Financial Crime Risk Assessment

Financial Crime Risk Assessment

A financial crime risk assessment is a firm-wide analysis of exposure across every type of financial crime, including money laundering, sanctions, fraud, and bribery. It is broader than an AML risk assessment, which looks only at money laundering, and it sits at the heart of a financial crime compliance function.

Key takeaways

  • A financial crime risk assessment covers all financial crime, not just laundering.
  • It spans money laundering, sanctions, fraud, bribery, and terrorist financing.
  • It is broader than an AML risk assessment, which covers money laundering alone.
  • The method is the same: inherent risk, minus controls, equals residual risk.
  • It is the foundation of a financial crime compliance function.
  • A stale or missing assessment is a common examination finding.

$800B to $2T

Laundered worldwide each year, one part of financial crime

Source: UNODC

~$300B

Laundered in the United States each year

Source: US Department of the Treasury

$3B

Paid by TD Bank in 2024 after control failures

Source: US Department of Justice

What is a financial crime risk assessment?

A financial crime risk assessment is a structured look at where a firm is exposed to financial crime of every kind. It maps the threats the business faces, rates how serious each is, and sets how strong the controls need to be.

The output is a single, ranked picture of financial crime risk, written down and defensible. That picture then guides how much effort each control deserves, across the whole range of crime types.

It is the base a financial crime function is built on. Read more: it underpins financial crime compliance as a whole.

Financial crime risk assessment vs AML risk assessment

This is the point that causes the most confusion, so it is worth being clear. The two assessments share a method but differ in scope.

An AML risk assessment looks only at money laundering. A financial crime risk assessment is wider: it covers money laundering plus sanctions, fraud, bribery, and terrorist financing. In many firms, the AML assessment is one part of the broader financial crime one.

AML risk assessment Financial crime risk assessment
Scope Money laundering only All financial crime
Covers Laundering risk Laundering, sanctions, fraud, bribery, TF
Sits within The AML program The financial crime function

Same discipline, wider lens. A firm with mature controls often runs the financial crime assessment as the parent, with the AML view nested inside it.

What a financial crime risk assessment covers

The assessment spans the full range of financial crime a firm can face. Each area has its own risks, but they are judged together in one view.

  • Money laundering. The risk of the firm being used to hide criminal money.
  • Sanctions. The risk of dealing with restricted parties or countries.
  • Fraud. The risk of deception that takes money from the firm or its customers.
  • Bribery and corruption. The risk of improper payments. See anti-bribery and corruption.
  • Terrorist financing. The risk of funds reaching terrorists.

Judging these together is the point. A firm that assesses each crime in isolation can miss how they overlap and reinforce each other.

Get an indicative financial crime risk rating

See where your financial crime risk is concentrated across customers, products, markets, and channels.

Try the AML Risk Assessment →

Why firms need one

A firm needs a financial crime risk assessment because it justifies the whole compliance function. Without it, controls are set on instinct rather than evidence.

It also focuses effort where it counts. Financial crime risk is spread unevenly across a business, so a clear assessment lets a firm put people and tools where the real threats are, rather than spreading them thin.

Regulators treat a weak assessment as a serious gap. The TD Bank case in 2024, with about $3 billion in penalties, stemmed in part from controls that did not match the firm’s real risk (US Department of Justice, 2024).

Risk factors across crime types

A sound assessment weighs several factors, each of which can apply to more than one crime type. They are judged together.

  • Customers. Who they are, including higher-risk types and complex ownership.
  • Products and services. Whether they favor anonymity or fast movement of funds.
  • Geography. Exposure to high-risk and sanctioned countries.
  • Channels. Whether business is done face to face or remotely.
  • Delivery and third parties. The agents and partners the firm relies on.

Do this: weigh the geographic side of your exposure with our Country Risk Checker.

Screen a customer across financial crime risks

Run one search across sanctions, PEP, and adverse media data to feed real signals into your assessment.

Try Combined AML Screening →

How to conduct one

The method mirrors an AML risk assessment, applied across a wider set of crimes. It moves from raw exposure to a considered rating.

  1. Identify inherent risk. List the financial crime risks the firm faces before controls.
  2. Assess controls. Judge how well existing controls reduce each risk.
  3. Calculate residual risk. Work out what remains after controls.
  4. Prioritize and act. Focus attention where residual risk is highest.
  5. Document it. Record the risks, ratings, reasoning, and review date.
Worth knowing. The advantage of one financial crime assessment over separate ones is that it shows how risks connect. Fraud and money laundering, for example, are often the same case seen from two ends. A single assessment catches that link, where two separate ones each see only half.

How often to refresh it

A financial crime risk assessment goes stale as the business changes. It should be refreshed on a schedule and whenever something material shifts.

Most firms review it at least once a year. A new product, a new market, a new customer segment, a regulatory change, or a lesson from an incident should all trigger an update outside the normal cycle.

