Every entity in BNDRY gets a risk rating, but there's no single fixed scale used across every organisation. How many bands there are, what they're called, and where the lines between them sit are all configured separately for each organisation using BNDRY — a scale of Low, Medium and High suits some; others run four or five bands with different names. This article uses Low, Medium and High as a working example throughout, but the same logic applies whatever your own bands look like.
Underneath that scale, though, there are two very different ways to write the rules that decide where an entity lands. One treats every fact as a yes/no switch. The other lets each fact add or subtract points, and only the total decides the outcome. BNDRY uses the second approach, and this article explains why.
Attribute-based vs quantitative: two ways to write a rule
Think about deciding whether to grab an umbrella on your way out the door.
A yes/no rule looks at one thing and gives you a straight answer: is it raining right now? Yes, take the umbrella. No, leave it. That works fine once it's already pouring. It has nothing useful to say when it isn't raining yet, but the sky's gone dark, the forecast says a 70% chance of showers, and the wind's picked up. None of those facts alone tells you to take the umbrella — but together, they're telling you something a single yes/no question can't.
A points rule handles it differently. Dark clouds add a little risk. A high chance of rain adds more. Strong wind adds a bit more again. None of them crosses the line on its own, but add them together and the total says take the umbrella anyway — before a single drop has fallen.
These are the two approaches a risk rule can take, and they have names:
| Attribute-based | Quantitative (numerical) |
|
|---|---|---|
| What a fact produces | A category, or a yes/no answer | A number |
| Do facts combine? | No — one matching fact decides the outcome on its own | Yes — every matching fact adds to a running total |
| Simplified example | "If confirmed PEP match, rate High" | "Confirmed PEP match adds 50 points" |
BNDRY's Entity Risk Rating uses the second approach — quantitative, points-based scoring. Here's why that matters.
Why one fact is rarely enough
An entity's risk rarely comes down to one thing. A customer might not be a confirmed match on any sanctions or politically exposed person (PEP) list, might not have a recent unusual activity report filed, and still be worth a second look — because they're linked to a higher-risk industry, their transaction pattern has recently changed, and their last identity check is overdue. Any one of those facts on its own might not be enough to flag anyone. Together, they add up to something a compliance officer should see.
An attribute-based rule engine can only ever act on the loudest single fact in front of it. It would miss the entity that's quietly accumulating three or four smaller concerns at once, because none of them individually trips a switch. Quantitative scoring fixes that: every fact that matters contributes something to a running total, and it's the total that decides the rating — not whichever single fact happened to be checked first.
How the points work in practice
Each rule behind an Entity Risk Rating checks one fact and, if it's true, adds a set number of points. Here's a simplified example, using Low/Medium/High as the bands:
| Fact about the entity | Points added |
|---|---|
| Confirmed match on a PEP list | +50 |
| Unusual activity report (UAR) filed in the last 12 months | +30 |
| Suspicious matter report (SMR) filed in the last 12 months | +40 |
BNDRY adds up every rule that fires and compares the total against your organisation's own thresholds. Cross into the next band up and the entity gets a closer look at the next review; cross into the top band and it's flagged straight away. The point values above, the bands themselves, and the thresholds between them are all configurable per organisation — a scale that fits a small independent venue looks different from one built for a large multi-site operator.
Why the total matters, not just the trigger
A quantitative rating gives you a better answer than an attribute-based rule ever could. "This entity scored 95 — a confirmed PEP match plus a recent unusual activity report pushed it well past our High threshold" is a stronger, more specific answer than "the system matched a rule and flagged them High." It also tells you how close an entity sits to the next band, not just which band it's currently in — useful when you're deciding which of several high-risk entities to review first.
Points-based scoring isn't free of trade-offs. It only works as well as the numbers behind it: if a serious fact is weighted too lightly, or several minor facts are weighted too heavily, the total can mislead as easily as it can inform. Getting the model right matters as much as choosing the model in the first place — which is exactly why the weights, the bands, and the thresholds between them are all configurable, and worth revisiting as your risk appetite changes.
See also
- Risk Rating — what a risk rating is and where it sits on an entity's profile
Comments
0 comments
Article is closed for comments.