Risk assessment
In AML, risk assessment operates at two levels. A firm-wide risk assessment identifies the overall money laundering risks facing a practice — covering client types, services offered, geographies, delivery channels, and funding sources. A client risk assessment scores an individual client as low, medium, or high risk and determines what level of due diligence to apply.
MLR 2017 requires every in-scope business to carry out, document, and regularly review a firm-wide risk assessment. HMRC inspectors routinely ask to see it.
How different roles use Risk assessment
A good definition should change the next action for the person reading it.
Partner or director
Check whether this term affects acceptance risk, fee scope, supervision exposure, or sign-off responsibility.
ContinueMLRO or compliance lead
Map the term to evidence, escalation, monitoring, training, and inspection readiness.
ContinueClient-facing team member
Use the plain-English explanation to ask better client questions and write clearer file notes.
ContinueOther terms that go with Risk assessment
Customer Due Diligence is the core legal obligation under MLR 2017 to identify clients, verify their identity using reliable independent sources, and understand the purpose and intended nature of the business relationship. Standard CDD applies to most clients. Where risk is elevated, Enhanced Due Diligence (EDD) is required instead.
Enhanced Due Diligence is a more thorough level of client verification required when a relationship presents a higher risk of money laundering or terrorist financing. EDD steps typically include verifying the source of funds, establishing source of wealth, obtaining senior management approval before onboarding, and applying more frequent ongoing monitoring.
A supervisory authority is the body responsible for overseeing AML compliance within a particular sector. For accountants not belonging to a professional body, the supervisory authority is HMRC. Members of recognised professional bodies (ICAEW, ACCA, CIMA, and others) are supervised by those bodies instead. For law firms in England and Wales, the supervisory authority is the Solicitors Regulation Authority (SRA), with parallel regulators in Scotland and Northern Ireland. Supervisory authorities set standards, conduct reviews, and can impose sanctions.
Before you treat Risk assessment as handled
- Confirm which regulation, policy, or internal procedure the term maps to.
- Document the decision or evidence trail in the client file, not only in email or chat.
- Escalate where the term indicates higher risk, sanctions exposure, PEP status, suspicion, or missing evidence.
- Keep the wording consistent across onboarding, review notes, training material, and inspection packs.
Put Risk assessment into practice with Certivus
Knowing the term is the first step. Certivus gives you the workflows — client intake, CDD, EDD, PEP and sanctions screening, audit-ready records — to apply it across every client.
Back to the full glossary