Fraud and Financial Crime · Session Seven
The Financial Crime Risk Assessment
The single document on which every other part of the programme depends. What supervisors expect. Where assessments most often fall short. The practical steps to build one that does the job.
Disclaimer
This course is provided for general information and education only. It is not legal advice. Legislation, rules and regulatory guidance change, sometimes quickly. Readers should confirm the current position and obtain jurisdiction-specific professional advice where needed. The views and experience expressed are Russel Fielding's own and do not represent any employer or client organisation.
Session Seven: The Financial Crime Risk Assessment
The financial crime risk assessment is the document on which the rest of the programme depends. It is also one of the first documents a supervisor will use to test whether the programme is real.
A working risk assessment is not a compliance artefact. It is the foundation for deciding where the organisation is exposed, which controls are needed, and where the programme should focus its time and resource. Done well, it gives a clear basis for decisions. Done badly, it weakens the rest of the programme.
This session covers what the risk assessment has to do, what supervisors and prosecutors expect to see, where assessments most often fall short in practice, and the steps that produce a credible, usable, defensible result.
Who this session is for. Compliance officers, MLROs, financial crime leads, senior managers, board members and risk leaders responsible for designing or approving the financial crime risk assessment. Also for internal audit and second line teams who test the assessment, and for transformation teams remediating it.
Why the risk assessment matters
Risk assessment runs through every major part of the framework. The Ministry of Justice guidance under section 9 of the Bribery Act 2010 includes it as one of the six principles. HMRC guidance on the corporate offences of failure to prevent the criminal facilitation of tax evasion does the same. The Home Office guidance on failure to prevent fraud does the same. For anti-money laundering purposes, regulation 18 of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 requires a firm-wide risk assessment. FCA guidance also expects firms to understand and assess their financial crime risk.
The reason for this consistency is structural. Without a risk assessment, the rest of the programme has nothing to calibrate against. Proportionate procedures cannot be designed if the risks are not understood. Due diligence cannot be scaled to risk if the risk has not been assessed. Training cannot be targeted to the right people in the right ways if the risk profile of those roles has not been mapped. Monitoring cannot identify exceptions if the baseline has not been defined.
The risk assessment is also a document prosecutors may examine closely. In any argument about adequate procedures or reasonable prevention procedures, the obvious question is how the organisation identified the risk in issue. If the assessment did not identify it, the position is weaker. If it did identify it but the controls did not respond to it, the position is weaker still. That is why the assessment matters so much.
What a working risk assessment has to do
A working financial crime risk assessment has to do five things.
| Inherent risk | Identify and assess the financial crime risks the organisation is exposed to before controls. Cover all four offence areas: fraud, bribery and corruption, market abuse where in scope, and money laundering and terrorist financing where in scope. Cover the relevant failure to prevent obligations. |
| Control environment | Identify the controls the organisation has in place to address each risk: governance, policies, procedures, due diligence, training, monitoring, audit. Assess design effectiveness and operating effectiveness. |
| Residual risk | Determine the level of risk that remains after controls. Express it in a way that can be used to drive decisions: heat maps, scoring, narrative ratings, or another method that works for the organisation, provided it is consistent and meaningful. |
| Action and ownership | Identify the gaps between residual risk and risk appetite. Allocate the work needed to close those gaps to named owners with defined timelines. |
| Review trigger | Set the conditions under which the assessment will be revisited: scheduled review dates, material business changes (new product, new market, acquisition), and external triggers (new offences, new guidance, supervisory findings). |
The four offence areas as risk categories
A consolidated financial crime risk assessment should cover four offence areas. The risks within each area need to be considered separately, even where the controls that address them overlap. This is the point at which the integrated programme design from Session Five becomes concrete.
Fraud
Fraud risk has two distinct dimensions in a modern programme. First, the risk that the organisation is defrauded: by employees, by customers, by third parties, by sophisticated external actors. Second, the risk that fraud is committed by or through the organisation: by an associated person, in a way that may expose an in-scope large organisation to corporate liability under section 199 of the Economic Crime and Corporate Transparency Act 2023. Both dimensions matter. Only one of them is what the failure to prevent regime is interested in.
Useful inputs to fraud risk assessment include the categories of fraud the organisation has actually experienced over the previous several years, sector typologies, customer and product mix, geographic footprint, and the way third parties interact with the business. The assessment should be specific enough to identify the fraud typologies to which the organisation is most exposed, rather than describing all fraud risks at the same level of generality.
Bribery and corruption
Bribery and corruption risk turns primarily on geographic footprint, customer mix, the role of third parties, the gifts and hospitality profile, and the public-sector dimension of the business. An organisation that does business only in the UK with private-sector counterparties faces a materially different risk profile from one that operates in markets with high corruption risk through agent networks engaging public officials.
The Ministry of Justice guidance, FCA guidance on bribery and corruption controls, and recognised country risk indices are all useful inputs. The assessment should produce a clear view of which markets, customers, third parties and business activities present the highest bribery risk, and the controls that address each.
