Free Risk Assessment Template: Your Foundation for a Sound Compliance Program
- Apr 7, 2023
- 3 min read
Updated: Jul 28
Last updated: July 25, 2026 | By: Kristin Parker, SVP of Compliance & Operations
Key Summary
A BSA/AML risk assessment maps the institution's products, services, customers/members, and geographies to the risks they carry, and it anchors how examiners scope a BSA exam. RiskScout's free downloadable template gives compliance teams a structured starting point, whether for a regular review or an expansion into a new market.
Risk Assessments are like oil changes: they're crucial to keep things running smoothly, they can be hard to prioritize with a busy schedule, and ignoring them can lead to big trouble down the road.
After seeing how difficult it is to find a good free Risk Assessment template in the wild, the RiskScout team decided to create our own to help guide you through your next review. Whether you're conducting a regular check or looking to expand into a new market, we hope this template gets you started on the right foot.
What a BSA/AML Risk Assessment Covers
Per the FFIEC BSA/AML Examination Manual, a risk assessment identifies the institution's specific risk categories, its products, services, customers/members, and geographic locations, and then analyzes that information to gauge how much risk each one carries. The assessment drives everything downstream: monitoring rules, due diligence depth, and where compliance staff spend their time. The template below turns that framework into a working document.
Frequently Asked Questions
What is a BSA/AML risk assessment?
A structured analysis of where money laundering and financial crime risk enters the institution, and how existing controls address each risk. The FFIEC framework has two steps: identify the specific risk categories that apply to the institution, then analyze them to decide how much attention each one needs.
How often should a BSA/AML risk assessment be updated?
There is no fixed regulatory interval. Most institutions update it at least annually and any time the risk profile changes: a new product, a new market such as cannabis or MSB banking, significant growth, or a merger. An assessment that predates the institution's current risk profile is the kind of gap examiners notice first.
What do examiners expect a risk assessment to show?
That the institution understands its own risk rather than a generic one: risk categories specific to its actual customer/member base and markets, analysis supporting each rating, and a clear link between the assessment and the program's controls. A template provides the structure; the institution's own data makes it credible.
How does a risk assessment connect to daily BSA work?
The ratings feed monitoring and due diligence, so higher-risk customers get deeper reviews and closer attention. RiskScout's BSA/AML Platform ties dynamic risk scoring to actual customer/member behavior, which keeps the risk assessment connected to what monitoring does day to day.
Meet the Author:

Kristin Parker, SVP of Compliance & Operations
Kristin is a seasoned expert in BSA/AML and fraud prevention, with extensive experience building and implementing monitoring programs for higher-risk industries. She has contributed to significant updates in the FFIEC manual, provided practical, risk-based AML guidance at industry events, and played a key role in the development of RiskScout’s innovative, actionable BSA solutions. Recognized by her peers as PBC's 2024 Compliance Person of the Year, Kristin continues to champion efficient, technology-driven approaches that empower financial institutions to confidently manage regulatory requirements.




