SIRA in the Netherlands — the DNB systematic integrity risk analysis, explained
In the Netherlands, the whole anti-financial-crime framework of a payment firm hangs off one document: the SIRA — the systematic integrity risk analysis. DNB treats it as the foundation, not the paperwork, and firms that cannot produce a current, credible one are the ones that draw enforcement. A SIRA is where a firm maps its integrity risks — money laundering, terrorist financing, sanctions, corruption, conflicts of interest — scores them, tests its controls against them and decides what to fix. This is what DNB expects, the legal anchor, and how a payments or e-money firm actually builds and maintains one.
1. What a SIRA is
A SIRA (systematische integriteitsrisicoanalyse — systematic integrity risk analysis) is a documented, firm-wide analysis of the integrity risks an institution is exposed to, the controls it has in place against them, and the residual risk that remains. It is not a one-off onboarding artefact and not the same thing as a transaction-monitoring rulebook: it is the risk assessment that justifies the rulebook, the customer-acceptance policy, the sanctions-screening configuration and the reporting process. If a Dutch supervisor asks “why is your framework calibrated this way?”, the SIRA is the answer.
The key word is systematic. A SIRA is not a gut-feel narrative; it is a structured pass over the business — products, customers, channels, geographies, third parties — that identifies each risk, rates it, and links it to a control. Done properly, it drives the whole integrity function; done as a box-tick, it exposes the firm on inspection.
2. The legal basis
The obligation is layered across the Dutch supervisory and AML statutes:
- Section 10 of the Bpr (Besluit prudentiële regels Wft) — the requirement to systematically analyse integrity risks and translate the analysis into policy, procedures and measures. This is the provision DNB anchors the SIRA expectation to for financial institutions.
- The Wft (Wet op het financieel toezicht) — the sound and controlled business-operations duty (integere en beheerste bedrijfsvoering) that requires a firm to run its business with integrity and to control the risks that threaten it.
- Article 2b of the Wwft — the anti-money-laundering law’s requirement to identify and assess the firm’s ML/TF risks (customers, products, services, transactions, delivery channels, countries), record that assessment and keep it up to date. In practice this ML/TF assessment lives inside the same SIRA.
- The Sanctiewet 1977 — sanctions-evasion and proliferation-financing risk sits in the same analysis.
In 2025 DNB refreshed its practical guidance, replacing the long-standing 2015 document (“The Integrity Risk Analysis — more where required, less where possible”) with new Good Practices SIRA. The shift matters: DNB no longer prescribes a single model, but sets out examples and points of attention and expects a genuinely risk-based analysis — probability and impact reasoned through, not a generic template lifted from elsewhere.
3. Which integrity risks it must cover
For a payments or e-money firm, the practically load-bearing categories are usually these:
| Integrity risk | Typical driver in a payments firm |
|---|---|
| Money laundering | High transaction velocity, pass-through accounts, cash-adjacent products, weak source-of-funds visibility |
| Terrorist financing | Low-value cross-border flows, remittance corridors, prepaid instruments |
| Sanctions / proliferation financing | Cross-border payments, screening gaps, ownership-chain complexity |
| Corruption & bribery | PEP exposure, high-risk sectors, intermediaries and agents |
| Conflicts of interest | Related-party flows, staff dealing, incentive structures |
| Socially improper conduct / tax integrity | Facilitation of tax evasion, reputationally damaging client segments |
4. The method: inherent risk, controls, residual risk
DNB does not mandate one scoring model, but the logic every credible SIRA follows is the same chain:
- Scope and prepare — inventory the business: products and services, customer types, delivery channels, geographies, third parties. Nothing material should be off the map.
- Identify risks — for each element, name the specific integrity risks it introduces. “Cross-border payments” is not a risk; “layering through rapid in-and-out cross-border transfers via correspondent chains” is.
- Assess inherent risk — rate each risk on likelihood and impact before controls. This is the gross exposure.
- Assess controls — map the mitigating measures (CDD, monitoring rules, screening, governance) to each risk and judge how effective they actually are, not how good they look on paper.
- Determine residual risk — inherent risk net of control effectiveness. Compare it to the board-set risk appetite.
- Act and monitor — where residual risk exceeds appetite, define remediation with owners and dates; then keep the analysis live, revisiting it on a set cycle and on every material change.
The output is not a score for its own sake. It is a set of decisions: which controls to strengthen, which customer segments to restrict, which products need extra monitoring — each traceable back to a rated risk.
