Enterprise-Wide Risk Assessment
An enterprise-wide risk assessment (EWRA) is a structured process a financial institution or other business uses to get a single, top-level view of its money laundering and terrorist financing risks across the whole organization. It looks at where risk exposure sits, such as across customers, geographies, products, and delivery channels, and helps the firm decide how to manage those risks. It is a risk-management tool used to identify and mitigate risk, not a guarantee that financial crime will be prevented.
An EWRA is a comprehensive, structured process used by financial institutions and other obliged entities to identify, assess, and mitigate money laundering (ML) and terrorist financing (TF) risks at an enterprise level, typically analyzing exposure across risk dimensions such as customers, geographies, products and services, and delivery channels. It produces a single, top-level statement or view of the firm's financial crime risk profile that informs the design and calibration of AML/CTF controls. As reflected in the evidence, the EWRA functions as an enterprise-level risk-management and mitigation mechanism; it is a measure to manage and reduce risk rather than to eliminate it. Note that specific obligations, scope, and methodology may vary by jurisdiction and applicable regulatory regime, and exact requirements should be confirmed against the relevant rules governing the entity.
Why it matters
An enterprise-wide risk assessment sits at the foundation of a risk-based AML/CTF program. Without a consolidated view of where money laundering and terrorist financing exposure concentrates, across customers, geographies, products and services, and delivery channels, a firm cannot credibly calibrate its controls to the risks it actually faces. The EWRA is the mechanism that translates a scatter of individual risk factors into a single, top-level statement of the institution's financial crime risk profile, which in turn informs how resources, monitoring intensity, and due diligence measures are allocated.
Regulators and supervisors across major regimes generally expect obliged entities to understand and document their risks before deciding how to mitigate them, and a well-constructed EWRA is often the artifact examiners look to as evidence that a program is genuinely risk-based rather than one-size-fits-all. The specific form, frequency, and scope of that expectation vary by jurisdiction and by the applicable regulatory regime, so firms should confirm the precise obligations against the rules governing their entity rather than assuming a single universal standard.
It is important to frame the EWRA correctly: it is a risk-management and mitigation tool used to identify, assess, and manage ML/TF risk, not a guarantee that financial crime will be prevented. A robust assessment can help a firm detect, deter, and reduce its exposure and direct attention to the areas of greatest concern, but no single control, including the EWRA, eliminates financial crime risk on its own.
Who it's relevant to
Inside EWRA
Common questions
Answers to the questions practitioners most commonly ask about EWRA.