Skip to main content
Category: Foundational Concepts

Compliance Risk

Also known as: Regulatory Compliance Risk, Legal and Regulatory Risk
Simply put

Compliance risk is the exposure an organization faces when it fails to follow the laws, regulations, rules, or standards that apply to its activities. Such failures can lead to legal or regulatory penalties, financial losses, and reputational harm. In a third-party context, this exposure can extend to the organization through the conduct of the vendors and suppliers it relies on.

Formal definition

Compliance risk is the risk to an organization's current or projected financial condition, operations, and reputation arising from violations of, or non-conformance with, applicable laws, rules, regulations, or prescribed standards. It encompasses legal, financial, and, in certain contexts, criminal exposure resulting from such failures. This term is distinct from broader risk categories such as operational, financial, or reputational risk, though outcomes may overlap; compliance risk specifically originates from the gap between an organization's practices and its regulatory or legal obligations. Applicable obligations and enforcement expectations typically vary by jurisdiction and sector, so the scope of compliance risk is not uniform across regions or industries. In third-party and supply chain programs, compliance risk may be assessed at onboarding and through ongoing monitoring; a compliance risk assessment identifies gaps between current practices and regulatory obligations but is a point-in-time exercise that does not by itself guarantee continued conformance.

Why it matters

Compliance risk matters because the consequences of non-conformance extend well beyond internal process failures. When an organization violates or falls short of applicable laws, rules, regulations, or prescribed standards, it can face legal or regulatory penalties, financial losses, and reputational harm. In some contexts the exposure includes criminal liability, not merely civil or administrative sanction. These outcomes may overlap with operational, financial, or reputational risk, but compliance risk is distinct in that it originates specifically from the gap between an organization's practices and its regulatory or legal obligations.

Who it's relevant to

Compliance and Legal Teams
These teams are typically responsible for mapping applicable laws, rules, and regulations to organizational practices and for identifying where gaps create legal, financial, or criminal exposure. Because obligations and enforcement expectations vary by jurisdiction and sector, they must account for differences in scope rather than applying a single standard uniformly across regions or industries.
Third-Party Risk and Procurement Professionals
In third-party and supply chain programs, compliance risk can extend to the organization through the conduct of the vendors and suppliers it relies on. These professionals typically assess compliance risk at onboarding and through ongoing monitoring, recognizing that a point-in-time compliance risk assessment identifies gaps but does not guarantee a third party's continued conformance.
Risk and Resilience Functions
Because compliance failures can affect an organization's current or projected financial condition, operations, and reputation, risk and resilience functions have an interest in how compliance risk interacts with broader risk categories. While outcomes may overlap with operational, financial, or reputational risk, these teams should keep compliance risk distinct, as it originates specifically from non-conformance with regulatory or legal obligations.

Inside Compliance Risk

Regulatory Compliance Risk
The risk that a third party's actions or omissions cause the organization to fall out of alignment with applicable laws and regulations, such as data protection, anti-bribery and corruption, sanctions, or sector-specific rules. Because regulatory expectations vary across jurisdictions and sectors, the same third-party arrangement may carry different exposure depending on where and how goods or services are delivered.
Contractual and Policy Compliance Risk
The risk that a third party fails to meet obligations set out in the contract or the organization's own policies and codes of conduct, which is distinct from statutory legal violations. This typically covers areas such as agreed controls, reporting duties, and standards of conduct that are enforceable between the parties but not necessarily mandated by law.
Screening and Due Diligence Components
Activities used to identify compliance exposure at onboarding, including sanctions and watchlist screening, adverse media checks, and beneficial ownership review. These typically establish a point-in-time picture and, on their own, do not provide ongoing assurance that a third party remains compliant over the life of the relationship.
Attestations and Evidence
Self-reported statements, questionnaire responses, and supporting documentation a third party provides to demonstrate compliance. An attestation reflects what the party asserts and is not equivalent to independent verification; the strength of assurance depends on whether the evidence is corroborated by testing or third-party audit.
Nth-Party and Extended Exposure
Compliance risk that arises not from the direct third party but from its own subcontractors and suppliers, for example a sanctioned entity or a labor violation deeper in the chain. Visibility beyond the first tier is often limited, so this exposure is frequently harder to detect and monitor than direct third-party compliance risk.
Ongoing Monitoring and Reassessment
Processes that track changes in a third party's compliance posture after onboarding, such as periodic reassessment, sanctions rescreening, and monitoring of regulatory or enforcement developments. This component addresses the tendency for point-in-time assessments to become stale as circumstances change.

