The BSA/AML risk assessment is the document examiners open first, and the one most institutions treat as an annual formality. That mismatch explains a large share of program findings: the assessment says one thing, the controls do another, and nobody noticed because the assessment was written to be filed rather than to be used.
This is a working method for building one that actually drives the program.
Its purpose is to identify the money laundering and terrorist financing risks specific to your institution so that controls can be designed proportionally. It is the bridge between "here is what we do and who we serve" and "here is why our program looks the way it does."
That bridge has to bear weight in both directions. An examiner reading the assessment should be able to predict what the monitoring rules, EDD categories, training content, and testing scope look like. An examiner reading the controls should be able to trace each one back to a risk the assessment identified.
When the two do not reconcile, one of them is wrong — and it is usually the controls, because the assessment is the honest document.
Start with data, not judgment. Pull the actual numbers rather than describing the institution from memory, because the memory version is always the institution of three years ago.
Products and services. Every product offered, with volumes and dollar values. Deposit accounts by type, lending products, wires (domestic and international, by count and value), ACH origination, remote deposit capture, cash services, safe deposit, prepaid, trust and investment services, correspondent relationships, and anything offered through a third party under your charter.
Customers. Counts by customer type and by NAICS code where available. Specifically quantify the categories your policy treats as higher risk: cash-intensive businesses, money services businesses, nonprofits, professional service providers holding client funds, marijuana-related businesses where applicable, privately held entities with complex ownership, non-resident aliens, and politically exposed persons.
Geographies. Where your customers are, where your branches are, and where funds move. Include wire corridors by country and volume, and any exposure to jurisdictions subject to sanctions or identified as higher risk.
Delivery channels. Branch, online, mobile, ATM, third party, and the proportion of accounts opened without face-to-face contact.
The inventory step is unglamorous and it is where the value is. Most institutions discover at least one thing they were not tracking — commonly a customer segment that grew quietly, or wire volume to a corridor nobody had flagged.
Inherent risk is the risk before considering controls. Assess each item in the inventory on a consistent scale — low, moderate, high is standard and sufficient.
The factors that drive an inherent rating up:
Rate honestly. The temptation to rate low because controls are good is the single most common methodological error — that is residual risk, and it comes later. An institution with substantial international wire activity has high inherent risk in that category no matter how good its screening is, and stating otherwise makes the assessment internally inconsistent.
For each inherent risk, document the controls that mitigate it — specifically, not generically. "Transaction monitoring" is not a control description. "Rule 14 flags structuring patterns across branches at a $9,000 threshold over a rolling 5-day window, reviewed daily by the BSA analyst" is.
For each control, record whether it is preventive or detective, who performs it, how often, and how its effectiveness is evidenced. Controls that have been tested by independent testing should reference the result.
Be honest about weak controls. An assessment that rates every control as effective, in an institution that had findings last cycle, is not credible.
Residual risk is what remains after controls. The arithmetic is not important; the reasoning is. Where residual risk remains higher than the institution's stated tolerance, the assessment should say what is being done about it — a control enhancement, a limit, a monitoring change, or an accepted risk with board visibility.
An assessment where every residual risk lands at "low" is a document nobody will believe. Real institutions carry residual risk; the question is whether they know where.
This is the step that separates a useful assessment from a filed one. Produce an explicit mapping showing, for each identified risk:
Gaps in that table are the program's actual to-do list. In most institutions, building the mapping for the first time surfaces two or three risks that are identified in the assessment and addressed nowhere in the controls — which is exactly the finding an examiner would have written.
Approval. The board or a designated committee should approve the assessment, and the approval should be minuted. Board members should be able to describe the institution's top risks — examiners ask.
Refresh cadence. At least annually, plus event-driven updates for new products, new markets, mergers or acquisitions, significant change in customer mix, or major regulatory developments.
Version control. Keep prior versions. The trajectory of the assessment over time is itself evidence that the program is being managed, and examiners often ask what changed since last year and why.
Named owner. One person accountable for the document, with a defined process for gathering input from lines of business.
From the FFIEC BSA/AML Examination Manual and consistent examination practice:
The most damaging finding is not a risk rated too low. It is an assessment that does not reconcile to the program, because that finding implies the program is not risk-based at all.
