BRA / EWRA Methodology Navigator | Citadel365
Citadel365Business-Wide Risk Assessment, UAE TCSP
Step 1 of 80% complete
TCSP sector tool

Business-Wide Risk AssessmentUAE TCSP

Walk the full BRA methodology stage by stage. See what to assess, why it matters, and where it sits in law, then take the method into your own assessment. A Business-Wide Risk Assessment (BRA) is also called an Enterprise-Wide Risk Assessment (EWRA).

Federal Decree-Law No. 10 of 2025 Cabinet Resolution No. 134 of 2025 MoET Guidelines, Section 8 UAE NRA 2024
Sector-specific
Purpose-built for Trust and Company Service Providers

A generic ML/FT Risk Assessment Methodology treats every business the same. This walkthrough is built for the TCSP sector alone, tailored to the services you provide, the clients you act for, and your obligations under UAE law.

This is a methodology walkthrough. It lists the risk factors as reference, it does not select or score them for you, and it does not calculate your residual risk.

About the BRA

The business-wide risk assessment sits at institution level. It sets your overall risk profile and the controls proportionate to it.

Stage 1

Legal basis

A BRA is a legal obligation under a risk-based approach, where your controls, resources, and attention must match the risks you actually face.

Article 19Federal Decree-Law No. 10 of 2025. Core preventive obligations, including the risk assessment.
Article 5Cabinet Resolution No. 134 of 2025. The risk-based approach and the BRA.
Section 8MoET Guidelines for DNFBPs (Revised V2, September 2025). Supervisory BRA methodology.
NRA 2024Integrate the findings of the UAE National Risk Assessment 2024 and any relevant Sectoral Risk Assessment.
TipWhen you document your EWRA methodology, make sure you cite the article each requirement rests on, not just the conclusion.
Phase, inherent risk

Inherent risk: identification and assessment

Inherent risk is the risk that exists before any controls are applied. For a TCSP it is identified across five categories, then each identified factor is assessed.

Customer risk
Who you act for, and the people behind them, including UBOs, PEPs, and sanctioned parties.
Geographical risk
Where the client, its owners, and its funds are connected, read against the FATF lists.
Product, service and transaction risk
The TCSP services you provide, and the activity patterns those relationships generate.
Delivery channel risk
How the relationship is established and how identity is verified.
Technology and proliferation financing risk
System and screening integrity, and exposure to weapons proliferation and dual-use goods.
Guidance. As a TCSP, your business-wide risk assessment must consider all five categories. The stages that follow take each in turn, so you first identify the factors that apply to your business, then assess them for likelihood and impact.

1. Identification

List the factors that apply to your business under each of the five categories above.

2. Assessment

Rate each identified factor for likelihood and impact, then combine the two into a gross rating of Low, Medium, or High.

Base it on evidence, not impression
  • Past data, including your client base, transaction history, alerts, and reports over the period under review.
  • Forward projections, including planned growth and any new products, services, or markets that will change your exposure.
  • The nature and size of your business, meaning the services you provide and the scale at which you operate.
  • The UAE National Risk Assessment 2024 and any Sectoral Risk Assessment for the TCSP sector, which set the baseline your profile is measured against.

Quantify wherever you can. State, for example, that 12 of 480 clients are PEPs, or that 8 percent of clients are connected to higher-risk jurisdictions, rather than describing the exposure in words alone. Numbers make each rating defensible and let you measure the change at your next review.

TipIdentify first, then score.
Inherent risk, factor group 1 of 5

Customer risk

Who you act for, and the people behind them. Most TCSP exposure starts here.

