Enterprise Wide AML Risk Assessment: Drivers, Scoring and Controls
Every bank operating in India must run an enterprise wide AML risk assessment at least once a year, and refresh it whenever the business changes. This is not a paperwork exercise. It is the single document that decides how much due diligence a customer gets, which transactions trigger an alert, and how often internal audit walks into a branch. For JAIIB and CAIIB candidates, understanding how this assessment is built - and how a bank turns a risk score into a control - is one of the most tested ideas in the KYC-AML syllabus.
📊 What an Enterprise Wide AML Risk Assessment Actually Does
An enterprise wide AML risk assessment (EWRA) is the bank's own inherent-risk map - a structured exercise that identifies where money laundering (ML) and terrorist financing (TF) exposure sits across the entire institution, not just at the account-opening desk. It looks across every business line, product, delivery channel and geography the bank touches, and rates each combination on how attractive it is to a launderer.
The exercise sits on a specific regulatory foundation. FATF Recommendation 1 requires countries and financial institutions to identify, assess and understand their ML/TF risks, and to apply resources on a risk-sensitive basis so controls are proportionate to the risk found - not uniformly heavy or uniformly light. In India this expectation flows through the RBI's KYC framework (see rbi.org.in) and the PMLA Rules, which require a written, board-approved risk assessment that is kept current.
Two ideas anchor the whole exercise. Inherent risk is the raw exposure before any control is applied - a walk-in cash-intensive remittance product in a high-risk border district is inherently riskier than a salary account opened through a corporate tie-up. Residual risk is what remains after the bank's controls - CDD, transaction monitoring, sanctions screening - are factored in. The gap between the two tells the bank, and its regulator, whether the control environment is doing its job.

🎯 The Four Risk Drivers: Customer, Product, Channel, Geography
Every enterprise wide AML risk assessment is built on four risk drivers, scored independently and then combined.
Customer risk looks at who the account holder is - occupation, ownership structure, politically exposed person status, cash intensity of the underlying business, and whether the relationship is face-to-face or non-face-to-face. Product and service risk looks at the instrument itself: a current account with high-value RTGS access carries more inherent risk than a small-savings account with a transaction cap, and trade finance products carry their own elevated profile, as explored in our piece on trade-based money laundering red flags.
Channel risk covers how the customer transacts - branch, internet banking, correspondent arrangements or agency banking all carry different exposure. Banks with cross-border correspondent relationships treat this driver with particular care; see the chapter on correspondent banking for how respondent-bank due diligence feeds into this score. Geography risk weighs the jurisdictions a customer, counterparty or transaction touches - FATF grey-listed and blacklisted countries, tax havens, and conflict zones score high, as covered in the chapter on country risk and money laundering.
No single driver decides the outcome alone - a low-risk customer using a high-risk channel into a high-risk geography can still land in the high-risk band.
| Risk Driver | Low-Risk Indicator | High-Risk Indicator | EDD Typically Triggered |
|---|---|---|---|
| Customer | Salaried employee, face-to-face onboarding | PEP, complex ownership, cash-intensive business | ✅ |
| Product | Small savings account, capped limits | Current account with high-value RTGS or trade finance | ❌ |
| Channel | Branch-based, verified video KYC | Correspondent banking, agency or BC channel | ✅ |
| Geography | Domestic, low-risk state | FATF grey/black-listed jurisdiction, border district | ✅ |

🧮 Scoring, Residual Risk and Control Effectiveness
Most banks convert the four drivers into a weighted numeric score, then map the score to a risk band - typically low, medium and high, sometimes with a very-high band reserved for cases needing the closest monitoring. The weights are not arbitrary; they must reflect the bank's own business mix and be defensible to the board and to supervisors.
The score at this stage is inherent risk - before controls. The assessment then asks a second question: how effective are the bank's existing controls at reducing that risk? CDD depth, sanctions screening coverage, staff training, and system-generated transaction monitoring alerts in AML compliance all count as mitigants. Subtracting control effectiveness from inherent risk gives residual risk - the number that actually drives day-to-day decisions.
💡 Exam Tip: Inherent risk minus control effectiveness equals residual risk. Questions often test whether you know which side of that equation a given fact belongs on - a cash-intensive business is inherent risk; a monthly review of that account is a control.
A high residual risk score is not a rejection signal - it is a resourcing signal, telling the bank where to put its best analysts, tightest thresholds and most frequent reviews.

