Summary
An enterprise-wide AML risk assessment (EWRA) is the anchor of a credible financial crime framework. Done well, it prioritises controls where the money is; done poorly, it becomes a compliance artefact that nobody trusts.
Structuring inherent risk
Inherent risk is assessed across four axes: customer, product, channel and geography. Each axis needs a defined methodology, weightings and evidence.
Control effectiveness
Effectiveness is challenged, not asserted. The EWRA should draw on control testing results, monitoring alert quality and remediation status.
Residual risk and appetite
Residual risk is compared to appetite. Where residual exceeds appetite, remediation is scoped and owned.
Governance and use
The EWRA drives KYC standards, monitoring rules, thresholds and MI. Where it does not, it is a document rather than a framework.
Limitations
This article does not constitute legal advice. Jurisdictional interpretation should be confirmed with qualified counsel.
Related expertise
Frequently asked questions
What should risk leaders know about structuring inherent risk?
Inherent risk is assessed across four axes: customer, product, channel and geography. Each axis needs a defined methodology, weightings and evidence.
What should risk leaders know about control effectiveness?
Effectiveness is challenged, not asserted. The EWRA should draw on control testing results, monitoring alert quality and remediation status.
What should risk leaders know about residual risk and appetite?
Residual risk is compared to appetite. Where residual exceeds appetite, remediation is scoped and owned.
What should risk leaders know about governance and use?
The EWRA drives KYC standards, monitoring rules, thresholds and MI. Where it does not, it is a document rather than a framework.