A Practice-Wide Risk Assessment (PWRA) is a structured, institution-level evaluation of the money laundering and terrorist financing risks that an organisation faces across all its products, services, customers, delivery channels, jurisdictions, and operational practices.
It identifies inherent risks, assesses the effectiveness of existing controls, and determines residual exposure.
PWRA is a statutory requirement across most AML/CFT regulatory frameworks and forms the foundation of a risk-based compliance programme.
The PWRA differs from customer-level risk assessments because it evaluates risk at the enterprise level, enabling management to design proportionate controls, allocate resources efficiently, and demonstrate regulatory alignment with national and FATF standards.
Explanation
A PWRA is a holistic assessment that examines how the organisation’s activities may be exposed to ML/TF risks.
It incorporates factors such as customer demographics, product complexity, transaction behaviours, geographic exposure, channel delivery models, and operational vulnerabilities.
The objective is to identify risk concentrations, understand how risks evolve with business strategy, and ensure AML/CFT controls remain adequate.
Regulators expect the PWRA to be documented, periodically refreshed, and reviewed by senior management or the board.
A robust PWRA supports:
Stronger governance and AML/CFT accountability.
More accurate calibration of CDD, EDD, and monitoring thresholds.
Allocation of resources based on materiality and exposure.
Fragmented ownership of risk information across departments.
Difficulty quantifying control effectiveness objectively.
Institutions address these challenges through enhanced MI, data aggregation, intelligence-led approaches, and periodic independent reviews.
Regulatory Oversight and Governance Expectations
Regulators expect institutions to:
Maintain a written PWRA that clearly identifies ML/TF risks.
Ensure the assessment informs policy design, monitoring, and resource allocation.
Link PWRA outcomes to board-approved risk appetite statements.
Refresh the PWRA in response to material business or regulatory changes.
Demonstrate traceability between the PWRA and downstream AML processes.
Provide evidence of senior management involvement and oversight.
Supervisory bodies often request PWRAs during thematic inspections, off-site reviews, or enforcement investigations.
Importance of PWRA in AML/CFT Compliance
A well-executed PWRA is central to an institution’s AML/CFT framework because it:
Defines the baseline risk landscape the organisation must manage.
Ensures proportional, risk-based deployment of controls and resources.
Strengthens governance and transparency for internal and external stakeholders.
Supports scalable compliance by aligning systems and processes with actual risk levels.
Enhances resilience to evolving threats and regulatory expectations.
As financial ecosystems digitalise and diversify, the PWRA becomes increasingly critical to sustaining an intelligence-driven, adaptable AML programme.