Most compliance failures don’t start with a missing policy. They start when a policy exists but nobody checks that it reached the right people, that they read it, or that the control behind it actually ran.
Equifax is the familiar example. According to the FTC, the company was alerted to a critical software vulnerability in March 2017 and didn’t patch it. Attackers exploited it from May 2017, and the settlement that followed was worth up to $700 million. The rule to patch existed; the check that it was followed did not. (We break down the full timeline in The Equifax Catastrophe.)
A compliance risk management framework is how you find those gaps before a regulator, auditor or attacker does. This guide covers compliance risk assessment, compliance risk analysis and ongoing compliance risk management as one process: what each term means, which regulators and standards expect it, how to score and prioritize risks, and how to keep evidence that your controls work.
What is compliance risk management?
Compliance risk is the chance of penalties, financial loss or reputational damage because your organization fails to meet its obligations. Those obligations include laws and regulations, contracts, industry standards you’ve committed to, and your own internal policies.
Compliance risk management is the ongoing process of identifying those obligations, assessing where you might fail them, putting controls in place, and checking that the controls work. It runs as a cycle, not a project.
Assessment, analysis and management: how the terms fit together
These terms are often used interchangeably. They describe different parts of the same process:
| Term | The question it answers | What it produces |
|---|---|---|
| Compliance risk assessment | Which obligations apply to us, where could we fail them, and how likely and serious would that be? | A scored risk register |
| Compliance risk analysis | The scoring step inside an assessment: how likely is each failure, how severe is the impact, and how well do current controls work? | Risk ratings and priorities |
| Compliance risk management | What are we doing about each risk, who owns it, and is it working? | Controls, owners, monitoring and reports |
| Compliance risk management framework | How do we run all of the above the same way every time? | A documented method: scope, scoring criteria, roles and review schedule |
How compliance risk differs from general enterprise risk
Enterprise risk management weighs risk against reward. A company may accept more market risk to pursue growth. Most compliance obligations can’t be traded off that way: you can choose how to meet a requirement, but not whether to meet it.
That changes how you respond. For most business risks, accepting the risk is a legitimate choice. For compliance risks, the response is almost always to reduce it, by strengthening a control, closing a gap or changing a process.
What regulators and standards expect
You don’t have to adopt a named standard to run a compliance risk assessment, but regulators in most sectors expect a documented, risk-based approach. These are the reference points compliance teams use most often:
- US Department of Justice, Evaluation of Corporate Compliance Programs (updated September 2024). Prosecutors ask, “What methodology has the company used to identify, analyze, and address the particular risks it faces?” and whether the risk assessment is “current and subject to periodic review.” They also ask how the company has communicated its policies and procedures to employees and relevant third parties, and how it assesses the impact of new technologies such as AI.
- ISO 37301:2021, Compliance management systems. A certifiable standard with requirements for establishing, implementing, evaluating, maintaining and improving a compliance management system.
- ISO 31000:2018, Risk management guidelines. A non-certifiable framework for identifying, analyzing, evaluating, treating, monitoring and communicating risk. Many teams borrow its process for compliance risk scoring.
- HIPAA Security Rule, 45 CFR 164.308(a)(1)(ii)(A). Covered entities and business associates must conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information.
- GDPR Article 35. Where processing is likely to result in a high risk to people’s rights and freedoms, the controller must carry out a data protection impact assessment before the processing starts.
- UK FCA Handbook, SYSC 6.1.1R. A firm “must establish, implement and maintain adequate policies and procedures sufficient to ensure compliance” with its obligations under the regulatory system.
The common thread: a method for finding risk, evidence that you applied it, and proof that policies reached the people who must follow them.
The six components of a compliance risk management framework
A framework is the written method that makes your assessment repeatable. Whatever its size, it needs these six parts.
Obligations register
A single list of every law, regulation, standard, contract clause and internal policy that applies to you, with the business units, regions and systems each one covers. Without it, assessments only look at the obligations people happen to remember.
Risk-to-process map
A link from each obligation to the processes, systems and roles that have to meet it. This is where you see dependencies: a data retention rule touches HR, IT, legal and every team that stores customer records.
Scoring criteria
Written definitions for each likelihood and impact score, so that a “4” means the same thing to the finance team as it does to operations. Inconsistent scoring is the most common reason two assessments of the same risk disagree.
Ownership and governance
A named owner for each risk and each control, plus a body that reviews results and approves priorities. Our guide to the policy governance model sets out the roles in detail.
Controls and mitigation plans
For each risk above your tolerance, the specific action that reduces it, who carries it out, by when, and what evidence will show it’s done.
Monitoring, evidence and review
How you check that controls keep working between assessments, what records you keep, and when the assessment is repeated. Continuous compliance monitoring covers this stage in depth.
