Risk Assessment

A risk assessment is the structured judgment an institution makes about where its exposure actually sits — which customers, products, channels and jurisdictions carry the most financial crime risk, and therefore where controls should be heaviest. It is the document every other AML decision is supposed to derive from.

Two levels Enterprise-wide, and per-customer
Enterprise-wide assessment The institution’s overall exposure across its business
Customer-level assessment A rating for each relationship, driving due diligence depth
Standard dimensions Customer types, products and services, delivery channels, geographies
Method Inherent risk, minus control effectiveness, equals residual risk
Regulatory basis The risk-based approach in FATF Recommendation 1
Refresh cadence At least annually, and on material change
What examiners check That controls actually follow from the assessment
Most common failure An assessment that exists but does not drive anything

How it works

The mechanics are unremarkable and the discipline is where institutions differ.

Inherent risk is the exposure a business line carries before any controls — a correspondent banking relationship in a high-risk jurisdiction is inherently riskier than a domestic savings account, whatever either institution does about it. Control effectiveness is an honest assessment of how well existing controls mitigate that. What remains is residual risk, and residual risk is what the institution has actually accepted.

The four standard dimensions — customers, products, channels, geographies — are assessed separately because risk concentrates differently in each. A firm may have low-risk customers using a high-risk product, or ordinary products delivered through a channel that makes verification hard.

The failure that matters is not a poor assessment. It is a good one that nothing follows from. An institution whose assessment identifies remote onboarding as its highest-risk channel, and which then applies identical verification to remote and in-branch customers, has produced a document rather than a control. Examiners look for exactly that disconnect, and it is among the most common findings in this area.

Customer-level assessment inherits from the enterprise one. The factors that make a customer high-risk are the factors the enterprise assessment identified, weighted the way it weighted them — which is why customer risk profiling methodologies should be traceable back to it and frequently are not.

Why it matters for identity verification

A risk assessment is where verification thresholds should come from, and in most institutions they come from somewhere else entirely.

Verification is not one setting. It is a set of decisions — which document types to accept, what biometric match threshold to require, when to escalate to a step-up check, what to send to manual review. Each of those should follow from an assessed risk. In practice they are often inherited from a vendor default, or set once during implementation and never revisited against the assessment that supposedly governs them.

The channel dimension is the sharpest example. Nearly every risk assessment rates remote onboarding above in-person, correctly. Comparatively few institutions then apply materially different verification depth to the two, which means the assessment identifies a risk the controls do not address.

Making that connection real requires verification that can actually be configured by risk rather than set globally. Thresholds that vary by segment, with the rationale recorded is what turns an assessment into a control, and Microblink’s KYC and AML workflow is built so those settings are explicit rather than buried.

Enterprise vs customer risk assessment

  Enterprise-wide Customer-level
Subject The institution’s business One relationship
Output Where exposure concentrates A risk rating for that customer
Drives Control design, resourcing, policy Due diligence depth and monitoring intensity
Frequency Annually, and on material change At onboarding, then on trigger and cycle
Owner Compliance and the board Applied by the onboarding system
Relationship Sets the factors and weightings Applies them to an individual

What it can’t do

It cannot predict specific events. A risk assessment describes where exposure concentrates, not what will happen. Institutions with sound assessments still suffer incidents, and that is not by itself evidence the assessment was wrong.

It cannot be accurate about control effectiveness without testing. The residual risk figure depends on an honest view of how well controls work, and most institutions rate their own controls optimistically unless something has independently tested them.

It cannot survive without refresh. Business lines change, products launch, geographies open. An assessment more than a year old describes an institution that may no longer exist in that shape.

It cannot substitute for the controls it recommends. The most common finding is not a bad assessment but a good one with no operational consequence — identified risks that no control was ever built to address.

Frequently asked questions

What is the difference between inherent and residual risk?

Inherent risk is the exposure before controls are applied. Residual risk is what remains after them. The difference is control effectiveness, and residual risk is what the institution has actually chosen to accept.

How often should an AML risk assessment be updated?

At least annually, and whenever something material changes — a new product, a new market, a significant shift in customer base, or a regulatory change. An assessment that has not moved in several years is usually a sign it is not driving anything.

What is the difference between an enterprise risk assessment and customer risk profiling?

The enterprise assessment identifies where the institution’s exposure sits and sets the factors and weightings. Customer risk profiling applies those to individual relationships. The second should be traceable to the first, and frequently is not.

What do examiners look for in a risk assessment?

Whether controls actually follow from it. A well-written assessment with no operational consequence — identified risks that nothing was built to mitigate — is a more common finding than a poorly written one.

Related reading

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data
This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.