From National Risk to Business Reality: Closing One of Malta’s Most Common Risk Assessment Gaps

Stephanie Mangani

9/22/20264 min read

worm's-eye view photography of concrete building
worm's-eye view photography of concrete building

A robust Business Risk Assessment (BRA) is the cornerstone of an effective Anti-Money Laundering and Countering the Financing of Terrorism (AML/CFT) framework. Maltese AML/CFT regulations require all subject persons to establish and maintain a documented BRA that identifies, assesses, and mitigates the specific financial crime risks faced by their business.

The BRA should not be viewed as a regulatory formality. Rather, it is the foundation upon which the entire AML/CFT framework is built. It should inform the firm's policies, procedures, customer risk-rating methodology, due diligence measures, transaction monitoring programme, and overall compliance strategy. In essence, the BRA directs where resources and controls should be focused to effectively manage financial crime risks.

Through supervisory inspections and compliance examinations, weaknesses continue to be identified in the quality and effectiveness of Business Risk Assessments. A recurring finding is that many subject persons fail to develop a BRA that reflects the size, nature, and complexity of their operations. Instead, some firms rely heavily on the findings of Malta's National Risk Assessment (NRA), treating it as a substitute rather than as an input into their own assessment process.

While the NRA is an important reference document, it cannot replace a firm-specific Business Risk Assessment. The NRA should serve as a guide that informs and enhances the BRA, rather than being replicated within it.

The National Risk Assessment, coordinated at a national level, evaluates Malta's exposure to money laundering and terrorist financing risks across various sectors. It identifies sector-specific threats, vulnerabilities, typologies, and emerging risks, providing valuable insight into the domestic financial crime landscape.

By contrast, a Business Risk Assessment is conducted at firm level and must focus specifically on the risks arising from the organisation's own activities, customer base, products and services, delivery channels, and geographic exposure. Whilst the NRA may highlight risks relevant to a particular sector, subject persons must independently assess how those risks materialise within their own business environment.

A comprehensive BRA should consider, at a minimum:

  • Customer risk factors.

  • Geographic and jurisdictional risks.

  • Product and service risks.

  • Delivery channel and interface risks.

  • Transactional and operational risks.

  • The effectiveness of existing controls and mitigating measures.

The assessment should not only identify inherent risks but also evaluate the adequacy of the controls designed to mitigate them, ultimately determining the firm's residual risk exposure.

When a new NRA is published, subject persons should conduct a structured review of its findings and evaluate their relevance to the business. This involves understanding both the inherent and residual risk ratings assigned within the NRA and assessing whether these conclusions align with the firm's own risk profile.

Where the NRA identifies risks relevant to the business that are not adequately addressed within the BRA, these should be incorporated into the assessment. Equally important is understanding the controls and mitigating measures expected by regulators and determining whether the firm's existing control framework effectively addresses those risks.

As the NRA directly influences the BRA, firms should ensure that the publication of a new NRA triggers a review and update of their Business Risk Assessment. The rationale for any amendments should be clearly documented, demonstrating how NRA findings have been considered and incorporated where necessary.

A well-designed BRA should do far more than document risks. It should actively drive customer risk classification, due diligence requirements, transaction monitoring scenarios, escalation procedures, and reporting decisions. Furthermore, it should be a living document that is periodically reviewed, challenged, and approved by senior management.

An effective BRA should also incorporate a documented scoring methodology that evaluates:

  • Inherent risk.

  • Control effectiveness.

  • Residual risk.

Understanding residual risk is particularly important, as it enables management to assess whether the firm's overall risk exposure remains within its established risk appetite. Any control weaknesses or assessment gaps identified during the process should be documented, monitored, and addressed through appropriate remediation plans.

In practice, many AML/CFT deficiencies arise not because firms are unaware of the NRA, but because they struggle to translate its findings into meaningful business controls. Generic risk matrices, unchallenged assumptions, and static assessments often result in risk frameworks that fail to reflect operational realities. This can expose firms to regulatory findings and weaken the effectiveness of their broader AML/CFT programme.

Bridging the gap between the National Risk Assessment and the Business Risk Assessment is therefore a critical component of effective financial crime risk management. Firms that invest in developing a tailored, proportionate, and dynamic BRA are better positioned to demonstrate regulatory compliance, respond to emerging risks, and build a resilient Financial Crime Compliance (FCC) framework.

How We Can Help

Developing and maintaining a meaningful Business Risk Assessment can be challenging, particularly as regulatory expectations continue to evolve and supervisory scrutiny intensifies. We can provide independent expertise in reviewing and enhancing existing BRAs, ensuring they accurately reflect the firm's risk profile and align with supervisory expectations. This includes conducting gap analyses, facilitating risk assessment workshops, validating scoring methodologies, reviewing control effectiveness, and ensuring appropriate linkage between the NRA and the firm's AML/CFT framework.

Additionally, MS Squared Compliance can assist businesses in translating regulatory requirements into practical and operational controls, helping management understand their residual risk exposure and identify areas requiring remediation.

By leveraging specialist knowledge and industry experience, firms can strengthen their governance arrangements, improve the effectiveness of their AML/CFT controls, and demonstrate a robust, risk-based approach to financial crime compliance that withstands both regulatory scrutiny and evolving financial crime threats.

Email

stephanie.mangani@mssquaredcompliance.com

© 2026 MS Squared Compliance. All rights reserved.