Bank compliance risk assessment: how to conduct and score one

Updated: 2 hours ago
In October 2024, TD Bank agreed to pay around US$3 billion in penalties to US authorities over failures in its anti-money laundering programme. No single missed transaction caused this. It was years of gaps in transaction monitoring coverage, customers who had never been properly risk-rated, and a transaction monitoring programme essentially unchanged from 2014 to late 2022.
A bank compliance risk assessment exists to stop that kind of drift. It shows where the bank's exposure sits and whether its controls still match it.
Today, we'll cover how to conduct a bank compliance risk assessment, the tools you can use and the mistakes to avoid to safeguard your business.
Bank compliance risk assessmentKey Takeaways |
|
|
|
|
|
|
|
|
What is a bank compliance risk assessment?
A bank compliance risk assessment is a systematic approach to finding, measuring and recording the regulatory risks that a bank encounters, mainly money laundering, terrorist financing, sanctions breaches, fraud and KYC failures, so that controls can be set in proportion to that risk.
It works at two levels. The institutional (or enterprise-wide) risk assessment looks at the bank as a whole: its customer base, products, geographies and delivery channels.
Customer risk ratings then apply that methodology to individual relationships. This guide focuses on the institutional assessment and shows where customer ratings feed into it.
Make a mistake in your risk assessment and every control built on it, including thresholds, escalation rules, and review cycles, will inherit that error.
Read also: AML Banking compliance
Difference between compliance risk and other risk types
The Basel Committee on Banking Supervision describes compliance risk as the risk of legal or regulatory sanctions, material financial loss or reputational damage that a bank may suffer when it fails to comply with the laws, regulations and standards that apply to its banking activities.
Credit risk asks whether a borrower will repay the loan. Operational risk asks whether a failure in your own processes, systems, or personnel will lead to losses.
Compliance risk looks at something else: does this particular business relationship, product or financial deal pose any risk to your bank of breaking the law or violating regulations?
Related content: How to detect fraud in banking
Regulatory reasons for performing compliance-specific risk assessments
Regulators expect banks not only to have controls, but to explain why they exist and how they relate to actual risk. A risk assessment forms the documented evidence linking the two.
Without it, a bank cannot demonstrate its risk-based approach to a supervisor, and every control will appear arbitrary rather than proportionate.
The US Department of Justice described TD Bank's programme in similar terms: elements that looked adequate on paper, with fundamental flaws underneath.

What are the common compliance risks for banks?
Money laundering via customer accounts, trade finance, or correspondent banking relationships
Sanctions breaches involving OFAC, UN or EU-designated people and companies
Terrorist financing risk in cash-intensive or cross-border business lines
Proliferation financing, which FATF and the UAE's 2025 AML law now treat alongside money laundering and terrorist financing
KYC and onboarding failures letting high-risk clients in without proper checks
Fraud exposure related to poor transaction monitoring or outdated customer risk scores
Read also: What is KYC?

