From Risk Assessment to Monitoring Rules: Building the Documentation Chain
Identifying a risk is only the beginning.
A Business-Wide Risk Assessment may conclude that certain customers, products, jurisdictions or transaction patterns create elevated exposure. But that conclusion has little practical value unless it changes how the organisation accepts, assesses, approves, monitors and reviews the relevant relationships.
The real question is not whether the risk has been recorded.
It is whether the risk has travelled through the documentation framework and reached the controls that employees and systems apply in practice.
A risk assessment should lead to decisions
Risk assessments are often treated as standalone governance documents.
They describe the organisation’s exposure, assign risk levels and refer to existing controls. Once approved, they may be reviewed annually or when a material change occurs.
But the assessment itself does not manage the risk.
It should lead to a series of documented decisions:
Is the organisation willing to accept the risk?
Under what conditions?
How should the risk affect the customer classification?
What information must be collected?
When is Enhanced Due Diligence required?
Who can approve the relationship?
What monitoring should apply?
How often should the relationship be reviewed?
What information should be reported to management?
If these decisions are not reflected elsewhere in the framework, the risk assessment remains descriptive rather than operational.
The documentation chain
A material risk will usually need to pass through several layers of documentation:
Business-Wide Risk Assessment
↓
Risk Appetite
↓
Customer Risk Methodology
↓
Onboarding and Due Diligence Requirements
↓
Escalation and Approval Rules
↓
Transaction Monitoring and Ongoing Monitoring
↓
Periodic Review
↓
Management Information
Each layer should answer a different question.
The Business-Wide Risk Assessment identifies the exposure.
The Risk Appetite determines whether the organisation is prepared to accept it.
The Customer Risk Methodology defines how the exposure affects the risk classification of an individual customer.
The onboarding and due diligence requirements specify what information and evidence must be obtained.
The escalation and approval framework determines who has authority to accept the relationship.
Monitoring rules define how the organisation will identify changes, unusual activity or behaviour inconsistent with the expected profile.
Periodic review requirements determine how frequently the relationship should be reassessed.
Management Information allows senior management to understand the scale of the exposure and whether the controls remain effective.
The chain is complete only when the original risk influences all relevant decisions.
A practical example
Consider an organisation that provides payment or financial services to platform-based businesses operating across several jurisdictions.
The Business-Wide Risk Assessment identifies several factors that may increase the organisation’s exposure:
complex payment flows involving multiple parties;
limited visibility over the platform’s underlying users or merchants;
rapid changes in transaction volumes;
activity across jurisdictions with different risk profiles;
reliance on information or controls operated by the platform itself.
Recording these factors in the risk assessment is not enough.
The organisation must decide how they affect the rest of the framework.
Step 1: Risk appetite
The Risk Appetite should clarify whether the organisation is prepared to accept platform-based customers and under what conditions.
For example, the organisation may decide that it will accept such customers only where:
the business model and payment flow are fully understood;
the platform can provide sufficient information about underlying activity;
higher-risk jurisdictions are restricted or subject to additional controls;
transaction data is available at a level that supports effective monitoring;
contractual rights allow the organisation to obtain information and investigate concerns.
The Risk Appetite should not merely state that the organisation has a “low”, “moderate” or “high” appetite. It should define the practical boundaries within which the risk may be accepted.
Step 2: Customer risk methodology
The Customer Risk Methodology should then translate the business-wide exposure into customer-level criteria.
The methodology may consider factors such as:
whether the customer operates as a platform, marketplace or intermediary;
the number and type of underlying participants;
the jurisdictions involved;
expected transaction volumes;
the transparency of payment flows;
the level of control exercised by the customer over its users;
the organisation’s access to transaction and customer-level data;
the use of outsourced compliance or technology providers.
These factors should affect the customer’s risk rating in a clear and repeatable way.
If the Business-Wide Risk Assessment identifies platform models as a material risk, but the Customer Risk Methodology does not recognise them, the documentation chain has already broken.
Step 3: Onboarding questions and evidence
The onboarding process should collect the information needed to apply the methodology. A generic questionnaire may not be sufficient.
The organisation may need to understand:
who the platform’s users or merchants are;
which parties send and receive funds;
whether the customer holds or controls client money;
whether payments are processed on behalf of third parties;
which jurisdictions are involved;
what controls the platform applies to its own users;
what transaction data can be provided;
how prohibited or restricted activity is identified;
how complaints, fraud and suspicious activity are handled.
The documentation chain should therefore connect the identified risk to specific onboarding questions and evidence requirements. A methodology cannot operate effectively if the onboarding process does not collect the information it needs.
Step 4: Enhanced Due Diligence
Where the risk exceeds defined thresholds, the framework should explain what additional due diligence is required.
This may include:
a more detailed review of the business model;
assessment of the platform’s own customer controls;
review of contractual arrangements with underlying users;
analysis of expected transaction flows;
confirmation of data-access rights;
evaluation of higher-risk jurisdictions or sectors;
independent verification of key information;
additional senior management review.
Enhanced Due Diligence should not be described as a general requirement to “obtain further information”. The procedure should explain what additional information is relevant to the specific risk and how it affects the decision.
Step 5: Escalation and approval
The approval framework should define who may accept the relationship.
Higher-risk platform customers may require approval from:
the MLRO;
a designated senior manager;
a risk or customer acceptance committee;
more than one control function, depending on the exposure.
