Risk identification by area
A systematic review of every business area to identify where noncompliance could occur.
Risk assessment
Evaluating the likelihood and impact of every identified risk, to prioritize the response.
Risk treatment
Deciding how to treat each risk: additional controls, specific training or a justified acceptance.
What an auditor usually asks for
- A compliance risk map by area
- A documented likelihood and impact assessment
- A treatment plan with actions and owners
- Periodic review of the risk map
How to cover risk identification in Kimobox
- 1Log the compliance risk map with its likelihood and impact in Kimobox.
- 2Link each risk to its treatment plan and owner.
- 3Schedule periodic review of the risk map.
The risk map stays linked to the actions treating it, not a document reviewed once a year.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- ISO 19600:2014 — Compliance management systems. Guidelines (withdrawn) ISO · Withdrawn
- ISO 37301:2021 — Compliance management systems. Requirements ISO · April 2021