General AML risk assessment
We review and strengthen your general AML risk assessment framework
Common deficiencies in the general AML risk assessment and how accounting firms can respond
6 mins read • Legal Writer • ANTI–MONEY LAUNDERING • 2 April 2026
For accounting firms, the general AML risk assessment is a central part of work to prevent money laundering and terrorist financing. It should not simply exist as a formal document. It should help the business understand where the risks actually arise, which services may be exploited and how resources should be directed in practice.
It is also important to distinguish between general AML risk assessment and customer risk assessment. The general AML risk assessment concerns the business as a whole. The customer risk assessment concerns the individual customer relationship. If these two levels are conflated, the risk of deficiencies in both governance and compliance increases.
For accounting firms, the issue is business-critical. A weak or overly generic risk assessment may lead to incorrect prioritisation, inadequate customer due diligence and difficulties in demonstrating to supervisory authorities how the business applies a risk-based approach.
Why the general AML risk assessment is so important
The general AML risk assessment is the foundation of a risk-based approach under anti-money laundering legislation. Its purpose is to identify how the business’s services, customer types, working methods and geographic links may be exploited for money laundering or terrorist financing.
For an accounting firm, this requires more than stating that the business “has low risk”. The assessment must show why the risk is assessed in a particular way, which factors affect the risk and how different circumstances interact.
Only once the overall risk has been analysed can the firm build relevant procedures for customer due diligence, monitoring, reporting, training and internal control.
Common deficiencies in an AML risk assessment
Supervisory reviews of anti-money laundering compliance have identified several recurring deficiencies in the general AML risk assessment. A clear pattern is that the documentation is often too generic, too template-driven or insufficiently connected to the firm’s own business.
Common issues include the following:
- The general AML risk assessment is confused with the customer risk assessment. This means that the business-level analysis is not carried out properly.
- The assessment is too general. A template has been completed, but without genuine adaptation to the firm’s services, customers and working methods.
- Services are not analysed separately. Ongoing bookkeeping, payroll administration, annual accounts, advisory services and handling of international transactions may each present different risk profiles.
- Threats and vulnerabilities are not linked. It is not enough to list risk factors. The business must show how they may lead to actual exploitation.
- Geographic risks are assessed too narrowly. It is not sufficient merely to state that customers are based in one domestic market.
- Risk levels are not justified. Stating “low”, “medium” or “high” without analysis is insufficient.
The difference between a general risk assessment and a customer risk assessment
A recurring pitfall is that the firm places too much emphasis on the individual customer and too little on the overall risk assessment of the business.
The general AML risk assessment should answer questions such as:
- Which services does the firm provide and how could they be misused?
- Which customer types or sectors present elevated risk?
- How do digital onboarding, remote contact or the use of third parties affect the risk profile?
- Are there geographic links that affect the risk level?
- Are there internal vulnerabilities, such as insufficient training or unclear allocation of responsibility?
The customer risk assessment follows the general AML risk assessment and uses that overall understanding as its foundation. If the general risk assessment is weak, the customer risk assessments will also be uncertain or inconsistent.
What a business-specific AML risk assessment should include
A strong general AML risk assessment must be concrete. It should reflect how the accounting firm actually operates.
This means that the firm needs to analyse:
- which services are offered and how each service may be exploited,
- which threat scenarios are relevant to the business,
- which vulnerabilities exist,
- how services are delivered, for example remotely or through digital processes,
- which geographic factors are relevant, and
- which business-specific circumstances affect the risks.
For an accounting firm, it may for example be relevant to assess risks linked to customers handling cash, customers with international payment flows, complex ownership structures, representatives with unclear backgrounds or engagements where the firm records transactions that may be used to create an appearance of legitimacy.
Practical pitfalls in the day-to-day work of accounting firms
In practice, deficiencies often arise when the general AML risk assessment is treated as a one-off document or template. The regulatory framework instead requires the assessment to be kept current and to reflect how the business develops over time.
Typical situations where the risk profile may need to be reassessed include:
- when the firm starts accepting customers in new sectors,
- when new digital working methods are introduced,
- when the service offering is expanded,
- when the firm accepts engagements with an international connection,
- when the organisation changes or staff with key responsibilities are replaced.
Another common pitfall is that internal vulnerabilities are underestimated. This may involve insufficient training, limited staff experience, unclear escalation channels or customer managers becoming too dependent on established relationships and therefore missing warning signs.
How accounting firms can build a more robust AML risk assessment
For the general AML risk assessment to work in practice, it should be a governance document that is used and developed, not merely filed away.
- Break down the analysis by service or service category rather than describing the business in general terms.
- Clearly justify each risk level and link it to identified threats and vulnerabilities.
- Describe why certain customer types, delivery methods or geographic links affect the risk.
- Ensure that the risk assessment aligns with procedures for customer due diligence, training and reporting.
- Update the document when the business changes, not only ahead of supervision or internal control.
- Avoid using templates without your own analysis and adaptation.
A well-prepared general AML risk assessment makes it easier to show how the firm prioritises its AML measures and why certain customers or services require greater vigilance than others.
We support firms with the general AML risk assessment
For accounting firms, the general AML risk assessment is not a formal appendix to compliance work. It is the starting point for how the business should understand and manage its risks under anti-money laundering legislation.
When the assessment is concrete, business-specific and clearly distinguished from the customer risk assessment, it becomes easier to build a proportionate and effective AML framework. When it is too generic or template-based, the risk of overlooking important vulnerabilities increases.
At Morling Consulting, our AML lawyers help businesses across Europe structure, review and develop their work on general AML risk assessment, customer due diligence and other aspects of the anti-money laundering framework.
