An ML/TF risk assessment is the document that justifies every other decision in your program. Get it wrong and a reasonable program looks arbitrary; get it right and the rest of the work follows from it.
The four risk factors
- Customer types - who you act for, including any politically exposed persons, trusts, or customers you cannot meet face to face.
- Products and services - which of your services could be used to move or disguise value, and how.
- Delivery channels - remote onboarding and intermediated relationships carry different risk to in-person work.
- Foreign jurisdictions - where your customers and their funds are connected, and what that implies.
How the tool works
Score each factor, record the reasoning, and get an overall risk rating with the workings visible. The point is not the number: it is being able to show, later, why you landed on it.
The rating then drives the rest of your program - which customers need enhanced due diligence, how often you review, and what your monitoring has to look for.
Keeping it current
A risk assessment is not a document you write once. New services, new customer types and changes in the regulatory picture all move it. Reviews are dated and kept, so the history of your thinking is part of the record.
Frequently asked questions
What is an ML/TF risk assessment?
An assessment of the money-laundering and terrorism-financing risk your business faces, across customer types, services, delivery channels and foreign jurisdictions. Your AML/CTF program has to be proportionate to it.
How often should it be reviewed?
Whenever something material changes - a new service, a new kind of customer, a new jurisdiction - and on a regular cycle in between. Reviews are dated and retained.
Is this legal advice?
No. It is a tool for producing and maintaining your own assessment. It does not replace advice from a qualified adviser.