top of page

azakaw named an IDC Innovator in Middle East Regulatory Technology Providers 2026 Report

azakaw colored logo.png
Arrow 6.png

Bank compliance risk assessment: how to conduct and score one

Writer: azakaw
azakaw
Jul 1
15 min read

Updated: 2 hours ago


In October 2024, TD Bank agreed to pay around US$3 billion in penalties to US authorities over failures in its anti-money laundering programme. No single missed transaction caused this. It was years of gaps in transaction monitoring coverage, customers who had never been properly risk-rated, and a transaction monitoring programme essentially unchanged from 2014 to late 2022.


A bank compliance risk assessment exists to stop that kind of drift. It shows where the bank's exposure sits and whether its controls still match it.


Today, we'll cover how to conduct a bank compliance risk assessment, the tools you can use and the mistakes to avoid to safeguard your business.

Bank compliance risk assessment

Key Takeaways

  • A bank compliance risk assessment identifies, measures and documents regulatory risks.

  • Effective assessments distinguish between inherent risk, control effectiveness and residual risk.

  • Banks typically assess risk across customers, products and services, jurisdictions, delivery channels and, in many frameworks, transaction characteristics such as volume and complexity.

  • A risk assessment should be treated as a continuous process rather than an annual documentation exercise.

  • Weak risk assessments can cause downstream failures because transaction-monitoring thresholds, escalation rules, review frequencies and enhanced due diligence decisions all depend on the quality of the underlying risk methodology.

  • Consistent scoring, reliable data, independent validation and documented justifications are critical because supervisors expect banks to explain how each risk rating was calculated and why each control is proportionate.

  • AML software, centralised risk engines, compliance dashboards, case management, audit trails and integration with KYC and transaction monitoring can make assessments more consistent, dynamic and easier to evidence.

  • Regulatory requirements differ by jurisdiction.


What is a bank compliance risk assessment?

A bank compliance risk assessment is a systematic approach to finding, measuring and recording the regulatory risks that a bank encounters, mainly money laundering, terrorist financing, sanctions breaches, fraud and KYC failures, so that controls can be set in proportion to that risk.


It works at two levels. The institutional (or enterprise-wide) risk assessment looks at the bank as a whole: its customer base, products, geographies and delivery channels.


Customer risk ratings then apply that methodology to individual relationships. This guide focuses on the institutional assessment and shows where customer ratings feed into it.


Make a mistake in your risk assessment and every control built on it, including thresholds, escalation rules, and review cycles, will inherit that error.



Difference between compliance risk and other risk types

The Basel Committee on Banking Supervision describes compliance risk as the risk of legal or regulatory sanctions, material financial loss or reputational damage that a bank may suffer when it fails to comply with the laws, regulations and standards that apply to its banking activities.


Credit risk asks whether a borrower will repay the loan. Operational risk asks whether a failure in your own processes, systems, or personnel will lead to losses.


Compliance risk looks at something else: does this particular business relationship, product or financial deal pose any risk to your bank of breaking the law or violating regulations?



Regulatory reasons for performing compliance-specific risk assessments

Regulators expect banks not only to have controls, but to explain why they exist and how they relate to actual risk. A risk assessment forms the documented evidence linking the two.


Without it, a bank cannot demonstrate its risk-based approach to a supervisor, and every control will appear arbitrary rather than proportionate.


The US Department of Justice described TD Bank's programme in similar terms: elements that looked adequate on paper, with fundamental flaws underneath.

What are the common compliance risks for banks?

  • Money laundering via customer accounts, trade finance, or correspondent banking relationships

  • Sanctions breaches involving OFAC, UN or EU-designated people and companies

  • Terrorist financing risk in cash-intensive or cross-border business lines

  • Proliferation financing, which FATF and the UAE's 2025 AML law now treat alongside money laundering and terrorist financing

  • KYC and onboarding failures letting high-risk clients in without proper checks

  • Fraud exposure related to poor transaction monitoring or outdated customer risk scores


Read also: What is KYC?

What are the key components of a compliance risk assessment?

A compliance risk assessment has four elements: determining your regulatory exposure, categorising risk across customers, products, jurisdictions and delivery channels, scoring inherent and residual risk, and documenting each step so it survives an audit.


  1. Identifying regulatory exposure

Start by listing each regulatory obligation by type.


AML/CFT, sanctions, fraud and KYC rules rarely come from the same instrument or the same regulator.


