How to run a Business-Wide Risk Assessment (BWRA) for the AMLR
The BWRA is the foundation document of your AML programme: everything else — your policies, your CDD depth, your monitoring — is supposed to follow from it. Most Irish firms wrote theirs for the CJA 2010 framework and last touched it at an inspection. Here is how to rebuild it properly for Regulation (EU) 2024/1624.
A BWRA identifies and scores the money-laundering and terrorist-financing risks your firm faces across four dimensions — services, client types, geographies and delivery channels — and records the controls that mitigate them. The AMLR sets its own risk-assessment and internal-controls expectations from 10 July 2027, so a CJA 2010-era BWRA needs rebuilding, not re-dating.
What is a BWRA — and why does the AMLR change it?
A Business-Wide Risk Assessment answers one question in writing: where could this firm realistically be used to launder money or finance terrorism, and what are we doing about it? It is a firm-level document, distinct from the client-level risk rating you assign during onboarding — though the two must connect: your client risk model should be derived from the BWRA, not invented separately.
From 10 July 2027 the AMLR applies directly in Ireland, with no transposition to wait for, and sets its own expectations for risk assessment and internal policies, procedures and controls. That is why re-dating last year’s document is not enough: the framework it was written against is being replaced. The assessment also has fresher inputs than it did — Ireland launched a new National Risk Assessment and a 30-point AML/CFT Action Plan on 18 June 2026, and the EU high-risk third-country list is updated periodically. A 2027-ready BWRA cites both.
How do you run a BWRA, step by step?
Work through the four risk dimensions first, then score, document and schedule the review. For a small firm this is one or two focused working sessions, not a consultancy project.
- 1
Inventory your services
List everything the firm actually does — every service line, not just the headline ones. A conveyancing sideline or occasional company-formation work can carry more money-laundering risk than the core practice.
- 2
Inventory your client types
Group clients into meaningful categories: individuals, owner-managed companies, trusts, non-resident clients, politically exposed persons, cash-intensive businesses. Each category will be scored separately.
- 3
Map your geographies
Where are your clients, their beneficial owners and their funds? Use the EU high-risk third-country list as a formal input, alongside Ireland’s National Risk Assessment, launched on 18 June 2026, for the domestic picture.
- 4
Map your delivery channels
How do clients reach you and how are they identified — face to face, remotely, through introducers or intermediaries? Non-face-to-face onboarding and reliance on third parties change the risk profile and belong in the assessment.
- 5
Score each combination
For each service, client type, geography and channel, assign a likelihood and impact rating on a simple scale — low, medium, high works for most firms. Resist false precision: a defensible three-point scale beats an arbitrary hundred-point one.
- 6
Map controls and residual risk
Against each material risk, record the control that mitigates it — CDD depth, approval steps, screening, monitoring — and the residual risk that remains. Residual risk is what your enhanced-measures decisions should hang off.
- 7
Document and sign off
Write it up as a single document: method, inputs, scores, controls, conclusions and the date. Have it approved at the top of the firm — under the AMLR that governance sits with your board-level compliance manager.
- 8
Set the review cadence
Schedule a full review at least annually, plus trigger-based reviews when something material changes: a new service, a new market, an updated EU high-risk list or National Risk Assessment, or a change in the law.
What should the finished document contain?
An inspector should be able to pick it up cold and follow your reasoning. That means: the method and scale you used; the inputs you relied on (the EU high-risk third-country list, the National Risk Assessment, supervisor guidance for your sector); the risk register itself — each material risk with its score, control and residual rating; your conclusions, including which client categories attract enhanced measures; and the approval — who signed it off, and when. Keep superseded versions: the history of the document is itself evidence that risk assessment is a living process in your firm.
How often should you review it?
At least annually, and sooner on trigger events: a new service line, a new client geography, an update to the EU high-risk list or the National Risk Assessment, new supervisor guidance, or a regulatory change — of which 10 July 2027 is the largest in a generation. Put the review date in the diary when you sign the document off, and record even a “reviewed, no change” outcome. If you are planning the wider run-up to the AMLR, the BWRA refresh has a natural slot in our 12-month AMLR readiness plan.
Build your BWRA against the AMLR, not around it
CompliDesk’s BWRA generator walks you through services, clients, geographies and channels, maps the output to Regulation (EU) 2024/1624, and reminds you when the refresh falls due.