OUT-LAW ANALYSIS

Why regulated firms must move beyond static risk assessments

Documents pile and magnifying glass

The future operating model will move beyond annual assessments and periodic reviews. bernie_photo/iStock.


Regulated firms in the UK should fundamentally rethink the way they identify risk, govern technology, measure control performance and make risk-sensitive decisions to address the potential for disconnect between the risk they assess and the risk they actually hold.

The publication of the UK government’s anti-money laundering and asset recovery strategy 2026-2029 (101-page / 5.4MB PDF) encourages firms to think differently in this respect.  Although the strategy focuses on money laundering and asset recovery, its underlying message extends across regulated sectors and challenges firms to focus on the highest-harm risks, reduce low-value activity, integrate intelligence and use people and technology more effectively.

For too long, organisations have built increasingly complex compliance frameworks around static assessments, periodic reporting and expanding control inventories. However, in an environment where risks emerge and evolve quickly, many firms may be managing an historical view of yesterday’s risks rather than fully understanding where risk exists today.

The BWRA should be the beginning, not the end

Many firms continue to treat the business wide risk assessment (BWRA) as an annual compliance deliverable. That approach is increasingly outdated. A modern BWRA should operate as the intelligence engine of the organisation, linking external threats and internal exposure to the design, operation and assurance of the control ecosystem.

Deep-dive analytics across customers, products, transactions, jurisdictions, delivery channels, counterparties, third parties, incidents and emerging typologies should identify where inherent risk genuinely resides. Only then can firms design proportionate controls, deploy scarce capability intelligently and make defensible decisions about risk acceptance, remediation and investment.

The challenge is that risk does not remain fixed between assessment cycles. Threats evolve, customer behaviour changes, products and distribution models develop, technology creates new vulnerabilities and regulatory expectations mature. The BWRA must therefore become an iterative process, refreshed when defined indicators show that the underlying risk profile has moved.

Controls are degrading assets

A second weakness is the assumption that a control, once implemented, continues to operate as designed. In practice, controls degrade. Processes drift, experienced staff leave, workarounds emerge, volumes rise, data quality falls, thresholds become outdated and system changes create unintended gaps.

The documented control environment may therefore remain unchanged while actual operating effectiveness deteriorates beneath the surface. If that deterioration is not identified promptly, the residual risk reported to senior management can remain artificially low and increasingly detached from operational reality.

This creates three moving variables that must be governed together:

  • inherent risk changes as the external threat and the firm’s exposure evolve;
  • control effectiveness changes as people, process, data and technology performance move;
  • residual risk changes as the relationship between exposure and mitigation changes.

A static residual risk rating cannot reliably represent a dynamic system. It should be treated as a conclusion supported by current evidence, not as a score carried forward until the next formal review.

Technology governance is now control governance

Automated onboarding, sanctions screening, transaction monitoring, customer risk models, behavioural analytics, workflow engines and AI-supported decision tools now sit at the centre of many control frameworks. As such technology is now, therefore, often the control and no longer merely an operational enabler.

This means technology governance must be integrated directly into risk and control governance. A control cannot be assessed as effective if the model, rules, data, interfaces or infrastructure on which it depends are not also demonstrably effective.

For each material technology-enabled control, governance should establish:

  • a named business control owner and a named technology service or model owner;
  • approved purpose, risk coverage and intended outcomes;
  • data lineage, quality standards and critical upstream dependencies;
  • model, rule and threshold governance, including validation and change control;
  • access, resilience, cybersecurity and business-continuity requirements;
  • human override and exception protocols, with monitoring for inappropriate use;
  • testing frequency, performance tolerances and escalation triggers;
  • a documented decision trail for material changes, risk acceptance and remediation.

Deployment approval is not the end of governance. Material technology should move through controlled design, validation, approval, implementation, monitoring, recalibration and retirement stages, with independent challenge proportionate to the risk it carries.

Decision governance must be explicit

Committee structures alone do not create effective governance. Firms also need to govern the decisions those committees and accountable executives make. Every material risk or control decision should leave a clear, reviewable record.

That record should evidence the decision owner, the intelligence available, the assumptions made, the data and control metrics considered, the challenge applied, the options rejected, the rationale selected, any conditions or time limits, and the mechanism for post-decision review.

Decision rights should follow severity. Routine tuning can be delegated within approved tolerances. Material model changes, risk-acceptance decisions, persistent control failures and movements outside appetite should escalate to the appropriate executive or board committee. Second-line challenge should be independent and evidenced, while the internal audit function should provide periodic assurance over whether the governance system itself is designed and operating effectively.

Every material control needs a defined metric set

Controls should be measured by whether they remain available, effective, timely and sustainable, and whether they are producing the intended risk outcome.

