Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

compliance risk assessment explained

Compliance Risk Assessment: A Complete Guide to ISO 37301 Cl. 4.6

A compliance risk assessment under clause 4.6 of ISO 37301:2021 answers a question the obligations register cannot: of everything the organisation has to comply with, where is it most likely to fail, and what would it cost? The standard defines compliance risk with unusual precision — “likelihood of occurrence and the consequences of noncompliance with the organization’s compliance obligations” (3.24) — and places the assessment inside clause 4, context, rather than in planning, because it is the input every later clause depends on: the controls in 8.2 are proportionate to it, the compliance objectives in 6.2 are set from it, the monitoring in 9.1 is prioritised by it, and the compliance function’s attention is allocated by it. An assessment that rates every obligation “medium” has told nobody anything and produces a system that treats a data-breach notification duty and a signage regulation as equals. This guide sets out what clause 4.6 requires, how to build the assessment from the clause 4.5 register, the likelihood and consequence criteria that make the scores defensible, how to evaluate existing controls honestly, how the result drives the rest of the CMS, and the five findings auditors raise.

Compliance risk assessment under ISO 37301 clause 4.6: from obligations to priorities
4.5 obligations register → per obligation: likelihood × consequence of noncompliance → existing controls → residual risk → 8.2 controls, 6.2 objectives, 9.1 monitoring, function focus → review on change.

What clause 4.6 requires of a compliance risk assessment

Element What ISO 37301:2021 expects Evidence
Basis The compliance obligations identified under 4.5 — mandatory and voluntarily chosen (3.25) Register with owners and requirement statements
Identify The compliance risks: the ways noncompliance (3.27) with each obligation could occur, considering causes, sources and consequences Risk statements per obligation
Analyse and evaluate Likelihood and consequences (3.24) against the organisation’s criteria; prioritisation Scores and rating; criteria documented
Existing controls Consider the controls in place and their adequacy Control column with effectiveness judgement
Review Periodically and when circumstances change — new obligations, activities, structure, incidents Dated versions; change triggers
Documented information Retained as evidence The assessment file

ISO 31000 is in the bibliography and supplies the vocabulary; the content is compliance-specific. Our guide to the compliance obligations register covers the 4.5 work the assessment starts from.

Building the compliance risk assessment from the register

Column What to record Example (data protection obligation)
Obligation The register row: source, what it requires of the organisation, owner GDPR Art. 33: notify the supervisory authority of a personal data breach within 72 hours; owner: DPO
Activities exposed Where in the operation the obligation bites All processing; incident handling in IT and customer service
How noncompliance would occur Causes and sources: process, people, systems, third parties, change Breach not recognised as personal data; escalation route unknown to first-line staff; supplier fails to notify us
Consequence Regulatory, legal, financial, operational, reputational, on customers and people Administrative fine; regulator scrutiny; customer notification duties; reputational harm
Likelihood Scale with anchors: frequency of the activity, history, complexity, control maturity, change 3 of 5 — two near misses in twelve months; new supplier onboarding
Consequence score Scale with anchors: financial, legal, reputational 4 of 5
Inherent rating Likelihood × consequence before controls 12 — high
Existing controls and adequacy Named controls; suitable? effective? evidenced? Incident procedure (suitable; partly effective — first-line awareness gap); supplier contract clause (effective)
Residual rating and owner After controls; who accepts it 8 — medium; CIO, dated
Treatment New or improved control (8.2), objective (6.2), monitoring (9.1), or accept Awareness training for first line; breach drill; KPI on time-to-recognition

Compliance risk assessment criteria that hold up

  1. Define the scales before scoring. Likelihood anchors in frequency terms (“has occurred in the last year”; “could occur during a normal year”; “conceivable over five years”); consequence anchors in money, sanction type, licence impact and reputational reach. Criteria written after the scores are a finding.
  2. Score the obligation in the activity, not the law in the abstract. The same regulation is high risk in one business line and low in another.
  3. Separate suitability from effectiveness when evaluating controls. A suitable control that is not operated is not a control; a policy is never a control on its own.
  4. Use evidence for likelihood. Incident and near-miss data (9.1), audit findings, concerns raised (8.3), regulator correspondence, change logs.
  5. Record the reasoning for low. Low switches off attention; it should be a decision with a rationale, not a default.
  6. Review on trigger and on cycle. New obligations, new activities or markets, acquisitions, incidents, regulator action, organisational change — and at least annually before management review.

How the compliance risk assessment drives the rest of the CMS

Output Clause it drives What proportionate looks like
High and medium residual risks 8.2 Establishing controls and procedures Preventive and detective controls designed for the failure mode, owned and tested
Top risks 6.2 Compliance objectives Measurable objectives — time to recognise a breach, training completion in exposed roles, third-party clause coverage
Risk-ranked obligations 9.1 Monitoring, measurement, analysis and evaluation Monitoring intensity by rating; our compliance monitoring guide covers the programme
Residual risk profile 5 Leadership; 9.3 Management review Governing body sees the profile and accepts or funds treatment
Exposed roles 7.2, 7.3 Training and awareness targeted by role
Third-party-driven risks 8.2 controls; contracts Flow-down clauses, assurance, audit rights
Culture-related causes Compliance culture requirements Where the cause is behaviour, the treatment is leadership and consequence, not another procedure

Our guide to compliance monitoring covers how the ratings set the monitoring programme; our guide to compliance culture covers the behavioural causes the assessment often finds behind its highest rows.

Five compliance risk assessment findings auditors raise

  • Everything medium. Undifferentiated scores; no prioritisation; the function’s attention allocated by habit.
  • Assessed by statute, not activity. One row per law with no view of where in the operation it applies.
  • Controls rated by existence. The policy cited as the control for every obligation.
  • No trace to clause 8.2. High risks with no control designed for them; controls with no risk behind them.
  • Never reviewed. Dated at implementation; the new regulation, the acquisition and the incident since are absent.

Frequently asked questions

What is a compliance risk assessment under ISO 37301?
The clause 4.6 requirement to identify, analyse and evaluate the risks of noncompliance with each compliance obligation identified under 4.5 — compliance risk being defined as the likelihood of occurrence and the consequences of noncompliance — considering existing controls, and to review the assessment when circumstances change.

How is it different from the obligations register?
The register (4.5) says what binds the organisation and who owns it; the assessment (4.6) says how likely each obligation is to be breached in the organisation’s activities, what it would cost, and therefore what deserves controls, objectives and monitoring first.

Do we need a separate assessment for bribery?
If bribery risk is material and you run ISO 37001, yes: its clause 4.5 bribery risk assessment is the deep version of the 4.6 row for anti-bribery obligations. Otherwise anti-bribery is assessed like any other obligation.

What scales should we use?
Any defined scale with written anchors for likelihood and consequence, set before scoring and consistent with the compliance policy. Five-point scales are common; the anchors matter more than the number of points.

How often should it be reviewed?
Periodically — annually before management review is the common cycle — and on change: new obligations, activities, markets, acquisitions, incidents, regulator action or restructuring.

Where this leaves you

Build the compliance risk assessment from the register outward, obligation by obligation in the activity where it applies, with scales set before scoring, controls judged on effectiveness rather than existence, and a rationale for every low. Then let the ratings decide the controls, the objectives, the monitoring and the function’s attention — because under ISO 37301 the assessment is not a record of the system, it is the reason the system looks the way it does.

References

More on ISO 37301

The Compliance Risk Assessment Methodology and Workbook — criteria, scales, the obligation-by-activity matrix, inherent and residual scoring and the control-effectiveness column — and the register it starts from are in the ISO 37301 Compliance Management Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.