1
Client or its UBOs appear on the UAE Local Terrorist List, the UNSC Consolidated List, or any other sanctions list.
A match on the UAE Local or UNSC lists is a freeze trigger, not a scoring input.
FDL Art. 19
2
Client or its UBOs have a negative history or criminal allegations involving financial crime.
Adverse media and prior allegations raise the inherent profile before any control.
3
Client or any UBO is a PEP or associated with a PEP, including undisclosed or indirectly connected PEPs.
PEP status drives Enhanced Due Diligence and source-of-wealth scrutiny.
CR 134 Art. 16
4
Client base includes High Net Worth Individuals.
Wealth concentration and complex affairs increase layering and source-of-funds risk.
5
Client operates in a high-risk sector vulnerable to ML or TF.
Read sector exposure against the UAE National Risk Assessment 2024.
6
Opaque, multi-layered, or cross-border ownership, or bearer shares or nominee arrangements that obscure the beneficial owner.
Structures that hide the natural person in control are a core TCSP red flag.
7
Newly formed entities with no clear commercial rationale, or clients reluctant to disclose beneficial ownership.
Shells without a business reason, and resistance to disclosure, both raise the rating.
TipAssess the beneficial owner, not just the named client. Risk usually sits one layer down.
Listed for reference. In a full assessment each factor is rated for likelihood and impact, never assumed.
Inherent risk, factor group 2 of 5

Geographical risk

Where the client, its owners, and its money are connected.

1
Clients or their UBOs connected to jurisdictions on the FATF Call for Action or Increased Monitoring lists.
Framing against the live lists keeps the assessment accurate over time.
CR 134 Art. 23
2
Clients or their UBOs based in jurisdictions known for financial secrecy or as tax havens.
Secrecy regimes weaken transparency of ownership and source of funds.
3
Clients or their UBOs operating in or through jurisdictions of significant sanctions or proliferation-financing concern.
Geographic links to PF concern feed both the customer and the PF assessment.
TipRead against the live FATF lists rather than memorised country names, since the lists change.
Listed for reference. In a full assessment each factor is rated for likelihood and impact, never assumed.
Inherent risk, factor group 3 of 5

Product, service and transaction risk

The TCSP services you provide, and the activity patterns those relationships generate. Each service line and each pattern carries a different inherent exposure.

1
Engagements involving the management of bank, savings, or securities accounts.
Handling client accounts brings you closer to the flow of funds.
2
Engagements involving corporate or ownership restructuring services.
Restructuring can be used to obscure control or relocate value.
3
Acting as, or arranging, a nominee shareholder or nominee director.
Nominee arrangements can mask the true beneficial owner.
4
Formation or administration of companies, trusts, or similar legal arrangements.
Core TCSP activity, and a recognised vector for misuse of legal persons.
5
Provision of a registered office, business address, or correspondence address.
Address services can lend apparent substance to a shell entity.
6
High-value or unusual cash activity relative to the client profile.
Cash intensity above the expected level raises the inherent rating.
7
Complex or unusually structured transactions with no clear economic or lawful purpose.
Structure without a business reason is a classic layering signal.
8
Rapid movement of funds, or flows inconsistent with the stated rationale.
Velocity and mismatch against stated purpose both warrant scrutiny.
TipRate each service line separately, and compare activity against the client's stated profile, not an abstract average.
Listed for reference. In a full assessment each factor is rated for likelihood and impact, never assumed.
Inherent risk, factor group 4 of 5

Delivery channel risk

How the relationship is established and how identity is verified.

1
Client relationships established remotely without face-to-face interaction.
Non face-to-face onboarding needs compensating identity controls.
2
Clients onboarded through an intermediary or introducer.
Reliance on a third party shifts part of the CDD, never the responsibility.
CR 134 Art. 20
3
Onboarding that relies on third-party CDD or documents certified overseas.
Certification quality and the certifier's standing both affect reliability.
CR 134 Art. 20
TipReliance on an introducer shifts the work, not the responsibility. The duty stays with you.
Listed for reference. In a full assessment each factor is rated for likelihood and impact, never assumed.
Inherent risk, factor group 5 of 5

Technology and proliferation financing risk

System integrity, and exposure to weapons proliferation networks.

