What Is Compliance Risk Management?

Photo of author
Written By Chris Ekai

What is compliance risk management? It is the process an organization uses to identify the laws, regulations, and standards it must follow, assess where and how it could breach them, put controls in place against the highest-rated breaches, and monitor whether those controls keep working. The output is an obligations register with owners, ratings, and evidence.

On August 3, 2026, the Financial Crimes Enforcement Network assessed a $125 million civil money penalty against UBS Financial Services Inc., the largest ever imposed on a broker-dealer under the Bank Secrecy Act. The firm had already paid $14.5 million in December 2018 for the same failure to monitor foreign currency wires.

FinCEN found that more than 50,000 wires worth over $10 billion went unmonitored after that first settlement, that due diligence on high-risk clients in Russia and Latin America was inadequate, and that hundreds of suspicious activity reports were never filed. Director Andrea Gacki said repeat violators jeopardize the integrity of the financial system.

What Is Compliance Risk Management: The Bottom Line

Compliance risk management is the process of identifying the laws, rules, and standards an organization must follow, assessing where it could break them, putting controls in place, and monitoring whether those controls work. The Basel Committee defined the underlying risk in April 2005.

FinCEN fined UBS Financial Services $125 million on August 3, 2026, the largest broker-dealer penalty under the Bank Secrecy Act. The firm had settled for $14.5 million in December 2018 over the same monitoring gap and then left more than 50,000 foreign currency wires unmonitored.

The cycle has four stages: identify obligations, assess the risk of breaching each, control the highest-rated ones, and monitor with indicators and testing. The output is an obligations register, and the worked example below builds one for a broker-dealer.

Global AML, KYC, and sanctions penalties totalled $3.8 billion in 2025, down from $6.6 billion in 2023 (Fenergo, January 13, 2026). Falling totals mean fewer very large cases, and they say nothing about any one firm’s exposure.

PwC’s Global Compliance Survey 2025 found 85 percent of 1,802 executives say compliance requirements grew more complex in three years, and 77 percent say that complexity hurt the business in five or more areas.

Ownership follows the IIA Three Lines Model: business units own the risk, the compliance function oversees it, and internal audit tests both. A program whose second line also runs the controls has no independent check.

 

UBS had a compliance department, a written program, and a prior consent order telling it what to fix. The 2018 settlement did not remedy the underlying monitoring gap, according to Troutman Pepper Locke’s analysis.

Having a compliance function and managing compliance risk are different things, and the gap between them is the subject of every consent order cited below.

What Is Compliance Risk Management? The Definitions Regulators Use

The Basel Committee on Banking Supervision defined compliance risk on April 29, 2005 as the risk of legal or regulatory sanctions, material financial loss, or loss to reputation a bank may suffer from failing to comply with laws, rules, and standards. Managing that risk is the compliance function’s job under ten principles the paper sets out.

US bank supervisors use the term compliance management system for the same set of activities. The OCC’s Comptroller’s Handbook booklet describes a CMS as the way a bank learns its obligations, assigns responsibility, and reviews performance against them. The FDIC’s examination manual breaks it into board oversight, a compliance program, and a compliance audit.

Source

How it defines the concept

Where it applies

Basel Committee, BCBS 113 (April 2005)

Compliance risk is the risk of sanctions, financial loss, or reputational loss from failing to comply with laws, rules, and standards; ten principles for the compliance function

Banks worldwide; adopted by most prudential supervisors

OCC and FDIC compliance management system

The system by which a bank manages the entire consumer compliance process: board oversight, program, and audit

US national banks, thrifts, and state non-member banks

Federal Reserve SR 08-8 (October 2008)

Firmwide compliance risk management with independence, board reporting, and testing across business lines

Large complex banking organizations

ISO 37301:2021

Requirements for a compliance management system built on obligations identification, risk assessment, and controls, certifiable by audit

Any organization, any sector, any country

DOJ Evaluation of Corporate Compliance Programs (September 2024)

Three questions: is the program well designed, is it applied earnestly and in good faith, does it work in practice

Any company facing a US criminal investigation

Outside banking, ISO 37301:2021 is the certifiable standard, and the Department of Justice’s guidance for prosecutors is the document that decides whether a program counts at charging time. Our explainer on compliance risk covers the risk itself; compliance risk management is the process of managing it.