Read also: KYC in banking


  1. Risk categorisation

Almost all frameworks categorise risk across four dimensions:

  • Customer risk: occupation or business activity, ownership structure, PEP status, source of funds

  • Product and service risk: cash-intensive products, trade finance, correspondent banking

  • Jurisdictional risk: FATF grey and black lists, sanctions exposure, local AML supervisory strength

  • Delivery channel risk: face-to-face onboarding versus remote digital channels


Several regulators add a fifth: transactions, including their volume and complexity. The UK's Money Laundering Regulations 2017 and the DFSA's AML Module both list transactions explicitly.


Fowler Oldfield, the jewellery business at the centre of NatWest's £264.8 million fine, shows what happens when categorisation slips. NatWest rated the customer high risk at onboarding, then erroneously downgraded it to low risk in December 2013 and moved it to medium in 2014. The rating only returned to high in March 2016.


Over the relationship, the business deposited about £365 million, of which around £264 million was cash, at up to £1.8 million a day at its peak.


For more than two years, the monitoring applied to the account did not reflect that risk. Southwark Crown Court imposed the fine in December 2021, in the FCA's first criminal prosecution under the Money Laundering Regulations 2007.



  1. Risk scoring methodology

Inherent risk represents how exposed a relationship or activity would be without controls. Control effectiveness measures how well existing controls reduce that inherent risk.


Residual risk is the remaining risk after applying controls, and it's this figure that matters when making decisions.


This three-part structure follows the conventional methodology described in the Wolfsberg Group's FAQs on risk assessments (2015): assess inherent risk, assess the design and operating effectiveness of controls, then derive residual risk.

Recalculate residual risk each time controls change, or you learn new information about the risk.


How to score compliance risk: a worked example

No regulator prescribes a formula. What supervisors expect is a method that is documented, applied consistently and easy to explain. A common approach has three steps:

  1. Score inherent risk for each category on a fixed scale (for example, low, medium, high), using weighted risk factors.

  2. Rate the controls that mitigate that category as strong, adequate or weak, testing both their design and how they operate in practice.

  3. Read residual risk from a risk matrix that combines the two.

Inherent risk

Strong controls

Adequate controls

Weak controls

High

Medium

High

High

Medium

Low

Medium

High

Low

Low

Low

Medium

This matrix is illustrative, not a regulatory template. Each bank sets its own scale and thresholds.


Take correspondent banking. Inherent risk is high: cross-border flows and limited visibility of the respondent bank's customers. If respondent due diligence, payment screening and dedicated monitoring scenarios are tested and rated adequate, residual risk stays high, and the business line needs enhanced monitoring and senior sign-off.


If testing shows those controls are strong, residual risk falls to medium. If the monitoring scenarios have not been reviewed for years, the controls are weak and residual risk is high, whatever the policy document says.



AI-Driven Risk Scoring

Learn how azakaw leverages AI to dynamically assess risk by analysing behavioural patterns, ensuring accurate identification of subjective elements.



Documentation and audit-readiness

Every scoring decision needs a written explanation. Supervisors want to know how that score was developed, what data went into it and who approved it.


Internal audit, or another independent function, should then test the assessment itself: whether the methodology was followed and whether the scores still match the data.

How to conduct a bank compliance risk assessment

Conducting a compliance risk assessment involves five stages: defining the scope, mapping obligations, analysing risk factors, scoring and documenting the results, and monitoring them continuously.


The steps below are an example workflow, not a procedure prescribed by any regulator.


1. Define objectives and scope

Decide what your assessment will cover: a particular business line, the launch of a new product or the whole institution.


Scope creep is a problem here: an assessment that tries to cover everything at once will usually end up being shallow everywhere. Regulators still expect the institution-wide view to exist, so narrower assessments should feed into it, not replace it.


2. Map business lines and regulatory obligations

Each product and service needs to be matched against the specific regulatory requirements it creates.


3. Analyse risk factors across the customer lifecycle

Work from data, not impressions: the number of customers in each risk band, transaction volumes and values by product, exposure to higher-risk jurisdictions, and the share of customers onboarded remotely.


Risk isn't set in stone when you onboard a client. It needs to be reviewed again during periodic reviews and every time a trigger event happens: a change in ownership, an unusual transaction pattern or adverse media coverage about your customer. 


Those customer-level changes should flow back into the institutional picture.


