A recent FIC Guidance Note places risk assessment at the heart of an effective Risk Management and Compliance Programme (RMCP). Find out how a well-developed business risk assessment (BRA) can help your institution identify its vulnerabilities and implement appropriate controls.
Before introducing a new product, service or technology, a business will usually consider the cost, operational requirements and potential benefits. But has it also considered how the change could be misused for money laundering, terrorist financing or proliferation financing?
This is one of the principles reinforced by the Financial Intelligence Centre’s (FIC) updated Guidance Note 7B, which took effect on 3 August 2026 and replaced Revised Guidance Note 7A.
The Guidance Note shows that risk assessment is not simply a periodic compliance exercise. It should help an accountable institution make decisions before changes are introduced and respond when its business or client risks change.
Against this backdrop, it is not enough for an accountable institution simply to have an RMCP on file. It should be able to show that the programme reflects the risks the institution faces.
It starts with the BRA
Accountable institutions are businesses listed in Schedule 1 to the Financial Intelligence Centre Act (FIC Act). They include financial service providers (FSPs), crypto asset service providers (CASPs), legal practitioners, property practitioners and high-value goods dealers, among others.
To protect itself from being exploited for financial crime, an accountable institution first needs to understand where and how it is vulnerable. This is the purpose of a BRA.
A BRA identifies and assesses the institution’s inherent risks, considers whether its controls are effective and determines the residual risk that remains once those controls have been applied. Its findings should then inform the policies, procedures, systems and controls contained in the RMCP.
Put simply, an accountable institution cannot develop an effective RMCP without first conducting an effective BRA. If it has not identified and properly assessed its risks, its RMCP may not contain all the controls needed to manage them.
The BRA identifies where the institution is vulnerable. The RMCP explains what the institution will do about those vulnerabilities. If the BRA is incomplete or generic, the RMCP is likely to contain the same weaknesses.
That means an effective RMCP should not simply repeat the requirements of the FIC Act. It should reflect the institution’s actual clients, products, services, technologies, delivery channels and geographic exposure. It should also influence how the institution operates, including who it deals with and how it deals with them.
Assess risk before introducing change
Guidance Note 7B strengthens this relationship between the BRA and RMCP by showing that risk assessment must continue to inform decisions as the business evolves.
Before introducing a new product, service, business process, technology or delivery mechanism, an accountable institution must identify and assess the related money laundering, terrorist financing and proliferation financing risks. This assessment must happen before the change is implemented.
Consider a business planning to introduce online onboarding, artificial intelligence or digital identity verification. These tools may make onboarding and ongoing due diligence faster, reduce manual work and support real-time client screening. However, their benefits do not remove the need to understand their risks.
Before implementation, the institution should ask:
- Does the technology change how clients are identified, verified or monitored?
- Could it provide anonymity or make beneficial ownership more difficult to establish?
- Could false information or fraudulent documents be used to bypass its controls?
- Does it reduce meaningful human oversight?
- Does it rely on automated decisions, external providers or non-face-to-face interaction?
- Will transaction monitoring, sanctions screening, recordkeeping and reporting remain effective?
- Could criminals exploit gaps between connected systems?
- What happens if the system or one of its data sources becomes unavailable?
An online onboarding system may, for example, rely on real-time access to external databases to verify client information. If one of those databases is unavailable, the institution may not be able to complete its usual due diligence process. Its RMCP should explain what must happen in this situation. This could include delaying the onboarding process or following an approved manual fallback procedure.
The assessment and resulting controls must be recorded in the BRA and RMCP before the product, service or system is launched. The risks must also be reassessed if the product, service, process or technology changes significantly later.
Turn identified risks into action
Identifying a risk is only useful if the business acts on it. Once a new or changed risk has been identified, it should be recorded in the BRA and translated into appropriate controls in the RMCP.
Depending on the risk, the institution may need to introduce or strengthen a control, update a procedure, adjust its monitoring or train employees. The RMCP should clearly explain:
- who is responsible for assessing new risks
- how findings must be reported and escalated
- who approves changes to the BRA and RMCP
- how the resulting controls will be implemented and communicated
This process should not rest with the compliance function alone. Employees working with clients, transactions or systems may be the first to identify an emerging risk. They should know where to report it and what happens next.
The institution should also set clear triggers for reviewing its BRA outside its scheduled review. These could include changes to its products, technologies, client base, delivery channels, ownership structure or geographic exposure.
Client risk can change
Guidance Note 7B also cautions against assuming that low-income or underserved clients automatically present a low risk. Income is only one consideration. It does not, on its own, show where funds come from, how a product may be used or whether the client’s activity is consistent with what the institution knows about them.
A low-risk classification must be based on an assessment of the relevant risk factors. Only then can the institution decide whether simplified due diligence is appropriate.
The assessment should also be revisited if the client later displays unusual or suspicious behaviour. The institution should investigate the activity, reassess the client and decide whether it has reasonable grounds to submit a suspicious or unusual transaction or activity report under Section 29 of the FIC Act.
If a report is submitted, the institution must stop applying simplified due diligence and conduct enhanced due diligence without informing the client that a report has been filed.
Do your documents reflect what happens in practice?
A simple way to test whether the BRA, RMCP and everyday operations remain aligned is to ask employees:
Why are we following this process, and why are we doing it this way?
If they cannot answer, either employees do not fully understand the RMCP or its documented requirements no longer reflect what happens in practice. This points to a need for further training, an update to the BRA, RMCP and procedures or both.
A gap analysis against Guidance Note 7B can help the accountable institution identify where changes are required. It should examine how risks are identified and documented, whether the updated risk indicators have been considered and whether the controls in the RMCP remain appropriate.
Having an RMCP on file does not, on its own, make it effective. Its value depends on the quality of the risk assessment behind it. After all, an RMCP can only manage the risks the institution has taken the time to identify and understand.
