Skip to main content
Category: Risk Assessment

Threat Assessment

Also known as: Threat Analysis, Threat Assessment and Management, TAM
Simply put

A threat assessment is a structured process for evaluating how serious and credible a potential threat is, and for describing its nature. It helps organizations understand what they are facing so they can decide how to respond. The specific approach varies widely depending on the setting, such as information security, physical safety, or violence prevention.

Formal definition

Threat assessment is the process of formally evaluating the degree, credibility, probability, and seriousness of a potential threat to a system, enterprise, or environment, and describing the nature of that threat. In information security contexts, it typically refers to evaluating threats to an information system or enterprise (per NIST usage). Related practice areas apply the concept differently; for example, threat assessment and management (TAM) focuses on determining the credibility, probability, and seriousness of a threat and managing the associated behavior, while school threat assessment applies a team-based, behavior-focused approach to violence prevention. The evidence provided addresses these general and sector-specific applications rather than AML/CFT-specific usage, and readers should note that threat assessment as applied within financial crime risk frameworks may differ and should be confirmed against the applicable regulatory guidance.

Why it matters

Threat assessment matters because organizations across very different sectors face potential harms that vary in credibility, probability, and seriousness, and responding effectively requires a structured way to evaluate those threats rather than relying on intuition or reaction after the fact. Whether the concern is a threat to an information system, physical safety in a school, or the risk of targeted violence, a disciplined assessment process helps decision-makers understand the nature of what they face and calibrate their response proportionately.

The practical value of threat assessment is most visible in its emphasis on early attention and prevention rather than punishment after a crisis. In school settings, for example, approaches such as the Comprehensive School Threat Assessment Guidelines (CSTAG) model developed through the University of Virginia's Youth Violence Project treat threat assessment as a team effort focused on identifying and addressing concerning behaviors, such as bullying or teasing, before they escalate. This framing positions threat assessment as a tool to help individuals and manage behavior, not merely to detect and sanction it.

It is important to recognize that the term carries different meanings depending on the discipline, and the evidence supporting this entry addresses general and sector-specific applications, information security, physical safety, and violence prevention, rather than AML/CFT-specific usage. Compliance professionals should not assume that threat assessment as described here maps directly onto the way the concept is applied within financial crime risk frameworks; that usage may differ and should be confirmed against the applicable regulatory guidance.

Who it's relevant to

Information Security Teams
Professionals responsible for protecting information systems and enterprises use threat assessment to formally evaluate the degree and nature of threats to those systems, consistent with NIST usage. The output helps prioritize defenses and characterize the risks an organization faces.
School Safety and Violence Prevention Teams
Educators, administrators, and multidisciplinary teams apply school threat assessment as a team-based, behavior-focused approach to keeping schools safe. Models such as CSTAG emphasize early attention to concerning behaviors and helping students before a crisis, rather than waiting for trouble and responding through punishment alone.
Threat Management Practitioners
Practitioners working in threat assessment and management (TAM) determine the credibility, probability, and seriousness of a potential threat and manage the associated behavior. This audience is concerned not only with evaluating a threat but with the ongoing management of the individual or behavior involved.
AML/CFT and Financial Crime Compliance Professionals
Compliance officers and financial crime risk professionals may encounter the term within their own risk frameworks, but should note that the evidence here addresses general and sector-specific uses rather than AML/CFT-specific usage. The meaning and methodology within financial crime contexts may differ and should be confirmed against the applicable regulatory guidance.

Inside Threat Assessment

Threat Identification
The systematic cataloguing of the money laundering, terrorist financing, proliferation financing, and predicate criminal threats to which an entity, sector, or jurisdiction may be exposed. This typically draws on national risk assessments, FATF-related typologies, law enforcement intelligence, and the entity's own experience, and should be treated as indicative rather than exhaustive.
Threat Sources and Actors
Identification of the persons, groups, or activities that generate illicit proceeds or seek to move funds, which may include organised crime, corruption and PEP-related abuse, fraud, tax evasion, human trafficking, and terrorist financing networks. The nature of relevant threat actors generally varies by jurisdiction, sector, and business model.
Threat Likelihood and Impact
An evaluation of how probable a given threat is to materialise and the potential harm it could cause, used to help prioritise attention. This is an analytical judgment informing a risk-based approach, not a legal determination that any particular threat is present.
Relationship to Vulnerability and Risk
Threat assessment addresses the external hazard, whereas vulnerability assessment addresses the weaknesses that a threat could exploit; in commonly used risk frameworks, risk is generally understood as a function of threat, vulnerability, and consequence. The threat component is only one input and does not on its own establish an entity's overall risk rating.
Levels of Application
Threat assessment may be conducted at the supranational level (for example EU-level assessments), the national level (national risk assessments referenced in the FATF Recommendations), the sectoral level, and the individual obliged-entity level as part of a business-wide risk assessment. The scope, methodology, and legal weight differ at each level.
Information Sources
Inputs typically include national and supranational risk assessments, FATF and FATF-style regional body reports and typologies, sanctions and law enforcement intelligence, suspicious activity or transaction reporting trends, and open-source information. Sources should be assessed for reliability, and their availability may vary by jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about Threat Assessment.