For accounting firms, the general AML risk assessment is a central part of work to prevent money laundering and terrorist financing. It should not simply exist as a formal document. It should help the business understand where the risks actually arise, which services may be exploited and how resources should be directed in practice.
It is also important to distinguish between general AML risk assessment and customer risk assessment. The general AML risk assessment concerns the business as a whole. The customer risk assessment concerns the individual customer relationship. If these two levels are conflated, the risk of deficiencies in both governance and compliance increases.
For accounting firms, the issue is business-critical. A weak or overly generic risk assessment may lead to incorrect prioritisation, inadequate customer due diligence and difficulties in demonstrating to supervisory authorities how the business applies a risk-based approach.
Why the general AML risk assessment is so important
The general AML risk assessment is the foundation of a risk-based approach under anti-money laundering legislation. Its purpose is to identify how the business’s services, customer types, working methods and geographic links may be exploited for money laundering or terrorist financing.
For an accounting firm, this requires more than stating that the business “has low risk”. The assessment must show why the risk is assessed in a particular way, which factors affect the risk and how different circumstances interact.
Only once the overall risk has been analysed can the firm build relevant procedures for customer due diligence, monitoring, reporting, training and internal control.
Common deficiencies in an AML risk assessment
Supervisory reviews of anti-money laundering compliance have identified several recurring deficiencies in the general AML risk assessment. A clear pattern is that the documentation is often too generic, too template-driven or insufficiently connected to the firm’s own business.
Common issues include the following:
- The general AML risk assessment is confused with the customer risk assessment. This means that the business-level analysis is not carried out properly.
- The assessment is too general. A template has been completed, but without genuine adaptation to the firm’s services, customers and working methods.
- Services are not analysed separately. Ongoing bookkeeping, payroll administration, annual accounts, advisory services and handling of international transactions may each present different risk profiles.
- Threats and vulnerabilities are not linked. It is not enough to list risk factors. The business must show how they may lead to actual exploitation.
- Geographic risks are assessed too narrowly. It is not sufficient merely to state that customers are based in one domestic market.
- Risk levels are not justified. Stating “low”, “medium” or “high” without analysis is insufficient.
The difference between a general risk assessment and a customer risk assessment
A recurring pitfall is that the firm places too much emphasis on the individual customer and too little on the overall risk assessment of the business.
The general AML risk assessment should answer questions such as:
- Which services does the firm provide and how could they be misused?
- Which customer types or sectors present elevated risk?
- How do digital onboarding, remote contact or the use of third parties affect the risk profile?
- Are there geographic links that affect the risk level?
- Are there internal vulnerabilities, such as insufficient training or unclear allocation of responsibility?
The customer risk assessment follows the general AML risk assessment and uses that overall understanding as its foundation. If the general risk assessment is weak, the customer risk assessments will also be uncertain or inconsistent.
What a business-specific AML risk assessment should include
A strong general AML risk assessment must be concrete. It should reflect how the accounting firm actually operates.
This means that the firm needs to analyse:
- which services are offered and how each service may be exploited,
- which threat scenarios are relevant to the business,
- which vulnerabilities exist,
- how services are delivered, for example remotely or through digital processes,
- which geographic factors are relevant, and
- which business-specific circumstances affect the risks.
For an accounting firm, it may for example be relevant to assess risks linked to customers handling cash, customers with international payment flows, complex ownership structures, representatives with unclear backgrounds or engagements where the firm records transactions that may be used to create an appearance of legitimacy.
Practical pitfalls in the day-to-day work of accounting firms
In practice, deficiencies often arise when the general AML risk assessment is treated as a one-off document or template. The regulatory framework instead requires the assessment to be kept current and to reflect how the business develops over time.
Typical situations where the risk profile may need to be reassessed include:
- when the firm starts accepting customers in new sectors,
- when new digital working methods are introduced,
- when the service offering is expanded,
- when the firm accepts engagements with an international connection,
- when the organisation changes or staff with key responsibilities are replaced.
Another common pitfall is that internal vulnerabilities are underestimated. This may involve insufficient training, limited staff experience, unclear escalation channels or customer managers becoming too dependent on established relationships and therefore missing warning signs.
How accounting firms can build a more robust AML risk assessment
For the general AML risk assessment to work in practice, it should be a governance document that is used and developed, not merely filed away.
- Break down the analysis by service or service category rather than describing the business in general terms.
- Clearly justify each risk level and link it to identified threats and vulnerabilities.
- Describe why certain customer types, delivery methods or geographic links affect the risk.
- Ensure that the risk assessment aligns with procedures for customer due diligence, training and reporting.
- Update the document when the business changes, not only ahead of supervision or internal control.
- Avoid using templates without your own analysis and adaptation.
A well-prepared general AML risk assessment makes it easier to show how the firm prioritises its AML measures and why certain customers or services require greater vigilance than others.
We support firms with the general AML risk assessment
For accounting firms, the general AML risk assessment is not a formal appendix to compliance work. It is the starting point for how the business should understand and manage its risks under anti-money laundering legislation.
When the assessment is concrete, business-specific and clearly distinguished from the customer risk assessment, it becomes easier to build a proportionate and effective AML framework. When it is too generic or template-based, the risk of overlooking important vulnerabilities increases.
At Morling Consulting, our AML lawyers help businesses across Europe structure, review and develop their work on general AML risk assessment, customer due diligence and other aspects of the anti-money laundering framework.
Related posts
9 July 2026
Money Laundering in Real Estate – Risks, Obligations and Practical Measures
7 July 2026
EU cooperation under the AMLR – final part on Articles 81–90
30 June 2026
Risk-mitigating measures against anonymous instruments and large cash payments – Articles 79–80 AMLR
Speak to an AML lawyer
Do you need a stronger general AML risk assessment? Contact us and we will review and strengthen it
"*" indicates required fields