Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Due Diligence

Risk-Based Approach

Also known as: RBA, Risk-Based Approach to AML/CFT
Simply put

A risk-based approach is a method in which organizations and their regulators first identify and understand the money laundering and terrorist financing risks they face, and then focus their controls and resources where those risks are highest. Rather than treating every customer or transaction the same way, it allows effort to be concentrated on areas of greater risk. It is a way of managing risk proportionately rather than applying a single uniform standard to everything.

Formal definition

In the AML/CFT context, the Risk-Based Approach (RBA) is a methodology under which countries, competent authorities, supervisors, and financial institutions (including banks, securities-sector firms, and intermediaries) identify, assess, and understand the money laundering and terrorist financing (ML/TF) risks to which they are exposed. Based on that risk understanding, obligated entities are generally expected to implement policies, procedures, systems, and controls calibrated to apply enhanced measures to higher-risk situations and, where permitted, simplified measures to lower-risk situations. The RBA is a foundational principle of the FATF Recommendations and is operationalized through firm-specific risk assessments and governance; the precise scope, thresholds, and expectations vary by jurisdiction, sector, and supervisory interpretation. This entry addresses the RBA as applied to AML/CFT; the same term may be used with different meaning in other compliance domains, and application to a specific institution should be informed by the relevant national implementing framework and, where appropriate, professional advice.

Why it matters

The risk-based approach is a foundational principle of the FATF Recommendations, the international standards that shape how countries and financial institutions structure their AML/CFT programs. Its significance lies in the recognition that resources for combating money laundering and terrorist financing are finite, and that treating every customer and transaction identically is neither efficient nor effective. By requiring countries, competent authorities, supervisors, and financial institutions to first identify, assess, and understand the ML/TF risks to which they are exposed, the RBA aims to direct controls and effort toward the areas where the threat is greatest.

For obligated entities, the RBA carries direct supervisory and reputational consequences. A firm that cannot demonstrate a credible understanding of its own risk exposure, or whose controls are not calibrated to that exposure, may struggle to satisfy supervisors that its program is adequate. The approach shifts the burden onto institutions to justify their choices: where enhanced measures are applied to higher-risk situations and, where permitted, simplified measures to lower-risk ones, those decisions must rest on a documented and defensible risk assessment rather than on convenience.

Because the RBA is a methodology rather than a fixed checklist, its practical demands vary by jurisdiction, sector, and supervisory interpretation. What a supervisor considers proportionate in one national framework may differ from expectations elsewhere, so firms operating across borders must reconcile potentially divergent expectations against a common internal risk methodology. This context-dependence is precisely why the approach places a premium on governance and on the ability to evidence the reasoning behind control decisions.

Who it's relevant to

AML/CFT Compliance Officers
Compliance officers at banks, securities-sector firms, and intermediaries are typically responsible for translating the institution's risk assessment into policies, procedures, systems, and controls. They must be able to evidence why particular measures are applied to particular risk categories, since the defensibility of those choices is central to demonstrating an adequate program.
Supervisors and Competent Authorities
Under the FATF framework, supervisors and competent authorities are themselves expected to identify, assess, and understand ML/TF risks and to evaluate whether supervised entities have calibrated their controls proportionately. Their interpretation of what constitutes a proportionate response can vary by jurisdiction and directly shapes how firms implement the approach.
Financial Institutions and Intermediaries
Banks, securities firms, and other intermediaries are the obligated entities expected to conduct firm-specific risk assessments and to apply enhanced measures to higher-risk situations and, where permitted, simplified measures to lower-risk ones. Institutions operating across multiple jurisdictions must reconcile differing national expectations against a coherent internal methodology.
Risk Managers and Governance Functions
Because the RBA is operationalized through risk assessments and governance, risk managers and senior governance bodies are relevant to overseeing that the risk understanding remains current and that control calibration is reviewed as the risk picture evolves. This oversight role supports the dynamic character of the approach.

Inside RBA

Risk Identification
The process of systematically cataloguing the risks relevant to an organization's activities, products, customers, and jurisdictions. This forms the foundation of an RBA by establishing what threats and vulnerabilities exist before resources are allocated to address them.
Risk Assessment and Rating
The evaluation of identified risks according to factors such as likelihood and potential impact, often expressed as a rating (for example, low, medium, or high). The specific methodology and rating scales generally vary by organization and by the regulatory regime under which it operates.
Proportionate Controls
The application of mitigation measures calibrated to the assessed level of risk, so that higher-risk areas receive enhanced scrutiny and lower-risk areas receive simplified or standard measures. What is considered proportionate is context-dependent and may be subject to regulator interpretation.
Risk Appetite and Tolerance
The articulation, typically by senior management or the board, of the level and types of risk the organization is willing to accept. This provides the reference point against which residual risk is judged acceptable or in need of further treatment.
Ongoing Monitoring and Review
The periodic reassessment of risks and the effectiveness of controls, recognizing that risk profiles change over time. Frequency and triggers for review generally depend on the nature of the risk and applicable regulatory expectations.
Documentation and Rationale
The recording of how risks were identified, assessed, and treated, including the reasoning behind decisions. Documentation supports the ability to demonstrate to regulators and auditors that the approach is defensible and consistently applied.

