AML Risk Assessment – what is it and how to prepare it?

September 24, 2026

An AML risk assessment helps determine where the risk of money laundering or terrorist financing may arise in a company’s activities and how significant that risk is. It does not concern one specific customer. An obliged institution analyses its business as a whole – including the types of customers it serves, the countries they are connected with, the products and services it offers, the nature of transactions and the way services are provided.

Such an assessment is one of the starting points for building an AML framework. If a company knows where the higher risks occur, it can appropriately adjust its KYC process, monitoring, safeguards and internal procedures.

Example:

Company A mainly serves Polish companies with simple ownership structures and starts business relationships with customers during face-to-face meetings. Company B provides similar services, but conducts onboarding entirely online, serves customers from multiple countries and frequently encounters complex ownership structures.

Both companies may be subject to the same AML obligations, but the risks associated with their activities will differ. Therefore, their risk assessments should not be identical.

What is an AML risk assessment?

An AML risk assessment is an analysis of the activities of an obliged institution from the perspective of whether its products, services or processes could be used for money laundering or terrorist financing. Preparing such an assessment is an obligation arising from Article 27 of the Polish AML Act. The regulations indicate that the assessment should take into account factors relating, among other things, to customers, countries and geographical areas, products, services, transactions and the way in which they are offered. The scope of the analysis should also be proportionate to the nature and size of the institution.

In practice, this means that there is no single ready-made document that can be used by every company. An assessment prepared for a small accounting firm will look different from one prepared for a payment institution operating in several countries.

The most important thing is that the assessment describes the actual risks arising from the activities of a specific company.

How to prepare an AML risk assessment

It is better not to start a risk assessment with a ready-made table containing “low”, “medium” and “high” columns. First, the company’s activities need to be understood and the areas where risks may actually occur need to be identified.

1. Determine how the company operates

The first step is to collect basic information about the business. In particular, it is important to determine:

  • which groups of customers the company serves,
  • which countries the customers and their activities are connected with,
  • which products and services are offered,
  • which types of transactions may occur,
  • how the relationship with the customer is established and conducted.

The aim is to create an accurate picture of how the company actually operates. For example, if a company serves customers only during face-to-face meetings, it makes little sense to build the entire assessment around risks associated with remote onboarding. If, however, most customers are onboarded online, this factor should be properly taken into account.

2. Identify risk factors

The next step is to determine which elements of the business may increase the risk of money laundering or terrorist financing. In the case of customers, relevant factors may include, for example, the type of business they conduct, their ownership structure or the way they use the services offered. In the case of geographical risk, it may be important to consider where the customer operates, where its counterparties are located or which countries are connected with the transactions being carried out.

The products and services themselves may also be relevant. Some allow funds to be transferred quickly or enable international transactions, while others are much more limited in nature. The Act identifies these types of factors as the basis for the general risk assessment of an obliged institution.

3. Determine the level of risk

Once individual risks have been identified, their significance for the company needs to be assessed. Different approaches may be used. In practice, risk is often classified as:

  • low,
  • medium,
  • high.

A points-based or more advanced model may also be used. However, the way in which the final result is labelled is less important than whether the company can explain why a particular risk was assessed in that way. For example, if geographical risk is classified as high, the document should show which circumstances led to that conclusion. A red cell in an Excel spreadsheet is not, by itself, a risk analysis.

4. Take existing safeguards into account

The assessment should also take into account the measures the company already uses to reduce identified risks. These may include, for example:

  • customer identification and verification,
  • identification of beneficial owners,
  • PEP status checks,
  • sanctions screening,
  • monitoring of business relationships and transactions,
  • additional verification of higher-risk customers,
  • internal approval rules for specific cases.

For example, remote onboarding may involve certain risks, but at the same time the company may use identity verification tools and additional controls to reduce those risks. The assessment should therefore not end with a statement that “a risk exists”. It should also show how the company manages that risk.