Compliance risk sits inside operational risk in most taxonomies, alongside fraud, conduct, and technology failure. It is distinct from compliance management, which is the day-to-day work of meeting each requirement, and from compliance in business as a general culture. Compliance risk management is the layer that decides which requirements get the most control effort.

Risk type

What goes wrong

How compliance risk differs

Credit risk

A borrower or counterparty fails to pay

Compliance risk is about the firm’s own conduct, not a counterparty’s

Market risk

Prices, rates, or currencies move against a position

Compliance breaches are not hedged; they are prevented or detected

Operational risk

Failed processes, people, systems, or external events cause loss

Compliance risk is the subset where the failure is a breach of a rule or standard

Legal risk

Contracts are unenforceable or litigation succeeds

Overlaps heavily; compliance risk includes regulatory sanctions that never reach a court

Reputational risk

Stakeholders lose confidence

A consequence of compliance failure rather than a separate cause

Why Compliance Risk Management Fails After the First Penalty

The UBS case is the clearest recent example of a program that existed on paper and failed in practice, and it was not alone in 2026. On March 6, 2026, FinCEN assessed $80 million against Canaccord Genuity LLC for failures between March 2018 and June 2024, then the broker-dealer record until UBS surpassed it five months later.

What Is Compliance Risk Management?

Figure 1. The UBS Financial Services penalty of August 3, 2026 in four figures, drawn from the FinCEN news release.

Canaccord failed to file at least 160 suspicious activity reports on over-the-counter securities trading. Holland & Knight’s summary of the consent order records four employees reviewing more than 100 surveillance reports a year, some left unreviewed for up to four years, alerts filtered on arbitrary thresholds, and nearly 400 falsified documents. The SEC and FINRA each added $20 million.

Both firms had compliance departments and both failed at compliance risk management, as OKX did before them. None linked known obligations to the resources assigned to them. The NYU compliance and enforcement program notes that FinCEN cited chronic under-investment as a cause at Canaccord, which is a resourcing decision made by management, not an oversight by a compliance officer.

Action

Date

Control that failed

Penalty

UBS Financial Services (FinCEN)

August 3, 2026

Transaction monitoring of foreign currency wires; CDD on high-risk clients; SAR filing

$125M, up to $15M waived on completion of an independent AML review

Canaccord Genuity (FinCEN, SEC, FINRA)

March 6, 2026

Surveillance review staffing; alert thresholds; independent testing; document integrity

$80M with $40M credited to SEC and FINRA; $5M suspended pending lookback

OKX / Aux Cayes Fintech (DOJ)

February 24, 2025

Money transmitter registration; KYC that let US users trade against the firm’s own policy

$504M: $420.3M forfeiture and $84.4M fine; three-year monitor

United Texas Bank and Community Federal Savings Bank (OCC)

July 2026

BSA/AML compliance program deficiencies

Cease-and-desist consent orders

Enforcement totals are falling and that is easy to misread. Fenergo’s analysis released January 13, 2026 counted $3.8 billion in AML, KYC, sanctions, and customer due diligence penalties in 2025, down from $4.6 billion in 2024 and $6.6 billion in 2023. North American fines fell 58 percent while EMEA rose 767 percent.

What Is Compliance Risk Management?

Figure 2. Global penalties for AML, KYC, sanctions, and customer due diligence failures, 2023 to 2025, per Fenergo.

A smaller global total means fewer very large cases and says nothing about any one firm’s odds. The first half of 2025 alone produced 139 penalties worth $1.23 billion, a 417 percent rise on the same period of 2024 according to Fenergo’s mid-year figures. Sanctions fines in that half year rose from $3.7 million to $228.8 million.

The Ponemon Institute’s 2017 study with Globalscape, summarized by Thomson Reuters, put the average cost of compliance at $5.47 million a year and the average cost of non-compliance at $14.82 million, a ratio of 2.71. Deloitte argues boards should question the productivity of that spend rather than its size.

The Four-Stage Cycle: Identify, Assess, Control, Monitor

Every compliance risk management framework in the first table reduces to the same loop, and ISO 37301 clause 4.5 makes the first stage explicit: identify compliance obligations and evaluate the risks of not meeting them. The four stages below map to the generic risk management process that ISO 31000 describes, with compliance-specific inputs at each step.

