
There's no single "update every X months" rule that applies to every institution. A community bank with a stable local customer base doesn't face the same clock as a fintech launching new products every quarter.
But outdated risk assessments have real consequences. In its 2022 consent order against USAA Federal Savings Bank, FinCEN cited a customer risk model so flawed that missing customer information caused it to materially understate the bank's actual BSA/AML risk — years after the bank had committed to fixing it.
This article breaks down the regulatory baseline for update frequency, the trigger events that demand immediate action, and what happens when institutions get the timing wrong.
Key Takeaways
- FFIEC independent testing guidance treats 12 to 18 months as the practical minimum for a full risk assessment refresh
- Trigger events—new products, M&A, new markets, regulatory shifts, adverse findings—require immediate off-cycle updates
- Higher-risk institutions with complex products or cross-border activity should default to annual or more frequent reviews
- An outdated assessment miscalibrates monitoring, CDD, and training against the wrong risk baseline
- 2024 interagency proposals signal formalized, event-driven update requirements ahead for supervised institutions
Why Timing Matters for AML Risk Assessment Updates
Your risk assessment is the upstream input for your entire program:
- Transaction monitoring thresholds are calibrated from it
- CDD and EDD requirements are scoped from it
- Staffing levels and training curricula trace back to it
When the assessment goes stale, every one of those downstream controls keeps operating on assumptions that no longer match reality.

Regulators Are Moving From Expectation to Requirement
For years, federal guidance has framed risk assessment updates as something institutions should do when their risk profile changes, without prescribing a specific calendar. That's shifting.
In August 2024, the Federal Reserve, FDIC, NCUA, and OCC jointly proposed new AML/CFT program requirements. The proposal would make the risk assessment a required program pillar, with mandated periodic updates tied to material changes in a bank's risk profile.
FinCEN published a parallel proposal the same year. Neither locked in a specific numeric interval, but both make clear that regulators want risk assessments treated as a structured, ongoing obligation—not an annual checkbox.
The Operational Cost of Getting It Wrong
Stale risk models misconfigure alert thresholds. When your customer risk ratings don't reflect actual behavior, your monitoring system either misses genuine suspicious activity or buries analysts in noise.
That noise is expensive. A 2024 LexisNexis Risk Solutions study found that financial crime compliance costs financial institutions in the United States and Canada $61 billion annually. Manual alert investigation drives much of that figure, and many of those alerts come from monitoring systems calibrated against outdated risk data.
The Blind-Spot and Reputational Risk
An assessment that hasn't caught up with a new product line or customer segment cannot account for the money laundering typologies specific to that unassessed risk. It's a blind spot by design.
Examiners notice. Outdated risk assessments regularly show up in Matters Requiring Attention (MRAs), consent orders, and enhanced supervision. They can also stall new product launches or M&A approvals until remediated.
How Often Should You Update Your AML Risk Assessment?
Update timing depends on three inputs working together:
- A periodic, regulatory-anchored review schedule
- Immediate updates triggered by material events
- Ongoing monitoring signals that feed into both
The Regulatory Baseline: Periodic Review Cycles
No federal regulator mandates a fixed calendar for risk assessment updates. The FFIEC's BSA/AML Examination Manual is explicit on this: there's no requirement to update risk assessments on a continuous or specified periodic basis.
That said, the FFIEC's independent testing guidance references 12 to 18 months as a reasonable interval example, and that benchmark has become the de facto industry floor for full risk assessment refreshes.
Institutions with any of the following should default to annual reassessments, not the 18-month ceiling:
- Complex or rapidly evolving product lines
- Concentrated high-risk customer bases (PEPs, cash-intensive businesses, MSBs)
- Cross-border operations or correspondent banking relationships
The 2024 interagency proposals point toward tighter expectations, including intervals tied to exam cycles or updates in FinCEN's national AML/CFT Priorities. Institutions that wait for a final rule before tightening their cadence will be playing catch-up.
Trigger Events That Require an Immediate Update
Certain changes require an update the moment they happen, not at the next scheduled review. Per FFIEC guidance, these include:
- New products or services: each offering brings its own typologies and control needs
- New customer types or geographic markets: different exposure requires different controls
- Mergers and acquisitions: you inherit the acquired entity's risk profile, known and unknown
- **Significant regulatory or sanctions changes**: OFAC list or FinCEN priority shifts can reshape risk overnight
- Adverse audit or exam findings: documented cause for more frequent independent testing
The real danger is the gap between when the change happens and when it lands in your risk assessment. Waiting for the next scheduled cycle means operating with a known blind spot.
Assign clear internal ownership so someone flags these events when they occur, not during the annual review.
Risk-Tiered Review Frequency by Customer and Product Segment
Not every part of your risk assessment runs on the same clock. Federal guidance supports closer, more frequent review of higher-risk customer relationships throughout their lifecycle. In practice, many programs structure this as:
- High-risk segments (PEPs, cash-intensive businesses): annual review
- Medium-risk segments: every 18 to 24 months
- Low-risk segments: up to three years between reviews

