Company Brochure

Building a Defensible AML/CFT Business Risk Assessment on the Isle of Man

A compliance officer reviewing a business risk assessment document in a calm Isle of Man office

Strengthen your compliance strategy

— with confidence. clarity. experts.

Book a
consultation

A Business Risk Assessment (BRA) is the documented assessment, required by paragraph 5 of the AML/CFT Code, that estimates the money-laundering and terrorist-financing risk your business and your customers pose. A defensible BRA is tailored to your own firm, recorded so its basis can be demonstrated, weighs the specific factors the Code names, and is kept under review rather than filed once. Get those four things right and it holds up under supervision. Buy a template and it does not.

If you are reading this in August, one date should have your attention. The Authority — the Isle of Man Financial Services Authority — expects firms to complete their consideration of the suite of National Risk Assessments within the BRA by 1 September 2026, with any resulting updates adopted and approved as soon as practicable after that. That is not a reason to panic, but it is a reason to have your BRA open on the desk now rather than in the autumn.

What the Code actually requires

The duty itself is short. Code para 5(1) requires a relevant person to carry out an assessment that estimates the risk of ML/FT posed by the relevant person's business and customers. Two things follow. First, the BRA looks at your firm as a whole — its activities, products and delivery channels — not at any one client. Second, it is an estimate you must reason towards, not a label you assign. The April 2026 Handbook broadens the concept to money laundering, terrorist financing and proliferation financing (ML/FT/PF), and a BRA built today should think in those terms even though the Code paragraph itself speaks of ML/FT.

Para 5(2) then sets three requirements that separate a real BRA from a document that merely exists. It must be undertaken as soon as reasonably practicable after the relevant person commences business; it must be recorded in order to demonstrate its basis; and it must be regularly reviewed — with the details of any review recorded — and, if appropriate, amended to keep it up to date. The word doing the work there is demonstrate: a rating with no recorded reasoning behind it is not a BRA the Authority can rely on, and it is not one you can defend.

A recorded business risk assessment on a desk showing dated review notes in the margin

The factors your BRA must weigh

Code para 5(3) does not leave the assessment to instinct. It requires you to have regard to a defined set of factors, and because this is one of the few places the Code gives you a genuine list, it is worth stating them plainly. Your BRA must have regard to:

  • the nature, scale and complexity of your activities, the products and services you provide, and the manner in which they are provided — including whether you actually meet your customers;
  • the involvement of any third parties in the customer due diligence (CDD) process, including reliance;
  • your customer risk assessments carried out under para 6, any technology risk assessment carried out under para 7, and any relevant findings of the most recent National Risk Assessment relating to the Island.

One point of precision matters, because firms often get it wrong. Geography is not a named factor in para 5(3); jurisdiction risk enters the framework chiefly through the Customer Risk Assessment. That said, the Handbook is clear that a firm should still have regard to the jurisdictions it is exposed to when building its business-level picture — so exposure to high-risk countries belongs in your BRA as context, not as a para 5(3) heading you can point to.

What good looks like, in the Handbook's own framing at §2.2.8, is an assessment that shows where, how and to what extent your firm is exposed to ML/FT/PF risk and which areas to prioritise. It should form the basis of your risk-based approach and your risk appetite, and it should conclude and summarise your inherent risks, your exposure, likelihood and impact, your mitigations, and the residual risk that remains. A BRA that lists factors but never reaches a reasoned residual position has done the reading without answering the question.

We help Isle of Man firms turn that list of Code factors into a BRA that actually reaches a defensible conclusion.

Tailored to your firm — not a template

This is the objection we hear most: we bought a BRA, or we use the group's — isn't that enough? The Handbook answers it directly at §2.2.8.1. The BRA must be tailored to your firm, and firms "may not be able to rely on group wide BRAs" to satisfy the Code. A generic assessment proves nothing about your exposure, because your products, your clients and the way you deliver services are not your parent's or your peer's.

That does not mean every BRA has to be elaborate. The Handbook accepts that a simple BRA may suffice where a firm has limited or no international exposure and no complex products — but even then it must, as a minimum, have adequate regard to all of the para 5(3) factors. "Simple" describes the depth the evidence justifies; it does not license skipping a factor. A one-page BRA that reasons honestly through every heading is defensible; a forty-page template that was never adapted to the firm reading it is not.

Two contrasting documents on a desk, one a generic template and one annotated with firm-specific notes

The 1 September 2026 National Risk Assessment duty

Para 5(3) requires your BRA to have regard to relevant findings of the most recent National Risk Assessment relating to the Island. The Handbook, at §2.2.8.3, sharpens this into a concrete piece of work. Your firm must include consideration of all topical NRAs — money laundering, terrorist financing and proliferation financing — together with any relevant sectoral NRAs that apply to what you do. And it sets an expectation with a date attached: "It is expected that consideration of the suite of NRAs should be completed by 1 September 2026", with any resulting BRA updates adopted and approved as soon as practicable after that.