1
Cyber risks such as hacking or phishing, and technology failures affecting AML compliance, for example a malfunction of screening software.
If the screening tooling fails, the whole control framework is exposed.
2
Proliferation-financing risk connected to weapons of mass destruction.
PF carries the same freeze obligations as terrorist financing for listed parties.
3
Clients involved in the trade of dual-use goods.
Dual-use trade is a recognised PF vector and needs specific scrutiny.
TipA screening tool that silently fails is worse than none, because it creates false comfort.
Listed for reference. In a full assessment each factor is rated for likelihood and impact, never assumed.
Inherent risk, assessment

Assess likelihood and impact

Assess every identified factor on two dimensions, and document both against the factor.

Likelihood

Rare, Possible, or Likely. How often the factor is expected to occur.

Impact

Low, Moderate, or Severe. The consequence to your entity if it occurs.

TipScore likelihood and impact independently before combining them, so a dramatic impact does not inflate a rare event.
Inherent risk, outcome

Gross (inherent) risk

Combine likelihood and impact for each factor and rate the result Low, Medium, or High. Gross risk is the inherent risk before any control is applied.

Gross Risk = Likelihood × Impact
TipResist netting off controls here. Controls belong to the next phase, not to the gross rating.
Phase, controls

Controls and control effectiveness

Gross risk is now identified and assessed. The next step is to identify the controls you rely on and assess how effective they are, which together determine your net or residual risk. Identify a specific control for every factor, confirm it is in place and not merely written, then rate effectiveness as Effective, Partially Effective, or Not Effective, on real evidence.

1
Real-time screening at onboarding and at the transaction stage, with CDD and timely periodic reviews.
FDL Art. 19; CD 74/2020
2
Enhanced Due Diligence for high-risk customers.
CR 134 Art. 5
3
PEP identification and adverse media screening.
CR 134 Art. 16
4
A prohibition policy for FATF Call for Action jurisdictions, with sanctions matches treated as unacceptable.
CR 134 Art. 23
5
Source of funds declaration, document verification, and digital identity verification at onboarding.
6
Third-party introducer or agent agreements, with verification of their documents.
CR 134 Art. 20
7
A cash transaction policy with a defined AED threshold.
8
Record retention for a minimum of five years, and ongoing monitoring.
FDL Art. 19; CR 134 Art. 25
Base the effectiveness rating on evidence
  • Sampling of compliance records and client files.
  • Staff interviews confirming awareness and correct practice.
  • Sanctions and PEP screening logs reviewed, with no unresolved alerts.
  • No adverse findings from the most recent independent audit or compliance review.
  • Training records confirming all relevant staff were trained in the last 12 months.
TipA written policy is not a control until it is operating. Rate what happens in practice, not what is on paper.
Identifying and rating controls is your responsibility. This guide states the requirement, it does not rate them for you.
Phase, net risk

Net (residual) risk

Net risk is gross risk adjusted by control effectiveness, the risk that remains once controls are applied. A High gross with strong controls can come down to Medium. A Low gross with no controls can rise.

Net Risk = Gross Risk adjusted by Control Effectiveness
Residual risk reference matrix
Gross \ ControlsEffectivePartially EffectiveNot Effective
Low grossLowLowMedium
Medium grossLowMediumHigh
High grossMediumHighHigh
Integrity checks on the Net Risk ratings
  • Net Risk is determined for every factor after applying controls.
  • Net Risk uses the correct logic, with Gross Risk adjusted by control effectiveness.
  • No Net Risk rating is manually lowered without a documented reason.
  • A High Gross Risk with only Partially Effective controls is not recorded as Low Net Risk.
TipIf a High gross becomes Low net, expect to justify it. Partially effective controls rarely drop a rating two bands.
Phase, treatment

Risk treatment and appetite

Risk appetite is the level of residual risk the business will accept after controls. It is set by the board, not by the assessor.

Residual above appetite

Add controls and record an action plan until residual sits within appetite.

Residual below the sector rating

Where residual sits below the NRA or sector rating, document a clear justification.

