The AML Enterprise-Wide Risk Assessment: Method and Template
Every AML programme is required to rest on a documented assessment of the risk it faces. Most firms produce one. Rather fewer produce one that would survive a determined examiner, because the document asserts conclusions instead of showing the working.
What an EWRA is for
The enterprise-wide risk assessment does one job: it justifies every other decision in the programme. Why is this customer segment subject to enhanced due diligence and that one is not? Why is the monitoring threshold set here? Why is the review cycle this length? Each answer should trace back to the EWRA.
This is the test that separates a real assessment from a compliance artefact. Take three control decisions from your programme and trace each to a line in the assessment. If you cannot, the document is decoration — and an examiner performing the same trace will reach the same conclusion faster than you would like.
The four-layer structure
Layer one: risk factor inventory
Enumerate what actually creates exposure, across five standard categories: customer types, products and services, delivery channels, geographies, and transaction characteristics. FATF's Recommendations and most national guidance use this framing, so following it makes your document legible to an examiner.
The common failure here is abstraction. "Corporate customers" is not a risk factor. "Corporate customers with beneficial owners in jurisdictions on the FATF grey list, onboarded non-face-to-face" is a risk factor, because it can be counted and controlled.
Layer two: inherent risk scoring
Score each factor before controls, on likelihood and impact. Two rules keep this defensible. Use a scale with an even number of points, so assessors cannot default to the middle. And anchor each point with a written definition — what distinguishes a three from a four — because unanchored scales drift between assessors and between years, which destroys comparability.
Critically, inherent scoring must be volume-aware. A high-risk product used by eleven customers is not equivalent to one used by eleven thousand. Carry exposure volume alongside the score.
Layer three: control effectiveness
This is where most assessments quietly collapse. For each inherent risk, identify the mitigating controls and rate how well they work — and rate it on evidence, not on the existence of a policy.
Evidence means testing results. QA sample pass rates, internal audit findings, monitoring model validation outcomes, screening tuning results. A control rated effective with no supporting test is an assertion, and an examiner will say so. Where no testing exists, the honest rating is "not evidenced", which is itself a finding worth having.
Layer four: residual risk and response
Residual risk is what remains after controls. For each residual risk above appetite, the document must state the response: accept with rationale, remediate with an owner and date, or avoid by exiting the activity. An EWRA that identifies residual risk without stating a response is an unfinished document.
Governance
Three things must be visible or the assessment carries no weight.
- Ownership. The MLRO owns it. Business lines contribute; they do not sign off their own risk ratings.
- Challenge. Evidence that someone tested the conclusions. A second-line review, an audit committee discussion, or a documented challenge log — all defensible. Silent approval is not.
- Board approval. Minuted, with the version approved identified. "The board has seen the risk assessment" is weaker than a minute referencing version 3.1 dated March 2026.
Refresh annually as a floor, and on material change — a new product, a new market, an acquisition, or a significant regulatory development. A document dated two years ago describing a business that has since changed shape is worse than none, because it demonstrates the process is not live.
Connecting it to the programme
The final section of a good EWRA is a mapping table: each material residual risk, the specific control that addresses it, and where that control is documented. This is the section that makes the document useful rather than ceremonial, and it is almost always the one that is missing.
It also makes the next assessment dramatically cheaper. With the mapping in place, the annual refresh becomes a question of what changed — in exposure, in controls, in testing results — rather than a rebuild from a blank page.
A practical starting sequence
Build the risk factor inventory first and circulate it before scoring anything. Disagreements about what counts as a risk factor are much cheaper to resolve before numbers are attached. Then score inherent risk with volumes. Then, for each material risk, ask the control owner one question: what test result demonstrates this control works? The pattern of answers to that question is, in practice, your most useful output — usually more useful than the scores themselves.
Related: building a risk-based AML programme covers the controls the assessment justifies, and customer risk rating covers the customer-level assessment that sits beneath this one.
Scoring Scales That Survive Challenge
Most of the criticism an assessment attracts is aimed not at its conclusions but at how those conclusions were reached. Three practices remove almost all of it.
Anchor every point on the scale
Write a definition for each score. What distinguishes a 3 from a 4 on likelihood? If the answer is "judgement", two assessors will score the same factor differently and the year-on-year comparison becomes meaningless. Anchors do not have to be quantitative, but they do have to be written down.
Calibrate before scoring, not after
Bring the assessors together and score three or four factors collectively before anyone works alone. Disagreements surfaced in that session are cheap; the same disagreements surfaced during board review are not.
Separate the scale from the appetite
A residual score of 4 is not automatically unacceptable. Whether it is depends on appetite, which the board sets — not on the scoring scale, which the MLRO owns. Conflating the two produces assessments that quietly understate risk because assessors are reluctant to record a number that implies a remediation project.
Where Assessments Most Often Fail
Four failure modes recur across firms of very different sizes.
- The document describes the industry, not the firm. If the text could be lifted into a competitor's assessment with only the name changed, it is not a firm-wide risk assessment in substance.
- Control effectiveness is asserted. Every control rated effective with no test result behind it is an invitation to challenge. "Not evidenced" is an honest and useful rating.
- Volume is missing. Risk scores without exposure volumes cannot be prioritised. A high-risk product used by eleven customers should not consume the same attention as one used by eleven thousand.
- Nothing downstream changed. If last year's assessment produced no change to any threshold, trigger or review cycle, either the business is genuinely static or the assessment is not being used.
Connecting the Firm-Wide View to the Customer View
The enterprise assessment and the customer risk model are frequently built by different people at different times, and the disconnect shows up under examination as an inability to explain why a customer scores as it does.
The relationship should be explicit in both directions. Every factor in the customer risk model — jurisdiction, product, channel, entity type, expected activity — ought to trace to a risk identified in the enterprise assessment. Conversely, every material risk in the enterprise assessment that manifests at customer level ought to appear somewhere in the customer model. A geography flagged as high risk firm-wide that carries no weighting in customer scoring is a gap worth explaining before someone else finds it.
Weightings deserve the same treatment as scores. If jurisdiction carries twice the weight of product, there should be a stated reason grounded in the firm's exposure rather than in convention inherited from a previous implementation.
The practical test is a single customer. Take one high-risk relationship, and trace every element of its rating back to the enterprise assessment. Where a rating element has no parent, the customer model is doing something the firm has not articulated. Where an enterprise risk has no child, the assessment has identified something the controls do not act on. Both are findings, and both are considerably cheaper to discover internally. See customer risk rating for the model itself.
A Risk Assessment That Connects to Controls
One Constellation links customer risk scoring, monitoring thresholds and EDD triggers back to the exposures your assessment identifies — so every control decision has a traceable rationale.
