How to run a financial crime typology risk assessment
A typology risk assessment maps the specific financial crime methods relevant to your firm to the controls needed to detect them. This is how to approach it, what the FCA expects to see, and the common gaps that lead to enforcement action.
A typology risk assessment sits inside the broader business-wide risk assessment (BWRA) that the MLR 2017 and the FCA both require. Where the BWRA identifies the categories of financial crime risk a firm faces, the typology risk assessment goes one level deeper: it identifies the specific methods criminals use in the context of that firm's products, customers and geography, and maps those methods to the controls needed to detect them.
The distinction matters because it determines what controls a firm actually deploys. Two firms might both assess themselves as high risk for money laundering, but if one distributes payments to consumers and the other provides trade finance to corporates, the typologies that are relevant to them are completely different, and so are the controls.
Step 1: Identify your firm's exposure by axis
The FATF Recommendations and JMLSG Guidance both describe the risk assessment as requiring a firm to consider risk across several dimensions: customer types, products and services, delivery channels and geographic exposure. The typology risk assessment adds a further dimension: which financial crime methods are associated with each combination of those factors.
For example, a firm that offers cross-border payments to high-net-worth individuals in higher-risk jurisdictions should assess typologies including offshore layering, source-of-wealth concealment and sanctions evasion via intermediaries. A firm that offers digital current accounts to retail consumers should assess typologies including money mule networks, account takeover, and structuring below reporting thresholds.
This is not a theoretical exercise. The FCA expects firms to be able to explain which typologies they have assessed as relevant and why, and to show that their controls are designed to detect those specific methods.
Step 2: Score and prioritise
Not all typologies present equal risk to every firm. A firm needs to score each typology across the relevant dimensions, weighting by the inherent likelihood given the firm's business model and the impact if the typology were exploited undetected.
Scoring should be documented and should reflect the firm's own data and intelligence, not just sector guidance. Firms that can point to actual cases of mule accounts detected, or SARs filed on a particular typology, have a stronger evidence base for their scoring than firms that rely entirely on external publications.
The output of this step should be a ranked list of typologies that drives the allocation of monitoring and control effort. The FATF risk-based approach principle applies here: more effort on higher-scoring typologies, less on demonstrably lower-risk ones.
Step 3: Map typologies to controls
For each material typology, the firm needs to identify the controls that are designed to detect it and assess whether those controls are in place and operating effectively. This is the bridge between the risk assessment and the control framework.
Where a material typology has no corresponding control, that is a gap that needs to be addressed. Where a control exists but is miscalibrated, undocumented or not being reviewed, the typology is not genuinely mitigated even if the control appears on paper.
The FCA Financial Crime Guide describes what the regulator looks for: controls that are explicitly designed to address the specific risks the firm has identified, with documented rationale for the design choices and evidence of ongoing effectiveness monitoring.
Step 4: Review and update
A typology risk assessment is not a one-time exercise. New typologies emerge, product sets change, and the external environment shifts. The FATF updates its typology guidance regularly, and national financial intelligence units publish sector-specific alerts. Firms need a process for incorporating new intelligence into their assessment.
The MLR 2017 requires the BWRA (and therefore the typology assessment within it) to be kept up to date. In practice this means an annual review as a minimum, with interim updates when a material change occurs in the business or when credible intelligence suggests a new typology is targeting the firm's sector.
Common gaps the FCA finds
The most common gap in typology risk assessments that the FCA identifies in supervisory work is that the assessment exists at a high level of abstraction but does not drive specific control decisions. A risk assessment that concludes the firm faces money laundering risk without specifying which typologies are most relevant, or what controls address them, does not satisfy the regulatory expectation.
A second common gap is that the assessment is written as a point-in-time document rather than a living framework. When the FCA asks to see evidence of how the assessment has been updated in response to new intelligence or product changes, firms that cannot provide it are demonstrating a process weakness rather than just a documentation one.
Try the tool
TypologyIQ maps the financial crime typologies most relevant to your firm type, products and customers. The output is a scored list of typologies with the detection controls for each, grounded in FATF, JMLSG and FCA frameworks.
Start a typology risk assessmentSources
- FFATF · FATF Recommendations
- JJMLSG · JMLSG Guidance
- FFCA · FCG
- MMLR · MLR 2017