Annual ML/TF/PF Risk Assessment Report
An annual ML/TF/PF risk assessment, also called an enterprise-wide risk assessment, is a structured review that identifies, rates and documents your money laundering, terrorist financing and proliferation financing risks, and shows whether your controls actually match them.
An effective AML programme is only as strong as its understanding of risk. Niyeahma delivers Annual ML/TF/PF Risk Assessment Reports that give regulated businesses a clear, structured and defensible view of their money laundering, terrorist financing and proliferation financing risks. Our reports go beyond compliance formality and give regulators, boards and senior management confidence that risks are properly identified, assessed and managed.
As a global AML consulting firm, we help you meet your annual risk assessment obligations while aligning with FATF principles and your regulator's expectations.
Why an Annual Risk Assessment Matters.
A current, well-evidenced risk assessment is the foundation of your whole AML programme. It sets the risk appetite your policies, controls and monitoring are built to meet. Done properly, an annual assessment demonstrates that your organisation:
Understands its evolving ML, TF and PF risk exposure.
Reviews risk in line with business growth, product changes and geographic expansion.
Aligns controls to actual risk rather than assumptions.
Provides evidence of board oversight and senior-management involvement.
A weak or outdated assessment is one of the most common regulatory findings. When the assessment does not reflect the business, controls end up aimed at the wrong risks, and that gap tends to surface at exactly the wrong moment: during an inspection.
Who Needs One, and How Often.
Under the risk-based approach, regulated businesses are expected to document and maintain a business-wide ML/TF/PF risk assessment. That includes financial institutions, DNFBPs, VASPs and fintechs. It is not a one-off exercise. You should review and refresh it:
/ At least once a year, as part of your regular compliance cycle.
/ When you launch new products or services, or change how existing ones are delivered.
/ When you enter new markets or customer segments, or your geographic exposure changes.
/ After a merger, acquisition or major restructuring.
/ When the law, guidance or a national risk assessment changes, or after a significant incident or regulatory finding.
An assessment built on volumes from before a product launch or a new market is a liability, not an asset. We help you keep it live.
The Risk Factors We Assess.
A defensible assessment looks across every dimension of your business, not just one. We assess your exposure across the five core risk factors:
Inherent Risk, Controls, Residual Risk.
The value of a risk assessment is in how it is scored. We follow the method regulators expect, and we keep it transparent and defensible:
1. Inherent risk
The risk you face before any controls, based on your customers, products, channels, geographies and transactions. It is the honest starting point, scored on a consistent, documented scale.
2. Control effectiveness
How well your existing controls, such as CDD, monitoring, screening and reporting, actually work, both by design and in day-to-day operation.
3. Residual risk
What remains once controls are applied. In plain terms, inherent risk reduced by control effectiveness gives residual risk, which is then judged against your risk appetite. Where residual risk sits too high, we set out the controls needed to bring it back in line.
Jurisdictions in Your Risk Assessment.
A risk assessment has to be built to the regime that actually governs you. For each jurisdiction below we set out the governing law, the risk assessment requirement it imposes, who it applies to, the supervisor you answer to, and how we build your assessment to meet it. Exposure to these and other markets is then scored as your geographic risk factor.
Federal Decree-Law No. 10 of 2025, with Cabinet Resolution No. 134 of 2025 (Executive Regulations).
Regulated entities must identify, assess and document their ML, TF and PF risks across customers, products, channels and geographies, and keep the assessment current. The 2025 regime expressly brings proliferation financing, virtual assets and an expanded DNFBP scope into that assessment.
Financial institutions; DNFBPs including real estate, dealers in precious metals and stones, auditors and accountants, legal professionals, corporate and trust service providers and commercial-gaming operators; and virtual asset service providers.
CBUAE for financial institutions, the Ministry of Economy and Tourism for most DNFBPs, and MoJ, CMA, VARA, DFSA and FSRA in their respective markets, with STRs filed to the UAE FIU through goAML.
We build and document your business-wide ML/TF/PF risk assessment to FDL No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, covering the new proliferation, virtual-asset and gaming scope, mapped to your specific supervisor.
The Money Laundering Regulations 2017 (MLRs 2017).
Regulation 18 requires a written, up-to-date business-wide risk assessment covering your customers, the countries you operate in, your products and services, transactions and delivery channels, informed by the information your supervisor provides.
