Tillbaka till nyheter
Educational Content

What is a Business-Wide Risk Assessment

What is a Business-Wide Risk Assessment

What Is a Business-Wide Risk Assessment — and How Should a Real Estate Business Do One?

One agent or 500 employees: under AMLR, compliance starts by understanding the risks of your own business.

Before you can properly assess a customer, you first need to understand your own business.

That is the principle behind the Business-Wide Risk Assessment — BWRA.

Fom 2027, when Regulation (EU) 2024/1624 — the new EU Anti-Money Laundering Regulation, or AMLR — becomes applicable, this becomes an especially important part of the AML framework for obliged entities, including real estate professionals.

The concept sounds complicated.

It does not need to be.

At its core, a Business-Wide Risk Assessment answers one fundamental question:

“Where could my real estate business realistically be exposed to money laundering or terrorist-financing risk?”

Not where real estate in general is exposed.

Not what a generic AML template says.

But:

Where is YOUR business exposed?

That distinction is fundamental.

Start with your own business — not your customers

Many businesses instinctively think AML begins with:

“Identify the customer.”

Under a proper risk-based AML framework, there is a step before that.

The business itself must understand its exposure.

AMLR Article 10 requires obliged entities to identify and assess the money-laundering and terrorist-financing risks to which they are exposed, as well as risks relating to the non-implementation or evasion of targeted financial sanctions.

The Regulation specifically says the measures should be proportionate to the nature of the business, its risks and complexity, and its size.

That is critical for real estate.

Because a one-person residential estate agency in a small local market does not have the same risk profile as an international luxury-property group operating across ten countries.

But both can be obliged entities.

So the objective is not: One identical AML system for everybody.

It is: An AML system appropriate to the risks of each business.

That is exactly what the BWRA is designed to establish.

What does a Business-Wide Risk Assessment actually assess?

AMLA describes the BWRA as a central part of the risk-based approach.

Its purpose is to enable an obliged entity to understand the risks arising from areas such as:

  • its business model;

  • its customers;

  • its products and services;

  • its transactions;

  • its delivery channels; and

  • its geographical exposure.

For real estate businesses, these concepts become very practical.

A BWRA should help you answer questions such as:

1. What kind of real estate business are you?

Start with the basics.

Are you:

  • an independent estate agent?

  • a residential sales agency?

  • a rental agency?

  • a luxury-property specialist?

  • a commercial real estate agency?

  • a developer?

  • an international brokerage?

  • a franchise?

  • a property investment intermediary?

  • a business operating several branches?

The activities of the business determine the type of risk it encounters.

An agency selling €200,000 residential properties locally will naturally face a different risk environment from an agency routinely handling €5 million villas for international clients.

2. Who are your customers?

Look at your customer base as a whole.

Ask:

  • Are most customers private individuals?

  • How many are companies?

  • Do you frequently deal with foreign purchasers?

  • Do you work with investment companies?

  • Do you encounter trusts?

  • Do customers regularly use holding companies?

  • Do you deal with professional investors?

  • Are politically exposed persons occasionally part of your clientele?

  • Do you work with customers from jurisdictions associated with greater AML risk?

The purpose is not to label particular customers as suspicious.

The purpose is to understand the types of customers your business normally encounters.

3. Where do your customers and transactions come from?

Geography matters.

A real estate agency should understand:

  • where its customers live;

  • where corporate entities are established;

  • where beneficial owners are located;

  • where transaction funds originate;

  • which countries regularly feature in its transactions;

  • and whether higher-risk jurisdictions regularly appear.

A local agency whose customers, properties and funding are overwhelmingly domestic may have one type of geographical exposure.

An agency specialising in international investment property may have a very different one.

Neither is automatically compliant or non-compliant.

They simply have different risks requiring different controls.

4. What types of properties do you deal with?

The characteristics of the property market also matter.

Consider:

  • residential properties;

  • commercial property;

  • luxury real estate;

  • land;

  • new developments;

  • investment properties;

  • high-value rentals;

  • off-plan transactions;

  • and other property categories.

Also consider typical values.

An agency whose average property transaction is €175,000 may have a different exposure from a firm whose average transaction is €4 million.

The purpose of the BWRA is to recognise these differences rather than pretend every real estate business is identical.

5. What kinds of transactions do you encounter?

Now move from the property to the transaction itself.

Ask:

  • Are transactions normally straightforward?

  • Do corporate purchasers frequently appear?

  • Do you regularly encounter complex ownership structures?

  • Do customers frequently change purchasing entities?

  • Are third-party payments common?

  • Are transactions frequently cross-border?

  • Are unusual financing structures used?

  • Do customers regularly purchase without mortgage finance?

  • How often do you see transactions involving multiple jurisdictions?

  • Do assignments, resales or rapid changes of ownership occur?

This is one reason Know Your Transaction — KYT is so important in real estate AML.

The nature of the transaction can tell you something that customer identification alone cannot.

6. How are properties paid for?

Understanding how transactions are funded is another important risk dimension.

