Skip to main content
Category: Risk Assessment

Business-Wide Risk Assessment

Also known as: BWRA, Enterprise-Wide Risk Assessment, EWRA
Simply put

A Business-Wide Risk Assessment is an exercise in which a firm looks across its whole business to identify and understand where it is exposed to money laundering and related financial crime risks. It typically results in a documented view of those risks, which the firm then uses to decide how to manage and reduce them. It is a foundational part of taking a risk-based approach rather than a check that any specific customer or transaction is criminal.

Formal definition

A Business-Wide Risk Assessment (BWRA), sometimes referred to as an Enterprise-Wide Risk Assessment (EWRA), is the process and resulting documentation by which an obliged entity identifies, evaluates, and records the money laundering and associated financial crime risks arising across its business as a whole. It is generally regarded as a central element of the risk-based approach and, in many frameworks, serves as the foundation for setting risk appetite and designing proportionate mitigating controls. In the EU context it is being addressed through AMLA guidelines and the AML Regulation (AMLR), and in the UK it falls within the scope of firms' risk assessment obligations examined by the FCA; practitioners should note that specific content, format, and frequency requirements vary by jurisdiction and by the type of obliged entity, and exact obligations should be confirmed against the applicable regime. The BWRA is an entity-level assessment and is conceptually distinct from customer-level risk assessment, though the two are intended to inform one another; it is a risk management and governance tool used to detect, deter, and mitigate risk, and does not by itself establish or prove wrongdoing.

Why it matters

The Business-Wide Risk Assessment sits at the foundation of a risk-based approach to financial crime. Regulators and standard-setters generally treat it as the exercise from which everything else in an AML programme flows: without a clear, entity-level understanding of where a firm is exposed to money laundering and related risks, controls tend to be designed on assumption rather than evidence. AMLA has described the BWRA as a central element of the risk-based approach from an obliged entity's perspective, and industry commentary frames it as the cornerstone of a financial crime framework, central to identifying and quantifying risk, setting risk appetite, and designing proportionate mitigation.

Because the BWRA is meant to inform the design of controls, weaknesses in it can cascade through an entire programme. The FCA's published findings on firms' risk assessment processes and controls centre on how well firms identify, understand, and assess risk and then appropriately mitigate it, indicating that supervisors examine both the quality of the assessment and whether firms act on its conclusions. A BWRA that is out of date, generic, or disconnected from the firm's actual products, customers, and geographies can leave residual exposure unaddressed and is a common area of supervisory criticism.

It is important to keep the BWRA in its proper role. It is a risk management and governance tool used to detect, deter, and mitigate risk at the level of the business as a whole; it does not, by itself, establish or prove that any customer, transaction, or the firm has engaged in wrongdoing. Its value lies in producing a documented, defensible view of risk that guides proportionate decisions, not in serving as a test of criminality.

Who it's relevant to

Compliance officers and MLROs
Those responsible for the AML programme generally own the BWRA and rely on it to justify how controls are calibrated. Because supervisors such as the FCA examine how firms identify, understand, assess, and mitigate risk, compliance leaders need the assessment to be current, evidence-based, and clearly linked to the controls it drives.
Senior management and boards
The BWRA is a governance tool used to set risk appetite at the level of the business as a whole. Senior management and boards use its documented output to understand the firm's overall exposure and to make proportionate decisions about how risk is managed, rather than to determine that any specific activity is criminal.
Obliged entities across sectors
AMLA frames the BWRA as a central element of the risk-based approach from an obliged entity's perspective. The exercise applies to obliged entities generally, but the precise content, format, and frequency expected depend on the type of entity and the applicable regime, so firms should confirm their obligations against the framework that governs them.
Financial intelligence analysts and investigators
Staff working at the customer and transaction level benefit from the BWRA because it establishes the enterprise-level context in which their work sits. The business-wide view and customer-level risk assessment are intended to inform one another, so patterns identified in investigations can feed back into the firm's overall understanding of its exposure.
Regulatory and audit functions
Supervisors, internal audit, and second-line assurance teams use the BWRA as a reference point for testing whether a firm's controls are proportionate to its stated risks. The FCA's findings on risk assessment processes highlight the assessment's role in demonstrating that a firm both understands its risks and mitigates them appropriately.

Inside BWRA

Risk Identification
The process of cataloguing the inherent money laundering and terrorist financing risks to which an obliged entity is exposed. This typically draws on established risk factor categories such as customer, product and service, transaction, delivery channel, and geographic risk, though the precise categorisation may vary by regime and by the nature of the business.
Customer Risk Factors
Consideration of the types of customers served and the risks they present, which may include categories such as politically exposed persons, complex ownership structures, or higher-risk business types. This component informs but is distinct from customer-level CDD; the business-wide assessment aggregates risk across the customer base rather than assessing any single relationship.
Product, Service and Transaction Risk Factors
Assessment of how the entity's products, services, and transaction types may be exploited for money laundering or terrorist financing, for example those enabling anonymity, rapid movement of funds, or high transaction values. Scope depends on the entity's actual offerings, so products not provided fall outside the assessment.
Delivery Channel Risk Factors
Evaluation of how products and services are distributed and how customers are onboarded, including non-face-to-face or intermediary-based channels, which may present differing levels of risk. This reflects how the relationship is established and maintained rather than the customer's identity itself.
Geographic Risk Factors
Consideration of the jurisdictions in which the entity operates or to which it is exposed through customers and transactions, taking into account factors such as jurisdictions identified as higher risk. What constitutes a higher-risk geography can differ across regimes and lists, and should be confirmed against applicable guidance.
Assessment and Rating Methodology
The documented approach used to weigh identified risk factors and arrive at an overall view of the entity's risk exposure. This is a compliance and governance exercise reflecting the entity's judgement, not a legal determination that any specific activity constitutes an offence.
Link to Controls and Mitigation
The connection between assessed inherent risk and the policies, controls, and procedures designed to detect, deter, and mitigate that risk, informing the residual risk view. These measures are intended to manage risk rather than guarantee prevention of financial crime.
Documentation, Review and Update
The recording of the assessment and its periodic review and updating to reflect changes in the business, its risk exposure, and the wider environment. In many jurisdictions this assessment is expected to be maintained and kept current, with specific expectations set by the applicable regime.

