An AML risk assessment is a structured, evidence-based read of where money laundering and terrorist financing risk sits across customers, products, regions, and channels. You rate the raw risk, subtract the controls in place, and land on the risk that remains, which then steers the whole program.
What is an AML risk assessment, in plain English?
An AML risk assessment is how a firm figures out where its money laundering and terrorist financing risk actually is. Rather than treating every customer and product the same, it maps risk across four main dimensions: customer types, products and services, geographies, and delivery channels. Each is scored on evidence, not gut feel.
The core method is to rate the raw or inherent risk of each area, then subtract the effect of the controls you have in place, to arrive at the residual risk that remains. That residual number is the honest picture of your exposure after mitigation, and it is what should be driving decisions.
Because it sets the baseline, the assessment steers everything downstream: how you staff the team, where you set monitoring thresholds, and how deep your customer checks go. Get it right and controls point at the real threats; get it wrong and the whole program is calibrated against the wrong targets.
Inherent, controls, residual
Inherent — Rate the raw risk. Score money laundering and terrorist financing risk across customers, products, regions, and channels before controls.
Controls — Weigh the mitigation. Assess how much the controls in place actually reduce each area of risk, with evidence they work.
Residual — Land on what remains. Subtract controls from inherent risk to get the residual exposure that should drive decisions.
Calibrate — Point the program. Use the residual picture to set staffing, monitoring thresholds, and the depth of customer checks.
Who is involved?
Who
Their role
The compliance function
Owns the assessment, gathers evidence, and scores inherent, control, and residual risk.
Business lines
Provide data on customers, products, geographies, and channels that feeds the ratings.
Senior management and the board
Review and sign off, since the assessment sets risk appetite in practice.
Independent testing and examiners
Challenge whether scores, control credit, and evidence hold up.
What it looks like in practice
In practice
A payments firm rates its inherent risk as high for cross-border transfers to several regions, then gives itself generous credit for a transaction monitoring system, dropping the residual risk to low. On paper, everything looks well controlled.
Independent testing asks for evidence that the monitoring actually covers those corridors and finds the relevant rules were never tuned for them. The control credit was unearned, so the true residual risk was far higher than recorded. Because thresholds and staffing had been set to the understated number, the whole program was quietly under-resourced against its real exposure.
Why it matters to operators
The risk assessment is the aiming mechanism for the entire program. Thresholds, staffing, and due diligence depth all descend from it, so a weak or stale assessment quietly miscalibrates controls everywhere downstream. If the assessment points at the wrong targets, even well-run controls are watching the wrong things.
That makes a few failure modes especially costly. Scores that never change suggest the assessment is not really being done. Control credit with no proof understates residual risk, as the example shows. And new products launched before the assessment is refreshed leave exposure unmeasured and unmanaged. If the assessment is wrong, the whole program is aimed at the wrong targets, which is why examiners scrutinize it so hard.
What to watch for
Frozen scores. Ratings that never change year to year, a sign the assessment is a formality rather than a live analysis.
Unproven control credit. Residual risk lowered by controls with no evidence they actually work as claimed.
Unassessed products. New products, markets, or channels launched before the assessment is refreshed to include them.
Thin evidence. Ratings based on assumption or gut feel rather than data on customers, volumes, and typologies.
Disconnected controls. Thresholds and staffing that do not actually track the residual risk the assessment reports.
Quick questions
What is the difference between inherent and residual risk?
Inherent risk is the raw exposure before controls; residual risk is what remains after the controls are applied. The assessment works by rating inherent risk, weighing controls, and landing on residual risk, which should drive decisions.
What dimensions does it cover?
Typically customer types, products and services, geographies, and delivery channels. Scoring each dimension separately gives a granular view of where risk concentrates rather than a single blanket rating.
Why is unproven control credit dangerous?
Because it understates residual risk. If you claim a control reduces risk but cannot show it works, the recorded exposure is too low, and thresholds and staffing get set beneath what the real risk demands.
How often should it be refreshed?
At least periodically, and whenever the business materially changes, such as a new product, market, or channel. Launching something new before reassessing leaves that exposure unmeasured and unmanaged.
How does it relate to an enterprise-wide risk assessment?
An enterprise-wide risk assessment is the firm-level version that aggregates risk across the whole business. An AML risk assessment can refer to that or to more focused assessments; the method of inherent minus controls equals residual is the same.
What happens if the assessment is wrong?
The whole program is aimed at the wrong targets. Because staffing, thresholds, and due diligence all flow from it, a miscalibrated assessment weakens every downstream control, which is why examiners treat it as foundational.
FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.
---
title: What is AML risk assessment?
source_page: https://www.sardine.ai/fraud-aml-glossary/aml-risk-assessment
canonical: https://www.sardine.ai/fraud-aml-glossary/aml-risk-assessment
format: text/markdown
description: This is a structured, evidence-based read of where money laundering and terrorist financing risk sits across customer types, products, regions, and channels. You rate the raw risk, then subtract the controls in place to land on the risk that remains. It steers staffing, monitoring thresholds, and how deep customer checks go.
