Skip to main content
Category: Risk Assessment

National Risk Assessment

Also known as: NRA, National Risk Assessment of Money Laundering and Terrorist Financing
Simply put

A National Risk Assessment (NRA) is a process by which a country systematically evaluates the money laundering, terrorist financing, and related financial crime threats and vulnerabilities it faces. It helps a jurisdiction understand where its greatest risks lie so that authorities can prioritise their response. The findings typically inform how a country applies a risk-based approach to fighting financial crime.

Formal definition

A National Risk Assessment is a country-level, systematic evaluation of threats and vulnerabilities relating to money laundering (ML), terrorist financing (TF), and, in some jurisdictions, proliferation financing (PF). It underpins a jurisdiction's risk-based approach as promoted by the FATF, which provides guidance and a supporting toolkit to help countries identify and address their most significant risks; note that the FATF materials constitute standards and guidance rather than binding law, and the precise scope, methodology, and periodicity of an NRA vary by jurisdiction. In practice, NRAs are conducted periodically and updated over successive iterations, for example, the UK describes its 2025 NRA as its fourth comprehensive assessment of ML and TF risk, while jurisdictions such as the Isle of Man frame their NRA as a systematic evaluation covering ML, TF, and PF and as a component of meeting international standards. NRA outputs are generally used to prioritise supervisory attention, allocate resources, and inform national policy; they are assessments of aggregate risk rather than determinations of wrongdoing by any specific entity or individual.

Why it matters

A National Risk Assessment sits at the foundation of a jurisdiction's risk-based approach to combating financial crime. Without a systematic understanding of where the greatest money laundering (ML), terrorist financing (TF), and, in some jurisdictions, proliferation financing (PF) threats and vulnerabilities lie, authorities cannot credibly prioritise supervisory attention, allocate limited resources, or design proportionate policy responses. The NRA is the mechanism through which a country moves from an abstract commitment to fight financial crime toward informed, targeted action. Its outputs generally shape how supervisors direct their oversight and how obliged entities are expected to calibrate their own risk assessments.

The NRA also reflects a jurisdiction's alignment with international standards. The FATF promotes the risk-based approach and provides guidance and a supporting toolkit to help countries identify and address their most significant risks; it is worth stressing that these FATF materials are standards and guidance rather than binding law. Bodies such as the Isle of Man Financial Services Authority describe their NRA as a crucial element of the Island's commitment to meeting international standards, illustrating how the exercise functions both as an internal planning tool and as evidence of a jurisdiction's engagement with the global AML/CFT framework.

Because NRAs are conducted periodically and refined over successive iterations, they also provide a longitudinal picture of how a country's risk profile evolves. The UK, for example, describes its 2025 NRA as its fourth comprehensive assessment of ML and TF risk. It is important to understand what an NRA is not: it is an assessment of aggregate, country-level risk, not a determination of wrongdoing by any specific entity, sector, or individual. A sector identified as higher risk in an NRA is being flagged for prioritised attention, not accused of criminality.

Who it's relevant to

National authorities and policymakers
Government departments, financial intelligence units, and other competent authorities lead or contribute to the NRA and rely on its findings to prioritise their response, allocate resources, and shape AML/CFT policy. For jurisdictions such as the Isle of Man, the NRA is also framed as a component of demonstrating commitment to international standards.
Supervisors and regulators
Supervisory bodies use NRA outputs to direct oversight toward areas identified as higher risk and to inform how they engage with the sectors they supervise. Because the NRA assesses aggregate risk rather than individual conduct, a higher-risk designation signals prioritised attention rather than a finding of wrongdoing.
Compliance officers and obliged entities
Firms and other obliged entities can use the national picture set out in the NRA as a reference point when calibrating their own institutional and business risk assessments. The NRA helps them understand the threats and vulnerabilities their jurisdiction faces, though it does not replace an entity's own obligation to assess and manage its specific risk exposure.
Financial intelligence and investigation professionals
Analysts and investigators can draw on the NRA's evaluation of ML, TF, and (where in scope) PF threats and vulnerabilities to contextualise their work, while recognising that the assessment describes country-level risk and is not evidence of criminality by any specific party.

Inside NRA

Threat Identification
A National Risk Assessment (NRA) typically catalogues the predicate offences and criminal activities generating illicit proceeds within a jurisdiction, such as fraud, drug trafficking, corruption, or tax evasion, alongside the terrorist financing threats relevant to that country. This threat mapping is generally informed by law enforcement data, financial intelligence, and typologies, though the specific threats identified vary by jurisdiction and over time.
Vulnerability Assessment
An NRA examines the weaknesses that may be exploited for money laundering or terrorist financing, including gaps in legal frameworks, supervisory capacity, product or sector characteristics, and cross-border exposure. Vulnerabilities are typically assessed by sector and product rather than treated as a single national figure.
Sectoral and Product Risk Ratings
Many NRAs assign relative risk levels to categories of obliged entities (for example banking, money services, real estate, or designated non-financial businesses and professions) and to particular products, services, delivery channels, and customer types. These ratings are generally comparative and qualitative rather than precise measurements.
Consequence or Impact Analysis
Some NRAs consider the potential harm or consequence associated with identified risks, combining threat and vulnerability with an assessment of impact. The methodology for weighing consequence differs between jurisdictions and is not uniform.
Methodology and Data Sources
An NRA typically documents the analytical approach used and the inputs relied upon, which may include supervisory findings, suspicious activity or transaction reporting data, law enforcement statistics, and private-sector consultation. The FATF Recommendations set an expectation that countries identify, assess, and understand their risks, but the specific methodology is left to each jurisdiction.
Risk-Mitigation and Policy Priorities
NRAs commonly identify priorities for allocating resources and shaping national AML/CFT policy, informing supervisory focus and the risk-based measures obliged entities are expected to apply. These are intended to inform, not replace, an obliged entity's own risk assessment.

