Skip to main content

AML firm-wide risk assessment: a template for accountants

By Syed Husnain Khalid · Published 8 October 2026 · Last checked 8 October 2026 · 10 min read

Drafted with AI. Each claim was checked against the primary sources listed below by AI on 8 October 2026; a person has not reviewed it yet.

Short answer

Every UK accounting practice must have a written firm-wide risk assessmentunder regulation 18 of the Money Laundering Regulations 2017. It must identify the practice’s money laundering and terrorist financing risks, cover the five risk factors in regulation 18(2)(b), take account of information published by its supervisor and reflect the size and nature of the practice.

This guide is for the owner of a UK accounting practice, or the person responsible for its anti-money laundering (AML) compliance, who has to produce the assessment, keep it current and then defend it when the supervisor asks for it. Two things make the timing worth fixing now: the accountancy sector’s guidance restates the law as it stood on 1 July 2026, and HMRC’s manual for supervised businesses was updated on 16 July 2026. We built a similar approval step into Filyst, our case management product for immigration firms. The sections cover the duty, who it binds, the five risk factors, scoring, review, approval, a copyable template and the penalty for having none.

What is a firm-wide risk assessment?

A firm-wide risk assessment is the written document that records the steps a practice takes to identify and assess its money laundering and terrorist financing risks. Regulation 18(1) of the Money Laundering Regulations 2017 requires every relevant person to take those steps, and regulation 18(4) requires an up-to-date written record of them unless the supervisor notifies the practice in writing that none is needed. The Regulations have applied since 26 June 2017.

ICAEW calls the document “a tool enabling firms to comply with regulation 18(1)” and distinguishes it from the AML compliance review, which is a different job: regulation 21(1)(c)requires a practice, where appropriate to its size and nature, to establish an independent audit function to examine and evaluate the adequacy and effectiveness of its policies, controls and procedures. Regulation 21(6) disapplies that duty for an individual who neither employs nor acts in association with any other person. Six per cent of the firms in ICAEW’s 2024 review said they had completed an assessment but sent an AML compliance review or a set of AML policies and procedures instead.

A second, parallel duty sits beside it. Regulation 18A, inserted on 1 September 2022 by SI 2022/860, requires the same structure for proliferation financing, with one difference: alongside the same five risk factors, the input it must take into account is the Treasury’s proliferation financing risk assessment report under regulation 16A. Regulation 16A(9) defines proliferation financing, in short, as providing funds or financial services for use in, or otherwise in connection with, chemical, biological, radiological or nuclear weapons, in contravention of a relevant financial sanctions obligation. ICAEW says a practice may cover it in the same document or write a separate assessment, and that many firms had not considered it at all.

Who must have one?

Every accounting practice acting in the course of business in the United Kingdom is in scope. Regulation 8(1) applies the Regulations to relevant persons listed in regulation 8(2) that are not excluded by regulation 15, and regulation 8(2)(c) lists auditors, insolvency practitioners, external accountants and tax advisers.

Regulation 11defines an external accountant as a firm or sole practitioner who by way of business provides accountancy services to other persons, and a tax adviser as one who provides material aid, or assistance or advice, in connection with the tax affairs of other persons. The duty is not scaled by headcount: ICAEW’s key reflection is that a firm must prepare one “regardless of the size of your firm”, and most of the firms in its review that had not prepared one were sole practitioners who judged client-level checks enough.

The practice’s supervisor is its professional body or HMRC. Regulation 7(1)(b) makes each professional body listed in Schedule 1 the supervisory authority for its members, and regulation 7(1)(c)(iv) gives HMRC the auditors, external accountants and tax advisers that no listed body supervises.

What must it consider?

Regulation 18(2) gives two inputs that must be taken into account: information the supervisory authority makes available under regulations 17(9) and 47, and risk factors covering five named areas of the practice. Regulation 18(3) adds a third: the size and nature of the business.

