No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Career Connection
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Whitepapers & Reports
    • eBooks
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
  • Subscribe
  • Home
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Career Connection
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Whitepapers & Reports
    • eBooks
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
  • Subscribe
No Result
View All Result
Corporate Compliance Insights
Home Risk

Risk Assessment for Small and Mid-sized Companies

by Jeff Kaplan
July 3, 2014
in Risk
Risk Assessment for Small and Mid-sized Companies

There are a great many things one can do with a risk assessment, some of which are discussed in the complementary e-book CCI has recently published of my four years of risk assessment columns: Compliance & Ethics Risk Assessments:  Concepts, Methods and New Directions. But for quite a few companies – particularly those that are small or mid-sized, do not operate in heavily regulated businesses or are not located in high-risk geographies – something simple may be enough.

Einstein famously said, “Make everything as simple as possible, but not simpler.” With that in mind, here is a description of an eight-part risk assessment process that for some companies should be as simple as possible – but not overly so.

1. Appoint someone to be responsible for the process.  Typically, but not always, this will be the C&E officer or attorney responsible for C&E matters.  (The latter approach may be useful if you want the process to be protected under the attorney-client privilege.) She should be charged not only with managing the process, but also documenting the key parts.

2. This person should develop a list of possible risks.  Your own code of conduct is a start, but one should supplement that with lists from industry publications and other sources. Indeed, the CCI e-book has an appendix with a pretty extensive list of risks which may be helpful for these purposes.

3. Try to imagine (or get subject matter experts at your company to help you imagine) what the most likely scenarios would be for your company to violate the various laws identified in your list.  For instance, with antitrust – what products or markets are most vulnerable to horizontal restraints? For corruption, are your greatest risks dealing with the government as customer or as regulator, and what geographic locations should you focus on?

4. For each of these scenarios, ask yourself (or others helping you), what is the most likely cause of the risk? Is it a possible failure to understand/appreciate the applicable legal standard?  Is it a potential weakness in controls on third parties?   This is a key step, because the nature of the mitigation you need will often depend on this analysis.

5. For each risk identified and analyzed, inventory your current compliance measures – but note that you need only do so for the five “risk area sensitive” compliance tools: standards/policies, training/communications, process controls,  accountabilities and auditing/monitoring.  (Other tools – e.g., the helpline – tend not to vary by risk areas.)  More specifically, for each of these, ask: is what we currently have for this tool enough to mitigate the risk, or do we need something more – and if so, what?    The answers to these questions help form the basis for your annual risk management plan.

6. Ask yourself whether there should be any variations on the compliance tools by either business line or geography. For many small companies the answer will be no – but this is still a key part of the process.

7. Determine who in your company should receive the assessment and mitigation plan – e.g., the audit committee of the Board, a management compliance committee or perhaps others.

8. As part of the process, ask for each risk area: what should next year’s risk assessment look like?  Adding this step can help avoid reinventing the wheel and make a relatively simple process simpler still – at least over the long run.


Previous Post

Finding the Right Person to Serve as CRO

Next Post

In Due Diligence and World Cup Bids: Follow the Money

Jeff Kaplan

Jeff Kaplan

Jeffrey M. Kaplan is a partner in the Princeton, New Jersey office of Kaplan & Walker LLP. He has specialized since the early 1990s in the practice of compliance- and ethics-related law, including assisting numerous companies in developing, implementing and reviewing C&E programs and conducting C&E risk assessments. He has also reviewed programs for many official bodies in connection with settlements of enforcement actions. He is the co-author of a C&E legal treatise, author of several e-books — including “Compliance & Ethics Risk Assessment” — and book chapters and many articles on C&E, a frequent speaker at C&E conferences, editor of the Conflict of Interest Blog and formerly an Adjunct Professor of Business Ethics at NYU’s Stern School of Business.

Related Posts

SEC emblem on building exterior

The Rise of a New FINRA Risk & How to Navigate It

by Sarah Hutchins and Corri Hopkins
May 31, 2023

Reg BI says brokers should act in the best interest of their retail customers, but are they? Sarah Hutchins and...

washington dc cherry blossoms

National Conference Lessons Run the Gamut From Messaging Apps to Rebranding Compliance Training

by Mary Shirley
May 31, 2023

CCI columnist Mary Shirley shares some of the lessons she learned during this year’s national compliance conference in Washington, D.C....

parliament

Tracing Key Legal Developments in the UK’s AML Regime

by Prateek Swaika and Sagar Gupta
May 24, 2023

Prateek Swaika and Sagar Gupta of Boies Schiller Flexner discuss the regulatory framework of UK’s anti-money laundering regime and explore...

moby dick illustration

Whaling: When Business Leaders Become Cyber Weapons

by Aileen Allkins
May 24, 2023

The threat of cyber crime is nothing new for the average business. But new tools like AI mean fraudsters have...

Next Post
In Due Diligence and World Cup Bids: Follow the Money

In Due Diligence and World Cup Bids: Follow the Money

Compliance Job Interview Q&A

Jump to a Topic

AML Anti-Bribery Anti-Corruption Artificial Intelligence (AI) Automation Banking Board of Directors Board Risk Oversight Business Continuity Planning California Consumer Privacy Act (CCPA) Communications Management Corporate Culture COVID-19 Cryptocurrency Culture of Ethics Cybercrime Cyber Risk Data Analytics Data Breach Data Governance DOJ Download Due Diligence Enterprise Risk Management (ERM) ESG FCPA Enforcement Actions Financial Crime Financial Crimes Enforcement Network (FinCEN) GDPR HIPAA Know Your Customer (KYC) Machine Learning Monitoring RegTech Reputation Risk Risk Assessment Sanctions SEC Social Media Risk Supply Chain Technology Third Party Risk Management Tone at the Top Training Whistleblowing
No Result
View All Result

Privacy Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2022 Corporate Compliance Insights

No Result
View All Result
  • Home
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Career Connection
  • Events
    • Calendar
    • Submit an Event
  • Library
    • Whitepapers & Reports
    • eBooks
    • CCI Press & Compliance Bookshelf
  • Podcasts
  • Videos
  • Subscribe

© 2022 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT