AML Business Risk Assessment
An AML business risk assessment is the documented study of the money laundering, terrorism financing, and proliferation financing risks your business carries, scored across your customers, products, geographies, and delivery channels, and set against the controls you rely on. UAE law requires every financial institution, DNFBP, and VASP to identify, assess, understand, and document those risks and keep the assessment current [Cabinet Resolution No. 134 of 2025, Article 5(1)]. We build it, score it, and hand you the methodology so your team can maintain it.
A note on the name before anything else, because it causes real confusion. Business risk assessment has two meanings. In general management, it means assessing strategic, operational, and financial risk, which this page is not about. In UAE AML practice, it is the statutory enterprise-wide assessment of financial crime risk, the same document your supervisor may call a business-wide, firm-wide, or enterprise-wide risk assessment, practice-wide, company-wide, institution-wide, or simply the EWRA, or ML/FT/PF risk assessment, or internal risk assessment (IRA).
Scored on your data, not a template.
Get an AML business risk assessment built from your own customer, product, and transaction profile, with the methodology handed over.
What Is a Business Risk Assessment Under UAE AML Law?
It is the analytical foundation of your entire AML programme, and every control you operate flows from it. Your policies must be proportionate to the risks it identifies [Cabinet Resolution No. 134 of 2025, Article 5(2)(b)]. EWRA helps you determine the risks and controls you need to consider when performing customer risk assessments. Simplified due diligence is defensible only where it supports that [Article 5(3)]. Enhanced due diligence triggers come from the risks it names [Article 5(2)(c)]. Your customer rating model, monitoring thresholds, screening configuration, and training content all inherit from enterprise-wide ML/FT/PF risk assessment.
The assessment answers three questions in sequence, and skipping any of them is the most common structural failure we see. What risk does this business face before any controls are applied, which is inherent risk. Control effectiveness is how well the controls we operate reduce it. What is left, which is residual risk, is the risk the business is willing to carry.
The EWRA must be documented. An enterprise-wide risk assessment that lives in the compliance officer’s head, however sophisticated, does not satisfy Article 5(1), and it cannot be tested by the independent audit function required under Article 21.
Business Risk Assessment vs Customer Risk Assessment
Two different exercises that get conflated constantly. The business risk assessment covers the risk your whole firm carries and drives your policies and controls. A customer risk assessment rates an individual customer at onboarding and during periodic reviews, and it operates within those controls. You need both, and the customer risk methodology is one of the outputs the business assessment justifies. If your customer rating model cannot be traced back to a finding in your business assessment, an inspector will ask where the ratings came from.
What Is EWRA? Enterprise-Wide Risk Assessment Explained
EWRA stands for enterprise-wide risk assessment. In AML, it means the same document as the business risk assessment: a single assessment covering the whole entity rather than one business line, product, or branch. The term comes from international practice and has become common in UAE compliance conversations, particularly in the financial free zones and among firms with group reporting lines.
Enterprise-wide is the important half of the phrase. An assessment covering only your largest business line, or only the customers your compliance team happens to see, is not enterprise-wide, and the gaps it leaves tend to sit exactly where risk concentrates: a small side business, an introducer channel, a legacy customer book nobody has reviewed. We scope the assessment to the whole legal entity and, where relevant, to the group structure around it.
Firm-Wide AML Risk Assessment: The Same Document, Four Names
Business risk assessment, business-wide risk assessment, firm-wide risk assessment, and enterprise-wide risk assessment all describe the same obligation. The variation comes from which rulebook or which group a firm grew up with, not from any difference in what the law requires. Article 5(1) of Cabinet Resolution No. 134 of 2025 sets one requirement, and the DFSA AML Module uses the term business risk assessment for DIFC Relevant Persons, which is why firms operating across the mainland and the financial free zones often hold documents with two different titles and identical purposes.