What are the key components of a compliance risk assessment?
A compliance risk assessment has four elements: determining your regulatory exposure, categorising risk across customers, products, jurisdictions and delivery channels, scoring inherent and residual risk, and documenting each step so it survives an audit.
Identifying regulatory exposure
Start by listing each regulatory obligation by type.
AML/CFT, sanctions, fraud and KYC rules rarely come from the same instrument or the same regulator.
Read also: KYC in banking
Risk categorisation
Almost all frameworks categorise risk across four dimensions:
Customer risk: occupation or business activity, ownership structure, PEP status, source of funds
Product and service risk: cash-intensive products, trade finance, correspondent banking
Jurisdictional risk: FATF grey and black lists, sanctions exposure, local AML supervisory strength
Delivery channel risk: face-to-face onboarding versus remote digital channels
Several regulators add a fifth: transactions, including their volume and complexity. The UK's Money Laundering Regulations 2017 and the DFSA's AML Module both list transactions explicitly.
Fowler Oldfield, the jewellery business at the centre of NatWest's £264.8 million fine, shows what happens when categorisation slips. NatWest rated the customer high risk at onboarding, then erroneously downgraded it to low risk in December 2013 and moved it to medium in 2014. The rating only returned to high in March 2016.
Over the relationship, the business deposited about £365 million, of which around £264 million was cash, at up to £1.8 million a day at its peak.
For more than two years, the monitoring applied to the account did not reflect that risk. Southwark Crown Court imposed the fine in December 2021, in the FCA's first criminal prosecution under the Money Laundering Regulations 2007.
Read more: AML Customer risk rating
Risk scoring methodology
Inherent risk represents how exposed a relationship or activity would be without controls. Control effectiveness measures how well existing controls reduce that inherent risk.
Residual risk is the remaining risk after applying controls, and it's this figure that matters when making decisions.
This three-part structure follows the conventional methodology described in the Wolfsberg Group's FAQs on risk assessments (2015): assess inherent risk, assess the design and operating effectiveness of controls, then derive residual risk.
Recalculate residual risk each time controls change, or you learn new information about the risk.
How to score compliance risk: a worked example
No regulator prescribes a formula. What supervisors expect is a method that is documented, applied consistently and easy to explain. A common approach has three steps:
Score inherent risk for each category on a fixed scale (for example, low, medium, high), using weighted risk factors.
Rate the controls that mitigate that category as strong, adequate or weak, testing both their design and how they operate in practice.
Read residual risk from a risk matrix that combines the two.
Inherent risk | Strong controls | Adequate controls | Weak controls |
High | Medium | High | High |
Medium | Low | Medium | High |
Low | Low | Low | Medium |
This matrix is illustrative, not a regulatory template. Each bank sets its own scale and thresholds.
Take correspondent banking. Inherent risk is high: cross-border flows and limited visibility of the respondent bank's customers. If respondent due diligence, payment screening and dedicated monitoring scenarios are tested and rated adequate, residual risk stays high, and the business line needs enhanced monitoring and senior sign-off.
If testing shows those controls are strong, residual risk falls to medium. If the monitoring scenarios have not been reviewed for years, the controls are weak and residual risk is high, whatever the policy document says.
Read more about: Difference between residual risk and inherent risk

AI-Driven Risk Scoring
Learn how azakaw leverages AI to dynamically assess risk by analysing behavioural patterns, ensuring accurate identification of subjective elements.
Documentation and audit-readiness
Every scoring decision needs a written explanation. Supervisors want to know how that score was developed, what data went into it and who approved it.
Internal audit, or another independent function, should then test the assessment itself: whether the methodology was followed and whether the scores still match the data.

How to conduct a bank compliance risk assessment
Conducting a compliance risk assessment involves five stages: defining the scope, mapping obligations, analysing risk factors, scoring and documenting the results, and monitoring them continuously.
The steps below are an example workflow, not a procedure prescribed by any regulator.
1. Define objectives and scope
Decide what your assessment will cover: a particular business line, the launch of a new product or the whole institution.
Scope creep is a problem here: an assessment that tries to cover everything at once will usually end up being shallow everywhere. Regulators still expect the institution-wide view to exist, so narrower assessments should feed into it, not replace it.
2. Map business lines and regulatory obligations
Each product and service needs to be matched against the specific regulatory requirements it creates.
3. Analyse risk factors across the customer lifecycle
Work from data, not impressions: the number of customers in each risk band, transaction volumes and values by product, exposure to higher-risk jurisdictions, and the share of customers onboarded remotely.
Risk isn't set in stone when you onboard a client. It needs to be reviewed again during periodic reviews and every time a trigger event happens: a change in ownership, an unusual transaction pattern or adverse media coverage about your customer.
Those customer-level changes should flow back into the institutional picture.
4. Score risks and document justifications
Assign your inherent risk scores, then carry out your control effectiveness assessment and work out the residual risk.
5. Monitor, review, and adjust regularly
The review cycle should be planned from the start.
Many banks refresh the assessment annually, and it should be revisited after changes in regulation, new product launches or M&A activity that changes the make-up of your bank's customer base.
Who is responsible for conducting the compliance risk assessment in a bank?
Responsibility usually sits with the compliance function or the MLRO, but it can't be done in isolation.
Heads of business lines have to contribute information about the products and customer groups involved, IT has to provide transactional and onboarding data, and senior management or the board needs to approve the final assessment and its implications for risk appetite.
Some regimes spell this out. Under the EU's AML Regulation, the business-wide risk assessment must be drawn up by the compliance officer and approved by the management body. Internal audit then provides the independent check.
Tools and technology to support compliance risk assessments
Manual, spreadsheet-based risk assessments become hard to maintain and to evidence as a bank grows. Four types of tools support most of the process.
AML software with risk engine
A centralised risk engine applies consistent scoring rules across the customer base, which reduces the inconsistency that arises when different analysts apply their own judgement.

