
A risk assessment that opens with "we are a medium-risk firm" has skipped the part that matters. AMLA's draft guidelines put a three-phase method behind that rating: the risk you carry before controls, how well they work, and what is left. That last figure has to change something.
This is a consultation paper, published in Frankfurt on 16 April 2026, and nothing in it binds anyone yet. Article 10(4) of Regulation (EU) 2024/1624 requires AMLA to issue guidelines specifying the minimum requirements for the content of the business-wide risk assessment drawn up under Article 10(1), and the additional sources of information to be taken into account when carrying it out. Responses were due by 15 July 2026, and AMLA says the final guidelines will be issued in Q4 2026.
The draft sets a floor for content. The BWRA should at least include a business and operational overview of the obliged entity, and the identification and assessment of its exposure to money laundering, terrorist financing and non-implementation and evasion of targeted financial sanctions risks, supported by a clear and documented methodology that follows a three-phase process comprising inherent risks, the quality of controls, and residual risks. Put plainly: describe the firm, then walk those three steps, and write down the method you used. The overview is not filler either. Obliged entities should use it as a basis to decide how complex and elaborate the BWRA needs to be, ensuring the approach is effective and proportionate to their size, nature and overall business complexity.
Phase one is what you are exposed to before you do anything about it. Obliged entities should begin by analysing how those risks could materialise within their business, including any emerging risks, taking a holistic view of all relevant risk factors related to customer, product, service and transaction, delivery channels and geographical exposure. For this purpose the draft says they should at least refer to the data points listed in the RTS on Article 40(2) of the AMLD, supplemented by any additional relevant quantitative and qualitative indicators such as strategic plan modifications, mergers or regulatory changes. That RTS is the supervisor's assessment of you; the BWRA is your assessment of yourself, borrowing its data points.
Phase two is the one that gets skipped. Once inherent risks are identified, obliged entities should assess how effectively their policies, procedures and controls mitigate those risks by clearly linking them together and explaining how the control mitigates the risk in practice, and should be able to demonstrate a clear, evidence-based view of how effectively current policies, procedures and controls mitigate inherent risks and where gaps or weaknesses remain. The draft splits the question in two: the design assessment should determine whether adequate controls exist to mitigate the risk, while the implementation assessment should verify that controls effectively mitigate the risk.
Phase three is subtraction you have to be able to show. Considering the inherent risk level in light of the quality of the controls, obliged entities should determine the residual risks they remain exposed to, and the draft adds that their methodology should recognise that inherently high-risk factors by their nature cannot be completely mitigated by control measures. An inherently high-risk factor does not get controlled down to nothing.
Then the draft says what the number is for. Upon completion, obliged entities should determine the priority areas for action and ensure timely implementation of necessary remediation measures, namely updates to policies, procedures, systems and controls to ensure effective mitigation of identified residual risks. The BWRA should be drawn up by the compliance officer, approved by the management body in its management function and, where such a body exists, communicated to the management body in its supervisory function. A third party may assist with drawing it up, provided the proposal and approval of the BWRA are carried out within the entity, which should understand and be able to explain the content, including the methodology used and the results obtained. A residual risk nobody remediated is a residual risk nobody assessed.
Not legal advice. Verify against the primary source before acting.
FIRMCY screens names against all of the lists above — plus a worldwide PEP database and adverse media — with fuzzy matching and an audit-ready report for every check. New organisations get 100 free credits, no card required.
Start screening free Free PEP & sanctions check FATF high-risk countries Weekly AML briefing Live on Telegram ↗