SardineCon SF/2026

Learn More
AML programs4 min read

What is Risk-based approach (RBA)?

SUBSCRIBE

A risk-based approach means putting your AML effort where the risk actually is: heavier scrutiny on higher-risk customers and activity, lighter touch where you can genuinely show the risk is lower. It is the core FATF principle, and it only holds up when you can evidence the reasoning behind every call.

What is a risk-based approach, in plain English?

A risk-based approach, or RBA, is the idea that a firm should aim its controls at the risk rather than spread them evenly across everyone. High-risk customers and transactions get more diligence and closer monitoring. Lower-risk ones get proportionally less. You cannot treat everything as high risk, because you would run out of people, budget, and patience, so the RBA is really about how you choose where to concentrate effort.

It is the foundational principle of modern AML, set out by the FATF and written into most national regimes. It replaced the older idea that every customer gets the same fixed checklist. The trade is flexibility for judgment: the firm decides how to allocate effort, but it has to defend those decisions.

That last part is the catch. An RBA done well concentrates scrutiny where it counts and frees up capacity from the genuinely low-risk mass. Done poorly it becomes an excuse to under-control, dressing up cost-cutting as risk-based. The line between the two is documentation: lower scrutiny is only defensible when you can show, on paper, why the risk was lower.

Rules-based versus risk-based

What changes

Rules-based

Risk-based

Effort

Same fixed checklist for every customer.

Effort scaled to each customer's assessed risk.

Low-risk customers

Full diligence regardless, wasting capacity.

Simplified diligence, freeing resources for real risk.

High-risk customers

Same treatment as everyone else.

Enhanced diligence and closer monitoring.

Evidence needed

Proof the checklist was followed.

Documented rationale for each risk-based call.

What it looks like in practice

In practice

A bank onboards two customers on the same day. One is a salaried local resident opening a basic account for their wages. The other is an import-export business with owners in three countries and cash-heavy activity.

Under an RBA, the first clears with standard identity checks and routine monitoring. The second gets enhanced due diligence, source-of-funds questions, and tighter thresholds. When an examiner later asks why the first got the lighter touch, compliance can point to a documented rating that shows exactly why the risk was judged lower, which is what turns a light touch into a defensible one.

Why it matters to operators

The RBA is what lets a real program function at scale. No firm has the resources to treat every customer as a potential launderer, and an examiner does not expect it to. What they expect is that the firm can show its heaviest controls landed on its highest risks. That is the whole test, and it is why the reasoning behind each call matters as much as the call itself.

For an operator, the practical takeaway is that lighter scrutiny is a position you have to be able to defend, not a default you can assume. An RBA with no documented rationale reads to examiners as arbitrary rather than risk-based, and arbitrary lightness looks identical to cutting corners. Write down why the risk was lower, and the light touch holds up.

What to watch

  • Undocumented low ratings. Customers rated low risk with no recorded reason are the classic exam finding.
  • Everything is high risk. Rating almost everyone high defeats the purpose and drowns the team in false effort.
  • Risk-based as a cost story. Reducing controls to save money, then calling it risk-based after the fact.
  • Stale ratings. Risk judged once at onboarding and never refreshed as behavior changes.
  • No link to effort. A rating that does not actually change how much diligence or monitoring a customer gets.

Quick questions

Where does the risk-based approach come from?

It is a core FATF principle now embedded in most national AML regimes. FATF guidance expects firms to identify their risks and allocate controls in proportion to them rather than applying one fixed standard to all.

Does risk-based mean I can skip checks on low-risk customers?

Not skip, scale. You still meet minimum requirements, but you can apply simplified diligence where you can evidence lower risk. The key word is evidence: the reduction has to be justified, not assumed.

How is it different from a rules-based approach?

A rules-based approach applies the same fixed checklist to everyone. A risk-based approach varies the depth of controls by assessed risk, which is more efficient but demands that you document your reasoning.

Why do examiners focus on documentation?

Because the flexibility of an RBA only works if decisions can be reconstructed. Without a written rationale, an examiner cannot tell a genuine risk judgment from a cost-driven shortcut, so undocumented equals indefensible.

Can a risk-based approach be wrong?

It can be poorly executed: risk under-estimated, ratings never refreshed, or controls not actually tied to risk. The approach itself is sound; the failures are in how firms apply and evidence it.

How does the RBA connect to risk appetite?

Risk appetite sets how much risk the firm will accept overall. The RBA is the method for allocating controls within that appetite, concentrating effort on the risks the firm has agreed it needs to manage most closely.

Go deeper

  • FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

What to know alongside Risk-based approach (RBA)