In practice this is a documented exercise, not a mental note. Work through each NRA, record where its findings touch your business, and either explain why your existing mitigations already address the risk or update the BRA so that they do. The evidence the Authority will look for is that the consideration happened, that it was reasoned, and that anything it surfaced was carried through into an approved version. Leaving it until the deadline turns a manageable review into a rushed one.

A wall planner and documents on a desk, marking an approaching compliance deadline

Keeping the BRA alive

Code para 5(2)(c) requires the BRA to be regularly reviewed, with review details recorded and amendments made where appropriate. The Handbook, at §2.2.6, explains when: risk assessments should be reviewed periodically, but also whenever circumstances change or new threats or technologies emerge. It also makes a practical point that catches firms out — your first BRA may need a shorter review cycle than later ones, because the earliest version is the one most likely to need correction as you test it against reality.

The Handbook's phrase for the target state, at §2.2.8, is that the BRA "should be considered a living, ever-changing, ongoing document." The discipline behind that phrase is evidence: the robustness, objectivity and reasonableness of the assessment and every review must be demonstrable and evidenced at all times, with a version and control history maintained. This is the same thesis that runs through the AML/CFT statistical return as the evidence behind your BRA — a compliance artefact you file and forget proves nothing, whereas a dated, version-controlled record of your reasoning proves a great deal.

Keeping the BRA current is exactly the kind of task that drifts when nobody owns it. Ownership usually sits with the MLRO, and it is worth naming who holds it explicitly.

How the BRA relates to the CRA and the TRA

The BRA is foundational: it looks at your business. The Customer Risk Assessment, under Code para 6, looks at each customer — and para 6(3)(a) requires every CRA to have regard to the BRA you carried out under para 5. The Technology Risk Assessment, under para 7 and covered at Handbook §2.2.11, looks at the risks in the technology you use — and para 7(3)(b) likewise requires the TRA to have regard to the BRA. Risk flows downward from the business picture into the customer and technology assessments.

That relationship also answers a practical question about paperwork. The Handbook, at §2.2.7, accepts that the BRA and TRA can be recorded within the same document — provided they remain distinct assessments, each considering the factors at Code paras 5 and 7 respectively, and each reaching its own overall residual risk rating. Sharing a cover is fine; blurring two separate judgements into one is not.

Common mistakes we see

The first is the template BRA — a bought or group-wide document that was never adapted, so it describes a firm that is not yours and satisfies neither para 5 nor §2.2.8.1. The second is the static BRA: assessed once, approved, and never touched again, in breach of the para 5(2)(c) duty to review and the §2.2.6 expectation to revisit when circumstances change. The third is listing factors without concluding — a document that recites para 5(3) but never reaches inherent risk, mitigations and a residual position, so it reads as preparation rather than assessment. The fourth, this year specifically, is treating the NRA duty as done when the suite of National Risk Assessments has not actually been worked through and evidenced ahead of 1 September 2026.

Each of these is fixable, and the fix is the same in every case: make the reasoning explicit, tailor it to your firm, conclude it, and keep the version history.

Frequently asked questions

We bought a template BRA — isn't that enough?

No. The Handbook at §2.2.8.1 requires the BRA to be tailored to your firm, and states that firms may not be able to rely on group-wide BRAs to satisfy the Code. A template can be a starting structure, but a BRA that is not adapted to your products, clients and delivery channels proves nothing about your actual exposure. Even a deliberately simple BRA must have adequate regard to every para 5(3) factor.

How often must we redo the BRA?

Code para 5(2)(c) requires regular review with the details recorded, and the Handbook at §2.2.6 adds that you should review periodically and also whenever circumstances change or new threats or technologies emerge. There is no fixed interval, but your first BRA may warrant a shorter cycle than later ones, and this year the NRA suite must be considered by 1 September 2026.

How is the BRA different from the CRA?

The BRA assesses your business as a whole under Code para 5; the Customer Risk Assessment assesses each individual customer under para 6. They are connected, not interchangeable: para 6(3)(a) requires every CRA to have regard to the BRA, so the business-level picture calibrates how you read each client. If your CRAs do not reconcile to your BRA, one of the two needs revisiting.

Can the BRA and TRA be the same document?

Yes, within limits. The Handbook at §2.2.7 permits the business and technology risk assessments to be recorded in one document, provided they remain distinct assessments — each addressing its own Code factors (paras 5 and 7) and each reaching a separate overall residual risk rating.

A BRA is not a certificate you obtain; it is a judgement you can show your working for — dated, tailored, and current on the day someone asks to see it.

Knight Consultancy Limited
(Company No: 136669C)
Design House, Hills Meadow, Douglas,
Isle of Man ,IM1 5EB

© Knight Consultancy Limited {{Y}}. All Rights Reserved. Privacy Policy

Website and marketing partner: Yellowstone Accounts

Knight