Skip to content
Home/Services/Annual ML/TF/PF Risk Assessment Report
Service Overview

Annual ML/TF/PF Risk Assessment Report

Built for regulatory confidence.

An annual ML/TF/PF risk assessment, also called an enterprise-wide risk assessment, is a structured review that identifies, rates and documents your money laundering, terrorist financing and proliferation financing risks, and shows whether your controls actually match them.

An effective AML programme is only as strong as its understanding of risk. Niyeahma delivers Annual ML/TF/PF Risk Assessment Reports that give regulated businesses a clear, structured and defensible view of their money laundering, terrorist financing and proliferation financing risks. Our reports go beyond compliance formality and give regulators, boards and senior management confidence that risks are properly identified, assessed and managed.

As a global AML consulting firm, we help you meet your annual risk assessment obligations while aligning with FATF principles and your regulator's expectations.

Why It Matters

Why an Annual Risk Assessment Matters.

A current, well-evidenced risk assessment is the foundation of your whole AML programme. It sets the risk appetite your policies, controls and monitoring are built to meet. Done properly, an annual assessment demonstrates that your organisation:

/

Understands its evolving ML, TF and PF risk exposure.

/

Reviews risk in line with business growth, product changes and geographic expansion.

/

Aligns controls to actual risk rather than assumptions.

/

Provides evidence of board oversight and senior-management involvement.

A weak or outdated assessment is one of the most common regulatory findings. When the assessment does not reflect the business, controls end up aimed at the wrong risks, and that gap tends to surface at exactly the wrong moment: during an inspection.

Who It's For

Who Needs One, and How Often.

Under the risk-based approach, regulated businesses are expected to document and maintain a business-wide ML/TF/PF risk assessment. That includes financial institutions, DNFBPs, VASPs and fintechs. It is not a one-off exercise. You should review and refresh it:

/ At least once a year, as part of your regular compliance cycle.

/ When you launch new products or services, or change how existing ones are delivered.

/ When you enter new markets or customer segments, or your geographic exposure changes.

/ After a merger, acquisition or major restructuring.

/ When the law, guidance or a national risk assessment changes, or after a significant incident or regulatory finding.

An assessment built on volumes from before a product launch or a new market is a liability, not an asset. We help you keep it live.

What We Assess

The Risk Factors We Assess.

A defensible assessment looks across every dimension of your business, not just one. We assess your exposure across the five core risk factors:

Customer RiskWho your customers are: ownership and control structures, source of funds, PEP status, adverse history and links to high-risk industries, across individuals, private companies, partnerships and higher-risk entities.
Product & Service RiskWhich offerings carry the most exposure. Cash-intensive services, private banking, wire transfers, correspondent and offshore services move value in ways that can be misused.
Delivery Channel RiskHow customers are onboarded and served. Non-face-to-face onboarding, intermediaries and agents, and digital channels each change the risk picture.
Geographic RiskWhere your customers and counterparties are based and operate: exposure to higher-risk or sanctioned jurisdictions, tax havens, corruption hotspots and conflict or transit zones.
Transaction RiskThe size, speed, frequency and pattern of transactions, and how easily unusual activity can be spotted and escalated.
How We Rate Risk

Inherent Risk, Controls, Residual Risk.

The value of a risk assessment is in how it is scored. We follow the method regulators expect, and we keep it transparent and defensible:

1. Inherent risk

The risk you face before any controls, based on your customers, products, channels, geographies and transactions. It is the honest starting point, scored on a consistent, documented scale.

2. Control effectiveness

How well your existing controls, such as CDD, monitoring, screening and reporting, actually work, both by design and in day-to-day operation.

3. Residual risk

What remains once controls are applied. In plain terms, inherent risk reduced by control effectiveness gives residual risk, which is then judged against your risk appetite. Where residual risk sits too high, we set out the controls needed to bring it back in line.

Global Coverage

Jurisdictions in Your Risk Assessment.

A risk assessment has to be built to the regime that actually governs you. For each jurisdiction below we set out the governing law, the risk assessment requirement it imposes, who it applies to, the supervisor you answer to, and how we build your assessment to meet it. Exposure to these and other markets is then scored as your geographic risk factor.

Governing law

Federal Decree-Law No. 10 of 2025, with Cabinet Resolution No. 134 of 2025 (Executive Regulations).

Risk assessment requirement

Regulated entities must identify, assess and document their ML, TF and PF risks across customers, products, channels and geographies, and keep the assessment current. The 2025 regime expressly brings proliferation financing, virtual assets and an expanded DNFBP scope into that assessment.

Who it applies to

Financial institutions; DNFBPs including real estate, dealers in precious metals and stones, auditors and accountants, legal professionals, corporate and trust service providers and commercial-gaming operators; and virtual asset service providers.

Supervisory authorities

CBUAE for financial institutions, the Ministry of Economy and Tourism for most DNFBPs, and MoJ, CMA, VARA, DFSA and FSRA in their respective markets, with STRs filed to the UAE FIU through goAML.

