An AML risk assessment is a firm-wide analysis of where a business is exposed to money laundering. It rates risk across customers, products, geographies, and channels, then sets how strong each control needs to be. It is the foundation of the whole AML program.
Key takeaways
- An AML risk assessment shows a firm where its laundering risk is highest.
- It looks at customers, products, geographies, channels, and transactions.
- It is firm-wide, which is different from rating a single customer’s risk.
- The method is inherent risk, minus the effect of controls, equals residual risk.
- It underpins the risk-based approach and the wider program.
- A stale or missing assessment is one of the most common examination findings.
On this page
What it isWhy it mattersFirm-wide vs customerThe risk factorsHow to conduct oneScoring and methodHow often to refreshCommon mistakesFAQsRead more
2012
Year the FATF made risk assessment central to its standard
Source: FATF
$800B to $2T
Laundered worldwide each year the assessment targets
Source: UNODC
$3B
Paid by TD Bank in 2024 after control gaps
Source: US Department of Justice
What is an AML risk assessment?
An AML risk assessment is a structured look at where a firm could be used to launder money. It maps the threats the business faces and rates how serious each one is.
The result is a clear picture of risk, written down and ranked. That picture then decides how much effort each control deserves, from light checks on low-risk activity to deep scrutiny on high-risk activity.
It is the first thing a regulator asks to see, because everything else depends on it. Read more: the assessment gives shape to your AML compliance program.
Why an AML risk assessment matters
The assessment matters because it justifies the whole program. Without it, a firm cannot explain why its controls are set the way they are.
It also focuses effort where it counts. Resources are limited, so a firm that knows its real risks can put people and tools where the threat is highest rather than spreading them thin.
Regulators treat a weak assessment as a serious gap. In 2024, TD Bank agreed to about $3 billion in penalties after leaving whole transaction types outside its controls, a failure that a sound assessment should have surfaced (US Department of Justice, 2024).
Get an indicative AML risk rating
Answer a few questions about your customers, products, and markets to see where your money laundering risk is concentrated.
Firm-wide risk assessment vs customer risk rating
An AML risk assessment and a customer risk rating are related but different. One looks at the whole firm, the other at a single customer.
The firm-wide assessment sets the framework. It decides which customer types, products, and countries are risky. A customer risk rating then applies that framework to one person or business at onboarding.
| AML risk assessment | Customer risk rating | |
|---|---|---|
| Scope | The whole firm | A single customer |
| Purpose | Set the risk framework | Rate one relationship |
| Frequency | Periodic and on change | At onboarding and on review |
The two work together. A strong firm-wide assessment makes every customer rating more accurate.
The risk factors to assess
A sound assessment looks across several factors. Each can raise or lower the overall picture, and they interact.
- Customer risk. The types of customers served, including politically exposed persons and complex ownership.
- Product and service risk. Whether products favor anonymity or fast movement of funds.
- Geographic risk. Exposure to high-risk countries. Check with our Country Risk Checker.
- Channel risk. Whether onboarding is face to face or fully remote.
- Transaction risk. The size, speed, and pattern of expected activity.
Screen customers as you assess risk
Run one search across sanctions, PEP, and adverse media data to feed real signals into your assessment.
How to conduct an AML risk assessment
Conducting an assessment follows a repeatable method. It moves from raw exposure to a considered rating.
- Identify inherent risk. List the money laundering risks the firm faces before any controls.
- Assess your controls. Judge how well existing controls reduce each risk.
- Calculate residual risk. Work out the risk that remains after controls.
- Prioritize and act. Focus attention where residual risk is highest.
- Document everything. Record the risks, ratings, reasoning, and review date.
Use the tool: turn a single customer’s details into a risk level with our Customer Risk Calculator as you apply the framework.
Scoring and methodology
Most assessments use a simple equation at their core: inherent risk, reduced by the strength of controls, leaves residual risk. The scoring puts numbers or bands around that idea.
Firms usually rate each factor as low, medium, or high, then combine them into an overall picture. The bands should be defined, so that a high rating means the same thing across the firm.
- Inherent risk. The threat before controls, based on the factors above.
- Control effectiveness. How much the firm’s controls actually reduce that threat.
- Residual risk. What remains, which is where attention should go.
The method matters less than consistency. A rating scheme applied evenly across the firm is worth more than a complex model used loosely.
How often to refresh the assessment
An assessment goes stale as the business changes. It should be refreshed on a schedule and whenever something material shifts.
