Skip to content
iGaming Times

Independent industry intelligence in your inbox. Unsubscribe any time - every newsletter carries a one-click link.

Lesson 2 of 7 · 14 min

The Business Risk Assessment

The document every control is supposed to derive from, the four risk factor categories, and the test a supervisor applies to find out whether it is a system or a filing.

In this lesson

  • Assess customer, product, delivery channel and geographic risk separately before combining them
  • Rate inherent risk before controls and defend a residual rating that is not low
  • Trace any control in the framework back to a risk in the assessment, and any high risk forward to a control
  • Design event triggers that recalculate customer risk instead of freezing it at onboarding

The document everything else is supposed to come from

A business-wide risk assessment identifies the money laundering and terrorist financing risks an operator faces, rates them, and drives the controls applied against them. In most regimes it is a legal requirement, it must be documented, it must be kept current, and the firm's policies and procedures must be demonstrably derived from it.

That last clause is where most operators fail, and the failure is easy to describe. The risk assessment is written once, filed, and never referenced again. The controls were designed separately, usually copied from a template or inherited from a platform provider. When a regulator asks why a particular threshold was set where it was, nobody can point to anything.

The test a supervisor applies is simple and you should apply it to yourself: take any control in the framework, and trace it back to a risk in the assessment. Then take any high-rated risk in the assessment, and find the control that addresses it. If either direction breaks, the assessment is a document rather than a system.

The four risk factor categories

Frameworks converge on four categories. Assess each separately before combining, because combining too early hides the driver.

Customer risk. Who the customers are. Relevant factors include whether the relationship is remote or face to face, the customer's jurisdiction of residence, whether they are a politically exposed person or an associate of one, whether their identity was verified electronically or by document, whether the account was opened through an intermediary, how long the relationship has run, and the deposit levels and patterns involved. High-value customers are a category of their own: the concentration of revenue in a small group means a large share of the operator's exposure sits with people it has strong commercial reasons not to scrutinise.

Product, service and transaction risk. What the customer can do. Peer-to-peer products where value can be transferred between customers are the highest-risk category by design. High-liquidity, low-margin products allow conversion with minimal expected loss. Anonymous or pay-and-play products reduce the identifying information available. Products permitting very large single transactions raise the value at risk per event. Balance transfer between accounts or brands, where it exists, is a laundering mechanism with a customer-service justification.

Delivery channel risk. How the relationship is conducted. Remote onboarding is the base case online and carries inherent risk that the framework must address rather than note. Third-party introduction through affiliates or agents means the operator did not observe the customer's origin. Retail terminals and venues carry cash risk that online does not.

Geographic risk. Where the customer, the money and the business are. Customer residence and IP geolocation, the jurisdictions of the payment instruments used, the operator's own licensing jurisdictions, and the FATF listings and equivalent national lists all feed this. Note that geographic risk is not simply a country list: a customer in a low-risk country funding from an instrument issued in a high-risk one is a geographic risk even though their residence is unremarkable.

Rating risk without pretending to precision

Most operators rate inherent risk, describe the controls, and derive a residual risk. The mechanics matter less than the discipline, but a few things separate a usable assessment from a coloured spreadsheet.

Rate inherent risk before controls. The point of inherent risk is to show what the exposure would be without mitigation. An assessment that rates everything low because controls exist cannot explain why the controls are needed, and it collapses the moment a control is found to be ineffective.

Say what the rating means. "High" should have a written definition tied to likelihood and impact, applied consistently. Without definitions, ratings drift with whoever wrote them and cannot be compared year on year.

Let some risks stay high. A residual rating of low everywhere is not a sign of good controls; it is a sign that the exercise was performed to produce a comfortable answer. Peer-to-peer products, high-value customers and remote onboarding are inherently risky and remain somewhat risky after mitigation. Saying so is what makes the rest of the document credible.

Record the reasoning, not just the score. The rating is the least useful part. The reasoning is what a supervisor reads and what your successor needs.

Assign an owner and a review trigger. Annual review is the common minimum. The more important trigger is event-driven: a new product, a new market, a new payment method, a new customer segment, a change in the law, or a material incident should each force a reassessment of the affected area rather than waiting for the calendar.

Where the assessment meets the controls

The derivation from risk to control is the part to get right, and it is mostly mechanical once the assessment is honest.

