Your Enterprise Risk Assessment Is Fiction
Most enterprise-wide risk assessments are fiction in a precise sense: the document exists but the understanding does not. Under the risk-based approach that anchors the FATF standards and the national frameworks built on them, including the UAE's, the enterprise-wide risk assessment, or EWRA, is meant to be the foundation from which the whole programme flows. The firm understands its risks, calibrates its controls proportionately to them, and allocates its compliance resources accordingly.
In practice the assessment is too often built once from a borrowed template, refreshed annually to satisfy a questionnaire, and approved by a board that never truly engages with it. Nothing in the programme would change if the file were deleted tomorrow. This article explains how a risk assessment becomes fiction, why an examiner sees through it in minutes, what the fiction costs, and what a living, decision-driving assessment looks like instead.
AML Expert
Get tailored guidance on your compliance obligations, SAR filing, or AML program review.
- What we mean by fiction
- The four ways a risk assessment becomes fiction
- Why examiners see through it immediately
- What the fiction costs
- What a non-fictional risk assessment looks like
- How to tell whether yours is fiction
- Frequently asked questions
An enterprise-wide risk assessment is one of the most important documents a regulated firm produces, because it provides the foundation for many elements of the programme's risk-based approach. The customer due diligence model, the transaction monitoring rules, the training plan, the resourcing of the compliance team: each is meant to be a proportionate response to a risk the assessment has identified. When the assessment is sound, the programme has a spine. When it is fiction, the programme risks becoming a collection of controls whose rationale is difficult to explain or defend.
This article is a direct argument, not a neutral explainer. It is not uncommon to encounter risk assessments that bear little resemblance to the firm's actual exposure. What follows sets out how the fiction takes hold, how it is detected, what it costs, and how to replace it with something real.
What We Mean by Fiction
Under the risk-based approach that sits at the centre of the international standards, and that national frameworks including the UAE's have written into law, a regulated firm is expected to identify and understand the money laundering and terrorist financing risks it faces, and then apply controls that are proportionate to those risks. The EWRA is the primary document in which understanding is recorded and articulated. It is not a form to be completed. It is the reasoning that informs the firm's risk-based compliance programme.
Fiction is what you get when the document exists, but the understanding does not. The pages are full, the matrix is colour-coded, the residual scores are calculated to two decimal places, and yet it has little observable influence on the controls the firm operates. The risk assessment is not describing the institution. It is describing an idealised version of the institution, lightly edited to carry the right logo and a plausible customer list. That gap, between the institution on paper and the institution in practice, is the fiction this article refers to, and it is a weakness that regulators continue to identify across many jurisdictions.
The uncomfortable part is that the fiction is usually sincere. Nobody sets out to fabricate a risk assessment. The compliance officer is stretched thin, the template looked professional, the deadline was real, and the document that resulted was good enough to pass the immediate test in front of it. The problem is that the immediate test, a bank questionnaire or a licence renewal, is not the test that matters. The test that matters comes later, when a supervisor or a court asks the firm to show that it actually understood its risks before the money moved.
A risk assessment that does not meaningfully influence the firm's controls risks becoming a brochure. The test I apply is simple: show me the decision this document changed. If nothing in the programme would look different without it, an examiner is likely to question whether the assessment is genuinely driving the programme.
Pathik Shah | FCA, CAMS, CISA, AML/CFT Practitioner, AML Guild
The Four Ways a Risk Assessment Becomes Fiction
Fiction rarely announces itself. It commonly develops through familiar shortcuts, each of which feels reasonable at the time and each of which gradually weakens the connection between the document and the firm's actual risk profile.
The Borrowed Template
An EWRA that begins life as another firm's document, or a generic model bought from a vendor, inherits that firm's risks rather than your own. The customer types are theirs, the geographies are theirs, the product list is theirs, and the control descriptions describe a maturity the borrowing firm has not reached. Templates are useful as a structure, but a structure is not an assessment. When the risk narrative describes correspondent banking that the firm does not offer, or omits the cash-intensive customer segment that is in fact its largest exposure, the document has stopped being about the institution before the first page is finished.
The Backward-Looking Snapshot
Risk is dynamic, but many risk assessments stay static. They are produced, approved and then revisited only during the next scheduled review unless a significant trigger prompts an earlier update. In the intervening year, the firm launches a product, enters a new market, onboards a category of customer it had never served, or watches a typology emerge that did not exist when the document was written. Yet, none of this reaches the assessment. By the time anyone reads it again, it describes a firm that has moved on. An assessment that is not revisited when the firm's risk profile changes will gradually become less representative of its current risks.
