TL;DR: A BSA/AML risk assessment is the institution-wide analysis of illicit finance risk across products and services, customers, geographies, and delivery channels, scored as inherent risk, mitigated by controls, and concluded as residual risk. The FFIEC BSA/AML Examination Manual sets no fixed refresh interval but expects updates whenever products, customers, or footprint change, and FinCEN's April 2026 proposed AML/CFT program rule would make a risk assessment process a required part of internal controls. Crowe counted 42 BSA/AML enforcement actions in 2024, 54 percent of bank actions against institutions under $1 billion in assets, and orders routinely require a rebuilt risk assessment as the first remedial step.
One Assessment for the Institution, Not One per Customer
The BSA/AML risk assessment is the enterprise-wide document that tells a bank, its board, and its examiner where money laundering and terrorist financing risk actually sits. It is not customer risk rating. Customer risk rating scores individual relationships; the enterprise assessment aggregates the whole book and asks which business lines, segments, geographies, and channels carry the exposure, and whether controls are sized to it. Sphinx covers the customer-level side in its guide to customer risk rating for AML.
The FFIEC manual is candid that the enterprise assessment is not a specific legal requirement today. It is also the first thing an examiner reads during scoping, and when a bank's assessment is missing or inadequate, the manual instructs the examiner to build one, which cedes the risk narrative for the entire exam. That is why every bank produces one, and why it sits underneath the five pillars of an AML compliance program rather than beside them.
The Four Categories Examiners Read Against Your Data

The manual describes a two-step process: identify the risk categories unique to the bank, then analyze the data inside each. The categories in nearly every assessment are products and services, customers and entities, geographic locations, and delivery channels, and FinCEN's 2026 proposal names the same five activities a risk assessment process must evaluate.
Identification is a census. Analysis is where assessments fail. The manual's example is two banks that each send 100 international wires a day. For one, 90 percent are recurring transfers for long-term customers; for the other, 90 percent are non-recurring or for non-customers. Same count, different risk. An assessment that stops at the count has done half the work.
The analysis has to be quantitative wherever the data exists: wire and ACH volume by product and corridor, growth since the last assessment, balances and alert rates by segment, the share of customers rated high, customers domiciled in higher-risk jurisdictions, and the share of accounts opened non-face-to-face or through a third party. The bank's own filings belong in that analysis too. An assessment that rates a segment low while it generates a disproportionate share of SARs will not survive the first question.
Inherent Risk, Controls, Residual Risk: Show the Math
A defensible methodology scores inherent risk for each category, evaluates the controls that mitigate it, and concludes on residual risk. Inherent risk is the exposure before any controls operate, driven by volume, velocity, anonymity, and geography. Control effectiveness is a judgment about whether monitoring, CDD, screening, training, and independent testing actually reduce that exposure, supported by alert output, QA results, and audit findings rather than by the policy that describes the control. Residual risk is what remains, and the board's risk appetite has to accommodate it.
The manual does not prescribe a format or scale and tells examiners not to advocate one. It does say sound practice is to document the factors considered, including any weighting. If wires count more than cash, the assessment should say so and why. Consent orders now spell this out. The OCC's 2026 consent order with Community Federal Savings Bank requires an institution-wide risk assessment that evaluates the adequacy of internal controls and assesses residual risk against the board-approved risk appetite, using data on current and proposed products, customer types, customer risk ratings, transaction volumes, and geographies served.
Two documentation habits separate assessments that hold up: a data appendix behind every figure, and a change log recording why each rating did or did not move. A rating that stays the same while volume triples is a finding waiting to be written.
When to Refresh, and What Forces It
The FFIEC manual states there is no requirement to update the BSA/AML risk assessment on a continuous or specified periodic basis. It then says assessments are generally updated, in whole or in part, when products, services, customers, or geographies change, naming new products, new customer types, and mergers and acquisitions as examples. Most banks settle on an annual refresh with interim updates. The annual cadence is a convention, not a defense when the risk profile moved in month three.
FinCEN's proposal tightens the trigger. Under the April 7, 2026 AML/CFT program NPRM, which supersedes and withdraws FinCEN's July 2024 proposal, risk assessment processes would have to be updated promptly upon any change the institution knows or has reason to know significantly changes its ML/TF risks. Comments closed June 9, 2026, with a proposed 12-month implementation period. The proposal also drops the idea of a single consolidated document: risk assessment can be multiple processes examined in their totality. A signed annual document is not current if a new business line launched and no process touched it.
The events that should force an interim update are predictable: a new product or payment rail, an acquisition, a shift in customer mix, a new third-party relationship, a jump in cross-border volume, a monitoring system change, and any significant exam finding. Fintech partnerships deserve their own line: a sponsor bank inherits the risk profile of every program it sponsors, so the assessment has to reflect end-user volume and geography, not just the counterparty. Sphinx's guide to bank-fintech partnership compliance oversight covers that diligence.
