For the first time in EU AML/CFT history, the methodology a supranational supervisor will use to grade financial institutions is publicly available. AMLA’s risk scoring framework – defined in the final Regulatory Technical Standard under Article 12(7) AMLAR – is detailed enough that compliance teams can study its structure, understand its logic, and adapt it for their own Business-Wide Risk Assessment before July 2027.
Our latest white paper, “AMLA’s Risk Scoring Methodology: A Blueprint for Your Own AML Risk Assessment,” breaks down how the framework works – and what every obliged entity should take from it.
The Three-Step Logic Behind AMLA’s Supervisory Model
AMLA’s methodology resolves a long-standing debate in AML risk practice. Rather than measuring risk along a probability-versus-impact axis, it adopts the inherent–controls–residual model — the same structural logic used in COSO ERM, ISO 31000, and the Wolfsberg Group’s financial crime frameworks. Three sequential steps drive the assessment:
- Inherent Risk Score – captures ML/TF exposure across four categories: customers, products and services, distribution channels, and geographies, scored on a 1–4 scale through weighted arithmetic averages
- Controls Quality Score – assesses the effectiveness of the AML/CFT programme across six categories: governance and culture, internal controls, risk assessment quality, CDD, transaction monitoring and SAR, and targeted financial sanctions
- Residual Risk Score – derived through a conditional rule: where controls are stronger than inherent risk, residual equals inherent; otherwise, the two are averaged – a design that stops institutions from explaining away exposure with self-assessed controls
Entities scoring 3.25 or above on the residual scale fall into the High risk band and become candidates for direct AMLA supervision.
Why This Matters Beyond the 40 Directly Supervised Entities
AMLA will directly supervise only 40 institutions. But the same data points that feed AMLA’s scoring model will be reported to national supervisors from 10 July 2027 under the parallel RTS on Article 40(2) AMLD6. In practical terms, the methodology will quietly become the lens every obliged entity is judged through – not just the largest cross-border institutions.
Institutions that align their BWRA architecture with AMLA’s four inherent and six controls categories now will be best positioned when supervisors begin applying the framework in their own assessments.
What’s Inside the White Paper
The analysis covers:
- Why AMLA adopted the inherent–controls–residual model and what it signals about supervisory expectations across the EU
- A step-by-step reconstruction of AMLA’s scoring methodology from the publicly available RTS, with illustrative examples for a mid-sized payment institution
- How the conditional residual risk rule works – and why it is one of the most valuable elements to import into your own framework
- Where AMLA’s methodology fits at entity level (BWRA) and where it does not (individual customer risk scoring)
- Five practical steps for adapting the framework to your own institution’s data, thresholds, and risk profile
- How to use the AMLA model as an early-warning tool – running your own numbers before the supervisor does it for you
Download the Full White Paper
👉 Click below to download “AMLA’s Risk Scoring Methodology: A Blueprint for Your Own AML Risk Assessment” – prepared by Eglė Kontautaitė, Head of Client Solutions at AMLYZE, with over 13 years of AML/CFT supervisory experience at the Bank of Lithuania.





