Why risk-based, not rule-based
The FATF standards and BNM's policy document both require reporting institutions to identify, assess and understand their money laundering, terrorist financing and proliferation financing risks — and then apply resources and controls in proportion to those risks. Treating every customer the same wastes effort on low-risk relationships and under-controls the high-risk ones.
The output of this exercise is the institutional risk assessment (IRA): a documented, board-approved analysis that becomes the reference point for CDD depth, monitoring intensity, and escalation thresholds.
The four risk dimensions
Customer risk
Customer type, ownership complexity, PEP status, adverse media, and industries prone to cash or illicit flows.
Geographic risk
Exposure to higher-risk jurisdictions, sanctioned countries, and locations with weak AML/CFT regimes or high predicate-crime prevalence.
Product & service risk
Products that favour anonymity, rapid movement of funds, or cross-border transfers carry higher inherent risk.
Delivery-channel risk
Non-face-to-face and digital onboarding, intermediaries, and agents change the risk profile of how the relationship is established.
Anchoring to the National Risk Assessment
An institution's IRA does not exist in isolation. Malaysia's National Risk Assessment (NRA), coordinated by the National Coordination Committee to Counter Money Laundering, sets out the country-level threats. The NRA 2023 identified fraud, corruption, illicit drug trafficking, organised crime, and smuggling among the highest-risk predicate crimes.
From inherent risk to residual risk
- 1Score inherent riskRate each dimension before controls — the risk that exists by virtue of your customers, geographies, products and channels.
- 2Assess control effectivenessEvaluate how well your CDD, monitoring, screening and governance mitigate each inherent risk.
- 3Derive residual riskInherent risk net of control effectiveness is your residual risk — the risk you actually carry and must manage.
- 4Act on the gapsWhere residual risk exceeds appetite, strengthen controls or exit the exposure. Feed the results into policies, CDD tiers and monitoring rules.
Keeping it alive
An IRA is not a one-off document. It must be reviewed periodically and whenever there is a material change — a new product line, entry into a new market, a significant regulatory update, or new typologies emerging from your STR patterns. A stale IRA silently mis-calibrates every downstream control.
Frequently asked questions
In conclusion
The risk-based approach only works if the institutional risk assessment is real, current, and actually drives control decisions. Done well, it is the single document that ties your whole AML/CFT framework together.
Get your risk assessment reviewed
We help reporting institutions build and independently validate their institutional risk assessments.