An Enterprise-Wide Risk Assessment (EWRA) — also called the overall ML/TF risk assessment — is the business-wide exercise that maps how an obliged entity can be exposed to money laundering and terrorist financing. From an EU and Belgian perspective it is a core regulatory obligation for credit institutions, stockbroking firms, licensed insurers and other financial institutions subject to Anti-Money Laundering regulation. Under Article 17 of the Belgian Anti-Money Laundering Law of 20 July 2020, the assessment must be documented, kept up to date and available to the supervisor. Done properly, it tells the firm where to concentrate controls — and how individual customer risk scoring should reflect the same risk picture.
In a broader risk context, Enterprise Risk Assessment (ERA) or Enterprise Risk Management (ERM) programmes help entities adapt how they manage risk as financial standards evolve. The AML EWRA remains specific: it is the ML/TF lens of that enterprise view.
How to carry out an effective AML risk assessment?
Conducting an AML risk assessment is not a one-off desk exercise. It means defining a risk-rating methodology, building a model that fits your business model and data, assigning clear governance (AMLCO, senior management, board oversight) and refreshing the assessment whenever the risk profile changes. Financial institutions manage AML exposure through sound processes and risk-based vigilance; the benefits only appear when regulatory expectations and operational reality are worked through together.
What is EWRA Compliance and the Risk-Based Approach (RBA) ?
An appropriate risk-based approach starts with an up-to-date understanding of the institution's risk exposure. A Risk-based approach (RBA) is essential to Risk Management and to the AML/CFT framework. RBA was highlighted in the 2012 FATF Recommendations:
“...countries should apply a risk-based approach (RBA) to ensure that measures to prevent or mitigate money laundering and terrorist financing are commensurate with the risks identified.”
It was embedded in the fourth European AML Directive and remains the backbone of later EU AML rules. Under the EBA ML/TF Risk Factors Guidelines (EBA/GL/2021/02), firms are expected to take a holistic view: the business-wide assessment informs AML/CFT policies and controls, and those findings must stay consistent with individual business-relationship risk assessments.
In practice, RBA prioritises activity based on analysed risk. Fewer measures may suffice in genuinely low-risk situations; enhanced measures are mandatory where risk is higher. That is how scarce compliance resources are allocated.
AML EWRA Enterprise-Wide Risk Assessment Methodology
A successful EWRA methodology is consistent across domains and is commonly built through three main stages: risk identification, gap analysis (controls) and the adjustment phase (corrections and mitigation). Senior management and, where required, the board must be able to challenge the results; the AMLCO owns the process end to end.

Documentation and updating of an EWRA
The AML overall risk assessment must be documented, updated and kept at the disposal of the supervisory authorities (for many Belgian institutions, the National Bank of Belgium). It is not a once-a-year ritual: it should be refreshed whenever an event can materially change the entity's ML/TF risk profile, so management always understands how those risks are evolving — including in connection with business relationships.

Beyond the EWRA report itself, supervisors expect a methodology note describing how the assessment was completed, the applicable legal framework and sectoral guidance used, monitoring and update procedures, and the involvement of the AMLCO, compliance, senior management and any other parties.
In Belgium, institutions under NBB AML supervision also work with a summary table of the overall risk assessment and periodic questionnaires. Circular NBB_2018_02 set the methodological frame; Communication NBB_2020_002 then spelled out supervisor findings on summary tables and the need to follow the steps in methodological order. Periodic questionnaire expectations have since been refreshed (including Circular NBB_2024_05). Firms must be able to show, on the basis of those documents, that their approach meets the Anti-Money Laundering Law of 20 July 2020.
What are the risk factors to consider?
To conduct their EWRA, firms must consider specific risk factors and the principle of proportionality.
The risk factors that must be considered are customers, countries or geographic areas, products, services, and transactions or delivery channels. All must be assessed proportionately to the size and nature of the entity. Firms that do not offer complex products or services and that have limited or no international exposure may not need an overly complex assessment — but they still need a documented, defensible one.

These factors are the pillars of the analysis. Each can break down into many sub-risks — for example, customer risk may include onboarding the wrong counterparty or lacking enough additional measures for a founded decision. Entities should weight factors by relevance to their business and transactions, and assign transparent scores. Under the EBA ML/TF Risk Factors Guidelines (EBA/GL/2021/02, as amended — including guidance relevant where crypto-asset service providers or crypto exposure are in scope), profit considerations must not drive the risk rating, and firms should be ready to override automated scores where necessary, with proper documentation.
The rationale behind the EWRA obligation
A business-wide ML/TF risk assessment is a cornerstone of AML/CFT. It supports informed decisions, lets supervisors assess whether internal organisation, policies and procedures are adequate, and shows the firm where higher ML/TF risk concentrates. It also gives a sound basis for customer AML risk scoring while assessing individual cases.
The legal framework of an AML EWRA
The Belgian and EU reference set for an AML EWRA now goes beyond the 2018 circular alone. Core sources include:
Directive (EU) 2018/843 (5th AML Directive) — historical EU baseline still reflected in national law;
Belgian Anti-Money Laundering Law of 20 July 2020 (overall risk assessment, Art. 17);
NBB Regulation of 21 November 2017;
Circular NBB_2018_02 on the overall assessment of ML/TF risks;
Communication NBB_2020_002 on summary tables of the overall risk assessment;
NBB periodic AML/CFT questionnaires (see Circular NBB_2024_05 and related updates);
EBA ML/TF Risk Factors Guidelines EBA/GL/2021/02 (replacing the earlier JC 2017 37 package), as amended.
Looking ahead, the EU AML package (AMLR, AMLA and the 6th AML Directive) will reshape supervision and some risk-assessment expectations through 2025–2027. Belgian firms should already treat their EWRA as living documentation that can absorb those changes without a full rebuild.
Useful FSMA materials for certain obliged entities include:
Practical guide for the overall risk assessment (FSMA_2018_07), available in French or Dutch.
Periodic questionnaire on ML/TF prevention (FSMA_2020_11) (French).
Used well, the EWRA is a chance to see the business clearly and to anticipate ML/TF risks before they become unmanageable.