5. Three worked examples
Example 1 — a new product raises inherent risk. Facts: a Dutch-authorised EMI plans to add a crypto on-ramp, letting customers convert e-money to crypto-assets through a partner. Rule: Section 10 Bpr requires the integrity analysis to be current, and Article 2b Wwft requires the ML/TF assessment to reflect the firm’s actual products. A new product that materially changes exposure means the SIRA must be updated before launch. What the firm does: re-scores the ML/TF and sanctions inherent risk for the on-ramp, maps controls (source-of-funds checks, transaction limits, travel-rule data, screening of the partner chain), lands the residual risk, and only launches once it sits within appetite. Outcome: the launch is defensible; shipping first and updating the SIRA afterwards would invert the required order and be a finding on inspection.
Example 2 — passporting in, not licensed locally. Facts: an EMI licensed in another EU state passports into the Netherlands and builds a Dutch customer base. Rule: Dutch AML and integrity obligations attach to the activity carried on in the Netherlands; the firm cannot rely solely on a home-state group risk assessment that never looks at its Dutch book. What the firm does: scopes a SIRA (or a Dutch chapter of the group SIRA) to the Netherlands segment — local product mix, Dutch customer risk profile, Dutch UTR reporting flow and sanctions exposure — and can produce it on request. Outcome: the firm meets the Dutch-activity expectation; a purely head-office assessment silent on the Netherlands is the gap DNB looks for.
Example 3 — the stale SIRA. Facts: a firm produced a solid SIRA at authorisation, then left it untouched for three years while its transaction volume tripled and it entered two new remittance corridors. Rule: the SIRA must be kept up to date and reflect the firm as it actually operates; a document that no longer describes the business does not satisfy Section 10 Bpr. What the firm does (too late): nothing, until an inspection surfaces the gap. Outcome: DNB has imposed enforcement measures, including fines, on firms that could not produce an adequate, current integrity risk analysis — a stale SIRA is treated as effectively no SIRA. The remediation is an annual refresh cycle plus an event-driven trigger on every material change.
6. How a payments firm builds and maintains it
- Own it at board level. Risk appetite is a board decision; the SIRA is signed off, not delegated into a drawer. DNB reads governance ownership as a signal of whether the analysis is real.
- Make it granular to your book. Generic risk libraries are a starting point, not the deliverable — the analysis has to reflect your specific products, corridors and customer segments.
- Link every risk to a control and every gap to an action. The value is the remediation plan with owners and dates, not the heat-map.
- Wire it to the operational layer. The SIRA should drive your monitoring rules, customer-acceptance thresholds and sanctions-screening configuration — and be updated when they change.
- Refresh on a cycle and on events. Annually at minimum, plus on any material change: new product, new geography, new third party, a spike in volume, a new typology. Record the trigger and the review.
- Keep the evidence. Version the document, minute the board approval, and retain the working papers — on inspection, “we did think about it” is worth nothing without the record.
7. FAQ
Is a SIRA the same as the Wwft risk assessment?
The Wwft Article 2b money-laundering and terrorist-financing risk assessment is a component of the SIRA, not a separate document in most firms. The SIRA is broader — it also covers sanctions, corruption, conflicts of interest and socially improper conduct — and is anchored in Section 10 Bpr as well as the Wwft.
Does DNB prescribe a specific SIRA model or template?
No. Since the 2025 Good Practices, DNB deliberately does not steer firms to one model. It expects a genuinely risk-based analysis with reasoned likelihood and impact, and offers examples and points of attention rather than a mandatory template.
How often must a SIRA be updated?
There is no single statutory interval, but the analysis must be kept current. Standard practice is a full refresh at least annually, plus an event-driven update whenever there is a material change — a new product, geography, third party or a significant shift in volume or typology.
We passport into the Netherlands — do we still need a SIRA?
Your Dutch activity attracts Dutch integrity and AML obligations. You need an integrity risk analysis that covers the Netherlands business specifically; a home-state group assessment that never examines your Dutch book will not satisfy a DNB review.
What happens if we don’t have an adequate SIRA?
A missing or inadequate integrity risk analysis is a supervisory failing in its own right. DNB has taken enforcement action, including fines, against firms that could not produce a current, credible SIRA — separate from any underlying money-laundering issue.
Who should sign off the SIRA?
The board. Risk appetite is a board-level decision and the analysis that measures residual risk against that appetite should be formally approved and minuted at that level.
8. What to do, today
- Confirm you hold a current SIRA that covers all integrity-risk categories, not just ML/TF — and that it describes the business as it operates now.
- Check the method: inherent risk, control effectiveness, residual risk against a board-set appetite, with a remediation plan for every gap.
- Set an annual refresh cycle plus event triggers (new product, geography, third party, volume spike).
- Trace your monitoring rules, acceptance thresholds and sanctions screening back to specific rated risks — and fix any control that isn’t anchored to one.
- If you passport in, scope a Netherlands-specific analysis you can hand to DNB on request.
Related: Dutch AML beyond goAML · FIU-Nederland UTR reporting · EMI licence in the Netherlands (DNB) · Sanctions screening for instant payments


