> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.flagright.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.flagright.com/_mcp/server.

# CRA Risk Level Update

POST 

Occurs whenever a user's CRA risk level is updated

Reference: https://docs.flagright.com/api-reference/webhooks/user/cra-risk-level-update

## Request

### Headers

- `x-flagright-signature` (string, required) — An [HMAC SHA256 signature](/guides/webhooks/signatures#verifying-signatures) generated using the webhook payload and a shared signing secret. This is then converted to a hex encoded string.

### Payload

- `id` (string, required) — Unique identifier for the event
- `triggeredBy` (enum, required) — Event triggered by a user or system
  - Allowed values: `MANUAL`, `SYSTEM`
- `createdTimestamp` (double, required) — Time at which the event was created. Measured in ms since the Unix epoch.
- `type` (enum, required)
  - Allowed values: `CRA_RISK_LEVEL_UPDATED`
- `data` (CRARiskLevelUpdatedDetails, required)
- `account` (string, optional) — Email ID associated with the event

## Types

### CRARiskLevelUpdatedDetails

- `riskLevel` (string, optional)
- `userId` (string, optional)
- `riskScore` (double, optional) — Current CRA (DRS) risk score for the user
- `kycRiskScore` (double, optional) — KRS score when a KRS record exists for the user
- `kycRiskLevel` (string, optional) — Risk level derived from the KRS score
- `riskFactors` (list of CRARiskLevelUpdatedRiskFactor, optional) — Per-factor or component breakdown from KRS when present; omitted when there is no KRS data or no breakdown rows

### CRARiskLevelUpdatedRiskFactor

KRS breakdown row from factor score details or component scores when available

- `riskFactorId` (string, optional)
- `riskFactorName` (string, optional)
- `riskFactorVersionId` (string, optional) — Set for KRS factor score detail rows
- `value` (string, optional)
- `riskScore` (double, optional)
- `riskLevel` (string, optional)
- `weight` (double, optional)