The risk-based approach is the foundation of the entire AML framework, and it is also the part small Irish firms are least confident about. "Rate each client's risk" sounds simple until you sit down with a real client and realise you have no model — just an instinct and a box marked low, medium or high. Instinct is not defensible in an inspection, and it does not transfer to the colleague who onboards the next client. With the EU's AML Regulation (the AMLR, Regulation (EU) 2024/1624) applying from 10 July 2027 and Irish supervision tightening ahead of it, now is the time to replace instinct with a model your whole firm can apply consistently.
Here is one that works at small-firm scale. It is a starting framework to adapt to your own business-wide risk assessment, not a universal answer.
Start from four factors
Client risk is conventionally assessed across four dimensions. For each client, ask what you see under each heading:
- Client factors. Who are they? An individual you meet face to face, or a company with layered ownership? Is beneficial ownership clear at the 25%-or-more threshold the AMLR harmonises? Is the client, a beneficial owner, or a close connection a politically exposed person? Does their profile make commercial sense?
- Geographic factors. Where are the client, the beneficial owners, the funds and the counterparties? Any connection to a country on the EU's high-risk third-country list moves the dial hard.
- Service factors. What are you doing for them? Some services carry inherently more laundering utility than others — moving client money, forming companies, buying and selling property — and your own business-wide risk assessment should say which of your services those are.
- Delivery-channel factors. How did the client arrive and how will you deal with them? Never-met, remotely onboarded clients introduced through chains of intermediaries sit differently from walk-in locals — though good electronic identification narrows that gap.
Score into three tiers — no more
Small firms sometimes copy bank-grade models with five tiers and decimal weightings. Resist that. Three tiers — standard, elevated, enhanced — are enough to drive genuinely different treatment, and simplicity is what keeps a model applied consistently:
| Tier | What it means | Typical treatment |
|---|---|---|
| Standard | Nothing in the four factors raises concern | Standard CDD, standard review cycle |
| Elevated | One or more factors warrant closer attention | Deeper verification, shorter review cycle |
| Enhanced | High-risk features present or an override applies | Full EDD, senior approval, closest monitoring |
For scoring, a simple approach beats a falsely precise one: rate each of the four factors, and let the worst factor set the floor. A client who is unremarkable on three dimensions but connects to a high-risk jurisdiction on the fourth is not a "medium on average" — averages are how models hide risk.
Build in overrides — the non-negotiables
Some features should bypass scoring entirely and force the enhanced tier or a refusal, whatever the rest of the picture looks like. Write them down as overrides:
- Sanctions match — a confirmed match is not a risk-rating question at all; it is a stop.
- PEP status — a politically exposed person, family member or known close associate is an enhanced-tier client requiring senior approval and source-of-wealth work.
- High-risk third-country connection — a listed-country link lifts the client to enhanced, full stop.
- AMLR-specific triggers — from 10 July 2027, the high-net-worth EDD test: handling assets of €5m or more for a client whose total wealth is €50m or more (both limbs, cumulatively) requires enhanced due diligence.
- Refusal criteria — decide in advance what your firm will simply not take on, such as clients whose beneficial ownership cannot be established.
Document the rating, not just the tier
The tier is the output; the reasoning is the compliance. Each client file should record who rated the client and when, what was found under each factor, which tier resulted and why, and any override applied. One or two sentences per factor is enough. This is also what makes ratings maintainable: when a trigger event lands later — an ownership change, a new screening hit — the reviewer can see what the original rating rested on and whether it still holds. Ratings are living things: re-rate at periodic review and on trigger events, not just at onboarding.
Connect the model to your business-wide risk assessment
A client risk model that floats free of your firm-wide risk assessment is a red flag in itself. The logic runs downhill: the business-wide risk assessment identifies the risks your firm faces across its services, clients, geographies and channels; the client model applies those conclusions client by client; and both documents cite the same national and EU context. The AMLR keeps this architecture and makes consistency between the layers easier to test, so build the two documents to agree with each other.
What to do now
- Adopt the four-factor, three-tier structure and adapt the factors to your actual services.
- Write your override list — sanctions, PEPs, high-risk countries, the AMLR high-net-worth test, refusal criteria.
- Re-rate your current client book against the model; expect a handful of surprises.
- Record reasoning on every file, including the standard-tier ones.
- Cross-check the model against your business-wide risk assessment and fix any contradictions.
Where CompliDesk fits
CompliDesk Ireland turns this model into your onboarding flow — factor-by-factor scoring, automatic overrides for sanctions, PEP and high-risk-country hits, and reasoning captured on every file. To get the foundation right first, start with our business-wide risk assessment guide.
General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.