Skip to content
Blog

AML Entity-Wide Risk Assessment in the UAE: EWRA, Customer & MoET Risk Assessment Guide

Learn how AML Entity-Wide Risk Assessment (EWRA) works in the UAE, including customer, transaction, geographic, product, and delivery channel risks, along with CRA and MoET risk assessment requirements.

Mashhooda Khan
Mashhooda Khan
23 Sep 2026  ·  6 min read
AML Entity-Wide Risk Assessment in the UAE: EWRA, Customer & MoET Risk Assessment Guide

An AML risk assessment is a structured process that helps a business identify, evaluate, and document its exposure to money laundering and terrorist financing. However, AML risk assessment is a broad term that can refer to different types of assessments, including Customer Risk Assessment (CRA), Entity-Wide Risk Assessment (EWRA), and MoET Risk Assessment.

This guide focuses primarily on the Entity-Wide Risk Assessment (EWRA), which evaluates an organisation's overall exposure to AML/CFT risks across its customers, products and services, geographic exposure, transactions, and delivery channels. It also explains how EWRA differs from customer-level risk assessment and other applicable regulatory risk assessment requirements in the UAE.

Firms working with ADS Auditors often use an EWRA to establish a structured, risk-based compliance framework that can support regulatory reviews and ongoing AML/CFT management.

What Are the Different Types of AML Risk Assessment?

Before conducting an AML risk assessment, businesses should identify which type of assessment they need. The scope and purpose can differ depending on the business, regulator, and assessment level.

Customer Risk Assessment (CRA)

A Customer Risk Assessment (CRA) focuses on the AML/CFT risk associated with an individual customer or business. It may consider factors such as customer type, ownership structure, geographical connections, PEP status, business activity, expected transactions, and other relevant risk indicators.

The outcome of a CRA can help determine the appropriate level of customer due diligence and whether enhanced due diligence or additional monitoring may be appropriate.

Entity-Wide Risk Assessment (EWRA)

An Entity-Wide Risk Assessment (EWRA) examines the AML/CFT risk exposure of the organisation as a whole. Unlike a CRA, which focuses on an individual customer, an EWRA considers the broader risk profile of the business.

An EWRA may assess:

  • Customer risk

  • Geographic risk

  • Product and service risk

  • Transaction risk

  • Delivery channel risk

  • The effectiveness of existing AML/CFT controls

The EWRA should identify inherent risk, assess control effectiveness, determine residual risk, and compare the results against the organisation's documented risk appetite.

MoET Risk Assessment

Businesses supervised by the Ministry of Economy and Tourism (MoET) should also consider the applicable regulatory requirements and sector-specific risks relevant to their activities. The assessment should reflect the nature of the business, its customers, products and services, geographic exposure, transactions, and other relevant AML/CFT risk factors.

Therefore, businesses should establish which regulator and supervisory framework applies to them before preparing or updating their risk assessment.

What a Sound Entity-Wide Risk Assessment Actually Covers

The Entity-Wide Risk Assessment (EWRA) should provide a comprehensive view of the organisation's AML/CFT exposure. It should not simply reproduce customer risk scores or rely on a generic template.

The assessment should consider the organisation's inherent risks, the effectiveness of its existing controls, and the resulting residual risk.

Key risk factors commonly considered within an EWRA include customer risk, geographic risk, product and service risk, transaction risk, and delivery channel risk.

Risk Factor

What It Measures

Common UAE Example

Customer risk

The types and characteristics of customers served

PEPs, high-risk customers, or complex ownership structures

Geographic risk

Countries and jurisdictions connected to customers, transactions, or business activities

Transactions involving higher-risk jurisdictions

Product and service risk

How products or services could potentially be misused

Cash-intensive services, virtual assets, or complex cross-border services

Transaction risk

The nature, value, volume, frequency, and patterns of transactions

Unusual high-value transactions, rapid movement of funds, or activity inconsistent with the customer's expected profile

Delivery channel risk

How customers access products and services

Remote or non-face-to-face onboarding

Understanding Transaction Risk

Transaction risk is a major component of an AML risk assessment and should be assessed separately rather than being treated only as part of customer risk.

Transaction risk considers whether the nature and pattern of transactions could increase the organisation's exposure to money laundering or terrorist financing. Relevant factors may include:

  • Transaction value

  • Transaction frequency

  • Transaction volume

  • Source and destination of funds

  • Geographic destination

  • Cash activity

  • Unusual or complex transaction patterns

  • Transactions inconsistent with the customer's known business or expected activity

  • Rapid movement of funds between accounts or jurisdictions

For an EWRA, businesses should look beyond individual transactions and consider overall transaction patterns across their customer base and business activities. Transaction monitoring results, suspicious transaction reports, unusual activity alerts, and other relevant data can provide important information when determining the organisation's inherent and residual risk.

Why Regulators Keep Asking for It

Supervisory focus in the UAE is not limited to whether a risk assessment exists. Businesses should be able to demonstrate that the assessment is based on appropriate data, uses a documented methodology, and informs their AML/CFT controls.

