What is the risk-based approach to AML, and how do firms identify their risks?
What the risk-based approach requires of a regulated firm in Cyprus, how risks are first identified and then assessed, which sources to use, and who sets the EU guidance today.
By the ExamPass CY editorial teamLast reviewed 6 min read
Topic 1 of 6 · all topics in this chapter
On this page
- Short answer
- The risk-based approach in brief
- What does the risk-based approach mean in practice?
- What must a firm document and do?
- How does a firm identify its money laundering and terrorist financing risks?
- Who sets the EU guidance on risk factors?
- How to think about it
- Common mistakes
- Looking ahead: changes from July 2027
- Legal references
- Practise this topic
Short answer
The risk-based approach means a firm puts most of its AML effort where the risk of money laundering and terrorist financing is highest, and less where it is lower, in proportion to its nature and size. Under Law 188(I)/2007 each obliged entity must identify and assess its risks by looking at its customers, countries, products, services, transactions and delivery channels, keep that assessment documented and up to date, and make it available to its supervisor. Identifying the risks comes first; assessing them comes second.
The risk-based approach in brief
| Point | What is required |
|---|---|
| Core idea | Focus effort and resources where ML/TF risk appears higher; lighter measures where it is lower |
| Scale | Measures proportionate to the firm's nature and size |
| What the firm's own risk assessment covers | Customers, countries or geographical areas, products, services, transactions and delivery channels |
| The firm's risk assessment | Documented, kept up to date and available to the supervisor |
| Where the approach is written down | The risk management and procedures manual, applied uniformly by people the board appoints |
| The two steps | First identify the ML/TF risks, then assess them |
| Starting point for information | What the firm learns during initial CDD, plus its own knowledge and expertise; then official and other credible sources |
| EU guidance on risk factors | EBA Risk Factors Guidelines; since 1 January 2026 the EU AML Authority (AMLA) holds the EBA's former AML/CFT role |
Source: Law 188(I)/2007, Articles 58, 58A and 58C, as amended up to 2026; CySEC AML Directive, paragraphs 12 to 17; EBA ML/TF Risk Factors Guidelines (EBA/GL/2021/02).
What does the risk-based approach mean in practice?
Money laundering and terrorist financing risk is not spread evenly. Some customers, countries, services and financial instruments carry more of it than others. The risk-based approach accepts that and asks the firm to concentrate its effort where the risk appears higher, applying stronger controls there and lighter ones where the risk is lower, so that resources go where they are most needed.
It is not a licence to ignore low-risk business. Every customer still goes through CDD, and every transaction can still be suspicious. What changes with risk is the depth of the checks, the frequency of reviews and the intensity of monitoring.
CySEC's AML Directive adds that the approach lets the board treat customers differently according to the risk of their business, shape policies to the firm's own circumstances, and build a more cost-effective system.
Terms used in this note
- Risk-based approach (RBA)
- Identifying and understanding the ML/TF risks a firm faces and applying measures proportionate to them, with more effort where the risk is higher.
- Business-wide risk assessment
- A firm's assessment of the ML/TF risks across its whole business: customers, countries, products, services, transactions and delivery channels.
- Risk management and procedures manual
- The document in which a CySEC-supervised firm records its AML/CFT policies, procedures and controls.
What must a firm document and do?
Every obliged entity must have policies, controls and procedures, proportionate to its nature and size, to mitigate and manage its money laundering and terrorist financing risks. It must take appropriate steps to identify and assess those risks, considering at least its customers, countries or geographical areas, products, services, transactions and delivery channels. The assessment must be documented, kept up to date and made available to the supervisor, and senior management must approve the policies and controls.
For CySEC-supervised firms, the approach has four parts: identifying and assessing the risks; documenting the policies, measures, procedures and controls in the risk management and procedures manual so that people appointed by the board apply them uniformly; managing and mitigating the assessed risks with effective controls; and continuously monitoring and improving how those controls work. The firm must always be able to show CySEC that its measures are proportionate to the risks it faces.
How does a firm identify its money laundering and terrorist financing risks?
Risk assessment has two distinct but linked steps: identifying the risks, then assessing them. The firm first works out which risks it would take on by accepting a customer or carrying out a one-off transaction, looking at who the customer is, where it operates, what it wants and how it is being served. Only then can it judge how serious those risks are.
The work runs at two levels. A business-wide risk assessment shows where the firm's risks lie overall. For each customer, CDD then gathers enough information to identify every relevant risk factor, including terrorist financing factors, and to weigh them together in a holistic view of that relationship. Monitoring afterwards checks that transactions still fit what the firm knows about the customer and its risk.
The starting point is the information the firm gathers during initial CDD, together with its own knowledge and professional expertise. The EBA guidelines add sources that firms should always consider: the EU's supranational risk assessment, the European Commission's list of high-risk third countries, Cyprus's national risk assessment, guidance from regulators and typologies from financial intelligence units. CySEC's Directive also tells the compliance officer to consult information from the FATF, MONEYVAL, the EU and UN sanctions bodies, IMOLIN and the IMF, and firms can add reliable open sources such as reputable newspapers. Open sources count only if they are credible and reliable; unverified forums, blogs or rumours do not meet that test.
Who sets the EU guidance on risk factors?
From 1 January 2020 the European Banking Authority (EBA) led, coordinated and monitored AML/CFT work across the EU financial sector, including its ML/TF Risk Factors Guidelines, which list factors for all firms and for specific sectors such as wealth management, investment firms and investment funds.
On 1 January 2026 the EBA's AML/CFT mandate passed to the new EU Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA). The EBA's existing AML/CFT guidelines, including the Risk Factors Guidelines, stay in force until AMLA replaces them.
How to think about it
Think prioritisation and proportion. Effort follows risk, scaled to the firm's nature and size, written down in the manual and kept under review. Uniform maximum controls miss the point as much as ignoring lower-risk business does. For identification, remember the order: identify first, then assess, starting from the firm's own CDD information and adding official and other credible sources.
Common mistakes
Applying the same controls to every customer. The approach varies the depth of checks and monitoring with the level of risk.
Dropping low-risk business from AML controls. Lower risk means lighter measures, not no measures; CDD and suspicion reporting still apply.
Reversing the two steps. Risks are identified first and assessed second.
Treating any open-source information as reliable. Open sources must be credible and reliable, such as reputable newspapers or official reports.
Naming the EBA as today's EU AML/CFT authority. It held that role from 2020 until the end of 2025; AMLA took over on 1 January 2026, with the EBA guidelines still in force.
Legal references
- The Prevention and Suppression of Money Laundering and Terrorist Financing Law of 2007 (Law 188(I)/2007), consolidated Greek text on CyLaw (amendments up to Law 25(I)/2026) (opens in a new tab)
Article 58: policies, controls and procedures · Article 58A: the firm's risk assessment · Article 58C: approval by senior management
- CySEC Directive for the Prevention and Suppression of Money Laundering and Terrorist Financing, as amended (opens in a new tab)
Paragraphs 12 to 17: the risk-based approach, identifying and recording risks, mitigation, monitoring and relevant international organisations
- EBA Guidelines on ML/TF risk factors (EBA/GL/2021/02), as amended (opens in a new tab)
- Regulation (EU) 2024/1620 establishing the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) (opens in a new tab)
- Regulation (EU) 2024/1624 (Anti-Money Laundering Regulation), applying from 10 July 2027 (opens in a new tab)
Practise this topic
Test what you just read
The Chapter 5 pack has 61 exam-style questions, 9 of them on this topic. Every question has a hint before you answer and a full explanation after.
Or revise the numbers first with 16 free Chapter 5 flashcards →