Phoenix Compliance Essentials #20
Today’s focus: risk assessment, a cornerstone or a weakness of your AML/CFT-P-C framework?
In the field of AML/CFT-P-C, the risk-based approach is more than a regulatory requirement: it is a structured methodology at the heart of every effective compliance framework.
At the core of this approach lies the enterprise-wide risk assessment.
Often regarded as a purely formal exercise, it is in fact a strategic management tool that enables entities to identify threats and analyse vulnerabilities.
The risk assessment also aims to provide a structured analysis of the level of risk to which the entity is exposed. The methodology is based, in particular, on the likelihood and impact of risks in order to determine an appropriate overall risk level.
👉 The objective: to ensure that control measures are effectively aligned with the actual risks faced by the entity.
➡️ A living obligation, not a static document
The enterprise-wide risk assessment must:
– Be carried out from the start of the activity
– Be formalised, documented and approved by senior management
– Be made available to the supervisory authority upon request and, where applicable, submitted when updated
Above all, it must be reviewed and updated regularly. Any significant change should be reflected, including:
– The development of new activities or services;
– Changes in customer profiles or distribution channels;
– Geographical expansion;
– The emergence of new risks (technology, outsourcing, etc.).
👉 An outdated risk assessment leads to an inadequate, or even ineffective, compliance framework.
➡️ Expected standards
A robust risk assessment is based on:
– A specific and tailored approach
– A formalised and justified methodology
– A comprehensive analysis covering, at a minimum, the five risk factors: customers, products and services, geographical areas, transactions and distribution channels
– The involvement of key functions (compliance, operations and control) to ensure a comprehensive view of risks
– A rigorous assessment of residual risk, taking into account the effectiveness of the mitigation measures implemented
➡️ A genuine management tool
A well-designed enterprise-wide risk assessment makes it possible to:
– Prioritise actions
– Optimise the allocation of resources
– Align the compliance framework with the entity’s risk appetite
– Anticipate changes in business activities
In practice, it is not simply a document to be produced, but a living tool that supports informed decision-making.




