Skip to main content
Can We Actually Use NRA Findings in Our Program?International Bodies & Standards
5 min readFor AML Compliance Officers

Can We Actually Use NRA Findings in Our Program?

These questions started landing in my inbox about 20 minutes after FATF published its latest NRA guidance report. They came from compliance officers at regional banks, fintech BSA teams, and even a few MLROs at payment processors who'd been handed the national assessment by their board and told to "align the program."

The questions were practical, sometimes blunt, and always rooted in the same tension: your regulator expects you to demonstrate that your AML/CFT framework reflects national risk priorities, but most National Risk Assessments read like policy documents written for diplomats, not compliance teams trying to calibrate transaction monitoring rules or adjust customer risk ratings.

Here's what I've been telling them.

Why Focus on National Risk Assessments?

FATF Recommendation 1 requires countries to identify, assess, and understand their money laundering risks, then take action to mitigate them effectively. That obligation cascades down to you. When your regulator conducts an NRA, they're building the evidence base that will inform their supervisory priorities, enforcement actions, and expectations for your program.

If your country's NRA identifies trade-based money laundering as a high-risk threat and your institution processes significant import-export transactions but you've never tuned your monitoring rules to detect TBML typologies, you're sitting in a regulatory blind spot. The NRA isn't just a policy paper. It's a roadmap to where examiners will focus during your next review.

Extracting Useful Insights from a Lengthy NRA

Start with Section 2 of the FATF guidance, which outlines the structured approach countries should follow when assessing threats, vulnerabilities, and risks. Even if your national assessment doesn't mirror this structure perfectly, you can reverse-engineer what matters.

Look for three things:

Threat rankings. Which predicate offenses does the assessment flag as generating the most criminal proceeds in your jurisdiction? Fraud? Drug trafficking? Corruption? Those rankings should inform your scenarios for unusual activity. If your country identifies cybercrime proceeds as a top-tier threat and you're still running generic structuring rules without any digital wallet or P2P platform monitoring, you're misaligned.

Sector vulnerabilities. The NRA should identify which financial sectors or products are most exposed. If it calls out cash-intensive businesses, correspondent banking, or virtual asset service providers as high-vulnerability, and you operate in one of those spaces, your Customer Due Diligence thresholds and ongoing due diligence intervals need to reflect that heightened risk.

Geographic risks. Does the assessment highlight specific regions, cities, or cross-border corridors as high-risk? Use that intelligence to weight your customer risk ratings and name screening protocols accordingly.

If the NRA doesn't break these out clearly, request a meeting with your supervisor. They have access to the working-level data that fed the assessment, and most regulators would rather brief you proactively than cite you for ignoring publicly available risk intelligence.

Why Small Fintechs Should Care About NRAs

Yes, but you're reading it for different reasons than the central bank is.

The Vienna Convention and Palermo Convention established the international legal framework requiring countries to criminalize money laundering and implement preventive measures. Your national NRA translates those treaty obligations into context-specific risks. For a small fintech, that context might reveal that your regulator is increasingly concerned about money mules using payment apps, or that synthetic identity fraud is driving predicate offense volume in your market.

You don't need to absorb every chapter on macroeconomic factors or international cooperation mechanisms. Focus on the sections that describe ML methods, typologies, and sectoral vulnerabilities. Those sections will help you justify your risk appetite decisions and resource allocation when examiners ask why you staffed sanctions screening but not advanced transaction monitoring analytics.

Demonstrating Consideration of NRA Findings

Document it in three places:

Your enterprise-wide risk assessment should explicitly reference the NRA's conclusions and explain how your institution's risk profile intersects with national-level threats. If the NRA identifies real estate as high-risk but you don't serve that sector, say so. If it flags cash businesses and you onboard them, describe your enhanced due diligence procedures.

Your AML/CFT policies and procedures should cite the NRA when explaining why certain controls exist. For example: "Transaction monitoring Rule 47 detects rapid movement of funds through nested accounts, a typology identified in the 2024 National Risk Assessment as associated with trade-based money laundering schemes."

Your board reporting should include an annual reconciliation between NRA findings and program updates. This doesn't need to be elaborate, but examiners want to see that senior management is aware of national risk priorities and has made conscious decisions about how the institution responds.

Understanding "Political Commitment" in NRAs

Section 1 of the FATF guidance emphasizes that a successful NRA requires political commitment and an inclusive mechanism involving multiple stakeholders. For a country, that means coordinating across law enforcement, regulators, and the private sector.

For your institution, it translates to executive sponsorship. If your board treats AML/CFT as a compliance department problem rather than an enterprise risk, you won't get the budget, technology, or staffing to address the risks your NRA identifies. Use the national assessment to frame the conversation with senior management. When the NRA flags correspondent banking vulnerabilities and your CEO wants to expand international wire services, you've got an evidence-based document to support your request for enhanced screening tools.

Addressing Outdated NRAs

No, but you should document the gap.

FATF describes risk understanding as "an ongoing, dynamic process" that responds to changing environmental factors. If your country's NRA is stale, that doesn't exempt you from maintaining current risk intelligence. You'll need to supplement it with other sources: FinCEN advisories, Egmont Group typology reports, FATF mutual evaluation reports for your jurisdiction, and your own suspicious activity report trends.

In your enterprise risk assessment, note the publication date of the national NRA and describe how you've updated your understanding since then. Examiners won't penalize you for your government's delay, but they will cite you if you're relying on obsolete risk assumptions.

Accessing the FATF Guidance

The FATF published the full NRA guidance report on November 7, 2024. It draws on experiences from over 90 countries and includes three sections: NRA Preparation and Set-up, Assessing and Understanding Money Laundering Risks, and Post-NRA Actions. Download it directly from the FATF website.

If your regulator has published an NRA summary or sectoral guidance based on the national assessment, start there. It'll be more concise and often includes practical examples relevant to your market. Then work backward to the full FATF methodology when you need to understand the analytical framework behind the conclusions.

And if your country hasn't conducted an NRA yet, or hasn't published one, look at assessments from jurisdictions with similar risk profiles. The methodology is what matters, not the specific findings.

You Might Also Like