The Score That Means Nothing
The residual-risk calculation is one place where the disconnect between appearance and substance often becomes visible. A firm takes an inherent-risk rating, applies a control-effectiveness adjustment, and produces a residual score. The arithmetic looks rigorous, and the output is reassuringly precise. But if no one can explain how the inherent rating was derived, what evidence supports the control-effectiveness figure, or why the two combine the way they do, the number is decoration. A residual score of 2.4 carries no meaning if the 2.4 was reverse-engineered to land in the medium band the firm was comfortable reporting. Precision is not the same as accuracy, and a spurious decimal place is one of the clearest tells that a risk assessment has become a spreadsheet exercise rather than an act of judgement. A false precision, particularly where the underlying methodology cannot support it, is often a sign that the exercise has become more mathematical than analytical.
One of the most common failure I see is arithmetic dressed up as analysis. A firm multiplies an inherent-risk number by a control score, produces a residual figure, and believes it has assessed risk. It has not. It has produced a number that nobody can derive from first principles and nobody can defend when an examiner asks, calmly, how you arrived at it.
Monika Shah | CAMS, AML/CFT Practitioner, AML Guild
The Document Nobody Uses
The final and most telling sign is disuse. A genuine risk assessment is referred to constantly. It is cited when a new product is scoped, when a customer is escalated, when the monitoring rules are tuned, when the board asks why the compliance budget is what it is. A fictional may only be revisited during periodic reviews or when requested by a third party. If the relationship managers have never seen it, cannot explain how monitoring scenarios reflect the risks identified in the assessment, and if senior management or the board is never engaged on significant changes arising from it, the document is unlikely to be meaningfully influencing the programme. It becomes an artefact produced primarily for inspection, which is precisely where its weaknesses are most likely to be exposed.
Why Examiners See Through It Immediately
Supervisors do not grade the enterprise-wide risk assessment as a piece of writing. They trace it. One of the most important things to understand about how a modern examination treats the document is covered in more detail in our analysis of what regulators are really looking for in an examination. The examiner may pick a high-risk customer segment named in the assessment and ask to see how the firm's due diligence measures reflect the higher risks identified. They pick a monitoring scenario and ask which documented risk it addresses. They read the residual scores and ask for the evidence behind the control-effectiveness ratings. At each step, they are testing a fundamental thing: does the programme the firm operates match the risks the document claims to have assessed?
When the assessment is fiction, the trace often breaks surprisingly quickly. The high-risk segment turns out to receive no differentiated due diligence despite being classified as higher risk. The monitoring rules map to no risk in particular. The control-effectiveness ratings cannot be supported by documented evidence. These weaknesses often become apparent through relatively straightforward testing. It requires them to ask the firm to connect its own document to its own operations, and a fictional document cannot be connected because it was never joined to operations in the first place. An examiner who has read a hundred risk assessments will often recognise the pattern in minutes, and the discussion often extends beyond the document itself. It is about whether the firm understands its business at all.
This is why a weak risk assessment is treated so seriously. It is not a paperwork defect. It may indicate that the firm's risk-based approach has not been effectively implemented. A firm can have adequate policies, functioning systems, and diligent staff and still fail an examination because the document that is meant to connect them to the firm's real risks turns out to describe a different firm entirely.
What the Fiction Costs
The cost of a fictional risk assessment is not the cost of rewriting it. It is the cost of everything that was built on top of it while it was wrong. If the assessment understated a risk, the controls informed by that assessment may not have been proportionate to the actual level of risk, monitoring scenarios may not have been appropriately aligned with the firm's risk profile, and the firm may have been carrying a level of ML/TF risk it had not fully recognised or mitigated. Those weaknesses often become visible at the least convenient time: during an enforcement review, in the aftermath of a suspicious pattern that was not detected, or when a correspondent bank asks a question the firm cannot answer and quietly begins the process of de-risking the relationship.
There is a governance cost as well. When an examination concludes that a firm did not understand its risks, the finding does not stay with the compliance team. It travels to the board and to senior management, whose responsibility for the risk-based approach is explicit in most frameworks, and it raises the personal exposure of the individuals who attested that the programme was sound. The deeper problem, that programmes are too often built to satisfy regulators rather than to stop crime, starts precisely here, with a foundational document produced for show.
Dealing with this in your own business? Put a vetted, CAMS-certified AML Guild expert on it and get hands-on support that holds up to scrutiny. Find your expert at amlguild.com.
What a Non-Fictional Risk Assessment Looks Like
A genuine enterprise-wide risk assessment has four properties that a fictional one lacks, and none of them is about length or presentation. The first is that it is specific to the institution. It names the firm's actual customer types, products, delivery channels, and geographies, in the proportions they actually occur, and it is honest about the segments that carry the most risk rather than the ones that are most comfortable to discuss. The second is that it is current. It is updated when the business changes, not only when the calendar or a questionnaire demands it, and it carries a visible record of what changed and why.
