FREE COMPLIANCE TOOL
Business-Wide Risk Assessment UAE TCSP
Business-Wide Risk AssessmentUAE TCSP
Walk the full BRA methodology stage by stage. See what to assess, why it matters, and where it sits in law, then take the method into your own assessment. A Business-Wide Risk Assessment (BRA) is also called an Enterprise-Wide Risk Assessment (EWRA).
A generic ML/FT Risk Assessment Methodology treats every business the same. This walkthrough is built for the TCSP sector alone, tailored to the services you provide, the clients you act for, and your obligations under UAE law.
About the BRA
The business-wide risk assessment sits at institution level. It sets your overall risk profile and the controls proportionate to it.
Legal basis
A BRA is a legal obligation under a risk-based approach, where your controls, resources, and attention must match the risks you actually face.
Inherent risk: identification and assessment
Inherent risk is the risk that exists before any controls are applied. For a TCSP it is identified across five categories, then each identified factor is assessed.
1. Identification
List the factors that apply to your business under each of the five categories above.
2. Assessment
Rate each identified factor for likelihood and impact, then combine the two into a gross rating of Low, Medium, or High.
- Past data, including your client base, transaction history, alerts, and reports over the period under review.
- Forward projections, including planned growth and any new products, services, or markets that will change your exposure.
- The nature and size of your business, meaning the services you provide and the scale at which you operate.
- The UAE National Risk Assessment 2024 and any Sectoral Risk Assessment for the TCSP sector, which set the baseline your profile is measured against.
Quantify wherever you can. State, for example, that 12 of 480 clients are PEPs, or that 8 percent of clients are connected to higher-risk jurisdictions, rather than describing the exposure in words alone. Numbers make each rating defensible and let you measure the change at your next review.
Customer risk
Who you act for, and the people behind them. Most TCSP exposure starts here.
Geographical risk
Where the client, its owners, and its money are connected.
Product, service and transaction risk
The TCSP services you provide, and the activity patterns those relationships generate. Each service line and each pattern carries a different inherent exposure.
Delivery channel risk
How the relationship is established and how identity is verified.
Technology and proliferation financing risk
System integrity, and exposure to weapons proliferation networks.
Assess likelihood and impact
Assess every identified factor on two dimensions, and document both against the factor.
Likelihood
Rare, Possible, or Likely. How often the factor is expected to occur.
Impact
Low, Moderate, or Severe. The consequence to your entity if it occurs.
Gross (inherent) risk
Combine likelihood and impact for each factor and rate the result Low, Medium, or High. Gross risk is the inherent risk before any control is applied.
Controls and control effectiveness
Gross risk is now identified and assessed. The next step is to identify the controls you rely on and assess how effective they are, which together determine your net or residual risk. Identify a specific control for every factor, confirm it is in place and not merely written, then rate effectiveness as Effective, Partially Effective, or Not Effective, on real evidence.
- Sampling of compliance records and client files.
- Staff interviews confirming awareness and correct practice.
- Sanctions and PEP screening logs reviewed, with no unresolved alerts.
- No adverse findings from the most recent independent audit or compliance review.
- Training records confirming all relevant staff were trained in the last 12 months.
Net (residual) risk
Net risk is gross risk adjusted by control effectiveness, the risk that remains once controls are applied. A High gross with strong controls can come down to Medium. A Low gross with no controls can rise.
| Gross \ Controls | Effective | Partially Effective | Not Effective |
|---|---|---|---|
| Low gross | Low | Low | Medium |
| Medium gross | Low | Medium | High |
| High gross | Medium | High | High |
- Net Risk is determined for every factor after applying controls.
- Net Risk uses the correct logic, with Gross Risk adjusted by control effectiveness.
- No Net Risk rating is manually lowered without a documented reason.
- A High Gross Risk with only Partially Effective controls is not recorded as Low Net Risk.
Risk treatment and appetite
Risk appetite is the level of residual risk the business will accept after controls. It is set by the board, not by the assessor.
Residual above appetite
Add controls and record an action plan until residual sits within appetite.
Residual below the sector rating
Where residual sits below the NRA or sector rating, document a clear justification.
