Back to Glossary

Entry · Business

Risk-Based Approach

A risk-based approach means directing your controls, checks and resources towards the areas most likely to cause harm, instead of applying identical procedures to everything. It is the standard expectation in anti-money-laundering rules, audit planning, health and safety and supplier management.

The idea is simple: spend more effort where the risk is higher and less where it is low, and be able to show the reasoning behind that split.

What it means

The alternative, sometimes called a rules-based or tick-box approach, applies the same procedure to every case regardless of circumstance. It is easy to administer and easy to audit, but it wastes effort on low-risk cases and often fails to catch the unusual high-risk one that does not fit the standard test.

A risk-based approach accepts more judgement in exchange for better coverage where it counts. The method has four steps that repeat: identify the risks, assess each one for likelihood and impact, apply controls in proportion to the score, then monitor and revise as circumstances change.

The scoring does not need to be sophisticated, and a simple high, medium and low rating with a written rationale is usually enough for a smaller organisation. What regulators care about is that the rating exists, is documented and actually drives what you do.

In financial compliance the approach is explicit. Customer due diligence is scaled by the risk a customer presents, so a domestic salaried customer with a small account gets simplified checks while a business customer with complex ownership in a higher-risk jurisdiction gets enhanced due diligence and more frequent review.

Applying enhanced checks to everyone would be both unaffordable and, oddly, less effective, because the genuine signals get buried. The same logic runs through audit and operations.

An auditor concentrates testing on the accounts most likely to contain a material error, and a procurement team runs full financial and security reviews on critical suppliers while accepting a short questionnaire from a stationery vendor. In every case the freed-up capacity moves to where the exposure sits rather than disappearing.

The main pitfall is using the approach to justify doing less across the board. A risk assessment that finds everything low risk and quietly halves the compliance budget is not a risk-based approach; it is a cost cut with paperwork attached.

Regulators test this by asking to see the assessment, the evidence behind the ratings and examples of cases where a high rating actually produced more work.

In practice

Real-world examples.

1

Example

A payments company segments its merchant base into three risk tiers and moves two compliance analysts from routine low-risk file reviews onto enhanced due diligence for high-risk merchants. Suspicious activity reports rise in the first year, which the regulator treats as evidence the approach is working.

2

Example

An external audit team reviews a manufacturer and concentrates testing on inventory valuation and revenue cut-off, the two areas where estimates and timing create the most scope for material error. Petty cash, which totals $8,000, is reviewed analytically rather than tested in detail.

3

Example

A hospital's procurement function grades suppliers by the consequence of failure. The single-source supplier of surgical implants gets an annual site visit and financial review, while the office furniture supplier completes a one-page self-assessment every three years.

Think of it

Risk-based approach means focusing on the biggest risks-prioritizing by risk level.

Formula

Calculation

Review effort = Sum over each risk tier of (Customers in tier x Hours per review / Review frequency in years). A bank has 4,000 business customers. It classes 200 as high risk, reviewed every year at 3 hours each, giving 200 x 3 = 600 hours. It classes 800 as medium risk, reviewed every two years at 1.5 hours each, giving 800 x 1.5 / 2 = 600 hours. The remaining 3,000 are low risk, reviewed every five years at 0.5 hours each, giving 3,000 x 0.5 / 5 = 300 hours. Total annual effort is 600 + 600 + 300 = 1,500 hours. Under a flat approach reviewing all 4,000 customers annually at 1.5 hours each, the requirement would be 4,000 x 1.5 = 6,000 hours. The risk-based model saves 6,000 - 1,500 = 4,500 hours, a 75% reduction, while devoting six times more attention per customer to the 200 accounts that carry most of the exposure.

Case study

Seen in the real world.

The following is an illustrative and fictional example. Aldercrest Bank, an invented mid-sized commercial bank, had been reviewing all 4,000 of its business customers annually at roughly 1.5 hours each, consuming 6,000 hours a year from a team that was permanently behind schedule.

A new compliance director built a risk model scoring customers on ownership structure, jurisdiction, transaction patterns and industry. It produced 200 high-risk customers reviewed annually at 3 hours, 800 medium-risk reviewed every two years at 1.5 hours, and 3,000 low-risk reviewed every five years at half an hour, for a total of 1,500 hours a year. The team went from overloaded to having capacity for investigation work it had never been able to do.

The fictional part that mattered to the board was not the 4,500 hours saved but what the freed capacity found: two customer relationships with layered ownership that the old uniform process had rated as satisfactory five years running. This illustrative case shows the point of the approach, which is better detection rather than lower cost, even though the cost saving is the number that gets quoted.

Watch out

Common mistakes.

  • Using a risk assessment to justify reducing controls everywhere, rather than moving effort from low-risk areas into high-risk ones.
  • Writing the risk assessment once and never updating it, so the ratings no longer match the business the organisation actually does today.
  • Rating risk without documenting the reasoning, which leaves nothing to show a regulator or auditor who asks why a customer was classed as low risk.

Questions

People also ask.

Is a risk-based approach cheaper than checking everything?

Usually yes in total effort, but the saving comes from reallocating work rather than removing it, and high-risk cases should cost noticeably more to handle.

How often should risk ratings be refreshed?

At minimum annually, and immediately when something changes, such as a customer entering a new market or a supplier becoming single-source.

What evidence do regulators expect to see?

A documented methodology, the ratings themselves, the evidence behind them and examples showing that a high rating genuinely produced additional checks.

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · September 5, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.