The anti-money-laundering framework asks businesses to be risk-based, and the document that makes that possible is the business risk assessment. It is the foundation the rest of a compliance programme is built on: without understanding where your own money-laundering risk actually lies, you cannot sensibly decide how much due diligence to do, what to monitor, or where to focus. Supervisors expect to see it, and a business that has none is starting its AML programme with no map. Here is what the assessment is and how to approach it.
What the risk assessment does
A business risk assessment is a structured look at how exposed your business is to being used for money laundering or terrorist financing, and why. It considers the customers you serve, the countries you deal with, the products and services you offer, and the ways you deliver them, and forms a view of where the risk concentrates. The output guides everything else: higher-risk areas get more scrutiny, lower-risk ones get proportionate checks. It turns a vague obligation into a targeted programme.
The risk factors to weigh
A sound assessment looks across a consistent set of dimensions rather than a single number.
| Risk factor | What raises the risk |
|---|---|
| Customer risk | Opaque ownership, cash-heavy, politically exposed |
| Geographic risk | Links to high-risk jurisdictions |
| Product and service risk | High-value, anonymous, or easily moved |
| Delivery channel risk | Non-face-to-face or intermediated onboarding |
| Transaction risk | Large, unusual, or hard-to-explain flows |
Risk-based means proportionate
The purpose of the assessment is to let you apply effort where it matters. A business that identifies its genuinely higher-risk customers, geographies, and products can concentrate its due diligence and monitoring there, while handling lower-risk business with lighter, standard checks. This is more effective and more efficient than treating everything identically. The assessment is what justifies those choices, both to yourself and to a supervisor asking why you did what you did.
The risk assessment is the map the rest of your AML programme reads from. Skip it and every later decision, how much to check, what to monitor, becomes a guess you cannot defend.
A living document, not a one-off
A risk assessment is not something you write once and file. As your business changes, new customers, new markets, new services, so does your risk, and the assessment should be reviewed and updated to keep pace. A years-old assessment that no longer reflects what the business does is little better than none, because the programme built on it is calibrated to risks that have moved. Keeping it current is part of keeping the whole programme honest.
What to do about it
Produce a genuine business risk assessment across customers, geography, products, delivery, and transactions, and use it to set the depth of your due diligence and monitoring rather than treating it as a document to file. Concentrate effort on the areas it flags as higher-risk. Review and update it as the business evolves. The risk assessment is unglamorous and easy to postpone, but it is the piece that makes a risk-based programme actually risk-based, and supervisors know to ask for it first.
This article is general information and is not legal advice. Risk-assessment requirements depend on your activity and supervisor. We would be glad to help you build and maintain one.
