What’s the likelihood x impact methodology in AML?

Likelihood x impact is the scoring method that some regulated businesses use to turn their AML risk levels into a numbered rating, to make the risk levels they face more tangible.
While it’s worthwhile understanding this methodology, it’s important to say that, like all other AML methodologies, it’s only as good as your assessment of risk.
Whatever scale you choose and whatever weighting you apply, the risk rating you land on needs to reflect the risk actually in front of you. Because what a supervisor is really testing when they review your business’ AML programme is that your assessment of the risk matches the reality.
Where does the likelihood x impact methodology come from?
Likelihood x impact is a standard risk management tool that’s common in frameworks like ISO 31000. A form of this methodology has been used by health and safety, project management and operational risk teams to calculate risk for decades.
In a nutshell, it asks you to assess how probable a risk event is, weigh up how serious the damage would be if it happened, and combine the two into a single score.
Most likelihood x impact matrices run on a simple scale. They give numerical scores for each level of risk, from low to high.
Think of it as a simple grid. Likelihood runs along the bottom, impact runs up the side, and each one gets its own score. A client might score low on likelihood but high on impact, or the other way round. Where the two meet on the grid gives you the overall rating.
How does likelihood x impact work for AML?
FATF frames money laundering, terrorist financing and proliferation financing risk in similar terms to the likelihood x impact methodology when describing how to take a risk-based approach:
“A risk-based approach means…identify, assess, and understand the money laundering and terrorist financing risk to which they are exposed, and take the appropriate mitigation measures in accordance with the level of risk” (Guidance for a Risk-Based Approach, FATF)
When you’re applying this to your business, you can look at risk-based approach as being in three linked stages.
- Risks are identified and assessed, looking at clients, jurisdictions, delivery channels, products and services to understand where exposure exists.
- Risks are mitigated, with controls, due diligence and monitoring applied in line with the level of risk found.
- Decisions are kept under review, because risks change and assessments need refreshing when circumstances shift.
Likelihood x impact is a way of identifying and assessing, before you decide what action to take.
Linking likelihood x impact with a risk-based approach
The risk scales vary a lot between sectors and businesses. None of them are set by FATF. A common approach is a three-point scale on each axis, giving a combined score from one to nine.
What matters more than the scale you choose is that whichever one you pick, you apply it the same way every time.
Getting this right doesn’t need to be complicated.
- Score every client using the same methodology every time
- Write down why you gave the score you did
- Update it if something about the client changes
There’s no perfect likelihood x impact scale. The only thing that counts is that someone looking back at your assessment, whether that’s you in six months or a supervisor tomorrow, can see how you got from the facts in front of you to the rating you gave.
What others have said
Making compliance easier








