Skip to content
ProofVoltSend us a company

Risk-based approach (RBA)

Checked against the official texts on .

The risk-based approach means identifying and assessing the money-laundering and terrorist-financing risks a firm is exposed to, and then applying controls in proportion to those risks: more scrutiny where risk is higher, less where it is demonstrably lower. It is the organising principle of both the FATF standards and EU anti-money-laundering law.

Also called: RBA, risk-sensitive approach.

Why it matters for PSPs and EMIs

A payment institution with thousands of merchants cannot apply the same depth of checks to all of them, and is not expected to. It is expected to know which of its customers, products, channels and geographies carry more risk, to act on that, and to show the reasoning when a supervisor asks.

What the law says

  • At firm level. AMLR Art. 10: a documented business-wide risk assessment, drawn up by the compliance officer, approved by the management body, kept up to date, and supplemented by a specific assessment before new products, services, channels or technologies are launched.

  • At customer level. AMLR Art. 20(2): the extent of customer due diligence follows an individual risk analysis, taking into account the business-wide assessment, the risk variables in Annex I and the risk factors in Annexes II (lower risk) and III (higher risk). Higher risk leads to enhanced measures (Art. 34), lower risk may allow simplified measures (Art. 33).

  • Accountability. AMLR Art. 20(4): the firm must be able to demonstrate that its measures are appropriate to the risks identified.

  • Guidance to come. AMLR Art. 20(3): AMLA guidelines on risk variables and risk factors (due by 10 July 2026). Art. 10(4): AMLA guidelines on the business-wide risk assessment; AMLA has consulted on a draft, and on its overview of 28 September 2026 the guidelines were not yet final.

  • International standard. FATF Recommendation 1 (assessing risks and applying a risk-based approach).

How ProofVolt handles it

In ProofVolt, approvals can require a second pair of eyes where the risk requires it. A risk never disappears: no later document, round or AI output can quietly clear it.

Sources

Informational only, not legal advice.