Skip to main content
Category: Risk Assessment

Supranational Risk Assessment

Also known as: SNRA, Supra National Risk Assessment
Simply put

The Supranational Risk Assessment (SNRA) is a report prepared by the European Commission that examines the money laundering and terrorist financing risks affecting the EU internal market, particularly those with a cross-border dimension. It looks at risk across the whole EU rather than for a single country, complementing the national-level assessments carried out by individual member states.

Formal definition

The SNRA is a periodic assessment published by the European Commission that systematically evaluates specific money laundering and terrorist financing (ML/TF) risks affecting the EU internal market, with a focus on cross-border risks. It operates at the supranational (EU-wide) level and is distinct from a National Risk Assessment (NRA), which under FATF guidance is a country-level process to evaluate and address ML/TF threats and vulnerabilities affecting that individual jurisdiction. As a strategic risk-assessment instrument, the SNRA informs obliged entities and competent authorities of prevailing risk exposures across the market; it is a risk-assessment output rather than a legal determination of wrongdoing, and its findings are typically read alongside jurisdiction-specific NRAs. The precise scope, methodology, and publication cycle should be confirmed against the applicable EU instruments and the relevant Commission report.

Why it matters

The Supranational Risk Assessment matters because money laundering and terrorist financing risks rarely respect national borders. Illicit flows, front companies, and layering schemes frequently move across jurisdictions within the EU internal market, which means that a purely country-by-country view can miss risks with a cross-border dimension. The SNRA, published by the European Commission, is designed to fill that gap by examining specific ML/TF risks affecting the internal market as a whole, complementing rather than replacing the National Risk Assessments (NRAs) that individual member states conduct under approaches consistent with FATF guidance.

For obliged entities and competent authorities, the SNRA functions as a strategic reference point that helps calibrate risk-based programs. Its findings can inform how firms think about their exposure to particular sectors, products, channels, or typologies that the Commission identifies as carrying elevated cross-border risk. Because the SNRA operates at the EU-wide level, it is generally read alongside jurisdiction-specific NRAs, allowing compliance functions to reconcile broad market-level risk signals with the more granular picture provided by their own national authorities.

It is important to treat the SNRA as a risk-assessment output rather than a legal determination. It identifies and characterizes risk to support informed decision-making; it does not establish wrongdoing by any entity, sector, or jurisdiction, nor does it guarantee that risks so identified will materialize or that others will not. Firms typically use it as one input into a broader, dynamic risk-based approach rather than as a definitive or exhaustive list of threats.

Who it's relevant to

Compliance Officers at Obliged Entities
Compliance officers can use SNRA findings as a market-level input when designing and calibrating their firm's risk-based approach, reconciling EU-wide cross-border risk signals with jurisdiction-specific National Risk Assessments. The SNRA does not replace a firm's own risk assessment and should be treated as one reference among several rather than an exhaustive or definitive list of risks.
Competent Authorities and Supervisors
National supervisors and competent authorities may draw on the SNRA to understand cross-border ML/TF risks affecting the internal market and to inform their supervisory priorities, reading it alongside their own NRA. It provides an EU-wide perspective that complements country-level assessments carried out under approaches consistent with FATF guidance.
Financial Intelligence Analysts and Investigators
Analysts and investigators can use the SNRA's characterization of cross-border ML/TF risks and typologies as context for their work, while recognizing that identified risks are analytical signals, not evidence of wrongdoing in any specific case. Its EU-wide framing can help situate patterns that span multiple member states.
Risk and Legal Professionals
Risk and legal teams may reference the SNRA when assessing exposure to sectors, products, or channels flagged at the EU level, confirming precise scope, methodology, and publication timing against the applicable EU instruments and the relevant Commission report before relying on its findings.

Inside SNRA

Cross-Border Threat Identification
A component that identifies money laundering and terrorist financing threats affecting the internal market as a whole, rather than those confined to a single Member State. It focuses on risks that span multiple jurisdictions and cannot be adequately assessed at the national level alone.
Sectoral Vulnerability Analysis
An examination of vulnerabilities across the sectors and products used by obliged entities, considering how particular services, distribution channels, or transaction types may be exposed to ML/TF risk. Coverage is generally tied to the obliged entities and activities within scope of the applicable EU framework.
Recommendations to Member States
Guidance addressed to national authorities on measures suitable to address the identified risks. In many cases Member States that choose not to apply a recommendation are expected to explain that decision on a 'comply or explain' basis, though the precise mechanism should be confirmed against the applicable instrument.
Periodic Review Cycle
The assessment is produced and updated on a recurring basis to reflect evolving threats and typologies. It functions as a living reference rather than a one-time exercise, informing subsequent national and firm-level risk assessments.
Relationship to National and Firm-Level Assessments
The supranational assessment sits above national risk assessments and business-wide risk assessments in a tiered structure. It is intended to inform, not replace, the risk assessments that Member States and obliged entities conduct at their own levels.

