Firm-Wide Risk Assessment: what it must include
Regulation 18 of the Money Laundering Regulations 2017 requires every regulated business to hold a written Firm-Wide Risk Assessment (FWRA) — the document that identifies where your business is exposed to money-laundering and terrorist-financing risk. It is also one of the first things an HMRC inspector will ask to see, and one of the most common weak points found at inspection.
This guide sets out the four categories the FWRA must cover, the mistake that gets businesses penalised, and how it connects to the rest of your AML programme.
1. What the FWRA actually is
The FWRA is a written, business-specific risk assessment — not a policy statement and not a certificate. It should read as an honest evaluation of where your business, specifically, is exposed to money laundering and terrorist financing, with enough detail that a reader unfamiliar with the business could understand the risk picture. It must be approved by senior management and produced to HMRC or your supervisor on request.
2. The four risk categories
| Category | What it covers |
|---|---|
| Customer risk | Types of client you act for — individuals, companies, trusts, overseas buyers, cash buyers, politically exposed persons |
| Product / service risk | The services you actually offer and how exposed each one is — e.g. high-value property sales versus straightforward lettings |
| Delivery channel risk | How the service is delivered — face to face with the client present, versus remote or online instructions where identity is harder to verify |
| Geographic risk | Countries connected to a transaction or client — overseas buyers, funds from or via higher-risk jurisdictions |
A thorough FWRA scores or rates each category, explains why the business sits where it does, and sets out what that means for how due diligence is applied day to day.
3. The mistake regulators penalise most
Signs a FWRA is generic rather than genuine: it never mentions the business by name in the body text, it lists risks the business does not actually face (e.g. cash handling for an agency that never touches client money), or it is identical, word for word, to a template freely available online.
4. How the FWRA drives the rest of your programme
The FWRA is not a standalone document — it is meant to shape everything downstream:
- Customer due diligence: higher-risk customer types identified in the FWRA should trigger enhanced due diligence, not the standard checks.
- Policies and procedures: your written AML policy should reference the risks the FWRA identifies, not exist in isolation from it.
- Staff training: training should focus on the red flags the FWRA says are most relevant to your business.
An inspector who finds an FWRA that does not match the rest of the file — for example, a firm that rates overseas-buyer risk as low but has no record of ever checking where funds came from — treats that mismatch as a sign the assessment was never really used.
5. Keeping it current
The FWRA must be reviewed and updated whenever the business changes in a way that affects its risk profile — new services, new markets, a shift toward more overseas buyers — and periodically even without a specific trigger. A dated document that has never been revisited since the business changed is treated much like having no FWRA at all.
Would your Firm-Wide Risk Assessment survive that kind of scrutiny?
Run the free vrisk AML readiness check: answer a few questions about your business and get a firm-specific risk assessment and the supporting documents HMRC expects, ready for professional review.
Run my free AML check →6. FAQ
What is a Firm-Wide Risk Assessment?
A written, regulation-18 assessment of the money-laundering and terrorist-financing risk your specific business faces.
What four categories must it cover?
Customer risk, product/service risk, delivery channel risk, and geographic risk.
Can I use a generic template?
No — a copied, non-specific document is one of the most common findings regulators penalise.
Who approves it?
Senior management, and it must be produced to HMRC or your supervisor on request.
How does it connect to CDD?
The risks it identifies should directly shape when enhanced due diligence is applied, rather than sitting apart from day-to-day checks.