Aml Risk Assessment Framework
Template
AML risk assessment framework
A practical framework for UK regulated firms (accountants, solicitors, estate agents, TCSPs) to document their firm-wide and client-level AML risk assessment.
Who it’s for: MLROs and partners in UK regulated firms with AML obligations
How to use
Follow these steps
List your risk categories
Client type (individual / company / trust / overseas), geography (UK / EEA / high-risk jurisdiction), service provided (incorporation / accounts / TCSP), and delivery channel (face-to-face / remote).
Score each category
Use a 3-point scale (low / medium / high) to score the inherent risk in each category. Document the rationale in 1-2 sentences per category — that''s what your supervisor wants to see.
Apply controls
For each high-risk category, document the controls you apply (enhanced due diligence, MLRO review, source of funds checks). For low-risk, simplified due diligence may be appropriate.
Document the residual risk
Inherent risk minus controls = residual risk. The residual risk drives ongoing monitoring frequency.
Review at least annually
Risk assessment is not a once-and-done exercise — review at least annually, and trigger an out-of-cycle review when something material changes (regulatory update, sanctions list change, supervisor visit feedback).
Rajoka Insights
Operating notes from a UK house of brands.
A weekly note from Mehmood. House-of-brands strategy, UK operating, and what's working across the portfolio. No fluff.
Delivered via Substack. Unsubscribe anytime.
Explore Rajoka
A family of firms. One operating standard.
Pick a brand, pick a stage, or tell us your problem.