Transactions & analysis
How to Run a Risk Analysis on Bank Statements
Audit a set of statements for lending risk: what the report checks, how to read the attention score and findings, and why it never recommends approving or declining.
Last verified in Bankflow on September 14, 2026.
What It's For
A risk analysis reads a set of statements the way a credit officer would: what the account actually held day to day, where money comes from and whether it will keep coming, what's already committed each month, whether payments have bounced, and whether the statements themselves can be relied on. It's built for lenders, brokers, and accountants reviewing someone's statements, and it works just as well on your own.
The report tells you what to look at and shows the transactions behind every finding. It does not recommend approving or declining anyone. That decision stays with you.
Step 1: Choose the Statements
Risk analyses start from the Statements page, never on their own. Select the statements you want read together; they can span several banks. Then choose Run risk analysis on N statements from the selection bar. For a single statement, the same option is in its row menu.
A one-statement audit is a thin one, and the report says so, but a single month is often all a lender has, so it's allowed.
Step 2: Check the Scope
Before anything runs, a dialog shows what the report will be based on: how many statements and transactions, the period and how many months it covers, the banks, and the currency. Nothing is analysed until you press Run audit, so this is your chance to fix the selection. The dialog warns you when:
- Days are missing between statements. Anything that happened in a gap is simply absent from the evidence. Add the missing statement now if you have it.
- The selection spans more than one currency. Amounts are withheld from the report rather than converted at a rate Bankflow picked. Ratios, counts, and timing patterns are unaffected.
- A selected statement is switched off. It contributes nothing, and the report records which ones were left out.
Reading the Report
The attention score
At the top, the report names what was audited and gives it a band, from most to least urgent: Read first, Read before deciding, Worth reading, and Little to follow up. When there isn't enough to go on, it says Not enough to assess. Beside the band is an attention score. Higher means more to look at. It's for ordering a queue of files. It is not a credit decision, a grade, or a probability of default.
What to read first
The most serious findings are pulled out of their sections and listed first, worst first. If nothing critical or high came up, the report says so, and the lesser findings stay in their sections below.
The sections
Every finding opens onto the transactions behind it. The sections are:
- Evidence: whether the statements can be relied on. Everything else is only as good as this, so it's shown first and in full.
- Liquidity: what the account actually held day by day, rather than on statement dates.
- Inflow: where the money comes from, and whether it can be expected to keep coming.
- Obligations: what's already committed each month before anything new is added.
- Distress: payments that have already failed. These are the most predictive rows in a statement.
- Laundering: structural patterns associated with moving money rather than earning it.
- Behaviour: how the account is used, limited to what a lender underwrites against.
Each section also lists the figures it measured, so a section with nothing flagged still shows you what was checked.
The written summary
The report includes a written summary of the findings in plain language. It's written after the analysis is complete and has no effect on it.
Past Analyses
Risk analysis in the sidebar lists every audit you've run, with its attention score. Open one to read it again, or delete it. A report is built only from the rows it was given, so reopening it months later shows the same result, even if you've imported more statements since.
Next Step
If the Evidence section flags a statement, open it and review it: the verification checks and source file history there are the same evidence the report is reading.