Practical consequence: if a bank, an auditor, or a supervisor asks for your firm-wide risk assessment and you hand over something called an EWRA, you have answered the question. What matters is scope and method, not the label on the cover page. Version control matters, because a group that maintains a firm-wide assessment centrally and a local one separately usually ends up with two documents that disagree, and the disagreement is the finding.
Is a Business Risk Assessment Mandatory in the UAE?
Yes, for every entity in scope, and it is not a light obligation. Article 5(1) of Cabinet Resolution No. 134 of 2025 requires identifying, assessing, understanding, and documenting risks; considering the results of the National Risk Assessment; retaining the study; and keeping the assessment updated. It sits inside the risk-based approach mandated by Article 19 of Federal Decree-Law No. 10 of 2025, and its absence is punishable in itself, with no money laundering required.
It is also the first document requested during a supervisory visit. When an inspection or review begins, examiners usually request three things before anything else: your AML policy and procedures, your risk assessment, and your compliance officer’s appointment. Two of those three depend on this one, which is why a weak assessment rarely produces a single finding. It can produce findings across CDD, monitoring, training, and reporting at the same time, because they all depend on it.
Not sure whether your current assessment would hold up?
Send us your latest version and we will tell you where the methodology would be challenged, with no obligation.
UAE AML Laws Behind Your Business Risk Assessment
Every assessment we prepare is mapped to the provisions that create the duty and shape its content:
| Legal Instrument | What It Requires | What It Means for Your Business Risk Assessment |
|---|---|---|
| Federal Decree-Law No. 10 of 2025 | The primary AML/CFT/CPF statute, in force 14 October 2025, repealing FDL No. 20 of 2018 (Article 41). Preventive measures on a risk-based approach (Article 19), STR duties (Article 18), supervisory powers (Article 16), and administrative penalties of AED 10,000 to AED 5,000,000 per violation (Article 17). Proliferation financing becomes a standalone offence. | The risk-based approach starts here, and PF must be assessed alongside ML and TF. Assessments written before October 2025 almost never cover proliferation financing, which makes legacy alignment the first thing we check. |
| Cabinet Resolution No. 134 of 2025, Article 5(1) | Identify, assess, understand, and document ML/TF/PF risks, take the National Risk Assessment results into account, retain the study, and keep it updated on an ongoing basis. | Your scope and your standard of proof in one article. Every rating in the assessment should be traceable to it, including the NRA integration that assessments most often omit. |
| Cabinet Resolution No. 134 of 2025, Articles 5(2) and 5(3) | Senior-management-approved policies, controls, and procedures proportionate to the nature and size of the business, with implementation monitored and effectiveness assessed; aligned with National Risk Assessment and Sectoral Risk Assessment, EDD for high-risk situations; simplified due diligence only where risk allows. | Why the assessment cannot be cosmetic. Proportionate means proportionate to something measured, and simplified due diligence applied without an assessment behind it is indefensible. |
| Cabinet Resolution No. 134 of 2025, Articles 6 to 10 and 16 | CDD and verification, thresholds including AED 55,000 for occasional transaction and AED 3,500 for wire transfer for Financial Institutions, ongoing monitoring, beneficial ownership to the 25% standard with the fallback cascade, and PEP identification. | The specific exposures the assessment has to score: customer type, ownership opacity, transaction size against your thresholds, and PEP presence in your book. |
| Cabinet Resolution No. 134 of 2025, Articles 20, 21, 22, 23 and 25 | Third-party reliance conditions, training and an independent audit function, the compliance officer at management level, countermeasures for high-risk countries, and record keeping with prompt retrieval. | Delivery channel risk where you rely on introducers, geographic risk where high-risk countries are involved, and the requirement that the assessment be retained, testable, and owned by a named officer. |
