Home Sectors Services Publications About Contact Book a consultation
Service

ML/TF Risk Assessment

We assess the risk profile of the firm as a whole. Everything else is built on it, from how deeply a customer is checked to which monitoring scenarios run.

Duration
Two to five weeks
Format
Remote
Result
Methodology, risk map and mitigation plan
Book a consultation

Two different levels that get confused

Enterprise risk assessment

The view from above: how exposed the firm as a whole, its products, its customer base and its processes are to money laundering and terrorist financing.

Customer risk rating

An operational step inside customer due diligence: which risk level to assign to a person or a company, which then sets the depth of checks and the intensity of monitoring.

Confusing the two is expensive. The right order is this: first understand the overall risk profile of the firm, then tune customer rating and monitoring on top of it.

Without the enterprise assessment, customer scoring hangs in the air: the points are assigned and there is nothing to explain why they are what they are.

How the work runs

We start with a meeting and a data request: business model, products and services, customer base, geography, sales channels, the internal control rules in force and any earlier assessments.

Then we work through the risk factors, internal and external.

  • CustomersWho your customers are and how they differ from each other.
    High
  • Products and servicesWhich of them leave more room for abuse.
    Medium
  • GeographyCountries of presence, of transactions, and of the source of funds.
    High
  • Acquisition channelsHow a customer arrives and how far they can be verified.
    Medium
  • ProcessesHow they are built and where they break.
    Low
This is how the risk map looks in the report. The levels shown are illustrative.

We then apply the assessment methodology, qualitative or quantitative, and assign risk levels. Those become the risk matrix and the risk map, and from them come the recommendations and the mitigation plan. The work ends with a final report and a presentation to management or the responsible officer. Where needed, we help implement the measures and update the related sections of your rules.

What we need from you

  • A description of the business, its products and customer segments.
  • The internal control rules in force and earlier risk assessments, if any exist.
  • Customer and transaction statistics in anonymised form.
  • Access to the responsible staff for interviews.
  • Timely feedback.

What you get

Assessment methodology

A methodology adapted to your firm that can be shown and explained, rather than a formula lifted from someone else's document.

Risk matrix and risk map

Risk levels for each factor, in a form that works both for daily use and for showing to management or an inspector.

Report with conclusions

The factors, the risk levels, the conclusions and practical recommendations, not general words about the importance of control.

Mitigation plan

Specific measures with priorities and dates. Where needed we update the sections of your rules that deal with risk management.

Duration and format

The duration depends on the size and complexity of the firm, the number of products and branches, how complete the data is, whether on-site interviews are needed and how urgent the work is. A scheduled assessment runs at a calmer pace than one done just before an inspection.

Frequently asked questions

Can the assessment be done once and forgotten?

No. It is carried out at least once a year, and whenever the business or the law changes materially. A new product, a new market or a new acquisition channel changes the risk profile, and the previous assessment stops describing your firm.

Do the results have to be filed with the regulator?

For certain categories of supervised entity, yes. We help prepare and submit the document so that it answers questions rather than raising new ones.

How is your assessment different from a template one?

We use current methodology, take the national risk assessment and inspection practice into account, and give practical recommendations. A template produces a document, not an understanding of where your firm is thin.

What does it cost?

The fee depends on the size of the firm, the number of products and branches and the volume of data. We name an exact figure after a short conversation and fix the scope in the engagement terms.

Related materials

Cover: Jurisdiction Risk Matrix
Materials

Jurisdiction Risk Matrix

An AML country risk model covering 255 jurisdictions: an Excel file and a 17-page methodology guide. Three risk tiers, five indicators, change log.

View material EXCEL · PDF · 2026

Shall we look at your case?

Tell us the task and we will say whether it needs the full piece of work or a narrower one.

Book a consultation

Northhold Advisory is an independent consultancy. We are not affiliated with, and do not represent, the AFM of Kazakhstan, the AIFC (AFSA) or the National Bank of Kazakhstan.

Book a consultation