Calculated Risk
Calculated Risk is Strise’s automated risk-scoring engine. It turns each entity’s data — countries, legal form, industry, PEPs, sanctions, custom fields — into a numeric score and a risk class (None, Low, Medium, High, Severe, Critical). That class then drives review frequency, trigger actions, and portfolio-level views.
This replaces the older “Review Settings” flow, which required teams to hand-configure risk rules per review. See the Risk Settings Migration guide if you’re still on the legacy system.
How It Works
- Collect data. For each entity in your portfolio, Strise gathers signals from the Knowledge Graph — jurisdictions, ownership, industry codes, PEP/sanctions screening results, and any custom risk fields your team has defined.
- Score per category. Each category contributes points based on how you’ve configured it. For example, a company with operations in one high-risk country and two PEP-linked owners earns points from both categories.
- Sum to total. Points are summed across all categories.
- Classify. The total is mapped to a risk class according to your team’s thresholds.
Risk Categories
| Category | Contributing Data |
|---|---|
| Sanctions | Direct and relation-based sanctions hits |
| PEP / RCAs | PEPs and their related close associates in ownership, roles, or relationships |
| Countries | Countries associated with the entity — registration, operation, ownership chain, directors |
| Industries | NACE codes for the entity’s industry |
| Legal Forms | The entity’s legal form |
| Custom | Any custom risk field your team has defined |
Each category is configured independently. You can disable a category entirely or tune the points it contributes. See Calculated Risk Settings for the full configuration surface.
Risk Classes
The engine supports seven class values. Teams typically use three to five:
| Class | Typical Use |
|---|---|
| None | No risk signal present |
| Low | Minimal risk — default for small, domestic entities with clean screening |
| Medium | Some risk signal — elevated country/industry exposure or minor screening hits |
| High | Material risk — requires manual review |
| Severe | Disabled by default; enable if you need a step above High |
| Critical | Disabled by default; use for entities that should be blocked outright |
| Inconclusive | Runtime-only; appears when there isn’t enough data to classify |
Thresholds between classes are fully configurable per team. Default thresholds: None=0, Low=20, Medium=40, High=60.
Where Risk Class Shows Up
- Entity pages — The calculated class and a breakdown of contributing factors are shown on every entity’s risk card.
- Portfolio — Each row shows its class; you can sort and filter by it.
- Monitoring — Alert lists include the entity’s current class.
- Reviews — The Review PDF can include the Calculated Risk breakdown as its own section.
- Portfolio Health — The aggregate view groups entities by risk factor using the same inputs.
- Review Triggers — Trigger rules can branch on risk class, so Medium entities move to manual review while Low entities close automatically.
Validity Periods
Each risk class can be given a validity period (in months) — the length of time a completed review stays valid before the entity is due for re-review. There are no pre-set periods: validity is unset until your team configures it, per class, directly in the Risk Class table in Calculated Risk Settings. A common risk-based pattern is longer validity for lower classes (for example 24 months for Low, 12 for Medium, 6 for High).
When a review is older than its class’s validity period, the entity is flagged as due for review. The next-review date follows the manual risk level set in the review when one exists, falling back to the calculated class.
Manual Risk Level
Compliance officers can set a Manual Risk Level on an individual entity to override the workflow that the calculated class triggers. The manual level is an override on the classification decision — it doesn’t change the underlying calculated score, so you always keep the raw evidence trail.
Private Persons
Private persons get a simpler scoring schema: PEP count, RCA count, sanctions count, and custom risk fields. They are classified against a separate threshold configuration from companies.
Permissions
Everyone on the team can view Calculated Risk settings — the page is read-only for non-managers, with a notice that only managers can edit. Editing risk points, classes, and thresholds requires manager (settings-write) permissions. All users see the computed class and its breakdown on entities.