Pideeco
RiskComplianceFinancial firmsKYCAMLFSMAAudit Findings5AMLDEWRARisk ManagementEUDue DiligenceAuditRisk Based Approach

EWRA: enterprise-wide AML risk assessment under Article 10 AMLR

How to design an EWRA aligned with Article 10 of AMLR (EU) 2024/1624: methodology, risk factors and NBB, FSMA and EBA expectations for Belgian obliged entities.

Oscar Canario da Cunha18 June 20195 min read64,483

An Enterprise-Wide Risk Assessment (EWRA) - also called the overall ML/TF risk assessment - is the business-wide exercise that maps how an obliged entity can be exposed to money laundering and terrorist financing. From an EU and Belgian perspective it is a core regulatory obligation for credit institutions, stockbroking firms, licensed insurers and other financial institutions subject to Anti-Money Laundering regulation. Under Article 17 of the Belgian Anti-Money Laundering Law of 20 July 2020, the assessment must be documented, kept up to date and available to the supervisor. That national baseline remains until Article 10 AMLR applies on 10 July 2027. Done properly, it tells the firm where to concentrate controls - and how individual customer risk scoring should reflect the same risk picture.

In a broader risk context, Enterprise Risk Assessment (ERA) or Enterprise Risk Management (ERM) programmes help entities adapt how they manage risk as financial standards evolve. The AML EWRA remains specific: it is the ML/TF lens of that enterprise view.

How to carry out an effective AML risk assessment?

Conducting an AML risk assessment is not a one-off desk exercise. It means defining a risk-rating methodology, building a model that fits your business model and data, assigning clear governance (AMLCO, senior management, board oversight) and refreshing the assessment whenever the risk profile changes. Financial institutions manage AML exposure through sound processes and risk-based vigilance; the benefits only appear when regulatory expectations and operational reality are worked through together.

What is EWRA Compliance and the Risk-Based Approach (RBA) ?

An appropriate risk-based approach starts with an up-to-date understanding of the institution's risk exposure. A Risk-based approach (RBA) is essential to Risk Management and to the AML/CFT framework. RBA was highlighted in the 2012 FATF Recommendations:

“...countries should apply a risk-based approach (RBA) to ensure that measures to prevent or mitigate money laundering and terrorist financing are commensurate with the risks identified.”

It was embedded in the fourth European AML Directive and remains the backbone of later EU AML rules. Under the EBA ML/TF Risk Factors Guidelines (EBA/GL/2021/02), firms are expected to take a holistic view: the business-wide assessment informs AML/CFT policies and controls, and those findings must stay consistent with individual business-relationship risk assessments.

In practice, RBA prioritises activity based on analysed risk. Fewer measures may suffice in genuinely low-risk situations; enhanced measures are mandatory where risk is higher. That is how scarce compliance resources are allocated.

AML EWRA Enterprise-Wide Risk Assessment Methodology

A successful EWRA methodology is consistent across domains and is commonly built through three main stages: risk identification, gap analysis (controls) and the adjustment phase (corrections and mitigation). Senior management and, where required, the board must be able to challenge the results; the AMLCO owns the process end to end.

EWRA compliance methodology
Risk Identification · Gap Analysis & Prioritization · Adjustment Phase

Documentation and updating of an EWRA

The AML overall risk assessment must be documented, updated and kept at the disposal of the supervisory authorities (for many Belgian institutions, the National Bank of Belgium). It is not a once-a-year ritual: it should be refreshed whenever an event can materially change the entity's ML/TF risk profile, so management always understands how those risks are evolving - including in connection with business relationships.

EWRA enterprise-wide risk assessment framework documentation

Beyond the EWRA report itself, supervisors expect a methodology note describing how the assessment was completed, the applicable legal framework and sectoral guidance used, monitoring and update procedures, and the involvement of the AMLCO, compliance, senior management and any other parties.

