What is an AML Risk Assessment?

An AML risk assessment is the process of identifying, scoring, and controlling the money laundering and terrorist financing risks a business faces.

An AML risk assessment answers a simple question. Which risks are most likely and most harmful, and how should the business control them? The answer shapes the rest of the AML program, from which customers receive enhanced due diligence to how transaction monitoring thresholds are set.

An AML risk assessment is the foundation of the risk-based approach, which comes from FATF Recommendation 1. Instead of treating every customer the same way, firms focus staff, time, and technology where risk is highest.

How do you conduct an AML risk assessment?

Conducting an AML risk assessment follows a repeatable sequence.

  1. Identify inherent risks across customers, products, delivery channels, and geography
  2. Score each risk by likelihood and potential impact
  3. Map customer, product, and geography combinations on a risk matrix
  4. Set controls for each risk level, from simplified due diligence for low risk to enhanced due diligence for high risk
  5. Document the methodology and the rationale behind each rating

What risk factors does an AML risk assessment cover?

Most assessments group risk factors into customer, product, channel, and geographic categories. Common examples include the following.

  • Politically exposed persons and non-resident customers
  • High-risk industries such as casinos and real estate
  • Cash-intensive products like prepaid cards and money orders
  • Opaque products like private banking and trust services
  • Crypto and other emerging products
  • Online-only onboarding and third-party introducers
  • Jurisdictions on the FATF grey list

How are AML risks scored?

Firms score AML risk qualitatively, quantitatively, or with a mix of both. Qualitative scoring relies on expert judgment and suits new products or markets with little data. Quantitative scoring assigns points to each risk factor and adds them into an overall score, such as 5 points for a politically exposed person and 3 points for remote onboarding.

On a risk matrix of likelihood against impact, a foreign politically exposed person making large cross-border transfers would typically rank as high risk. Many firms now use dynamic risk scoring so customer risk scores update as behavior changes.

How often should an AML risk assessment be updated?

Most firms reassess their AML risk assessment at least once a year. They also run interim reviews after major changes, such as a new product launch or a country moving on or off the FATF grey list. Each review cycle should be signed off by the MLRO or a risk committee. The results then drive action, typically through enhanced due diligence, tighter monitoring rules, and regular reporting to the board.