Skip to main content
Category: Risk Assessment

Emerging Risk Assessment

Also known as: Emerging Risk Analysis, Emerging Risk Identification
Simply put

An emerging risk assessment is a forward-looking process organizations use to spot new or evolving threats before they become serious problems. Unlike a standard risk review that checks existing controls against known requirements, it focuses on identifying, evaluating, and preparing for risks that are not yet fully understood or established. The goal is to respond proactively rather than react after a risk has already caused harm.

Formal definition

An emerging risk assessment is a proactive, forward-looking analytical process for identifying, assessing, and developing mitigation strategies for new and evolving threats before they materialize as established risks. It is generally distinguished from a conventional risk assessment, which is typically performed against defined compliance requirements, implemented controls, or existing processes; by contrast, emerging risk analysis addresses risks that are novel, uncertain, or not yet fully characterized. Effective practice generally relies on a collaborative, comprehensive, and flexible approach that leverages new data and monitors market changes with agility, and may be supported by connected risk technology to enable timely identification and response. The output is typically used to inform proactive strategy and control design rather than to confirm compliance with a fixed standard.

Why it matters

In financial crime compliance, the threat environment shifts continually as criminals adapt to new products, channels, and technologies. A conventional risk assessment measures existing controls and processes against defined compliance requirements, but by design it tends to look at known and established risks. An emerging risk assessment complements that work by focusing on threats that are novel, uncertain, or not yet fully characterized, giving compliance and risk functions a structured way to anticipate change rather than only respond to it after harm has occurred.

The practical value is proactive positioning. By identifying new and evolving threats before they turn into major issues, organizations can inform strategy and control design ahead of time instead of retrofitting controls in the wake of an incident or a regulatory finding. This forward-looking orientation is particularly relevant in a field where typologies and delivery channels evolve, and where the absence of a fixed compliance benchmark for a new risk means firms must exercise judgment about how to detect, deter, and mitigate exposures that regulations may not yet address explicitly.

It is important to treat the output of an emerging risk assessment as an input to strategy and control design, not as a guarantee of prevention or a confirmation of compliance with any fixed standard. No single assessment or control eliminates financial crime risk; the aim is to manage and mitigate exposures more effectively by identifying them earlier. Because emerging risks are by nature uncertain, conclusions should be revisited as new data becomes available and the market changes.

Who it's relevant to

Chief Risk Officers and Risk Management Functions
Risk leaders use emerging risk assessments to spot new and evolving threats before they become established, informing enterprise strategy and control design. The collaborative, comprehensive, and flexible approach these functions coordinate, leveraging new data and monitoring market changes, supports timely identification and response across the organization.
Compliance Officers
Compliance teams rely on this process to look beyond conventional assessments performed against defined requirements and existing controls, addressing novel or not-yet-characterized risks. It helps them position controls proactively rather than reacting after a risk has already caused harm, while recognizing that the output informs strategy and does not confirm compliance with a fixed standard.
Financial Intelligence Analysts and Investigators
Analysts and investigators benefit from forward-looking identification of new and evolving threats, which can inform how they monitor for and respond to changing patterns. Emerging risk analysis is intended to help detect and mitigate exposures earlier, not to serve as proof of wrongdoing in any individual case.
Technology and Data Teams Supporting Risk
Teams responsible for risk technology and data can enable the process, since connected risk technology may facilitate proactive identification, assessment, and response to emerging risks. Their role includes supporting the agile use of new data and the monitoring of market changes on which effective emerging risk assessment depends.

Inside Emerging Risk Assessment

Horizon Scanning
The systematic, forward-looking process of identifying new or evolving financial crime threats, typologies, products, technologies, and regulatory developments that are not yet fully reflected in an obliged entity's existing risk assessment. This is generally an operational and governance activity rather than a specific requirement defined identically across regimes.
Trigger Events and Reassessment
The identification of events, such as new product launches, entry into new markets or jurisdictions, technological changes, or newly published typologies from bodies like the FATF, that may prompt an interim update to a firm's risk assessment. The FATF Recommendations promote a risk-based approach and periodic review, though the precise cadence and triggers are typically set by national law and supervisory expectations.
Source Inputs
The intelligence and information feeding an emerging risk assessment, which may include supervisory guidance, FATF and FSRB publications, sanctions and geopolitical developments, internal SAR/STR trends, and industry threat information. The relevance and weighting of these inputs generally depend on the entity's business model and the jurisdictions in which it operates.
Risk Rating and Mitigation Response
The assessment of the likelihood and potential impact of an identified emerging risk, followed by the design or adjustment of controls to detect, deter, and manage that risk. Such controls are measures to mitigate risk and do not guarantee prevention of financial crime.
Governance and Documentation
The recording of how emerging risks were identified, assessed, escalated, and addressed, together with oversight by senior management or the board where applicable. Documentation expectations vary by regime and are typically driven by national AML law and supervisory requirements rather than a single global standard.

Common questions

Answers to the questions practitioners most commonly ask about Emerging Risk Assessment.