The framework should also define what the approver is expected to assess.
An approval should not become a procedural signature confirming that onboarding has been completed. It should record a reasoned decision that the identified risks are understood, fall within the organisation’s appetite and can be managed through the proposed controls.
Any conditions attached to the approval should also be documented.
For example:
restricted jurisdictions;
transaction limits;
additional reporting requirements;
enhanced monitoring;
a shorter initial review period;
completion of specific remediation before launch.
Step 6: Monitoring rules
This is where many documentation chains fail.
The customer may be classified as high risk and subjected to Enhanced Due Diligence, but once onboarded, the same standard monitoring may apply as for every other customer.
If the original risk relates to complex payment flows, rapid growth or limited transparency over underlying activity, the monitoring framework should reflect those characteristics.
Relevant monitoring may include:
unexpected changes in transaction volume;
activity outside the approved business model;
new or previously undisclosed jurisdictions;
concentration in particular merchants or counterparties;
unusual flow-through activity;
deviations from expected ticket size or frequency;
material changes in the number or type of underlying users;
repeated fraud, complaints or chargebacks;
failure to provide agreed data or reporting;
activity involving restricted sectors or jurisdictions.
Not every risk must result in a unique automated scenario. But the organisation should be able to explain how the identified risk is addressed through automated monitoring, manual review, customer reporting, contractual controls or a combination of these measures.
Step 7: Periodic review
The same risk should also affect the timing and scope of periodic review.
A higher-risk relationship may require:
more frequent review;
reassessment after a significant increase in activity;
review when new jurisdictions or products are introduced;
confirmation that previously imposed conditions remain effective;
renewed assessment of the customer’s own controls;
comparison of actual activity with the profile approved at onboarding.
Periodic review should not simply repeat the original onboarding process.
It should assess whether the assumptions on which the relationship was approved remain valid.
Step 8: Management Information
Senior management should receive information that reflects the risks identified in the Business-Wide Risk Assessment.
For platform customers, this may include:
the number of active relationships;
the proportion classified as higher risk;
the jurisdictions and sectors involved;
transaction volumes;
onboarding rejections and escalations;
approval conditions;
overdue reviews;
monitoring alerts;
material incidents;
breaches of agreed restrictions;
trends in fraud, complaints or suspicious activity.
If a risk is considered material at business-wide level but is invisible in management reporting, senior management cannot meaningfully oversee it.
Where the chain commonly breaks
A documentation chain may fail at any stage.
The risk appears in the BWRA but not in the methodology
The organisation recognises the exposure at business-wide level, but individual customers are not assessed against the same factors.
The methodology identifies the risk, but onboarding does not collect the required information
Employees cannot apply the methodology consistently because the necessary questions and evidence are missing.
The customer receives a higher risk rating, but the treatment does not change
There is no additional due diligence, approval, monitoring or review.
The rating becomes a label rather than a control.
Enhanced Due Diligence is completed, but the conclusions are not carried forward
Important conditions or concerns identified during onboarding are not reflected in monitoring or periodic review.
Approval is required, but decision criteria are unclear
The approver confirms acceptance without a documented basis for assessing whether the risk falls within appetite.
Monitoring is disconnected from the approved customer profile
Alerts focus on generic transaction patterns but do not test the assumptions and restrictions on which the relationship was approved.
Management reporting does not reflect the risk
Senior management receives aggregate figures but cannot see the organisation’s actual exposure to the customer type identified as material.
The chain should work in both directions
A strong documentation chain should be traceable from risk to control.
The organisation should be able to start with a risk identified in the Business-Wide Risk Assessment and follow it through:
risk appetite;
customer classification;
due diligence;
approval;
monitoring;
review;
management reporting.
But traceability should also work in the opposite direction. If a monitoring rule, approval requirement or onboarding question exists, the organisation should be able to explain:
which risk it addresses;
which internal decision created it;
where the relevant criteria are defined;
who owns the control;
how its effectiveness is reviewed.
This helps prevent controls from remaining in place simply because “they have always been there”.
How to test the documentation chain
A practical review can begin with one material risk.
Select a risk from the Business-Wide Risk Assessment and ask:
Where is the organisation’s acceptance position documented?
How does the risk affect the customer risk rating?
What information is collected because of that risk?
What additional control or decision is triggered?
How does the risk affect ongoing monitoring and review?
How is the exposure reported to management?
What evidence shows that the controls are applied?
If the answers cannot be traced across the framework, the risk may have been identified but not fully operationalised.
The objective is alignment, not duplication
Building the documentation chain does not mean repeating the same paragraph in every document. Each document should contribute something different.
The risk assessment identifies the exposure.
The Risk Appetite sets the boundary.
The methodology defines the criteria.
The procedure describes the action.
The approval framework allocates authority.
Monitoring identifies changes and unusual activity.
Periodic review reassesses the relationship.
Management Information supports oversight.
The strength of the framework lies in the alignment between these functions.
Key takeaway
A risk recorded in a Business-Wide Risk Assessment should not remain contained within that document. It should change how the organisation assesses customers, collects information, performs due diligence, grants approvals, monitors activity, conducts reviews and reports exposure to management.
The purpose of the documentation chain is to make that connection visible and repeatable.
A risk is not fully managed because it has been identified. It is managed when it reaches the decisions and controls that shape how the organisation operates.


Comments