Consider what your agency normally encounters.

  • Bank financing?

  • Private financing?

  • Corporate funds?

  • International transfers?

  • Funds from third parties?

  • Complex financing structures?

  • Transactions involving several accounts or jurisdictions?

Again, none of these automatically indicate money laundering.

The objective is to understand the characteristics of the business so the agency knows when something falls outside its normal pattern.

7. How do you interact with customers?

AMLR also refers to delivery channels.

For a real estate business this might include:

  • face-to-face contact;

  • remote onboarding;

  • email;

  • online platforms;

  • international referrals;

  • agents or intermediaries;

  • remote property transactions;

  • digital identification methods.

A customer physically visiting the agency and providing documentation may create different verification considerations from an overseas customer conducting the complete transaction remotely.

The BWRA should recognise those differences.

8. What controls do you already have?

Identifying risk is only half the exercise.

The next question is:

“What are we doing to control it?”

For example, your business may have:

  • customer identification procedures;

  • beneficial-ownership checks;

  • PEP screening;

  • sanctions screening;

  • customer risk scoring;

  • source-of-funds procedures;

  • Enhanced Due Diligence;

  • transaction assessment;

  • management approval for higher-risk cases;

  • AML training;

  • ongoing monitoring;

  • record-retention procedures;

  • internal reporting procedures.

These are your risk-mitigation measures.

The BWRA should therefore connect:

RISK → CONTROL

For example:

Risk

High proportion of international corporate buyers.

Controls

Corporate verification + beneficial-ownership identification + geographical risk assessment + PEP/sanctions screening + appropriate source-of-funds checks.

That is a risk-based AML approach. Inherent risk and residual risk

There is another useful distinction.

INHERENT RISK

The risk that exists before your controls are applied.

For example:

  • Your business operates in international luxury real estate and regularly handles high-value transactions involving corporate buyers.

  • That creates an inherent exposure.

  • Then you apply controls.

  • CDD.

  • UBO verification.

  • PEP screening.

  • Sanctions checks.

  • Risk assessment.

  • Source-of-funds procedures.

  • KYT.

  • Enhanced Due Diligence where required.

  • Monitoring.

The question then becomes:

"What risk remains after those controls?"

That is your residual risk.

This matters because a BWRA should not simply create a long list of risks.

It should help the business understand:

What risks exist?

How significant are they?

What controls address them?

What risk remains?

Do we need additional controls?

That is a functioning risk-management process.

But does a one-person agency really have to do all of this?

This is where AMLR's proportionality principle becomes extremely important.

The Regulation expressly requires measures to be proportionate to:

  • the nature of the business;

  • its risk;

  • its complexity; and

  • its size.

AMLA's 2026 work on BWRA reinforces this principle.

Its draft guidelines are intended to establish common minimum requirements while ensuring businesses take ownership of their own assessment and make it proportionate to their individual characteristics, risks and complexity.

So consider two examples:

A one-person local agency

Imagine an independent estate agent with:

  • one owner;

  • no employees;

  • primarily local residential transactions;

  • mostly private buyers and sellers;

  • average transaction values around €250,000;

  • very limited corporate activity;

  • little exposure to international customers.

Its BWRA could be relatively simple. It still needs to be meaningful and documented. But there is no reason to make the assessment unnecessarily complex.

Now consider an international real estate group

Imagine another business with:

  • 20 offices;

  • 250 employees and agents;

  • luxury property;

  • international buyers;

  • significant corporate ownership;

  • frequent cross-border transactions;

  • high-net-worth customers;

  • multiple countries;

  • complex financing arrangements.

Its BWRA will naturally need to be significantly more sophisticated.

  • More risks.

  • More segmentation.

  • More controls.

  • More governance.

  • Possibly different risk assessments across business units or geographical areas.

  • Same obligation. Different implementation.

That is proportionality.

It does not mean: “Small businesses do not need AML.”

It means: The AML framework should fit the actual business.

The Business-Wide Risk Assessment cannot be copied from another agency

This is another important point.

Imagine two agencies operating on the same street.

They may appear almost identical.

But:

Agency A handles mostly local residential sellers.

Agency B specialises in foreign property investors purchasing through corporate structures.

Their AML risks are different.

Therefore their BWRAs should also be different.

A generic document downloaded from the internet cannot automatically describe the risk profile of either business.

AMLA's current approach explicitly emphasises that obliged entities themselves must take ownership of their BWRA.

That makes sense.

Nobody understands the activities of a real estate business better than the business itself.

And the BWRA cannot simply be created once

AMLR requires the Business-Wide Risk Assessment to be:

  • documented;

  • kept up to date; and

  • regularly reviewed.

A review is also required when internal or external events materially affect the risk profile of the business.

Imagine an agency that historically only handled local residential transactions.

Then it decides to enter the luxury market.

  • Or starts attracting clients from several new countries.

  • Or launches a remote online sales model.

  • Or begins handling investment transactions through corporate structures.

Its risk profile has changed.