4. Score risks and document justifications

Assign your inherent risk scores, then carry out your control effectiveness assessment and work out the residual risk.


5. Monitor, review, and adjust regularly

The review cycle should be planned from the start.


Many banks refresh the assessment annually, and it should be revisited after changes in regulation, new product launches or M&A activity that changes the make-up of your bank's customer base.


Who is responsible for conducting the compliance risk assessment in a bank?

Responsibility usually sits with the compliance function or the MLRO, but it can't be done in isolation.


Heads of business lines have to contribute information about the products and customer groups involved, IT has to provide transactional and onboarding data, and senior management or the board needs to approve the final assessment and its implications for risk appetite.


Some regimes spell this out. Under the EU's AML Regulation, the business-wide risk assessment must be drawn up by the compliance officer and approved by the management body. Internal audit then provides the independent check.


Tools and technology to support compliance risk assessments

Manual, spreadsheet-based risk assessments become hard to maintain and to evidence as a bank grows. Four types of tools support most of the process.


AML software with risk engine

A centralised risk engine applies consistent scoring rules across the customer base, which reduces the inconsistency that arises when different analysts apply their own judgement.


Effortless Bank Compliance Software

Discover how azakaw enables your business to deliver exclusive banking services without compromising on stringent compliance requirements.



Compliance dashboards and heat maps

A compliance heat map gives senior managers and the board a clear view of where the risks are concentrated, by product, by location and by customer group, without having to read a 200-page report.


It also makes changes between assessment cycles easier to spot.


Audit trail and case management systems

Every risk score, every exception and every escalation should be recorded with a timestamp and the person responsible.


Integration with KYC & transaction monitoring

A risk assessment that doesn't link up with KYC software or a transaction monitoring system produces static scores that lose relevance.


When a customer's behaviour changes, integration means the risk rating can be updated promptly. The TD Bank case shows the cost of the alternative: FinCEN's consent order records a backlog of about 1.6 million customers who had never been risk-scored.


End-to-End Compliance Solution

Streamline compliance from identity and business verification to corporate compliance and AML transaction monitoring, reducing costs and complexity so you can scale with confidence.



Common mistakes to avoid

The same small group of errors recurs in enforcement cases involving weak risk assessment and monitoring: static assessments, inconsistent scoring, outdated frameworks and fragmented data.


Treating risk assessments as one-time exercises

Risk assessments performed once and never reviewed again go out of date as soon as circumstances change.


TD Bank's transaction monitoring programme, which saw no material scenario changes from 2014 to late 2022, is a recent example of controls falling behind the business.


Inconsistent risk scoring methods

When different teams or areas set up their own scoring logic for similar clients, the whole risk picture becomes incoherent. Supervisors and auditors look for one methodology applied consistently across business lines.


Failing to update frameworks after regulatory changes

New rules change what the assessment has to cover. The UAE's 2025 AML law brought proliferation financing into scope, the EU's AML Regulation adds sanctions evasion from July 2027, and FATF revised Recommendation 1 in 2025.


Manual data collection without centralised systems

Extracting information from separate spreadsheets and old systems brings delays and errors into each stage of the procedure.


Automation is not a cure on its own. Part of NatWest's problem was that its automated monitoring system treated cash paid in through cash centres as cheque deposits. Centralised systems still need accurate data mapping and regular testing.


AI-Powered AML Compliance Tool

Stop relying on fragile spreadsheets. Our platform centralises your data with precision mapping and continuous validation, delivering true, error-free compliance.



Regulatory frameworks that require or expect compliance risk assessments

There isn't a single global law laying out a fixed method for this. FATF sets the international standard, and each jurisdiction turns it into law or supervisory expectation in its own way.


The distinction matters: in some countries a documented risk assessment is a statutory duty, while in others it is something examiners expect to see.