Common questions

Answers to the questions practitioners most commonly ask about Compliance Risk.

Is compliance risk the same as legal risk?
No. Although the two overlap, they are distinct. Compliance risk typically refers to the risk of failing to adhere to applicable laws, regulations, rules, codes of conduct, or contractual obligations that govern a third party's operations. Legal risk is broader and includes exposure to litigation, unenforceable contracts, and disputes that may arise even where a party is technically compliant. A third party can be in full regulatory compliance yet still carry significant legal risk, and treating the terms as interchangeable can leave gaps in how each is assessed and monitored.
Does a supplier attestation or a passing questionnaire response confirm that a third party is compliant?
Not on its own. An attestation is a self-reported statement by the third party and is not the same as independent verification. Similarly, a completed compliance questionnaire captures what the party represents at a point in time, not validated evidence of ongoing adherence. Depending on the risk tier, many programs supplement self-reported responses with independent assessments, documentation review, or third-party audits, because self-attestation alone does not confirm that controls exist, operate as described, or remain effective over time.
How do programs typically assess a third party's compliance risk during onboarding?
Onboarding assessment often combines screening (such as sanctions, watchlist, and adverse media checks where applicable), collection of relevant certifications or attestations, and a questionnaire covering the regulatory obligations that apply to the engagement. The depth usually depends on the risk tier, the nature of the service, and the jurisdictions involved. It is worth noting that onboarding assessment is point-in-time and does not by itself provide assurance of continued compliance, which is why many programs pair it with ongoing monitoring.
What falls outside the scope of a compliance risk assessment?
A compliance risk assessment generally focuses on adherence to specified laws, regulations, and contractual obligations. It typically does not, on its own, address financial stability, operational resilience, information security, geopolitical exposure, or ESG performance, though these may be evaluated in parallel workstreams. Scope also depends on which obligations are in view; an assessment scoped to one regulatory regime may not cover requirements in another jurisdiction or sector.
How can compliance risk be kept current after onboarding?
Because compliance status can change, many programs supplement point-in-time onboarding with ongoing monitoring, such as periodic reassessment aligned to the risk tier, refreshed screening, tracking of regulatory changes relevant to the engagement, and review of updated certifications or attestations as they expire. The appropriate cadence typically varies with the criticality of the relationship and the volatility of the applicable regulatory environment.
How does jurisdiction affect the assessment of a third party's compliance risk?
Regulatory expectations differ across regions and sectors, so the obligations that define compliance risk for a given third party depend on where it operates, where the goods or services flow, and which regime governs the engagement. A control considered adequate under one regulatory framework may not satisfy another. Programs generally scope compliance assessments to the specific jurisdictions and sectors relevant to the relationship rather than assuming a single global standard applies.

Common misconceptions

Compliance risk is fully addressed once due diligence is completed at onboarding.
Onboarding due diligence typically establishes a point-in-time view and does not, by itself, provide assurance that a third party stays compliant. Regulatory obligations, ownership, and conduct can change, so many programs pair onboarding checks with ongoing monitoring and periodic reassessment.
A third party's attestation or a completed questionnaire confirms it is compliant.
An attestation reflects what the third party asserts about itself and is not the same as independent verification. Depending on the risk tier, stronger assurance may require corroborating evidence such as independent audit or testing rather than relying on self-reported responses alone.
Compliance risk is a single unified category covering all forms of exposure.
Compliance risk is distinct from financial, operational, geopolitical, and ESG risk, and even within compliance, statutory regulatory obligations differ from contractual and policy obligations. It is also jurisdiction- and sector-dependent, so the same relationship can carry different compliance exposure in different regions.

Best practices

Tier third parties by compliance exposure and calibrate the depth of screening, evidence, and reassessment to the risk tier rather than applying a uniform approach to every relationship.
Distinguish attestations and self-reported questionnaire responses from independently verified evidence, and require corroboration such as audit or testing for higher-risk relationships.
Supplement point-in-time onboarding due diligence with ongoing monitoring, including periodic reassessment and rescreening against sanctions and watchlists, so that compliance findings do not become stale.
Map applicable regulatory obligations by jurisdiction and sector for each relationship, recognizing that expectations vary regionally and that a control adequate in one regime may not satisfy another.
Seek visibility into Nth-party and subcontractor arrangements where feasible, and document where first-tier limits your view of deeper compliance exposure so that residual gaps are acknowledged rather than assumed away.
Separate regulatory compliance obligations from contractual and policy obligations in your assessments so that gaps in one are not masked by conformance in the other.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide