Compliance risk management,
from score to treatment.
Every framework an auditor tests, from SOC 2 to ISO 27001 to NIS2, starts from a risk assessment. This guide covers how compliance risk differs from operational risk, a scoring method that holds up in an audit, the four treatment options, and what a usable risk register contains. General guidance, not legal advice.
Last updated Published by TryTrustableNot legal advice
Compliance risk management is how a company finds the ways it could break a law, regulation, contract or standard it has committed to, scores how likely and how harmful each would be, and decides what to do about the ones above its appetite. In practice it is a risk assessment (likelihood x impact, before and after controls), a treatment decision for each risk (mitigate, accept, transfer or avoid), a named owner, and a risk register that is reviewed on a schedule and whenever the business or the rules change.
What is compliance risk management?
Compliance risk is the chance of legal or regulatory sanctions, financial loss or damage to reputation because the company fails to meet a law, regulation, contract, standard or its own policy. Compliance risk management is the discipline of finding those risks, ranking them and treating them before a regulator, auditor or customer does. ISO 31000 describes the general cycle (identify, analyse, evaluate, treat, monitor) and ISO 37301 applies it to a compliance management system.
It is also what prosecutors and auditors look for first. The US Department of Justice's guidance on corporate compliance programmes (updated September 2024) asks whether a programme is designed around the company's actual risks; ISO 27001 clause 6.1.2 and SOC 2 criteria CC3.1 to CC3.4 require a documented risk assessment before controls are chosen.
Compliance risk vs operational risk
| Compliance risk | Operational risk | |
|---|---|---|
| The question | Could we fail an obligation we are bound by? | Could a process, system, person or external event disrupt us? |
| Typical examples | Processing personal data without a lawful basis; missing a breach-notice deadline; a vendor without a required contract; selling into a market without meeting its rules | A cloud outage; a failed deployment; a key person leaving; a ransomware incident |
| Harm | Fines, enforcement orders, lost certifications, contract breaches, personal liability for managers | Downtime, lost revenue, recovery cost, data loss |
| Who usually owns it | Legal, compliance, the DPO or the CISO | Engineering, operations, the business owner |
| Where they meet | An operational failure becomes a compliance failure once a law or contract attaches a duty to it | A ransomware incident that exposes personal data starts the 72-hour notice clock under GDPR Article 33 |
Score both on the same scale and keep them in one register, or you will rank them inconsistently.
How to do a compliance risk assessment
- List your obligations. Laws (GDPR, US state privacy laws, NIS2, sector rules), frameworks you are certified or audited against (SOC 2, ISO 27001), and customer contracts. This is your universe of things that can be breached.
- Identify risks against them. For each obligation, ask how it could fail: a missing process, a control that is not operating, a vendor, a new product, a market you are entering.
- Score inherent risk. Likelihood x impact, assuming no controls, using fixed definitions.
- Map existing controls and score residual risk: the same risk given the controls that actually operate today, not those planned.
- Compare with appetite. Anything above the threshold you set needs a treatment decision.
- Assign an owner and a review date to every risk. A risk with no owner is not being managed.
Likelihood x impact: a 5x5 scoring method
| Score | Likelihood (1 to 5) | Impact (1 to 5) |
|---|---|---|
| 1 | Rare: not expected in the next few years | Negligible: no regulatory interest, trivial cost |
| 2 | Unlikely: could happen, no history of it | Minor: internal finding, quick fix |
| 3 | Possible: has happened here or to peers | Moderate: customer or auditor finding, contract issue |
| 4 | Likely: expected within a year | Major: regulator notification, enforcement possible, lost deal |
| 5 | Almost certain: happening or imminent | Severe: fine, enforcement order, lost certification, personal liability |
Inherent score = likelihood x impact, from 1 to 25. Write your own definitions down and keep them stable, so scores mean the same thing next year.
Inherent risk vs residual risk
Inherent risk is the score with no controls in place: what the exposure would be if you did nothing. Residual risk is the score after the controls you actually operate. The gap between the two is the value of your control set, and the residual figure is what management accepts.
The common failure is a residual score typed in once and never revisited. If the access review stops happening, the residual risk it was justifying has gone up, whether or not the spreadsheet says so. Tie residual risk to evidence that the controls still work, and review it when they fail.