Market abuse
Market abuse risk is relevant only to organisations within scope of UK MAR or any applicable cryptoasset market abuse regime. For those organisations, the risk assessment should cover the inside information flows in the business, the populations who handle inside information, the products that present the highest manipulation risk, the wall crossing process, and the suspicious transaction and order reporting infrastructure.
FCA Market Watch is the most useful single source for market abuse typologies. The FCA's published enforcement decisions are also a useful indicator of where supervisors' attention currently sits.
Money laundering and terrorist financing
Money laundering and terrorist financing risk applies to firms within scope of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017. This area is covered in detail in the AML Compliance course, particularly the session on the risk-based approach. For a regulated firm, the wider financial crime risk assessment should align with the firm-wide AML/CFT risk assessment required by regulation 18, using shared inputs and a consistent methodology. Keeping the AML/CFT risk assessment as a separate document may be sensible. Treating it as a separate exercise usually is not.
The HM Treasury National Risk Assessment is the key external input for UK firms.
The risk dimensions
Within each offence area, the assessment should examine risk across several common dimensions. The dimensions are similar across offence types, although the weight given to each will differ.
| Customer or counterparty | Who the organisation deals with. Customer mix, counterparty mix, beneficial ownership, PEP exposure, sanctions exposure, sector concentration. |
| Product or service | What the organisation does. Products and services offered, their inherent financial crime characteristics, their attractiveness to bad actors. |
| Geographic | Where the organisation operates. Country risk for AML, bribery, sanctions. Source and destination of funds. Location of associated persons. |
| Channel | How the organisation interacts. Face to face, remote, digital, agent, broker, intermediary. Channels carry different risks. |
| Third party | Who acts for or on behalf of the organisation. Associated persons under the failure to prevent regimes. Suppliers, agents, consultants, intermediaries, partners. |
| Internal | What the organisation looks like inside. Employee population, role mix, geographic distribution, change activity, integration activity. |
In a consolidated assessment, each risk should be located against these dimensions. The result is a clear view of where the highest residual risks sit, which is what drives the rest of the programme.
What supervisors and prosecutors expect
Three things consistently appear in supervisory feedback and published guidance on what an adequate risk assessment looks like.
First, the assessment must be specific to the organisation. A risk assessment that could belong to any firm in the sector is unlikely to be good enough for the firm using it. What matters is whether it engages with the particular features of the business, its markets, its products and its people.
Second, the assessment must be live. It must be revisited when the business changes, when new offences come into force, when supervisory findings or external incidents indicate previously unrecognised risk. A risk assessment that has not been refreshed despite business change and regulatory change will struggle to be defended as adequate.
Third, the assessment must drive decisions. The real test is whether it is used. If controls are not aligned to it, if enhanced due diligence is not applied where it indicates higher risk, and if training is not targeted to the higher-risk populations it identifies, the assessment is not doing its job.
Where assessments most often fall short
Financial crime risk assessments most often fall short in three ways.
The first is that the assessment is treated as a document rather than a tool. It is produced, refreshed each year by changing the date, and then left to one side. Controls do not align with it. Enhanced due diligence is not applied consistently where it points to higher risk. The assessment and the programme drift apart. That usually becomes obvious quite quickly in a review meeting.
The second is that the assessment is generic. It uses sector standard risk categories, sector standard ratings, sector standard wording. There is no evidence that the organisation has done the work to identify the specific characteristics of its own business. The risk register reads like an industry briefing rather than an assessment of this firm. A defence built on this risk assessment would be difficult to sustain under close scrutiny.
The third is that the assessment is incomplete. It covers AML thoroughly because the 2017 Regulations require it. It says less about bribery, less still about fraud, and nothing about market abuse or other offence categories. The failure to prevent fraud offence and the senior manager attribution reform in section 196 of the Economic Crime and Corporate Transparency Act 2023 have increased the importance of a wider and more current assessment. Firms whose assessments have not caught up are exposed.
Building a working risk assessment
A working risk assessment is a planned exercise, not an annual ritual. The steps that produce a credible result are summarised below.
Define the scope deliberately
Before any analysis starts, define what the assessment covers. The four offence areas. The legal entities within scope. The geographic footprint. The business lines. The associated persons. The reporting period. Scope creep and scope vagueness account for a substantial proportion of weak risk assessments.
Gather inputs from inside the business
The single most important input is what people inside the business actually see. Interviews with business heads, sales teams, operations, finance, legal, HR, technology and audit will produce a richer picture than any external source. Document the conversations. Use what they tell you. The risk assessment should reflect how the business actually works, not how it is supposed to work on the org chart.
Map the inputs from outside
National risk assessments, supervisory communications, enforcement outcomes, sector typologies, public failures in peer firms, and academic and practitioner literature all add depth. The assessment is stronger if it can show that external signals were considered, not just internal anecdote.
