A compliance risk assessment under clause 4.6 of ISO 37301:2021 answers a question the obligations register cannot: of everything the organisation has to comply with, where is it most likely to fail, and what would it cost? The standard defines compliance risk with unusual precision — “likelihood of occurrence and the consequences of noncompliance with the organization’s compliance obligations” (3.24) — and places the assessment inside clause 4, context, rather than in planning, because it is the input every later clause depends on: the controls in 8.2 are proportionate to it, the compliance objectives in 6.2 are set from it, the monitoring in 9.1 is prioritised by it, and the compliance function’s attention is allocated by it. An assessment that rates every obligation “medium” has told nobody anything and produces a system that treats a data-breach notification duty and a signage regulation as equals. This guide sets out what clause 4.6 requires, how to build the assessment from the clause 4.5 register, the likelihood and consequence criteria that make the scores defensible, how to evaluate existing controls honestly, how the result drives the rest of the CMS, and the five findings auditors raise.

What clause 4.6 requires of a compliance risk assessment
| Element | What ISO 37301:2021 expects | Evidence |
|---|---|---|
| Basis | The compliance obligations identified under 4.5 — mandatory and voluntarily chosen (3.25) | Register with owners and requirement statements |
| Identify | The compliance risks: the ways noncompliance (3.27) with each obligation could occur, considering causes, sources and consequences | Risk statements per obligation |
| Analyse and evaluate | Likelihood and consequences (3.24) against the organisation’s criteria; prioritisation | Scores and rating; criteria documented |
| Existing controls | Consider the controls in place and their adequacy | Control column with effectiveness judgement |
| Review | Periodically and when circumstances change — new obligations, activities, structure, incidents | Dated versions; change triggers |
| Documented information | Retained as evidence | The assessment file |
ISO 31000 is in the bibliography and supplies the vocabulary; the content is compliance-specific. Our guide to the compliance obligations register covers the 4.5 work the assessment starts from.
Building the compliance risk assessment from the register
| Column | What to record | Example (data protection obligation) |
|---|---|---|
| Obligation | The register row: source, what it requires of the organisation, owner | GDPR Art. 33: notify the supervisory authority of a personal data breach within 72 hours; owner: DPO |
| Activities exposed | Where in the operation the obligation bites | All processing; incident handling in IT and customer service |
| How noncompliance would occur | Causes and sources: process, people, systems, third parties, change | Breach not recognised as personal data; escalation route unknown to first-line staff; supplier fails to notify us |
| Consequence | Regulatory, legal, financial, operational, reputational, on customers and people | Administrative fine; regulator scrutiny; customer notification duties; reputational harm |
| Likelihood | Scale with anchors: frequency of the activity, history, complexity, control maturity, change | 3 of 5 — two near misses in twelve months; new supplier onboarding |
| Consequence score | Scale with anchors: financial, legal, reputational | 4 of 5 |
| Inherent rating | Likelihood × consequence before controls | 12 — high |
| Existing controls and adequacy | Named controls; suitable? effective? evidenced? | Incident procedure (suitable; partly effective — first-line awareness gap); supplier contract clause (effective) |
| Residual rating and owner | After controls; who accepts it | 8 — medium; CIO, dated |
| Treatment | New or improved control (8.2), objective (6.2), monitoring (9.1), or accept | Awareness training for first line; breach drill; KPI on time-to-recognition |
Compliance risk assessment criteria that hold up
- Define the scales before scoring. Likelihood anchors in frequency terms (“has occurred in the last year”; “could occur during a normal year”; “conceivable over five years”); consequence anchors in money, sanction type, licence impact and reputational reach. Criteria written after the scores are a finding.
- Score the obligation in the activity, not the law in the abstract. The same regulation is high risk in one business line and low in another.
- Separate suitability from effectiveness when evaluating controls. A suitable control that is not operated is not a control; a policy is never a control on its own.
- Use evidence for likelihood. Incident and near-miss data (9.1), audit findings, concerns raised (8.3), regulator correspondence, change logs.
- Record the reasoning for low. Low switches off attention; it should be a decision with a rationale, not a default.
