No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • The Business of GRC
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Risk

Risk Assessment – By the Book

by Jeff Kaplan
March 24, 2014
in Risk
stack of old leather bound books with antique pocketwatch

Nothing is more important to developing and maintaining an effective C&E program than risk assessment, and effective risk assessment is, as a general matter, perhaps the most daunting task a C&E officer is likely to face.  The challenges are both conceptual (a surprising lack of consensus on what the point of a risk assessment is) and practical (getting business people and others to be candid and thoughtful about what they may view as unpleasant and unnecessary topics).

But C&E risk assessment has been an expectation of the U.S. government since the 2004 amendments to the Federal Sentencing Guidelines for Organizations, and anti-corruption compliance standards of other countries are turning these expectations into something of a global mandate. Beyond this, many companies’ C&E programs are in desperate need of some sort of refreshment – and, as much as any program function, a risk assessment can provide a powerful foundation for this.

To help companies and their advisors meet these and related challenges, I’ve assembled my CCI risk assessment columns for the past four years into an e-book – Compliance and Ethics Risk Assessment: Concepts, Methods and New Directions, which is available for free download here.  The book – which, in addition to past columns, has new content, including a comprehensive list of legal risk areas and a very detailed index – covers such topics as:

  • The government’s expectations regarding risk assessment.
  • Why assessing the “nature” of the risk is critically important to – but missing from – many assessments.
  • A framework for assessing third-party risks.
  • “Nano compliance,” meaning identifying risks that may be very specific to a location, business area or function but are still significant.
  • Refresher risk assessments.
  • Assessing managers’ C&E risks.
  • Use of the attorney-client privilege in risk assessment.

The book also looks at risk assessment in several key substantive areas – competition law, conflicts of interest, corruption and insider trading.  Additionally, it explores practical ways of turning risk assessments into risk mitigation plans and points of intersection between risk assessment and program assessment. Finally, the book looks at some new directions risk assessments can take, including assessing genuine ethics risks (which very few companies do) and incorporating key learnings from social science (particularly behavioral ethics) into one’s assessment approach.

So, that’s risk assessment “by the book.” But to learn more, you don’t need to “buy the book” – just click on the above link for a free download.

Tags: Anti-CorruptionCorporate Communication
Previous Post

Contracts and Compliance: What You Don’t Know Might Hurt You

Next Post

5 Risk Categories for Focusing the Board’s Risk Oversight

Jeff Kaplan

Jeff Kaplan

Jeffrey M. Kaplan is a partner in the Princeton, New Jersey office of Kaplan & Walker LLP. He has specialized since the early 1990s in the practice of compliance- and ethics-related law, including assisting numerous companies in developing, implementing and reviewing C&E programs and conducting C&E risk assessments. He has also reviewed programs for many official bodies in connection with settlements of enforcement actions. He is the co-author of a C&E legal treatise, author of several e-books -- including "Compliance & Ethics Risk Assessment" -- and book chapters and many articles on C&E, a frequent speaker at C&E conferences, editor of the Conflict of Interest Blog and formerly an Adjunct Professor of Business Ethics at NYU’s Stern School of Business.

Related Posts

recycled materials label on plastic bottle

With New EU EmpCo Rules, Greenwashing Moves From Reputation Risk to Compliance Risk

by Andreas Pyrcek
September 25, 2026

Seemingly innocuous wording could bring fines under new EU framework

manage subscription page on phone

New York City’s ‘Click to Cancel’ Rule Reinforces Important Auto-Renewal Requirements

by Zach Lerner, Maddie Rana and Emma Bourgeois
September 17, 2026

Rules may be mostly familiar, but the practical significance of the NYC regime lies in enforcement

brazil flag

New Terrorist Designations in Brazil Mean New Compliance Requirements

by Rafael Antal
September 16, 2026

More listings by the US are likely, and each round seems to roil a new set of companies

doj scoular collage

The State of FCPA Enforcement: Fewer Cases, but Risk Remains

by Thad McBride
September 16, 2026

Corporate FCPA enforcement is down, but enforcement involving international business, especially under export controls and economic sanctions, remains active, Thad...

Next Post
interlocking-boards-sec

5 Risk Categories for Focusing the Board’s Risk Oversight

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • The Business of GRC
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights