Firm-Wide Risk Assessment: what it must include

Updated August 2026 · 7-minute read · General information, not legal advice

Regulation 18 of the Money Laundering Regulations 2017 requires every regulated business to hold a written Firm-Wide Risk Assessment (FWRA) — the document that identifies where your business is exposed to money-laundering and terrorist-financing risk. It is also one of the first things an HMRC inspector will ask to see, and one of the most common weak points found at inspection.

This guide sets out the four categories the FWRA must cover, the mistake that gets businesses penalised, and how it connects to the rest of your AML programme.

In this guide 1. What the FWRA actually is 2. The four risk categories 3. The mistake regulators penalise most 4. How the FWRA drives the rest of your programme 5. Keeping it current 6. FAQ

1. What the FWRA actually is

The FWRA is a written, business-specific risk assessment — not a policy statement and not a certificate. It should read as an honest evaluation of where your business, specifically, is exposed to money laundering and terrorist financing, with enough detail that a reader unfamiliar with the business could understand the risk picture. It must be approved by senior management and produced to HMRC or your supervisor on request.

2. The four risk categories

CategoryWhat it covers
Customer riskTypes of client you act for — individuals, companies, trusts, overseas buyers, cash buyers, politically exposed persons
Product / service riskThe services you actually offer and how exposed each one is — e.g. high-value property sales versus straightforward lettings
Delivery channel riskHow the service is delivered — face to face with the client present, versus remote or online instructions where identity is harder to verify
Geographic riskCountries connected to a transaction or client — overseas buyers, funds from or via higher-risk jurisdictions

A thorough FWRA scores or rates each category, explains why the business sits where it does, and sets out what that means for how due diligence is applied day to day.

3. The mistake regulators penalise most

A copied or generic risk assessment is the single most common finding in enforcement action. A document that could describe almost any estate agency — with no mention of your actual client base, your services, or the geographies you deal with — does not satisfy regulation 18, even if the headings look right.

Signs a FWRA is generic rather than genuine: it never mentions the business by name in the body text, it lists risks the business does not actually face (e.g. cash handling for an agency that never touches client money), or it is identical, word for word, to a template freely available online.

The FWRA is not a standalone document — it is meant to shape everything downstream:

An inspector who finds an FWRA that does not match the rest of the file — for example, a firm that rates overseas-buyer risk as low but has no record of ever checking where funds came from — treats that mismatch as a sign the assessment was never really used.

5. Keeping it current

The FWRA must be reviewed and updated whenever the business changes in a way that affects its risk profile — new services, new markets, a shift toward more overseas buyers — and periodically even without a specific trigger. A dated document that has never been revisited since the business changed is treated much like having no FWRA at all.

Would your Firm-Wide Risk Assessment survive that kind of scrutiny?

Run the free vrisk AML readiness check: answer a few questions about your business and get a firm-specific risk assessment and the supporting documents HMRC expects, ready for professional review.

Run my free AML check →

6. FAQ

What is a Firm-Wide Risk Assessment?

A written, regulation-18 assessment of the money-laundering and terrorist-financing risk your specific business faces.

What four categories must it cover?

Customer risk, product/service risk, delivery channel risk, and geographic risk.

Can I use a generic template?

No — a copied, non-specific document is one of the most common findings regulators penalise.

Who approves it?

Senior management, and it must be produced to HMRC or your supervisor on request.

How does it connect to CDD?

The risks it identifies should directly shape when enhanced due diligence is applied, rather than sitting apart from day-to-day checks.

Disclaimer: this guide is general information about Firm-Wide Risk Assessments under the Money Laundering Regulations 2017 and is not legal or regulatory advice. For advice on your specific circumstances, consult a qualified UK solicitor or AML professional.