
The problem? Many EWRAs get built once, filed away, and dusted off only when a review is due. They become tick-the-box paperwork instead of the living framework they're supposed to be. In 2024-25 alone, FINTRAC conducted more than 1,300 assessment activities — over 40% more than the previous year — including 294 formal examinations, and issued 23 notices of violation totalling more than $25 million. A stale or poorly reasoned risk assessment leaves the rest of the program resting on assumptions that no longer hold.
This article breaks down what an EWRA actually is, the core components regulators expect, how to build one properly, and the mistakes that tend to draw scrutiny.
Key Takeaways
- An EWRA assesses ML/TF risk across the whole organization, not only individual clients
- A risk-based FINTRAC examination may include your business-based risk assessment to gauge whether you understand your own exposure
- Five risk dimensions (customer, geographic, product/channel, operational, and cross-factor exposure) are a practical grouping, not a required taxonomy; they map onto the prescribed factors of clients and business relationships, products, services and delivery channels, geography, affiliates for certain entities, new developments and technologies, and the sector risks in the latest National Risk Assessment
- Ongoing risk-assessment maintenance is separate from the statutory two-year effectiveness-review cadence (PCMLTFR s.156)
- Material changes warrant updating the risk assessment and controls as sound practice; they do not universally require an early statutory effectiveness review
- Independent challenge of your methodology can identify weaknesses, assumptions and remediation priorities
What Is an Enterprise-Wide Risk Assessment (EWRA)?
An EWRA is a structured, periodic process for identifying, measuring, and documenting an organization's inherent and residual exposure to ML/TF risk across business lines, products, customers, geographies, and delivery channels.
In Canada, FINTRAC refers to this as a business-based risk assessment: entities must first assess risk across the business as a whole, before turning to individual clients and relationships (FINTRAC risk-based approach guidance).
This assessment is the foundation of the risk-based approach required under Canada's Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA). Your policies, controls, staffing, and monitoring thresholds should all trace back to what the EWRA found. If they don't, that's a gap regulators notice quickly.
EWRA vs. Business Risk Assessment vs. Customer Risk Assessment
These terms get used interchangeably, but they aren't the same thing:
- EWRA / business-based assessment: organization-wide, strategic view across the whole entity
- Business risk assessment: often used to describe a specific line of business or product
- Customer risk assessment: client-level scoring that feeds into and is informed by the EWRA

International guidance from FATF and the EBA describes a credible business-wide assessment as holistic, timely, and tailored to the entity's profile. Neither body prescribes exact methodology, which is exactly why quality varies so much between institutions. Some entities build rigorous, defensible frameworks; others produce something closer to a checklist.
Inherent Risk vs. Residual Risk
Every credible EWRA rests on this distinction:
- Inherent risk: the raw risk level before any controls are applied
- Residual risk: what remains after your KYC, monitoring, and training controls are factored in
If your assessment doesn't separate the two, you can't demonstrate that your controls are actually doing anything. That's the logic examiners are looking for.
Why EWRA Matters: Regulatory Expectations for Canadian Reporting Entities
A risk-based FINTRAC examination may include the EWRA under RBA guidance. The assessment shows whether an entity understands its own risk footprint before assessing whether its controls are proportionate to that footprint. If the risk picture is wrong or incomplete, everything built on top of it (monitoring rules, escalation thresholds, staffing) can be harder to defend.
FINTRAC's harm-assessment guide classifies failure to assess and document ML/TF risk using the prescribed factors as a serious violation, with indicative penalty levels ranging from $25,000 to $100,000 depending on how much of the assessment was missing, under the AMP policy that still applies to violations committed entirely before 26 March 2026 (for later conduct, see FINTRAC's live AMP materials) (FINTRAC guide on harm-done assessment).
That risk is not theoretical. FATF's 2016 mutual evaluation of Canada found large federally regulated financial institutions generally had comprehensive risk assessments, while risk awareness among certain non-financial sectors, particularly real estate, was materially weaker.
The Independent Challenge Problem
Here's the structural issue: reporting entities design and score their own EWRA methodology. There's no built-in check on whether:
- The weighting makes sense
- Risk criteria are internally consistent
- A scoring model quietly understates exposure in a growing product line
This is where an independent, senior-level review earns its keep. AlphaDelta's independent EWRA and effectiveness review work is built for that gap: pressure-testing assumptions, weighting logic, and scoring methodology before a FINTRAC examiner does it for you. Catching a flawed assumption internally costs far less than defending it in a formal examination.
Key Risk Categories Every EWRA Must Assess
Most regulatory frameworks — FINTRAC, FATF, the EBA, and others — expect broadly similar risk dimensions to be covered, even though none of them mandates one universal taxonomy. Missing a dimension entirely is a common cause of "incomplete" findings.
Customer Risk
This covers high-risk customer segments, politically exposed person (PEP) exposure, adverse media hits, and behaviour that doesn't line up with a client's stated business purpose. A client whose transaction pattern shifts sharply from their onboarding profile belongs in the EWRA itself, not only in transaction monitoring.
Geographic Risk
Assess exposure to high-risk jurisdictions, sanctioned countries, and FATF-flagged regions — both through customer and counterparty relationships, and through your own operational footprint if you have offices or agents abroad.
Products, Services, and Delivery Channels
Your EWRA should weight product and channel features that raise inherent ML/TF risk, including:
- Cash-intensive services that obscure the source of funds
- Anonymous or low-transparency products
- Cross-border fund flows with limited intermediary visibility
- Non-face-to-face onboarding with weaker identity assurance
Operational and Entity-Level Risk

