77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Conducting compliance risk analysis: template, method and assessment
Governance & Compliance

Conducting compliance risk analysis: template, method and assessment

2 August 202613 min readBy Dr. Henrik Bauer
CIVAC

Compliance risk analyses are required by IDW PS 980, ISO 37301 and § 130 OWiG. Read how to identify, assess, document and convert risks into a test-proof template that passes an audit.

A compliance risk analysis is the basis of every effective compliance management system according to IDW PS 980 (2022), ISO 37301:2021 and Section 130 OWiG. It requires an organisation to systematically determine which business processes are at risk of which legal and regulatory violations, with what probability of occurrence and what financial, criminal and reputational consequences. The result is a prioritised risk map that serves as a management tool for management and as evidence to auditors and supervisory authorities. Without this analysis, every CMS lacks the legal basis and the auditor can refuse the certificate.

This article explains the five phases of a compliance risk analysis, presents an auditable template with the necessary columns and evaluation logic and shows how you can transfer the results into the action and reporting process. The recipients are compliance officers, management and supervisory boards who are setting up their risk analysis for the first time, adapting it to new regulations such as NIS-2, LkSG or the EU AI Act or who need to sharpen the existing procedure according to the IDW-PS-980 audit. At the end you will receive a concrete column structure that you can copy into a table or into the CIVAC workspace, as well as information on the update frequency and the integration with internal auditing. The article focuses on the procedure and does not replace legal advice on individual cases, but it does provide a verifiable framework in which legal advice can begin efficiently.

Key Takeaways

  • According to IDW PS 980 and ISO 37301:2021, a compliance risk analysis is a mandatory part of an effective CMS.
  • The template must contain at least process, cause of risk, probability of occurrence, amount of damage, gross risk, control, net risk, measure, deadline and responsible person.
  • The analysis must be updated at least annually and as needed; every change is documented in an audit-proof manner.

Legal basis and auditor expectations for the risk analysis

The legal anchor of the compliance risk analysis lies in Section 130 OWiG, which standardises the supervisory obligation of management. Anyone who fails to take supervisory measures that would have been necessary to prevent violations is personally liable with a fine of up to 10 million euros in the event of intent in the corporate sector. The prerequisite for assessing necessity is knowledge of the risks, i.e. systematic risk analysis. IDW PS 980 in the 2022 version requires risk analysis as one of the seven basic elements of a CMS, ISO 37301:2021 requires in Section 4.6 the documented process of risk assessment and its regular review.

From the auditor's perspective, the risk analysis is the central document against which the effectiveness of the CMS is measured. An auditor according to IDW PS 980 regularly asks: Which risk areas have been identified? How were they rated? What controls are in place? How is the effectiveness of controls monitored? What residual risks remain and who has accepted them? The Compliance Officer must be able to provide documented answers to these five questions for each risk area. Others run compliance like a filing cabinet. We run it like software. The CIVAC workspace stores the answers as linked data objects so that the risk analysis, the control documentation and the list of measures are in a consistent data model and not in three parallel Excel files. Audit-proof, documented, Section 130-proof. Practical experience from fine proceedings also shows that a poorly documented risk analysis is viewed as an indication of an ineffective CMS and has an unfavorable influence on the assessment of fines in accordance with Section 30 OWiG. Conversely, a demonstrably effective CMS that is based on a current risk analysis can be taken into account in fine proceedings to mitigate punishment, as the Federal Court of Justice has recognised since 2017. The risk analysis is therefore not only a test document, but also a liability protection document for the management. This dual function justifies the effort required for careful maintenance.

Phase 1: Risk identification along the business processes

The first phase is the structured identification of all relevant compliance risks. Methodologically, the top-down approach has proven its worth along the central business processes: sales, purchasing, human resources, finance, IT, production, logistics, marketing and research. For each process, the relevant legal areas are reviewed: criminal corruption law, antitrust law, data protection, occupational safety, money laundering prevention, foreign trade law, tax law, competition and consumer protection law, supply chain due diligence obligations. The top-down approach is supplemented by bottom-up interviews with the departments, in which specific incidents, near-violations and suspicions are recorded.

