The Guidelines on the business-wide risk assessment: what the consultation asks of you
AMLA is consulting on Guidelines for the business-wide risk assessment under Article 10 AMLR. The structure they expect, the link to the supervisory methodology and what changes for institutions with a SIRA.
Dieser Artikel ist in dieser Sprache noch nicht verfügbar; das englische Original wird angezeigt. Die Übersetzung folgt automatisch.
Article 10 of the AMLR requires every obliged entity to identify and assess the money-laundering and terrorist-financing risks it is exposed to, to document the assessment, to keep it up to date and to make it available to the supervisor. AMLA's draft Guidelines on the business-wide risk assessment, now in consultation, describe how that is expected to be done. For Dutch institutions this is the successor of the SIRA that DNB has asked for since 2015; for institutions elsewhere it may be new.
The shape the Guidelines expect
The draft follows a familiar logic: inherent risk per risk factor, the controls that address it, and the residual risk that remains. The risk factors are the ones the AMLR names: customers, countries and geographic areas, products and services, transactions and delivery channels, plus the findings of the supranational and national risk assessments. What the Guidelines add is precision on granularity (per business line, per entity in a group, per country) and on evidence: which data supports each rating and who approved it.
The link with supervision
The risk-assessment RTS submitted to the Commission in July sets the methodology supervisors use to rate obliged entities. The Guidelines are its mirror image on the entity side. Where your own assessment and the supervisor's risk profile diverge, expect questions. A well-documented business-wide assessment is therefore also your best argument in a supervisory dialogue.
What changes for institutions that already have a SIRA
- Frequency becomes event-driven. An annual refresh remains the minimum, but a new product, a new market or a material change in the customer base triggers an update.
- Group perspective. Parent undertakings must be able to show a group-wide view alongside the entity views.
- Traceability to controls. Each residual risk must point to the policies, procedures and controls of Article 9 that mitigate it, and to the monitoring that proves the controls work.
- Management body involvement. The compliance manager presents the assessment; approval is recorded.
What to do now
- Compare your current SIRA structure with the draft: same risk factors, same granularity, same evidence?
- Build the link table between residual risks and controls if you do not have one; it is the piece supervisors ask for first.
- Decide the group-level view now if you are a parent undertaking; it drives the reporting lines of the compliance function.
- Respond to the consultation on proportionality if you are a small entity; the draft expects the same logic at every size, with less depth.
The dashboard tracks these Guidelines under Strategy & Risk; the workspace lets you record where the assessment stands.