AML Agent Blog
How to Perform an AMLR Business-Wide Risk Assessment: AMLA Guidelines, Methodology and Example
A practical guide to AMLR business-wide risk assessments, covering AMLA’s four draft minimum requirements, a six-step methodology, worked example, evidence checklist and common mistakes.
What is an AMLR business-wide risk assessment?
AMLA's four minimum requirements

1. Business and operational overview
Start with a concise description of how the organisation actually operates. Cover its legal and group structure, customer base, products and services, delivery channels, geographical exposure, AML/CFT organisation, outsourcing and use of new or emerging technologies.2. Inherent-risk assessment
| Risk dimension | Practical question |
|---|---|
| Customers | Which customer types, ownership structures, occupations or behaviours increase or reduce exposure? |
| Products, services and transactions | Could a service conceal ownership, move value rapidly or facilitate unusually complex activity? |
| Delivery channels | Is the relationship remote, intermediated, outsourced or reliant on new technology? |
| Geography | Where are customers, beneficial owners, counterparties and transactions located? |
| Targeted financial sanctions | How could sanctions be missed, circumvented or evaded through the organisation’s activities? |
Use both quantitative data, such as customer counts, transaction volumes and geographic concentrations, and qualitative evidence such as typologies, regulatory findings and expert judgement. If factors are weighted, document why one factor carries more weight than another. Avoid a model in which one data point automatically determines the entire result without a reasoned explanation.
AMLA's draft allows targeted-financial-sanctions exposure to be incorporated into the broader assessment or addressed through a separate, complementary risk assessment. Either way, the relevant risks should be connected to the organisation’s activities and controls.
3. Control-quality assessment
- Design: Is the control capable of addressing the identified risk?
- Implementation: Is the control operating effectively in practice?
4. Residual-risk assessment
A practical six-step methodology
- Define scope and ownership. Confirm the entities, branches, business lines and assessment period covered. Assign the compliance officer and management approvers.
- Build the evidence base. Gather internal data and current external sources. Article 10 points to AMLR risk variables, EU and national risk assessments, relevant AMLA or Commission publications, competent-authority information and customer-base data.
- Set the methodology. Define rating levels, weighting, aggregation, evidence standards and escalation rules before scoring. AMLA’s draft does not prescribe a universal numerical formula.
- Assess inherent risks. Analyse customers, products and services, transactions, delivery channels, geography, emerging risks and targeted-financial-sanctions exposure.
- Assess controls and residual risk. Link risks to controls, test design and implementation, and explain the resulting residual-risk judgement.
- Approve, act and review. Obtain management approval, record remediation, communicate relevant findings and set event-driven and periodic review arrangements.
Illustrative BWRA example
| Stage | Illustrative conclusion |
|---|---|
| Inherent risk | High exposure from company-formation services, multi-layer ownership, remote delivery and customers or beneficial owners connected with higher-risk jurisdictions. |
| Controls | CDD and beneficial-ownership procedures are appropriately designed, but sample testing identifies stale ownership evidence and inconsistent escalation of complex structures. |
| Residual risk | High for complex cross-border formations and medium for the wider customer base. Strong controls reduce exposure but do not remove the underlying risk. |
| Actions | Introduce event-driven ownership refreshes, strengthen escalation criteria, perform targeted file remediation and report progress to management. |
This example is deliberately qualitative. It illustrates the reasoning chain expected by the draft Guidelines; it is not an AMLA-prescribed scoring model.
What evidence should you retain?
- The approved methodology, assumptions and reasons for weightings.
- A dated inventory of official, internal and credible external sources.
- Underlying customer, product, transaction, channel and geography data.
- The risk-and-control mapping and control-testing evidence.
- Management approval, challenge and decisions.
- A remediation log with actions, owners, deadlines and status.
- Review triggers, previous versions and a clear change history.
Common mistakes to avoid
- Treating the BWRA as a generic template rather than an entity-specific assessment.
- Confusing inherent risk with residual risk.
- Giving controls credit without evidence that they operate effectively.
- Using unexplained scores or weightings that produce false precision.
- Ignoring internal evidence such as STR experience, audit findings and supervisory feedback.
- Completing the assessment without converting findings into owned remediation.