A BSA/AML risk assessment is the documented analysis that shows where an institution is exposed to money-laundering and terrorist-financing risk, and how well its controls manage that exposure. The method has three moves: rating inherent risk across the institution's products, customers, geographies, and channels; evaluating the controls; and documenting the residual risk that remains. No single line of the BSA commands a standalone risk assessment, but the FFIEC manual treats it as the foundation of the program and an examiner reads it first.
Every other part of a BSA/AML program borrows its logic from the risk assessment: customer due diligence rates customers against it, transaction monitoring sets thresholds around it, and training, staffing, and independent testing are scaled to it. When the risk assessment is thin or generic, everything built on top inherits the same weakness, and that weakness is visible to an examiner early in a review.
This article covers what a risk assessment is, what the law requires, the categories of risk an institution inventories, the method for getting from inherent risk to residual risk, the approaches to scoring it, and the failure modes that turn a risk assessment into an examination finding.
What a BSA/AML risk assessment is
A risk assessment is a structured judgment about exposure. It identifies the specific ways the institution could be used to move illicit funds, rates how serious each exposure is on its own, weighs the controls in place against it, and arrives at a residual risk that the program then has to manage. The output is a written analysis with a methodology, ratings, and the reasoning behind them, not a score in isolation.
The function of the exercise is allocation. A program has finite attention, and the risk assessment is how an institution decides where to spend it. It identifies which customer types require enhanced due diligence, which products require tighter monitoring, and where additional compliance resources are directed. It is also the document a BSA officer uses to explain, to a sponsor bank or an examiner, why the program is configured as it is.
Requirement status under the BSA
No provision of the Bank Secrecy Act says, in those words, that an institution must conduct a risk assessment. What the law requires is a program that is reasonably designed to guard against money laundering, and the implementing rules for banks and other institutions require written, risk-based programs. The risk assessment is the means by which an institution demonstrates that its program is risk-based.
Three sources turn that into a practical expectation:
- The FFIEC BSA/AML Examination Manual describes a well-developed risk assessment as the basis of a sound program and instructs examiners to evaluate it. For a supervised institution, the manual is the standard the program is measured against.
- The Customer Due Diligence rule (31 CFR 1010.230, effective in 2018) requires risk-based procedures for customer due diligence and beneficial-ownership identification. Risk-based CDD presupposes a risk assessment underneath it.
- FinCEN's proposed AML/CFT Program Rule (RIN 1506-AB72) would make a documented risk assessment process an explicit, named program component, tied to the national AML/CFT priorities. It is a proposal, not yet final law, but it points where supervision is heading.
The precise position is therefore that a standalone risk assessment is not named in the statute, while a program without a defensible one fails the standard it is held to; in supervisory practice it operates as a requirement. For how the assessment fits the wider program, see the guide to the BSA/AML program pillars.
The risk categories inventoried
The FFIEC manual frames inherent risk around products and services, customers and entities, and geographic locations. In practice most programs add delivery channels as a fourth, because how a customer is onboarded and how they move money changes the exposure. Within each category, the institution lists the drivers that apply to it and rates them. The categories are the same everywhere; the drivers are institution-specific.
| Category | What is rated | Higher-risk drivers |
|---|---|---|
| Products & services | What the institution offers and how easily it can move value | Cash-intensive activity, international wires, prepaid access, virtual currency, trade finance, private banking. |
| Customers & entities | Who the customers are and the laundering risk they carry | Money services businesses, cash-intensive businesses, non-resident or foreign customers, politically exposed persons, complex ownership structures. |
| Geographies | Where customers, counterparties, and activity are located | Jurisdictions under sanctions, high-risk or non-cooperative jurisdictions, and domestic high-intensity financial-crime or drug-trafficking areas. |
| Channels | How customers are onboarded and how they transact | Non-face-to-face onboarding, third-party or agent intermediaries, and embedded or platform relationships where the customer never touches the bank directly. |
A common failure is to inventory the categories generically, listing risks that apply to every bank rather than the ones that apply to the institution in question. A risk assessment that would read identically for a different institution has not assessed that institution's exposure.
The method: from inherent risk to residual risk
The analytical core of a risk assessment is moving from inherent risk to residual risk. The steps below are the practitioner method, and they map to the categories above.
Step 1: Rate inherent risk
Each inventoried driver is rated for the risk it carries before any controls are considered. This is inherent risk: the raw exposure of the activity itself. The rating is applied on a consistent scale, usually low, moderate, and high, with the reasoning recorded. Volume and dollar value bear on the rating, not only the presence of a risk: ten foreign wires a year is a different exposure than ten thousand.
