AML Agent Blog

How to Perform an AMLR Business-Wide Risk Assessment: AMLA Guidelines, Methodology and Example

A practical guide to AMLR business-wide risk assessments, covering AMLA’s four draft minimum requirements, a six-step methodology, worked example, evidence checklist and common mistakes.

By AML Agent
AMLRBusiness-Wide Risk AssessmentEU AML ComplianceAMLA Guidelines
In brief: An AMLR business-wide risk assessment should explain the risks your organisation faces before controls, assess how well those controls work, determine the risks that remain and turn the results into prioritised action. AMLA's draft Guidelines organise this into four minimum requirements: a business overview, inherent-risk assessment, control-quality assessment and residual-risk assessment.

Regulatory status: This guide reflects Article 10 of Regulation (EU) 2024/1624 (AMLR) and AMLA's draft Business-Wide Risk Assessment Guidelines as reviewed on 26 July 2026. The consultation closed on 15 July 2026 and AMLA indicated that final Guidelines are expected in Q4 2026. The draft may therefore change.

What is an AMLR business-wide risk assessment?

A business-wide risk assessment, or BWRA, is the documented assessment of the money laundering and terrorist financing risks to which an obliged entity is exposed across its business. Under AMLR, it must also address risks relating to the non-implementation and evasion of targeted financial sanctions.

The BWRA is not the same as an individual customer risk assessment. Customer assessments should feed into the BWRA, while the BWRA should inform customer-risk methodology and the level of due diligence applied. One cannot replace the other.

Article 10 requires a proportionate assessment that is documented, kept up to date, regularly reviewed and made available to supervisors on request. It must be drawn up by the compliance officer, approved by the management body in its management function and, where one exists, communicated to the management body in its supervisory function.

AMLA's four minimum requirements


AMLA's four draft minimum requirements for an AMLR business-wide risk assessment.
AMLA's four draft minimum requirements for an AMLR business-wide risk assessment.

1. Business and operational overview

Start with a concise description of how the organisation actually operates. Cover its legal and group structure, customer base, products and services, delivery channels, geographical exposure, AML/CFT organisation, outsourcing and use of new or emerging technologies.

This overview establishes the scope of the assessment and helps determine how detailed the methodology needs to be.

2. Inherent-risk assessment


Risk dimensionPractical question
CustomersWhich customer types, ownership structures, occupations or behaviours increase or reduce exposure?
Products, services and transactionsCould a service conceal ownership, move value rapidly or facilitate unusually complex activity?
Delivery channelsIs the relationship remote, intermediated, outsourced or reliant on new technology?
GeographyWhere are customers, beneficial owners, counterparties and transactions located?
Targeted financial sanctions How could sanctions be missed, circumvented or evaded through the organisation’s activities?

Use both quantitative data, such as customer counts, transaction volumes and geographic concentrations, and qualitative evidence such as typologies, regulatory findings and expert judgement. If factors are weighted, document why one factor carries more weight than another. Avoid a model in which one data point automatically determines the entire result without a reasoned explanation.

AMLA's draft allows targeted-financial-sanctions exposure to be incorporated into the broader assessment or addressed through a separate, complementary risk assessment. Either way, the relevant risks should be connected to the organisation’s activities and controls.


3. Control-quality assessment

Map each material inherent risk to the controls intended to mitigate it. Then assess both:
  • Design: Is the control capable of addressing the identified risk?
  • Implementation: Is the control operating effectively in practice?
Support conclusions with evidence. Useful indicators include compliance testing, file reviews, alert or case-quality testing, internal and external audit findings, incidents, management information and supervisory actions. A policy’s existence alone does not demonstrate that the control works.

4. Residual-risk assessment

Residual risk is the risk remaining after controls are considered. Determine residual risk for each material risk area and then reach an overall entity-level conclusion. AMLA’s draft cautions that inherently high-risk factors cannot necessarily be reduced to low risk simply because controls exist.

The outcome should identify unacceptable or insufficiently controlled exposure, remediation priorities, owners and target dates. It should also inform resource allocation and updates to policies, procedures, systems and controls.

A practical six-step methodology

  1. Define scope and ownership. Confirm the entities, branches, business lines and assessment period covered. Assign the compliance officer and management approvers.
  2. Build the evidence base. Gather internal data and current external sources. Article 10 points to AMLR risk variables, EU and national risk assessments, relevant AMLA or Commission publications, competent-authority information and customer-base data.
  3. Set the methodology. Define rating levels, weighting, aggregation, evidence standards and escalation rules before scoring. AMLA’s draft does not prescribe a universal numerical formula.
  4. Assess inherent risks. Analyse customers, products and services, transactions, delivery channels, geography, emerging risks and targeted-financial-sanctions exposure.
  5. Assess controls and residual risk. Link risks to controls, test design and implementation, and explain the resulting residual-risk judgement.
  6. Approve, act and review. Obtain management approval, record remediation, communicate relevant findings and set event-driven and periodic review arrangements.

Illustrative BWRA example

Consider an EU trust and company service provider that forms companies for a cross-border customer base and onboards many customers remotely.

StageIllustrative conclusion
Inherent riskHigh exposure from company-formation services, multi-layer ownership, remote delivery and customers or beneficial owners connected with higher-risk jurisdictions.
Controls CDD and beneficial-ownership procedures are appropriately designed, but sample testing identifies stale ownership evidence and inconsistent escalation of complex structures.
Residual riskHigh for complex cross-border formations and medium for the wider customer base. Strong controls reduce exposure but do not remove the underlying risk.
Actions Introduce event-driven ownership refreshes, strengthen escalation criteria, perform targeted file remediation and report progress to management.

This example is deliberately qualitative. It illustrates the reasoning chain expected by the draft Guidelines; it is not an AMLA-prescribed scoring model.

What evidence should you retain?

  • The approved methodology, assumptions and reasons for weightings.
  • A dated inventory of official, internal and credible external sources.
  • Underlying customer, product, transaction, channel and geography data.
  • The risk-and-control mapping and control-testing evidence.
  • Management approval, challenge and decisions.
  • A remediation log with actions, owners, deadlines and status.
  • Review triggers, previous versions and a clear change history.

Common mistakes to avoid

  • Treating the BWRA as a generic template rather than an entity-specific assessment.
  • Confusing inherent risk with residual risk.
  • Giving controls credit without evidence that they operate effectively.
  • Using unexplained scores or weightings that produce false precision.
  • Ignoring internal evidence such as STR experience, audit findings and supervisory feedback.
  • Completing the assessment without converting findings into owned remediation.

Turning the assessment into a working document

A useful BWRA should be short enough for management to understand, detailed enough for compliance teams to operate and sufficiently evidenced for supervisory review. The methodology and conclusions matter more than the number of pages.

If you are starting from a blank page, the AML Agent EU AML Document Generator can create an editable business-wide risk assessment draft based on your entity profile. The output remains a professional working draft: its risk data, methodology, scoring, control evidence and conclusions must be reviewed and validated for the specific obliged entity.

Last reviewed: 26 July 2026.

This article provides general regulatory information and is not legal advice. Obliged entities should consider the final AMLA Guidelines, applicable national requirements and supervisory expectations.