Horizon scanning is the ongoing practice of monitoring for emerging risks, regulatory changes and new typologies before they affect a firm’s compliance programme. It sits ahead of the periodic risk assessment, feeding it new inputs as the environment shifts. Firms that scan systematically catch new obligations before they become findings, rather than after.
Key takeaways
On this page
What horizon scanning means in practiceWhat a horizon scanning process actually watchesHorizon scanning vs the risk assessmentHow firms run it: sources, cadence, ownershipWhat happens when horizon scanning is skippedBuilding horizon scanning into governanceFAQsRead more
Horizon scanning is a continuous watch, not a one-off exercise. Compliance teams track regulator publications, enforcement outcomes, new typologies and geopolitical developments on a rolling basis, then assess what each one means for the firm’s own risk exposure.
The output is usually a log: a running record of what was spotted, when, and what action it triggered, whether that’s a policy update, a control change, or simply a note that no action is needed yet.
A useful scan covers several distinct sources at once. Regulator consultations and policy statements signal changes before they’re mandatory. Enforcement actions against other firms show where supervisors are actually focusing attention, which often differs from what’s written in guidance. FATF statements on high-risk jurisdictions shift geographic risk ratings. New typologies published by financial intelligence units and law enforcement reveal how criminal methods are evolving.
The two are related but distinct. A risk assessment is a structured, periodic exercise that produces a formal risk rating for the business. Horizon scanning is the ongoing input that keeps that assessment current between formal reviews, rather than letting it go stale for a year at a time.
A firm can have an excellent risk assessment on paper and still be caught off guard, if nothing is feeding it new information as the environment changes.
Most programmes assign a named owner, usually within compliance or the MLRO’s team, to review sources on a set cadence, weekly or monthly is common, and log anything relevant. Larger firms sometimes split this by domain: sanctions, financial crime typologies, and data or technology regulation each get a separate scan.
Findings typically get triaged into three buckets: immediate action required, monitor for now, and no action needed, with the reasoning recorded in each case.
Without it, a firm’s controls only change when something forces them to, usually a new law taking effect, an audit finding, or an enforcement action against a peer. That’s a reactive posture, and it shows up in examinations as a gap: a firm that can’t demonstrate it was aware of a relevant development ahead of time looks worse than one that spotted it late but flagged it early.
The strongest programmes report scanning outputs up to senior management or the board on a regular cycle, not just log them and move on. That creates a paper trail showing the firm was actively watching, and it gives leadership visibility into risks building before they become findings.
Stay ahead of emerging AML risk
See where regulatory and typology risk is shifting before it shows up in your controls.
Horizon scanning is the ongoing practice of monitoring regulator publications, enforcement actions, and emerging typologies to catch relevant changes before they affect a firm’s compliance programme. It feeds the periodic risk assessment rather than replacing it.
There’s no single mandated frequency, but most programmes review sources weekly or monthly and log findings continuously, rather than treating it as an annual task.
Ownership usually sits with compliance or the MLRO’s team, often reporting outputs up to senior management or the board on a regular cycle.
A risk assessment is a structured, periodic exercise producing a formal risk rating. Horizon scanning is the continuous input that keeps that assessment current between formal reviews.
Typical sources include regulator consultations and policy statements, enforcement actions against other firms, FATF statements on high-risk jurisdictions, and new typologies published by financial intelligence units and law enforcement.
Related guides and resources to help you act on what you just read.
Last reviewed July 19, 2026 · 5 min read · Written for compliance and risk professionals · By the WhoWiki editorial team
Key takeaway: Horizon scanning is the ongoing practice of monitoring for emerging risks, regulatory changes and new typologies before they affect a firm’s compliance programme. It sits ahead of the periodic risk assessment, feeding it new inputs as the environment shifts. Firms that scan systematically catch new obligations before they become findings, rather than after.
Check any name
Sanctions Screening PEP Check OFAC / SDN Search Adverse Media Watchlist Check Country Risk Crypto Sanctions All screening →Confirm any business
Company Lookup LEI Lookup VAT Validator EIN Lookup IBAN Validator SWIFT / BIC Domain Checker All verification →Score & generate
AML Risk Assessment Customer Risk Rating CDD vs EDD UBO Calculator AML Policy Generator SAR / STR Template All calculators →For your sector & stage
Accountants Law Firms Estate Agents Payments & Fintech For Startups For Developers Comparisons →Learn & cite
Glossary Country Guides Blog & Regulations Statistics Sanctioned Countries Data Sources Templates FAQAbout WhoWiki
About How It Works Pricing Developers / API API Docs Trust & Security Careers ContactPlain-English compliance updates and new tools. No spam, unsubscribe anytime.