Youverify
  • Developers
Login

Subscribe to our newsletter

Subscribe to our weekly newsletter for expert insights, regulatory updates, and actionable tips to optimize your compliance strategy.

By subscribing, you'll receive updates from Youverify.

Solution

    Customer OnboardingFraud InsightsTransaction MonitoringRegulatory ReportingVyra AIPricing

Industry

    Commercial banksFintech & PaymentsGamingGig WorkersGovernment

Company

    About UsCompliance CertificationsPress and MediaPartnersCareersContact Us

Resources

    BlogsGlossaryDevelopersIndustry ReportsData SourcesFAQsCountry CoverageAI Governance

Legal

    Privacy PolicyTerms of UseCookies PolicyPAIAInformation Security PolicyGDPR Compliance StatementResponsible AI

    Customer OnboardingFraud InsightsTransaction MonitoringRegulatory ReportingVyra AIPricing

youverify-logo

©2026 Copyright. All Rights Reserved

How to Conduct an AML Risk Assessment That Survives Examination
Anti-Money Laundering (AML)

How to Conduct an AML Risk Assessment That Survives Examination

ByTemitope Lawal
September 3, 2026•5mins Read

Key Takeaways

  • An AML risk assessment is the document that explains where your institution's money laundering risk actually sits, and it is the thing every other control is supposed to be built on.
  • Most assessments fail review not because the risk was misjudged, but because nothing in the document connects the risk identified to the control applied.
  • Inherent risk minus control effectiveness gives you residual risk. That subtraction is the whole exercise, and it is the step most assessments skip.
  • The FFIEC states there are no required risk categories, and no requirement to update on a continuous or specified periodic basis. The annual review most teams treat as mandatory is convention, not rule.
  • A risk assessment that identifies a high-risk area and changes nothing about how that area is monitored is not a risk assessment. It is a description.

An AML risk assessment is a documented analysis of where your institution is exposed to money laundering and terrorist financing, how well your existing controls address that exposure, and what risk remains after those controls are applied. It covers your products, services, customers and geographies, and it is the foundation the rest of your compliance programme is built on.

 

Here is the moment it matters.

 

An examiner sits down and asks to see your risk assessment. You hand over a document. They read it, then ask one question: you rated cross-border payments as high risk, so what did you do differently because of that?

 

That question ends more examinations badly than any scoring error. Not because the institution assessed the risk wrongly, but because nothing downstream changed when it did. The rating sat in a document, and the monitoring rules, the due diligence thresholds and the resourcing carried on exactly as before.

 

This guide covers how to build an assessment where that question has an answer.

 

What Is an AML Risk Assessment?

An AML risk assessment identifies your money laundering and terrorist financing exposure, evaluates the controls you have in place against it, and records what remains.

It operates at the level of the institution, not the customer.

 

That distinction trips people up, so it is worth stating plainly. Your enterprise-wide AML risk assessment asks "where is this business exposed?" Your customer risk rating model asks "how risky is this particular person?" The first sets the framework. The second applies it, one customer at a time.

 

The requirement comes from Recommendation 1 of the Financial Action Task Force, which obliges countries and institutions to identify and assess their money laundering risks and apply resources proportionately. Almost every national regime, Nigeria's included, is a local expression of that idea.

 

The FFIEC BSA/AML Examination Manual describes the process in two steps: identify the specific risk categories relevant to your operations, then analyse those categories to develop appropriate internal controls.

Note the end of that sentence. The output of a risk assessment is not a rating. It is a control decision.

 

Why Do Most AML Risk Assessments Fail Review?

 

There are 4 things that accounts for AML risk assessment failure.

 

1. The assessment describes the industry rather than the institution:

Pages on money laundering typologies in general, with almost nothing about this bank, its actual customer base, its actual corridors. An examiner can tell within two minutes.

 

2. Controls are assumed to work:

The document lists a control and treats listing it as evidence it is effective. A transaction monitoring system that generates 400 alerts a week and closes 380 of them without meaningful review is not the control the assessment claims it is.

 

3. There is no residual risk:

Inherent risk gets scored, controls get described, and the two are never subtracted. Without that step the assessment cannot tell you where to spend money, which is the only reason to do it.

 

4. Nothing changed:

This is the fatal one. The assessment identifies a high-risk area, and the monitoring rules, thresholds, review frequency and staffing for that area are identical to the month before.

The common thread is that each failure breaks the link between analysis and action. Which tells you what the method has to protect.

 

How Do You Conduct an AML Risk Assessment?

 

There are Five steps to conducting an AML risk assessment. Each one produces something the next step needs, and the last one is where the value is.

