KYC AML: risk categorisation of customers explained for 2026
Every bank branch in India runs on one quiet but powerful engine: risk categorisation of customers. The moment an account is opened, the KYC desk assigns a grade — low, medium or high — and that single tag decides how deep the onboarding checks go, how often the file comes up for review, and how closely transactions are watched afterward. For JAIIB, CAIIB and IIBF certification candidates this is one of the most heavily tested ideas in the KYC, AML and CFT paper, because examiners love "which category" and "how often reviewed" questions.
This article breaks down the framework banks actually run — the factors that push a customer up the risk ladder, the profiles that automatically land in the high-risk bucket, and how periodic review keeps the whole system honest year after year.
🔍 What Risk Categorisation of Customers Actually Means
Risk categorisation of customers is the process by which a bank sorts every account holder into a risk tier — typically low, medium or high — based on the likelihood that the relationship could be misused for money laundering or terrorist financing. It sits at the heart of the risk-based approach that both India's regulator and the global standard-setter for anti-money-laundering rules expect every bank to follow, rather than treating every customer with identical, one-size-fits-all checks.
The idea is simple: a bank has finite compliance bandwidth, so it should spend the most scrutiny on the relationships that carry the most risk. A salaried employee drawing a fixed monthly salary through the same branch for a decade does not need the same monitoring intensity as a cash-intensive trading firm with cross-border remittances. Categorisation turns that intuition into a documented, auditable process.
The framework is drawn from India's own national-level KYC and AML legislation, which in turn tracks the risk-based approach recommended internationally. Every bank's board-approved KYC policy must spell out the exact parameters used to place a customer in a tier, and internal auditors routinely test whether the categorisation logged in the core banking system actually matches the customer's real profile.
⚖️ The Factors That Decide Low, Medium or High
No single factor decides a customer's risk tier; banks combine several inputs into one score. The most common ones are the customer's occupation and declared income, the nature and location of the business, whether the account will see cash-heavy turnover, whether the customer resides or transacts across international borders, and the mode of account operation — face-to-face versus remote onboarding.
Geography matters a great deal. A customer based in or transacting frequently with a jurisdiction the FATF lists as having strategic deficiencies is pushed up the risk scale almost automatically, regardless of how clean the individual's own profile looks. Product type matters too — a current account with expected high-value forex flows is treated differently from a basic savings account used only for salary credit.
Banks also weigh the mode of onboarding. A customer who never visits a branch and completes everything through digital channels is inherently harder to verify face-to-face, so many banks nudge such relationships toward a higher tier unless strong compensating controls, like liveness checks during video-based onboarding, are in place. All of this is recorded at account opening and refreshed whenever a material change in the relationship is detected.
💡 Exam Tip: If a question lists multiple risk indicators and asks you to pick the customer's category, apply the "highest risk factor wins" rule — one strong red flag (say, a politically exposed connection) is usually enough to override several low-risk indicators.

🚨 Profiles That Almost Always Land in High Risk
Certain categories of customers are treated as high risk by default across nearly every bank's policy, not because of anything they have done, but because of the structural exposure their profile carries. Politically exposed persons and their close family members top this list, since their positions of influence make bribery or embezzlement proceeds easier to disguise through a bank account.
Non-government organisations and trusts receiving funds from unclear or overseas sources, firms in cash-intensive sectors such as bullion, real estate and money-changing, non-resident customers with complex fund flows, and accounts opened for entities with opaque or layered ownership structures all typically sit in the high-risk tier. Correspondent accounts held for foreign banks carry their own dedicated scrutiny, covered in depth in the chapter on correspondent banking.
Understanding why a category is treated as high risk is more exam-relevant than simply memorising the list, because IIBF questions frequently present a fresh, unlisted scenario and expect the candidate to reason from first principles — ownership opacity, cash intensity, cross-border exposure — rather than recall a fixed list. A firm-wide view of these drivers is covered in more depth in the article on enterprise wide AML risk assessment.