The vendor template never localized. Recognizable because it discusses risks the institution does not have and omits ones it does.
The assessment that never changes. Three consecutive years of identical ratings while the institution grew, entered new markets, or launched products.
Ratings without support. Categories rated moderate with no data and no reasoning recorded.
No linkage to controls. The assessment exists, the controls exist, and nothing connects them.
Written by one person in isolation. Compliance writing about business lines it does not operate, without input from the people who do.
For a community institution doing this properly for the first time, expect six to eight weeks: two weeks gathering data, two weeks drafting with business line input, one to two weeks reviewing controls and building the mapping, and a cycle for management and board review. Subsequent annual refreshes take a fraction of that, because the structure and the data pulls already exist.
Institutions that want the underlying framework taught rather than reverse-engineered should look at the Certificate in BSA and AML Compliance, which covers risk assessment alongside the program elements it drives, or the broader BSA training catalog.
Two institutions can reach the same risk ratings and receive very different examination outcomes, because the ratings are not what gets tested — the reasoning behind them is. A methodology section is what makes an assessment reviewable, and it is the part most templates omit.
At minimum, the methodology should state five things.
The rating scale and what each level means. "High" needs a definition. Without one, ratings are not comparable across categories and cannot be applied consistently by different people in different years.
The data sources used and the as-of date. Which reports were pulled, from which systems, covering which period. This lets a reviewer — or your successor — reproduce the analysis, and it prevents the quiet drift where each year's assessment is edited from the last without anyone re-pulling the numbers.
How inherent risk was derived. Which factors were considered and how they were weighted, whether formally or through documented judgment. Both approaches are acceptable; an undocumented one is not.
How control effectiveness was evaluated. Whether the assessment relied on independent testing results, on management self-assessment, on examination findings, or on some combination — and what happens to a rating when a control has not been tested.
How residual risk was calculated or reasoned. If a matrix is used, include it. If judgment is used, say so and record who applied it.
Alongside the methodology, keep a short change log: what moved since the prior version and why. When an examiner asks why cash-intensive business risk went from high to moderate, the answer should be a documented control enhancement with a date, not a recollection.
One further discipline is worth building in from the start. Have someone outside compliance read the assessment before it goes to the board — ideally a business line leader whose area it describes. If they do not recognize their own operation in it, the assessment is describing an institution that does not exist, and every control built on it inherits that error.
A final point on audience. The risk assessment has three readers with different needs: the board, which needs to understand the institution's top exposures in plain language; the compliance team, which needs the detail to design controls; and the examiner, who needs to see the reasoning. Trying to serve all three in one undifferentiated document usually serves none. The workable structure is a short executive summary stating the top risks and what is being done about them, followed by the detailed analysis and the control mapping as supporting sections.
It is not listed as a pillar in the program regulation, but a program must be reasonably designed for the institution's risk profile, and that cannot be demonstrated without a documented assessment. Examination procedures treat it as expected, and in practice a missing or inadequate assessment supports a program-level finding.
At least annually, and whenever the risk profile changes materially — new products or services, new markets or geographies, mergers and acquisitions, significant changes in customer composition, or major regulatory change. Document the date and the reason for each update.
Inherent risk is the risk present before considering controls — a function of the product, customer, geography, or channel itself. Residual risk is what remains after mitigating controls are applied. Rating inherent risk low because controls are strong is the most common methodological error and makes the assessment internally inconsistent.
Compliance should own and assemble it, but the content requires input from the business lines that operate the products and serve the customers. An assessment written entirely within compliance typically misunderstands how products are actually used, and that gap shows up as monitoring calibrated to a process nobody follows.
Long enough to cover products, services, customers, geographies, and channels with data and reasoning, and no longer. A twelve-page assessment that reconciles to the controls is far stronger than an eighty-page document that does not. Examiners assess coherence, not volume.
Producing an assessment that does not connect to anything. If the monitoring rules, EDD categories, training content, and testing scope cannot be traced back to risks the assessment identified, then the program is not risk-based, whatever the document says — and that is the finding examiners write.