Documentation and governance
The assessment is documented, signed off, and kept current.
You have walked the full method
From legal basis to sign-off, here is the assessment lifecycle you stepped through. Identify, assess, control, derive net risk, treat what exceeds appetite, then document and sign off.
Vertex Compliance can prepare your assessment with you, or review one you have drafted, against FDL 10/2025, CR 134/2025, and the MoET Guidelines.
Ready to Defeat Your AML Compliance Obstacles?
Citadel Brings Revolution with Secure Solutions to AML Compliance Problems
What is the UAE TCSP Business-Wide Risk Assessment Tool?
Citadel365 built this tool specifically for Trust and Company Service Providers (TCSPs) in the UAE.
A Business-Wide Risk Assessment, also known as an Enterprise-Wide Risk Assessment (EWRA), is mandatory for all DNFBPs, including TCSPs operating in the UAE under Article 5 of Cabinet Resolution No. 134 of 2025. This TCSP EWRA tool walks you through exactly how to design your EWRA through a step-by-step procedure, in simple language.
The risk factors and control measures reflect the TCSP’s actual operations and the UAE regulatory expectations. The tool follows the 7-step EWRA methodology that aligns with Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025. It is designed specifically for compliance officers, MLROs, senior managers, and TCSP business owners in the UAE to fulfil their AML obligations.
Key Legislation Underpinning DNFBP Obligation for Business-Wide Risk Assessment (BWRA)
- Article 19, Federal Decree-Law No. 10 of 2025. Core preventive obligations, including the risk assessment.
- Article 5, Cabinet Resolution No. 134 of 2025. The risk-based approach and the BRA.
- Section 8, MoET Guidelines for DNFBPs (September 2025). Supervisory BRA methodology.
- Integrate the findings of the UAE National Risk Assessment 2024 and any relevant Sectoral Risk Assessment.
Why Must TCSPs in the UAE Have a Business-Wide Risk Assessment?
TCSPs are classified as DNFBPs under Article 3 of Cabinet Resolution No. 134 of 2025. The classification mandates TCSPs to comply with AML/CFT/CPF obligations, including conducting and documenting a Business-Wide Risk Assessment (BWRA). Further, the UAE NRA 2024 specifically mentions TCSPs as a medium risk for money laundering, requiring them to identify, understand and mitigate their ML/TF/PF risk exposure. Conducting BWRA helps TCSPs to ensure regulatory compliance, identify sector vulnerabilities, develop control measures, and avoid severe penalties.
Why Use This TCSP EWRA Tool?
The TCSP EWRA tool is a free guidance tool that provides TCSPs operating in the UAE with a systematic methodology for conducting EWRA. It tells you what your EWRA needs to cover, why each part matters, the common risk factors for a TCSP, how to score your risks, how to assess your controls, and how to develop a risk assessment that meets regulatory expectations.
The tool guides you through the EWRA methodology in a step-by-step process. An EWRA methodology without board approval, or a generic EWRA, often leads to regulatory penalties and actions during inspections. The EWRA TCSP tool helps you conduct an EWRA specific to your sector risks, adopt a risk-based approach, and align with AML/CFT/CPF obligations.
What Does the EWRA Methodology Cover?
The EWRA methodology covers the risk factors expected by authorities. It includes risk factors such as customers, geographies, product/services, delivery channels, transactions, technology and proliferation financing. EWRA helps determine gross risk (calculated before controls are applied), apply controls, and calculate the residual or net risk (gross risk adjusted by control effectiveness). Further, the EWRA methodology includes measures to apply when net risk exceeds appetite, as well as clear documentation of the risk assessment.
Step-by-Step Guide to the UAE TCSP Business-Wide Risk Assessment Tool
The UAE TCSP BWRA tool follows a 7-step procedure to guide you in assessing your business risk, with a summary section at the end. The following steps are covered:
Step 1: Legal Basis
EWRA is a legal obligation that requires TCSP to adopt a risk-based approach. TCSP must align their EWRA with the current Federal Law, Cabinet Resolution, MoET guidelines, and NRA findings.
