Help Centre/Firm-wide risk assessment

Firm-wide risk assessment

In brief: MLR reg 18 assessment of your firm's risks: what must be completed, how often, and which sources to use.

Every firm covered by the Money Laundering Regulations must assess the money laundering, terrorist financing and proliferation financing risks its business faces (MLR 2017 reg 18 and 18A). This is the firm-wide risk assessment. Your policies, controls and procedures are then built on it.

Find it in Settings, Risk. Firm owners and managers can create and sign it off.

The four steps

  1. Introduction. Shows when the next assessment is due and your past assessments, each of which you can download as a PDF.
  2. Risk factors. Assess each category. Where Certivus has enough data it shows a live data signal: a suggested level worked out from your own clients and work, with the evidence behind it. You can adopt it or set your own level.
  3. Actions. Record what you will do about the risks you found, who owns each action and by when.
  4. Review and sign off. Check everything, pick when it is next due, tick the sources you used, and sign off.

What must be completed

You cannot sign off until each of these has a risk level and a summary:

  • Clients
  • Services
  • Geographic
  • Delivery channels (how you deal with clients: face to face, remote or through someone else)
  • Transactions: client money
  • Transactions: office account
  • Proliferation financing

"Other" is optional. Any category rated above Low also needs the detail of the risk and how you will reduce it.

Certivus checks this again when you sign off, so an incomplete assessment is never saved as signed.

How often

The guidance for the accountancy sector says the assessment must be reviewed at least once a year, and sooner when something changes, for example a new service, a new type of client or a new country you work with.

So when you sign off you can choose 6 months or 12 months. The firm-wide review cadence in Settings, Risk, Review cadence can be set anywhere from 30 to 365 days.

Sources you considered

At sign-off, tick every source you used. The list includes:

  • the UK National Risk Assessment of money laundering and terrorist financing (July 2025)
  • the UK National Risk Assessment of proliferation financing (September 2021)
  • your supervisor's risk information for your sector
  • the AASG Risk Outlook, published by the accountancy supervisors
  • HMRC's "Risks common to accountancy service providers" (January 2026), if HMRC supervises you
  • the FATF call-for-action and increased-monitoring lists, and the UK sanctions list

If you tick none of the national or supervisor sources, Certivus shows a warning. You can still sign off, but your supervisor will expect to see that you took them into account.

Older assessments may show "UK high-risk third countries list (MLR Schedule 3ZA)". That list was withdrawn in January 2024; the regulations now refer to the FATF call-for-action list directly.

Once signed off

  • The assessment is locked. It cannot be edited or deleted. To record a change, start a new assessment.
  • Your sign-off, name and role are recorded in the audit trail.
  • The next due date is set from the interval you chose.
  • It appears in your Compliance Health score as "Firm-wide risk assessment current": full points while it is in date, half once it is overdue, none if you have never signed one off.

Live data signal and drift

After you sign off, Certivus keeps comparing the live picture with the levels you signed. If they drift apart, for example you now have clients in a higher-risk country, or more of your clients are dealt with remotely, it shows the change so you know it is time to review.

Some categories cannot be worked out from data yet (client money and office account). For delivery channels, the signal uses the answer to "how do you deal with this client" in each client's risk assessment; if none of your clients has that answer, it asks you to assess the category yourself.

Didn't find what you needed?

Contact support