Most firms review it at least once a year. A new product, a new market, a new customer segment, or a regulatory change should all trigger an update outside the normal cycle.
A short note in the assessment recording when it was last reviewed and when it is next due keeps this on track. It also gives an examiner an instant read on whether the document is current. Common out-of-cycle triggers include:
- A new product, service, or delivery channel.
- Entry into a new market or country.
- A new customer segment, or a spike in a risky one.
- A regulatory change or a major enforcement case.
Common mistakes
Assessments fail in predictable ways. Avoiding these keeps the document useful and defensible.
- Set and forget. An assessment that is never updated stops matching the firm.
- Score without reasoning. A rating with no written logic does not satisfy an examiner.
- Ignoring controls. Rating inherent risk but never judging control strength misses the point.
- No action. An assessment that does not change what the firm does is just paperwork.
Turn customer details into a risk rating
Enter a few details about a customer and get an indicative money laundering risk level to guide your due diligence.
Frequently asked questions
What is an AML risk assessment?
An AML risk assessment is a firm-wide analysis of where a business is exposed to money laundering. It rates risk across customers, products, geographies, and channels, then sets how strong each control needs to be. It is the foundation of the AML program, because every other control is built on its findings.
Why is an AML risk assessment important?
It matters because it justifies the whole program and focuses effort where risk is highest. Without it, a firm cannot explain why its controls are set the way they are. Regulators treat a weak or missing assessment as a serious gap, since it usually means controls are not aligned with real risk.
What is the difference between an AML risk assessment and a customer risk rating?
An AML risk assessment looks at the whole firm and sets the risk framework, deciding which customers, products, and countries are risky. A customer risk rating applies that framework to a single customer at onboarding. The firm-wide assessment shapes every individual rating, so the two work together.
What factors go into an AML risk assessment?
The main factors are customer risk, product and service risk, geographic risk, channel risk, and transaction risk. Each can raise or lower the overall picture, and they interact. The skill is weighing them together and recording the reasoning, since an examiner cares more about the logic than the final score.
How do you conduct an AML risk assessment?
Identify inherent risk, the threats before controls. Assess how well existing controls reduce each risk. Calculate residual risk, what remains after controls. Prioritize attention where residual risk is highest, then act on it. Finally, document the risks, ratings, reasoning, and review date so the assessment can be defended.
What is inherent risk in an AML risk assessment?
Inherent risk is the money laundering threat a firm faces before any controls are applied. It is based on factors such as the customers served, the products offered, and the countries involved. Subtracting the effect of controls from inherent risk gives residual risk, which is where attention should focus.
What is residual risk?
Residual risk is the money laundering risk that remains after a firm’s controls have been taken into account. It is calculated as inherent risk reduced by the effectiveness of controls. Residual risk shows where a firm is still exposed, so it is the part of the assessment that should drive action and resources.
How often should an AML risk assessment be updated?
An AML risk assessment should be reviewed at least once a year for most firms, and updated whenever something material changes. Triggers include a new product, a new market, a new customer segment, or a regulatory change. An assessment that still describes last year’s business is a common examination finding.
Who is responsible for the AML risk assessment?
Senior management owns the AML risk assessment, and the compliance officer usually prepares and maintains it. It must be documented, kept current, and available to the regulator. Because the assessment justifies the entire program, responsibility for it sits at a senior level rather than with front-line staff alone.
What is an enterprise-wide risk assessment?
An enterprise-wide risk assessment is another name for a firm-wide AML risk assessment. It covers the whole business rather than a single customer or product line. It brings together the firm’s exposure across customers, products, geographies, and channels into one view that shapes the overall AML program.
How does an AML risk assessment relate to the risk-based approach?
The AML risk assessment is what makes the risk-based approach possible. The risk-based approach means matching controls to risk, and the assessment is where that risk is identified and rated. Every control in the program, from customer due diligence to monitoring, is set in proportion to what the assessment finds.
What tools help with an AML risk assessment?
Structured questionnaires and scoring models help turn judgment into a consistent rating across customers, products, and geographies. An indicative tool can give a starting point for the firm-wide view, and a customer risk calculator can apply the framework to individual relationships. The key is applying the method evenly and recording the reasoning.
Read more: our ultimate guides, whitepapers and templates
Related guides and resources to help you act on what you just read.
Last reviewed July 12, 2026 · 11 min read · Written for compliance and risk professionals · By the WhoWiki editorial team
Key takeaway: an AML risk assessment is the firm-wide analysis that shows where laundering risk is highest, and it is the foundation every other control is built on.