IRU Circular 17/2026 — National Risk Assessment in institutional risk reviews
IRU Circular 17/2026 requires supervised firms to study the published National Risk Assessment executive summaries and use relevant findings, indicators and risks to review/update institutional risk assessments, policies, procedures and internal controls. Official sources and an evidence-led implementation checklist.
تعميم رقم (17) لسنة 2026 بشأن تقارير التقييم الوطني للمخاطرOfficial Arabic title
- Issued
- 05.08.2026
- Published
- 06.08.2026
- Guide reviewed
- 11.10.2026
- Instrument
- IRU Circular 17/2026
Action at a glance
What this instrument asks you to do
IRU Circular 17/2026 requires supervised firms to study the published National Risk Assessment executive summaries and use relevant findings, indicators and risks to review/update institutional risk assessments, policies, procedures and internal controls.
Source-backed
Stated legal requirements
Requirements below are attributed to the instrument or cited guidance; each item includes its source location.
- 01
Study the six referenced Arabic executive summaries published by the Kuwait FIU, covering TF, NPOs, cross-border ML/TF, ML threats, legal persons/arrangements and virtual assets.
Citation · Page 1, numbered list 1–6
- 02
Use findings relevant to the firm's business to review and update institutional risk assessment, policies, procedures and internal controls under the risk-based approach.
Citation · Page 1, paragraph following the six summaries
Dates and applicability
Timing, grace period and deadline
Timing
Signed 5 August; published 6 August. No separate numerical completion deadline or grace period is stated on this one-page circular.
Grace period
Only the specifically stated submission period or validity condition applies. No additional general grace period is asserted.
Expit suggested practices
Build a reviewable closure record
These suggested actions are implementation practices, not additional legal requirements.
- 01
Map each NRA theme to the firm's customers, products and channels.
- Suggested owner
- MLRO / enterprise risk
- Evidence to retain
- Dated NRA source list and relevance assessment
- Complete when
- Each theme has a documented relevance decision, including reasons where exposure is limited.
- Expit support context
- Document extraction can support research; the firm owns its risk judgement.
- 02
Approve and evidence the resulting control changes.
- Suggested owner
- Risk committee / compliance
- Evidence to retain
- Updated risk assessment, policy changes and residual-gap register
- Complete when
- Relevant changes have accountable owners and the approved risk assessment reflects the new evidence.
- Expit support context
- Evidence-linked workflows can track updates rather than equating a downloaded report with closure.
Further clarification
Frequently asked questions
Does downloading the NRA summaries close the requirement?
Not by itself. The circular calls for study and use of relevant findings to review and update the firm's assessments and controls.
Can Expit declare our national risk assessment in institutional risk reviews gap closed?
No. Expit can support document processing, evidence reconciliation and accountable workflows. Your responsible officers and advisers must assess legal applicability, complete any required official submission and approve closure.
Primary references
Official sources
- Official IRU Circular 17/2026 PDF (opens in a new tab)SOURCE 01
Operative circular visually reviewed. The underlying NRA summaries were identified but not analysed here in full. This guide states the circular's review duty; it does not assign a risk score to your entity or claim every national threat applies identically to every insurer.
Read with care
Enforcement and limitations
Enforcement stated in source
The circular refers to IRU's powers under Insurance Law 125/2019 and applicable regulations/instructions. No fixed fine or individual enforcement outcome is inferred.
Limitations of this guide
The underlying NRA summaries were identified but not analysed here in full. This guide states the circular's review duty; it does not assign a risk score to your entity or claim every national threat applies identically to every insurer.