How Niyeahma helps

We build and document your business-wide ML/TF/PF risk assessment to FDL No. 10 of 2025 and Cabinet Resolution No. 134 of 2025, covering the new proliferation, virtual-asset and gaming scope, mapped to your specific supervisor.

Governing law

The Money Laundering Regulations 2017 (MLRs 2017).

Risk assessment requirement

Regulation 18 requires a written, up-to-date business-wide risk assessment covering your customers, the countries you operate in, your products and services, transactions and delivery channels, informed by the information your supervisor provides.

Who it applies to

Credit and financial institutions, and DNFBPs including accountants, auditors, tax advisers, legal professionals, estate agents, trust and company service providers and high-value dealers.

Supervisory authorities

The FCA, HMRC and the professional body supervisors, with suspicious activity reports going to the National Crime Agency.

How Niyeahma helps

We prepare a Regulation 18 compliant written risk assessment that stands up to FCA or HMRC review and aligns to your policies and controls.

Governing law

The AML/CTF Act 2006, as amended by the AML/CTF Amendment Act 2024, with the AML/CTF Rules 2025.

Risk assessment requirement

Reporting entities must assess and document the ML and TF risk they face and reflect it in their AML/CTF program. The 2024 reforms require the risk assessment to be in place before services are provided and kept current.

Who it applies to

Existing reporting entities in financial services, bullion and gambling, and, under the Tranche 2 reforms, real estate professionals, lawyers, accountants and dealers in precious metals and stones.

Supervisory authorities

AUSTRAC, which is both the regulator and the financial intelligence unit.

How Niyeahma helps

We build your ML/TF risk assessment and align it to your AML/CTF program so it meets AUSTRAC expectations under the amended regime.

Governing law

The CDSA and TSOFA, with the MAS AML/CFT Notices such as Notice 626.

Risk assessment requirement

MAS notices require an enterprise-wide risk assessment: institutions must identify, assess and understand their ML and TF risks across customers, countries, products and channels, document it and keep it current.

Who it applies to

Banks, capital markets intermediaries, payment service providers, insurers and other MAS-regulated financial institutions.

Supervisory authorities

The Monetary Authority of Singapore (MAS), with suspicious transaction reports filed to the Suspicious Transaction Reporting Office.

How Niyeahma helps

We prepare your enterprise-wide risk assessment to the relevant MAS notice and inspection expectations.

Governing law

The Prevention of Money Laundering Act 2002 (PMLA) and PML (Maintenance of Records) Rules 2005, with RBI, SEBI, IRDAI and IFSCA guidelines.

Risk assessment requirement

Regulated entities must carry out and periodically review a documented ML and TF risk assessment covering customers, products, geographies and channels, as set out in the RBI KYC Master Direction and the IFSCA AML, CFT and KYC Guidelines.

Who it applies to

Banks and financial institutions, market intermediaries, insurers and IFSC entities, and reporting entities under the PMLA.

Supervisory authorities

RBI, SEBI, IRDAI and IFSCA by sector, with reporting to FIU-IND and enforcement by the Enforcement Directorate.

How Niyeahma helps

We build your risk assessment to your sector regulator's requirements and the PMLA framework.

Governing law

The Anti-Money Laundering Law and its Implementing Regulations, with the SAMA AML/CTF guidance.

Risk assessment requirement

Institutions must identify, assess, document and understand their ML and TF risks under the risk-based approach and reflect them in their controls, as set out in the Implementing Regulations and SAMA rules.

Who it applies to

Banks and financial institutions supervised by SAMA, capital-market institutions supervised by the CMA, and DNFBPs.

Supervisory authorities

SAMA for financial institutions and the CMA for capital-market entities, with reporting to the Saudi FIU.

How Niyeahma helps

We prepare your enterprise-wide risk assessment to the Saudi AML Law, its Implementing Regulations and SAMA expectations.

Governing law

The Anti-Money Laundering and Counter-Terrorist Financing Ordinance (AMLO, Cap. 615).

Risk assessment requirement

Financial institutions and DNFBPs must conduct and document an institution-wide assessment of their ML and TF risks across customers, products, geographies and channels, and keep it current, as set out in the AMLO and the regulators' guidelines.

Who it applies to

Authorised institutions, licensed corporations, insurers, and designated non-financial businesses and professions.

Supervisory authorities

The HKMA, SFC, Insurance Authority and Customs and Excise Department by sector, with reporting to the Joint Financial Intelligence Unit.

How Niyeahma helps

We build your institution-wide risk assessment to the AMLO and the relevant regulator's guideline.

The standard

The FATF 40 Recommendations, in particular Recommendation 1.

Risk assessment requirement

Recommendation 1 sets the risk-based approach: businesses must identify, assess, understand and document their ML, TF and PF risks and direct resources to where risk is highest. This is the standard behind every national regime above.

Who it applies to

The global baseline for financial institutions and DNFBPs, applied through each country's own laws.

Supervisory authorities

Applied by national regulators and tested through FATF mutual evaluations.

How Niyeahma helps

Where you operate outside the jurisdictions above, we build your risk assessment to FATF standards so it is defensible in any market.

For the full policy and control documentation mapped to each of these regimes, see our AML/CFT policy, procedures and control documentation service.