The interviews result in risk descriptions that are formulated according to the cause-event-effect pattern. Example: The cause is the lack of separation between ordering and goods receipt in purchasing, the event is the manipulation of supplier master data, the effect is financial loss through bogus invoices and at the same time a breach of trust offense according to Section 266 of the Criminal Code. This three-level logic is mandatory because it allows both the control and the effect of the measures to be precisely located. The 490 ready-to-use audit templates in the CIVAC workspace contain industry-specific risk catalogues for industry, financial services, healthcare, IT and the public sector, which you can use as a starting point and add your specifics. Licence the workspace for your internal representatives or have our representatives appointed. The risk catalogue is identical in both models and is updated quarterly to include new regulations, such as the NIS 2 offenses or the EU AI Act obligations. The bottom-up interviews last around 60 to 90 minutes per department and are conducted using standardised key questions that are stored in the workspace. The protocols are recorded with date, participants and identified risks and linked to the risk analysis. Important: Risk identification must not be based on point-two-zero schemes. Standard catalogues are only the starting point, not the end point. Every organisation has specific risk areas that arise from the business model, market, customer structure, supplier structure and IT architecture and do not appear in the standard catalogue. These specifics are supplemented in the bottom-up interviews and are particularly acknowledged in the audit.

Phase 2: Assessment of probability of occurrence and amount of damage

The second phase is the assessment of each identified risk according to the probability of occurrence and the amount of damage. A five-stage scale has become established in practice: very low, low, medium, high, very high. What is important is the quantitative deposit of each stage. Very low can mean, for example: occurrence less than once every ten years and damage less than 50,000 euros. Very high can mean: occurrence several times a year or damage over 10 million euros. This quantification prevents the assessment in the annual workshops from becoming a question of faith and allows the risks to be compared over time.

The assessment is initially carried out as a gross risk, i.e. without taking existing controls into account. The existing controls that reduce the risk are then evaluated: four-eye principle, separation of functions, automated plausibility checks, training, audit routines, technical safeguards. The gross risk and the effectiveness of the controls result in the net risk, which describes the actual remaining risk. The appointment certificate, signed, filed, verifiable. This separation of gross and net is mandatory in IDW PS 980 and is checked first in the audit. The CIVAC platform links each control to the associated template and to internal audit evidence, so that the effectiveness assessment is not asserted but substantiated. The auditor calls, the evidence is ready. The assessment is also linked to the ISO/IEC 27001:2022 risk methodology for IT-related risks so that the assessment scales remain consistent across the regulations. A common weakness in risk analysis is the mixing of gross and net risk: the evaluators are already thinking about the controls when they are supposed to estimate the gross risk, and so produce unrealistically low values. The workspace carries out the evaluation in two separate steps so that the effect of the controls becomes visible and can be shown as an independent effect in the reporting to management and the supervisory board.

Phase 3: Risk matrix and prioritization of measures

The third phase is the visualization of the assessments in a risk matrix and the prioritization of the measures. The risk matrix is ​​a five-by-five matrix with probability of occurrence on one axis and amount of damage on the other. Each cell is categorised by colour: Green for accepted residual risks, Yellow for monitored risks with clearly defined triggers, Orange for risks with an action plan, Red for risks with immediate actions. This four-stage logic corresponds to the four possible responses to a risk according to ISO 31000: Avoid, Mitigate, Transfer, Accept.

The prioritization does not exclusively follow the position in the matrix, but takes into account three additional factors: regulatory obligations with hard deadlines, reputation sensitivity in the respective industry and the possibility of short-term quick wins through simple control reinforcement. A yellow risk with a regulatory deadline can be given higher priority than an orange one without a deadline. For each prioritised risk, a measure is defined, a person responsible is named, an implementation deadline is set and an effectiveness indicator is set. The appointment certificate, signed, filed, verifiable. Licence the workspace for your internal representatives or have our representatives order it. In the CIVAC workspace, the risk matrix is ​​dynamic: Anyone who changes a value can immediately see the impact in the list of measures and in the reporting to management. The matrix is ​​consolidated together with the data protection officer and the ISB, so that data protection and IT security risks are not shifted to a separate world, but appear as integral compliance risks. The risk matrix is ​​also linked to a versioned audit log so that every change in the assessment remains traceable and the historical development of the top risks can be evaluated over time. This trend presentation is particularly valuable in the annual report to the management because it makes the effect of compliance measures visible and underpins investments in strengthening controls with measurable effects.

Phase 4: List of measures with deadlines and responsible persons

The fourth phase is the transfer of the prioritised risks into a concrete list of measures. Every measure must meet four characteristics: it is specifically described, it has a responsible person with a name and function, it has a deadline, and it has a measurable indicator of effectiveness. A measure without an indicator is a declaration of intent, a measure without a deadline is a delayed decision, a measure without a named person gets lost in the hierarchy. The measures are tracked in status: open, in progress, implemented, effectiveness tested, closed. Only the last status allows the associated net risk to be reduced.

