Compliance risk management

Compliance risk management,
from score to treatment.

Every framework an auditor tests, from SOC 2 to ISO 27001 to NIS2, starts from a risk assessment. This guide covers how compliance risk differs from operational risk, a scoring method that holds up in an audit, the four treatment options, and what a usable risk register contains. General guidance, not legal advice.

Likelihood x impactInherent vs residualMitigate, accept, transfer, avoidISO 31000ISO 27001 6.1.2

Last updated Published by TryTrustableNot legal advice

Short answer

Compliance risk management is how a company finds the ways it could break a law, regulation, contract or standard it has committed to, scores how likely and how harmful each would be, and decides what to do about the ones above its appetite. In practice it is a risk assessment (likelihood x impact, before and after controls), a treatment decision for each risk (mitigate, accept, transfer or avoid), a named owner, and a risk register that is reviewed on a schedule and whenever the business or the rules change.

01

What is compliance risk management?

Compliance risk is the chance of legal or regulatory sanctions, financial loss or damage to reputation because the company fails to meet a law, regulation, contract, standard or its own policy. Compliance risk management is the discipline of finding those risks, ranking them and treating them before a regulator, auditor or customer does. ISO 31000 describes the general cycle (identify, analyse, evaluate, treat, monitor) and ISO 37301 applies it to a compliance management system.

It is also what prosecutors and auditors look for first. The US Department of Justice's guidance on corporate compliance programmes (updated September 2024) asks whether a programme is designed around the company's actual risks; ISO 27001 clause 6.1.2 and SOC 2 criteria CC3.1 to CC3.4 require a documented risk assessment before controls are chosen.

02

Compliance risk vs operational risk

Compliance riskOperational risk
The questionCould we fail an obligation we are bound by?Could a process, system, person or external event disrupt us?
Typical examplesProcessing personal data without a lawful basis; missing a breach-notice deadline; a vendor without a required contract; selling into a market without meeting its rulesA cloud outage; a failed deployment; a key person leaving; a ransomware incident
HarmFines, enforcement orders, lost certifications, contract breaches, personal liability for managersDowntime, lost revenue, recovery cost, data loss
Who usually owns itLegal, compliance, the DPO or the CISOEngineering, operations, the business owner
Where they meetAn operational failure becomes a compliance failure once a law or contract attaches a duty to itA ransomware incident that exposes personal data starts the 72-hour notice clock under GDPR Article 33

Score both on the same scale and keep them in one register, or you will rank them inconsistently.

03

How to do a compliance risk assessment

  1. List your obligations. Laws (GDPR, US state privacy laws, NIS2, sector rules), frameworks you are certified or audited against (SOC 2, ISO 27001), and customer contracts. This is your universe of things that can be breached.
  2. Identify risks against them. For each obligation, ask how it could fail: a missing process, a control that is not operating, a vendor, a new product, a market you are entering.
  3. Score inherent risk. Likelihood x impact, assuming no controls, using fixed definitions.
  4. Map existing controls and score residual risk: the same risk given the controls that actually operate today, not those planned.
  5. Compare with appetite. Anything above the threshold you set needs a treatment decision.
  6. Assign an owner and a review date to every risk. A risk with no owner is not being managed.
04

Likelihood x impact: a 5x5 scoring method

ScoreLikelihood (1 to 5)Impact (1 to 5)
1Rare: not expected in the next few yearsNegligible: no regulatory interest, trivial cost
2Unlikely: could happen, no history of itMinor: internal finding, quick fix
3Possible: has happened here or to peersModerate: customer or auditor finding, contract issue
4Likely: expected within a yearMajor: regulator notification, enforcement possible, lost deal
5Almost certain: happening or imminentSevere: fine, enforcement order, lost certification, personal liability

Inherent score = likelihood x impact, from 1 to 25. Write your own definitions down and keep them stable, so scores mean the same thing next year.

05

Inherent risk vs residual risk

Inherent risk is the score with no controls in place: what the exposure would be if you did nothing. Residual risk is the score after the controls you actually operate. The gap between the two is the value of your control set, and the residual figure is what management accepts.

The common failure is a residual score typed in once and never revisited. If the access review stops happening, the residual risk it was justifying has gone up, whether or not the spreadsheet says so. Tie residual risk to evidence that the controls still work, and review it when they fail.

