Skip to Content

How is a risk matrix calculated under the risk-based approach (RBA)?

The intelligence behind prevention.
April 16, 2026 by
How is a risk matrix calculated under the risk-based approach (RBA)?
Barbara Ynojosa


The risk matrix is the most important living document for a compliance officer. Under the risk-based approach (RBA) promoted by FATF, companies must abandon generic control and move to stratified monitoring: allocating more resources to clients that represent a greater threat.


Essential components of the calculation: 

The matrix assesses the likelihood of a money laundering event occurring against the impact it would have on the organization. To determine this, four key risk factors are analyzed:

  1. Jurisdiction factor: Does the client operate in border areas or in countries with low regulation?

  2. Client factor: Is it a PEP? Does their economic activity handle a lot of cash (e.g., casinos, jewelry stores)?

  3. Product/service factor: Does the product allow for anonymous transfers or to third parties?

  4. Channel factor: Is the relationship face-to-face or through non-presential digital platforms?


AgileCheck: real-time risk rating

With AgileCheck, the matrix stops being a static excel sheet and becomes a decision engine. When entering a client, a category (low, medium, or high) can be assigned immediately, triggering enhanced due diligence alerts when the risk exceeds the allowed threshold.