Jurisdiction

Main instrument

Status of the risk assessment

International

FATF Recommendation 1

International standard, not law

UAE

(federal)

Federal Decree-Law No. 10 of 2025, Article 19; Cabinet Resolution No. 134 of 2025, Article 5

Legal requirement

DIFC

DFSA AML Module, chapter 5

Regulatory rule

Saudi

Arabia

Anti-Money Laundering Law (Royal Decree M/20), Article 5

Legal requirement

European

Union

Directive (EU) 2015/849, Article 8; Regulation (EU) 2024/1624, Article 10 from 10 July 2027

Legal requirement

United

Kingdom

Money Laundering Regulations 2017, regulation 18

Legal requirement

United

States

Bank Secrecy Act; FFIEC BSA/AML Examination Manual

Supervisory expectation; a proposed FinCEN rule would make it a regulatory requirement

Singapore

MAS Notice 626, paragraph 4

Regulatory requirement

FATF's risk-based approach

The Financial Action Task Force (FATF) developed its 40 Recommendations based on one idea: apply more scrutiny to areas of higher risk and less where the risk is lower. In short, adopt a risk-based approach.


Recommendation 1 calls on countries to identify, assess and understand their money laundering, terrorist financing and proliferation financing risks, and to require financial institutions to identify, assess and mitigate their own.


FATF Recommendations are not law in themselves. They bind a bank only once a country writes them into its own legislation or rules. FATF revised Recommendation 1 in February 2025 to stress proportionality and encourage simplified measures where risk is lower.

UAE: federal law, the CBUAE and the DFSA

Federal Decree-Law No. 10 of 2025, in force since 14 October 2025, replaced the UAE's 2018 AML law. Article 19 requires financial institutions to identify, assess, document and keep up to date their money laundering, terrorist financing and proliferation financing risks.


The executive regulations, Cabinet Resolution No. 134 of 2025, list the factors to cover: customers, countries or geographic areas, products, services, transactions and delivery channels.


The Central Bank of the UAE (CBUAE) has also published non-binding best practices on institutional risk assessments, which recommend updating the assessment at least annually and after trigger events.


The Dubai Financial Services Authority (DFSA) applies risk-based customer due diligence (CDD) requirements aligned with FATF for DIFC-regulated businesses. Its AML Module devotes chapter 5 to the business risk assessment and chapter 6 to customer risk assessment. The DIFC and ADGM have their own rulebooks, so a group should confirm which regime applies to each entity.


Saudi Arabia takes a similar approach. Article 5 of its Anti-Money Laundering Law requires financial institutions to identify, assess, document and regularly update their risks.


Read more about:


European Union: what 6AMLD does and does not require

Directive (EU) 2018/1673, widely known as 6AMLD, harmonised the definition of money laundering offences across member states, set out 22 categories of predicate offences and extended liability to legal persons. It is a criminal law instrument. It does not itself require banks to carry out risk assessments.


From a risk assessment perspective, this means EU banks need to consider a wider range of underlying crime in their categorisation of both customers and products.


The duty to assess risk comes from Article 8 of Directive (EU) 2015/849, which requires obliged entities to identify, assess and document their risks. From 10 July 2027, Article 10 of the AML Regulation (EU) 2024/1624 replaces it with a directly applicable business-wide risk assessment covering money laundering, terrorist financing and the evasion of targeted financial sanctions.


One source of confusion: the directive that accompanies the new regulation, Directive (EU) 2024/1640, is also commonly labelled 6AMLD.


Fully Compliant Across Jurisdictions

Whether you are a large global firm or a startup, operating in one market or across multiple jurisdictions, our KYC & KYB solutions provide the flexibility and robustness you need.



United Kingdom: the Money Laundering Regulations and the FCA

The UK did not opt in to the 2018 directive. Its own requirement sits in regulation 18 of the Money Laundering Regulations 2017: firms must identify and assess their risks, taking into account customers, countries, products or services, transactions and delivery channels, and keep an up-to-date written record.


The FCA expects UK banks to have systems and controls proportional to the risks associated with each part of their business. NatWest was convicted under the earlier 2007 regulations for failing to apply risk-based ongoing monitoring to a single customer.


United States: FinCEN and the BSA

The Bank Secrecy Act requires US banks to maintain an AML programme. It does not currently impose a uniform, stand-alone risk assessment requirement. The FFIEC BSA/AML Examination Manual says a risk assessment is not a specific legal requirement, while making clear that examiners expect a well-developed one.


That may change. In April 2026, FinCEN proposed a rule that would make risk assessment processes an explicit part of a bank's internal controls. At the time of writing, no final rule has been published.


The TD Bank case shows what happens when a programme stops keeping pace with the bank's risk. According to the US Department of Justice, the bank added no new transaction monitoring scenarios and made no material changes to existing ones from 2014 to late 2022. Between January 2018 and April 2024, 92% of its transaction volume, around US$18.3 trillion, went unmonitored.


