Compliance risk assessment
Identifying and assessing noncompliance risks by area, with their likelihood and impact.
Compliance objectives
Measurable objectives, consistent with the policy, with an action plan and an assigned owner.
Planning of changes
Assessing the compliance impact of any relevant change in the organization or its activity.
What an auditor usually asks for
- A compliance risk matrix by area
- Compliance objectives with an indicator, an owner and a date
- An action plan per objective with tracking
- A compliance impact assessment for relevant changes
How to cover planning in Kimobox
- 1Log the compliance risk matrix with its owner and linked action.
- 2Define compliance objectives with an indicator and let the system track them.
- 3Document the impact assessment for every relevant change.
The compliance risk map stays linked to the actions that mitigate it, not a static document.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- ISO 37301:2021 — Compliance management systems. Requirements with guidance for use ISO · April 2021
- Ley 2/2023 on the protection of persons who report regulatory breaches BOE-A-2023-4513 · 21 February 2023
- ISO 37001:2016 — Anti-bribery management systems ISO · 2016 ed.