---
**Quick links:** [Human page](https://www.sardine.ai/fraud-aml-glossary/aml-risk-assessment) · [Home](https://www.sardine.ai) · [Customers](https://www.sardine.ai/customers) · [Blog](https://www.sardine.ai/blog) · [Demo](https://www.sardine.ai/demo)
---
# What is AML risk assessment?
**Read time:** 4
This is a structured, evidence-based read of where money laundering and terrorist financing risk sits across customer types, products, regions, and channels. You rate the raw risk, then subtract the controls in place to land on the risk that remains. It steers staffing, monitoring thresholds, and how deep customer checks go.
An AML risk assessment is a structured, evidence-based read of where money laundering and terrorist financing risk sits across customers, products, regions, and channels. You rate the raw risk, subtract the controls in place, and land on the risk that remains, which then steers the whole program.
What is an AML risk assessment, in plain English?
An AML risk assessment is how a firm figures out where its money laundering and terrorist financing risk actually is. Rather than treating every customer and product the same, it maps risk across four main dimensions: customer types, products and services, geographies, and delivery channels. Each is scored on evidence, not gut feel.
The core method is to rate the raw or inherent risk of each area, then subtract the effect of the controls you have in place, to arrive at the residual risk that remains. That residual number is the honest picture of your exposure after mitigation, and it is what should be driving decisions.
Because it sets the baseline, the assessment steers everything downstream: how you staff the team, where you set monitoring thresholds, and how deep your customer checks go. Get it right and controls point at the real threats; get it wrong and the whole program is calibrated against the wrong targets.
Inherent, controls, residual
Inherent — Rate the raw risk. Score money laundering and terrorist financing risk across customers, products, regions, and channels before controls.
Controls — Weigh the mitigation. Assess how much the controls in place actually reduce each area of risk, with evidence they work.
Residual — Land on what remains. Subtract controls from inherent risk to get the residual exposure that should drive decisions.
Calibrate — Point the program. Use the residual picture to set staffing, monitoring thresholds, and the depth of customer checks.
Who is involved?
What it looks like in practice
In practice
A payments firm rates its inherent risk as high for cross-border transfers to several regions, then gives itself generous credit for a transaction monitoring system, dropping the residual risk to low. On paper, everything looks well controlled.
Independent testing asks for evidence that the monitoring actually covers those corridors and finds the relevant rules were never tuned for them. The control credit was unearned, so the true residual risk was far higher than recorded. Because thresholds and staffing had been set to the understated number, the whole program was quietly under-resourced against its real exposure.
Why it matters to operators
The risk assessment is the aiming mechanism for the entire program. Thresholds, staffing, and due diligence depth all descend from it, so a weak or stale assessment quietly miscalibrates controls everywhere downstream. If the assessment points at the wrong targets, even well-run controls are watching the wrong things.
That makes a few failure modes especially costly. Scores that never change suggest the assessment is not really being done. Control credit with no proof understates residual risk, as the example shows. And new products launched before the assessment is refreshed leave exposure unmeasured and unmanaged. If the assessment is wrong, the whole program is aimed at the wrong targets, which is why examiners scrutinize it so hard.
What to watch for
Frozen scores. Ratings that never change year to year, a sign the assessment is a formality rather than a live analysis.
Unproven control credit. Residual risk lowered by controls with no evidence they actually work as claimed.
Unassessed products. New products, markets, or channels launched before the assessment is refreshed to include them.
Thin evidence. Ratings based on assumption or gut feel rather than data on customers, volumes, and typologies.
Disconnected controls. Thresholds and staffing that do not actually track the residual risk the assessment reports.
Quick questions
### What is the difference between inherent and residual risk?
Inherent risk is the raw exposure before controls; residual risk is what remains after the controls are applied. The assessment works by rating inherent risk, weighing controls, and landing on residual risk, which should drive decisions.
### What dimensions does it cover?
Typically customer types, products and services, geographies, and delivery channels. Scoring each dimension separately gives a granular view of where risk concentrates rather than a single blanket rating.
### Why is unproven control credit dangerous?
Because it understates residual risk. If you claim a control reduces risk but cannot show it works, the recorded exposure is too low, and thresholds and staffing get set beneath what the real risk demands.
### How often should it be refreshed?
At least periodically, and whenever the business materially changes, such as a new product, market, or channel. Launching something new before reassessing leaves that exposure unmeasured and unmanaged.
### How does it relate to an enterprise-wide risk assessment?
An enterprise-wide risk assessment is the firm-level version that aggregates risk across the whole business. An AML risk assessment can refer to that or to more focused assessments; the method of inherent minus controls equals residual is the same.
### What happens if the assessment is wrong?
The whole program is aimed at the wrong targets. Because staffing, thresholds, and due diligence all flow from it, a miscalibrated assessment weakens every downstream control, which is why examiners treat it as foundational.
Go deeper
FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.
FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.