Dimension

Governance question

Illustrative metrics

What it reveals

Availability

Is the control operating as designed?

System uptime; execution success; workflow completion; failed jobs; unprocessed population

Whether the control was present

Coverage

Is the relevant risk population being assessed?

Population coverage; exclusions; unmapped products; data-feed completeness; scenario coverage

Whether exposure is being missed

Effectiveness

Is the control preventing, detecting or correcting risk?

True-positive yield; detection rate; escape rate; repeat failures; loss or incident outcomes

Whether the control changes risk

Timeliness

Does the control act within the required window?

Queue ageing; time to alert; investigation cycle time; escalation latency; overdue actions

Whether intervention is early enough

Quality

Are decisions and outputs accurate and consistent?

Quality assurance pass rate; rework; decision overturns; documentation quality; data defects

Whether outputs are reliable

Sustainability

Can performance be maintained?

Capacity utilisation; backlog; attrition; key-person dependency; resilience tests; technical debt

Whether performance can endure

Change sensitivity

Is the control keeping pace with risk?

Threshold drift; model stability; typology coverage; tuning frequency; post-change defects

Whether the control remains relevant

Outcome

Is residual risk actually reducing?

Incidents; losses; customer harm; regulatory breaches; risk appetite position; remediation recurrence

Whether the ecosystem works

No single metric proves effectiveness. Metrics must be read together, with defined thresholds, tolerances, trend rules and escalation routes. Volumes alone can be actively misleading: more alerts may indicate stronger detection, excessive false positives, worsening risk or poor calibration. Governance must interpret cause, not simply report movement.

Interactive monitoring is the missing layer

Monthly committees and quarterly reporting remain important, but they are insufficient where threat, exposure and control performance can change daily. Firms should move towards interactive monitoring that connects risk indicators, control metrics, technology telemetry, incidents, assurance findings and remediation status.

An effective monitoring environment should allow accountable leaders to move from an enterprise view to the underlying risk, business line, control, technology component, owner and evidence. It should distinguish leading indicators from lagging outcomes and show not only current status but trend, volatility, data confidence and the reason for movement.

The monitoring cycle should operate as follows:

  • detect: automated and human indicators identify a change in exposure or control performance;
  • triage: the accountable owner determines materiality, scope and immediate containment needs;
  • challenge: Risk, Compliance, Technology Risk or Model Risk tests the evidence and assumptions;
  • decide: the authorised forum accepts, mitigates, escalates or stops the activity within defined decision rights;
  • act: controls, thresholds, resources, processes or customer treatment are adjusted;
  • validate: testing confirms whether the intervention achieved the intended outcome;
  • recalibrate: inherent and residual risk, appetite usage and resource priorities are updated.

Interactive monitoring is a governed feedback mechanism. It should trigger action when performance moves outside tolerance and retain an audit trail showing what was known, what was decided and whether the response worked.

Residual risk must be iteratively validated

Residual risk should be recalibrated whenever there is a material movement in inherent risk, control coverage or control effectiveness. Firms should define both scheduled reviews and event-driven triggers, including new typologies, product launches, acquisitions, material system changes, rapid volume growth, data failures, control breaches, adverse assurance results and sustained metric deterioration.

Where evidence is incomplete or unreliable, governance should reduce confidence in the residual risk assessment rather than default to the previous rating. A residual risk score without current control evidence is not a reliable measure. It is an unsupported assumption.

Boards therefore need to see both the residual risk position and the confidence attached to it. Reporting should distinguish between risk that is within appetite because controls are demonstrably effective and risk that appears within appetite only because testing, data or monitoring is incomplete.

A new operating model for regulated firms

The future operating model will move beyond annual assessments and periodic reviews. It will be a continuously learning ecosystem in which:

  • deep-dive analytics identify changes in inherent risk;
  • the BWRA translates external threat and internal exposure into clear control requirements;
  • technology governance validates the data, models and systems on which controls depend;
  • defined control metrics show whether controls remain available, effective, timely and sustainable;
  • interactive monitoring identifies deterioration and drives timely escalation;
  • decision governance records accountability, challenge, rationale and outcomes;
  • residual risk is recalibrated as risk and control evidence change;
  • resources are redirected to the areas where they can achieve the greatest reduction in harm.

The government’s strategy is right to emphasise targeting, integration and empowerment. For regulated firms, the practical challenge is to apply those principles inside their own operating models: target the risks that matter, integrate intelligence and controls, and empower accountable owners to act on evidence.

Co-written by Gregor Gottlieb of Pinsent Masons.

We are processing your request. \n Thank you for your patience. An error occurred. This could be due to inactivity on the page - please try again.