The enterprise-wide risk assessment that every CBE and FRA supervised institution must be able to produce on demand — how inherent risk, control effectiveness and residual risk actually connect.
Inherent risk is what your business model exposes you to before any control. Residual risk is what remains after controls are tested for effectiveness — not after they are merely documented.
Customers, products, channels, geographies, transactions
Design tested, then operating effectiveness tested
What the board must accept, mitigate or avoid
Each risk factor is scored on likelihood and impact, then plotted. The output is not a number for its own sake — it drives where enhanced due diligence and monitoring resources are directed.
Vertical axis: likelihood. Horizontal axis: impact.
FATF Recommendation 1 requires the assessment to cover each of these dimensions and to be evidenced, not asserted.
PEPs, complex ownership structures, cash-intensive businesses, non-resident customers, and customers with no clear economic rationale.
Products offering anonymity, cross-border capability, rapid movement of value, or third-party funding.
Non-face-to-face onboarding, agent networks, introduced business and digital-only relationships.
FATF grey and black lists, sanctions exposure, jurisdictions with weak AML regimes and high corruption indices.
Value, velocity, structuring patterns, dormancy followed by activity, and round-tripping behaviour.
When an inspection opens, these are the documents requested first.
Every engagement is led by a senior practitioner and closes with documented, regulator-ready evidence of what was built.