A client risk assessment is the written record of why you rated a client low, normal or high: who the client is, who owns and runs it, what you do, how you deal with it, where it operates, and why you chose that rating. Your supervisor can ask to see it, so each conclusion and source must be clear.
- What a client risk assessment is, and why it must be written down
- The five things the file must show
- What Companies House can fill in, and what it cannot
- Turning the factors into a rating: low, normal or high
- Keeping the assessment current
- Checklist you can copy
- FAQ
What a client risk assessment is, and why it must be written down
A client risk assessment explains the risk in a particular client relationship and the checks that follow from it. Regulation 28(12) says your due diligence must reflect both the firm-wide risk assessment and your assessment of the risk in the particular case. Regulation 28(16) says you must be able to show your supervisor that the extent of those measures was appropriate to the risk.
The file should not be a blank form with a risk label added at the end. It should show:
- the information considered;
- the source of important facts;
- the factors that increased or reduced risk; and
- the reason for the final rating.
The CCAB Anti-Money Laundering and Counter-Terrorist Financing Guidance for the Accountancy Sector 2026 says at paragraph 4.7.1 that the assessment must be documented and made available to the supervisor on request. The same guidance is available through the CCAB accountancy sector guidance.
Read regulation 28 alongside the Money Laundering Regulations. The exact form is for the practice to decide. The evidence and rationale are not optional.
The five things the file must show
A usable file covers identity and ownership, client risk, service risk, geographic risk and delivery channel risk. It should also state the purpose and intended nature of the relationship. These categories follow section 4.6 of the CCAB guidance and the customer due diligence requirements in regulation 28(2) and 28(4).
1. Identity and ownership
Record the client’s legal identity, legal form, registration details and the people who own or control it. Record how identity was checked. Regulation 28(2) requires you to identify and verify the customer, and regulation 28(4) to identify the beneficial owner and take reasonable measures to verify who they are.
2. Client risk
Consider the legal form, sector, ownership structure and control arrangements. Complex or secretive ownership can increase risk under paragraph 4.6.4. Consider whether a person is a politically exposed person, as addressed in paragraph 4.6.5, and record the outcome of your checks.
3. Service risk
Describe the services your practice will provide and why they create a particular level of risk. Paragraphs 4.6.9 to 4.6.13 cover service risk. Services where the practice itself could be drawn into a money laundering offence should be treated as higher risk (paragraph 4.6.12).
4. Geographic risk
Record where the client operates, where its customers and suppliers are located, and where funds or assets may move. Paragraphs 4.6.14 to 4.6.18 address geographic risk, including relevant FATF list considerations. Do not treat the registered office as proof of where the business actually trades.
5. Delivery channel, purpose and relationship
State whether you met the client face to face, whether intermediaries are involved and how instructions are received. Paragraphs 4.6.19 to 4.6.22 cover delivery channel risk. Also state the purpose and intended nature of the relationship, as required by regulation 28(2)(c).
What Companies House can fill in, and what it cannot
Companies House can provide useful registry evidence, but it cannot write the firm’s assessment. Use register data for identity, status, ownership and filing history. You must still document the relationship, your checks, your risk rating and the reason for it. A register is a source, not a complete client file.
| From the register | Only the accountancy firm can write |
|---|---|
| Company name and number | Purpose and intended nature of the relationship |
| Legal form | Services you provide |
| Status, such as active, dissolved or in liquidation | How you met and deal with the client |
| Incorporation date | Where the client actually trades |
| Registered office | Whether anyone is a politically exposed person after your checks |
| SIC codes as declared | Source of funds where the risk calls for it |
| Directors and appointment dates | Identity verification of the director who is your key contact |
| PSC register entries | The risk rating and the reason for it |
| Filing history | Review date, approval and supporting judgement |
The guidance warns that registers are populated by companies and may contain errors. Paragraph B.2.9 says the PSC register can be used as a source of information and verification, but not solely relied upon. Before establishing a relationship with a UK company or LLP, obtain a PSC register excerpt or record that the register holds no information, as stated in paragraph 5.7.1.
If you identify a material discrepancy, report it to Companies House under paragraph 5.7.6. Paragraph 5.7.10 says this will normally be within 15 working days of establishing the discrepancy.
EntityWatch reads the UK register fields for you and leaves the firm-only fields for you to write and approve.