Is an emerging risk assessment the same as the enterprise-wide risk assessment required of obliged entities?
No. Although the two are related and often feed into one another, they are not interchangeable. An enterprise-wide (or business-wide) risk assessment is the comprehensive exercise many regimes expect obliged entities to conduct across their customers, products, services, delivery channels, and geographies. An emerging risk assessment is narrower and forward-looking: it focuses on newly identified or evolving threats, typologies, technologies, or regulatory developments that may not yet be fully reflected in the standing enterprise-wide assessment. In practice, findings from an emerging risk assessment typically inform updates to the broader enterprise-wide assessment rather than replacing it. The precise expectations depend on the applicable regime and should be confirmed against relevant guidance and regulations.
Does identifying an emerging risk mean the firm has a compliance deficiency or that customers involved are engaged in wrongdoing?
No. Identifying and documenting an emerging risk is generally regarded as a sign of a functioning, risk-based program rather than evidence of a control failure. Recognizing a new or evolving threat does not establish that any customer, transaction, or product is connected to money laundering, terrorist financing, or other criminal activity; it signals an area that may warrant enhanced monitoring, further analysis, or mitigating measures. Treating an emerging risk finding as proof of wrongdoing conflates a risk-management observation with a legal conclusion, which are distinct.
Who within an AML program should be responsible for conducting an emerging risk assessment?
Responsibility is typically shared rather than assigned to a single function. Ownership often sits with the compliance or financial crime risk function, frequently under the direction of the MLRO or equivalent officer, but meaningful input generally comes from business lines, technology teams, sanctions and fraud specialists, and legal. In many organizations, governance bodies or risk committees review the outputs. The specific allocation of roles depends on the entity's size, structure, and the expectations of its supervisor, so responsibilities should be defined in internal policies and confirmed against applicable guidance.
What sources can be used to identify emerging risks?
Firms commonly draw on a combination of external and internal sources. External inputs may include supervisory publications, FATF and regional body reports, national risk assessments, financial intelligence unit typology alerts, sanctions and enforcement developments, and industry information-sharing forums, among others. Internal inputs may include transaction monitoring trends, SAR or STR patterns, customer feedback, product development pipelines, and audit or testing findings. These sources are illustrative rather than exhaustive, and their relevance will vary by the entity's risk profile and jurisdiction.
How often should an emerging risk assessment be performed?
There is generally no single mandated frequency, and expectations vary by regime and supervisor. Many programs treat emerging risk assessment as an ongoing or periodic activity rather than a fixed annual event, updating it when significant new threats, typologies, technologies, or regulatory changes arise. Some firms align it with the review cycle of their enterprise-wide risk assessment while also allowing for ad hoc assessments triggered by specific events. The appropriate cadence should be set on a risk-sensitive basis and documented, and confirmed against applicable regulatory expectations.
How should the output of an emerging risk assessment be documented and acted upon?
As a matter of good practice, findings are typically recorded in a way that captures the nature of the risk, the analysis performed, any assessment of likelihood and impact, and the proposed or implemented mitigating measures. Outputs often feed into updates to the enterprise-wide risk assessment, adjustments to controls such as monitoring rules or due diligence measures, and reporting to senior management or relevant governance bodies. Documentation supports the ability to demonstrate a risk-based approach to supervisors. It is important to note that mitigating measures are intended to detect, deter, or manage risk, not to guarantee prevention, and specific documentation and escalation expectations should be confirmed against the applicable regime.

Common misconceptions

Emerging risk assessment is a one-off exercise completed alongside the annual enterprise-wide risk assessment.
It is generally understood as an ongoing, forward-looking process. Because new typologies, products, and regulatory changes can arise between scheduled reviews, many jurisdictions and supervisors expect firms to reassess on the occurrence of relevant trigger events, not solely on a fixed annual cycle. Exact frequency expectations should be confirmed against the applicable regulation and supervisory guidance.
Identifying an emerging risk or a new typology means the firm has detected wrongdoing or must file a report.
An emerging risk assessment identifies potential exposure to evolving threats; it does not establish that any customer or transaction involves criminal conduct. Any reporting obligation, such as a SAR or STR, arises from the applicable reporting framework and its suspicion threshold, which is separate from the risk-assessment exercise.
Published typologies and red flags provide a complete checklist of emerging risks to monitor.
Typologies and red-flag lists are illustrative and conceptual, not exhaustive. New methods evolve continuously, and the presence of a red flag is not proof of criminality. Firms generally need to tailor their scanning to their own products, customers, and jurisdictions rather than relying solely on any single published list.

Best practices

Establish a defined process for horizon scanning that draws on multiple sources, including supervisory and FATF/FSRB publications, sanctions and geopolitical developments, and internal SAR/STR trend data, and calibrate these inputs to your specific business model and jurisdictions.
Define and document trigger events, such as new products, new markets, or newly identified typologies, that prompt an interim reassessment rather than waiting for the next scheduled enterprise-wide risk assessment.
Assess each identified emerging risk for likelihood and potential impact, and link the outcome to specific control adjustments designed to detect, deter, or mitigate the risk, recognising that no single control eliminates financial crime risk.
Maintain clear documentation of how emerging risks were identified, assessed, escalated, and addressed, and ensure appropriate senior management or board oversight consistent with your applicable national requirements.
Feed the results of emerging risk assessments back into CDD, EDD, monitoring, and screening frameworks so that changes in the risk landscape are reflected operationally, not just recorded on paper.
Confirm the specific frequency, trigger, and documentation expectations against your applicable regime, such as the EU AML framework, the US BSA/FinCEN rules, or the UK Money Laundering Regulations, since these diverge and a single global rule should not be assumed.