Business-wide risk assessment — the six mandatory inputs
The business-wide risk assessment is the document every other AML control is supposed to descend from — and Article 10 tells you exactly what has to go into it. Regulation (EU) 2024/1624 requires obliged entities to identify and assess the money laundering and terrorist financing risks they are exposed to, as well as the risks of non-implementation and evasion of targeted financial sanctions, taking into account at least six named inputs. “At least” makes the list a floor, and the sanctions limb makes it broader than most existing assessments.
1. The six inputs
| Limb | Input |
|---|---|
| (a) | The risk variables in Annex I and the risk factors in Annexes II and III |
| (b) | The findings of the Union-level risk assessment conducted by the Commission under Article 7 of Directive (EU) 2024/1640 |
| (c) | The findings of the national risk assessments carried out by Member States under Article 8 of that Directive, and any relevant sector-specific national assessment |
| (d) | Relevant information published by international standard setters in the AML/CFT area, or relevant publications by the Commission or AMLA |
| (e) | Information on ML/TF risks provided by competent authorities |
| (f) | Information on the customer base |
The measures taken must be proportionate to the nature of the business, including its risks and complexity, and its size. Proportionality shapes the depth of the analysis; it does not remove any of the six inputs.
2. The sanctions limb changes the scope
Article 10(1) requires the assessment to cover the risks of non-implementation and evasion of targeted financial sanctions, in addition to ML/TF risk. Many firms run sanctions risk as a separate exercise owned by a different team, and the Regulation does not forbid that — but the business-wide assessment has to reach it, which in practice means the two exercises must at least be reconciled and cross-referenced.
The same duality runs through Article 9, which requires internal policies, procedures and controls to mitigate and manage both the ML/TF risks and, in addition to the obligation to apply targeted financial sanctions, the risks of their non-implementation and evasion.
3. The pre-launch duty
Article 10(1) continues past the six inputs with an obligation attached to change rather than to the calendar: it applies prior to the launch of new products and services. Read alongside the wider AMLR governance provisions, the practical trigger is broader than a product launch in the marketing sense — a new geography or a new customer segment engages it even where the product itself is unchanged.
That makes the assessment a gate in the change process, not an annual document. The operational test is simple: can your product governance show, for each launch in the last year, the risk assessment that preceded it? If the assessment is refreshed only once a year, the answer is structurally no.
4. Who draws it up, and who approves it
The AMLR separates the two, and the split is one of the more commonly missed features of the new regime. Under the Article 11 compliance-function architecture, the compliance officer draws up the business-wide risk assessment and the management body approves it. Neither role can be outsourced: Article 18(3) puts the proposal and approval of the business-wide risk assessment on the list of tasks that may never be outsourced under any circumstances.
Article 9 adds a second altitude that is easy to collapse. Internal policies are approved by the management body; procedures and controls are approved at least at compliance-manager level. A single omnibus document approved once by the board maps to neither, and unpicking it later is harder than structuring it correctly at the outset.
FAQ
How often must the assessment be updated?
Article 10 frames the obligation around carrying out and updating the assessment, with the pre-launch duty attaching to new products and services. A purely annual cycle will miss the change-driven trigger.
Does it have to cover sanctions?
Yes. Article 10(1) requires the risks of non-implementation and evasion of targeted financial sanctions to be assessed alongside ML/TF risk.
Can we outsource the assessment?
No. Article 18(3) lists the proposal and approval of the business-wide risk assessment among the tasks that may never be outsourced under any circumstances.
Related: AMLR governance · Policies, procedures and controls · The customer risk profile