Risk mitigation and treatment options
ISO 27001 clause 6.1.3 asks for a risk treatment plan, approved by the risk owners, who also accept the residual risk. The four classic options are below. Most compliance risks are mitigated; acceptance is legitimate when it is a recorded decision by someone with the authority to make it.
| Option | What it means | Compliance example | Evidence to keep |
|---|---|---|---|
| Mitigate (reduce) | Add or strengthen controls to lower likelihood or impact | Enforce MFA and quarterly access reviews to reduce unauthorised access to personal data | Control description, test results, the review records |
| Accept (retain) | Live with the risk because it is within appetite or treatment costs more than it saves | Accept a low-impact gap in a legacy internal tool scheduled for retirement | A signed acceptance by the risk owner, with an expiry or review date |
| Transfer (share) | Move part of the financial impact to another party | Cyber insurance, or contract terms that put breach costs on a processor | Policy schedule or contract clause. Note the legal duty usually stays with you |
| Avoid | Stop the activity that creates the risk | Stop collecting a category of sensitive data you do not need | The decision, and proof the activity stopped |
Transferring a risk rarely transfers the compliance obligation. Under GDPR, for example, a controller stays responsible for its processors.
How to create a risk register
A risk register is the working record of all of the above. At minimum each entry needs: an ID and title, a description of the cause and the consequence, the obligation or framework it relates to, a category, likelihood and impact (inherent), the linked controls, residual score, treatment decision and notes, owner, and next review date. Our free risk register template has the columns, the 5x5 bands and two worked examples.
Keep one register for security, privacy, vendor and compliance risk, so the board sees one ranked list. Review the top risks monthly, the whole register at least yearly, and whenever you launch a product, enter a market, change a critical vendor or a new law starts to apply.
Risk management automation: what helps and what does not
Automation helps with the parts that go stale: keeping residual scores tied to control status, reminding owners of reviews, and connecting risks to the evidence behind their controls. It does not help with judgement: deciding what could go wrong, how bad it would be, and what the company is willing to accept. Be wary of tools that generate a risk register for you; a register no one in the company wrote is one no one will defend in an audit.
How TryTrustable handles compliance risk
The risk register sits on the same control library as your frameworks and evidence, so a risk and the controls that treat it are one record, not two spreadsheets.
| In TryTrustable | What it does today |
|---|---|
| Scoring | Likelihood and impact from 1 to 5; inherent risk is their product |
| Residual risk | Derived from the live status of the controls you link to the risk, every time it is read. With nothing linked, residual equals inherent. Operating controls reduce a risk by at most 80 percent, so no risk falls to zero on paper |
| Treatment | Mitigate, accept, transfer or avoid, with notes, a named owner and a review date |
| Categories | Infrastructure, vendor, data, people and process, ranked on one scale |
| Controls | Linked by control id, library key or framework reference, from the same control library used for SOC 2, ISO 27001, NIS2, GDPR and the other modelled frameworks |
| Vendors and privacy | Vendor risk lives beside it in the vendor register; privacy risk assessments are covered on the DPIA page |
When a linked control starts failing, the residual score rises without anyone editing the risk.
The things people ask us
What is compliance risk?
The chance of legal or regulatory sanctions, financial loss or reputational damage because the company fails to meet a law, regulation, contract, standard or its own policy.
What is the difference between inherent and residual risk?
Inherent risk is the score with no controls in place. Residual risk is the score after the controls you actually operate. Management accepts the residual risk, so it should move when those controls fail.
What are the four risk treatment options?
Mitigate (reduce likelihood or impact with controls), accept (retain it as a recorded decision), transfer (share the financial impact, for example through insurance or contract) and avoid (stop the activity).
How often should a compliance risk assessment be done?
At least yearly, and whenever something material changes: a new product, market, critical vendor, law or a significant incident. ISO 27001 requires risk assessments at planned intervals and on significant change.
Is there a free risk register template?
Yes. The TryTrustable risk register template has the columns, a 5x5 scoring matrix with bands and worked examples, and can be pasted into any spreadsheet.
Does TryTrustable calculate residual risk automatically?
Yes, from the live status of the controls linked to each risk. With no controls linked, residual equals inherent; passing controls reduce it, failing ones do not.
A risk register that moves when your controls do.
Thirty minutes on your top risks, the controls behind them and the frameworks you answer to.