5. Document the assessment

The Act requires the general risk assessment to be prepared in paper or electronic form. The document should make it possible to understand:

  • what was analysed,
  • which risks were identified,
  • how their level was determined,
  • which safeguards the company uses,
  • what conclusions were drawn from the assessment.

This does not mean that the document has to be dozens of pages long. What matters much more is that it clearly shows why the company adopted a particular assessment and what information it was based on.

Company risk assessment vs customer risk assessment – what is the difference?

These two concepts are easy to confuse. The risk assessment referred to in Article 27 of the Polish AML Act concerns the activities of the institution as a whole. The company therefore analyses its business model, customers, products, markets and other factors that affect risk. A customer risk assessment, on the other hand, concerns a specific relationship with a specific customer or a specific occasional transaction. This obligation arises from Article 33 of the Polish AML Act. GIIF clearly distinguishes between these two types of assessment.

For example, as part of its general risk assessment, a company may determine that serving a certain type of customer involves a higher level of risk. This information may then be used when assessing a specific customer belonging to that group. The two assessments are therefore related, but they are not the same.

The process of assessing a specific customer is also one of the elements of KYC. In the article “KYC – what is it and how does it work?” we explain in more detail what information is collected and how it affects the customer’s risk profile.

How often should an obliged institution update its AML risk assessment?

A risk assessment is not a document prepared once and then left unchanged forever. Under Article 27(3) of the Polish AML Act, it should be updated whenever necessary, but at least once every 2 years. This does not mean, however, that every company can simply set a reminder for two years’ time and ignore the document until then. An earlier update may be necessary, for example, when the company:

  • introduces a new product or service,
  • begins serving a new group of customers,
  • starts operating in new markets,
  • changes the way customers are onboarded,
  • identifies new risks arising from its activities.

Example:

A company previously onboarded customers only during face-to-face meetings but then decided to introduce online onboarding. The way business relationships are established has changed and new risks may arise as a result. The company should therefore check whether its existing risk assessment still reflects its actual activities. There is no need to wait until the end of the two-year period.

The most common mistakes in AML risk assessments

One of the most common mistakes is treating the risk assessment as a document that simply needs to be prepared and kept in case of an inspection.

In practice, problems most often arise when:

  1. The assessment is based on a generic template. The document contains standard risks but does not show which of them actually apply to the specific company.
  2. The document does not reflect current activities. The company has changed its customers, products or the way it provides services, but the assessment still describes the previous business model.
  3. It is unclear how the adopted risk level was determined. The table contains “low”, “medium” and “high” values, but there is no explanation of why those particular ratings were applied.
  4. The assessment does not take existing safeguards into account. The document describes risks but does not show what the company does to reduce them.
  5. The assessment does not affect other AML processes. If the document states that a particular area involves high risk, but this has no impact on KYC, monitoring or other safeguards, the assessment has little practical value.

GIIF points out that the general risk assessment should be linked to the institution’s actual activities and should also affect the way in which the risk of specific customers is assessed.

Can the preparation of an AML risk assessment be outsourced?

External specialists can support the preparation or update of an AML risk assessment. This support may include analysing the company’s activities, identifying relevant risk factors, developing the assessment methodology and preparing the documentation. However, this does not mean that a reliable assessment can be prepared without information from the company itself. The organisation knows which customers it serves, which products it offers, which markets it operates in and how its processes work in practice. For this reason, preparing a risk assessment should begin with understanding the company’s activities, not with inserting its name into a ready-made template.

Do you need support in preparing or updating your AML risk assessment?

We can analyse your organisation’s business model, customer structure, products and services offered, and the AML measures currently in place. Based on this, we can support you in preparing or updating a risk assessment that reflects the actual nature of your business. We can also help you connect the assessment with other elements of your AML framework – including procedures, KYC, monitoring and customer due diligence measures.

Contact us

office@amloutsourcing.pl

    More articles about AML

    Learn more about AML outsourcing