Single Blog

  • Home
  • Practical Guide to Compliance Risk Registers
Practical Guide to Compliance Risk Registers

Practical Guide to Compliance Risk Registers

August 27, 2026

A compliance risk register is often requested shortly before an audit, board meeting or regulatory review. At that point, a hurried spreadsheet can create more concern than confidence. A useful guide to compliance risk registers starts from a different premise: the register should show how the business understands its exposure, who owns it, and whether its controls genuinely work in practice.

For AML-regulated firms, this is not merely an administrative record. It is a working governance tool that connects the Business Risk Assessment, client due diligence processes, transaction monitoring, staff training, outsourcing oversight and senior management reporting. Maintained properly, it supports consistent decisions and provides evidence that risks are actively managed rather than acknowledged and forgotten.

What a compliance risk register should achieve

A compliance risk register records the risks that could prevent an organisation from meeting its legal, regulatory and internal obligations. It should make the relationship between a risk, the controls intended to manage it and the remaining exposure clear enough for management to make informed decisions.

For a payment business, for example, a risk may arise where onboarding controls do not reliably identify beneficial owners or high-risk jurisdictions. The register should not stop at a broad statement such as “KYC failure”. It should explain the relevant regulatory obligation, the affected activity, the potential consequence, the current controls, the responsible owner and the residual risk after those controls are considered.

That level of specificity matters. Regulators and internal audit teams need to see a traceable line from risk assessment to operational practice. Boards need a concise view of the issues that could lead to enforcement action, financial loss, customer harm or reputational damage. Operations teams need actions that are realistic to implement.

A register cannot replace a Business Risk Assessment or a client risk assessment. The BRA establishes the organisation’s wider exposure across customers, products, delivery channels, geography and other relevant factors. The register converts significant compliance risks into a managed programme of controls, monitoring and accountability.

Build the register around real regulatory exposure

The strongest registers are built from evidence, not copied from a generic template. Begin with the organisation’s regulatory perimeter, business model and documented risk assessments. Consider the services provided, client base, distribution model, jurisdictions served, reliance on third parties, systems used and volume or complexity of transactions.

AML and CFT exposure will be central for many regulated firms, but the register may also need to address sanctions compliance, data protection, conduct obligations, prudential requirements, complaints handling, conflicts of interest and reporting duties. The scope depends on the firm’s permissions, jurisdiction and operating model. A corporate service provider and an online gaming operator may both face AML obligations, yet their risk events, monitoring indicators and control environment will differ considerably.

Sources of evidence should include regulatory findings, internal audit reports, compliance monitoring results, suspicious activity reporting trends, customer file reviews, incidents, complaints, staff feedback and changes to legislation or guidance. Near misses are particularly valuable. A case that was corrected before it became a breach may reveal a weak control, an unclear procedure or an inappropriate system rule.

Describe the risk event, not just the topic

Vague labels make ownership and testing difficult. “Sanctions” is a topic. “A sanctioned person or entity is onboarded or retained because screening is incomplete, poorly configured or not reviewed following a relevant trigger event” is a risk event.

A clear risk description usually answers three questions: what could happen, why could it happen, and what would the consequence be? This approach helps distinguish related but separate risks. Incomplete screening at onboarding, delayed rescreening of an existing client and inappropriate handling of a potential match may require different controls and owners.

The essential fields in a compliance risk register

There is no single mandatory format, but a register needs enough detail to support challenge, action and reporting. In practice, each entry should capture at least the following:

  • a unique reference, risk title and clear risk description;
  • the relevant regulatory requirement, policy or internal standard;
  • the inherent risk rating before controls are applied;
  • existing preventive and detective controls, including control owners and frequency;
  • an assessment of control design and operating effectiveness;
  • the residual risk rating, risk appetite position and accountable risk owner;
  • treatment actions, deadlines, status and evidence of completion; and
  • review dates, triggers for reassessment and a record of material decisions.

The distinction between inherent and residual risk is especially important. Inherent risk reflects the exposure before controls. Residual risk reflects what remains after considering whether controls are suitably designed and operating effectively. If those ratings are identical throughout the register, the organisation may not be assessing control effectiveness with sufficient rigour.

