Risk Assessment Policy
How the Company assesses its AML and regulatory compliance risk, rates it, and keeps the assessment current.
| Field | Value |
|---|---|
| Document | Risk Assessment Policy |
| Version | 1.0 |
| Owner | Compliance Officer |
| Review | Annual, or on material change |
Authorities
This policy implements, within the sponsor bank's program:
- FFIEC BSA/AML Examination Manual, BSA/AML Risk Assessment, the expectation that a program rests on a documented assessment of products, customers, geographies, and delivery channels.
- 31 CFR 1020.210, the anti-money-laundering program rule, under which risk-based controls flow from the assessment.
- CFPB Supervision and Examination Manual, Compliance Management Review, for the regulatory compliance risk assessment.
- The sponsor bank's program agreement, which sets the assessment cadence and the bank's review of it.
1. Purpose and Methodology
The Company maintains two risk assessments: an AML risk assessment covering money-laundering and terrorist-financing risk, and a regulatory compliance risk assessment covering consumer-protection and other non-AML regulatory risk. Each is the document every other control traces back to: it decides where controls go, how customers are tiered, how monitoring rules are built, and what the independent audit covers.
Both use a three-component method. Inherent risk is the likelihood and impact of a violation or misuse if no controls existed. Control effectiveness is the strength and maturity of the controls in place. Residual risk is what remains after the controls are applied. Ratings are High, Moderate-High, Moderate, Low-Moderate, and Low.
2. Scope
The AML risk assessment covers the program the Company operates under its sponsor bank's charter, including every product, customer segment, geography, and channel that moves or holds funds. The regulatory compliance risk assessment covers the federal, state, and sponsor bank requirements that apply to those same products and customers. Where a topic sits in both, such as sanctions screening, the AML assessment owns the analysis and the regulatory assessment references it.
3. AML Inherent Risk Dimensions
Inherent AML risk is scored across four dimensions:
- Customer. Each customer type is described with its key risk factors: the nature of its business, its regulatory status, how its beneficial ownership can be corroborated, and whether consumers reach the Company through it. Enhanced due diligence applies to customer types the assessment rates High and to any customer whose owners are politically exposed, carry adverse media, or come from elevated-risk jurisdictions.
- Product. Each product is listed with the money-laundering typologies it could carry: commingling and layering through accounts, structuring through payment rails, return manipulation, round-dollar and velocity patterns in wires, jurisdiction and correspondent risk in cross-border transfers, credit used as a layering vehicle, and the distinct typologies of digital assets where they are offered.
- Geography. The Company's own operating jurisdictions, its customers' operating jurisdictions, and the jurisdictions of counterparties and wallets that send or receive funds are each rated, with elevated-risk and listed jurisdictions driving screening, monitoring, and escalation.
- Channel. How customers are onboarded and how transactions reach the Company. Non-face-to-face digital onboarding is standard for the program and is mitigated by document-based verification; where consumers transact through a customer's platform, the customer's own controls are part of the channel risk.
4. Regulatory Compliance Risk
The regulatory compliance risk assessment keeps a regulatory inventory and rates the risk of each requirement product by product:
- Regulatory inventory. The federal laws that reach the program, such as electronic fund transfer, unfair or deceptive practices, privacy and safeguarding, funds availability, payment network rules, marketing and endorsement standards, deposit insurance disclosure, accessibility, and telephone consumer protection rules; the sponsor bank's third-party oversight expectations; and the state privacy, lending, money transmission, and consumer financial services laws that apply.
- Product-by-product risk. For each product, the specific compliance risks and the control that addresses each, rated for inherent risk, control effectiveness, and residual risk.
- Customer cohort risk. The regulatory considerations specific to each customer segment, including any industry-specific licensing, reporting, or disclosure duties that reach the Company as a service provider.
5. Control Environment and Residual Risk
Each control that mitigates an identified risk is listed with its status and an adequacy assessment. Residual risk for each dimension is inherent risk adjusted for control effectiveness, and an overall program rating is derived from the dimensions that drive it. The control assessment names any control that is not yet implemented or configured, because an unimplemented control leaves the inherent risk in place.
6. Rating Scale and Required Response
| Rating | Meaning | Response |
|---|---|---|
| High | A significant threat to program viability or regulatory standing | Immediate remediation; escalate to the board and the CEO |
| Moderate-High | Meaningful control gaps creating exposure to a violation | Remediation roadmap with a 30 to 90 day timeline |
| Moderate | Notable risk requiring monitoring and modest control enhancement | Integrate into the annual compliance plan |
| Low-Moderate | Minor or emerging risk; controls adequate with routine maintenance | Monitor in the annual review cycle |
| Low | Minimal or mitigated risk requiring standard care | Standard operational baseline |
7. Mitigation Actions
Each assessment ends with the actions required to bring residual risk to an acceptable level, each with an owner and a date. Actions are tracked to closure and their status is reported with the quarterly compliance report. A mitigation that misses its date is escalated under the Issues Management Policy.
8. Review Cadence and Triggers
Both assessments are reviewed and updated annually. A targeted reassessment is triggered out of cycle by any material change: a new product or product feature, a new customer segment or geography, a significant regulatory change, a control failure, or the implementation of a new control. The Compliance Officer may refresh a section on a shorter cycle where warranted.
9. Approval, Distribution, and Recordkeeping
Each assessment is prepared by the Compliance Officer, approved by the CEO, and provided to the sponsor bank's compliance team for review. Supporting workpapers, control assessments, and mitigation tracking are retained for seven years under the Recordkeeping Policy.