An AML risk assessment that makes decisions
An inspector can open with one question: name a client whose due diligence level changed after your last risk assessment update. If the honest answer is none, the assessment describes risk and steers nothing, and every other document in the file gets read in that light. A business-wide risk assessment earns its keep in decisions: who you onboard, what you verify, when you escalate, which business you decline.
Three ways an assessment goes dead
The annual matrix for the audit file. Someone refreshes the colours once a year, the management board approves the document in five minutes, and nothing downstream moves. The document exists to be shown, and that is all it does.
Scores without data. Geography scores three, products score two, and nobody can point to the transactions, corridors or client segments behind the numbers. When a score has no source, every argument about it turns into an argument about opinions, and the loudest opinion wins.
The missing wire to onboarding. The assessment rates a corridor high risk while onboarding keeps accepting clients from it on standard due diligence, because the two systems were built by different teams in different years. The gap shows from outside too. Picture the email from your partner bank: the correspondent team asks for the business-wide risk assessment and for evidence that it drives customer due diligence. A matrix with last year’s date answers the first request and fails the second.
Wire the assessment into decisions
Three connections make it steer. Scores map to measures: a client or product in the top band triggers enhanced due diligence, and the mapping is written down, so analysts stop negotiating it case by case. Thresholds trigger escalation: when exposure in a rated segment crosses a set level, the MLRO signs off, and the risk appetite statement says in numbers what the firm does not open, what it caps and what it watches. Events reopen the assessment: a serious incident, a new product or a new corridor reopens the affected part within a defined number of days, so the annual cycle confirms a picture the firm already knows.
Data closes the loop. Every risk factor gets a named owner and a named source: transaction data, alert statistics, refusal rates, incident reports. An assessment built this way survives questioning, because each rating has an answer attached.
What the AMLR changes, and when
The AMLR, Regulation (EU) 2024/1624, applies from 10 July 2027 and will bind obliged entities directly across the EU. AMLA, the new authority seated in Frankfurt, is consulting on draft regulatory technical standards during 2026, including customer due diligence standards under Article 28(1), with a consultation paper dated 9 February 2026. These are drafts and may change; read them for direction and hold off rebuilding your forms around them. From 2028, AMLA takes over direct supervision of selected obliged entities.
Less than a year remains to 10 July 2027: one full review cycle. Run this year’s assessment as a rehearsal, built on data and wired to decisions, and it becomes the baseline you defend under the new rulebook.
What we recommend now
Five steps fit into the next two weeks.
- Mark every rating in the current assessment that lacks a named data source. That list is work package one.
- Pull ten recent onboardings and compare the due diligence applied with what the assessment implies. Each mismatch is a broken wire or a wrong score; decide which, in writing.
- Write the one-page mapping from score band to due diligence level to monitoring intensity, approved by the MLRO.
- Define three out-of-cycle triggers, for example an incident above a set severity, a new product, a new corridor, each with a deadline in days.
- Put one person on the AMLA consultations, with a standing note on every summary: draft, may change.
Sources: Regulation (EU) 2024/1624 (AMLR), EUR-Lex · AMLA public consultations