Go back to Blog
Jennifer Edidiong
Marketing
9 min read
Share to
What Is Dynamic Risk Assessment and How Should African Fintechs Build It
Â

Most platforms have a risk gap they do not realise they have. Standard KYC confirms who a customer is at onboarding and assigns a risk tier, but that tier can remain unchanged until a manual review is triggered. A customer who was genuinely low-risk at signup but became high-risk months later may never be flagged because the system is still relying on the original assessment.
Dynamic risk assessment closes that gap by continuously updating the customer’s risk profile as new signals arrive, including behavioural shifts, device changes, and SIM activity. The CBN’s March 2026 Baseline Standards introduce requirements for automated AML monitoring and risk-based analysis, including dynamic risk scoring as new information becomes available.Â
This article explains what dynamic risk assessment is, the signals that feed it, how to build it, and where African fintechs commonly have gaps.
What Dynamic Risk Assessment Is and How It Differs From Static KYC

Static KYC and dynamic risk assessment work at different points in the customer lifecycle. Static KYC establishes who the customer is and sets the initial risk profile; dynamic risk assessment tracks how that risk changes over time. Both are necessary. Checking a guest’s ID at the door does not tell you what they do after they walk in.
The distinction becomes clearer in three areas:
- Static KYC is a one-time gate: At onboarding, the customer submits identity data, the platform verifies it, assigns a risk tier, and the customer enters the system. That tier reflects what the platform knew at that moment and does not change unless a review is triggered. A customer who was genuinely low-risk at signup can become high-risk six months later without the original KYC check surfacing it.
- Dynamic risk assessment keeps the score moving: Instead of relying on a fixed onboarding tier, the platform reassesses risk as new signals arrive. A SIM swap, unusual transaction, login from a new device, or change in spending pattern can alter the score. The result is a view of the customer’s current risk, not just their onboarding snapshot.
- The regulatory direction is moving beyond onboarding: In Nigeria, the CBN’s March 2026 Baseline Standards require automated AML solutions to update customer risk profiles as new data and behavioural changes emerge, using risk-based CDD and transaction analysis. South Africa’s FICA requires ongoing due diligence, including monitoring transactions throughout the customer relationship and keeping customer information up to date. The direction is clear: customer risk cannot be treated as a one-time assessment at signup.
Building a dynamic risk assessment capability starts with understanding which signals actually move a risk score.
The Signals That Feed a Dynamic Risk Score

A dynamic risk score is only as useful as the signals behind it. For African fintechs, real-time risk scoring depends on seeing what changes after onboarding, not just what was verified at signup. The right signals give the customer risk score context and show when their risk profile starts to shift.
The key signals include:
- Identity signals establish the baseline: BVN/NIN verification, document authenticity, liveness, and face matching help establish the customer’s identity and initial risk profile. A clean verification result can support a lower baseline, while verification flags, a low-confidence face match, or a partial name match can increase the initial risk level. Later signals can then be assessed against that baseline.
- Device intelligence catches changes:Â A known device presents a different risk picture from a new device, particularly when the device is associated with other accounts or shows signs of an emulator or rooted environment. A SIM swap followed by a new device and a high-value transaction, for example, creates a stronger risk signal than any of those events viewed alone.
- Phone intelligence adds context around SIM stability:Â A long-standing phone number provides a different signal from one that was recently swapped or provisioned. Number age, recent SIM activity, and other available fraud signals can add context to the customer risk score. A SIM swap shortly before a high-value transaction is a change that static KYC would not capture.
- Behavioural and transaction signals show changes: Transaction patterns, login timing, session behaviour, and counterparties can reveal when activity moves away from a customer’s normal pattern. A transfer that is significantly larger than usual, a new beneficiary followed by a large transfer, or activity at an unusual hour or from a new location can become elevated-risk events.
The right signals create the foundation. The next challenge is combining them into a risk assessment that can actually drive action.
How to Build a Dynamic Risk Assessment Capability

