What's the difference between a compliance risk assessment and a standard organizational risk assessment?

684 views1 Upvote2 Comments
Sort By:
General Counsela year ago
I don't think there is any difference. Obviously, a well-designed compliance program must be risk-based. If companies follow the DOJ guidance, everybody will more or less have a similar one. Additionally, when a company must have an enterprise risk management assessment, which is the case for several organizations, it typically includes compliance risk and specific groups of risk. Why should we have two different types of risk assessment? It creates confusion among the Board of Directors and other stakeholders. Overall, it’s difficult to compare risk that can and cannot be quantified, but this is only a matter of having the right tools. I think it’s best to have one risk taxonomy and risk management system where compliance risks are included.
lock icon

Please join or sign in to view more content.

By joining the Peer Community, you'll get:

  • Peer Discussions and Polls
  • One-Minute Insights
  • Connect with like-minded individuals
General Counsel15 days ago
The organizational risk assessment would include specific themes relevant to the enterprise's strategy and business, including talent management, employee retention risk, macro themes like geopolitical disruption, macroeconomic instability, etc.  These themes typically would not feature in a compliance risk assessment, which focuses more on legal and regulatory risk. 

Content you might like

Cyber attacks & Data breaches47%

Supply chain disruptions39%

Regulatory non-compliance40%

Financial risks27%

Reputation risks24%

All of the above23%

None of the above

View Results
11.6k views9 Upvotes1 Comment

Once a week30%

Once every 2 weeks49%

Once a month15%


What 1-on-1?

View Results
13.1k views12 Upvotes25 Comments