The document everything else is supposed to come from
A business-wide risk assessment identifies the money laundering and terrorist financing risks an operator faces, rates them, and drives the controls applied against them. In most regimes it is a legal requirement, it must be documented, it must be kept current, and the firm's policies and procedures must be demonstrably derived from it.
That last clause is where most operators fail, and the failure is easy to describe. The risk assessment is written once, filed, and never referenced again. The controls were designed separately, usually copied from a template or inherited from a platform provider. When a regulator asks why a particular threshold was set where it was, nobody can point to anything.
The test a supervisor applies is simple and you should apply it to yourself: take any control in the framework, and trace it back to a risk in the assessment. Then take any high-rated risk in the assessment, and find the control that addresses it. If either direction breaks, the assessment is a document rather than a system.
The four risk factor categories
Frameworks converge on four categories. Assess each separately before combining, because combining too early hides the driver.
Customer risk. Who the customers are. Relevant factors include whether the relationship is remote or face to face, the customer's jurisdiction of residence, whether they are a politically exposed person or an associate of one, whether their identity was verified electronically or by document, whether the account was opened through an intermediary, how long the relationship has run, and the deposit levels and patterns involved. High-value customers are a category of their own: the concentration of revenue in a small group means a large share of the operator's exposure sits with people it has strong commercial reasons not to scrutinise.
Product, service and transaction risk. What the customer can do. Peer-to-peer products where value can be transferred between customers are the highest-risk category by design. High-liquidity, low-margin products allow conversion with minimal expected loss. Anonymous or pay-and-play products reduce the identifying information available. Products permitting very large single transactions raise the value at risk per event. Balance transfer between accounts or brands, where it exists, is a laundering mechanism with a customer-service justification.
Delivery channel risk. How the relationship is conducted. Remote onboarding is the base case online and carries inherent risk that the framework must address rather than note. Third-party introduction through affiliates or agents means the operator did not observe the customer's origin. Retail terminals and venues carry cash risk that online does not.
Geographic risk. Where the customer, the money and the business are. Customer residence and IP geolocation, the jurisdictions of the payment instruments used, the operator's own licensing jurisdictions, and the FATF listings and equivalent national lists all feed this. Note that geographic risk is not simply a country list: a customer in a low-risk country funding from an instrument issued in a high-risk one is a geographic risk even though their residence is unremarkable.
Rating risk without pretending to precision
Most operators rate inherent risk, describe the controls, and derive a residual risk. The mechanics matter less than the discipline, but a few things separate a usable assessment from a coloured spreadsheet.
Rate inherent risk before controls. The point of inherent risk is to show what the exposure would be without mitigation. An assessment that rates everything low because controls exist cannot explain why the controls are needed, and it collapses the moment a control is found to be ineffective.
Say what the rating means. "High" should have a written definition tied to likelihood and impact, applied consistently. Without definitions, ratings drift with whoever wrote them and cannot be compared year on year.
Let some risks stay high. A residual rating of low everywhere is not a sign of good controls; it is a sign that the exercise was performed to produce a comfortable answer. Peer-to-peer products, high-value customers and remote onboarding are inherently risky and remain somewhat risky after mitigation. Saying so is what makes the rest of the document credible.
Record the reasoning, not just the score. The rating is the least useful part. The reasoning is what a supervisor reads and what your successor needs.
Assign an owner and a review trigger. Annual review is the common minimum. The more important trigger is event-driven: a new product, a new market, a new payment method, a new customer segment, a change in the law, or a material incident should each force a reassessment of the affected area rather than waiting for the calendar.
Where the assessment meets the controls
The derivation from risk to control is the part to get right, and it is mostly mechanical once the assessment is honest.
A high customer-risk rating should produce enhanced due diligence triggers, lower monitoring thresholds, and senior approval for the relationship. A high product-risk rating should produce product-specific monitoring rules, transaction limits, or restrictions on which customers can access the product. A high geographic rating should produce jurisdiction-specific onboarding requirements, restricted payment methods, or a decision not to accept the business at all. A high delivery-channel rating should produce identity verification depth and third-party oversight requirements.
Two derivations are worth stating explicitly because they are the ones most often missing.
Thresholds should be derived, not inherited. Every monetary trigger in the framework should trace to a rationale. "It came with the platform" is the answer a supervisor hears most often and it is not an answer.
The customer risk rating should actually do something. Many operators calculate a customer risk score at onboarding, store it, and never use it. If a high-risk rating does not change the monitoring thresholds, the review frequency, the payment methods permitted or the approval required, the rating is decoration.
Dynamic risk, not a snapshot
A customer's risk is not fixed at onboarding, and a framework that treats it as fixed will be wrong about exactly the customers that matter.
Risk should be recalculated on events: a significant change in deposit level or pattern, a new payment method added, a change of address or jurisdiction, a sanctions or adverse media hit, a failed or unusual verification, a third-party deposit attempt, a pattern matching a monitoring rule, or the customer becoming politically exposed. Periodic review catches what events miss, and the review interval should itself be risk-based, with high-risk customers reviewed considerably more often than low-risk ones.
The failure mode here is the customer who onboarded at a low risk rating in year one, escalated steadily over three years, and was never reassessed because nothing triggered a review. That customer appears in enforcement notices with some regularity, and the finding is not that the operator misjudged the risk at onboarding. It is that the operator never looked again.
The risk assessment as a commercial document
There is a version of this exercise that produces a real strategic input rather than a compliance artefact, and it is worth arguing for internally.
An honest business risk assessment tells the operator where its exposure is concentrated: which products, which markets, which customer segments, which payment methods. That is directly useful for decisions about market entry, product roadmaps and payment partnerships. An operator that knows a proposed product creates a peer-to-peer value transfer route, before building it, can design the controls in rather than bolting them on after a supervisor asks.
It also tells the operator what it cannot currently support. The clearest output of a good assessment is sometimes a decision not to take a category of business, because the controls required would cost more than the revenue justifies. A framework incapable of producing that conclusion is a framework that will eventually produce an enforcement action instead.