A generic assessment with unchanged scores year after year may fail to reflect changes in the business, customer base, products, transactions, geographic exposure, or regulatory environment.

The EWRA should therefore function as a living document, with findings used to inform policies, procedures, customer due diligence, transaction monitoring, training, and other compliance controls.

The Difference Between Inherent and Residual Risk

A sound EWRA should distinguish between inherent and residual risk.

Inherent risk represents the organisation's exposure before considering the effectiveness of its controls. Controls may include customer due diligence, sanctions screening, transaction monitoring, employee training, policies, procedures, and management oversight.

Residual risk represents the exposure that remains after those controls are taken into account.

For example, a business may have significant inherent transaction risk because it handles high-value or complex transactions. Effective transaction monitoring, customer due diligence, escalation procedures, and management oversight may reduce the resulting residual risk.

The assessment should show this movement clearly using a documented and consistently applied methodology.

Steps to Conduct an Entity-Wide Risk Assessment

Start by defining the scope of the Entity-Wide Risk Assessment (EWRA), including the entities, products, services, customers, transactions, jurisdictions, and delivery channels covered.

Next, collect relevant data relating to:

  • Customer profiles and risk classifications

  • Transaction volumes and values

  • Geographic exposure

  • Products and services

  • Delivery channels

  • Suspicious activity and transaction monitoring

  • Existing AML/CFT controls

Identify and score the relevant inherent risks using a defined methodology. Evaluate the effectiveness of existing controls and calculate residual risk.

The organisation should then compare the results against its documented risk appetite and identify areas requiring stronger controls or additional resources.

Finally, senior management should review and approve the EWRA and use its findings to strengthen the organisation's AML Policy Framework, policies, procedures, controls, monitoring measures, and training.

What an AML Risk Score Actually Measures

An AML risk score is a numerical representation of the level of risk identified through a documented assessment methodology. Depending on the type of assessment, the score may incorporate customer, geographic, product and service, transaction, and delivery channel factors.

For an EWRA, the methodology should reflect the organisation's overall business model and risk exposure rather than simply applying a customer-level scoring model to the entire organisation.

The score itself is less important than the methodology behind it. Businesses should be able to explain how risk factors were selected, weighted, scored, and adjusted based on control effectiveness.

Common Mistakes That Undermine the Whole Exercise

Common weaknesses include:

  • Treating the assessment as an annual compliance formality

  • Confusing Customer Risk Assessment with Entity-Wide Risk Assessment

  • Failing to include transaction risk as a separate risk factor

  • Copying scores from a previous assessment without reviewing current data

  • Launching new products or services without reassessing risk

  • Ignoring changes in customer profiles or geographic exposure

  • Relying entirely on software-generated risk scores

  • Failing to connect risk assessment findings with actual AML/CFT controls

A strong EWRA should reflect the organisation's current business model and provide evidence that identified risks are actively managed.

Where to Start If You Are Behind

Begin with a gap analysis against the methodology and requirements applicable to your business and regulator. Determine whether you need a Customer Risk Assessment, Entity-Wide Risk Assessment, MoET-related risk assessment, or a combination of these assessments.

Identify the data already available and determine what additional information is required, including customer, transaction, geographic, product, and delivery-channel data.

If the organisation lacks internal expertise, engaging specialists familiar with UAE AML/CFT requirements can help establish an appropriate methodology. Proper AML registration records and current AML training for staff can also support the overall effectiveness of the AML/CFT control framework.


Frequently Asked Questions

AML risk assessment can refer to different types of assessments depending on the purpose and regulatory context. These include Customer Risk Assessment (CRA), Entity-Wide Risk Assessment (EWRA), and MoET Risk Assessment. A CRA focuses on an individual customer, while an EWRA evaluates the organisation's overall AML/CFT exposure.
The main risk factors may include customer risk, geographic risk, product and service risk, transaction risk, and delivery channel risk. The specific factors and weighting should reflect the organisation's business model, activities, customers, and applicable regulatory requirements.
Transaction risk refers to the risk arising from the nature, value, frequency, volume, pattern, and other characteristics of transactions conducted through a business. Examples include unusual high-value transactions, rapid movement of funds, complex transactions, or activity that does not appear consistent with the customer's expected profile.
A Customer Risk Assessment (CRA) evaluates the AML/CFT risk associated with an individual customer. An Entity-Wide Risk Assessment (EWRA) evaluates the organisation's overall exposure across customers, products and services, geographic areas, transactions, and delivery channels.
An AML risk score represents the level of risk identified using a documented risk assessment methodology. Depending on the assessment, factors can include customer type, geographic exposure, products and services, transaction activity, and delivery channels. The methodology should be documented, consistently applied, and appropriate to the organisation's business model and regulatory requirements.
Mashhooda Khan
About the Author

Mashhooda Khan

Head - Accounts & Compliance
Join the Conversation

Leave a Comment

Have a question or a thought on this article? Share it below and our team will be in touch.

Your email is never published. We reply within 24 hours.