AML/CFT  ·  Enterprise-Wide Risk Assessment  ·  Enterprise-Wide Risk Assessment

AML/CFT Enterprise-Wide Risk Assessment (EWRA)

Enterprise-Wide AML/CFT risk assessment for CASPs, fintech, payment institutions and other regulated businesses — analysing inherent and residual risk across customers, geographies, products, services, transaction flows and delivery channels, with a documented methodology aligned to the applicable regulatory framework.

You receive a documented Enterprise-Wide Risk Assessment built on a structured analysis of your actual business model — not a checklist — with inherent and residual risk ratings, control gap assessment and remediation recommendations.

FATF
R.1 risk-based
approach
AMLR
Reg. (EU)
2024/1624
Czech
zákon č. 253/2008 Sb.
FAÚ / ČNB
MiCA
CASP licensing
requirement
The foundation of AML/CFT compliance

What Is an Enterprise-Wide Risk Assessment?

An enterprise-wide risk assessment is a structured analysis of the AML/CFT risks facing a business across all relevant dimensions — customers, geographies, products, services, transaction flows and delivery channels. It determines how compliance resources should be allocated and forms the basis of a risk-based AML/CFT programme.

It is not a generic risk matrix. An effective Enterprise-Wide Risk Assessment reflects the actual operational profile of the business — how it onboards customers, what products it offers, where transactions flow, and what exposure it has to financial crime risk.

Regulators, banking partners and licensing authorities increasingly treat the Enterprise-Wide Risk Assessment as a primary indicator of AML/CFT programme maturity. A weak or template-based Enterprise-Wide Risk Assessment — one that does not reflect the real risk profile of the business — is one of the most common findings in AML/CFT reviews and supervisory examinations.

Why it matters
"A generic Enterprise-Wide Risk Assessment that does not reflect the actual business model is typically identified immediately — by regulators, banking compliance teams and external auditors. It raises more questions than it answers."
The quality of an Enterprise-Wide Risk Assessment directly affects how regulators, banks and licensing authorities evaluate the maturity and credibility of your AML/CFT programme.

Businesses that present a credible, operationally grounded Enterprise-Wide Risk Assessment demonstrate that their compliance programme is built on a genuine understanding of their risk — not on generic templates.
Under Czech zákon č. 253/2008 Sb., EU AMLD and FATF Recommendation 1, obliged entities are required to document their assessment of financial crime risk exposure. The new AMLR (Reg. (EU) 2024/1624) codifies this as a directly applicable obligation from July 2027.
When businesses request an Enterprise-Wide Risk Assessment

Who Needs an Enterprise-Wide Risk Assessment?

An Enterprise-Wide Risk Assessment is relevant for any regulated or higher-risk business — both as a proactive compliance measure and in response to specific regulatory or business events.

Building or reviewing an AML/CFT programme
Businesses building a new AML/CFT programme or conducting a review require an Enterprise-Wide Risk Assessment as the foundational document — it drives all downstream control design.
Licensing application
MiCA CASP authorisation, PSP/EMI licensing, VASP registration and other regulated authorisation processes require a documented Enterprise-Wide Risk Assessment as part of the AML/CFT programme file.
Banking or EMI onboarding
Banking and EMI partners frequently request the Enterprise-Wide Risk Assessment as part of their AML due diligence on new clients. A credible, operationally grounded Enterprise-Wide Risk Assessment materially supports the onboarding process.
Regulatory review or inspection
Where a supervisory examination or thematic review is anticipated, an up-to-date Enterprise-Wide Risk Assessment that accurately reflects current operations is essential to demonstrate AML/CFT programme maturity.
Material business model change
New products, new markets, new customer segments or corporate restructuring materially change the risk profile. An existing Enterprise-Wide Risk Assessment that does not reflect these changes no longer meets regulatory expectations.
Post-audit finding or annual review
Following AML audit findings or as part of an annual independent review, an updated Enterprise-Wide Risk Assessment demonstrates that identified gaps have been addressed and the risk framework remains current.
Scope of assessment

What an Enterprise-Wide Risk Assessment Covers.

A comprehensive Enterprise-Wide Risk Assessment analyses risk across all dimensions of the business — not only policies, but the operational reality of how the business functions.

