By Rotunda · Published 11 September 2026
An enterprise-wide risk assessment (EWRA), also known as a business-wide risk assessment (BWRA), brings together the risks a business faces, the controls it relies on and the risk that remains. Start with the business you actually operate, then build an evidence-backed explanation of your conclusions.
EWRA, BWRA and firm-wide: three names for one assessment
In financial crime work, these terms describe the same thing: an assessment across the whole organisation. EWRA means enterprise-wide risk assessment; BWRA means business-wide risk assessment; legal practices usually say firm-wide risk assessment. Use whichever your regulator uses. The label alone does not determine scope: record the entities, activities and risk types covered. A broader enterprise risk assessment may also cover operational, strategic and other risks outside this guide.
The FCA’s November 2025 review uses BWRA and distinguishes it from customer risk assessment. It highlights business-specific analysis, evidence for control effectiveness and clear connections between inherent and residual risk. Read the FCA’s findings.
1. Define the scope and owners
Record the legal entities, products, locations and review period. Identify who prepares the assessment, who challenges it and who approves it. Separate money laundering and terrorist financing from other risk types where their drivers or controls differ. Explain any exclusions so a reviewer can understand the boundary.
2. Gather information you already hold
For a payments business, a useful starting pack includes customer or merchant counts, transaction values and volumes, geographical exposure, products, onboarding channels and distribution arrangements. Add control-testing results, incidents, overdue reviews and known data gaps. Record each source, owner and reporting date; do not mix annual activity with a point-in-time population without explaining it.
3. Describe and assess inherent risk
Explain the exposure before giving credit for controls. What could happen through each customer group, product, country or channel? Combine figures with business context. If you use ratings or weights, define them before scoring and explain why they fit the business. A high-risk pocket should remain visible even when a business-wide average is lower.
4. Evaluate the controls against the risks
Map each material risk to the controls intended to address it. Distinguish a control being documented from it operating effectively. Record the evidence reviewed, exceptions and limitations. A policy’s existence is not evidence that staff follow it or that a system works as intended.
5. Explain residual risk and actions
Use the agreed methodology to reach a conclusion about the risk remaining after controls. Keep the calculation and judgement traceable. Where the result is outside appetite, identify an action, an accountable owner and a completion date. Explain overrides rather than adjusting scores until they look comfortable.
A worked payments example
Fictional scenario: a payments firm has 4,000 merchants, including 320 in a higher-risk segment. That is 8% of merchants, but the segment accounts for 22% of transaction value. Looking only at customer counts would miss part of the exposure.
The assessor describes the segment’s products and settlement routes, then reviews onboarding checks and transaction-monitoring evidence. A sample of 40 reviews contains six overdue cases. This is a control weakness to investigate; the sample does not establish a failure rate for the entire population.
The assessment records the exposure, sample selection, exceptions and reasoning for its residual-risk conclusion. An action assigns the overdue reviews to an owner with a deadline and a follow-up test. There is no universal score for this example: the conclusion depends on the firm’s methodology and the wider evidence.
6. Challenge, approve and keep it current
Ask reviewers to challenge assumptions, missing populations and unsupported conclusions. Preserve their questions and the responses alongside the approved version. Set a review date and triggers for earlier reassessment, such as a new product, acquisition or material control failure.
What should the final record contain?
- Business scope, assessment period and accountable owners.
- Data sources, limitations and the rating methodology.
- Risk exposures and supporting figures.
- Controls, evidence of effectiveness and residual-risk reasoning.
- Actions, challenge, approval and the next review arrangements.
Can you do an EWRA without consultants?
An internal team can prepare the assessment when it has the knowledge, information and capacity to do so. Software can organise the work and generate reporting, but judgement and approval remain with the business. Seek specialist input where the team cannot resolve a material gap.
Explore Rotunda’s EWRA and BWRA software, join the EWRA pilot or try the payments assessment with fictional data.
For more context, read what regulators look for in a risk assessment. This guide is a practical starting point; apply the requirements and guidance relevant to your business.
Putting this into practice? Explore Rotunda’s EWRA platform to see how risk inputs, controls, review and reporting connect, or work through the existing payments and legal demos.