A high customer-risk rating should produce enhanced due diligence triggers, lower monitoring thresholds, and senior approval for the relationship. A high product-risk rating should produce product-specific monitoring rules, transaction limits, or restrictions on which customers can access the product. A high geographic rating should produce jurisdiction-specific onboarding requirements, restricted payment methods, or a decision not to accept the business at all. A high delivery-channel rating should produce identity verification depth and third-party oversight requirements.

Two derivations are worth stating explicitly because they are the ones most often missing.

Thresholds should be derived, not inherited. Every monetary trigger in the framework should trace to a rationale. "It came with the platform" is the answer a supervisor hears most often and it is not an answer.

The customer risk rating should actually do something. Many operators calculate a customer risk score at onboarding, store it, and never use it. If a high-risk rating does not change the monitoring thresholds, the review frequency, the payment methods permitted or the approval required, the rating is decoration.

Dynamic risk, not a snapshot

A customer's risk is not fixed at onboarding, and a framework that treats it as fixed will be wrong about exactly the customers that matter.

Risk should be recalculated on events: a significant change in deposit level or pattern, a new payment method added, a change of address or jurisdiction, a sanctions or adverse media hit, a failed or unusual verification, a third-party deposit attempt, a pattern matching a monitoring rule, or the customer becoming politically exposed. Periodic review catches what events miss, and the review interval should itself be risk-based, with high-risk customers reviewed considerably more often than low-risk ones.

The failure mode here is the customer who onboarded at a low risk rating in year one, escalated steadily over three years, and was never reassessed because nothing triggered a review. That customer appears in enforcement notices with some regularity, and the finding is not that the operator misjudged the risk at onboarding. It is that the operator never looked again.

The risk assessment as a commercial document

There is a version of this exercise that produces a real strategic input rather than a compliance artefact, and it is worth arguing for internally.

An honest business risk assessment tells the operator where its exposure is concentrated: which products, which markets, which customer segments, which payment methods. That is directly useful for decisions about market entry, product roadmaps and payment partnerships. An operator that knows a proposed product creates a peer-to-peer value transfer route, before building it, can design the controls in rather than bolting them on after a supervisor asks.

It also tells the operator what it cannot currently support. The clearest output of a good assessment is sometimes a decision not to take a category of business, because the controls required would cost more than the revenue justifies. A framework incapable of producing that conclusion is a framework that will eventually produce an enforcement action instead.

Key terms

Business-wide risk assessment
The documented identification and rating of the money laundering and terrorist financing risks a firm faces, from which its policies, controls and thresholds must be demonstrably derived.
Inherent risk
The exposure before mitigation. Rated first so the assessment can show what the controls are for, rather than assuming them away.
Residual risk
The exposure remaining after controls. Some categories should legitimately remain elevated, and saying so is what makes the rest of the assessment credible.
Delivery channel risk
Risk arising from how the relationship is conducted: remote onboarding, third-party introduction through affiliates or agents, or retail channels carrying cash.
Event-driven review
Recalculating customer risk on a trigger such as a change in deposit pattern, a new payment instrument, a jurisdiction change or a screening hit, rather than waiting for the periodic cycle.

Key takeaways

  • The supervisor’s test runs in both directions: every control should trace back to a risk, and every high risk should trace forward to a control.
  • Rate inherent risk before controls. An assessment that rates everything low because controls exist cannot explain why the controls are needed.
  • A residual rating of low everywhere is evidence the exercise was performed to produce a comfortable answer.
  • Thresholds should be derived with recorded reasoning. "It came with the platform" is the answer supervisors hear most often and it is not an answer.
  • A customer risk rating that does not change a threshold, a review interval, a permitted payment method or an approval requirement is decoration.

Check your understanding

3 questions · answer them all, then check.

  1. 1. An operator’s risk assessment rates every category as low residual risk. What does that most likely indicate?

  2. 2. A customer onboards at low risk, escalates steadily over three years and is never reassessed. What is the finding?

  3. 3. Which is the strongest evidence that a risk assessment is operative rather than decorative?

Sign in to track your progress through the course.

Cookie Preferences

Choose which cookies you want to accept. Essential cookies are required for the website to function properly.

Required

Necessary for the website to function. Cannot be disabled.

Help us understand how visitors interact with our website.

Used to deliver relevant advertisements and track ad performance.

Remember your preferences and settings for a better experience.

The Business Risk Assessment - Learning hub | iGaming Times