Singapore: MAS Notice 626

Under Notice 626, the Monetary Authority of Singapore (MAS) requires continuous customer due diligence that matches the client's risk classification. The Notice also requires banks to assess enterprise-level risks across customers, countries, products, services, transactions, and delivery channels.

FAQs

How often should a bank perform a compliance risk assessment?

Many banks carry out a comprehensive institutional risk assessment once a year, with individual customer risk ratings reviewed on a cycle set by their risk level.


No single interval applies everywhere. US examination guidance sets no fixed schedule, while the CBUAE's best practices recommend updating at least annually.


Customer review cycles are set by each bank's own policy: as an illustration, high-risk customers are often reviewed every year and lower-risk customers every few years.


Certain trigger events should prompt a reassessment right away.


What tools are used for risk assessment in banking compliance?

Financial institutions rely upon AML software with a built-in risk engine, compliance dashboards or heat maps, case management tools, an audit trail and KYC software integrated with transaction monitoring systems.


What is the difference between inherent and residual risk?

Inherent risk refers to the amount of risk present before any controls are applied. Residual risk is the amount left over after the controls. The residual risk is the figure that guides ongoing decisions.


Is a compliance risk assessment required by law?

It depends on the jurisdiction. A documented risk assessment is an explicit legal requirement in the UAE, Saudi Arabia, the EU and the UK. In the United States, it is currently a supervisory expectation, which a FinCEN rule proposed in April 2026 would turn into a regulatory requirement.


FATF Recommendation 1 is the international standard behind all of these regimes, but it is not law in itself.


How does a compliance risk assessment support AML programmes?

A risk assessment forms the base upon which an entire AML programme is constructed. It determines which clients require enhanced due diligence, the frequency with which accounts are reviewed and how transaction monitoring thresholds are set.


How can compliance risk assessments be automated or digitised?

Automation works through a centralised risk engine that retrieves information from KYC records, transaction history and external watchlists and then applies consistent scoring rules automatically. This reduces manual error, helps keep risk ratings current as customer behaviour changes, and generates the audit trail supervisors will expect to see.


Getting the bank compliance risk assessment right

A bank compliance risk assessment proves its value when a supervisor or auditor asks why a control is set the way it is. If the answer traces back to a documented score, the data behind it and a named approver, the assessment is doing its job.

Both enforcement cases in this guide failed that test.


Three questions show whether your own assessment would hold up:

  • Does it reflect the law as it stands today? That includes proliferation financing under the UAE's 2025 AML law and, from July 2027, sanctions evasion under the EU's AML Regulation.

  • Can you evidence every residual risk score? That means the inherent risk rating, the control rating behind it, and the date those controls were last tested.

  • How quickly do changes reach it? When a customer's rating changes or a new product launches, the institutional assessment should not wait for the next annual cycle.


This is a question of safeguarding your business and your clients.


Fully Compliant Across Jurisdictions

azakaw helps banks apply AI-driven risk scoring, keep customer risk ratings current through automated KYC and KYB refreshes, and manage alerts and cases in one platform.



Related articles


DISCLAIMER: This content is provided for general informational purposes and does not constitute legal or regulatory advice. AML and compliance requirements vary by jurisdiction, business type and regulatory status. Organisations should consult the applicable legislation, regulator guidance and qualified legal or compliance professionals where necessary.


Sources

  • FCA: NatWest fined £264.8 million

  • Judiciary UK: FCA v NatWest sentencing remarks

  • US Department of Justice: TD Bank guilty plea

  • FinCEN: TD Bank consent order

  • FATF: February 2025 revision of Recommendation 1

  • CBUAE Rulebook: Federal Decree-Law No. 10 of 2025

  • CBUAE Rulebook: Cabinet Resolution No. 134 of 2025

  • CBUAE: best practices on institutional risk assessments

  • Saudi Anti-Money Laundering Law

  • EUR-Lex: Regulation (EU) 2024/1624

  • EUR-Lex: Directive (EU) 2018/1673

  • UK Money Laundering Regulations 2017, regulation 18

  • FFIEC BSA/AML Examination Manual: risk assessment

  • Federal Register: FinCEN proposed AML/CFT program rule

  • MAS Notice 626

  • Wolfsberg Group: FAQs on risk assessments

  • Basel Committee: Compliance and the compliance function in banks

 
 
bottom of page