Insights on Crypto Payments, Infrastructure, and Operations

AML Risk Assessment

Pronunciation: A-M-L RISK uh-SESS-ment

Definition

An AML Risk Assessment is a structured evaluation of exposure to money laundering, terrorist financing, proliferation financing, and related financial-crime risks arising from customers, products, geographies, channels, transactions, and delivery models. It is broader than a single customer risk score and should evaluate both inherent risk and the effectiveness of mitigating controls. The methodology should document factors, data, weighting, limitations, residual-risk decisions, governance approval, review triggers, and how findings change due diligence, monitoring, staffing, and product limits.

Overview

An AML Risk Assessment is a structured evaluation of exposure to money laundering, terrorist financing, proliferation financing, and related financial-crime risks arising from customers, products, geographies, channels, transactions, and delivery models. The control exists to identify, assess, and control financial-crime exposure while supporting proportionate customer due diligence, transaction decisions, investigation, and regulatory reporting. It is broader than a single customer risk score and should evaluate both inherent risk and the effectiveness of mitigating controls. It should be interpreted alongside Enterprise-Wide Risk Assessment (EWRA) because the concepts can affect the same decision without representing the same control, event, or risk.

The workflow combines customer and beneficial-owner information, expected activity, transaction data, counterparties, geography, delivery channel, typologies, and external intelligence. Automated indicators should create explainable alerts or risk changes, while trained analysts review context, request evidence, document uncertainty, and escalate according to authority. In this context, the methodology should document factors, data, weighting, limitations, residual-risk decisions, governance approval, review triggers, and how findings change due diligence, monitoring, staffing, and product limits.

It should connect the term to Customer Risk Profile where that relationship changes access, transaction treatment, investigation, communication, or recovery.

Records should preserve source data, rule and model versions, timestamps, thresholds, attribution confidence, customer explanations, analyst notes, approvals, restrictions, and links to cases or reports. Data quality, false positives, missed scenarios, and changes in products or threats need periodic testing.

Useful measures include review coverage, alert volume, true-positive yield, investigation time, overdue cases, risk-rating changes, reporting outcomes, data-quality exceptions, and effectiveness findings from independent testing.

The relationship with Suspicious Activity Monitoring should be documented where it affects residual risk or control ownership.

Key Takeaway

The methodology should document factors, data, weighting, limitations, residual-risk decisions, governance approval, review triggers, and how findings change due diligence, monitoring, staffing, and product limits.

Sources

  1. Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPs — FATF (2026-08-03)
  2. Virtual Assets Red Flag Indicators of Money Laundering and Terrorist Financing — FATF (2026-08-03)
  3. Sanctions Compliance Guidance for the Virtual Currency Industry — U.S. Treasury OFAC (2026-08-03)