| Cabinet Decision No. 74 of 2020 | Targeted financial sanctions: screening against UN and UAE Local Terrorist Lists, freezing without delay, and reporting to the Executive Office for Control and Non-Proliferation. | Sanctions exposure is a risk factor in its own right, and the effectiveness of your screening control is among the harder ratings to justify honestly. |
| Cabinet Resolution No. 109 of 2023 | Real Beneficiary Procedures: the beneficial ownership register, the 25% threshold, and update deadlines. | Ownership opacity is scored against this standard, which matters most for corporate service providers and layered structures. |
| Cabinet Resolution No. 71 of 2024 | The administrative penalty schedule for DNFBPs supervised by the MoET and MoJ: 41 listed violations with fines of AED 50,000 to AED 1,000,000, doubling where the same violation recurs within one year. | Quantifies the cost of a missing or inadequate assessment, and useful to read alongside the gap list your assessment produces. |
| Sectoral guidance and free zone rulebooks | MoET Guidelines for DNFBPs (September 2025), CBUAE, CMA, MoJ, GCGRA and VARA expectations, the DFSA AML Module, which requires a documented business risk assessment for DIFC Relevant Persons, and the FSRA AML Rulebook in the ADGM. Plus the National and Sectoral Risk Assessments. | Determines the terminology, the scope, and the supervisory emphasis that applies to you. Free zone entities carry the federal obligation and the rulebook obligation together, not one instead of the other. |
The gap we find most often: no traceable link between the National Risk Assessment and the firm’s own ratings. The NRA gets a paragraph of acknowledgement and then never changes a score. Article 5(1) requires its results to be taken into account, and taken into account means visible consequences somewhere in the document.
AML Risk Assessment Methodology: How We Build Yours
The methodology is the part supervisors actually read, and it is the part most assessments cannot survive. A rating without a documented basis is an opinion, and an opinion cannot be re-run, tested, or defended by anyone other than the person who formed it.
A defensible methodology answers six questions in writing before a single score is assigned:
1. What are we scoring?
The risk factors and the sub-factors under each, chosen for your business rather than lifted from a generic model.
2. On what scale?
The rating bands and what each one means in concrete terms, so that medium means the same thing on page two and page forty.
3. With what weightings?
Which factors carry more influence, and why, since equal weighting across all factors is itself an assertion about your business that usually isn’t true.
4. From what data?
Provide the source for each input so an auditor can trace a score back to a customer file, a transaction report, or a documented judgement.
5. How is control effectiveness rated?
The criteria distinguishing an effective control from a documented one, and the evidence required to claim the former.
6. How is residual risk derived?
The arithmetic or logic connecting inherent risk and control effectiveness, stated explicitly rather than left implied.
We document all six, hand over the working model, and structure the engagement so your compliance officer can model the assessment next year without us. Firms that intend to keep this in-house should say so at the outset, because it changes how we build the build.
AML Risk Scoring: Inherent Risk, Controls, Residual Risk
Scoring is where ML/FT assessments quietly become useless. Two failure patterns account for most of what we see. The first is compression: every factor lands on medium, which tells the reader nothing and usually means the scale was never defined. The second is generosity: controls are rated effective because they exist in a policy, which produces a residual risk figure that cannot be defended the moment anyone tests a file.
On the quantitative assessment of ML/TF/PF risks, since it comes up in most kick-off meetings: numbers are useful, and they are not the point. A weighted numeric model brings consistency and makes year-on-year comparison possible, which matters. It also creates a temptation to treat the output as objective when every weighting inside it was a judgement. We build numeric models where the data supports them, and we document the reasoning behind each weighting so the score remains explainable. A score you cannot explain is worse than a qualitative rating you can.
Risk appetite belongs in this section too, and it is frequently missing. Residual risk tells you what is left. Appetite tells you whether that is acceptable, and it is a decision for senior management, stated explicitly, not inferred from whatever the business is currently doing.