Stage

What the compliance team does

Output

Standard that requires it

1. Identify obligations

Inventory every law, regulation, licence condition, code, and contract clause the firm is subject to, by entity, product, and jurisdiction

Obligations register with a source, an owner, and a change date for each entry

ISO 37301 clause 4.5; Basel principle 7; OCC CMS booklet

2. Assess the risk

Rate the likelihood of breaching each obligation and the impact if it happens; weight for enforcement history, control maturity, and transaction volume

Rated register; heat map; list of obligations above appetite

ISO 37301 clause 4.6; DOJ ECCP risk assessment questions; Fed SR 08-8

3. Control the top risks

Design preventive and detective controls for high-rated obligations: policies, system limits, training, monitoring rules, approval gates

Control library mapped to obligations; RCSA results

Basel principle 7; USSG section 8B2.1(b)(2) to (b)(5)

4. Monitor and test

Track key risk indicators, run compliance testing, review breaches and near misses, feed results back to the register

KRI dashboard; testing reports; board compliance report

Basel principles 7 and 8; DOJ ECCP monitoring and data questions; ISO 37301 clause 9

Stage one is where most compliance risk management programs are weakest, and it is the stage FinCEN faulted at both broker-dealers. A compliance risk assessment that starts from a partial obligations list rates the wrong things. The guide to risk identification explains the search techniques; for compliance, the product of that search is the obligations register.

Assessment uses the same likelihood and impact scales as the rest of the operational risk framework, with two compliance-specific weights: how actively the regulator enforces that obligation, and how much transaction volume passes through it. The compliance risk analysis guide shows the scoring; the bank template gives a worked scale.

What Is Compliance Risk Management?

Figure 3. What 1,802 executives told PwC’s Global Compliance Survey 2025 about complexity, business impact, technology spend, and scope.

The assessment stage is getting harder because the obligations list keeps growing. PwC’s Global Compliance Survey 2025 found 85 percent of 1,802 executives say compliance requirements became more complex in the last three years, rising to 90 percent in financial services. Nearly 90 percent say their compliance responsibilities widened over the same period.

Stages three and four are where the risk controls and key risk indicators sit. The DOJ’s September 2024 revision, summarized by Covington & Burling, now asks prosecutors whether the compliance function has access to the same data the business uses, and whether monitoring resources are proportionate to the risk. Both are stage-four questions.

The indicators below are the ones we would put on a compliance risk management dashboard first. Each one maps to a failure that FinCEN, the SEC, or FINRA named in a 2025 or 2026 order, so a board can ask why any of them is missing:

  • Surveillance alerts open beyond 30 days, and the oldest open alert in days
  • Suspicious activity reports filed late against the 30-day BSA deadline, as a count and a percentage
  • High-risk customers whose enhanced due diligence review is past due
  • Regulatory changes logged in the last quarter that have no assigned owner or control
  • Compliance testing findings open past their agreed remediation date
  • Ratio of alerts to analysts, tracked monthly, because Canaccord’s four staff to 100 reports a year was the number FinCEN quoted

A Worked Obligations Register for a Broker-Dealer

The register below applies the four stages to a mid-sized US broker-dealer with international clients, using the obligations FinCEN, the SEC, and FINRA cited in 2026. Ratings use a five-point scale for likelihood and impact, and the residual column shows the rating after the listed controls. Adapt the entries with the RCSA template.

Obligation and source

Breach scenario

Inherent (L x I)

Key controls

Residual

Maintain a risk-based AML program (31 CFR 1023.210; FINRA Rule 3310)

Program exists on paper but monitoring rules are not tuned to product mix and client geography

4 x 5 = 20

Annual independent test; monitoring rule review after any new product or market; board sign-off on scope

2 x 5 = 10

File SARs within 30 days of detection (31 CFR 1023.320)

Alerts age past 30 days because review staff are outnumbered

4 x 4 = 16

Alert-to-analyst ratio KRI with a hiring trigger; escalation at day 20; monthly aged-alert report to the CCO

2 x 4 = 8

Customer due diligence and beneficial ownership (31 CFR 1010.230)

High-risk clients in Russia, Latin America, or sanctioned-adjacent sectors onboarded without enhanced review

3 x 5 = 15

Risk-rated onboarding workflow; EDD refresh at 12 months for high-risk; second-line approval for tier-one jurisdictions

2 x 4 = 8

Sanctions screening (OFAC 31 CFR Part 501)

Screening lists lag list updates or exclude wire counterparties

3 x 5 = 15

Daily list refresh; screening of all wire parties; quarterly false-negative testing

1 x 5 = 5

Foreign currency wire monitoring (BSA transaction monitoring expectations)

Wires routed through a channel the monitoring system does not read

3 x 5 = 15

Data lineage map of every payment channel to the monitoring feed; reconciliation of wire volumes monthly

1 x 5 = 5

Records retention and document integrity (SEC Rule 17a-4)

Staff backdate or alter review records to close findings

2 x 5 = 10

Immutable audit log on the case management system; sample re-performance by internal audit

1 x 5 = 5

The fifth row is the UBS failure and the second row is the Canaccord failure, and both have controls that cost far less than the penalties. A data lineage map for payment channels is a one-time exercise; the aged-alert KRI is a query. The KRI examples directory lists a hundred more indicators with thresholds.

