Saudi Arabia: a business risk assessment is not your customer risk model, and it is audited every year
On the last day of 2025 the Saudi Central Bank (SAMA) issued its Guidance on Assessing Business Risks Related to Money Laundering, Terrorist Financing, and Proliferation Financing, by circular No. (472039915), dated 11/7/1447H, corresponding to 31 December…
On the last day of 2025 the Saudi Central Bank (SAMA) issued its Guidance on Assessing Business Risks Related to Money Laundering, Terrorist Financing, and Proliferation Financing, by circular No. (472039915), dated 11/7/1447H, corresponding to 31 December 2025. SAMA’s rulebook shows its status as In-Force, and the guide’s final chapter says it enters into force from the date of its publication on SAMA’s website. The English text in the rulebook is marked as a translated document.
The guide calls itself guidance, but much of it is written in the language of obligation: the financial institution “shall” conduct, document, update and audit its business risk assessment. It is short, four chapters, and it is worth reading for two things. The first is a line that separates the institution’s own risk assessment from the customer risk model. The second is an annual independent audit of that assessment, with the results going to the board.
Who it binds
The guide applies to Financial Institutions, which it defines as any financial institution subject to SAMA’s regulation, monitoring and supervision and tasked with implementing anti-money laundering, counter-terrorist financing and counter-proliferation financing requirements. It is SAMA’s text for the institutions SAMA supervises. Insurance has its own regulator: the Insurance Authority says that from 23 November 2023 it became the authorised regulator of the insurance industry in Saudi Arabia.
The guide adds to the existing framework rather than replacing it. Its final provisions say it does not supersede the requirements and conditions in the relevant regulations, instructions and decisions, provided they do not conflict with its provisions.
Two assessments, two different questions
The definitions draw the line. A Business Risk Assessment identifies and understands the level of risk to which the institution may be exposed, in line with the nature of its activities and the size of its operations. A Customer Risk Assessment identifies and understands the level of risk that each customer, natural or legal person, may pose to the institution. Paragraph 1.2(c) then turns the definitions into a duty:
> “The Financial Institution shall ensure that the Business Risk Assessment > process is not confused with the Customer Risk Assessment”
The two are connected. Customer risk, meaning the risk arising from the customer base, is one of the inherent risk categories the business assessment must weigh. But the unit of analysis is different. A customer risk rating answers a question about one relationship. The business risk assessment answers a question about the institution: its ownership and governance structure, its customer base, products, services and operations, delivery channels, geography, the technologies it uses, and the risks that are emerging. A spreadsheet that aggregates customer ratings into a heat map is not the same thing.
What the assessment has to be
Chapter Two sets the governance. The institution conducts a business risk assessment as a key element of its risk-based approach, covering its business activities, customer base, products, services, geographic exposure and service delivery channels, so as to identify, measure and understand both its inherent and its residual risks. It documents the assessment and relies on it to decide how to mitigate risk through internal control systems, to find residual risks and gaps in controls, and to set its risk appetite and priorities.
Paragraph 2.11 lists the minimum criteria. The assessment must:
- be written and approved by the board of directors or senior management, as the case may be;
- encompass all factors and risks associated with the institution’s business;
- cover the risks for all elements specified in the guide;
- clearly distinguish between money laundering, terrorist financing and proliferation financing risks;
- take into account high-level external sources, such as national and sectoral risk assessments;
- identify priorities for risk treatment according to their level of risk and their impact on business continuity;
- be updated on an ongoing basis, at least once annually, unless a triggering event occurs under paragraph 2.5.
Three further paragraphs close the usual shortcuts. Under 2.3, a general assessment that is not developed and adapted to the institution’s business, and that does not take into account the key elements in the guide, does not meet the minimum requirements. Under 2.8, an institution that is part of a group conducts its own individual assessment and does not rely solely on the group-level one. Under 2.4, the institution may choose its methodology, but it must be able to demonstrate to SAMA that the methodology is appropriate, effective and suited to its needs and the nature of its business.
Six stages
Chapter Three describes the assessment as six stages.
