Risk Scoring and Compliance Health
Risk scoring is Cowork’s expression of the risk-based approach (RBA) that AML and fraud management processes require: every entity gets a risk rating so you can apply proportionate due diligence and monitoring. It is a per-entity, operational score (distinct from Compliance Health, which measures your programme’s regulatory standing).
How Risk Scoring works
Cowork computes a single entity risk score from 0 to 100 using a transparent, weighted model. The score is the sum of weighted factor categories, and each category is built from underlying sub-factors. The default categories and weights are:


Weighted factor model
Personal Factors
35%
Identity verification, PEP screening, sanctions, adverse media
Geographical Factors
25%
Country, city, length of stay
Product / Financial Factors
20%
Industry, product exposure, alerts
Behavioural Factors
20%
Behavioural analysis
Worked example: Personal 8.50 + Geographical 17.77 + Product/Financial 6.00 + Behavioural 9.00 = entity risk score 41.27 (Medium). A radar across the four categories shows where risk concentrates; a detailed breakdown expands each into its sub-factors.
Eachsub-factor contributes points toward its category; the category contributes its weighted share to the total. For example, an entity might score Personal 8.50%, Geographical 17.77%, Product/Financial 6.00% and Behavioural 9.00%, for a total entity risk score of 41.27%, which falls in the medium band. The platform also renders the score as a radar across the four categories so an analyst can see where the risk concentrates at a glance, and a detailed factor breakdown that expands each category into its sub-factors (e.g. “Country (Nigeria) 10.27%”, “PEP Screening 4.00%”).
The score is dynamic, not point-in-time
The risk score always reflects current data. The underlying screening sources, country risk, PEP, adverse media and sanctions, are updated daily, and behavioural data is retrieved dynamically, so every time an entity is scored the result is recomputed against the latest information rather than a stale snapshot. A customer who was clear last week but appears on a sanctions list or in adverse media today will score differently the next time the model runs, which is also what lets ongoing monitoring raise a signal the moment a previously clear entity becomes a hit (see 2.8).
Risk bands
The 0 to 100 score maps to Low / Medium / High risk bands. The band an entity lands in drives downstream behaviour (for example whether an AI-agent workflow auto-approves, escalates, or rejects).

Configurable from Cowork settings
The risk model is yours to tune. From Cowork settings → Transaction Settings → Rule Score Settings, a customer sets the score range for each band (the Low / Medium / High boundaries). Category weights and sub-factor contributions are likewise configurable so the model reflects your own risk appetite and regulatory posture rather than a fixed vendor opinion. Because scoring is weighted and explicit, every score is explainable: you can show exactly which factors drove it.
Risk scoring drives operational decisions on a customer (what diligence, whether to approve, how closely to monitor). It is NOT the same as Compliance Health, which measures how well your programme meets regulators’ requirements. The two are deliberately separate.
Evidence & confidence
Risk and compliance signals carry a source type and confidence: Platform (automated, 100%), Evidence (uploaded document, ~80%), Attested (self-attestation, ~60%). Upload to the Evidence Vault or attest to raise a domain's score.
Compliance Health: regulator audit & reporting (GRC)
Compliance Health is a governance, risk and compliance (GRC) tool, not a risk score. Where risk scoring rates a customer, Compliance Health tells a Chief Compliance Officer how well the organisation complies with regulators’ requirements, and produces the evidence to prove it. It is built for AML and regulator audit and reporting, and works much like the GRC platforms firms use to evidence ISO and other audits, but purpose-built for financial-crime compliance.

It measures readiness across roughly a dozen baseline-standard domains using Youverify’s patent pending DGE methodology, three pillars each scored 0 to 100:
Patent-pending status and the exact DGE methodology are Youverify-proprietary.

A headline platform-verified percentage, a count of critical issues, and an improvement streak summarise overall standing.
The confidence/evidence model. Each domain is backed by a signal whose strength depends on how it is substantiated, which is what makes the output audit-grade:
Platform (automatically verified by Cowork): highest confidence, treated as 100%.
Evidence (a document uploaded to the Evidence Vault): high confidence, treated as ~80%.
Attested (a self-attestation the officer records): lower confidence, treated as ~60%.
A CCO raises a domain’s score and confidence by uploading evidence or recording an attestation, exactly as they would build an audit file. The result is a defensible, continuously-updated view of regulatory compliance that can be exported for an examiner or an internal-audit review.
Last updated
Was this helpful?
