Skip to main content

Using Passfort

Application risk

With Passfort's Risk module, you can determine the risk that a profile's product application poses to your company.

Contact us to find out how to get started with the Risk module.

How risk is determined

When a profile starts a new product application, the risk model for that product is applied to the profile.

Every risk model includes two things:

  • Risk factors: A risk factor is some detail about the profile that can influence the risk to your organization, for example, an individual's age, nationality, or PEPs matches. Each risk factor is assigned a score that shows how significant that factor is to the overall risk; the higher the score, the greater the risk. Any risk factor can be required or optional.

  • Risk levels: A risk level indicates the overall risk the application poses to your company: Low risk, Medium risk, or High risk. Each risk level has a range, for example, 0-50. If a product application's total risk score falls within this range, it is assigned this risk level.

When a risk model is applied to a product application, the risk factors are evaluated and a risk level is assigned.

A product application's risk level can change throughout the course of onboarding and monitoring. The risk model is re-applied any time profile details used in the risk model change, for example, when the individual's birthday is reached and their age changes.

Risk models are specific to the profile type, either individual or company. One product may have one risk model for individuals and another for companies. When a risk model is re-applied to a product application, all risk factors in the model are re-evaluated. Learn more about risk factors.

See the risk of a product application

A product application's risk level is displayed:

  • In the Risk level column on the Profiles page.

  • On the profile's Application overview page.

  • In the Risk level section on the profile's page for the product application.

Profile application with Medium risk level badge

If the risk score can't be calculated, the risk level is undetermined. If the risk level is displayed as Calculating risk, the risk model is still being applied. Note that it may take some time to calculate the risk, especially in the case of company profiles that have many associates.

To learn more about how the risk level was determined, go to the profile's Application risk scores.

Every product application that has a risk model is displayed. The risk level is shown with the product application's name.

If two product applications are using the same risk model, each is still listed separately.

Click on a product application to see the breakdown of the risk level.

The risk score showing the breakdown of risk for an application.

The breakdown includes the overall risk score:

The overall risk score for an application with the breakdown of risk scores into levels.

This is the cumulative score from every risk factor. It determines which risk level is used for the product application.

The risk level thresholds are also displayed, so you can see exactly which threshold the overall risk score falls into and which risk level is applied.

In this example, the overall risk score is 50, which means the product application falls into the 50-99 threshold of Medium risk.

You can also see every risk factor in the risk model:

Breakdown of the risk score for an application by its risk factors.

Risk factors can be combined into a group where the highest single risk score, Max of factors, lowest single risk score, Min of factors, mean risk score, or the sum of all risk scores is used. Select the name of a risk factor group to see which risk factors are included. In this example, there is a risk factor group named Country risk factors, which takes the highest single score in the group.

If the risk factor must be evaluated before the risk score can be determined, it's marked Required. Otherwise, the risk score is optional and is only used for the overall risk score if the relevant information is in the profile.

The Value shows what information the profile has for that risk factor. The value is displayed as -- if the profile has no information. Risk factor groups always display --.

Action enables you to edit the profile information for that risk factor. To edit the information, select the Edit Pencil icon_no border button. If the result of a check determines the value for the factor, for example, PEPs matches, you can't directly edit the information, and the action is displayed as --. Risk factor groups always display --.

The Score displays the risk score for that risk factor or risk factor group. This score is added to the product application's overall risk score. If there is no value for the risk factor, the score is set as follows:

  • If a default value is specified in the policy configuration, this default is applied.

  • If no default value is specified, the risk factor score is Undetermined.

If a risk factor is optional and its score is Undetermined, it is assigned a score of zero for the purposes of calculating the overall application risk score. If all the risk factors are optional and the profile doesn't have values for any of them, the overall risk score is zero.

If a risk factor is required and its score is Undetermined, the overall application risk score is not computed until the relevant data is provided. If the risk factor is determined by running a check, you can go to the relevant task to run the check.

If associate risk factors have been configured in the risk model, and no associates have been added to the verification list, the risk factor value is considered not present. The risk score is set to the default value if specified, else is Undetermined.

Undetermined risk

If the risk level is Undetermined risk, the risk score cannot be calculated because at least one required risk factor does not have a value.

To learn which risk factors are missing, go to the profile's Application risk scores and select the product application with Undetermined risk.

Risk score breakdown showing missing required factors.

For every risk factor marked Required:

  1. Select the Edit Pencil icon_no border button. The Edit risk factor dialog is displayed.

    Edit risk factor dialog.
  2. Complete the information.

  3. Select Update risk factor.

If the risk factor does not have an Edit Pencil icon_no border button, the value of the factor is determined by a check. Go to the relevant task and run the check.

Each time a value is added for a risk factor, the risk score is recalculated.