The AML risk assessment: the foundation of your compliance programme

Supervisors expect every UAE business with AML duties to have a documented risk assessment. What it should cover and how often to update it.

Illustration of a shield with a check mark and a flagged network node

When an AML supervisor inspects a business, one of the first documents they ask for is the business-wide risk assessment. It is the foundation on which everything else is meant to be built: policies, customer due diligence, screening, monitoring and training. Without it, the rest of a compliance programme has nothing to stand on.

What the risk assessment does

It identifies how your business could be used for money laundering, terrorist financing or proliferation financing, how serious those risks are, and what you do about them. In short, it explains why your controls look the way they do.

What it should cover

A good assessment looks at the main sources of risk in your business:

  • Customers: individuals or companies, residents or non-residents, complex ownership structures, politically exposed persons.
  • Products and services: which are attractive to someone trying to move or disguise money.
  • Geographies: where customers, funds and counterparties are located.
  • Delivery channels: face-to-face, remote or through intermediaries.
  • Transactions: cash, high-value or unusual payment patterns.

For each, it considers the inherent risk, the controls in place and the residual risk that remains.

Making it useful

The most common weakness is a generic document that could belong to any business. Supervisors look for an assessment that reflects your actual customers, products and processes, and that clearly links to the controls you apply. A real estate broker, a gold trader and an accounting firm should have very different assessments.

Keeping it current

Review the assessment at least once a year, and sooner when something changes: a new product, a new market, a new type of customer, or new guidance from your supervisor. Keep a record of each review and what changed as a result.

Where to start

Gather a picture of your customer base and activities, score the risks using a consistent method, document the controls, and agree the result with senior management.

If you would like help building or refreshing your risk assessment, please get in touch.

This article is general information based on the rules as we understand them at the date of publication. It is not advice on your circumstances. Laws and practice change, so please speak to us before acting on it.

Consultation

Book a consultation

Tell us a little about your business and what you need. We will come back to you to arrange a conversation, usually by phone or WhatsApp.