How to conduct a compliance risk assessment in 8 steps
Step 1: Define scope and objectives
Decide what this assessment covers: the whole organization, one region, one regulation, or one business process. A narrow, well-defined first assessment is more useful than a broad one that never finishes. Write down the objective, such as preparing for an ISO 37301 certification audit or responding to a new regulation.
Step 2: Build the obligations register
List the obligations in scope. Bring in legal, HR, IT, security, finance and operations, because each knows rules the others miss. For each obligation, record the source, the requirement in plain language, where it applies, and who owns it.
Step 3: Map policies and controls to each obligation
For every obligation, identify the internal policy or procedure that addresses it and the control that enforces it. A control is anything that makes the requirement happen: an approval step, a system setting, a training course, a review. Obligations with no policy, or a policy with no control, are your first gaps.
Step 4: Identify compliance risks and gaps
Ask how each obligation could fail in practice. The gaps that show up most often are:
- An obligation with no policy at all
- A policy that’s out of date after a regulatory or process change
- A policy that’s published but never assigned to the people who must follow it
- No record that employees read the current version
- Contractors and third parties left out of policy distribution (see tracking contractor policy acknowledgement)
- A control that’s documented but has never been tested
Step 5: Score likelihood, impact and control effectiveness
Rate each risk on two scales, using written criteria:
| Score | Likelihood | Impact |
|---|---|---|
| 1 | Rare: no history of this failure and strong controls | Minor: internal finding only, no regulatory or customer effect |
| 2 | Unlikely: could happen, but controls usually catch it | Limited: small remediation cost, no penalty |
| 3 | Possible: has happened elsewhere in the sector or once internally | Moderate: regulator inquiry or audit finding |
| 4 | Likely: has happened internally or controls are weak | Major: fine, enforcement action or notifiable breach |
| 5 | Almost certain: happening now or no control exists | Severe: large penalty, license risk, or personal liability for executives |
Multiply likelihood by impact to get the inherent risk score (1 to 25). Then judge how well current controls reduce it, and score again to get the residual risk. The gap between the two shows how much you rely on each control, which tells you which controls to test first. Also weigh factors a simple score misses: legal consequences for individuals, reputational damage, and operational disruption.
Step 6: Prioritize with rating bands
| Residual score | Rating | Response |
|---|---|---|
| 20–25 | Critical | Act now. Executive owner, weekly tracking, report to the board or risk committee. |
| 10–16 | High | Mitigation plan within 30 days with a named owner and deadline. |
| 5–9 | Medium | Address in the next planning cycle; monitor quarterly. |
| 1–4 | Low | Monitor through routine reviews. |
Adjust the bands to your own risk appetite, but write them down and apply them the same way across every business unit.
Step 7: Plan and assign mitigation
For each high or critical risk, define a specific action, an owner, a deadline and the evidence that will prove it’s done. Typical mitigations include updating a policy, standardizing a process, adding mandatory training, assigning policies with tracked acknowledgement, and adding a review step. Avoid vague actions such as “raise awareness”: an auditor can’t verify them.
Step 8: Document, report and monitor
Record the scope, method, scores, decisions and owners in one place. Report the results to leadership in terms of exposure and progress, not activity. Then set the triggers for reassessment (see below) and track controls between assessments, so that a new hire, a policy update or a new system doesn’t quietly reopen a closed gap.
Example: a compliance risk register
An illustrative register for a mid-size regulated organization. Your obligations and scores will differ.
| Obligation | Risk | L | I | Score | Control | Evidence |
|---|---|---|---|---|---|---|
| SEC and CFTC recordkeeping rules | Staff use WhatsApp or text for business, so messages aren’t retained | 4 | 5 | 20 Critical | Approved-channels policy assigned to all client-facing staff; periodic attestation; message archiving | Acknowledgement report by policy version; archive coverage report |
| HIPAA Security Rule | Staff send ePHI to personal email accounts | 3 | 5 | 15 High | Acceptable use policy assigned to clinical and admin staff, re-acknowledged on every update; email data loss prevention rule | Acknowledgement report; DLP incident log |
| GDPR Article 35 | A new HR analytics tool goes live without a data protection impact assessment | 3 | 4 | 12 High | Procurement procedure requires DPIA sign-off before purchase | Completed DPIA; procurement approval record |
| Internal information security policy | Contractors work under an outdated version of the policy | 3 | 3 | 9 Medium | Contractor onboarding includes policy assignment; updates trigger re-acknowledgement | Contractor acknowledgement report |
The first row is not hypothetical as a risk: US regulators fined JPMorgan $200 million in December 2021 ($125 million from the SEC and $75 million from the CFTC) over staff using WhatsApp and personal texts for business, and the SEC alone charged 16 more firms more than $1.1 billion in September 2022. Read The $200 Million WhatsApp Mistake for how that sweep unfolded.