Credit and financial institutions, and DNFBPs including accountants, auditors, tax advisers, legal professionals, estate agents, trust and company service providers and high-value dealers.
The FCA, HMRC and the professional body supervisors, with suspicious activity reports going to the National Crime Agency.
We prepare a Regulation 18 compliant written risk assessment that stands up to FCA or HMRC review and aligns to your policies and controls.
The AML/CTF Act 2006, as amended by the AML/CTF Amendment Act 2024, with the AML/CTF Rules 2025.
Reporting entities must assess and document the ML and TF risk they face and reflect it in their AML/CTF program. The 2024 reforms require the risk assessment to be in place before services are provided and kept current.
Existing reporting entities in financial services, bullion and gambling, and, under the Tranche 2 reforms, real estate professionals, lawyers, accountants and dealers in precious metals and stones.
AUSTRAC, which is both the regulator and the financial intelligence unit.
We build your ML/TF risk assessment and align it to your AML/CTF program so it meets AUSTRAC expectations under the amended regime.
The CDSA and TSOFA, with the MAS AML/CFT Notices such as Notice 626.
MAS notices require an enterprise-wide risk assessment: institutions must identify, assess and understand their ML and TF risks across customers, countries, products and channels, document it and keep it current.
Banks, capital markets intermediaries, payment service providers, insurers and other MAS-regulated financial institutions.
The Monetary Authority of Singapore (MAS), with suspicious transaction reports filed to the Suspicious Transaction Reporting Office.
We prepare your enterprise-wide risk assessment to the relevant MAS notice and inspection expectations.
The Prevention of Money Laundering Act 2002 (PMLA) and PML (Maintenance of Records) Rules 2005, with RBI, SEBI, IRDAI and IFSCA guidelines.
Regulated entities must carry out and periodically review a documented ML and TF risk assessment covering customers, products, geographies and channels, as set out in the RBI KYC Master Direction and the IFSCA AML, CFT and KYC Guidelines.
Banks and financial institutions, market intermediaries, insurers and IFSC entities, and reporting entities under the PMLA.
RBI, SEBI, IRDAI and IFSCA by sector, with reporting to FIU-IND and enforcement by the Enforcement Directorate.
We build your risk assessment to your sector regulator's requirements and the PMLA framework.
The Anti-Money Laundering Law and its Implementing Regulations, with the SAMA AML/CTF guidance.
Institutions must identify, assess, document and understand their ML and TF risks under the risk-based approach and reflect them in their controls, as set out in the Implementing Regulations and SAMA rules.
Banks and financial institutions supervised by SAMA, capital-market institutions supervised by the CMA, and DNFBPs.
SAMA for financial institutions and the CMA for capital-market entities, with reporting to the Saudi FIU.
We prepare your enterprise-wide risk assessment to the Saudi AML Law, its Implementing Regulations and SAMA expectations.
The Anti-Money Laundering and Counter-Terrorist Financing Ordinance (AMLO, Cap. 615).
Financial institutions and DNFBPs must conduct and document an institution-wide assessment of their ML and TF risks across customers, products, geographies and channels, and keep it current, as set out in the AMLO and the regulators' guidelines.
Authorised institutions, licensed corporations, insurers, and designated non-financial businesses and professions.
The HKMA, SFC, Insurance Authority and Customs and Excise Department by sector, with reporting to the Joint Financial Intelligence Unit.
We build your institution-wide risk assessment to the AMLO and the relevant regulator's guideline.
The FATF 40 Recommendations, in particular Recommendation 1.
Recommendation 1 sets the risk-based approach: businesses must identify, assess, understand and document their ML, TF and PF risks and direct resources to where risk is highest. This is the standard behind every national regime above.
The global baseline for financial institutions and DNFBPs, applied through each country's own laws.
Applied by national regulators and tested through FATF mutual evaluations.
Where you operate outside the jurisdictions above, we build your risk assessment to FATF standards so it is defensible in any market.
For the full policy and control documentation mapped to each of these regimes, see our AML/CFT policy, procedures and control documentation service.
This service is backed by the entire AMLVerse.
No NIYEAHMA service operates alone. Every engagement draws on a connected network of jurisdiction platforms, knowledge bases, professional tools, and technology, built and run by the same team.
Our Risk Assessment Process.
A clear, repeatable process that produces a report you can operate from and defend.
