Nineteen References, One Dependency: The Business-Wide Risk Assessment in AMLA's Draft Ongoing Monitoring Guidelines

Nineteen References, One Dependency: The Business-Wide Risk Assessment in AMLA's Draft Ongoing Monitoring Guidelines

AMLA's draft guidelines on ongoing monitoring refer to the business-wide risk assessment 19 times across 57 pages. This article maps every reference, sets out how each one is framed, and looks at what the pattern means for firms designing a monitoring framework.

On 3 June 2026 the Authority for Anti-Money Laundering and Countering the Financing of Terrorism published its Consultation Paper on draft Guidelines on ongoing monitoring of a business relationship under Article 26(5) of Regulation (EU) 2024/1624. The consultation closed on 3 September 2026, and AMLA has said the final guidelines will be issued in Q4 2026.

The draft is structured in three parts: general principles applying to both guidelines, Guideline 1 on keeping customer documents, data or information up to date, and Guideline 2 on the transaction and activity monitoring framework. There are 95 numbered paragraphs in total.

Two features of the draft are particularly noticeable. The first is the risk-based treatment of expired identity documents, which are not required to be re-collected by default. The second is the confirmation that automated monitoring is not mandatory and that the deployment of such tools is not, in itself, an indicator of effectiveness. Both are significant. This article looks at something less visible, which is how consistently the draft points back to the same upstream assessment.

1. The count

The phrase business-wide risk assessment appears 19 times across the 57-page consultation paper. What the assessment itself has to contain is set by Article 10 of the AMLR and is covered separately; this article is about how the monitoring guidelines depend on it.

Thirteen of those occurrences sit inside the numbered Guidelines, spread across 12 paragraphs. Paragraph 34 contains the phrase twice, once in its opening sentence and again in point (f). The other occurrences are in paragraphs 5, 25, 28, 35, 41, 42, 43, 46, 52, 81 and 83. The remaining six sit in the framing and accompanying material: once in the executive summary, twice in section 3.2 on AMLA's approach, once in the section 3.3 interaction table, once in the section 3.4 description of Guideline 2, and once in the impact assessment.

Two further variants appear. The abbreviation BWRA is used once, in the section 3.3 table. The phrase "business risk assessment" appears once, at paragraph 85. Counting every variant separately gives a lexical total of 21 references to the same concept.

A note on the count. The section 3.3 occurrence sits in a column-based table and can be lost when PDF text is extracted out of reading order. The 19-count above was checked against the published paper with that table occurrence included.

2. How each reference is framed

The framings are worth reading as a set, because the references connect the assessment to particular aspects of monitoring design, calibration, review or feedback rather than simply acknowledging that it exists.

ParagraphContextWhat the assessment does there
5General principlesThe monitoring framework should be aligned with the risks identified in it
25Event-driven reviewsThe type and level of sophistication of trigger-detection processes should be based on it
28Detecting trigger eventsWhether automated or semi-automated systems are needed is assessed having regard to it, among other factors
34, openingMonitoring framework, general principlesThe framework is based on it
34, point (f)Monitoring framework, general principlesThe framework should be designed to be effective at implementation in addressing the risks identified in it
35Limited or no transaction and activity data, or no transaction processingAlternative measures should be aligned with it
41Enhanced scrutinyEnhanced scrutiny is tailored to it and to the customer's risk profile
42Manual, automated or semi-automatedDesign and intensity should be risk-based and mitigate the risks identified in it
43Adapting to new typologiesEarlier framework decisions should be revisited where needed, including as part of the review of the assessment
46Manual processes and controlsWhether manual controls suffice is assessed on the basis of it
52Link between CDD and monitoringMonitoring outputs may have implications for it
81Internal controls and ongoing reviewPeriodic review and testing should ensure that the framework remains effective and aligned with the risks identified in it
83Internal controls and ongoing reviewDefined monitoring outcomes are reassessed in light of it

Most of that vocabulary points in the same direction: the assessment is being used as an input to monitoring decisions. Paragraphs 43 and 52 qualify the pattern, by connecting the two review processes and by creating a feedback route from monitoring back into the assessment.

3. The direction of travel

Eleven of the thirteen references treat the business-wide risk assessment as an input to the design, calibration, review or operation of the monitoring framework.

One runs the other way. Paragraph 52 provides that where monitoring outputs indicate emerging or evolving ML/TF risks, obliged entities should consider whether these have implications for their business-wide risk assessment.

Paragraph 43 belongs in neither category. It says earlier decisions about the monitoring framework should be revisited where needed, and identifies the review of the business-wide risk assessment as one occasion when that may happen. It links the two review processes rather than pointing in one direction.

Practitioner interpretation. The following is my reading, not a finding stated by AMLA.

