
Introduction
Most fintechs, payments companies, and financial institutions treat their AML risk assessment like a compliance chore: draft it, file it, revisit it next year. But financial crime risk doesn't wait for your annual calendar.
New products launch, new geographies open up, and typologies shift in the meantime. Regulators have made that lag a liability.
In its 2024 consent order against TD Bank, FinCEN found the bank's risk-assessment methodology was inadequate and overlooked key risk factors. It also lacked the depth to accurately reflect the bank's actual BSA/AML risk exposure.
The same order carried a $1.3 billion penalty and a four-year monitorship.
This post breaks down the warning signs of an outdated risk assessment, why leadership should care, and what to do when you spot them.
Key Takeaways
- Outdated AML risk assessments are a recurring weakness in exams and enforcement actions.
- Review on a set cadence plus event triggers—not as a once-a-year checkbox.
- Gaps between your risk assessment and monitoring rules are a top examiner red flag.
- Proactive refreshes protect funding rounds, bank partnerships, and exam outcomes.
Why an Outdated AML Risk Assessment Puts Your Business at Risk
The FFIEC BSA/AML Examination Manual treats the risk assessment as the foundation of the entire compliance program. Every policy, control, and monitoring rule is supposed to flow from it. When the foundation is stale, everything built on top inherits that weakness, including your transaction monitoring, your CDD procedures, and your staffing decisions.
A stale risk assessment creates a specific operational problem: misalignment between documented risk and actual monitoring. This shows up two ways:
- Alert fatigue from rules tuned to risks that no longer reflect your business, burying analysts in low-value alerts
- Blind spots around real exposure that grew after the last update, meaning genuine suspicious activity slips through
Examiners are trained to test exactly this connection. FFIEC examination procedures direct them to check whether a risk assessment was updated as business circumstances changed—not just whether one exists on file.
Regulatory actions bear this out. The Federal Reserve's 2024 consent order against Green Dot Bank required a revised program built around a comprehensive BSA/AML risk assessment within 90 days, alongside internal controls and CIP updates. The OCC's 2022 agreement with Blue Ridge Bank required an effective written BSA Risk Assessment Program on the same accelerated timeline.
The exposure is not only regulatory. Sponsor banks, investors, and acquirers scrutinize risk assessment currency during due diligence.
The OCC's Blue Ridge order, for example, required the bank to maintain a BSA risk assessment for each individual fintech partner, tailored to that partner's products and activities. A fintech that shows up to a sponsor bank review with a two-year-old risk assessment hands that bank a reason to slow-walk or reject the partnership.
Resourcing costs compound the problem. A static risk assessment misallocates your compliance budget: you keep spending on controls for risks that shrank while underinvesting where exposure actually grew.

7 Signs Your AML Risk Assessment Is Already Outdated
These seven red flags show up often in exams and internal reviews. If any describe your current AML risk assessment, treat the document as due for a full refresh—not a light edit.
Your Business Has Changed But the Risk Assessment Hasn't
New products, customer segments, geographies, or delivery channels launched since your last update mean the documented inherent risk no longer matches reality.
If you added crypto off-ramps, expanded into new states, or started serving a new customer vertical and your risk assessment doesn't mention it, the document is already behind your business.
Emerging Typologies and Products Aren't Addressed
A risk assessment that only references traditional typologies while staying silent on synthetic identity fraud, real-time payments abuse, or crypto on/off-ramps hasn't kept pace.
FinCEN's 2025 notice on convertible virtual currency kiosks found FBI complaints involving these kiosks jumped 99% year-over-year in 2024, with reported losses up 31% to roughly $246.7 million.
If your business touches crypto rails and your assessment doesn't reflect that kind of trend, it's overdue.
Regulatory Guidance and Enforcement Trends Have Moved Past It
New FinCEN advisories, updated FFIEC manual sections, or sanctions program changes that never made it into your risk factors signal an assessment that's fallen behind. The FFIEC InfoBase itself gets periodically revised, most recently with changes effective in 2026, so documents built on older guidance can drift out of alignment fast.
Transaction Monitoring Scenarios Don't Align With Stated Risk
If your risk assessment ranks a product or customer type as high-risk but your monitoring system's scenarios and thresholds don't reflect that ranking, that's a governance gap examiners flag quickly. It tells them the two documents were built in isolation rather than as one connected control environment.
