A financial crime risk assessment is a documented analysis of where a financial institution is most exposed to money laundering, terrorist financing, fraud, and sanctions violations, used to direct compliance resources toward the highest-risk customers, products, and geographies. Federal law does not yet name it as a standalone obligation, but examiners treat it as the foundation of every anti-money laundering program, and a FinCEN proposed rule would formalize it as a mandate.1Federal Register. Anti-Money Laundering and Countering the Financing of Terrorism Programs Without one, an institution has no rational basis for deciding where to focus its compliance spending, which customers warrant closer scrutiny, or whether its controls actually work.
Is a Risk Assessment Legally Required
The short answer is: not by name, but effectively yes. The FFIEC examination manual states plainly that a BSA/AML risk assessment is “not a specific legal requirement.”2FFIEC BSA/AML InfoBase. FFIEC BSA/AML Risk Assessment What the Bank Secrecy Act does require, under 31 U.S.C. 5318(h), is an AML/CFT program with four components: internal policies and controls, a designated compliance officer, ongoing employee training, and an independent audit function.3Office of the Law Revision Counsel. 31 USC 5318 – Compliance, Exemptions, and Summons Authority Those requirements apply to banks, credit unions, casinos, money services businesses, broker-dealers, mutual funds, insurance companies, and other categories under the BSA umbrella.
The Anti-Money Laundering Act of 2020 amended the BSA to specify that these programs should be “risk-based,” directing more resources toward higher-risk customers and activities.4Financial Crimes Enforcement Network. Fact Sheet – Proposed Rule to Strengthen and Modernize Financial Institution AML/CFT Programs You cannot build a risk-based program without first assessing the risk, and examiners consistently expect a documented assessment as the basis for every other compliance decision. Show up without one, and demonstrating that your controls are reasonably designed becomes very difficult.
FinCEN’s 2024 proposed rule would formalize this by adding a mandatory risk assessment process to the program rules for banks, casinos, money services businesses, broker-dealers, and several other institution types.1Federal Register. Anti-Money Laundering and Countering the Financing of Terrorism Programs As of early 2026 the rule has not been finalized, but its direction is clear.
What the Assessment Has to Cover
Under the proposed FinCEN rule, an institution’s risk assessment process would need to consider the government-wide AML/CFT Priorities alongside the institution’s own business activities, customer base, geographic footprint, and the suspicious activity reports it has filed.1Federal Register. Anti-Money Laundering and Countering the Financing of Terrorism Programs FinCEN issued the first set of Priorities in June 2021, identifying eight threat areas: corruption, cybercrime (including virtual currency considerations), domestic and foreign terrorist financing, fraud, transnational criminal organization activity, drug trafficking, human trafficking and smuggling, and proliferation financing.5Financial Crimes Enforcement Network. AML/CFT Priorities The AML Act directs FinCEN to update the Priorities at least every four years. Even before the rule is finalized, aligning your risk assessment with them is a practical necessity. Examiners are already looking at how institutions account for them.
Collecting the Data
An assessment is only as good as the data behind it. Collection starts with customer due diligence records and extends to product usage, transaction patterns, and geographic exposure.
Customer Due Diligence
CDD records form the backbone. FinCEN’s CDD Rule requires covered institutions to verify customer identities, identify the beneficial owners of legal entity customers, understand the nature and purpose of each relationship, and conduct ongoing monitoring.6FinCEN.gov. Information on Complying with the Customer Due Diligence (CDD) Final Rule Compliance teams pull transaction history to establish volume and frequency baselines, typically covering at least the previous twelve months, and extract data from customer relationship management systems and internal ledgers. Outdated records produce inaccurate risk scores, so a validation step normally runs before anything moves into scoring.
Geographic Risk
Institutions cross-reference their customer and counterparty data against jurisdictions flagged for weak anti-money-laundering controls. The Financial Action Task Force maintains two public lists, updated three times a year, identifying countries with strategic deficiencies in their AML/CFT regimes.7Financial Action Task Force. Black and Grey Lists Customers or transactions tied to those jurisdictions receive elevated scores. Domestic geography matters too: regions with heavy cash-economy activity or proximity to international borders can raise the profile for certain product lines.
Products and Services
Not all offerings carry equal risk. Products that move funds quickly or offer a degree of anonymity get more scrutiny. Wire transfers, correspondent banking relationships, private banking accounts, and prepaid access products are among the most commonly flagged.2FFIEC BSA/AML InfoBase. FFIEC BSA/AML Risk Assessment Document the volume and dollar value flowing through each product line so scoring works from concrete numbers.
Scoring Inherent Risk
Once the data is assembled, the institution applies weights to produce an inherent risk score, meaning the level of risk that exists before accounting for any internal controls. The FFIEC manual does not prescribe a specific methodology or format; bank management designs the approach.2FFIEC BSA/AML InfoBase. FFIEC BSA/AML Risk Assessment
Most institutions assign numerical values to individual risk factors and then aggregate them into low, medium, and high tiers. A customer running a cash-intensive business typically scores higher than a salaried professional with direct-deposit paychecks. A foreign correspondent banking relationship might receive a weight of 7 or 8 on a 10-point scale, while a standard domestic retail account might land at a 2. The scoring logic should be documented clearly enough that an examiner can trace how any individual score was derived.
Some institutions use specialized compliance software to automate scoring. Others run the process manually against a rubric that defines what moves a customer, product, or geography from one risk tier to another. Either approach works, as long as the methodology is consistent and defensible. The output is an inherent risk profile across all business lines, showing where exposure would sit if the institution had no compliance controls at all.
