Skip to content

BSA/AML risk assessment

Your risk assessment drives everything else. Make it one you can defend.

An obligation-level BSA/AML risk assessment. We rate your inherent risk, score it against the controls you actually run, and show you the residual risk that's left, with every rating traced back to the rule and the evidence behind it.

Your problem

A spreadsheet of high, medium and low that nobody can explain

  • Examiners expect your monitoring, your customer due diligence and your training to follow from your risk assessment. If the assessment is weak, everything built on it is questioned.
  • Last year's assessment rated broad categories like products and geographies. It didn't say which obligations carry the risk or which controls address it.
  • The residual ratings were judgment calls with no record of how they were reached, so they're hard to defend when someone asks.
  • Your business changed since then: new products, new states, new partners. The assessment didn't.

What you get

Ratings you can trace, obligation by obligation

  • An inherent risk rating for your products, services, customers, geographies and delivery channels, built from what your business actually does.
  • Residual risk scored against your controls. Each obligation is matched to the controls that address it, and the rating reflects what those controls do in practice.
  • A clear trail for every rating: the rule, the facts about your business, the control and the evidence.
  • A priority list of the places where residual risk is highest, so you know where to put effort first.
  • A written assessment for your board and your examiners, in the form they expect to read.

How we do it

In stages, from facts to residual risk

  • We start with your facts: what you offer, who your customers are, where they are and how they reach you. Nothing goes into the assessment until you've confirmed it.
  • From those facts we build the list of BSA/AML obligations that apply to you, and rate the inherent risk each one carries.
  • We map your controls to those obligations and look at the evidence that they work, not just that they're written down.
  • A practitioner reviews the ratings, walks through the judgment calls with you and signs the assessment.

The risk assessment is where a BSA/AML program starts. When it's done, it tells you what your control testing and your independent test should look at first.

How the work is done

The audit you already buy, performed by an engine.

  1. Every record testedControls are tested against the full population of accounts and transactions, not a sample of twenty-five.
  2. Every requirement citedEach requirement the work runs against is cited to the rule it comes from, with the facts behind it labelled.
  3. Findings pricedFindings arrive priced in dollars, so remediation is ordered by what each gap is worth.
  4. A signed reportThe report is signed, and any reader can check that nothing in it changed after signing.

Pricing

Sized to your business

The price depends on your size and how many products, customer types and states are in scope.

Priced at scoping. How pricing works

The published method

How this is normally done

The regulator's and the standard-setter's own method for this work, explained in plain English and cited to the source. We have nothing to hide about how we do it: check our process against it.

What happens next

Three steps from here.

  1. 01

    A call with our founder

    Tell us about your business, your last assessment and when the next exam is. We'll tell you plainly whether we're the right fit.

  2. 02

    A written scope

    What the assessment covers, what you'll receive, the timeline and the price, in writing before you commit.

  3. 03

    The assessment

    We confirm your facts, rate the risk, score your controls, and a practitioner signs the assessment you receive.

Book a call with our founder