The list of measures is discussed at least quarterly in the compliance committee, which consists of management, compliance officers, internal audit, legal and, if necessary, other representatives. Delays will be recorded with reasons and a new date. If measures are repeatedly postponed, this is interpreted as a weakness in the CMS and documented in the IDW-PS-980 audit. Others run compliance like a filing cabinet. We run it like software. In the CIVAC workspace, the measures are linked to tickets, the status is automatically updated as soon as the assigned person documents the step in their system, and reporting to management is generated at the push of a button. The reporting line is clearly defined: from the responsible employee to the compliance officer to the management and annually to the supervisory board or advisory board, with acknowledgment of every step. Audit-proof, documented, Section 130-proof. Escalations are triggered based on predefined thresholds: a red risk without action within ten working days, a violation of a hard deadline under the GDPR, NIS-2 or LkSG immediately, a repeated failure to take action within three months. These thresholds are documented in the escalation matrix and approved by the supervisory board.

Phase 5: Documentation, updating and effectiveness testing

The fifth phase is the ongoing documentation and updating of the risk analysis. ISO 37301:2021 requires continuous monitoring of the CMS in Section 9.1, IDW PS 980 requires annual effectiveness testing. Occasional updates are required for significant business changes, new legislation, compliance incidents, audit findings and reorganizations. Every change to the risk assessment is versioned with date, author and reason, so that the audit can understand why a risk was upgraded or downgraded. Deadline begins as soon as we become aware of it. An update that occurs more than four weeks after the event became known will be critically examined in the audit.

The effectiveness check is carried out by the internal audit department or by a body independent of the compliance officer. It checks whether the controls identified in the risk analysis actually work, whether the measures have been implemented and whether the net risk confirms the assessment assumption. This audit results in an annual compliance report to the management. The CIVAC SLA is two business days instead of the industry standard two to six weeks, meaning short-term updates, such as after a compliance incident or a government request, are possible without a bottleneck. Licence the workspace for your internal representatives or have our representatives order it. Versioning occurs immutably in encrypted storage with EU data residency and ISO/IEC 27001:2022 protection level, so neither manipulation nor data leakage is possible. The effectiveness test also includes hearing samples of employees from the affected processes, because the formal existence of a control and its actual application in practice can differ. This sample hearing is documented in the workspace with the date, function and key statement without revealing the identity of the employees. Only when formal existence and actual application are confirmed is the control considered effective and the net risk is adjusted.

The column structure of the auditable template

A verifiable template for the compliance risk analysis contains at least the following 14 columns: serial number, risk area, process, risk description (cause-event-effect), legal reference (norm and paragraph), gross probability of occurrence, gross amount of damage, gross risk, control (description and reference), net probability of occurrence, net amount of damage, net risk, measure with deadline and person responsible, status of the measure. Optional but recommended additional columns are: risk owner in the specialist department, date of last assessment, trigger for reassessment, source (audit, interview, incident report) and link to other risk registers (GDPR, NIS-2, LkSG).

The template as an Excel table has the advantage of being easy to introduce, but the disadvantage of the lack of versioning and the lack of link to the control and measures data sets. At the very first audit, it becomes clear that the Excel columns and the measure trackers are maintained in different files and that the data diverges. Others run compliance like a filing cabinet. We run it like software. The CIVAC workspace converts the template into a relational data model with an immutable audit log so that every change has an associated rationale and the net risks are automatically updated when a control is validated and released. The FAQ and the knowledge database also link the relevant standards for each risk field, so that the research does not take place in the browser, but in the risk analysis itself. The template can also be exported with a colour heatmap representation, which is suitable as an attachment for the management meeting and can be adopted into supervisory board templates without further processing. The appointment certificate, signed, filed, verifiable. Licence the workspace for your internal representatives or have our representatives order it, the template and data flow are identical in both models and follow the same relational data model with immutable audit log.

Interlocking with ISMS, data protection risk analysis and LkSG

The compliance risk analysis must not be conducted in isolation. It is interlinked with three other risk analyses that are required by regulation: firstly with the data protection impact assessment according to Art. 35 GDPR, which is required for high-risk processing, secondly with the ISO/IEC 27001:2022 risk analysis in the ISMS, which is linked to the 93 controls from Annex A, thirdly with the risk analysis according to Section 5 LkSG, which is used for human rights and environmental risks the supply chain applies. These three analyses share data, assessment criteria and measures, but they are located in different legal regimes and must be presented in separate files depending on the auditor.

