The Institutional Risk Assessment: Malaysia's Risk-Based Approach — CWC & ENG PLT
Articles & Resources
AMLA 7 min read·23 July 2026

The Institutional Risk Assessment: Malaysia's Risk-Based Approach

The risk-based approach is the foundation of AML/CFT. Here is how to build an institutional risk assessment that drives your controls — and connects to Malaysia's National Risk Assessment.

01

Why risk-based, not rule-based

The FATF standards and BNM's policy document both require reporting institutions to identify, assess and understand their money laundering, terrorist financing and proliferation financing risks — and then apply resources and controls in proportion to those risks. Treating every customer the same wastes effort on low-risk relationships and under-controls the high-risk ones.

The output of this exercise is the institutional risk assessment (IRA): a documented, board-approved analysis that becomes the reference point for CDD depth, monitoring intensity, and escalation thresholds.

02

The four risk dimensions

1

Customer risk

Customer type, ownership complexity, PEP status, adverse media, and industries prone to cash or illicit flows.

2

Geographic risk

Exposure to higher-risk jurisdictions, sanctioned countries, and locations with weak AML/CFT regimes or high predicate-crime prevalence.

3

Product & service risk

Products that favour anonymity, rapid movement of funds, or cross-border transfers carry higher inherent risk.

4

Delivery-channel risk

Non-face-to-face and digital onboarding, intermediaries, and agents change the risk profile of how the relationship is established.

03

Anchoring to the National Risk Assessment

An institution's IRA does not exist in isolation. Malaysia's National Risk Assessment (NRA), coordinated by the National Coordination Committee to Counter Money Laundering, sets out the country-level threats. The NRA 2023 identified fraud, corruption, illicit drug trafficking, organised crime, and smuggling among the highest-risk predicate crimes.

Use the NRA as an inputSupervisors expect your IRA to reflect the NRA findings and any sectoral risk assessments relevant to your licence — not to assess risk in a vacuum.
04

From inherent risk to residual risk

  1. 1
    Score inherent risk
    Rate each dimension before controls — the risk that exists by virtue of your customers, geographies, products and channels.
  2. 2
    Assess control effectiveness
    Evaluate how well your CDD, monitoring, screening and governance mitigate each inherent risk.
  3. 3
    Derive residual risk
    Inherent risk net of control effectiveness is your residual risk — the risk you actually carry and must manage.
  4. 4
    Act on the gaps
    Where residual risk exceeds appetite, strengthen controls or exit the exposure. Feed the results into policies, CDD tiers and monitoring rules.
05

Keeping it alive

An IRA is not a one-off document. It must be reviewed periodically and whenever there is a material change — a new product line, entry into a new market, a significant regulatory update, or new typologies emerging from your STR patterns. A stale IRA silently mis-calibrates every downstream control.

Never updating the assessment
An IRA that is years out of date no longer reflects the business it is meant to protect.
Assessing inherent risk but ignoring controls
Without a residual-risk view, resources are misallocated.
No board approval
The IRA must be endorsed at the top; unapproved, it carries no governance weight.
FAQ

Frequently asked questions

A documented, board-approved analysis of a reporting institution's money laundering, terrorist financing and proliferation financing risks across customer, geographic, product/service and delivery-channel dimensions — used to calibrate its controls.
The NRA sets Malaysia's country-level risk picture; institutions must reflect its findings and any relevant sectoral assessments in their own IRA rather than assessing risk in isolation.
Inherent risk is the risk before controls; residual risk is what remains after control effectiveness is applied. Controls should target areas where residual risk exceeds the institution's risk appetite.
Periodically, and whenever there is a material change — new products, new markets, regulatory changes, or new typologies from monitoring and STR data.

In conclusion

The risk-based approach only works if the institutional risk assessment is real, current, and actually drives control decisions. Done well, it is the single document that ties your whole AML/CFT framework together.

AMLA · AML/CFT Advisory

Get your risk assessment reviewed

We help reporting institutions build and independently validate their institutional risk assessments.

Request a consultation