top of page

Want more great resources?

Subscribe to receive all the latest industry research, trends, and updates directly in your inbox.

Free Risk Assessment Template: Your Foundation for a Sound Compliance Program

  • Apr 7, 2023
  • 3 min read

Updated: Jul 28

Last updated: July 25, 2026 | By: Kristin Parker, SVP of Compliance & Operations


Key Summary

A BSA/AML risk assessment maps the institution's products, services, customers/members, and geographies to the risks they carry, and it anchors how examiners scope a BSA exam. RiskScout's free downloadable template gives compliance teams a structured starting point, whether for a regular review or an expansion into a new market.

Risk Assessments are like oil changes: they're crucial to keep things running smoothly, they can be hard to prioritize with a busy schedule, and ignoring them can lead to big trouble down the road.


After seeing how difficult it is to find a good free Risk Assessment template in the wild, the RiskScout team decided to create our own to help guide you through your next review. Whether you're conducting a regular check or looking to expand into a new market, we hope this template gets you started on the right foot.


What a BSA/AML Risk Assessment Covers

Per the FFIEC BSA/AML Examination Manual, a risk assessment identifies the institution's specific risk categories, its products, services, customers/members, and geographic locations, and then analyzes that information to gauge how much risk each one carries. The assessment drives everything downstream: monitoring rules, due diligence depth, and where compliance staff spend their time. The template below turns that framework into a working document.

Frequently Asked Questions

What is a BSA/AML risk assessment?

A structured analysis of where money laundering and financial crime risk enters the institution, and how existing controls address each risk. The FFIEC framework has two steps: identify the specific risk categories that apply to the institution, then analyze them to decide how much attention each one needs.

There is no fixed regulatory interval. Most institutions update it at least annually and any time the risk profile changes: a new product, a new market such as cannabis or MSB banking, significant growth, or a merger. An assessment that predates the institution's current risk profile is the kind of gap examiners notice first.

That the institution understands its own risk rather than a generic one: risk categories specific to its actual customer/member base and markets, analysis supporting each rating, and a clear link between the assessment and the program's controls. A template provides the structure; the institution's own data makes it credible.

The ratings feed monitoring and due diligence, so higher-risk customers get deeper reviews and closer attention. RiskScout's BSA/AML Platform ties dynamic risk scoring to actual customer/member behavior, which keeps the risk assessment connected to what monitoring does day to day.


Meet the Author:

A smiling headshot of Kristin Parker facing the camera

Kristin Parker, SVP of Compliance & Operations

Kristin is a seasoned expert in BSA/AML and fraud prevention, with extensive experience building and implementing monitoring programs for higher-risk industries. She has contributed to significant updates in the FFIEC manual, provided practical, risk-based AML guidance at industry events, and played a key role in the development of RiskScout’s innovative, actionable BSA solutions. Recognized by her peers as PBC's 2024 Compliance Person of the Year, Kristin continues to champion efficient, technology-driven approaches that empower financial institutions to confidently manage regulatory requirements.


Stay Up to Date

Want to keep your finger on the pulse of the latest industry news, trends, and data? 

Enter your email and be the first to know when there's new content added. 

bottom of page