For the person who has to sign, what is compliance risk management is a phrase that gets searched by two people: the one who wants a definition for a memo and the one who has to sign an attestation about it next quarter. This page is written for the second. For a regulated small business, what is compliance risk management comes down to a record and a set of figures: the record is the obligations, the controls, the evidence, the incidents, the cases and the attestations, kept with an owner, a date and a status; the figures are the evidence load that record puts on its reviewers, the days an audit of it takes, the gaps an audit will find and what they cost, the incidents and cases it produces, and the training it requires. The sections below explain what is compliance risk management in those terms, say what it is not, and show where the free sheets on this site work each figure from the programme's own numbers with no account.
What what is compliance risk management means in practice
For a regulated small business, it means being able to show, for each obligation, which control satisfies it, what evidence proves the control operated, who reviewed the evidence and who attested to the result. The record is the obligations, the controls, the evidence, the incidents, the cases and the attestations. The regulator's own material, linked below, says what the obligations are; this site publishes none of that and no legal advice. What it publishes is the arithmetic: the obligations register sheet turns the count of obligations, controls and evidence items into reviewer hours and the months to a full attestation.
The figures behind what is compliance risk management
Evidence items and reviewer hours; audit samples, days and coverage; expected gaps, remediation hours and cost; incident hours; case backlog months; training seats outstanding. Each is a free sheet on this site and each computes from the programme's own inputs. For regulatory compliance the sheet to start with is the obligations register sheet, which works the figure a regulated small business is examined on first. A programme that knows those numbers has stopped estimating its own compliance.
Risk management, scored
Compliance risk management is the ranking of obligations by what failing them would cost, on a scale the programme chooses, so that reviewer hours go to the obligations that matter. The HIPAA risk analysis sheet on this site works a score per item from likelihood and impact and the cost of the analysis; the same arithmetic ranks any programme's register.
What what is compliance risk management is not
It is not a certificate, a piece of software or a consultant's memo, although all three are sold under the name. It is a record and the figures that follow from it, kept by the business that owes the obligations. The guide this page supports covers choosing among regulatory compliance consulting firms, the help a small business buys around that record. Attestvio Pro keeps the record at one flat price; the sheets are free with no account.
Questions people ask about what is compliance risk management
What is what is compliance risk management?
For a regulated small business: keeping the obligations, the controls, the evidence, the incidents, the cases and the attestations as a record with an owner, a date and a status, and being able to show for each obligation the control, the evidence and the attestation. The regulator's own material, linked below, defines the obligations; the free sheets on this site work the arithmetic.
Who is responsible for what is compliance risk management in a small business?
The compliance officer, or the owner wearing that hat, who signs the attestation. The sheets on this site are written for that person and need no account.
Does Attestvio make a business compliant with regulatory compliance?
No. The business meets the obligations; Attestvio keeps the record and works the figures, and publishes no rule and no advice. Counsel and the regulator's own material say what the obligations are.