Risk assessment should shape the Financial Crime control architecture.
A Financial Crime risk assessment is most useful when it changes decisions: what is in scope, which customers and activities receive greater scrutiny, what data and controls are required, where resources are concentrated, and what management action follows. FCRisk treats the assessment as an operating input to control design and assurance — not as a standalone compliance document.
Identify, understand and assess risk — then show what changed because of it.
The FCA says a thorough understanding of Financial Crime risk is key to proportionate and effective systems and controls. Its Financial Crime Guide expects business-wide risk assessments to be comprehensive, draw on relevant information and be proportionate to the nature, scale and complexity of the firm.
UK Money Laundering Regulations require relevant persons to identify and assess money-laundering and terrorist-financing risks, taking account of customers, geography, products or services, transactions and delivery channels, and to establish policies, controls and procedures to mitigate and manage the risks identified.
Primary source — FCA Financial Crime Guide ↗ · Primary source — Money Laundering Regulations 2017, regulations 18–19 ↗
A risk assessment without control consequences is incomplete as an operating artefact.
The useful question is not only whether a BWRA or customer risk assessment exists. It is whether the conclusions are translated into control scope, customer treatment, monitoring and screening design, data requirements, operational capacity, governance decisions and tracked actions.
The assessment should connect to the parts of the control chain that manage the risk.
Risk & Scope
What Financial Crime risks arise from customers, products, services, channels, legal entities and jurisdictions — and what is explicitly in or out of scope?
Customer & Population
How do business-wide conclusions translate into customer risk assessment, higher-risk treatment and the populations subject to monitoring, screening or review?
Data & Context
Which information supports the assessment, how reliable is it, and can downstream controls access the customer and transaction context implied by the risk?
Control Design
Do KYC, screening, transaction monitoring, investigation and escalation controls map to the material risks and typologies identified?
Operation & Capacity
Are people, technology and operating capacity sufficient for the size of the business, risk profile and rate of growth or change?
Governance & Action
Who challenges the assessment, what decisions and actions result, how are they tracked, and what evidence shows that controls remain effective?
The quality question is increasingly about evidence, linkage and action.
In its November 2025 multi-firm review of BWRA and customer risk assessment processes, the FCA highlighted weaknesses including assessments that were solely qualitative, unclear methods for identifying and assessing inherent risk, conclusions about low risk or control effectiveness without appropriate evidence, weak linkage between assessments and decision-making, limited testing, static approaches and insufficient documented senior challenge.
The same review also identifies good-practice characteristics such as documented methodologies, regular or triggered updates, joined-up BWRA and customer-risk assessments, senior oversight and challenge, and actions that flow from the assessment into wider business decisions.
Primary source — FCA Risk assessment processes and controls in firms: our findings ↗
- What material decisions changed because of the latest risk assessment?
- Can the firm explain how inherent risk, control effectiveness and residual risk are distinguished and evidenced?
- How are BWRA conclusions reflected in customer risk assessment and control treatment?
- Which actions were raised, who owns them and how is completion tested?
- What triggers reassessment when products, technology, geography, regulation or threat patterns change?
- Can senior management evidence challenge, approval and follow-through?
The method should be proportionate to the business and defensible in evidence.
FCRisk does not publish a generic spreadsheet and present it as a universal Financial Crime risk-assessment solution. The appropriate methodology depends on the legal and regulatory perimeter, nature and scale of the business, products, customers, geography, transaction profile and control architecture.
What can be tested consistently is whether the method is clear, the evidence is sufficient, the conclusions are traceable, the assessment remains current, and its outputs actually influence the controls that manage Financial Crime risk.
Three connected review questions
Risk assessment
Do we understand and evidence the risks to which the business is exposed?
Control effectiveness
Can we demonstrate that the controls addressing those risks are appropriately designed and operating effectively?
Remediation
Where weaknesses exist, can we show that the underlying risk is removed and remains controlled?
Move from risk assessment to evidence of control effectiveness.
Use a focused Financial Crime Diagnostic to identify material gaps, or the Control Effectiveness Diagnostic where the key question is whether the organisation can evidence that its control architecture actually works.