
Yet many fintechs, payments companies, and financial institutions still build risk assessments as static, checkbox exercises. The result is a widening gap between what the business actually looks like today and what the controls were designed to catch.
This guide breaks down what an AML/CFT risk assessment is, its core components, how to build one step-by-step, and the practices that keep it exam-ready year-round. Pillars FinCrime Advisory, founded by Joshua Douglas, works directly with fintech, payments, and financial institution leadership to build these frameworks so they scale with the business instead of becoming outdated the moment it changes.
Key Takeaways
- Risk assessments must drive staffing, monitoring, and CDD decisions—not sit unused in a binder
- Cover five pillars: customer, product/service, geography, delivery channel, and national priorities
- Documentation gaps and stale methodologies rank among top enforcement findings
- Update when products, markets, or M&A change—not only on a fixed annual calendar
What Is an AML/CFT Risk Assessment?
An AML/CFT risk assessment is the structured process of identifying, evaluating, and documenting an institution's exposure to money laundering, terrorist financing, fraud, and sanctions risk. It looks across customers, products, services, delivery channels, and geographies to build a full picture of where illicit activity is most likely to surface.
The FFIEC's BSA/AML Examination Manual frames it this way: while not historically a standalone statutory requirement, "a well-developed BSA/AML risk assessment assists the bank in identifying ML/TF and other illicit financial activity risks and in developing appropriate internal controls."
In other words, everything downstream (customer due diligence intensity, transaction monitoring rules, staffing, and training) should trace back to what the risk assessment concludes.
That historical flexibility is narrowing. Proposed FinCEN and interagency rulemaking has moved toward making a documented risk assessment process a mandatory program pillar, not an optional best practice. Institutions that still treat it as a supporting document rather than the backbone of their program are increasingly out of step with where regulation is heading.
AML vs. CFT: What's the Difference?
The two terms get used together so often that the distinction blurs, but they're targeting different problems:
- AML (Anti-Money Laundering) focuses on concealment and integration: stopping criminals from disguising illicit proceeds as legitimate funds.
- CFT (Countering the Financing of Terrorism) focuses on disrupting funds intended for terrorist activity, even when those funds come from entirely legitimate sources like donations or legal business income.
Despite that difference in intent, institutions assess both together. They share overlapping red flags, the same underlying customer and transaction data, and identical reporting mechanisms like Suspicious Activity Reports (SARs). Separating them into two processes creates duplicate work.
Why AML/CFT Risk Assessments Matter: Regulatory Expectations & Business Impact
Examiners grade effectiveness, not the existence of paperwork. A risk assessment that exists but doesn't visibly influence CDD depth, monitoring rules, training priorities, or technology spend raises immediate questions during an exam.
This shift has regulatory backing. In 2024, FinCEN proposed a rule that would have formalized mandatory risk assessments tied directly to the National AML/CFT Priorities. The Federal Reserve, FDIC, NCUA, and OCC issued parallel proposals for their supervised institutions. That specific 2024 proposal has since been withdrawn and superseded by later rulemaking, but the direction hasn't changed: regulators want risk assessments that demonstrably drive program decisions.
Beyond the exam room, risk assessments carry real business weight:
- Give leadership a clear view of current exposure against the institution's stated risk appetite
- Inform go/no-go decisions before launching a new product or entering a new market
- Justify budget and headcount requests to the board with data, not guesswork
If the assessment never changes a decision, examiners will treat it as shelfware.
The 5 Key Components of an Effective AML/CFT Risk Assessment
Regulators and industry frameworks generally expect five interconnected elements, each documented with clear rationale.
Customer Risk
Customer risk goes well beyond basic demographics. A complete evaluation factors in:
- Ownership structure and beneficial ownership transparency
- Behavioral patterns and transaction velocity
- Red flags such as politically exposed persons (PEPs)
- Cash-intensive business models
- Unusual or inconsistent activity relative to the stated purpose of the account

