Back to all briefings
/ GOVERNANCE 26 Aug 2026 · 5 min read

The AML business risk assessment.

The framework asks businesses to be risk-based, and the document that makes that possible is the business risk assessment. Without knowing where your risk lies, you cannot decide what to check or monitor. Here is what it is and how to approach it.

The anti-money-laundering framework asks businesses to be risk-based, and the document that makes that possible is the business risk assessment. It is the foundation the rest of a compliance programme is built on: without understanding where your own money-laundering risk actually lies, you cannot sensibly decide how much due diligence to do, what to monitor, or where to focus. Supervisors expect to see it, and a business that has none is starting its AML programme with no map. Here is what the assessment is and how to approach it.

What the risk assessment does

A business risk assessment is a structured look at how exposed your business is to being used for money laundering or terrorist financing, and why. It considers the customers you serve, the countries you deal with, the products and services you offer, and the ways you deliver them, and forms a view of where the risk concentrates. The output guides everything else: higher-risk areas get more scrutiny, lower-risk ones get proportionate checks. It turns a vague obligation into a targeted programme.

The risk factors to weigh

A sound assessment looks across a consistent set of dimensions rather than a single number.

Risk factorWhat raises the risk
Customer riskOpaque ownership, cash-heavy, politically exposed
Geographic riskLinks to high-risk jurisdictions
Product and service riskHigh-value, anonymous, or easily moved
Delivery channel riskNon-face-to-face or intermediated onboarding
Transaction riskLarge, unusual, or hard-to-explain flows

Risk-based means proportionate

The purpose of the assessment is to let you apply effort where it matters. A business that identifies its genuinely higher-risk customers, geographies, and products can concentrate its due diligence and monitoring there, while handling lower-risk business with lighter, standard checks. This is more effective and more efficient than treating everything identically. The assessment is what justifies those choices, both to yourself and to a supervisor asking why you did what you did.

The risk assessment is the map the rest of your AML programme reads from. Skip it and every later decision, how much to check, what to monitor, becomes a guess you cannot defend.

A living document, not a one-off

A risk assessment is not something you write once and file. As your business changes, new customers, new markets, new services, so does your risk, and the assessment should be reviewed and updated to keep pace. A years-old assessment that no longer reflects what the business does is little better than none, because the programme built on it is calibrated to risks that have moved. Keeping it current is part of keeping the whole programme honest.

What to do about it

Produce a genuine business risk assessment across customers, geography, products, delivery, and transactions, and use it to set the depth of your due diligence and monitoring rather than treating it as a document to file. Concentrate effort on the areas it flags as higher-risk. Review and update it as the business evolves. The risk assessment is unglamorous and easy to postpone, but it is the piece that makes a risk-based programme actually risk-based, and supervisors know to ask for it first.

This article is general information and is not legal advice. Risk-assessment requirements depend on your activity and supervisor. We would be glad to help you build and maintain one.

/ FW GLOBAL CONSULTING

If this briefing raises a question on your file, we are glad to take it on a call.