TipAppetite is a board decision. The assessor measures, the board accepts. Keep the two roles separate in the record.
Phase, governance

Documentation and governance

The assessment is documented, signed off, and kept current.

Art. 22Compliance Officer or MLRO sign-off on the assessment.
NormSenior management approval, and a next review within 12 months as the accepted norm rather than a fixed statutory deadline, since the law frames updates as ongoing.
Review is also triggered by
New product or serviceNew jurisdictionRegulatory changeMaterial incident or SARChange in client base
TipAn unsigned assessment is a draft. Sign-off is what turns it into the firm's stated position.
Methodology complete

You have walked the full method

From legal basis to sign-off, here is the assessment lifecycle you stepped through. Identify, assess, control, derive net risk, treat what exceeds appetite, then document and sign off.

Inherent risk
Legal basis
Risk factor identification
Likelihood and impact
Gross risk
Controls
Control identification
Effectiveness rating on evidence
Net risk
Gross adjusted by controls
Integrity checks
Treatment and governance
Compare against appetite
Sign-off and review triggers
Ready to run your own BRA?

Vertex Compliance can prepare your assessment with you, or review one you have drafted, against FDL 10/2025, CR 134/2025, and the MoET Guidelines.

This guide explains the BRA methodology under UAE AML/CFT law. It does not constitute legal advice, and your business-wide risk assessment should be prepared and signed off by your appointed compliance officer.
Copyright Citadel365 by Vertex Compliance. For UAE DNFBPs.citadel365.com
Table of Contents

Ready to Defeat Your AML Compliance Obstacles?

Citadel Brings Revolution with Secure Solutions to AML Compliance Problems

What is the UAE TCSP Business-Wide Risk Assessment Tool?

Citadel365 built this tool specifically for Trust and Company Service Providers (TCSPs) in the UAE.

A Business-Wide Risk Assessment, also known as an Enterprise-Wide Risk Assessment (EWRA), is mandatory for all DNFBPs, including TCSPs operating in the UAE under Article 5 of Cabinet Resolution No. 134 of 2025. This TCSP EWRA tool walks you through exactly how to design your EWRA through a step-by-step procedure, in simple language.

The risk factors and control measures reflect the TCSP’s actual operations and the UAE regulatory expectations. The tool follows the 7-step EWRA methodology that aligns with Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025. It is designed specifically for compliance officers, MLROs, senior managers, and TCSP business owners in the UAE to fulfil their AML obligations.

Key Legislation Underpinning DNFBP Obligation for Business-Wide Risk Assessment (BWRA)

  • Article 19, Federal Decree-Law No. 10 of 2025. Core preventive obligations, including the risk assessment.
  • Article 5, Cabinet Resolution No. 134 of 2025. The risk-based approach and the BRA.
  • Section 8, MoET Guidelines for DNFBPs (September 2025). Supervisory BRA methodology.
  • Integrate the findings of the UAE National Risk Assessment 2024 and any relevant Sectoral Risk Assessment.

Why Must TCSPs in the UAE Have a Business-Wide Risk Assessment?

TCSPs are classified as DNFBPs under Article 3 of Cabinet Resolution No. 134 of 2025. The classification mandates TCSPs to comply with AML/CFT/CPF obligations, including conducting and documenting a Business-Wide Risk Assessment (BWRA). Further, the UAE NRA 2024 specifically mentions TCSPs as a medium risk for money laundering, requiring them to identify, understand and mitigate their ML/TF/PF risk exposure. Conducting BWRA helps TCSPs to ensure regulatory compliance, identify sector vulnerabilities, develop control measures, and avoid severe penalties.

Why Use This TCSP EWRA Tool?

The TCSP EWRA tool is a free guidance tool that provides TCSPs operating in the UAE with a systematic methodology for conducting EWRA. It tells you what your EWRA needs to cover, why each part matters, the common risk factors for a TCSP, how to score your risks, how to assess your controls, and how to develop a risk assessment that meets regulatory expectations.
The tool guides you through the EWRA methodology in a step-by-step process. An EWRA methodology without board approval, or a generic EWRA, often leads to regulatory penalties and actions during inspections. The EWRA TCSP tool helps you conduct an EWRA specific to your sector risks, adopt a risk-based approach, and align with AML/CFT/CPF obligations.