Common questions

Answers to the questions practitioners most commonly ask about NRA.

Is a National Risk Assessment the same as an obliged entity's own business-wide risk assessment?
No. A National Risk Assessment (NRA) is conducted at the country level, typically by government bodies or a designated competent authority, to identify and evaluate the money laundering and terrorist financing risks facing the jurisdiction as a whole. An obliged entity's business-wide (or firm-wide) risk assessment is conducted by the individual institution to assess the risks specific to its own customers, products, services, delivery channels, and geographies. The two are related but distinct: in many jurisdictions, firms are expected to take the findings of the NRA into account when preparing and updating their own risk assessments, but the NRA does not replace the entity-level assessment. Exact expectations depend on the applicable regime and should be confirmed against local requirements.
Does an NRA impose direct legal obligations or penalties on individual firms?
Not directly. An NRA is primarily an analytical and policy instrument used to inform a country's overall approach to combating money laundering and terrorist financing, including how supervisory resources and legislative priorities are allocated. It is generally not itself the source of enforceable obligations on individual obliged entities. Binding obligations typically flow from the applicable statutory and regulatory framework, such as national AML legislation and implementing rules. That said, in some jurisdictions firms are expected to reflect NRA findings in their own risk-based controls, and failure to do so may be relevant to a supervisor's assessment of a firm's compliance. The precise legal effect of an NRA varies by jurisdiction and should be confirmed against local law.
Who is typically responsible for conducting a National Risk Assessment?
Responsibility generally rests with government authorities, often coordinated by a lead body such as a ministry of finance, a financial intelligence unit, or a dedicated inter-agency working group. The process typically draws input from supervisors, law enforcement, the FIU, and sometimes private sector and other stakeholders. The specific institutional arrangements vary by jurisdiction. The FATF Recommendations set an expectation that countries identify, assess, and understand their ML/TF risks and designate an authority or mechanism to coordinate this work, but as standards rather than binding law, their implementation depends on how each country gives them effect.
How should a compliance team use NRA findings in practice?
In many jurisdictions, firms are expected to consider relevant NRA findings when designing and updating their own risk assessments and risk-based controls. Practically, this may involve reviewing the NRA to identify sectors, products, geographies, or typologies flagged as higher risk, then assessing how those findings map to the firm's own exposure. Where relevant, teams may document how NRA insights were considered, adjust customer risk-rating factors or monitoring parameters, and note areas the firm concludes are out of scope for its business. The NRA is one input among several and does not substitute for the firm's own analysis. The weight given to NRA findings and the documentation expected should be confirmed against the applicable regime.
How often are National Risk Assessments updated, and how should firms respond to a new one?
There is no single universal frequency; NRAs are generally updated periodically or when significant changes in the risk environment occur, with the exact cadence varying by jurisdiction. When a new or revised NRA is published, firms typically review it to identify changes relevant to their business, assess whether their own risk assessment and controls remain appropriate, and update them where necessary. Exact timing expectations and any triggers for review should be confirmed against local requirements.
What is the relationship between an NRA and supra-national or sectoral risk assessments?
An NRA sits at the country level and may coexist with assessments at other levels. For example, in some regions a supra-national body may produce a broader risk assessment intended to inform member states, and individual sectors or supervisors may produce sectoral risk assessments focused on particular activities. These are complementary layers rather than substitutes: a firm may need to consider the NRA alongside any applicable supra-national or sectoral assessments when calibrating its own controls. The existence, status, and legal effect of each layer depend on the applicable framework and should be confirmed against the relevant instruments.

Common misconceptions

A National Risk Assessment is a legally binding rulebook that dictates the exact controls each firm must apply.
An NRA is primarily an assessment and policy document produced at the country level, generally reflecting the FATF expectation that jurisdictions understand their risks. It informs supervisory priorities and the risk-based approach, but obliged entities are typically still required to conduct their own business-wide and customer-level risk assessments under the applicable regime, and should confirm specific obligations against the relevant law.
A sector rated 'high risk' in the NRA means firms in that sector are involved in money laundering.
Risk ratings describe the relative likelihood and vulnerability to abuse, not evidence of wrongdoing by any particular entity. A high-risk rating signals where enhanced attention or mitigation may be warranted; it does not establish that criminal activity has occurred.
There is a single global National Risk Assessment or a uniform methodology applied everywhere.
NRAs are produced at the national (or in some cases supranational) level, and methodologies, data sources, and risk ratings diverge between jurisdictions. Findings from one country's NRA cannot be assumed to apply to another, and terminology may differ across regimes.

Best practices

Incorporate relevant NRA findings into your firm's own business-wide risk assessment, mapping identified national threats and sectoral vulnerabilities to your specific products, customers, delivery channels, and geographies rather than adopting national ratings wholesale.
Treat NRA risk ratings as inputs that inform, but do not replace, your independent risk-based analysis and the customer due diligence, enhanced due diligence, and monitoring measures required under the applicable regime.
Document how NRA outputs have influenced your policies, controls, and risk appetite, so that supervisory examiners can trace the link between national findings and your firm's mitigation measures.
Review and refresh your risk assessment when an updated NRA is published or when new threats and vulnerabilities are identified, treating risk assessment as an ongoing rather than one-off exercise.
Avoid treating any NRA-identified typology or high-risk category as exhaustive or as proof of criminality; use it to focus detection and mitigation efforts while confirming specific thresholds and obligations against the relevant regulation.
Where your firm operates across borders, consult the NRAs of each applicable jurisdiction separately, since threats, vulnerabilities, and methodologies differ and one country's assessment should not be assumed to cover another.