Business-Wide Risk Assessment
A Business-Wide Risk Assessment is an exercise in which a firm looks across its whole business to identify and understand where it is exposed to money laundering and related financial crime risks. It typically results in a documented view of those risks, which the firm then uses to decide how to manage and reduce them. It is a foundational part of taking a risk-based approach rather than a check that any specific customer or transaction is criminal.
A Business-Wide Risk Assessment (BWRA), sometimes referred to as an Enterprise-Wide Risk Assessment (EWRA), is the process and resulting documentation by which an obliged entity identifies, evaluates, and records the money laundering and associated financial crime risks arising across its business as a whole. It is generally regarded as a central element of the risk-based approach and, in many frameworks, serves as the foundation for setting risk appetite and designing proportionate mitigating controls. In the EU context it is being addressed through AMLA guidelines and the AML Regulation (AMLR), and in the UK it falls within the scope of firms' risk assessment obligations examined by the FCA; practitioners should note that specific content, format, and frequency requirements vary by jurisdiction and by the type of obliged entity, and exact obligations should be confirmed against the applicable regime. The BWRA is an entity-level assessment and is conceptually distinct from customer-level risk assessment, though the two are intended to inform one another; it is a risk management and governance tool used to detect, deter, and mitigate risk, and does not by itself establish or prove wrongdoing.
Why it matters
The Business-Wide Risk Assessment sits at the foundation of a risk-based approach to financial crime. Regulators and standard-setters generally treat it as the exercise from which everything else in an AML programme flows: without a clear, entity-level understanding of where a firm is exposed to money laundering and related risks, controls tend to be designed on assumption rather than evidence. AMLA has described the BWRA as a central element of the risk-based approach from an obliged entity's perspective, and industry commentary frames it as the cornerstone of a financial crime framework, central to identifying and quantifying risk, setting risk appetite, and designing proportionate mitigation.
Because the BWRA is meant to inform the design of controls, weaknesses in it can cascade through an entire programme. The FCA's published findings on firms' risk assessment processes and controls centre on how well firms identify, understand, and assess risk and then appropriately mitigate it, indicating that supervisors examine both the quality of the assessment and whether firms act on its conclusions. A BWRA that is out of date, generic, or disconnected from the firm's actual products, customers, and geographies can leave residual exposure unaddressed and is a common area of supervisory criticism.
It is important to keep the BWRA in its proper role. It is a risk management and governance tool used to detect, deter, and mitigate risk at the level of the business as a whole; it does not, by itself, establish or prove that any customer, transaction, or the firm has engaged in wrongdoing. Its value lies in producing a documented, defensible view of risk that guides proportionate decisions, not in serving as a test of criminality.
Who it's relevant to
Inside BWRA
Common questions
Answers to the questions practitioners most commonly ask about BWRA.