Image related to AMLA reflects new reality of geographic risk

AMLA reflects new reality of geographic risk

This article is a free excerpt from inCOMPLIANCE, ICA's bi-monthly, member exclusive magazine. To gain access to more articles like this, sign in to the Learning Hub or become a member of ICA.

Geographic risk frameworks in the AMLA era will be defined by dynamism and moving parts, writes Gary Youinou

The days of using static country rating lists to assess geographical money-laundering risk are over. The EU’s new Anti-Money Laundering Authority (AMLA)-led framework – alongside the UK risk-based expectations and the eight AML/CFT priorities of the Financial Crimes Enforcement Network (FinCEN) – all point toward a more dynamic model in which firms combine formal country risk scoring with ongoing typology analysis. The aim is that country risk reflects not just where exposure sits, but how money laundering and terrorist financing risk actually manifests through jurisdictions, sectors and remittance corridors.

A more structured regulatory direction

The EU’s post-Anti-Money Laundering Directive (AMLD) package places the business-wide risk assessment at the centre of AML/CFT governance. AMLA’s 2026 consultation on business-wide risk assessment states that obliged entities must identify money laundering/terrorist financing risk across their operations and use that assessment to make risk-based decisions, while group-wide requirements are intended to give firms a consolidated view of risks across their organisations, including cross-border activity and third-country operations.

This builds on the revised money laundering/terrorist financing risk factors guidelines issued by the European Banking Authority (EBA), which place the risk-based approach at the centre of the EU regime and require firms to assess risk both at business-wide level and at the level of individual relationships and transactions.

The EBA has also made explicit the fact that firms should take a holistic approach at business-wide level and consider the full range of risk factors, including products, customer categories, distribution channels and the jurisdictions in which they or their customers operate.

The UK continues in a similar direction. The Joint Money Laundering Steering Group and supervisory expectations require firms to maintain a documented business-wide risk assessment covering customer, product, delivery-channel and geographic risks, and to apply enhanced due diligence where higher-risk jurisdictions or strategic AML/CFT deficiencies are involved.

Although the institutional architecture differs from the EU’s new AMLA model, the practical message is comparable: firms must be able to explain how country risk has been identified, weighted, reviewed and linked to controls.

In the US, FinCEN’s eight AML/CFT priorities reoriented firms toward a threat-led assessment of:

  • corruption
  • cybercrime
  • terrorist financing
  • fraud
  • transnational criminal organisations
  • drug trafficking
  • human trafficking, and
  • proliferation financing.

Curiously, although generally covered within the priorities, tax crime, environmental crime and small arms trafficking are not directly named as priorities.

Despite these priorities not being a list of countries, they have a strong geographical effect. This is because each threat tends to cluster in particular jurisdictions, regions, secrecy hubs or cross-border corridors.

Other countries are also developing their guidelines; some like the UAE, consequent to their removal from the Financial Action Task Force (FATF) grey list, have made significant upgrades moving towards a more mature, enforcement-heavy regime, with notable emphasis on proliferation financing, tax crimes, virtual assets and strengthened governance/board accountability.

What this means for risk frameworks

Taken together, these developments support a more analytical geographical risk framework. A firm should still use a structured country risk-scoring matrix, but that matrix should be only the foundation layer of a wider system.

At a minimum, the country model should draw on objective sources such as FATF outcomes, national and supranational risk assessments, corruption and governance indicators, sanctions exposure, conflict risk and other credible public information relevant to money laundering/terrorist financing vulnerability.

It should also distinguish between different dimensions of geographic exposure, including customer residence, beneficial ownership, source of funds, destination of funds, transactional corridors, booking location and operational presence.

That structure is important, because supervisory expectations are no longer satisfied by the assignation of a single, static country label. Under the EBA framework, risk assessment and mitigation are ongoing processes, and firms must ensure that updated controls apply to existing as well as new relationships when circumstances change.

The same logic is embedded in AMLA’s expectation that firms maintain a business-wide understanding of risk across their operations and adapt policies and controls accordingly.

speech marks

Supervisory expectations are no longer satisfied by the assignation of a single, static country label.

Why typologies matter

This is where typologies become essential. A country risk model tells a firm the baseline vulnerability of a jurisdiction, but typologies show how risk is currently being exploited in practice.

Without typologies, a framework can become overly dependent on lagging indicators such as formal listings or periodic index changes, which may not capture shifts in criminal behaviour quickly enough.

Typologies add value because they identify the methods, products, sectors and corridors through which money laundering/terrorist financing risk is moving. A jurisdiction that appears only moderate on a generic country score may nonetheless present elevated risk for a specific activity because recent typologies show growth in trade-based money laundering, sanctions evasion, cash smuggling, abuse of legal entities or virtual-asset misuse linked to that country or corridor.

The EBA’s own approach supports this broader use of information. Its guidelines state that the listed factors are not exhaustive and that firms should consider other factors and measures as appropriate.

The UK’s risk-based approach similarly expects firms to look beyond a narrow checklist and apply judgement to the actual risks arising from their customers, business model and geographic exposure.

speech marks

A country risk model tells a firm the baseline vulnerability of a jurisdiction, but typologies show how risk is currently being exploited in practice.

Typologies in ongoing country assessment

For practical purposes, typologies should operate as a live overlay on top of the country-rating matrix. They should not replace the model; they should continuously challenge and recalibrate it.

A robust framework therefore needs a formal typology intake process. Firms should regularly review typologies from FATF-style bodies, national risk assessments, financial intelligence units, law-enforcement actions, supervisory publications and internal suspicious activity experience, then map those patterns to affected countries, products, sectors and corridors.

Where new typologies indicate heightened exposure, firms should adjust country or corridor scores, create targeted risk flags, revise monitoring rules or trigger enhanced due diligence, even if the underlying country’s macro rating has not yet changed.

In the wake of FinCEN’s publication of its priorities, this is especially important for US-regulated businesses where, in practice, firms need to connect each priority to the countries and routes most relevant to their business – for example corruption-linked politically exposed person (PEP) exposure, cyber-enabled fraud flows, trafficking corridors or proliferation-sensitive trade routes – and then reflect that intelligence in their geographical risk assessment and control framework.

A practical model for firms

An effective framework now has four moving parts.

First, a documented country risk matrix, which establishes baseline geographic ratings using transparent factors and governance. Second, corridor analysis identifying combinations of origin, transit and destination risk (which may be more meaningful than any single-country score).

Third, a typology register, recording current money laundering/terrorist financing methods relevant to particular jurisdictions, sectors and products, with defined triggers for score changes or control enhancements. And fourth, governance, which ensures periodic and event-driven reassessment, with clear ownership, escalation and auditability.

The resulting framework is one that is both defensible and operational, meeting the EU and UK expectation for a holistic, business-wide and ongoing risk assessment, while also translating FinCEN’s priority based threat view into practical country and corridor decisions.

About the author

Gary Youinou

Gary Youinou is the Founder of KnowYourCountry, the global standard for jurisdictional AML risk intelligence.