Compliance risk differs from operational risk in one structural way: its source sits outside the organisation. A server failure is an event you can engineer against. A compliance risk exists because somebody wrote a rule that binds you, and that rule can change while nothing whatsoever happens inside your company.
That single property explains most of what follows, including why a compliance risk register goes stale faster than an operational one and why watching the legal landscape has to be part of the process rather than an annual chore.
What the risk actually is
Stated precisely, a compliance risk has three parts: a binding obligation, a plausible breach of it, and the consequences of that breach. Register only the middle part, "data protection breach", and you have written a keyword, not a risk.
The consequences run wider than the fines table suggests. Alongside penalties and damages sit exclusion from public procurement, supervisory orders up to and including prohibitions on carrying on an activity, loss of certifications and customer approvals, personal liability of the management body, and the sheer management time an official proceeding consumes simply by lasting.
Assessment starts with an obligations inventory
The starting point is a register of the obligations that apply to you, a legal register or obligations catalogue. Without it you assess the risks you already know about and miss the ones you do not. A missing register is the single most common finding in compliance reviews, and it is not a documentation problem: an organisation that cannot list its obligations cannot demonstrate that it manages them.
With that register in place, each obligation can be assessed along these lines.
| Dimension | Guiding question |
|---|---|
| Likelihood | How likely is a breach given today's processes and controls? |
| Impact | What sanctions, liability and business interruption would follow? |
| Likelihood of detection | Would a breach surface internally, or only through a supervisor, a customer or a whistleblower? |
| Effect on others | Who would be affected: staff, customers, data subjects, the wider public? |
| Reputational effect | How would a breach that became public land with customers, supervisors and your own workforce? |
Splitting the assessment into gross risk before controls and net risk after they take effect is worth the extra column. Only that split shows which controls actually carry weight and which merely exist on paper. Every assessment also needs a named risk owner; anonymous risks do not get treated.
Three properties to build into the method
First, compliance risks change through legal change rather than through operational events, so monitoring the legal environment belongs in the process itself.
Second, risk acceptance is bounded. A breach of mandatory law cannot be accepted on the grounds that treatment is too expensive. What can legitimately be prioritised is the route and the timetable, not whether the obligation is met.
Third, likelihood of detection behaves differently from the technical case. Whistleblowing channels, tax and regulatory inspections and customer audits are independent triggers, largely outside your control, and they do not follow the frequency curves an operational model assumes.
The German liability picture
If your group has a German entity, or a German counterparty is running due diligence on you, two provisions of German regulatory-offence law explain why compliance sits with the management body there rather than with a department.
§ 130 OWiG (the German Act on Regulatory Offences) sanctions the failure to supervise: the owner of a business who omits the supervisory measures necessary to prevent business-related contraventions commits an administrative offence. § 30 OWiG builds on that and allows a fine against the entity itself; the maximum amounts are ten million euros for intentional and five million euros for negligent criminal offences, while numerous sector statutes provide their own frameworks, some of them turnover-based.
On top of that sits company law. The duties of care of the management body under § 43 GmbHG (the German Limited Liability Companies Act) and § 93 AktG (the German Stock Corporation Act) include the duty to ensure compliance with the rules applicable to the company. A compliance risk in a German entity is therefore never only a corporate risk; it is always also a personal one for the people running it.
Where the assessment belongs
Risk assessment is not an end in itself but the joint between obligations and measures. In ISO 37301, the international standard for compliance management systems that superseded ISO 19600, assessing compliance risks is a load-bearing element. IDW PS 980, the German auditing standard for compliance management systems, places it among seven basic elements, alongside compliance culture, compliance objectives, the compliance programme, the compliance organisation, compliance communication, and compliance monitoring and improvement. COSO, with its five components, supplies the equivalent view for the internal control system.
The consequence is concrete: every material compliance risk should produce a named measure, a control, or a documented acceptance decision. Every control should produce evidence that survives a review.