You've Had an Exam Finding, MRA, or Enforcement Action Since the Last Update
Commitments you made to regulators during remediation that never made it into the current risk assessment leave the document obsolete, regardless of its file date. Examiners will check this specifically on the next exam cycle.
SAR Trends and Alert Volumes Have Shifted, But Risk Ratings Haven't Moved
Flat customer or product risk scores despite meaningful changes in SAR filing volume, alert dispositions, or typology trends suggest nobody is revisiting the scoring methodology. Numbers moving while ratings stay frozen is a pattern examiners notice fast.
It's Been Longer Than Your Documented Review Cycle
Missing your own stated annual or biennial review date is a governance failure on its own. Skipping a trigger-based review after M&A, a core system conversion, or leadership turnover counts the same way, separate from whatever content gap turns up.

How Often Should You Review Your AML Risk Assessment?
There's no single universal deadline written into federal regulation. FFIEC guidance is explicit on this: there's no requirement to update the risk assessment on a continuous or specified periodic basis. But that doesn't mean "whenever we get around to it" is defensible.
FFIEC points to a risk-based cadence instead:
- Full annual review as the general baseline most institutions adopt
- Partial updates more frequently, whenever a specific factor changes
- Event-driven reviews that happen immediately, regardless of the calendar
Event triggers matter as much as the calendar. FFIEC specifically calls out changes that should prompt an update on their own timeline—not the next scheduled review:
- New products or services
- New customer types
- M&A activity
One detail catches teams off guard: examiners care about the documentation of the review schedule itself, not just the content. Evidence that you set a cadence and actually followed it demonstrates governance maturity. A great risk assessment on an untracked, ad hoc schedule still reads as a control weakness.
What to Do When You Spot These Warning Signs
Finding one or more of these signs doesn't mean you need to start from scratch. A full rebuild is often overkill and burns time you don't have.
- Run a targeted gap analysis first. Focus on the highest-risk areas: new products, high SAR-volume segments, and typologies your current document doesn't address at all.
- Realign transaction monitoring to your updated risk ratings. Update rules and thresholds so they actually reflect your updated risk ratings, closing the governance gap examiners look for first.
- Formalize approval and document the trail. Get board or senior management sign-off and keep a clear record of what changed and why. That audit trail is often what separates a minor exam comment from a Matter Requiring Attention.
Prioritizing this way gets the highest-exposure gaps closed fast, while still building toward a document that holds up under scrutiny.
Partner with Pillars FinCrime Advisory
Pillars FinCrime Advisory is a CAMS-certified, founder-led advisory firm for fintechs, payments companies, and financial institutions. The firm helps teams modernize compliance programs that have fallen behind, without slowing growth.
Founder Joshua Douglas brings 12+ years of financial crime experience and nearly 20 years across financial services. That experience supports the full lifecycle of a compliance program:
- Risk assessment refreshes tied to your actual current business
- Transaction monitoring optimization so controls match documented risk
- Audit and exam readiness support ahead of your next review
If any of the seven signs above sounded familiar, find out before an examiner does. Reach out to Pillars FinCrime Advisory to request a risk assessment review and see where your program stands.
Frequently Asked Questions
How often should a risk assessment be updated?
There's no fixed federal deadline, but the general expectation is a full review at least annually. This should be supplemented with partial updates whenever significant business or regulatory changes occur.
When should a risk assessment be challenged?
Challenge or refresh the assessment when you launch new products, enter new geographies, complete an M&A deal, receive an exam finding, or see meaningful shifts in SAR or alert trends. Those signals usually mean the written risk picture no longer matches reality.
How many years should a risk assessment be kept?
General BSA/AML recordkeeping rules under 31 CFR 1010.430 set a five-year retention period for required records, though this provision doesn't explicitly name risk assessments. Confirm current retention requirements with counsel or your regulator.
What specifically triggers an unscheduled AML risk assessment update?
Leadership changes, core system or TM platform migrations, and new regulatory guidance or advisories that reframe examiner expectations are common drivers. If the change would alter inherent risk ratings or control design, schedule an update outside the annual cycle.
Who should be involved in reviewing an AML risk assessment?
Typically the BSA/AML compliance officer leads the process, with oversight from senior management or the board. Business line input and independent testing or audit review help confirm the document reflects operational reality.
What happens if examiners find your AML risk assessment is outdated?
Outcomes range from a Matter Requiring Attention noted in your exam report to formal enforcement actions like consent orders, depending on severity. Either outcome typically brings heightened scrutiny on your next exam cycle.


