Skip to content
complianceofficer

Enterprise risk assessment software with risk assessment tools for compliance risk assessment

Risk assessment software turns a scoring exercise into a repeatable process: one methodology, questionnaires that reach the people who actually run the process, inherent and residual scores recorded separately, and an evidence trail showing how every number was reached. The hard part was never the arithmetic. It is keeping the assessment true after the rules underneath it move. Complianceofficer scores your obligations and then watches the regulations behind them, so an assessment flags itself when its own basis changes.

Run your first assessment now

Pick your sector below. The scan returns the obligation set a compliance risk assessment should be scored against, with each obligation linked to its primary source and the last 12 months of regulatory movement. No signup, nothing stored.

§ Live · Compliance scan

No signup. Nothing you pick is stored.

Frameworks you answer to

Sample register · fintech, US · what a scan returns

  • § 01 Written AML program with a named officer
  • § 02 KYC and customer due diligence
  • § 03 Sanctions screening lists Changed
  • § 04 PCI DSS v4.0 validation
§ 81 What the category covers

What risk assessment software actually does

Almost every organization already performs risk assessments. They live in a workbook a senior manager updates each spring, with a colour-coded grid and a column of scores whose origin nobody can reconstruct by autumn. That workbook is not wrong. It is unrepeatable, and unrepeatable is the specific thing an auditor, a regulator or a board committee will push on.

Software in this category exists to fix four things, in roughly this order of value. First, one methodology, so a likelihood of 3 means the same thing in the treasury assessment and the vendor assessment. Second, distribution, so the person who actually runs the reconciliation answers the question about the reconciliation instead of a director guessing on their behalf. Third, the inherent and residual split, recorded as two numbers with the controls that justify the gap between them. Fourth, the trail: who scored, what they saw, when it was approved, and what changed since last time.

The fifth thing, which most of the category does not do, is keep the assessment honest between cycles. A compliance risk scored as low because a rule was only proposed becomes a different risk the day that rule is final. Nothing in a conventional assessment tool knows that happened.

Assessment type What it scores Typical cadence Who signs it
Compliance risk assessment Failure to meet a specific legal or regulatory obligation Annual, plus on rule change Chief compliance officer
Enterprise risk assessment Strategic, operational, financial and reputational exposure Annual, reviewed quarterly Risk committee or board
Security risk analysis Threats to confidentiality, integrity and availability of data Annual, plus on system change Security officer
Vendor or third party assessment Exposure introduced by a supplier or service provider At onboarding, then by tier Procurement with compliance
Data protection impact assessment Risk to individuals from a high-risk processing activity Before processing begins Data protection officer
Fraud or AML risk assessment Money laundering, sanctions and fraud exposure by product and channel Annual, plus on new product BSA officer

Buyers often assume one tool should run all six. In practice the first three share a methodology and belong together; vendor assessment usually justifies dedicated vendor risk management software once the supplier count passes a few dozen.

§ 82 Scoring methodology

Inherent versus residual, and why recording only one number fails

Inherent risk is the exposure before any control is credited. Residual risk is what is left after the controls you actually operate are taken into account. The distance between those two numbers is the measured value of your control environment, and it is the single most useful figure a risk assessment produces.

Programs that record only residual scores lose that figure permanently. Everything looks acceptable, because of course it does, the controls are being credited silently. Then a control fails and nobody can say what the exposure just reverted to, because the pre-control number was never written down. The reverse failure, recording only inherent risk, produces a register where everything is red and nothing is actionable.

The discipline that makes the split real is naming the specific controls that justify the reduction. A compliance risk that drops from high to low needs to point at the controls doing that work, and those controls need evidence that they operated. Where an assessment tool and a control library are separate systems, this link is where the process quietly breaks: the score says low, the control has not been tested in three years, and nobody reconciles the two.

Step 01

Inventory the obligations

Start from the rules that bind you, cited to source. An assessment scored against a generic risk library measures somebody else's organization.

Step 02

Score inherent exposure

Likelihood against impact, with the scale defined in writing before scoring starts, and no credit given for any control.

Step 03

Map and test the controls

Name the controls that reduce each score and attach evidence that they ran. An untested control cannot justify a reduction.

Step 04

Set residual and re-trigger

Record what remains, compare it to appetite, and define the events that force a reassessment before the next annual cycle.

§ 83 Where it is mandatory

Where a risk assessment is legally required, not just advisable

A point that gets lost in vendor material: for a lot of US regulated organizations the risk assessment is not a governance nicety, it is a named requirement with a citation behind it. The clearest example is the HIPAA Security Rule, where risk analysis is one of the implementation specifications marked Required rather than Addressable, which means the flexibility that applies elsewhere in the rule does not apply to it.

The regulation reads: conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate. That text sits at 45 CFR 164.308(a)(1)(ii)(A), and its source credit shows it was last amended in 2013, so the HIPAA Security Rule updates proposed in January 2025 have still not changed it. Verified against the eCFR in August 2026.