The Five AML Risk Factors: Customer, Product/Service/Transaction, Geography, Delivery Channel, Technology
These five are the standard basis of a risk-based assessment:
Risk Factor
What Gets Assessed
Customer risk
Customer types and segments, ownership opacity and layered structures, PEP exposure, cash-intensive businesses, non-resident and non-face-to-face customers, and concentration in a single relationship
Product/service/transaction risk
Which offerings can move or store value, transaction sizes relative to the AED 55,000 and AED 3,500 thresholds wherever applicable, third-party payment exposure, and anonymity or speed features
Geographic risk
Customer, counterparty, and transaction jurisdictions against high-risk country lists, sanctions exposure, and the countermeasures required under Article 23
Delivery channel risk
Face-to-face against remote or digital onboarding, use of intermediaries, agents, and introducers, and reliance on third-party due diligence under Article 20. This is the factor most often scored too generously, because the firm never sees the customer the introducer met
Technology risk
Risks arising from emerging technologies like artificial intelligence, machine learning, and introduction of new products which use blockchain and other cutting-edge technologies.
How to Do an AML Risk Assessment, Step by Step
If you are preparing your own Business Risk Assessment (BRA), follow this sequence to produce a defensible document. It is also, in outline, what we do:
1. Define the scope.
Which legal entity, which business lines, which branches, and whether group exposures are in or out. Keep it in writing so you can prove you not only implemented it but also have evidence.
2. Gather the data.
Customer, product, geography, channel, and transaction data, plus your existing policies, registers, and any inspection findings, findings of NRA and SRA, supervisory guidance, if any.
3. Design the methodology.
Define risk categories, risk factors, sub-factors, scales, and weightings. Document the rationale behind your assumptions and describe your methodology in full.
4. Score inherent risk.
Score factor by factor, recording the reasoning next to each rating rather than in a separate note.
5. Test control effectiveness.
Interviews plus sample testing. A control described in a policy and a control operating on a Tuesday are different findings, and only testing distinguishes them.
6. Derive residual risk and set appetite.
Residual position calculated, appetite decided by senior management explicitly.
7. Integrate the NRA and SRA.
Map national and sectoral findings to your exposure, and record the resulting changes. [Cabinet Resolution No. 134 of 2025, Article 5(1)]
8. Produce the gap list and action plan.
Include findings with owners and deadlines, as evidence that you acted on your analysis.
9. Obtain senior management approval.
Dated, named, and minuted, then diarise the review cycle and the trigger events. [Cabinet Resolution No. 134 of 2025, Article 5(2)(a)]
Who Performs an AML Risk Assessment?
Accountability sits with the entity and, specifically, with senior management who approve the framework and the compliance officer who owns it [Cabinet Resolution No. 134 of 2025, Articles 5(2)(a) and 22]. Who does the work is a separate question with three common answers.
The compliance officer, internally.
Workable where the officer has a methodology, the data access, and the time. The usual constraint is not competence but independence of judgement: rating your own controls is uncomfortable, and most people rate them kindly.
An external specialist.
Common for a first assessment, for firms without a methodology, or where an independent challenge to internal control ratings is wanted. The risk to watch is dependency, which is why the methodology handover matters.
A hybrid, which is what most of our clients run.
We build the first assessment and the model, then support the annual refresh while the compliance officer owns and signs it.
One thing worth knowing : whoever performs the assessment, the independent audit function required under Article 21 should not be the same person or team. If your compliance officer prepares the assessment and also tests it, the testing is not independent in any sense a supervisor accepts.
Business Risk Assessment Services: What You Receive
Deliverable
What it does
AML business risk assessment report
The full documented assessment: scope, inherent risk, control effectiveness, residual risk, appetite, and conclusions
Documented methodology
Factors, scales, weightings, and the basis for each, so the assessment is reproducible by you, your auditor, and your supervisor
Working risk model
The scoring model itself, handed over so next year’s refresh does not start from a blank page
Control effectiveness working papers
The evidence behind each rating, which is exactly what an independent audit under Article 21 will ask to see
NRA and SRA integration record
National and sectoral findings mapped to your business, with the resulting changes to ratings and controls recorded
Gap list and action plan
Findings with owners, deadlines, and a tracker your compliance officer can run
Senior management approval pack
Board or owner-level summary and the sign-off documentation supervisors expect
Want the model, not just the report?