One Ecosystem · Every Platform

This service is backed by the entire AMLVerse.

No NIYEAHMA service operates alone. Every engagement draws on a connected network of jurisdiction platforms, knowledge bases, professional tools, and technology, built and run by the same team.

21Platforms
5Verses
10+Jurisdictions
1Connected System
Consulting Verse Knowledge Verse Professional Verse Implementation Verse Technology Verse
Our Process

Our Risk Assessment Process.

A clear, repeatable process that produces a report you can operate from and defend.

01

Scope & data gathering

We agree what the assessment covers, then gather the inputs: customer segments, product inventory, channels, geographies, transaction data, prior findings and the relevant national and sectoral risk assessments.

02

Identify inherent risks

We map your ML, TF and PF exposure across every risk factor, before crediting any of your controls.

03

Assess your controls

We evaluate how effective your existing controls are, both in design and in practice.

04

Rate residual risk

We calculate residual risk factor by factor, using a consistent, defensible scoring method, and set it against your risk appetite.

05

Findings & action plan

We document the gaps and set out a clear remediation plan: what to fix, who owns it, and by when.

06

Report & board sign-off

We produce a clear, structured report for board and senior-management approval, ready for your regulator.

07

Monitor & refresh

We help you keep the assessment current, refreshing it annually and on material trigger events.

Tangible Output

What Is in Your Report.

You receive a complete, board-ready document, not a spreadsheet of scores without a story:

/

Scope & methodology

What the assessment covers and how each risk factor was scored, so it is transparent and repeatable.

/

Risk factor ratings

Customer, product, channel, geographic and transaction risk, each rated with narrative justification.

/

Inherent vs residual risk

The exposure before and after controls, so the effect of your controls is visible.

/

Risk matrix / heat map

A clear visual summary of exposure by business line for board-level presentation.

/

Control gaps & findings

Where controls fall short of the risk, stated honestly rather than hidden.

/

Remediation action plan

Each gap with an owner, a deadline and a status, because an empty action plan is itself a finding.

/

Board sign-off & risk appetite

A clear statement of accepted residual risk, approved by senior management.

Avoid the Usual Mistakes

Common Pitfalls We Help You Avoid.

Most weak assessments fail in the same predictable ways. We design these out from the start:

A copy-paste template: a generic assessment that does not reflect your actual business.

Left to go stale: an assessment running on volumes from before a product launch or new market.

Confusing inherent and residual risk: a single score that already bakes in controls, which examiners see through.

All-green ratings: an assessment that acknowledges no weaknesses raises flags immediately.

Scoping out small but risky products: low volume does not mean low risk.

No action plan: findings with no owner, deadline or follow-up.

No board sign-off: residual risk that senior management never saw or approved.

Ignoring national and sectoral risk assessments: missing the risks your regulator has already flagged.

Why Niyeahma

Defensible, Regulator-Ready, Yours.

A risk assessment is the beating heart of every AML decision. It sets the direction for your policies, procedures and monitoring across the business. We make sure yours is one you can stand behind:

/

A defensible methodology you can explain to any regulator.

/

Tailored to your business, your products, customers, channels and jurisdictions, never generic.

/

Risk linked to action, with findings, controls and a remediation plan, not just ratings.

/

Board-ready reporting that evidences oversight and stands up at inspection.

Your risk assessment should connect directly to the controls it drives. We align it with your AML/CFT policy, procedures and control documentation, and it can feed a wider AML/CFT Health Check of your whole programme.

Frequently Asked Questions

Risk Assessment Report, FAQ.

It is a structured, business-wide review that identifies, rates and documents your money laundering, terrorist financing and proliferation financing risks, measures how well your controls address them, and records the result for your board and regulator.

Under the risk-based approach, regulated businesses are expected to maintain a current business-wide risk assessment. In practice that means reviewing it at least once a year, and updating it whenever your business, products, markets or the regulations change materially.

Inherent risk is the exposure you face before any controls. Residual risk is what remains after your controls are applied. The point of the assessment is to show that residual risk sits within the level your board is willing to accept.

Scope and methodology, ratings for each risk factor, inherent versus residual risk, a risk matrix or heat map, control gaps and findings, a remediation action plan, and a board sign-off with a risk appetite statement.

Your board or senior management. Regulators expect evidence that leadership has seen the assessment, understood the residual risk, and formally accepted or acted on it.

Whenever something material changes: a new product or channel, a new market or customer segment, a merger or acquisition, a change in law or national risk assessment, or a significant incident.

Directly. The assessment sets the risks your controls must address. We align it with your AML/CFT policy and control documentation so risk, policy and controls all point the same way.

No. A risk assessment measures your risk exposure and whether controls match it. An AML/CFT Health Check tests whether your whole programme is working. They complement each other.

It depends on the size and complexity of your business and the quality of the data available. We agree a realistic timeline at the scoping stage and work to your regulatory deadlines.

Get Started

Let's Map Your Risk with Confidence.

Speak to our global AML consultants to prepare an Annual ML/TF/PF Risk Assessment Report that is defensible, regulator-ready and aligned with your business.