Internal weaknesses count too — staffing gaps, system limitations, a growing backlog of unresolved alerts, or rapid business expansion that's outpaced your controls. FINTRAC's guidance also directs entities to factor in new developments and technologies before they're rolled out, not after (FINTRAC compliance program requirements).
None of these categories should be assessed in isolation. A high-risk customer using a high-risk delivery channel in a high-risk jurisdiction produces a materially higher combined risk profile than any single factor on its own. If your methodology scores each category separately and never combines them, you're likely understating your real exposure.
How to Conduct an Enterprise-Wide Risk Assessment
A defensible EWRA follows a structure similar to the ISO 31000 risk management process: establish scope and context, assess the risk, then treat it.
Define Scope, Context, and Risk Criteria
Before any scoring happens, set clear boundaries:
- Entities, products, and geographies in scope
- Time period the assessment covers
- Measurable risk criteria, scoring thresholds, and weighting logic
Skipping this step is how you end up with inconsistent scoring, with different reviewers applying different judgment calls to the same risk factor.
Identify and Analyze Risks
Pull together internal data (customer base composition, transaction volumes, product mix) alongside external inputs. Canada's 2025 national risk assessment of ML/TF threats, FINTRAC guidance, and relevant typology reports should all feed into this inventory.
Score Inherent Risk and Map Controls
Assign inherent risk scores to each factor, then map your existing controls (KYC procedures, transaction monitoring rules, staff training) against each risk to calculate residual risk. That mapping turns the inherent-versus-residual distinction into an operational calculation.
Evaluate Residual Risk and Determine Treatment
Once residual risk is calculated, there are four paths forward:
- Accept: the risk is within tolerance
- Monitor: track it more closely without immediate action
- Mitigate: add or strengthen controls
- Avoid: exit the product, relationship, or market entirely
Senior management and the board need to formally sign off on the final risk position and any remediation plan. Document every stage: regulators assess not only your conclusions, but whether the reasoning trail behind them is complete and explainable under questioning.
Common Mistakes That Undermine EWRA Effectiveness
Three patterns show up repeatedly in weak EWRAs:
- No defined risk appetite before scoring: Without a benchmark for acceptable residual risk, scoring has no reference point
- Static, annual paperwork exercise: The EWRA should be a living document updated for regulatory change, new products, and emerging typologies
- Missing senior management and cross-functional input: Compliance, risk, IT, and legal each hold part of the risk picture; leave any out and scoring goes incomplete
FINTRAC's harm-assessment framework treats omissions on a sliding scale. Missing "other relevant factors" is one thing. Omitting basic factors such as products, clients, or geography, or conducting no meaningful assessment at all, escalates the severity of the finding considerably.
A recent case shows the stakes. In December 2025, FINTRAC published an AMP of $536,853.35 against a foreign MSB. One cited violation was failure to assess and document ML/TF risk using the prescribed factors (FINTRAC enforcement notice).
Risk assessment gaps draw real enforcement consequences, not just findings on paper.
How Often Should EWRA Be Reviewed or Updated?
Reporting entities should keep their documented risk assessment current and revisit it when relevant risks, operations, products, clients, delivery channels or geographic exposure change. Separately, the compliance program's effectiveness must be reviewed at least every two years. Material changes may warrant additional review work depending on their nature and impact, but they do not create a universal statutory requirement to conduct an immediate new effectiveness review. A 30-day action-plan deadline applies where FINTRAC requests an action plan following an examination.
Material events that commonly warrant revisiting the risk assessment include:
- Launching a new product or service
- Expanding into new markets
- Mergers or acquisitions
- Significant regulatory change
Between formal refreshes, watch key risk indicators (for example, shifts in high-risk customer concentration) so the assessment doesn't go stale between review cycles.
Periodically validate the methodology itself, not just the outputs. A scoring model built two years ago may no longer match your current product mix or customer base. Independent challenge, including AlphaDelta's risk assessment and control work, tests whether the scoring logic still holds, not only whether the paperwork is current.

Frequently Asked Questions
What is an enterprise-wide risk assessment?
An EWRA is an organization-wide process for identifying, measuring, and documenting money laundering and terrorist financing (ML/TF) risk across customers, products, geographies, and delivery channels. It forms the foundation for every policy and control decision that follows.
How do you perform an enterprise-wide risk assessment?
Follow three core stages: define scope and risk criteria, identify and score inherent risk against existing controls, then determine treatment (accept, monitor, mitigate, or avoid). See the methodology breakdown above for the full sequence.
What are the 5 components of ERM?
COSO's Enterprise Risk Management framework identifies five components: Governance & Culture, Strategy & Objective-Setting, Performance, Review & Revision, and Information & Communication. An AML-specific EWRA is a narrower, specialized application that sits within this broader enterprise risk framework.
How often should enterprise-wide risk assessments be conducted by financial institutions?
Reporting entities should keep their documented risk assessment current and revisit it when relevant risks, operations, products, clients, delivery channels or geographic exposure change. Separately, the compliance program's effectiveness must be reviewed at least every two years. Material changes may warrant additional review work depending on their nature and impact, but they do not create a universal statutory requirement to conduct an immediate new effectiveness review. A 30-day action-plan deadline applies where FINTRAC requests an action plan following an examination.
What's the difference between an EWRA and a Business Risk Assessment?
An EWRA is the organization-wide, strategic assessment. Business or customer risk assessments are typically more granular, transaction- or client-level scoring exercises that feed data and findings into the broader EWRA.
What happens if FINTRAC identifies deficiencies in an EWRA during an examination?
When FINTRAC requests an action plan in certain examination cases, it is often due within 30 days unless otherwise stated. Deficiencies can also trigger follow-up examinations or enforcement action. They also weaken the credibility of your broader compliance program, which is why an independent compliance audit readiness assessment or effectiveness review before an examination is worth doing.