Regime Citation What it requires
HIPAA Security Rule 45 CFR 164.308(a)(1)(ii)(A) Risk analysis, marked Required. Risk management at (B) is also Required.
Bank Secrecy Act AML program 31 CFR 1020.210 A risk-based program including risk-based ongoing customer due diligence, which only a documented assessment can evidence.
GDPR Article 35 A data protection impact assessment before processing likely to result in high risk to individuals.
ISO/IEC 27001:2022 Clause 6.1.2 A defined and repeatable information security risk assessment process producing consistent, comparable results.
PCI DSS v4.0.1 Requirement 12.3.1 A targeted risk analysis for each requirement the standard allows to be met flexibly.
SOX internal control COSO 2013, principles 6 to 9 Risk assessment is one of the five components management's framework must cover, including fraud risk.
OIG compliance program guidance GCPG, element 6 Risk assessment sits inside the monitoring and auditing element following the November 2023 reorganization.

Citations verified August 2026. The practical consequence of this table is that most regulated organizations owe several assessments to several supervisors on different cadences, which is exactly the workload regulatory compliance software exists to hold in one place.

§ 84 Assessment versus management

Risk assessment software or risk management software?

These are sold as the same thing often enough that it is worth separating them, because buying the wrong one is a common and expensive mistake. Risk assessment software runs the scoring event. Risk management software holds what happens between scoring events.

Assessment tooling owns the methodology, the questionnaire, the distribution list, the inherent and residual scores and the approval. Its output is a point-in-time picture with a defensible derivation. Management tooling owns the register that picture feeds, the risk appetite statement the scores are compared against, the treatment plans with owners and due dates, and the aggregation that reaches a board pack. Our enterprise risk management software page covers that second half in detail, including risk appetite and key risk indicators.

The diagnostic question is which half is currently failing. If your board gets a register but no one can explain how a risk earned its score, or two departments scored the same exposure differently, the assessment layer is the problem. If the scores are sound but nothing visibly changes as a result of them, the management layer is the problem. Buying a register when the methodology is broken just gives you inconsistent numbers in a nicer view.

§ 85 Questions

Risk assessment software questions, answered

What is risk assessment software?

Risk assessment software is a system that runs a repeatable scoring process over a defined set of risks: it holds the assessment methodology, distributes questionnaires to the people who know the process, scores likelihood against impact, records the controls that reduce each score, and stores the evidence trail showing who assessed what and when. The distinguishing feature against a spreadsheet is not the scoring math, which is simple. It is that the methodology is applied identically across every assessment and every cycle, so scores from different departments and different years can actually be compared.

What is a compliance risk assessment?

A compliance risk assessment scores the risk that an organization fails to meet a legal or regulatory obligation, rather than the risk of a business loss generally. It starts from an obligation inventory, the actual rules that bind you, then asks for each one how likely a failure is, how bad the consequence would be, and which controls currently reduce that exposure. The output is a ranked list of obligations where the residual risk exceeds what the organization is willing to accept, which is what drives the compliance work plan for the year.

What is the difference between inherent risk and residual risk?

Inherent risk is the exposure before any control is credited, and residual risk is what remains after the controls you actually operate are taken into account. The gap between the two numbers is the measured value of your control environment. Assessing only residual risk hides that value and makes it impossible to see what happens if a control fails, which is why regulators and auditors generally expect both scores to be recorded, along with the specific controls that justify the reduction.

Is a risk assessment required by law?

For many US regulated organizations, yes, and it is often written as a mandatory rather than optional step. The HIPAA Security Rule at 45 CFR 164.308(a)(1)(ii)(A) marks risk analysis as Required, not Addressable. GDPR Article 35 requires a data protection impact assessment for high-risk processing. ISO/IEC 27001:2022 clause 6.1.2 requires a defined information security risk assessment process. Bank Secrecy Act program rules require a risk-based approach that only a documented risk assessment can evidence.

What is the difference between risk assessment software and risk management software?

Risk assessment software runs the scoring event: the questionnaire, the methodology, the inherent and residual scores, the sign-off. Risk management software holds what happens between those events: the register, the risk appetite statement, treatment plans with owners and dates, and board reporting. Most buyers eventually need both, but they fail differently. If nobody can explain how a risk got its score, buy assessment first. If the scores exist but nothing is being done about them, buy management first.

How often should a compliance risk assessment be performed?

Annually is the common baseline for a full refresh, but the more useful rule is that an assessment is stale the moment one of its inputs changes materially. A new regulation, a new product line, a new jurisdiction, an acquisition, a failed control, or an enforcement action against a peer are all events that should trigger a targeted reassessment of the affected obligations rather than a wait for the annual cycle. Assessments that only move once a year tend to describe the organization as it was, not as it is.

§ 90

Related registers

§ 99 · Final entry

Get on the early-access list

Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.