According to best practices, an enterprise-wide AML/CFT risk assessment should, at a minimum, consider which of the following core risk categories?