HomeInsightsBusiness-Wide Risk Assessment
AML/CFT · Risk-Based Approach
Your business-wide risk assessment: the bar has just risen
The EU's new AMLA has set out four minimum requirements for the business-wide risk assessment. Here is what Mauritius firms should change now.
Published 1 June 2026 · 5 min read
The business-wide risk assessment is the document most firms write once and rarely reopen. Yet it is the foundation every other control is built on — and in the space of two months it has moved twice: once in Mauritius law, which binds you, and once in Europe, which does not — but which will shape what your counterparties expect of you.
What happened
On 28 May 2026 the European Union’s Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) held a public hearing on its draft Guidelines on the business-wide risk assessment. Issued under Article 10(4) of Regulation (EU) 2024/1624 — the EU AML Regulation — the draft guidelines propose four minimum requirements for an adequate business-wide risk assessment (BWRA) and would apply to every obliged entity, financial and non-financial alike. The consultation closed on 15 July 2026, with final guidelines expected in the fourth quarter. It followed a companion hearing on 20 May on draft regulatory technical standards for group-wide AML/CFT requirements, signalling how prescriptive Europe’s new single supervisor intends to be. None of it binds a Mauritius reporting person. The guidelines are addressed to “obliged entities” under the EU AML Regulation, and a firm licensed here is not one. They matter for a different reason. Mauritius knows what European anti-money-laundering decisions cost — it sat on the EU’s own list of high-risk third countries until Commission Delegated Regulation (EU) 2022/229 removed it, following the FATF’s delisting at the October 2021 plenary — and the EU banks, investors and fund managers behind much of the global-business sector will treat these guidelines as the content standard for a BWRA long before any Mauritian supervisor mentions them.
The timing matters for Mauritius. Weeks earlier, the island enacted the Anti-Money Laundering, Combatting the Financing of Terrorism and Countering Proliferation Financing (Miscellaneous Provisions) Act 2026 — Act No. 3 of 2026, in force 18 April 2026. It writes proliferation financing into the risk assessment itself: section 17 of FIAMLA now requires every reporting person to identify, assess and understand proliferation financing risk alongside money laundering and terrorism financing, and a new section 17(2A) allows that work to sit inside an existing targeted financial sanctions or compliance programme rather than beside it. Different regulators, the same direction of travel: the institutional risk assessment is no longer a formality to be filed and forgotten.
Why it matters
Under section 17 of FIAMLA, every Mauritius reporting person must identify, assess and understand its money laundering, terrorism financing and proliferation financing risks (s.17(1)(a)), and must document the risk assessments in writing, keep them up to date and make them available to competent authorities on request (s.17(4)). The board must own it and base the firm’s AML/CFT strategy on it — and if you are an FSC licensee, the FSC AML/CFT Handbook says so as well. Firms supervised by the Bank of Mauritius or by another regulatory body should read their own supervisor’s guidance alongside the section. This is the local expression of FATF Recommendation 1 — the risk-based approach on which the whole regime rests. A BWRA that is stale, generic, or silent on an entire risk category is not a minor paperwork defect. It undermines every downstream control, because customer risk-rating, enhanced due diligence triggers and transaction-monitoring rules are all meant to flow from it. If the source document is weak, everything built on it is weak too.
One nuance the same Act introduced, and it cuts the other way: section 17(5) lets a supervisory authority determine that its reporting persons need not document their risk assessments at all, provided the risks inherent to the sector are clearly identified and understood and each firm understands its own. Unless your supervisory authority has made that determination for its reporting persons, section 17(4) still applies and the documented assessment remains the default. And the relief, where it is given, is from the paperwork — never from the thinking.
The convergence is the real signal. When the EU’s standard-setter spells out the minimum content of a BWRA, and Mauritius adds proliferation financing to the risks a firm must assess and brings more businesses into scope, “we have a risk assessment” stops being a sufficient answer. The question a supervisor — or an independent AML/CFT auditor — will ask is sharper: is the assessment specific to your business model, and does it genuinely drive what you do? For management companies, DNFBPs and the wider global-business community serving cross-border structures, a generic template lifted from a peer is precisely the kind of document that now invites a finding.