⚠️ Common Mistake: Candidates often assume risk category is fixed for the life of the account. It is not — a low-risk customer who suddenly starts routing large, unexplained international transfers must be re-categorised immediately, not at the next scheduled review date.
🌍 Cross-Border Exposure and Country Risk in the Mix
Domestic risk factors are only half the picture. Once a customer's transactions cross a border, the destination or origin country's own AML framework becomes part of the categorisation logic, an idea explored fully in the chapter on country risk in money laundering. A remittance corridor to a jurisdiction with weak regulatory oversight or known sanctions exposure automatically raises the risk profile of the customer sending or receiving funds through it.
Correspondent banking relationships amplify this further, because a single Indian bank's nostro account can sit behind thousands of underlying customer transactions from a foreign respondent bank, none of which the Indian bank directly onboarded. This is why respondent bank due diligence and ongoing monitoring of correspondent flows are treated as a distinct, higher layer of scrutiny rather than folded into ordinary retail categorisation.
Screening lists also feed into this layer of the process — a name match against a sanctions list changes a customer's status instantly, a workflow covered in the companion piece on sanctions screening in banks. Together, country exposure and sanctions screening form the cross-border half of a bank's overall risk categorisation engine, working alongside the domestic factors already discussed. Branches that handle a large NRI or trade-finance book typically build a separate country-risk matrix into their onboarding system so front-line staff are not left guessing which corridors need the extra layer of scrutiny.

🔄 Periodic Review and Risk-Based Monitoring Cycles
Categorisation is not a one-time event stamped at account opening; it is refreshed on a cycle tied directly to the assigned risk tier. High-risk customers are reviewed most frequently — commonly once every two years — medium-risk relationships on a longer cycle of around eight years, and low-risk accounts on the longest cycle, typically once every ten years, unless a trigger event forces an earlier look.
Monitoring intensity between reviews scales the same way. High-risk accounts sit under tighter transaction thresholds and more sensitive rule sets in the bank's monitoring engine, generating alerts at lower value bands than a low-risk savings account would. How those alerts are actually scored and tuned in practice is covered in the companion article on transaction monitoring alerts in AML compliance.
Trigger events — a large unexplained credit, a change in occupation, an adverse media hit, or a request to change registered address to a high-risk jurisdiction — can force an out-of-cycle review regardless of when the last scheduled update happened. The branch and the compliance function that oversee this cadence are described in the chapter on the AML compliance structure mandated in national legislation.
📌 Remember: The review cycle length is inversely proportional to risk — the higher the category, the shorter the gap between reviews. Examiners frequently swap the numbers around in MCQ distractors, so lock in "high = shortest cycle" as your anchor point.
The table below pulls the three tiers together in one view, a comparison that comes up directly in KYC, AML and CFT objective questions.
| Risk Category | Typical Examples | Review Cycle | Enhanced Checks |
|---|---|---|---|
| Low Risk | Salaried individuals, government employees, regulated entities | Around every 10 years | ❌ Not required |
| Medium Risk | Self-employed professionals, small traders, standard businesses | Around every 8 years | Standard checks only |
| High Risk | PEPs, NGOs/trusts with unclear funding, cash-intensive firms, correspondent accounts | Around every 2 years | ✅ Required |
This tiering also shapes how quickly a suspicious pattern gets escalated internally before it ever reaches a filing decision with the regulator; the escalation workflow ties back to the same enterprise-wide risk assessment logic banks build their monitoring rules around.
Risk categorisation of customers rarely sits in isolation from the rest of a bank's compliance stack. Once a name is flagged during onboarding or periodic review, it typically flows straight into the bank's sanctions screening in banks workflow, and any resulting alerts are handled through the same transaction monitoring alerts in AML compliance pipeline covered earlier. Firms that also handle cyber incidents affecting customer data should cross-check their obligations under the CERT-In incident reporting directions, since a data breach touching KYC records can trigger both a regulatory notification and an emergency re-categorisation review.