The balance of these provisions suggests a sequence rather than two parallel exercises: the assessment informs the framework, the framework generates information that may feed back, and the two reviews are expected to be connected. Where a firm's governance treats the business-wide risk assessment and the monitoring framework as separate annual tasks owned by different people, the connection paragraph 43 assumes may not exist in practice.

4. Reading the frequency against section 3.3

Thirteen mentions means little in isolation. Section 3.3 provides useful context, but only if the counting methods are kept separate.

Section 3.3 of the consultation paper sets out how these guidelines interact with other Level 1, Level 2 and Level 3 measures. Six are listed:

  • Guidelines under Article 10(4) AMLR, on the business-wide risk assessment
  • Article 9 AMLR and future guidelines under Article 9(4),on internal policies, procedures and controls
  • RTS under Article 19(9) AMLR, defining business relationships, occasional and linked transactions
  • RTS under Article 28(1) AMLR, on customer due diligence requirements
  • Guidelines under Article 69(5) AMLR, on indicators of suspicious activity or behaviour
  • Article 8 AMLAR and Article 40(3) AMLD, on AML/CFT supervisory methodology and risk-based supervision

There are two different ways of looking at these cross-references, and they should not be confused.

If the test is an explicit citation to the legal basis, then inside the 95 numbered paragraphs Article 28(1) appears twice, Articles 19(9) and 69(5) once each, while Article 10(4),Article 9, Article 8 AMLAR and Article 40(3) AMLD are not expressly cited at all.

The result for the business-wide risk assessment is different in kind. Article 10(4) is named in the section 3.3 table, but it is not expressly cited anywhere in the 95 numbered paragraphs. What appears there instead, thirteen times, is the business-wide risk assessment referred to substantively. It is the repeated use of the concept, rather than repeated citation of the article, that is the relevant finding. The two figures measure different things and cannot be read as a single ranking.

The Article 9 figure needs a qualification. It records that the guidelines contain no explicit reference to Article 9 or to future guidelines under Article 9(4). Policies and procedures as a subject matter appear throughout the draft, including at paragraphs 8, 24, 45 and 77.

Paragraph 37 also refers once each to AMLA's outsourcing mandate under Article 18(8) and reliance on other obliged entities under Article 50. Those are additional cross-references, not two of the six measures listed in section 3.3.

AMLA's own description in the section 3.3 table is that a robust business-wide risk assessment underpins the risk-based approach and is essential for applying the core principles of ongoing monitoring. The distribution of references inside the operative text is consistent with that description.

5. Monitoring-design flexibilities and what they rest on

The draft guidelines are generous on proportionality. AMLA is explicit that the deployment of automated tools is not in itself an indicator of effectiveness, and that manual processes and controls may be sufficient depending on the entity's circumstances.

Several of the most consequential monitoring-design flexibilities are expressly tied to the business-wide risk assessment.

  • Paragraph 28. Whether automated or semi-automated systems are needed to capture changes in customer information is assessed having regard to the nature, risks and complexity of the business, the size of the obliged entity and the overall business-wide risk assessment. Where the business model is limited in scale, risk and complexity, manual or semi-automated processes may be a proportionate option.
  • Paragraph 35. Obliged entities that structurally have limited or no access to transaction and activity data, or that do not process transactions, should apply proportionate and effective alternative measures aligned with their business-wide risk assessment.
  • Paragraph 42. The design and intensity of the monitoring framework should be risk-based and mitigate the risks identified in the business-wide risk assessment. Obliged entities should document the rationale for the chosen framework, its design and, where needed, any adjustments, and should be able to demonstrate its functionality, rationale and effectiveness to competent authorities on request.
  • Paragraph 46. Whether manual processes and controls are sufficient to achieve effective monitoring outcomes is assessed on the basis of the business-wide risk assessment.

Read together, paragraphs 42 and 46 put a fair amount of weight on a document drafted for a different mandate, which makes how the assessment is built a live question for the monitoring framework rather than a separate exercise.

Not every proportionality decision in the draft works this way. Others turn on the customer's risk profile, the information already held, the nature of the products or services, the business model, the size of the entity, or objective legal and technical constraints. The pattern above is specific to the design and intensity of the monitoring framework.

Practitioner interpretation. The following is my reading of the consequences, not a finding stated by AMLA.

Where these particular flexibilities are relied on, the business-wide risk assessment becomes an important part of the supervisory rationale, because the provisions repeatedly connect monitoring choices to it. Paragraph 42 separately says obliged entities should document the rationale for the chosen monitoring framework, its design and, where needed, any adjustments, and should be able to demonstrate the framework's functionality, rationale and effectiveness. The practical issue is therefore whether the assessment and the documented monitoring rationale are consistent with one another, rather than whether every part of that rationale sits inside the assessment itself.