Products and Services Risk
Every product and service carries its own inherent vulnerability to money laundering. Correspondent banking, trade finance, and cross-border payment tools sit on the higher-risk end, while a basic domestic savings account sits lower. The assessment needs to score each offering individually rather than applying one blanket rating across the whole product catalog.
Geographic Risk
Geographic risk tracks where customers and counterparties are located, and where funds move. This includes jurisdictions flagged by the Financial Action Task Force (FATF) for strategic deficiencies, along with countries subject to sanctions programs. A fintech onboarding customers across dozens of countries carries meaningfully different geographic risk than one operating in a single domestic market.
Delivery Channel Risk
How customers access products matters as much as what they're accessing. Channels that each need their own risk lens include:
- Online banking and mobile apps
- ATMs
- Third-party or fintech partnership channels
Each introduces different opportunities for anonymity and rapid movement of funds.
Alignment with FinCEN's National Priorities & Documentation
The fifth component ties everything together: mapping risk factors to FinCEN's National AML/CFT Priorities:
- Corruption
- Cybercrime (including virtual currency)
- Terrorist financing
- Fraud
- Transnational criminal activity
- Drug trafficking
- Human trafficking and smuggling
- Proliferation financing
Documentation is where most institutions fall short. Assigning a risk rating alone does not satisfy examiners; the assessment must show the data sources, weighting logic, and reasoning behind every conclusion. BSA/AML enforcement actions in 2024 repeatedly cited weak or missing rationale as a core deficiency.
How to Conduct an AML/CFT Risk Assessment: A Step-by-Step Process
Building a defensible assessment follows a logical sequence. The FFIEC frames the work as two core moves—category identification and analysis—which break down into six practical steps.
- Gather data across all risk categories. Pull customer base information, product and geographic footprints, delivery channel usage, plus internal reports like SAR filings and transaction monitoring alerts.
- Identify and categorize inherent risk factors. Tailor this to the institution's size, complexity, and business model — a five-person fintech and a regional bank shouldn't use the same template.
- Analyze and quantify risk within each category. Weight factors based on materiality, such as the volume of international wires versus routine domestic transactions.
- Evaluate existing control effectiveness. Determine residual risk after mitigation and flag gaps between inherent risk and current safeguards.
- Document conclusions with clear rationale. Assign risk ratings in language the board, senior management, and examiners can all understand without a compliance dictionary.
- Integrate findings into the compliance program. Adjust CDD intensity, monitoring rules, staffing levels, training priorities, and independent testing scope based on what the assessment actually found.

That last step is where most programs stall. Findings get documented, then filed away without ever touching the operational controls they were meant to inform.
Best Practices for Building a Dynamic, Exam-Ready AML/CFT Risk Assessment
An assessment that only gets touched once a year can't keep pace with a growing fintech or payments company. These practices keep it current and exam-ready:
- Set triggering events, not just an annual cadence. New products, market expansion, M&A, or regulatory guidance changes should each prompt an interim update.
- Involve the board earlier. Bring leadership into methodology discussions and resource allocation decisions, not just the final sign-off meeting.
- Break down the fraud/AML silo. Fraud proceeds frequently flow directly into laundering activity, so investigation findings should feed customer risk ratings, and vice versa.
- Govern any AI-driven risk tools carefully. Automation can improve data quality and consistency, but every model needs to be validated and explainable to an examiner, not a black box.
- Run independent testing regularly. Catch weaknesses in risk-rating methodology or documentation before an exam finds them first.
Many growing fintechs and payments companies reach a point where building this in-house stretches lean compliance teams too thin. That's typically where an advisory partner like Pillars FinCrime Advisory fits in: helping design a risk-based assessment methodology that scales with the business without slowing product launches or market expansion.
Common Pitfalls That Trigger Regulatory Scrutiny
Three patterns show up again and again in enforcement actions:
- Static, one-size-fits-all assessments. A methodology that hasn't been updated for new products, customer segments, or geographic footprint quickly stops reflecting actual risk.
- Thin documentation of rationale. Missing data sources or unclear weighting logic behind risk conclusions frequently draws examiner findings.
- Weak national-priority alignment and no follow-through. Assessments that ignore FinCEN priorities, or never convert findings into monitoring thresholds, controls, or staffing, defeat the purpose of the exercise.
The scale of these gaps can be severe. When the OCC assessed a $450 million civil money penalty against TD Bank in October 2024, the findings specifically cited deficiencies in risk assessments, customer risk ratings, and staffing. Those gaps became enforcement findings, not paperwork footnotes.

Frequently Asked Questions
What is an AML/CFT risk assessment?
An AML/CFT risk assessment identifies and evaluates an institution's money laundering, terrorist financing, and illicit finance risks across customers, products, geographies, and channels. The results shape a risk-based compliance program.
What are the 5 things a risk assessment should include?
Customer risk, product/service risk, geographic risk, delivery channel risk, and alignment with FinCEN's National AML/CFT Priorities plus supporting documentation. All five need to be evaluated together, not in isolation.
What's the difference between AML and CFT?
AML targets the concealment of illicit proceeds after a crime occurs. CFT targets funds intended for terrorist activity, even when those funds originate from legitimate sources.
How often should an AML/CFT risk assessment be updated?
There's no fixed regulatory interval. Updates should happen whenever material changes occur (new products, new markets, M&A), alongside a periodic full review, typically annually.
Who is responsible for conducting the AML/CFT risk assessment?
The BSA/AML compliance officer typically leads the process with input from business lines across the institution. Senior management and the board must review and formally approve the final results.
What happens if a financial institution fails to maintain an adequate risk assessment?
Inadequate risk assessments are among the most commonly cited deficiencies in enforcement actions. They often lead to consent orders, civil money penalties, or mandated remediation programs.