Step 2: Inherent Risk: Identification and Assessment
TCSP, in the next step, requires calculating the inherent risk, which exists before any controls are applied. It includes assessing risks through various factors:
Customer Risk: Assess your clients- whether they’re a match on the sanctions lists, PEP lists, or adverse media, operate in a high-risk sector, are a shell company or are an entity with a complex business structure.
Geographical Risk: Identify whether the client, its beneficial owners, and funds are connected to high-risk jurisdictions to determine the risk.
Product, Service and Transaction Risk: Evaluate your TCSP services and customer transaction patterns to define the risk level.
Delivery Channel Risk: Onboarding remotely or through a third party poses a high risk. TCSP need to add such factors to their EWRA.
Technology and Proliferation Financing Risk: Include cyber risks, software malfunction risks, and risks from clients involved in dual-use goods or linked to weapons of mass destruction as factors in BRA.
After identifying risks from the above factors, TCSP should assess the likelihood (the frequency with which a factor is expected to occur) and impact (consequence if it occurs) to calculate the gross risk as low, medium or high.
Gross Risk = Likelihood x Impact
Step 3: Controls and Control Effectiveness
Identify the controls you put in practice, and evaluate their effectiveness. The controls must be identified for every risk factor, and their effectiveness must be rated based on how well they are applied.
Step 4: Net (Residual) Risk
Calculate the net risk by adjusting the gross risk with control effectiveness. It is basically the risk that remains after your controls are applied. For instance, with medium gross risk and ineffective controls, the net risk will be high.
Net Risk = Gross Risk Adjusted by Control Effectiveness
Step 5: Risk Treatment and Appetite
Once you have your Net Risk ratings, assess whether the residual risk is within your business appetite. Risk appetite is the level of risk your business is willing to accept after controls are applied. It is a business decision made by Senior Management or the Board, not the Compliance Officer alone. Further, you also check if the identified residual risk aligns with the NRA/SRA and document justification.
Step 6: Documentation and Governance
Document the EWRA, obtain sign-off from the compliance officer or MLRO, and obtain senior management approval. Additionally, review or update your EWRA every 12 months or in response to triggers such as regulatory changes, material incidents or SAR, operations with a new jurisdiction, engaging in a new product or service, or a change in client base.
Step 7: Summary
The TCSP EWRA tool provides a summary that ensures you walked through each step. Click on the print or save as PDF option to get a summarised view of the complete procedure. Ensure your assessment follows the complete procedure, and if you identify gaps, focus on minimising them or consult specialists.
Frequently Asked Questions About the TCSP Business-Wide Risk Assessment
An Enterprise-Wide Risk Assessment (EWRA) is a structured, comprehensive process by which a financial institution identifies, assesses, and prioritises its exposure to money laundering (ML) and terrorist financing (TF) risks across its entire organisation. It forms the foundation of an effective AML/CFT/CPF Program.
Yes. The EWRA must be reviewed and re-approved by your Board or Senior Management at least once every 12 months. You also need to update it sooner if something material changes, such as incorporating a new service, a new client segment, a change in your regulatory status, or an update to the FATF jurisdiction lists.
Operating as a TCSP in the UAE without a current documented EWRA is a breach of Federal Decree-Law No. 10 of 2025. Regulators review EWRA assessments during inspections. A missing, outdated, or generic EWRA may result in administrative fines or revocation of your licence.
Yes. TCSPs can use it as a gap analysis to go through the seven steps and check whether their existing document covers everything it should and whether the scoring still reflects their current business reality.
No. Input from board members, senior management, and the MLRO should all feed into the EWRA. The compliance officer coordinates and owns the process, but risk ratings, risk appetite, and final approval are not theirs alone to decide.Our Business is very small, just two or three people. Do we still need a full EWRA?
Yes. The obligation applies to all TCSPs regardless of size. However, the depth and complexity of your EWRA should be proportionate to your business.
Gross Risk is the level of risk your business faces before you apply compliance controls. Net Risk is what remains after your controls. The gap between the two is the controls, i.e., the compliance program, doing its job.
Build an EWRA that Meets Regulatory Expectations.
At Citadel365, we help you design tailored risk assessments that align with your specific TCSP business and strengthen your AML compliance.