For the underlying regulatory text, the Reserve Bank of India publishes its KYC-related directions on its official website, and the Financial Action Task Force's risk-based approach guidance is available at fatf-gafi.org. Candidates can browse every article tagged under KYC, AML and CFT for the rest of the syllabus, or test the concept immediately with chapter-wise mock tests.

🧠 Practice MCQs: Risk Categorisation of Customers
Q1. Under a bank's standard risk-based KYC framework, which customer would typically be reviewed most frequently? (a) A salaried government employee (b) A politically exposed person (c) A retired pensioner (d) A regulated mutual fund
Answer: (b) — Politically exposed persons are treated as high risk by default and sit on the shortest review cycle, commonly around every two years.
Q2. Which of the following is the correct order of periodic review cycles, from shortest to longest? (a) Low, Medium, High (b) High, Low, Medium (c) High, Medium, Low (d) Medium, High, Low
Answer: (c) — Review frequency is inversely proportional to risk: high-risk customers are reviewed most often, followed by medium, then low.
Q3. A previously low-risk customer suddenly starts receiving large, unexplained international remittances. What should the bank do? (a) Wait until the next scheduled 10-year review (b) Ignore it since the customer was already verified at onboarding (c) Trigger an immediate, out-of-cycle risk re-categorisation (d) Close the account without any review
Answer: (c) — A material change in transaction behaviour is a trigger event that forces an out-of-cycle review regardless of the scheduled date.
Q4. Why are non-face-to-face onboarded customers often nudged toward a higher risk tier? (a) They always have lower account balances (b) Digital-only onboarding makes identity verification inherently harder without compensating controls (c) They are always non-resident customers (d) Regulators ban remote onboarding entirely
Answer: (b) — Without in-person verification, banks rely on compensating controls like liveness checks, and absent those, remote onboarding carries higher inherent risk.
Q5. What role does correspondent banking play in a bank's overall risk categorisation approach? (a) It has no bearing on categorisation since only the foreign bank is responsible (b) Correspondent accounts are automatically treated as low risk because they involve regulated banks (c) Correspondent relationships receive a distinct, higher layer of scrutiny because they carry underlying transactions the Indian bank never directly onboarded (d) Correspondent banking is unrelated to AML compliance
Answer: (c) — A single correspondent account can carry thousands of underlying transactions from a foreign respondent bank's own customers, which is why it is treated as a distinct higher-risk layer with its own due diligence.
Want chapter-wise mock tests with 100+ MCQs? Start practising free
What is risk categorisation of customers in KYC?
It is the process by which a bank classifies every customer into a risk tier — commonly low, medium or high — based on factors like occupation, geography, cash intensity and mode of onboarding, so that verification depth and monitoring intensity can be matched to the actual risk the relationship carries.
How often are high-risk customers reviewed compared to low-risk customers?
High-risk customers are typically reviewed around every two years, medium-risk customers around every eight years, and low-risk customers around every ten years, with any category eligible for an earlier, trigger-based review if the relationship changes materially.
Can a customer's risk category change after the account is opened?
Yes. Risk categorisation is dynamic — a change in occupation, an adverse media report, a sanctions list match, or an unusual transaction pattern can all force an immediate re-categorisation well before the next scheduled review date.
Why do politically exposed persons automatically fall into the high-risk category?
Their position of public influence makes it structurally easier to disguise proceeds of bribery or embezzlement through a bank account, so most bank policies place them in the high-risk tier by default rather than assessing them like an ordinary retail customer.
🎯 Conclusion: Turn Risk Categorisation Into Easy Marks
Risk categorisation of customers is one of the most logical, formula-free topics in the entire KYC, AML and CFT syllabus once the underlying pattern clicks — more exposure means a shorter review cycle and tighter monitoring, and a handful of profiles almost always sit in the high-risk tier by default. Revisit the tier table above, work through the practice MCQs a second time, and the "which category" style questions become fast, reliable marks. Put this to the test with a full timed set on the JAIIB course page or jump straight into chapter-wise mock tests to see how these scenarios show up under real exam pressure.
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.
Keep reading