RBA: risk-based approach
1) What is RBA and why is it needed
Risk-Based Approach (RBA) is a principle in which the depth of checks, limits and friction (SCA/3DS, manual reviews) depend on the specific risk of the client, operation, geography or counterparty. The goal is the minimum necessary control at a given level of residual risk:- retain conversion and LTV of bona fide customers,
- reduce fraud, AML incidents and chargebacks,
- comply with the requirements of regulators/banks/PSP and schemes.
2) Risk map: what to evaluate
The RBA relies on systematic assessment by strata:1. Customer (KYC): account age, tier, rainfall, documents, SoF/SoW, PEP/adverse media, deposit/withdrawal history, chargebacks.
2. Counterparty (KYB): jurisdiction, UBO/directors, licenses, sanctions, payment "health" (AR/CBR).
3. Transaction/Behavior: Sum/Frequency, Velocity, AVS/CVV/3DS Results, Device/IP/Geo Consistency, Link Graph.
4. Payment method/provider: card/A2A/wallet/crypto, quality of ACS/issuers, KYT risk, PSP degradation.
5. Geography and regulation: sanctions, FATF high-risk, local SCA/TRA modes, age/game restrictions.
6. Product/Scenario: Quick Takeaways, Bonus Policies, High Limits, Tournaments.
3) Risk rate and segmentation
Form a composite quilt (0-100) and segments:- Low Risk (0-30): verified client, matching geo, positive history, low-risk method.
- Medium Risk (31-70): new accounts, international BINs, partial AVS/address mismatches, rare methods.
- High Risk (71-100): PEP/adverse media, anomalous velocity, rapid in-out, sanctioned/high-risk geo, crypto with high KYT.
Speed is a signal, not a sentence: the final decision is the RBA matrix.
4) RBA Matrix: Policies by Segment
5) RBA and SCA/3DS (TRA exceptions)
In PSD2 zones, use Transaction Risk Analysis (TRA) for partners with a low fraud rate: skip low-risk operations frictionless, keeping the liability profile.
Threshold strategy:- 'score ≤ T1 '→ approve/frictionless (if the provider allows TRA),
- `T1 < score ≤ T2` → 3DS challenge,
- 'score> T2 '→ decline/alternate method.
- Consider the cost of the challenge vs chargeback risk: RBA is economic optimization, not just "security."
6) Integration of RBA into processes
6. 1 KYC/KYB
Progressive KYC: As risk/limits increase, add PoA, SoF/SoW, video-KYC.
KYB-RBA: offshore/complex UBO/PEP → EDD and reduced limits, simple CDD → fast go-live.
6. 2 Payments Orchestrator
BIN/geo/risk scoring routing: low-risk → PSP with best AR, high-risk → PSP with strong 3DS/ARF.
Auto Retrai: soft-decline → repeat with 3DS; Fix idempotency.
6. 3 AML/Crypto
Rule Engine with thresholds by segments (structuring, rapid in-out, mule).
KYT: addresses/exchanges with high-risk → high-severity alerts and hold.
7) Threshold policies and triggers
Gain triggers (example):- Amount ≥ local S₁ threshold or turnover ≥ S₂ (30/90 days).
- Inconsistent GEO (IP ≠ BIN ≠ bill_country), new high-risk BIN.
- Accelerated deposit → withdrawal cycle (≤ 30-60 min).
- PEP/adverse media/sanctions (hard flag).
- Crypto on/off-ramp without KYC exchange/high KYT.
- Network token, stable COF payments, good story covered by SoF/SoW, high KYC tier.
8) UX to RBA (friction minimum)
Transparent reasons: "You need to confirm the address to increase the limit," "The bank asks for SCA - confirm in the application."
Alternatives: when decline, offer A2A/wallets.
Contextual help: checklists of SoF/PoA documents, localization of requirements.
Cooldowns and soft-holds with timers instead of "deaf" blocks.
9) Data, storage and privacy
PII minimization, storage segregation (PAN-safe), encryption, RBAC.
RBA decision logs: 'risk _ score', key features (top-k), action taken, result.
Retention in accordance with the law (often 5 + years for compliance cases).
DSR procedures (access, repair, deletion).
10) RBA Metrics and Quality Control
Business/Conversion
Approval Rate, Cost/approved.
Frictionless % / 3DS rate / Challenge success %.
Risk
Chargeback Rate (CBR%) in segments (Low/Med/High).
Fraud-loss/1k txn, SAR-conversion (from alerts to reports).
Processes
SLA hit rate by onboarding/output/EDD.
False Positive Rate of rules/scoring, the share of escalations without finds.
Time-to-Decision p95 by key events.
Calibration
ROC/PR with cost weights (profit-weighted), Brier score (risk calibration), data drift (PSI).
11) Governance and change
RBA policy: describe risk factors, T1/T2 thresholds, roles, exclusions.
Change-control: RFC and A/B for new rules/thresholds; release magazine.
Model card: owner, version, KPI, date of the next review.
Quarterly review of results and retrospective of lost cases/incidents.
Business Continuity: KYC/KYT/PSP fallback providers, ACS/issuer degradation scenarios.
12) Examples of RBA scenarios
A. New customer, same country card, low amount
Speed low → frictionless/approve, Tier 1 is sufficient, without PoA.
B. Customer with history, high deposit, new GEO/IP
Speed average → 3DS challenge + PoA when exceeding the S₁ threshold, output T + 1.
C. Fast deposit → withdrawal, crypto off-ramp
Fast high → hold, SoF request (exchange report + KYT), with cleanliness - partial release.
D. Affiliate partner with unexpected traffic growth from high-risk GEO
KYB-rate ↑ → time limits, channel/domain reviews, payments T + 1-T + 3.
13) Anti-patterns
One size for all: uniform stringent KYC/SoF requirements → a drop in conversion.
Rules only or ML only: lack of safety-net or explainability.
Ignore economics: optimizing AUC instead of unit economics.
No solution logging: You cannot protect an audit position.
Twisted thresholds: CBR growth → too gently; too hard → revenue losses.
RBA outside geo/regulatory context: PSD2/TRA, local limits are not considered.
14) Implementation checklist (short)
- Risk map (customer/counterparty/transaction/geo/method/product).
- Composite Risk Rate + Segments (Low/Med/High).
- Solution Matrix for KYC/KYB/Payments/AML/Withdrawals.
- SCA/3DS and TRA policies; T1/T2 thresholds with economic calibration.
- Integrates with orchestrator: routing, retray, holds, idempotency.
- KPI dashboards (AR/CBR/Frictionless/Cost) and SLA alerts.
- Governance: RFC/magazine, model map, quarterly reviews.
- Degradation scenarios (ACS/issuer/PSP/KYC/KYT).
- Data policies: PII minimization, encryption, retention, DSR.
- Command training (Risk/Payments/Compliance/Support) and playbooks.
15) Summary
RBA is the "operational logic of common sense": just as much control as you need. Combine scoring, rules and economic thresholds, consider geo and regulation, make friction point (SCA/TRA), and decisions explainable and measurable. Then the payment rails will remain fast, the risks will remain manageable, and the monetization will remain stable.