The neat interlinking succeeds when the compliance risk analysis, as a higher-level view, links all three analyses and keeps the assessments consistent where risks appear in several regimes. Example: A cyber incident is simultaneously a compliance risk (Section 130 OWiG), an ISMS risk (ISO 27001 A.5), a data protection risk (Article 32 GDPR) and potentially an NIS 2 incident with 24-hour early warning. The CIVAC workspace represents this multiple connection. Licence the workspace for your internal representatives or have our representatives order it; in both models you receive a consolidated view across the 25 representative roles. The information security officers work with the same risk methodology, so that the risk matrices from ISMS and CMS can be mapped directly to one another without having to laboriously compare two different scales. When consolidating, we recommend having the compliance committee meet once a year together with the data protection and information security officer to jointly prioritise the top ten risks from each regime and bundle measures where synergies exist. This shared prioritization prevents the typical situation in which three representatives, each with their own list, go to the management meeting and compete for the budget. Instead, there is a consolidated top list that can provide management with advice ready for decision-making. Audit-proof, documented, § 130-proof.

Turn risk analysis into an effective compliance engagement

The compliance risk analysis is not a one-time project, but an ongoing process. Anyone who updates it as an Excel table once a year meets the form, but not the substance. Anyone who builds it as a data-driven, versioned view that is linked to the controls meets both the form and the substance and also gains a control instrument that management actually uses. The 490 ready-to-use audit templates in the CIVAC workspace cover risk analysis, control documentation, the list of measures and reporting to management. You can have the process productive in two weeks, with appointment certificate, reporting line and initial risk analysis, instead of the traditional wait of two to six weeks per iteration.

CIVAC is a compliance platform and officer-as-a-service: you licence the workspace for your internal officers or you have our officers appointed, depending on the maturity of your organisation. In both models you receive the appointment certificate, the reporting line to management, the EU data residency and the ISO/IEC 27001:2022 hosting environment with 93 controls. The CIVAC SLA is two business days instead of the industry standard two to six weeks, and the risk analysis template is ready to use as a workspace module. Turn reading into an assignment. Write to info@civac.de or use the contact form if you want to set up your compliance risk analysis for the first time, adapt it to new regulations or completely outsource it. We deliver an initial analysis with five risk areas within ten working days, and the complete CMS risk analysis usually within four to six weeks. You will then receive a written report with a prioritised risk map, action plan and template for the next supervisory board meeting. The report will be discussed with you in a handover meeting so that non-legal members of the management can also classify and support the results.

FAQ

How often does a compliance risk analysis need to be carried out?

At least annually in accordance with IDW PS 980 in the 2022 version and ISO 37301:2021, as appropriate in the event of significant changes to business activities, new regulations, compliance incidents or reorganizations. Updates should ideally be made within four weeks of the event becoming known, otherwise they will be critically questioned in the audit. The workspace monitors the annual deadline and triggers preparation in a timely manner.

Do I need my own risk analysis for data protection and IT security?

Yes, formally yes, because GDPR Art. 35, ISO 27001 Appendix A and LkSG § 5 require separate risk analyses. In terms of content, however, these analyses are interlinked so that a risk is not assessed differently several times. The CIVAC workspace maintains the links in a consistent data model so that the gross risk from a compliance perspective and the risk from an ISMS perspective remain consistent.

What is the difference between gross risk and net risk?

The gross risk is the assessment without taking existing controls into account. The net risk takes into account the effectiveness of the controls in place, such as separation of functions, the dual control principle or automated plausibility checks. IDW PS 980 requires both assessments because this is the only way the effect of compliance investments can be seen and management can consciously accept the residual risk or initiate further measures.

Which columns must the template contain?

At least: serial number, process, risk description with cause-event-effect, legal reference, probability of occurrence and amount of damage gross and net, control, measure, deadline and person responsible as well as status. Optional columns capture risk owner, assessment date, reassessment trigger and links to GDPR, NIS 2 or LkSG registers. The template is available in the CIVAC workspace as a module with a relational data model and is immediately ready for use via the 37 audit templates.

Can I outsource risk analysis?

Yes, in CIVAC's Officer-as-a-Service model, an external compliance officer with an appointment document carries out the initial risk analysis, carries out the annual update and reports quarterly to the management. The management responsibility according to Section 130 OWiG remains within the company, the operational burden shifts to the external representative. Reporting line, appointment certificate and SLA are transparent in the order documentation.

How long does it take to create the initial risk analysis?

For a medium-sized company with clearly defined business processes, CIVAC expects four to six weeks for the complete initial analysis, including bottom-up interviews in the specialist departments and consolidation in the compliance committee. CIVAC delivers an initial analysis with five prioritised risk areas and an action plan within ten working days, based on the stored industry templates for industry, finance, health, IT and the public sector.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles