The Risk Scores Module found within KYCMATIC is potentially the most important element of your KYCMATIC environment/integrations. Firstly, this module is required to be configured per environment/integration since typically every environment/integration is a s Subject Person in its own right, therefore assessed differently by the regulator. The exception would typically be the Real Estate sector whereby a branch would be an environment/integration, yet all risk score configuration would be the same throughout all environments/integrations.
There may be other subject person in other sectors who may also opt to have the same configuration - yet is solely based on how the subject person operates.
This module is typically solely accessible by the MLRO's, therefore by users who are set within the MLRO Group Structure.
Select the Menu from the top left and select the 'Risk Scores' Menu item.
Selecting the 'Risk Scores' Menu item shall direct you to the Risk Scores Module. Initially, as shown in the above image, you are able to view and alter the Weighting Summary (more detail on this further below). Furthermore, you are able to review the different Risk Factor Pillars (coming from the 4th AML Directive ) being that of the:
Customer Risk Factor Pillar
Geographies Risk Factor Pillar
Channel & Interface Risk Factor Pillar
Products & Services Risk Factor Pillar
The Customer Risk Assessment Methodology found within KYCMATIC is calculated in the following manner:
As information is being entered into KYCMATIC throughout the profile and associated products/services provided to the entity, KYCMATIC will identify per risk factor pillar the highest possible risk - e.g. the customer may have the highest possible risk as Medium, whilst the Product risk factor pillar may be High. Therefore, each risk factor pillar is given an associated number depending on the highest available risk (see the far right column in the above image).
Once the highest available risk is assigned to each risk factor pillar, KYCMATIC would then apply the overall weighting found within the Weighting Summary page (as shown in the above image). Therefore, based on the above image;
Assuming the Customer Risk Factor Pillar had its highest available score of 'Medium-High' / '6', once the weighting of '40%' is applied, the Customer Risk Factor Pillar would be reduced to '2.4';
Assuming the Geographies Risk Factor Pillar had its highest available score of 'Medium-Low' / '2', once the weighting of '35%' is applied, the Customer Risk Factor Pillar would be reduced to '0.7';
Assuming the Channel & Interface Risk Factor Pillar had its highest available score of 'Medium' / '4', once the weighting of '15%' is applied, the Customer Risk Factor Pillar would be reduced to '0.6';
Assuming the Products & Services Risk Factor Pillar had its highest available score of 'High' / '8', once the weighting of '10%' is applied, the Customer Risk Factor Pillar would be reduced to '0.8';
As each pillar has the weighting applied, the final step KYCMATIC would perform would be aggregating the results; therefore aggregating 2.4 + 0.7 + 0.6 + 0.8 = 4.5. Based on the above table (2nd column from the right), 4.5 falls within the bracket of 'Medium', thus setting the CRA for this example entity to a Medium Risk Nature.
KYCMATIC has an element of exceptions whereby the above calculation is ignored and the risk is set to High or Critical, such as when the entity is Politically Exposed (CRA set to High as a form of an exception) or Sanctioned (CRA set to Critical as a form of an exception).
It is imperative to note that the overall weighting configuration and the individual risk scores configurations per risk factor is fully owned and understood by the Subject Person, and must be in line with the Subject Person's Policies and Procedures.
With the above knowledge in mind, the first thing to do is to set the overall weighting per risk factor pillar which would be based on you internal policies and procedures.
The first risk factor pillar being the Customer, would provide a list of all Data Touch points featuring under this Risk Factor.
For every data touch point (such as Employment Status, Industry, and so on), you are able to alter the associated risk per parameter as shown below.
As you select the risk found in step 3 pertaining to any parameter, the image shown to the left would be presented to you whereby you would be able to alter the configuration of the risk for, in this case, the 'Employed' parameter found within the Employment Status data touch point.
Further to the alteration of the risk, a reason would be required so your rational is kept, defining why the change of risk to this parameter is to be made.
As risks are updated throughout the module, KYCMATIC would automatically update all CRA's for every entity (provided that the entity is still active).
Step 3 and Step 4 would then be repeated for the other Risk Factor Pillars - until the KYCMATIC solution would be configured based on your policies and procedures.