Enterprise-wide financial crime risk assessment

The assessment that writes the report as you complete it.

Answer structured questions and every scored response produces an immediate risk signal — while your report, risk tables and year-on-year analysis build alongside. No separate reporting exercise at the end.

Enterprise-wide Risk AssessmentFY 2026 assessment
OVERALL RESIDUAL RISKModerate
In review
Customer riskHigh
Product riskModerate
Geographic riskModerate
Channel riskLow

Visible progress, question by question

See the risk take shape.

01 / Answer

Enter the figures you know.

Capture current and prior-year data once, against a structured question and clear rationale.

02 / Understand

See what the answer means.

Percentage change, score and risk signal appear immediately, with the calculation kept visible.

03 / Report

Build the record as you go.

The result flows into the risk table and overall assessment without a separate reporting step.

One answer. An immediate signal. One less section to assemble later.

Where assessments break down

Do you make these common mistakes in your risk assessment?

01

No documented firm-wide assessment

Risk is discussed, but the rationale, evidence and firm-wide conclusion are not recorded in one defensible assessment.

02

Out-of-date methodology

The framework no longer reflects the business, current financial crime threats or the way risk is actually managed.

03

No audit trail of reviews and sign-off

Comments, challenges and approvals sit across inboxes and files, leaving no reliable record of who decided what, and when.

Different names, the same core obligation

UK supervisors are asking harder questions about organisation-wide financial crime risk.

Terminology varies by sector. Financial services commonly uses business-wide or enterprise-wide risk assessment; legal services generally uses firm-wide risk assessment. In every case, the assessment must reflect the organisation, address the relevant risk factors and show how the conclusion was reached.

Financial services

FCA-regulated firms

The FCA has published good and poor practice from reviews focused on business-wide and customer risk assessments. In a separate 2025 survey, 11% of responding corporate finance firms reported having no documented business-wide risk assessment.

Read the FCA survey findings
Try the financial services demo

No sign-up needed. Sample data only.

Legal services

SRA-regulated firms

The SRA says a significant proportion of firm-wide risk assessments still fall short of its expectations. Its published supervisory record includes compliance plans, referrals for investigation and fines where no compliant assessment was in place.

AML supervision is moving to the FCA. The Government has decided that the FCA will take over AML/CTF supervision of legal-sector firms. Legislation and the transition timetable are still pending, and the SRA remains responsible until the transfer is complete. The firm-wide risk assessment obligation continues throughout.

Read about the transfer of AML supervision See the SRA supervisory findings
Try the legal practice demo

No sign-up needed. Sample data only.

One product, two dedicated sector configurations.

Rotunda supports business-wide assessments for financial services and firm-wide assessments for legal practices, with sector-specific questions, risk factors, terminology and reporting informed by the relevant regulatory guidance. Your organisation remains responsible for its own risk-based judgement and regulatory obligations.

A controlled assessment lifecycle

From inherent risk to signed-off report.

Rotunda gives each stage of the EWRA a clear owner, method and record. The result is easier to maintain, explain and challenge.

01 / Map the risk

Five domains, one firm-wide view

Assess customers, products, geography, channels and emerging risks through structured, evidence-backed questionnaires.

  • Consistent questions and scoring criteria
  • Evidence and rationale captured at source
  • Separate sanctions risk assessment module
02 / Assess the controls

Make residual risk traceable

Score control design and operating effectiveness against inherent risk. Rotunda applies a consistent calculation and keeps the inputs visible.

  • Control effectiveness scoring
  • Transparent residual risk calculation
  • Clear record of overrides and rationale
03 / Govern the outcome

Review, challenge and report

Move the assessment through defined review and challenge, compare the result year on year, then produce a clear record for senior management and regulators.

  • Review and challenge workflow
  • Year-on-year comparison and audit trail
  • PDF and CSV regulator-ready reports
See every feature

Purpose-built

Built for one job. Designed to finish it.

Rotunda is not a general-purpose GRC platform, continuous monitoring system or integration programme. It exists to produce a governed, defensible firm-wide or enterprise-wide risk assessment, properly.

NotA general-purpose GRC platform
NotA continuous monitoring system
NotAn integration programme
It isA focused system for producing a governed, defensible firm-wide or enterprise-wide risk assessment.

A proportionate investment

Know the cost of the alternative.

An EWRA should stand up to scrutiny without consuming months of specialist time. Compare the implementation cost, operational drag and potential exposure.

Illustrative figures only. External engagement costs vary by scope. The SRA can fine traditional firms up to £25,000; FCA penalties for financial crime control failures have run into millions. The Rotunda price is the founding-customer rate for the first 12-month term.

ApproachIndicative cost
External projectConsultant-built EWRA£5,000–£15,000Typical external engagement
Potential exposureRegulatory finesUp to £25,000SRA maximum for traditional firms; other regulators higher

A better way to run your EWRA

Make your next assessment easier to defend.

See how Rotunda turns a fragmented exercise into a controlled, repeatable process.

Book a demo