Turning the factors into a rating: low, normal or high
A small practice can use low, normal and high as its client risk categories. The CCAB guidance gives these as an example in paragraph 4.5.4 and accepts a simple matrix under paragraph 4.5.6. The rating is not the evidence: write the factors that moved the rating and the decision that followed.
A practical matrix can use these factors:
- Legal form and ownership structure.
- Country of operation and relevant geographic exposure.
- Sector and the nature of the client’s activities.
- Services the practice will provide.
- Delivery channel and use of intermediaries.
- PEP and other relevant screening results.
For each factor, write one short sentence. For example, state what you found, where it came from and whether it increased or reduced risk. Then write a separate sentence explaining the overall rating.
Higher risk should lead to additional controls. Paragraph 4.5.7 identifies enhanced due diligence, more frequent reviews and extra controls as possible responses. Your file should connect the response to the risk. A high rating with no change in checks is difficult to explain. So is a low rating with no rationale.
Keeping the assessment current
The assessment must remain useful after onboarding. Regulation 28(11) requires ongoing monitoring, including reviewing existing records. Paragraph 4.5.5 says monitoring applies regardless of risk category and should match the level of risk. Set a review date by risk class and review sooner when a material fact changes.
At each review, consider whether:
- the client’s ownership or control has changed;
- a director or PSC has changed;
- the client’s activities or countries have changed;
- the services you provide have changed;
- new screening or identity information affects the rating; and
- the existing evidence still supports the assessment.
Paragraph 5.7.4 says to obtain a fresh PSC excerpt when updating customer due diligence. For UK clients, EntityWatch re-reads Companies House and alerts you when a director or person with significant control changes. You still review the alert, decide what it means and approve any change to the file.
Checklist you can copy
Use this checklist as the minimum structure for a client file. Each item should be completed, marked not applicable with a reason, or linked to supporting evidence. The person approving the file should be clear about what was checked and when.
Identity and ownership
- Legal name, company number and legal form.
- Registration status and incorporation date.
- Registered office and operating address, if different.
- Directors, beneficial owners and control structure.
- Identity checks and source documents.
- PSC excerpt or record that the register holds no information.
Client risk
- Sector and business activities.
- Ownership complexity or secrecy concerns.
- PEP check and result.
- Other client-specific risk factors.
Service
- Services the practice will provide.
- Why those services create the stated level of risk.
- Any additional controls required.
Geography
- Countries where the client operates.
- Countries connected to customers, suppliers, assets or funds.
- Relevant geographic risk and the source considered.
Delivery channel
- How the client was introduced.
- Whether meetings were face to face.
- Use of intermediaries or remote instructions.
Purpose
- Purpose of the relationship.
- Intended nature and expected activity.
Rating and approval
- Low, normal or high rating.
- Reason for each factor that affected the rating.
- Decision on the checks and controls required.
- Review date.
- Name or role of approver and approval date.
FAQ
These answers address common questions for UK accountancy practices. Keep the answers tied to your own firm-wide risk assessment, written procedures and client evidence. The legal requirement is not satisfied by choosing a label alone; the file must explain the particular case and support the measures taken.
Do I need a separate risk assessment for every client?
Yes. Regulation 28(12) refers to the assessment of risk in the particular case, alongside the firm-wide assessment under regulation 18. It can be short for a low-risk client, but it must exist and show why that rating was chosen.
Can I rely on the Companies House PSC register for beneficial owners?
Use it as a source, not the only source. Paragraph B.2.9 of the CCAB guidance says the register is populated by the company and may contain errors. Obtain an excerpt before the relationship starts under paragraph 5.7.1 and report material discrepancies under paragraph 5.7.6.
What risk categories should a small practice use?
Low, normal and high are suitable example categories under paragraph 4.5.4. Paragraph 4.5.6 says a simple matrix can be acceptable. Your procedures should explain what checks and controls apply to each category.
How often should a client risk assessment be reviewed?
The regulations require ongoing monitoring under regulation 28(11), at a level matching risk under paragraph 4.5.5. Set the interval by risk class in your policy and review sooner when something changes. The rules do not state one fixed interval for every client.
Start your first client file
Enter a UK company number. EntityWatch fills the register fields with their source, you write the rest and approve it. The first note is free.
Write your first client file free
This article is general guidance, not legal advice.
This content was generated with artificial intelligence.