Tell us whether you intend to maintain this in-house and we will build the handover into the engagement.
AML Risk Management: What Happens After the Assessment
An assessment measures risk. AML risk management is what you do about it, and the two are not the same deliverable. The assessment tells you where exposure sits and how well controls contain it. Risk management is the ongoing business of closing the gaps it found, adjusting controls as the business changes, and keeping the picture current between formal assessments.
In practice this means four things running continuously. Remediation of the gap list, on the deadlines it set. Control adjustment when the assessment says a control is ineffective, which is a policy and procedure change rather than a note in a file. Monitoring of the risk drivers that would change your ratings, meaning new products, new markets, new channels, and shifts in your customer mix. And re-assessment when any of those move materially, rather than waiting for the annual cycle to come round.
This is also where the business risk assessment earns its cost. A firm that treats it as an annual document files it and changes nothing. A firm that treats it as a management tool usually discovers that some controls were over-applied while others were missing, which is why clients that move to a genuine risk-based approach often reduce compliance costs rather than increase them.
Who Needs an AML Business Risk Assessment in the UAE?
Banks and financial institutions.
Any of the fourteen listed financial activities, supervised by the CBUAE, with capital market companies under the CMA.
[Cabinet Resolution No. 134 of 2025, Article 2]
DNFBPs.
Real estate brokers and agents, dealers in precious metals and stones, lawyers and notaries, independent accountants, company and trust service providers, and commercial gaming operators.
[Cabinet Resolution No. 134 of 2025, Article 3]
Front-line and customer-facing staff.
Virtual asset service providers, supervised by VARA in Dubai or the relevant federal authority elsewhere.
[Cabinet Resolution No. 134 of 2025, Article 4]
DIFC Relevant Persons prepare a business risk assessment under the DFSA AML Module alongside the federal obligation, and ADGM entities under the FSRA AML Rulebook. Size does not exempt anyone. A proportionate assessment for a single-officer DNFBP is a great deal shorter than a bank’s, and proportionate is not a synonym for absent.
Penalties for a Missing Business Risk Assessment
Administrative penalties.
AED 10,000 to AED 5,000,000 per violation, plus warnings, licence suspension or cancellation, restrictions on responsible individuals, and public naming. Note per violation, because a missing assessment rarely produces one finding.
[Federal Decree-Law No. 10 of 2025, Article 17]
The DNFBP penalty schedule.
41 listed violations at AED 50,000 to AED 1,000,000 for MoET- and MoJ-supervised businesses, doubling if the same violation recurs within one year.
[Cabinet Resolution No. 71 of 2024]
The consequential exposure.
Without a defensible assessment, you cannot justify a single control decision, so one gap becomes findings across CDD, EDD, monitoring, screening, and training simultaneously.
AML Risk Assessment Tools and Software: Where They Fit
An ML/FT risk assessment tool can hold your model, do the arithmetic, keep a version history, and produce a presentable output. All of that is genuinely useful once you have a methodology. What no tool can do is choose your risk categories, risk factors, weightings, judge whether a control is effective, or take a national risk finding into account on your behalf. Those are judgements, and they are precisely what a supervisor examines.
So the sequencing matters more than the selection. Firms that license a tool before they have a methodology end up with a well-formatted assessment whose numbers nobody in the room can explain, which is a worse position than a plain spreadsheet with documented reasoning. Build the business risk assessment, then decide whether an EWRA tool is worth paying to maintain it. If you are already evaluating platforms, our AML software selection service covers requirements, vendor scoring, and contract terms.
AML Business Risk Assessment by Sector in the UAE
Real estate brokers and agents.
Non-resident buyers, third-party payments, cash exposure, and beneficial ownership through layered purchasers. Geographic and customer risk usually dominate, and delivery channel risk is understated wherever agents onboard independently.
Dealers in precious metals and stones.
Cash intensity against the AED 55,000 threshold, rapid buy and sell patterns, split payments, and supply chain provenance.