- Review on trigger and on cycle. New obligations, new activities or markets, acquisitions, incidents, regulator action, organisational change — and at least annually before management review.
How the compliance risk assessment drives the rest of the CMS
| Output | Clause it drives | What proportionate looks like |
|---|---|---|
| High and medium residual risks | 8.2 Establishing controls and procedures | Preventive and detective controls designed for the failure mode, owned and tested |
| Top risks | 6.2 Compliance objectives | Measurable objectives — time to recognise a breach, training completion in exposed roles, third-party clause coverage |
| Risk-ranked obligations | 9.1 Monitoring, measurement, analysis and evaluation | Monitoring intensity by rating; our compliance monitoring guide covers the programme |
| Residual risk profile | 5 Leadership; 9.3 Management review | Governing body sees the profile and accepts or funds treatment |
| Exposed roles | 7.2, 7.3 | Training and awareness targeted by role |
| Third-party-driven risks | 8.2 controls; contracts | Flow-down clauses, assurance, audit rights |
| Culture-related causes | Compliance culture requirements | Where the cause is behaviour, the treatment is leadership and consequence, not another procedure |
Our guide to compliance monitoring covers how the ratings set the monitoring programme; our guide to compliance culture covers the behavioural causes the assessment often finds behind its highest rows.
Five compliance risk assessment findings auditors raise
- Everything medium. Undifferentiated scores; no prioritisation; the function’s attention allocated by habit.
- Assessed by statute, not activity. One row per law with no view of where in the operation it applies.
- Controls rated by existence. The policy cited as the control for every obligation.
- No trace to clause 8.2. High risks with no control designed for them; controls with no risk behind them.
- Never reviewed. Dated at implementation; the new regulation, the acquisition and the incident since are absent.
Frequently asked questions
What is a compliance risk assessment under ISO 37301?
The clause 4.6 requirement to identify, analyse and evaluate the risks of noncompliance with each compliance obligation identified under 4.5 — compliance risk being defined as the likelihood of occurrence and the consequences of noncompliance — considering existing controls, and to review the assessment when circumstances change.
How is it different from the obligations register?
The register (4.5) says what binds the organisation and who owns it; the assessment (4.6) says how likely each obligation is to be breached in the organisation’s activities, what it would cost, and therefore what deserves controls, objectives and monitoring first.
Do we need a separate assessment for bribery?
If bribery risk is material and you run ISO 37001, yes: its clause 4.5 bribery risk assessment is the deep version of the 4.6 row for anti-bribery obligations. Otherwise anti-bribery is assessed like any other obligation.
What scales should we use?
Any defined scale with written anchors for likelihood and consequence, set before scoring and consistent with the compliance policy. Five-point scales are common; the anchors matter more than the number of points.
How often should it be reviewed?
Periodically — annually before management review is the common cycle — and on change: new obligations, activities, markets, acquisitions, incidents, regulator action or restructuring.
Where this leaves you
Build the compliance risk assessment from the register outward, obligation by obligation in the activity where it applies, with scales set before scoring, controls judged on effectiveness rather than existence, and a rationale for every low. Then let the ratings decide the controls, the objectives, the monitoring and the function’s attention — because under ISO 37301 the assessment is not a record of the system, it is the reason the system looks the way it does.
References
- ISO 37301:2021 — Compliance management systems — Requirements with guidance for use — First edition, April 2021; clause 4.6 and the definitions of compliance risk (3.24), compliance obligations (3.25) and noncompliance (3.27) are readable on the ISO Online Browsing Platform.
- ISO 31000:2018 — Risk management — Guidelines — The risk vocabulary and process ISO 37301 cites.
More on ISO 37301
- Compliance risk assessment — you are here
- ISO 37301 explained
- The compliance obligations register
- Compliance monitoring
- The compliance function
- Compliance culture
The Compliance Risk Assessment Methodology and Workbook — criteria, scales, the obligation-by-activity matrix, inherent and residual scoring and the control-effectiveness column — and the register it starts from are in the ISO 37301 Compliance Management Toolkit, or start with the free templates.