Effortless Bank Compliance Software
Discover how azakaw enables your business to deliver exclusive banking services without compromising on stringent compliance requirements.
Compliance dashboards and heat maps
A compliance heat map gives senior managers and the board a clear view of where the risks are concentrated, by product, by location and by customer group, without having to read a 200-page report.
It also makes changes between assessment cycles easier to spot.
Audit trail and case management systems
Every risk score, every exception and every escalation should be recorded with a timestamp and the person responsible.
Integration with KYC & transaction monitoring
A risk assessment that doesn't link up with KYC software or a transaction monitoring system produces static scores that lose relevance.
When a customer's behaviour changes, integration means the risk rating can be updated promptly. The TD Bank case shows the cost of the alternative: FinCEN's consent order records a backlog of about 1.6 million customers who had never been risk-scored.

End-to-End Compliance Solution
Streamline compliance from identity and business verification to corporate compliance and AML transaction monitoring, reducing costs and complexity so you can scale with confidence.
Common mistakes to avoid
The same small group of errors recurs in enforcement cases involving weak risk assessment and monitoring: static assessments, inconsistent scoring, outdated frameworks and fragmented data.
Treating risk assessments as one-time exercises
Risk assessments performed once and never reviewed again go out of date as soon as circumstances change.
TD Bank's transaction monitoring programme, which saw no material scenario changes from 2014 to late 2022, is a recent example of controls falling behind the business.
Inconsistent risk scoring methods
When different teams or areas set up their own scoring logic for similar clients, the whole risk picture becomes incoherent. Supervisors and auditors look for one methodology applied consistently across business lines.
Failing to update frameworks after regulatory changes
New rules change what the assessment has to cover. The UAE's 2025 AML law brought proliferation financing into scope, the EU's AML Regulation adds sanctions evasion from July 2027, and FATF revised Recommendation 1 in 2025.
Manual data collection without centralised systems
Extracting information from separate spreadsheets and old systems brings delays and errors into each stage of the procedure.
Automation is not a cure on its own. Part of NatWest's problem was that its automated monitoring system treated cash paid in through cash centres as cheque deposits. Centralised systems still need accurate data mapping and regular testing.

AI-Powered AML Compliance Tool
Stop relying on fragile spreadsheets. Our platform centralises your data with precision mapping and continuous validation, delivering true, error-free compliance.
Regulatory frameworks that require or expect compliance risk assessments
There isn't a single global law laying out a fixed method for this. FATF sets the international standard, and each jurisdiction turns it into law or supervisory expectation in its own way.
The distinction matters: in some countries a documented risk assessment is a statutory duty, while in others it is something examiners expect to see.
Jurisdiction | Main instrument | Status of the risk assessment |
International | FATF Recommendation 1 | International standard, not law |
UAE (federal) | Federal Decree-Law No. 10 of 2025, Article 19; Cabinet Resolution No. 134 of 2025, Article 5 | Legal requirement |
DIFC | DFSA AML Module, chapter 5 | Regulatory rule |
Saudi Arabia | Anti-Money Laundering Law (Royal Decree M/20), Article 5 | Legal requirement |
European Union | Directive (EU) 2015/849, Article 8; Regulation (EU) 2024/1624, Article 10 from 10 July 2027 | Legal requirement |
United Kingdom | Money Laundering Regulations 2017, regulation 18 | Legal requirement |
United States | Bank Secrecy Act; FFIEC BSA/AML Examination Manual | Supervisory expectation; a proposed FinCEN rule would make it a regulatory requirement |
Singapore | MAS Notice 626, paragraph 4 | Regulatory requirement |
FATF's risk-based approach
The Financial Action Task Force (FATF) developed its 40 Recommendations based on one idea: apply more scrutiny to areas of higher risk and less where the risk is lower. In short, adopt a risk-based approach.
Recommendation 1 calls on countries to identify, assess and understand their money laundering, terrorist financing and proliferation financing risks, and to require financial institutions to identify, assess and mitigate their own.
FATF Recommendations are not law in themselves. They bind a bank only once a country writes them into its own legislation or rules. FATF revised Recommendation 1 in February 2025 to stress proportionality and encourage simplified measures where risk is lower.