Scope & data gathering
We agree what the assessment covers, then gather the inputs: customer segments, product inventory, channels, geographies, transaction data, prior findings and the relevant national and sectoral risk assessments.
Identify inherent risks
We map your ML, TF and PF exposure across every risk factor, before crediting any of your controls.
Assess your controls
We evaluate how effective your existing controls are, both in design and in practice.
Rate residual risk
We calculate residual risk factor by factor, using a consistent, defensible scoring method, and set it against your risk appetite.
Findings & action plan
We document the gaps and set out a clear remediation plan: what to fix, who owns it, and by when.
Report & board sign-off
We produce a clear, structured report for board and senior-management approval, ready for your regulator.
Monitor & refresh
We help you keep the assessment current, refreshing it annually and on material trigger events.
What Is in Your Report.
You receive a complete, board-ready document, not a spreadsheet of scores without a story:
Scope & methodology
What the assessment covers and how each risk factor was scored, so it is transparent and repeatable.
Risk factor ratings
Customer, product, channel, geographic and transaction risk, each rated with narrative justification.
Inherent vs residual risk
The exposure before and after controls, so the effect of your controls is visible.
Risk matrix / heat map
A clear visual summary of exposure by business line for board-level presentation.
Control gaps & findings
Where controls fall short of the risk, stated honestly rather than hidden.
Remediation action plan
Each gap with an owner, a deadline and a status, because an empty action plan is itself a finding.
Board sign-off & risk appetite
A clear statement of accepted residual risk, approved by senior management.
Common Pitfalls We Help You Avoid.
Most weak assessments fail in the same predictable ways. We design these out from the start:
A copy-paste template: a generic assessment that does not reflect your actual business.
Left to go stale: an assessment running on volumes from before a product launch or new market.
Confusing inherent and residual risk: a single score that already bakes in controls, which examiners see through.
All-green ratings: an assessment that acknowledges no weaknesses raises flags immediately.
Scoping out small but risky products: low volume does not mean low risk.
No action plan: findings with no owner, deadline or follow-up.
No board sign-off: residual risk that senior management never saw or approved.
Ignoring national and sectoral risk assessments: missing the risks your regulator has already flagged.
Defensible, Regulator-Ready, Yours.
A risk assessment is the beating heart of every AML decision. It sets the direction for your policies, procedures and monitoring across the business. We make sure yours is one you can stand behind:
A defensible methodology you can explain to any regulator.
Tailored to your business, your products, customers, channels and jurisdictions, never generic.
Risk linked to action, with findings, controls and a remediation plan, not just ratings.
Board-ready reporting that evidences oversight and stands up at inspection.
Your risk assessment should connect directly to the controls it drives. We align it with your AML/CFT policy, procedures and control documentation, and it can feed a wider AML/CFT Health Check of your whole programme.
Risk Assessment Report, FAQ.
It is a structured, business-wide review that identifies, rates and documents your money laundering, terrorist financing and proliferation financing risks, measures how well your controls address them, and records the result for your board and regulator.
Under the risk-based approach, regulated businesses are expected to maintain a current business-wide risk assessment. In practice that means reviewing it at least once a year, and updating it whenever your business, products, markets or the regulations change materially.
Inherent risk is the exposure you face before any controls. Residual risk is what remains after your controls are applied. The point of the assessment is to show that residual risk sits within the level your board is willing to accept.
Scope and methodology, ratings for each risk factor, inherent versus residual risk, a risk matrix or heat map, control gaps and findings, a remediation action plan, and a board sign-off with a risk appetite statement.
Your board or senior management. Regulators expect evidence that leadership has seen the assessment, understood the residual risk, and formally accepted or acted on it.
Whenever something material changes: a new product or channel, a new market or customer segment, a merger or acquisition, a change in law or national risk assessment, or a significant incident.
Directly. The assessment sets the risks your controls must address. We align it with your AML/CFT policy and control documentation so risk, policy and controls all point the same way.
No. A risk assessment measures your risk exposure and whether controls match it. An AML/CFT Health Check tests whether your whole programme is working. They complement each other.
It depends on the size and complexity of your business and the quality of the data available. We agree a realistic timeline at the scoping stage and work to your regulatory deadlines.
Let's Map Your Risk with Confidence.
Speak to our global AML consultants to prepare an Annual ML/TF/PF Risk Assessment Report that is defensible, regulator-ready and aligned with your business.




