| Stage | What the guide asks for |
|---|---|
| 1. Data collection | Assess inherent risk from multiple external and internal sources, with the relevant departments taking part. The external examples include the Kingdom’s national risk assessment, risks identified by the Anti-Money Laundering Permanent Committee (AMLPC) and the Permanent Counter Terrorism Committee (PCTC), SAMA’s instructions, and blacklists, grey lists and international sanctions lists. The internal examples include customer and beneficial owner data, the results of analysing unusual or suspicious transactions, internal and external audit findings, the percentage of cash transactions, reliance on third parties, and remote transactions without the customer physically present. |
| 2. Inherent risk analysis | Analyse quantitative and qualitative data across structural, customer, product and service, delivery channel, geographical, technology, emerging and operational risks, bearing in mind that the categories may overlap and raise the level of risk when they occur together. Technology risks must be assessed before launching any new or developing products, services, business practices or technologies. |
| 3. Mitigation analysis | Assess the controls against the inherent risk, recording at a minimum whether each control is automated or manual, primary or secondary, preventive or detective, whether it has been tested by an independent auditor, and whether it has been in place for more than a year. |
| 4. Risk response | Identify the residual risks, assess whether they are consistent with the risk appetite, and prepare an action plan with concrete steps where residual risk exceeds acceptable limits. |
| 5. Endorsement | Document and endorse the assessment and action plan, and inform employees of the results through a continuous training programme. |
| 6. Follow-up and review | Keep the assessment under continuous review. Where the institution becomes aware of a new risk or the exacerbation of an existing one, it reflects it in the assessment as soon as possible and notifies SAMA. |
Two points in that table are easy to miss. Stage 3 asks whether each control has been tested by an independent auditor, so the audit trail for individual controls feeds the assessment itself. And stage 6 carries a notification to SAMA, not only an internal update.
Where it reaches your rating engine
Paragraph 3.2.4 sets rules for weighting risk factors that any risk-scoring model should be read against. The weighting must not be unjustifiably influenced by a single factor; economic or profitability considerations must not influence the risk classification; the weighting must not make it impossible to classify any business relationship as high risk; cases identified under the AML, CTF and CPF instructions are always classified as high risk; and any decision to override a rating generated by automated systems needs governance of its rationale, with the decision and the rationale documented.
Paragraph 3.2.5 deals with bought-in models. Where an institution uses automated systems from an external provider to set overall risk ratings, it must fully understand the provider’s classification methodology and how it combines risk factors into an overall rating. The methodology must meet the institution’s own risk assessment requirements and the Kingdom’s AML, CTF and CPF requirements, and the institution must make sure the ratings are accurate and reflect its understanding of the risks. Using a vendor’s model does not exempt the institution from the statutory requirements.
The annual independent audit
Paragraph 2.6 is the provision to plan the calendar around. The institution subjects its business risk assessment to an ongoing independent audit, conducted by an independent auditor at least once annually. The audit covers three things: the methodology, the quality of the data, and the effectiveness of controls and preventive measures. The results go to the board of directors or senior management, as the case may be, for discussion and for addressing deficiencies and areas for improvement. The paragraph requires an independent auditor; it does not say whether that auditor must be internal or external.
The audit sits alongside four other recurring duties in Chapter Two:
- Annual board review. Under 2.9 the board or senior management reviews the business risk report annually, to check it is consistent with the risk appetite and with the human and technical resources allocated. This is without prejudice to other SAMA instructions, including the requirement to submit a quarterly report on the institution’s risks.
- Annual update, or sooner. Under 2.11(g) the assessment is updated at least once annually, and under 2.5 it is updated immediately when any new or increasing risk element emerges, including material changes in customer segments, products, services, transactions, delivery channels, business practices, technologies or regulatory requirements, or material weaknesses in preventive and mitigation measures.
- On request to SAMA. Under 2.7 the institution provides SAMA with a written business risk assessment on request, including an executive report and detailed appendices commensurate with its activities, size and risk exposure.
- Documented sources. Under 1.2(e) the assessment must be effective, reasonable and adequately documented in writing, and must clearly indicate the bases, evidence and information it relies on, with reference to the sources used.
Not a licence to de-risk
Paragraph 2.10 says the guide does not aim to encourage unjustified de-risking, which it describes as terminating or restricting business relationships with customers or categories of customer in a comprehensive, excessive and unjustified manner to avoid risks rather than manage them. Institutions manage risks and apply mitigation measures commensurate with their risk appetite. For anyone planning to answer a high-risk finding in the assessment by exiting a whole customer segment, that paragraph is the one to read first.
Three things worth doing
- Put the two documents side by side and check they answer different questions. If the business risk assessment is mostly a roll-up of customer risk ratings, it is missing the structural, product, channel, technology and emerging-risk analysis the guide lists, and it may also be missing the separate treatment of money laundering, terrorist financing and proliferation financing that 2.11(d) requires.
- Book the independent audit and scope it to paragraph 2.6. Methodology, data quality and control effectiveness are three separate workstreams. Decide who the independent auditor is, when the results reach the board, and how the findings feed the action plan from stage 4.
- Test your rating engine against 3.2.4 and 3.2.5. Can any relationship still reach high risk? Does revenue touch the score anywhere? Are overrides documented with their rationale? If the model is a vendor’s, can your team explain how it combines factors into an overall rating?
Sources
This article draws on the following sources. Follow the links for the original text.
- Saudi Central Bank (SAMA) — Guidance on Assessing Business Risks Related to Money Laundering, Terrorist Financing, and Proliferation Financing (circular No. 472039915, 31 December 2025)
- Insurance Authority (Saudi Arabia) — FAQs
AML compliance financial-crime intermediate jurisdiction-briefing saudi-arabia what-changed