The register only works if the residual ratings are compared with a stated appetite. A compliance risk appetite statement for this firm might read: no tolerance for unfiled SARs; low tolerance for alerts aged over 30 days, capped at 2 percent of open alerts. Sector examples show how banks and insurers phrase these.

Regulatory obligations also arrive through third parties. The sanctions screening guide and the financial crime lifecycle cover the vendor and correspondent side. For broker-dealers, the OCC’s July 2026 enforcement list shows the same BSA program deficiencies appearing at the community banks that provide their payment services.

Who Owns Compliance Risk: The Three Lines Model

The Australian Prudential Regulation Authority’s three lines of accountability remain a sound reference. APRA’s CPS 230 Operational Risk Management, in force since July 1, 2025, requires regulated entities to identify and manage operational risks, including compliance risk, with clear accountability at each line. The IIA’s Three Lines Model from July 2020 is the international reference.

Line

Compliance risk role

Evidence it is working

Common failure

First line: business units

Own the obligations that apply to their products; operate the controls; report breaches

Control owners named in the register; breaches self-reported before testing finds them

Business treats compliance as the compliance team’s job and starves it of data

Second line: compliance function

Maintain the register; set policy; rate the risks; monitor and challenge the first line; report to the board

Independent reporting line to the board or a board committee; unrestricted data access (DOJ ECCP 2024)

Compliance also operates the controls, so no one challenges it

Third line: internal audit

Test the design and operation of the compliance program; verify second-line monitoring

Audit plan covers the top-rated obligations each year; findings tracked to closure

Audit relies on compliance’s own testing and re-performs nothing

Board and CEO

Set appetite; approve the program; resource it in proportion to the risk

Board minutes show compliance reporting and resourcing decisions

Board receives breach counts with no trend, appetite comparison, or root cause

The three lines of defense explainer goes deeper on the model. In our experience the second line is the most frequently misdesigned: compliance teams that write the policies, run the monitoring, and clear the alerts have no one checking their work, which is the design the Federal Reserve’s SR 08-8 letter warned about in 2008.

The DOJ adds a fourth party to the model. Under the US Sentencing Guidelines section 8B2.1, an effective program requires that specific high-level personnel be assigned overall responsibility and that the board exercise reasonable oversight. Culpability scores fall when those two things are documented, so the risk culture question has a dollar value at sentencing.

Projects change obligations faster than annual reviews catch. New products, new markets, and new systems each add entries to the register, which is why the project manager’s role in compliance risk deserves a formal gate. A GRC platform can hold the register, the controls, and the testing evidence in one place; it cannot decide what belongs in it.

Where Compliance Risk Management Programs Break Down

Regulators publish the failure modes in every consent order, so the list below is drawn from the 2025 and 2026 actions cited above. Each row names the trap, the case that illustrates it, and a fix that costs less than the penalty. The compliance requirements overview covers the obligations side of the same list.

Trap

Where it showed up

Fix

Remediating the finding, not the cause

UBS fixed the 2018 items and left the wire-monitoring gap that produced the 2026 penalty

Root-cause analysis on every regulatory finding; register entry updated with the cause, not the symptom

Staffing set by budget rather than by volume

Canaccord: four employees for 100-plus surveillance reports a year

Alert-to-analyst KRI with a hiring trigger; resourcing shown to the board against volume

Unreviewed monitoring output

Canaccord surveillance reports unread for months to four years

Aged-alert report to the CCO monthly; anything over 30 days escalates

Arbitrary alert filtering

Canaccord thresholds set to reduce workload rather than risk

Threshold changes need second-line approval and a documented risk rationale

Policy that the business ignores

OKX kept a written ban on US users while onboarding them

Control testing that samples actual customers against policy, not the policy text

Falsified or backdated records

Nearly 400 documents at Canaccord

Immutable case management logs; internal audit re-performs a sample

Data the compliance function cannot see

DOJ ECCP 2024 asks this question directly

Data access for compliance written into the program charter and tested

What Is Compliance Risk Management?

