Risk-Based Approach
A risk-based approach is a method in which organizations and their regulators first identify and understand the money laundering and terrorist financing risks they face, and then focus their controls and resources where those risks are highest. Rather than treating every customer or transaction the same way, it allows effort to be concentrated on areas of greater risk. It is a way of managing risk proportionately rather than applying a single uniform standard to everything.
In the AML/CFT context, the Risk-Based Approach (RBA) is a methodology under which countries, competent authorities, supervisors, and financial institutions (including banks, securities-sector firms, and intermediaries) identify, assess, and understand the money laundering and terrorist financing (ML/TF) risks to which they are exposed. Based on that risk understanding, obligated entities are generally expected to implement policies, procedures, systems, and controls calibrated to apply enhanced measures to higher-risk situations and, where permitted, simplified measures to lower-risk situations. The RBA is a foundational principle of the FATF Recommendations and is operationalized through firm-specific risk assessments and governance; the precise scope, thresholds, and expectations vary by jurisdiction, sector, and supervisory interpretation. This entry addresses the RBA as applied to AML/CFT; the same term may be used with different meaning in other compliance domains, and application to a specific institution should be informed by the relevant national implementing framework and, where appropriate, professional advice.
Why it matters
The risk-based approach is a foundational principle of the FATF Recommendations, the international standards that shape how countries and financial institutions structure their AML/CFT programs. Its significance lies in the recognition that resources for combating money laundering and terrorist financing are finite, and that treating every customer and transaction identically is neither efficient nor effective. By requiring countries, competent authorities, supervisors, and financial institutions to first identify, assess, and understand the ML/TF risks to which they are exposed, the RBA aims to direct controls and effort toward the areas where the threat is greatest.
For obligated entities, the RBA carries direct supervisory and reputational consequences. A firm that cannot demonstrate a credible understanding of its own risk exposure, or whose controls are not calibrated to that exposure, may struggle to satisfy supervisors that its program is adequate. The approach shifts the burden onto institutions to justify their choices: where enhanced measures are applied to higher-risk situations and, where permitted, simplified measures to lower-risk ones, those decisions must rest on a documented and defensible risk assessment rather than on convenience.
Because the RBA is a methodology rather than a fixed checklist, its practical demands vary by jurisdiction, sector, and supervisory interpretation. What a supervisor considers proportionate in one national framework may differ from expectations elsewhere, so firms operating across borders must reconcile potentially divergent expectations against a common internal risk methodology. This context-dependence is precisely why the approach places a premium on governance and on the ability to evidence the reasoning behind control decisions.
Who it's relevant to
Inside RBA
Common questions
Answers to the questions practitioners most commonly ask about RBA.