Trust and company service providers.
Ownership opacity as the dominant factor, nominee and trustee arrangements, and cross-border structures that make the 25% test genuinely difficult rather than merely administrative.
Lawyers, notaries, and accountants.
Which matters fall inside DNFBP scope, client money exposure, and engagement acceptance treated as a control rather than a commercial step.
Banks, exchange houses, and payment providers.
Corridor and volume analysis, correspondent exposure, PEP concentration, and monitoring effectiveness measured rather than assumed.
VASPs.
Transaction speed, counterparty and chain exposure, Travel Rule obligations, and the AED 3,500 occasional transaction threshold.
Commercial gaming operators.
Player due diligence, rapid fund movement, and behavioural indicators under GCGRA expectations.
Why AML UAE for Your Business Risk Assessment
Methodology improves with repetition, and this is the deliverable we have produced more than any other:
1,000+
EWRA and AML/CFT/CPF policy sets delivered to UAE reporting entities, which is where our sector benchmarks come from
300+
AML compliance projects across FIs, DNFBPs, and VASPs
45%+
cost saving achieved by clients moving to a genuine risk-based approach, because a real assessment usually shows controls over-applied in one place and missing in another
750+
professionals trained across 3,000+ hours, so the assessment is understood by the people operating the controls it justifies
Our team combines CAMS-certified compliance practitioners with CISA and DISAqualified information systems auditors, which is why control effectiveness testing here means testing rather than interviewing, and why our models are built to be audited.
The Specialists Who Build Your Assessment

Pathik Shah
CAMS, FCA, CS, CISA, DISA (ICAI), FAFP (ICAI)
Experience
28+ years
Regulatory Coverage
MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · AML/CFT framework design, RegTech

Jyoti Maheshwari
CAMS, ACA
Experience
11+ years
Regulatory Coverage
MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · AML/CFT/CPF framework, health checks

Dipali Vora
CAMS, ACS
Experience
10+ years
Regulatory Coverage
MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · Consulting, training, implementation

Monika Shah
CAMS
Experience
3+ years
Regulatory Coverage
MoET, MoJ, CBUAE, CMA, FSRA, DFSA, VARA · managed KYC, consulting, goAML reporting
AML Risk Assessment Examples From Our Engagements
A brokerage where every factor scored medium
The existing assessment rated all factors medium and every control adequate. Analysis of the actual customer data showed heavy concentration in non-resident buyers from two jurisdictions and a material proportion of third-party payments, neither of which appeared anywhere in the document. Raising geographic and customer risk produced a shorter, far more defensible assessment, and it changed the EDD triggers, which was the point.
A firm that discovered it was over-controlled
Enhanced due diligence was being applied to nearly every customer, which reads as caution and was in fact a finding waiting to happen: nobody could explain the basis, and applying EDD everywhere meant applying it properly nowhere. The assessment identified where risk genuinely sat, documented simplified due diligence where Article 5(3) allowed it, and reduced onboarding time without weakening a control that mattered.
A group with two assessments that disagreed
A regional group maintained a firm-wide assessment centrally and a UAE assessment locally, prepared on different methodologies in different years. They rated the same customer segment differently, which is the kind of inconsistency a supervisor finds immediately, and a compliance team never notices. We reconciled them onto one methodology with a documented local overlay, so the group view and the UAE view could differ where the risk genuinely differed, and only there.
FAQs on Business Risk Assessment in the UAE
It is the documented assessment of the money laundering, terrorism financing, and proliferation financing risks your business carries, scored across customers, products, geographies, technological, and delivery channels, and set against the effectiveness of your controls. UAE law requires it under Article 5(1) of Cabinet Resolution No. 134 of 2025. In general management, the same phrase means strategic and operational risk, which is a different exercise entirely.
Enterprise-wide risk assessment. In AML, it means the same document as a business risk assessment, business-wide risk assessment, or firm-wide risk assessment: one assessment covering the whole entity rather than a single business line, product, or branch.
Yes. Every financial institution, DNFBP, and VASP in the scope of Articles 2 to 4 of Cabinet Resolution No. 134 of 2025 must identify, assess, understand, and document its ML/TF/PF risks under Article 5(1), taking the National Risk Assessment into account and keeping the assessment updated. Failure to do so is independently punishable under Article 17 of Federal Decree-Law No. 10 of 2025.
The business risk assessment covers the risk your whole firm carries and drives your policies and controls. A customer risk assessment rates one customer at onboarding and on review, and operates within those controls. You need both, and your customer rating methodology should be traceable back to a finding in the business assessment.
Yes, and it’s the same as an enterprise-wide risk assessment (EWRA). The variation in naming comes from which rulebook or group a firm grew up with rather than any difference in the obligation. The DFSA AML Module uses business risk assessment for DIFC Relevant Persons, which is why firms operating across the mainland and the free zones often hold two documents with different titles and the same purpose.
Define the scope, gather and analyse your customer, product, geography, channel, and transaction data, design and document the methodology before scoring, score inherent risk factor by factor, test control effectiveness rather than accepting descriptions, derive residual risk and set appetite with senior management, integrate the National and Sectoral Risk Assessment findings, produce a gap list with owners and deadlines, and obtain dated senior management approval.
Accountability sits with senior management and the compliance officer [Cabinet Resolution No. 134 of 2025, Articles 5(2)(a) and 22]. The work itself can be done internally, by an external specialist, or in a hybrid arrangement where a consultant builds the first assessment and methodology, and the officer owns the annual refresh. Whoever prepares it, the independent audit function under Article 21 should be someone else.
The documented basis for your scores, which risk factors and sub-factors are assessed, on what rating scale, with what weightings and why, from what data sources, how control effectiveness is judged, and how residual risk is derived from inherent risk and control effectiveness. Supervisors read the methodology, not just the conclusion, because a rating without a documented basis cannot be tested or re-run.
Inherent risk is scored per factor before controls, control effectiveness is rated against each, and residual risk is derived from the two. Scoring can be quantitative with weighted numeric models or qualitative with defined rating bands, and both are acceptable as long as the reasoning is documented. The two most common failures are compressing everything to medium, which signals an undefined scale, and rating controls as effective because they exist on paper.
The law requires it to be kept updated on an ongoing basis rather than naming a fixed interval, and an annual cycle is the working standard in practice. Update sooner on a material change: a new product, market, delivery channel, or licence; a new National or Sectoral Risk Assessment; a change in the law; a shift in your customer mix; or an audit or inspection finding.
A template can organise the structure, and it cannot produce the assessment. Article 5(1) requires the risks of your business to be identified and understood, and Article 5(2)(b) requires the resulting controls to be proportionate to your nature and size. A downloaded template carries someone else’s risk universe and, more damagingly, someone else’s weightings, which is visible on a first read. We build from your data and hand over the model so you can maintain it.
The assessment measures risk at a point in time. AML risk management is the continuous work that follows: remediating the gaps it found, adjusting controls rated ineffective, monitoring the drivers that would change your ratings, and re-assessing when they move materially. An assessment that is filed and never acted on is a document; risk management is what makes it a control.
Yes. DIFC Relevant Persons prepare one under the DFSA AML Module, which also applies the MLRO regime and an annual AML return. ADGM entities follow the FSRA AML Rulebook, with the ADGM Registration Authority supervising DNFBPs. Both obligations sit on top of the federal framework rather than replacing it, and groups applying a single standard across mainland and free zone entities usually have gaps in at least one.
Typically two to four weeks for a mid-sized entity from data request to approved report. The analysis is rarely the constraint. The timeline depends on how quickly you can provide customer, transaction, and geography data, and how quickly stakeholders are available for control effectiveness interviews.
Build an assessment you can defend.
One short form, one focused conversation, and a clear scope. A CAMS-certified specialist will come back with timeline and price.