UAE: federal law, the CBUAE and the DFSA
Federal Decree-Law No. 10 of 2025, in force since 14 October 2025, replaced the UAE's 2018 AML law. Article 19 requires financial institutions to identify, assess, document and keep up to date their money laundering, terrorist financing and proliferation financing risks.
The executive regulations, Cabinet Resolution No. 134 of 2025, list the factors to cover: customers, countries or geographic areas, products, services, transactions and delivery channels.
The Central Bank of the UAE (CBUAE) has also published non-binding best practices on institutional risk assessments, which recommend updating the assessment at least annually and after trigger events.
The Dubai Financial Services Authority (DFSA) applies risk-based customer due diligence (CDD) requirements aligned with FATF for DIFC-regulated businesses. Its AML Module devotes chapter 5 to the business risk assessment and chapter 6 to customer risk assessment. The DIFC and ADGM have their own rulebooks, so a group should confirm which regime applies to each entity.
Saudi Arabia takes a similar approach. Article 5 of its Anti-Money Laundering Law requires financial institutions to identify, assess, document and regularly update their risks.
Read more about:
European Union: what 6AMLD does and does not require
Directive (EU) 2018/1673, widely known as 6AMLD, harmonised the definition of money laundering offences across member states, set out 22 categories of predicate offences and extended liability to legal persons. It is a criminal law instrument. It does not itself require banks to carry out risk assessments.
From a risk assessment perspective, this means EU banks need to consider a wider range of underlying crime in their categorisation of both customers and products.
The duty to assess risk comes from Article 8 of Directive (EU) 2015/849, which requires obliged entities to identify, assess and document their risks. From 10 July 2027, Article 10 of the AML Regulation (EU) 2024/1624 replaces it with a directly applicable business-wide risk assessment covering money laundering, terrorist financing and the evasion of targeted financial sanctions.
One source of confusion: the directive that accompanies the new regulation, Directive (EU) 2024/1640, is also commonly labelled 6AMLD.

Fully Compliant Across Jurisdictions
Whether you are a large global firm or a startup, operating in one market or across multiple jurisdictions, our KYC & KYB solutions provide the flexibility and robustness you need.
United Kingdom: the Money Laundering Regulations and the FCA
The UK did not opt in to the 2018 directive. Its own requirement sits in regulation 18 of the Money Laundering Regulations 2017: firms must identify and assess their risks, taking into account customers, countries, products or services, transactions and delivery channels, and keep an up-to-date written record.
The FCA expects UK banks to have systems and controls proportional to the risks associated with each part of their business. NatWest was convicted under the earlier 2007 regulations for failing to apply risk-based ongoing monitoring to a single customer.
United States: FinCEN and the BSA
The Bank Secrecy Act requires US banks to maintain an AML programme. It does not currently impose a uniform, stand-alone risk assessment requirement. The FFIEC BSA/AML Examination Manual says a risk assessment is not a specific legal requirement, while making clear that examiners expect a well-developed one.
That may change. In April 2026, FinCEN proposed a rule that would make risk assessment processes an explicit part of a bank's internal controls. At the time of writing, no final rule has been published.
The TD Bank case shows what happens when a programme stops keeping pace with the bank's risk. According to the US Department of Justice, the bank added no new transaction monitoring scenarios and made no material changes to existing ones from 2014 to late 2022. Between January 2018 and April 2024, 92% of its transaction volume, around US$18.3 trillion, went unmonitored.
Singapore: MAS Notice 626
Under Notice 626, the Monetary Authority of Singapore (MAS) requires continuous customer due diligence that matches the client's risk classification. The Notice also requires banks to assess enterprise-level risks across customers, countries, products, services, transactions, and delivery channels.

