Horizon scanning
Horizon scanning is the ongoing practice of monitoring for emerging risks, regulatory changes and new typologies before they affect a firm’s compliance programme. It sits ahead of the periodic risk assessment, feeding it new inputs as the environment shifts. Firms that scan systematically catch new obligations before they become findings, rather than after.
Key takeaways
- Horizon scanning is ongoing external monitoring, not a one-off annual exercise.
- It feeds the periodic risk assessment rather than replacing it.
- Typical inputs: regulator publications, FATF statements on high-risk jurisdictions, enforcement actions, and new typologies from law enforcement and FIUs.
- Skipping it means a firm’s controls fall behind changes it should have seen coming.
- Ownership usually sits with compliance or the MLRO, reporting to senior management or the board.
- A documented horizon scanning log is something examiners commonly expect to see as evidence.
On this page
What horizon scanning means in practiceWhat a horizon scanning process actually watchesHorizon scanning vs the risk assessmentHow firms run it: sources, cadence, ownershipWhat happens when horizon scanning is skippedBuilding horizon scanning into governanceFAQsRead more
What horizon scanning means in practice
Horizon scanning is a continuous watch, not a one-off exercise. Compliance teams track regulator publications, enforcement outcomes, new typologies and geopolitical developments on a rolling basis, then assess what each one means for the firm’s own risk exposure.
The output is usually a log: a running record of what was spotted, when, and what action it triggered, whether that’s a policy update, a control change, or simply a note that no action is needed yet.
What a horizon scanning process actually watches
A useful scan covers several distinct sources at once. Regulator consultations and policy statements signal changes before they’re mandatory. Enforcement actions against other firms show where supervisors are actually focusing attention, which often differs from what’s written in guidance. FATF statements on high-risk jurisdictions shift geographic risk ratings. New typologies published by financial intelligence units and law enforcement reveal how criminal methods are evolving.
Horizon scanning vs the risk assessment
The two are related but distinct. A risk assessment is a structured, periodic exercise that produces a formal risk rating for the business. Horizon scanning is the ongoing input that keeps that assessment current between formal reviews, rather than letting it go stale for a year at a time.
A firm can have an excellent risk assessment on paper and still be caught off guard, if nothing is feeding it new information as the environment changes.
How firms run it: sources, cadence, ownership
Most programmes assign a named owner, usually within compliance or the MLRO’s team, to review sources on a set cadence, weekly or monthly is common, and log anything relevant. Larger firms sometimes split this by domain: sanctions, financial crime typologies, and data or technology regulation each get a separate scan.
Findings typically get triaged into three buckets: immediate action required, monitor for now, and no action needed, with the reasoning recorded in each case.
What happens when horizon scanning is skipped
Without it, a firm’s controls only change when something forces them to, usually a new law taking effect, an audit finding, or an enforcement action against a peer. That’s a reactive posture, and it shows up in examinations as a gap: a firm that can’t demonstrate it was aware of a relevant development ahead of time looks worse than one that spotted it late but flagged it early.
Building horizon scanning into governance
The strongest programmes report scanning outputs up to senior management or the board on a regular cycle, not just log them and move on. That creates a paper trail showing the firm was actively watching, and it gives leadership visibility into risks building before they become findings.
Stay ahead of emerging AML risk
See where regulatory and typology risk is shifting before it shows up in your controls.
Frequently asked questions
What is horizon scanning in compliance?
Horizon scanning is the ongoing practice of monitoring regulator publications, enforcement actions, and emerging typologies to catch relevant changes before they affect a firm’s compliance programme. It feeds the periodic risk assessment rather than replacing it.
How often should horizon scanning happen?
There’s no single mandated frequency, but most programmes review sources weekly or monthly and log findings continuously, rather than treating it as an annual task.
Who owns horizon scanning in a firm?
Ownership usually sits with compliance or the MLRO’s team, often reporting outputs up to senior management or the board on a regular cycle.
What’s the difference between horizon scanning and a risk assessment?
A risk assessment is a structured, periodic exercise producing a formal risk rating. Horizon scanning is the continuous input that keeps that assessment current between formal reviews.
What sources feed a horizon scanning process?
Typical sources include regulator consultations and policy statements, enforcement actions against other firms, FATF statements on high-risk jurisdictions, and new typologies published by financial intelligence units and law enforcement.
Read more: our ultimate guides, whitepapers and templates
Related guides and resources to help you act on what you just read.
Last reviewed July 19, 2026 · 5 min read · Written for compliance and risk professionals · By the WhoWiki editorial team
Key takeaway: Horizon scanning is the ongoing practice of monitoring for emerging risks, regulatory changes and new typologies before they affect a firm’s compliance programme. It sits ahead of the periodic risk assessment, feeding it new inputs as the environment shifts. Firms that scan systematically catch new obligations before they become findings, rather than after.