Start with the business
Firm-wide, business-wide and enterprise-wide risk assessment are terms used across different sectors. The useful starting point is your own business: its customers, services, jurisdictions and delivery channels.
The FCA’s November 2025 review examined business-wide and customer assessments. It describes stronger practice as tailored, current and connected to how a firm manages risk. These examples include good practice beyond minimum requirements. Read the FCA findings
Make the assessment easy to follow
A practical way to structure the work is to ask five questions:
- What are we exposed to? Describe the business and identify the material risks. Show which information informed the assessment.
- How did we reach the rating? Keep evidence and reasoning alongside the score. Explain limitations in the available information.
- What changes the risk? Connect the assessment to controls the firm actually operates and considers effective.
- Who reviewed it? Keep dated evidence of challenge, decisions and approval, including the rationale for overrides.
- When will we revisit it? Define review points and business changes that should prompt an update.
This is an organising framework for the work, rather than a substitute for your sector’s rules or guidance.
Use supervisory findings as a review prompt
The FCA identified weaknesses including generic assessments and poor records of discussion, challenge and approval. Its corporate-finance survey separately found that 11% of responding firms had no documented business-wide assessment. That statistic relates to the responding population, not all regulated firms. Read the survey context
Keep firm-level and client-level work connected
The SRA’s 2024–25 AML report discusses weaknesses in firm-wide assessments, policies and controls, and client and matter assessments. These are related parts of a firm’s arrangements; completing one does not complete the others. Read the SRA annual report
A sensible internal review follows a sample of decisions from the business assessment into the relevant procedure and then into a client or matter file. Look for an explanation that remains consistent at each step.
Keep a record you can maintain
Give the assessment a named owner and review date. Record the version, the information used and significant changes since the prior assessment. Keep unresolved questions visible and assign someone to resolve them.
Before sign-off, ask a reviewer who did not prepare the document to follow one conclusion back to its evidence. Gaps in that explanation are useful signals for further work.
Related reading
Enforcement examples and finesThis guide provides general information, not legal advice. Check the current source material and requirements applicable to your firm. Software does not confer regulatory approval.
Putting this into practice? Explore Rotunda’s EWRA platform to see how risk inputs, controls, review and reporting connect, or work through the existing payments and legal demos.