A short note in the assessment recording when it was last reviewed, and when it is next due, keeps this on track and shows an examiner the document is current.

Common mistakes

Financial crime assessments fail in familiar ways. Avoiding these keeps the assessment useful and defensible.

  • Treating it as AML only. Covering laundering but ignoring fraud, sanctions, or bribery.
  • Set and forget. An assessment that is never updated stops matching the firm.
  • Scoring without reasoning. A rating with no written logic does not satisfy an examiner.
  • No action. An assessment that does not change what the firm does is just paperwork.

Check a country’s financial crime risk

Look up a country against corruption and financial crime data to weigh exposure across your markets.

Try the Country Risk Checker →

Frequently asked questions

What is a financial crime risk assessment?

A financial crime risk assessment is a firm-wide analysis of exposure across every type of financial crime, including money laundering, sanctions, fraud, and bribery. It maps the threats a business faces, rates how serious each is, and sets how strong the controls need to be. It is the foundation of a financial crime compliance function.

What is the difference between a financial crime risk assessment and an AML risk assessment?

An AML risk assessment looks only at money laundering, while a financial crime risk assessment is broader, covering money laundering plus sanctions, fraud, bribery, and terrorist financing. The two share the same method, but differ in scope. In many firms, the AML assessment is one part of the wider financial crime assessment.

What does a financial crime risk assessment cover?

It covers money laundering, sanctions, fraud, bribery and corruption, and terrorist financing. Each area has its own risks, but they are judged together in one view. Assessing them together, rather than in isolation, helps a firm see how the crimes overlap and reinforce one another, which separate assessments can miss.

Why do firms need a financial crime risk assessment?

A firm needs one because it justifies the whole compliance function and focuses effort where risk is highest. Without it, controls are set on instinct rather than evidence. Regulators treat a weak assessment as a serious gap, since it usually means controls are not aligned with the firm’s real financial crime risk.

How do you conduct a financial crime risk assessment?

Identify inherent risk, the threats before controls, across all crime types. Assess how well existing controls reduce each risk. Calculate residual risk, what remains after controls. Prioritize attention where residual risk is highest, then act. Finally, document the risks, ratings, reasoning, and review date so the assessment can be defended.

What risk factors does it consider?

It considers customers, including higher-risk types and complex ownership, products and services and whether they favor anonymity, geography and exposure to high-risk countries, delivery channels such as remote onboarding, and third parties such as agents and partners. Each factor can apply to more than one crime type, and they are weighed together.

How often should a financial crime risk assessment be updated?

Most firms review it at least once a year, and update it whenever something material changes, such as a new product, a new market, a new customer segment, or a regulatory change. An assessment that still describes last year’s business is a common examination finding, so keeping it current matters.

What is inherent risk in a financial crime risk assessment?

Inherent risk is the financial crime threat a firm faces before any controls are applied, based on factors such as its customers, products, and geographies. Subtracting the effect of controls from inherent risk gives residual risk, the risk that remains. Residual risk is where a firm should focus its attention and resources.

Who is responsible for the financial crime risk assessment?

Senior management owns the financial crime risk assessment, and the compliance function, often led by a chief compliance officer, prepares and maintains it. It must be documented, kept current, and available to regulators. Because it justifies the entire financial crime function, responsibility sits at a senior level.

What is the difference between a financial crime risk assessment and financial crime compliance?

A financial crime risk assessment is the analysis that identifies and rates a firm’s financial crime risk. Financial crime compliance is the wider function that manages that risk, including screening, monitoring, reporting, and investigations. The assessment is the foundation, and the compliance function is what acts on its findings.

Can one assessment cover both AML and other crimes?

Yes, and many firms prefer it. A single financial crime risk assessment can cover money laundering, sanctions, fraud, and bribery together, with the AML view nested inside it. This shows how the risks connect, such as the overlap between fraud and laundering, which separate assessments would each see only in part.

What are common mistakes in a financial crime risk assessment?

Common mistakes include treating it as AML only and ignoring fraud, sanctions, or bribery, never updating it so it drifts from the real business, scoring risks without written reasoning, and producing an assessment that does not change what the firm actually does. Each of these turns a useful control into paperwork.

Read more: our ultimate guides, whitepapers and templates

Related guides and resources to help you act on what you just read.

Last reviewed July 12, 2026 · 11 min read · Written for compliance and risk professionals · By the WhoWiki editorial team

Key takeaway: a financial crime risk assessment is the firm-wide view of risk across all financial crime, wider than an AML risk assessment that covers only money laundering.

Learn & stay current

A compliance reference that keeps up with the regulators

Plain-English explainers, country rules, and data you can cite, updated as the landscape moves.

Comparing tools before you commit?

See how WhoWiki lines up against the platforms you already know, and which free tools fit which job.

See how current your screening could be

Book a walkthrough with our team, or start with the tools today. No account needed to run your first check.