
FINTRAC's enforcement activity backs this up. In its 2024-25 Annual Report, the regulator disclosed that it completed more than 1,300 assessment activities, a jump of over 40% year over year, including 294 formal examinations. It also issued 23 Notices of Violation that year, its highest single-year total, totalling more than $25 million in penalties, according to FINTRAC's 2024-25 Annual Report.
Behind many of those findings sits the same root problem: a risk assessment matrix built once, filed away, and never seriously revisited. Regulators don't just want the document. They want to see the reasoning behind it.
This guide walks through what a compliance risk assessment matrix actually is, its core components, how to build one step by step, and how to keep it defensible when someone comes asking questions.
Key Takeaways
- Plot likelihood against impact so you rank compliance risks and put resources where they matter most
- Every rating rests on three pillars: inherent risk, control strength, and residual risk
- Risk categories should reflect your actual products, customers, channels, and geography, not a generic template
- 3x3 or 5x5 scales and formal approval steps are examples of one practical approach - not universal requirements
- A compliance risk assessment matrix is a methodology tool under Senior AML Advisory / risk-assessment challenge - not a standalone AlphaDelta service product
- Independent senior review of your methodology can surface gaps in reasoning and documentation
What Is a Compliance Risk Assessment Matrix and Why Does It Matter?
A compliance risk assessment matrix is a visual or tabular tool that plots the likelihood of a compliance risk against its impact, then sorts the result into categories like low, moderate, and high. It's how a reporting entity decides where to focus limited compliance resources instead of spreading effort evenly across every possible risk.
FINTRAC doesn't prescribe a single format. What it does require is that entities conduct and document their own assessment, including every step of the process and the rationale behind it, according to FINTRAC's risk assessment guidance.
What FINTRAC cares about is the reasoning behind the ratings—not whether the matrix matches a preferred template.
Regulators Test the Reasoning, Not Just the Document
During an examination, FINTRAC may verify whether the assessment reflects the entity's actual type, size, and complexity. Examiners do not follow one universal checklist of areas; scope is risk-based. One practical readiness approach is to be able to:
- Sample client and transaction records to check whether ratings match the real risk profile
- Explain ratings with documented rationale rather than arbitrary assignment
- Show that relevant business areas were considered
- Show that enhanced measures were applied where high-risk situations require them
A firm that can produce the matrix but can't explain why a customer segment is rated moderate rather than high faces real examination risk.
Independent challenge of methodology, assumptions, and control mapping - before that pressure arrives - is part of AlphaDelta's Senior AML Advisory (risk assessment and control challenge), not a standalone product.
The Three Core Components of a Compliance Risk Assessment Matrix
One practical approach is to consider inherent risk, control effectiveness and residual risk; FINTRAC does not prescribe one matrix or approval model.
Inherent Risk
Inherent risk is the exposure that exists before any controls are applied. FINTRAC groups the drivers into legal factors (domestic laws and regulatory expectations), structural factors (your business model and processes), business-based factors, and relationship-based factors, per FINTRAC's risk assessment guidance.
In practice, inherent risk climbs fast when a business offers:
- International wire transfer products with limited transparency into originating funds
- Cash-intensive business lines, such as certain MSB or real estate activity
- Higher-risk customer types, including politically exposed persons or non-resident clients
- New technologies or delivery channels introduced without a prior risk review
A mortgage lender offering only domestic, in-branch products carries a very different inherent risk profile than a fintech offering instant cross-border transfers to unverified counterparties. The matrix needs to reflect that difference, not flatten it.
Risk Controls (Quality of Risk Management)
Controls are what stand between inherent risk and actual loss or regulatory exposure. One practical approach is to evaluate four areas (illustrative - not a universal examiner checklist):
- Board and senior management oversight — is leadership actually engaged, or just signing off?
- Policies, procedures, and training — do they exist, and do staff apply them consistently?
- Risk monitoring and management information systems — is data flowing to the people who need it?
- Internal controls and testing — has anyone independently verified these controls work?
Here's the trap: a policy sitting in a shared drive isn't a control. A defensible compliance program documents relevant controls and maintains evidence showing how they operate in practice. Effectiveness-review testing can provide additional evidence about whether those controls are functioning as intended.
That's the same standard AlphaDelta applies during its Independent AML Effectiveness Reviews. The firm uses document review, interviews, walkthroughs, file sampling, and end-to-end testing to confirm controls function in practice rather than just on paper.
Residual Risk
Residual risk is what's left after weighing inherent risk against how well your controls actually perform. It's the number that should drive your remediation priorities, not the inherent risk score alone.
A quick example: a business line with high inherent risk - say a cash-intensive MSB corridor - paired with strong, tested controls might land at a moderate residual rating. Robust transaction monitoring, tight enhanced due diligence, and active senior oversight can meaningfully offset the exposure.
Flip that: high inherent risk with weak or untested controls stays high residual risk. That's where remediation dollars need to go first.

How to Build Your Compliance Risk Assessment Matrix: A Step-by-Step Process
Building a matrix that can be explained and evidenced takes more than filling in a template. One practical approach follows this sequence.