In Belgium, institutions under NBB AML supervision also work with a summary table of the overall risk assessment and periodic questionnaires. Circular NBB_2018_02 set the methodological frame; Communication NBB_2020_002 then spelled out supervisor findings on summary tables and the need to follow the steps in methodological order. Periodic questionnaire expectations have since been refreshed (including Circular NBB_2024_05). Firms must be able to show, on the basis of those documents, that their approach meets the Anti-Money Laundering Law of 20 July 2020.

What are the risk factors to consider?

To conduct their EWRA, firms must consider specific risk factors and the principle of proportionality.

The risk factors that must be considered are customers, countries or geographic areas, products, services, and transactions or delivery channels. All must be assessed proportionately to the size and nature of the entity. Firms that do not offer complex products or services and that have limited or no international exposure may not need an overly complex assessment - but they still need a documented, defensible one.

AML EWRA - List of risk factors to consider

These factors are the pillars of the analysis. Each can break down into many sub-risks - for example, customer risk may include onboarding the wrong counterparty or lacking enough additional measures for a founded decision. Entities should weight factors by relevance to their business and transactions, and assign transparent scores. Under the EBA ML/TF Risk Factors Guidelines (EBA/GL/2021/02, as amended - including guidance relevant where crypto-asset service providers or crypto exposure are in scope), profit considerations must not drive the risk rating, and firms should be ready to override automated scores where necessary, with proper documentation.

The rationale behind the EWRA obligation

A business-wide ML/TF risk assessment is a cornerstone of AML/CFT. It supports informed decisions, lets supervisors assess whether internal organisation, policies and procedures are adequate, and shows the firm where higher ML/TF risk concentrates. It also gives a sound basis for customer AML risk scoring while assessing individual cases.

The Belgian and EU reference set for an AML EWRA now goes beyond the 2018 circular alone. Core sources include:

  • Directive (EU) 2018/843 (5th AML Directive) - historical EU baseline still reflected in national law;

  • Belgian Anti-Money Laundering Law of 20 July 2020 (overall risk assessment, Art. 17);

  • NBB Regulation of 21 November 2017;

  • Circular NBB_2018_02 on the overall assessment of ML/TF risks;

  • Communication NBB_2020_002 on summary tables of the overall risk assessment;

  • NBB periodic AML/CFT questionnaires (see Circular NBB_2024_05 and related updates);

  • EBA ML/TF Risk Factors Guidelines EBA/GL/2021/02 (as amended); AMLA is taking over the EBA's AML mandate and will issue BWRA guidelines (Art. 10(4) AMLR).

From 10 July 2027, the enterprise-wide risk-assessment duty moves to Article 10 of Regulation (EU) 2024/1624 (AMLR). The AML EWRA then also covers the risk of non-implementation and circumvention of targeted financial sanctions (TFS), on top of ML/TF risks. Article 10(4) requires AMLA to issue guidelines on the minimum content of the BWRA by 10 July 2026. Article 16 requires a group assessment and a consolidated BWRA. The scope of obliged entities widens (crypto, crowdfunding). Selected groups will fall under direct AMLA supervision from 2028. Directive (EU) 2024/1640 (AMLD6) will gradually replace the Belgian national framework, including Article 17 of the Law of 20 July 2020, by 10 July 2027. See also the AML package / AMLR 2027, shell companies and, for the ERM angle (overall risk exposure outside the AML single rulebook), the EWRA-ERM.

Useful FSMA materials for certain obliged entities include:

Used well, the EWRA is a chance to see the business clearly and to anticipate ML/TF risks before they become unmanageable.

Need assistance with your EWRA?

Pideeco conducts independent compliance reviews and helps financial institutions design, challenge and remediate enterprise-wide AML risk assessments — so methodology, scoring and governance meet Belux and EU supervisor expectations.

Oscar

Written by

Oscar Canario da Cunha

Consultant at Pideeco - supporting financial institutions on AML, KYC and regulatory transformation.