Risk factor in regulation 18(2)(b)Questions the assessment answersRegulation
Its customersWho the practice takes on: types of client, complex or layered ownership, politically exposed persons18(2)(b)(i)
The countries or geographic areas in which it operatesWhere clients, work and funds come from, and whether the practice deals with jurisdictions rated high risk18(2)(b)(ii)
Its products or servicesWhich services are offered, such as bookkeeping, payroll, insolvency or company formation18(2)(b)(iii)
Its transactionsWhat the practice handles, including client money and transactions that are unusually complex or large18(2)(b)(iv)
Its delivery channelsHow services are delivered: face to face, remotely, or through introducers and intermediaries18(2)(b)(v)

HMRC’s manual renders the same duty as four things to take into account: the nature and size of the business; all wider factors relevant to the business activity; risks specific to the business, such as those that apply to particular services or customers; and information made available by HMRC, which the practice must act on. Practices supervised by HMRC also take its own sector assessment into account: AMLG3700is published under regulations 17 and 47 and says it must be taken into account when carrying out the practice’s own assessment. Its reading of the National Risk Assessment 2025 is that accountancy service provider services are high risk for money laundering and low risk for terrorist financing.

Regulation 18 from the first step to the supervisor's requestRegulation 18(1) requires the practice to take appropriate steps to identify and assess the risks of money laundering and terrorist financing. Regulation 18(2)(a) requires it to take into account information the supervisory authority makes available under regulations 17(9) and 47. Regulation 18(2)(b) requires the five risk factors covering customers, countries and geographic areas, products and services, transactions and delivery channels. Regulation 18(3) requires the size and nature of the business to be taken into account. Regulation 18(4) requires an up-to-date written record of all the steps taken. Regulation 18(6) requires the practice to provide the assessment, the information it was based on and the record to its supervisory authority on request.1. Identifymoney launderingand terroristfinancing risks· reg 18(1)2. Readwhat thesupervisorpublishes · reg18(2)(a)3. Ratefive riskfactors · reg18(2)(b)4. Sizesize and natureof the practice· reg 18(3)5. Recordwritten recordof the steps ·reg 18(4)6. Hand overassessment andrecord onrequest · reg18(6)
Regulation 18 sets the sequence; the written record and the hand-over are part of it.

What should the document contain?

ICAEW’s methodology paper gives three steps: identify the money laundering risks faced by the different areas of the business and the clients and markets it serves; assess each identified risk by the likelihood of it occurring and the impact if it does; then review the mitigating checks, systems and controls that bring the net risk down to an acceptable level.

The CCAB guidance, written for the accountancy sector, requires the assessment to consider at least the risks presented by clients, countries or geographic areas, products and services, transactions and delivery channels, (paragraph 4.3.1), and says it should take into account the findings of the most recent UK National Risk Assessment, the National Risk Assessment on proliferation financing and information issued by the supervisor (paragraph 4.3.3). Firms that skip the supervisor’s information miss a named input in regulation 18(2)(a).

ICAEW’s worked example shows the shape: a table of risk factor, summary of firm, assessment of risk and mitigating actions; a second table of action, delivery date and owner; then a signature, a date and a next review date. A small practice with a limited range of services and few clients may be succinct, because regulation 18(3) says the assessment must take the size and nature of the business into account.

How do you score likelihood and impact?

The practice rates each identified risk twice: how likely the risk is to occur, and the impact if it does. ICAEW offers one possible range for likelihood and a sensible range for impact, and says a practice may set its own ranges.

Likelihood (five levels)Impact (four levels)
Almost certain — the event will occur in all but exceptional circumstancesCritical — significant sums could be laundered, with potential criminal prosecution against principals in the firm
Probable — the event is expected to occur in most circumstancesMajor — large sums could be laundered, with significant reputational damage to the firm
Possible — the event should occur at some timeSignificant — moderate sums could be laundered, with some reputational damage to the firm
Unlikely — the event may occur at some timeMinor — limited sums could be laundered, with negligible reputational impact
Rare — the event may occur at some time, but it would be exceptional—

ICAEW pairs the scales with examples: it is almost certain that a criminal would want to use a chartered accountant to legitimise the proceeds of a crime, while it is rare that a locally based client met face to face will lie about their identity. The rating then sets how much mitigation the practice needs, which is step three of ICAEW’s method.

How often must it be reviewed?

The Regulations set no review interval; they require an up-to-date record instead. The CCAB guidance for the accountancy sector says a risk assessment should be conducted at least annually, with new and changing risks considered as and when they are identified, and information from the practice’s AML supervisory authority considered.

