Source: https://rotundahq.com/guides/what-regulators-look-for-firm-wide-risk-assessment Regulatory guide # What regulators look for in a firm-wide risk assessment How to make an assessment specific to your business, explain its conclusions and keep a useful review record. Updated 7 September 2026 ## Start with the business Firm-wide, business-wide and enterprise-wide risk assessment are terms used across different sectors. The useful starting point is your own business: its customers, services, jurisdictions and delivery channels. The FCA’s November 2025 review examined business-wide and customer assessments. It describes stronger practice as tailored, current and connected to how a firm manages risk. These examples include good practice beyond minimum requirements. [Read the FCA findings](https://www.fca.org.uk/publications/good-and-poor-practice/risk-assessment-processes-and-controls-firms-our-findings) ## Make the assessment easy to follow A practical way to structure the work is to ask five questions: 1. **What are we exposed to?** Describe the business and identify the material risks. Show which information informed the assessment. 2. **How did we reach the rating?** Keep evidence and reasoning alongside the score. Explain limitations in the available information. 3. **What changes the risk?** Connect the assessment to controls the firm actually operates and considers effective. 4. **Who reviewed it?** Keep dated evidence of challenge, decisions and approval, including the rationale for overrides. 5. **When will we revisit it?** Define review points and business changes that should prompt an update. This is an organising framework for the work, rather than a substitute for your sector’s rules or guidance. ## Use supervisory findings as a review prompt The FCA identified weaknesses including generic assessments and poor records of discussion, challenge and approval. Its corporate-finance survey separately found that 11% of responding firms had no documented business-wide assessment. That statistic relates to the responding population, not all regulated firms. [Read the survey context](https://www.fca.org.uk/news/press-releases/gaps-financial-crime-oversight-corporate-finance-firms) ## Keep firm-level and client-level work connected The SRA’s 2024–25 AML report discusses weaknesses in firm-wide assessments, policies and controls, and client and matter assessments. These are related parts of a firm’s arrangements; completing one does not complete the others. [Read the SRA annual report](https://media.sra.org.uk/sra/research-publications/aml-annual-report-2024-25/) A sensible internal review follows a sample of decisions from the business assessment into the relevant procedure and then into a client or matter file. Look for an explanation that remains consistent at each step. ## Keep a record you can maintain Give the assessment a named owner and review date. Record the version, the information used and significant changes since the prior assessment. Keep unresolved questions visible and assign someone to resolve them. Before sign-off, ask a reviewer who did not prepare the document to follow one conclusion back to its evidence. Gaps in that explanation are useful signals for further work. ## Related reading [Enforcement examples and fines](https://rotundahq.com/guides/risk-assessment-failures-and-fines) [Changing legal-sector supervision](https://rotundahq.com/guides/legal-sector-aml-supervision) This guide provides general information, not legal advice. Check the current source material and requirements applicable to your firm. Software does not confer regulatory approval. [More guides](https://rotundahq.com/guides)[Explore EWRA](https://rotundahq.com/ewra)