Therefore its BWRA should change too.

AMLR goes further.

Before launching new products, services, business practices or delivery channels — or entering new customer segments or geographical areas — relevant AML risks must be identified and assessed.

In other words:

  • Risk assessment should become part of business planning.

  • Not just compliance administration.

So how should a real estate business actually create its BWRA?

A practical process can look like this:

STEP 1 — Describe your business

  • What do you do?

  • Where?

  • For whom?

  • At what transaction values?

STEP 2 — Identify your risk areas

Look at:

  • Customers

  • Geographies

  • Services

  • Properties

  • Transactions

  • Delivery channels

  • Payment and financing patterns

  • Sanctions exposure

STEP 3 — Identify the individual risk factors

What characteristics increase or reduce risk?

STEP 4 — Determine your inherent risk

Assess the exposure before controls.

For example:

  • LOW

  • MEDIUM

  • HIGH

or another documented methodology appropriate to the business.

STEP 5 — Identify your controls

What procedures currently reduce those risks?

STEP 6 — Evaluate whether those controls are adequate

A control existing on paper does not necessarily mean it is effective.

Ask:

  • Is it actually performed?

  • Is it documented?

  • Does everyone understand it?

  • Can compliance with it be demonstrated?

STEP 7 — Determine residual risk

After applying those controls, what risk remains?

STEP 8 — Identify gaps

Where does the business need:

  • better procedures?

  • better documentation?

  • additional screening?

  • additional training?

  • stronger transaction assessment?

  • more management oversight?

STEP 9 — Create an action plan

The BWRA should lead to action.

Not merely generate a document.

STEP 10 — Review it

Update the assessment as the business or risk environment changes.

This sounds logical. Doing it properly is harder.

And this is exactly where many smaller real estate businesses encounter difficulty.

A large organisation might have:

  • a compliance department;

  • risk specialists;

  • legal advisers;

  • AML officers;

  • internal audit;

  • dedicated software.

A two-person real estate agency normally has none of those.

Yet it still needs a defensible way of answering:

  • What are our AML risks?

  • How did we determine them?

  • What controls address them?

  • And can we demonstrate that?

That is why Immosurance walks the real estate business through the Business-Wide Risk Assessment step-by-step.

Instead of expecting an estate agent to interpret AMLR Article 10 and build a risk methodology from scratch, Immosurance structures the process around the realities of a real estate business.

The business is guided through the relevant areas of risk.

YOUR BUSINESS

What activities do you perform?

YOUR CUSTOMERS

Who do you normally deal with?

YOUR GEOGRAPHICAL EXPOSURE

Where do customers, companies and funds come from?

YOUR REAL ESTATE ACTIVITIES

What properties and services do you handle?

YOUR TRANSACTIONS

What types of transactions normally occur?

YOUR RISK FACTORS

Where are your vulnerabilities?

YOUR CONTROLS

What are you doing to mitigate them?

YOUR RESIDUAL RISK

What remains after those controls?

YOUR ACTIONS

Where does your AML framework need strengthening?

The result is not merely another compliance form.

It becomes the foundation of the company's AML framework.

And everything else should flow from it

This is perhaps the most important point.

The Business-Wide Risk Assessment should not exist separately from the rest of AML compliance.

It should determine how the business designs:

  • its internal AML policy;

  • its Customer Due Diligence procedures;

  • its customer risk assessment;

  • its Enhanced Due Diligence;

  • its PEP and sanctions controls;

  • its Know Your Transaction processes;

  • its monitoring;

  • its training;

  • and its internal controls.

Think of the BWRA as the first layer:

KNOW YOUR BUSINESS

Know Your Customer

Know the Beneficial Owner

Know the Risk

Know Your Transaction

Apply the appropriate controls

Document the decision

Demonstrate compliance

That is why the BWRA is so important.

It turns AML from a collection of generic obligations into a compliance framework that actually reflects the business.

One agent or 500 — start in the same place

The assessment for a one-person estate agency may be much simpler than the assessment for a multinational real estate group.

And that is exactly how it should be. But both should be able to answer the same fundamental question:

“Do we understand the money-laundering risks created by the business we actually conduct?”

If the answer is yes, AML compliance can be built around those risks.

If the answer is no, performing individual KYC checks cannot solve the underlying problem.

Because before you can properly Know Your Customer, you first need to KNOW YOUR BUSINESS.

Immosurance walks you through it — step-by-step.

From understanding your business risk to creating a structured, demonstrable AML framework designed specifically for real estate.

Immosurance — compliance built for real estate.

#AMLR #AMLA #AML #BusinessWideRiskAssessment #BWRA #RealEstate #RealEstateCompliance #AntiMoneyLaundering #KYB #KYC #KYT #CDD #Compliance #RegTech #Immosurance

Early Bird-erbjudande

PRE-REGISTER for the EARLY BIRD CONDITIONS

Exceptional conditions are available for early birds which will no longer be available soon. Secure your preferred pricing before the official launch.
View Pricing