Step 2: Assess the control environment
For each area of inherent risk, the controls that manage it are identified and assessed for design adequacy and for whether they operate as intended. Customer due diligence, transaction monitoring, sanctions screening, enhanced due diligence for higher-risk customers, training, and independent testing are the usual controls. A control counts toward risk reduction only where it exists and operates: a monitoring rule that is never tuned, or an EDD process that collects documents but never reaches a conclusion, does not reduce risk.
Step 3: Determine residual risk
The inherent rating is combined with control strength to reach residual risk, the exposure that remains after controls. Residual risk describes what the institution actually carries. A high-inherent-risk product with strong, tested controls can land at moderate or low residual risk, and a moderate product with weak controls can land at high. The logic is stated explicitly, because an examiner tests whether the documented controls justify the residual rating assigned.
Step 4: Aggregate to an enterprise-wide rating
The individual ratings are rolled up into an enterprise-wide risk profile. This is the view a board, a sponsor bank, and an examiner use: where the institution's residual exposure concentrates, and why. The aggregate is a reasoned conclusion rather than an average, since a single high-residual-risk line can define the program's posture even when most of the book is low risk.
Step 5: Document and refresh
The methodology, the ratings, the supporting data, and the rationale are recorded, so that a reader who was not present can follow how each conclusion was reached. The full assessment is then refreshed periodically and updated whenever a material change occurs.
Scoring and the risk matrix
Most institutions express the assessment as a matrix: risk drivers down one axis, and inherent risk, control strength, and residual risk across the columns, each rated on a low-to-high scale. Some programs attach numeric weights so the aggregation is repeatable; others stay qualitative with written justification. Either approach is defensible. What an examiner looks for is consistency: the same logic applied across every line, and a residual rating that the documented controls actually support.
Consistency of application carries more weight than the granularity of the scale: a three-point scale applied consistently and supported by written reasoning is more defensible than a ten-point scale assigned without a stated basis. Whichever scale is used, each level is defined before any driver is rated against it.
The enterprise-wide assessment and refresh cadence
The enterprise-wide risk assessment is the consolidated view of the whole institution, and it is the version examiners and sponsor banks ask for by name. There is no fixed statutory interval for refreshing it. Common practice is a full refresh at least every twelve to eighteen months, plus an update on any material change: a new product or service, a new market, a new customer segment, a merger, a new bank or fintech partner, or a significant shift in volume. A risk assessment that no longer matches the business is treated as stale, and a stale assessment undercuts every control that was supposed to be scaled to it.
Recurring failure modes at examination
The recurring failures appear across public enforcement actions and take six forms.
- Template-driven content. A risk assessment that lists generic industry risks rather than the institution's actual drivers. It reads as if it could belong to anyone.
- No documented methodology. Ratings appear with no explanation of how they were reached, so the conclusions cannot be tested or reproduced.
- Inherent and residual risk conflated. The assessment never separates raw exposure from the controls that manage it, so there is no way to see what the program is actually carrying.
- Controls asserted, not evidenced. Residual ratings rely on controls that are weak, untuned, or not operating, so the residual number is not earned.
- Stale. The business changed and the assessment did not, so it describes an institution that no longer exists.
- Disconnected from the program. The risk assessment sits in a binder while CDD, monitoring, and staffing are scaled to something else entirely.
An AML gap analysis is often where these surface, and the exam-preparation guide covers what examiners request and how the review unfolds.
Risk assessment for fintechs and sponsor-bank programs
In a banking-as-a-service relationship the responsibility does not move. The sponsor bank holds the non-delegable regulatory obligation for BSA/AML, including the risk assessment, even when a fintech performs the work. A fintech operating under a sponsor bank still needs its own risk assessment, sized to its products and customers, and that assessment rolls up into the bank's enterprise view.
Two things change in this model. First, the channel category carries more weight, because embedded and platform relationships put distance between the bank and the end customer. Second, the bank's own enterprise risk assessment has to account for the risk each fintech partner introduces, which means the bank needs visibility into the partner's risk assessment, not just its own. A money transmitter operating across states faces a parallel version of this; the money transmitter compliance guide covers the licensing layer that sits on top.
The standard the assessment is held to is a stable one: content specific to the institution, an explicit method, residual ratings that reflect what the controls actually do, and a document kept current. An assessment meeting those conditions functions as the foundation the rest of the program rests on, and an examination of it is a review of reasoning already documented.
Primary sources
- FFIEC BSA/AML Examination Manual: The interagency supervisory standard; see the BSA/AML Risk Assessment section for the risk categories and the foundational role of the assessment.
- 31 CFR 1010.230: Beneficial ownership requirements for legal entity customers (the CDD rule, effective 2018).
- 31 CFR 1020.210: Anti-money laundering program requirements for banks, which must be risk-based.
- 31 U.S.C. 5318(h): The statutory anti-money laundering program requirement.
- FinCEN, proposed AML/CFT Program Rule (RIN 1506-AB72): Would make a documented risk assessment process an explicit program component. A proposal, not final law.