The business risk assessment is two years old

Firm-level · 12 questions

Scenario

The firm is eleven people: registered office and company secretarial work, accounting, VAT and tax compliance, and audit for a handful of clients. Drafting her annual report to the partners, the MLRO has found that she cannot describe the firm’s risk exposure by reference to the business risk assessment, because the assessment describes a different firm.

  • The firm: eleven staff and two partners, acting for around 240 client entities
  • The assessment: nine pages, adapted from a template supplied by a professional body, and approved by the two partners in September 2024. It has not been revisited since.
  • New service: since March 2025 the firm has provided individual directors to client companies. There are fourteen such appointments.
  • New delivery channel: since mid-2025 most onboarding is done remotely, using an electronic identity verification tool. Before that, clients were seen in the office.
  • New sector: the firm now acts for four companies whose business involves virtual assets. In 2024 it acted for none.
  • New clients: the book has grown by about 60 entities, of which roughly 30 arrived in one block in January 2026 when a retiring sole practitioner transferred his clients. Eleven of those have beneficial owners resident in countries the assessment does not mention.
  • What the assessment says: it describes the client base as “predominantly local trading companies and private clients”, lists no directorship service, and does not mention remote onboarding or virtual assets.
  • Controls in place: written policies and procedures, a designated MLRO, a screening tool, and training delivered to all staff in November 2025. The training covered customer due diligence and reporting; it did not cover the directorship service or the verification tool.
  • Internal record: nine internal reports were made to the MLRO in the last two years, of which she reported four onwards. Three of the nine concerned clients in the acquired book.
  • The partners’ view: asked about the assessment, one partner said it was reviewed “informally, all the time” and that nothing about how the firm operates had really changed

Grounded in: PMLFTR (S.L. 373.01) (Business risk assessment; policies, controls and procedures; training; the MLRO and internal reporting) · FIAU Implementing Procedures, Part I (Business risk assessment and its relationship to customer risk assessment; senior management approval; the MLRO's annual report) · Directive (EU) 2015/849 as amended (Art. 8 — business-wide risk assessment, proportionate policies and controls) · FATF Recommendations (R.1 and its interpretive note — the risk-based approach and assessing risk at firm level) · Malta National Risk Assessment (National assessment of money laundering and terrorist financing risk, as an input to a firm's own)