AMLConsensus · course
Programme · Lesson 4.2
Section 4 · Lesson 4.2

Category weights, direction and recency

In the previous lesson we obtained an exposure profile: "22% through no-KYC P2P, 4% through a mixer, 6% through darknet". But 4% contact with a sanctioned address and 4% contact with an online casino are a completely different level of alarm. In this lesson we examine how weights are assigned to exposure shares, why the direction and recency of contact change the assessment, what hard flags are, and how a single number from 0 to 100 is born out of all this.

Why sanctions weigh more than casinos

Not all risk categories are equal. Scoring assigns each category a weight — a multiplier reflecting the severity and legal consequences of contact. The logic of the weights follows from real regulatory risk, not from abstract "badness".

Key principle. The final assessment is not simply "what percentage is dirty" but the sum of shares multiplied by category weights. 6% of darknet with a high weight gives a bigger contribution than 30% of a casino with a low one. That is exactly why two wallets with the same "overall percentage of risk" can receive scores of 25 and 85.

Incoming versus outgoing exposure

The direction of the money flow changes the meaning of the risk, and a good engine weighs these two directions differently depending on the task.

Incoming (source)
Source ⟶ YOU
"Where did the money come from?" Laundering risk: you are accepting funds of criminal origin. Critical for exchanges, sellers, escrow.
Outgoing (destination)
YOU ⟶ Recipient
"Where is the money going?" Financing risk: you are sending funds to a prohibited service. Critical for payment and withdrawal compliance.

Example: a wallet that receives a salary from an exchange but sends it to a sanctioned service is an outgoing problem, and it is invisible if you look only at sources. And vice versa: a wallet with clean withdrawals but dirty inflows is dangerous for whoever accepts those inflows. That is why a report always has two exposure blocks, and they must not be confused.

Recency: how long ago the contact was

Risk ages. Contact with a mixer a week ago and contact three years ago are a different level of current threat. Engines introduce a recency factor (recency / time decay).

  1. Fresh contact (days–weeks). Full weight. The money is "hot", the link is current.Especially important for hacks and sanctions: freshly stolen funds are actively tracked.
  2. Medium age (months). The weight is partially reduced.The wallet may have changed behaviour, the funds may have been mixed many times over.
  3. Old contact (years). The weight is markedly lower, but not zero for heavy categories.A sanctions or CSAM contact is not "forgiven" by time the way a P2P casino is.
An important caveat. Recency does not reduce weight equally for all categories. For a casino, age quickly zeroes out the risk. For sanctions and terrorist financing, age barely helps — legal liability does not have a statute of limitations in the same sense. A good engine applies different decay curves to different categories.

Hard flags: when the number no longer matters

Standing apart are hard flags — conditions under which the assessment is forced to the maximum regardless of shares, weights and recency. These are "red kill switches".

The point of hard flags is not to let a catastrophe be "averaged out". Without them, a wallet with 2% direct sanctions exposure and 98% clean funds would get a low weighted assessment and pass the check. A hard flag overrides all the arithmetic: 2% of sanctions matters more than 98% of cleanliness.

How a 0–100 number comes out of all this

Let's assemble the whole formula. The final assessment is a pipeline:

Exposure shares
from taint analysis
× category weight
sanctions ≫ casino
× direction and recency
source/dest, age
Σ + hard flags
0–100
  1. Take each exposure share from the taint analysis (Lesson 4.1).For example, 6% darknet at the 2nd hop.
  2. Multiply by the category weight. Darknet is high, a casino is low.This is how severity is accounted for quantitatively.
  3. Adjust for direction and recency. Fresh outgoing exposure to sanctions is almost the maximum.Old incoming casino is almost zero.
  4. Sum the weighted contributions and normalise onto a 0–100 scale.Usually non-linearly: the first percentages of a heavy category raise the assessment faster than the later ones.
  5. Check the hard flags. If at least one has triggered — the assessment is forced to the maximum.It overrides the whole calculation.
Wallet risk score bands

The finished number is laid out into a "traffic light". The band boundaries are a matter of threshold policy (see Lesson 4.3): one service will call 55 "medium", another "high".

How to read the risk bands

Lesson summary. A 0–100 number is not a measured quantity but a constructed one: exposure shares × category weights × adjustments for direction and recency, plus overriding hard flags. Understanding these three levers, you stop believing the figure blindly and start reading what it is assembled from. Hence a direct bridge to the next lesson: since every service sets weights, thresholds and label databases in its own way, their assessments of the same wallet naturally diverge — and this is not a bug but the reason the consensus approach exists.

This material is for educational purposes only.