 

Step 1: Define the Scope and Choose Your Risk Categories

Decide what the assessment covers: which entities, which business lines, which jurisdictions, and the period it applies to.

Then choose your risk categories. The conventional four are customers, products and services, geographies, and delivery channels. They are a reasonable starting point, and they are a starting point rather than a rule.

The FFIEC is explicit that there are no required risk categories, that they are bank-specific, and that they vary with the institution's size and complexity. So a Nigerian payments company should not be assessing itself against a category list built for a US community bank with a branch network. If agent networks, mobile money corridors or merchant acquiring are where your exposure lives, those are categories in their own right.

Under each category, list what you actually have. Not product types in the abstract, but your products, your corridors, your customer segments, with volumes attached.

 

Step 2: Score Inherent Risk Before Controls

Inherent risk is the exposure that exists before you apply any control. It is the risk of the business you are in.

Score each item on likelihood and impact, using data rather than impression. Transaction volume and value, customer counts by segment, corridor exposure, the proportion of cash or anonymous funding, how many customers are politically exposed persons, how many sit in higher-risk jurisdictions.

Two disciplines make this defensible.

 

i. Use a consistent scale and write down what each level means. "High" has to mean something specific and repeatable, or two people assessing the same product will score it differently.

 

ii.And resist the urge to score low because you have good controls. That is the next step. Mixing the two is the most common technical error in the exercise, and it hides your real exposure by crediting controls twice.

 

Step 3: Assess Control Effectiveness Honestly

Now assess what your controls actually do, item by item. Not whether the control exists. Whether it works.

The honest questions are uncomfortable ones. Does the monitoring rule covering this product actually fire, and when it fires does anyone act? Are screening lists updated on the frequency you claim? What proportion of enhanced due diligence files reviewed last quarter were complete? Does the training your staff receive cover the typology you just rated high?

Where you have testing results, audit findings or quality assurance data, use them. A control rated effective on the strength of somebody's confidence is the weakest link in the document, and it is the first thing an examiner pulls on.

Rate each control on a stated scale, and record the evidence supporting the rating.

 

Step 4: Calculate Residual Risk

Residual risk is what remains after controls are applied to inherent risk. Inherent risk, reduced by control effectiveness, equals residual risk.

Present it as an AML risk assessment matrix, so the relationship is visible on one page:

Risk areaInherent riskControl effectivenessResidual risk
Cross-border paymentsHighModerateHigh
Domestic retail accountsMediumStrongLow
Agent network cash-inHighWeakHigh
Corporate onboardingMediumModerateMedium
AML Risk Assessment Matrix

 

The rows that matter are the ones where residual risk stays high. Those are the only outputs of this whole exercise that require a decision, and this is where the assessment starts being useful rather than descriptive.

Note that inherent risk and residual risk can both be high. That is not a failure. Being in a risky business with good controls still leaves risk, and saying so is more credible than a document where every row resolves to low.

 

Step 5: Decide What Changes

Every remaining high residual risk gets one of three responses, and all three are legitimate: strengthen the control, reduce the exposure, or accept it with senior management sign-off and a stated reason.

What is not legitimate is a fourth option, which is to note it and move on.

This is where the assessment stops being a document and becomes a control. Concretely, the outputs look like changed monitoring thresholds for the products you rated high, revised customer risk weightings, additional screening coverage, more frequent review cycles for a segment, or headcount moved to where the risk is.

Write each decision down with an owner and a date. That list is the answer to the examiner's question at the top of this article.

 

What Does an AML Risk Assessment Document Look Like?

Assessments are frequently rejected on structure rather than substance. This is the arrangement that reads well to a reviewer:

  1. Scope and methodology. What is covered, what scales were used, what each rating level means.
  2. Data sources. What the scoring drew on, and as at what date.
  3. Risk categories and rationale. What you assessed and why those categories.
  4. Inherent risk analysis. Scores with supporting data.
  5. Control environment. Controls mapped to risks, with effectiveness ratings and evidence.
  6. Residual risk matrix. The one-page table.
  7. Action register. Every high residual risk, its decision, owner and date.
  8. Governance. Who prepared it, who reviewed it, who approved it, on what dates.
  9. Appendices. Underlying data.

 

Two things reviewers look for immediately. Section 7, because it shows the assessment produced decisions. And section 8, because an assessment nobody senior approved carries no weight.

If you are working from an AML risk assessment template, check it contains sections 5, 6 and 7. Many circulating templates cover inherent risk and stop.

 

How Often Should You Update Your AML Risk Assessment?

Most guidance says annually. It is worth knowing that this is convention rather than requirement.

