How to write a business-wide risk assessment that survives review
Most business-wide risk assessments I am handed are a grid of ratings with the reasoning removed. The ratings might even be right, but nobody can tell, which means nobody can challenge them and nothing changes. This note is about writing the version that holds up when a regulator, an auditor or your own successor reads it cold.
The question the document actually has to answer
I have lost count of the business-wide risk assessments I have read over about twenty years, but the shape is usually the same. A table. Products down the left. Three columns across the top: inherent risk, controls, residual risk. Every cell in the middle column says something like "CDD, ongoing monitoring, screening". Every cell in the third column says medium.
The ratings may well be defensible. That is not the problem. The problem is that the reasoning has been deleted, so a reader cannot agree or disagree with anything. They can only accept it or reject it wholesale.
Here is the test I apply, and I would encourage you to apply it to whatever you inherit. Could a competent stranger — a new MLRO, a supervisor, an external auditor who knows the sector but not your firm — read this document and come away able to explain, in their own words, why your firm is exposed to what it is exposed to, and why the people running it are comfortable? If the answer is no, the assessment is a compliance artefact rather than a risk assessment. It exists to be shown, not to be used.
FATF's first Recommendation is built on the idea that a firm identifies and understands its own risks and then allocates resources accordingly, and the FATF framing matters here: understanding comes before allocation. A rating with no reasoning behind it cannot direct resources anywhere, because it contains no information about where the exposure sits. In the UK, the Money Laundering Regulations require the assessment to be written down and kept up to date; other jurisdictions frame the requirement differently, and if you operate across several you should be writing to the strictest of them rather than the average.
Start with an inventory, not a rating
Before you assess anything, write down what the firm actually is. Not what the website says it does. What it does.
I ask for four things, and I ask for them from people who are not in compliance. Revenue and volume by product line, from finance. Onboarding volumes by channel, from operations. Customer counts by type and by risk band, from the CRM or the KYC platform. Payment flows by counterparty country, both directions, from the payments team. Then I reconcile them, and the reconciliation is where the interesting material is.
Almost every time, two things fall out. The assessment in front of me describes at least one product the firm stopped selling years ago, complete with a carefully worded control narrative. And it omits at least one thing launched in the last two or three quarters, because the assessment is refreshed annually and the product roadmap is not.
The other omission worth hunting for is the legacy book. Customers onboarded under an older standard, sometimes under an acquired entity's standard, who have never been through a refresh. Nobody wants that paragraph in the document. It belongs in the document.
Geography deserves particular care. "Emerging markets" is not a geography. A list of the eleven countries that account for ninety-something per cent of your outbound corridors, with the two you have deliberately chosen to keep despite the risk and your reasons, is a geography. Similarly with customer types: "corporates" tells me nothing, whereas "about four hundred small money service businesses, of which roughly sixty are themselves licensed in third countries" tells me a great deal, including where I would look first.
Make the reasoning visible
For every item in your inventory, I want a short paragraph before the rating. Three or four sentences will usually do. What is the vulnerability in this product, channel, customer type or corridor? Which typology does it map to? And — this is the part that is nearly always missing — what evidence do you have of your own exposure, as opposed to the sector's?
That evidence is sitting in your case management system. Alert volumes and outcomes by rule and by segment. SAR counts by product. Exit numbers and exit reasons. Fraud losses. Complaint themes. Law enforcement production orders, which are a superb and underused indicator of where your firm shows up in other people's investigations. If your cash-intensive retail segment generated a disproportionate share of your disclosures last year, and much of that was structuring on the statement, then say so and cite the number. An inherent rating of high, followed by "because thirty-one of our fifty-eight disclosures last year came from a segment representing four per cent of customers", is an argument. "High — cash" is a label.
Use the word "because" liberally. It forces a clause after it.
Controls: designed, or operating?
The controls column is where most assessments quietly stop being true. Someone lists the control that exists in the policy. Nobody asks whether it is doing anything.
A control credit belongs in the document only if you can point to evidence that the control operated during the period, at the coverage and quality you are claiming. That means calibration evidence for monitoring rules, sample testing results for CDD files, match-rate and clearance data for screening, and quality assurance findings for the analyst work. Where you are relying on what an EDD file should contain as your mitigant for high-risk relationships, someone should have read a sample of those files recently and written down what they found.
Case note
A composite from work I have done at two e-money institutions. The firm handled outbound payouts to about thirty countries. Its assessment rated residual risk for one high-volume corridor as low, on the strength of "automated transaction monitoring and one hundred per cent sanctions screening". Both statements were true.
When I pulled the rule configuration, the corridor's principal monitoring rule carried a per-transaction threshold of £5,000, set in early 2019 when the average payment on that corridor was around £180. By mid-2023 the average had risen to roughly £1,240, and about eighty-nine per cent of payments in the corridor fell below the threshold. Over the fourteen months to June 2023 the rule produced eleven alerts across some 46,000 payments worth about £57m. The control existed. It was not reaching the population it was written for. Residual risk went from low to high in the revised assessment, and to medium the following March after recalibration — which generated 340 alerts in its first quarter and nine disclosures, three of them on relationships that had been open since 2020.
Nobody had lied. The rule had simply been left where it was while the business grew around it. That is the ordinary way controls decay, and an assessment that only records design will never catch it.
Residual risk you can derive
Residual risk is where assertion is most common and least excusable. Inherent high, controls listed, residual medium — with no visible relationship between the second and third.
You do not need a sophisticated model. You need a stated method, applied consistently, that a reader can follow. Whatever you choose, write down the rule: how many rating steps a fully effective control can move a risk, what "fully effective" requires as evidence, and what happens when control testing is overdue or has failed. Then apply it even when the answer is uncomfortable. An assessment where nothing came out high has usually been reverse-engineered from the answer.
Two habits I would press on you. First, resist false precision — a 3.7 residual score implies a measurement you do not have, and I would rather see four honest bands with clear definitions. Second, record direction of travel alongside the rating. A stable medium and a medium that was low eighteen months ago are different facts, and only one of them needs a decision from the board this quarter.
The borrowed template, and why it fails
Most weak assessments I see were good assessments somewhere else. Someone brought the file from a previous employer, changed the firm name and the product headings, and kept the risk narratives. It is understandable. It is also the single most reliable way to produce a document that describes no firm at all.
The narratives from a retail bank do not fit a payment institution with no branches and no cash. A crypto firm's exposure is shaped by on-chain flows, hosted wallet counterparties and the limits of what a trace can support — which is a different discipline from correspondent banking, and one where reading a blockchain analytics trace without over-reading it is itself a control question. Copy across and you inherit assumptions about channels you do not operate and controls you do not have.
Templates are useful as structure. Sector guidance is useful for method: JMLSG guidance for UK firms is worth reading properly rather than mining for quotations, and the Wolfsberg Group material is helpful on how to frame institutional exposure. What you cannot borrow is the content, because the content is the point.
Two practical additions before you circulate a draft.
- Write down what you decided not to do. Risks you have accepted, appetite limits you have set, and the reasoning — this is the part supervisors ask about most and firms record least.
- Tie the assessment to something downstream. If your rules and thresholds in transaction monitoring alert triage do not visibly reflect the segments you rated highest, one of the two documents is wrong.
- Name your review triggers. Annual is a floor, not a policy; a new corridor, an acquisition, a licence variation, or a material change in alert or disclosure patterns should each pull the assessment forward, and the FCA has been consistent that firms are expected to keep pace with their own change, not with the calendar.
Write it so that the person who replaces you can argue with it. That is the whole standard.
Worth remembering: An assessment that could describe any firm in your sector describes none, and least of all yours.