Our own servers in Europe · GDPR · Support in your language

Module 2 of 5 · ISO 19600 · Section 2

Identifying noncompliance risks

ISO 19600 recommends a noncompliance risk map as the central tool for prioritizing where to put controls.

Content reviewed on

Risk identification by area

A systematic review of every business area to identify where noncompliance could occur.

Risk assessment

Evaluating the likelihood and impact of every identified risk, to prioritize the response.

Risk treatment

Deciding how to treat each risk: additional controls, specific training or a justified acceptance.

What an auditor usually asks for

  • A compliance risk map by area
  • A documented likelihood and impact assessment
  • A treatment plan with actions and owners
  • Periodic review of the risk map

How to cover risk identification in Kimobox

  1. 1Log the compliance risk map with its likelihood and impact in Kimobox.
  2. 2Link each risk to its treatment plan and owner.
  3. 3Schedule periodic review of the risk map.

The risk map stays linked to the actions treating it, not a document reviewed once a year.

See how objectives and indicators work in Kimobox

Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. ISO 19600:2014 — Compliance management systems. Guidelines (withdrawn) ISO · Withdrawn
  2. ISO 37301:2021 — Compliance management systems. Requirements ISO · April 2021