Common questions

Answers to the questions practitioners most commonly ask about SNRA.

Is the Supranational Risk Assessment a legally binding instrument that obliged entities must follow?
No. The Supranational Risk Assessment (SNRA) is an assessment document rather than a binding legal instrument. It is prepared by the European Commission to identify, analyse, and address money laundering and terrorist financing risks affecting the EU internal market. Its findings inform policy and are intended to guide Member States and obliged entities, but the enforceable obligations themselves flow from the applicable AML legislation transposed and applied in each Member State. Obliged entities should treat the SNRA as an input into their own risk understanding, not as a standalone rulebook.
Does the Supranational Risk Assessment replace a firm's own business-wide risk assessment?
No. The SNRA operates at the EU level and addresses risks across sectors and the internal market as a whole; it does not substitute for an obliged entity's own business-wide risk assessment or for national risk assessments. In many jurisdictions, obliged entities are generally expected to take relevant supranational and national risk assessment findings into account when designing and documenting their own risk assessment, but the firm remains responsible for assessing the specific risks arising from its own customers, products, services, delivery channels, and geographies.
How should a firm incorporate SNRA findings into its own risk assessment?
A common approach is to map the sectors, products, and threats highlighted in the SNRA against the firm's own activities and customer base, documenting where identified supranational risks are relevant and where they fall outside the firm's exposure. Where an SNRA finding aligns with the firm's operations, it can be used to support or challenge the risk ratings and mitigating measures in the business-wide risk assessment. Firms should retain a record of how these findings were considered, as this demonstrates a risk-based approach; the exact expectations may vary by jurisdiction and should be confirmed against applicable requirements.
How does the SNRA relate to national risk assessments and firm-level risk assessments?
These generally sit at different levels of a layered risk-based framework. The SNRA addresses risks across the EU internal market; national risk assessments address risks within a specific Member State; and the firm-level (business-wide) risk assessment addresses the risks specific to an individual obliged entity. Findings typically flow downward as inputs, with each level narrowing the focus. A firm should be prepared to reconcile its own assessment against both supranational and national findings and to explain any divergence based on its actual exposure.
How often should firms revisit their risk assessments in light of SNRA updates?
The SNRA is produced and updated periodically rather than continuously. Firms generally review and update their own risk assessments on a defined cycle and when material changes occur, which may include the publication of a new or revised SNRA that identifies risks relevant to the firm. The specific frequency and triggers for review depend on the applicable national requirements and the firm's own policies, so exact expectations should be confirmed against the relevant regulation.
What should a firm do if an SNRA-identified risk does not apply to its business?
Where an SNRA finding relates to a sector, product, or channel outside the firm's activities, a common practice is to document that the risk was considered and explain why it is not relevant to the firm's exposure. Recording this reasoning helps evidence that the firm has engaged with supranational findings as part of a risk-based approach, even where no additional mitigating measures are warranted. This documentation supports supervisory dialogue but does not, by itself, establish the adequacy of the overall programme.

Common misconceptions

The Supranational Risk Assessment is legally binding and imposes direct obligations on obliged entities.
It is primarily an assessment and guidance instrument. It informs the design of controls and national policy, and any recommendations to Member States typically operate on a comply-or-explain basis rather than as directly enforceable requirements on individual firms. Binding obligations generally derive from the underlying EU AML Directives or Regulation and their national transposition, which should be checked directly.
Because a supranational assessment exists, obliged entities and Member States no longer need to perform their own risk assessments.
The supranational assessment is one tier in a layered system. It is intended to inform national risk assessments and firm-level business-wide risk assessments, not to substitute for them. Obliged entities generally remain responsible for assessing risks specific to their own customers, products, geographies, and channels.
The threats and vulnerabilities it lists represent an exhaustive and definitive catalogue of ML/TF risk.
It reflects a point-in-time analysis of identified cross-border risks and is updated periodically. Typologies and vulnerabilities described are illustrative of areas of concern and should not be treated as complete, static, or as proof of criminality in any individual case.

Best practices

Use the supranational assessment as a reference input when scoping your business-wide risk assessment, but map its findings to the specific sectors, products, channels, and geographies relevant to your firm rather than adopting them wholesale.
Cross-reference supranational findings against the applicable national risk assessment to identify where cross-border risks are amplified, mitigated, or treated differently in your jurisdiction.
Track the periodic update cycle and refresh your own risk assessment when a new version is published, documenting how any changed threats or vulnerabilities have been considered.
Where the assessment issues recommendations to Member States, monitor how national authorities respond on a comply-or-explain basis, as this may signal forthcoming changes to national requirements.
Treat identified vulnerabilities as areas warranting proportionate, risk-based controls to detect and mitigate risk, not as definitive lists or as guarantees that all relevant risks have been captured.
Confirm any specific obligations, thresholds, or enforcement mechanisms against the underlying EU instruments and their national transposition rather than relying on the assessment document alone.