01
Customer Risk
Analysis of the customer base — types of customers, onboarding channels, geographic exposure, PEP and higher-risk customer categories, and overall customer risk profile. Assessment of whether customer risk scoring appropriately reflects actual customer risk.
02
Geographic Risk
Assessment of country and jurisdiction risk — target markets, transaction corridors, customer residence, and exposure to higher-risk or sanctioned jurisdictions. Calibration against FATF grey/black lists and applicable sanctions regimes.
03
Product & Service Risk
Review of the risk profile of each product and service offered — including transaction types, value thresholds, anonymity features, speed of execution and financial crime vulnerability specific to each offering.
04
Transaction & Channel Risk
Analysis of transaction flows, payment channels, delivery mechanisms and operational risk — including cross-border flows, virtual asset exposure, third-party payment relationships and cash or high-value transaction exposure.
05
Operational & Governance Risk
Assessment of internal governance, outsourcing arrangements, third-party reliance, staff competency and the effectiveness of the overall control environment — including MLRO oversight and management reporting.
06
Sanctions & PEP Risk
Specific analysis of sanctions exposure, PEP customer risk and the adequacy of screening and monitoring controls relative to the business risk profile and applicable EU and international sanctions regimes.
Deliverables

What the Enterprise-Wide Risk Assessment Produces.

LEX ARTA delivers a structured, documented Enterprise-Wide Risk Assessment built on analysis of the actual business model and designed for use in regulatory, licensing, banking, governance and investor due-diligence contexts. Acceptance or evaluation remains with the relevant authority or institution.

The Enterprise-Wide Risk Assessment is not a standalone document. Where required, LEX ARTA integrates findings with your existing AML/CFT policies and procedures, and provides ongoing support to implement remediation recommendations.

Documented Enterprise-Wide Risk Assessment aligned with FATF risk-based approach methodology
Customer, geographic, product, channel and operational risk analysis
Inherent and residual risk analysis with risk ratings
Risk scoring framework calibrated to business model
Control environment assessment for residual-risk analysis
Identified risk gaps and control deficiencies
Remediation recommendations prioritised by risk
Management summary for regulatory, banking or investor use
Who we work with

Businesses We Support.

LEX ARTA delivers Enterprise-Wide Risk Assessments for regulated and higher-risk businesses at different stages of the compliance lifecycle — including initial programme design, periodic review and post-audit updates.

CASPs & VASPs
CASPs, VASPs and crypto exchanges — Enterprise-Wide Risk Assessment for licensing, operational compliance and periodic review where applicable.
Payment Institutions & EMIs
PSPs and EMIs requiring a documented Enterprise-Wide Risk Assessment for regulatory compliance, banking onboarding and supervisory readiness.
FinTech Companies
Fintech businesses building AML/CFT programmes — Enterprise-Wide Risk Assessment as the foundational document for proportionate control design.
Investment Firms & Brokers
Investment businesses, forex brokers and financial intermediaries requiring a risk-based Enterprise-Wide Risk Assessment aligned with MiFID II and AMLD requirements.
iGaming & Online Gaming
Gaming operators with AML/CFT obligations requiring sector-specific risk assessment covering player risk, payment channel risk and geographic exposure.
Other Regulated Businesses
Any business subject to AML/CFT obligations as a povinná osoba under Czech law or as an obliged entity under EU AMLD — requiring a documented, current Enterprise-Wide Risk Assessment.
Regulatory framework

Enterprise-Wide Risk Assessment Requirements in the Czech Republic and EU.

Czech Republic
zákon č. 253/2008 Sb.
Czech AML legislation requires obliged entities (povinné osoby) to identify, assess and understand their exposure to money laundering and terrorist financing risks — and to document this assessment. The Enterprise-Wide Risk Assessment should reflect the entity’s current activities, risk exposure and the requirements applicable under Czech law and the relevant supervisory framework.
Supervised by FAÚ and ČNB
European Union
AMLR & AMLD
Regulation (EU) 2024/1624, applicable from 10 July 2027 for most obliged entities, contains directly applicable business-wide risk-assessment requirements. AMLA contributes to the common EU supervisory framework and will begin direct supervision of selected high-risk cross-border financial-sector obliged entities in 2028.
AMLD6 · AMLR 2024/1624 · AMLA · MiCA
International Standards
FATF Recommendations
FATF Recommendation 1 (Risk-Based Approach) requires financial institutions and VASPs to identify, assess and understand their ML/TF risks — and to document this assessment. FATF Recommendation 15 sets out equivalent requirements for virtual asset service providers. LEX ARTA aligns Enterprise-Wide Risk Assessment methodology to both EU requirements and applicable FATF standards.
FATF R.1 · FATF R.15 · FATF Guidance on Virtual Assets
Why LEX ARTA

Risk Assessments Grounded in Operational Reality.

Generic risk-assessment templates can fail to reflect the actual risk profile of a business. The service is built around structured analysis of the client’s business model, customer base, transaction flows, control environment and relevant risk factors.