Apply a consistent methodology
Use a single methodology across all four offence areas, with shared rating definitions, shared dimensions and a shared treatment of inherent versus residual risk. Inconsistent methodology between offence types makes the assessment harder to use, harder to govern and harder to defend.
Get senior management engagement and board approval
The risk assessment is not a compliance document. It is a senior management and board document. Top-level commitment requires that senior management has actually engaged with what the assessment says, challenged the conclusions where appropriate, and approved the resulting programme. Board approval is not a formality. It is the evidence that the leadership has accepted accountability for the risk profile and the response.
Document the result
Records are the evidence. The risk assessment should be a documented output, not a conversation. It should record the methodology, the inputs, the analysis, the conclusions, the actions and the ownership. It should be capable of being read and understood by someone who was not present in the meeting that produced it.
Refresh on a defined cadence
Set the rhythm. An annual full refresh is conventional but not always sufficient. Material change triggers, such as a new offence in force, new market entry, an acquisition, a new product, a supervisory finding or an external incident, should produce targeted refreshes. The risk assessment is a living document, not a calendar exercise.
Jurisdiction equivalents
New Zealand
The Anti-Money Laundering and Countering Financing of Terrorism Act 2009 requires reporting entities to undertake a risk assessment of money laundering and terrorist financing risk under section 58. Current supervisory material from the Department of Internal Affairs sets out what that assessment should cover. For organisations exposed to bribery, corruption, fraud or other financial crime risks, a broader financial crime risk assessment is good practice, even though New Zealand does not mirror the UK failure to prevent framework across those offence categories.
Australia
The Anti-Money Laundering and Counter-Terrorism Financing Act 2006 and the Anti-Money Laundering and Counter-Terrorism Financing Rules require reporting entities to assess money laundering, terrorism financing and, under the reformed framework, proliferation financing risk. AUSTRAC publishes detailed guidance. For organisations within scope of the failure to prevent foreign bribery offence under section 70.5A of the Criminal Code Act 1995 (Cth), guidance on adequate procedures makes bribery risk assessment a central step. In practice, many organisations use a broader financial crime risk assessment across multiple offence areas, but the legal drivers should be kept distinct.
Key takeaways
- The financial crime risk assessment is the analytical foundation of the programme. It is required or strongly driven by the main UK legal and regulatory frameworks, and it is an important document for supervisors and prosecutors.
- A working risk assessment covers inherent risk, the control environment, residual risk, action and ownership, and review triggers. It addresses all four offence areas using a consistent methodology.
- Risk should be assessed across the same dimensions across offence types: customer or counterparty, product or service, geographic, channel, third party, and internal.
- Supervisors and prosecutors look for assessments that are specific to the organisation, refreshed in response to business and regulatory change, and actually used to drive controls and resource allocation.
- The three most common failure modes are that the assessment is treated as a document rather than a tool, it is too generic, or it is incomplete and has not kept pace with the wider failure to prevent framework and the section 196 senior manager attribution reform.
- Senior management engagement and board approval are not formalities. They are the evidence that the organisation's leadership has accepted accountability for the risk profile and the response.
Coming up in Session Eight
Session Eight covers building and running the financial crime programme as a whole: programme architecture, the three lines of defence, governance and senior management oversight, policies and procedures, due diligence, training, monitoring, internal audit, MI and reporting. The session translates the risk assessment into the working programme that addresses the residual risks and provides the documented basis on which the organisation can demonstrate that its procedures are adequate or reasonable, depending on which offence is engaged.
Further reading and resources
The following primary and supervisory sources are useful companions to this session. Use the current public version rather than a downloaded copy, particularly for regulatory guidance, market abuse materials, AML/CTF rules and national risk assessments.
- Ministry of Justice guidance under section 9 of the Bribery Act 2010. Principle 3 covers risk assessment. Available at gov.uk.
- HMRC guidance on the corporate offences of failure to prevent the criminal facilitation of tax evasion. Guidance under the Criminal Finances Act 2017, including risk assessment. Available at gov.uk.
- Home Office guidance on the failure to prevent fraud offence. Covers the six principles, including risk assessment. Available at gov.uk.
- Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, regulation 18. The firm-wide AML/CFT risk assessment obligation. Available at legislation.gov.uk.
- FCA Financial Crime Guide. Available through the FCA Handbook.
- HM Treasury National Risk Assessment of Money Laundering and Terrorist Financing. Available at gov.uk.
- UK anti-corruption strategy and related government policy material. Available at gov.uk.
- Transparency International country risk and corruption perception material. Available at transparency.org.
- FCA Market Watch and published market abuse enforcement material. Available at fca.org.uk.
- JMLSG Guidance, Part I, Chapter 4. Available at jmlsg.org.uk.
- New Zealand. AML/CFT Act 2009, section 58, and current Department of Internal Affairs AML/CFT supervisory guidance. Available at legislation.govt.nz and dia.govt.nz.
- Australia. Australian AML/CTF legislation, current rules and AUSTRAC risk assessment guidance. Available at legislation.gov.au and austrac.gov.au.
Ārai Tika