Skip to main content
POST /v1/kyc/assess takes the same request as /verify, runs the same verification, and builds an assessment on top of it. Scope: kyc:verify. It is not a credit score. It returns four read-outs for an advisor: risk tolerance, financial capacity, compliance risk and suitability. Every number on this page is computed by a deterministic function of values and the verdict. Same input, same output.

Response

verification is shortened here; it is the full verdict of /verify. The assessment also repeats the verdict under assessment.verification. The example is the engine’s real output for fake data (see the walkthrough).

Risk tolerance

Needs all four answers in values. If any is empty, score and band are null and missing lists the absent keys. No partial score is made and no default is assumed. An answer that is present but not in the table scores a default: objective 50, horizon 50, knowledge 40, experience 40. Use the exact strings above.
If uses_leverage is true (boolean), "true" or "Yes", add 8. The result is rounded and held between 0 and 100. Example: balanced (50), 5-10 years (68), Good (70), under 5 years (50) gives 50 x 0.35 + 68 x 0.25 + 70 x 0.20 + 50 x 0.20 = 58.5, rounded to 58, Balanced.

Capacity

Needs at least one of annual_income, net_liquid_assets, total_net_worth. With none, score and band are null. With one or two, the score is computed and missing lists the others. A missing amount counts as a value of 0, which falls in the lowest bracket (sub-score 12 or 15), so a missing answer pulls the score down. Values are parsed from strings such as 84000, 150,000, $1.2M or 84k.
Example: income 84,000 (35), liquid 20,000 (12), net worth 60,000 (15) gives 10.5 + 4.2 + 5.25 = 19.95, rounded to 20, Low. The sample amounts are read as MAD. The engine reads amounts as plain numbers against fixed bands that are not currency specific, so 84,000 scores the same in any currency. The API does not convert currencies. The brackets are in the unit you send.

Compliance risk

Points add up from the profile and the verdict. A workspace policy can lower the Low ceiling (default 1) and the Medium ceiling (default 3), never raise them. factors lists each contribution in words, for example Flag: <label> (<detail>) or Verification failed: <label> (<detail>). Info checks add nothing. Note that a warning counts even if it is one the client cannot fix, such as completeness below 80 percent: a thin file scores one point.

Geography tiers

Derived from the FATF public lists as of 19 June 2026 (FATF_LISTS_AS_OF). The set is a snapshot in the code and is refreshed after each FATF plenary. Codes are ISO alpha-2. A few alpha-3 codes and names are understood (IRN, iran, usa, canada). Anything else counts as standard. A prohibited country alone scores 6, which is High. Do not hard-code this table in your application: it changes with each FATF publication.

Suitability

The first rule that matches wins. Suitable is a read-out for an advisor, not a regulatory determination of suitability. The firm makes that determination.

Worked examples

A complete, clean file gives:
The same file with an expired national ID (critical failures add 3 points each and force High):
Its suitability is Blocked — document verification failed, and risk_level still reads Balanced.

Example request

With documents: [] and require_documents: false the example above has no document checks, so compliance risk depends on the completeness warning and the screening line of your environment. The expected risk_profile and capacity are the same as above.

Webhook summary

The kyc.case_assessed event carries risk_level and suitability in its verdict summary. There, risk_level is compliance_risk.level (Low, Medium, High), not the risk tolerance band. See Webhooks.