What Examiners Criticize
The recurring criticisms are stale, generic, and disconnected. Stale means the document describes a bank that no longer exists: last year's volumes, no mention of the payments line that now drives half the wire activity. Generic means a vendor template with the bank's name substituted in, rating every category moderate without institution-specific data. Disconnected means the assessment concludes something and the program does not respond: a segment rated high with no monitoring scenario, no EDD trigger, and no staffing behind it.
The Community Federal order illustrates all three. The OCC found that the bank had significantly grown its payment processing line since 2020, relative to its size, while controls did not keep pace. Monitoring thresholds were never tuned to the payments line, an automated triage system auto-closed a very high percentage of alerts, CDD did not capture what payment processing customers actually did, and internal audit never scoped the high-risk areas. Each is a control failure. They compounded because nothing upstream said the risk had changed.
Enforcement data shows how often the assessment is the root. According to Crowe's analysis of 2024 BSA/AML enforcement, federal banking agencies, NYDFS, and FinCEN issued 42 actions in 2024, up from 29 in 2023, with 28 citing suspicious activity monitoring deficiencies and 54 percent of bank actions issued to institutions under $1 billion in assets. K&L Gates' review of the same actions found many required a revised, ongoing risk assessment methodology, because the old one did not describe the bank.
The supervisory vocabulary is changing, which raises the assessment's evidentiary weight. The OCC and FDIC's final rule on unsafe or unsound practices and matters requiring attention, effective November 2, 2026, limits MRAs to practices reasonably expected to cause material financial harm or to actual violations of banking law, with violation-based MRAs reserved for substantive violations such as systemic or patterned failures. A thin risk assessment on its own may now arrive as a supervisory observation. A program not reasonably designed for the bank's risk is still a program-rule violation, and the risk assessment is what proves reasonable design. That makes it the first exhibit in community bank BSA exam preparation.
The Assessment Has to Drive Something
A risk assessment that does not change the program is a report, not a control. The FFIEC manual's Appendix I links the assessment to the compliance program, and the manual states that suspicious activity monitoring should be risk-based, adding screening for the higher-risk products, customers, and geographies the assessment identified. FinCEN's proposal requires institutions to direct more attention and resources toward higher-risk customers and activities than lower-risk ones.
That traceability shows up in four places. Transaction monitoring scenarios and thresholds should map to the risks rated high, and tuning decisions should cite the assessment. CDD and EDD triggers should reflect the segments and geographies it flagged. Staffing and training should scale with the residual risk conclusion. Independent testing should sample hardest where the assessment points and should test the assessment itself, since the manual directs audit to review it and how it was used to build the program. Sphinx's guide to AML independent testing requirements covers that second half. When the assessment, the rule inventory, the CDD procedures, the org chart, and the audit plan all reach the same conclusions, the assessment has done its job.
Where Sphinx Fits
Sphinx's agents work inside the case management, monitoring, and screening systems a bank already runs, and every disposition carries the data reviewed, the reasoning, and the outcome. That record is the evidence a risk assessment needs when it rates control effectiveness: alert outcomes by segment and geography, escalation rates by scenario, and the reasoning behind closures. Sphinx does not write the enterprise risk assessment. It gives the people who do a reconstructible record of how controls performed against the risk it described.
Frequently Asked Questions
Is a BSA/AML risk assessment legally required?
Not as a standalone requirement today. The FFIEC BSA/AML Examination Manual calls the enterprise risk assessment a sound practice rather than a specific legal requirement, but examiners evaluate it at every exam and build their own if the bank's is missing or inadequate. FinCEN's April 2026 proposed AML/CFT program rule would require risk assessment processes as part of the internal controls pillar.
How often should a BSA/AML risk assessment be updated?
The FFIEC manual sets no fixed interval but expects updates when products, services, customers, or geographies change, including through new offerings and mergers or acquisitions. Most banks refresh annually with interim updates. FinCEN's 2026 proposal would require updates promptly upon any change the institution knows or has reason to know significantly changes its ML/TF risks.
What is the difference between a BSA/AML risk assessment and customer risk rating?
The BSA/AML risk assessment is institution-wide: it evaluates products, services, customers, geographies, and delivery channels in aggregate and concludes on the bank's residual risk profile. Customer risk rating scores individual relationships to set due diligence and monitoring intensity. The rating distribution feeds the enterprise assessment, and the enterprise assessment decides which segments the rating model must treat as higher risk.
What do examiners most often criticize in a BSA/AML risk assessment?
Stale assessments that omit new products, partners, or volume growth; generic templates that rate every category moderate without bank-specific data; and assessments whose conclusions never reach monitoring scenarios, EDD triggers, staffing, or audit scope. Under the OCC and FDIC final rule effective November 2, 2026, a weak assessment alone may be a supervisory observation, but a program not reasonably designed for the bank's risk is still a program-rule violation.

.png)