The same guidance requires regular refreshes by periodic reviews set at a frequency that reflects the risks, and says it should also be refreshed by an event-driven review whenever senior management sees that events have affected those risks. ICAEW found most firms review at least annually and states the position plainly: “The regulations don’t require an annual review, but we do consider it good practice.” Its suggested triggers are a new service line, a risk bulletin that affects the practice, a suspicious activity report, or an update to the National Risk Assessment.

Who signs it off and who can ask for it?

The money laundering reporting officer (MLRO) may carry out the risk analysis, but it must be approved by senior management including the senior manager responsible for compliance, if that is a different person from the MLRO. The CCAB guidance puts the ultimate responsibility for identifying the risks and developing risk-based procedures for taking on new clients on the board member or senior manager responsible for compliance.

Regulation 18(4) then requires the practice to keep an up-to-date written record of all the steps it has taken, unless the supervisory authority notifies it in writing that no record is required, and regulation 18(5) says the supervisor may not give that notification unless it considers the sector’s risks clear and understood. Under regulation 18(6) the practice must provide the assessment, the information on which it was based and any record kept under regulation 18(4) to its supervisory authority on request. The CCAB guidance states the same duty: the assessment must be documented and made available to the supervisor on request.

We designed Filyst so that a case stage cannot advance on its own approval: the server rejects self-approval. The assessment has a similar approval step: where the MLRO drafts it, senior management, including the senior manager responsible for compliance if that is a different person, must approve it. That is why the approval sits at the end of the document rather than in a person’s head.

The risks rated here decide how much review the rest of the practice’s work needs, so they carry into the guide to AI for accountants in the UK, which sets out where a person signs off on an AI output, and into software for accounting practices, where we build the client file and its risk rating.

Firm-wide risk assessment template

This template is a starting point to adapt to your own practice. ICAEW’s review found firms that used boilerplate templates without adapting them, so replace every [bracket], delete anything that does not apply and add the risks your client base actually carries.

Purpose and scope

This document records the steps [Firm name] has taken under regulation 18 of the Money Laundering Regulations 2017 to identify and assess the risks of money laundering and terrorist financing to which its business is subject, and under regulation 18A the risks of proliferation financing [or: a separate proliferation financing assessment is kept at [location]].

The practice

[Firm name] is a [sole practitioner / partnership / limited company] providing [services] to [clients] from [locations], with [number] staff. Turnover band disclosed in the supervisor’s annual return: [band]. This section is the size and nature of the business that regulation 18(3) requires the assessment to take into account.

Sources read

Before rating any risk, the practice read [supervisor and date], the National Risk Assessment [year], the National Risk Assessment of Proliferation Financing [year] (the Treasury report that regulation 18A(2)(a) requires), HMRC’s risk assessment for accountancy service providers or your supervisor’s equivalent, and the risk bulletins issued since [date]. This is the information that regulations 18(2)(a) and 18A(2)(a) require the assessments to take into account.

Risks identified

Customers: [risks]. Countries and geographic areas: [risks]. Products and services: [risks]. Transactions: [risks]. Delivery channels: [risks]. Proliferation financing: [risks or “none identified, and why”].

Likelihood, impact and mitigating controls

[Risk] is rated [almost certain / probable / possible / unlikely / rare] with an impact of [critical / major / significant / minor]. Mitigating controls: [control], owned by [name], effective from [date]. Residual rating after mitigation: [rating].

Actions

[Action] · delivery date [DD Month YYYY] · owner [name and role]. [Action] · delivery date [DD Month YYYY] · owner [name and role].

Approval and review

Approved by [name], [role], on [DD Month YYYY]. Next review due [DD Month YYYY], or earlier if a trigger in the review section occurs: a new service line, a risk bulletin, a suspicious activity report or a new National Risk Assessment.

What happens if it is missing?

Schedule 6, paragraph 5(a)(i)lists regulation 18 among the Regulations’ “relevant requirements”, alongside regulation 18A, regulations 19, 19A, 20, 21, 23 and 24, and supervisory action under regulation 25. A practice that fails to prepare the assessment contravenes a relevant requirement.

The first route is regulatory. Under regulation 76, a designated supervisory authority, which means the FCA or HMRC, may impose a penalty of such amount as it considers appropriate, publish a statement censuring the practice, or both. Contravention is also a criminal offence under regulation 86(1).