FATF-aligned methodology
Enterprise-Wide Risk Assessment methodology aligned with the risk-based approach — covering inherent risk, the control environment and residual risk across the relevant dimensions.
Regulated-sector expertise
Experience across crypto-asset and fintech compliance engagements informs analysis of digital-asset risk factors, including wallet, transaction-flow, counterparty and blockchain-related exposures where relevant.
Operational AML experience
Experience gained through AML and compliance functions within regulated businesses informs how business-wide risk assessments connect to governance, controls, management reporting and operational decision-making.
Cross-border & multi-jurisdiction
Cross-border and multi-jurisdiction risk understanding — relevant for businesses operating across EU member states and international markets, supported by our partner network.
ACAMS Certified
Certified Anti-Money Laundering Specialist — global standard in AML/CFT compliance and risk assessment
CySEC AML Certified
AML certification for EU investment services — Cyprus Securities & Exchange Commission
MLRO & Compliance Officer Experience
Experience gained through MLRO and Compliance Officer functions within regulated businesses across financial services and digital assets
Financial Crime Background
Experience in economic crime and financial crime — informing risk typology analysis within the Enterprise-Wide Risk Assessment
Common questions

Enterprise-Wide Risk Assessment — Frequently Asked Questions.

What is an enterprise-wide risk assessment?
+
An enterprise-wide risk assessment is a structured analysis of the AML/CFT risks facing a business across all relevant dimensions — customers, geographies, products, services, transaction flows and delivery channels. It is the foundation of a risk-based AML/CFT programme and determines how compliance resources should be allocated. Regulators, banking partners and licensing authorities treat the Enterprise-Wide Risk Assessment as a primary indicator of AML/CFT programme maturity.
Is an Enterprise-Wide Risk Assessment a regulatory requirement?
+
Yes. Under Czech zákon č. 253/2008 Sb., EU AMLD and FATF Recommendation 1, obliged entities are required to identify, assess and understand the money laundering and terrorist financing risks to which they are exposed — and to document that assessment. The new EU Anti-Money Laundering Regulation (AMLR, Reg. (EU) 2024/1624) further codifies enterprise-wide risk assessment requirements as directly applicable obligations across EU member states.
How often should an Enterprise-Wide Risk Assessment be updated?
+
There is no universal annual update rule applicable to every business. The Enterprise-Wide Risk Assessment should be kept current in accordance with the applicable legal and internal review framework and revisited when material changes occur, including changes to products, services, customer base, geographies, delivery channels, transaction flows or the regulatory environment.
What is the difference between an Enterprise-Wide Risk Assessment and a customer risk assessment?
+
An enterprise-wide risk assessment analyses risk at the business level — across all customer segments, products, geographies and channels. A customer risk assessment is conducted at the individual customer level as part of CDD and onboarding. The Enterprise-Wide Risk Assessment informs the standards and thresholds used in individual customer risk assessments — it sets the framework within which customer-level decisions are made.
Can an Enterprise-Wide Risk Assessment help with a licensing application?
+
Yes, where the relevant authorisation framework requires a documented business-wide AML/CFT risk assessment. For MiCA CASP authorisation, Commission Delegated Regulation (EU) 2025/305 expressly requires information on the applicant’s assessment of inherent and residual money-laundering and terrorist-financing risks. Requirements for payment institutions, electronic money institutions and other applicants depend on the applicable sectoral and national framework.
How long does an Enterprise-Wide Risk Assessment take to complete?
+
Timelines depend on the complexity of the business model, number of entities and jurisdictions, data availability, product and customer diversity and the depth of analysis required. The delivery timetable is agreed after initial scoping rather than applying a single standard duration to every engagement.
Pricing

Enterprise-Wide Risk Assessment Pricing.

Pricing is individually scoped because the work depends on the regulatory perimeter, number of entities and jurisdictions, products and services, customer and geographic exposure, transaction flows, data availability and the depth of control-environment analysis required.

Fixed-fee proposal
Defined after initial scoping
The agreed scope sets the methodology, data inputs, risk dimensions, deliverables, review depth and any jurisdiction-specific or crypto-specific workstreams.
AML/CFT Services

Explore AML/CFT Services.

01
AML Audit & Compliance Review →
02
Outsourced MLRO & AML Support →
03 · Current
AML/CFT Enterprise-Wide Risk Assessment
04
AML Regulatory Gap Analysis →
05
Travel Rule & TFR Compliance →
06
AML Training →
← Hub
AML/CFT Overview →
Related
AML Audit & Compliance Review →
Need an Enterprise-Wide Risk Assessment grounded in your actual business model?
For licensing, banking onboarding, periodic review or AML/CFT framework development, the assessment is scoped to the actual activities, customers, products, geographies, transaction flows and control environment.