By Jonas Osman AbdelfourPublished January 20, 2026Last reviewed May 12, 2026
Summary An enterprise-wide AML risk assessment (EWRA) is the anchor of a credible financial crime framework. Done well, it prioritises controls where the money is; done poorly, it becomes a compliance artefact that nobody trusts.
Structuring inherent risk Inherent risk is assessed across four axes: customer, product, channel and geography. Each axis needs a defined methodology, weightings and evidence.
Control effectiveness Effectiveness is challenged, not asserted. The EWRA should draw on control testing results, monitoring alert quality and remediation status.
Residual risk and appetite Residual risk is compared to appetite. Where residual exceeds appetite, remediation is scoped and owned.
Governance and use The EWRA drives KYC standards, monitoring rules, thresholds and MI. Where it does not, it is a document rather than a framework.
Limitations This article does not constitute legal advice. Jurisdictional interpretation should be confirmed with qualified counsel.
Related expertise See [Anti-Money Laundering and Financial Crime Risk](/expertise/aml).
Frequently asked questions
What should risk leaders know about structuring inherent risk?
Inherent risk is assessed across four axes: customer, product, channel and geography. Each axis needs a defined methodology, weightings and evidence.
What should risk leaders know about control effectiveness?
Effectiveness is challenged, not asserted. The EWRA should draw on control testing results, monitoring alert quality and remediation status.
What should risk leaders know about residual risk and appetite?
Residual risk is compared to appetite. Where residual exceeds appetite, remediation is scoped and owned.
What should risk leaders know about governance and use?
The EWRA drives KYC standards, monitoring rules, thresholds and MI. Where it does not, it is a document rather than a framework.