Evaluating Controls and Residual Risk
Inherent risk is only half the picture. The next step evaluates how effectively internal controls mitigate it. Controls generally fall into categories like transaction monitoring systems, employee training programs, customer screening procedures, and escalation protocols.2FFIEC BSA/AML InfoBase. FFIEC BSA/AML Risk Assessment Document what each control is designed to catch, how it performs in practice, and where the gaps sit.
Residual risk is what remains after subtracting the effect of those controls from the inherent risk. There is no single mandated formula, and the FFIEC manual intentionally leaves the methodology to management discretion. What matters is that the institution can articulate the relationship: high inherent risk paired with strong, well-tested controls should produce moderate or low residual risk. High inherent risk paired with weak or untested controls means residual risk is still high, and that gap should trigger immediate attention.
This is where most assessments prove their value or fall apart. An institution that documents inherent risk beautifully but hand-waves about control effectiveness is building on sand. Examiners push on exactly this connection, asking for evidence that each control has been tested and that the residual rating is justified by actual performance data rather than assumptions.
Sanctions Risk Belongs in the Same Assessment
The exercise should not focus exclusively on money laundering. The Office of Foreign Assets Control administers U.S. sanctions programs, and violations can result in penalties even when the institution had no knowledge of the sanctioned party’s status. OFAC’s compliance framework identifies five essential components for a sanctions program: management commitment, risk assessment, internal controls, testing and auditing, and training.8U.S. Department of the Treasury. A Framework for OFAC Compliance Commitments
A sanctions risk assessment evaluates exposure based on customers, products, geographic reach, supply chain, and transaction patterns. OFAC expects institutions to screen customer databases against the Specially Designated Nationals and Blocked Persons lists. Those lists update on an unpredictable schedule, sometimes multiple times in a single day, so periodic manual checks leave real exposure open. Most institutions automate screening against every new account, transaction, or list update.8U.S. Department of the Treasury. A Framework for OFAC Compliance Commitments
Integrating sanctions risk into the broader financial crime risk assessment avoids duplication and gives leadership a complete picture. A customer who scores low for money laundering risk but operates in a comprehensively sanctioned jurisdiction still represents significant institutional exposure.
Board Approval and Independent Testing
The AML program itself must be approved by the institution’s board of directors.9Board of Governors of the Federal Reserve System. 31 CFR 1020.210 – Anti-Money Laundering Program Requirements for Banks In practice, the risk assessment that drives every decision in that program needs to reach the board as well. The FFIEC manual recommends sharing it with all business lines, the board, management, and appropriate staff.2FFIEC BSA/AML InfoBase. FFIEC BSA/AML Risk Assessment The chief compliance officer typically walks the board through concentrations of high-risk activity, material changes since the last assessment, and any gaps between inherent risk and control effectiveness. That sign-off creates a record that leadership was informed and either accepted or acted on the exposure.
Independent testing is one of the four required program components.3Office of the Law Revision Counsel. 31 USC 5318 – Compliance, Exemptions, and Summons Authority Testing can be performed by qualified internal staff outside the compliance function or by an outside party. Examiners evaluate the tester’s audit experience, professional credentials such as ACAMS certification, and familiarity with the institution’s specific AML systems.
The FFIEC examination manual recommends testing every 12 to 18 months, though institutions with elevated risk profiles, recent acquisitions, or prior enforcement actions may need a shorter cycle. Testing should cover the risk assessment methodology itself, not just the outputs. Are the risk weights reasonable? Do the scores reflect actual activity? Have material changes in the business been captured? A test that merely confirms the paperwork exists without probing the substance behind it adds little value.
How Often to Update
No regulation sets a fixed schedule.2FFIEC BSA/AML InfoBase. FFIEC BSA/AML Risk Assessment Most institutions refresh annually, and examiners generally expect at least that frequency. The more important trigger is material change: a new product launch, expansion into a new geography, a significant shift in customer demographics, a merger or acquisition, or a spike in SAR filings should all prompt reassessment outside the regular cycle.
FinCEN’s proposed rule would require institutions to review and update their risk assessments “at a minimum, when there are material changes to their ML/TF risks.”4Financial Crimes Enforcement Network. Fact Sheet – Proposed Rule to Strengthen and Modernize Financial Institution AML/CFT Programs Retain prior versions. Examiners will want to see how the institution’s risk profile has evolved, and BSA record retention rules require keeping supporting AML documentation for five years.10FFIEC BSA/AML InfoBase. Appendix P – BSA Record Retention Requirements
What Noncompliance Costs
Consequences for BSA violations run on two tracks: civil and criminal.
On the civil side, a financial institution that willfully violates the BSA’s program, recordkeeping, or reporting requirements faces a penalty of up to the greater of $100,000 or $25,000 per violation. A pattern of negligent violations can trigger an additional penalty of up to $50,000. Violations involving international counter-money-laundering provisions carry a penalty of between two times the transaction amount and $1,000,000.11Office of the Law Revision Counsel. 31 USC 5321 – Civil Penalties Because penalties accrue per violation and can stack across transactions, offices, and days, total enforcement actions against a single institution regularly reach into the tens of millions.
Criminal penalties for willful violations include fines up to $250,000 and imprisonment up to five years. When the violation occurs alongside another federal crime or as part of a pattern of illegal activity exceeding $100,000 in a twelve-month period, those caps double to $500,000 and ten years. The AML Act of 2020 added a further layer: anyone convicted of a BSA violation must forfeit the profits gained from the violation, and individual officers or employees must repay any bonus received during the year the violation occurred or the following year.12Office of the Law Revision Counsel. 31 USC 5322 – Criminal Penalties
These penalties apply to the institution and to individuals. Compliance officers, directors, and other employees can be personally liable for civil money penalties and criminal prosecution when they bear responsibility for the failure. The pattern in FinCEN’s recent enforcement actions is consistent: regulators pursue both the institution and the people who let the program deteriorate.