🛡️ How the Score Drives Due Diligence, Thresholds and Audit
The whole point of an enterprise wide AML risk assessment is that it is not left on a shelf. Every high-risk customer segment must get deeper onboarding checks, more frequent periodic KYC updation, and lower alert thresholds in the transaction monitoring system.
Internal audit uses the same output. Audit coverage should be risk-weighted, so a correspondent banking desk or a high cash-intensity branch gets audited more often than a low-risk salary-account book - the practical meaning of "risk-based": resources chase risk, not headcount convenience.
The assessment also feeds the bank's overall organisational response - how the AML function is structured, where the principal officer sits, and how findings escalate. For the structural side of this, see the chapter on the organization structure in India for AML compliance.
⚠️ Common Mistake: Treating the risk assessment as a one-time onboarding document. If the score does not visibly change monitoring thresholds, due-diligence intensity and audit frequency, the assessment has not actually been operationalised - and examiners will flag exactly that gap.
🏛️ Board Approval, Periodic Refresh and Proportionate Controls
An enterprise wide AML risk assessment is a board-owned document, not a compliance-department memo. The board, or a board-level committee, must approve the methodology, review the outcome, and be told when residual risk in any segment rises materially.
Refresh is periodic and event-driven both. A full re-assessment is typically expected at least annually, with interim updates whenever the bank launches a new product, enters a new geography, or a material adverse finding surfaces. For the broader legal backdrop, see the chapter on legislation at national level, and the companion piece on the RBI KYC master direction.
FATF Recommendation 1's proportionality principle cuts both ways: supervisors expect stronger controls where risk is higher, and simpler controls where risk is genuinely low, rather than uniform heavy-handed checks everywhere.
📌 Remember: Proportionality is a two-way test - under-control on high-risk segments and over-control on low-risk segments are both assessment failures examiners look for.
The same discipline extends beyond traditional banking channels. Digital lending has its own emerging risk profile, and gaps in that assessment show up as illegal loan apps and digital lending fraud risk that a bank's partnership and outsourcing oversight must also capture.
✅ Get Exam-Ready on Risk-Based AML Compliance
The enterprise wide AML risk assessment ties together nearly every other KYC-AML topic - due diligence intensity, monitoring thresholds, audit planning and board oversight all trace back to it. Candidates who can explain how a risk score moves from inherent to residual, and what that number changes operationally, consistently score well on this segment of JAIIB and CAIIB papers.
Browse more chapter-linked reading on the KYC, AML and CFT tag hub, or test yourself with a full mock at iibf.store/course/caiib.
🧠 Practice MCQs: Enterprise Wide AML Risk Assessment
Q1. Under FATF Recommendation 1, banks are expected to apply AML controls that are: (a) uniform across all customers regardless of risk (b) proportionate to the ML/TF risk identified (c) decided solely by the IT department (d) applied only to non-resident customers
Answer: (b) - FATF Recommendation 1 requires a risk-sensitive approach, so control intensity matches assessed risk rather than being applied uniformly.
Q2. In an enterprise wide AML risk assessment, "residual risk" refers to: (a) risk before any assessment is conducted (b) risk remaining after control effectiveness is factored in (c) risk that applies only to correspondent banks (d) risk that is reported only to FIU-India
Answer: (b) - Residual risk is inherent risk reduced by the effectiveness of existing controls such as CDD and transaction monitoring.
Q3. Which of the following is NOT one of the four standard risk drivers used in an enterprise wide AML risk assessment? (a) Customer (b) Product (c) Employee headcount (d) Geography
Answer: (c) - The four recognised drivers are customer, product/service, channel and geography; staffing levels are not a risk driver in this framework.
Q4. An enterprise wide AML risk assessment should ordinarily be approved and periodically reviewed by: (a) the branch manager alone (b) the board or a board-level committee (c) the customer's relationship manager (d) the external auditor only
Answer: (b) - The assessment is a board-owned document; the board or a designated committee approves the methodology and reviews outcomes.
Q5. A bank's enterprise wide AML risk assessment flags a branch as high residual risk. The most appropriate response is to: (a) leave audit frequency unchanged since audit is independent of risk scoring (b) increase audit coverage and tighten monitoring thresholds for that branch (c) close the branch immediately (d) exempt the branch from KYC updation
Answer: (b) - Audit coverage and monitoring intensity must be risk-weighted, so a high residual risk branch gets closer, more frequent scrutiny.
Want chapter-wise mock tests with 100+ MCQs? Start practising free →
What is an enterprise wide AML risk assessment?
It is a structured, board-approved exercise that maps a bank's inherent money laundering and terrorist financing risk across customer, product, channel and geography, then evaluates residual risk after existing controls are factored in.
How often should the assessment be refreshed?
At least annually, with additional interim updates whenever the bank changes its products, channels or geographic footprint, or when a material adverse finding emerges.
What is the difference between inherent risk and residual risk?
Inherent risk is the raw exposure before any control is applied; residual risk is what remains after control effectiveness - such as CDD depth and transaction monitoring - is factored in.
Why does FATF Recommendation 1 matter for this assessment?
It is the international standard requiring countries and institutions to identify, assess and understand their ML/TF risk and apply controls proportionate to that risk, which underpins India's own KYC and AML regulatory expectations.
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.
Keep reading