The Risk-Based Approach in AML: Framework, Calibration, and Implementation
Try This First
Test your knowledge before reading. Don't worry if you get it wrong — that's part of learning.
Key Insights
- The risk-based approach (RBA) is the cornerstone of modern AML compliance, requiring institutions to identify, assess, and mitigate money laundering risks proportionally.
- This module covers the FATF risk-based approach framework, risk assessment methodologies (inherent risk, control effectiveness, residual risk), customer risk scoring models, the calibration of CDD/EDD measures to risk levels, and 2025-2026 trends including automated risk scoring with machine learning, regulatory expectations for dynamic risk assessment, and the integration of RBA with broader enterprise risk management frameworks.
Overview
Implementing a risk-based approach (RBA) requires translating high-level regulatory expectations into practical, operational processes. This involves developing risk assessment methodologies, building risk scoring models, establishing risk appetite statements, and creating governance frameworks that ensure consistent application across the organization.
A practical RBA implementation begins with a comprehensive business-wide risk assessment that identifies inherent risks across customer types, products, geographies, and delivery channels. This assessment informs the design of tiered due diligence measures, monitoring frequency, and threshold settings. Regular validation ensures the RBA remains effective as risks evolve.
Key Concepts
- Business-Wide Risk Assessment: An organization-level evaluation of all ML/TF risks across customers, products, geographies, and channels.
- Risk Scoring Model: A quantitative model that assigns risk scores based on weighted risk factors, determining due diligence levels.
- Tiered Due Diligence: Applying different levels of customer scrutiny — simplified, standard, enhanced — based on risk scores.
- Risk Appetite Statement: A formal document defining the level of ML/TF risk the organization is willing to accept.
- Model Validation: Independent testing of risk models to ensure they are accurate, calibrated, and performing as intended.
Key Takeaways
- RBA implementation requires systematic risk assessment, scoring, and tiered control application.
- Business-wide risk assessment is the foundation for all subsequent RBA processes.
- Risk scoring models must be validated regularly to maintain effectiveness.
- Tiered due diligence ensures compliance resources are focused on highest-risk relationships.
Article Metadata
Review with Spaced Repetition
Add this lesson's 4 flashcards to your SM-2 study queue. They will appear when due in the Study Queue.
Feynman Concept Cards
Master each building block: read the ELI5, explore the analogy, work the example, find your gaps, teach it back, build it.
Risk-Based Approach in AML is a concept in foundations. In simple terms, Risk-Based Approach in AML covers foundational knowledge in Compliance. This compliance concept addresses key topics in the foundational knowledge in compliance domain. Also known as: RBA, risk-based
Analogy
Example
Find Gaps
Explain Risk-Based Approach in AML as if teaching a colleague who is new to foundations. Cover: what it is, how it works, and why it matters.
Create
Create a diagram that demonstrates Risk-Based Approach in AML in a real-world foundations scenario. Walk through your design decisions.
Show solution
A diagram for Risk-Based Approach in AML should include: 1. The core components of risk based approach 2. How they interact 3. Expected outcomes or outputs
Customer Due Diligence is a concept in cdd kyc. In simple terms, Customer Due Diligence covers customer due diligence within Compliance. This compliance concept addresses key topics in the customer due diligence within compliance domain. Also known as: CDD. Related
Analogy
Example
Find Gaps
Explain Customer Due Diligence as if teaching a colleague who is new to cdd kyc. Cover: what it is, how it works, and why it matters.
Create
Create a checklist that demonstrates Customer Due Diligence in a real-world cdd kyc scenario. Walk through your design decisions.
Show solution
A checklist for Customer Due Diligence should include: 1. The core components of cdd 2. How they interact 3. Expected outcomes or outputs
Enhanced Due Diligence is a concept in cdd kyc. In simple terms, Enhanced Due Diligence covers customer due diligence within Compliance. This compliance concept addresses key topics in the customer due diligence within compliance domain. Also known as: EDD. Related
Analogy
Example
Find Gaps
Explain Enhanced Due Diligence as if teaching a colleague who is new to cdd kyc. Cover: what it is, how it works, and why it matters.
Create
Create a checklist that demonstrates Enhanced Due Diligence in a real-world cdd kyc scenario. Walk through your design decisions.
Show solution
A checklist for Enhanced Due Diligence should include: 1. The core components of edd 2. How they interact 3. Expected outcomes or outputs
AML Risk Scoring Models is a concept in risk assessment. In simple terms, AML Risk Scoring Models covers risk assessment for Compliance. This compliance concept addresses key topics in the risk assessment for compliance domain. Also known as: risk scoring, AML risk assessme
Analogy
Example
Find Gaps
Explain AML Risk Scoring Models as if teaching a colleague who is new to risk assessment. Cover: what it is, how it works, and why it matters.
Create
Create a matrix that demonstrates AML Risk Scoring Models in a real-world risk assessment scenario. Walk through your design decisions.
Show solution
A matrix for AML Risk Scoring Models should include: 1. The core components of aml risk scoring 2. How they interact 3. Expected outcomes or outputs
Feynman Synthesis — Prove You Understand
1. The One-Pager
Explain this lesson's core idea to a smart 15-year-old. No jargon allowed.
2. The Gap Map
List 3 things you are still unsure about. Be specific.
Knowledge Check
Test your understanding of this lesson.
Flashcards
Space = flip · 1-4 = grade · Swipe on mobile