Figure 4. Average annual cost of compliance against the cost of non-compliance in the Ponemon Institute’s 2011 and 2017 benchmark studies.

Figure 4 is the case for funding stages three and four. Ponemon’s 2017 sample put non-compliance at 2.71 times the cost of compliance, and Secureframe’s 2026 compilation reports 82 percent of PwC respondents plan more compliance technology spend while only 38 percent in NAVEX’s 2025 survey considered more staff. Technology without reviewers reproduces the Canaccord problem.

One more trap sits outside any consent order: treating the register as a compliance document rather than a management one. COSO’s 2020 guidance with the SCCE, Compliance Risk Management: Applying the COSO ERM Framework, places compliance risk inside the enterprise risk management framework so the board sees it beside credit, market, and strategy.

Common Compliance Risk Management Questions Practitioners Ask

What is compliance risk management in simple terms?

Compliance risk management is finding out which rules apply to your organization, working out where you are most likely to break them and what it would cost, putting controls on those points, and checking that the controls work. It produces an obligations register, and the compliance risk definition explains the risk the register is managing.

What is the difference between compliance risk management and compliance management?

Compliance management is doing what each rule requires: filing the report, running the training, screening the customer. Compliance risk management decides which rules get the most control effort by rating the likelihood and impact of breaching each one. A firm can be fully staffed for compliance management and still fail the risk part, as UBS did between 2018 and 2026.

What are the four steps of compliance risk management?

Identify the obligations, assess the risk of breaching each one, control the highest-rated risks, and monitor whether the controls hold. ISO 37301 clauses 4.5 and 4.6 cover the first two steps, while Basel principle 7 covers the compliance function’s control and monitoring duties and principle 8 covers internal audit’s testing. The compliance risk assessment guide walks through the assessment step.

Who is responsible for compliance risk management?

Business units own the obligations and operate the controls, the compliance function maintains the register and challenges the business, and internal audit tests both. The board sets appetite and resources the program. The US Sentencing Guidelines require named high-level personnel with overall responsibility, and the DOJ checks whether that person had authority and data access.

What does a compliance risk management framework include?

A framework includes the obligations register, the assessment method and scales, the control library mapped to obligations, the monitoring indicators and testing plan, the reporting lines to the board, and the change process for new laws and products. ISO 37301 is the certifiable version; the Basel Committee’s ten principles and the OCC’s CMS booklet are the supervisory versions.

How is compliance risk management different from operational risk management?

Compliance risk is a subset of operational risk in the Basel taxonomy, covering losses that arise from breaching laws, rules, and standards. Operational risk management also covers process failures, fraud, system outages, and external events that break no rule. The two share scales, registers, and the three lines model, and many firms run them from one function.

What tools support compliance risk management?

A GRC platform for the register, controls, and testing evidence; a transaction monitoring system with tuned rules; a regulatory change feed that pushes new obligations into the register; and a case management system with an immutable audit log. None of these replaces the analysts who review the output. FinCEN’s 2026 orders cited under-resourced review teams at both broker-dealers.

The Road to 2027: FinCEN Whistleblowers and AI Oversight

Two changes will reshape stage four before the end of 2027. FinCEN proposed a whistleblower program on March 30, 2026 that would pay 10 to 30 percent of penalties above $1 million for AML and sanctions tips, per Mayer Brown’s analysis. Staff who can see unreviewed alerts now have a financial reason to report externally.

The other change is the DOJ’s AI question: since September 2024 prosecutors ask whether a company assessed the risks of the AI it uses. Thomson Reuters’ ten concerns for 2026, published December 11, 2025, ranks tech-enabled fraud first and ethical AI use second. The Basel Committee’s 2008 implementation review already expected human ownership of automated compliance.

Rebuild the obligations register before either change takes effect. Start with the entities, products, and jurisdictions that carry the most transaction volume, rate them against enforcement history, and give every high-rated obligation a named owner and a monitored indicator. APRA’s operational risk pages describe the same expectation for Australian entities under CPS 230.

If your last compliance risk assessment predates your newest product line, we rebuild the register against ISO 37301, the Basel principles, and the DOJ’s 2024 questions. The services page lists the engagement formats and the contact page reaches us directly. UBS paid $125 million for a gap a lineage map would have shown.