One Constellation
Risk Management

The AML Enterprise-Wide Risk Assessment: Method and Template

Every AML programme is required to rest on a documented assessment of the risk it faces. Most firms produce one. Rather fewer produce one that would survive a determined examiner, because the document asserts conclusions instead of showing the working.

Published: September 2026 Category: Risk Management Read time: ~4 minutes
Quick Answer
This guide is about the artefact, not the principle. If you want the principle, the risk-based approach covers what regulators expect conceptually. What follows is how to produce the document that evidences it.

What an EWRA is for

The enterprise-wide risk assessment does one job: it justifies every other decision in the programme. Why is this customer segment subject to enhanced due diligence and that one is not? Why is the monitoring threshold set here? Why is the review cycle this length? Each answer should trace back to the EWRA.

This is the test that separates a real assessment from a compliance artefact. Take three control decisions from your programme and trace each to a line in the assessment. If you cannot, the document is decoration — and an examiner performing the same trace will reach the same conclusion faster than you would like.

The four-layer structure

Layer one: risk factor inventory

Enumerate what actually creates exposure, across five standard categories: customer types, products and services, delivery channels, geographies, and transaction characteristics. FATF's Recommendations and most national guidance use this framing, so following it makes your document legible to an examiner.

The common failure here is abstraction. "Corporate customers" is not a risk factor. "Corporate customers with beneficial owners in jurisdictions on the FATF grey list, onboarded non-face-to-face" is a risk factor, because it can be counted and controlled.

Layer two: inherent risk scoring

Score each factor before controls, on likelihood and impact. Two rules keep this defensible. Use a scale with an even number of points, so assessors cannot default to the middle. And anchor each point with a written definition — what distinguishes a three from a four — because unanchored scales drift between assessors and between years, which destroys comparability.

Critically, inherent scoring must be volume-aware. A high-risk product used by eleven customers is not equivalent to one used by eleven thousand. Carry exposure volume alongside the score.

Layer three: control effectiveness

This is where most assessments quietly collapse. For each inherent risk, identify the mitigating controls and rate how well they work — and rate it on evidence, not on the existence of a policy.

Evidence means testing results. QA sample pass rates, internal audit findings, monitoring model validation outcomes, screening tuning results. A control rated effective with no supporting test is an assertion, and an examiner will say so. Where no testing exists, the honest rating is "not evidenced", which is itself a finding worth having.

Layer four: residual risk and response

Residual risk is what remains after controls. For each residual risk above appetite, the document must state the response: accept with rationale, remediate with an owner and date, or avoid by exiting the activity. An EWRA that identifies residual risk without stating a response is an unfinished document.

Governance

Three things must be visible or the assessment carries no weight.

  • Ownership. The MLRO owns it. Business lines contribute; they do not sign off their own risk ratings.
  • Challenge. Evidence that someone tested the conclusions. A second-line review, an audit committee discussion, or a documented challenge log — all defensible. Silent approval is not.
  • Board approval. Minuted, with the version approved identified. "The board has seen the risk assessment" is weaker than a minute referencing version 3.1 dated March 2026.

Refresh annually as a floor, and on material change — a new product, a new market, an acquisition, or a significant regulatory development. A document dated two years ago describing a business that has since changed shape is worse than none, because it demonstrates the process is not live.

Connecting it to the programme

The final section of a good EWRA is a mapping table: each material residual risk, the specific control that addresses it, and where that control is documented. This is the section that makes the document useful rather than ceremonial, and it is almost always the one that is missing.

It also makes the next assessment dramatically cheaper. With the mapping in place, the annual refresh becomes a question of what changed — in exposure, in controls, in testing results — rather than a rebuild from a blank page.

A practical starting sequence

Build the risk factor inventory first and circulate it before scoring anything. Disagreements about what counts as a risk factor are much cheaper to resolve before numbers are attached. Then score inherent risk with volumes. Then, for each material risk, ask the control owner one question: what test result demonstrates this control works? The pattern of answers to that question is, in practice, your most useful output — usually more useful than the scores themselves.

Related: building a risk-based AML programme covers the controls the assessment justifies, and customer risk rating covers the customer-level assessment that sits beneath this one.

Scoring Scales That Survive Challenge

Most of the criticism an assessment attracts is aimed not at its conclusions but at how those conclusions were reached. Three practices remove almost all of it.

Anchor every point on the scale

Write a definition for each score. What distinguishes a 3 from a 4 on likelihood? If the answer is "judgement", two assessors will score the same factor differently and the year-on-year comparison becomes meaningless. Anchors do not have to be quantitative, but they do have to be written down.

Calibrate before scoring, not after

Bring the assessors together and score three or four factors collectively before anyone works alone. Disagreements surfaced in that session are cheap; the same disagreements surfaced during board review are not.

Separate the scale from the appetite

A residual score of 4 is not automatically unacceptable. Whether it is depends on appetite, which the board sets — not on the scoring scale, which the MLRO owns. Conflating the two produces assessments that quietly understate risk because assessors are reluctant to record a number that implies a remediation project.

Where Assessments Most Often Fail

Four failure modes recur across firms of very different sizes.

  • The document describes the industry, not the firm. If the text could be lifted into a competitor's assessment with only the name changed, it is not a firm-wide risk assessment in substance.
  • Control effectiveness is asserted. Every control rated effective with no test result behind it is an invitation to challenge. "Not evidenced" is an honest and useful rating.
  • Volume is missing. Risk scores without exposure volumes cannot be prioritised. A high-risk product used by eleven customers should not consume the same attention as one used by eleven thousand.
  • Nothing downstream changed. If last year's assessment produced no change to any threshold, trigger or review cycle, either the business is genuinely static or the assessment is not being used.

Connecting the Firm-Wide View to the Customer View

The enterprise assessment and the customer risk model are frequently built by different people at different times, and the disconnect shows up under examination as an inability to explain why a customer scores as it does.

The relationship should be explicit in both directions. Every factor in the customer risk model — jurisdiction, product, channel, entity type, expected activity — ought to trace to a risk identified in the enterprise assessment. Conversely, every material risk in the enterprise assessment that manifests at customer level ought to appear somewhere in the customer model. A geography flagged as high risk firm-wide that carries no weighting in customer scoring is a gap worth explaining before someone else finds it.

Weightings deserve the same treatment as scores. If jurisdiction carries twice the weight of product, there should be a stated reason grounded in the firm's exposure rather than in convention inherited from a previous implementation.

The practical test is a single customer. Take one high-risk relationship, and trace every element of its rating back to the enterprise assessment. Where a rating element has no parent, the customer model is doing something the firm has not articulated. Where an enterprise risk has no child, the assessment has identified something the controls do not act on. Both are findings, and both are considerably cheaper to discover internally. See customer risk rating for the model itself.

A Risk Assessment That Connects to Controls

One Constellation links customer risk scoring, monitoring thresholds and EDD triggers back to the exposures your assessment identifies — so every control decision has a traceable rationale.

← The Risk-Based Approach FATF Grey List 2026 All Articles
Scroll to Top