Skip to content

Compliance Risk

What is Compliance Risk?

The potential for legal penalties, financial loss, or reputational damage arising from an organization's failure to comply with laws, regulations, or standards.

Compliance and Regulatory

Each of these is named in at least one of the same controls as compliance risk. The number is how many controls name both.

What the standards actually require on compliance risk

Requirements naming compliance risk across 6 standards, quoted from the control text.

Requirement defined in ISO 37301:2021, clause 4.6 (Compliance risk assessment). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requirements.

iso-37301-2021::4.6 · Compliance risk assessment
Solvency II2 controls

Advisory function on compliance with laws, regulations, and administrative provisions. Assess impact of changes in the legal environment and identify compliance risk (Article 46).

SII-P2-06 · Compliance Function

The institution must have a designated compliance function assisting senior management to effectively manage compliance risks, adequately staffed by appropriately trained and competent people with sufficient authority to perform their role and with a reporting...

CPS220-P43 · Designated Compliance Function

Category 5 - the right to a safe and healthy working environment - added to the Declaration on 10 June 2022 at the 110th International Labour Conference, recognising occupational safety and health (OSH) as a fundamental right alongside the other four categorie...

ILO-FPRW-Cat5-OSH-SafeHealthyEnvironment-C155-C187-2022Amendment · ILO Fundamental Category 5 - Safe and Healthy Working Environment (C155 + C187) + 2022 Amendment Adding OSH as Fundamental Right
ISMAP (Japan)1 control

ISMAP Assessment positions ISMAP within the comprehensive Japanese and international cloud security regulatory landscape. (1) External Assessment by ISMAP-Approved Auditor: CSP must undergo annual third-party assessment by ISMAP-approved audit organisation inc...

ISMAP-Assessment-ExternalAuditor-AnnualReview-CustomerTransparency-Coord-FedRAMP-IRAP-GCloud-PIPA-ISO27017 · ISMAP Assessment - External ISMAP-Approved Auditor + Annual Review + Customer Information and Transparency + Coordination FedRAMP/UK G-Cloud/Australia IRAP/Singapore MTCS + ISO 27017 + PIPA + Japan Digital Agency

Determine scope and applicability of the OCC Heightened Standards per 12 CFR Part 30 Appendix D Section I and the OCC Heightened Standards for Large Banks final rule (effective November 2014 + revisions).

OCCHS-1 · Scope, Applicability, and Definitions of Heightened Standards

Questions people ask about compliance risk

What is Compliance Risk?
The potential for legal penalties, financial loss, or reputational damage arising from an organization's failure to comply with laws, regulations, or standards.
Why is Compliance Risk important for compliance?
Compliance Risk is a key concept in Compliance and Regulatory. Understanding compliance risk helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Compliance Risk?
Compliance Risk appears in the requirement text of ISO 37301:2021, Solvency II, APRA CPS 220 Risk Management, ILO Declaration on Fundamental Principles and Rights at Work (Core Conventions), ISMAP (Japan). Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Compliance Risk?
Explore our compliance framework pages to see how compliance risk applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Compliance Risk applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.