06

Risk mitigation and treatment options

ISO 27001 clause 6.1.3 asks for a risk treatment plan, approved by the risk owners, who also accept the residual risk. The four classic options are below. Most compliance risks are mitigated; acceptance is legitimate when it is a recorded decision by someone with the authority to make it.

OptionWhat it meansCompliance exampleEvidence to keep
Mitigate (reduce)Add or strengthen controls to lower likelihood or impactEnforce MFA and quarterly access reviews to reduce unauthorised access to personal dataControl description, test results, the review records
Accept (retain)Live with the risk because it is within appetite or treatment costs more than it savesAccept a low-impact gap in a legacy internal tool scheduled for retirementA signed acceptance by the risk owner, with an expiry or review date
Transfer (share)Move part of the financial impact to another partyCyber insurance, or contract terms that put breach costs on a processorPolicy schedule or contract clause. Note the legal duty usually stays with you
AvoidStop the activity that creates the riskStop collecting a category of sensitive data you do not needThe decision, and proof the activity stopped

Transferring a risk rarely transfers the compliance obligation. Under GDPR, for example, a controller stays responsible for its processors.

07

How to create a risk register

A risk register is the working record of all of the above. At minimum each entry needs: an ID and title, a description of the cause and the consequence, the obligation or framework it relates to, a category, likelihood and impact (inherent), the linked controls, residual score, treatment decision and notes, owner, and next review date. Our free risk register template has the columns, the 5x5 bands and two worked examples.

Keep one register for security, privacy, vendor and compliance risk, so the board sees one ranked list. Review the top risks monthly, the whole register at least yearly, and whenever you launch a product, enter a market, change a critical vendor or a new law starts to apply.

08

Risk management automation: what helps and what does not

Automation helps with the parts that go stale: keeping residual scores tied to control status, reminding owners of reviews, and connecting risks to the evidence behind their controls. It does not help with judgement: deciding what could go wrong, how bad it would be, and what the company is willing to accept. Be wary of tools that generate a risk register for you; a register no one in the company wrote is one no one will defend in an audit.

09

How TryTrustable handles compliance risk

The risk register sits on the same control library as your frameworks and evidence, so a risk and the controls that treat it are one record, not two spreadsheets.

In TryTrustableWhat it does today
ScoringLikelihood and impact from 1 to 5; inherent risk is their product
Residual riskDerived from the live status of the controls you link to the risk, every time it is read. With nothing linked, residual equals inherent. Operating controls reduce a risk by at most 80 percent, so no risk falls to zero on paper
TreatmentMitigate, accept, transfer or avoid, with notes, a named owner and a review date
CategoriesInfrastructure, vendor, data, people and process, ranked on one scale
ControlsLinked by control id, library key or framework reference, from the same control library used for SOC 2, ISO 27001, NIS2, GDPR and the other modelled frameworks
Vendors and privacyVendor risk lives beside it in the vendor register; privacy risk assessments are covered on the DPIA page

When a linked control starts failing, the residual score rises without anyone editing the risk.

Questions

The things people ask us

What is compliance risk?

The chance of legal or regulatory sanctions, financial loss or reputational damage because the company fails to meet a law, regulation, contract, standard or its own policy.

What is the difference between inherent and residual risk?

Inherent risk is the score with no controls in place. Residual risk is the score after the controls you actually operate. Management accepts the residual risk, so it should move when those controls fail.

What are the four risk treatment options?

Mitigate (reduce likelihood or impact with controls), accept (retain it as a recorded decision), transfer (share the financial impact, for example through insurance or contract) and avoid (stop the activity).

How often should a compliance risk assessment be done?

At least yearly, and whenever something material changes: a new product, market, critical vendor, law or a significant incident. ISO 27001 requires risk assessments at planned intervals and on significant change.

Is there a free risk register template?

Yes. The TryTrustable risk register template has the columns, a 5x5 scoring matrix with bands and worked examples, and can be pasted into any spreadsheet.

Does TryTrustable calculate residual risk automatically?

Yes, from the live status of the controls linked to each risk. With no controls linked, residual equals inherent; passing controls reduce it, failing ones do not.

Book a walkthrough

A risk register that moves when your controls do.

Thirty minutes on your top risks, the controls behind them and the frameworks you answer to.