6. What AMLA says outside the guidelines text

The framing sections state the position more directly than the numbered paragraphs do.

The executive summary records that across the guidelines AMLA emphasises proportionality, cross-sectoral applicability, and the importance of a sound business-wide risk assessment as the basis for effective ongoing monitoring.

Section 3.2, on the simplification agenda, explains that the text focuses on effective outcomes rather than prescribing how they should be achieved, allowing each entity to determine the appropriate approach based on its business-wide risk assessment. The same section records that the guidelines have been aligned with AMLA's separate mandate on business-wide risk assessment.

Section 3.4, describing the structure of Guideline 2, states that monitoring should be based on the nature, risks and complexity of the business and the size of the obliged entity, as well as on the entity's overall business-wide risk assessment and its knowledge of its customers.

The most direct statement is in the impact assessment, in the reasoning for the preferred option on structure. AMLA writes that the approach emphasises that obliged entities "should first have a clear understanding of their business-wide risk assessment" before establishing their ongoing monitoring framework, and that such an assessment ultimately forms the necessary basis for complying with Article 26 of the AMLR.

AMLA acknowledges in the same passage that obtaining a sufficiently comprehensive understanding of those risks may entail additional initial costs, particularly for smaller obliged entities. It nevertheless describes the assessment as the necessary basis for complying with Article 26 and applying the draft Guidelines appropriately, linking that approach to the avoidance of formalistic or tick-the-box compliance.

7. Questions worth asking of your own assessment

Practitioner interpretation. The questions below are drawn from the framings set out above. They are my suggestions for applying the draft, not requirements set out by AMLA.

Working back from the thirteen in-text occurrences suggests that, if the business-wide risk assessment is to perform the role the draft assigns to it, a high-level list of risk categories may not be enough. The following are practitioner questions rather than requirements expressly stated by AMLA.

  • Are risks identified at a level of granularity that a monitoring rule, scenario or threshold could be calibrated against?
  • Does the assessment cover products, services, customers, geographic exposure and distribution channels, which is the list paragraph 5 attaches to the alignment obligation?
  • Are emerging risks addressed, and is there a route for monitoring outputs to feed back into the assessment, as paragraph 52 contemplates?
  • Where the framework is manual or partly manual, does the assessment contain the reasoning that supports that choice, or does the reasoning sit only in a separate policy?
  • Is the review cycle for the assessment connected in practice to review of the monitoring framework, as paragraph 43 contemplates?
  • Could someone reading only the assessment reconstruct why the monitoring framework looks the way it does?

Paragraph 42 does not require that reasoning to sit in the business-wide risk assessment itself. It does say that obliged entities should document that rationale and be able to demonstrate the framework's functionality, rationale and effectiveness. The practical question is whether the assessment and that documented rationale tell a coherent story when read together.

8. Status and timing

This is a draft. The consultation closed on 3 September 2026 and AMLA has said the final guidelines will be issued in Q4 2026. Paragraph numbering and wording may change, and the analysis above is tied to the draft text as published on 3 June 2026.

Of the seven consultation questions, two ask specifically about the impact of the guidelines on compliance costs and operational processes.

Practitioner interpretation. My expectation, not an AMLA statement: the cost questions make the proportionality provisions one of the more likely areas for drafting proposals, since that is where respondents can point to concrete operational impact.

Whatever changes, the relationship described here is already spread across multiple parts of the draft rather than resting on a single provision. It appears in the general principles, in both guidelines, in the internal controls section, in the framing chapters and in the impact assessment.

Sources

Authority for Anti-Money Laundering and Countering the Financing of Terrorism, Consultation Paper on Draft Guidelines on ongoing monitoring of a business relationship under Article 26(5) of Regulation (EU) 2024/1624, Frankfurt am Main, 3 June 2026. Consultation page.

Regulation (EU) 2024/1624 of the European Parliament and of the Council of 31 May 2024 (AMLR). Official Journal.

All counts in this article were taken from the published 57-page consultation paper and include the occurrence in the section 3.3 interaction table.

Know what is coming before it arrives. The final guidelines are expected in Q4 2026, and their monitoring-design provisions point repeatedly back to the Article 10 assessment. Our Business-Wide Risk Assessment seminar is built on Article 10 of the AMLR and works through the assessment step by step, including the level of risk identification these monitoring provisions assume.

AML/CTF Business-Wide Risk Assessment seminar
Free AMLR Article 10 BWRA workbook
Business-Wide Risk Assessment Under AMLR

This article is for information and training purposes. It is not legal advice. The guidelines discussed are in draft form and subject to change before the final text is issued.

Nikolas Demetriades

Article by Nikolas Demetriades

Published 07 Sep 2026