Knowing which signals matter is only the first step. A fintech still needs the right infrastructure to collect those signals, establish a customer baseline, and turn changes in risk into clear actions.
A practical dynamic risk assessment framework can be built in layers:
- Start with a clean identity baseline: Reliable identity data gives the risk model a solid starting point. Government database verification, liveness, face matching, and AML screening can help establish who the customer is and the initial level of risk.
- Add device and phone intelligence at every session: Device and phone signals should not stop at onboarding. Monitoring them throughout the customer lifecycle helps the platform spot changes such as a new device, SIM activity, or other signals that may change the customer’s risk profile.
- Build a behavioural baseline over time: A customer’s normal activity becomes clearer with continued observation. Transaction patterns, login behaviour, session activity, and counterparties can establish what is normal for that account. Using only generic thresholds can miss account-specific anomalies or create unnecessary alerts.
- Set risk thresholds that trigger action: A risk score only becomes useful when it leads to a defined response. Depending on the risk level and the fintech’s controls, that response could include step-up authentication, holding a transaction, or sending the case for compliance review. Thresholds should be defined, tested, and calibrated before they go live.
The infrastructure that makes this work is the part most African fintechs are still building.
The Common Gaps in How African Fintechs Currently Do This

Most African fintechs already have some form of risk scoring. The gaps usually appear in how those systems update and connect, creating room for real fraud to go undetected while legitimate users get caught in unnecessary alerts.
The problems tend to show up in three places:
- Risk tiers stay fixed after onboarding: A customer assigned a low-risk tier at signup can remain there even after their behaviour changes. A new device, unusual transaction pattern, or other risk signal may be detected but never feed back into the customer’s risk tier, leaving the system to rely on an outdated assessment.
- Rule-based systems catch known patterns and miss new ones: A rule that flags transfers above a specific amount catches what it was designed to catch. It will not adapt when fraud patterns change or when suspicious behaviour looks different for a particular account. Large alert volumes can also overwhelm compliance teams, making thorough review harder.
- Identity and monitoring layers remain disconnected: A customer can trigger a risk flag during identity verification while their transaction monitoring profile remains unchanged. Likewise, a new fraud signal from transaction activity may not trigger re-verification. The systems detect risk separately instead of sharing a current view of the customer.
Closing these gaps requires infrastructure that connects the identity layer, the monitoring layer, and the risk scoring layer in one system.
How Dojah Supports Dynamic Risk Assessment Across the Full Customer Lifecycle
Dynamic risk assessment connects onboarding checks with what happens after onboarding. Dojah supports both stages through EasyOnboard and Profiled Risk.
Here is how Dojah supports this across the customer lifecycle:
- Establish the identity baseline with EasyOnboard: EasyOnboard provides configurable onboarding and identity verification flows, including biometric checks such as face matching and liveness. This gives fintechs a reliable starting point for assessing customer risk.
- Monitor changes with Profiled Risk: Profiled Risk brings behavioural, device, transaction, and identity signals into a continuously updated risk profile. Instead of relying on the original onboarding assessment, fintechs can see when a customer’s activity changes.
- Dynamic risk scores that update in real time: Risk does not remain a fixed onboarding decision. Profiled Risk continuously updates risk scores as new events and signals arrive, giving fraud and compliance teams a current view of customer and event risk.
- A connected risk picture across both layers: EasyOnboard handles the verification layer, while Profiled Risk connects identity, behavioural, device, and transaction signals into a unified risk view. Instead of investigating each signal in isolation, teams can see the customer’s activity and risk across the lifecycle.
For African fintechs, this connects the two sides of dynamic risk assessment: establishing a reliable identity baseline and continuously assessing what changes after onboarding.
See how Dojah helps African fintechs build dynamic risk assessment across the customer lifecycle.
Frequently Asked Questions
1. What is dynamic risk assessment in fintech?
Dynamic risk assessment continuously evaluates a customer’s risk as new identity, device, behavioural, and transaction signals emerge. Unlike a fixed onboarding assessment, the risk profile can change as customer activity changes.
2. How is dynamic risk assessment different from static KYC?
Static KYC establishes and verifies a customer’s identity at onboarding. Dynamic risk assessment goes further by monitoring changes after onboarding and updating the customer’s risk profile as new signals appear.
3. What signals should feed a dynamic risk score for African fintechs?
A dynamic risk score can combine identity, device, phone, behavioural, and transaction signals. Examples include SIM changes, new devices, unusual transaction patterns, session anomalies, and changes from a customer’s normal activity.
4. How does real-time risk scoring help African fintechs detect fraud?
Real-time risk scoring allows fintechs to assess new activity as it happens rather than relying only on an onboarding risk tier. This can help surface changes in behaviour and transaction activity that may indicate increased risk.
5. How often should a customer risk score be updated?
A customer risk score should update when meaningful new risk signals or changes in behaviour are detected. The goal is to maintain a current risk picture rather than wait for a scheduled manual review.
Start using Dojah for all your business needs