Common questions

Answers to the questions practitioners most commonly ask about BWRA.

Is a business-wide risk assessment the same as assessing the risk of individual customers?
No. A business-wide risk assessment (BWRA) evaluates the money laundering and terrorist financing risks facing the firm as a whole, across its customer base, products and services, delivery channels, and geographic exposure. It is distinct from customer risk assessment, which rates the risk posed by a specific customer relationship. The two are related: the BWRA typically informs the risk factors and rating methodology used at the customer level, but conducting customer due diligence does not, on its own, satisfy the obligation to maintain a firm-level assessment. In many jurisdictions both are separately required of obliged entities, so completing one does not discharge the other.
Once we complete a business-wide risk assessment, is it a one-time exercise that we can file away?
No. A BWRA is generally expected to be a living document that is reviewed and updated on a periodic basis and when material changes occur, for example, the launch of new products, entry into new markets, changes in the customer base, or shifts in the external threat environment reflected in national or supranational risk assessments. Treating it as a static, one-off document risks leaving the assessment out of date and misaligned with the firm's actual risk profile. The specific frequency and triggers for review may be set or influenced by the applicable regulations and supervisory expectations, which should be confirmed against the regime the firm operates under.
What risk factors should a business-wide risk assessment typically cover?
A BWRA generally considers risk across several dimensions, commonly including customer types, the products and services offered, delivery or distribution channels, and geographic exposure (both where the firm operates and where its customers and counterparties are located). Many frameworks encourage firms to consult relevant national risk assessments, supranational assessments where applicable, and typologies published by bodies such as the FATF as inputs. The precise categories and level of granularity expected can vary by regime and by the nature of the obliged entity, so firms should align their factors with the requirements applicable to them rather than assuming a single universal template.
How should the business-wide risk assessment connect to our AML policies, controls, and procedures?
The BWRA is typically the foundation of a risk-based approach: the risks it identifies should inform the design and calibration of the firm's policies, controls, and procedures, so that mitigating measures are proportionate to the risks identified. In practice this means the assessment feeds into areas such as customer due diligence standards, thresholds for enhanced measures, transaction monitoring scenarios, and resource allocation. These controls are measures intended to detect, deter, and mitigate risk rather than guarantees of prevention, and the linkage between the assessment and the controls should be demonstrable to supervisors.
Who should own and approve the business-wide risk assessment?
Responsibility for producing a BWRA often sits with the compliance or MLRO function, but accountability for the firm's overall AML/CFT framework generally rests with senior management and, where applicable, the board. Many regimes and supervisory expectations point toward senior management approval or sign-off of the assessment, reflecting the principle that risk management is a governance responsibility rather than solely a compliance-team task. The exact allocation of roles and approval requirements can differ by jurisdiction and by the size and structure of the firm, and should be confirmed against the applicable rules.
How much documentation is expected to support a business-wide risk assessment?
Firms are generally expected to be able to evidence how the assessment was conducted, what data and sources were used, how risks were rated, and how the conclusions link to the firm's controls. Documenting the methodology, the inputs considered, the rationale for risk ratings, and the dates and triggers of reviews helps demonstrate a defensible, risk-based approach to supervisors. The level of detail that is appropriate may depend on the size, nature, and complexity of the business, and specific record-keeping expectations should be confirmed against the regulations and supervisory guidance applicable to the firm.

Common misconceptions

A business-wide risk assessment is the same as customer-level due diligence.
They operate at different levels. The business-wide risk assessment evaluates the risks facing the entity as a whole across risk factor categories, whereas CDD and EDD assess and manage the risk of individual customer relationships. The business-wide assessment typically informs how the entity calibrates its customer-level measures, but the two are distinct exercises.
There is a single, globally uniform legal standard for how a business-wide risk assessment must be conducted.
Expectations derive from different source instruments and diverge across regimes. The FATF Recommendations set standards rather than binding law, while obligations may flow from instruments such as the EU AML framework, the US Bank Secrecy Act and FinCEN rules, or the UK Money Laundering Regulations. The precise scope, format, and update expectations should be confirmed against the regime applicable to the entity.
Completing a risk assessment and implementing its controls prevents money laundering.
The assessment and associated controls are measures to identify, detect, deter, and mitigate risk, not guarantees of prevention. A rating or the presence of controls does not eliminate financial crime risk, nor does it establish that any particular activity is or is not criminal.

Best practices

Structure the assessment around recognised risk factor categories relevant to the business, such as customer, product and service, transaction, delivery channel, and geographic risk, while tailoring the scope to the entity's actual activities.
Confirm the specific requirements, expected format, and update cadence against the regime applicable to the entity, rather than assuming a single global standard applies.
Document the methodology used to weigh risk factors and reach an overall rating, so that judgements are transparent, repeatable, and defensible to supervisors.
Explicitly link identified inherent risks to the policies, controls, and procedures intended to mitigate them, and describe the resulting residual risk position.
Review and update the assessment periodically and in response to material changes in the business, its customer base, its offerings, or its wider risk environment.
Keep the business-wide assessment distinct from, but connected to, customer-level CDD and EDD, using the entity-level view to help calibrate the intensity of customer-level measures.