Compliance
Risk-Based Approach
Definition
The principle that anti-money laundering resources should be directed in proportion to assessed risk, applying enhanced measures where risk is higher and simplified measures where it is lower.
Why it matters
A risk-based approach is the organising idea of modern anti-money laundering regulation, replacing uniform checks applied identically to every customer. It requires a documented risk assessment, controls that follow from it, and evidence that the controls were actually applied.
The practical difficulty is that it makes judgment auditable. An operator cannot simply say it assessed risk; it must show the assessment, the threshold, the trigger and the action taken. Enforcement cases very often turn not on whether laundering occurred but on whether the licensee's own framework engaged when its own criteria were met, since a control that exists on paper and never fires provides no assurance at all.
It also cuts both ways. Applied properly it permits lighter treatment of demonstrably low-risk customers, which is the commercial argument for taking it seriously rather than defaulting to blanket checks.
The bottom line
A risk-based approach is judgment that has to be evidenced. Regulators penalise the failure to apply your own rules far more often than the failure to write them.