How to run an AML risk assessment for a crypto business: risk factors, a scoring matrix, the five pillars of a BSA/AML program and what the EU AMLR expects.

An AML risk assessment is a documented analysis of how a business could be used for money laundering, terrorist financing or sanctions evasion, how likely and serious each risk is, and how well its controls reduce it. For a crypto exchange or other virtual asset business, it is the foundation of the whole AML compliance program: it decides where to apply enhanced due diligence, what transaction monitoring rules to run and where to spend compliance budget.
This guide covers the enterprise-wide (or business-wide) risk assessment for crypto firms: the risk factors to cover, a sample scoring matrix, the US "five pillars" of a BSA/AML program, and what the EU's Anti-Money Laundering Regulation expects. It ends with a short note for users on why risk ratings affect their accounts.
A risk-based approach works at two levels, and it helps to keep them apart:
If the business-wide assessment is weak, every downstream control is set at the wrong level, which is why supervisors usually ask for it first.
The EU Anti-Money Laundering Regulation, Regulation (EU) 2024/1624 (AMLR), applies from 10 July 2027. Crypto-asset service providers (CASPs) are included in its definition of financial institutions and are therefore obliged entities. Article 10 sets out the business-wide risk assessment. Firms must identify and assess their money laundering and terrorist financing risks, and the risk of not implementing or evading targeted financial sanctions, taking into account at least:
Article 10 also requires a fresh assessment before launching new products, services, delivery channels or technologies, or entering a new customer segment or country. The assessment must be documented, kept up to date and regularly reviewed, drawn up by the compliance officer, approved by the management body and made available to supervisors on request. Article 10(4) required AMLA to issue guidelines on its minimum content by 10 July 2026.
For crypto firms, recital 30 adds that the assessment should consider transactions with self-hosted addresses, and Article 79 bars CASPs from keeping anonymous crypto-asset accounts or accounts that allow the anonymisation or increased obfuscation of transactions, including through anonymity-enhancing coins. Licensing under MiCA is a separate regime; see our guide to the CASP licence under MiCA.
In the US, businesses that exchange or transmit convertible virtual currency are generally money services businesses (MSBs), as FinCEN set out in its 2019 guidance FIN-2019-G001. Our sibling guide on the money transmitter licence covers registration. MSBs must run an AML program under 31 CFR 1022.210, which must be written and "commensurate with the risks" of the business, and must include at minimum:
These are the classic "four pillars". Banks and other covered financial institutions have a fifth: risk-based customer due diligence, which under 31 CFR 1020.210 means understanding the nature and purpose of customer relationships to build a customer risk profile, and ongoing monitoring. Crypto firms with bank charters or bank partners will often be held to all five.
Today's rules do not explicitly require a written risk assessment. The FFIEC BSA/AML examination manual says that while it is "not a specific legal requirement", a well-developed risk assessment helps a bank identify its risks and design controls, and it describes a two-step method: identify risk categories (products, services, customers, geography), then analyse the data in each. That may change. On 10 April 2026 FinCEN proposed a rule to reform AML/CFT program requirements, under which internal policies, procedures and controls would include risk assessment processes. Comments closed on 9 June 2026, and the rule was still at the proposal stage when we checked the Federal Register on 9 October 2026.
Both regimes organise risk the same way. The AMLR's Annex I groups risk variables into customer, product/service/transaction and delivery channel risk, and Annex III adds higher-risk geography. For a crypto firm, that translates into:
There is no required format. The FFIEC manual says examiners have "no expectation for a particular method or format". A common approach scores inherent risk, assesses control effectiveness and derives residual risk. The table below is an illustrative example, not a regulatory template; your own weights should come from your data.
| Risk area | Inherent risk (1-5) | Key controls | Control strength | Residual risk |
|---|---|---|---|---|
| Customers: share of high-risk and corporate clients | 4 | Risk-based onboarding, KYB, PEP and adverse media screening, EDD | Strong | Medium |
| Products: OTC desk and fiat ramps | 4 | Source of funds checks, trade limits, senior approval for large trades | Adequate | Medium-high |
| Transactions: self-hosted wallet transfers | 3 | Wallet screening, address ownership checks, Travel Rule process | Adequate | Medium |
| Geography: users near high-risk jurisdictions | 3 | Geo-blocking, IP and document checks, sanctions screening | Strong | Low-medium |
| Channels: affiliates and API partners | 2 | Partner due diligence, contractual controls, audits | Weak | Medium |
Inherent risk is often scored as likelihood multiplied by impact, using measurable indicators such as volumes, customer counts and alert rates. Control strength should be backed by evidence, such as testing results and audit findings, not by the existence of a policy. Where residual risk is above the firm's risk appetite, the assessment should end in a dated action plan with owners.
Monitoring tools should reflect the result. Many vendors let firms tune rules and risk scores to their own assessment. iDenfy's transaction monitoring software, for example, lets compliance teams write custom rules that produce configurable risk scores. Our comparison of crypto transaction monitoring software covers other options, and the crypto AML compliance guide covers the wider program.
Your exchange's risk assessment decides which customers get extra checks. If you use a higher-risk product, move funds from a flagged wallet, or live in or connect from a higher-risk country, you may be asked for more documents even if you have done nothing wrong. Our guide to AML red flags in crypto lists the patterns that tend to trigger reviews. JewelSwap's DeFi apps are non-custodial and do not run these checks themselves; see KYC in DeFi explained.
An AML risk assessment is a documented analysis of how a business could be used for money laundering, terrorist financing or sanctions evasion, how likely and serious each risk is, and how well existing controls reduce it. It drives decisions on due diligence, monitoring and resources.
A business-wide assessment looks at the whole firm: customers, products, transactions, countries and channels. A customer risk assessment rates each individual customer using that framework and decides how much due diligence they receive.
In the US, they are internal policies, procedures and controls; a designated compliance officer; ongoing staff training; independent testing; and risk-based customer due diligence. MSBs, which include most US crypto exchanges, are required to have the first four under 31 CFR 1022.210.
In the EU, yes: Article 10 of the AMLR, which applies from 10 July 2027, requires a documented business-wide risk assessment approved by the management body. In the US, current rules do not explicitly require one, but examiners expect it, and a FinCEN proposal from April 2026 would make risk assessment processes part of program requirements.
The EU AMLR requires it to be kept up to date and regularly reviewed, and reassessed before launching new products, channels, technologies or markets. Many firms review it at least once a year and after any material change.
Customer type, products such as OTC and fiat ramps, transactions with self-hosted wallets and exposure to mixers or other high-risk services, geography including sanctioned and high-risk countries, and remote or partner-led delivery channels.
This article is educational and is not legal advice. Legal references are to Regulation (EU) 2024/1624 (the AMLR, applicable from 10 July 2027), 31 CFR 1022.210 and 1020.210, FinCEN guidance FIN-2019-G001, the FFIEC BSA/AML examination manual and FinCEN's proposed rule published on 10 April 2026, all checked on 9 October 2026. The scoring matrix is an illustrative example, not a regulatory template. Rules change; check the current versions before relying on them.