A customer risk rating is the most consequential field in the whole file, because it decides what evidence you collect and how often you look again. It is also the field most often filled in by feel. This page is about building a rating that a stranger could reproduce, which is the only real test of whether you have a model or a habit.
The factors, written down before the customer arrives
Most models use the same handful: what the customer is, what product or service they use, where they and their money are, how they were acquired, and how the ownership is structured for a business. The specific list matters less than the fact that it is written down in advance and applied the same way twice. A rating produced from a list agreed in a quiet week is defensible. The same rating produced by judgement on a busy day is not, even when it is identical.
A model is factors plus weights plus a rule
Factors alone do not produce a rating. You need a way of combining them, whether that is a score with weights or a set of rules that escalate on any single high factor, and you need a stated outcome: which combination produces standard, which produces higher, which produces enhanced. Then you need the override, because every model meets a customer it gets wrong, and an override with a written reason and a name on it is a strength rather than an admission.
The rating is only worth what the clock does with it
A rating that does not change the evidence set and the review interval is decoration. This is where most of the value is realised: higher-risk customers should be carrying more evidence and coming back sooner, and if your book has one review cycle for everybody, then the rating is not doing any work. It is also why re-rating has to move the date. A customer rated up in March should be on the shorter clock from March.
Questions people ask about customer risk assessment
How many risk ratings should we have?
Three is enough for most firms and more than five is usually unusable, because the distinctions stop being meaningful and the evidence sets start overlapping.
Should the rating be automatic?
The proposal can be. The acceptance should be a person, with a reason, because the reason is what somebody will read later and a generated one tells them nothing about whether anybody was paying attention.
How often should a rating be revisited?
At every scheduled review, and immediately on any event that changes a factor, such as a change of ownership or a move into a different product. The review is the natural place for it, which is another reason the review date has to be a fact on the record rather than an intention.