On summary conviction in England and Wales the penalty is imprisonment for a term not exceeding three months, a fine, or both; on conviction on indictment it is imprisonment for a term not exceeding two years, a fine, or both (regulation 86(1)(a)(i) and (b)). A court deciding the case must consider whether the practice followed relevant guidance issued by the FCA or issued by another supervisory authority or appropriate body and approved by the Treasury (regulation 86(2)(b)), and the CCAB guidance for the accountancy sector records that it has been approved by HM Treasury. Regulation 86(3) provides a defence where the practice took all reasonable steps and exercised all due diligence to avoid the offence.

Where does this fit in your AML work?

The assessment is one of the written records a practice must hold. Our AML record keeping requirements for UK accountants lists regulation 18(4) alongside due diligence copies and transaction records kept for five years under regulation 40. The client-level rating collected during onboarding follows from the risks set here, as set out in the client onboarding checklist for UK accountants.

Frequently asked questions

Does a sole practitioner need a firm-wide risk assessment?

Yes. Regulation 18(1) applies to every relevant person in scope of regulation 8, and ICAEW states that a firm must prepare one regardless of its size. Regulation 18(3) only lets the document be shorter, because it must reflect the size and nature of the business.

How often must the assessment be reviewed?

The Regulations set no interval, but they require an up-to-date written record. CCAB guidance says a risk assessment should be conducted at least annually, with new and changing risks considered as they arise, and ICAEW treats an annual cycle as good practice.

Is the firm-wide risk assessment the same as an AML compliance review?

No. The assessment is the tool for regulation 18(1), which identifies and assesses the practice's own risks. The AML compliance review is the independent audit function in regulation 21(1)(c), required where appropriate to the size and nature of the business, which examines and evaluates the adequacy and effectiveness of the policies, controls and procedures.

Must the assessment cover proliferation financing?

Yes. Regulation 18A, inserted on 1 September 2022, requires a matching assessment for proliferation financing, with the same five risk factors and the Treasury's report under regulation 16A as its input. ICAEW says the practice may cover it inside the same document or write a separate assessment.

Does the assessment have to be sent to the supervisor?

Not on a fixed cycle. Regulation 18(6) requires the practice to provide the assessment, the information it was based on and any record kept under regulation 18(4) to its supervisory authority on request.

Sources

  1. Money Laundering Regulations 2017, regulation 18 (risk assessment by relevant persons)
  2. Money Laundering Regulations 2017, regulation 18A (risk assessment for proliferation financing)
  3. Money Laundering Regulations 2017, regulation 8 (application)
  4. Money Laundering Regulations 2017, regulation 11 (auditors and others)
  5. Money Laundering Regulations 2017, regulation 7 (supervisory authorities)
  6. Money Laundering Regulations 2017, regulation 21 (internal controls)
  7. Money Laundering Regulations 2017, regulation 16A (risk assessment by the Treasury: proliferation financing)
  8. Money Laundering Regulations 2017, regulation 76 (power to impose civil penalties: fines and statements)
  9. Money Laundering Regulations 2017, regulation 86 (criminal offence)
  10. Money Laundering Regulations 2017, regulation 40 (record-keeping)
  11. Money Laundering Regulations 2017, Schedule 6 (meaning of relevant requirement)
  12. Money Laundering and Terrorist Financing (Amendment) (No. 2) Regulations 2022 (SI 2022/860), regulation 6
  13. Money Laundering and Terrorist Financing (Amendment) (No. 2) Regulations 2022 (SI 2022/860), regulation 1 (commencement)
  14. HMRC, AMLG1800: Guidance for all sectors: Risk Assessment (updated 16 July 2026)
  15. HMRC, AMLG3700: Sector Risk Assessments: Risk Assessment of Accountancy Service Providers (updated 16 July 2026)
  16. CCAB, Anti-Money Laundering, Counter-Terrorist and Counter Proliferation Financing Guidance for the Accountancy Sector (based on law as at 1 July 2026)
  17. ICAEW, Firm-wide risk assessment methodology (2023)
  18. ICAEW, The money laundering firm-wide risk assessment: thematic review (29 October 2024)

Start with two weeks and £950.

You get a map of your systems and a fixed price to fix them. If you build with us, the £950 comes off.