The test for an adequate BWRA
Read your assessment as an examiner would. Could you have written it for any firm in your sector, or only for yours? Does each identified risk connect to a named control? Has anything changed since last year? If the honest answers are “any firm”, “not really” and “no”, the document is overdue for rebuilding.
What firms should do
- Re-open the document, not just the calendar. Treat the BWRA as a living assessment rather than an annual ritual. If yours has not changed despite new products, clients or jurisdictions over the past year, that lack of change is itself a finding.
- Add proliferation financing as a distinct risk — but read the definition first. Act No. 3 of 2026 inserted a definition into FIAMLA section 2 confining “proliferation financing risk” strictly and only to the potential breach, non-implementation or evasion of targeted financial sanctions under the United Nations (Financial Prohibitions, Arms Embargo and Travel Ban) Sanctions Act and FATF Recommendation 7. Section 17 uses that defined term, so the statutory duty is a sanctions-evasion duty and screening is its core. Dual-use goods and high-risk shipping and trade routes are real proliferation typologies worth assessing on their own merits — but they sit outside the statutory definition, so treat them as risk management rather than as what the Act obliges.
- Start from the statutory list, not the European one. Section 17(2)(a) requires every relevant risk factor to be taken into account, and names six that must be among them: the nature, scale and complexity of your activities; your products and services; to whom and how they are provided; the nature, scale, complexity and location of the customer’s activities; reliance on third parties for customer due diligence; and technological developments. Section 17(2)(b) adds one more that firms routinely omit — the outcome of the national risk assessment and any guidance issued. And section 17(3) requires you, before you launch a new product or business practice or start using a new or developing technology, to identify and assess the risks that may arise from it — for new and pre-existing products alike — and to take appropriate measures to manage and mitigate them.
- Then cross-check against the European dimensions. Map business model, customers, products and services, delivery channels, transactions and geographic exposure — the risk dimensions AMLA’s draft guidelines expect a business-wide risk assessment to cover, and a useful checklist whatever your jurisdiction. A gap in any one is the easiest finding for an examiner to write up.
- Show the line from risk to control. Make the link explicit: this risk, therefore this control. An assessment that does not visibly shape your risk-rating model, EDD thresholds and monitoring rules has failed its only real purpose.
- Evidence board ownership. Record that the board reviewed, challenged and approved the assessment — with a date and a minuted discussion, not merely a signature on a circulated file.
Audacia's view
The business-wide risk assessment is quietly becoming the document supervisors read first, because it reveals at a glance whether a firm understands its own exposure or is simply going through the motions. With Act No. 3 of 2026 reshaping the Mauritius framework and the EU codifying minimum BWRA expectations, this is the moment to refresh yours — on your own timetable, before an inspection makes the point for you. We help firms rebuild the assessment so it does real work: specific to the business, current, and visibly connected to the controls it is meant to drive.
This article is general commentary and does not constitute legal or compliance advice. Specific advice should be sought on individual circumstances.
Talk to Audacia's compliance team
If this development affects your firm, we can help you assess your exposure and update your AML/CFT framework before your next inspection.
Related
AML/CFT · Audit
Is your AML/CFT framework ready for an independent audit?
What regulators actually expect from an independent AML/CFT audit, how to scope it, and the common gaps we see across Mauritius licensees.
Read article →AML/CFT · Training
Building an audit-ready AML/CFT training programme
The four properties of a training programme that survives FSC and FIU inspection — scalable, role-specific, auditable and current.
Read article →RegTech · KYC / Onboarding
Rethinking KYC onboarding: from paperwork to risk-based decisions in minutes
Digital ID, sanctions screening, hybrid AI risk scoring, beneficial ownership capture — and the audit trail regulators expect, by default.
Read article →