What Does the EWRA Methodology Cover?

The EWRA methodology covers the risk factors expected by authorities. It includes risk factors such as customers, geographies, product/services, delivery channels, transactions, technology and proliferation financing. EWRA helps determine gross risk (calculated before controls are applied), apply controls, and calculate the residual or net risk (gross risk adjusted by control effectiveness). Further, the EWRA methodology includes measures to apply when net risk exceeds appetite, as well as clear documentation of the risk assessment.

Step-by-Step Guide to the UAE TCSP Business-Wide Risk Assessment Tool

The UAE TCSP BWRA tool follows a 7-step procedure to guide you in assessing your business risk, with a summary section at the end. The following steps are covered:

Step 1: Legal Basis

EWRA is a legal obligation that requires TCSP to adopt a risk-based approach. TCSP must align their EWRA with the current Federal Law, Cabinet Resolution, MoET guidelines, and NRA findings.

Step 2: Inherent Risk: Identification and Assessment

TCSP, in the next step, requires calculating the inherent risk, which exists before any controls are applied. It includes assessing risks through various factors:

Customer Risk: Assess your clients- whether they’re a match on the sanctions lists, PEP lists, or adverse media, operate in a high-risk sector, are a shell company or are an entity with a complex business structure.

Geographical Risk: Identify whether the client, its beneficial owners, and funds are connected to high-risk jurisdictions to determine the risk.

Product, Service and Transaction Risk: Evaluate your TCSP services and customer transaction patterns to define the risk level.

Delivery Channel Risk: Onboarding remotely or through a third party poses a high risk. TCSP need to add such factors to their EWRA.

Technology and Proliferation Financing Risk: Include cyber risks, software malfunction risks, and risks from clients involved in dual-use goods or linked to weapons of mass destruction as factors in BRA.

After identifying risks from the above factors, TCSP should assess the likelihood (the frequency with which a factor is expected to occur) and impact (consequence if it occurs) to calculate the gross risk as low, medium or high.

Gross Risk = Likelihood x Impact

Step 3: Controls and Control Effectiveness

Identify the controls you put in practice, and evaluate their effectiveness. The controls must be identified for every risk factor, and their effectiveness must be rated based on how well they are applied.

Step 4: Net (Residual) Risk

Calculate the net risk by adjusting the gross risk with control effectiveness. It is basically the risk that remains after your controls are applied. For instance, with medium gross risk and ineffective controls, the net risk will be high.

Net Risk = Gross Risk Adjusted by Control Effectiveness

Step 5: Risk Treatment and Appetite

Once you have your Net Risk ratings, assess whether the residual risk is within your business appetite. Risk appetite is the level of risk your business is willing to accept after controls are applied. It is a business decision made by Senior Management or the Board, not the Compliance Officer alone. Further, you also check if the identified residual risk aligns with the NRA/SRA and document justification.

Step 6: Documentation and Governance

Document the EWRA, obtain sign-off from the compliance officer or MLRO, and obtain senior management approval. Additionally, review or update your EWRA every 12 months or in response to triggers such as regulatory changes, material incidents or SAR, operations with a new jurisdiction, engaging in a new product or service, or a change in client base.

Step 7: Summary

The TCSP EWRA tool provides a summary that ensures you walked through each step. Click on the print or save as PDF option to get a summarised view of the complete procedure. Ensure your assessment follows the complete procedure, and if you identify gaps, focus on minimising them or consult specialists.

Frequently Asked Questions About the TCSP Business-Wide Risk Assessment

Build an EWRA that Meets Regulatory Expectations.

At Citadel365, we help you design tailored risk assessments that align with your specific TCSP business and strengthen your AML compliance.