timing or type of measures but never removing them.
Enhanced due diligence (EDD)
Additional measures for higher-risk situations, applied on top of standard CDD.
Holistic view
Weighing all identified risk factors together to reach one overall risk level for a relationship or transaction.

What are the usual risk levels and what does each trigger?

Firms choose how to categorise risk according to the nature and size of their business, but the usual scheme has three levels: high, medium (or normal) and low. CySEC-supervised firms must set criteria for putting customers into low, normal and high-risk categories in their customer acceptance policy, and keep lists of customers in each category up to date.

Low risk reflects situations with potentially lower risk related to the customer, geography, product, service, transaction or delivery channel. Where the law allows, and only once the lower risk has been established and there is no suspicion of money laundering or terrorist financing, the firm may apply simplified due diligence, adjusting the amount, timing or type of CDD measures to the low risk. It is never an exemption from CDD, and ongoing monitoring continues.

Medium or normal risk is the expected level, where the standard rules apply. The firm applies all the CDD measures in the law but may set their extent on a risk-sensitive basis, and it must be able to show its supervisor that what it did was proportionate to the risk.

High risk requires more stringent controls to bring the risk down to an acceptable level: enhanced due diligence and more rigorous transaction monitoring. Enhanced measures are added to standard CDD; they never replace it. A high rating does not mean automatic rejection or an automatic report to MOKAS.

Which cases must always be treated as high risk?

Whatever a firm's own model says, the law requires enhanced due diligence in certain situations. Two appear most often: a customer or beneficial owner who is a politically exposed person, or a family member or known close associate of one, and business relationships or transactions involving a high-risk third country. Cross-border correspondent relationships involving payments are another. Firms may also classify any other customer as high risk on the basis of their own assessment.

A high-risk third country is one on the European Commission's list or one the firm itself rates as high risk in its own assessment. A link to any other non-EU country does not on its own make a customer high risk. The enhanced measures for these countries include more information on the customer, the beneficial owner, the intended relationship and the purpose of transactions, the source of funds and wealth, senior management approval and closer monitoring. There is one narrow exception: a branch or majority-owned subsidiary of an EU firm located in such a country, which fully applies the group's policies, is assessed on a risk-sensitive basis rather than automatically.

What rules apply when weighting risk factors?

Weighting must be an informed judgement about how relevant each factor is to the relationship. The EBA guidelines add safeguards: the rating must not be unduly driven by a single factor, revenue or profit must play no part in it, and the method must always leave room for a relationship to be rated high risk. A model that can only ever produce low and medium scores is defective, and cases the law treats as always high risk cannot be weighted down.

How to think about it

Map risk to measures: low may mean SDD, normal means CDD, high means CDD plus EDD. EDD is always an addition and SDD is never an exemption. Before trusting any model's output, check the overrides: PEPs and high-risk third countries are high whatever the score. And test the weighting method itself: if one factor or the revenue from a client can decide the rating, or if nothing can ever score high, the method is wrong.

Common mistakes

  1. Replacing CDD with EDD for high-risk customers. Enhanced measures are always applied in addition to standard CDD.

  2. Treating SDD as an exemption. SDD adjusts the amount, timing or type of measures; all the CDD measures still apply.

  3. Rejecting or reporting every high-risk customer automatically. High risk calls for stronger controls; rejection or a report depends on the facts.

  4. Letting a lucrative client's revenue lower its rating. Economic or profit considerations must never influence the risk rating.

  5. Treating any non-EU link as compulsory high risk. The compulsory rule covers high-risk third countries, on the EU list or rated high risk by the firm; other links are weighed like any factor.

Practise this topic

Test what you just read

The Chapter 5 pack has 61 exam-style questions, 16 of them on this topic. Every question has a hint before you answer and a full explanation after.

Try the free demo

Or revise the numbers first with 16 free Chapter 5 flashcards →

Last reviewed on by the ExamPass CY editorial team against the law in force on that date. Study notes help you prepare for the CySEC exams; they are not legal advice. ExamPass CY is not affiliated with CySEC.

How we write study notesReport an error