Join our Newsletter — 33% off our NHI Course

Why does benchmarking VASP activity against similar firms improve risk decisions?

Benchmarking helps separate normal industry behaviour from activity that is unusual for a specific VASP. A gambling-related exposure, for example, may look concerning in isolation but be common across the broader category. Comparing the entity with peers improves context, reduces false positives, and makes escalation decisions more consistent and explainable.

Why peer benchmarking changes the quality of a VASP risk view

Peer benchmarking gives context that a single-entity review cannot. A behaviour that looks unusual in isolation may be normal for a similar firm because of product mix, geography, customer base, or market role. That distinction matters in risk work because it reduces false positives and helps analysts focus on genuinely outlier activity.

It also makes escalation decisions more defensible. When the same pattern is compared against a relevant peer set, reviewers can explain why it is ordinary, borderline, or truly exceptional instead of relying on intuition or a fixed threshold that may not fit the business model.

What “similar firms” should mean in practice

The value of benchmarking depends on how well the peer group is defined. Similarity should be based on the factors that shape expected activity, such as the types of assets handled, customer profile, jurisdictions served, transaction volumes, and whether the firm operates as an exchange, broker, custodian, or payment-linked service.

If the peer group is too broad, the comparison loses signal and can produce misleading comfort or unnecessary concern. If it is too narrow, the benchmark can be distorted by a small sample or by firms with unusual operating models. Good benchmarking is therefore less about finding an average and more about finding the right reference class.

Practitioners often use external baselines alongside internal trend analysis. The external comparison helps answer “is this unusual for the sector?”, while the internal comparison answers “is this unusual for this firm relative to its own history?”. Those two questions are related, but they are not the same.

How benchmarking improves escalation decisions

Benchmarking improves decisions by turning a raw alert into a contextual judgement. A pattern that appears high-risk on its own may be expected for a VASP segment exposed to a particular customer type, asset class, or market behaviour. Conversely, a pattern that looks benign may become more concerning when peers show much lower activity under similar conditions.

That context makes risk scoring more explainable to operations, compliance, and leadership teams. It also supports more consistent triage because analysts can document why they did or did not escalate a case, rather than treating every deviation as equally suspicious.

For a risk function, the main benefit is better prioritisation. Benchmarking should help direct human review toward the cases where the firm is genuinely outside its expected operating envelope, rather than consuming attention on sector-wide behaviour that is noisy but not necessarily abnormal.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
CIS Controls v8 CIS-14 — Security Awareness and Skills Training Helps analysts make consistent, explainable risk judgments from contextual evidence.
Recommendation — Train reviewers to use peer context before escalating unusual but expected activity.
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy Peer benchmarking supports a risk strategy that defines how much deviation is material.
ID.RA-01 — Asset Vulnerabilities Are Identified and Recorded Comparing a VASP to peers helps identify when observed activity is materially atypical.
Recommendation — Define benchmark-based thresholds that distinguish expected sector behaviour from true outliers. Use peer comparisons to separate normal operating patterns from anomalous risk indicators.
ISO/IEC 27001:2022 A.5.7 — Threat intelligence Sector peer comparison is a practical form of external intelligence for risk context.
Recommendation — Incorporate sector intelligence when assessing whether activity is genuinely unusual.

Practitioner Guidance

What to verify: Make sure the peer set is comparable on the dimensions that actually drive activity, not just on company size or brand recognition. If the peer group is mis-specified, the benchmark can be more misleading than having no benchmark at all.

Decision rule: Treat a deviation as more material when it is unusual both versus peers and versus the firm’s own history. If it is only unusual in one view, investigate the business explanation before escalating.

What practitioners underestimate: Benchmarking is a decision-support tool, not a substitute for case-level review. The best use of the comparison is to improve consistency, reduce noise, and justify why a case deserves attention now.

Practitioner takeaway: Peer benchmarking is most valuable when it changes the question from “is this activity high?” to “is this activity high for this type of VASP under these conditions?”