The FFIEC states plainly that there is no requirement to update the BSA/AML risk assessment on a continuous or specified periodic basis. What it expects is that the assessment is updated to reflect changes in products, services, customers and geographic locations, and that it remains current.

That is a more useful standard than a calendar date, because it makes the trigger a change in the business rather than a month in the year. In practice that means refreshing when you launch a product, enter a market, acquire a portfolio, change a delivery channel, or when a national risk assessment or regulator directive changes the risk picture around you.

An annual cycle is still sensible as a backstop. The distinction worth holding onto is that a risk assessment dated eleven months ago is not automatically compliant, and one dated fourteen months ago is not automatically deficient. What matters is whether it reflects the business as it is now.

 

What Do Nigerian Regulators Expect in an AML Risk Assessment?

Nigerian institutions work from the Money Laundering (Prevention and Prohibition) Act 2022 and the CBN AML/CFT/CPF Regulations 2022, both of which require a risk-based approach with an assessment underneath it.

Three points specific to this market are worth building in.

 

1. Use the national risk assessment. Nigeria's NRA and the sector risk assessments identify where the country's exposure concentrates. An institutional assessment that ignores what your own national assessment found is difficult to defend, and referencing it demonstrates the assessment was informed rather than generic.

 

2. Domestic PEP exposure is a genuine category here. Frameworks imported from markets with different political and corruption dynamics tend to under-weight it. If your category list came from a global template, this is the line most likely to be wrong for Nigeria.

 

3. Delisting did not lower the bar. Nigeria left the FATF grey list in October 2025, and supervisory expectations have tightened rather than relaxed since. We covered what that means in Nigeria is off the FATF grey list. A risk assessment that lowers country risk ratings on the strength of the delisting alone is making an argument it will have to defend.

 

How Youverify Makes Your Risk Assessment Defensible

Everything above is work. The question is how much of it your systems do for you and how much your team does by hand at eleven at night before a board deadline.

 

Youverify is built for the two steps where assessments break.

Step 2 and 3: the evidence arrives as a report, not a project.

Inherent risk and control effectiveness both need numbers you already own but probably cannot reach quickly: transaction volumes by corridor and product, customer distribution across risk bands, how many politically exposed persons and high-risk-jurisdiction customers you hold, alert volumes by rule, escalation rates, suspicious transaction report counts and filing times.

 

In most institutions those numbers live in four systems and a spreadsheet, so every assessment cycle starts with three weeks of manual extraction and ends with figures that were already a month old when the document was signed. Youverify holds onboarding, screening, monitoring and regulatory reporting on one platform, so the evidence base for your assessment is a query rather than a project, current as at the day you run it.

That single change moves your assessment from "we believe this control is effective" to "here is the data showing what it caught."

Step 5: the decision actually happens, and you can prove when.

This is where most programmes lose the examiner. You rated agent network cash-in as high residual risk. What changed?

 

With Youverify, you describe the risk in plain language and Vyra, our AI compliance agent, builds the detection logic for it. Before anything goes live it is backtested against your own historical transactions, and the backtest is a gate: nothing deploys until it passes on your real traffic. You see the precision before you commit, rather than discovering three months later that a rule you wrote in a risk workshop is drowning your analysts in false positives.

 

Every version is recorded. The rule, the date it changed, the risk it was built for, the conditions it evaluates, and every analyst decision made on the alerts it raised.

That record is the answer to the examiner's question. Not a paragraph explaining your intentions, but the rule, the date, the backtest result and what it has caught since. Youverify's transaction monitoring turns an action register from a list of promises into an audit trail.

 

Institutions across Nigeria, the UK and the wider African market use Youverify to run compliance programmes their regulators can inspect, with identity verification across 145+ jurisdictions, continuous PEP, sanctions and adverse media screening, real-time monitoring, and suspicious transaction reports generated in the format your financial intelligence unit expects.

 

Your next assessment is coming whether the evidence is ready or not.

Book a demo with our compliance experts and we will show you exactly what evidence Youverify would produce for each step of it, using your own risk categories.

 

FAQs

Frequently Asked Questions

Related Articles

Why is Negative News Screening (NNS) Important?
Anti-Money Laundering (AML)
Lola, Edited by Emmanuel Agwu•April 25, 2023

Why is Negative News Screening (NNS) Important?

Read More
What is a Sanctions List?
Anti-Money Laundering (AML)
Priscilla, Edited by Emmanuel Agwu•April 28, 2023

What is a Sanctions List?

Read More
RegTech's Influence On Regulatory Policy and Reform
Anti-Money Laundering (AML)
Emmanuel Agwu•February 14, 2024

RegTech's Influence On Regulatory Policy and Reform

Read More