FAQs
How often should a bank perform a compliance risk assessment?
Many banks carry out a comprehensive institutional risk assessment once a year, with individual customer risk ratings reviewed on a cycle set by their risk level.
No single interval applies everywhere. US examination guidance sets no fixed schedule, while the CBUAE's best practices recommend updating at least annually.
Customer review cycles are set by each bank's own policy: as an illustration, high-risk customers are often reviewed every year and lower-risk customers every few years.
Certain trigger events should prompt a reassessment right away.
What tools are used for risk assessment in banking compliance?
Financial institutions rely upon AML software with a built-in risk engine, compliance dashboards or heat maps, case management tools, an audit trail and KYC software integrated with transaction monitoring systems.
What is the difference between inherent and residual risk?
Inherent risk refers to the amount of risk present before any controls are applied. Residual risk is the amount left over after the controls. The residual risk is the figure that guides ongoing decisions.
Is a compliance risk assessment required by law?
It depends on the jurisdiction. A documented risk assessment is an explicit legal requirement in the UAE, Saudi Arabia, the EU and the UK. In the United States, it is currently a supervisory expectation, which a FinCEN rule proposed in April 2026 would turn into a regulatory requirement.
FATF Recommendation 1 is the international standard behind all of these regimes, but it is not law in itself.
How does a compliance risk assessment support AML programmes?
A risk assessment forms the base upon which an entire AML programme is constructed. It determines which clients require enhanced due diligence, the frequency with which accounts are reviewed and how transaction monitoring thresholds are set.
How can compliance risk assessments be automated or digitised?
Automation works through a centralised risk engine that retrieves information from KYC records, transaction history and external watchlists and then applies consistent scoring rules automatically. This reduces manual error, helps keep risk ratings current as customer behaviour changes, and generates the audit trail supervisors will expect to see.
Getting the bank compliance risk assessment right
A bank compliance risk assessment proves its value when a supervisor or auditor asks why a control is set the way it is. If the answer traces back to a documented score, the data behind it and a named approver, the assessment is doing its job.
Both enforcement cases in this guide failed that test.
Three questions show whether your own assessment would hold up:
Does it reflect the law as it stands today? That includes proliferation financing under the UAE's 2025 AML law and, from July 2027, sanctions evasion under the EU's AML Regulation.
Can you evidence every residual risk score? That means the inherent risk rating, the control rating behind it, and the date those controls were last tested.
How quickly do changes reach it? When a customer's rating changes or a new product launches, the institutional assessment should not wait for the next annual cycle.
This is a question of safeguarding your business and your clients.

Fully Compliant Across Jurisdictions
azakaw helps banks apply AI-driven risk scoring, keep customer risk ratings current through automated KYC and KYB refreshes, and manage alerts and cases in one platform.
Related articles
DISCLAIMER: This content is provided for general informational purposes and does not constitute legal or regulatory advice. AML and compliance requirements vary by jurisdiction, business type and regulatory status. Organisations should consult the applicable legislation, regulator guidance and qualified legal or compliance professionals where necessary.
Sources
FCA: NatWest fined £264.8 million
Judiciary UK: FCA v NatWest sentencing remarks
US Department of Justice: TD Bank guilty plea
FinCEN: TD Bank consent order
FATF: February 2025 revision of Recommendation 1
CBUAE Rulebook: Federal Decree-Law No. 10 of 2025
CBUAE Rulebook: Cabinet Resolution No. 134 of 2025
CBUAE: best practices on institutional risk assessments
Saudi Anti-Money Laundering Law
EUR-Lex: Regulation (EU) 2024/1624
EUR-Lex: Directive (EU) 2018/1673
UK Money Laundering Regulations 2017, regulation 18
FFIEC BSA/AML Examination Manual: risk assessment
Federal Register: FinCEN proposed AML/CFT program rule
MAS Notice 626
Wolfsberg Group: FAQs on risk assessments
Basel Committee: Compliance and the compliance function in banks