Step 1: Map the Risk Landscape
Pull input from compliance, business lines, legal, and technology teams to build a full inventory of risks. Cover regulatory, operational, reputational, and third-party/technology categories.
Skipping cross-functional input is a common way to miss a risk that later shows up in an examination finding.
Step 2: Select Risk Criteria and a Rating Scale
Define what "likelihood" and "impact" actually mean for your organization before scoring anything. Decide whether you'll use numeric, qualitative (low/medium/high), or colour-coded ratings. Consistency here matters more than sophistication.
Step 3: Score and Document Each Risk
Score every identified risk against your criteria, calculate a combined risk score, and write down why each rating was assigned. FINTRAC's Assessment Manual describes areas FINTRAC may assess; a written rationale supports defensibility if residual ratings are challenged. Undocumented gut-feel ratings are hard to defend.
Step 4: Prioritize Risks and Build an Action Plan
Rank risks by combined score. Turn the highest-priority items into concrete remediation plans with:
- A named owner responsible for the fix
- A realistic timeline
- A clear definition of what "resolved" looks like
Step 5: Obtain Governance Review and Sign-Off
Senior-officer engagement with the risk assessment supports governance. Formal board approval of every matrix cell is an example of strong practice in some structures - not a universal FINTRAC prescription. Documented ownership and rationale matter more than a single approval ritual.
Choosing Rating Scales and Reflecting AML-Specific Risk Categories
3x3 vs. 5x5 Rating Scales (examples, not mandates)
FINTRAC does not require a 3x3 or 5x5 scale. A 3x3 structure (low, medium, and high on both axes) is one common example that can fit smaller or less complex reporting entities.
A 5x5 scale is another example that can suit larger, more complex entities that need finer-grained prioritization. Choose the scale that fits your methodology - not as a universal requirement.
Neither FINTRAC nor international standards like IEC 31010:2019 mandate a specific scale. What matters is that the scale fits your actual complexity and that you use at least three categories per axis so ratings aren't overly compressed.
AML and Canadian Regulatory Risk Categories
Under the Proceeds of Crime (Money Laundering) and Terrorist Financing Regulations, Canadian reporting entities must assess and document risk across specific factors, according to the PCMLTFR current consolidation:
- Client and business relationship risk, including correspondent banking
- Product, service, and delivery channel risk
- Geographic risk, covering where clients and transactions are located
- Affiliated-entity risk, where applicable
- New developments and technologies, assessed before they're introduced, not after
These risk categories - and the assumptions and controls mapped against them - may be assessed during FINTRAC examinations and effectiveness reviews per FINTRAC's Assessment Manual framing. An independent, senior-level assessment can surface gaps in that reasoning and documentation. 3x3 and 5x5 grids remain illustrative examples, not prescriptions.
AlphaDelta provides that independent challenge for Canadian reporting entities preparing for scrutiny, drawing on experience building AML programs.

Maintaining Your Matrix and Avoiding Common Pitfalls
FINTRAC treats risk assessment as an ongoing process. Entities should reassess regularly and refresh the matrix after a new product, service, technology, location, or affiliation, according to FINTRAC's risk assessment guidance. At minimum, the full compliance program, including the risk assessment, must undergo an effectiveness review at least every two years.
Common pitfalls:
- Inconsistent scoring when different assessors apply the same scale differently
- Stale risk inventories that never account for new products or channels
- Treating the matrix as a checkbox exercise rather than a living decision tool
Those operational gaps sit alongside a deeper design risk. Research from GARP notes that risk matrices can oversimplify complex, interrelated risks. They can also create a false sense of precision around subjective judgments, according to GARP's analysis of risk matrix limitations.
Keep the matrix, but anchor rating scales to concrete thresholds and run periodic calibration discussions among assessors. That keeps scoring consistent and defensible over time.
Frequently Asked Questions
What is a compliance risk assessment matrix?
It's a tool that plots likelihood against impact to rank and prioritize compliance risks. Reporting entities use it to decide where compliance resources and controls need the most attention.
How do you calculate a risk score using a risk assessment matrix?
Most methodologies combine a likelihood rating with an impact rating, either multiplied or plotted together in a grid. The resulting score then falls into predefined low, moderate, or high risk zones based on set cutoffs.
What is the difference between a 3x3 and a 5x5 risk matrix?
A 3x3 matrix uses three categories per axis for nine total cells, suited to smaller or less complex organizations. A 5x5 matrix offers 25 cells for finer-grained prioritization, better suited to larger, more complex reporting entities.
How often should a compliance risk assessment matrix be updated?
At minimum, alongside your compliance program's effectiveness review every two years. It should also be refreshed sooner after new products, regulatory changes, or examination findings.
What are the main limitations of a compliance risk assessment matrix?
Ratings are inherently subjective, and different assessors can score the same risk differently without calibration. Matrices can also compress a wide range of exposures into just a few categories, masking real differences.
Who should review or challenge an organization's compliance risk assessment methodology?
Independent, senior-level reviewers with regulatory and program-ownership experience add the most value here. They can validate whether assumptions and controls genuinely reflect actual risk exposure, not just documented intent.