Segment-level findings don't stay siloed. A material shift in a high-risk customer population can (and often should) trigger an update to the enterprise-wide risk assessment, not just the segment file.
Signs It's Time to Update
Beyond the calendar and formal triggers, watch for these signals:
- Rising SAR filings or alert volumes: your risk model may no longer match how customers actually behave
- An upcoming exam or audit: refresh proactively, not after findings surface
- Leadership discussing a new product, market, or acquisition: scope the assessment before launch, not after
Calendar cadence, event triggers, and these monitoring signals work together. When any one moves, reassess whether your current risk assessment still reflects how the business operates.
What Happens If Your Risk Assessment Update Is Too Late
Stale risk ratings misconfigure monitoring thresholds. That miscalibration cuts both ways: genuine suspicious activity slips through undetected, or analysts drown in false positives tied to outdated risk logic.
Financial crime compliance already costs U.S. and Canadian institutions $61 billion a year, largely in labor. A poorly tuned monitoring program only compounds that bill.
Examiners cite this specifically. Outdated risk assessments are a recurring theme in MRAs and formal enforcement actions. The consequences aren't abstract:
- FinCEN's 2022 USAA order required a full program overhaul after the risk model was found materially inadequate, despite roughly $500 million already spent
- In October 2024, the OCC issued a cease-and-desist against TD Bank for BSA/AML deficiencies, including a cap on growth
- Reuters reported AML concerns helped sink TD's proposed First Horizon acquisition in 2023
The cost differential is real. An on-schedule update might take a few weeks of focused work. A reactive remediation after an exam finding is a different scale of project. Lookback reviews, independent monitors, and consultant fees can stretch the work across years and push costs into the tens or hundreds of millions. Staying on schedule meets the compliance obligation and keeps the spend far lower.
Best Practices for Staying Ahead of Your AML Risk Assessment Cycle
Getting ahead of the timing problem takes structure.
- Build a compliance calendar. Map periodic review dates to exam cycles, independent audits, and FinCEN Priorities updates so reviews never depend on someone remembering to schedule them.
- Assign trigger-event ownership. Give new product launches, M&A activity, and regulatory changes a named owner who tracks them against risk assessment obligations in real time.
- Treat the risk assessment as a living document. Use it to inform monitoring tuning, CDD/EDD standards, and training—not as a static annual report.
- Document your rationale. Every risk rating needs a written basis, and senior management and the board should formally review findings. That record meets regulatory expectations and strengthens your position in exams.
Fintechs and payments companies that scale quickly often outgrow their original risk assessment before anyone notices. An advisor like Pillars FinCrime Advisory can turn these expectations into a practical update framework that keeps pace with growth instead of lagging behind it.

Conclusion
There's no universal answer to "how often." The right cadence blends a regulatory floor with your institution's actual risk profile and how fast your business is changing.
Keep the three-part framework in mind:
- Scheduled periodic reviews at a 12-to-18-month minimum
- Immediate updates when trigger events occur
- Continuous monitoring feeding into both
Institutions that treat these as separate, disconnected obligations are the ones examiners tend to flag.
If you're unsure whether your current update cycle meets regulatory expectations, Pillars FinCrime Advisory offers a practical, business-focused program review. Reach out at 281-825-1603 or pillarsfincrimeadvisory@gmail.com.
Frequently Asked Questions
How often should you update your AML risk assessment?
Most programs treat 12 to 18 months as a practical floor for a full refresh, based on FFIEC's independent testing guidance. Higher-risk institutions should review annually, and trigger events require updates outside that schedule entirely.
How often do you have to do AML checks?
Transaction monitoring and customer due diligence checks run continuously as part of daily operations. The full risk assessment cycle, by contrast, runs on a periodic schedule of 12 to 18 months—or more often for higher-risk programs.
What triggers an immediate risk assessment update outside the normal schedule?
Key triggers include launching new products or services, entering new markets, mergers and acquisitions, significant regulatory or sanctions changes, and adverse audit or exam findings. Any of these should prompt an update regardless of your next scheduled review date.
Who is responsible for keeping the AML risk assessment current?
The BSA Officer or Chief Compliance Officer typically owns the process, with input from business lines on product and customer changes. Ultimate accountability rests with the board of directors.
What happens if a bank's risk assessment is outdated during an exam?
Examiners may issue Matters Requiring Attention, require formal remediation plans, or in severe cases pursue enforcement actions. These findings can also delay new product rollouts or M&A approvals until the gaps are resolved.
Does a higher-risk customer base mean more frequent AML risk assessments?
Yes. A book heavy with PEPs, cash-intensive businesses, or other high-risk segments usually supports an annual enterprise risk assessment. Customer-level CDD refresh still runs on its own cycle—often annual for high-risk, 18–24 months for medium-risk, and up to three years for low-risk.