The third property is methodological transparency. Those reviewing the assessment can understand how a rating was reached, what data and judgement fed it, and the factors that could reasonably influence that rating over time. The scoring is a tool for reasoning, not a substitute for it, and where judgement was applied the document says so plainly rather than hiding behind a decimal. The fourth, and the one that ultimately separates fact from fiction, is that it drives decisions. The controls, the monitoring, the due diligence tiers, and the training plan can each be traced back to a risk the assessment identifies, and when the assessment changes, those things change with it. If you want the practical shape of this, our guides on what a good business risk assessment actually looks like in practice and on how to build one that actually drives compliance decisions set it out step by step.
A living risk assessment is one the business argues about. When the business challenges a rating, when the board asks why a customer segment moved from medium to high, that discussion is often a sign the assessment is being actively used. Silence around a risk assessment is not agreement. It may indicate that the document is not being actively used in decision making.
Dipali Vora | CAMS, ACS, AML/CFT Practitioner, AML Guild
How to Tell Whether Your Enterprise-Wide Risk Assessment Is Fiction
A short and honest self-test will usually settle the question faster than a formal review. Ask the following, and answer as an examiner would rather than as the author hopes:
- Can you identify a control whose design or implementation was informed by the risks identified in the enterprise-wide risk assessment?
- Where the firm's products, customers, delivery channels, geographies or risk profile have changed, has the enterprise-wide risk assessment been updated to reflect those changes?
- Can someone outside compliance, a relationship manager or a board member, explain the firm's principal money laundering and terrorist financing risks as identified in the assessment?
- Can you derive how each inherent and residual risk rating was reached, showing the evidence behind the control rating?
- Can you demonstrate how key monitoring scenarios, due diligence measures and other risk controls align with the risks identified in the assessment?
- If the enterprise-wide risk assessment were removed today, would it materially affect the way the firm makes AML/CFT risk-based decisions?
If several of those answers are uncomfortable, the assessment may no longer be fully reflecting the firm's risk profile or informing its compliance programme as effectively as it should. That is not a reason for alarm, because it is the ordinary condition of a great many risk assessments and it is entirely fixable. It is a reason to stop treating the assessment as a deliverable to be produced and start treating it as the reasoning that the rest of the programme depends on.
Frequently Asked Questions
Everything you need to know about the enterprise-wide risk assessment and how AML Guild supports your business.
The enterprise-wide, or business-wide, risk assessment looks at the money laundering and terrorist financing risk of the institution as a whole, across all of its customer types, products, channels, and geographies. A customer risk assessment rates the risk of an individual relationship at onboarding and through its life. The two are connected: the enterprise assessment sets the framework and the risk appetite within which individual customers are rated, and patterns emerging from customer-level ratings feed back into the enterprise view. A firm needs both, and neither substitutes for the other.
A common expectation is at least annually, but the more important trigger is material change. A new product, a new market, a new customer segment, a significant regulatory development, or an emerging typology should each prompt a review, whether or not a year has passed. An assessment that is refreshed only on an annual cycle will always lag the business, and the lag is exactly where undetected risk collects.
Most supervisors do not mandate a single methodology. They expect the approach to be reasonable, documented, and applied consistently, and above all they expect it to produce an assessment that reflects the firm's real risks and drives its controls. This is why methodological transparency matters more than the choice of model: an examiner is far less interested in whether you used a particular scoring scale than in whether you can explain and defend the ratings it produced.
Ownership sits with the compliance function, usually the MLRO, but the assessment cannot be produced by compliance in isolation. It needs input from the business lines that understand the customers and products, and it needs the visible engagement of the board and senior management, whose responsibility for the risk-based approach is set out in most frameworks. An assessment written by one person and seen by no one is fiction by construction, however good that one person is.
- What a Good Business Risk Assessment Actually Looks Like in Practice
- Risk Assessment in Practice: How to Build One That Actually Drives Compliance Decisions
- Most AML Programmes Are Built to Satisfy Regulators, Not to Stop Crime
- What Regulators Are Really Looking For in an AML Examination
- AML Governance That Works: What Boards and Senior Management Actually Need to Do
- Find an AML Guild expert
Work With Pathik Shah Through AML Guild
Pathik Shah and the AML Guild network provide on-demand, CAMS-certified AML/CFT support for regulated businesses, from building and remediating compliance programmes to preparing for regulatory examination and rebuilding an enterprise-wide risk assessment that examiners trust.