Is a threat assessment the same thing as a risk assessment?
No. A threat assessment and a risk assessment are related but distinct exercises. A threat assessment typically focuses on identifying and analysing the sources, actors, and predicate offences that generate criminal proceeds or financing (the 'threat' side), whereas a risk assessment more broadly combines threats with vulnerabilities and consequences to produce an overall assessment of risk. In many frameworks, threat is treated as one input into the wider risk picture rather than a synonym for it. The exact relationship and terminology can vary by jurisdiction and by the methodology an obliged entity or authority adopts, so the scope of each exercise should be confirmed against the applicable guidance.
Does a threat assessment identifying a particular typology mean that related activity is criminal?
No. A threat assessment describes potential sources of criminal proceeds or financing and the methods by which they may move through the financial system; it does not establish that any specific customer, transaction, or activity is criminal. Typologies and identified threats are conceptual and analytical tools used to inform where attention and controls may be directed. They are not proof of wrongdoing, and they should not be treated as exhaustive or as a legal test. Any conclusion about actual criminality is a separate matter determined through investigation and, ultimately, the applicable criminal-law process.
Who typically produces a threat assessment, and at what level?
Threat assessments are generally produced at multiple levels. At the supranational and national level, bodies such as standard-setters, financial intelligence units, law enforcement, and supervisory authorities may publish threat or risk assessments that describe prevailing criminal threats. At the institutional level, obliged entities may incorporate threat analysis into their own risk assessment processes. The precise obligations, ownership, and required outputs differ by jurisdiction and by the type of entity involved, so responsibilities should be confirmed against the applicable regulatory framework and supervisory expectations.
How does a threat assessment feed into an institution's control framework?
A threat assessment typically informs where an institution focuses its detection, deterrence, and mitigation measures by highlighting the sources and methods of potential criminal activity most relevant to its business. In practice this may influence customer due diligence intensity, transaction monitoring scenarios, screening parameters, and the allocation of compliance resources. It is important to frame these as measures to manage and mitigate risk rather than as guarantees of prevention, and no single control derived from a threat assessment eliminates financial crime risk on its own.
How often should a threat assessment be reviewed or updated?
Threat assessments are generally treated as living documents that should be refreshed as the threat environment, business activities, products, and geographies change. Many frameworks expect periodic review as well as updates triggered by significant events, new typologies, or changes in published national or supranational assessments. Exact frequency and triggering criteria vary by jurisdiction and by supervisory expectation, so the required review cadence should be confirmed against the applicable rules and internal governance standards.
What sources of information typically inform a threat assessment?
A threat assessment is usually built from a combination of sources, which may include published national and supranational risk or threat assessments, guidance and typologies from standard-setters and financial intelligence units, law enforcement and supervisory outputs, and an entity's own internal data such as customer profiles, transaction patterns, and prior alerts or filings. The mix and weighting of sources depend on the level at which the assessment is produced and on the entity's business model. These inputs support analysis of potential threats and should not be treated as establishing criminality in any individual case.

Common misconceptions

A threat assessment is the same thing as a risk assessment.
In commonly used frameworks, threat is only one component of risk, alongside vulnerability and consequence. A threat assessment identifies and evaluates external hazards, but a full risk assessment must combine that with the entity's own vulnerabilities and the potential impact before a risk rating can be reached.
Identifying a threat means wrongdoing or criminal activity has occurred or is occurring within the entity.
A threat assessment is an analytical and risk-management exercise, not a legal finding. Identifying that a particular threat exists or is plausible does not establish that any customer, transaction, or party has engaged in criminal conduct.
A single national or FATF typology list captures all relevant threats and can be used as an exhaustive checklist.
Typologies and national risk assessments are indicative and evolve over time; they should be treated as inputs rather than a complete or static catalogue. Threats generally vary by jurisdiction, sector, and business model, and new methods emerge that may not yet be reflected in published sources.

Best practices

Distinguish clearly in documentation between the threat component and the vulnerability and consequence components, so the overall risk assessment shows how each input contributes to the final rating.
Draw on multiple sources, including national and supranational risk assessments, FATF and FATF-style regional body typologies, law enforcement intelligence, and internal reporting trends, and record an assessment of each source's reliability.
Tailor the threat assessment to the entity's specific jurisdictions, sectors, products, and customer base rather than relying on generic threat lists, and note explicitly what falls in and out of scope.
Treat typologies and red flags as indicative rather than exhaustive, and avoid framing any identified threat as proof of criminal activity within the entity.
Review and refresh the threat assessment on a defined cadence and following material changes, such as new products, new markets, or updated national risk assessments, so it remains current.
Confirm any specific thresholds, obligations, or reporting requirements referenced against the applicable regulation for each relevant jurisdiction, since these diverge across regimes.