Common questions

Answers to the questions practitioners most commonly ask about RBA.

Does a risk-based approach mean we can ignore or skip lower-risk obligations?
No. A risk-based approach (RBA) is generally about proportionately allocating resources and controls according to assessed risk, not about waiving legal obligations. Where a regulation imposes a baseline or mandatory requirement, that obligation typically applies regardless of assessed risk level; an RBA governs the intensity and depth of measures above any such floor, not whether the requirement is met at all. Treating lower-risk items as optional can itself create compliance and enforcement exposure.
Is a risk-based approach a way to reduce compliance effort or costs overall?
Not necessarily. An RBA is intended to direct effort where risk is highest rather than to minimize effort generally. In practice it may increase scrutiny and controls for higher-risk areas while streamlining lower-risk ones. The objective is proportionality and defensibility, not cost reduction as such. Any efficiency gains depend on context and should not come at the expense of meeting applicable requirements.
How do we document a risk-based approach so it is defensible to a regulator?
Documentation generally includes a clear methodology (how risks are identified, assessed, and scored), the criteria and rationale behind risk ratings, the controls mapped to each risk tier, and evidence that decisions were reviewed and approved by appropriate accountable parties. Regulators typically expect to see not only the outcome but the reasoning, so maintaining an audit trail of assessments and the basis for proportionality decisions is important. Specific expectations may depend on the applicable regime and should be confirmed against the relevant requirements.
How often should risk assessments underlying an RBA be reviewed or refreshed?
Review frequency generally depends on the regulation, the volatility of the risk environment, and any material changes to the business, such as new products, markets, technologies, or regulatory developments. Many programs combine periodic scheduled reviews with event-driven reassessments triggered by significant changes. There is no single universal interval; the appropriate cadence should be defined in the methodology and aligned with applicable requirements and internal governance expectations.
Who is responsible for setting risk criteria versus applying them in day-to-day operations?
Responsibilities typically follow a lines-of-defense structure. Business or operational units (often described as the first line) generally apply risk criteria within their processes, while the compliance or risk function (second line) commonly sets and oversees the methodology, criteria, and consistency of application. Internal audit (third line) provides independent assurance over the design and effectiveness of the approach. These boundaries should be clearly assigned to avoid blurred accountability, and the exact allocation may vary by organization and regulatory context.
How do we handle residual risk that remains after applying risk-based controls?
Residual risk is the risk that remains after controls are applied. It generally needs to be assessed against a defined risk appetite or tolerance and either accepted, mitigated further, transferred, or escalated to accountable decision-makers. Acceptance decisions should typically be documented, approved at an appropriate level, and revisited as part of ongoing review. Where residual risk touches mandatory obligations, acceptance may not be an available option, and legal or professional advice may be needed for specific situations.

Common misconceptions

A risk-based approach means an organization can simply choose to do less compliance work in areas it deems low-risk.
An RBA reallocates effort in proportion to assessed risk; it does not eliminate baseline obligations. Lower-risk areas may warrant simplified measures, but any decision to reduce scrutiny generally must be justified, documented, and consistent with applicable regulatory expectations rather than treated as a discretionary shortcut.
Adopting a risk-based approach guarantees compliance because the organization is focusing on the highest risks.
Prioritizing high-risk areas does not by itself ensure compliance. The adequacy of an RBA is context-dependent and may be judged differently by regulators; a flawed risk assessment, inconsistent application, or inadequate documentation can leave an organization exposed even where high-risk areas receive attention.
A risk assessment is a one-time exercise that can be completed and then set aside.
Risk profiles typically change as products, customers, jurisdictions, and threats evolve. An RBA is generally expected to include ongoing monitoring and periodic review, so a static, one-time assessment is unlikely to remain defensible over time.

Best practices

Document your risk methodology, rating scales, and the rationale for control decisions so the approach can be demonstrated to regulators and auditors as defensible and consistently applied.
Anchor the approach in a clearly articulated risk appetite set or endorsed by senior management or the board, and use it as the reference point for judging acceptable residual risk.
Calibrate controls proportionately to assessed risk, applying enhanced measures to higher-risk areas while ensuring lower-risk areas still meet applicable baseline obligations.
Establish periodic review cycles and event-driven triggers to reassess risks and control effectiveness as products, customers, jurisdictions, and threats change.
Confirm the RBA aligns with the specific requirements and expectations of each applicable jurisdiction and regulatory regime, since what is considered proportionate may differ across regimes.
Seek qualified professional or legal advice when applying the approach to novel, ambiguous, or high-stakes situations where regulator interpretation may be uncertain.
Promotional banner for the Pentest Readiness checklist download