Avoid treating a control as effective because a policy exists. A policy may set the correct expectation, but effectiveness depends on whether staff follow it, systems support it, exceptions are approved appropriately and evidence can be retrieved. A quarterly sample review may demonstrate that CDD files are checked, but it may also reveal that the sample is too small, outcomes are not reported or recurring errors are not remedied.

Score risks consistently, but do not let scores obscure judgement

Most organisations use likelihood and impact scales to determine a risk rating. This can provide useful discipline, provided definitions are clear. Likelihood might consider frequency, control failure history and the degree of manual intervention. Impact may include regulatory consequences, financial cost, customer impact, operational disruption and reputational harm.

The scoring methodology should be proportionate. A small, lower-risk firm may use a straightforward five-by-five matrix. A larger group may need separate financial crime, conduct and operational impact dimensions. More complex scoring is not automatically better. If management cannot explain why a risk is rated high or what would change that rating, the methodology is too detached from decision-making.

Risk appetite adds the necessary governance layer. A residual risk may be tolerable temporarily where a documented remediation plan is underway, but it should not be silently accepted. The register should state whether the risk sits within appetite, outside appetite or requires escalation. It should also record who accepted any temporary exposure and on what basis.

Connect controls to testing and remediation

A register becomes credible when it is linked to the compliance monitoring plan and internal audit activity. Each key control should be capable of being tested for both design and operation. Testing should ask whether the control addresses the identified risk and whether it was performed consistently, by an appropriately authorised person, with adequate evidence.

Consider a control requiring enhanced due diligence approval for high-risk clients. A meaningful test would examine whether the client was correctly risk-rated, whether source-of-wealth information was proportionate and corroborated, whether approval was obtained before the relationship commenced, and whether periodic review occurred on time. Counting approvals alone would not establish that the control is effective.

Where testing identifies a weakness, record a focused action rather than a broad promise to “improve compliance”. A useful action specifies the required outcome, accountable owner, target date, dependencies and how closure will be verified. For example, a remediation action could require revised screening rules, documented user acceptance testing, staff guidance and a retrospective review of potentially affected clients.

Closure should be evidence-based. An action is not complete when a procedure is drafted or a system change is requested. It is complete when the change has been implemented, embedded and tested to a level proportionate to the risk.

Make ownership visible at the right level

Compliance should facilitate and challenge risk management, but it should not own every operational risk. The first line usually owns the activity and controls. The compliance function provides oversight, advice and monitoring. Senior management and the board retain responsibility for governance, risk appetite and material decisions.

Assigning named owners prevents the register becoming a document maintained solely by compliance. Owners should be senior enough to direct resources and resolve obstacles. They should also understand the underlying process. Giving responsibility for an onboarding system control to a manager with no influence over operations creates an accountability gap that will surface during review.

Management reporting should focus on what requires a decision: risks outside appetite, overdue high-priority actions, deteriorating control performance, emerging regulatory developments and recurring findings. A board pack does not need every operational detail, but it should not reduce the register to a reassuring heat map with no explanation of exposure or response.

Review when the business changes, not only on a calendar date

A quarterly or semi-annual review cycle is sensible for many firms, but fixed dates alone are insufficient. The register should be reassessed when there is a material change in products, client profile, geography, technology, outsourcing arrangements, regulatory expectations or the volume and nature of alerts and incidents.

A new distribution partner, for instance, may change customer verification risk before the first client is onboarded. Similarly, a regulatory publication or enforcement outcome may require a review of existing controls even where the organisation has not experienced a failure. Proactive reassessment is usually less costly than remediation after a finding.

For organisations seeking a clearer view of their compliance exposure, Complipal can help translate regulatory requirements and operational evidence into a register that supports practical control improvements and defensible governance.

The value of a compliance risk register is not measured by the number of risks it contains. Its value lies in whether people use it to identify uncomfortable issues early, make accountable choices and show that compliance obligations are being managed with care, evidence and integrity.