Somewhere in your firm there is a business risk assessment. It was probably written years ago under the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, it probably lives in a Word document, and it has probably been "reviewed" by changing the date on the front page.
That approach is running out of road. From 10 July 2027, Regulation (EU) 2024/1624 (the AMLR) applies directly in Ireland and replaces the substantive rulebook that Irish designated persons have worked under for more than fifteen years. The AMLR expects your policies, procedures and controls to be built on a documented, current, business-wide understanding of your money laundering and terrorist financing risk - and it changes several of the inputs your old assessment was built on.
This walkthrough covers what a Business-Wide Risk Assessment (BWRA) needs to do under the new regime, and how to rebuild yours so it stands up to your supervisor - whether that is the PSRA, the Law Society of Ireland, a designated accountancy body (Chartered Accountants Ireland, ACCA or CPA Ireland), the AMLCU in the Department of Justice, or the Central Bank of Ireland.
What the BWRA is actually for
The BWRA is not a form you file. It is the document that explains, in your own words and with your own evidence, where money laundering and terrorist financing risk enters your business - and what you do about it.
Everything else in your compliance programme hangs off it:
- Your customer due diligence approach should reflect the risks the BWRA identifies.
- Your policies, controls and procedures should mitigate those specific risks, not generic ones copied from an unadapted template.
- Your training should cover the scenarios your staff will actually face.
- At inspection, the BWRA is usually the first document your supervisor reads, because it tells them whether the rest of your file is likely to make sense.
A BWRA that does not match how your firm really operates undermines every other document in your pack.
Step 1: describe your business honestly
Start with a plain description of the firm: services offered, client types, transaction sizes, how you take on new clients, and how money moves. Resist the urge to make the firm sound lower-risk than it is. A conveyancing practice acting for overseas purchasers, or an accountancy practice forming companies for non-resident clients, should say so - the point is to identify risk, then show you control it.
Step 2: work through the four risk lenses
Assess your exposure under each of the classic headings, and record your reasoning, not just a rating.
| Lens | Questions to answer |
|---|---|
| Customers | Who are they? Companies with layered ownership? Non-residents? Politically exposed persons? Clients you never meet face to face? |
| Products and services | Which of your services could be used to launder money - client accounts, company formation, property transactions, high-value goods? |
| Delivery channels | Do you onboard clients remotely? Through introducers or referrers? |
| Geography | Where are your clients and their funds connected to? Factor in the EU's list of high-risk third countries. |
For each factor, write down the risk you see, rate it (a simple low / medium / high scale is fine if you apply it consistently), and name the control that addresses it. A rating with no reasoning is the single most common weakness supervisors find in small-firm risk assessments.
Step 3: build in what the AMLR changes
This is where a pre-2027 assessment goes stale. Several inputs that shaped your old risk and CDD framework move under the AMLR:
- Occasional transaction CDD threshold drops to 10,000 euro, down from 15,000 euro. If your BWRA or procedures reference the old figure, they will be wrong on day one.
- Occasional cash transactions of 3,000 euro or more trigger limited CDD. If your firm touches cash at all, your assessment needs to address this.
- An EU-wide cash payment cap of 10,000 euro applies to commercial transactions, single or linked. Firms in sectors where large cash payments were possible need to treat this as both a control and a risk indicator.
- Beneficial ownership is harmonised at 25 per cent or more, direct or indirect. Your customer-risk analysis should reflect how you identify beneficial owners and how you use the RBO, including your obligation to obtain an extract before a new business relationship and to report discrepancies.
- Enhanced due diligence applies to high-net-worth relationships - clients with assets of 5 million euro or more handled for a client whose total wealth is 50 million euro or more. If your client base could include such clients, your BWRA should say how you would identify and handle them.
You need not quote the Regulation at length - just show your framework was built against the AMLR, not thresholds that stopped applying in July 2027.
Step 4: connect risks to controls
For every material risk you identify, your BWRA should point to the specific control that mitigates it: your CDD procedure, your escalation route to the MLRO, your screening process, your record-keeping. Under the AMLR, records are retained for five years and then deleted - so your assessment should also acknowledge how retention and deletion are managed.
A risk with no corresponding control is not a reason to delete the risk from the document. It is a finding. Record it, assign an owner and a deadline, and fix it. An honest action list is far more credible than a document that claims perfection.
Step 5: get it owned and keep it alive
The AMLR prescribes compliance roles: a board-level compliance manager and a compliance officer of sufficiently high standing (who also takes responsibility for targeted financial sanctions implementation from 10 July 2027). Even in a small firm, the BWRA should record who holds these roles, and the senior owner should formally approve the assessment.
Then schedule reviews: at least annually, and whenever something material changes - a new service line, a new client market, a new EU high-risk third country listing, or new AMLA guidance. Date each version and keep the old ones. The review trail is itself evidence.
What to do now
- Dig out your current business risk assessment and note when it was last genuinely reviewed.
- Check it for the old thresholds - 15,000 euro occasional transactions is the obvious one - and flag every figure the AMLR changes.
- Re-describe your business as it operates today, including remote onboarding and any cash exposure.
- Rate your risks across customers, services, channels and geography, with written reasoning for each rating.
- Map every material risk to a named control, and log any gaps as actions with owners and deadlines.
- Record who your compliance manager and compliance officer will be, and get senior sign-off.
- Diarise an annual review, plus a full AMLR refresh well before 10 July 2027.
Where CompliDesk fits
CompliDesk Ireland is building a BWRA and policy-pack generator designed around Regulation (EU) 2024/1624 from day one, so your risk assessment starts from the new rulebook rather than a retrofitted template. See the AMLR explainer for the full picture of what changes in July 2027.
General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.