Where policy acknowledgement fits in the framework
Look at the control column in any register and the same item keeps appearing: a policy or procedure that people must read and follow. When a regulator or auditor tests that control, the question is no longer “Do you have a policy?” It’s “Who received it, which version, when did they read it, and who hasn’t?”
What Microsoft 365 gives you natively
- SharePoint stores your policies and keeps version history.
- The Microsoft Purview audit log records SharePoint and OneDrive file activities, so you can see who opened a file. Audit (Standard) keeps records for 180 days by default; E5 licenses keep them for one year.
- Microsoft Purview Compliance Manager helps you assess technical and organizational controls against more than 360 regulatory templates and track improvement actions.
None of these assign a policy to a group of people, set a reading deadline, chase the people who haven’t read it, or record that a person confirmed they read a specific version. Building that requires a custom Power Automate solution that your team then has to maintain.
What DocRead adds
DocRead runs inside SharePoint Online and Microsoft 365, and SharePoint Server 2019 and 2016. It turns the “policy assigned and acknowledged” control into evidence you can produce on request:
- Assigns policies and procedures to SharePoint or Microsoft Entra ID groups, so new joiners pick up the right documents automatically
- Sets reading deadlines, sends reminders and escalates overdue tasks to managers
- Requires the reader to open the document before they can confirm
- Records a time-stamped acknowledgement of the exact version read
- Shows who has and hasn’t read each policy in dashboards and reports
- Links quizzes and surveys to documents through DocSurvey, to check understanding as well as receipt
See how this works on the policy and procedure management software page, or read how to prove policy compliance without chasing employees.
Common challenges and how to avoid them
Treating the assessment as a one-off
Obligations, systems and people change every month. An assessment filed after an audit goes stale quickly. Set reassessment triggers and a fixed annual review.
Copying a template without adapting it
Templates help you start, but a generic list of risks misses what’s specific to your sector, regions and systems. Use a template for structure, not for content.
Leaving out the business
Compliance teams can’t see every process. Without input from HR, IT, operations and finance, the register reflects what compliance already knows rather than where risk sits.
Scoring without evidence
A control rated “effective” because nobody has complained is a guess. Base control scores on test results, records and reports.
Tracking in scattered spreadsheets
Risk registers in one file, policies in another site, and acknowledgements in email make it hard to show an auditor a complete picture. Keep policies, assignments and acknowledgement records in one system of record.
Ignoring new technology
The DOJ now asks how companies assess the compliance impact of AI. Add new tools to the register when they’re introduced, not after an incident. Our article on the impact of AI on compliance and risk management covers the main risks.
How often should you reassess compliance risk?
No regulation sets one frequency for everyone. HHS guidance on the HIPAA risk analysis doesn’t mandate a schedule; it says the analysis should be ongoing and updated when the organization introduces new technology or changes its operations. The DOJ asks whether the risk assessment is current and periodically reviewed.
A practical approach is a full review once a year, plus a targeted review when any of these happens:
- A new or changed regulation takes effect
- You enter a new market, launch a product or acquire a business
- An incident, complaint or audit finding exposes a gap
- You introduce a significant new system, including AI tools
- A reorganization changes who owns a process
Frequently asked questions
What is a compliance risk management framework?
It’s the documented method an organization uses to identify its compliance obligations, assess the risk of failing them, apply controls and monitor results. It sets out the scope, scoring criteria, roles and review schedule, so assessments are consistent from year to year.
What is the difference between a compliance risk assessment and compliance risk management?
A compliance risk assessment is a point-in-time exercise that identifies and scores risks. Compliance risk management is the ongoing program around it: mitigation, ownership, monitoring and reporting. The assessment tells you where to act; management is the acting.
Who should be involved in a compliance risk assessment?
Compliance or risk leads run it, with input from legal, HR, IT and security, finance, operations, and the managers who own the processes being assessed. Senior leadership or a risk committee should review and approve the results.
What should a compliance risk assessment template include?
At minimum: the obligation and its source, the related policy and control, the risk description, likelihood and impact scores, inherent and residual risk, the risk owner, the mitigation action and deadline, and the evidence that the control works.
Does a compliance risk assessment help with audits?
Yes. It shows auditors and regulators that you have a method for finding risk, that you applied it, and that you acted on the results. Pair it with records that prove controls ran, such as policy acknowledgement reports, so you can answer follow-up questions with evidence.
How does software support compliance risk management?
Software replaces manual tracking where it matters most for evidence: assigning policies to the right people, recording who read which version, chasing overdue readers and producing reports on demand. Tools like Microsoft Purview Compliance Manager track technical controls; DocRead covers the policy distribution and acknowledgement controls inside SharePoint and Microsoft 365.
See how DocRead records policy acknowledgements in Microsoft 365. Running SharePoint Server 2019 or 2016? Try DocRead for SharePoint Server free.