From the FinCrime Agent course
Want to do this for a living?
This is the kind of story financial-crime professionals act on every day. Learn the craft in Marco’s AML & Financial Crime course.
AMLA consultation closes on the risk assessment every control descends from
The window to shape AMLA's business-wide risk assessment guidelines shut on 15 July, so the window to test your own assessment against the draft is now open.
What happened
AMLA (the EU Anti-Money Laundering Authority) closed its public consultation on draft Guidelines on business-wide risk assessment at 23:59 CEST on 15 July 2026. The consultation opened on 16 April 2026 and the page now reads “Closed”. AMLA states only that results will follow.
The draft guidelines sit under Article 10(4) of Regulation (EU) 2024/1624, the EU AML Regulation (AMLR). AMLA describes the business-wide risk assessment (BWRA) as a central element of the risk-based approach from an obliged entity’s perspective, enabling firms to understand the risks arising from their business model, customers, products, services and transactions, delivery channels, and geographical exposure.
According to the consultation page, the draft proposes four minimum requirements that can be applied across all types of obliged entity when conducting a BWRA. AMLA does not enumerate them on the landing page. The draft also provides a list of additional information sources to be taken into account alongside those already listed in Article 10(1) of the AMLR. A public hearing on the draft was planned for 28 May 2026, 10.00 to 12.00 CET.
Why it matters
Read as analysis rather than as AMLA’s position: the most consequential line in the consultation is not the count of requirements. It is the framing. AMLA stresses the obliged entity’s responsibility to take ownership of its BWRA and ensure it is proportionate to that firm’s individual specificities, risks, and complexity.
That wording lands directly on a familiar problem. The BWRA is the document every other control is supposed to descend from, and it is often the least owned artefact in the file: bought as a vendor template, written once, refreshed annually by a junior analyst, and signed off without anyone testing whether its conclusions changed a single threshold or customer risk rating.
A minimum-requirements standard applied across all obliged entity types raises the floor. It also gives a supervisor a clean, comparable checklist to hold a firm’s assessment against. Firms that cannot show ownership will find that harder to argue after the guidelines land than before.
Practitioner angle
Pull the consultation paper now and read it side by side with your current BWRA. Do not wait for the final text. The four minimum requirements are the structure your assessment will be measured against, and mapping gaps against a draft costs far less than remediating them under a supervisory request.
Test the traceability, not the prose. Take three conclusions from your existing assessment and follow each one downstream: which customer risk rating, which monitoring scenario, which threshold, which enhanced due diligence trigger actually changed because of it? If the trail dies in the document, that is the finding.
Then check your information sources against Article 10(1) of the AMLR and note which of the draft’s additional sources you do not currently ingest.
The single most important action: establish, in writing and before the final guidelines arrive, who in your firm owns the BWRA and what evidence proves that assessment drives your controls.
Want to do this for a living?
Turn this weekly intelligence into a career. Marco’s AML & Financial Crime course takes you from curious to hireable.
AML & Financial Crime course →