Home/Insights/AML/CFT Risk Assessment
Financial Crime

AML/CFT Risk Assessment

The enterprise-wide risk assessment that every CBE and FRA supervised institution must be able to produce on demand — how inherent risk, control effectiveness and residual risk actually connect.

Typical duration
6–10 weeks
Legal basis
AML Law 80/2002
Standard
FATF Recommendation 1
Review cycle
Annual, or on material change
0Risk factor categories assessed
0FATF Recommendations mapped
0Enterprise-wide assessment, refreshed annually

How residual risk is derived

Inherent risk is what your business model exposes you to before any control. Residual risk is what remains after controls are tested for effectiveness — not after they are merely documented.

Inherent risk

Customers, products, channels, geographies, transactions

Control effectiveness

Design tested, then operating effectiveness tested

Residual risk

What the board must accept, mitigate or avoid

Scoring the risk

Each risk factor is scored on likelihood and impact, then plotted. The output is not a number for its own sake — it drives where enhanced due diligence and monitoring resources are directed.

5
10
15
20
25
4
8
12
16
20
3
6
9
12
15
2
4
6
8
10
1
2
3
4
5
Low impactHigh impact

Vertical axis: likelihood. Horizontal axis: impact.

The five risk factor categories

FATF Recommendation 1 requires the assessment to cover each of these dimensions and to be evidenced, not asserted.

01

Customer risk

PEPs, complex ownership structures, cash-intensive businesses, non-resident customers, and customers with no clear economic rationale.

Customer risk rating model
02

Product & service risk

Products offering anonymity, cross-border capability, rapid movement of value, or third-party funding.

Product risk matrix
03

Channel risk

Non-face-to-face onboarding, agent networks, introduced business and digital-only relationships.

Channel assessment
04

Geographic risk

FATF grey and black lists, sanctions exposure, jurisdictions with weak AML regimes and high corruption indices.

Country risk register
05

Transaction risk

Value, velocity, structuring patterns, dormancy followed by activity, and round-tripping behaviour.

Monitoring rule set

What supervisors ask to see

When an inspection opens, these are the documents requested first.

Need this assessed for your organisation?

Every engagement is led by a senior practitioner and closes with documented, regulator-ready evidence of what was built.

Talk to an Expert All Insights
PreviousESG Strategy & Disclosure NextKYC & Customer Onboarding